Sionic AI Inc. — Privacy Policy

    Sionic AI Inc. (the “Company”) complies with the Personal Information Protection Act (“PIPA”) and related laws to protect the freedom and rights of data subjects, processing personal information lawfully and managing it securely. In accordance with Article 30 of PIPA, the Company establishes and discloses the following privacy policy (this “Policy”) to inform data subjects of the procedures and standards for processing personal information and to handle related grievances promptly and smoothly. This Policy has been drafted in accordance with the laws of the Republic of Korea. For data subjects residing in overseas jurisdictions, matters concerning the rights of the data subject and the obligations of the Company under the laws of such jurisdiction may additionally apply, and in such case the Company will provide the relevant information through a separate supplementary policy or supplementary provision.

    Article 1 (Purpose, Items, and Retention Period of Personal Information Processing)

    1. The Company processes data subjects’ personal information as follows. However, the retention and use period shall extend to the end of the relevant period where retention is required and not subject to destruction under applicable law.

    ServicePurpose of ProcessingItems ProcessedProcessing and Retention Period
    Membership registration and managementTo confirm intent to register, identify and authenticate the member, maintain and manage membership status, prevent fraudulent use, deliver notices, and handle grievances<Required> name, address, contact, company name, email<Optional> occupationUntil membership withdrawal
    Service provision and performance improvementService provision and performance improvement, error verification, technical research and development, content provision, customized services<Required> name, address, contact, email, items entered by the user during service use, personal information contained in uploaded files and output results<Optional> occupation, company name5 days from membership withdrawal, or until consent is withdrawn
    Inquiry and complaint handlingTo verify the identity of the inquirer/complainant, confirm and respond to inquiries/complaints, contact/notify for fact-finding, and notify processing resultsname, company name, contact, email3 years from membership withdrawal
    Social (SNS) sign-upSocial (SNS) sign-up<Required> nickname, email<Optional> profile image, locale (region and language)Until membership withdrawal
    PaymentFee payment, invoice issuance, payment-card registration and payment, collection<Required> credit card number, card expiration date, financial account (holder, account number), date of birth (business registration number for businesses), emailUntil membership withdrawal

    2. The personal information processed by the Company is not used beyond the purposes stated in Paragraph 1, and where the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of PIPA.

    3. The Company processes and retains personal information within the retention and use period prescribed by law or consented to by the data subject at the time of collection.

    4. The Company does not collect sensitive information that may infringe the data subject’s fundamental human rights (such as race and ethnicity, ideology and belief, place of origin, political orientation, criminal records, and health status) except with the data subject’s consent or as provided by law.

    5. The data subject has the right to refuse consent to the collection and use of personal information. However, refusal to consent to required items may render the service unavailable or restrict service provision; refusal to consent to optional items may restrict all or part of the services that require such optional items.

    6. The Company permits registration by data subjects aged 14 or older and does not collect or use the personal information of children under the age of 14.

    Article 2 (Processing of Children’s Personal Information)

    The Company’s website and online services are not intended for individuals under the age of 14, and the Company does not knowingly collect, sell, or share the personal information of children under 14. If a parent or legal guardian believes that the Company has collected a child’s personal information, please contact the Company immediately at the contact set out in Article 13 (Chief Privacy Officer) of this Policy.

    Article 3 (Provision of Personal Information to Third Parties)

    The Company processes the data subject’s personal information within the scope specified in the purposes of processing, and provides it to third parties only to the minimum extent and only where Articles 17 and 18 of PIPA apply, such as the data subject’s consent or special provisions of law.

    The Company does not “sell” the data subject’s personal information, nor does it “share” it for cross-context behavioral advertising.

    Article 4 (Entrustment of Personal Information Processing)

    1. For the smooth processing of personal information, the Company entrusts personal information processing tasks as follows.

    Entrustee (Recipient)Entrusted Tasks
    Amazon Web Services, Inc.Data storage and operation/management of computing systems
    OpenAI OpCo, LLC / OpenAI, LLCGeneration, summarization, and analysis of text based on given information, and agent development
    NAVER CorporationGeneration, summarization, and analysis of text based on given information, and agent development
    Microsoft, Inc.Generation, summarization, and analysis of text based on given information, and agent development
    Anthropic, PBCGeneration, summarization, and analysis of text based on given information, and agent development
    Cohere Inc.Embedding extraction
    New Relic, Inc.Operation of a monitoring system to track and analyze performance, errors, and usage behavior
    Re-entrustee (Sub-processor)Entrusted Tasks
    OpenAI, LLCGeneration, summarization, and analysis of text based on given information, and agent development

    2. When entering into an entrustment contract, the Company specifies in the contract or other documents, in accordance with Article 26 of PIPA, matters concerning the prohibition of processing beyond the purpose of the entrusted tasks, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the entrustee, and liability for damages, and supervises whether the entrustee processes personal information safely.

    3. If the content of the entrusted tasks or the entrustee changes, the Company will disclose it without delay through this Policy.

    Article 5 (Overseas Transfer of Personal Information)

    The Company transfers personal information overseas as follows, in accordance with Article 28-8, Paragraph 1 of PIPA. If you do not wish your personal information to be transferred overseas, you may request the suspension of such overseas transfer through the Chief Privacy Officer or the department in charge of personal information. If you refuse the overseas transfer, your use of the Service may be restricted.

    EntityCountry·Time·Method of TransferItems TransferredRecipient’s Purpose of UseRetention and Use PeriodContact of the Information Manager
    Amazon Web Services, Inc.United States, Japan / network transmission at the time of service useSame as the collection purpose, items, and the processing and retention period set out in Article 1Same as the collection purpose, items, and the processing and retention period set out in Article 1Same as the collection purpose, items, and the processing and retention period set out in Article 1aws-korea-privacy@amazon.com
    OpenAI, OpCo LLCUnited States / remote transmission via API integration during service usePersonal information entered/uploaded by the user during service useText generation/summarization/analysis based on given information, and agent developmentSame as the processing and retention period set out in Article 1privacy@openai.com
    Microsoft, Inc.United States / remote transmission via API integration during service usePersonal information entered/uploaded by the user during service useText generation/summarization/analysis based on given information, and agent developmentSame as the processing and retention period set out in Article 1Microsoft Corporation (82 (2) 5314840)
    Anthropic, PBCUnited States / remote transmission via API integration during service usePersonal information entered/uploaded by the user during service useText generation/summarization/analysis based on given information, and agent developmentSame as the processing and retention period set out in Article 1privacy@anthropic.com
    Cohere Inc.United States / remote transmission via API integration during service usePersonal information entered/uploaded by the user during service useEmbedding extractionSame as the processing and retention period set out in Article 1privacy@cohere.com
    New Relic, Inc.United States / network transmission upon monitoring integrationPersonal information entered/uploaded by the user during service useOperation of a monitoring system to track and analyze performance, errors, and usage behaviorSame as the processing and retention period set out in Article 1privacy@newrelic.com

    Article 6 (Procedure and Method of Destroying Personal Information)

    1. The Company destroys personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.

    2. Where personal information must continue to be retained under other laws even after the retention period has expired or the processing purpose has been achieved, the Company transfers it to a separate database (DB) or stores it in a different location.

    3. The procedure and method of destroying personal information are as follows.

    (i) Destruction procedure: The Company selects the personal information for which a destruction cause has arisen and destroys it upon approval of the Company’s Chief Privacy Officer.

    (ii) Destruction method: For personal information recorded and stored in paper documents, the Company shreds or incinerates it; for personal information stored in electronic files, the Company uses technical methods that render the records irreproducible.

    Article 7 (Rights of the Data Subject and Legal Representative and How to Exercise Them)

    1. The data subject may, at any time, exercise rights against the Company, such as requesting access to, correction, deletion, or suspension of processing of personal information.

    2. Rights may be exercised against the Company in writing, by email, by facsimile, etc., in accordance with Article 41, Paragraph 1 of the Enforcement Decree of PIPA, and the Company will act on them without delay.

    3. Rights may be exercised through a representative such as the data subject’s legal representative or a duly authorized agent. In this case, a power of attorney in the form of Annex 11 of the Notice on the Method of Processing Personal Information (No. 2023-12) must be submitted.

    4. Requests for access and suspension of processing may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of PIPA.

    5. Where the personal information is specified as subject to collection under other laws, its deletion may not be requested.

    6. Upon a request for access, correction/deletion, or suspension of processing, the Company verifies whether the requester is the data subject or a legitimate representative.

    7. The Company acts on the data subject’s request to exercise rights within the period prescribed by applicable law, and where there is an unavoidable delay, notifies the data subject of the reason and the processing schedule.

    Article 8 (Measures to Ensure the Safety of Personal Information)

    The Company takes the following measures to ensure the safety of personal information.

    1. Administrative measures: establishment and implementation of an internal management plan, operation of a dedicated organization, and regular employee training.

    2. Technical measures: management of access rights to personal information processing systems, installation of an access control system, encryption of personal information, and installation and updating of security programs.

    3. Physical measures: access control to computer rooms, data storage rooms, etc.

    Article 9 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof)

    1. The Company uses “cookies,” which store and frequently retrieve usage information, to provide individually customized services to users.

    2. Cookies are small pieces of information that the server operating the website sends to the user’s computer browser and may be stored on the hard disk of the user’s PC.

    (i) Purpose of cookies: to understand visit and usage patterns, popular search terms, and secure-connection status for each service and website visited, in order to provide optimized information to users.

    (ii) Installation, operation, and refusal of cookies: you may refuse the storage of cookies through the option settings in the Tools > Internet Options > Privacy menu at the top of your web browser.

    (iii) If you refuse the storage of cookies, you may experience difficulty using customized services.

    Article 10 (Collection, Use, and Refusal of Behavioral Information)

    1. The Company collects and uses behavioral information to provide data subjects with optimized, customized services and benefits and online customized advertising in the course of service use. The data subject may refuse the collection and use of behavioral information, in which case service use may be restricted.

    2. Items collected: the user’s service visit date/time, service usage records, access IP information, cookies, and usage screens / Collection method: automatic collection upon service visit or execution / Purpose: to improve service performance, provide technical support, and provide personalized product recommendation services (including advertising) based on user interests and tendencies / Retention and use period: until membership withdrawal or withdrawal of consent.

    3. The Company collects only the minimum behavioral information necessary for online customized advertising, etc., and does not collect sensitive behavioral information that may clearly infringe an individual’s rights, interests, or privacy, such as ideology, belief, family and kinship relations, education/medical history, and other social activity history.

    4. The Company does not collect behavioral information for customized advertising purposes from children known to be under 14 or from online services primarily used by children under 14, and does not provide customized advertising to children known to be under 14.

    5. The Company collects and uses advertising identifiers for online customized advertising on mobile devices. The data subject may block or allow customized advertising in apps by changing the settings of the mobile device.

    Android: Settings → Privacy → Ads → Reset advertising ID or Delete advertising ID

    iPhone: Settings → Privacy → Tracking → Turn off Allow Apps to Request to Track

    ※ Menus and methods may differ somewhat depending on the mobile OS version.

    6. The data subject may collectively block or allow online customized advertising by changing the cookie settings of the web browser. However, changing cookie settings may affect the use of some services, such as automatic website login.

    Microsoft Edge: Settings > Privacy, search, and services > Tracking prevention

    Chrome: Settings > Privacy and security > select a blocking method under Third-party cookies

    Article 11 (Use of Data for AI Model Training)

    1. Matters concerning the processing and use of data that a user inputs or uploads in the course of using the Service (hereinafter "Input Data") and the results of processing thereof (hereinafter "Output Data") shall be governed by the Company's Terms of Service.

    2. The Company may analyze and utilize the Input Data and Output Data processed in the API service and the STORM Platform console for the purposes of providing the Service, improving its features, verifying errors, and conducting technical research and development. When analyzing or utilizing such data, the Company shall take measures necessary to ensure safety.

    3. Where a user does not wish to have its Input Data or Output Data used, under Paragraph 2, for the training or research of artificial intelligence models, the user may select the parsed-file deletion option when making an API call, or request exclusion from the training data in accordance with the procedures established by the Company. Upon receipt of such a request, the Company shall exclude the relevant data from the scope of training and research.

    Article 12 (Use and Provision of Personal Information Within a Scope Reasonably Related to the Collection Purpose)

    The Company may use or provide personal information to third parties without the user’s consent, within a scope reasonably related to the original collection purpose, taking into account the following criteria.

    1. Whether it is related to the original collection purpose

    2. Whether additional use or provision is foreseeable in light of the circumstances of collection or processing practices

    3. Whether it unfairly infringes the user’s interests

    4. Whether measures necessary to ensure safety, such as pseudonymization or encryption, have been taken

    Article 13 (Chief Privacy Officer)

    1. The Company designates a Chief Privacy Officer as follows, who is overall responsible for personal information processing tasks and for handling data subjects’ complaints and remedies related to personal information processing.

    NameDeokhyun Kim
    PositionHead of Development
    Contactprivacy@sionic.ai

    Personal information protection department: Information Security Team / Contact person: Deokhyun Kim / Contact: privacy@sionic.ai

    2. The data subject may direct any inquiries, complaints, and requests for remedy relating to personal information protection arising from the use of the Company’s services to the Chief Privacy Officer and the department in charge. The Company will respond to and handle the data subject’s inquiries without delay.

    Article 14 (Request for Access to Personal Information)

    The data subject may submit a request for access to personal information under Article 35 of PIPA to the department below. The Company will endeavor to process the data subject’s access request promptly.

    Department: Information Security Team / Contact: privacy@sionic.ai

    Article 15 (Methods of Remedy for Infringement of Rights)

    1. To obtain remedy for personal information infringement, the data subject may apply for dispute resolution or counseling with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency’s Personal Information Infringement Report Center, etc. For other reports and counseling on personal information infringement, please contact the agencies below.

    ContactPhoneWebsite
    Personal Information Infringement Report Center(no area code) 118https://privacy.kisa.or.kr/
    Personal Information Dispute Mediation Committee(no area code) 1833-6972https://www.kopico.go.kr/
    Supreme Prosecutors’ Office Cybercrime Investigation Division(no area code) 1301http://www.spo.go.kr/
    National Police Agency Cyber Safety Bureau(no area code) 182https://www.police.go.kr/

    2. The Company guarantees the data subject’s right to self-determination of personal information and endeavors to provide counseling and remedies for personal information infringement. If you need to report or consult, please contact the Information Security Team (contact person: Deokhyun Kim, privacy@sionic.ai).

    3. A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution regarding a request under Articles 35 (Access), 36 (Correction/Deletion), or 37 (Suspension of Processing) of PIPA may file an administrative appeal in accordance with the Administrative Appeals Act. (Central Administrative Appeals Commission: 110, www.simpan.go.kr)

    Addendum

    (1) This Privacy Policy takes effect on June 29, 2026.