This English version is provided for convenience. In case of any discrepancy, the Korean version prevails.
VeriBrain Inc. (the "Company") establishes and discloses this Privacy Policy under Article 30 of the Korean Personal Information Protection Act ("PIPA") to protect the personal information of data subjects and to handle related complaints promptly and smoothly.
Article 1. Purposes of processing personal information
The Company processes personal information for the following purposes. Personal information will not be used for any other purpose. If a purpose changes, the Company will take the necessary steps, such as obtaining separate consent under Article 18 of PIPA.
Receiving and answering website inquiries The Company receives inquiries sent through the website inquiry form and replies to them.
Preventing misuse of the inquiry form The Company limits repeated inquiries sent from the same IP address or email address within a short time.
Blocking attacks with a web application firewall The Company inspects website request information to block attacks on the website and excessive requests.
Article 2. Personal information we process
The Company processes the following personal information.
Required items
- Name: receiving and answering website inquiries
- Organization: receiving and answering website inquiries
- Email: receiving and answering website inquiries; preventing misuse of the inquiry form
- Inquiry message: receiving and answering website inquiries
Optional items
- Phone number: receiving and answering website inquiries
Information recorded with an inquiry
- Inquiry number, time received, language, and whether consent to collection and use was given (stored in the inquiry email): receiving and answering website inquiries
Collection method
Website inquiry form
Items generated or collected automatically
- The IP address from which the inquiry form is sent: preventing misuse of the inquiry form
- The IP address and request information (including request headers) when the website is accessed: blocking attacks with a web application firewall
The email address sent with an inquiry is kept as entered in the Company's mailbox so that the Company can reply. For the request-count records used to prevent misuse, the IP address and email address are not stored as entered; only values converted with a secret key are stored.
The Company does not use cookies or analytics tools.
Article 3. Processing and retention periods
The Company processes and retains personal information within the retention period set by law or the period the data subject agreed to at the time of collection.
| Purpose | Retention period | Legal basis |
| Receiving and answering website inquiries (inquiry emails, including the information recorded with an inquiry) | Until the end of the month in which 3 years have passed since the last reply (for inquiries not replied to, since the inquiry was received) | Consent of the data subject |
| Preventing misuse of the inquiry form (IP address and email address converted with a secret key) | Used for up to 24 hours, then expires; expired records are deleted automatically by the system (deletion may take a few more days) | Legitimate interests (Article 15(1), item 6 of PIPA) |
| Blocking attacks with a web application firewall (IP address, request information) | Only a sample of some requests is kept, for up to 3 hours | Legitimate interests (Article 15(1), item 6 of PIPA) |
Article 4. Provision of personal information to third parties
The Company processes personal information only within the scope set out in Article 1 (Purposes of processing personal information). It provides personal information to third parties only in the cases allowed under Articles 17 and 18 of PIPA, such as with the data subject's consent or under a specific provision of law.
Article 5. Outsourcing of personal information processing
The Company outsources the following personal information processing to run its services smoothly.
| Processor | Outsourced work |
| Amazon Web Services Korea LLC | Website operation, receiving inquiry form submissions and sending them by email, storing converted data for misuse prevention, operating the web application firewall |
| NAVER Cloud Corp. | Receiving and storing inquiry emails through NAVER WORKS |
Under Article 26 of PIPA, the Company has a prohibition on processing personal information for purposes other than the outsourced work, technical and administrative safeguards, restrictions on re-outsourcing, management and supervision of the processors, and liability such as compensation for damages set out in the processors' terms of service and data processing addenda, and supervises whether the processors handle personal information securely.
If the outsourced work or a processor changes, the Company will disclose it without delay through this Privacy Policy.
Inquiries are processed and stored in the AWS Seoul Region and in NAVER WORKS in Korea. While the website is delivered, data may pass through content delivery network (CDN) servers located outside Korea.
Article 6. Destruction procedure and method
When personal information is no longer needed, for example because the retention period has passed or the purpose has been achieved, the Company destroys it without delay.
Inquiry emails At the start of each month, the Data Protection Officer deletes the inquiry emails whose retention period ended in the previous month from the Company mailbox and the mailbox they are automatically forwarded to, and empties the trash.
Misuse prevention records Records of IP addresses and email addresses converted with a secret key are used for up to 24 hours and then expire. Expired records are deleted automatically by the system without human approval (deletion may take a few more days).
Article 7. Rights of data subjects and legal representatives, and how to exercise them
Data subjects may at any time ask the Company to give access to, correct, delete, or stop processing their personal information, or to transfer it. Requests may be made in writing, by email, or by fax under Article 41(1) of the Enforcement Decree of PIPA, and the Company will act on them without delay. For children under 14, a legal representative may exercise these rights on the child's behalf.
How to exercise your rights
Article 8. Automatic collection devices
The Company does not use cookies that store and retrieve usage information, and does not install analytics tools.
Article 9. Security measures
The Company takes the following measures to keep personal information secure.
- Minimal collection: the inquiry form takes only the items needed for a reply and checks the length and format of each.
- Protection in transit: the website and the inquiry form are served only over encrypted connections (HTTPS).
- Access control: the inquiry system blocks unauthenticated direct calls and handles public inquiry requests only through the website delivery path (CloudFront), and inquiry emails can be sent only to an address designated by the Company.
- Minimal stored data: for misuse prevention, only values of the IP address and email address converted with a separately stored secret key are recorded; these records do not contain the original values.
- Minimal processing records: the execution records of the inquiry processing function keep only the inquiry number or request ID, the result and the processing time, and contain no name, contact details, inquiry message or IP address. Their retention period is set to 90 days, after which deletion is handled by the processor (AWS).
- Intrusion prevention: the Company operates a web application firewall that blocks known malicious IP addresses, known attack patterns and excessive requests.
- Administrative measures: the Company has set up and carries out an internal management plan and runs regular self-inspections, and only the Data Protection Officer reads inquiry emails.
- Physical measures: the Company has no server room of its own; personal information is processed and stored only in the processors' data centers, where entry is controlled.
Article 10. Data Protection Officer and complaint handling
The Company has designated a Data Protection Officer who is responsible for all personal information processing and for handling data subjects' complaints and remedies related to it.
Data Protection Officer
The Company has no separate complaint handling department. The Data Protection Officer handles complaints.
Remedies for infringement of data subject rights
To seek a remedy for an infringement of personal information rights, data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency (KISA), and other agencies. The phone numbers below can be dialed within Korea without an area code.
Changes to this Privacy Policy
This Privacy Policy applies from its effective date. If content is added, deleted, or corrected because of changes in law or policy, the Company will post a notice on the Privacy Policy screen of the website at least 7 days before the change takes effect.
Revision history
- October 11, 2026: first established
This Privacy Policy takes effect on October 11, 2026.