Legal

Artificial Intelligence (AI) Services Operation Policy

Effective Date: July 3, 2026

This translation is provided for convenience only. In case of any discrepancies between this translation and the original in Korean, the original in Korean shall prevail.

The purpose of this Operation Policy (hereinafter referred to as this "Policy") is to establish the rights, obligations, scope of liability, and legal compliance issues of business clients who are parties to the contract (hereinafter referred to as the "Client") and Software Creation Studio (hereinafter referred to as the "Company") in relation to the use of AI-based solutions provided by the Company (PolyBot, PolyGlot, and all AI SaaS provided hereinafter, collectively referred to as the "AI Services").

Article 1 (Data Governance and Confidentiality)

The Company prioritizes the intellectual property rights and data security of the Client and complies with applicable legislation.

1. Ownership of Data

All intellectual property rights over the prompts, source code, databases, documents, and other elements that the Client inputs into the AI Services (hereinafter referred to as the "Input Data"), as well as the results generated by the AI system in response to them (hereinafter referred to as the "Output Data"), generally belong to the Client.

2. Prohibition of Use for Retraining

The Company does not use any data input by the Client as data for further refinement, weight adjustment, or retraining of the AI model. However, fully pseudonymized and aggregated statistical information that does not allow for the identification of individuals or the Client (e.g., average response time, error rates, token consumption, etc.), used to monitor service quality and ensure system stability, does not constitute retraining data and may only be used for service operation improvement purposes.

Stored data is subject to encryption technologies compliant with industry standards, such as AES-256, and transmissions are encrypted using TLS. Furthermore, once the purpose of service provision is fulfilled, data is securely deleted or pseudonymized in accordance with applicable legislation and the internal data retention policy.

(※ Related legislation: Personal Information Protection Act, Article 21 (Destruction of personal information))

3. Real-time Pseudonymization of Personally Identifiable Information (PII) National and International and Global Regulatory Compliance

When processing the AI Services, if not only personal information and unique identifying information under the Personal Information Protection Act of Korea are detected but also Personally Identifiable Information (PII) defined by the laws and standards of other countries, the Company will pseudonymize (mask) it using applicable technical safeguards before transmitting it to the language model.

This includes PII in accordance with U.S. federal government regulations and NIST guidelines, as well as the definition of personal information under the European GDPR, and applies technical and administrative safeguards to mitigate the risk of the Client violating global regulations.

Specific technical specifications applied to the pseudonymization of PII (detection method, scope of masking, processing flow, etc.) are provided in a separate technical document upon the Client's request.

(※ Related regulations: Personal Information Protection Act of Korea, Article 29; NIST SP 800-122 of the U.S. (guidelines for PII protection); European GDPR, Article 4, Paragraph 1 (definition of personal data))

4. Strict Isolation of PolyBot Session and Conversation Memory

When providing the AI chatbot solution service (PolyBot), each conversation session of the Client and the context memory used are loaded and processed in a logically isolated independent area within a multitenant environment.

To prevent memory confusion or data interference with other Clients or sessions, logical isolation, access control, and other technical and administrative safeguards are applied. Upon completion of the corresponding conversation session or termination of the contract, the real-time stored memory data is securely deleted or pseudonymized in accordance with applicable legislation and the internal data retention policy.

5. Recommendation for Control and Filtering of Sensitive Information

Despite the Company's real-time pseudonymization (masking) measures and memory isolation, the Client must fulfill its own management and oversight duties to prevent its authenticated users from excessively inputting trade secrets, undisclosed financial data, or third-party trade secrets.

6. Notice Regarding Third-Party AI Model Providers

For the provision of AI Services, the Company may utilize language models or APIs from third-party AI model providers (hereinafter referred to as "AI Subcontractors"). In such cases, the Company guarantees, through contracts with the AI Subcontractors, the obligations to prohibit the use of Client data for retraining, data security, and confidentiality, and will notify the Client in writing in advance when there is a change in AI Subcontractor.

Article 2 (Technical Limitations and Disclaimers)

Since these AI Services are based on generative language models and machine learning algorithms, the following technical limitations exist.

1. Disclaimer Regarding the Accuracy of Output Information (Hallucinations)

Due to the nature of AI technology, the Output Data may contain partially inaccurate or biased information, or hallucination phenomena (hereinafter referred to as "hallucinations") that do not correspond to facts.

These Services are a support and reference solution for work, and the Company does not guarantee the completeness or commercial suitability of the Output Data.

2. Responsibility for Final Decision

All responsibility for the final management decisions and business actions of the Client in legal, financial, human resources, etc., made based on the Output Data generated by the AI Services, lies with the Client.

(※ Related legislation: analog application of the business judgment rule under Article 399 (Liability for damages of the company) and Article 401-2, among others, of the Korean Commercial Act)

3. Disclaimer for Infringement of Third-Party Rights

The Company applies reasonable technical measures to ensure that the Output Data from the AI system does not infringe patents, copyrights, trademarks, or other third-party rights.

However, due to the nature of generative AI, the Company does not guarantee the accuracy or completeness of all results, nor the non-infringement of third-party rights.

In particular, the Company shall not be liable for disputes arising from the illegality or infringement of rights of the Input Data provided by the Client and shall be exempt from liability unless there is willful misconduct or gross negligence on the part of the Company.

Article 3 (Acceptable Use Policy and Infrastructure Protection)

The Client must not use the AI Services in a manner that harms the stability of the Company's system or violates applicable laws.

1. Prohibition of system circumvention and reverse engineering

Prompt injection and jailbreak attempts aimed at neutralizing the AI security filtering system established by the Company, as well as reverse engineering aimed at extracting the source code of the solution, are prohibited.

(※ Related legislation: Act on the Prevention of Unfair Competition and Protection of Trade Secrets, Article 2 (Definitions))

2. Prohibition of infrastructure overload

When using the API integration and PolyBot, generating a significant load on the AI infrastructure and the operational environment of the Company's servers through automated crawlers or unapproved scripts is prohibited.

(※ Related legislation: Act on Promotion of Information and Communications Network Utilization and Information Protection, Article 48 (Prohibition of acts of intrusion into information and communications networks))

3. Prohibition of generating illegal or harmful content

Using the solution for illegal acts, such as creating works that defame third parties through deepfakes, inducing infringement of third-party intellectual property rights, developing malicious code, and generating scripts for fraud and phishing purposes, is prohibited.

4. Procedure for action in case of non-compliance

When the Company becomes aware of an act that violates this article, it will act according to the following stepped procedure.

  • (1) Notification of remedy: The Company will notify the Client in writing (including email) of the non-compliance and the required remedial measures.
  • (2) Remedy period: The Client must remedy the non-compliance within 14 business days from the receipt of the notification of remedy.
  • (3) Restriction of service use: If the Client does not remedy the non-compliance within the remedy period, the Company may restrict the total or partial use of the AI Services.
  • (4) Termination of the license agreement: If the state of non-compliance persists after the restriction of service use, the Company may terminate the license agreement.

However, if a non-compliance with sections 1 to 3 of this article poses an urgent and serious threat to the security of the Company's infrastructure, it may immediately restrict or block the use of the service without granting the remedy period specified in the previous procedure, and will notify the Client without delay thereafter.

Article 4 (Global Transparency of AI and Responsible Use)

To support Clients developing global businesses with PolyGlot, PolyBot, and other solutions, the Company strives to operate the AI Services responsibly, taking into account trends in international AI regulation and related standards.

1. Assurance of AI system transparency

When the Client integrates solutions like PolyBot into their own customer-facing services (B2C chatbots, etc.), they must clearly inform end users that such service is powered by an artificial intelligence system.

(※ Legislación relacionada: Ley de IA de la Unión Europea (EU AI Act), artículo 52 (Obligaciones de transparencia para determinados sistemas de IA))

2. Respuesta a las decisiones automatizadas

Cuando un usuario final del Cliente rechace el asesoramiento basado en IA y solicite la interacción con un agente humano (opt-out), el Cliente deberá proporcionar un procedimiento alternativo para atender dicha solicitud.

La Empresa presta soporte a la API y al entorno técnico necesarios para ello. La provisión de la API básica de la función de opt-out se ofrece sin coste adicional, y los costes derivados de la propia operación del Cliente, como la asignación de agentes humanos, corren a cargo del Cliente. Cuando se requiera una personalización técnica adicional, esta se regirá por un acuerdo separado entre ambas partes.

(※ Legislación relacionada: Ley de Protección de Información Personal de Corea, artículo 37; RGPD europeo, artículo 22)

3. Cumplimiento normativo relativo a los modelos de IA de uso general (GPAI)

La Empresa supervisa y responde de forma continua a los requisitos aplicables de la regulación global de la IA durante la prestación de los Servicios de IA, incluidas las disposiciones sobre los modelos de IA de uso general (GPAI: General-Purpose AI Model) de la Ley de IA de la Unión Europea (EU AI Act). Cuando utilice modelos de IA de terceros, verificará en un ámbito razonable que el proveedor del modelo correspondiente cumple sus obligaciones normativas y se esforzará por proporcionar al Cliente la información de transparencia necesaria.

Artículo 5 (Disponibilidad del servicio y mantenimiento)

La Empresa realiza esfuerzos técnicos y administrativos comercialmente razonables para prestar los Servicios de IA de forma estable y continua.

En cualquiera de los siguientes casos, la totalidad o una parte de los Servicios podrá restringirse o suspenderse temporalmente.

  • Cuando se requiera una inspección del sistema, mantenimiento, mejora de funciones o una actualización de seguridad
  • Cuando se produzcan causas fuera del control razonable de la Empresa, como desastres naturales, cortes de energía, fallos de comunicación y fallos de los proveedores de infraestructura de nivel superior (Upstream Provider) y de los servicios en la nube
  • Cuando se requieran medidas inevitables para una respuesta de seguridad urgente o para garantizar la estabilidad del servicio
  • Cuando se produzca una restricción del servicio en virtud de la legislación aplicable o de una orden de una autoridad gubernamental

Cuando se haya celebrado un Acuerdo de Nivel de Servicio (Service Level Agreement, SLA) separado, dicho acuerdo se aplicará con prioridad.

Artículo 6 (Relación de esta Política con otras políticas)

Esta Política se aplica junto con los Términos del Servicio (Terms of Service), la Política de Privacidad (Privacy Policy), la Política de Cookies (Cookie Policy) y la Política de Ética de la Inteligencia Artificial (IA) (AI Ethics Policy) de la Empresa.

Cuando el contenido de esta Política entre en conflicto con el de otra política, la prioridad se determinará aplicando los siguientes criterios.

  • Cuestiones relativas a la recopilación, el uso, la conservación y la transferencia de la información personal: prevalece la Política de Privacidad
  • Cuestiones relativas al uso de cookies y tecnologías similares: prevalece la Política de Cookies
  • Cuestiones relativas al uso del servicio, los contratos, la responsabilidad y las exenciones de responsabilidad: prevalecen los Términos del Servicio
  • Principios de operación de los Servicios de IA, tratamiento de datos y política de uso aceptable: prevalece esta Política
  • Principios de ética de la IA y directrices de operación responsable de la IA: véase la Política de Ética de la Inteligencia Artificial (IA)

Artículo 7 (Modificación y notificación de la Política)

Cuando se modifique esta Política, la Empresa lo anunciará en el sitio web y dentro del servicio al menos 30 días antes de la fecha de entrada en vigor, especificando los motivos de la modificación, el contenido modificado y la fecha de entrada en vigor. No obstante, cuando exista una causa urgente, como una modificación obligatoria derivada de una reforma legislativa, la Empresa podrá anunciarlo al menos 7 días antes de la fecha de entrada en vigor.

Las versiones anteriores de la Política se conservan para su consulta a través del sitio web.

Si el Cliente no está de acuerdo con la Política modificada, podrá rescindir el acuerdo de uso del servicio. Si el Cliente continúa utilizando los Servicios después de la fecha de entrada en vigor de la Política modificada, se considerará que ha aceptado la Política modificada.

Disposición adicional

Esta Política de Operación entra en vigor el 3 de julio de 2026.