MAIPOLE legal
Privacy Policy
This Policy explains how Reshenie Co., Ltd. processes personal data in the hosted MAIPOLE service. An organization running MAIPOLE on premises is responsible for its own deployment and privacy notice; Reshenie processes its data only to the extent described in a support or data processing agreement.
1. Controller and privacy contact
Reshenie Co., Ltd. (business registration number 149-86-02229), represented by Yongkwan Lee, is the controller for account administration, hosted-service operation, billing, security, legal compliance, and its own communications.
Personal Information Protection Officer: Yongkwan Lee, RepresentativeRoom 601, Gwanggyo Flex Desian, 50 Changnyong-daero 256beon-gil,
Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea
Email: info@reshenie.co.kr
Phone: +82 070-8285-2269
Contact us through these channels to ask a privacy question, make a complaint, or exercise a right. Please do not send passwords, authentication codes, full payment-card details, or sensitive industrial secrets by email.
2. Our role for Customer Data
A customer organization normally decides why and how personal data in its tenant is used, including data about its employees, contractors, visitors, equipment users, camera subjects, and alert recipients. For that Customer Data, the customer is the controller and Reshenie is its processor, acting under the customer's documented instructions and the applicable data processing agreement.
Requests concerning Customer Data should first be sent to the relevant customer. We will assist the customer with access, deletion, correction, security, incident response, impact assessments, and regulator enquiries as required by contract and applicable law. We do not use one customer's identifiable Customer Data to advertise to another customer or to train a general-purpose model unless the customer separately and expressly agrees.
3. Data, purposes, legal bases, and retention
The table describes MAIPOLE's current processing. "Contract" includes steps requested before a contract and performance of the service; "legitimate interests" means operating a secure, reliable B2B service while balancing individual rights.
| Activity and data | Purpose and legal basis | Retention |
|---|---|---|
| Account and tenant administration. Identity subject ID, name, email, email-verification state, role, organization membership, invitations, preferences, permissions, and multi-factor status. | Create and authenticate accounts, administer tenants, enforce access, and communicate about the service. Contract; legitimate interests in access control; legal obligations where applicable. | For the account and service relationship. Account records are deleted when the account is deleted, except linked records that must be retained or de-identified. Pending or historical invitation records remain only as needed for security, disputes, and administration. |
| Authentication and browser state. Session ID, encrypted identity-provider tokens, login time and expiry, OIDC state, nonce and verifier, theme, UI and analytics-consent preferences, and temporary one-use handoff or remote-session data. | Sign users in, preserve secure sessions, prevent request forgery, and remember requested settings. Contract; strictly necessary service operation; legitimate interests in security. | Authentication cookies expire with the identity session; temporary OIDC cookies expire after 5–10 minutes. Server sessions end at expiry, sign-out, or account deletion. Local or session storage remains until it expires, is consumed, or the user clears browser data. |
| Tenant and industrial operations. Company, lines, machines, DataStone and other device configuration, device identifiers and network endpoints, telemetry, thresholds, alerts, commands, WebRTC session metadata, dashboards, and operational activity. | Provide customer-requested monitoring, connectivity, alerts, analysis, remote support, and equipment operations. Customer instructions and contract. The customer must establish any legal basis required for identifiable worker, visitor, or camera data. | For the customer-selected service term and instructions. If the last user leaves a hosted tenant, it is marked orphaned and scheduled for deletion after a 14-day recovery period. Alert event and delivery history is ordinarily cleaned after 365 days. |
| Files, workflows, and support. Uploaded files and versions, file names and content types, uploader ID/name/email, chat or support text, attachments, job inputs and outputs, datasets, models, and troubleshooting material. | Store and share tenant files, perform requested analytics or machine-learning jobs, and provide support. Customer instructions and contract; legitimate interests in resolving incidents and improving support. | Until the customer deletes the material, the tenant is deleted, or the relevant support matter ends, subject to contractual and legal retention. Restricted backup copies may remain until the normal backup rotation completes and are used only for recovery or security. |
| Phone verification and notifications. User ID, phone number, verification state and challenge metadata, IP address, session ID, CAPTCHA result, KakaoTalk opt-in, recipients, Slack webhook, and quiet-hour settings. | Verify an optional phone number and deliver customer-configured operational alerts. Contract or the user's request; consent where required for electronic communications; legitimate interests in preventing abuse. | The verified number and preferences remain until removed, the account is deleted, or the service ends. Verification challenges and delivery records follow the notification service's anti-abuse and operational retention schedule. Terminal MAIPOLE alert history is ordinarily cleaned after 365 days. |
| Billing and payment. Tenant, plan and add-ons, order and receipt IDs, price, currency, status, billing periods, renewal attempts, payment-provider billing token, card brand/name and masked card number, billing email, and transaction timestamps. | Process subscriptions, renewals, receipts, refunds, accounting, and payment disputes. Contract; tax, accounting, and electronic-commerce obligations; legitimate interests in preventing payment fraud. | For the subscription relationship and then for the period required by tax, accounting, electronic-commerce, and limitation laws. Where Korean electronic-commerce recordkeeping applies, contract and payment records are generally retained for five years. MAIPOLE does not store the full card number or card security code. |
| Security and audit events. Actor ID/email or API-key label, tenant snapshot, action, affected resource, result, relevant before/after state, path, IP address, user agent, timestamps, and correlation ID. | Detect and investigate misuse, maintain accountability, respond to incidents, and establish or defend claims. Legitimate interests in service and network security; contract; legal obligations. | Audit events are append-only during their retention period and expire 365 days after the event. They may remain after an account or tenant is deleted to preserve security evidence, with identifiers limited to what the event recorded. |
| Optional Google Analytics. Page path and title, event name, connection-quality diagnostics about WebRTC (stage/status parameters), pseudonymous truncated hashes of tenant/device/widget identifiers, device or cookie identifiers, and an IP address used during transmission and location derivation. | Measure service use and diagnose reliability, based on your consent. Analytics is not required for MAIPOLE's core functions. | Only after you allow analytics in a deployment that configures a Google Analytics measurement ID. Collection stops when you withdraw. Event-data retention follows the configured Analytics property and Google's service controls. The standard repository configuration leaves this integration disabled. |
4. Sources and required information
We receive data directly from users, customer administrators, connected DataStone devices and industrial systems, customer-selected integrations, payment or identity responses, and automatically generated service and security logs. A customer may provide an employee's or contractor's business details when creating a tenant, invitation, alert, or support request.
Name, business email, authentication data, and tenant membership are generally required to use protected hosted functions. Refusing them prevents account or service access. Phone number, KakaoTalk alerts, optional files, and analytics are optional, although a feature that needs them will not work without the relevant data. The fields and price shown during a paid checkout are required to complete that transaction.
5. Recipients and service providers
Access is limited to authorized customer users, Reshenie personnel who need it for service, security, billing, or support, and the providers below. We may also disclose data when a law or binding process requires it, to protect people or systems, or in a corporate transaction subject to appropriate confidentiality and notice.
- NAVER Cloud Corp. — Korean cloud, Kubernetes, networking, database/storage, backup, and object-storage infrastructure for the hosted service.
- Bootpay Co., Ltd. and its payment network participants. — payment entry, authorization, receipt verification, recurring billing, and refunds when hosted billing is enabled.
- Reshenie-operated identity, WebRTC signaling, AutoML, and notification services. — authentication, P2P session establishment, requested model workflows, phone verification, and alerts. A configured email, SMS/KakaoTalk, CAPTCHA, or Slack provider receives only the information necessary for that channel.
- Google LLC. — Google Analytics only if the deployment enables it; page and product-reliability events are sent under Google's data-processing terms.
- Customer-selected systems. — connected devices, identity providers, endpoints, or integrations chosen and controlled by the customer.
Provider names can differ for an on-premises or separately contracted environment. The relevant customer or Reshenie privacy contact can provide the current deployment-specific list. We require processors to protect personal data and use it only for the contracted purpose.
6. International transfers
The primary hosted MAIPOLE environment and object storage are configured in the Republic of Korea. Personal data may nevertheless be accessed from another country by an authorized customer user or transferred through a customer-selected integration. Google Analytics, if enabled, may process data in countries where Google and its subprocessors operate.
For personal data transferred from the EEA to Reshenie in Korea, we may rely on the European Commission's Korea adequacy decision where it applies. For transfers not covered by adequacy, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and supplementary measures after assessing the transfer. Optional Google Analytics transfers are governed by Google's disclosed transfer mechanisms. Contact us for a copy or description of the relevant safeguard.
7. Cookies, local storage, and analytics choices
MAIPOLE uses a necessary HTTP-only session cookie and short-lived OIDC cookies for login and request protection. It uses local storage for theme and interface preferences and session storage for limited one-use registration or remote-session handoffs. Blocking necessary storage can prevent sign-in or requested features.
Google Analytics is disabled unless a measurement ID is configured. If configured, MAIPOLE presents an analytics choice and does not load the Google script or send analytics events before you select “Allow analytics.” You can refuse without losing core functions and later reopen “Privacy choices” to withdraw or grant consent. Withdrawing blocks new MAIPOLE analytics events and removes accessible Google Analytics cookies. We disable Google advertising signals and do not use MAIPOLE Analytics events for advertising personalization. This analytics choice does not enable, disable, carry, or control the DataStone WebRTC connection itself.
8. Your rights
Subject to applicable law, you may request access, a copy, correction, deletion, restriction or suspension of processing, portability of data you provided, or objection to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You may also delete your MAIPOLE account in profile settings; tenant data can be affected by your administrator role and the 14-day orphan recovery process.
We may need to verify your identity and authority and may retain or refuse deletion of data where law, security, another person's rights, or an unresolved claim requires it. Under the GDPR, we normally respond within one month; a complex or numerous request may be extended by up to two additional months with notice. We do not discriminate against a person for making a privacy request.
You may complain to the Korean Personal Information Protection Commission or your local data protection authority. Korean support channels include the Personal Information Infringement Report Center (118) and the Personal Information Dispute Mediation Committee (+82 1833-6972). EEA residents may complain to the authority where they live, work, or believe an infringement occurred.
9. Automated analysis
MAIPOLE may calculate thresholds, anomaly scores, forecasts, or other industrial analytics. Reshenie does not use those outputs to make solely automated decisions about a person that produce legal or similarly significant effects. A customer that applies MAIPOLE outputs to employment, safety, access, or another significant decision must provide required notice, human review, and a lawful basis and must independently validate the output.
10. Security and incident response
MAIPOLE uses measures designed to match the risk, including encrypted network transport, OIDC authentication, role- and tenant-based access controls, optional multi-factor authentication, encrypted stored session tokens, protected secrets, request-origin checks, file and input limits, audit events, and operational backup and incident procedures. Access is limited according to role and operational need. No system can guarantee absolute security.
If a personal-data breach occurs, we will investigate, contain, document, and notify affected controllers, individuals, or authorities within the periods required by applicable law. Please report a suspected incident promptly to info@reshenie.co.kr.
11. Children and sensitive data
MAIPOLE is a business and professional service, not a service directed to children. Do not provide personal data about a child or special-category/sensitive data unless the customer has confirmed a lawful purpose, completed any required assessment, and agreed suitable safeguards with Reshenie. We may remove unnecessarily submitted sensitive data.
12. Changes to this Policy
We will post an updated Policy and effective date here. We will provide reasonable advance notice of a material change to purposes, data categories, recipients, transfers, or rights, unless immediate notice is required for law or security. A new purpose that requires consent will not apply until valid consent is obtained. Previous versions may be requested through the privacy contact.