Terms & policies
Privacy policy
RenaAi (legal name: 주식회사 레나에이아이) (the "Company") values users' personal information and complies with the Personal Information Protection Act (PIPA) of Korea and other relevant laws.
Effective date: April 1, 2026
This English version is provided for convenience. If there is any conflict, the Korean version prevails. Korean version
Article 01 (Personal information collected)
The Company collects the following personal information in order to provide its services.
■ Items collected when applying for a service (EV Assessment application)
• Required: name, email address, contact number (telephone), company name, job title
• Optional: industry, revenue size, background to the service application and inquiry details
■ Items collected automatically while the service is used
• IP address, cookies, date and time of visit, browser type, OS, service usage records
■ Additional items collected when entering into a paid service contract
• Corporate name, business registration number, contract contact person's details, bank account details (for issuing tax invoices)
Article 02 (Purposes of collection and use of personal information)
The Company uses the personal information it collects for the following purposes.
① Providing and operating the service
• Receiving EV Assessment applications and delivering results
• Performing consulting services for the adoption of AI solutions
• Concluding, performing and managing contracts
② User management and consultation
• Identity verification and confirmation of the intention to apply for the service
• Receiving and handling inquiries and complaints, and delivering notices
③ Service improvement and marketing
• Statistical analysis of service usage and quality improvement
• Information on new services and events (only where prior consent has been given)
Article 03 (Retention and use period of personal information)
① In principle, the Company destroys personal information without delay once the purposes of its collection and use have been achieved.
② However, where the relevant laws require retention for a certain period, the information is kept for that period.
• Records of contracts or withdrawal of offers, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
• Records of payment and supply of goods, etc.: 5 years (same Act)
• Records of consumer complaints or dispute resolution: 3 years (same Act)
• Tax invoices and other tax-related records: 5 years (Framework Act on National Taxes)
• Access logs and access IP information: 3 months (Protection of Communications Secrets Act)
③ Where a service application does not lead to a contract, the application information is destroyed one year after the date the consultation ends.
Article 04 (Provision of personal information to third parties)
① In principle, the Company does not provide users' personal information to outside parties.
② The following cases are exceptions.
• Where the user has given prior consent
• Where required under the provisions of laws, or where an investigative agency requests it for investigative purposes in accordance with the procedures and methods prescribed by law
Article 05 (Entrustment of personal information processing)
① Where necessary to provide the service, the Company may entrust personal information processing tasks to outside companies as follows.
• Email delivery service: an external email service provider
• Analytics tools: an analytics platform for collecting web usage statistics (information collected: de-identified access statistics)
② When entering into an entrustment contract, the Company specifies in the contract the provisions required by the relevant laws so that personal information is managed securely, and manages and supervises how the entrustee processes personal information.
③ If the entrusted tasks or the entrustee change, the Company will disclose the change through this Policy.
Article 06 (Rights of data subjects and how to exercise them)
① Users (data subjects) may exercise the following rights against the Company at any time.
• Request access to personal information
• Request correction where there are errors, etc.
• Request deletion
• Request suspension of processing
② Users may exercise these rights by email (info@renaai.co), and the Company will take action without delay (within 10 days).
③ Where a user requests correction or deletion of errors, etc. in personal information, the Company will not use or provide that personal information until the correction or deletion is complete.
④ Users may exercise these rights only with respect to their own personal information as data subjects, and should take care not to infringe on the personal information and privacy of others.
Article 07 (Destruction of personal information)
① When personal information is no longer needed, such as when the retention period has expired or the purpose of processing has been achieved, the Company destroys that personal information without delay.
② The methods of destruction are as follows.
• Personal information stored in electronic files: deleted using technical methods that make the records unrecoverable
• Personal information printed on paper: shredded or incinerated
③ Where personal information must continue to be retained under law even though the retention period consented to by the user has expired or the purpose of processing has been achieved, the personal information is moved to a separate database (DB) or stored in a different location.
Article 08 (Use of cookies)
① The Company may use cookies to provide users with personalized services.
② A cookie is a small amount of information that the server used to operate the website sends to the user's browser, and it is stored on the hard disk of the user's computer.
③ Users have a choice regarding the installation of cookies. Through browser settings, users can choose to allow cookies, to be asked before they are saved, or to refuse them. However, refusing to store cookies may limit the use of some services.
e.g. Chrome: Settings → Privacy and security → Cookies and other site data
Article 09 (Measures to ensure the security of personal information)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, managerial and physical measures necessary to ensure security.
① Technical measures
• Encryption (HTTPS/TLS) when personal information is transmitted
• Access control and restriction of access by unauthorized persons
• Installation of security programs and periodic updates and checks
② Managerial measures
• Minimizing the number of employees who handle personal information and providing regular training
• Establishing and implementing internal personal information processing guidelines
③ Physical measures
• Restricting access to physical storage locations such as server rooms and records storage rooms
Article 10 (Chief privacy officer)
The Company has designated a chief privacy officer, as follows, to take overall responsibility for personal information processing and to handle related user complaints and remedies for damage.
■ Chief privacy officer
• Name: Byung-Geun Choi
• Title: CEO (Representative Director)
• Email: info@renaai.co
Users may direct any inquiries, complaints or requests for remedies relating to personal information protection that arise while using the Company's services to the chief privacy officer. The Company will respond to and handle user inquiries without delay.
Article 11 (Remedies for infringement of rights)
Users may contact the following organizations for remedies for, or consultation on, infringement of personal information.
■ Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency, KISA)
• Website: privacy.kisa.or.kr
• Phone: 118 (no area code)
■ Personal Information Dispute Mediation Committee
• Website: www.kopico.go.kr
• Phone: 1833-6972
■ Cyber Investigation Division, Supreme Prosecutors' Office
• Website: www.spo.go.kr
• Phone: 1301 (no area code)
■ Cyber Bureau, Korean National Police Agency
• Website: cyberbureau.police.go.kr
• Phone: 182 (no area code)
Article 12 (Changes to this privacy policy)
① This privacy policy may change in line with changes to relevant laws and internal policies.
② If this privacy policy changes, the Company will post the changes through service notices or on this page, and where the changes materially affect users, it will notify them individually by email.
③ The amended privacy policy takes effect 7 days after the date it is posted.
Addendum
This privacy policy takes effect on April 1, 2026.
Privacy inquiries
Please send inquiries about this privacy policy, or requests for access, correction or deletion, to the address below.
RenaAi (legal name: 주식회사 레나에이아이) · Chief privacy officer Byung-Geun Choi
info@renaai.co