Artificial Intelligence (AI) Service Operation Policy
Effective Date: July 3, 2026
This translation is provided for convenience only. In case of discrepancies between this translation and the original Korean, the original Korean prevails.
This operation policy (hereinafter referred to as the 'Policy') aims to define the rights, obligations, scope of responsibilities, and legal compliance requirements of Software Creation Studio (hereinafter referred to as the 'Company') and the enterprise clients party to the contract (hereinafter referred to as the 'Client') in the context of using AI-based solutions provided by the Company (PolyBot, PolyGlot, and all AI SaaS services provided hereinafter, collectively referred to as 'AI Services').
Article 1 (Data Governance and Privacy)
The Company places the highest priority on the Client's intellectual property rights and data security and complies with applicable laws.
1. Ownership of Data
All intellectual property rights to the prompts, source code, databases, documents, and other elements entered by the Client into the AI Services (hereinafter referred to as 'Input Data'), as well as the results produced by the AI system in response to them (hereinafter referred to as 'Output Data'), shall, in principle, belong to the Client.
2. Prohibition of Use for Retraining Purposes
The Company does not use any data entered by the Client for the refinement, weight adjustment, or retraining of the AI model. However, fully anonymized and aggregated statistical information that cannot identify individuals or Clients (e.g., average response time, error rate, token consumption, etc.), used for monitoring service quality and ensuring system stability, does not constitute retraining data and may only be used for improving service operation.
Stored data is subject to encryption technologies compliant with industry standards, such as AES-256, and data in transit is encrypted according to the TLS protocol. Furthermore, once the purpose of providing the service is achieved, the data is securely deleted or anonymized in accordance with applicable laws and the Company's internal data retention policy.
(※ Applicable legislation: Article 21 of the Personal Information Protection Act (destruction of personal information))
3. Real-time Anonymization of Personally Identifiable Information (PII) and Compliance with Global Regulations
When processing AI Services, if not only personal information and unique identifiers as defined by the Korean Personal Information Protection Act are detected, but also Personally Identifiable Information (PII) as defined by the laws and standards of various foreign countries, the Company will anonymize (mask) such information using applicable technical safeguards before transmitting it to the language model.
This encompasses the PII rules from the guidelines of the U.S. federal government and NIST, as well as the definition of personal data under the European GDPR, and implements technical and organizational safeguards aimed at reducing the risk of global regulatory non-compliance for the Client.
The specific technical specifications applied to the anonymization of PII (detection method, scope of masking, processing flow, etc.) are provided in a separate technical document upon the Client's request.
(※ Applicable regulations: Article 29 of the Korean Personal Information Protection Act, NIST SP 800-122 of the United States (guidelines for protecting PII), Article 4, Section 1 of the European GDPR (definition of personal data))
4. Strict Isolation of PolyBot Sessions and Conversation Memory
When providing the AI chatbot solution (PolyBot), each conversation session of the Client and the context memory used are loaded and processed in a logically isolated independent space within the shared environment (Multi-tenancy).
To prevent any memory confusion or data interference with other Clients or sessions, the Company applies logical isolation, access control, and other technical and organizational safeguards; at the end of the relevant conversation session or in the event of contract termination, the retained real-time memory data is securely deleted or anonymized in accordance with applicable laws and the internal data retention policy.
5. Recommendation for Monitoring and Filtering Sensitive Information
Notwithstanding the real-time anonymization (masking) measures and memory isolation implemented by the Company, the Client must fulfill its own management and oversight obligations to ensure that its authenticated users do not excessively input trade secrets, non-public financial data, or third-party business secrets.
6. Information Regarding Third-Party AI Model Providers
The Company may utilize language models or APIs from third-party AI model providers (hereinafter referred to as 'subsequent AI subcontractors') to provide the AI Services. In this case, the Company ensures, through contracts with the subsequent AI subcontractors, the prohibition of using Client data for retraining purposes as well as obligations for data security and confidentiality, and notifies the Client in writing and in advance of any changes regarding the subsequent AI subcontractors.
Article 2 (Technical Limitations and Disclaimer)
As these AI Services are based on generative language models and machine learning algorithms, the following technical limitations exist.
1. Disclaimer Regarding the Accuracy of Produced Information (Hallucinations)
Due to the nature of AI technology, the Output Data may contain partially inaccurate or biased information, or hallucination phenomena contrary to facts (Hallucination, hereinafter referred to as 'hallucinations').
This service is intended as a work assistance solution and for reference purposes, and the Company does not guarantee the completeness or commercial adequacy of the Output Data.
2. Responsibility for Final Decisions
All responsibility for the final decisions and business actions of the Client in legal, financial, human resources, and other management matters, made based on the Output Data from the use of the AI Services, rests with the Client.
(※ Applicable legislation: analogous application of management judgment under Articles 399 (liability for damages of directors) and 401-2 of the Korean Commercial Code, among others)
3. Disclaimer Regarding Infringement of Third-Party Rights
The Company applies reasonable technical measures to ensure that the Output Data from the AI system does not infringe on patents, copyrights, trademarks, and other third-party rights.
However, due to the nature of generative AI, the Company does not guarantee the accuracy or completeness of all results, nor the absence of infringement on third-party rights.
In particular, the Company is not responsible for disputes arising from the illegality or infringement of the Input Data itself provided by the Client, and is exempt from liability except in cases of intent or gross negligence on its part.
Article 3 (Acceptable Use Policy and Infrastructure Protection)
The Client must not use the AI Services in a manner that compromises the stability of the Company's systems or violates laws.
1. Prohibition of System Circumvention and Reverse Engineering
Prompt injections and attempts to circumvent the AI's security filtering system established by the Company, as well as acts of reverse engineering aimed at extracting the source code of the solution, are prohibited.
(※ Applicable legislation: Article 2 (definitions) of the Unfair Competition Prevention and Trade Secret Protection Act)
2. Prohibition of infrastructure overload actions
When integrating APIs and using PolyBot, any action that generates a significant load on the Company's AI infrastructure and server operating environment through automated indexing robots or unapproved scripts is prohibited.
(※ Applicable legislation: Article 48 (prohibition of acts harming the information communication network) of the Act on Promotion of Information and Communication Network Utilization and Information Protection, etc.)
3. Prohibition of generating illegal or harmful content
The use of the solution for illegal acts such as producing works that harm the reputation of others (deepfakes, etc.), inciting violations of third-party intellectual property rights, developing malware, and generating scripts for fraud and phishing is prohibited.
4. Procedure applicable in case of violation
When the Company becomes aware of an act contrary to this article, it will take measures according to the following progressive procedure.
- (1) Compliance notification: The Company will notify the Client in writing (including by email) of the facts constituting the violation and the compliance requirements.
- (2) Compliance deadline: The Client must remedy the violation within 14 business days from the date of receipt of the compliance notification.
- (3) Restriction of service use: If the Client does not remedy the violation within the compliance deadline, the Company may restrict all or part of the use of the AI Services.
- (4) Termination of the license agreement: If the violation persists after the restriction of service use, the Company may terminate the license agreement.
However, if a violation of points 1 to 3 of this article poses an urgent and serious threat to the security of the Company's infrastructure, it may immediately restrict or block the use of the service without granting the compliance deadline provided in the above procedure, and will notify the Client promptly thereafter.
Article 4 (Global Transparency of AI and Responsible Use)
In order to support Clients engaged in global business, particularly through PolyGlot and PolyBot, the Company strives to operate the AI Services responsibly, considering developments in international AI regulations and applicable standards.
1. Guarantee of AI system transparency
When the Client integrates solutions such as PolyBot into its own customer-oriented services (B2C chatbots, etc.), it must clearly inform end users that the service in question is powered by an artificial intelligence system.
(※ Applicable legislation: Article 52 (transparency obligations for certain AI systems) of the European Union AI Act (EU AI Act))
2. Response to automated decisions
When an end user of the Client refuses an AI-based consultation and requests interaction with a human advisor (opt-out), the Client must provide an alternative procedure to address this request.
La Société fournit à cet effet les API et l'environnement technique nécessaires. La fourniture de l'API de base de la fonctionnalité d'opt-out est assurée sans frais supplémentaires, tandis que les coûts liés à l'exploitation propre du Client, tels que l'affectation de conseillers humains, sont à la charge du Client. Toute autre personnalisation technique distincte requise est régie par un accord distinct entre les deux parties.
(※ Législation applicable : article 37 de la loi sur la protection des informations personnelles, article 22 du RGPD européen)
3. Conformité aux réglementations relatives aux modèles d'IA à usage général (GPAI)
La Société surveille et prend en compte en permanence les exigences réglementaires mondiales applicables en matière d'IA dans le cadre de la fourniture des Services d'IA, y compris les dispositions relatives aux modèles d'IA à usage général (GPAI : General-Purpose AI Model) de la loi de l'Union européenne sur l'IA (EU AI Act). Lorsqu'elle recourt à des modèles d'IA tiers, la Société vérifie dans une mesure raisonnable que le fournisseur du modèle concerné s'acquitte de ses obligations réglementaires et s'efforce de fournir au Client les informations de transparence nécessaires.
Article 5 (Disponibilité et maintenance du service)
La Société déploie des efforts techniques et organisationnels commercialement raisonnables pour fournir des Services d'IA stables et continus.
Tout ou partie du service peut être temporairement restreint ou interrompu dans l'un des cas suivants.
- Lorsqu'une inspection du système, une maintenance, une amélioration des fonctionnalités ou une mise à jour de sécurité est nécessaire
- Lorsque survient un motif échappant au contrôle raisonnable de la Société, tel qu'une catastrophe naturelle, une coupure de courant, une défaillance de communication ou une défaillance d'un fournisseur d'infrastructure en amont (Upstream Provider) et de services cloud
- Lorsqu'une mesure inévitable est nécessaire pour une réponse de sécurité urgente ou pour garantir la stabilité du service
- Lorsqu'une restriction du service intervient conformément aux lois applicables ou à un ordre d'une autorité publique
Lorsqu'un accord de niveau de service (Service Level Agreement, SLA) distinct a été conclu, cet accord s'applique en priorité.
Article 6 (Relation entre la présente Politique et les autres politiques)
La présente Politique s'applique conjointement aux Conditions d'utilisation (Terms of Service), à la Politique de confidentialité (Privacy Policy), à la Politique relative aux cookies (Cookie Policy) et à la Politique d'éthique de l'intelligence artificielle (IA) (AI Ethics Policy) de la Société.
En cas de contradiction entre la présente Politique et une autre politique, l'ordre de priorité est déterminé selon les critères suivants.
- Questions relatives à la collecte, à l'utilisation, à la conservation et au transfert des informations personnelles : la Politique de confidentialité s'applique en priorité
- Questions relatives à l'utilisation des cookies et technologies similaires : la Politique relative aux cookies s'applique en priorité
- Questions relatives à l'utilisation du service, au contrat, à la responsabilité et à l'exonération : les Conditions d'utilisation s'appliquent en priorité
- Principes d'exploitation des Services d'IA, traitement des données et politique d'utilisation acceptable : la présente Politique s'applique en priorité
- Principes d'éthique de l'IA et orientation vers une exploitation responsable de l'IA : se reporter à la Politique d'éthique de l'intelligence artificielle (IA)
Article 7 (Modification de la Politique et notification)
En cas de modification de la présente Politique, la Société annonce le motif, le contenu de la modification et la date d'entrée en vigueur, au moins 30 jours avant la date d'entrée en vigueur, sur le site web et au sein du service. Toutefois, en cas de motif urgent, tel qu'une modification obligatoire résultant d'une révision de la loi, la Société peut donner un préavis d'au moins 7 jours avant la date d'entrée en vigueur.
Les versions antérieures de la Politique sont conservées afin de pouvoir être consultées sur le site web.
Si le Client n'accepte pas la Politique modifiée, il peut résilier le contrat d'utilisation du service. Si le Client continue à utiliser le service après la date d'entrée en vigueur de la Politique modifiée, il est réputé avoir accepté la Politique modifiée.
Dispositions additionnelles
La présente politique d'exploitation entre en vigueur le 3 juillet 2026.