GenON Inc. Privacy Policy
Effective Date: July 23, 2026
🌐 한국어 버전 (Korean Version)GenON Inc. (the "Company") complies with the Personal Information Protection Act ("PIPA") and other relevant laws and regulations in providing its products and services, in order to protect the freedom and rights of data subjects, and processes and manages personal information lawfully and safely.
Accordingly, pursuant to Article 30 of PIPA, the Company establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards applicable to the processing of personal information, and to ensure that related grievances can be handled promptly and smoothly.
The Company's Privacy Policy may be revised in response to changes in applicable laws, government guidelines, or the Company's internal policies. Any such changes will be disclosed through this Privacy Policy.
- 1. Purposes of Collection and Use of Personal Information
- 2. Items of Personal Information Collected and Retention Period
- 3. Processing of Personal Information of Children Under 14
- 4. Provision of Personal Information to Third Parties
- 5. Outsourcing of Personal Information Processing
- 6. Cross-Border Transfer of Personal Information
- 7. Procedures and Methods for Destruction of Personal Information
- 8. Automated Decision-Making
- 9. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
- 10. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
- 11. Measures to Ensure the Safety of Personal Information
- 12. Personal Information Processing Related to Generative AI Services
- 13. Chief Privacy Officer and Complaint Handling
- 14. Remedies for Infringement of Data Subject Rights
- 15. Exclusion from Application of this Privacy Policy
- 16. Changes to this Privacy Policy
1. Purposes of Collection and Use of Personal Information
a. The Company collects the minimum personal information necessary and processes it only for the following purposes. Where the purpose of use changes, the Company will obtain separate consent and take other measures required under Article 18 of PIPA.
| Type | Purpose |
|---|---|
| Handling of Inquiries or Complaints | Consultation regarding inquiries about products, technology, and purchases |
| Provision of Goods or Services | Providing services, content, and customized services / Consultation regarding inquiries about products, technology, and purchases |
| Use of Advertising for Marketing | Development of new services (products) and provision of customized services / Provision of event and promotional information, participation opportunities, and related statistics |
| Type | Purpose |
|---|---|
| Membership Registration and Management | Confirming intent to register / Identity verification and authentication / Maintaining and managing membership status / Preventing fraudulent use of the service / Notices and announcements / Handling grievances |
| Provision of Goods or Services | Providing the GenA service (an AI-based conversation, generation, and inference service) / Checking service usage history / Generating and providing responses to user requests and queries (prompts) / Providing content |
| Provision of AI Inference Service | Providing AI model inference services / Performance monitoring |
| Service Operation and Improvement | Analyzing service usage / Improving service quality / Responding to errors and failures / Detecting and responding to security threats and fraudulent use |
| Customer Support | Handling inquiries and complaints related to service use / Retaining records for dispute resolution / Delivering notices |
| AI Model Training and Performance Improvement (Consent-Based) | Training and retraining AI models using content entered by users (prompts, uploaded files, conversation content, etc.) and usage records, and improving response quality / Developing new AI features and models, and improving service accuracy and safety |
| Use of Advertising for Marketing (Consent-Based) | Promoting new services (features) and providing customized services / Providing event and promotional information, participation opportunities, and related statistics |
| Type | Purpose |
|---|---|
| Membership Registration and Management | Confirming intent to register / Identity verification and authentication / Maintaining and managing membership status / Preventing fraudulent use of the service / Notices and announcements / Handling grievances |
| Provision of Goods or Services | Providing the OneAgent service (an AI agent-based work automation and assistance service) / Checking service usage history / Generating and providing responses to user requests and queries |
| Provision of AI Inference Service | Providing AI model inference services / Performance monitoring |
| Service Operation and Improvement | Analyzing service usage / Improving service quality / Responding to errors and failures / Detecting and responding to security threats and fraudulent use |
| Customer Support | Handling inquiries and complaints related to service use / Retaining records for dispute resolution / Delivering notices |
| AI Model Training and Performance Improvement (Consent-Based) | Training and retraining AI models using content entered by users (prompts, uploaded files, conversation content, etc.) and usage records, and improving response quality / Developing new AI features and models, and improving service accuracy and safety |
| Use of Advertising for Marketing (Consent-Based) | Promoting new services (features) and providing customized services / Providing event and promotional information, participation opportunities, and related statistics |
b. The Company does not directly collect personal information in connection with recruitment; job applications are processed through external platforms. When such services are used, the processing of personal information is governed by the relevant platform's privacy policy.
c. For AI inference processing for the GenA and OneAgent services, the Company operates "GenOS," its own AI platform developed and operated in-house, on domestic infrastructure. GenOS is the Company's internal system, does not constitute outsourcing to an external third party, and does not involve any transfer of data overseas.
To improve service quality, the Company may, in addition to its own model, enter into outsourcing agreements with external AI model providers (such as Anthropic and OpenAI) to provide inference services, and the Company designates which model is used for each service. Where input data is transmitted to an external AI model provider, it is processed as described in "5. Outsourcing of Personal Information Processing" and "6. Cross-Border Transfer of Personal Information."
2. Items of Personal Information Collected and Retention Period
The Company collects the minimum personal information necessary from users. The processing purpose, items collected, and retention period for each category are as follows.
| Type | Purpose of Collection | Items Collected | Retention Period |
|---|---|---|---|
| Marketing | Promotion of company products, provision of event/promotional information, sending newsletters | (Required) Email, name, company affiliation, phone number / (Optional) Department | Destroyed immediately upon achievement of the purpose |
| Type | Purpose of Collection | Items Collected | Retention Period |
|---|---|---|---|
| Membership Registration | Identifying members and confirming intent to register | (Required) Email, nickname, profile image, unique Google account identifier | Until membership withdrawal (or the period required under applicable law, if any) |
| Service Personalization | Service personalization and user analysis | (Optional) Birth year, industry, interests, referral source | Until membership withdrawal |
| Service Use | Providing the AI inference service, checking usage history | User input content (prompts, uploaded files, conversation content), AI response results, service usage records | Until membership withdrawal |
| Service Operation | Service operation, security, prevention of fraudulent use | IP address, access logs, cookies, device information (OS, browser, device identifier), service usage records | As prescribed by relevant laws (access records: 3 months, under the Protection of Communications Secrets Act) |
| Customer Inquiries | Handling inquiries and complaints, dispute resolution | Inquirer's email, inquiry content, attachments | 3 years after completion of inquiry processing (Act on Consumer Protection in Electronic Commerce) |
| AI Training (Consent-Based) | AI model training and quality improvement | User input content, usage records | Until consent is withdrawn or membership is withdrawn |
| Marketing | Product promotion, provision of event/promotional information | (Required) Email, nickname, birth year / (Optional) Industry, interests, referral source | Until consent is withdrawn or membership is withdrawn |
| Type | Purpose of Collection | Items Collected | Retention Period |
|---|---|---|---|
| Membership Registration | Identifying members and confirming intent to register | (Required) Email, name, profile photo | Until membership withdrawal (or the period required under applicable law, if any) |
| Service Use | Providing the AI inference service, checking usage history | User input content (prompts, uploaded files, conversation content), AI response results, service usage records | Until membership withdrawal |
| Service Operation | Service operation, security, prevention of fraudulent use | IP address, access logs, cookies, device information (OS, browser, device identifier), service usage records | As prescribed by relevant laws (access records: 3 months, under the Protection of Communications Secrets Act) |
| Customer Inquiries | Handling inquiries and complaints, dispute resolution | Inquirer's email, inquiry content, attachments | 3 years after completion of inquiry processing (Act on Consumer Protection in Electronic Commerce) |
| AI Training (Consent-Based) | AI model training and quality improvement | User input content, usage records | Until consent is withdrawn or membership is withdrawn |
| Marketing | Product promotion, provision of event/promotional information | (Required) Email, nickname, birth year / (Optional) Industry, interests, referral source | Until consent is withdrawn or membership is withdrawn |
3. Processing of Personal Information of Children Under 14
As a general rule, the Company does not collect or process the personal information of children under the age of 14.
The Company restricts registration by children under 14 through a birth-year verification procedure at the time of membership registration, and where a user is confirmed to be under 14, registration may be refused or membership may be revoked.
If it is discovered that the personal information of a child under 14 has been collected without the consent of a legal representative, the Company will destroy such information without delay.
4. Provision of Personal Information to Third Parties
a. The Company processes users' personal information only within the scope of the purposes set out in this Privacy Policy, and does not process such information beyond that scope or provide it to third parties without the data subject's prior consent. However, the Company may provide personal information without the user's consent in cases falling under Article 17(1)(ii) and each subparagraph of Article 18(2) of PIPA.
b. Cases in which the Company provides personal information to third parties with the data subject's consent are as follows.
| Service | Recipient | Purpose of Provision | Items Provided | Retention and Use Period |
|---|---|---|---|---|
| There is currently no regular or ongoing provision of personal information to third parties based on data subjects' consent. Where such provision becomes necessary, the Company will obtain separate prior consent and disclose the details through this Privacy Policy. | ||||
c. Pursuant to Article 17(1)(ii) and each subparagraph of Article 18(2) of PIPA, the Company may provide personal information where a special provision of law exists, where it is unavoidable in order to comply with a legal obligation, or in accordance with procedures prescribed by law, such as a request made under a warrant issued by an investigative agency.
5. Outsourcing of Personal Information Processing
a. For the smooth provision of its services, the Company outsources the processing of personal information as follows.
| Trustee | Description of Outsourced Work | Personal Information Retention and Use Period |
|---|---|---|
| SalesForce | Managing the customer database for service provision | Until the purpose of use is achieved, membership is withdrawn, or the outsourcing agreement ends |
| Stibee Co., Ltd. | Sending newsletters | Until the purpose of use is achieved or the outsourcing agreement ends |
| Feat Inc. | Use of a proposal/company profile delivery solution | Until the purpose of use is achieved or the outsourcing agreement ends |
| Bizgo | Sending SMS, LMS, and MMS messages | Until the purpose of use is achieved, membership is withdrawn, or the outsourcing agreement ends |
| Forms.app | Use of a solution for collecting service and event application forms | Until the purpose of use is achieved or the outsourcing agreement ends |
| Remember & Company Inc. | Managing the customer database for service provision | Until the purpose of use is achieved or the outsourcing agreement ends |
| Wanted Lab, Inc. | Use of a recruitment management solution | Until the purpose of use is achieved or the outsourcing agreement ends |
| Celonis, Inc. | Collecting customer inquiry and event application forms; managing the customer database for service provision | Until the purpose of use is achieved or the outsourcing agreement ends |
| Google LLC | System operation for service provision, customer database management / Processing social login (SSO) authentication | Until the purpose of use is achieved, membership is withdrawn, or the outsourcing agreement ends |
| Microsoft Corporation (Microsoft Azure) | Providing and operating cloud infrastructure for the GenA and OneAgent services (Korea Central region, domestic) | Until membership is withdrawn or the outsourcing agreement ends |
| Anthropic, PBC | Processing Claude model inference for the GenA and OneAgent services | Until membership is withdrawn or the outsourcing agreement ends |
| OpenAI, LLC | Processing GPT model inference for the GenA and OneAgent services | Until membership is withdrawn or the outsourcing agreement ends |
| OpenRouter, Inc. | AI model routing and inference processing for the OneAgent service | Until membership is withdrawn or the outsourcing agreement ends |
| Microsoft Corporation (Microsoft Clarity) | Analyzing website usage behavior for the GenA service (page visits, clicks, mouse movement, scrolling, device/browser information) | In accordance with Microsoft Clarity's retention policy (up to 1 year) |
b. When entering into an outsourcing agreement, the Company specifies, in the contract or other documentation, matters such as the prohibition of processing personal information for purposes other than the outsourced work, technical and managerial safeguards, restrictions on re-subcontracting, supervision of the trustee, and liability for damages, as required by Article 26 of PIPA, and supervises whether the trustee processes personal information safely.
c. If the details of the outsourced work or the trustee change, the Company will disclose this without delay through this Privacy Policy.
d. Outsourcing to trustees located overseas is addressed collectively in "6. Cross-Border Transfer of Personal Information."
6. Cross-Border Transfer of Personal Information
The Company transfers personal information collected from service users overseas as set out below, and provides the following notice pursuant to Article 28-8 of PIPA.
| Legal Basis | Recipient (Contact) | Recipient Country | Timing and Method of Transfer | Items Transferred | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|---|
| Article 28-8(1)(iii) of PIPA (outsourcing for contract performance) | Google LLC (privacy-policy-support@google.com) | United States | Immediately upon use of the service / Remote transmission via a dedicated network with TLS encryption | Email, name, company affiliation, phone number, department | Service provision and customer management | Destroyed immediately upon achievement of the purpose of use |
| Article 28-8(1)(iii) of PIPA | Salesforce, Inc. (privacy@salesforce.com) | Japan | Immediately upon use of the service / Remote transmission via a dedicated network with TLS encryption | Email, name, company affiliation, phone number, department | Service provision and customer management | Destroyed immediately upon achievement of the purpose of use |
| Article 28-8(1)(iii) of PIPA | Forms.app (support@forms.app) | Türkiye | Immediately upon use of the service / Remote transmission via a dedicated network with TLS encryption | Email, name, company affiliation, phone number, department | Service provision and customer management | Destroyed immediately upon achievement of the purpose of use |
| Article 28-8(1)(iii) of PIPA | Celonis, Inc. (privacy@celonis.com) | Czech Republic, United States | Immediately upon use of the service / Remote transmission via a dedicated network with TLS encryption | Email, name, company affiliation, phone number, department | Service provision and customer management | Destroyed immediately upon achievement of the purpose of use |
| Legal Basis | Recipient (Contact) | Recipient Country | Timing and Method of Transfer | Items Transferred | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|---|
| Article 28-8(1)(iii) of PIPA (outsourcing for contract performance) | Anthropic, PBC (privacy@anthropic.com) | United States | At the time a user enters and transmits a prompt / Remote transmission over the internet with TLS encryption | Conversation content (queries, documents, which may include personal information), attachments | Generating AI responses and providing the service | Until membership withdrawal or the outsourcing agreement ends (processed in accordance with the trustee's policy and the Company's agreement) |
| Article 28-8(1)(iii) of PIPA | OpenAI, LLC (privacy@openai.com) | United States | At the time a user enters and transmits a prompt / Remote transmission over the internet with TLS encryption | Conversation content (queries, documents, which may include personal information), attachments | Generating AI responses and providing the service | Until membership withdrawal or the outsourcing agreement ends (processed in accordance with the trustee's policy and the Company's agreement) |
| Legal Basis | Recipient (Contact) | Recipient Country | Timing and Method of Transfer | Items Transferred | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|---|
| Article 28-8(1)(iii) of PIPA (outsourcing for contract performance) | Microsoft Corporation – Microsoft Clarity (privacy@microsoft.com) | United States | At the time of visiting/using a service page / Remote transmission over the internet with TLS encryption | Page URL, click events, mouse movement, scrolling, device information, browser information, IP address, session identifier | Analyzing website usage behavior, improving user experience (UX) | In accordance with Microsoft Clarity's retention policy (up to 1 year) |
| Article 28-8(1)(iii) of PIPA (outsourcing for contract performance) | Amplitude, Inc. (privacy@amplitude.com) | United States | At the time of visiting/using a service page / Remote transmission over the internet with TLS encryption | User identifier (randomly generated UUID), device identifier (device_id), session identifier, service usage event records (event names/parameters such as page views and feature usage), device information, browser information, IP address, referral source (UTM) | Analyzing product usage behavior, improving the service and its features | In accordance with Amplitude's retention policy and the Company's agreement |
| Legal Basis | Recipient (Contact) | Recipient Country | Timing and Method of Transfer | Items Transferred | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|---|
| Article 28-8(1)(iii) of PIPA | OpenRouter, Inc. (support@openrouter.ai) | United States | At the time of an inference request by the user / Remote transmission over the internet with TLS encryption | AI inference request context (prompts, file contents, screenshots, terminal output, system environment information, etc.) | AI model routing and inference processing | Until membership withdrawal or the outsourcing agreement ends (processed in accordance with the trustee's policy and the Company's agreement) |
7. Procedures and Methods for Destruction of Personal Information
a. When personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose, the Company destroys the relevant personal information without delay pursuant to Article 21 of PIPA.
b. Where the retention period consented to by the data subject has expired or the processing purpose has been achieved, but the personal information must continue to be retained under other laws, such personal information is transferred to a separate database (DB) or stored in a separate location.
c. The procedures and methods for the destruction of personal information are as follows.
(1) Destruction Procedure
The Company selects personal information for which grounds for destruction have arisen and destroys it upon approval of the Chief Privacy Officer.
(2) Destruction Method
- Personal information recorded and stored in electronic file form: destroyed using technical methods that render the record unrecoverable (e.g., low-level formatting, degaussing, physical shredding).
- Personal information recorded and stored on paper: destroyed by shredding or incineration.
8. Automated Decision-Making
The Company processes personal information through fully automated systems employing artificial intelligence (AI) technology in the GenA and OneAgent services to generate responses and inference results. Pursuant to Article 37-2 of PIPA, the Company provides the following notice regarding automated decision-making.
a. The Fact that Automated Decision-Making Occurs, Its Purpose, and the Scope of Data Subjects Concerned
- Services Concerned: GenA (an AI-based conversation, generation, and inference service), OneAgent (an AI agent-based work automation and assistance service)
- Purpose: Analyzing prompts, files, and context entered by users to automatically generate and provide results such as natural language responses, content generation, and task performance
- Data Subjects Concerned: All members using the relevant service
b. Types of Key Personal Information Used in Automated Decision-Making and Their Relationship to the Decision
- User input data: prompts (text), uploaded files, conversation content, screenshots, terminal output, etc.
- Usage context: system environment information, prior conversation context, user settings
- The above information is used as input to the AI model and determines the content, accuracy, and relevance of the response generated.
c. Considerations and Processing Procedure in the Automated Decision-Making Process
- Step 1 (Receiving Input): The prompt and/or files entered by the user are received. The Company does not review or filter the input content in advance, and passes the data entered by the user to the inference stage as is.
- Step 2 (Model Inference): Inference is performed using the AI model designated by the Company for the relevant service. Inference is performed either on GenOS (domestic infrastructure), the Company's own AI platform, or the input is transmitted through a secure channel (TLS) to an external AI model provider (such as Anthropic or OpenAI) with which the Company has an outsourcing agreement, in order to generate a response.
- Step 3 (Returning the Response): The generated response is returned to the user. The manner in which an external AI model provider stores, uses, or uses for training the data it receives is governed by that provider's policy and the Company's outsourcing agreement.
- Considerations: The possibility of inaccuracy, bias, or hallucination in responses, the risk of exposure of sensitive information, and the need to safeguard user control
d. Processing of Sensitive Information or Personal Information of Children Under 14
The Company does not intentionally collect or process sensitive information or the personal information of children under 14 in the automated decision-making process. However, because the Company does not review or filter in advance the content users enter in the chat window, if a user voluntarily enters sensitive information, such information may be processed during inference.
e. Data Subject's Right to Refuse and Request an Explanation
A data subject may refuse an automated decision where it has a material effect on the data subject's rights or obligations, and may request an explanation of that decision.
- Method of Exercise: Apply via 'Settings > Customer Support > Refuse Automated Decision / Request Explanation' within the service, or via the Chief Privacy Officer's email
- Technical Limitations: Where data has already been reflected in AI model training and it is technically impossible to isolate and delete a specific individual's data, use of and deletion from that model may unavoidably be restricted. However, refusal and deletion requests are always available for data at the pre-training stage.
9. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
a. A data subject may at any time exercise, against the Company, the right to access, request transmission of, correct or delete, suspend the processing of, withdraw consent regarding, and refuse or request an explanation of automated decisions regarding, their personal information.
b. Rights may be exercised in writing, by telephone, by email, by fax, via the internet, or by other means, pursuant to Article 41(1) of the Enforcement Decree of PIPA, and the Company will act on such requests without delay.
- A data subject may, at any time, directly view, correct, delete, suspend the processing of, or withdraw consent regarding their personal information via 'My Info > Member Information' within the service, or may request access via 'Customer Support.'
- Refusal of, and requests for an explanation of, automated decisions may be submitted via 'Settings > Customer Support' within the service or via the Chief Privacy Officer's email.
c. Rights may also be exercised through the data subject's legal representative or an authorized agent. In such cases, a power of attorney in the form prescribed in [Annexed Form No. 11] of the "Notification on the Methods of Processing Personal Information" must be submitted.
d. A data subject's right to request access to, and suspension of processing of, personal information may be restricted pursuant to Article 35(4) and Article 37(2) of PIPA.
e. Deletion of personal information may not be requested where such information is designated for collection under other laws.
f. The Company verifies whether a person exercising a right is the data subject or a duly authorized agent.
g. The Company will respond within 10 days of receiving a data subject's request to exercise a right.
h. Data subjects are responsible for protecting their own personal information, and the Company bears no responsibility for problems arising from the theft or negligent handling of IDs, passwords, or similar credentials that occur without fault or negligence attributable to the Company.
10. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
a. Operation of Cookies
The Company uses "cookies" that store and periodically retrieve usage information in order to provide individually customized services to users.
- Purpose of Using Cookies: To understand users' visit and usage patterns, secure connection status, popular search terms, and similar information, in order to provide optimized information
- Installation, Operation, and Refusal of Cookies: You may refuse to store cookies via Tools > Settings > Privacy and Security in your web browser's menu.
- If you refuse to store cookies, you may experience difficulty using customized services.
b. Operation of Google Analytics
Pursuant to Article 15(1)(i) (consent) of PIPA, the Company uses Google Analytics, a web log analysis tool provided by Google. This tool collects non-identifiable information that cannot be used to identify individual users.
- Method of Refusal: Install the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout)
c. Operation of Microsoft Clarity (Collection of GenA Behavioral Information)
To improve user experience (UX) and analyze usability for the GenA service, the Company uses "Microsoft Clarity," a web analytics tool provided by Microsoft. Microsoft Clarity collects users' behavioral information through cookies and other automatic collection devices, and the Company provides the following notice pursuant to the "Guidelines for Drafting Privacy Policies (April 2026)" of the Personal Information Protection Commission.
- Legal Basis: Article 15(1)(i) of PIPA (consent of the data subject)
- Items Collected: Page URL and visit history, click events, mouse movement/scrolling and other interaction information, device information (OS, screen resolution, etc.), browser information, IP address, session identifier
- Method of Collection: Automatically collected when a user accesses and uses a GenA service page
- Purpose of Collection: Analyzing website usage behavior, improving user experience (UX) and services, diagnosing errors/failures
- Retention and Use Period: In accordance with Microsoft Clarity's own retention policy (up to 1 year)
- Method of Refusal: If a user enables the "Do Not Track (DNT)" setting in their browser, data collection by Microsoft Clarity is automatically disabled in accordance with Microsoft Clarity's own policy. DNT settings can be found in each browser's privacy settings menu.
d. Blocking Cookies by Browser
- Chrome: Settings > Privacy and Security > Third-party cookies > Block
- Edge: Settings > Privacy, search, and services > Tracking prevention > Strict
- Safari: Preferences > Privacy > Block All Cookies
- Firefox: Settings > Privacy & Security > Custom > Block cookies
11. Measures to Ensure the Safety of Personal Information
Pursuant to Article 29 of PIPA and the "Standards for Measures to Ensure the Safety of Personal Information" (a notification of the Personal Information Protection Commission), the Company implements the following safety measures to prevent personal information from being lost, stolen, leaked, forged, altered, or damaged.
a. Administrative Measures
- Establishing and implementing an internal management plan for the safe processing of personal information
- Providing regular training to personnel handling personal information and obtaining security pledges
- Operating a dedicated personal information protection organization and conducting internal inspections
- Minimizing the number of personnel handling personal information and granting differentiated access rights
b. Technical Measures
- Managing access rights to, and installing access control systems for, personal information processing systems
- Storing important information such as passwords using one-way encryption
- Using encrypted communication channels (TLS/SSL) when transmitting and receiving personal information
- Retaining access records and taking measures to prevent their forgery or alteration
- Installing, operating, and regularly updating antivirus and security programs
- Checking for and remedying vulnerabilities to guard against external intrusion
c. Physical Measures
- Controlling entry to and access of computer rooms, data storage rooms, and similar facilities
- Storing documents and auxiliary storage media in a secure, lockable location
- Controlling the movement of auxiliary storage media into and out of the premises
- Establishing safety measures against disasters
12. Personal Information Processing Related to Generative AI Services
In operating generative AI services, including GenA and OneAgent, the Company provides the following notice with reference to the "Appendix on Privacy Policies for Generative AI Services" of the "Guidelines for Drafting Privacy Policies (April 2026)" of the Personal Information Protection Commission.
a. Processing of User Input Information
Information directly entered by users in the course of using the service (text, documents, images, attachments, etc.) and results generated in the course of using the service (answers, search results, etc.) are collected and used pursuant to Article 15(1)(iv) (performance of a contract) of PIPA.
b. Notice to Users Regarding Input of Sensitive Information
The Company does not review or filter in advance the content of information voluntarily entered by users in the chat window. Because the nature of the service allows free-form input by users, users should take particular care not to enter the following types of information, whether their own or that of others, in the chat window.
- Unique identification information: resident registration numbers, passport numbers, driver's license numbers, alien registration numbers
- Sensitive information: ideology/beliefs, membership/withdrawal from labor unions or political parties, political opinions, health/sex life information, genetic information, criminal history, etc.
- Financial information: credit card numbers, account numbers, passwords
- Other confidential information: the Company's internal confidential information, trade secrets, other individuals' personal information, etc.
If a user enters such information, it may be transmitted to the external AI model providers specified in "6. Cross-Border Transfer of Personal Information," and the user who entered the information is responsible for any resulting consequences.
c. Use of Data for AI Model Training and Opt-Out
The Company uses input data for AI model training and performance improvement only where the user has consented. Users may withdraw their consent to such use for training at any time by the following methods.
- Method of Requesting Refusal: Request refusal of use for training via the personal information protection department email (hello@genon.ai), specified in "13. Chief Privacy Officer and Complaint Handling" below, or via the customer center
- Processing Deadline: The Company will process the refusal request within 10 days of receipt and notify the user of the result.
- Effect: Input data collected after completion of the refusal request will not be used for model training.
- Limitation: Because some personalization features are provided based on training, refusing such use may result in a degradation of the quality of some services.
d. Outsourcing to, and Notice Regarding, External AI Model Providers
To improve service quality, the Company has entered into outsourcing agreements with external AI model providers (such as Anthropic and OpenAI), in addition to its own model (GenOS), to provide inference services. The Company designates which model is used for each service.
- The manner in which an external AI model provider stores, uses, uses for training, or destroys the data it receives is governed by the relevant provider's policy and the Company's outsourcing agreement.
- Further details regarding external AI model providers can be found in "5. Outsourcing of Personal Information Processing" and "6. Cross-Border Transfer of Personal Information."
e. Technical Limitations on the Exercise of Rights
After AI model training has been completed, it may be technically limited to isolate and delete only a specific individual's data from that model. However, requests to refuse use for training or to delete data remain available at any time for data at the pre-training stage.
f. Feedback and Reporting Regarding Inappropriate Responses
If a user receives a response containing sensitive personal information or an inappropriate response while using the AI service, the user may provide feedback or report the matter through the following channels.
- Feedback: Click the positive/negative feedback button on the relevant response
- Reporting: 'Customer Support > Report' within the service, or the Chief Privacy Officer's email
13. Chief Privacy Officer and Complaint Handling
The Company operates a Chief Privacy Officer and a dedicated department, as set out below, to have overall responsibility for matters relating to the processing of personal information, and to handle data subjects' complaints and remedy any resulting harm.
| Chief Privacy Officer | Personal Information Protection Department |
|---|---|
| Name: Minkyung Kim | Department: Management Support Group |
| Title: Senior Manager | Email: hello@genon.ai |
| Email: hello@genon.ai | Phone: +82-2-2088-6035 |
| Phone: +82-2-2088-6035 |
Data subjects may submit requests to exercise rights, such as requests to access personal information under Article 35 of PIPA, to the department above. The Company will make every effort to respond to and process data subjects' inquiries without delay.
14. Remedies for Infringement of Data Subject Rights
To obtain a remedy for infringement of their personal information, data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and other relevant bodies.
For other inquiries regarding, or to report, personal information infringement, please contact the following agencies.
| Agency | Phone (no area code) | Website |
|---|---|---|
| Personal Information Infringement Report Center | 118 | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 | www.spo.go.kr |
| National Police Agency Cyber Crime Reporting System (ECRM) | 182 | ecrm.cyber.go.kr |
15. Exclusion from Application of this Privacy Policy
The Company may provide users with links, via its homepage, to other websites or materials. In such cases, the Company has no control over such external sites and materials, and this Privacy Policy does not apply to the collection of personal information by such sites. If you follow a link provided by the Company to another site, you should review the privacy policy posted on that newly visited site.
16. Changes to this Privacy Policy
a. This Privacy Policy is effective as of July 23, 2026.
b. In the event of any change to this Privacy Policy, the Company will disclose the effective date and content of the change on the Company's website without delay. However, where there is a material change to users' rights or obligations, the Company will provide notice at least 7 days prior to the effective date, and where the change has a material effect on data subjects' rights, the Company will provide a comparison of the prior and revised content.
c. Previous versions of this Privacy Policy can be found below.
© 2026 GenON Inc. All rights reserved.

