Skip to content
Privacy policy

How Veilink handles personal data.

Veilink Inc. (주식회사 베일링크), Business Registration No. 843-87-03690, operates Veilink from the Republic of Korea. This policy describes private hiring and any limited B2B preview or testing explicitly enabled for selected users. It is effective September 8, 2026.

Current document · privacy-2026-09-08-r1

This document applies to Veilink hiring and any limited B2B preview or testing explicitly enabled for selected users. Review it before creating an account or connecting an AI agent.

01

Operator and scope

This policy applies to veilink.ai, Veilink-controlled API and MCP endpoints, account and dashboard pages, authentication links, hiring workflows, and any limited B2B preview or testing Veilink explicitly enables for selected users.

When you use ChatGPT, Codex, Claude, Google sign-in, or an email provider, that provider separately controls information processed in its own product. Its terms and privacy policy also apply.

02

What we collect

Account and consent data: email address, Google account identifier when Google sign-in is used, account role, selected data region, self-declared residence country, terms-acceptance and privacy-policy acknowledgment records, authentication attempts, session identifiers, and login results. Only when trusted edge verification is configured and available, we may also record a network-derived signup-country signal and the associated policy epoch. That signal may be unavailable and is not treated as nationality or proof of residence.

Candidate data: work history and evidence summaries, capabilities, supported outcomes, target work, location region, work arrangement, availability, compensation expectations, aspirations, preferences, constraints, and information you choose to submit during hiring requests and contact sharing.

Company data: company name, work-email domain, optional website, company region, representative contact details, the account user's confirmation that they may act for their own company, hiring briefs and expected outcomes, work location, compensation range, requirements, and information submitted through requests and contact sharing. When limited B2B preview or testing is explicitly enabled, this may also include seller offerings, private buyer sourcing briefs, commercial and delivery conditions, and evidence. Agency business verification does not request or collect client-mandate, client-consent, delegation, or per-role authority evidence.

Company billing data: selected plan, checkout and subscription identifiers, payment status, amount, currency, tax and invoice metadata, billing contact, and provider event history. Payment-card or bank-account details entered in Creem checkout are collected by Creem and are not stored by Veilink.

Generated and operational data: structured individual and hiring records and, where limited B2B testing is enabled, offering and sourcing records; embeddings and relevance signals; closed clarification questions and answers; summaries; drafts; workflow status; consent and contact-sharing history; connected AI metadata; request logs; device or browser metadata; errors; abuse-prevention signals; and monitoring records.

03

Purposes and legal bases

We use personal data to obtain and record consent; create and secure accounts; link supported AI clients; structure confirmed individual evidence, preferences, and hiring briefs and, in limited B2B testing where enabled, seller offerings and private buyer sourcing briefs; identify potentially relevant records; issue closed clarification questions; keep requests and replies; present summaries; operate controlled contact sharing; administer company plans and payments; enforce allowances or billing pauses; provide support; prevent abuse; diagnose failures; and comply with legal obligations.

We use the self-declared residence country and any available trusted-edge signup-country signal to apply regional availability rules, investigate inconsistent signup claims, and prevent policy evasion. A network signal does not by itself determine residence or nationality.

Depending on the activity and applicable law, processing is based on consent, steps requested before or during service provision, performance of our agreement with you, compliance with law, or our legitimate interests in security and reliable operations.

For individuals protected by Korean law, we apply the relevant basis under the Personal Information Protection Act to each activity. Contract-related processing is limited to what is necessary to provide the requested service; a legitimate-interest basis requires the statutory balancing of interests. Reading this policy or accepting the Terms is not blanket consent to optional processing, third-party disclosure, or overseas transfers.

Optional contact sharing requires a separate user action where indicated. Veilink does not make an employer's hiring decision, a person's career decision, a buyer's purchasing decision, or a seller's contracting decision.

04

AI-assisted processing

Veilink uses AI models to normalize individual and hiring inputs and, where limited B2B testing is enabled, offering and sourcing inputs; create embeddings; identify potentially relevant records; and generate summaries or suggested next steps. Relevant inputs and system instructions may be sent to our AI processor as needed for those tasks.

AI outputs and similarity signals can be incomplete or wrong. Veilink does not expose a candidate-quality, employability, or hiring-eligibility score. Internal role-specific retrieval signals are used only to organize potentially relevant records for review; they are not a final employment or purchasing decision and do not send contact details on your behalf.

You may ask for access, correction, deletion, an explanation of automated processing, or human review where applicable by emailing support@veilink.ai.

05

Controlled contact sharing

Before direct contact sharing, hiring uses limited individual and company information. A permitted hiring conversation request identifies the company, while the representative's name, email, and phone number remain separate. In limited B2B testing where enabled, buyer sourcing briefs are not searchable by sellers or exposed as leads. After a buyer initiates an inquiry, the selected seller receives only the approved, stage-limited structured projection needed to review the seller offering against that sourcing need. Direct contact details are not part of an initial request.

Names, email addresses, phone numbers, and other direct contact details open through the secure contact-sharing flow only after the required user actions. This is the intended product flow, not an absolute technical guarantee.

Where Korean law requires consent to third-party provision, the disclosure must identify the recipient, purpose, data items, recipient retention period, and the right to refuse and consequences before consent is requested. Accepting a conversation request alone does not authorize contact disclosure. Refusing optional contact sharing prevents that exchange and does not itself require account closure.

06

Other users and service providers

When you approve an AI-client connection requesting identity access, Veilink provides that client with a stable account identifier. If you also approve email access, the client can receive your verified sign-in email and its verification status for account identity and organization domain restrictions. For an OpenAI connection, OpenAI receives this information. Existing connections do not gain email access without a new approval. This identity access is separate from disclosure to hiring participants; you can revoke the client connection in your account settings.

Other hiring participants receive only the information allowed by the current request, clarification, and contact-sharing stage. In limited B2B testing where enabled, the same staged-access principle applies; sellers cannot search private buyer sourcing briefs or use Veilink for outbound pitching. Do not submit another person's data unless you are authorized to do so.

Google Cloud processes hosting, databases, logs, and monitoring data; Resend processes transactional email; Google processes OAuth sign-in data; OpenAI processes the inputs needed for normalization, embeddings, relevance checks, and summaries; and Creem processes company checkout, subscription, payment, tax, invoice, cancellation, and refund information. Each provider processes data for its service role and under its own terms and safeguards.

We may disclose information when required by law or reasonably necessary to investigate fraud, abuse, security incidents, rights violations, or threats to users or the service. We do not sell personal data or use it for behavioral advertising.

07

International processing

New accounts are currently available only outside the EEA, United Kingdom, and South Korea. Any Veilink-managed account data retained for an existing user or company representative in Korea remains assigned to the US region and stored in the shared US service infrastructure for permitted account management, closure, security, and legal-retention purposes. We do not offer a separate Korea-only database or Korean data-residency option. Access in these temporarily restricted territories is planned for a future release.

Google, Resend, OpenAI, and Creem may process necessary data in the United States and other provider locations through encrypted network transmission when you sign in, receive email, use AI-assisted features, or manage company billing. Retention follows the periods below and each processor's service lifecycle.

For Korean personal data, overseas processing or storage necessary to enter into or perform the service agreement may rely on Article 28-8(1)(3) of the Personal Information Protection Act only with the required disclosures. A transfer outside that basis requires a separate lawful basis, including separate consent where applicable. An overseas recipient's own policy or acceptance of these Terms does not replace Veilink's obligations.

Before a Korean-law transfer begins, Veilink must disclose the recipient's legal name and contact details, country, data items, transfer timing and method, purpose, retention period, and refusal procedure and consequences through the applicable policy or notice. A generic reference to other provider locations does not replace those disclosures.

You can refuse international processing before submitting information or contact support@veilink.ai to request processing suspension, consent withdrawal where processing relies on consent, or account deletion. If the refused transfer is necessary for account hosting, we cannot provide the account on the current US infrastructure. Refusal relating only to an optional feature restricts that feature. Withdrawal does not erase a separate statutory retention duty.

08

Retention and destruction

Account, individual, company, and hiring-position data, plus seller-offering and buyer-sourcing data created in limited B2B testing, is kept while the account or applicable record is active. After a valid deletion request, access is disabled and the request enters retention review. Data is then deleted or irreversibly anonymized unless a legal, security, dispute, or shared-workspace reason requires limited retention. Residual backup copies expire through the applicable backup lifecycle.

After an account deletion request, the account-linked retention deadlines run from the request date: up to 180 days for authentication and security records, 365 days for structured request and workflow records, and 1,095 days for consent and contact-sharing evidence needed to establish what users authorized. These are deletion-related retention periods, not a promise that active-account logs expire that many days after creation. Complaint and dispute evidence is retained only as needed for the applicable dispute or legal obligation.

Subscription, invoice, transaction, tax, cancellation, and refund records may be retained for the period required by accounting, tax, payment-dispute, anti-fraud, and other applicable legal obligations, even after a company stops using a paid plan.

A legal hold, security investigation, unresolved dispute, or statutory duty may require longer retention. When data is no longer needed, it is deleted or irreversibly anonymized using the applicable database, storage, and backup deletion process.

09

Your rights

Subject to applicable law, you may request access, a copy, correction, deletion, suspension or restriction of processing, withdrawal of consent, information about contact sharing, and review or explanation of automated processing.

Send requests to support@veilink.ai from the email associated with the account. We may verify identity and authority before acting. You may authorize a representative where applicable law permits.

Residents of California, the EEA, the United Kingdom, Korea, and other jurisdictions may have additional rights under local law. We will honor those rights where they apply and will not discriminate for exercising them.

10

Cookies and local storage

Veilink uses an essential secure session cookie after authentication. Restricted pre-release access may use a separate essential access cookie. These are required to keep the relevant session available and protected.

The website stores theme preference and dismissed in-app notices in browser local storage. We do not currently use advertising cookies or cross-site behavioral advertising trackers.

11

Security and operator access

We use safeguards including access controls, signed AI-agent requests, session expiration, encryption in transit, restricted contact-sharing stages, rate limits, logging, and monitoring. No internet service can guarantee absolute security.

Authorized Veilink operators may access account, workflow, security, and support data only when needed to operate, secure, investigate, or support the service. Sensitive access may require additional controls and is logged where supported.

12

Children

Veilink is a professional introduction service and is not directed to children. Do not create an account unless you have the legal capacity to use the service and provide the required consent.

13

Privacy contact

Privacy contact: Eam Juhyuk, Representative and Privacy Contact, Veilink Inc. (주식회사 베일링크). Email: support@veilink.ai.

You may also contact the competent privacy or data-protection authority in your jurisdiction. In Korea, this includes the Personal Information Protection Commission and the channels it identifies for complaints and remedies.

14

Changes

We may update this policy as the service, providers, data flows, or law changes. The current version and effective date will remain published here. We will provide additional notice or request renewed consent when a material change requires it.

Current access, company-plan pricing, and operational limits are described on the Pricing page. A material change to payment processing or the categories of personal data involved will be reflected in this policy before it applies where required.

The current version and effective date remain published on this page. Mandatory privacy rights are not reduced by this policy.

Questions or data requests

Email support@veilink.ai from your account address for privacy questions, access, correction, or deletion requests.