Privacy
Deyo Privacy Policy
Effective and last updated · July 19, 2026
주식회사 스텝하우 (the “Company”) processes personal data lawfully and securely to provide Deyo. This Policy explains the data, purposes, retention, processors, international processing, and data-subject rights.
A member operating Deyo for its own customers remains responsible for its customer-facing privacy notice and lawful basis. This Policy also describes the Company’s processing as a service provider under the member’s instructions.
The July 19, 2026 update clarifies deletion, temporary import data, workspace content, payment evidence, and statutory retention without expanding processing purposes or consent.
1. Controller and privacy contact
- Controller: 주식회사 스텝하우; Representative: 황성욱
- Address: 서울특별시 동작구 노량진로 10, 서울창업센터동작 209호
- Privacy officer: 차지형 CTO
- Privacy rights and complaints: cto@stephow.me
- General service and contract inquiries: ceo@stephow.me
2. Data, purposes, and retention
Data is provided directly or generated through use. Optional fields are not required for unrelated core features.
- Account and login: email, optional Google identifier/profile, authentication and consent version/time; retained until account deletion, with legally required consent and contract evidence retained separately.
- Workspace: names, member emails and roles, settings, websites, files, Q&A, and usage; used for answers, retrieval, team operations, quality, security, and cost controls. A normal deleted source is excluded immediately, restorable for 7 days, then deleted. Onboarding deletion is immediate. Trial overage is inactive for 30 days. Workspace customer content is deleted 30 days after deactivation.
- Temporary import data: extracted text, URL, title, byte count, state, and error; cleared after publication, cancellation, or final failure. Orphaned temporary objects are normally cleared within 24 hours.
- Widget and support: conversation, optional name/email/phone, current page, referrer, state, browser, OS, and device; used for AI answers, handoff, replies, history, and quality. Deleted with workspace customer content 30 days after deactivation unless a shorter member policy applies.
- Billing: order, plan, interval, amount, status, timestamps, Toss customer key, encrypted billing key, issuer, and masked card details. Keys are deleted with permanent workspace deletion; contract, order, approval, and refund evidence is detached and retained for 5 years or another legally required period.
- Implementation inquiries: name, email, company, role, website, team size, interest, and message; retained for 3 years after completion, or the contract-record period if converted.
- Access and security: timestamps, IP or one-way identifier, cookies, request/error/security events, browser and device; normally retained for 3 months, longer only for an incident or dispute.
The Company does not directly collect or store card numbers or CVC. Toss Payments provides and processes payment authentication.
3. Legal basis and children
Processing relies on applicable consent, performance of the service agreement, legal obligations, and legitimate interests such as security and abuse prevention. Any optional marketing consent is separated from required service consent.
Deyo is a business service and is not directed to children under 14. Data known to have been collected from a child under 14 without lawful guardian consent is deleted promptly after verification.
4. Member customer data and processor role
A member operating the widget generally determines the purposes and means of its customer-data processing; the Company may act as its service provider. The member must disclose fields, purposes, retention, handoff, vendors, and international processing and establish a lawful basis.
The Company does not sell member customer data or use it for independent advertising. AI API data is operated on the basis of provider API settings under which it is not used to train general models by default; this Policy will be updated if the actual setting changes.
5. Third-party disclosure
The Company does not sell or disclose personal data to third parties without consent, except as permitted by law.
- Where a data subject consents after receiving recipient, purpose, fields, and retention details.
- Where required by law, a lawful court or agency order, or protection of life and safety.
- Where rights and obligations transfer through a lawful merger, acquisition, or business transfer.
6. Service providers
The Company contractually manages providers used to deliver the Service. Data for an optional feature may not be sent when that feature is unused.
- Supabase, Inc.: authentication, database, file storage, and realtime functions; account, workspace, source, conversation, and operational data.
- Vercel Inc.: hosting, delivery, application logs, and security; request, access, and processed service data.
- OpenAI, L.L.C. and affiliates: answers, embeddings, and classification; questions, selected knowledge context, instructions, and pseudonymous request identifiers.
- Resend, Inc.: login, service, and inquiry email; email, recipient name, alert, and inquiry content.
- Toss Payments Co., Ltd.: payment authentication, billing keys, recurring approval and cancellation; customer key, order, amount, method, and approval data.
- Google LLC: optional Google OAuth; email, authentication identifier, and public profile.
- Slack Technologies, LLC: optional handoff notifications; conversation summary, customer-provided contact, current page, and Inbox link.
7. International transfer and processing
Some providers or support personnel operate outside Korea. The Company uses applicable contractual, consent, service-performance, or other lawful safeguards. A user may avoid an optional function or request account/service termination at cto@stephow.me, but core AI, authentication, and email functions may then be unavailable.
- OpenAI / United States and provider operating countries: question, context, and instructions for AI and embeddings; encrypted network transfer on request; abuse-monitoring data normally up to 30 days, subject to provider legal/security exceptions and eligible zero-retention settings.
- Vercel / Seoul, United States, and operating countries: request and processed data for hosting and security; retained for the contract and configured log period.
- Supabase / Seoul region and United States support operations: account, workspace, and conversation data for authentication, storage, and realtime; retained through the contract and deletion process.
- Resend / United States: email address and content for delivery; retained under configured delivery, security, and dispute periods.
- Google and Slack / global operating countries: only when the corresponding login or notification feature is selected; retention follows the connection and provider/workspace settings.
8. Statutory retention
- Contract and withdrawal records: 5 years under Korean e-commerce law.
- Payment and service-supply records: 5 years under Korean e-commerce law.
- Consumer complaint and dispute records: 3 years under Korean e-commerce law.
- Website access logs: 3 months under applicable communications law.
9. Deletion
When a purpose or retention period ends, electronic data is deleted in a manner designed to prevent recovery, and paper is shredded or incinerated. Statutory records are separated with distinct access control and used only for that purpose.
Encrypted backups are deleted through provider backup rotation and are not restored or used except for disaster recovery.
10. Data-subject rights
A data subject may request access, applicable portability, correction, deletion, restriction, withdrawal, and account deletion at cto@stephow.me. The Company verifies the requester or lawful representative and responds under applicable procedures.
Requests may be limited where permitted to protect another person, comply with retention law, or avoid materially impairing contract performance. A member’s customer can first contact the member operating the widget; the Company assists with a lawful member request.
11. Cookies and automated processing
Essential cookies and similar technologies maintain login, security, settings, and widget operation. Blocking them can limit login and widget functionality. Behavioral data is not sold for third-party advertising.
AI automates retrieval, answers, and handoff signals, but the Company does not use this function alone to make decisions with a material legal effect. Members must provide human review and a way to object in customer operations.
12. Security and incident response
Reasonable measures include role-based access, workspace separation, encryption in transit, secret separation, AES-256-GCM encryption of Toss billing keys, log and event controls, allowed-domain verification, rate and cost limits, and vulnerability response.
If a personal-data incident occurs, the Company investigates and contains it and, where required, promptly notifies data subjects and authorities.
13. Remedies and Policy changes
Privacy concerns may be sent to the privacy officer. Data subjects may also use Korea's privacy infringement hotline (118), dispute mediation, police, prosecutors, or other competent authorities.
Changes are normally announced seven days in advance. Material changes to data-subject rights are announced 30 days in advance by email or another method and follow any required consent process.
Consent remains effective from the July 17, 2026 version. The July 19, 2026 clarification aligns deletion and statutory-record explanations with actual behavior.