Privacy Policy
CUBIG CORP. ("CUBIG", "the Company") protects personal information processed through its on-premises product LLM Capsule and related web, download, and support channels ("the Service").
We comply with the Personal Information Protection Act and all other relevant laws.
This policy explains how CUBIG collects, uses, and protects personal information, and how users ("data subjects") may exercise their rights.
1. Purpose of Processing Personal Information
CUBIG processes personal information only within the scope of the purposes below. If a purpose changes, we take the necessary measures, such as obtaining separate consent as required by law.
| Category | Purpose of Processing |
|---|---|
| Membership registration / account management | Confirm registration intent, identify and authenticate the user, set organisation/permissions, and maintain account security (notifying of unusual activity). |
| Service provision and maintenance | Issue and verify licences, provide technical support (tickets), announce updates/patches, and post outage and security notices. |
| Enquiry and complaint handling | Respond to customer enquiries, provide notices and announcements, and retain dispute-mediation records. |
| Payment / settlement (optional) | Bill and settle maintenance fees and issue tax invoices (primarily B2B for corporate clients). |
| Security / access logs (minimum required) | Record administrator portal access, detect abnormal access, and protect accounts. |
2. Items of Personal Information Processed
CUBIG destroys personal information without delay once its purpose is achieved. Where retention is required by law, the data is kept for the applicable statutory period.
| Category | Items Collected / Used |
|---|---|
| Sign-up (registration & login) |
[Required] Email (ID), encrypted password, organisation/role [Optional] Name, company name, department/position, phone number |
| Social sign-up | [Optional] Minimum information provided by the social login provider (email, profile, etc.) |
| Provision of goods and services | Licence/serial, administrator account, update history, access logs (IP/browser/OS, minimally collected) |
| Enquiries / complaints | Email, name, phone number, enquiry content |
| Payment / settlement | Payment-gateway / tax-invoice processing data (contact name, business registration details, payment identifier) |
3. Processing and Retention Periods
CUBIG processes and retains personal information within the retention/use period required by law or the retention/use period consented to at the time of collection.
The processing and retention periods for each type of personal information are as follows.
- Website membership registration and management: until membership withdrawal. Information that must be preserved under applicable law is retained for the statutory period.
- Provision of goods or services: until delivery and payment/settlement are complete. Usage and activity records generated during use, for fraud prevention, complaint handling, and litigation response, are retained for five years after withdrawal.
- Enquiries / complaints: five years after withdrawal, or the statutory period where the law requires preservation.
- Payment / settlement: five years after withdrawal, or the statutory period where the law requires preservation.
4. Provision of Personal Information to Third Parties
CUBIG does not provide personal information to third parties except in the following cases.
- The data subject has given consent.
- There is a special provision of law, or a lawful request from an investigative authority.
- For corporate (organisation) accounts, the minimum information needed for administration — such as member account details and access status — may be provided to or viewed by the organisation administrator. (Using a serial licence is deemed consent to provision within this scope.)
5. Outsourcing of Personal Information Processing
To provide services smoothly, CUBIG outsources the personal-information processing tasks below and supervises the contractors in accordance with the Personal Information Protection Act. Each outsourcing contract stipulates limits on re-outsourcing, technical and administrative safeguards, and liability in the event of an incident.
| Contractor | Outsourced Task | Items Provided (Processed) | Retention / Use Period |
|---|---|---|---|
| Naver Cloud Corp. (NCP) | Sending SMS for registration, identity verification, etc. | Mobile number, authentication code, delivery log (timestamp/success status, etc.) | For the duration of delivery completion and log retention (period per relevant law or contract) |
| Google LLC | Provision of SMTP / mail-transmission system (sending and receiving enquiry email) | Enquiry-form input (email address, name, enquiry content, access records, etc.) | For the period transmission and storage are required (company mail retention policy or relevant law) |
| PayPal | Payment processing via overseas cards | Payment ID/transaction number, order/authorisation data, payment-method token (masked), amount/currency, buyer identifier (e.g. email), and IP/device and other data required for payment security | Until payment, membership withdrawal, or termination of the outsourcing contract |
6. Cross-Border Transfer of Personal Information
CUBIG may transfer personal information overseas as follows. Users have the right to refuse the cross-border transfer, but refusal may limit service use (receiving enquiry email, payment, etc.).
| Recipient & Items Transferred | Country / Recipient | Transfer Timing & Method | Purpose | Retention / Use Period |
|---|---|---|---|---|
| Google LLC Enquiry-form input (email address, name, enquiry content) and transmission-related metadata |
United States | Real-time transfer over the network upon enquiry submission (encrypted communication) | Mail transmission/storage and customer-enquiry support (operating the company email system) | Per company mail retention policy or relevant law |
| PayPal Transaction/identification/security data required for payment processing (same scope as the third-party table above) |
United States | Real-time transfer over the network upon payment authorisation request (encrypted communication) | Payment authorisation/settlement, fraud prevention, customer support | Until payment, membership withdrawal, or termination of the outsourcing contract |
7. Rights and Duties of the Data Subject and How to Exercise Them
- Users may request to view (inspect), correct (amend), or terminate their contract (withdraw membership) regarding their personal information.
- Users may withdraw consent to the provision of personal information at any time. However, withdrawal may limit use of the Service.
- A user or their legal representative may request to view, correct, or terminate their contract in writing, by phone, or by email to the Personal Information Protection Officer or a contact person, and CUBIG will act without delay. However, the ID required for service management cannot be changed.
- Users must keep their personal information current; users are responsible for problems arising from inaccurate information they enter.
- Registering by misappropriating another person's personal information may result in loss of user status or penalties under applicable data-protection law.
- Users are responsible for keeping their email, password, and similar credentials secure, and may not transfer or lend them to third parties.
- If a user enters false information, such as by misappropriating another person's data, membership may be revoked.
- Users must comply with the Act on Promotion of Information and Communications Network Utilisation and Information Protection, the Personal Information Protection Act, the Resident Registration Act, and other relevant laws.
- The rights under paragraph 1 may be exercised through the data subject's legal representative or an authorised agent. In that case, a power of attorney in the form of Schedule 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
8. Automatic Data-Collection Devices (Cookies): Operation and Refusal
What Are Cookies
CUBIG uses "cookies", which store and periodically retrieve user information, to provide personalised and customised services.
A cookie is a very small text file that the server operating a website sends to the user's browser and stores on the hard drive of the user's computer.
On subsequent visits, the website server reads the cookie stored on the user's hard drive to maintain the user's preferences and provide customised services.
Cookies do not automatically or actively collect personally identifying information, and users may refuse or delete stored cookies at any time.
Purpose of Cookies
Cookies are used to understand visit and usage patterns, popular search terms, and the scale of users across each of CUBIG's services and websites, in order to provide optimised, personalised information including advertising.
Installation, Operation, and Refusal of Cookies
Users have a choice over cookie installation. By setting options in the web browser, users can allow all cookies, be prompted each time a cookie is stored, or refuse the storage of all cookies.
However, if you refuse cookie storage, some of CUBIG's services that require login may be difficult to use.
You can specify whether to allow cookie installation as follows.
- Internet Explorer: Tools menu > Internet Options > Privacy tab > set the privacy level
- Chrome: Settings menu > Show advanced settings > Privacy — Content settings > set the cookie level
- Safari: Preferences menu > Privacy tab > set the Cookies and website data level
9. Procedures and Methods for Destroying Personal Information
When the retention period elapses or the processing purpose is achieved, CUBIG destroys the information without delay. Information in electronic file form is deleted by an irrecoverable method, and paper documents are shredded or incinerated.
- Grounds for destruction: expiry of the retention period, achievement of the processing purpose, withdrawal of consent, etc.
- Method of destruction: electronic files are deleted irrecoverably; paper documents are shredded/incinerated.
- Partial destruction: items that must be kept by law even after the purpose is achieved are stored separately and destroyed immediately when the period expires.
10. Personal Information Protection Officer and Contact
Officer: Ha Heonseok
Position: CPO
Email: [email protected]
11. Remedies for Infringement of Personal Information (Government Agencies)
Users may contact the agencies below for remedies or advice regarding infringement of personal information. These are government agencies; please contact them if you are not satisfied with CUBIG's own complaint handling or remedy for personal-information damage, or if you need detailed assistance.
| Agency | Contact |
|---|---|
| Personal Information Infringement Reporting Centre | Website: https://privacy.kisa.or.kr Phone: 118 (no area code) |
| Personal Information Dispute Mediation Committee | Website: https://www.kopico.go.kr Phone: 1833-6972 |
| Supreme Prosecutors' Office Cyber Investigation Division | Website: http://www.spo.go.kr Phone: 1301 (no area code) |
| National Police Agency Cyber Bureau | Website: https://cyberbureau.police.go.kr Phone: 182 (no area code) |
12. LLM Capsule-Specific Notice (On-Premises / Encapsulation Policy)
- On-premises principle: business data is processed and stored within the customer's infrastructure, and CUBIG does not access it by default.
- External integration policy: where external LLM integration is required, only encapsulated (pseudonymised/masked) data is transmitted; external transmission of original data is prohibited by default.
- Access control during remote support: where unavoidable remote support (such as fault analysis) is required, CUBIG follows the principles of prior approval, session logging, and least-privilege access.
- Remote/telemetry (optional): transmission of minimal diagnostic information (error codes, version, module status, etc.) for quality improvement is operated on an opt-in (consent-based) basis and does not include business-data content.
13. Changes to This Privacy Policy
This Privacy Policy takes effect on 1 October 2025.
If the Privacy Policy is revised, the change will be announced on the website before it takes effect.