AlRouter

Privacy Policy

Effective Date: July 1, 2026  |  ATTO-Research Co., Ltd.

ATTO-Research Co., Ltd. (the "Company") establishes and discloses this Privacy Policy as set out below, pursuant to Article 30 of the Personal Information Protection Act ("PIPA"), in order to protect the personal information of data subjects and to promptly and effectively handle any related grievances. This Privacy Policy is incorporated into, and forms part of, the Data Processing Addendum (DPA) of the Enterprise Service Terms of Use by reference.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the purposes set out below. Personal information processed will not be used for any purpose other than the following, and where the purpose of use is changed, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18(2)(1) of PIPA.

Purpose of Processing Items Collected Retention Period
Conclusion of the service agreement and identification and management of members User ID, email address Deleted immediately upon termination of the service agreement (except where retention is required by statute, for such period)
Service-related notices and notifications, receipt of electronic communications, and grievance handling Email address Deleted immediately upon termination of the service agreement
Payment, billing, and refund processing User ID, email address, token usage, billing details Retained for 5 years pursuant to Article 6 of the E-Commerce Act
Prevention of fraudulent use and service security and operation User ID, email address Deleted immediately upon termination of the service agreement
Service operation and incident response API call timestamp, model used, response status code 1 year after termination of the service agreement
Provision of communication confirmation data User ID, email address Retained for 12 months pursuant to Article 15-2 of the Protection of Communications Secrets Act

Article 2 (Categories of Personal Information Processed)

(1) The Company processes the following categories of personal information:

  1. Required items: User ID, email address.
  2. Automatically generated/collected items: Service usage records, access IP address, cookies, and access logs (request time, status code, API Key identifier, etc. — processed only to the extent that they are not combined with personal information).

(2) The Company collects only the minimum necessary personal information and does not collect sensitive information (Article 23 of PIPA).

Article 3 (Processing and Retention Periods)

(1) The Company processes and retains personal information within the retention and use period prescribed by statute or consented to by the data subject at the time of collection.

(2) The processing and retention periods for each category of personal information are as follows:

  1. Member registration and management: Until termination of the service agreement; provided that, where an investigation or inquiry into a violation of applicable laws is in progress, until the conclusion of such investigation or inquiry.
  2. E-commerce payment and billing records: 5 years (Article 6 of the Act on Consumer Protection in Electronic Commerce, etc.).
  3. Communication confirmation data: 12 months (Article 15-2 of the Protection of Communications Secrets Act).
  4. Service operation and incident response (API call timestamp, model used, response status code): 1 year after termination of the service agreement.

(3) Where personal information becomes unnecessary — for example, upon expiry of the retention period or fulfilment of the processing purpose — the Company will destroy it without delay.

Article 4 (Provision of Personal Information to Third Parties)

(1) The Company processes the personal information of data subjects only within the scope specified in Article 1 (Purposes of Processing), and provides personal information to third parties only where one of the grounds under Articles 17 and 18 of PIPA applies, such as the consent of the data subject or special provisions of law.

(2) At the user's request, the prompt (text) entered by the user and the call metadata (request identifier and call option parameters) are provided and transferred overseas to the LLM Provider selected by the user.

(3) The details of the third-party provision and overseas transfer under paragraph (2) are as follows:

Recipient Destination Country Items Provided / Transferred Purposes of Use Retention/Use Period
Anthropic United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy
OpenAI United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy
Google United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy

The detailed privacy policy of each provider is available at the following pages:

(4) Users may choose whether to consent to the third-party provision under paragraph (2) by way of separate consent at the time of registration. If consent is withheld, use of the AI response generation service may be restricted.

(5) Where the external AI model provider changes, the Company will update and disclose this Privacy Policy without delay.

Article 5 (Entrustment of Personal Information Processing)

(1) The Company does not entrust the processing of personal information to any external party.

(2) Should any such entrustment (sub-processing) arise in the future, the Company will, in accordance with Article 26 of PIPA, specify in the entrustment agreement the matters necessary to ensure that the trustee processes personal information securely, and will manage and supervise the trustee's personal information processing.

(3) Where the trustee or the scope of entrusted work changes, the Company will update and disclose this Privacy Policy without delay.

Article 6 (Processing of Customer Content)

(1) All rights in the Inputs submitted by the user to the Service and the Outputs generated by the Service (collectively, "Customer Content") belong to the user.

(2) The Company does not store or collect Customer Content (the contents of prompts and responses). Prompts entered by the user are transmitted directly to the external AI model provider selected by the user and are not stored on the Company's servers.

(3) However, for service operation and quality management, the Company collects and stores the following API call logs (metadata):

Purpose of Processing Items Collected Retention Period
Service operation and incident response API call timestamp, model used, response status code 1 year after termination of the service agreement
Billing processing and dispute resolution Token usage, billing details Retained for 5 years pursuant to Article 6 of the E-Commerce Act

(4) The logs in paragraph (3) do not include the contents of prompts, and the Company does not use them for any purpose other than the provision of the Service.

(5) The processing of personal information contained in Customer Content is governed by the privacy policy of the external AI model provider selected by the user; with respect to the processing of personal information within Customer Content that occurs on the servers of the external AI model provider selected by the user, such provider bears responsibility as an independent personal information controller in accordance with its own privacy policy.

Article 7 (Destruction of Personal Information)

(1) Where personal information becomes unnecessary — for example, upon expiry of the retention period or fulfilment of the processing purpose — the Company will destroy it without delay.

(2) Where, notwithstanding the expiry of the consented retention period or the fulfilment of the processing purpose, personal information must continue to be retained pursuant to statute, the Company will transfer such personal information to a separate database (DB) or store it in a different storage location.

(3) The procedures and methods for destroying personal information are as follows:

  1. Destruction procedure: The Company identifies the personal information for which grounds for destruction have arisen and destroys it upon approval of the Chief Privacy Officer.
  2. Destruction method: Personal information stored in electronic file form is destroyed so that the records cannot be reproduced, and personal information recorded on paper documents is shredded or incinerated.

Article 8 (Rights and Obligations of Data Subjects and Methods of Exercise)

(1) The data subject may exercise the following rights against the Company at any time:

  1. The right to request access to the status of processing of personal information;
  2. The right to request correction of personal information containing errors;
  3. The right to request deletion of personal information;
  4. The right to request suspension of the processing of personal information.

(2) The rights under paragraph (1) may be exercised vis-à-vis the Chief Privacy Officer in writing, by email, by facsimile (FAX), or by similar means, and the Company will act on such requests without delay.

(3) The rights may also be exercised through an agent, such as the data subject's statutory representative or a duly authorized person. In such case, a power of attorney in the form of Annex Form No. 11 of the Enforcement Rules of PIPA must be submitted.

(4) The data subject's right to request access to, and suspension of the processing of, personal information may be restricted under Articles 35(4) and 37(2) of PIPA.

(5) A request for correction or deletion of personal information may not be made where the personal information is specified as a subject of collection under other statutes.

(6) Where a request for access, correction/deletion, or suspension of processing is made pursuant to the data subject's rights, the Company verifies that the person making the request is the data subject in person or a legitimate agent.

Article 9 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of PIPA, the Company implements the technical, administrative, and physical measures necessary to ensure security, as follows:

(1) Administrative measures

  1. Establishment and implementation of an internal management plan;
  2. Regular personal information protection training for staff;
  3. Minimization of staff handling personal information and management of access privileges.

(2) Technical measures

  1. Management of access privileges to personal information processing systems and assurance of password security;
  2. Installation, and periodic updating and inspection, of security programs to guard against hacking and other personal information breaches;
  3. Encryption of personal information: important information such as passwords is stored and transmitted in encrypted form;
  4. Retention of access logs and measures to prevent forgery or alteration (retained for at least 1 year).

(3) Physical measures

  1. Access control over server rooms, data storage rooms, and the like.

Article 10 (Installation, Operation, and Refusal of Automatic Collection Devices)

(1) The Company uses cookies, which store and periodically retrieve usage information, in order to provide users with personalized services.

(2) A cookie is a small piece of information that the server operating the website sends to the user's computer browser and that is stored on the hard disk of the user's computer.

(3) Users may choose to allow, block, or delete cookies through their web browser settings. However, if the storage of cookies is refused, the use of some services may be difficult.

Article 11 (Receipt of Electronic Communications)

(1) For the performance of the service agreement and to fulfil statutory notification obligations, the Company may send the following electronic communications to users by means of email, in-service notifications, website postings, and the like:

(2) Where the Company sends electronic communications for marketing or promotional purposes, it obtains separate consent from the user, distinct from the consent under paragraph (1), in accordance with Article 22(1)(7) of PIPA.

(3) Users may withdraw consent to receive electronic communications for marketing or promotional purposes at any time, and the withholding of such consent does not restrict the use of the Service.

Article 12 (Overseas Transfer of Personal Information)

(1) As the external AI model providers under Article 4 are located outside the Republic of Korea, information contained in prompts may be transferred overseas in the course of using the Service.

(2) Users may separately consent to the overseas transfer at the time of registration; if consent is withheld, the use of services relying on the relevant external AI model may be restricted.

(3) The details of the overseas transfer are as follows:

Recipient Destination Country Items Provided / Transferred Purpose of Use Retention/Use Period Details
Anthropic United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy Anthropic Privacy Policy
OpenAI United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy OpenAI Privacy Policy
Google United States Prompt, call metadata AI response generation After response generation, per each provider's privacy policy Google Privacy Policy

(4) Where the external AI model provider changes, the Company will update and disclose this Privacy Policy without delay.

Article 13 (Chief Privacy Officer)

(1) The Company designates a Chief Privacy Officer (CPO), as set out below, to take overall responsibility for matters relating to the processing of personal information and to handle complaints from data subjects and provide remedies in connection with the processing of personal information.

Category Details
Name ATTO-Research Chief Privacy Officer
Title Head of the Privacy Protection Department
Contact (Email) privacy@atori.ai

(2) Data subjects may submit to the Chief Privacy Officer requests such as access requests under Article 35 of PIPA, correction/deletion requests under Article 36, and suspension-of-processing requests under Article 37. The Company will respond to and handle the data subject's requests without delay.

Article 14 (Remedies for Infringement of Rights and Interests)

To obtain a remedy for the infringement of personal information, data subjects may apply for dispute resolution or counseling to bodies such as the Personal Information Dispute Mediation Committee and the Privacy Infringement Report Center of the Korea Internet & Security Agency (KISA). For other reports of, or counseling on, personal information infringement, please contact the bodies below.

Organization Website Telephone
Personal Information Dispute Mediation Committee (KOPICO) www.kopico.go.kr 1833-6972
Privacy Infringement Report Center (118) privacy.kisa.or.kr 118
Supreme Prosecutors' Office, Cybercrime Investigation Unit www.spo.go.kr 02-3480-3573
National Police Agency, Cyber Investigation Bureau ecrm.cyber.go.kr 182

Article 15 (Amendment of the Privacy Policy)

(1) This Privacy Policy applies from the Effective Date.

(2) Prior versions of the Privacy Policy can be reviewed via the service screen or by separate notice.

(3) The Company may amend this Privacy Policy, including for the purpose of reflecting changes in statutes or in the Service. Where the Privacy Policy is amended, the Company will give notice of the changes via the service screen or by email at least 7 days in advance; provided that, where a material change to the rights of data subjects occurs, notice will be given at least 30 days in advance.

Addendum This Privacy Policy takes effect on July 1, 2026.
ATTO-Research Co., Ltd.