REGNA privacy policy

Effective: 15 June 2026 Last revised: 15 June 2026


REGNA (the “Company”) complies with the Personal Information Protection Act and other applicable law, and establishes and publishes this privacy policy to protect users' personal data.

Article 1 (What personal data we collect, and how)

The Company collects the following personal data to provide the Service.

Category Data collected How it is collected
Sign-up and authentication Email, name, password (stored as a hash), company email (optional) Entered by the user
Social login Social account identifier, email, profile (nickname and the like) — the items Kakao, Naver or Google provide Received from the provider when the user chooses social login
Use of the Service Conversation content (questions and answers), uploaded files, posts Entered or uploaded by the user
Collected automatically Access IP, device information, usage records (number of questions, credit use and the like) Generated automatically in the course of using the Service
Payment (planned) Payment details To be collected and processed through a payment gateway when paid services begin
Updates (optional) Email address Entered by the user with consent on the subscription screen

Passwords are never stored in plain text; they are stored as a hash. Payment details are not collected at present. When paid services begin they will be collected through a payment gateway under a processing arrangement, with separate notice. Where social login (Kakao, Naver, Google) is used, the Company receives from the provider only the minimum needed to identify the user (identifier, email, profile). Authentication details such as the social account password are not provided to the Company. The items shared follow the policy of each provider and what the user agreed to there.

Article 2 (Why we collect and use personal data)

Purpose Detail
Member management Identity confirmation, sign-up and authentication (OTP/MFA, social login), one-account-per-company management, prevention of misuse
Providing the Service Generating AI answers, providing the community, newsroom and drafting tools, managing credits
Improving quality Internal analysis of conversation logs (auditing wrong answers, strengthening answer rules and the knowledge base)
Support and notices Responding to enquiries, sending service notices
Security and legal duties Retaining access logs, responding to abuse and misuse, meeting statutory obligations

Updates (optional subscription)

On the free tool screens and the English introduction page we collect an email address only, to tell you when a new free tool or feature opens or when something important about the Service changes. Subscribing is optional; you can use every free tool without agreeing. Clicking the unsubscribe link at the foot of any email stops delivery immediately and the address is no longer used. We do not send advertising, and we do not provide this address to third parties or use it for any other purpose.

Article 2-2 (Principles for handling data users enter)

Recognising that users may enter sensitive or confidential information given the nature of medical device regulatory work, the Company handles entered data on the following principles.

  1. Purpose limitation: the Company processes conversation and attachment data only within the purposes stated in Article 2, and does not read, use or provide it for any other purpose.

  2. Advice against entering confidential information: this Service exists to provide general regulatory information. We recommend that you avoid entering confidential information whose disclosure could cause harm — trade secrets, unpublished filing materials, a third party's personal data. Whether to enter information that is not strictly necessary, and the consequences of doing so, is the user's own judgement and responsibility.

  3. Protection of data: the Company controls access during processing and endeavours to apply the security measures set out in Article 10.

  4. Not used to train external models: conversation and attachment data may be transmitted to an external AI provider to generate an answer, but account information such as email and name is not transmitted, and under the provider's API agreement the data is not used as training data for external models.

Article 3 (How long we keep personal data)

As a rule the Company destroys personal data without delay once the purpose is achieved or the member withdraws. Where law requires retention, it is kept for that period.

Item Retention
Member details (email, name, password hash and the like) Until withdrawal of membership
Conversation content and uploaded files Until withdrawal of membership. De-identified or summarised analytical records for quality improvement may be kept afterwards
Posts (content published on the forum) Until deleted by the user or under Company policy (backups and archives for a reasonable period)
Logs such as access IP and device information 3 months (meeting obligations under the Protection of Communications Secrets Act and related law)
Update subscription email Until the user unsubscribes
Records relating to labelling and advertising and other e-commerce records The period set by law (contracts and withdrawal 5 years, payment 5 years, consumer complaints and disputes 3 years and the like)

Article 4 (Processing entrusted to others)

The Company entrusts processing of personal data as follows in order to provide the Service.

Processor Entrusted work Data entrusted
Amazon Web Services, Inc. (AWS) Hosting the service infrastructure and storing data (Korea region) All personal data processed in the course of the Service
Resend, Inc. Sending authentication and notice emails Email address

Processing agreements provide for personal data to be managed securely. Any change of processor is announced through this policy.

Article 5 (Transfer of personal data abroad)

The Company transfers personal data abroad as follows in order to send authentication and notice emails. Users are given this notice during sign-up and use of the Service, and consent to the transfer by agreeing to it.

Recipient Country Data transferred Purpose When and how Retention
Resend, Inc. United States Email address Sending authentication and notice emails Transmitted over the network (API) at the moment an email is sent Until the purpose is achieved

You may refuse the transfer abroad, but in that case features such as authentication and notice emails may be unavailable.

Article 6 (Destruction of personal data)

  1. The Company destroys personal data without delay once the retention period has passed or the purpose has been achieved.
  2. Method: electronic files are permanently deleted by means that prevent recovery or reconstruction; printed material is shredded or incinerated.
  3. Where other law requires retention, that information is stored separately.

Article 7 (Your rights and how to exercise them)

  1. A user (including a legal representative) may at any time request access, correction, deletion or suspension of processing of their personal data.
  2. Rights may be exercised through features in the Service or by written or email request to the data protection officer, and the Company acts without delay.
  3. The Company may verify that a request comes from the person concerned or a duly authorised representative.

Article 8 (Cookies and other automatic collection)

  1. The Company uses session cookies to maintain a login session and similar purposes.
  2. You may refuse cookies through your browser settings, but parts of the Service such as login may then be unavailable.

Article 9 (Children under 14)

The Company does not collect personal data of children under 14. This Service is for medical device regulatory practitioners and is not directed at children under 14.

Article 10 (Security measures)

The Company takes the following measures to handle personal data safely.

  1. Administrative: establishing and implementing an internal management plan, minimising the number of people who handle personal data, and controlling access rights.
  2. Technical: storing passwords as hashes, encrypting data in transit (HTTPS/TLS), access control and privilege management, and retention of access logs.
  3. Physical: access control over the infrastructure where data is stored (including the hosting provider's own measures).

Article 11 (Data protection officer)

The Company designates the following person as responsible overall for the handling of personal data.

You may direct enquiries, complaints and remedy requests about personal data to the officer, and the Company will answer and act without delay.

Article 12 (Remedies for infringement)

To obtain a remedy for infringement of personal data, you may apply to the following Korean bodies for dispute resolution or advice.

Article 13 (Changes to this policy)

This policy takes effect on 15 June 2026. Any addition, deletion or amendment is announced in the Service at least 7 days before it takes effect.