Privacy Policy

AISUM Co., Ltd. · AEDI-V (Claude Connector · ChatGPT plugin)

This is an English translation provided for convenience. In case of any discrepancy, the Korean original prevails.

AISUM Co., Ltd. (hereinafter the "Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act, so as to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This Policy applies where AEDI-V, an AI product matching solution (hereinafter the "Service"), is used through Anthropic's Claude Connector or OpenAI's ChatGPT plugin (based on the Model Context Protocol).

The Service is available wherever Claude and ChatGPT are offered, and the product pool can be set to Korea or the United States. The Company is established in the Republic of Korea and this Policy is governed by Korean law. As set out in Section 2, the Company does not collect information that establishes a user's identity, from users in any country.

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes, and does not use the personal information it has processed for any purpose other than those purposes.

Provision of the Service: providing AEDI-V features

Handling integration requests from the Claude Connector and the ChatGPT plugin: analyzing requests delivered through Claude and ChatGPT and providing product matching results

Operation and improvement of the Service: detecting errors and fraudulent use, ensuring stability, and improving quality through statistical analysis

Customer support and handling of inquiries: receiving inquiries, replying with the results of their handling, and responding to disputes

2. Items of Personal Information Processed

In providing the Service through the Claude Connector or the ChatGPT plugin, the Company does not collect information that establishes a user's identity (such as a name, account, or contact details). There is no sign-up or account-linking step, and the Company holds no means of establishing a user's identity. For transparency, the data the Company does process and the data it does not process are set out separately below.

a. Data the Company processes

Category

Request data

Generated data

Server operational logs

Inquiry and rights-request data

Items

Values the user includes in a request (video URL, search terms, product-pool region selection, and similar)

Analysis status, product matching results, and images generated while producing them

Records generated automatically in the course of accessing and operating the Service (which may include connection information such as IP addresses)

Name, contact details, and the content of the message, as supplied by the user themselves when making an inquiry or exercising a right

How it reaches us / purpose

Delivered through Claude or ChatGPT / performing product matching

Generated by the Service / returning and re-retrieving results

Recorded automatically by the server / diagnosing errors, detecting fraudulent use, and ensuring stability

Received directly at the contact details in Section 12 / receiving inquiries, replying with the results, and responding to disputes

This data is not information used to identify a particular individual, and the Company does not link it to any individual. Retention periods for each item are set out in Section 3. An image

generated during processing may contain a person, but the Company's analysis looks only at products and performs no facial recognition or any other processing that identifies a person.

b. Data the Company does not process

Account and authentication information — the Service runs as a public server with no authentication, and the Company processes no logins, linked accounts, or access tokens.

Cookies and other information used to identify or track users (see Section 11).

Unique identification information such as resident registration numbers, and sensitive information under Article 23 of the Personal Information Protection Act.

Payment card information, health information, government-issued identifiers, and authentication secrets such as passwords or API keys.

Product matching requests are routed through the infrastructure of Anthropic and OpenAI, so for those requests the source address the Company's server sees is that of those providers. However, some resources on the results view, such as images, are fetched by the user's browser directly from the Company's server, and connection information such as the user's IP address may be recorded in the server's operational logs in the course of doing so. The Company does not use this information to identify or track any particular individual, and its retention is governed by Section 3.

The Company does not offer the Service to children under the age of 14 and does not knowingly collect a child's personal information. Users are advised not to voluntarily enter personal information or sensitive information into their requests (prompts); where such information is entered, it is deleted automatically once the retention period in Section 3 has elapsed.

3. Processing and Retention Periods of Personal Information

The Company processes and retains personal information within the retention and use period prescribed by law, or the retention and use period consented to by the data subject.

Item / purpose of processing

Request data, analysis status, and product matching results

Images created or collected during processing (still-frames and the product image cache)

Server operational logs

Inquiry and rights-request data

Retention period

Deleted automatically by a clean-up process once 30 days have passed since creation

Once the storage limit is reached, the oldest images are deleted automatically

Once the log size limit is exceeded, the oldest records are deleted automatically

Destroyed without delay once the inquiry has been handled and any dispute concluded

This table corresponds item by item to Section 2(a), "Data the Company processes". The Company holds no records it is required to retain under applicable law.

Personal information whose retention period has elapsed is destroyed without delay.

4. Provision of Personal Information to Third Parties

The Company processes the personal information of data subjects only within the scope specified in this Policy, and provides it to third parties only where Article 17 or Article 18 of the Personal Information Protection Act applies, such as with the consent of the data subject or under special provisions of law. At present there is no separate, regular provision to third parties.

For the routing of user requests and Company responses through the infrastructure of Anthropic and OpenAI, see Section 6; for the infrastructure on which the Service runs, see Section 5.

5. Service Infrastructure and Entrustment of Personal Information Processing

The Company does not currently entrust the processing of personal information to any third party. Should such entrustment arise in the future, the Company will disclose the trustee and the entrusted work in this Policy in accordance with Article 26 of the Personal Information Protection Act, and will reflect in the contract the matters necessary for safe processing.

The data listed in Section 2(a) may be stored in data centres in or outside the Republic of Korea used by the Company. Where a cross-border transfer of personal information takes place, the Company will disclose the required matters, such as the items transferred, the recipient, and the destination country, through this Policy in accordance with Article 28-8 of the Personal Information Protection Act. The Company uses no external analytics or advertising services for the purpose of identifying or tracking users.

6. Cross-Border Transfer of Personal Information

The Company does not currently transfer personal information outside Korea, and as stated in Section 2 it does not collect information that establishes a user's identity. For where data is stored, see Section 5.

However, because the Service is used through the Claude Connector or the ChatGPT plugin, a user's request and the Company's response are routed through the infrastructure of Anthropic and OpenAI (outside Korea, including in the United States). Processing on that leg is governed by each provider's own privacy policy and is outside the Company's control. So that users can make an informed judgement, the Company gives notice of the following matters, following Article 28-8(2) of the Personal Information Protection Act.

Item

Parties routed through

Contact details

Country

Timing and method

Items routed

Purpose

Retention and use period

How to refuse, and the effect of refusing

Details

Anthropic PBC (United States) / OpenAI OpCo, LLC (United States)

Anthropic PBC : privacy@anthropic.com, 548 Market St, PMB 90375, San Francisco, CA 94104, USA

OpenAI OpCo, LLC : privacy.openai.com, dsar@openai.com, 1455 Third Street, San Francisco, CA 94158, USA

United States

Transmitted over the network when the user sends a request through Claude or ChatGPT, and when the Company returns its response

Values the user includes in a request (video URL, search terms, product-pool region selection, and similar), and the product matching results the Company returns

Sending and receiving requests and responses through the Claude Connector and the ChatGPT plugin

The period under the data processing policies of Anthropic and OpenAI

Removing this connector or plugin from Claude or ChatGPT stops the routing immediately. Once it is removed, the Service can no longer be used through that host.

Matters concerning Anthropic's processing of personal information are governed by the Anthropic Privacy Policy (anthropic.com/legal/privacy).

Matters concerning OpenAI's processing of personal information are governed by the privacy policy OpenAI publishes for users in the Republic of Korea (openai.com/policies/kr-privacy-policy).

Under their own policies, Anthropic and OpenAI may use a user's inputs and outputs to train AI models; each provider lets the user choose this in their account settings. Please refer to the policies above for details.

7. Use for AI Model Training

The Company does not use the content of requests entered through the Claude Connector or the ChatGPT plugin, or user data, to train the Company's AI models, and does not provide such data to any third party for training purposes.

Use of data within the Claude and ChatGPT hosts themselves is, however, governed by the policies of Anthropic and OpenAI respectively and is outside the Company's control. See Section 6.

The Company does not collect conversation data beyond what its tools need in order to run, and does not query or extract Claude's or ChatGPT's memory, chat history, conversation summaries, or files uploaded by the user.

8. Rights and Obligations of Data Subjects and Their Legal Representatives, and How to Exercise Them

A data subject may exercise the following rights against the Company at any time.

Request for access to personal information

Request for correction where there is an error or similar defect

Request for erasure

Request for suspension of processing

Disconnection of the connector or plugin integration (removing the connection from the Claude or ChatGPT host)

These rights may be exercised in writing, by e-mail, or by other means using the contact details of the Privacy Officer below, and the Company will take action without delay. Requests for access are received and handled at the same contact details, and a data subject may exercise these rights through a legal representative or a duly authorised agent.

The Company makes no automated decision that has a significant effect on a data subject's rights or obligations, so there is no decision subject to a request for refusal or explanation under Article 37-2 of the Personal Information Protection Act. Product matching results are recommendations responding to a user's request and do not determine any right or obligation of the user.

9. Procedure and Method for Destroying Personal Information

Where personal information becomes unnecessary — because its retention period has elapsed, the purpose of processing has been achieved, or for a similar reason — the Company destroys that personal information without delay.

Destruction procedure: personal information whose retention period has elapsed is deleted under the criteria in Section 3, and other personal information is destroyed with the approval of the Privacy Officer once grounds for destruction arise.

Destruction method: information in the form of electronic files is permanently deleted by a method that makes recovery and reproduction impossible, and paper documents are shredded or incinerated.

10. Measures to Ensure the Safety of Personal Information

The Company takes the following safeguards pursuant to Article 29 of the Personal Information Protection Act.

Administrative measures: establishing and implementing an internal management plan, and providing regular employee training

Technical measures: managing access privileges, installing an access control system, encrypting data in transit (HTTPS), and installing security programs

Physical measures: controlling access to the computer room, the data storage room, and similar facilities

11. Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof

The Company does not use cookies to identify or track users in this connector or plugin service. Service state (for example, restoring the selected product-pool region) is handled using a request identifier and server-side storage, and no cookies are stored in the user's browser. That state is a service setting and does not identify any particular individual.

The YouTube embedded player included in the results view uses YouTube's cookie-reduced domain (youtube-nocookie.com). Where a user plays a video in the embedded player, the resulting data processing is governed by YouTube's policies.

12. Privacy Officer

The Company designates a Privacy Officer as set out below, who takes overall responsibility for work relating to the processing of personal information and who handles complaints from data subjects and remedies for damage in connection with such processing.

Privacy Officer (CPO)

Telephone

E-mail

CTO

+82-2-2088-0868

cto@aisum.com

13. Changes to This Privacy Policy

This Privacy Policy applies from its effective date. Where there is any addition, deletion, or correction of its contents in accordance with laws or with Company policy, the Company will give notice through its announcements from 7 days before the change takes effect.

Where this Policy is changed, the Company will disclose the reason for and content of the change and will keep earlier versions available so that data subjects can compare the position before and after.

Date of announcement: 2026-07-28

Effective date: 2026-07-28