AI 데이터 처리 정책AI Data Processing Policy

시행일: 2026-06-22 · 최종 수정일: 2026-08-26 Effective date: 2026-06-22 · Last updated: 2026-08-26

본 정책은 주식회사 베리티(이하 “회사”)의 감사 워크플로우 소프트웨어(AuditMind)에서 AI 기능이 데이터를 처리하는 방식을 설명합니다. 구체적인 처리 경로, 제공자, 보존기간 및 배포 통제는 개별 고객과의 계약 및 배포 구성에서 정합니다. This policy explains how AI features in the audit workflow software (AuditMind) of Verity Co., Ltd., a corporation organized under the laws of the Republic of Korea (the “Company”), process data. Specific processing paths, providers, retention periods, and deployment controls are defined in the applicable customer agreement and deployment configuration.

1. 처리되는 자료 유형1. Types of Data Processed

2. 데이터가 전달될 수 있는 클라우드/AI 제공자2. Cloud/AI Providers Data May Be Sent To

분석·문서 처리를 위해 다음과 같은 제3자 AI/클라우드 제공자에게 데이터가 전달될 수 있습니다. 특정 배포에 실제로 적용되는 제공자는 해당 고객과의 계약 및 배포 구성에서 정합니다.Data may be sent to the following third-party AI/cloud providers for analysis and document processing. The providers that apply to a given deployment are set out in that customer's agreement and deployment configuration.

3. 국외 이전 여부 및 국가3. Overseas Transfer and Countries

제공자의 처리 위치에 따라 처리 국가가 다릅니다. AWS, Supabase는 대한민국 서울(ap-northeast-2)에서, Azure OpenAI는 대한민국 Korea Central에서 처리됩니다. Vercel은 서버 함수를 대한민국 서울(icn1)에서 운영하되 CDN은 글로벌 네트워크를 사용합니다. OpenAI API 및 Anthropic Claude API는 글로벌 처리 환경에서, 업무용 이메일(Google Workspace)과 트랜잭션 이메일(Resend)은 미국에서 처리됩니다. 즉, 모든 처리가 국내에서만 이루어지는 것은 아니며 일부 처리는 국외에서 이루어집니다. 국외 이전의 구체적 항목·목적·보유기간은 개인정보처리방침에 명시하고 법령상 요구되는 절차를 따릅니다.Processing countries differ depending on each provider's processing location. AWS and Supabase process data in Seoul, Republic of Korea (ap-northeast-2), and Azure OpenAI in Korea Central, Republic of Korea. Vercel runs server functions in Seoul, Republic of Korea (icn1) but uses a global CDN network. OpenAI API and Anthropic Claude API process data in a global processing environment, and business email (Google Workspace) and transactional email (Resend) are processed in the United States. Accordingly, not all processing takes place solely within Korea; some processing occurs overseas. The specific items, purposes and retention periods for overseas transfers are specified in the Privacy Policy and follow procedures required by law.

4. 보존기간 및 삭제4. Retention and Deletion

AI 처리를 위해 전달된 데이터의 보존기간은 제공자의 처리 정책 및 회사와 각 제공자 간 계약에 따릅니다. OpenAI API에는 아래 5항의 Zero Data Retention(ZDR) 조건이 적용됩니다. ZDR이 적용되지 않는 제공자의 경우 기본적으로 최대 30일의 오남용 모니터링 목적 보존기간 또는 계약상 보유기간이 적용될 수 있습니다. 회사는 고객 계약 종료 또는 삭제 요청 시 정해진 절차에 따라 데이터를 삭제합니다.Retention of data sent for AI processing follows each provider's processing policy and the contract between the Company and that provider. The OpenAI API is subject to the Zero Data Retention terms described in Section 5 below. For providers not covered by Zero Data Retention, an abuse-monitoring retention period of up to 30 days, or the retention period under the applicable contract, may apply by default. Upon contract termination or a deletion request, the Company deletes data per defined procedures.

5. 계약상 데이터 보호장치 (DPA · Zero Data Retention)5. Contractual Data Protections (DPA and Zero Data Retention)

회사는 OpenAI OpCo, LLC와 데이터 처리 부속합의서(Data Processing Addendum, DPA) 및 Modified Data Retention Amendment를 체결하였습니다. 아래는 그 적용 범위입니다.The Company has executed a Data Processing Addendum (DPA) and a Modified Data Retention Amendment with OpenAI OpCo, LLC. Their scope is as follows.

5.1 데이터 처리 부속합의서(DPA)5.1 Data Processing Addendum

5.2 Zero Data Retention 적용 범위5.2 Scope of Zero Data Retention

회사는 OpenAI 데이터 보존 통제에 대한 승인을 받았으며, AuditMind 처리에 지정된 OpenAI 프로젝트에 Zero Data Retention이 활성화되어 있습니다. Zero Data Retention의 적용 범위는 사용하는 엔드포인트와 기능에 따라 달라집니다.The Company has been approved for OpenAI data-retention controls, and Zero Data Retention is enabled for the OpenAI projects designated for applicable AuditMind processing. The scope of Zero Data Retention depends on the endpoint and feature used.

OpenAI가 Zero Data Retention 적용 대상으로 정한 엔드포인트 및 기능에서는, OpenAI의 해당 문서에 기재된 제한에 따라 고객 콘텐츠가 오남용 모니터링 로그에서 제외되며 애플리케이션 상태로 보존되지 않습니다.For endpoints and features identified by OpenAI as eligible for Zero Data Retention, Customer Content is excluded from abuse-monitoring logs and is not retained as application state, subject to the limitations in OpenAI's applicable documentation.

일부 엔드포인트 및 기능은 Zero Data Retention 적용 대상이 아니며, 해당 기능 제공에 필요한 기간 동안 애플리케이션 상태를 보존할 수 있습니다. 이미지 및 파일 입력은 자동 안전성 검사 대상이 될 수 있으며, OpenAI의 해당 문서에서 정한 제한적 상황에서 사람의 검토를 위해 보존될 수 있습니다.Certain endpoints and features are not eligible for Zero Data Retention and may retain application state for the period required to provide that feature. Image and file inputs may also be subject to automated safety scanning and, in limited circumstances described in OpenAI's applicable documentation, may be retained for manual review.

적용되는 AI 공급자, 엔드포인트, 보존 구성 및 처리 리전은 고객의 배포 구성과 계약에 따라 정합니다. Zero Data Retention은 해당 OpenAI API 처리 경로에만 적용되며, 다른 AI 또는 클라우드 공급자에게 자동으로 적용되지 않습니다.The applicable AI provider, endpoint, retention configuration and processing region are determined by the customer's deployment configuration and agreement. Zero Data Retention applies only to the applicable OpenAI API processing path and does not automatically apply to other AI or cloud providers.

회사가 체결한 OpenAI DPA 및 해당 데이터 보존 부속합의서 사본은 고객 실사 과정에서 비밀유지 조건으로 제공할 수 있습니다.Copies of the Company's executed OpenAI DPA and applicable data-retention amendment may be provided under confidentiality during customer due diligence.

6. 고객 데이터의 모델 학습 사용 여부6. Use of Customer Data for Model Training

회사는 AI 서비스 제공자에게 고객 데이터 또는 고객 문서 내용을 모델 학습 목적으로 제공하거나 학습 사용을 허용하지 않습니다. 회사는 엔터프라이즈/API 등급의 계약 조건을 통해 제공자가 입력·출력 데이터를 모델 학습에 사용하지 않도록 합니다. 다만 서비스 운영, 보안, 오남용 방지 및 법령상 의무 이행을 위하여 각 제공자의 계약 및 정책에 따른 제한적 보관이 발생할 수 있습니다.The Company does not provide customer data or customer document contents to AI service providers for model-training purposes, nor permit their use for training. Through enterprise/API-tier contract terms, the Company ensures that providers do not use input or output data for model training. However, limited retention under each provider's contracts and policies may occur for service operation, security, abuse prevention and compliance with legal obligations.

7. 고객별 데이터 격리7. Per-Customer Data Isolation

AI 처리 과정에서도 권한 기반 접근통제와 테넌트 격리 원칙을 적용하여, 한 고객의 데이터가 다른 고객의 처리에 사용되지 않도록 구성합니다.Permission-based access control and tenant isolation are applied during AI processing so that one customer's data is not used in another customer's processing.

8. 고객의 삭제·내보내기 요청8. Deletion and Export Requests

고객은 info@verityaudits.com 으로 데이터 삭제 또는 내보내기를 요청할 수 있으며, 회사는 계약 및 법령에서 정한 절차·기한에 따라 처리합니다.Customers may request deletion or export of data at info@verityaudits.com, and the Company processes such requests per the procedures and timelines set by the contract and applicable law.

9. 보안사고 통지 절차9. Incident Notification

AI 처리 경로를 포함한 데이터 침해사고를 인지한 경우, 관련 법령 및 계약에 따라 영향을 받는 고객에게 통지하고 필요한 조치를 취합니다.Upon becoming aware of a data breach, including via the AI processing path, the Company notifies affected customers and takes necessary measures in accordance with applicable law and the contract.

10. 문의10. Contact

AI 데이터 처리 관련 문의: info@verityaudits.comAI data-processing inquiries: info@verityaudits.com