Rudolphinic™ Privacy Policy
Applicable Version: 2026.08.19 Date Enacted: August 19, 2026 Effective Date: August 19, 2026
Hanco Lab (hereinafter, the “Company”) lawfully processes and securely manages personal information in compliance with the Personal Information Protection Act and applicable laws and regulations in order to protect the freedoms and rights of Data Subjects. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses this Privacy Policy as follows in order to inform Data Subjects of the procedures and standards for processing personal information and to ensure that related grievances can be handled promptly and smoothly.
Notice: Scope of Application to the Beta Service
This Privacy Policy applies to the Rudolphinic™ beta Service, which does not provide paid-payment features. During the beta period, the Company does not collect or process payment methods, billing addresses, or tax-identification information for the sale of RCC, recurring payments, or refunds. Before introducing Paid Services or external payment features, the Company will amend this Policy to reflect the actual payment structure and personal-information processing status and will complete any notices or consent procedures required by applicable laws and regulations.
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. The Company uses personal information within the scope of the disclosed purposes of processing and, if the purpose of processing changes, will take necessary measures under applicable laws and regulations, including obtaining additional consent and amending and disclosing this Privacy Policy.
- Member management: The Company processes personal information to confirm the intent to register as a Member, conduct email verification, create and maintain Accounts, identify Members, provide Service-related notices, and prevent improper use.
- Provision of the Rudolphinic™ beta Service: The Company processes personal information to store Strategy code, configuration values, and analysis conditions entered by Members; run Backtests and parameter analyses; view and retain Deliverables; and manage free beta-usage limits.
- Protection of Data Subjects and operation of the Service: The Company processes personal information to detect, prevent, and respond to acts that interfere with Service operations, including improper use and Account theft; provide Service-related announcements and notices; handle customer inquiries and grievances; and respond to disputes.
- Service stability analysis and improvement: The Company processes personal information to analyze Service-use, access, error, and security records; respond to failures; enhance security; and improve functionality, performance, and quality.
- Optional LLM-based statistical explanations: Where a Member requests the explanation feature, the Company processes personal information to the extent necessary to explain statistical summaries of analytical results in natural language.
2. Items of Personal Information Processed, Collection Methods, and Retention Periods
The Company collects and processes the minimum personal information necessary during membership registration or use of the Service. While using the Service, information about the use environment—including IP address, access date and time, Service-use history, browser and operating system—session and cookie information, and error and security logs may be automatically generated and collected. Optional marketing information is not collected during the beta period.
| Legal Basis | Category | Method of Collection | Items Collected and Processed | Retention and Use Period |
|---|---|---|---|---|
| Article 15(1)(4) of the Personal Information Protection Act | ||||
| (Formation and performance of a contract) | Membership registration, login, and Account management | Direct input by the Member and email verification | Email address; password (stored using one-way encryption as a hash value); Account identifier; membership-registration and login date and time; consent history for the Terms of Service and Privacy Policy; hash value of email-verification tokens; and verification result | Until withdrawal from membership or the purpose of processing is fulfilled. Verification tokens and verification-attempt records are deleted within 7 days after issuance or completion of verification. Service data for withdrawn Accounts are deleted from the operational database without delay, and backup copies are successively deleted within up to 30 days. |
| Article 15(1)(4) of the Personal Information Protection Act | ||||
| (Formation and performance of a contract) | Provision of the Rudolphinic™ beta Service | Direct input by the Member and generation during use of the Service | Account identifier; Strategy code; Strategy configuration values and parameters; analysis conditions; Backtest and optimization Deliverables; filter and scoring settings; free beta-usage limit and consumption history; and Service-use history | Until withdrawal from membership or the purpose of processing is fulfilled. Service data for withdrawn Accounts are deleted from the operational database without delay, and backup copies are successively deleted within up to 30 days. |
| Article 15(1)(4) of the Personal Information Protection Act | ||||
| (Performance of a contract or action upon the Data Subject’s request) | Email verification and mandatory Service notices | Direct input by the Member; generation during use of the Service; and transmission through OCI Email Delivery | Email address; date and time of verification and notice delivery; delivery result; and verification result | Until the Account is maintained or the purpose of delivery is fulfilled. Verification tokens and delivery-failure records are retained for up to 7 days. |
| Article 15(1)(4) of the Personal Information Protection Act | ||||
| (Performance of a contract or action upon the Data Subject’s request) | Customer support, inquiry, and dispute handling | Direct input through an in-Service inquiry or email | Email address; Account identifier; inquiry content; attachments; and consultation and handling history | 3 years after completion of inquiry or dispute handling. However, where there is a retention obligation under applicable laws and regulations, until the relevant period ends. |
| Article 15(1)(6) of the Personal Information Protection Act | ||||
| (Legitimate interests) | Security, prevention of improper use, and failure analysis | Automatically collected during use of the Service | IP address; access date and time; login and logout records; Service-use history; session and cookie information; browser and operating-system information; and error and security logs | 1 year from the date of collection or until the purpose of processing is fulfilled. |
| Article 15(1)(4) of the Personal Information Protection Act | ||||
| (Provision of a Service upon the Member’s request) | Optional LLM-based statistical explanations | Member’s request for an explanation and generation during use of the Service | Analysis-request identifier; statistical summary values of analytical results; selected explanation language and format; LLM input prompts; and output results | The same period as retention of the analytical result to which the explanation is linked. The separate retention period of the LLM provider is governed by Section 5. |
3. Provision of Personal Information to Third Parties
The Company does not currently provide Members’ personal information to third parties. However, exceptions apply where permitted by applicable laws and regulations, such as where the Company obtains the separate consent of the Data Subject or a law provides otherwise.
Where the Company entrusts an external service provider with personal-information processing for the performance of processing tasks or transfers personal information overseas, the relevant details are provided in Sections 4 and 5. If provision to a third party occurs in the future, the Company will notify Data Subjects in advance of the recipient, purpose of provision, items provided, retention and use period, and right to refuse consent, and will take the necessary measures.
4. Entrustment of Personal-Information Processing Tasks
For provision of the beta Service, the Company entrusts the following tasks to specialized external service providers. Through entrustment agreements or the data-processing agreements of the relevant Services, the Company establishes and manages provisions concerning prohibition of processing for purposes other than those entrusted, security measures, management of sub-entrustment, and management and supervision of entrusted parties.
| Entrusted Party | Entrusted Task | Personal Information Processed | Retention and Use Period |
|---|---|---|---|
| Oracle Cloud Infrastructure (OCI) | Operation of servers, databases, and backups, and email transmission (OCI Email Delivery) | The Account, Service-use, customer-support, and log information under Section 2, as well as email-verification and notice-delivery information | Until the entrustment agreement ends or the purpose of processing is fulfilled. Backup copies are successively deleted within up to 30 days. |
| Cloudflare, Inc. | Execution of the web application, network security, and request forwarding | Account and Service information contained in web-application requests and responses; IP address; access and security logs; and session information | Until the entrustment agreement ends or the purpose of processing is fulfilled. |
| Framer B.V. | Publishing and hosting of the static website | Website visitor IP addresses, access and use-environment information, and web-request logs | Until the entrustment agreement ends or the purpose of processing is fulfilled. |
| Google LLC | Optional LLM-based statistical explanations using the Gemini API | The optional LLM-based statistical-explanation information under Section 2 | Until the entrustment agreement or API use ends. |
| OpenAI, L.L.C. | Optional LLM-based statistical explanations using the OpenAI API | The optional LLM-based statistical-explanation information under Section 2 | Until the entrustment agreement or API use ends. |
5. Overseas Transfer of Personal Information
For the formation and performance of a contract with a Data Subject under Article 28-8(1)(3) of the Personal Information Protection Act, the Company may transfer overseas the personal information necessary to operate the Service. The Company applies security measures such as encryption in transmission and follows the legal basis and procedures required for overseas transfers under applicable laws and regulations.
| Recipient and Contact Information | Country of Transfer | Time and Method of Transfer | Items Transferred | Purpose of Transfer | Retention and Use Period | Method and Effect of Refusing Transfer |
|---|---|---|---|---|---|---|
| Oracle Corporation and its affiliates (Oracle Cloud Infrastructure, OCI) | ||||||
| Oracle Privacy Inquiry Page | Japan | At membership registration, login, use of the Service, or email verification, through encrypted communications | The Account, Service-use, customer-support, and log information under Section 2, as well as email-verification and notice-delivery information | Operation of servers, databases, and backups, and email verification and notice delivery | For the duration of the entrustment agreement or the purpose of processing. Backup copies are successively deleted within up to 30 days. | The Data Subject may discontinue use of the Service. In that event, use of core features, including Account creation, login, analysis Execution, and email verification, will be restricted. |
| Framer B.V. | ||||||
| legal@framer.com | The Netherlands and the United States | When accessing the website, through encrypted communications | IP address, access and use-environment information, and web-request logs | Publishing and hosting of the static website | For the duration of the agreement with Framer and the purpose of processing | The Data Subject may discontinue use of the website. In that event, use of the Service’s core features is not affected. |
| Cloudflare, Inc. | ||||||
| privacyquestions@cloudflare.com | The United States and countries in which Cloudflare operates its global network | When using the web application, through encrypted communications | Account and Service information contained in web-application requests and responses; IP address; access and security logs; and session information | Execution of the web application, request forwarding, and network security | For the duration of the agreement with Cloudflare and the purpose of processing | The Data Subject may discontinue use of the web application. In that event, use of the Service will be restricted. |
| Google LLC | ||||||
| Google Privacy Help and Inquiry Page | The United States and countries in which Google or its processors operate facilities | Each time a Member requests the explanation feature, through encrypted API communications | Analysis-request identifier; statistical summary values; and explanation prompts and output results | Generation of optional statistical explanations using the Gemini API | The Company retains explanation results for the retention period under Section 2. Google Gemini API input, output, and logs related to security and abuse monitoring are processed in accordance with Google’s applicable terms, privacy policy, and Service operational settings. | The Member may choose not to request or use the explanation feature. In that event, use of the Service’s core features is not affected. |
| OpenAI, L.L.C. | ||||||
| privacy@openai.com | The United States | Each time a Member requests the explanation feature, through encrypted API communications | Analysis-request identifier; statistical summary values; and explanation prompts and output results | Generation of optional statistical explanations using the OpenAI API | The Company retains explanation results for the retention period under Section 2. OpenAI API input, output, and logs related to security and abuse monitoring are processed in accordance with OpenAI’s applicable terms, privacy policy, and Service operational settings. | The Member may choose not to request or use the explanation feature. In that event, use of the Service’s core features is not affected. |
6. Destruction of Personal Information
-
When personal information becomes unnecessary due to the expiration of the retention period, fulfillment of the purpose of processing, withdrawal from membership, or similar circumstances, the Company will destroy the relevant personal information without delay. However, records that must be retained under applicable laws and regulations will be stored and managed separately from other personal information and destroyed without delay after the relevant retention period ends.
Purpose of Retention Legal Basis Retention Period Scope Retained in the Beta Service Records concerning contracts or withdrawal of offers, etc. Act on the Consumer Protection in Electronic Commerce, Etc. 5 years The minimum Account-identification and consent information included in statutory transaction records, such as consent to the Terms, formation, amendment, and termination of service-use agreements ※ Does not include Strategy code, analysis conditions, or analytical Deliverables Records concerning consumer complaints or dispute handling Act on the Consumer Protection in Electronic Commerce, Etc. 3 years Customer inquiry, complaint and dispute-handling records, and results of their handling -
Personal information in electronic-file form is deleted so that it cannot be restored or reproduced. Where data subject to deletion remains in backup copies, it is successively deleted within up to 30 days according to the relevant backup cycle and is neither restored nor separately used during that period.
-
Personal information recorded or stored in paper documents is destroyed by shredding or incineration.
7. Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Rights
- A Data Subject may exercise the following rights with respect to the Company at any time concerning their personal information:
- Request access to the processing of personal information.
- Request correction or deletion where there is an error or similar issue.
- Request suspension of the processing of personal information.
- Withdraw consent and request withdrawal from membership.
- Request transfer of personal information to the extent prescribed by applicable laws and regulations.
- A Data Subject may exercise the rights under Paragraph 1 through functions provided within the Service or through the Personal Information Protection and Related Grievance-Handling Department. Where a legal representative or an agent lawfully authorized by the Data Subject exercises a right, the Company may verify the authority of representation in accordance with applicable laws and regulations.
- Before processing a request by a Data Subject or their agent, the Company may request the minimum information or documents necessary to verify the requester’s identity and authority of representation.
- The Company processes a Data Subject’s request in accordance with the procedures and periods prescribed by applicable laws and regulations. However, if there are grounds for restriction under applicable laws and regulations, such as a duty to retain records under law or a risk of unfairly infringing another person’s life, body, property, or rights and interests, the Company may restrict or reject all or part of a request for access, correction, deletion, or suspension of processing, or postpone its handling. In such cases, the Company will provide guidance on the reason and the method of objection as prescribed by law.
- Records concerning contracts, payments, dispute handling, and similar matters that must be retained separately under applicable laws and regulations are retained separately for the period prescribed in Section 6. A deletion request for such records will be processed after the statutory retention obligation ends.
- Members must keep their personal information accurate and up to date and must not provide a third party’s personal information without authorization or use a third party’s Account.
- The Company does not provide the Service to children under 14 years of age or intentionally collect their personal information. If the Company learns that it has collected the personal information of a child under 14 without the consent of a legal representative, it will take necessary measures without delay.
8. Measures to Ensure the Security of Personal Information
To ensure the security of personal information, the Company takes the following technical, administrative, and physical measures:
- Designation of a person responsible for personal-information protection, establishment of an internal management plan, and management of persons handling personal information
- Minimization of access rights to personal-information processing systems, access controls, and retention and review of access records
- Encryption in transmission (TLS), one-way encryption of passwords, encryption of important information, and separate management of confidential information
- Prevention of malware, vulnerability inspections, security updates, incident response, and backup management
- Physical and logical access controls for servers, databases, and work environments
9. Installation and Operation of Automatic Personal-Information Collection Devices and Matters Concerning Refusal
-
The Company may use automatic collection devices, such as cookies, to maintain login status, secure sessions, and provide the Service. Cookies are small pieces of information transmitted by a website’s operating server and stored in the Member’s browser; when the Member accesses the Service, they may be transmitted to the Company through the browser.
-
The types and purposes of automatic collection devices currently used by the Company are as follows:
Category Purpose Retention Period Method and Effect of Refusal Essential cookies Maintaining login status, session security, authentication, and provision of the Service Until logout or session expiration The Member may refuse storage of cookies in browser settings, but login, authentication, or use of some Services may be restricted. Personalized advertising and optional analytics cookies Not currently used Not applicable Not applicable -
Members may allow or block the storage of cookies through their web-browser settings. For specific configuration methods, consult the help or settings menu of the browser in use.
-
If the Company introduces cookies for personalized advertising, optional analytics, or collection of third-party online behavioral information in the future, it will follow the notice and consent procedures required by applicable laws and regulations and update this Policy.
10. Personal Information Protection and Related Grievance-Handling Department
-
The Company operates the department below to oversee personal-information processing and to handle Data Subjects’ inquiries, complaints, and remedies for damage related to personal-information processing.
Category Department Contact Information Personal-information protection and grievance-handling department Hanco Lab Customer Support contact@hancolab.com -
A Data Subject may contact the department above concerning all matters related to personal-information protection arising from use of the Company’s Service, including inquiries, requests for access, handling of complaints, and remedies for damage. The Company will process them in accordance with the procedures and periods prescribed by applicable laws and regulations.
11. Remedies for Infringement of Rights and Interests of Data Subjects
To obtain relief for an infringement of personal information, a Data Subject may request consultation or dispute mediation from the institutions below. The Company will endeavor to give priority to handling Data Subjects’ personal-information-related inquiries, requests for access, correction, deletion, or suspension of processing, and complaints.
- Personal Information Infringement Report Center (118 without area code / privacy.kisa.or.kr)
- Personal Information Dispute Mediation Committee (1833-6972 without area code / www.kopico.go.kr)
- Supreme Prosecutors’ Office (1301 without area code / www.spo.go.kr)
- National Police Agency Cyber Safety Bureau (182 without area code / ecrm.police.go.kr)
12. Changes to the Privacy Policy
- If content is added to, deleted from, or revised in this Policy, the Company will notify Data Subjects of the effective date and major changes through an in-Service notice or another reasonable method.
- Where a change materially affects the rights of Data Subjects, the Company will, in principle, provide notice at least 30 days before the effective date. For other changes, the Company will, in principle, provide notice at least 7 days before the effective date. However, where applicable laws and regulations require a longer notice period or separate consent, those requirements apply.
- The Company will make previous versions of the Privacy Policy available on the Privacy Policy history page within the Service.
This Policy applies from its effective date.