Privacy & data protection

SolverX Privacy Policy

Version 1.0

Last updated

Effective from

View version history

This Privacy Policy explains how SolverX Co., Ltd. ("SolverX", "we", "our" and "us") collects, uses, discloses and otherwise processes personal data in connection with our websites and applications that link to this Policy (the "Sites"), our Physics Intelligence products and services delivered through the SolverX Physics AI Platform, including AI Solver, AI Optimizer, AI Enhancer and AI Generator (the "Platform"), and our ordinary business activities such as sales, events, partner programs, investor relations and customer support (together, the "Services"). It also explains the choices and rights you have in relation to your personal data.

SolverX develops Physics Intelligence: AI that understands the physical world. Our models learn from the physical data produced by engineering simulation and are used by manufacturers to shorten analyses, evaluate and propose designs, and learn from test and production data. The Platform is delivered as a cloud service to organisations and their engineering professionals. It is not intended for consumers.

We process personal data in accordance with the data protection laws that apply to us, including the Personal Information Protection Act of the Republic of Korea ("PIPA") and, where we offer our Services to individuals in the European Economic Area or the United Kingdom, the EU and UK General Data Protection Regulation (together, "GDPR").

1. Scope of this Policy

We provide the Platform to our customers under a written agreement with each of them, solely for their benefit and the benefit of the personnel they authorise to use it ("Authorized Users"). This Policy does not apply to the data that customers and their Authorized Users upload to, submit to or generate through the Platform ("Customer Data"), which we process on behalf of the customer as a service provider. Our handling of Customer Data, including its confidentiality, ownership, retention and destruction, is governed exclusively by our agreement with the relevant customer. If your personal data has been submitted to the Platform by or on behalf of a customer and you wish to exercise your rights, please direct your request to that customer.

This Policy does not apply to personal data of job applicants, which is covered by our Applicant Privacy Notice, to personal data of our employees and contractors, or to third-party websites, marketplaces, products or services that have their own privacy notices, even where they link to or integrate with the Services.

Where this Policy applies, SolverX determines the purposes and means of processing and is the controller of your personal data.

2. Information We Collect

Information you provide

When you interact with us, we collect the information you choose to give us. This includes: your name, business email address, telephone number, job title, employer, department and business address when you contact us, request a demo, register for an event or webinar, subscribe to our updates or exchange business cards with us; authentication information such as user IDs, hashed credentials, single sign-on identifiers and role settings when an account is created for you on the Platform; commercial information such as quotations, contract and licence details, proof of concept scope, order and payment records and tax identifiers required by law; the content of your communications with us, including emails, support tickets, meeting notes, survey responses and, where we give notice at the start of a call or meeting, recordings and transcripts; and information required for know-your-customer, anti-money-laundering, sanctions or export-control screening where you deal with us as an investor, partner or supplier.

Providing your name and business contact details, and, where an account is created for you on the Platform, your authentication information, is necessary to enter into and perform a contract with you or your organisation and to respond to your requests. Providing tax identifiers and screening information is a statutory requirement where you deal with us as an investor, partner or supplier. If you do not provide such personal data to us, we may not be able to create your account, respond to your enquiry, or enter into or perform a contract with you or your organisation.

We ask that you do not provide us with sensitive information, such as information about health, religion, political opinions, trade union membership, sexual life, genetic or biometric data or criminal records, or unique identifiers such as resident registration or passport numbers, unless we expressly request it because the law requires us to collect it. Where you volunteer dietary or accessibility requirements for an event, we use them only for that event.

Information we collect automatically

When you visit the Sites we and our authorised service providers collect information from your device using cookies, pixels and similar technologies: IP address, device and browser type, operating system, language and time zone, referring URL, the pages you view and the links you click. We may use your IP address to derive your general location. When you use the Platform we automatically collect information about how it is used ("Usage Data"): the features accessed, commands executed, API calls made, time spent, and the types and sizes of files processed. Most Usage Data is not personal data. Where it is associated with a user account we use it to provide, support, secure, bill for and improve the Platform. Section 9 describes our use of cookies and how you can control them.

Information from other sources

We receive information about you from your employer or its Platform administrator when it provisions your account; from resellers, distributors, referral partners and system integrators involved in offering or delivering the Services; from cloud marketplace operators when you procure the Platform through them; from co-hosts and sponsors of events, accelerator and government-affiliated programs in which we participate; from professional networking platforms and publicly available sources; and from screening and due diligence providers. We may combine this information with the information you give us and the information we collect automatically.

If you provide us with personal data about other people, for example by nominating colleagues as Authorized Users or introducing a contact, you confirm that you are authorised to do so and that you have made this Policy available to them.

3. How We Use Your Information

We use personal data to provide, maintain, secure and improve the Services and to run our business. Specifically, we use it:

  • to provide and operate the Platform, create and administer accounts, authenticate Authorized Users, and provide training, onboarding and technical support;
  • to prepare quotations and proposals, conclude and perform contracts, manage licences and proofs of concept, issue invoices and collect payment;
  • to respond to your enquiries, arrange meetings and manage our relationship with you and your organisation;
  • to send you newsletters, product updates, event and webinar invitations and other marketing communications, in accordance with your preferences and applicable law;
  • to operate partner, reseller and cloud marketplace programs, including co-selling, referrals and marketplace transactions;
  • to communicate with investors and prospective investors, conduct due diligence and financing, and meet know-your-customer, anti-money-laundering and sanctions requirements;
  • to protect the security and integrity of the Services, detect and prevent fraud, abuse and unauthorised access, and enforce our agreements and policies;
  • to understand how the Sites and Platform are used, diagnose faults, develop new features and generate aggregate statistics;
  • to comply with legal, tax, accounting, export-control and regulatory obligations, respond to lawful requests from public authorities and establish, exercise or defend legal claims;
  • to evaluate or carry out a merger, acquisition, financing, reorganisation, group restructuring or sale of assets; and
  • for any other purpose with your consent or as otherwise described to you at the time of collection.

Legal bases under GDPR

We process personal data where you have given consent, which you may withdraw at any time, for the following purposes: to send you newsletters, product updates, event and webinar invitations and other marketing communications, in accordance with your preferences; to communicate with investors and prospective investors, conduct due diligence and financing. Where we rely on consent, we tell you at the point of collection what we collect, why, and for how long.

We process personal data where it is necessary to conclude or perform a contract with you or your organisation, for the following purposes: to provide and operate the Platform, create and administer accounts, authenticate Authorized Users, and provide training, onboarding and technical support; to prepare quotations and proposals, conclude and perform contracts, manage licences and proofs of concept, issue invoices and collect payment; to respond to your enquiries, arrange meetings and manage our relationship with you and your organisation; and to operate partner, reseller and cloud marketplace programs, including co-selling, referrals and marketplace transactions.

We process personal data where we are required to do so by law, for the following purposes: to comply with legal, tax, accounting, export-control and regulatory obligations, respond to lawful requests from public authorities and establish, exercise or defend legal claims; and to meet know-your-customer, anti-money-laundering and sanctions requirements.

We process personal data where it is necessary for our legitimate interests, such as operating and securing the Services, developing our business with organisations that have shown interest in it, improving our products and defending our rights, provided those interests are not overridden by your interests and rights, taking into account the business-to-business context in which we operate, for the following purposes: to protect the security and integrity of the Services, detect and prevent fraud, abuse and unauthorised access, and enforce our agreements and policies; to understand how the Sites and Platform are used, diagnose faults, develop new features and generate aggregate statistics; to exercise or defend legal claims; to evaluate or carry out a merger, acquisition, financing, reorganisation, group restructuring or sale of assets.

Legal bases under PIPA

Items of personal data that we process based on your consent are: your name, business email address, employer and job title, for the purpose of sending you marketing communications.

Details of personal data that we process without your consent are as follows:

Legal basis for collection and use; Items of personal data
Legal basis for collection and useItems of personal data
Conclusion or execution of contract(PIPA Article 15(1)(iv)Name, business email address, telephone number, job title, employer, department and business address; user IDs, hashed credentials, single sign-on identifiers and role settings; quotations, contract and licence details, proof of concept scope, order and payment records; and the content of your communications with us.
Legitimate interest(PIPA Article 15(1)(vi))IP address, device and browser type, operating system, language and time zone, referring URL, pages viewed and links clicked; Usage Data associated with a user account; access and security logs; and meeting notes and, where we give notice, recordings and transcripts.
Legal obligation(PIPA Article 15(1)(ii))Items listed in Section 7

De-identified and aggregated information

We may pseudonymise, anonymise or aggregate information so that it can no longer reasonably be used to identify you. We may use and disclose anonymised and aggregated information for any lawful purpose without restriction under this Policy. Where we hold information in de-identified form we maintain it in that form, do not attempt to re-identify it other than to test the effectiveness of our de-identification, and contractually prohibit recipients from re-identifying it.

Automated decision-making

We do not make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects. The Platform produces engineering predictions about physical systems, not about people.

4. How We Share Information

We do not sell personal data, and we do not share personal data with third parties for cross-context behavioural advertising. We disclose personal data only as follows:

  • Service providers. With providers who process personal data on our behalf and on our instructions under written contracts, such as providers of cloud infrastructure and hosting, email, document and collaboration tools, and website analytics. We do not allow service providers to use personal data for their own purposes. A current list of our service providers is available on request.
  • Channel partners and marketplaces. With resellers, distributors, referral partners, system integrators and cloud marketplace operators involved in offering, procuring or delivering the Services to you or your organisation, to the extent necessary for that transaction. Their use of your information is governed by their own privacy notices.
  • Professional advisers. With law firms, accountants, auditors, banks, insurers and investment and investor relations advisers bound by duties of confidentiality.
  • Legal and safety. With courts, regulators, tax authorities, law enforcement and other public bodies where required by law, legal process or a binding request, or where we believe in good faith that disclosure is necessary to protect the rights, property or safety of SolverX, our customers or others, or to enforce our agreements.
  • Corporate transactions. With actual or prospective acquirers, investors, merger partners, lenders and their advisers in connection with a merger, acquisition, financing, reorganisation, group restructuring or sale of all or part of our business or assets. If such a transaction proceeds, the successor may use personal data as described in this Policy and we will give notice where required by law.
  • With your consent or at your direction.

We do not currently provide personal data to, or outsource the processing of personal data to, any third party located in the Republic of Korea. The overseas recipients of personal data are set out in Section 5.

5. International Data Transfers

SolverX is headquartered in the Republic of Korea. Some of our service providers store or process personal data in other countries, in particular the United States, whose data protection laws may differ from those of your country. Wherever we process personal data, we protect it in accordance with this Policy and applicable law, and we enter into written agreements with overseas recipients that require them to protect personal data to the standard required by the laws that apply to us.

We transfer personal data to third parties in other countries as follows. You have the right to refuse the cross-border transfer of your personal data by submitting a request using the contact details in Section 12. Because our email, collaboration and cloud hosting systems are operated by overseas providers, if you refuse we may not be able to create or maintain your account or respond to your enquiry.

Legal basis for cross-border transfer; Name of recipient (Contact information); Items of personal data to be transferred; Countries of recipients and date, time, and methods of transfer; Purpose of use by recipient; Period of retention/use by recipient
Legal basis for cross-border transferName of recipient (Contact information)Items of personal data to be transferredCountries of recipients and date, time, and methods of transferPurpose of use by recipientPeriod of retention/use by recipient
Outsourcing or storage(PIPA Article 28-8(1)(iii))Microsoft Corporation (privacy.microsoft.com/privacystatement); Amazon Web Services, Inc. (aws.amazon.com/privacy)Account and authentication information of Authorized Users, Usage Data, and personal data contained in records stored on the Platform or our systemsRepublic of Korea (Seoul region) and United States; continuously while the Services are provided, via networkCloud infrastructure and hosting for the Platform and the SitesUntil our agreement with the recipient ends or the data is deleted in accordance with Section 7, whichever is earlier
Outsourcing or storage(PIPA Article 28-8(1)(iii))Google LLC (policies.google.com/privacy)Name, email address, contact details and the content of emails, calendar entries and documentsUnited States; at the time of collection or communication, via networkBusiness email, calendar, document storage and collaboration (Google Workspace)Until our agreement with the recipient ends or the data is deleted in accordance with Section 7, whichever is earlier
Outsourcing or storage(PIPA Article 28-8(1)(iii))Slack Technologies, LLC (slack.com/trust/privacy/privacy-policy); Notion Labs, Inc. (notion.so/privacy)Names, contact details, meeting notes and business information contained in internal messages, files and recordsUnited States; at the time of collection or communication, via networkInternal communication, collaboration and record keepingUntil our agreement with the recipient ends or the data is deleted in accordance with Section 7, whichever is earlier

Where GDPR applies, transfers from the European Economic Area and the United Kingdom to SolverX in Korea are covered by the respective adequacy decisions for the Republic of Korea. For transfers to service providers in other countries we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by supplementary measures where appropriate. You may request further information about the safeguards we use, or the countries to which your personal data is transferred, using the contact details in Section 12.

6. Security

We maintain technical, administrative and physical measures appropriate to the risk and to the nature of the data we hold. These include encryption of data in transit and at rest, logical isolation of each customer's data on the Platform, role-based access control on a least-privilege basis, multi-factor authentication for administrative access, access logging and monitoring, vulnerability management and secure development practices, confidentiality obligations and training for our personnel, due diligence and contractual controls over service providers, and documented incident response procedures. Information about our security program is available to customers and prospective customers on request under a non-disclosure agreement. If a personal data breach affects you, we will notify you and the competent authority where and within the time required by applicable law.

No security measure is perfect. Although we work to protect your personal data, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential and for telling us promptly if you suspect unauthorised use.

7. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, tax, accounting and reporting requirements, to resolve disputes and to enforce our agreements. As a general rule, account data of Authorized Users is retained for the term of the relevant customer agreement and deleted or anonymised within 90 days after it ends; business contact and sales records are retained for the duration of our relationship with you or your organisation and for up to three years after our last meaningful interaction; marketing data is retained until you withdraw consent or object, after which we keep only a suppression record; and contract, invoicing and tax records are retained for the periods required by law.

We may retain personal data beyond these periods where required by law, court order or litigation hold, as necessary to establish, exercise or defend legal claims, and in anonymised form. Items of personal data that we retain in accordance with law are as follows:

  • Records of website visit and IP addresses used: 3 months (Protection of Communications Secrets Act)
  • Records on cancellation of contracts or subscriptions, payment, and supply of goods or services: 5 years (Act on the Consumer Protection in Electronic Commerce, etc.)
  • Records of consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce, etc.)
  • Records related to labels and advertisements: 6 months (Act on the Consumer Protection in Electronic Commerce, etc.)
  • Proof documents related to accounting books and transactions, tax invoices and receipts: 5 years (Framework Act on National Taxes of Korea, Value Added Tax Act, and Corporate Tax Act)

When the retention period ends we destroy personal data without undue delay: electronic files are deleted using methods that prevent recovery, and paper records are shredded or incinerated.

8. Your Rights and Choices

Depending on the law that applies to you, you may have the right to request access to and a copy of your personal data; to have inaccurate or incomplete data corrected; to have your personal data deleted; to restrict or suspend processing; to object to processing, including for direct marketing; to receive your personal data in a portable format; to withdraw consent at any time without affecting processing already carried out; and to refuse, or request an explanation of, a decision made solely by automated processing that significantly affects you. Such rights may also be exercised through your legal representatives or other duly authorized persons. We respond within the time required by applicable law. If we refuse a request in whole or in part in accordance with applicable law, we will explain why.

To exercise your rights, contact us at young@solverx.ai or by post at the address in Section 12. We may need to verify your identity before acting on a request, and we will use any information you provide for that purpose only to process and keep a record of your request. We do not charge a fee unless a request is manifestly unfounded, excessive or repetitive. Your rights are subject to exceptions under applicable law: we may retain personal data where required by law, where necessary to establish, exercise or defend legal claims, or where it has been anonymised, and we may decline requests that would adversely affect the rights of others, including the trade secrets and intellectual property of SolverX or a customer, in accordance with applicable law. If your request concerns Customer Data, please contact the relevant customer as described in Section 1. You may also lodge a complaint with a relevant supervisory authority regarding our processing of your personal data.

Marketing

You can opt out of marketing communications at any time by following the instructions in the message or by contacting us using the details in Section 12. We will continue to send service communications, such as security notices, contract and invoicing notices and responses to your requests. We send electronic marketing only with your prior consent or as otherwise permitted by law, and every message tells you how to unsubscribe.

9. Cookies and Similar Technologies

Cookies are small text files placed on your computer or mobile device by a website you visit. We and our authorised service providers use cookies, web beacons, pixel tags, scripts and local storage (together, "cookies") on the Sites and the Platform to make them work, to keep them secure, to remember your preferences and to understand how they are used. Cookies may be "session" cookies, which are deleted when you close your browser, or "persistent" cookies, which remain on your device for a set period or until you delete them. They may be "first-party" cookies set by us or "third-party" cookies set by our service providers.

Category; Purpose; Set by; Duration; Your choice
CategoryPurposeSet byDurationYour choice
Strictly necessaryAuthentication and session management on the Platform, security and fraud prevention, load balancing, and remembering the choices you make in our cookie preference tool.SolverXSession, or up to 12 months for the cookie preference recordCannot be switched off through our cookie tool because the Sites and Platform cannot function without them. You may block them in your browser, but parts of the Services will not work.
FunctionalRemembering your language, region and display preferences and whether you have already seen a notice.SolverXUp to 12 monthsConsent where required by law; otherwise on by default and adjustable in our cookie preference tool.

Managing cookies

You can accept or refuse non-essential cookies through the cookie preference tool on the Sites, which you can reopen at any time from the link in the site footer. You can also delete or block cookies through your browser settings (for example, in Chrome: Settings, Privacy and security, Cookies and other site data). Refusing cookies may prevent parts of the Services from functioning. We do not currently respond to "Do Not Track" or similar browser signals because no common industry standard has been adopted; use the cookie preference tool instead.

10. Children

The Services are directed to businesses and professionals. We do not knowingly collect personal data from anyone under 14 years of age, or under any higher age at which the law applicable to that person requires parental consent. If you believe a child has provided personal data to us, please contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time to reflect changes in law, our Services, our service providers or our practices. We will post the updated Policy on the Sites with a new "Last updated" date. If we make material changes, we will provide more prominent notice, for example on the Sites or by email, and where the law requires your consent to a change we will obtain it. If you disagree with a change, you may exercise your rights under Section 8 and, where you use the Platform, stop using it.

This is the first version of this Policy published on the Sites. There are no previous versions.

12. Contact Us

If you have any questions about this Policy or wish to exercise your rights, you can contact us by email at young@solverx.ai or by post at SolverX Co., Ltd., Attn: Chief Privacy Officer (Yunyoung Choi, Chief Executive Officer), 1002, 258 Seonyu-ro, Yeongdeungpo-gu, Seoul, Republic of Korea.

Version history

This is the first version of this Policy published on the Sites. There are no previous versions.

Previous versions and their effective periods will be listed here when this Policy is updated.

Privacy policy versions and effective periods
VersionEffective periodPolicy
1.0 (current)2026-09-23 – PresentView policy