Co-Founders Build With Us Contact

Legal / Privacy Policy

Privacy Policy

Last updated: 2026-09-14

#1. Scope of This Policy

This Privacy Policy describes how a2sys Co., Ltd. ("Company," "we," "us," or "our") processes personal data as a controller in connection with our corporate website, business inquiries and communications, recruitment, security administration, and the Request Metadata described below.

We provide model inference services through OpenRouter and other marketplaces that we expressly approve (the "Services"). We do not offer direct retail inference accounts to marketplace end users. Business Contacts include individuals representing a marketplace, prospective business counterparty, vendor, or other organization that communicates with us. A marketplace's collection, account administration, payments, and other processing are governed by its own policies.

Inputs and Outputs ("Customer Content") are processed on behalf of the relevant Customer under our Terms of Service and Data Policy. This Privacy Policy governs our own controller processing; it does not replace the Data Policy's content-processing terms or reduce its Zero Data Retention commitments. Where Request Metadata identifies or can reasonably be linked to an individual and we process it for our own purposes, this Policy governs, and we apply the Data Policy's retention limit to the records that Policy covers. Personal metadata processed solely on a Customer's instructions is governed by the Data Processing Terms instead.

#2. Who We Are

a2sys Co., Ltd. (주식회사 에이투시스), established under the laws of the Republic of Korea, is the controller responsible for the processing described in this Policy. Our registered address is 2F, Twosun World Building, 221 Pangyoyeok-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea. Our representative is Dongsoo Lee.

#3. Personal Data and Sources

We process the following information to the extent relevant to the interaction:

  • Inquiries and business contacts: name, business email address, company, job title, telephone number where provided, inquiry content, and correspondence or support records. We receive these from you, your organization, or the marketplace through which the Services are supplied.
  • Website access information: IP address and technical access information generated when a browser requests our website. Our hosting provider processes website access information as described in Section 6.
  • Request Metadata: request, model and routing identifiers, input and output token counts, request timestamp and latency, computed cost, API credential identifier, user, team, organization or session identifiers where supplied, request tags, connection address, User-Agent, call type, response status, and cache usage indicators. We receive these from the marketplace or generate them while handling requests. A connection address generally reflects the upstream proxy or marketplace; we do not assume that technical identifiers can never identify an individual. The full scope and limitations are in Sections 3 and 4 of the Data Policy.
  • Operational and security logs: connection addresses, timestamps, authentication events, request identifiers, status and error codes, and non-content diagnostic information. Cloud administration audit records may also contain administrator identities and addresses, resource identifiers, and details of administrative actions.
  • Job applicant information: the information described in Section 4.

We do not retain Inputs or Outputs in Request Metadata or operational logs. Diagnostic logs exclude Customer Content; their separate retention period is not permission to retain prompts, responses, or content-bearing request fragments. Please do not put prompt content, sensitive personal data, or secrets in metadata fields or business inquiry forms.

#4. Job Applicants

We act as controller for applications to the Company, including applications received through Ninehire, operated by 웍스피어 유한책임회사 (Worksphere LLC).

  • Purpose and categories: We use your name, contact details, resume or curriculum vitae, cover letter, education and employment history, interview and evaluation records, and relevant information you submit to assess your application, communicate with you, and make a hiring decision. We collect only information necessary for that process. Any processing requiring separate consent or another specific legal basis, including sensitive information, is subject to the applicable collection notice and legal requirements.
  • Retention: We delete application information without delay after the recruitment purpose has ended, including withdrawal or closure of the relevant recruitment process, except for information lawfully transferred to employment records if you are hired. Where necessary to address recruitment complaints or establish or defend legal claims, we may retain the minimum relevant decision and correspondence records only for as long as necessary to address a recruitment complaint or to establish or defend a legal claim, and we delete them when that need ends. This is not a blanket retention period for the entire application. A specific legal retention obligation or an active claim may require identified records to be kept longer, with restricted access and no unrelated use.
  • Future opportunities: Retention for future openings requires a separate, optional consent specifying the information and retention period. You may withdraw that consent at any time.
  • Rights: Section 10 applies to applicants, including applications made through Ninehire.

#6. Service Providers and Other Disclosures

We do not sell personal data. The following providers support our processing:

ProviderFunction and scope
Google CloudAPI gateway, database, network delivery, logging, monitoring and related cloud infrastructure for the Services and corporate administration
ELICE INC. (주식회사 엘리스그룹), operating Elice CloudGPU inference infrastructure in the Republic of Korea; Customer Content processing is governed by the Data Policy
GitHub, Inc.Corporate website hosting through GitHub Pages, including website access information; separate from inference service delivery
Google FormsCollection and hosting of inquiry responses submitted through our contact form
웍스피어 유한책임회사, operating NinehireReceiving and managing applications and recruitment communications on our behalf

We impose the protections required by applicable law on processing entrusted to providers and supervise that processing. A provider may separately process information for its own account security, legal compliance, or other independent purposes under its own applicable terms and privacy notice. GitHub's own processing of website visitor information should not be understood as occurring solely on our instructions. External inquiry and recruitment pages may also have their own provider notices in addition to our collection notice.

The Subprocessors page describes providers engaged for inference service delivery. Corporate website, inquiry and recruitment providers are disclosed in this Section; they are not all inference subprocessors.

We may also disclose the minimum information necessary to professional advisers under applicable confidentiality duties, to competent authorities where legally required, or in a business transfer subject to applicable notice and other legal requirements. A category listed here does not itself authorize a disclosure: where consent or a specific legal basis is required, we obtain or establish it before disclosure.

#7. Processing Locations and International Transfers

Inference is performed in the Republic of Korea. Our API gateway, request-level database and designated API access-log storage are in the Seoul region. Routine database backups are stored in a multi-region location that is not limited to Korea. Network delivery and TLS termination use Google's global infrastructure and may take place outside Korea before requests reach the Korean backend. Accordingly, domestic inference and designated storage do not mean that every processing operation is confined to Korea.

Cloud resource administration audit logs are separate from Customer Content and request-level billing records. Their storage is not limited to Korea, and they may contain administrator personal data. Cloud monitoring and other management services also have their own processing locations; the Seoul location statement above applies to the specifically identified resources.

Our corporate website is hosted by GitHub, Inc. in the United States. Requests to the website disclose visitors' IP addresses and technical access information to the hosting infrastructure. Inquiries submitted through Google Forms are processed by Google. Ninehire is operated by a Korean entity; its location alone does not establish the location of every downstream processing operation. Its own privacy policy identifies the overseas providers it engages and the terms on which it transfers applicant information to them.

We rely on Article 28-8(1)3(a) of PIPA for the transfers identified in this Section, both those set out in the table below and the recruitment transfers identified by reference after it. They are necessary to perform the agreement under which the Services and our website are provided, and the matters listed in Article 28-8(2) are disclosed here.

RecipientCountryData transferredTiming and methodPurpose
GitHub, Inc.United StatesVisitor IP address and technical access informationEach time a browser requests our website, over the networkHosting our corporate website
Google LLCUnited StatesInformation the individual enters in our inquiry formWhen the form is submitted, over the networkReceiving and hosting inquiry responses
Google, for cloud services and network deliveryNot limited to KoreaAdministrator identifiers in cloud administration audit records, monitoring data, and routine database backups; request data while in transit through the global network, including TLS terminationContinuously while the Services operate, over the networkCloud administration audit logging, monitoring, backup, and delivery of requests to the Korean backend

For recruitment, applicant information is transferred to the overseas providers that the recruitment service engages, in the countries its own policy, linked above, identifies. Those transfers occur over the network while an application is handled through that service, for the purposes and periods that policy states. We identify them by reference rather than restating them here; restating them would put this Policy out of step whenever that provider changes them.

Each recipient publishes its own retention terms and privacy contact, and those published terms apply to the data it holds. GitHub states them in its privacy statement and receives privacy enquiries at privacy@github.com. Google states them in its privacy policy and, for cloud services, in its cloud privacy notice, with enquiries through the contact routes named there. Where a recipient publishes a standard rather than a fixed period, that standard is the applicable term.

You may refuse a transfer by writing to the contact in Section 14 and identifying the transfer you object to. We will respond without undue delay. The consequence differs by transfer. Website hosting: the transfer occurs when a browser requests the site, so the only way to avoid it is not to request the site. Inquiries: write to the address in Section 14 instead of using the form. Recruitment: we cannot receive an application through the recruitment service, and you may contact us to ask whether another route is available. Cloud administration records: these arise from operating the Services and we cannot provide the Services without them, so we cannot separate an individual record from that processing.

#8. Retention

RecordRetention limit
Inquiry and support informationUntil the inquiry or support matter is resolved and any related transaction or complaint is closed; information no longer necessary for that purpose is deleted without delay
Business contact informationWhile needed for the active business relationship or the individual's representative role; obsolete contact details are removed when no longer needed
Request-level billing and audit metadata (the limited settlement fields in Data Policy Section 4.2)365 days from the request, with residual copies in routine backups for no more than seven additional days, as specified in Data Policy Section 4
API access and non-content operational error-diagnostic logs, including operational user/session/tag/connection fieldsNo more than 30 days from creation
Cloud administration audit logsUp to 400 days from creation, separately from request-level records
Operational infrastructure metricsUp to 24 months, depending on the metric type and the provider's applicable retention settings
Job applicant informationAs specified in Section 4

Daily aggregate statistics that do not identify and cannot reasonably be linked back to an individual may be retained for operational reporting. Where metrics or totals remain identifiable, the personal-data safeguards and applicable retention limits continue to apply.

Where a specific law requires longer retention or particular records are necessary for an active legal claim on a valid legal basis, we keep only those records, restrict their use and access, and delete them when that requirement or purpose ends. For records governed by the Data Policy, this exception does not extend its retention limits unless mandatory law requires the extension, and it never authorizes voluntary retention of Customer Content. We do not treat all request records as statutory tax or accounting records merely because some financial records must be retained by law.

#9. Security

We maintain administrative, technical and organizational safeguards appropriate to the processing, including access restrictions, authentication controls, transport protection, logging of administrative access, provider oversight, and deletion procedures. If an incident requires notification to individuals or a regulator, we provide the notices and reports required by applicable law without undue delay and within the applicable deadline. Our contractual notification to a marketplace does not replace these duties.

#10. Your Rights

Subject to applicable law, you may request access to, correction of, deletion of, or suspension or restriction of processing of your personal data, object where applicable, and withdraw consent for consent-based processing. A legal representative or an authorized agent may submit a request on your behalf. Where applicable statutory conditions are met, you may also exercise rights concerning transmission of personal data or fully automated decisions.

Contact infra@a2sys.ai or write to the address in Section 14. We may request proportionate information to verify identity and an agent's authority. We respond within the statutory period, explain any lawful limitation or refusal and how to challenge it, and do not require a marketplace account to receive a request. Withdrawal does not invalidate processing already lawfully performed; it may prevent us from continuing an optional activity that requires the withdrawn consent.

For data received from a marketplace or another organization, you may also request information about its source and our processing purposes where applicable. We assist with requests concerning data we control. For Customer Content processed on behalf of a Customer, we support the responsible controller as described in the Data Policy. Our ZDR design means we do not maintain stored prompt or response histories for retrieval.

#11. Children's Privacy

Our corporate website and business contact services are not directed to children under 14, and we do not knowingly collect their personal data through those channels. If such information is brought to our attention, we take appropriate steps, including deletion where required. Where applicable law requires a legal representative's consent, we do not substitute a child's agreement for that consent. The handling of personal data within marketplace-submitted Customer Content is governed by the Data Policy and applicable law.

#12. Cookies and Similar Technologies

We do not deploy analytics or advertising-tracking scripts on our corporate website. Website hosting and external inquiry or recruitment pages may use technical cookies or similar functions under their applicable notices. You can manage cookies through your browser settings; disabling them may affect functions that depend on them. Where consent is required for a technology we deploy, we obtain it before use.

#13. Changes to This Policy

We post updates on the Privacy Policy page and revise the date above. Material changes will be identified in the updated Policy, with any advance notice or notice period required by applicable law. We obtain fresh consent before a change that legally requires it. A policy update alone does not authorize incompatible use of previously collected information.

#14. Contact and Personal Information Protection Officer

Our Personal Information Protection Officer (개인정보 보호책임자) is Dongsoo Lee, Chief Executive Officer. Questions, complaints and rights requests may be directed to:

a2sys Co., Ltd.
2F, Twosun World Building, 221 Pangyoyeok-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
Email: infra@a2sys.ai

#15. Additional Korean Privacy Disclosures

Destruction: When a purpose ends or a retention period expires, we delete the relevant personal data without delay. Electronic records are deleted using methods designed to prevent recovery; paper records are shredded or incinerated. Records retained under a specific legal requirement are segregated or otherwise access-restricted and used only for that purpose. Routine request-database backup deletion follows the additional seven-day limit in Section 8; restored backups are subject to the same deletion rules.

Outsourcing and overseas processing: Sections 6 and 7 describe corporate processing providers and overseas processing. The inference Subprocessors page supplements these disclosures for the Services.

Remedies: You may seek assistance from the Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회) or the Personal Information Infringement Report Center (개인정보침해신고센터) operated by the Korea Internet & Security Agency. These remedies are available in addition to contacting us and pursuing other remedies under applicable law.