개인정보 처리방침

시행일: 2026년 8월 20일 | 최종 수정: 2026년 8월 13일

그린다에이아이주식회사(이하 "회사")는 「개인정보 보호법」 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.

제1조 (개인정보의 처리 목적)

회사는 다음의 목적을 위하여 개인정보를 처리합니다. 처리하고 있는 개인정보는 다음의 목적 이외의 용도로는 이용되지 않으며, 이용 목적이 변경되는 경우에는 별도의 동의를 받는 등 필요한 조치를 이행합니다.

회원 가입 및 관리:

회원 가입의사 확인, 회원제 서비스 제공에 따른 본인 식별·인증, 회원자격 유지·관리, 서비스 부정이용 방지, 각종 고지·통지, 고충처리

서비스 제공:

AI 기반 리드 발굴, 이메일 자동화, 다국어 번역, 캠페인 분석 등 서비스 제공, 콘텐츠 제공, 맞춤 서비스 제공. 가입 시 수집한 국가 정보를 기반으로 서비스 지역·언어 최적화, 수출 원산지 추정, 결제 통화 결정에 이용합니다.

결제 및 정산:

유료 서비스 이용에 따른 요금 결제·정산, 구독 관리, 환불 처리

마케팅 및 광고:

신규 서비스 안내, 이벤트 및 광고성 정보 제공 (동의 시)

AI 기반 바이어 리서치:

AI 기술을 활용한 잠재 바이어 정보 수집·분석, 기업 웹사이트 정보 추출, 바이어 리드 스코어링 및 이메일 연락처 탐색

제2조 (수집하는 개인정보 항목)

구분

수집 항목

수집 방법

필수정보

이메일, 이름, 회사명, 비밀번호(자체 가입 시), 온보딩 설문 정보(업종, 타겟 시장, 수출 대상 국가, 수출 경험 여부 등)

회원가입, 소셜 로그인

소셜 로그인 추가수집

프로필 사진 URL, 소셜 계정 식별자

Google OAuth 연동 시 자동 수집

결제정보

결제수단 정보(카드사명, 카드번호 일부), 결제 금액, 결제 일시

결제 시 수집

자동수집

IP주소, 브라우저 정보, 접속 기록, 쿠키, 서비스 이용 기록, 국가·지역 정보(IP 주소 기반 추정 국가코드)

서비스 이용 시 자동 수집

결제 정보 보안 안내:

신용카드 번호, CVC 등 민감한 결제 정보는 회사가 직접 저장하지 않습니다. 국내 결제는 PCI-DSS 인증을 받은 토스페이먼츠를 통해, 해외 결제는 PCI-DSS Level 1 인증을 받은 Paddle.com Market Ltd를 통해 안전하게 처리됩니다.

제3조 (개인정보의 처리 및 보유 기간)

회사는 법령에 따른 개인정보 보유·이용기간 또는 정보주체로부터 개인정보를 수집 시에 동의받은 개인정보 보유·이용기간 내에서 개인정보를 처리·보유합니다.

항목

보유 기간

근거

회원 정보

회원 탈퇴 시까지

정보주체 동의

계약/구독 기록

5년

전자상거래법 제6조

결제 및 대금결제 기록

소비자 불만/분쟁 처리 기록

3년

접속 기록

1년

통신비밀보호법 제15조의2

제4조 (개인정보의 제3자 제공)

회사는 원칙적으로 정보주체의 개인정보를 수집·이용 목적으로 명시한 범위 내에서 처리하며, 다음의 경우를 제외하고는 정보주체의 사전 동의 없이 본래의 목적 범위를 초과하여 처리하거나 제3자에게 제공하지 않습니다.

정보주체로부터 별도의 동의를 받은 경우

법률에 특별한 규정이 있는 경우

정보주체 또는 그 법정대리인이 의사표시를 할 수 없는 상태에 있거나 주소불명 등으로 사전 동의를 받을 수 없는 경우로서 명백히 정보주체 또는 제3자의 급박한 생명, 신체, 재산의 이익을 위하여 필요하다고 인정되는 경우

제5조 (개인정보 처리의 위탁)

회사는 원활한 서비스 제공을 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.

수탁업체

위탁 업무

보유 기간

위탁 계약 종료 시

토스페이먼츠㈜

결제 처리 및 대행

Paddle.com Market Ltd

해외 결제 처리, 세금 징수 및 송금 (Merchant of Record)

Amazon Web Services, Inc.

클라우드 서버 운영

Twilio SendGrid, Inc.

이메일 발송 및 수신거부·반송 처리

Google LLC

소셜 로그인(OAuth) 인증

Google LLC

AI 기반 리드 분석(Gemini API)

Hunter.io

이메일 리드 탐색 서비스

Jina AI GmbH

기업 웹사이트 정보 추출

제6조 (정보주체의 권리·의무 및 행사방법)

정보주체는 회사에 대해 언제든지 다음 각 호의 개인정보 보호 관련 권리를 행사할 수 있습니다:

개인정보 열람 요구

오류 등이 있을 경우 정정 요구

삭제 요구

처리정지 요구

권리 행사는 서면, 전자우편, 고객센터를 통하여 하실 수 있으며, 회사는 이에 대해 지체없이 조치하겠습니다.

권리 행사는 정보주체의 법정대리인이나 위임을 받은 자 등 대리인을 통하여 하실 수도 있습니다.

제6조의2 (개인정보·앱 데이터 삭제 요청)

이 조는 웹 서비스와 안드로이드 앱 Rinda Field(패키지명 ai.grinda.telinfo)에 모두 적용됩니다. 두 서비스는 그린다에이아이주식회사가 운영합니다.

삭제를 요청하는 방법

[email protected] 로 메일을 보냅니다. 제목에 「데이터 삭제 요청」을 적어 주세요.

본문에 가입하신 이메일 주소와, 계정 전체를 삭제할지 앱에서 수집한 데이터만 삭제할지를 적어 주세요.

본인 확인 후 접수일로부터 30일 이내에 처리하고 결과를 회신합니다.

앱에서 직접 지우는 방법

명함과 미팅 기록은 앱 안에서 건별로 삭제할 수 있고, [설정 > 내 계정 > 다른 계정으로 연결]에서 이 기기의 연결을 해제하면 기기에 저장된 사진·녹음도 함께 지워집니다.

삭제 요청 시 지워지는 것

계정 정보, 명함 사진과 인식 결과, 미팅·통화 녹음 파일과 전사·AI 요약, 동의 후 전송된 통화기록을 지체 없이 파기합니다.

삭제 요청 후에도 남는 것

법령이 보관을 요구하는 기록은 그 기간 동안 분리 보관 후 파기합니다. 계약·구독 및 결제 기록 5년, 소비자 불만·분쟁 처리 기록 3년, 접속 기록 1년입니다(제3조와 동일).

제7조 (개인정보의 파기)

회사는 개인정보 보유기간의 경과, 처리목적 달성 등 개인정보가 불필요하게 되었을 때에는 지체없이 해당 개인정보를 파기합니다.

전자적 파일 형태의 정보는 복구 및 재생할 수 없도록 기술적 방법을 사용하여 완전하게 삭제하고, 기록물, 인쇄물, 서면 등은 분쇄하거나 소각하여 파기합니다.

제8조 (개인정보의 안전성 확보 조치)

회사는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다:

관리적 조치:

내부관리계획 수립·시행, 직원 교육 등

기술적 조치:

개인정보처리시스템 접근권한 관리, 전송구간 TLS 암호화 및 민감정보(문자메시지·통화기록·통화 전사·AI 요약)의 저장 시 AES-256 암호화 적용, 보안프로그램 설치

물리적 조치:

전산실, 자료보관실 등의 접근 통제

제9조 (쿠키의 설치·운영 및 거부)

회사는 이용자에게 개별적인 맞춤서비스를 제공하기 위해 이용정보를 저장하고 수시로 불러오는 '쿠키(cookie)'를 사용합니다.

쿠키는 웹사이트를 운영하는데 이용되는 서버가 이용자의 컴퓨터 브라우저에게 보내는 소량의 정보이며 이용자 컴퓨터의 하드디스크에 저장됩니다.

이용자는 쿠키 설치에 대한 선택권을 가지고 있습니다. 웹브라우저에서 옵션을 설정함으로써 모든 쿠키를 허용하거나, 쿠키가 저장될 때마다 확인을 거치거나, 모든 쿠키의 저장을 거부할 수 있습니다.

제10조 (개인정보 보호책임자)

회사는 개인정보 처리에 관한 업무를 총괄해서 책임지고, 개인정보 처리와 관련한 정보주체의 불만처리 및 피해구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.

개인정보 보호책임자

성명: 강호진

직책: 대표이사

연락처:

이메일:

부칙

이 개인정보 처리방침은 2026년 8월 20일부터 시행합니다.

Google LLC

서비스 이용 행태 분석(Google Analytics)

Mixpanel, Inc.

서비스 이용 행태 분석(Mixpanel)

모바일 애플리케이션(Rinda Field) 관련 개인정보 처리

이용자가 안드로이드 앱 "Rinda Field"(패키지명 ai.grinda.telinfo)를 이용하는 경우, 통화·문자·녹음의 통합 관리와 박람회 현장에서의 명함 수집·미팅 기록이라는 앱의 핵심 기능을 제공하기 위하여 다음 개인정보가 추가로 처리됩니다. 통화기록의 서버 전송은 앱 최초 실행 시 표시되는 동의 안내에 명시적으로 동의한 경우에만 이루어지며, 녹음 파일 업로드·연락처 조회·명함 촬영·미팅 녹음은 각각 해당 기능의 안드로이드 권한을 허용하고 이용자가 그 기능을 실행한 경우에만 작동합니다. 이 데이터는 어떠한 경우에도 광고·마케팅 목적으로 사용되지 않습니다.

통화기록

발신자명, 전화번호, 통화 방향(수신/발신), 통화 시각을 이용자의 명시적 동의(최초 1회 동의 다이얼로그) 후 서버로 전송하여 통화 상대 식별 및 통화 인사이트 제공에 사용합니다.

문자메시지(SMS)

문자메시지는 기기 안에서만 읽어 앱 화면에 표시하며, 발신·수신 번호와 본문 모두 회사 서버로 전송하거나 저장하지 않습니다. 수신함·발신함을 읽기 전용으로 조회하며, 실시간 수신 가로채기(broadcast)는 사용하지 않습니다.

통화 녹음 파일

기기에 이미 저장되어 있는 통화 녹음 오디오 파일을 읽어 AWS S3(대한민국 서울 리전)에 업로드하고 음성-텍스트 변환(STT) 및 AI 요약·분석을 제공합니다. 회사는 이용자의 통화를 앱에서 직접 녹음하지 않으며, 기기(제조사 기본 통화 앱 등)가 생성해 둔 파일만 처리합니다(현장 미팅 녹음은 아래 별도 항목 참조). 전사(STT)된 텍스트는 저장 전 전화번호·카드번호·계좌번호·주민등록번호가 자동으로 마스킹 처리됩니다(마스킹은 녹음 전사 텍스트에 한해 적용됩니다).

연락처

발신자 이름 표시를 위하여 기기 안에서만 조회하며, 연락처 자체를 서버로 업로드하지 않습니다.

기기 식별자

기기 인증 토큰의 발급·검증을 위한 앱 자체 생성 기기 식별자를 처리합니다. 이는 광고 식별자(ADID)나 IMEI 등 하드웨어 고유 식별자가 아니며, 기기·워크스페이스 연결 확인 용도로만 사용됩니다.

서비스 이용·오류 기록

서비스 안정성 및 품질 개선을 위하여 앱 화면 이동·기능 사용 통계와 오류 로그를 처리합니다(telemetry.rinda.ai).

명함 이미지

이용자가 박람회 현장에서 촬영한 명함 사진을 AWS S3(대한민국 서울 리전)에 업로드하여 AI 광학문자인식(OCR)으로 기재 정보를 추출합니다. 카메라는 이용자가 명함 촬영 화면에 직접 진입한 경우에만 작동하며, 촬영본은 인터넷이 끊긴 경우 기기에 임시 보관되었다가 연결이 복구되면 전송됩니다. 사진첩에서 불러오는 경우에는 안드로이드 시스템 사진 선택 도구를 통해 이용자가 직접 고른 사진만 앱에 전달되며, 앱은 사진첩 전체를 조회하지 않고 사진 접근 권한도 요청하지 않습니다.

명함에서 추출한 제3자 정보

명함 이미지에서 회사명, 담당자 이름, 직책, 이메일 주소, 전화번호, 웹사이트, 주소를 추출하여 이용자의 워크스페이스에 바이어 리드로 등록합니다. 이 정보의 정보주체는 앱 이용자 본인이 아니라 명함을 건넨 상대방(제3자)입니다. 회사는 이 정보를 이용자를 대신하여 처리하는 수탁자의 지위에 있으며, 명함 제공자와의 관계에서 수집의 적법성(명함 교환이라는 사회통념상 예정된 범위 내의 이용, 필요한 경우 별도 고지·동의)에 대한 책임은 해당 명함을 수집한 이용자에게 있습니다. 추출된 정보는 이용자 워크스페이스의 영업 활동 목적으로만 사용되며, 회사가 자체 마케팅이나 제3자 판매에 이용하지 않습니다.

현장 미팅 녹음

이용자가 명함 카드에서 [미팅 기록 시작]을 누르고 녹음 시작 버튼을 누른 경우에 한하여, 앱이 기기 마이크로 대면 미팅의 음성을 직접 녹음합니다. 녹음은 이용자가 정지를 누를 때까지만 이루어지며, 백그라운드나 상시 녹음은 하지 않습니다. 녹음 파일은 AWS S3(대한민국 서울 리전)에 업로드되어 음성-텍스트 변환(STT) 및 AI 요약을 거칩니다. 대면 대화에는 이용자 외의 참석자가 포함되므로, 녹음 전 참석자에게 고지하고 필요한 동의를 얻을 책임은 이용자에게 있습니다.

[민감정보 처리] 통화 녹음의 음성 및 통화 내용은 민감할 수 있는 정보로, 이용자가 녹음 업로드 기능을 사용하는 경우에 한하여 처리됩니다. 전사·요약된 통화 내용은 같은 워크스페이스의 권한 있는 구성원에게 표시될 수 있으므로, 특정 녹음을 공유하지 않으려면 앱에서 해당 녹음을 업로드하지 않거나 업로드된 녹음을 삭제할 수 있습니다.

[처리위탁 및 국외이전] 회사는 위 기능 제공을 위하여 다음과 같이 개인정보 처리를 위탁합니다. ▲ 녹음 오디오 파일 및 명함 이미지 저장 — Amazon Web Services(대한민국 서울 ap-northeast-2 리전에 저장, 국내 보관). ▲ 녹음 음성의 텍스트 변환 및 AI 분석, 명함 이미지의 광학문자인식(OCR) 및 정보 추출 — OpenAI, L.L.C. 및 Google LLC. 이 과정에서 녹음 오디오·전사 텍스트 및 명함 이미지·추출 정보가 미국으로 이전(국외이전)될 수 있습니다. 국외이전 개인정보 항목: 통화·현장 미팅 녹음 오디오 및 전사 텍스트, 명함 이미지 및 그로부터 추출된 회사명·담당자명·직책·이메일·전화번호 / 이전 국가: 미국 / 이전 시기·방법: 각 녹음·명함 처리 시 암호화된 통신망(TLS)을 통해 전송 / 이전받는 자: OpenAI, L.L.C.·Google LLC(연락처 [email protected]) / 이용 목적: 음성 텍스트 변환 및 요약·분석, 명함 문자인식 및 정보 추출 / 보유·이용 기간: 처리 완료 후 지체 없이 파기. 위탁·이전된 데이터는 서비스 핵심 기능 제공 목적으로만 사용되며 광고·마케팅에 사용되지 않습니다. 이용자는 녹음 업로드·명함 촬영 기능을 사용하지 않음으로써 국외이전을 거부할 수 있으며, 이 경우 통화 인사이트·명함 자동 등록 등 관련 기능은 제한됩니다.

[앱 권한별 이용 목적] 각 권한은 앱 설명에 명시된 핵심 기능에만 사용됩니다. READ_CALL_LOG(통화 이력 표시 및 녹음 매칭 — 대체 수단 없음), READ_SMS(문자 이력 통합 표시 — 읽기 전용, 기기 내 처리이며 본문을 서버로 전송하지 않음), SEND_SMS(부재중 자동 회신 문자 발송 — 이용자가 선택적으로 켠 경우에 한하며, 발송 내용·수신번호는 기기에서 처리되어 회사 서버로 전송·저장되지 않음), READ_CONTACTS(발신자 이름 표시 — 기기 내 처리), READ_MEDIA_AUDIO·저장소 접근 권한(기기에 저장된 통화 녹음 파일 읽기), CAMERA(기기 연결용 QR 코드 스캔 및 명함 촬영 — 해당 화면에 진입한 경우에만 작동. 사진첩에서 명함을 불러오는 경우 안드로이드 시스템 사진 선택 도구를 사용하므로 사진 접근 권한을 요청하지 않으며, 이용자가 고른 사진 외에는 앱에 전달되지 않음), RECORD_AUDIO(현장 미팅 녹음 — 이용자가 녹음 시작 버튼을 누른 경우에만 작동하며 정지 시 종료, 백그라운드·상시 녹음 없음). 각 권한은 실제 사용 시점에 안드로이드 런타임 권한 안내를 통해 개별적으로 요청되며, 앱 최초 실행 시 일괄 요청하지 않습니다.

[보관 및 파기] 위 데이터는 이용자 또는 워크스페이스 관리자가 삭제할 때까지 보관되며 자동 만료되지 않습니다. 명함 이미지는 인식 완료 후에도 재확인·재인식을 위해 보관되며, 추출된 바이어 정보는 해당 리드가 삭제될 때까지 워크스페이스에 유지됩니다. 이용자는 앱 또는 웹 관리 화면에서 개별 녹음·명함을 삭제하고 기기 연결을 해제할 수 있으며, 통화기록 수집 동의는 앱 내에서 언제든 철회할 수 있습니다. 명함 주인 등 제3자를 포함한 데이터의 완전한 삭제는 개인정보 열람·삭제 요청 페이지(https://app.rinda.ai/privacy/request) 또는 워크스페이스 관리자를 통해 요청할 수 있습니다.


Privacy Policy

Effective: August 20, 2026 | Last Updated: August 13, 2026

Grinda AI Inc. (hereinafter "the Company") establishes and discloses the following Privacy Policy to protect personal information of data subjects and to handle related grievances promptly and smoothly in accordance with Article 30 of the Personal Information Protection Act.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed shall not be used for purposes other than those listed below, and necessary measures such as obtaining separate consent shall be taken if the purpose of use changes.

Membership Registration and Management:

Verification of membership intent, identification and authentication for membership services, maintenance and management of membership, prevention of fraudulent use, various notices and notifications, grievance handling

Service Provision:

Providing services including AI-based lead generation, email automation, multilingual translation, campaign analytics, content provision, and customized services. Country information collected at sign-up is used to optimize the service region and language, estimate the country of origin for exports, and determine the payment currency.

Payment and Settlement:

Payment and settlement for paid services, subscription management, refund processing

Marketing and Advertising:

New service announcements and provision of event and advertising information (with consent)

AI-based Buyer Research:

Collection and analysis of potential buyer information using AI technology, extraction of corporate website information, buyer lead scoring and email contact discovery

Article 2 (Personal Information Collected)

Category

Items Collected

Collection Method

Required Information

Email, name, company name, password (for direct registration), onboarding survey information (industry, target market, export destination countries, export experience, etc.)

Registration, social login

Additional Social Login Data

Profile picture URL, social account identifier

Automatically collected during Google OAuth integration

Payment Information

Payment method information (card issuer, partial card number), payment amount, payment date

Collected during payment

Automatically Collected

IP address, browser information, access logs, cookies, service usage records, country/region information (country code estimated from IP address)

Automatically collected during service use

Payment Information Security Notice:

Sensitive payment information such as credit card numbers and CVC are not stored directly by the Company. Domestic payments are securely processed through TossPayments (PCI-DSS certified), and international payments through Paddle.com Market Ltd (PCI-DSS Level 1 certified).

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law or agreed upon when collecting personal information from data subjects.

Item

Retention Period

Legal Basis

Member Information

Until membership withdrawal

Data subject consent

Contract/Subscription Records

5 years

Article 6 of the Electronic Commerce Act

Payment and Settlement Records

Consumer Complaint/Dispute Records

3 years

Access Logs

1 year

Article 15-2 of the Protection of Communications Secrets Act

Article 4 (Provision of Personal Information to Third Parties)

In principle, the Company processes personal information within the scope specified for the purpose of collection and use, and does not process beyond the original purpose or provide it to third parties without prior consent of the data subject, except in the following cases.

When separate consent is obtained from the data subject

When there are special provisions in laws

When the data subject or their legal representative is unable to express their will or prior consent cannot be obtained due to unknown address, etc., and it is clearly necessary for the urgent benefit of life, body, or property of the data subject or a third party

Article 5 (Entrustment of Personal Information Processing)

The Company entrusts personal information processing as follows for smooth service provision.

Trustee

Entrusted Task

Retention Period

Until end of entrustment contract

TossPayments Co.

Payment processing and agency

Paddle.com Market Ltd

International payment processing, tax collection and remittance (Merchant of Record)

Amazon Web Services, Inc.

Cloud server operation

Twilio SendGrid, Inc.

Email delivery and unsubscribe/bounce handling

Google LLC

Social login (OAuth) authentication

Google LLC

AI-based lead analysis (Gemini API)

Hunter.io

Email lead discovery service

Jina AI GmbH

Corporate website information extraction

Article 6 (Rights and Obligations of Data Subjects and Exercise Methods)

Data subjects may exercise the following personal information protection rights against the Company at any time:

Request to access personal information

Request for correction in case of errors

Request for deletion

Request for suspension of processing

Rights may be exercised through written documents, email, or customer center, and the Company shall take action without delay.

Rights may also be exercised through an agent such as a legal representative or authorized person of the data subject.

Article 6-2 (Requesting Deletion of Personal and App Data)

This article applies to both the web service and the Android app Rinda Field (package name ai.grinda.telinfo), both operated by Grinda AI Inc.

How to request deletion

Send an email to [email protected] with "Data deletion request" in the subject line.

In the body, include the email address you signed up with and whether you want the entire account deleted or only the data collected by the app.

After identity verification, we process the request within 30 days of receipt and reply with the result.

Deleting directly in the app

Business cards and meeting records can be deleted individually inside the app. Disconnecting this device in [Settings > My account > Connect a different account] also removes photos and recordings stored on the device.

What is deleted when you request it

Account information, business card photos and their recognition results, meeting and call recordings with their transcripts and AI summaries, and call logs transmitted with your consent are destroyed without delay.

What is retained even after a deletion request

Records that the law requires us to keep are stored separately for the required period and then destroyed: contract, subscription and payment records for 5 years, consumer complaint and dispute records for 3 years, and access logs for 1 year (identical to Article 3).

Article 7 (Destruction of Personal Information)

The Company shall destroy personal information without delay when it becomes unnecessary, such as expiration of the retention period or achievement of the processing purpose.

Electronic file information is completely deleted using technical methods to prevent recovery and reproduction, and records, printed materials, and documents are shredded or incinerated.

Article 8 (Measures to Ensure Security of Personal Information)

The Company takes the following measures to ensure the security of personal information:

Administrative Measures:

Establishment and implementation of internal management plans, employee training, etc.

Technical Measures:

Access control for personal information processing systems, TLS encryption in transit and AES-256 encryption at rest for sensitive data (text messages, call logs, call transcripts, AI summaries), installation of security programs

Physical Measures:

Access control for server rooms, data storage rooms, etc.

Article 9 (Installation and Operation of Cookies and Refusal)

The Company uses 'cookies' that store and retrieve usage information to provide individualized customized services to users.

Cookies are small pieces of information sent by the server operating the website to the user's computer browser and are stored on the user's computer hard disk.

Users have the right to choose regarding cookie installation. By setting options in the web browser, users can allow all cookies, require confirmation each time a cookie is stored, or refuse all cookies.

Article 10 (Personal Information Protection Officer)

The Company designates a Personal Information Protection Officer as follows to take overall responsibility for personal information processing and to handle complaints and remedies of data subjects related to personal information processing.

Personal Information Protection Officer

Name: Hojin Kang

Position: CEO

Contact:

Email:

Addendum

This Privacy Policy shall be effective from August 20th 2026.

Google LLC

Service usage analytics (Google Analytics)

Mixpanel, Inc.

Service usage analytics (Mixpanel)

Personal Data Processing in the Mobile Application (Rinda Field)

When a user uses the Android app "Rinda Field" (package name ai.grinda.telinfo), the following personal information is additionally processed in order to provide the app's core features: unified management of calls, texts and recordings, and the collection of business cards and recording of meetings at trade shows. Call logs are transmitted to the server only where the user has explicitly agreed to the consent notice shown on first launch, and recording upload, contact lookup, business-card capture and meeting recording each operate only where the user has granted the corresponding Android permission and has actively started that feature. This data is never used for advertising or marketing purposes.

Call logs

Caller name, phone number, call direction (incoming/outgoing), and call time are transmitted to the server after the user's explicit consent (a one-time consent dialog), and used to identify the other party and provide call insights.

Text messages (SMS)

Text messages are read on the device only and shown in the app; neither the sender/recipient numbers nor the message body are transmitted to or stored on Company servers. The inbox and sent box are accessed read-only, and real-time interception of incoming messages (broadcast) is not used.

Call recording files

The app reads call recording audio files already stored on the device, uploads them to AWS S3 (Seoul, Republic of Korea region), and provides speech-to-text (STT) and AI summarisation and analysis. The Company does not record the user's phone calls within the app and processes only files created by the device (such as the manufacturer's default dialer); field meeting recordings are covered separately below. Before storage, phone numbers, card numbers, account numbers and resident registration numbers are automatically masked in the transcribed (STT) text (masking applies only to recording transcripts).

Contacts

Accessed only on the device to display caller names; the contacts themselves are not uploaded to the server.

Device identifier

An app-generated device identifier is processed to issue and verify the device authentication token. This is not an advertising ID (ADID), IMEI, or other hardware identifier, and is used solely to verify the device–workspace link.

Service usage and error logs

App screen-navigation and feature-usage statistics and error logs are processed to improve service stability and quality (telemetry.rinda.ai).

Business card images

Photographs of business cards taken by the user at a trade show are uploaded to AWS S3 (Seoul, Republic of Korea region), and the printed details are extracted using AI optical character recognition (OCR). The camera operates only when the user has entered the card capture screen, and captures are held temporarily on the device while offline and sent once connectivity is restored. When cards are added from the photo library, only the photos the user selects are handed to the app through the Android system photo picker; the app does not browse the whole library and does not request photo access permission.

Third-party information extracted from business cards

Company name, contact name, job title, email address, phone number, website and address are extracted from the business card image and registered as a buyer lead in the user's workspace. The data subject of this information is not the app user but the third party who handed over the business card. The Company acts as a processor handling this information on the user's behalf, and responsibility for the lawfulness of collection in relation to the card provider (use within the scope reasonably expected from the exchange of a business card, and separate notice or consent where required) rests with the user who collected that card. Extracted information is used solely for the sales activities of the user's workspace and is not used by the Company for its own marketing or sold to third parties.

Field meeting recordings

Only when the user taps [Start meeting notes] on a business card and then presses the record button does the app record the audio of an in-person meeting directly through the device microphone. Recording continues only until the user presses stop; there is no background or always-on recording. The recording file is uploaded to AWS S3 (Seoul, Republic of Korea region) and passes through speech-to-text (STT) and AI summarisation. Because an in-person conversation involves attendees other than the user, the responsibility to inform attendees before recording and to obtain any necessary consent rests with the user.

[Sensitive Data] The audio and content of call recordings may constitute sensitive information and are processed only when you use the recording-upload feature. Transcribed and summarized call content may be visible to authorized members of the same workspace; if you do not wish to share a particular recording, you can choose not to upload it or delete an uploaded recording within the app.

[Outsourcing and overseas transfer] The Company outsources the processing of personal information as follows in order to provide the above features. ▲ Storage of recording audio files and business card images — Amazon Web Services (stored in the Seoul, Republic of Korea ap-northeast-2 region; retained domestically). ▲ Speech-to-text conversion and AI analysis of recordings, and optical character recognition (OCR) and information extraction from business card images — OpenAI, L.L.C. and Google LLC. In this process, recording audio and transcripts, and business card images and extracted information, may be transferred to the United States. Items transferred overseas: call and field meeting recording audio and transcripts; business card images and the company name, contact name, job title, email address and phone number extracted from them / Destination country: United States / Timing and method: transmitted over an encrypted network (TLS) as each recording or card is processed / Recipients: OpenAI, L.L.C. and Google LLC (contact [email protected]) / Purpose: speech-to-text conversion, summarisation and analysis, and business card character recognition and information extraction / Retention period: destroyed without delay after processing is complete. Outsourced and transferred data is used solely to provide core service features and is not used for advertising or marketing. Users may refuse the overseas transfer by not using the recording upload and business card capture features, in which case related features such as call insights and automatic card registration will be limited.

[Purpose of each app permission] Each permission is used only for the core features stated in the app description. READ_CALL_LOG (displaying call history and matching recordings — no alternative means), READ_SMS (unified display of message history — read only, processed on the device; message bodies are not transmitted to the server), SEND_SMS (sending an automatic reply text for missed calls — only where the user has opted in; the content and recipient number are handled on the device and are neither transmitted to nor stored on Company servers), READ_CONTACTS (displaying caller names — processed on the device), READ_MEDIA_AUDIO and storage access (reading call recording files stored on the device), CAMERA (scanning the device-pairing QR code and capturing business cards — active only on those screens. Adding cards from the photo library uses the Android system photo picker, so no photo access permission is requested and nothing beyond the photos the user selects is handed to the app), RECORD_AUDIO (recording field meetings — active only after the user presses the record button and ending when they press stop; no background or always-on recording). Each permission is requested individually through the Android runtime permission prompt at the point of actual use, and is not requested in bulk on first launch.

[Retention and destruction] The above data is retained until deleted by the user or a workspace administrator and does not expire automatically. Business card images are retained after recognition so they can be re-checked or re-processed, and extracted buyer information remains in the workspace until the corresponding lead is deleted. Users can delete individual recordings and business cards and disconnect the device from the app or the web management screen, and consent to the collection of call logs can be withdrawn at any time within the app. Complete deletion of data, including that concerning third parties such as business card holders, can be requested through the personal data access and deletion request page (https://app.rinda.ai/privacy/request) or via a workspace administrator.