Privacy

Privacy Policy

How we collect, use, and protect your information

GDPR Compliant
CCPA Compliant
Last Updated: January 2026

11. Introduction

i-ESG Inc. ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our ESG Report Platform (the "Service"). We are committed to protecting your privacy and strive to align our data practices with the principles of major data protection regulations, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection Act (PIPA) of Korea, the Act on Protection of Personal Information (APPI) of Japan, and the Personal Information Protection Law (PIPL) of China. We are continuously improving our systems and processes to better serve your privacy rights. For specific data subject requests (access, deletion, portability, etc.), please contact us at info@i-esg.io, and we will process your request in accordance with applicable laws. By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with our practices, please do not use the Service.

22. Data Controller

i-ESG Inc. is the data controller responsible for your personal data. Contact Information: i-ESG Inc. Address: 8F, Room 823, Twin City Namsan 2 Office, 366 Hangang-daero, Yongsan-gu, Seoul, Republic of Korea Phone: +82-2-3211-4374 Email: info@i-esg.io If you are located in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.

33. Information We Collect

We collect information in several ways: Account Information • Name and email address • Company name and industry • Password (encrypted) • Profile preferences and settings Report Data • ESG questionnaire responses • Company environmental, social, and governance metrics • Uploaded documents and images • Report content and customizations Usage Information • Features used and actions taken • Report creation and editing history • Session duration and frequency • Browser type and device information Payment Information • Billing address • Payment method (processed by Stripe; we do not store full card numbers) • Transaction history Technical Information • IP address • Browser type and version • Operating system • Referring URLs • Pages visited and time spent

55. How We Use Your Information

We use collected information for: Service Delivery • Creating and managing your account • Providing AI-powered report generation • Enabling report editing and customization • Generating PDF exports • Creating shareable report links Customer Support • Responding to inquiries and requests • Providing technical assistance • Sending service updates and notifications Service Improvement • Analyzing usage patterns and trends • Developing new features and functionality • Fixing bugs and improving performance • Training and improving AI models (using anonymized data only) AI Model Training Opt-Out We may use anonymized and aggregated data to improve our AI models. If you prefer that your data not be used for AI model training, you may opt out by contacting us at info@i-esg.io with the subject line "AI Training Opt-Out." Please note that opting out does not affect our ability to use your data for providing the Service or for other purposes described in this Privacy Policy. Security and Compliance • Protecting against unauthorized access • Detecting and preventing fraud • Complying with legal obligations

66. Third-Party Service Providers

We share data with trusted third-party service providers who assist in operating our Service: Authentication • Supabase Auth: Manages user authentication and session tokens • Data processed: Email, password hash, authentication tokens Database and Storage • Amazon Web Services (AWS) RDS: Stores application data in PostgreSQL database • Supabase Storage / AWS S3: Stores uploaded files and generated PDFs • Data processed: All account and report data Payment Processing • Stripe: Processes all payment transactions • Data processed: Payment method, billing address, transaction details • Stripe's privacy policy: https://stripe.com/privacy AI Processing • Dify AI: Powers report generation and content suggestions • Data processed: Questionnaire responses (processed for report generation) • Data is not retained by Dify after processing All third-party providers are bound by data processing agreements and are required to protect your data in accordance with applicable laws.

77. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including countries that may not have equivalent data protection laws. Data Storage Locations • Primary database: AWS data centers (region-specific) • Authentication: Supabase infrastructure • File storage: Regional storage with CDN distribution Safeguards for Transfers When transferring data internationally, we implement appropriate safeguards: • Standard Contractual Clauses (SCCs) approved by the European Commission • Data Processing Agreements with all service providers • Technical measures including encryption in transit and at rest • Regular security assessments of third-party providers For transfers from the EEA to the United States, we rely on Standard Contractual Clauses and ensure our US-based providers maintain appropriate data protection standards.

88. Data Retention

We retain your data for the following periods: Account Data • Active accounts: Retained while account is active • After account closure: 3 years for business and legal purposes • Anonymized data may be retained indefinitely for analytics Report Data • Active reports: Retained while associated account is active • Draft reports: 90 days of inactivity before automatic deletion • Exported reports: 30 days in storage cache Payment Records • Transaction records: 7 years for tax and accounting compliance • Payment method details: Stored by Stripe, not retained by us Usage Logs • Server logs: 90 days • Analytics data: 26 months (anonymized) After Termination • You may export your data within 30 days of account closure • Data is permanently deleted within 90 days of account closure • Backups are purged within 180 days

99. Your Rights

GDPR Rights (EEA Residents) • Right of Access: Request a copy of your personal data • Right to Rectification: Correct inaccurate or incomplete data • Right to Erasure: Request deletion of your personal data ("right to be forgotten") • Right to Restriction: Limit how we process your data • Right to Data Portability: Receive your data in a structured, machine-readable format • Right to Object: Object to processing based on legitimate interests • Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing CCPA Rights (California Residents) • Right to Know: Learn what personal information we collect and how it's used • Right to Delete: Request deletion of your personal information • Right to Opt-Out: Opt out of the "sale" of personal information (we do not sell personal information) • Right to Non-Discrimination: Not be discriminated against for exercising your rights Exercising Your Rights To exercise any of these rights, contact us at privacy@i-esg.io. We will respond to your request within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before processing your request.

1010. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience: Essential Cookies • Authentication and session management • Security features • Load balancing These cookies are necessary for the Service to function and cannot be disabled. Functional Cookies • Language and region preferences • User interface customizations • Remember login status These cookies enhance functionality but are not strictly necessary. Analytics Cookies • Usage patterns and feature adoption • Performance monitoring • Error tracking These help us improve the Service. Managing Cookies You can control cookies through: • Browser settings (blocking or deleting cookies) • Our cookie consent banner (where applicable) • Opting out of analytics (contact us) Note that disabling certain cookies may affect Service functionality.

1111. Security Measures

We implement comprehensive security measures to protect your data: Encryption • Data encrypted in transit using TLS 1.3 • Data encrypted at rest using AES-256 • Password hashing using industry-standard algorithms Access Controls • Role-based access for employees • Multi-factor authentication for administrative access • Regular access reviews and audits Infrastructure Security • Firewalls and intrusion detection systems • Regular security assessments and penetration testing • DDoS protection • Secure development practices (OWASP guidelines) Monitoring • 24/7 system monitoring • Automated threat detection • Incident response procedures • Regular security training for staff While we implement robust security measures, no system is completely secure. If you discover a security vulnerability, please report it to security@i-esg.io.

1212. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@i-esg.io. If we discover we have collected personal information from a child under 18, we will delete it promptly. If you are under 18, please do not use the Service or provide any personal information.

1313. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. Notification of Changes We will notify you of material changes by: • Email notification to your registered email address • Prominent notice on our website • In-app notification when you next log in Effective Date Changes become effective 30 days after notification, unless: • Required immediately by law • Changes are to your benefit (effective immediately) Your Choices If you do not agree with changes to this Privacy Policy, you may close your account before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically. The "Last Updated" date at the top indicates when this Policy was last revised.

1414. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: i-ESG Inc. Address: 8F, Room 823, Twin City Namsan 2 Office, 366 Hangang-daero, Yongsan-gu, Seoul, Republic of Korea Phone: +82-2-3211-4374 Email: info@i-esg.io For data protection inquiries, security concerns, or data access requests, please contact us at the email address above with the appropriate subject line. We aim to respond to all privacy inquiries within 5 business days and will address data access requests within the timeframes required by applicable law (30 days for GDPR, 45 days for CCPA, as applicable under regional laws).

1515. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: Notification to Authorities • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33 • Provide detailed information about the nature of the breach, categories of data affected, and measures taken Notification to Affected Individuals • If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay • Notification will include a description of the breach, potential consequences, and measures you can take to protect yourself Breach Response Measures • Immediate containment and assessment of the breach • Investigation to determine the cause and scope • Implementation of measures to prevent future occurrences • Documentation of all actions taken for compliance purposes Your Role If you suspect any unauthorized access to your account or believe your data has been compromised, please contact us immediately at info@i-esg.io.

1616. Regional Privacy Law Compliance

In addition to GDPR and CCPA, we comply with the following regional privacy laws: Korea - Personal Information Protection Act (PIPA) If you are a resident of the Republic of Korea, you have the following rights: • Right to be informed about the collection and use of your personal information • Right to consent or refuse consent to the processing of your personal information • Right to request access to your personal information • Right to request correction of inaccurate personal information • Right to request suspension of processing • Right to request deletion of your personal information • Right to withdraw consent at any time Japan - Act on Protection of Personal Information (APPI) If you are a resident of Japan, you have the following rights: • Right to request disclosure of your personal information • Right to request correction, addition, or deletion of inaccurate information • Right to request cessation of use or provision of personal information • Right to request deletion of personal information obtained improperly China - Personal Information Protection Law (PIPL) If you are a resident of the People's Republic of China, you have the following rights: • Right to know and decide regarding your personal information • Right to restrict or refuse the processing of your personal information • Right to request access to and copy your personal information • Right to request correction or supplementation of your personal information • Right to request deletion of your personal information • Right to request explanation of personal information processing rules • Right to withdraw consent To exercise any of these rights, please contact us at info@i-esg.io with the subject line "Regional Privacy Rights Request" and specify your country of residence.

If you have any questions about this Privacy Policy, please contact us at info@i-esg.io

Privacy Policy | ESG Report Platform