NOWORX · 조직을 위한 AI 에이전트 그룹웨어

Privacy Policy

Updated on June 13, 2026
Published and sold by Paprika US, Inc. · 131 Continental Dr, Suite 305, Newark, DE 19713, US · CEO Jaehoon Jeung
Developed by Snake Steak Inc. · 11F Trutec Tower, 12 World Cup buk-ro 56-gil, Mapo-gu, Seoul, Korea · Business Reg. No. 666-81-02807
Contact meshedwell@pprk.xyz

1. Overview

Snake Steak Inc. ("Company") operates the NOWORX service ("Service", domain: noworx.app) and complies with the Personal Information Protection Act and other applicable privacy laws in Korea. This policy explains how we collect, use, retain, and protect personal information and describes the rights available to data subjects.

2. Purposes of Processing

Personal information is processed only for the purposes listed below. If a purpose changes, we will announce the change and take required steps, including obtaining additional consent where necessary.

1.Member management
Identify members, provide and improve member services
Confirm sign-up intent, process membership changes and withdrawals
Restrict access for violations, resolve disputes, handle complaints
2.Service delivery and AI automation
Provide core NOWORX functions (marketing, accounting, procurement, HR auto-processing, and human-approval workflows)
Integrate with external services (e-commerce platforms, payment gateways, tax authority systems, etc.)
Generate, store, and deliver AI-produced outputs
Process credit and subscription payments and settle charges
3.New service development, marketing, and advertising
Develop new features and improve existing ones
Compile usage statistics, serve and measure advertising effectiveness
Send promotional information and analyze usage frequency
4.Legal evidence
Retain records necessary to respond to disputes or lawful requests

3. Items Processed and Retention Periods

1.Membership
CategoryTimingData ItemsRetention
Email sign-upAfter e-mail verificationName, e-mail, password, contact numberDeleted 30 days after withdrawal
SNS sign-up (Google, Apple)After social login verificationName, e-mailDeleted 30 days after withdrawal
2.Optional marketing consent
TypeItemsRetention
Member marketing consentName, e-mailUntil consent is withdrawn or 30 days after withdrawal
Non-member (inquiry / application)Name, e-mail, contact number3 years after consultation ends, or until consent withdrawal
3.Information collected while using the Service
PurposeTypeItemsRetention
BillingCredit / subscription purchaseName, e-mail, masked card number or virtual account info5 years
Tax invoicesSettlement and tax receiptsCompany name, name, contact, e-mail5 years
RefundsRefund processingName, e-mail, contact, payment info5 years
Customer support (members)Identity check and supportCompany, name, e-mail or contact3 years
AI Service usageNOWORX AI automation featuresInput data (business documents, files, connected account credentials, etc.), outputs and metadataUntil membership withdrawal or vendor contract termination
External integrationsE-commerce, PG, tax authority, etc.External service credentials (OAuth tokens, API keys) and related data provided by the userDeleted upon disconnection or membership withdrawal
Customer support (non-members)Identity check and supportCompany, name, e-mail or contact3 years
InquiriesOnboarding / integration / trialOrganization name, requester name, e-mail, contact3 years
PartnershipsPartnership or reseller requestsOrganization name, requester name, e-mail, contact, website URL3 years
4.Legal and internal retention
Legal BasisDataPeriod
Act on Consumer Protection in Electronic CommerceContract and withdrawal records5 years
Same ActPayment and supply records5 years
Same ActConsumer complaints or disputes3 years
Same ActAdvertising and labeling records3 months
Communications Secrets Protection ActWebsite access logs3 months
Personal Information Protection Act art.15(1)(5)Data necessary to prevent fraudulent useDeleted 30 days after withdrawal

4. Children's Data

The Service is not intended for children (under 14 for Korean nationals, under 16 for foreign nationals). If we learn that we have collected data from a child, we will delete it and close the account. Please contact us at the address in Section 13 if you believe a child's data was collected.

5. Provision to Third Parties

We use personal information within the scope described in Section 2 and do not disclose it to third parties without consent. Exceptions:

1.When the data subject has provided explicit prior consent.
2.When required by law or when investigative agencies present a valid warrant or order (Criminal Procedure Act art.215, PIPA art.18(2)2).

Provision under legal requests follows this procedure: present warrant → verify scope → CPO review and approval → deliver the minimum required dataset.

Business data, documents, and AI-generated outputs are never used to train AI models or shared with third parties (including model providers) without explicit consent.

6. Domestic Processors

We outsource certain tasks under written agreements that prohibit processing for unauthorized purposes, mandate security controls, require supervision, and prohibit onward transfers.

ScopeProcessorPurposeRetention
Cloud infrastructureAmazon Web Services Inc.Hosting and cloud servicesUntil withdrawal or contract termination
Customer supportChannel Corporation (Channel Talk)Customer support SaaSSame as above
PaymentsStripe, Inc.Card billingSame as above

7. Overseas SaaS Entrustment

Users who refuse overseas transfer may not be able to use the corresponding features. You may withdraw by deleting your account or contacting us via customer support.

Data transferredDestinationRecipientPurposeRetention
Business data, documents, and images entered when using NOWORX AI automation featuresUnited States (real-time API transfer)Anthropic, PBC (support@anthropic.com)Generative AI (LLM) processing and automation featuresDeleted immediately after processing; no data stored by Anthropic
SameUnited States (real-time API transfer)Google Cloud Platform (googlekrsupport@google.com)AI and cloud infrastructure servicesDeleted immediately after processing
Payment information (name, e-mail, card details, etc.)United States (real-time at checkout)Stripe, Inc. (privacy@stripe.com)International card payment processingPer Stripe's Privacy Policy

8. Destruction

We delete personal data without delay once retention periods expire or the processing purpose is achieved. When other laws require longer retention, the data is moved to a separate database or storage area.

9. Rights of Data Subjects

Users may exercise the following rights by e-mail or customer support:

Request access, correction, deletion, or suspension of processing
Request corrections; we will stop using the data until complete and notify any third parties of corrections if data was shared
Withdraw consent or request deletion (some services may become unavailable; statutory data cannot always be deleted)
Withdraw membership inside the Service or via e-mail

10. Safeguards

Limit and train staff who have access to personal data
Maintain and enforce internal management plans
Encrypt personal data and passwords; apply file-level encryption for sensitive exports
Maintain security programs against hacking and malware; place systems in access-controlled environments
Control database access rights and use firewalls to block unauthorized connections
Log all access to personal-information systems and protect logs from tampering

11. Cookies and Similar Technologies

We use cookies to improve the Service and analyze usage. You may configure your browser to block or delete cookies; however, some sign-in features may not work without them.

Google Chrome: Settings > Privacy and security > Third-party cookies
Mozilla Firefox: Settings > Privacy & Security > Enhanced Tracking Protection (Strict)
Microsoft Edge: Settings > Privacy, search, and services > Tracking prevention

12. Additional Use Criteria

Without additional consent, further processing is allowed only when it is reasonably related to the original purpose, foreseeable from the context of collection, does not unfairly infringe the user's interests, and when safeguards such as pseudonymization or encryption are applied.

13. Data Protection Officer

RoleNameContact
Data Protection OfficerDonghyun Limmeshedwell@pprk.xyz

14. Remedies

Users may contact the following agencies for external remedies regarding privacy infringements:

KISA Privacy Infringement Center: 118 (privacy.kisa.or.kr)
Personal Information Dispute Mediation Committee: 1833-6972 (kopico.go.kr)
Supreme Prosecutors' Office Cyber Investigation Division: 1301 (spo.go.kr)
National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)

15. Changes

We will announce any additions, deletions, or amendments to this policy through our website and provide at least 30 days' advance notice when user rights are materially affected.

Effective date: 13 June 2026

Google User Data (Gmail Integration)

When you connect a Gmail account in the Mailbox feature, the Company processes Google user data via Google APIs as follows.

1.Scope of access: reading Gmail messages and changing their read state (gmail.modify), and your account email address (userinfo.email).
2.Purpose: displaying and managing the mail of the mailbox you connected. We do not use this data for any other purpose.
3.Storage and deletion: connected mail data is stored only within your workspace and is deleted when you disconnect (delete the mailbox).
4.Prohibitions: we do not sell Google user data to third parties, do not use it for advertising, and do not use it to train generalized AI/ML models.
5.Our use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.