NOWORX · 조직을 위한 AI 에이전트 그룹웨어

Privacy Policy

Updated on June 13, 2026

1. Overview

Snake Steak Inc. ("Company") operates the NOWORX service ("Service", domain: noworx.app) and complies with the Personal Information Protection Act and other applicable privacy laws in Korea. This policy explains how we collect, use, retain, and protect personal information and describes the rights available to data subjects.

2. Purposes of Processing

Personal information is processed only for the purposes listed below. If a purpose changes, we will announce the change and take required steps, including obtaining additional consent where necessary.

1.Member management
Identify members, provide and improve member services
Confirm sign-up intent, process membership changes and withdrawals
Restrict access for violations, resolve disputes, handle complaints
2.Service delivery and AI automation
Provide core NOWORX functions (marketing, accounting, procurement, HR auto-processing, and human-approval workflows)
Integrate with external services (e-commerce platforms, payment gateways, tax authority systems, etc.)
Generate, store, and deliver AI-produced outputs
Process credit and subscription payments and settle charges
3.New service development, marketing, and advertising
Develop new features and improve existing ones
Compile usage statistics, serve and measure advertising effectiveness
Send promotional information and analyze usage frequency
4.Legal evidence
Retain records necessary to respond to disputes or lawful requests

3. Items Processed and Retention Periods

1.Membership

| Category | Timing | Data Items | Retention |

| :--- | :--- | :--- | :--- |

| Email sign-up | After e-mail verification | Name, e-mail, password, contact number | Deleted 30 days after withdrawal |

| SNS sign-up (Google, Apple) | After social login verification | Name, e-mail | Deleted 30 days after withdrawal |

2.Optional marketing consent

| Type | Items | Retention |

| :--- | :--- | :--- |

| Member marketing consent | Name, e-mail | Until consent is withdrawn or 30 days after withdrawal |

| Non-member (inquiry / application) | Name, e-mail, contact number | 3 years after consultation ends, or until consent withdrawal |

3.Information collected while using the Service

| Purpose | Type | Items | Retention |

| :--- | :--- | :--- | :--- |

| Billing | Credit / subscription purchase | Name, e-mail, masked card number or virtual account info | 5 years |

| Tax invoices | Settlement and tax receipts | Company name, name, contact, e-mail | 5 years |

| Refunds | Refund processing | Name, e-mail, contact, payment info | 5 years |

| Customer support (members) | Identity check and support | Company, name, e-mail or contact | 3 years |

| AI Service usage | NOWORX AI automation features | Input data (business documents, files, connected account credentials, etc.), outputs and metadata | Until membership withdrawal or vendor contract termination |

| External integrations | E-commerce, PG, tax authority, etc. | External service credentials (OAuth tokens, API keys) and related data provided by the user | Deleted upon disconnection or membership withdrawal |

| Customer support (non-members) | Identity check and support | Company, name, e-mail or contact | 3 years |

| Inquiries | Onboarding / integration / trial | Organization name, requester name, e-mail, contact | 3 years |

| Partnerships | Partnership or reseller requests | Organization name, requester name, e-mail, contact, website URL | 3 years |

4.Legal and internal retention

| Legal Basis | Data | Period |

| :--- | :--- | :--- |

| Act on Consumer Protection in Electronic Commerce | Contract and withdrawal records | 5 years |

| Same Act | Payment and supply records | 5 years |

| Same Act | Consumer complaints or disputes | 3 years |

| Same Act | Advertising and labeling records | 3 months |

| Communications Secrets Protection Act | Website access logs | 3 months |

| Personal Information Protection Act art.15(1)(5) | Data necessary to prevent fraudulent use | Deleted 30 days after withdrawal |

4. Children's Data

The Service is not intended for children (under 14 for Korean nationals, under 16 for foreign nationals). If we learn that we have collected data from a child, we will delete it and close the account. Please contact us at the address in Section 13 if you believe a child's data was collected.

5. Provision to Third Parties

We use personal information within the scope described in Section 2 and do not disclose it to third parties without consent. Exceptions:

1.When the data subject has provided explicit prior consent.
2.When required by law or when investigative agencies present a valid warrant or order (Criminal Procedure Act art.215, PIPA art.18(2)2).

Provision under legal requests follows this procedure: present warrant → verify scope → CPO review and approval → deliver the minimum required dataset.

Business data, documents, and AI-generated outputs are never used to train AI models or shared with third parties (including model providers) without explicit consent.

6. Domestic Processors

We outsource certain tasks under written agreements that prohibit processing for unauthorized purposes, mandate security controls, require supervision, and prohibit onward transfers.

| Scope | Processor | Purpose | Retention |

| :--- | :--- | :--- | :--- |

| Cloud infrastructure | Amazon Web Services Inc. | Hosting and cloud services | Until withdrawal or contract termination |

| Customer support | Channel Corporation (Channel Talk) | Customer support SaaS | Same as above |

| Payments | Toss Payments Co., Ltd. | Credit-card and account billing | Same as above |

| Payments | Stripe, Inc. | International card billing | Same as above |

7. Overseas SaaS Entrustment

Users who refuse overseas transfer may not be able to use the corresponding features. You may withdraw by deleting your account or contacting us via customer support.

| Data transferred | Destination | Recipient | Purpose | Retention |

| :--- | :--- | :--- | :--- | :--- |

| Business data, documents, and images entered when using NOWORX AI automation features | United States (real-time API transfer) | Anthropic, PBC (support@anthropic.com) | Generative AI (LLM) processing and automation features | Deleted immediately after processing; no data stored by Anthropic |

| Same | United States (real-time API transfer) | Google Cloud Platform (googlekrsupport@google.com) | AI and cloud infrastructure services | Deleted immediately after processing |

| Payment information (name, e-mail, card details, etc.) | United States (real-time at checkout) | Stripe, Inc. (privacy@stripe.com) | International card payment processing | Per Stripe's Privacy Policy |

8. Destruction

We delete personal data without delay once retention periods expire or the processing purpose is achieved. When other laws require longer retention, the data is moved to a separate database or storage area.

9. Rights of Data Subjects

Users may exercise the following rights by e-mail or customer support:

Request access, correction, deletion, or suspension of processing
Request corrections; we will stop using the data until complete and notify any third parties of corrections if data was shared
Withdraw consent or request deletion (some services may become unavailable; statutory data cannot always be deleted)
Withdraw membership inside the Service or via e-mail

10. Safeguards

Limit and train staff who have access to personal data
Maintain and enforce internal management plans
Encrypt personal data and passwords; apply file-level encryption for sensitive exports
Maintain security programs against hacking and malware; place systems in access-controlled environments
Control database access rights and use firewalls to block unauthorized connections
Log all access to personal-information systems and protect logs from tampering

11. Cookies and Similar Technologies

We use cookies to improve the Service and analyze usage. You may configure your browser to block or delete cookies; however, some sign-in features may not work without them.

Google Chrome: Settings > Privacy and security > Third-party cookies
Mozilla Firefox: Settings > Privacy & Security > Enhanced Tracking Protection (Strict)
Microsoft Edge: Settings > Privacy, search, and services > Tracking prevention

12. Additional Use Criteria

Without additional consent, further processing is allowed only when it is reasonably related to the original purpose, foreseeable from the context of collection, does not unfairly infringe the user's interests, and when safeguards such as pseudonymization or encryption are applied.

13. Data Protection Officer

| Role | Name | Contact |

| :--- | :--- | :--- |

| Data Protection Officer | Donghyun Lim | sales@quelsuite.com |

14. Remedies

Users may contact the following agencies for external remedies regarding privacy infringements:

KISA Privacy Infringement Center: 118 (privacy.kisa.or.kr)
Personal Information Dispute Mediation Committee: 1833-6972 (kopico.go.kr)
Supreme Prosecutors' Office Cyber Investigation Division: 1301 (spo.go.kr)
National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)

15. Changes

We will announce any additions, deletions, or amendments to this policy through our website and provide at least 30 days' advance notice when user rights are materially affected.

Effective date: 13 June 2026

Google User Data (Gmail Integration)

When you connect a Gmail account in the Mailbox feature, the Company processes Google user data via Google APIs as follows.

1.Scope of access: reading Gmail messages and changing their read state (gmail.modify), and your account email address (userinfo.email).
2.Purpose: displaying and managing the mail of the mailbox you connected. We do not use this data for any other purpose.
3.Storage and deletion: connected mail data is stored only within your workspace and is deleted when you disconnect (delete the mailbox).
4.Prohibitions: we do not sell Google user data to third parties, do not use it for advertising, and do not use it to train generalized AI/ML models.
5.Our use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.