Privacy Policy
[Dermacoa Co., Ltd.] (hereinafter "Company") values the personal information of members and users who use the OMNIGRID service (hereinafter "Service") and complies with the Personal Information Protection Act and other applicable laws and regulations.
This Privacy Policy is intended to inform users of how the Company collects, uses, stores, and destroys personal information on the OMNIGRID website and related services operated by the Company.
Article 1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes.
Personal information processed shall not be used for purposes other than those listed below. If the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with applicable laws and regulations.
1. Member Registration and Management
- Member identification and identity verification
- Confirmation of intent to register as a member
- Account creation and management
- Prevention of fraudulent use of the Service
- Handling member inquiries and delivering notices
2. Service Provision
- Provision of OMNIGRID features including AI image generation, text generation, blog post generation, prompt generation, and scenario generation
- Management of AI usage count
- Provision and storage of generated outputs
- Checking usage history per member
- Displaying service usage status and remaining usage
3. Paid Services and Payment Processing
- Payment for paid subscription products
- Recurring payment and subscription management
- Confirmation of payment history
- Processing refunds and withdrawal of subscription
- Verification of payment errors and duplicate payments
- Tax calculation, settlement, and accounting
4. Customer Support and Complaint Handling
- Receiving and responding to inquiries
- Confirming service errors
- Processing refund requests
- Responding to usage restrictions and disputes
- Sending notices and important announcements
5. Service Quality Improvement and Statistical Analysis
- Statistical analysis of service usage
- Analysis of usage by feature
- Analysis of errors and failures
- Service improvement and development of new features
- Internal review for improving AI generation quality
6. Fraud Prevention and Security Management
- Detection of abnormal access
- Prevention of account sharing and use of automated programs
- Prevention of service abuse
- Prevention and response to security incidents
7. Marketing and Advertising
- Announcements of new services
- Notifications of events and promotions
- Provision of benefit information
- Marketing information is only sent when the user has separately consented.
Article 2. Personal Information Items Processed
The Company collects the minimum personal information necessary to provide the Service.
1. Information Collected at Registration
- Name, email address, password, mobile phone number, member ID, date and time of registration, access IP, service usage records
Passwords are stored in encrypted form, and the Company cannot access a user's password in plain text.
2. Information Collected for Paid Service Payments
The Company may process the following information for payment processing.
- Payer information, payment product name, payment amount, payment date and time, payment status, subscription status, partial payment method information, payment approval number, refund processing records
Full card numbers, full account numbers, and other key payment method details are processed directly by the payment processor or simple payment provider.
The Company does not directly store such information.
3. Information Automatically Collected During Service Use
- Access IP address, cookies, browser information, device information, operating system information, access date and time, service usage records, AI usage count, chatbot usage records, usage by feature, error logs
4. Information Processed During AI Service Use
When users use AI features, the following information may be processed.
- Prompts entered by the user, uploaded images or files, entered text, generation request content, AI-generated outputs, generation date and time, chatbot or feature name used, AI model information used, AI usage deduction records
Users must not upload or enter third-party personal information, sensitive information, portraits, copyrighted works, trade secrets, or similar materials without authorization.
Article 3. Retention and Use Period of Personal Information
The Company processes and retains personal information within the retention and use period stipulated by law or agreed upon when collecting personal information from users.
1. Member Information
- Retention period: Until account deletion
- However, if retention is required by applicable law, the information will be retained for the relevant period.
2. Service Usage Records
- Retention period: Up to 3 years after account deletion
- Retention purpose: Responding to customer inquiries, fraud prevention, confirming service operation records, dispute resolution
3. AI Generation Request Records and Outputs
- Retention period: Until the purpose of service provision is achieved or upon member deletion request
- However, information may be retained for a certain period in cases of technical backup, fraud prevention, dispute resolution, or legal retention obligations.
4. Payment and Refund Records
The following records may be retained in accordance with the Act on the Consumer Protection in Electronic Commerce and other applicable laws.
- Records related to contracts or withdrawal of offers: 5 years
- Records related to payment and supply of goods: 5 years
- Records related to consumer complaints or dispute resolution: 3 years
- Records related to labeling and advertising: 6 months
- Communication confirmation data such as access logs: Period stipulated by applicable law
Article 4. Provision of Personal Information to Third Parties
The Company processes users' personal information only within the scope of the purposes set forth in Article 1 and does not, in principle, provide users' personal information to third parties.
However, personal information may be provided in the following cases.
- When the user has given prior consent
- When there are special provisions in the law
- When there is a lawful request from an investigative authority, court, or other relevant authority
- When provision to a related company is necessary within the scope required for service provision and payment processing
When the Company provides personal information to third parties, it will notify the recipient, purpose, items, and retention and use period in advance and obtain consent where required.
Article 5. Entrustment of Personal Information Processing
The Company may entrust personal information processing to external companies as follows for the smooth provision of services.
- FastSpring (Bright Market, LLC) Entrusted tasks: Payment processing, subscription management, invoicing, tax handling, refund processing Retention and use period: Until termination of entrustment agreement or end of legally required retention period
- Hostinger Entrusted tasks: Website hosting, server operation, email service Retention and use period: Until termination of entrustment agreement
- Google Cloud / Google AI Entrusted tasks: AI API integration, image and text generation, TTS and other feature provision Retention and use period: Until purpose of service provision is achieved or entrustment agreement is terminated
- OpenAI Entrusted tasks: AI API integration, image and text generation feature provision Retention and use period: Until purpose of service provision is achieved or entrustment agreement is terminated
- Make Entrusted tasks: Automation scenario processing, usage data transmission and integration Retention and use period: Until purpose of service provision is achieved or entrustment agreement is terminated
- Email delivery service or SMTP provider Entrusted tasks: Sending notices, authentication, and customer guidance emails Retention and use period: Until termination of entrustment agreement
The Company supervises and manages subcontractors to ensure that personal information is handled safely in accordance with relevant personal information protection laws when executing entrustment agreements.
If a subcontractor listed above is not actually in use, that entry may be removed from this Privacy Policy.
Article 6. International Transfer of Personal Information
The Company may use external AI APIs, cloud services, or automation service providers located overseas for the provision of the Service.
In this process, prompts entered by users, uploaded images, generation request content, and other data may be transferred overseas or processed on overseas servers.
- FastSpring / Bright Market, LLC (Transfer country: United States) Items transferred: Payment information, payer name, email address, billing address, subscription status, payment records Purpose of transfer: Payment processing, subscription management, invoicing, tax handling, refund processing Compliance basis: EU-U.S. Data Privacy Framework (DPF); FastSpring is GDPR-compliant and certified under the DPF program Retention and use period: Until termination of entrustment agreement or end of legally required retention period
- Google LLC (Transfer country: United States and other countries where Google operates) Items transferred: Prompts, uploaded images, generation request data, partial usage records Purpose of transfer: Provision of AI generation features, TTS feature provision, cloud processing Retention and use period: Until purpose of service provision is achieved or as per provider's policy
- OpenAI, L.L.C. (Transfer country: United States and other countries where OpenAI operates) Items transferred: Prompts, uploaded images, generation request data, partial usage records Purpose of transfer: Provision of AI image and text generation features Retention and use period: Until purpose of service provision is achieved or as per provider's policy
- Make / Celonis SE (Transfer country: Countries where the service operates) Items transferred: Email address, name, usage records, feature usage history Purpose of transfer: Automation processing, usage log management, spreadsheet integration Retention and use period: Until purpose of service provision is achieved or entrustment agreement is terminated
- Hostinger International / Related affiliates (Transfer country: Countries where the service operates) Items transferred: Account information, access records, website data Purpose of transfer: Website hosting and server operation Retention and use period: Until termination of entrustment agreement
When international transfer of personal information is required, the Company will provide information on the recipient, transfer country, items transferred, purpose of transfer, and retention and use period in accordance with applicable laws.
Users may refuse international transfer; however, in such cases, use of certain services that require external AI API or cloud integration may be restricted.
Article 7. Procedures and Methods for Destruction of Personal Information
The Company destroys personal information without delay when the retention period has expired or the purpose of processing has been achieved.
1. Destruction Procedure
- Users' personal information is moved to a separate database after the purpose is achieved, and is retained for a certain period in accordance with internal policies and applicable laws before being destroyed.
- Personal information that must be retained by law is kept separately for the period specified by the relevant law.
2. Destruction Method
- Personal information in electronic file form is deleted in a manner that makes recovery and regeneration impossible.
- Personal information printed on paper documents is destroyed by shredding or incineration.
- Due to the technical nature of backup data, immediate deletion may be difficult.
It is safely managed through separate access restrictions and destroyed at the end of the retention period.
Article 8. Rights of Data Subjects and Legal Representatives and How to Exercise Them
Users may exercise the following rights against the Company at any time.
- Request to access personal information, request to correct personal information, request to delete personal information, request to suspend processing of personal information, request to withdraw membership, withdrawal of consent to receive marketing information
Users may exercise their rights through the My Page section of the service, customer center, or email inquiry.
The Company will take action without delay upon receiving a user's request in accordance with applicable laws.
However, deletion may be restricted for information that must be retained by law.
Legal representatives of children under the age of 14 may request access, correction, deletion, and suspension of processing of the child's personal information.
Article 9. Processing of Personal Information of Children Under 14
The Company does not, in principle, provide services to children under the age of 14.
If the Company must collect personal information of children under 14, it will collect only the minimum necessary personal information after obtaining consent from a legal representative.
Legal representatives may request access, correction, deletion, and suspension of processing of the child's personal information.
Article 10. Installation, Operation, and Refusal of Automatic Data Collection Devices Such as Cookies
The Company may use cookies to provide better services to users.
1. Purpose of Using Cookies
- Maintaining login status, member authentication, providing service convenience, analyzing access frequency and usage statistics, security and fraud prevention, providing customized services
2. How to Refuse Cookie Settings
Users may refuse or delete cookie storage through browser settings.
- Chrome: Settings → Privacy and security → Cookies and other site data
- Safari: Settings → Privacy → Block Cookies
- Edge: Settings → Cookies and site permissions → Manage cookies and site data
However, if cookie storage is refused, login, payment, and some service functions may be restricted.
Article 12. Measures to Ensure the Safety of Personal Information
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures: Minimization of personal information handlers, establishment of internal management plans, regular security inspections, management of personal information access rights
- Technical measures: Encrypted storage of passwords, application of SSL secure communication, restriction of access rights, application of security programs, retention and inspection of access records, measures to prevent external intrusion
- Physical measures: Restriction of access to servers and data storage locations, management of storage and disposal of important data
Article 13. Protection of Personal Information When Using AI Services
Due to the nature of AI-based SaaS services, the Company may process prompts entered by users, uploaded images, generated outputs, and other data. Users must comply with the following.
- Do not enter third-party personal information without authorization.
- Do not enter unnecessary personal information such as resident registration numbers, account numbers, card numbers, health information, or sensitive information.
- Do not upload or use third-party faces, portraits, voices, names, or contact information in generation without authorization.
- The Company may review AI generation request records for the purposes of service operation, fraud prevention, customer support, and troubleshooting.
- The Company does not guarantee the accuracy, legality, or non-infringement of third-party rights of AI-generated outputs.
The Company endeavors to ensure that information entered by users and generated outputs are processed safely.
Article 14. Additional Use and Provision of Personal Information
The Company may additionally use or provide personal information without the user's consent within a scope reasonably related to the original collection purpose, as permitted by applicable laws. In such cases, the Company considers the following.
- Whether it is related to the original collection purpose
- Whether it is predictable in light of the circumstances in which the personal information was collected or processing practices
- Whether it does not unfairly infringe the user's interests
- Whether necessary measures to ensure safety such as pseudonymization or encryption have been taken
Article 15. Personal Information Protection Officer
The Company designates a Personal Information Protection Officer to oversee all tasks related to personal information processing and to handle users' complaints and provide relief for damages related to personal information processing.
- Personal Information Protection Officer
- Name: [Jun Heon Kim]
- Position: Representative
- Email: [sc35445682@gmail.com]
- Contact: [010-3544-5682]
For inquiries, complaints, and requests for relief regarding personal information, please contact us at the above.
Article 16. Request to Access Personal Information
Users may request access to personal information through the Personal Information Protection Officer or customer center. The Company endeavors to ensure that users' requests for access to personal information are processed promptly.
- Personal Information Access Request Contact
- Department: Operations Team
- Email: [sc35445682@gmail.com]
- Contact: [010-3544-5682]
Article 17. Methods to Remedy Rights Violations
Users may contact the following organizations for relief, consultation, and other matters related to personal information violations.
- Personal Information Infringement Report Center
- Personal Information Dispute Mediation Committee
- Cybercrime Investigation Division of the Supreme Prosecutors' Office
- Cybercrime Investigation Division of the National Police Agency
The above organizations are separate from the Company. Users may seek assistance from these organizations independently of the Company's own personal information complaint handling.
Article 18. Changes to the Privacy Policy
This Privacy Policy may be revised in accordance with changes to applicable laws, the Company's service policies, or the integration structure of external AI APIs and payment services. When the Company revises this Privacy Policy, it will announce the revised content and effective date through a notice on the website or service screen.
- Announcement date: May 8, 2026
- Effective date: May 8, 2026
Article 19. Business Information and Contact
Company Name: Dermacoa Co., Ltd.
CEO: Jun Heon Kim
Business Registration Number: 790-87-01762
Mail-order Business Report Number: No. 2025-Daegu Buk-gu-1091
Address: Room 312, 51 Hoam-ro, Buk-gu, Daegu (Samsung Creative Campus Venture Office)
Email: sc35445682@gmail.com
Operating Hours: Mon - Fri, 09:00 - 18:00 (KST)
For any inquiries regarding this Privacy Policy or Terms of Service, please contact us via the information above.
