BIMFactory Co., Ltd. ("Company") values the personal data of its users and establishes this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of Korea ("PIPA") and Articles 13–14 of the EU General Data Protection Regulation ("GDPR").
This Policy applies to the service "Forecast AI" operated by the Company (the "Service").
1. Controller and Contact
- Controller: BIMFactory Co., Ltd.
- Representative: Seo Hee-chang
- Business Registration No.: 261-86-03265
- Address: 3F–5F, S&C Tower, 223-1 Yulgok-ro, Jongno-gu, Seoul, Republic of Korea
- Email: forecast-ai@bimfactory.co.kr
- Website: https://forecastai.co.kr
2. Purposes of Processing and Legal Bases
The Company processes personal data for the following purposes and on the following legal bases (GDPR Art. 6).
| Purpose | Legal Basis |
|---|---|
| Account registration, identity verification, account management | Contract performance (Art. 6(1)(b)) |
| Provision of the Service (persona simulation, AI analysis, generated outputs) | Contract performance |
| Payment processing and refunds | Contract performance |
| Customer support and complaint handling | Contract performance |
| Creating, publishing and search-indexing partner store pages | Contract performance |
| Sharing partner-store inquiry conversations with the store Host (to respond to inquiries, correct inaccurate answers and update store information) | Contract performance |
| Providing the mobile app and managing in-app purchases and subscription status | Contract performance |
| Serving and measuring advertising within the mobile app | Legitimate interest (personalized ads can be turned off in device settings) |
| Service improvement and new feature development (aggregated usage analysis) | Legitimate interest (Art. 6(1)(f)) |
| Fraud prevention and security | Legitimate interest |
| Marketing, promotions, event notifications | Consent (Art. 6(1)(a)) |
| AI model training and quality improvement | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations (tax, e-commerce law) | Legal obligation (Art. 6(1)(c)) |
Processed data shall not be used for purposes other than those listed above without separate consent.
3. Categories of Personal Data Collected
3.1 Account and Authentication
- Required: email address, password (hashed), nickname, avatar URL
- Social login: OAuth identifier, name, email, profile picture (when using Google or Kakao)
3.2 Payment and Billing
- Individual: payment history (amount, product, timestamp, payment method), refund records
- B2B / Enterprise: contact name, email, phone, representative name, business registration number, company address
- Card details are collected and stored by the payment processor (Payple, Lemon Squeezy); the Company stores only payment identification tokens.
3.3 Service Usage
- Simulation records (persona, conversation content, turn count, timestamps)
- Inquiry conversations with partner-store personas (questions and answers, timestamps, the time the Host-viewing notice was acknowledged)
- AI-generated outputs (analysis reports, slide decks, scripts, next-simulation suggestions)
- User-created custom personas and scenarios
- User-uploaded files (documents and persona knowledge materials; audio/meeting recordings and their transcription/diarization results)
3.4 Automatically Collected Data
- IP address, browser and device information (User-Agent), access logs, service usage logs
- Cookies (login session, CSRF token, language preference)
- Google Analytics 4 identifiers (non-essential; can be disabled via browser settings)
- GA4 User-ID: a non-PII pseudonymous internal UUID of logged-in users, transmitted to enable cross-device and cross-session analytics (no email, name, or other directly identifying data is sent)
- Microsoft Clarity behavioral data: clicks, scrolls, and mouse movement for session replay and heatmaps (non-essential; text inputs are masked by default and not collected)
- Sentry error-tracking data (error message, stack trace, browser/OS, error URL)
3.5 Partner Store (Host) Information
To operate the pages of stores partnered with the Company, we collect the following information from store operators ("Hosts"). Where the Host is a sole proprietor, some of these items constitute personal data.
- Store details: trade name, short description, business category, road-name and lot-number address, geographic coordinates (latitude/longitude), phone number, opening hours
- Store content: menu and price listings, signature product lineup, store photos, store and operator introduction text, awards and recognitions, external links (Instagram, Naver Place, online store, etc.)
- Operator details: host (representative) name, linked member account
Public disclosure — This information is published on the store page (/store/{slug}) and indexed by search engines such as Google and Naver. To enable search visibility, the Company also provides the trade name, address, phone number and opening hours as structured data (schema.org LocalBusiness). Hosts may request correction of published items or unpublication of the store page at any time.
3.6 Mobile Application
When using the Company's mobile app (Android/iOS), the following data is additionally processed.
- Device and app data: operating system type and version, device model, app version, app error logs
- Advertising identifier: where ads are served in the app, the Android Advertising ID (AAID) or iOS Advertising Identifier (IDFA). Users may reset it or turn off personalized advertising in device settings (see Section 10.4).
- In-app purchase data: app store transaction identifier, subscription status. Payment credentials such as card numbers are handled by the app store and are not collected by the Company.
On iOS, App Tracking Transparency (ATT) consent is requested separately before accessing the advertising identifier. Declining does not restrict use of the app.
3.7 Collection Methods
- Direct input by the user during registration or use of the Service
- Transmitted via API from social login providers
- Automatically generated and logged during Service use
- For partner stores, provided directly by the Host or registered after the Host's confirmation
3.8 Children Under 14
The Company does not knowingly collect personal data from children under the age of 14 and does not permit such users to register. If the Company becomes aware that a user is under 14, the account will be suspended and related information will be deleted.
4. Retention Periods
4.1 Internal Retention Policy
| Item | Retention Period |
|---|---|
| Account information (email, nickname) | Destroyed 7 days after a deletion request |
| Simulation usage records | Destroyed together with the account information (data subject to legal retention kept separately) |
| Re-registration abuse record | Retained for 30 days after deletion, then destroyed (hashed email fingerprint and remaining credit balance only) |
| Marketing consent record | Until consent withdrawal |
| AI-training consent record | Until consent withdrawal |
| Partner store (Host) information | Until the partnership ends or the Host requests deletion |
A deletion request starts a 7-day grace period. Its purpose is to guard against unwanted deletion, such as deletion by someone who gained access to the account, and during that window the user can sign in and stop the deletion. Personal data is retained for that purpose alone during the grace period; after 7 days the account and its data are destroyed.
4.2 Statutory Retention (Republic of Korea)
| Item | Period | Legal Basis |
|---|---|---|
| Records of contract or withdrawal of offer | 5 years | Act on the Consumer Protection in Electronic Commerce |
| Records of payment and supply of goods | 5 years | Act on the Consumer Protection in Electronic Commerce |
| Records of consumer complaints or dispute resolution | 3 years | Act on the Consumer Protection in Electronic Commerce |
| Records of display/advertisement | 6 months | Act on the Consumer Protection in Electronic Commerce |
| Website access logs (IP) | 3 months | Protection of Communications Secrets Act |
5. Disclosure to Third Parties
The Company does not disclose personal data to third parties except:
- With the user's prior consent;
- When required by law or compelled to do so by law enforcement authorities through legally prescribed procedures;
- When required for imminent threats to the life, body, or property of the data subject or third parties;
- As necessary for the conclusion or performance of a contract related to the provision of the Service, where it is difficult to obtain ordinary consent.
Host Viewing of Partner-Store Inquiry Conversations
A partner-store persona answers inquiries on behalf of that store's Host, so it is provided on the basis that the conversation is passed on to the Host. The Host must be able to read the conversation in order to correct inaccurate answers (opening hours, prices, availability and the like). This processing is necessary to provide the Service and is therefore based on performance of the contract.
| Item | Details |
|---|---|
| Recipient | The Host (operator) of the partner store concerned |
| Purpose | Responding to user inquiries; identifying and correcting inaccurate answers; updating store information (menu, opening hours, visit guidance, etc.) |
| Data shared | The conversation with that store's persona (questions and answers) and its timestamps — account identifiers such as the user's email or nickname are not shared |
| Retention | Until the user deletes the conversation room or withdraws from membership |
The Company informs the user of this before the conversation begins and keeps the same notice visible on screen throughout the conversation. A conversation does not start until the user acknowledges the notice, and a user who does not wish this processing can simply not start the conversation. All other parts of the Service remain fully available.
Deleting a conversation room destroys the room and its messages, removing it from Host viewing. Related inquiries can be directed to the contact channels in Section 12.
Partner-store inquiry conversations that took place before August 13, 2026 are also made available to the Host within the same scope. Users who do not want such a conversation to be viewable may delete the conversation room or contact the channels in Section 12.
6. Processors (Entrusted Parties)
The Company entrusts the following processors to provide the Service. Contracts include GDPR Art. 28-compliant data-processing terms.
| Processor | Entrusted Task | Location |
|---|---|---|
| Supabase Inc. | Authentication and database hosting, verification emails | USA |
| Vercel Inc. | Web hosting, CDN, basic logging | USA |
| Resend Inc. | Transactional and marketing email delivery | USA |
| Payple Inc. | Domestic (KR) card payment processing | Republic of Korea |
| Lemon Squeezy (Paddle.com Market Ltd.) | International payment processing (Merchant of Record) | USA / UK |
| Google LLC | Social login (OAuth), web analytics (GA4), Gemini AI, in-app advertising (AdMob) | USA |
| RevenueCat, Inc. | In-app purchase and subscription status management (mobile app) | USA |
| Microsoft Corporation | Usage behavior analytics (Clarity — session replay, heatmaps) | USA |
| Kakao Corp. | Social login (OAuth) | Republic of Korea |
| OpenAI, L.L.C. | AI simulation and analysis (GPT models) | USA |
| Anthropic, PBC | AI simulation and analysis (Claude models) | USA |
| AssemblyAI, Inc. | Speech-to-text and speaker diarization of uploaded audio/meeting recordings | USA |
| Perplexity AI, Inc. | AI web search | USA |
| Functional Software, Inc. (Sentry) | Error tracking and monitoring | USA |
Processors related to the mobile app (AdMob, RevenueCat) apply only where the user uses an app build that includes those features.
7. International Data Transfers
The Company transfers personal data outside Korea / the EEA to the processors listed in Section 6. Transfers are carried out pursuant to Article 28-8 of PIPA and Chapter V (Articles 44–50) of GDPR.
Appropriate safeguards are in place:
- Standard Contractual Clauses (SCC) entered into with each processor located outside the EEA (Art. 46(2)(c)), or
- Adequacy decisions of the European Commission where applicable.
Users may request a copy of the applicable safeguards by contacting the Company at the address listed in Section 1.
| Recipient | Country | Data Transferred | Transfer Method | Retention |
|---|---|---|---|---|
| Supabase Inc. | USA | All categories in Section 3 | HTTPS/TLS | Per Section 4 |
| Vercel Inc. | USA | IP, cookies, access logs | HTTPS/TLS | Per Section 4 |
| Resend Inc. | USA | Email, nickname, email open records | HTTPS/TLS | 30 days after dispatch |
| Google LLC | USA | OAuth identifier, GA4 identifier, GA4 User-ID (non-PII UUID), prompts | HTTPS/TLS | Per Section 4 |
| Google LLC (AdMob) | USA | Advertising identifier (AAID/IDFA), device and app data, ad impression and click records | HTTPS/TLS | Per Section 4 |
| RevenueCat, Inc. | USA | App store transaction identifier, subscription status, app user identifier | HTTPS/TLS | Per Section 4 |
| Microsoft Corporation | USA | Behavioral data (clicks, scrolls, mouse movement) for Clarity session replay and heatmaps | HTTPS/TLS | Per Section 4 |
| OpenAI, L.L.C. | USA | Simulation conversation content; user-uploaded documents and persona knowledge content; persona profiles | HTTPS/TLS | Per Section 4 |
| Anthropic, PBC | USA | Simulation conversation content; user-uploaded documents and persona knowledge content; persona profiles | HTTPS/TLS | Per Section 4 |
| AssemblyAI, Inc. | USA | Uploaded audio/meeting recordings and their transcription/diarization results | HTTPS/TLS | Per Section 4 |
| Perplexity AI, Inc. | USA | Web search queries (may include partial simulation context) | HTTPS/TLS | Per Section 4 |
| Lemon Squeezy | USA/UK | Payment identifier, email, amount | HTTPS/TLS | Per Section 4 |
| Functional Software, Inc. | USA | IP, browser/OS, error message | HTTPS/TLS | 90 days |
8. Data Subject Rights
Users may exercise the following rights regarding their personal data at any time:
- Right of access — confirm processing and obtain a copy of the data (PIPA §35; GDPR Art. 15)
- Right to rectification — correct inaccurate or incomplete data (PIPA §36; GDPR Art. 16)
- Right to erasure — request deletion ("right to be forgotten") (PIPA §36; GDPR Art. 17), except where retention is mandated by law
- Right to restrict processing (PIPA §37; GDPR Art. 18)
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing
- Right to data portability — receive personal data in a machine-readable format and transmit it to another controller (PIPA §35-2; GDPR Art. 20)
- Right to object to processing based on legitimate interest or for direct marketing (GDPR Art. 21)
- Right not to be subject to automated decision-making (PIPA §37-2; GDPR Art. 22) — see Section 9
- Right to lodge a complaint with a supervisory authority (GDPR Art. 77)
How to exercise your rights:
- Withdraw consent: Settings → Consent in the Service, where marketing and AI-training consent can be turned on or off directly.
- Delete your account and data: Settings → Account in the Service (subject to the 7-day grace period in Section 4).
- Access, rectification, restriction, portability: Settings → Contact in the Service, or email forecast-ai@bimfactory.co.kr.
- Requests by an authorized representative require a written authorization.
The Company responds within 10 days (PIPA) or 30 days (GDPR, extendable by 60 days for complex requests).
Data Portability — Procedure
Pursuant to PIPA Article 35-2 and its Enforcement Decree, the procedure for transmission requests is as follows.
| Item | Details |
|---|---|
| How to request | Email forecast-ai@bimfactory.co.kr stating (i) identity verification details, (ii) the data items requested, and (iii) the recipient (yourself or another controller) |
| Data in scope | Account information, simulation usage records, personas and scenarios created by the user, payment history — that is, data the user provided or that was generated through use of the Service |
| Format | Structured, machine-readable format such as JSON |
| Processing time | Within 10 days of receipt (extendable with notice of the reason) |
| Checking status and history | A reference number is issued on receipt; progress and completion are communicated through the same email channel, where users may also request a record of past transmissions |
Transmission may be restricted where it would infringe the rights of another data subject or where retention is required by law; in such cases the reason will be explained.
9. Automated Decision-Making
Pursuant to PIPA Article 37-2 and GDPR Article 22:
- The Company currently does not perform solely automated decisions that produce legal or similarly significant effects on users (e.g., eligibility determination, tiered pricing based on profiling, account suspension without human review). Restrictions or suspensions for breach of the Terms are decided after human review and are never applied automatically.
- What is automated: usage-limit checks and credit deduction are calculated automatically against the published plan terms. This is performance of the contract the user selected and does not constitute profiling or evaluation of the user.
- AI-generated outputs provided through the Service are advisory reference material. Final decisions and actions remain with the user.
- Where the user has given separate consent for AI training, conversation data is used in a form from which personal identifiers have been removed for model quality improvement. Consent may be withdrawn at any time, and data is not used for training thereafter.
- Users may request an explanation of, or object to, any automated decision (see Section 8, Right 8).
10. Cookies and Behavioral Data
10.1 Categories
| Category | Description | Consent Required |
|---|---|---|
| Essential | Session, CSRF, language preference — required to operate the Service | No |
| Functional | Theme, onboarding state — user convenience | No or Optional |
| Analytics | Google Analytics 4 (_ga, _ga_*), Microsoft Clarity (_clck, _clsk) |
No (can be disabled via browser settings) |
| Advertising | Not in use (separate consent will be obtained if introduced) | N/A |
10.2 Managing Cookies
The Company does not currently operate a cookie consent banner on its website. Users may block all cookies other than essential ones through the following steps. Blocking essential cookies will prevent sign-in and limit use of the Service.
Step 1 — Delete stored cookies
- Chrome: Settings → Privacy and security → Delete browsing data → Cookies and other site data
- Safari: Preferences → Privacy → Manage Website Data → Remove
- Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data → Clear Data
Step 2 — Block third-party cookies via the browser's privacy settings.
Step 3 — Block all cookies, noting that sessions will not persist.
Step 4 — Use a private/incognito window, where history and cookies are cleared on close.
Step 5 — Opt out of individual analytics tools
- Google Analytics 4: install the opt-out browser add-on
- Microsoft Clarity: enable the browser's tracking prevention, or apply Steps 1–3
10.3 Behavioral / Interest-Based Advertising
- Website: the Company does not collect behavioral data for interest-based advertising and installs no advertising cookies. Conversion-tracking tools such as Google Ads tags or the Meta Pixel are not deployed. If introduced, this Policy will be updated and a separate consent mechanism provided beforehand.
- Mobile app: where ads are served in the app, Google AdMob uses the advertising identifier (AAID/IDFA) to deliver ads and measure performance. Users may turn off personalized advertising or reset the identifier as described in Section 10.4; non-personalized ads may still be shown.
- Behavioral data is processed in a form that does not directly identify the user and never includes special categories of data.
10.4 Advertising Identifiers — How to Opt Out
- Android: Settings → Privacy → Ads → "Delete advertising ID" or "Reset advertising ID"
- iOS: Settings → Privacy & Security → Tracking → turn off "Allow Apps to Request to Track"
10.5 Cookie Details
The name, purpose and retention period of each cookie are listed in the Cookie Policy.
11. Security Measures
Administrative
- Minimization and regular training of personnel handling personal data
- Internal management plan establishing responsibilities
- Retention and review of personal-data processing records
Technical
- Password hashing (bcrypt) and one-way encryption
- TLS 1.2+ encryption in transit
- Role-based access control and principle of least privilege
- Security monitoring and periodic reviews
- Firewall and intrusion detection systems
Physical
- Physical security of cloud infrastructure (Supabase, Vercel) in accordance with the respective providers' security policies
- Access control to office premises
12. Data Protection Officer (DPO) / Chief Privacy Officer (CPO)
- Name: Seo Hee-chang
- Title: Chief Privacy Officer (concurrent CEO)
- Email: forecast-ai@bimfactory.co.kr
Intake department for access and complaint requests:
- Department: Privacy Team
- Email: forecast-ai@bimfactory.co.kr
- Hours: Weekdays 08:00–17:00 KST (closed weekends and public holidays)
13. Responsibility of the Business Operator
Pursuant to PIPA Article 30-3 (effective 2026.9.11), the business operator and the representative of the Company bear overall responsibility for personal data processing, including publication of this Policy, implementation of safeguards, and notification and remedial action in the event of a personal-data breach.
14. Data Breach Notification
Where personal data is, or is likely to have been, lost, stolen, leaked, forged, altered or damaged, the Company will notify affected data subjects without undue delay and report to the relevant supervisory authority within 72 hours pursuant to GDPR Art. 33–34 and PIPA Art. 34 (as amended 2026.9.11), including:
- The categories of personal data affected
- When and how the breach occurred
- Steps the user can take to minimize harm
- Measures taken by the Company and the remedies available
- The point of contact for further information
- How to claim damages and how to apply for personal-data dispute mediation (see the channels in Section 15)
Where not all of the above can be confirmed at the time of notification, the Company will notify what has been confirmed first and provide the remainder as soon as it is established.
15. Remedies
Users may contact the following authorities for grievance resolution related to personal data.
Republic of Korea
| Authority | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | https://www.kopico.go.kr |
| KISA Privacy Infringement Report Center | 118 | https://privacy.kisa.or.kr |
| Cyber Investigation Bureau, Supreme Prosecutors' Office | 1301 | https://www.spo.go.kr |
| Cyber Investigation Bureau, National Police Agency | 182 | https://ecrm.police.go.kr |
EU / EEA
Users residing in the EU/EEA may lodge a complaint with their national supervisory authority. A list is available at edpb.europa.eu/about-edpb/about-edpb/members_en.
16. Changes to this Policy
Material changes, or changes unfavourable to users, will be announced at least 30 days prior to their effective date through the Service's notice section; other changes will be announced at least 7 days prior.
- Publication date of the current version: August 10, 2026
- Effective date of the current version: September 9, 2026
Revision History
| Effective date | Summary of changes |
|---|---|
| April 20, 2026 | Initial version |
| July 30, 2026 | 7-day grace period for account deletion; shortened account-information retention |
| September 9, 2026 | Added email open records to the international transfer list; added partner store (Host) data collection and public disclosure; added Host viewing of partner-store inquiry conversations (contract performance — notice shown before the chat starts and kept visible during it); added mobile app processing (device data, advertising identifier, in-app purchases); added AdMob and RevenueCat as processors and international transfer recipients; added Microsoft to the processor list; detailed the data portability procedure; added step-by-step opt-out for behavioral data and advertising identifiers; expanded breach notification items |
Previous versions of this Policy are available on request through the contact channels above.