Privacy Policy
1. Scope
This Privacy Policy describes how Sapiens Q Inc. (주식회사 사피엔스큐; "Sapiens Q," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit sapiensq.com, submit a contact form, request a demo, join a waitlist, access research pages, or otherwise interact with our websites and related online services (the "Services").
This Policy is intended to describe our global privacy practices. Additional rights or disclosures may apply depending on where you live, the product you use, and whether you interact with us as a website visitor, prospective customer, beta user, or enterprise customer. If a separate written agreement or product-specific notice applies, it will control to the extent it conflicts with this Policy.
2. Information We Collect
We collect information you provide directly, information generated when you use the Services, and limited information from service providers.
- Contact and lead information: name, email address, company, role or industry, area of interest, use case, timeline, and message content.
- Submission metadata: the form or page used to contact us, timestamps, and delivery status for confirmation emails.
- Technical and security data: IP address, device and browser information, requested URLs, referrer, language or locale, and logs generated by hosting, security, and delivery providers.
- Future product data: if you later access beta products, we may collect prompts, settings, agent configurations, outputs, feedback, and interaction records as described in the product notice shown at that time.
Please do not submit sensitive personal information, government identifiers, financial account numbers, health information, biometric data, precise location data, children's data, third-party personal information, trade secrets, or confidential enterprise information unless we have expressly agreed to receive it in a separate written agreement.
3. How We Use Information
We use personal information for the following purposes:
- to respond to inquiries, process demo requests, manage waitlists, and send confirmation emails;
- to operate, secure, debug, and improve the Services;
- to evaluate interest in Sapiens Q products, research, and beta programs;
- to send service, administrative, and, where permitted or consented to, product-update communications;
- to prevent spam, abuse, fraud, security incidents, and misuse of AI or simulation features;
- to comply with law, enforce our terms, and protect the rights, safety, and integrity of Sapiens Q, users, and the public.
4. Legal Bases and Regional Grounds
Where laws require a legal basis for processing, we rely on one or more of the following grounds, depending on the context:
| Purpose | Typical Data | Typical Legal Basis |
|---|---|---|
| Responding to inquiries, demo requests, and waitlists | Contact, company, role, use case, message content | Pre-contract steps, legitimate interests, consent where required |
| Operating, securing, and debugging the Services | Technical logs, device data, request metadata | Legitimate interests, legal obligations |
| Product research and improvement | Aggregated, de-identified, or limited product-use data | Legitimate interests, consent, or separate agreement where applicable |
| Product updates or marketing communications | Email address, communication preferences, engagement metadata | Consent or legitimate interests where permitted, with opt-out where required |
| Legal, compliance, safety, and dispute handling | Relevant records, communications, logs, and account or lead data | Legal obligations, legitimate interests, establishment or defense of claims |
5. AI, Research, and Model Improvement
We may use aggregated or de-identified information to analyze interest in our products, improve our Services, and conduct research. We do not use identifiable contact-form, waitlist, demo-request, or enterprise confidential submissions to train or fine-tune AI models unless you expressly opt in or the use is governed by a separate written agreement. If a beta product uses prompts, outputs, agent memory, or interaction records for model improvement, we will provide a product-specific notice or control before or at the point of collection.
6. Disclosure of Information
We do not sell personal information. We also do not currently share personal information for cross-context behavioral advertising. We may disclose information only as described below:
- Service providers: hosting, security, email delivery, infrastructure, analytics if enabled, and operational vendors that process information for us.
- Email recipients: authorized Sapiens Q team members who need the information to respond to your submission.
- Legal and safety purposes: regulators, courts, law enforcement, or other parties when required by law or necessary to protect rights, safety, security, or service integrity.
- Business transfers: parties involved in a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality or notice obligations.
7. Service Providers and International Transfers
Our website currently uses Cloudflare for hosting, routing, and security; Resend for email delivery; and external font/CDN resources such as Google Fonts and jsDelivr/Pretendard. These providers may process technical data such as IP addresses, request URLs, user-agent strings, email addresses, message content, and delivery metadata as needed to provide their services.
| Provider | Purpose | Typical Data | Location |
|---|---|---|---|
| Cloudflare | Hosting, routing, security, caching, and service reliability | IP address, request metadata, URLs, security logs | United States and other provider-operated locations |
| Resend | Email delivery and confirmation messages | Email address, message content, delivery metadata | United States and other provider-operated locations |
| Google Fonts | Font delivery | IP address, request URL, browser and device metadata | Provider-operated locations |
| jsDelivr / Pretendard CDN | Font and static asset delivery | IP address, request URL, browser and device metadata | Provider-operated locations |
Where required, we use appropriate safeguards for international transfers, which may include contractual protections, transfer impact assessments, vendor due diligence, security measures, or other mechanisms recognized by applicable law.
8. Cookies, Analytics, and Tracking
We do not currently use advertising cookies or cross-context behavioral advertising on the main website. If we add analytics, advertising, or non-essential cookies later, we will update this Policy and provide any consent or opt-out controls required by applicable law. We do not currently respond to browser "Do Not Track" signals because there is no common legal or technical standard for those signals. If we later engage in activities that require honoring browser-based opt-out preference signals, we will do so where required.
9. Retention
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy. Retention periods vary based on the nature of the data and our relationship with you.
- Contact, demo, and waitlist submissions are generally retained for up to 24 months after the last meaningful interaction.
- Security and technical logs are generally retained only as needed for security, debugging, reliability, and legal purposes.
- Email delivery metadata may be retained according to our operational needs and provider settings.
- Aggregated or de-identified information may be retained for research, analytics, and service improvement.
We may retain information longer where reasonably necessary for legal, security, accounting, dispute-resolution, audit, compliance, or business-continuity purposes.
10. Your Choices and Rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how we disclose personal information. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and be free from discrimination for exercising privacy rights. To make a request, contact us at a.sapiens@sapiensq.com.
We may need to verify your identity before fulfilling a request. Where required, you may designate an authorized agent, appeal a decision, or lodge a complaint with a competent data protection authority. We will not discriminate against you for exercising privacy rights.
11. Regional Notices
The following regional notices apply only where the corresponding laws apply to Sapiens Q or to your interaction with the Services.
- United States and California: We describe the categories of personal information collected, sources, purposes, disclosures, and retention above. We do not sell personal information or currently share it for cross-context behavioral advertising.
- EEA, United Kingdom, and Switzerland: We provide information about purposes, legal bases, recipients, retention, rights, and international transfers in this Policy. You may have the right to complain to your local supervisory authority.
- Republic of Korea: We describe processing purposes, categories of personal information, retention, outsourced processing, overseas processing, rights, security measures, and the contact point for privacy requests in this Policy.
- Asia-Pacific and other regions: Where applicable, we will honor rights relating to notice, consent, access, correction, deletion, withdrawal of consent, overseas transfer, and complaint handling as required by local law.
12. Automated Decision-Making
We do not currently use website contact, waitlist, or demo-request submissions to make solely automated decisions that produce legal or similarly significant effects about you. If we introduce such processing in a product or enterprise workflow, we will provide additional notice, controls, or human-review options where required by law.
13. International Processing
Sapiens Q and our service providers may process information in the United States, South Korea, and other countries where we or our providers operate. Those countries may have data protection laws different from the laws where you live. Where required, we use appropriate safeguards for international transfers.
14. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, including HTTPS transport, access controls, limited internal recipients, and reputable infrastructure providers. No website, email system, or online service can be guaranteed to be completely secure.
If a security incident affects personal information and applicable law requires notice, we will notify affected individuals, customers, regulators, or other parties as required.
15. Children
The Services are not directed to individuals under 18, and we do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us personal information, contact us so we can review and delete it where appropriate.
16. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will update the date above and provide additional notice when required by law.
For privacy questions or requests, contact us at a.sapiens@sapiensq.com.