Privacy Policy

Last updated: 14 July 2026 This Privacy Policy explains how ITG insights Co., Ltd. (“we”, “us”, “our”), operating the ai42001.ai platform (“ai42001”, the “Service”), collects, uses, and protects personal data. ai42001.ai provides an ISO/IEC 42001 AI governance readiness assessment platform and related digital products (including the AI Governance Toolkit with bundled AI Threat Intelligence). For questions about this policy or your data, contact us at privacy@ai42001.ai.
Note on payments: Purchases on ai42001.ai are processed by Paddle.com Market Ltd (“Paddle”), which acts as the Merchant of Record and reseller. Paddle collects and processes your payment and billing information under its own privacy policy. We do not receive or store your full payment card details.

1. Who is responsible for your data

ITG insights Co., Ltd. is the controller of personal data processed through ai42001.ai.
  • Company: ITG insights Co., Ltd.
  • Registered address: A101, 4F, 17 Gukhoe-daero 28-gil, Yeongdeungpo-gu, Seoul 07256, Republic of Korea
  • Privacy contact: privacy@ai42001.ai

2. Data we collect

Information you provide – Contact details: email address, and (optionally) name, company name, and role/title. – Assessment responses: your answers to the readiness assessment questionnaire. – Supporting evidence: documents you choose to upload as part of an assessment. – Inquiries: any information you send us by email or contact forms. Information collected automatically – Usage and device data: IP address, browser type, pages viewed, and similar technical data. – Cookies and analytics: see Section 9. Information from payment processing – When you purchase, Paddle (as Merchant of Record) shares limited transaction data with us, such as your email address, the product purchased, and transaction identifiers. We do not receive full card numbers. Toolkit and Threat Intelligence access – When you purchase the AI Governance Toolkit, we process the email address used for the purchase and issue a unique Access ID that delivers the templates and grants 12 months of Threat Intelligence access. Delivered materials are watermarked and traceable to your purchase to deter unauthorized sharing. Benchmarking attributes – To provide peer comparison, we process organizational attributes you supply (for example industry, organization size, region, AI adoption stage). These are used in de-identified, aggregated form.

3. How we use your data and our legal bases

  • To provide the Service (create your assessment, store answers and evidence, score readiness): performance of a contract.
  • To deliver access links, Access IDs, and service emails: performance of a contract.
  • To provide the AI Governance Toolkit and Threat Intelligence access: performance of a contract.
  • To generate aggregated, de-identified industry benchmarking: our legitimate interest in providing comparative insight; benchmarking outputs do not identify you.
  • To respond to inquiries and provide support: legitimate interest / pre-contract steps.
  • For analytics and marketing cookies: your consent (see Section 9).
  • To comply with legal, tax, and accounting obligations: legal obligation.

4. How we share data

We share personal data only as needed to operate the Service, with: – Service providers (processors) that host and support the platform. These currently include, for example: Supabase (database and file storage; EU/Frankfurt region), Resend (transactional email), Cloudflare (content delivery and security), Kinsta (website hosting), Google (workspace email and analytics), and CookieYes (cookie-consent management). – Paddle, as Merchant of Record for payments. – Authorities or third parties where required by law, or to protect our rights. We do not sell your personal data.

5. International transfers

Our platform data is primarily stored in the EU (Frankfurt). As we operate from the Republic of Korea and use providers located in other countries, your data may be transferred internationally. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

6. Data retention

  • Submitted assessments. Assessment personal data and uploaded evidence are retained for up to 51 days after you submit the assessment, after which identifying personal data and uploaded evidence are erased automatically and a deletion record is generated. De-identified responses and benchmarking attributes may be retained afterwards (see below).
  • Unsubmitted or abandoned assessments. If an assessment is never submitted, your access link expires 30 days after it is issued. Shortly after the link expires (currently within about 14 days), the associated personal data, answers, and uploaded evidence are erased automatically. You may also request earlier deletion at any time.
  • De-identified assessment responses and benchmarking attributes may be retained after personal identifiers are removed, to maintain industry benchmarks. This retained data does not identify you.
  • Toolkit and Threat Intelligence entitlements (such as your access record and Access ID) are retained for the 12-month access term and for a reasonable period afterwards to administer renewals and records.
  • We retain transaction and tax records as required by applicable law; these records are also used to verify deletion-certificate requests.
When personal data is erased, identifying fields are removed and the deletion is logged.

Deletion certificates

When your assessment data is erased under the schedules above, the deletion record takes the form of a deletion certificate, issued automatically and written to our audit log. The certificate record contains no personal data: it consists only of the certificate ID, a pseudonymous session reference (a random identifier that names no person or organization), the deletion timestamp, and counts of the records removed. Because it identifies no one, we retain it indefinitely as proof that the deletion was executed.

Requesting your deletion certificate

Your contact details are erased together with your assessment data, so we cannot send the certificate to you automatically — once the deletion has run, no email address for you remains in our assessment systems. You may request your certificate at any time by emailing tier2@ai42001.ai with:
  • your assessment reference — the 8-character code shown when you submitted your assessment and included in your confirmation email — and/or
  • your order receipt (Paddle receipt or order number), which allows us to verify that the request comes from the genuine purchaser.
We verify the request against the transaction records retained under this section and normally reply within 3 business days. Correspondence relating to deletion-certificate requests is processed solely to verify and respond to the request (see Section 3) and is deleted within 90 days of the request being resolved. We do not add your details back into our assessment systems, and we do not use this correspondence for marketing.

7. Security

We apply administrative, technical, and organizational measures aligned with recognized information security practices, including access controls, least-privilege access, encryption in transit, and audit logging. Uploaded evidence is held in an isolated, locked storage bucket and is accessible only to the reviewing analyst through short-lived, expiring download links. No method of transmission or storage is fully secure, but we work to protect your data appropriately.

8. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw consent at any time. To exercise these rights, contact privacy@ai42001.ai. You may also have the right to complain to your local data protection authority.

9. Cookies and analytics

We use cookies and similar technologies to operate the site, remember preferences, and (with your consent) measure usage. We manage cookie consent through a consent banner provided by CookieYes, and you can change your choices at any time. Our analytics are configured with a limited retention period and with data sharing for other purposes disabled. For details of the specific cookies used, see our cookie settings / cookie notice.

10. Children

The Service is intended for businesses and professional users and is not directed at children. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date above.

12. Contact

ITG insights Co., Ltd. Privacy contact: privacy@ai42001.ai A101, 4F, 17 Gukhoe-daero 28-gil, Yeongdeungpo-gu, Seoul 07256, Republic of Korea