This policy outlines the rules for the collection, use, and protection of personal information processed by BLYNX LAB (hereinafter referred to as the “Service”).

Effective Date: 2025.05.10


1. General Provisions

2. Items of Personal Information Collected and Collection Methods

Category Items Collected Collection Method
Required Agent conversation data (user input and agent responses) Automatically collected when the user inputs messages into the service
Required IP address Automatically collected when the user inputs messages into the service
Optional Web behavior data (clicks, scrolls, session ID, page URL, browser/OS/device info, etc.) Automatically collected via Microsoft Clarity script (uses cookies and local storage)

※ If any additional personal information is collected or used, separate consent will be obtained in advance.

3. Purpose of Collection and Use of Personal Information

  1. Service Provision and Feature Improvement

    – Enhancing agent response quality and analyzing errors based on conversation history

  2. Security and Service Stability

    – Preventing abuse/spam, managing traffic, and analyzing logs using IP addresses

  3. UI/UX Improvement and Product/Ad Optimization

    – Improving screens and experience using Clarity session replay and heatmaps

  4. Legal Obligations and Dispute Resolution

    – Compliance with applicable laws and fact-checking/responding to disputes

  5. Service Usage Statistics

    – Understanding usage patterns and planning new features

4. Retention and Use Period of Personal Information

Category Retention Period Legal Basis
Chat content Up to 2 years from the time the service purpose is fulfilled or upon user request for deletion Personal Information Protection Act, Article 21
IP address Up to 1 year from the date of access Protection of Communications Secrets Act, Article 15-2
Clarity session replay 30 days Microsoft Clarity policy
Clarity heatmaps & aggregated data Up to 13 months Microsoft Clarity policy

※ When retention is required by e-commerce or other relevant laws, personal information will be stored separately for the required period and then destroyed.

5. Procedures and Methods for Destroying Personal Information

  1. Destruction Procedures

    – Personal information is selected and destroyed in accordance with internal policies and legal requirements after the retention period or once processing purposes are fulfilled.