Privacy Policy
Version 1.0.2 · Effective date 2026-07-23
Pronika Privacy Policy
Effective Date: 2026-07-12
Version: 1.0.2
Nature Combined Co., Ltd. (the “Company”) values the personal information of members and users who use “Pronika,” the cloud-based project collaboration service provided by the Company (the “Service”), and complies with applicable laws including the Personal Information Protection Act (「개인정보 보호법」), the Act on the Consumer Protection in Electronic Commerce, etc. (「전자상거래 등에서의 소비자보호에 관한 법률」), the Protection of Communications Secrets Act (「통신비밀보호법」), and the Framework Act on National Taxes (「국세기본법」).
This Privacy Policy explains what personal information the Company collects, uses, stores, and destroys in the course of providing the Service; what happens when personal information is provided to third parties, entrusted for processing, or transferred overseas; what rights users have; and how they may exercise those rights.
The Company processes personal information only for necessary purposes such as consent of the data subject, contract formation and performance and service provision, compliance with legal obligations, and service security, prevention of unauthorized use, and incident response within a scope that does not unduly infringe users’ rights, in accordance with Article 15 of the Personal Information Protection Act and related provisions.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Processed personal information will not be used for purposes other than those listed below. If the purpose of use changes, the Company will obtain separate consent or take necessary measures in accordance with Article 18(3) of the Personal Information Protection Act.
1. Membership registration and account management
Member identification, contact verification, login, account creation and management, permission settings, workspace invitation and member management, prevention of unauthorized use, authentication and security management
2. Service provision and operation
Project creation and management, project request drafting and review, quote requests and submissions, contract, agreement, acceptance, and settlement management, task assignment, schedule management, file sharing, chat and notifications, document creation and transmission, customer support
3. Workspace and project collaboration features
Member management by workspace owners and administrators, information sharing among project participants, role-based screen provision, review of collaboration history, management of work progress status
4. AI feature provision
AI-based document summarization, Q&A, analysis of project requests, quotes, contracts, and task content, text generation, project operations assistance, error analysis, abuse prevention, quality improvement, security review
5. Electronic contract and electronic agreement features
Contract drafting, sending, viewing, signing, approval, and rejection; verification of electronic intent; prevention of document tampering; evidence of contract formation and performance; dispute response
6. Payment, billing, refunds, and settlement
Paid service payment, subscription management, usage calculation, issuance of invoices, receipts, and tax invoices, refund processing, settlement, accounting
7. Customer support and complaint handling
Receipt and response to inquiries, incident response, review of usage history, dispute mediation, delivery of notices, notification of changes to terms and policies
8. Informational content email delivery
Where the user has given optional consent, delivery of informational content emails such as the Pronika newsletter, new blog posts, project management tips, collaboration know-how, and industry trends, and management of opt-in and opt-out history
9. Promotional email delivery
Where the user has given optional consent, delivery of promotional emails regarding new features, product updates, events, promotions, pricing plans, and benefits, and management of opt-in and opt-out history
10. Security and audit
Retention of access logs, review of authentication records, detection of abnormal access, prevention of unauthorized use, incident response, internal audit, preservation of legal rights
11. Service improvement and statistical analysis
Service quality improvement through de-identified and aggregated statistical analysis of feature usage, error rates, response speed, usage volume, token counts, costs, access environment, and similar metrics
12. Promotion and referral program operation
Promotion Center participation applications and consent, issuance and sharing of referral links and codes, verification of fulfillment of conditions such as referred-user signup and payment, payment, recovery, and adjustment of benefits such as bonus AI Credits and discounts, prevention of fraud and duplicate participation, notice of program guidance, changes, and termination, and related dispute response
12. Public Agency Profile and directory
Display an Agency Profile expressly published by a Member to signed-in members of Client Workspaces and provide agency discovery, comparison, project request, and collaboration connection features.
13. Operating Entity and business verification
Manage Individual or Company selection, verify business identity and authority for Company profiles, prevent duplicate verification of the same business registration number, and maintain a consistent verified legal entity.
14. Profile publication history
Record publication, privacy changes, replacement of the published profile, and unpublication caused by ownership transfer for user requests, security, dispute response, and audit evidence.
Article 2 (Personal Information Items Processed)
The Company may process the following personal information to the extent necessary to provide the Service.
Category | Items Processed | Purpose of Processing |
|---|---|---|
Membership registration and account | Name, email, password, phone number, SMS verification records, affiliated company or organization name, job title or role, permissions, invitation history, email verification records | Member identification, login, account management, permission management, security |
Profile and display information | Profile photo, department, rank or title, region or country, public introduction, contact visibility settings | Profile display, collaboration contact, workspace member identification |
Business verification | Business registration number, business registration certificate or business verification documents, verification status and results | Verification of corporate or business workspaces, feature restrictions and display |
Workspace management | Workspace name, owner, administrator, and member information, invitation email, role, permissions, participating projects, activity status | Workspace operation, member management, access control |
Project collaboration | Project name, project requests, quotes, contracts, agreements, acceptance, tasks, schedules, comments, chat, files, documents, links, memos, and other content entered or uploaded by users | Project collaboration, task processing, document creation and transmission, dispute response |
Electronic contracts and agreements | Original contract documents, signing, approval, and rejection history, signer information, send, view, and download history, IP address, User-Agent, timestamps, document hash values | Electronic contract execution, electronic agreement evidence, tampering prevention, dispute response |
AI features | AI request content, AI response content, attached or referenced documents, files, and project information, feature name, screen name, model information, token count, processing status, error information, request and response timestamps | AI feature provision, error analysis, customer support, security, abuse prevention, quality improvement |
Payment and settlement | Payment method identifiers, payment approval numbers, billing and refund records, subscription products, usage volume, tax invoice issuance information, business information | Fee billing, payment, refunds, settlement, accounting |
Customer support | Inquiry content, response content, attachments, email, phone number, consultation history | Handling customer inquiries, incident response, dispute response |
Informational content email | Email, opt-in status for informational content emails, consent and withdrawal timestamps, consent source, IP address, User-Agent | Delivery of informational content such as newsletters, new blog posts, project management tips, collaboration know-how, and industry trends, and management of opt-in and opt-out history |
Promotional email | Email, opt-in status for promotional emails, consent and withdrawal timestamps, consent source, IP address, User-Agent | Delivery of promotional information such as new features, product updates, events, promotions, pricing plans, and benefits; management of opt-in and opt-out history; compliance with laws on transmission of promotional information |
Access and audit logs | IP address, User-Agent, browser, OS, device information, request ID, access timestamp, authentication method, event logs, change history | Security, incident response, prevention of unauthorized use, audit evidence |
Notifications and delivery | Email, phone number, delivery recipients, delivery content, receipt status, read status, delivery failure information | Authentication, notifications, announcements, notice of changes to terms and policies |
Promotion and referral program | Participation application and consent history, referral link and code identifiers, referrer and referred-user relationship information, condition fulfillment and reward payment and recovery history, IP address, User-Agent, access and event logs | Operation of promotion and referral programs, benefit payment and recovery, fraud prevention, dispute response |
However, original business registration certificate files are deleted without delay after verification is approved or rejected, and only minimum information such as verification results, business registration number, and verification status may be retained where necessary.
In principle, the Company processes only the minimum personal information necessary to provide the Service. Items related to informational content emails and promotional emails are processed only where the user has given optional consent. However, where users enter or upload personal information in project documents, contracts, attachments, chat, task content, or similar materials, such information may also be processed to the extent necessary to provide the Service.
Category | Items Processed | Purpose |
|---|---|---|
Operating Entity | Individual or Company type, entity selection timestamp, verification completion timestamp | Apply profile type, verification flow, and publication requirements |
Public Agency Profile | Publication status and timestamps, target Workspace, public display name, company or Workspace name, profile image, public introduction, specialties, rating and review count, completed project count, activity start year, website, location visibility and region when public | Agency directory and direct profile, agency discovery, evaluation, and project connection |
Profile publication audit log | Actor, Workspace, publication state, event timestamp, IP address, User-Agent, applicable policy version, and replacement reason | Security, user request handling, dispute response, and audit evidence |
Duplicate business verification prevention | Digit-normalized business registration number, verified account, and verification status | Prevent the same business registration number from being verified to multiple active accounts |
Article 3 (User-Uploaded Content and Third-Party Personal Information)
Because the Service provides project collaboration, document management, electronic contracts, file sharing, and AI assistance features, users may enter or upload materials containing their own personal information or that of third parties in the course of using the Service.
Materials uploaded by users may include the following information:
1. Names, emails, phone numbers, affiliations, and job titles of customers, contacts, outsourced personnel, partners, and project stakeholders
2. Project requests, quotes, contracts, tax invoices, settlement materials, and business information
3. Project deliverables, work instructions, meeting minutes, acceptance materials, and attachments
4. Other information directly entered or uploaded by users to the Service
Where users enter or upload materials containing third-party personal information to the Service, they must have lawful authority to collect, use, and provide that information.
The Company processes user-uploaded content only within the scope of the purposes set forth in this Privacy Policy, including service provision, security, incident response, customer support, and preservation of legal rights.
Article 4 (Processing of Personal Information When Using AI Features)
To provide AI features within the Service, the Company may process users’ AI request content, AI response content, related project information, attached or referenced documents and files, and usage records such as feature, screen, model, token, error, and processing status information.
For AI feature provision, error analysis, customer support, security, abuse prevention, and service quality improvement, authorized operations personnel may view the raw text of AI requests and responses only to the extent necessary to achieve those purposes. The Company does not routinely review or inspect all AI usage content.
The Company does not use content entered or uploaded by users to Pronika for training of its own AI models or third-party AI models. The Company also does not configure external AI service providers to use user content for model training or improvement without separate notice or consent.
However, for AI feature provision, user request content, related content, and technical usage records may be transmitted to external AI service providers such as OpenAI, LLC (United States). Where possible, the Company applies protective measures such as minimization of personal information, masking, access restriction, and encryption in transit. External AI service providers may temporarily process data to the extent necessary for service provision, including AI response generation, security, abuse prevention, and incident response; the scope follows the Company’s API settings, contractual terms, and the provider’s policies.
The raw text of AI requests and responses is retained for a maximum of 90 days from the date of creation and is automatically deleted or de-identified upon expiration of the retention period by default. Where processing purposes such as error analysis, customer support, or security response have been achieved, operations personnel may delete raw text even before 90 days have elapsed. Where there is a legitimate reason such as a legal preservation order or dispute response, retention may exceptionally occur within the relevant scope and period. After raw text is deleted or de-identified, technical usage records and de-identified aggregated statistics that cannot identify individuals—such as feature name, model, token count, processing status, cost, irreversible hash values, call counts, feature usage volume, and error rates—are retained and used for 5 years. However, where necessary for security, duplicate detection, or dispute response, technical identifiers that cannot restore raw text may be retained on a limited basis.
Depending on the type of AI feature, the Company processes personal information as follows:
1. Processing by AI feature type
(a) Website support chat: Logged-in users may ask questions based on public FAQs, policies, and content. Conversation content is not persistently stored on the server; only recent conversation context transmitted from the user’s device is referenced at the time of request. Search queries, search scope, result counts, and similar data are retained as temporary operational logs and are not linked to personal identifiers. Raw text of AI request and response content during response generation follows the earlier part of this Article and “AI request and response raw text” in Article 5.
(b) Roni: In agency workspaces, agency account members receive project operations assistance and general Q&A; in client workspaces, client account members receive the same. When the user has entered the relevant project screen, the system may reference document search (embeddings) for that project together with public FAQ, policy, and content search, and does not batch-search documents from other projects in the workspace. Workspace-level queries without entering a project screen reference public FAQs, policies, content, and metadata such as accessible project lists and status, and do not batch-search document bodies or embeddings from other projects.
(c) Document Q&A: Provides Q&A on project documents for agency account members in agency workspaces. Search scope is limited to the relevant project, as in (b).
(d) Roni conversation history: When using Roni, the user’s questions and AI responses are stored as conversation history. Retention and destruction periods follow Article 5.
(e) Roni context memos: Operational memos at workspace or project scope (Roni suggestions or direct user input) may be stored. Where an expiration date is set, they are excluded from reference after that time; retention and destruction follow Article 5.
2. Processing of AI search embeddings (vectors)
(a) Project documents: In agency workspaces, project documents manually reflected by users may be converted and stored as vectors for AI search. They are destroyed without delay upon workspace deletion or permanent deletion of the original file (retried in daily batch if operationally delayed); project closure alone does not trigger automatic destruction. Vectors may remain until files in the trash are permanently deleted.
(b) Public knowledge for website support chat: Vectors are generated and managed based on public information provided by the Company such as FAQs, policies, and content, and do not identify individual users.
Users should exercise caution when entering personal information, sensitive information, trade secrets, or non-public contract information when using AI features. The Company may provide guidance on precautions for AI feature use through service screens or policies.
Article 5 (Retention and Use Period of Personal Information)
The Company destroys personal information without delay when the purpose of processing is achieved or when the user requests membership withdrawal. However, where there is a statutory retention obligation or retention is necessary for dispute response, prevention of unauthorized use, or preservation of legal rights, information may be retained for the relevant period.
Category | Retention Period |
|---|---|
Member account information | Until membership withdrawal or achievement of processing purpose. Upon withdrawal, account personal information (name, email, phone number, authentication information, personally uploaded materials, 1:1 inquiries, etc.) is immediately deleted or de-identified |
Remaining data after withdrawal | Information contained in shared work records (chat, projects, quotes, contracts, etc.) may be retained to the extent necessary for other users’ legitimate use, dispute response, and statutory preservation; the withdrawing member’s identifying information is masked or de-identified. Content authored by the member that is subject to deletion or anonymization is handled under this Policy and the Terms of Service. Work message bodies authored by others may be retained within the scope of collaboration and dispute purposes. Residual disaster-recovery backup data is retained for a maximum of 90 days |
Workspace and project information | Service access is blocked immediately upon workspace deletion. Transaction and collaboration records such as quotes, contracts, agreements, chat, and project files are separately retained for the statutory retention period (default 5 years) and then destroyed. AI search embeddings (vectors) for project documents follow the corresponding item in this table |
AI search embeddings (vectors) for project documents | Destroyed without delay upon workspace deletion or permanent deletion of the original file (retried in daily batch if operationally delayed). Not automatically destroyed upon project closure alone. Trash files may be retained until permanent deletion. Residual disaster-recovery backup data is retained for a maximum of 90 days |
Project chat | Retained for 5 years after project closure is confirmed; messages and attachments destroyed after the period (deferred if a legal preservation order is registered) |
Transaction-related records such as contracts, agreements, acceptance, and settlement | 5 years after transaction completion (Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree; Framework Act on National Taxes) |
Payment, billing, refund, and tax invoice records | 5 years (Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree; Framework Act on National Taxes) |
Consumer complaint or dispute handling records | 3 years after dispute resolution (Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree) |
Electronic contract and electronic agreement audit logs | 5 years after contract termination or until dispute resolution |
AI request and response raw text | Maximum 90 days from creation date. By default, request and response raw text is deleted or de-identified. Technical usage records such as feature name, model, tokens, processing status, and irreversible hash values are separately retained under “AI usage aggregated statistics.” Early deletion is possible when processing purposes are achieved (exceptions for legal preservation orders, dispute response, etc.) |
AI conversation (Roni) history | Maximum 90 days from creation or last update date. Automatically deleted by default. Immediately destroyed upon membership withdrawal, user manual deletion, or workspace deletion |
Roni context memos | During workspace or project maintenance or until a configured expiration date. Destroyed without delay upon membership withdrawal, workspace deletion, or user deletion |
AI usage aggregated statistics | After AI request and response raw text is deleted or de-identified, retained in de-identified aggregated form that cannot identify individuals—such as feature name, model, tokens, processing status, and irreversible hash values—for 5 years |
Informational content email opt-in and opt-out history | Until consent withdrawal or membership withdrawal. Opt-out history is retained for 1 year after withdrawal or membership termination to prevent re-sending and for dispute response |
Promotional email opt-in and opt-out history | Until consent withdrawal or membership withdrawal. Retained for 1 year after withdrawal or membership termination for compliance with laws on promotional information transmission, prevention of re-sending, and dispute response |
Promotion and referral program records | Until program termination or achievement of processing purpose. Retained for 3 years after termination or withdrawal for benefit payment, recovery, dispute response, and fraud prevention (or longer where required by applicable law) |
Access and audit logs | Service security and audit logs such as login, administrator activity, permission changes, and major data changes are retained for a maximum of 2 years for security, prevention of unauthorized use, incident response, and preservation of legal rights. Among these, internet log records, access trace data, and similar items subject to retention under the Protection of Communications Secrets Act and its Enforcement Decree may be retained for the period prescribed by those laws. |
Temporary operational logs (RAG search, notification delivery, signup authentication challenges, etc.) | 90 days. RAG search logs include search queries, search scope, result counts, response paths, and similar data, and are not linked to personal identifiers (including operational review and search testing) |
Authentication, session, and invitation residual records | 90 days after expiration, revocation, or acceptance |
Business verification materials | Original files deleted immediately upon approval or rejection of verification. Business registration number, verification status, and results (including rejection reasons) are retained for the lifetime of the verified account and destroyed without delay upon account withdrawal unless statutory retention or dispute response requires otherwise |
Trash files | 30 days after deletion, then permanently deleted |
Backup data (RDS snapshots, object storage versions) | Rolling retention for disaster recovery for a maximum of 90 days, then sequentially deleted |
Where there is a statutory retention obligation, the Company may retain relevant information as follows:
Items Retained | Retention Period | Legal Basis |
|---|---|---|
Records on labeling and advertising | 6 months | Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree |
Records on contracts or withdrawal of offers | 5 years | Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree |
Records on payment and supply of goods, etc. | 5 years | Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree |
Records on consumer complaints or dispute handling | 3 years | Act on the Consumer Protection in Electronic Commerce, etc. and its Enforcement Decree |
Tax invoices, books, and supporting documents | 5 years | Framework Act on National Taxes |
Access logs and other information subject to statutory retention | Period prescribed by applicable law | Protection of Communications Secrets Act and its Enforcement Decree, etc. |
Public Agency Profile items are displayed until the Member makes the profile private or withdraws the account. A privacy change removes the profile immediately from directory and direct profile results. Publication and privacy audit logs are retained for up to two years from the event for security, dispute response, and audit evidence.
Article 6 (Provision of Personal Information to Third Parties)
In principle, the Company does not provide users’ personal information to third parties. However, personal information may be provided to third parties in any of the following cases:
1. Where the user has given prior consent
2. Where specially prescribed by law or where there is a lawful request from an authorized body such as an investigative agency, court, or supervisory authority
3. Where provided to parties with whom the user directly shares or grants permissions within collaboration features such as workspaces, projects, contracts, quotes, and tasks in connection with service provision
4. Where provided to parties selected or requested by the user to the extent necessary for use of the Service, such as payment, settlement, electronic contracts, and notification delivery
5. Where deemed necessary to protect vital interests in life, body, or property
Within the Service, workspace owners, administrators, and project participants may view other members’ names, emails, affiliations, roles, project participation history, work history, comments, files, contract and agreement progress status, and similar information within the scope of granted permissions.
Where the Company provides personal information to third parties, it notifies users of and obtains consent to the recipient, purpose of provision, items provided, and retention and use period in accordance with Articles 17 and 18 of the Personal Information Protection Act. This does not apply where consent is exempted by law.
In-Service Disclosure of a Public Agency Profile
Recipients | Signed-in members of Pronika Client Workspaces |
|---|---|
Purpose | Agency discovery, comparison and evaluation, project requests, and collaboration connection |
Items | Public display name, company or Workspace name, profile image, public introduction, specialties, rating and review count, completed project count, activity start year, website, and region only when location visibility is Public |
Retention and use | The profile can be viewed in the Service while the Member keeps it public. The Company does not provide recipients with a separate profile file. A recipient’s independent capture of screen content is governed by that user’s responsibility and applicable law. |
Right to refuse and consequence | A Member may refuse publication or make the profile private at any time. Refusal does not prevent account or internal collaboration use, but the profile will not appear in the Agency directory or receive directory-based project connections. |
Before the publication button is confirmed, the Company displays the audience, purpose, items, period, refusal right, and a link to this Privacy Policy. If the Company processes the information beyond the Member-requested publication scope or in a manner requiring separate consent, it provides additional notice and obtains consent as required by law.
Article 7 (Entrustment of Personal Information Processing)
For smooth service provision, the Company may entrust part of personal information processing to external vendors. In accordance with Article 26 of the Personal Information Protection Act, when entering into entrustment agreements, the Company includes necessary provisions to ensure safe processing by processors and manages and supervises processors’ personal information processing status.
Processor | Entrusted Tasks | Items Processed | Retention and Use Period |
|---|---|---|---|
OpenAI, LLC | AI response generation, security, abuse prevention, incident response | AI request content, related content, technical usage records | Period necessary for service provision including AI response generation, security, abuse prevention, and incident response. The specific processing and retention scope of external AI service providers follows the Company’s API settings, contractual terms, and the provider’s policies. Within the Company, AI request and response raw text is retained for a maximum of 90 days from creation and then deleted or de-identified. |
Amazon Web Services, Inc. | Relational database (RDS) operation and backup (Republic of Korea ap-northeast-2, Seoul region) | Data processed in the course of using the Service | Duration of service provision (backup residual data: maximum 90 days) |
Cloudflare, Inc. | Object storage (R2) operation and backup | User-uploaded data such as files and media | Duration of service provision (backup residual data: maximum 90 days) |
Viva Republica Co., Ltd. (Toss Payments) | Payment approval, refunds, settlement, billing key management | Payment and billing-related information (direct payment method information such as card numbers is not stored on Company servers) | 5 years under applicable law including the Act on the Consumer Protection in Electronic Commerce, etc., and contractual retention period |
Aligo Co., Ltd. | SMS verification codes and notification delivery | Phone number, delivery content, delivery history | 90 days for delivery and evidence purposes |
Amazon Web Services, Inc. | Email delivery (Amazon SES, Republic of Korea ap-northeast-2) | Email, delivery content, delivery history | 90 days for delivery and evidence purposes |
Google LLC | Mobile push notifications (Firebase Cloud Messaging) | Device token, notification title and content | While device registration is maintained or until deregistration or withdrawal |
1:1 inquiries and customer support are handled through systems operated by the Company within the Pronika Service and are not entrusted to separate external customer support SaaS. The primary database (AWS RDS) and transactional email (Amazon SES) use the Republic of Korea ap-northeast-2 (Seoul) region. Even where a processor is a foreign entity, whether overseas transfer notice is required is reviewed based on actual storage and processing location, accessibility, and contractual structure.
If the content of entrusted tasks or processors changes, the Company discloses such changes through this Privacy Policy in accordance with Article 26(2) of the Personal Information Protection Act.
Article 8 (Overseas Transfer of Personal Information)
For service provision including AI features, object storage, and push notifications, the Company may transfer personal information overseas or have it processed by overseas businesses. The primary database (AWS RDS) and transactional email (Amazon SES) use the Republic of Korea ap-northeast-2 (Seoul) region.
Recipient and Contact | Destination Country | Items Transferred | Purpose of Transfer | Timing and Method of Transfer | Retention and Use Period |
|---|---|---|---|---|---|
OpenAI, LLC | United States | AI request content, related content, technical usage records | AI response generation, security, abuse prevention, incident response | TLS-encrypted network transmission when using AI features | Period necessary for service provision including AI response generation, security, abuse prevention, and incident response. The specific processing and retention scope of external AI service providers follows the Company’s API settings, contractual terms, and the provider’s policies. Within the Company, AI request and response raw text is retained for a maximum of 90 days from creation and then deleted or de-identified. |
Cloudflare, Inc. | United States and other countries where Cloudflare infrastructure operates, or countries according to the R2 bucket jurisdiction configured by the Company | User-uploaded data such as files and media | Object storage, file delivery, backup | Encrypted network transmission and storage upon file upload and download | Duration of service provision (backup residual data: maximum 90 days) |
Google LLC | United States | Device token, notification title and content | Mobile push notification delivery | TLS-encrypted network transmission upon notification delivery | While device registration is maintained or until deregistration or withdrawal |
Users may refuse overseas transfer of personal information. However, where overseas transfer is essential for service provision (AI features, file storage and sharing, mobile push notifications, etc.), use of the relevant feature or Service may be restricted.
Where overseas transfer occurs, the Company notifies users of the recipient, destination country, items transferred, purpose of transfer, timing and method of transfer, and retention and use period through this Privacy Policy or separate notice in accordance with Article 28-8 of the Personal Information Protection Act.
Article 9 (Procedures and Methods for Destruction of Personal Information)
The Company destroys personal information without delay when the retention period has expired or the purpose of processing has been achieved.
1. Destruction procedure
The Company identifies personal information for which a reason for destruction has arisen and destroys it according to internal procedures. Information subject to statutory retention obligations is stored in a separate database or segregated storage space and destroyed after the relevant period expires.
2. Destruction method
Personal information in electronic file form is deleted so that recovery or regeneration is difficult. Printed materials such as paper documents are shredded or destroyed by an equivalent method.
3. Backup data
Backup data may not be immediately deletable and is sequentially deleted according to the Company’s backup cycle and retention policy (maximum 90 days). Backup data is not used for general service provision purposes other than recovery.
Article 10 (Rights of Users and Legal Representatives and How to Exercise Them)
Users may exercise the following rights against the Company at any time under Articles 35 through 37 of the Personal Information Protection Act:
1. Request access to personal information
2. Request correction where there are errors
3. Request deletion
4. Request suspension of processing
5. Withdraw consent
6. Request membership withdrawal and account deletion
Users may exercise their rights through the personal information access, correction, and deletion request functions on the Settings > Data & Privacy screen within the Service, by email (contact@naturecombined.com), or in writing. Where a user makes a request, the Company conducts identity verification as required by law before taking necessary measures.
Upon receiving requests for access, correction, deletion, or suspension of processing, the Company notifies the user of the result or reason for delay within the period prescribed by applicable law. For access requests, the Company generally informs the user within 10 days whether access is available, the method of access, or the reason for restriction or refusal. Where extension is necessary for legitimate reasons, the Company informs the user of the reason and expected processing date. The Company takes necessary measures such as access and copy provision to the extent permitted by law and does not refuse the exercise of rights itself even if it does not provide an immediate bulk download function through the service screen.
However, requests may be restricted by law in the following cases:
1. Where there is a statutory retention obligation
2. Where there is concern of harm to another person’s life, body, property, or rights and interests
3. Where necessary for contract performance, fee settlement, or dispute response
4. Where necessary to preserve legal evidence such as electronic contracts and audit logs
5. Where necessary for service security and prevention of unauthorized use
After processing a user’s request, the Company informs the user of the result.
Article 11 (Processing of Personal Information of Children Under 14)
The Company does not permit membership registration or use of the Service by children under 14 years of age.
If the Company confirms that personal information of a child under 14 has been collected or processed without consent of a legal representative, it deletes such information or takes necessary measures without delay.
Article 12 (Processing of Sensitive Information and Unique Identifying Information)
In principle, the Company does not collect unique identifying information such as resident registration numbers, passport numbers, driver’s license numbers, or alien registration numbers, or sensitive information such as ideology or beliefs, labor union or political party membership, health, sexual life, genetic information, or criminal records.
However, where users arbitrarily include sensitive information or unique identifying information in project documents, contracts, attachments, chat, AI request content, or similar materials, the Company does not recommend such input and processes it only to the minimum extent unavoidable for service provision. Under the Terms of Service, the Company may take measures such as masking and access restriction for unnecessary sensitive or unique identifying information, may automatically mask certain patterns such as resident registration numbers, card numbers, and account numbers when storing text such as chat, and may minimize or mask personal information when integrating with external services such as AI to the extent possible. Upon membership withdrawal or deletion requests under Article 10, such information is deleted or de-identified as set forth in this Policy.
Users should refrain from entering or uploading unnecessary sensitive information or unique identifying information when using the Service.
Article 13 (Installation, Operation, and Refusal of Automatic Collection Devices)
For service provision, login maintenance, security, user environment settings, and service usage analysis, the Company may use automatic collection devices such as cookies, sessions, local storage, SDKs, and log analysis tools.
1. Purpose of use
Maintaining login status, security authentication, saving user settings, service usage statistical analysis, error analysis, prevention of unauthorized use
2. Information that may be collected
IP address, cookie identifiers, session information, browser information, OS, device information, access timestamp, screens used, click and event logs, error logs
3. How to refuse
Users may refuse or delete cookie storage through browser settings. However, if essential cookies or security-related storage devices are refused, use of services requiring login may be restricted.
4. Email opt-in and opt-out
The Company may send informational content emails or promotional emails where the user has given separate optional consent. Informational content emails may include newsletters, new blog posts, project management tips, collaboration know-how, and industry trends. Promotional emails may include new features, product updates, events, promotions, pricing plans, and benefits. Users may opt out of each type of email at any time through service settings or the unsubscribe method in the email. When transmitting promotional information, the Company complies with applicable laws including Article 50 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
Where the Company collects or uses behavioral information for advertising purposes or provides it to third parties, it establishes separate notice and consent procedures under the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. Currently, the Company does not collect or use behavioral information for personalized advertising purposes.
Article 14 (Measures to Ensure Security of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act, the Company implements the following technical, administrative, and physical measures to ensure the security of personal information:
1. Access rights management
Access rights to personal information processing systems are granted to the minimum scope necessary for job performance, and history of permission changes and revocations is managed.
2. Authentication and access control
Administrator account protection, password policies, multi-factor authentication where necessary, and access control measures such as restriction of accessible IP addresses or networks are implemented.
3. Encryption
Passwords are stored in a non-reversible manner, and protective measures such as encryption during transmission or storage are applied to important information.
4. Retention and review of access logs
Access logs to personal information processing systems, administrator activity history, and major change history are retained and checked for anomalies.
5. Security programs and vulnerability management
Security updates, vulnerability assessments, and incident response procedures are operated.
6. Internal management plans and training
Internal standards for personal information protection are established, personnel who process personal information are limited, and necessary training is provided.
7. Backup and recovery
Backups are performed against failures and data loss, and access to backup data is restricted.
8. Physical protective measures
Physical access to systems and materials storing personal information is restricted.
Article 15 (Processing of Personal Information by Workspace Administrators)
Because the Service is B2B SaaS premised on organization-level collaboration, workspace owners or administrators may view and manage certain information of members for operation of the relevant workspace.
Information that workspace owners or administrators may view may include:
1. Members’ names, emails, affiliations, roles, and permissions
2. Project participation history
3. Task assignment and processing history
4. Collaboration activity history such as file uploads, comments, chat, and document creation
5. Progress status related to contracts, agreements, acceptance, and settlement
6. Access and activity logs for security and audit purposes within the scope of permissions
Workspace owners or administrators must lawfully process members’ personal information in accordance with applicable laws and internal regulations.
Where a workspace owner or administrator processes personal information beyond the scope of permissions or uses the Service in violation of applicable laws, the Company may take necessary measures such as restriction of service use.
Participation in another company’s Workspace does not automatically link or disclose that company’s information with a personal or Studio Workspace or profile separately owned by the Member. Owners and administrators may view member information only within granted permissions and may not complete or publish the Member’s separately owned Workspace profile on the Member’s behalf.
Article 16 (Personal Information Protection Officer and Contact Information)
In accordance with Article 31 of the Personal Information Protection Act, the Company designates a Personal Information Protection Officer and responsible department as follows to oversee personal information processing and handle inquiries, complaints, and requests for relief related to personal information:
Company Information
Legal Name: Nature Combined Co., Ltd.
Address: Room 518, Incubating Center, 57 Dongtan Advanced Industry 1-ro, Yeongcheon-dong, Hwaseong-si, Gyeonggi-do 18469, Republic of Korea
Business Registration Number: 881-86-02075
Personal Information Protection Officer
Name: Dong Bang-jin
Title: Chief Executive Officer
Email: contact@naturecombined.com
Phone: +82-2-1811-0729
Contact for Access Requests and Grievance Handling
Department: Pronika Customer Support Team
Email: contact@naturecombined.com
Phone: +82-2-1811-0729
Users may contact the above department regarding all personal information protection inquiries, complaint handling, and requests for relief arising in connection with use of the Service. The Company will respond to and process user inquiries without delay.
Article 17 (Remedies for Infringement of Rights)
Users may apply for consultation or dispute resolution to the following institutions to obtain relief for personal information infringement:
1. Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (without area code) (privacy.kisa.or.kr)
2. Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
3. Supreme Prosecutors’ Office Cyber Investigation Division: 1301 (without area code) (www.spo.go.kr)
4. National Police Agency Cyber Bureau: 182 (without area code) (ecrm.police.go.kr)
The above institutions are separate from the Company. If users are not satisfied with the Company’s own personal information complaint handling or relief results, or need more detailed assistance, they may contact those institutions.
Article 18 (Amendments to This Privacy Policy)
The Company may amend this Privacy Policy when applicable laws, service content, personal information processing methods, processors, or overseas transfer details change.
When amending this Privacy Policy, the Company notifies users of the amended content, reason for amendment, and effective date through appropriate methods such as in-service announcements, email, login screens, separate notifications, or website posting.
Where an amendment has a material impact on users’ rights or obligations, the Company follows the period prescribed by applicable law where such a period exists, and where no separate period is clearly specified, notifies users in principle at least 7 days before the effective date. For amendments with material impact on users—such as changes to processing purposes, items, third-party provision, overseas transfer, or retention periods—the Company notifies users, where possible, at least 30 days before the effective date.
Where amended content requires separate user consent under applicable law, the Company obtains user consent before processing personal information under the amended terms.
Supplementary Provisions
This Privacy Policy is effective as of July 12, 2026.
If a previously announced scheduled version is superseded by a higher version, the Company preserves the prior version and its notice, consent, and audit evidence together with the supersession relationship and timestamp, rather than deleting it or reverting it to draft.