AI Service Operational Policy
Effective Date: July 3, 2026
This operational policy (hereinafter referred to as "this policy") aims to define the rights, obligations, scope of responsibility, and legal compliance matters between the corporate clients (hereinafter referred to as "clients") and the company in relation to the AI-based solutions (PolyBot, PolyGlot, and all other AI SaaS provided hereinafter, collectively referred to as "AI services") supplied by 주식회사 Software Creation Studio (hereinafter referred to as "the company").
Article 1 (Data Governance and Confidentiality)
The company prioritizes the intellectual property rights and data security of its clients and complies with relevant laws.
1. Data Ownership
All intellectual property rights related to the prompts, source codes, databases, documents, etc. (hereinafter referred to as "input data") provided by the client to the AI service and the resulting outputs generated by the AI system (hereinafter referred to as "output data") shall, in principle, belong to the client.
2. Prohibition of Relearning Utilization
The company does not use any data input by clients for further enhancement of AI models, weight adjustments, or re-learning data. However, completely anonymized and aggregated statistical information that cannot identify individuals or clients (e.g., average response time, error rate, token usage, etc.) does not constitute re-learning data and may be used solely for the purpose of improving service operations.
Data stored will apply industry-standard encryption technologies such as AES-256, and transmission intervals will utilize TLS-based encryption. Additionally, after the purpose of service provision is fulfilled, data will be securely deleted or anonymized in accordance with relevant laws and internal data retention policies.
(※ Relevant laws: Personal Information Protection Act Article 21 (Destruction of Personal Information))
3. Real-time anonymization of domestic and international personally identifiable information (PII) and compliance with global regulations
In the process of handling AI services, if personal information and unique identification information under the Personal Information Protection Act of Korea, as well as personally identifiable information (PII) defined by laws and standards of various countries, are detected, the company will process them through applicable technical protective measures for anonymization (masking) before delivering them to the language model.
This includes the PII regulations under U.S. federal government and NIST guidelines, as well as the definition of personal data under the European GDPR, and applies technical and managerial protective measures to reduce the risk of global regulatory violations for the client.
Specific technical specifications applicable to PII anonymization (detection methods, masking scope, processing flow, etc.) will be provided in a separate technical document upon the client's request.
(※ Relevant regulations: Personal Information Protection Act of South Korea Article 29, US NIST SP 800-122 (PII Protection Guidelines), European GDPR Article 4(1) (Definition of personal data))
4. Thorough Isolation of PolyBot Sessions and Conversation Memory
When providing the AI chatbot solution (PolyBot), each conversation session and the context memory used by the client are loaded and processed in logically isolated independent areas within a multi-tenancy environment.
To prevent memory confusion or data interference with other clients or sessions, logical isolation, access control, and other technical and managerial protective measures will be applied, and any retained real-time memory data will be securely deleted or anonymized in accordance with relevant laws and internal data retention policies upon termination of the conversation session or contract.
5. Recommendations for sensitive information control and filtering
Despite the company's real-time anonymization (masking) and memory isolation measures, clients must fulfill their own management and oversight obligations to ensure that their authenticated users do not excessively input corporate secrets, undisclosed financial data, or third-party trade secrets.
6. Notice Regarding Third-Party AI Model Providers
The company may utilize third-party AI model providers (hereinafter referred to as 'AI Sub-processors')' language models or APIs to provide AI services. In this case, the company secures prohibitions on the re-learning use of client data, data security, and confidentiality obligations through contracts with AI Sub-processors, and will notify clients in writing in advance of any changes to the AI Sub-processors.
Article 2 (Technical Limitations and Disclaimer)
This AI service is based on generative language models and machine learning algorithms, and therefore has the following technical limitations.
1. Disclaimer of Accuracy of Output Information (Hallucination)
Due to the nature of AI technology, output data may contain some inaccurate or biased information, or hallucinations that differ from facts (hereinafter referred to as "hallucinations").
This service is a solution for business assistance and reference, and the company does not guarantee the completeness and commercial suitability of the output data.
2. Responsibility for Final Decision-Making
All responsibilities for final decisions and business actions made by the client based on output data derived from AI services lie with the client.
(※ Relevant laws: Commercial Act Article 399 (Company's Liability for Damages) and Article 401-2 regarding business judgment application)
3. Exemption from Third-Party Rights Infringement
The company applies reasonable technical measures to ensure that the output data of the AI system does not infringe on third-party patent rights, copyrights, trademarks, etc.
However, due to the nature of generative AI, the company does not guarantee the accuracy, completeness, or non-infringement of third-party rights of all results.
In particular, the company shall not be liable for disputes arising from the illegality or infringement of rights of the input data provided by the client, and shall be exempt from liability unless there is intent or gross negligence on the part of the company.
Article 3 (Acceptable Use Policy and Infrastructure Protection)
The client must not use the AI service in a manner that undermines the stability of the company's system or violates laws.
1. Prohibition of system circumvention and reverse engineering
The acts of prompt injection, jailbreak attempts, and reverse engineering to disable the AI safety filtering system set by the company are prohibited.
(※ Relevant laws: Article 2 (Definitions) of the Act on Unfair Competition Prevention and Trade Secret Protection)
2. Prohibition of Infrastructure Overload Activities
When using API integration and PolyBot, it is prohibited to cause significant load on the company's AI infrastructure and server operating environment using automated crawlers or scripts that have not been agreed upon in advance.
(※ Relevant laws: Article 48 of the Act on Promotion of Information and Communications Network Utilization and Information Protection (Prohibition of Information and Communications Network Infringement))
3. Prohibition of generating illegal or harmful content
The use of the solution for illegal activities such as creating works that defame others, inducing infringement of third-party intellectual property rights, developing malware, and generating scripts for fraud and phishing purposes is prohibited.
4. Procedures for Action in Case of Violation
If the company becomes aware of violations of this article, it will take action according to the following step-by-step procedure.
- (1) Correction Notice: The company will notify the client in writing (including email) of the violation and the required corrective actions.
- (2) Correction Period: Clients must rectify the violation within 14 business days from the date of receiving the correction notice.
- (3) Service Use Restrictions: If the client does not rectify the violations within the correction period, the company may restrict the use of all or part of the AI services.
- (4) Termination of License Agreement: If the violation persists even after service usage restrictions, the company may terminate the license agreement.
However, if a violation of the provisions of this article poses an urgent and significant threat to the security of the company's infrastructure, the company may immediately restrict or block service use without granting a correction period as per the above procedures and will notify the client without delay thereafter.
Article 4 (Global AI Transparency and Responsible Use)
The company strives to operate responsible AI services by considering international AI regulatory trends and related standards to support clients engaged in global business, such as PolyGlot and PolyBot.
1. Ensuring AI System Transparency
When the client integrates solutions such as PolyBot into their customer-facing services (e.g., B2C chatbots), they must clearly inform end users that the service is operated by an AI system.
(※ Relevant laws: EU AI Act Article 52 (Transparency obligations for specific AI systems))
2. Response to Automated Decisions
If the end user of the client refuses AI-based consultation and requests interaction with a human consultant (Opt-out), the client must provide alternative procedures to handle this.
The company supports the necessary APIs and technical environment for this purpose. The basic API provision for the opt-out feature is supported at no additional cost, while costs incurred for customer operations, such as assigning human consultants, will be borne by the client. Any additional technical customization required will be subject to a separate agreement between the two parties.
(※ Relevant laws: Personal Information Protection Act Article 37, European GDPR Article 22)
3. Compliance with General AI Model (GPAI) Regulations
The company continuously monitors and responds to applicable global AI regulatory requirements, including regulations regarding General-Purpose AI Models (GPAI) under the EU AI Act. When utilizing third-party AI models, the company will reasonably verify whether the model provider is fulfilling relevant regulatory obligations and strives to provide necessary transparency information to the client.
Article 5 (Service Availability and Maintenance)
The company makes commercially reasonable technical and managerial efforts to provide stable and continuous AI services.
In cases that fall under any of the following reasons, all or part of the service may be temporarily restricted or suspended.
- In cases where system checks, maintenance, functional improvements, or security updates are needed
- In the event of natural disasters, power outages, communication failures, or other reasons beyond the reasonable control of the company, such as upstream provider and cloud service failures
- In cases where urgent security responses or unavoidable measures are needed to ensure service stability
- In the event of service restrictions due to relevant laws or government agency orders
If a separate Service Level Agreement (SLA) is established, that agreement shall take precedence.
Article 6 (Relationship with Other Policies)
This policy applies in conjunction with the company's Terms of Service, Privacy Policy, Cookie Policy, and AI Ethics Policy.
In case of conflicting content between this policy and other policies, the following criteria will be applied to determine priority.
- Matters regarding the collection, use, storage, and transfer of personal information: Privacy Policy takes precedence
- Matters regarding the use of cookies and similar technologies: Cookie Policy takes precedence
- Matters related to service use, contracts, responsibilities, and disclaimers: Terms of Use take precedence
- AI service operational principles, data processing, and acceptable use policy: This policy takes precedence
- AI ethical principles and responsible AI operation direction: Refer to the AI Ethics Policy
Article 7 (Changes to Policy and Notice)
In the event of changes to this policy, the company will announce the reasons for the changes, the content of the changes, and the effective date at least 30 days prior to the effective date on the website and within the service. However, in cases of urgent reasons such as mandatory changes due to legal amendments, notice may be given at least 7 days prior to the effective date.
Previous versions of the policy will be retained for review on the website.
If the client does not agree to the changed policy, they may terminate the service agreement, and continued use of the service after the effective date of the changed policy will be considered as acceptance of the changed policy.
Supplementary Provisions
This operational policy will take effect from July 3, 2026.