Privacy Policy

Effective date: June 30, 2026

Chilloen Inc. (the "Company") complies with the Personal Information Protection Act (PIPA) and related laws, and establishes and discloses this Privacy Policy to protect the personal information of data subjects. For data subjects to whom the EU General Data Protection Regulation (GDPR) applies, the additional notice in Article 11 also applies.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes in order to provide the Linkmusic API service (the "Service").

  • Verifying intent to register and identifying/authenticating users under the administrator-approval model
  • Providing the Service and processing API calls
  • Measuring usage, settling fees, and managing subscriptions
  • Operating and securing the Service and preventing misuse
  • Responding to customer inquiries and delivering notices

Article 2 (Categories of Personal Information Processed)

The Company processes the following personal information. The Company does not collect personal information of children under 14 or sensitive information.

  • Account: name, email, company name, Microsoft Entra (Azure AD) account identifier, and password (for direct sign-up)
  • API usage records: API key identifier, call metadata such as endpoint, timestamp, response status and response time, and search inputs (text and images)
  • Payment and subscription: Azure Marketplace subscription identifier, plan, and subscription status (payment-method information is processed by Microsoft and not stored by the Company)
  • Automatically generated/collected: access IP, cookies, service usage records, device and browser information

Article 3 (Processing and Retention Periods)

The Company processes and retains personal information within the retention and use period required by law or consented to by the data subject.

  • Member information: until withdrawal of membership or termination of the service agreement
  • API usage records: 1 year from the date of collection (for operations, settlement, and security)
  • Payment and transaction records: 5 years in accordance with the Act on Consumer Protection in Electronic Commerce and related laws

Article 4 (Provision to Third Parties)

The Company does not provide personal information to third parties except with the data subject's consent or where there is a legal basis.

Article 5 (Outsourcing and Cross-Border Transfer of Personal Information)

To provide a stable Service, the Company outsources the processing of personal information as set out below, and some processors are located overseas. Data subjects may refuse cross-border transfer, in which case use of the Service may be restricted. Each item is disclosed in the order: recipient — purpose — items transferred — country — time and method of transfer — retention period.

  • Microsoft (Azure, Entra ID, Azure Marketplace, Azure Blob) — cloud infrastructure, SSO authentication, subscription billing, file storage — account, authentication, subscription and usage records — United States and others — at time of service use, via network transmission — until termination of the outsourcing agreement
  • Supabase Inc. — database hosting — member and usage records — United States — at time of service use, via network transmission — until termination of the outsourcing agreement
  • OpenAI, L.L.C. — text embedding (search processing) — search input text — United States — at time of search request, via network transmission — until termination of the outsourcing agreement
  • Cyanite GmbH — audio analysis — metadata of the analyzed audio — Germany — at time of analysis request, via network transmission — until termination of the outsourcing agreement
  • ElevenLabs Inc. — SFX and music generation (when the feature is used) — generation request inputs — United States — at time of request, via network transmission — until termination of the outsourcing agreement

Article 6 (Rights of Data Subjects and How to Exercise Them)

Data subjects may at any time request access to, correction, deletion, or suspension of processing of their personal information. Where GDPR applies, data subjects additionally have the right to data portability, the right to restriction of processing, rights regarding automated decisions, and the right to lodge a complaint with a supervisory authority. Rights may be exercised via the contact in Article 10, and the Company will act without delay.

Article 7 (Destruction of Personal Information)

The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved. Electronic files are permanently deleted by an irrecoverable method, and printed materials are shredded or incinerated.

Article 8 (Measures to Ensure Security)

The Company implements measures including encryption of authentication credentials such as passwords, encryption of transmission channels (TLS), minimization of access privileges and access control, retention of access logs, and management of processors through outsourcing agreements.

Article 9 (Cookies and Other Automatic Collection Tools)

The Company uses essential cookies to maintain login sessions and operate the Service. Data subjects may refuse the storage of cookies through their browser settings, but in that case use of some features, such as login, may be restricted. The Company does not use cookies for advertising or tracking purposes.

Article 10 (Chief Privacy Officer)

The Company designates a Chief Privacy Officer as below to take overall responsibility for the processing of personal information and to handle complaints and remedies of data subjects.

  • Chief Privacy Officer: Jaeho Song (Head of Research)
  • Inquiry email: dev@chilloen.com
  • Phone: +82-2-6952-8716
  • For GDPR Data Protection Officer (DPO) and EU representative matters: same contact as above

Article 11 (Additional Notice for Data Subjects under GDPR)

The legal bases for processing are performance of a contract (GDPR Art. 6(1)(b)), legitimate interests (f), consent (a), and legal obligation (c). Cross-border transfers are based on appropriate safeguards such as standard contractual clauses. Data subjects have the right to lodge a complaint with the competent supervisory authority.

Article 12 (Remedies for Infringement of Rights)

Data subjects may apply for dispute resolution or counseling to the following bodies.

  • Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
  • Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cybercrime Division: 1301
  • National Police Agency Cyber Bureau: 182

Article 13 (Changes to This Policy)

This Policy applies from June 30, 2026. Any additions, deletions, or amendments will be announced within the Service at least 7 days before they take effect.