Privacy Policy
Treeru's privacy policy regarding the protection of personal information.
This translation is for reference; the Korean version prevails. Korean version
Treeru (the “Company”) establishes and publishes the following personal information processing guidelines under Article 30 of the Personal Information Protection Act to protect data subjects and promptly and smoothly handle related complaints.
Article 1 (Purposes of Processing Personal Information)
We process personal information for the following purposes. We do not use the information for other purposes. If a purpose changes, we will take the necessary measures, including obtaining separate consent, under Article 18 of the Personal Information Protection Act.
1. Website membership registration and management
We process personal information to confirm the intention to join, identify and authenticate users for membership services, maintain and manage membership, verify identity under the limited identity verification system, prevent misuse, verify legal representative consent when processing personal information of children under 14, deliver notices, and handle complaints.
2. Service provision
We process personal information to provide services, send contracts and invoices, provide content and personalized services, verify identity, and process and settle payments.
3. Marketing and information
We process personal information for marketing and promotional purposes, including newsletters about AI, IT, and development, new service announcements, event and promotion information, and personalized advertising. We obtain prior consent before sending promotional information and stop sending it immediately upon opt-out.
4. Complaint handling
We process personal information to identify complainants, confirm complaints, contact and notify people for fact-finding, and communicate results.
5. TreeTalk platform account management
We process account information needed to identify and authenticate business staff, manage permissions, maintain login sessions, and manage access records for the conclusion and performance of TreeTalk service agreements and account security.
Our administrators manage platform permissions and access for each business. Business staff view their own business’s consultation materials and visit and engagement analytics according to their assigned permissions. Administrator accounts are managed separately from business staff accounts.
Article 2 (Processing and Retention Periods)
- ① We process and retain personal information within the retention and use periods prescribed by law or agreed to by the data subject when the information was collected.
- ② The processing and retention periods for each category are as follows.
Website membership registration and management
Retention period: until withdrawal from the business or organization’s website
However, where any of the following applies, information is retained until the relevant circumstances end.
- Until an ongoing investigation or inquiry into a violation of applicable law ends
- Until any outstanding claims and debts arising from website use are settled
TreeTalk platform account information
We retain business account access records for 1 year and then automatically delete them. Account information for a business that terminates its service is pseudonymized 90 days after termination. Requests for deletion following account termination or the end of access permissions can be sent to info@treeru.com. Information subject to a legal retention obligation is stored separately for the required period.
Customer information processed on behalf of businesses
We process customer personal information for the period specified in the business’s privacy policy and contract. When the processing arrangement ends, we return or destroy it according to the business’s request and the contract. Each business’s policy is available through the privacy policy link in its chat window.
Article 3 (Provision of Personal Information to Third Parties)
We process personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information). We provide it to third parties only in circumstances covered by Articles 17 and 18 of the Personal Information Protection Act, such as data subject consent or specific statutory provisions, and do not otherwise provide it to third parties.
Article 3-2 (Scope of TreeTalk Processing on Behalf of Businesses)
Businesses entrust us with operating the TreeTalk consultation system. Each business determines the purposes and retention periods for its customers’ personal information. The processing arrangement is established under the service agreement with the business. The personal information processing provisions in the TreeTalk Terms of Service specify the scope of work, safeguards, subprocessors, supervision, and return or destruction of information.
- Scope of processing
- Storage and management of customer conversations and consultation submissions, provision of consultation materials for each business, visit and engagement analytics, and operation of the consultation system. The actual information processed and its purposes depend on each business’s services and policy.
- Customer identification and consultation submissions
- Customers can use the chat without logging in. We store a random visitor identifier in browser storage and do not use customer cookies or social login. Name and phone number entry is optional, but both are required when submitting them to request a reply. Each business explains any additional inquiry form fields before collecting them.
- Scope of visit analytics
- We process visitor identifiers, visit times, page URLs and titles, referring URLs, browser and device information, view counts, time spent, screen viewing time, scroll depth, exit reasons, and records of chat window, conversation, contact field, and inquiry form use. We do not track ordinary clicks. Purposes, retention periods, and opt-out methods follow the business’s policy. You can delete stored identifiers or prevent storage by deleting or blocking site data in your browser; this may limit features such as resuming a conversation.
- Exercising rights and contacting the responsible business
- Customers may request access, correction, deletion, or suspension of processing through the contact listed in the relevant business’s privacy policy. We assist with the necessary processing at the business’s request (info@treeru.com). Rights concerning account information that we process directly can be exercised through the contacts in Articles 9 and 10.
- Safeguards for processing on behalf of businesses
- We separate consultation materials by business and encrypt submitted names and phone numbers for storage. We distinguish staff and administrator accounts and permissions, and record logins and major access and processing activities. Before storage, we mask resident registration, foreign resident registration, passport, driver’s license, and payment card numbers entered in the chat window. Only the last 4 digits of payment card numbers remain visible.
- Subprocessors
- We engage Anthropic, PBC as a subprocessor to generate AI answers. Approval of this arrangement follows the service agreement with the business. The information transmitted, countries, and retention periods are described in the AI processing notice below.
Article 3-3 (TreeTalk AI Processing and International Transfers)
We do not send names or contact details received through separate input fields to the AI. We mask portions detected as personal information in questions and previous conversations before sending them to the AI. We also mask portions detected as personal information in guidance materials and response instructions registered by the business before sending them to the AI. However, information published by the business, such as its address and main phone number, is excluded from masking.
Automatic masking cannot recognize every expression, so please do not enter sensitive or unnecessary personal information in the chat window. AI processing takes place outside Korea even when masking is applied.
- AI provider and contact
- Anthropic, PBC · privacy@anthropic.com
- Countries of processing
- United States. Information may be processed in other countries under the provider’s privacy policy.
- Information transmitted
- We send questions, previous conversations, and the business’s guidance materials and response instructions needed for answers after masking portions detected as personal information. Information published by the business, such as its address and main phone number, is excluded from masking. Values from the separate contact fields are not transmitted.
- Timing and method
- Whenever a question is answered, information is sent from our servers over encrypted communications.
- Purpose and retention and use periods
- Information is used to generate AI answers. Retention and use for training follow the provider’s policies and vary with the subscription account settings. The provider retains information for as long as reasonably necessary for the purposes and criteria in its privacy policy. When conversations on a personal subscription are deleted, they are removed from storage systems within 30 days. If model improvement is allowed, information may be retained in de-identified form for up to 5 years. Inputs and outputs flagged for policy violations may be retained for up to 2 years, safety classification scores for up to 7 years, and materials related to submitted feedback for 5 years. Exceptions apply, including legal obligations and dispute handling.
- Applicability and legal basis for international transfers
- If the information to be transmitted includes personal information, the business must establish a legal basis for the international transfer under applicable law and provide the necessary notices and obtain consent. Agreement to this policy or the terms alone does not constitute separate consent to international transfers.
- How to decline, procedures, effects, and alternative consultation
- You may choose not to use AI consultation or stop using it. AI answers will then be unavailable, and you may use the telephone, email, or other contact channels on the business’s website. Rights concerning information already processed may be exercised through the business.
Article 4 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)
- ① Data subjects may exercise the following personal information protection rights against us at any time.
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
- ② Rights under paragraph 1 may be exercised by writing, telephone, email, fax, or similar means. We will act without delay.
- ③ If a data subject requests correction or deletion of personal information, we do not use or provide that information until correction or deletion is complete.
- ④ Rights under paragraph 1 may be exercised through a legal representative or an authorized agent. In that case, a power of attorney using Form No. 11 attached to the Enforcement Rule of the Personal Information Protection Act must be submitted.
- ⑤ Data subjects must not infringe on their own or others’ personal information and privacy processed by us in violation of the Personal Information Protection Act or other applicable laws.
Article 5 (Categories of Personal Information Processed)
We process the following categories of personal information.
1. Website membership registration and management
Required: Name, email address, password
Optional: Company name, phone number, areas of interest
2. Marketing and information
Required: Email address
Optional: Name, areas of interest, newsletter consent status
3. Account information we process directly in TreeTalk
- Business staff: login ID, encrypted password, role and permissions, display name, name, notification recipient, last login time, access address and browser information, access and processing records, and the version and time of terms acceptance.
- Treeru administrators: login ID, display name, encrypted password, login access address and browser information, and access and processing records.
- When issuing an account, we receive the information needed for authentication, such as an ID and password. Names and notification recipients are processed when configuring accounts and notifications. We obtain acceptance of the terms when businesses log in and record the accepted version and time. We use staff and administrator session cookies to keep users logged in. Blocking cookies prevents login to the management interface.
The scope of customer information processed on behalf of businesses is described in Article 3-2 and the relevant business’s policy. TreeTalk is not intended for children under 14, and we do not have a procedure for collecting children’s information with legal representative consent. If information is identified as belonging to a child, we work with the business to destroy it without delay.
Article 6 (Destruction of Personal Information)
- ① We destroy personal information without delay when it is no longer needed, including when its retention period expires or its processing purpose is fulfilled.
- ② If another law requires continued retention after the consented retention period expires or the processing purpose is fulfilled, we move the information to a separate database or store it in a separate location.
- ③ The procedures and methods for destruction are as follows.
- Destruction procedure: We select personal information for which a reason for destruction has arisen and destroy it with approval from our personal information protection officer.
- Destruction method: We destroy electronically recorded or stored personal information so that it cannot be reproduced. Paper records are shredded or incinerated.
④ Information processed on behalf of businesses in TreeTalk follows the periods and return or destruction conditions in each business’s policy and contract. When a business requests return or destruction, we assist by checking the scope of conversations, submissions, visit information, and copies such as logs and backups. Information that must be retained by law is stored separately for that purpose only.
⑤ We automatically delete backup copies stored on our servers after retaining them for no more than 6 months. We make external backups daily and automatically delete them after retention periods of 14 days for daily backups, 8 weeks for weekly backups, and 6 months for monthly backups. Backup copies are used only for recovery.
Article 7 (Measures to Safeguard Personal Information)
We take the following measures to safeguard personal information.
- Administrative measures: Establishment and implementation of internal management plans, regular staff training, and similar measures
- Technical measures: Management of access permissions to personal information processing systems, installation of access control systems, encryption of unique identification information, and installation of security software
- Physical measures: Access controls for computer rooms, data storage rooms, and similar facilities
Article 8 (Installation, Operation, and Rejection of Automatic Personal Information Collection Tools)
- ① We use cookies that store and retrieve usage information to provide personalized services.
- ② Cookies are small pieces of information sent by the website’s HTTP server to a user’s computer browser and stored on the user’s computer or mobile device.
- ③ Data subjects may allow or block cookies through browser settings. Refusing cookie storage may make personalized services difficult to use.
Allowing or blocking cookies in desktop browsers
- Chrome: Browser settings > Privacy and security > Delete browsing data
- Edge: Browser settings > Cookies and site permissions > Manage and delete cookies and site data
Allowing or blocking cookies in mobile browsers
- Chrome: Mobile browser settings > Privacy and security > Delete browsing data
- Safari: Device settings > Safari > Advanced > Block All Cookies
- Samsung Internet: Mobile browser settings > Browsing history > Delete browsing data
④ We collect and use information about visits and usage patterns across services and websites, popular search terms, and secure connections during service use to provide information tailored to users.
Article 9 (Personal Information Protection Officer)
We designate the following personal information protection officer to oversee personal information processing and handle data subjects’ complaints and remedies related to that processing.
Personal Information Protection Officer
- Name: Kyungnam Kim
- Position: Representative
- Email: info@treeru.com
Data subjects may contact the personal information protection officer about any personal information protection inquiries, complaints, or remedies arising from use of our services or business. We will respond and handle them without delay.
Article 10 (Requests to Access Personal Information)
Data subjects may request access to personal information under Article 35 of the Personal Information Protection Act through the contact below. We will work to process requests promptly.
Contact for receiving and processing access requests
- Email: info@treeru.com
Article 11 (Remedies for Infringement of Rights)
Data subjects may contact the following organizations for remedies and consultation regarding personal information infringements.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code within Korea; www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code within Korea; privacy.kisa.or.kr)
- Supreme Prosecutors’ Office: 1301 (no area code within Korea; www.spo.go.kr)
- Korean National Police Agency: 182 (no area code within Korea; ecrm.police.go.kr/minwon/main)
Article 12 (Effective Date and Changes to This Privacy Policy)
This Privacy Policy takes effect on September 26, 2026.
- February 24, 2026: Previous Privacy Policy took effect.
- September 25, 2026: Added TreeTalk account information processing, the scope and safeguards of processing on behalf of businesses, AI processing, and standards for handling children’s information.
- September 26, 2026: Updated TreeTalk masking before storage, masking of business materials before AI transmission, terms acceptance records, and retention standards for accounts, access records, and backups.