1. Scope
This policy applies to the Kairen website and Kairen Connect (the “Service”), operated by Kairen Co., Ltd. (the “Company”). The Company processes personal data in accordance with applicable laws, including the Personal Information Protection Act of the Republic of Korea.
Kairen Connect is a service for managing records about people, organizations, interactions, and tasks. Personal records managed by an individual user and work records shared with an organization have different access permissions and storage arrangements.
The Service is intended for users aged 14 or older. Children under 14 may not register.
2. Personal data collected and purposes of use
The Company processes information necessary to identify members, store and synchronize records, provide AI features requested by users, respond to inquiries, and operate the Service reliably. Information for optional features is processed when those features are used.
Website inquiries and beta applications
| Category | Data collected | Purpose of use |
|---|---|---|
| Closed beta applications | Email address and the application content you send | Confirming applications, providing participation information, and related communication |
| General inquiries and recruitment correspondence | Email address, inquiry content, and any name or attachments provided voluntarily | Responding to inquiries and recruitment communication |
Website forms create a draft to send from your email app. Entering information alone does not send it to the Company; the Company receives the content when you send the email yourself. Please do not send sensitive information unrelated to your inquiry or resident registration numbers.
Information provided by Connect users
| Category | Data collected | Purpose of use |
|---|---|---|
| Registration and login | Email address and password hash | Creating accounts, identifying users, and logging in |
| Third-party account login Optional | Email address and name from the selected third-party account | Identifying members and logging in with a third-party account |
| Your profile | Name and optionally entered organization affiliation | Identifying users and managing profiles |
| Work records | Names of people and organizations, affiliations, job titles, work email addresses and phone numbers, main phone numbers, addresses, websites, and notes | Managing records about people and organizations |
| Personal records | Personal mobile phone numbers and email addresses, birthdays, and personal notes | Storing records managed privately by the user |
| Interactions and tasks | Dates, times, and context of meetings and events, notes, follow-up tasks, and same-person markers | Managing relationship context and follow-up activities |
| Business card registration | Images of the front and back of a business card, the photographer’s name, where, how, and when you met, relationships with the user and organization, notes, and any research request entered | Extracting business card information, creating records, and providing related briefings |
| Organizing source text On request | Source text entered or pasted by the user, including any names, contact details, and notes it contains | Extracting information and structuring records at the user’s request |
| Third-party deletion requests | Name and affiliation of the person concerned, the requester’s contact details, and request content | Verifying identity and handling requests to exercise rights |
Third-party account login uses permissions needed to verify basic profile information. Providers and their processing activities are listed under Processors and international transfers.
Information generated during use of the Service
- Login records: Session creation and renewal times and browser information. Used to maintain login status and manage sessions.
- Error records: Error messages and diagnostic information, browser and app versions, and the page path where the error occurred. URL query parameters and fragments are excluded.
- Feature usage records: Whether a briefing was read to the end, a second business card was captured, a catalog search found a match, or personal record features were used. These records do not contain the record content itself and are used to improve features.
- Usage: Number of research runs and research depth. Used to manage usage limits for each feature.
- Operations and consent records: Account creation and deletion, changes to organization ownership and permissions, handling of deletion requests, versions of documents agreed to, and times of consent and withdrawal. Used for security, handling requests, and verifying consent.
In providing the Service, IP addresses, browser and device information, access times and paths, and page performance information are processed to the extent necessary for hosting, delivery, and performance and security management. If you allow optional browser push notifications, we process notification subscription endpoints and authentication keys.
3. Retention and destruction of personal data
The Company destroys personal data without delay when its purpose of use has been fulfilled or its retention period has expired. Information that must be retained by law is stored separately to the extent necessary.
| Information | Retention period |
|---|---|
| General inquiry emails | Until the inquiry response and any follow-up discussions arising from that inquiry are complete |
| Beta application emails | Until participation confirmation and guidance are complete, or further contact is no longer necessary because the application was withdrawn or recruitment ended. Information that leads to Service registration is subject to the retention rules for member information |
| Recruitment correspondence | Until the recruitment inquiry response or the relevant recruitment process is complete. Separate retention for future recruitment is limited to the scope and period agreed to by the applicant |
| Member accounts and profiles, personal records, interactions and tasks, same-person markers, individually owned relationships and work records, and usage records | Deleted upon account deletion. Information subject to the exceptions below, such as records shared with an organization, follows the applicable rules |
| Login sessions | Deleted upon logout, revocation of the session, or account deletion |
| Business card images registered in the app | Deleted when the relevant person’s record or the account is deleted |
| Business cards and capture records stored externally through existing personal capture links | Deletion procedures begin without delay upon account deletion or a deletion request. Materials in external storage are deleted within 30 days of receipt of the request |
| Consent records | Three years after account deletion, with information linking the records to the deleted account removed |
| Operational audit and error records | One year after account deletion, with information linking the records to the deleted account removed |
| Records of handling third-party deletion requests | Three years after processing is complete. Information linking the records to the requester’s account is removed |
Information deleted upon account deletion
The account and records managed privately by the user are deleted upon account deletion. Business card images, interactions, tasks, same-person markers, and individually owned relationships and work records are also deleted. Materials in existing external storage are deleted under the rules in the table above.
Records that may remain after account deletion
- Work records that the user explicitly shared with an organization and that became organization-owned remain as the organization’s records.
- Information about people and organizations referenced by other users may remain after information linking it to the author’s deleted account is removed.
- Organization catalogs compiled from public information and research briefings linked to relevant subjects may remain. Information linking a briefing to the requesting account is removed.
These exceptions do not mean that personal records are disclosed to the organization. People whose information is recorded may request access to, correction of, or deletion of their personal data, among other rights.
Before deleting your account, you may save your records using the Service’s export feature. You are responsible for managing exported files.
Destruction procedures and methods
The Company destroys personal data without delay when its retention period has expired or the purpose of processing has been fulfilled. Electronic files are deleted so that they cannot be recovered or reproduced, and paper materials are destroyed by shredding or similar methods.
Where retention is required by applicable law or necessary to respond to an ongoing dispute, investigation, or lawsuit, the relevant information is stored separately to the extent necessary on grounds permitted by law and destroyed without delay once the reason for retention ends.
The Service currently operates as a free closed beta and does not collect paid transaction information. If processing changes, such as when paid services are introduced, we will provide the necessary information in advance.
4. Sharing records
Records managed privately by a user are not automatically shared with their organization. Work records are shared with organization members according to the applicable access permissions only when the user explicitly shares them. Personal records, including personal mobile phone numbers, personal email addresses, birthdays, and personal notes, are excluded from organization sharing.
The Company does not sell contacts recorded by users or provide them to outside parties for advertising. Processing by external providers to operate the Service is described in the next section.
5. Processors and international transfers
The Company entrusts some activities necessary to operate the Service to the providers below. Each provider processes information necessary for its assigned activities, and the Company takes measures required by applicable law for processing agreements, management, and supervision.
| Provider | Assigned activities and information processed | Processing location |
|---|---|---|
| Supabase Inc. | Account authentication, database services, and file storage. Member accounts, records stored in the Service, and business card images | Seoul region, Republic of Korea |
| Cloudflare, Inc. | Website and Service hosting, content delivery, and performance and security management. IP addresses and access, device, and page performance information | The United States and locations listed in the official list of network operating countries. |
| OpenAI OpCo, LLC | Processing business card and source-text information and generating AI briefings. Business card images and capture context, source text the user asks to organize, and information listed in the AI features section below | United States |
| Google LLC | Receiving and storing emails; storing, retrieving, and managing existing capture records and business cards; and processing requested research | The United States and locations listed in the official list of processing countries. |
| Google LLC Optional features | Verifying email addresses and names for third-party account login; processing subscription endpoints and authentication keys when browser push notifications are allowed | The United States and locations listed in the provider’s privacy information. |
Transfer timing and methods, and retention periods
International transfers take place by transmitting information needed for the relevant activity over a network when users access the Service, log in, send emails, retrieve records, or run AI features. Processing countries vary according to the features used and distributed processing routes. Each provider’s operating locations are available in the country lists in the table above.
- Hosting and delivery: The access, performance, and security information listed above is processed when you access the Service and retained for the period necessary to provide and secure the relevant service and any retention period required by applicable law.
- Emails and stored materials: Until the purpose of the email or record is fulfilled or the user requests deletion, we apply the retention rules in Section 3. Backups and copies of materials deleted by the Company are handled according to the provider’s contractual deletion procedures. System deletion of business email may take up to 180 days after a permanent deletion request.
- AI processing: Business card and input information and generated results are processed upon request. The provider’s default response storage period is 30 days, and response data may be retained for at least 30 days. Abuse monitoring logs are generally retained for up to 30 days, subject to exceptions under the provider’s official data processing rules, such as legal retention obligations or safety reviews.
- Optional login and notifications: Information is processed for the period necessary to use the feature and maintain the account or notification subscription. Users may revoke the relevant permissions.
Where entrusted processing or storage is necessary to enter into or perform a contract, the Company complies with notice and other requirements under Article 28-8(1)(3) of the Personal Information Protection Act. Processing that requires separate consent takes place within the scope of that consent. Publication of this policy alone does not replace consent or a lawful basis for processing information about other people registered by users.
- Supabase privacy information and inquiries
- Cloudflare privacy information · dpo@cloudflare.com
- OpenAI data processing and retention information · privacy@openai.com
- Google Workspace data processing information · Data protection inquiries
- Google Account and login privacy information
You may send inquiries about international transfers or requests to refuse them to privacy@kairenhq.com. You may choose not to use optional features or revoke the relevant permissions. Where processing is essential to provide the Service, use of the relevant features may be restricted.
6. Personal data processing when using AI features
To provide business card processing and research briefings requested by users, the Company uses the external AI processors listed in Section 5. The information transmitted depends on the feature, as follows.
- Business card processing: The registered business card image and the context of the meeting supplied with it are transmitted to extract information and generate a briefing.
- Organizing source text: Source text entered or pasted by the user when requesting information extraction or organization is transmitted. Contact details or notes included in the text may also be processed.
- Research on people and organizations: Names, affiliations, job titles, work email addresses, and work phone numbers are transmitted. A research request field is supported, but its contents are not currently transmitted through this research path in the app.
- Web search: During briefing generation, the information above may be included in search terms sent to an external search service.
Contact details entered in work records may not be publicly available and may be transmitted to external services during AI research. Mobile phone numbers, personal email addresses, birthdays, and personal notes stored separately as personal records are not transmitted through the research path for people and organizations.
Information contained in business card images is transmitted during image processing. Please take care not to register images containing information that does not need to be processed.
Research briefings are generated from publicly available information. Research using private sources or sources requiring login, or aimed at inferring sensitive information, is not permitted.
AI briefings are automatically generated reference materials. They may be inaccurate or outdated, so please check the original sources before making important decisions. Access to a briefing follows the access permissions of the linked record.
7. Information stored in your browser
The Service uses browser storage to maintain login status and preferences. Records or business card images created while offline may be stored on the device while awaiting transmission.
You may delete stored information through your browser settings. Doing so resets your login status and preferences, and records that have not yet been transmitted may become unrecoverable.
The Company does not use tracking tools for advertising. Error and feature usage records needed to operate the Service are processed within the scope described under Information generated during use of the Service.
8. Your rights and how to exercise them
You may request access to, correction of, or deletion of your personal data, suspension of processing, and withdrawal of consent. Within the Service, you may directly edit, delete, or export records, revoke login sessions, or delete your account.
For requests that cannot readily be handled within the Service, please contact privacy@kairenhq.com. After verifying that you are the requester or an authorized representative, the Company will process the request in accordance with applicable law and inform you of the outcome. Where verification requires it, we may request minimal additional information.
If withdrawal of consent or suspension of processing prevents the processing of information essential to provide the Service, use of the relevant features may be restricted. If a request cannot be fulfilled in whole or in part because of legal retention obligations or other grounds, we will explain why.
9. Other people’s information and rights
When recording information about other people, users must only register lawfully collected information. The Company does not permit use of the Service to collect information unlawfully or infer sensitive information.
People whose information is recorded in the Service may request access to, correction of, or deletion of their information, among other rights, even if they are not members. Contact privacy@kairenhq.com with details of the information concerned and your contact information, or use the request feature provided in the Service for non-members.
10. Personal data security measures
The Company applies the following measures to manage personal data securely.
- We separate access permissions by account and organization and manage personal records separately from records shared with an organization.
- Business card images stored in the app are held in private storage with account-specific access permissions. Materials received through personal capture links are managed with the permissions needed for the relevant processing activities.
- Communications between the Service and its servers are encrypted, and password hashes are stored instead of plaintext passwords.
- We log account and permission changes and consent details so that the history of personal data processing can be checked.
11. Privacy Officer and inquiries
Please send personal data inquiries, complaints, or requests to exercise your rights to the contact below.
- Company
- Kairen Co., Ltd.
- Privacy Officer
- KangKyu Lee
- privacy@kairenhq.com
If you need advice about a personal data infringement or help resolving a dispute, you may contact the Personal Information Infringement Report Center or the Personal Information Dispute Mediation Committee for assistance.
12. Changes to this Privacy Policy
The Company may revise this policy to reflect changes in laws or the Service. Changes to processing will be announced through Service notices at least 7 days before they take effect; significant changes unfavorable to users will be announced 30 days in advance. Where separate consent is required, we will obtain it in accordance with applicable law.
This revision reorganizes the existing processing details and retention rules for readability and adds guidance on website inquiries and beta applications. The 2026-09-06 revision changed the privacy inquiry and rights-request channel to privacy@kairenhq.com.