Privacy Policy
Effective Date: 10 August 2026 (previous: 1 June 2026)
CUBIG CORP. ("CUBIG", "the Company") protects personal information processed through its products and services, including SaaS applications and integrations with third-party platforms such as Slack, as well as related web, download, and support channels ("the Service"). Product-specific data handling, including on-premises products and integrated applications, is described in the dedicated sections below.
We comply with the Personal Information Protection Act and all other relevant laws.
This policy explains how CUBIG collects, uses, stores, transfers, and protects personal information, and how users ("data subjects") may exercise their rights.
Purpose of Processing Personal Information
CUBIG processes personal information only for the purposes below. If these purposes change, we will obtain additional consent in accordance with the law.
| Category | Purpose |
|---|---|
| Membership registration and account management | Confirm registration intent, verify identity, manage roles and permissions, and maintain account security (including notifications of unusual activity). |
| Service provision and maintenance | Issue and verify licences, provide technical support, send update and patch notifications, communicate outages or security alerts, and provide CUBIG products, SaaS applications, and integrated services. |
| Integrated application services | Provide AI assistant and related functionality through third-party platforms such as Slack, process user requests and content necessary to provide responses, maintain conversation or thread context, and prevent service abuse. |
| Enquiries and complaint handling | Respond to customer enquiries, provide notifications or announcements, and retain records for dispute resolution. |
| Payment and settlement (optional) | Process maintenance fees, billing, and tax invoices, primarily for B2B clients. |
| Security and access logs (minimum required) | Record administrator access logs, detect abnormal access, prevent abuse, and protect accounts and services. |
| Marketing (optional, with consent) | Send newsletters, seminar and event invitations, and information on new services to data subjects who have given marketing consent. |
Items of Personal Information Processed
CUBIG processes only the personal information necessary to provide the Service. CUBIG destroys personal information without delay once the processing purpose is achieved, unless retention is required by law or otherwise described in this Policy.
| Category | Items Collected / Used |
|---|---|
| Sign-up | [Required] Email (ID), encrypted password, organisation/role. [Optional] Name, company name, department/position, phone number. |
| Social sign-up | [Optional] Minimum information provided by the social login provider (email, profile, etc.). |
| Goods and services provision | Licence or serial number, administrator account, update history, and minimal access logs (IP, browser, OS). |
| Integrated applications (including Slack) | Slack user ID, Slack workspace ID, message content submitted to or processed by the Service, and files or attachments submitted to or processed by the Service. |
| Enquiries and complaints (incl. website form) | Company name, department, position/title, name, phone number, email, industry, and enquiry details. |
| Payment and settlement | Payment gateway or tax invoice data (contact name, business registration details, payment identifier). |
For usage metering and abuse prevention in integrated applications, CUBIG may generate and retain HMAC-based hashed identifiers. Plain-text user or workspace identifiers are not stored in the usage-counter database.
Retention and Deletion of Personal Information
Retention Period
Personal information is retained only for the period allowed by law or agreed to by the user ("data subject"). The main retention periods are:
- Website membership: until membership withdrawal.
- Goods or service provision: until delivery and settlement are complete. Usage records related to fraud prevention or disputes are retained for five years after withdrawal.
- Enquiries and complaints: retained for five years after termination or as required by law.
- Enquiry/consultation form submissions: retained until the purpose of the enquiry is achieved, then destroyed without delay.
- Marketing consent records: until consent is withdrawn or membership is closed.
- Payment and settlement: retained for five years after termination or as required by law.
- Slack and other integrated application content: masked content may be retained on CUBIG servers as necessary to provide the Service. Original content used for information restoration is retained only temporarily and is deleted after one hour of inactivity and, in all cases, no later than seven days after collection.
- Integrated application credentials and mappings: bot tokens, thread mappings, and retained original content associated with an installed application are deleted without delay when the application is uninstalled.
- Hashed usage counters: HMAC-based hashed usage counters may be retained after uninstallation solely to prevent reinstall-based abuse and enforce usage limits. These records contain no plain-text user or workspace identifiers.
Disposal Method
Personal information is destroyed once its purpose has been achieved or the retention period has expired.
- Electronic files: permanently deleted so they cannot be recovered.
- Paper records: shredded or incinerated.
- Partially retained items: stored separately until statutory retention periods expire, then destroyed.
Provision of Personal Information to Third Parties
CUBIG does not share personal information with third parties except when:
- The user ("data subject") has provided explicit consent.
- Required by law or a legitimate request from investigative authorities.
- For corporate accounts, limited data (such as account status or access history) is shared with the organisation's administrator. Use of serial licences constitutes consent within this scope.
Where an external AI service is used to provide an integrated application, CUBIG transmits only content that has been masked or pseudonymised before transmission. Original Slack messages, files, or other unmasked customer content are not transmitted to external AI model providers.
Outsourcing of Personal Information Processing
To provide services effectively, CUBIG may outsource certain tasks. We supervise contractors in line with the Personal Information Protection Act and include security obligations in each contract.
| Contractor | Task | Data Processed | Retention / Use Period |
|---|---|---|---|
| Naver Cloud Corp. (NCP) | SMS for registration and verification | Mobile number, authentication code, transmission logs | Until transmission is completed and logs expire (per contract or law). |
| Google LLC | Email transmission for enquiries | Email, name, enquiry content, access records | For the duration of transmission and storage per policy or law. |
| PayPal | International payment processing | Payment ID, transaction data, amount, masked card token, buyer email, device/IP | Until payment completion or termination of the entrusted contract. |
| HubSpot, Inc. | CRM system operation, storage and management of enquiry/lead data, marketing activities | Company name, department, position/title, name, phone number, email, industry, enquiry details | Until the purpose is achieved or consent is withdrawn. |
| Anthropic, PBC | External large language model processing for applicable AI assistant functionality | Masked or pseudonymised content necessary to process the request. Original unmasked Slack content is not transmitted. | Processed only as necessary to provide the AI functionality, subject to CUBIG's agreement with the provider and applicable law. |
Cross-Border Transfers
Some data may be transferred overseas as follows. Users ("data subjects") may refuse overseas transfer, though this may limit certain services (for example, receiving enquiry replies, processing payments, or using AI assistant functionality that relies on an external model provider).
| Recipient | Country | Transferred Items | Transfer Method and Timing | Purpose | Retention / Use Period |
|---|---|---|---|---|---|
| Google LLC | United States | Email address, name, enquiry content, transmission metadata | Real-time encrypted transfer upon enquiry submission | Support for email transmission and storage | Retained per company email policy or relevant laws. |
| PayPal | United States | Payment data and verification information | Real-time encrypted transfer upon payment authorisation | Payment settlement, fraud prevention, and support | Until payment completion or termination of the contract. |
| HubSpot, Inc. | United States | Company name, department, position/title, name, phone number, email, industry, enquiry details | Real-time transfer upon website form submission | Customer data storage, CRM operation, enquiry/lead management (and marketing where consent is given) | Until the purpose of the enquiry is achieved, then destroyed without delay. |
| Anthropic, PBC | United States | Masked or pseudonymised content necessary to process AI assistant requests | Real-time encrypted transfer when a user invokes functionality requiring external LLM processing | Generation of AI assistant responses | Processed and retained per CUBIG's agreement with the provider and applicable law. Original unmasked Slack content is not transferred. |
User ("Data Subject") Rights and How to Exercise Them
Users ("data subjects") may:
- Request to view, correct, or delete their personal information.
- Withdraw consent or close their account at any time. Marketing consent may be withdrawn at any time, after which the transmission of advertising information stops.
- Exercise these rights by written request, phone, or email to the Personal Information Protection Officer.
CUBIG will respond promptly. Certain identifiers necessary for system management cannot be modified. Users must ensure their information is accurate and up to date. Using another person's information or providing false data may result in account suspension or legal penalties.
Cookies and Automatic Collection
CUBIG uses cookies to remember user settings and provide customised services. Cookies are small text files stored on the user's device by the website server. They do not automatically collect personal information, and users may refuse or delete them at any time.
Purpose: To analyse visits, usage patterns, and search terms to improve the Service and deliver relevant content.
Refusal: Users can refuse or delete cookies and reset mobile advertising identifiers as described below. Blocking all cookies may limit functions that require login.
- Chrome: Settings > Privacy and security > Cookies and other site data.
- Safari: Settings > Privacy > Manage cookies and website data.
- Edge: Settings > Cookies and site permissions.
- Block third-party cookies: enable the "block third-party cookies" option in your browser.
- Reset mobile advertising identifier: iOS — Settings > Privacy & Security > Tracking; Android — Settings > Privacy > Ads > Reset advertising ID.
Personal Information Protection Officer
| Role | Name | Position | |
|---|---|---|---|
| Personal Information Protection Officer | Ha Heonseok | CPO | [email protected] |
Remedies and External Contacts
If you are dissatisfied with how your personal information has been handled, you may contact the following government agencies for mediation or advice:
| Agency | Website / Contact |
|---|---|
| Personal Information Infringement Reporting Centre | privacy.kisa.or.kr / (+82) 118 |
| Personal Information Dispute Mediation Committee | www.kopico.go.kr / (+82) 1833-6972 |
| Supreme Prosecutors' Office Cyber Investigation Division | www.spo.go.kr / (+82) 1301 |
| National Police Agency Cyber Safety Bureau | cyberbureau.police.go.kr / (+82) 182 |
Product-Specific Data Handling
11.1 On-Premises Products (including LLM Capsule)
- On-premises principle: Business data is processed and stored within the customer's infrastructure. CUBIG does not access this data by default.
- External integration: When external LLM integration is enabled, only encapsulated (pseudonymised or masked) data is transmitted. Original data is never shared.
- Remote support: Remote troubleshooting requires prior approval, session logging, and least-privilege access.
- Telemetry (optional): Minimal diagnostic data (error codes, version, status) may be transmitted with consent. Business data content is never included.
11.2 Slack Application and AI Assistant
- Data processed: the Service may process Slack user IDs, workspace IDs, message content, and files or attachments when necessary to respond to user requests and provide assistant functionality.
- Masking before external LLM processing: content is masked or pseudonymised by CUBIG before it is transmitted to an external LLM provider. Original unmasked Slack content is not transmitted to the external LLM provider.
- Original-content retention: original content required for information restoration is retained temporarily and deleted after one hour of inactivity and, in all cases, no later than seven days after collection.
- Stored service content: CUBIG retains only masked content on its servers for ongoing assistant functionality, except for the temporary original-content retention described above.
- Usage counters: usage counters use HMAC-based hashed identifiers. The usage-counter database does not store plain-text Slack user IDs or workspace IDs.
- Application uninstallation: when the Slack application is uninstalled, CUBIG deletes the associated bot token, thread mappings, and any retained original content without delay. HMAC-based usage counters may be retained solely to prevent abuse through repeated reinstallation.
- Credential security: Slack bot tokens retained by CUBIG are encrypted at rest using Fernet encryption.
- No AI model training: CUBIG does not use Slack messages, files, attachments, or other customer content to train AI or machine learning models.
- External model providers: only masked or pseudonymised content necessary to generate a response is transmitted to an external model provider. CUBIG does not transmit original unmasked Slack content for model processing.
Changes to This Policy
This Privacy Policy takes effect on 10 August 2026. Any future updates will be announced on the CUBIG website before they take effect.
- 10 August 2026: Expanded the scope of the Privacy Policy to cover SaaS and third-party platform integrations; added processing and retention provisions for the CUBIG Slack application and AI assistant; added Anthropic, PBC as an external processing provider and cross-border transfer recipient; clarified masking, temporary original-content retention, application-uninstallation deletion, credential encryption, and AI model-training restrictions; provided step-by-step guidance for refusing cookies and behavioural information.
- 1 June 2026: Added website enquiry-form collection items; added HubSpot, Inc. (United States) as a processor and cross-border transfer recipient; added marketing-consent provisions.
- 1 October 2025: Initial version.