WESSGLOBAL 개인정보처리방침

WESS AI 챗봇

개인정보처리방침

웨스글로벌(주)(이하 “회사”)은 공개 고객지원 챗봇을 운영하면서 처리하는 개인정보의 항목, 목적, 보유기간 및 이용자의 권리를 다음과 같이 안내합니다.

시행일: 2026년 8월 18일 · 최종 수정: 2026년 10월 7일

1. 처리하는 정보

구분항목
대화 정보질문, AI 답변, 선택한 제품·언어, 접속시각, 피드백, 답변 신고 사유·접수시각·요청 식별값, 첨부 여부, 대화·요청 식별값
접속 정보전체 IP 주소, IP를 기반으로 Cloudflare가 추정한 국가와 시·도/주 단위 광역지역
브라우저 저장현재 브라우저의 대화 기록, 화면 언어와 테마 설정

GPS, 위도·경도, 주소, 우편번호, 구·군 단위 정밀 위치는 수집하지 않습니다. 국가·광역지역은 네트워크 출구의 추정값으로, VPN·프록시·회사망·이동통신망 사용 시 실제 위치와 다를 수 있습니다. 전화번호와 이메일 형식은 서버 저장 전에 마스킹하며 사진·PDF 원본은 서버 대화기록에 저장하지 않습니다.

2. 처리 목적과 근거

  • 사용자가 요청한 WESS AI 제품 답변 제공과 대화 흐름 유지
  • 서비스 품질관리, 오류 분석 및 고객지원 내용 개선
  • 비정상 이용·남용·보안사고 예방과 대응
  • 국가·광역지역별 이용 현황 분석과 서비스 운영계획 수립

대화 처리는 이용자가 요청한 서비스 제공을 위해 필요한 범위에서 수행하며, 접속정보 처리는 서비스 보안·남용 방지 및 운영 분석이라는 회사의 정당한 이익을 위해 필요한 범위에서 수행합니다. 회사는 목적의 정당성, 처리의 필요성, 이용자 권리와의 균형 및 아래의 보호조치를 검토합니다. 관련 근거는 개인정보 보호법 제15조 제1항 제4호 및 제6호입니다.

3. 보유기간과 파기

  • 전체 IP·국가·광역지역·접속시각: 각 대화의 마지막 수집일로부터 1년(365일)을 만료 기준으로 설정합니다. 만료된 접속정보는 관련 저장·조회 코드 실행 시 삭제 대상이 됩니다.
  • 집계 지역 통계: 대화 연결과 IP를 제거한 월별 국가·광역지역 건수만 통계 목적으로 남길 수 있습니다.
  • 질문·AI 답변·피드백·신고 사유: 현재 서버 저장 구현에는 자동 만료가 없으며 관리자 삭제 전까지 보관합니다. 이용자는 아래 문의처로 삭제를 요청할 수 있습니다.
  • 브라우저 기록: 이용자가 해당 브라우저에서 삭제하거나 저장공간 정책에 따라 정리될 때까지 보관합니다.

원본 IP는 AES-GCM 방식으로 암호화하여 별도 보호키와 함께 관리합니다. 삭제 코드에는 연결된 행 삭제와 SQLite 보안삭제, WAL 체크포인트 및 저장소 정리 절차가 포함되어 있습니다.

4. 처리위탁 및 국외 이전

로컬 AI 처리: 현재 질문·대화 문맥·첨부자료의 답변 생성과 로컬 사진 분석은 회사 로컬 시스템에서 처리합니다. 답변 생성을 위해 이러한 내용을 OpenAI 등 외부 AI 서비스로 전송하지 않습니다. 로컬 AI가 사용할 수 없거나 요청 처리에 실패하면 오류 또는 일시적인 서비스 제한을 안내하며, 외부 AI로 자동 전환하지 않습니다. 공개 서비스의 네트워크 경로인 Cloudflare를 통한 요청 전달과 아래의 처리는 계속 적용됩니다.

수탁자·이전받는 자Cloudflare, Inc.
목적CDN, 보안, 요청 중계, IP 기반 국가·광역지역 추정
이전 항목IP 주소, 요청시각·경로 등 요청 메타데이터와 이용자가 전송한 요청 내용
국가·시기·방법미국을 포함한 Cloudflare의 글로벌 처리거점으로 서비스 접속 시 암호화된 네트워크를 통해 전송
보유기간Cloudflare의 보유기간은 적용 서비스 설정 등에 따라 달라질 수 있습니다. 회사 DB의 대화별 접속정보는 마지막 수집일로부터 365일을 만료 기준으로 설정합니다.

Cloudflare가 공개한 일반 안내는 Data Processing Addendum과 Subprocessor List에서 확인할 수 있습니다. Cloudflare를 통한 전송을 원하지 않으면 아래 문의처로 처리정지를 요청할 수 있으나, Cloudflare가 공개 서비스의 네트워크 경로이므로 챗봇 제공이 제한될 수 있습니다.

5. 이용자의 권리와 행사 방법

이용자는 자신의 개인정보에 대해 열람, 정정, 삭제, 처리정지 및 이의를 요청할 수 있습니다. 아래 이메일로 대화 일시, 선택한 제품, 첫 질문 등 기록을 찾는 데 필요한 최소 정보를 보내 주세요. 회사는 요청자 본인 확인 후 관련 법령이 정한 절차에 따라 처리합니다.

개인정보 문의: mt@wessglobal.com · 전화 +82-42-936-7060

6. 안전성 확보조치

  • 원본 IP의 필드 단위 암호화와 키 파일 접근권한 제한
  • 관리자 인증과 업무상 필요한 인원으로의 접근 제한
  • 외부가 위조할 수 있는 전달 헤더 제거 및 Cloudflare 경계의 짧은 유효시간 HMAC 서명 검증
  • 접근 로그에 원격 IP와 URL 질의문자열을 남기지 않는 최소 로그 정책
  • 접속정보의 1년 만료 기준과 삭제·유지보수 코드

7. 처리방침 변경

이 방침이 변경되면 시행 전에 챗봇 화면에서 안내합니다. 이용자 권리에 중대한 변경이 있는 경우에는 충분한 사전 안내기간을 둡니다.

WESS AI Customer Support Chatbot

Privacy Policy

WESS Global, Inc. (“WESS”) explains below how the public customer-support chatbot processes personal data, why it is processed, how long it is retained, and how users may exercise their rights.

Effective: August 18, 2026 · Last updated: October 7, 2026

1. Data processed

  • Conversation data: questions, AI answers, selected product and language, access time, feedback, reply report reasons, receipt time and request identifier, attachment indicators, and conversation/request identifiers.
  • Connection data: full IP address and the country and broad state/province-level region estimated by Cloudflare from that IP.
  • Browser data: conversation history and language/theme settings stored in the current browser.

WESS does not collect GPS data, coordinates, street addresses, postal codes, or district-level precise location. IP geolocation is only an estimate and can differ from the actual location when a VPN, proxy, corporate network, or mobile carrier is used. Phone-number and email patterns are masked before server storage; original image and PDF attachments are not stored in server conversation records.

2. Purposes and legal basis

Data is processed to provide requested product support, maintain conversation context, manage quality, analyze errors, prevent abuse and security incidents, and understand country/broad-region usage. Conversation processing is limited to what is needed to provide the requested service. Connection data is processed within what is necessary for WESS’s legitimate interests in service security, abuse prevention, and operational analysis, after considering necessity, proportionality, user rights, and the safeguards below. The cited bases are Article 15(1)(4) and (6) of Korea’s Personal Information Protection Act.

3. Retention and deletion

  • Full IP, country, broad region, and access time: an expiry threshold of one year (365 days) from the last collection for each conversation. Expired connection data is eligible for deletion when the relevant storage or query code runs.
  • Aggregated regional statistics: monthly country/region counts with no IP or conversation link may remain for statistics.
  • Questions, AI answers, feedback, and report reasons: the current server storage implementation has no automatic expiry; records remain until administrator deletion. Users can request deletion through the contact below.
  • Browser records: until the user deletes them or browser storage limits remove them.

Full IP addresses are encrypted with AES-GCM and managed with a separately protected key. The deletion code includes linked-row deletion, SQLite secure deletion, WAL checkpointing, and storage cleanup.

4. Cloudflare processing and international transfer

Local AI processing: Customer AI answer generation and local image analysis of questions, conversation context, and attachments are currently processed on the company’s local system. This content is not sent to OpenAI or other external AI services to generate answers. If local AI is unavailable or processing fails, the service reports an error or temporary limitation and does not automatically fall back to an external AI service. Request transport and the processing described below through Cloudflare, which remains part of the public service network path, still apply.

Cloudflare, Inc. provides CDN, security, request relay, and IP-based country/region estimation. IP addresses, request metadata, and submitted request content may be transferred over encrypted networks at access time to Cloudflare processing locations worldwide, including the United States. Cloudflare retention may vary with the applicable service settings. WESS configures a 365-day expiry threshold for conversation-linked connection metadata from its last collection. Public general information is available in Cloudflare’s Data Processing Addendum and Subprocessor List. Users may object or request suspension through the contact below, but the chatbot may become unavailable because Cloudflare is part of the public service network path.

5. User rights and contact

Users may request access, correction, deletion, suspension of processing, or raise an objection. Email the minimum details needed to locate the record, such as conversation date/time, selected product, and first question. WESS will verify the requester and respond under applicable law.

Privacy contact: mt@wessglobal.com · +82-42-936-7060

6. Safeguards and changes

Safeguards include field-level IP encryption, restricted administrator access, removal of spoofable proxy headers, short-lived HMAC verification between trusted relays, minimal access-log configuration without remote IP or query strings, and code for the one-year connection-data expiry threshold and deletion. Policy changes will be announced in the chatbot before taking effect, with additional advance notice for material changes affecting user rights.