AnserX
Terms of Service

Contents

  1. Article 1 (Purposes of Processing Personal Data)
  2. Article 2 (Categories of Personal Data Processed)
  3. Article 3 (Legal Bases for Processing)
  4. Article 4 (Retention and Use Period)
  5. Article 5 (Provision to Third Parties)
  6. Article 6 (Entrustment of Processing)
  7. Article 7 (Overseas Transfer of Personal Data)
  8. Article 8 (Rights of Data Subjects and How to Exercise Them)
  9. Article 9 (Special Provisions on Buyer Lead Information)
  10. Article 10 (Cookies and Other Automatic Collection Devices)
  11. Article 11 (Destruction of Personal Data)
  12. Article 12 (Measures to Ensure Security)
  13. Article 13 (Personal Data Protection Officer)
  14. Article 14 (Remedies for Infringement of Rights)
  15. Article 15 (Changes to this Privacy Policy)
  16. Addendum
  17. Company Information

Privacy Policy

Effective
1 August 2026
Last updated
12 August 2026
Version
v1.1

This is a draft. This document is an internal draft that has not been through legal review, and it is not yet in force. It will be published on its effective date once reviewed and finalised.

This is a reference translation. The Korean original is the legally binding version. If the two differ in meaning, the Korean original prevails.Read the Korean original

AnserX (the "Company") establishes and discloses the following Privacy Policy in accordance with Article 30 of the Republic of Korea's Personal Information Protection Act (PIPA), in order to protect the personal data of data subjects and to handle related grievances promptly.

Article 1 (Purposes of Processing Personal Data)

The Company processes personal data for the following purposes, and will obtain consent in advance if a purpose changes.

  1. Membership registration and management: identity verification, confirmation of intent to join, review and approval of Buyer members, prevention of misuse, handling of grievances
  2. Service provision: operating the digital exhibition (profile cards), proposing buyer matches, sending outreach and managing its performance, delivering inquiries, ingredient regulatory screening
  3. Service improvement and statistics: improving service quality through analysis of usage records
  4. Notices and announcements: notifying changes to the terms and material service matters (marketing messages are sent only with separate consent)

Article 2 (Categories of Personal Data Processed)

CategoryItemsMethod of collection
Brand member (required)Email, name, company name, passwordEntered by the user at sign-up
Brand member (optional)Contact number, target markets and channels, and other onboarding informationEntered by the user during onboarding
Buyer member (required)Email, name, company name, country, product categories handled, passwordEntered by the user at sign-up
Buyer leadCompany name, contact person's name, email, country, items handled, and other business contact informationCollected by the Company through lawful channels such as public sources (see Article 9)
Non-member inquiry (required)Name, company name, email, inquiry contentEntered in the website inquiry form (with consent)
Automatically collectedIP address, browser and device information, cookies, service usage recordsGenerated automatically in the course of using the Service
Outreach relatedRecords of email sending, delivery, opening, replies and opt-outsGenerated automatically in the course of sending outreach

The Company does not collect sensitive data or unique identifiers, such as data on beliefs, health or sex life.

The full ingredient list (INCI) entered by a Brand is not personal data. It is treated as that Brand's trade secret, and its protection follows Article 9 of the Terms of Service.

Article 3 (Legal Bases for Processing)

  1. Members' personal data: the data subject's consent and performance of a contract (PIPA Article 15(1)(1) and (4)).
  2. Non-member inquirers' personal data: the data subject's consent (PIPA Article 15(1)(1); GDPR Art. 6(1)(a)). Consent may be refused, in which case the inquiry cannot be accepted.
  3. Business contact information of buyer leads: the legitimate interests of the Company and Brands (PIPA Article 15(1)(6)). The Company keeps that information limited to the scope related to business activity rather than private life, and minimises the scope of collection so that it does not override the rights of the data subject.

Article 4 (Retention and Use Period)

  1. As a rule the Company destroys personal data without delay once the purpose of processing has been achieved.
  2. Specific retention periods are as follows.
ItemRetention period
Member informationUntil withdrawal of membership
Records of misuse1 year after withdrawal
Non-member inquiry records1 year after the inquiry is resolved
Opt-out recordsIndefinite (only the email address is kept, as the minimum needed to block re-sending)
Records on contracts or withdrawal of subscription5 years (Act on Consumer Protection in Electronic Commerce)
Records on payment and supply of goods5 years (Act on Consumer Protection in Electronic Commerce)
Records on consumer complaints or dispute handling3 years (Act on Consumer Protection in Electronic Commerce)
Service usage records (access logs, IP and so on)3 months (Protection of Communications Secrets Act)

Article 5 (Provision to Third Parties)

  1. The Company processes personal data only within the purposes set out in Article 1, and provides it to third parties only with the data subject's consent or where specifically provided by law.
  2. In the following cases information is transmitted by the nature of the Service.
    • When a Buyer member sends an inquiry to a Brand: the inquiry content is delivered to that Brand together with the buyer's name, company name and email. This is inherent in the act of making an inquiry, and is explained at the point of sending.
    • When a Brand sends outreach: the recipient's reply is delivered to the Brand through the reply address.

Article 6 (Entrustment of Processing)

To provide the Service smoothly, the Company entrusts personal data processing as follows.

ProcessorEntrusted workRetention and use period
Supabase Inc.Operating cloud infrastructure such as database, authentication and file storageUntil the end of the entrustment contract or withdrawal of membership
Resend Inc.Sending email and processing delivery resultsUntil the end of the entrustment contract

The Company specifies matters concerning safe management of personal data in the entrustment contract and supervises the processor's compliance. Any change of processor or entrusted work will be disclosed through this Policy.

Article 7 (Overseas Transfer of Personal Data)

The processors in Article 6 keep servers outside Korea, so personal data is transferred overseas when the Service is used.

RecipientCountryItems transferredTime and method of transferPurposeRetention period
Supabase Inc.United StatesMember information and automatically collected information under Article 2Transmitted over the network at the time of service useOperating cloud infrastructureUntil the end of the entrustment contract or withdrawal of membership
Resend Inc.United StatesRecipient email address, message contentTransmitted over the network at the time of sendingSending email and processing resultsUntil the end of the entrustment contract

A data subject may refuse the overseas transfer. However, the transfer is essential to providing the Service, so refusal may restrict use of the Service.

Article 8 (Rights of Data Subjects and How to Exercise Them)

  1. A data subject may exercise the following rights against the Company at any time.
    • Request access to personal data
    • Request correction where there is an error
    • Request deletion
    • Request suspension of processing
  2. Rights may be exercised through the settings menu in the Service or through the contact in Article 13, and the Company will act without delay (within 10 days of receiving the request).
  3. Where a data subject has requested access, correction, deletion or suspension of processing, the Company will not use or provide the personal data concerned until the action is complete.
  4. Rights may also be exercised through a legal representative or an authorised agent.

Article 9 (Special Provisions on Buyer Lead Information)

By the nature of the Service, the Company holds business contact information for potential buyers who have not joined. In relation to that information the Company guarantees the following.

  1. Minimised collection: limited to information related to business activity (company name, contact person's name, business email, country, items handled). Information belonging to private life is not collected.
  2. Source management: the Company records and manages the collection source and legal basis for each record, and on request will tell a data subject where their information was collected from.
  3. Right to opt out: an outreach recipient may opt out at any time through the opt-out link in the email. Opt-out takes effect immediately and requires no separate confirmation step. The system blocks any Brand from sending outreach to an address that has opted out.
  4. Right to request deletion: a data subject may request deletion of their lead information, and the Company will delete it without delay. To prevent re-sending, only the email address remains on the opt-out list. That is the minimum retention, kept in the data subject's own interest.

Article 10 (Cookies and Other Automatic Collection Devices)

  1. The Company uses cookies to maintain login sessions.
  2. A data subject may refuse cookie storage through browser settings, in which case using services that require login may be difficult.

Article 11 (Destruction of Personal Data)

  1. The Company destroys personal data without delay once the retention period has passed or the purpose of processing has been achieved.
  2. Information in electronic file form is permanently deleted by a method that makes recovery impossible, and printed material is shredded or incinerated.
  3. Information that must be retained under the law is stored separately.

Article 12 (Measures to Ensure Security)

The Company takes the following measures.

  1. Access control: row level security (RLS) is applied at the database level so that a Brand can access only its own data. The server determines the authorisation of every request.
  2. Password protection: passwords are stored encrypted in a form that cannot be decrypted, with a safety standard of at least 10 characters.
  3. Encryption in transit: all communication takes place over an encrypted channel (HTTPS).
  4. File protection: uploaded brochures, videos and similar files are kept in private storage and provided only through expiring links to users whose authorisation has been confirmed.
  5. Access privilege management: authority to process personal data is limited to the minimum number of people needed for the work.

Article 13 (Personal Data Protection Officer)

The Company designates a personal data protection officer who has overall responsibility for personal data processing and handles grievances and remedies for data subjects.

ItemDetail
Personal data protection officerJeong Geon (CTO)
Contactadmin@anserx.co.kr

A data subject may direct any privacy-related inquiry arising from use of the Service to the contact above, and the Company will respond without delay.

Article 14 (Remedies for Infringement of Rights)

To obtain a remedy for infringement of personal data rights, a data subject may apply for dispute resolution or counselling to the following bodies.

BodyContact
Personal Information Dispute Mediation Committee+82-1833-6972 (www.kopico.go.kr)
Privacy Infringement Report Centre+82-118 (privacy.kisa.or.kr)
Cybercrime Investigation Division, Supreme Prosecutors' Office+82-1301 (www.spo.go.kr)
National Office of Investigation, Korean National Police Agency+82-182 (ecrm.police.go.kr)

Article 15 (Changes to this Privacy Policy)

Where there is an addition, deletion or amendment to this Policy, notice is given within the Service from 7 days before the effective date. Where there is a material change to the rights of data subjects, notice is given 30 days in advance.

Addendum

This Privacy Policy takes effect on 1 August 2026.

Company Information

ItemDetail
Company nameAnserX
RepresentativeKim Jinhyun
AddressRoom 216, Samuiwon Startup Center, Kyung Hee University Campus Town, 26 Kyungheedae-ro, Dongdaemun-gu, Seoul, Republic of Korea
Business registration number187-06-03456
Contactadmin@anserx.co.kr
AnserX대표 김진현사업자등록번호 187-06-03456서울특별시 동대문구 경희대로 26 경희대학교 캠퍼스타운 삼의원창업센터 216호admin@anserx.co.kr
© 2026 AnserX
Terms of ServicePrivacy Policy