AISRC Co., Ltd. (주식회사 에이아이에스알씨, “AISRC,” “we,” “us,” or the “Company”) processes personal information in accordance with the Personal Information Protection Act of the Republic of Korea and other applicable laws.
This Privacy Policy applies to the aisrc.ai website and services directly operated or provided by AISRC, including AICATCHER and the VoxGazer web service.
Where an enterprise customer provides personal information relating to its customers, employees or users and AISRC processes such information on that customer’s instructions, the enterprise customer’s privacy policy and the applicable data processing or other agreement between AISRC and the enterprise customer may also apply.
Nothing in such agreements limits rights granted to individuals under applicable law.
AISRC processes personal information only where there is a lawful basis under applicable law, including consent, performance of or steps requested in connection with a contract, compliance with legal obligations, or another lawful basis. Where AISRC processes personal information on behalf of an enterprise customer, the enterprise customer is responsible for establishing the applicable lawful basis and AISRC processes the information in accordance with the applicable data processing agreement and law.
1. Categories of Personal Information and Purposes of Processing
Website and Business Inquiries
AISRC may process:
- first and last name;
- email address;
- company or organization;
- product or service of interest; and
- information voluntarily provided in a message.
Purposes:
- responding to inquiries;
- responding to product and service inquiries;
- business and B2B inquiries; and
- related follow-up communications.
Product and Research Updates
When a user subscribes for AISRC updates, AISRC may process:
- email address; and
- company or organization.
Purposes:
- product updates;
- research and company news; and
- related information requested by the subscriber.
Where required by applicable law, AISRC will obtain separate consent before sending commercial marketing communications. Subscribers may unsubscribe or withdraw consent at any time.
Service Accounts
Depending on the applicable service, AISRC may process:
- email address; and
- account or authentication identifiers.
Purposes:
- authentication;
- account administration;
- service delivery; and
- prevention of unauthorized use.
Voice Data
Depending on the applicable service, AISRC may process:
- uploaded voice or audio recordings;
- voice recordings made by the user; and
- other voice data submitted for analysis.
Purposes:
- deepfake voice detection;
- speaker authentication; and
- other voice security analyses requested by the user.
VoxGazer Case and Forensic Data
Depending on the features used and the enterprise customer’s deployment, AISRC may process:
- case names, case numbers, investigator or responsible-person information, and other case information entered by users;
- original voice or audio recordings and related metadata such as file name, format and hash values;
- identifiable voice feature values generated for speaker authentication, comparison or identification, such as voice embeddings or voiceprints;
- information registered in watchlists or speaker databases;
- deepfake, manipulation and acoustic forensic analysis results, annotations and automatically generated reports; and
- evidence-handling history, audit logs and chain-of-custody records.
Purposes:
- case and digital evidence management;
- speaker authentication, comparison and identification;
- deepfake, manipulation and acoustic forensic analysis;
- visualization of analysis results, automated report generation and evidence-history management; and
- service operation, audit and security management.
Service, Error and Security Information
AISRC may process:
- IP address;
- access date and time;
- service usage records;
- operating system and application version;
- error records; and
- security logs.
Purposes:
- service operation and reliability;
- error and incident analysis;
- prevention and investigation of security incidents; and
- prevention of unauthorized use.
2. Voice and Biometric Information
Not all voice data constitutes biometric identification information.
Information technically generated from physical, physiological or behavioral characteristics of a voice for the purpose of authenticating or identifying a specific individual may constitute sensitive biometric identification information under applicable law. Identifiable voice feature values generated by VoxGazer for speaker authentication, comparison or identification may fall within this category, and AISRC applies the safeguards required by applicable law and the relevant data processing agreement when such information is processed.
Where AISRC directly processes such information from individual users, AISRC will obtain any separate consent or other lawful basis required under applicable law and apply appropriate safeguards.
Where AISRC acts as a processor on behalf of an enterprise customer, the enterprise customer is responsible for establishing the applicable lawful basis and AISRC processes the information in accordance with applicable law and the relevant agreement.
3. AICATCHER Original Voice Data
Original voice data submitted to AICATCHER for deepfake detection is processed only to the extent necessary to perform the requested analysis.
As a general policy, original voice data is deleted immediately after completion of the analysis.
Where separate storage is required for Enterprise API, SPEEKEY or another enterprise service, the applicable purpose and retention period may be specified in the relevant service information or Customer Agreement.
4. VoxGazer and Enterprise Voice Forensic Data
VoxGazer may be provided either as an on-premises deployment or as a web service operated by AISRC, depending on the customer environment.
For on-premises deployments, customer data is stored and processed in servers or internal networks controlled by the customer, and AISRC does not ordinarily have remote access to such customer data. Technical support is provided using logs or materials supplied by the customer or through other customer-approved support procedures. Any exceptional access to customer data requires a separate written agreement with the customer in advance.
For the web service, AISRC performs routine operation and maintenance using system information, metadata and logs where reasonably practicable. Authorized AISRC personnel may access the contents of customer data only where reasonably necessary for a customer-requested support matter, troubleshooting, service operation, or security incident response, and only to the minimum extent necessary for the relevant purpose. AISRC applies role-based and least-privilege access controls, maintains and reviews access records as required by applicable law, and does not access or use customer data for unrelated purposes. Where reasonably practicable, content-level access for support or troubleshooting will be based on the enterprise customer’s request or approval, except where immediate access is necessary to address an urgent security incident or comply with applicable law.
For the VoxGazer web service, original voice data, voice feature values, case information, analysis results and automatically generated reports are retained for the period configured by the customer or specified in the applicable Customer Agreement. If no separate retention period is specified, data for a case marked as closed will generally be deleted within 90 days after the case is closed. Following termination of the applicable agreement, such data will generally be deleted within 90 days unless a longer period is required by law or the Customer Agreement.
5. AI Model Training
AISRC does not use original voice data submitted by individual AICATCHER users to train or retrain AISRC’s general AI models without separate consent or another lawful basis.
AISRC does not use an enterprise customer’s original voice data, voice feature values, case information, analysis results or reports, including data processed through VoxGazer, to train or retrain AISRC’s general AI models or for general performance improvement without the enterprise customer’s express written agreement. Any customer-specific model development, research or performance improvement separately agreed in writing will be governed by applicable law and the relevant agreement.
6. Retention
AISRC retains personal information only for the period necessary for the applicable purpose and deletes information when the retention period expires or the information is otherwise no longer necessary, subject to applicable legal retention requirements.
| Information | Retention Period |
|---|---|
| Website contact and business inquiry information | 2 years from the last inquiry or communication |
| Update subscription information | Until consent is withdrawn or subscription is cancelled |
| VoxGazer web-service case and forensic data | As configured by the customer or specified in the Customer Agreement; if no separate period is specified, generally deleted within 90 days after the case is closed |
| Service account information | Until account deletion or termination |
| Original AICATCHER voice data | Deleted upon completion of the analysis, as a general policy |
| General service, error and security logs | 2 years from creation |
| Enterprise customer data | As specified for the applicable service or Customer Agreement |
| Information required to be retained by law | For the period required by applicable law |
Access records, access authorization histories and other security records for which applicable law specifies a separate retention period are maintained for at least the legally required period.
7. Disclosure to Third Parties
AISRC does not disclose personal information to third parties as a general practice.
Personal information may be disclosed where:
- the individual has consented;
- disclosure is required by law; or
- another lawful basis permits disclosure.
If AISRC begins regularly disclosing personal information to third parties, this Policy will be updated to identify the recipient, purpose, information disclosed and applicable retention period.
8. Service Providers
AISRC’s principal service infrastructure is currently operated on AISRC-owned servers located in the Republic of Korea, and AISRC does not currently use an external cloud infrastructure provider for its principal service infrastructure.
Personal information submitted through the Contact and Subscribe functions is currently stored and processed on AISRC-owned servers located in the Republic of Korea. AISRC does not currently outsource the processing of such personal information to an external service provider.
AISRC will comply with applicable contractual, supervisory and disclosure requirements when appointing service providers in the future.
9. International Transfers
AISRC’s principal service servers are located in the Republic of Korea.
AISRC does not currently transfer personal information covered by this Policy outside the Republic of Korea for the purpose of providing its services.
If AISRC transfers personal information outside Korea in the future, AISRC will provide the information and implement the procedures required by applicable law.
10. Deletion
AISRC deletes personal information without undue delay when the applicable retention period expires or the information is otherwise no longer necessary.
Electronic information is deleted using methods designed to make restoration or recovery impracticable.
Information required to be retained by law may be separately protected and maintained for the applicable statutory period.
11. Individual Rights
Subject to applicable law, individuals may request:
- access to personal information;
- correction or deletion;
- suspension of processing;
- withdrawal of consent; and
- exercise of other rights provided by applicable law.
Requests may be submitted to the Operations Department by email, telephone or another reasonably accessible method, and AISRC will process requests in accordance with the procedures and time periods required by applicable law.
Where AISRC acts as a processor for an enterprise customer, the enterprise customer may primarily handle an individual’s request and AISRC will provide assistance as required by applicable law and the applicable agreement.
12. Security
AISRC applies technical, organizational and physical safeguards appropriate to the nature, volume and risk of the personal information processed.
Measures may include:
- least-privilege access authorization;
- access controls protecting personal information systems;
- secure management of authentication credentials;
- secure transmission and storage where required;
- access and security logging;
- vulnerability management;
- malware and incident response measures;
- management of personnel who process personal information; and
- physical controls protecting servers and facilities.
13. Cookies and Website Analytics
AISRC does not currently use third-party advertising or website analytics and tracking tools such as Google Analytics or Meta Pixel on aisrc.ai, and does not separately use cookies or localStorage for user identification or persistent login functionality.
Technical information such as server access records may nevertheless be generated where necessary to deliver, secure and troubleshoot the website or services.
If AISRC introduces website analytics, advertising tracking, or similar technologies in the future, this Privacy Policy will be updated to reflect the actual processing, and users will be provided with any choices required by applicable law.
14. Children
AISRC services are not generally directed to children under the age of 14.
Where consent from a legal representative is required under applicable law, AISRC will implement the required procedures before processing such information.
15. Privacy Contact and Access Requests
Privacy and personal information inquiries:
Privacy Department: Operations Department
Email: [email protected] · Telephone: +82-2-826-9197
Address: 46, Sadang-ro, Dongjak-gu, Seoul, Republic of Korea
Personal Information Access Request Department: Operations Department · Email: [email protected] · Telephone: +82-2-826-9197
16. Remedies for Privacy Infringement
Individuals may seek mediation, reporting or consultation regarding privacy infringements through the competent Korean privacy authorities, including the Personal Information Dispute Mediation Committee and the Personal Information Infringement Report Center.
- Personal Information Dispute Mediation Committee: +82-1833-6972
- Personal Information Infringement Report Center: 118 (within Korea)
17. Changes to This Privacy Policy
AISRC may update this Privacy Policy in response to changes in applicable law, services or personal information processing practices.
Material changes will be communicated through the website or applicable service as required.
Effective Date: August 14, 2026