Decisionproof Terms of Use
IMPORTANTWhat this document is, and what governs
The contract between you and the company is the Korean 이용약관 published at /ko/terms.html. This English document states the same terms in English so that an English-reading customer can read them.
- The Korean text prevails. Where a Korean version and a version in another language coexist, the Korean version prevails for a contract governed by the law of the Republic of Korea (Article 34(3)).
- This document does not add to or change the contract. Under Article 4(4) the documents the company publishes other than the Korean 이용약관 — including this English text, information and marketing pages, machine-readable files and technical documentation — do not modify or supplement the contract and do not become part of it. Article 4(5) preserves the company's liability under law for what it publishes, and no statement here limits a mandatory consumer right.
- If the two texts ever differ, that is a defect in this document, not a second set of terms. Please report it to contact@decisionproof.io.kr.
The Korean instrument marks its most important clauses with the label 「중요」, as Korean law on standardised terms requires. The same clauses are marked IMPORTANT here, in the same places.
IMPORTANTSummary of the important clauses
This summary carries no meaning different from the body. Where the two differ the body applies, and the summary is not read less favourably to the customer than the body.
- IMPORTANT — Articles 12 and 17: acts performed with a credential or an authenticated session. An execution, use or order made with your credential or through your authenticated session is presumed to be your act, whether a person or a system you permitted composed it. The presumption is rebuttable. If you learn that a credential or a session has been compromised, notify the company without delay. For executions and orders made after your notice was sent, the presumption is rebutted with no time limit, and your own record of having sent the notice is all that is needed. Claiming a rebuttal backdated to the time you state you became aware is subject to a look-back limit, and anything beyond that limit must be supported by material you submit (Articles 12(5)–(6) and 17(6)–(7)). If you are a consumer, that limit and that evidential requirement are relaxed (Articles 12(10) and 17(11)). Where you dispute the presumption, the company gives you the execution, payment and credential records it holds. The presumption does not apply to the company's own wilful misconduct or gross negligence.
- IMPORTANT — Article 15: a one-time purchase does not renew. Access ends when the period expires. A subscription, if you choose one, renews automatically at the interval shown on the purchase screen until you cancel it, and you may cancel at any time from your billing page.
- IMPORTANT — Article 18: withdrawal of subscription. A statutory right of withdrawal prevails over this contract. Withdrawal may be restricted for the portion of the service already supplied only where you were told so in advance at the time of purchase and gave separate consent.
- IMPORTANT — Article 19: refunds. There is no automatic, immediate or self-service refund. The company reviews the records and then decides whether to refund and how much.
- IMPORTANT — Article 22: temporary suspension (protective measure). Only on the stated grounds and only to the extent needed, with notice and restoration.
- IMPORTANT — Article 25: retention. The inputs in an execution request are deleted 30 days after the execution completes; the execution record itself is kept for audit and is not deleted. Online access to a result artifact is blocked after the same 30-day period.
- IMPORTANT — Article 26: overseas processing. Transmission of the question and context you submit to an AI model provider located in the United States was suspended on 4 August 2026 and resumes on 20 August 2026. The company has recorded the resumption and its date in the privacy policy, and the resumption follows that policy's effective date.
- IMPORTANT — Article 30: limitation of liability. The scope and the ceiling of damages are limited. Liability for the company's wilful misconduct or gross negligence, and liability that mandatory law does not permit to be limited, are not limited.
Chapter 1 — General provisions
Article 1 (Purpose)
These terms set out the rights, duties and responsibilities as between 디플런트 (D_FFERENT, the "company") and the customer in relation to use of the Decisionproof service (the "service").
Article 2 (Definitions)
(1) In these terms:
- "You" means the natural or legal person who has entered into a use contract with the company under these terms and holds a workspace. "You" and "customer" have the same meaning.
- "Workspace" means the unit of service use attributed to you.
- "Delegated system" means a software system you have permitted to operate your credential or your authenticated session, including an artificial-intelligence system, a model, a tool, a script or an automation.
- "Credential" means an API key issued to your workspace.
- "Label" means the statement you attach to a credential identifying the system or purpose that will use it.
- "Execution" means one work request you submit to the service and its processing.
- "Customer content" means the question, context and other material you submit as part of an execution request.
- "Usage limits" means the limits on use of the service that the company publishes.
- "Maximum usage" means the ceiling the company applies to a single execution.
- "Usage review" means inspecting the record of your use of the service.
- "Consumer" means an individual using the service for a purpose other than a business or professional activity, and includes anyone recognised as a consumer under applicable consumer-protection law.
- "Business customer" means a legal person, organisation or individual using the service for a business or professional purpose who is not a consumer.
(2) Whether you are a consumer is determined under applicable law. The definition in paragraph (1)11 does not exclude or limit the status of consumer that the law recognises in you, and you are not treated as a business customer by force of these terms where you are in fact a consumer. If the company wishes to treat you as a business customer it must state its grounds.
(3) Terms not defined here have the meaning given by applicable law and trade practice.
IMPORTANTArticle 3 (Publication, explanation and effect of these terms)
(1) The company publishes the full text of these terms on the service screen at all times so that a customer can read them whenever they wish.
(2) At the conclusion of a use contract the company presents these terms, explains the important clauses so that the customer can understand them, and gives the customer a copy on request.
(3) The company assigns each version an identifier and an effective date, and maintains a route by which the full text of a superseded version can be read. The full text of the immediately preceding version (en-20260820-4) is available at https://decisionproof.io.kr/legal/terms/en-20260820-4.html.
(4) The Korean 이용약관 is itself the contract document applying to a use contract governed by the law of the Republic of Korea, and is not replaced by a notice of, or a link to, these English terms.
Article 4 (Interpretation, and relationship to other published documents)
(1) These terms are interpreted fairly and in good faith, and are not interpreted differently for different customers.
(2) Where the meaning of a provision is not clear, it is interpreted in the customer's favour.
(3) As to the price, the access period and the usage limits of the access you purchased, what the purchase screen displayed at the moment you completed the purchase applies. Where that display and these terms differ, the more favourable to you applies, as to those three items.
(4) Except for the three items and the purchase screen named in paragraph (3), the content of the contract between you and the company is as these terms provide. Other documents the company publishes — including these English terms, information and introduction pages, machine-readable files, technical documentation and promotional material — do not modify or supplement the contract and do not become part of it.
(5) Paragraphs (3) and (4) do not limit a mandatory right that applicable law guarantees a consumer. Nor do they exclude or limit the liability the company bears under applicable law for the representations, advertising and information it publishes.
Article 5 (Amendment of these terms)
(1) The company may amend these terms to the extent that doing so does not contravene applicable law.
(2) The company gives notice of the content of an amendment and its effective date, on the service and to the e-mail address you registered, from 7 days before the effective date.
(3) For an amendment that is disadvantageous to the customer the company gives that notice from 30 days before the effective date — a longer period than paragraph (2) — and gives it individually, both on the service and to the registered e-mail address.
(4) When giving notice under paragraphs (2) and (3) the company also states that a customer who does not agree to the amendment may terminate the use contract, and how to do so. Where the customer neither expresses refusal within the notified period nor stops using the service, the amended terms apply to that customer from the effective date. However, for an amendment that is disadvantageous to the customer the company does not apply the amended terms on the strength of this paragraph alone; it gives individual notice and obtains the customer's express consent.
(5) Where a customer terminates because they do not agree to an amendment, the company decides whether and how much of the price corresponding to the unused period to refund, under Article 19.
(6) Each use contract is governed by the version in force at the time that contract was concluded.
Article 6 (Exception for the company's wilful misconduct or gross negligence)
(1) A provision of these terms that limits or excludes the company's liability, that attributes a risk or an act to you, or that imposes an indemnity or a hold-harmless obligation on you, does not apply to any part arising from the company's own wilful misconduct or gross negligence.
(2) Nothing in these terms excludes or limits liability of the company that mandatory law does not permit to be excluded or limited.
(3) Paragraphs (1) and (2) apply whether or not an individual provision of these terms carries wording to the same effect.
Article 7 (Operator information)
(1) The company's operator information is as follows.
| Trade name | 디플런트 (D_FFERENT) |
|---|---|
| Representative | 배성무 (Bae Sungmoo) |
| Business address | (18469) 경기도 화성시 동탄첨단산업1로 58, 지하2층 B201호 (영천동, 퍼스트코리아), Republic of Korea |
| Telephone | +82 10-7634-6265 |
| contact@decisionproof.io.kr | |
| Business registration number | 502-70-09679 |
| Mail-order sales registration number | 2026-화성동탄-1685 |
| Privacy officer | 배성무 / contact@decisionproof.io.kr |
(2) The company displays the information in paragraph (1) on its landing screen so that a customer can find it easily. That display is currently made on the Korean landing screen at /ko/; the same information is reproduced in this Article and in the privacy policy.
Chapter 2 — Parties, automated means and credentials
Article 8 (Formation of the use contract, and eligibility)
(1) A use contract is formed when the customer agrees to these terms and the company accepts.
(2) On concluding a use contract the customer represents and warrants each of the following.
- That they are at least 19 years of age, or of the age of majority under the law of their place of residence. Where the two differ, the higher age applies.
- That they have the legal capacity required to conclude a contract under these terms.
- That, where concluding the contract for a legal person or an organisation, they hold authority to do so on its behalf.
(3) The representations in paragraph (2) are made by you in your own capacity and are not affected by the fact that you use a delegated system.
(4) Where the company establishes that a person of limited capacity has used the service, it notifies that person or their legal representative and discusses how the use contract is to be handled. The company confirms that the representations in paragraph (2) do not by themselves exclude a statutory right of avoidance held by a person of limited capacity or by their legal representative.
Article 9 (Parties, and the use of automated means)
(1) The parties to a contract under these terms are the company and you.
(2) A delegated system is not a party. It has no capacity to accept these terms, to hold a workspace or to bear an obligation, and an acceptance transmitted by a delegated system is your acceptance.
(3) Nothing in these terms confers on a delegated system authority to make a declaration on your behalf. A delegated system cannot bind you to a third party, amend these terms, or waive a right of yours.
(4) The company forms no direct contractual relationship with a delegated system.
(5) The company does not detect or determine whether the party submitting a request is a person or a system, and holds no means of determining it.
Article 10 (Attribution of a delegated system's acts during performance)
(1) In the performance of a contract already formed, you bear responsibility as between you and the company for the acts, and the intent or negligence, of a delegated system you permitted to be used, as for your own acts and your own intent or negligence.
(2) A third party the company uses in order to provide the service, including a model provider, is a party the company uses for its own performance. You are not in a direct contractual relationship with that third party and owe it no payment obligation of any kind. The company neither makes nor intermediates any payment between you and that third party.
(3) Paragraph (1) applies at the performance stage. Formation of a contract, including the submission of an order, is governed by Article 17.
(4) This Article does not limit liability for the company's wilful misconduct or gross negligence.
Article 11 (Issue and labelling of credentials, and matters the company does not verify)
(1) You may issue credentials from your workspace. You must attach to each credential a label identifying the system or the purpose that will use it; attaching a label is mandatory.
(2) That label is only your own statement. The company does not verify it, does not represent that it verifies it, and holds no means of verifying it.
(3) A scope recorded alongside a credential is a matter of your own record: it is recorded and is not enforced. Every credential issued to a workspace carries that workspace's full authority.
(4) The request-rate limit applies per workspace, and all credentials of a workspace share one limit. Issuing further credentials does not increase it, and one delegated system can exhaust the limit available to another. The value in force on the effective date is 60 requests per rolling 60 seconds.
(5) The company's execution records identify the workspace only; they do not identify which credential or which system submitted an individual request.
(6) A credential's secret value is displayed once at issue. The company cannot recover it or present it again. You must keep it secure.
(7) Issuing, rotating and revoking a credential are recorded with the account and the time of the person who performed the act. That record records acts performed upon a credential; it does not record acts performed by means of a credential.
(8) Where the system operating a credential changes, you must revoke that credential and issue a new one bearing an accurate label. The company does not provide a facility for editing a label already attached.
(9) A workspace may hold at most 3 concurrently valid credentials.
IMPORTANTArticle 12 (Attribution of acts performed with a credential)
(1) Presumption. A request authenticated with a credential issued to your workspace is presumed to be your act, whether it was composed by a person directly or by a system you permitted to operate that credential.
(2) Effect. You bear responsibility for the executions, usage and charges arising under paragraph (1). That includes use by your officers and employees, contractors, persons performing work for you, automated systems, and anyone else who obtains access to the credential. This does not apply to any part for which the presumption in paragraph (1) is rebutted under paragraph (6).
(3) Matters the company does not verify. The company does not verify whether the system indicated by a credential's label in fact made a request, does not represent that it verifies it, and holds no means of verifying it. The company's execution records identify the workspace only (Article 11(2) and 11(5)).
(4) Exclusion for the company's wilful misconduct or gross negligence. The presumption in paragraph (1) and the responsibility in paragraph (2) do not apply to any part arising from the company's own wilful misconduct or gross negligence. This Article does not limit liability for the company's wilful misconduct or gross negligence.
(5) Notice of compromise — a fact you can create yourself. You must keep your credentials secure and must notify the company, at the contact in Article 33, without delay from the time you become aware of theft, disclosure, damage or unauthorised use of a credential. You may state in that notice the time at which you became aware. The fact and the time of sending that notice can be proved by your own sending record alone; no record of the company's is required.
(6) Grounds of rebuttal. The presumption in paragraph (1) is rebutted where there is a cause not attributable to you. The following are examples of such a cause and are not an exhaustive list.
-
Where the request in question falls within any of the following. Whether
it does is decided by comparing the time on your own record of sending the notice against
the times in the execution and payment records the company provides under paragraph (8);
no other proof is required of you.
- a. A request made after the notice under paragraph (5) was sent to the company. There is no time limit on this sub-paragraph.
- b. A request made after the time of awareness stated in the notice under paragraph (5), where that time of awareness is within 7 days back from the time the notice was sent.
- c. Where the time of awareness reaches back beyond the period in sub-paragraph b, and you submit material supporting that time of awareness. It is enough that the material is what you would ordinarily come to hold had the compromise actually occurred; material held only by the company is not required. Examples are the fact that you revoked or rotated the credential, a security-incident record from your own systems or devices, a report or filing made to a law-enforcement body, a specialist security organisation or an insurer, or a record of your having informed your staff or counterparties of the compromise.
- A part arising from an error in the company's systems, a duplicate execution, or a failure of a third-party service the company uses
- Where the company knew, or could have known, of the theft, disclosure or damage of a credential and failed to take the necessary measures
- Any other case in which you are found not to be at fault
(7) Rules that make paragraph (6)1 usable in practice. The time of awareness under paragraph (6)1 is the time stated in your notice; where the company disputes that the stated time is correct, the company must produce the facts. You may also invoke paragraphs (6)2 to (6)4 in respect of requests made before the time of awareness. However, you may not invoke paragraph (6)1 for any part where you continued to use the credential after the time of awareness or received and used the results of the request, and the company must produce the records under paragraph (8) to show it.
(8) The company's duty to produce records. Where you dispute the presumption in paragraph (1), the company gives you, within a reasonable period from your request, the records it holds in relation to the matter. These include execution records (times and counts), payment records, and the history of issue, rotation and revocation of credentials with the actor and the time. The company cannot produce records it does not hold under paragraph (3), and does not require you to prove a fact of which it holds no record.
(9) Separate wording for consumers. Where you are a consumer, the company must, before asserting the presumption in paragraph (1), produce circumstances supporting that the use in question was made by you or by a system you permitted — for example that the time, frequency or content of the requests is consistent with your usual pattern of use, or that you received or used the results of that use — and where you show that you are not at fault, the presumption in paragraph (1) is rebutted.
(10) Where you are a consumer, paragraph (6)1 and paragraph (7) apply as relaxed below.
- The period in paragraph (6)1.b is 14 days.
- As to the material in paragraph (6)1.c, submitting what you hold is sufficient. Where circumstances mean you hold none, you may dispute the matter under paragraph (6)4, and paragraph (9) then applies as well.
- The proviso in paragraph (7) applies only to the part whose results you actually received and used.
Article 13 (Revocation of a credential, and termination of a delegation)
(1) You may revoke an individual credential at any time and for any reason, and may revoke every credential of a workspace at once.
(2) Issuing, rotating and revoking a credential can be done only from a session in which you are logged in as a person, and cannot be done with an issued credential. Your power of revocation therefore does not depend on the cooperation of a delegated system.
(3) A delegated system cannot issue, rotate or transfer a credential to another system, and you must not permit it to. A further delegation requires a fresh act of permission by you.
(4) You may notify the company of the termination of a delegation at the contact in Article 33. The company receives that notice. What actually ends access is your own act of revocation under paragraph (1). The company does not undertake a processing deadline or a response time for a notice under this paragraph.
(5) Where the access right has ceased to be valid (including expiry of the access period, non-payment, cancellation or return of the price, or termination of the use contract), requests to the service are refused at the entitlement check. Even then, the company does not revoke the credentials issued to you. Revocation of a credential is effected only by your own act under paragraph (1).
(6) Where the company applies a protective measure under Article 22, its effect operates at workspace granularity. The company does not provide a facility for suspending an individual delegated system selectively.
Chapter 3 — Purchase, price and refunds
Article 14 (Order acknowledgement)
(1) On receiving your declaration of offer the company notifies you without delay, to the e-mail address you registered, of the fact of receipt and of the content of the contract. That notice is the order acknowledgement by which the company informs you that it has received your offer, under the Act on Consumer Protection in Electronic Commerce, etc.
(2) The notice under paragraph (1) states each of the following.
- The order identifier
- The payment provider and its order reference
- The price and the currency
- The type of access purchased and the access period
- The date and time at which payment was confirmed
- The versions of the terms of use and the privacy policy applicable to that order
- Guidance on withdrawal under Article 18 and on the refund procedure under Article 19
- The operator information in Article 7(1)
(3) The time at which the notice under paragraph (1) takes effect is governed by Article 33(3).
(4) Where sending fails, the notice takes effect when the announcement on the service is posted, under the second sentence of Article 33(3), and the company records the outcome of the send. The company does not treat a failure to send as discharging its duty under paragraph (1), and you may request a resend or a copy of that notice at the contact in Article 33.
(5) The notice under paragraph (1) does not alter the purchase-screen display referred to in Article 4(3). Where the notice and the actual payment record differ, the more favourable to you applies.
(6) The notice under paragraph (1) uses the e-mail address of the account you signed in with. The company does not collect a separate delivery address for this notice, and that address is the "e-mail address you registered" for the purposes of Article 33(2).
IMPORTANTArticle 15 (Content of the service, and usage limits)
(1) By paying the price you acquire the right to access the service for the period shown on the purchase screen for the plan you bought — currently 30 days or 365 days, within the usage limits the company publishes. Where the screen and this article differ, Article 4(3) makes the screen controlling.
(2) The period in paragraph (1) runs from completion of payment. A one-time purchase does not renew: access to the service ends when the period expires, and to continue using the service you must purchase again.
(2)-2 A subscription renews automatically. Where you purchase a subscription, each renewal grants a further period of the length shown on the purchase screen, and renewal continues until you cancel it under Article 16(6). The price and the renewal interval are those displayed on the purchase screen at the moment you subscribe.
(3) The usage limits the company applies include the request-rate limit (Article 11(4)) and a ceiling on maximum usage per execution, and their specific values are as stated in the documents the company publishes. Requests exceeding a usage limit are refused. The values in force on the effective date are:
- an access period per payment of 30 days, or 365 days where the purchase screen showed an annual plan — a one-time purchase does not renew, and a subscription renews each cycle until cancelled (Article 15(2), 15(2)-2);
- a per-execution spend ceiling (
reservation.max_cost_usd) of US$5.00 — the maximum amount reserved for a single execution, not an account-level, workspace-level, monthly or billing-cycle budget; - a workspace request-rate limit of 60 requests per rolling 60 seconds;
- a metered-operation ceiling of 2,000 operations per 30-day access period, and twelve times that ceiling for a 365-day access period, hard-capped and fail-closed — once the ceiling is reached further requests are refused with HTTP 429
quota-exceededuntil the next paid access period; - a per-execution timeout of 30 seconds;
- per-execution input and output token limits of 16,000 and 4,000 respectively;
- at most 3 credentials (of the form
dp_live_{secret}) per workspace; - no overage billing — a request that would exceed any of the limits above is refused fail-closed with HTTP 429 rather than accepted for a further charge.
(4) The company does not charge any amount for use of the service beyond the price displayed on the purchase screen. The price displayed on the purchase screen at the moment you complete the purchase is the price that applies (Article 4(3)).
(5) You bear the taxes and public charges imposed on you by law in connection with your use of the service.
(6) When capacity is exhausted and the service stops accepting your requests until the next access period, the company records that stop. A stop of this kind — exhaustion of the metered-operation ceiling, exhaustion of the prepaid execution budget, or an inactive entitlement — is recorded with its type, the time it first occurred, the time it last occurred and the number of requests refused, and that record is retrievable through the usage API for the period you ask it about. A refusal that clears itself within a minute, such as the request-rate limit in paragraph (3), is not a stop of this kind and is not recorded this way. The company does not operate any state in which the service stops producing evidence without recording that it has stopped.
(7) The record described in paragraph (6) covers this service only. The company records the executions it governs and the refusals it issues. It cannot record what your systems do outside the service after a refusal. If your integration calls a model provider directly while the service is refusing your requests, the company holds no record of those executions. The company recommends that your integration stop on a refusal, and publishes the handling it recommends in the developer quickstart at https://decisionproof.io.kr/docs/quickstart.html. That document is published in English only.
(8) Where you purchase again while an access period you have already paid for is still running, the days remaining in it are added to the new period rather than replaced. The new access period ends the stated number of days after the end of the period you had already paid for, and the usage limits in paragraph (3) are measured afresh from the new purchase. Where the earlier period has already ended there are no remaining days to add, and the new period runs from completion of payment as stated in paragraph (2). This applies both where you purchase the same plan again and where you purchase a higher one.
Article 16 (Purchase procedure)
(1) You pay the price by the payment method the company designates. The method in use, and the payment provider operating it, are identified on the purchase screen and in the privacy policy.
(2) Every order is bound at the moment of its creation to your account and workspace, and that binding is not changed afterwards. Purchase without an account is not offered.
(3) Completing payment requires your approval step on the payment provider's screen. That step takes place under the agreement between you and the payment provider; the company is not a party to it and cannot complete it on your behalf.
(4) The company does not store your payment method. For a one-time purchase a fresh approval is required for each access period. For a subscription, the authorisation you give is held by the payment provider, and it is the payment provider that raises each renewal charge under it; the company neither holds that authorisation nor initiates the charge. The company does not receive or store card numbers, expiry dates or security codes.
(5) The price and the renewal interval of a subscription are those shown on the purchase screen when you subscribe. The company does not increase the price of an existing subscription without your consent.
(6) You may cancel a subscription at any time from the billing page of your account, without contacting the company. Cancellation takes effect from the next renewal: access for a period you have already paid for continues until that period ends. Cancellation is not a refund; refunds are governed by Articles 18 and 19.
IMPORTANTArticle 17 (Formation and attribution of an order submitted through an authenticated session)
(1) Your own advance declaration — the principal basis of formation. By agreeing to these terms you consent in advance to orders being submitted through your authenticated session within a scope you have fixed in advance. That advance consent is your own declaration and confers no authority on a delegated system.
(2) Fixing the scope in advance — it must be narrowly specified. The scope in paragraph (1) must be fixed in advance by specifying each of the following concretely.
- The service concerned
- The type and period of access permitted
- The ceiling on amount or usage permitted
- The identifiers of the credentials and sessions permitted
- The validity period of the advance consent
A blanket permission, or a permission whose scope is not specified, is not recognised as advance consent under paragraph (1). What is left to the delegated system is confined to choosing the timing and the quantity within the scope in paragraph (1).
The scope in paragraph (1) is a matter you determine on your own judgment and responsibility and keep yourself. The company does not receive it, does not record it and does not enforce it. The company does not check any request against that scope, and does not identify or block a request that exceeds it. The advance consent in paragraph (1) may be proved by a record you create and keep yourself.
(3) Attribution of the order. An order submitted through your authenticated session is presumed to be your order and your authorisation of payment, made on the basis of the advance consent in paragraph (1), whether you composed it directly or a system you permitted to operate that session composed it. Your obligation to pay does not depend on which of the two composed it.
(4) Ratification of an act done under your own advance consent — a supporting basis. Where you use the service provided pursuant to an order under paragraph (3), or retain its benefit, that ratifies the act done under your own advance consent and reinforces the advance consent in paragraph (1). This does not apply where you did not know of the order or reserved an objection to it.
(5) The limits of the company's payment records. The company's payment records show only that the order was submitted through your account. They do not show whether a person or a system composed it, and do not represent that they show it.
(6) Notice of session compromise — a fact you can create yourself. You must notify the company, at the contact in Article 33, without delay from the time you become aware that your authenticated session or your sign-in means has been stolen, disclosed, taken over or used without authority. You may state in that notice the time at which you became aware. The fact and the time of sending that notice can be proved by your own sending record alone; no record of the company's is required.
(7) Grounds of rebuttal. The presumption in paragraph (3) is rebutted where there is a cause not attributable to you. The following are examples of such a cause and are not an exhaustive list.
-
Where the order in question falls within any of the following. Whether it
does is decided by comparing the time on your own record of sending the notice against the
times in the payment and order records the company provides under paragraph (8); no other
proof is required of you.
- a. An order submitted after the notice under paragraph (6) was sent to the company. There is no time limit on this sub-paragraph.
- b. An order submitted after the time of awareness stated in the notice under paragraph (6), where that time of awareness is within 7 days back from the time the notice was sent.
- c. Where the time of awareness reaches back beyond the period in sub-paragraph b, and you submit material supporting that time of awareness. It is enough that the material is what you would ordinarily come to hold had the compromise actually occurred; material held only by the company is not required. Examples are the fact that you changed your sign-in means or ended the session, a security alert the authentication provider sent you, a record of your having disputed a transaction notice the payment provider sent you, or a report or filing made to a law-enforcement body, a specialist security organisation or an insurer.
- A part arising from an error in the company's systems, duplicate order processing, or a failure of a third-party service the company uses
- Where the company knew, or could have known, of the theft, disclosure or takeover of the session or the sign-in means and failed to take the necessary measures
- Where the order in question fell outside the scope you fixed under paragraph (2) and you produce a record of that scope
- Any other case in which you are found not to be at fault
(8) The company's duty to produce records. Where you dispute the presumption in paragraph (3), the company gives you, within a reasonable period from your request, the records it holds in relation to that order. These include the time the order was created, the identifiers of the account and workspace bound to it, and the payment-processing history. The company cannot produce records it does not hold under paragraph (5), and does not require you to prove a fact of which it holds no record.
(9) Where the time of awareness under paragraph (7) is disputed. The time of awareness under paragraph (7)1 is the time stated in your notice; where the company disputes that the stated time is correct, the company must produce the facts. However, you may not invoke paragraph (7)1 for any part where you continued to use the session after the time of awareness or received and used the service provided under that order, and the company must produce the records under paragraph (8) to show it.
(10) Separate wording for consumers. Where you are a consumer, the company must, before asserting the presumption in paragraph (3), produce circumstances supporting that the order in question was submitted by you or by a system you permitted — for example that the time or content of the order is consistent with your usual pattern of use, or that you used the service provided under that order — and where you show that you are not at fault, the presumption in paragraph (3) is rebutted.
(11) Where you are a consumer, paragraph (7)1 and paragraph (9) apply as relaxed below.
- The period in paragraph (7)1.b is 14 days.
- As to the material in paragraph (7)1.c, submitting what you hold is sufficient. Where circumstances mean you hold none, you may dispute the matter under paragraph (7)5, and paragraph (10) then applies as well.
- The proviso in paragraph (9) applies only to the part of the service provided under that order which you actually received and used.
(12) Related law. The effect of a declaration made through automated means is governed by applicable law, including the Framework Act on Electronic Documents and Transactions.
(13) Exclusion for the company's wilful misconduct or gross negligence. The presumption in paragraph (3) does not apply to any part arising from the company's own wilful misconduct or gross negligence. This Article does not limit liability for the company's wilful misconduct or gross negligence.
IMPORTANTArticle 18 (Withdrawal of subscription)
(1) A right of withdrawal that applicable law guarantees you prevails over these terms. You may withdraw your subscription within the period and on the conditions that applicable law provides.
(2) In respect of the portion of the service whose provision has begun, withdrawal may be restricted as applicable law provides. The company relies on that restriction only where it gave you notice of that fact in advance at the time of purchase and obtained your separate consent.
(3) The "portion whose provision has begun" in paragraph (2) is judged per execution. Your right of withdrawal survives in respect of the portion not yet executed and not yet provided.
(4) Where the company did not give the advance notice and obtain the separate consent required by paragraph (2), the company cannot assert the restriction in paragraph (2).
(5) The method and timing of refund on withdrawal are as provided in Article 19, save that the period and method that applicable law provides take precedence.
IMPORTANTArticle 19 (Refund procedure)
(1) You may request the company to terminate the use contract and refund the price, as applicable law and these terms provide.
(2) Where you request a refund under paragraph (1), the company reviews the payment record, the record of service use and any other relevant evidence, and then decides whether a refund is possible and in what amount.
(3) The refund amount is calculated on the basis of the number of executions already used and the remaining access period.
(4) Where a refund is decided, the company refunds it, as a rule, to the payment method by which you paid. Only where a refund to the original payment method is impossible does it pay to an account you designate.
(5) The company completes the review under paragraph (2) within 3 business days, and pays the refund within the period applicable law provides or, where applicable law provides none, within 3 business days.
(6) In addition to paragraphs (1) to (5), the company operates a commercial policy of individually reviewing a refund request received within 48 hours of the date of first purchase. That commercial policy does not by itself guarantee a refund, and does not limit any right applicable law guarantees you.
(7) Where the service was not provided for a cause attributable to the company, the company does not exclude a refund of that portion.
(8) A refund request is received at the contact in Article 33. There is no automatic, immediate or self-service refund: every refund is decided by the review in paragraph (2).
Article 20 (Changes to the content of the service)
(1) The company may, where there is good cause, change the following aspects of the service.
- Addition, modification or removal of features
- API endpoints
- The request-rate limit
- The ceiling on maximum usage per execution
- Operational defaults
(2) Good cause in paragraph (1) means compliance with law, a security need, a change in a third-party component, or a technical need for the stable provision of the service.
(3) For a change under paragraph (1) the company gives notice of its content and effective date, on the service and to the e-mail address you registered, no later than 30 days before the effective date. Where the matter is urgent for security reasons or applicable law requires immediate implementation, the company may give notice afterwards.
(4) Where a change disadvantageous to you is made you may terminate the use contract, and Article 19 applies to the treatment of the price corresponding to the unused period.
Chapter 4 — Provision of the service, support and suspension
Article 21 (Support)
(1) The company reviews and replies in order of receipt to enquiries and requests about use of the service, in respect of items received within business hours (weekdays 09:00–18:00, excluding weekends and public holidays).
(2) The support in paragraph (1) does not constitute a service level agreement under which the company guarantees a response within a particular time or a particular service availability.
(3) The company does not guarantee service availability.
(4) Support is by e-mail. There is no on-call rota and no telephone support line. The company does not support AI model output quality, prompt correctness, or a third-party provider's outage; support covers settlement, state, export and control-plane behaviour within the published API surface.
IMPORTANTArticle 22 (Temporary suspension of the service — protective measure)
(1) In any of the following cases the company may temporarily suspend part or all of the service, within the extent necessary to protect the stability of the service (a "protective measure", presented to customers as a "protective pause").
- Where a material error in the consistency of data within the service is suspected
- Where abnormal access or a serious security threat is detected
- Where the company otherwise reasonably judges that urgent action is required to protect the core functions and the data integrity of the service
(2) Where the company applies a protective measure it notifies the customer without delay of its reason, its duration and its scope. Where advance notice is technically impossible or seriously impracticable, it may notify afterwards.
(3) Once the company judges that the cause of the protective measure has been resolved, it resumes provision of the service without delay.
(4) A protective measure takes effect at workspace granularity, and the company does not provide a facility for suspending an individual delegated system selectively.
(5) You may object to the reason for, or the scope of, a protective measure, and the company reviews your objection.
(6) This Article does not limit liability for the company's wilful misconduct or gross negligence.
Article 23 (Termination of the contract)
(1) You may request termination of the use contract at any time, by the method in Article 33.
(2) In any of the following cases the company may terminate the use contract after demanding rectification within a reasonable period it specifies. Where there is an unlawful act, or a serious threat to the stability of the service, such that a demand is inappropriate, it may terminate without one.
- Where you have materially breached these terms and have not complied with the company's demand for rectification
- Where the price is unpaid, or payment is cancelled or returned
- Where you have used the service in breach of applicable law
- Where material or statements you submitted are untrue and the purpose of the contract cannot for that reason be achieved
(3) Article 19 applies to the treatment of the price corresponding to the unused period on termination.
(4) Termination does not delete the execution records. The inputs contained in an execution request are deleted as Article 25(1) provides; everything else in the execution record is retained. Article 25 sets this out in detail.
(5) After termination, Articles 6, 10(2), 12, 17, 25, 26, 29, 30, 31, 34, 35 and 36 survive by their nature.
Chapter 5 — Customer content, records and personal data
Article 24 (Submission of customer content, and input minimisation)
(1) You must not include personal data, sensitive data, unique identifying information or a third party's confidential information in an execution request.
(2) Where you unavoidably include information of the kind in paragraph (1), you must hold lawful authority to process it and to submit it to the company.
(3) The company currently holds no technical means of deleting an individual submitted input on request. Article 25 sets this out in detail.
(4) Where you breach paragraph (1) or (2) the company notifies you of that fact and discusses the necessary measures.
(5) Paragraphs (1) to (4) do not relieve or reduce the obligations the company itself bears under applicable law, including personal-data protection law.
IMPORTANTArticle 25 (Retention of, and access to, execution records and results)
(1) The inputs contained in an execution request (your question and context) are deleted from the database 30 days after the execution completes. The execution record itself — the identifiers, the input hash, the idempotency key, the cost items and the status — is retained for audit purposes and is not deleted. Three limits apply to that deletion and the company states them rather than leaving them to be assumed.
- It is a logical deletion, not cryptographic erasure. The database may hold the previous value until its internal cleanup runs, and a backup holds the previous value until the backup expires under its own lifecycle.
- It covers the execution inputs only. No other record in the database is deleted by it.
- The automatic deletion applies only to an execution that reached completion and produced a result artifact. An execution that did not complete, one that produced no result artifact, and one already marked as cleared are not covered.
(2) Online access to a result artifact is blocked once the retention period (30 days by default) has passed. That is a block on access and is not a deletion.
(3) Erasure of the result artifact itself from storage begins at the same point at which access is blocked under paragraph (2), but the versioning policy of the store means that complete erasure takes about 30 days more (about 60 days in total): the delete marks the current version as deleted while the immediately preceding version remains in storage until a separate storage rule removes it, and erasure is complete only once both rules have applied in sequence. Article 3 of the privacy policy states the same periods.
(4) No storage-level default retention rule is set on the audit-evidence store; a retention period is specified per record at the time the record is written. The legacy result store of the closed pilot was disposed of in full on 5 August 2026 and no longer exists.
(5) Destruction of personal data that applicable law requires to be destroyed is governed by the company's privacy policy. Paragraph (1) does not exclude or limit a right to require deletion or destruction that applicable law gives you.
(6) What the company can currently perform in response to a deletion request is limited to the access block in paragraph (2) and the erasure of the result artifact in paragraph (3). The company currently holds no technical means of deleting an individual database record. Article 8 of the privacy policy states how a deletion request is handled and records that this technical limitation is a defect to be fixed and not a ground of refusal.
IMPORTANTArticle 26 (Overseas processing and transfer)
(1) The function that transmits the question and context you submit to an AI model provider located in the United States, for the purpose of performing the service, was suspended on 4 August 2026 and resumes on 20 August 2026. For the duration of the suspension the company keeps the setting of the component that performs executions so that it does not use the model-invocation function, with the result that while the suspension lasts, submitting an execution request does not cause that transmission. Content already transmitted before the suspension is not recovered, and from the resumption date subsequent execution requests are transmitted again. The previous text undertook that the company would record the resumption and its date in the privacy policy before resuming and update this paragraph before resuming; this amendment is that performance. The detail is as Article 6(1)1 of the privacy policy provides.
(2) The company's storage infrastructure (database, file storage, message queue, in-memory store) is located in the Republic of Korea (ap-northeast-2). However, the sending of e-mail from the company to you, including the order acknowledgement under Article 14, is performed through a provider located outside the Republic of Korea and does not take place in the Republic of Korea. The detail is as the privacy policy provides.
(3) During payment and sign-in, transaction information and account identifiers are transmitted overseas to the payment provider and the authentication provider.
(4) The company's database is located in the Republic of Korea, but the provider of that database service is a company incorporated abroad. The company expresses no view in these terms on the legal character of that structure and states the facts only.
(5) You must submit only content in respect of which you hold authority for overseas processing.
(6) The statutory disclosure items for a cross-border transfer of personal data (the legal basis, the items transferred, the country of transfer, the timing and method of transfer, the recipient and its contact details, the purpose of use and the retention period) are as Article 6 of the privacy policy provides.
Article 27 (Privacy policy)
(1) The handling of personal data is governed by the privacy policy the company separately establishes and publishes.
(2) The privacy policy is published at /privacy.html in English and at /ko/privacy.html in Korean. The two state one processing operation; where they differ, the Korean text prevails (Article 34(3)).
(3) Where the company amends the privacy policy it announces that fact and the effective date on the service screen.
Article 28 (Role in the consignment of personal-data processing)
(1) Where customer content you submit contains personal data relating to your own data subjects, you are the controller of that personal data and the company stands in the position of your processor.
(2) The company processes personal data under paragraph (1) only for the purpose of providing the service, and where it uses a third party in order to provide the service it states that fact in the privacy policy.
(3) The specific conditions of the consignment in paragraph (1) may be agreed separately in writing between the company and you.
Article 29 (Intellectual property and licence)
(1) Intellectual property rights in the service and its components belong to the company or to the rightsholder.
(2) The company grants you, for the access period under these terms, a non-exclusive, non-transferable and non-sublicensable right to use the service. That right ends when the use contract ends.
(3) Where an open-source licence applies to a component of the service, that open-source licence applies in priority to paragraph (2). Which open-source licence applies to which component is set out at /ko/licenses.html.
(4) Rights in customer content are reserved to you. The company uses customer content only to the extent necessary to provide the service and to keep the records these terms require.
Chapter 6 — Liability
IMPORTANTArticle 30 (Limitation of liability)
(1) The company is not liable for indirect, special, consequential or punitive damages, or for lost profit, lost revenue, lost data, damage to goodwill, or loss arising from business interruption.
(2) The company's total liability in damages to you in connection with these terms is limited to the amount you actually paid to the company during the 3 months immediately preceding the occurrence of the event that caused the loss.
(3) Paragraphs (1), (2) and (6) do not apply to loss arising from the company's wilful misconduct or gross negligence.
(4) Nothing in this Article excludes or limits liability of the company that mandatory law does not permit to be excluded or limited. That includes, where applicable, liability for death or personal injury caused by negligence and liability for fraud.
(5) Where you are a consumer, paragraphs (1) and (2) apply only to the extent that applicable consumer-protection law permits.
(6) The service is provided "as is" during the paid private beta, and the company gives no express or implied warranty other than a warranty that mandatory law does not permit to be excluded. The company does not guarantee that the output of an AI-driven execution will be accurate, complete, unbiased or fit for any particular decision; you are responsible for reviewing an output before relying on it. The company claims no third-party compliance certification during the paid private beta. Architectural controls described on the Security page are design-level measures and are not legal or regulatory guarantees.
Article 31 (Indemnity by a business customer)
(1) Where you are a business customer and not a consumer, you indemnify the company for loss it incurs by reason of the following.
- Your breach of these terms
- Customer content you submitted infringing a third party's rights or breaching applicable law
(2) The indemnity in paragraph (1) is limited to loss actually incurred by the company and to amounts the company has paid to a third party, and does not include the company's indirect loss or lost profit.
(3) Paragraph (1) does not apply to any part arising from the company's wilful misconduct or gross negligence.
(4) Paragraph (1) does not apply to a customer who is a consumer.
Chapter 7 — Consumer protection, notices and general provisions
Article 32 (Consumer rights and dispute resolution)
(1) Rights that applicable law guarantees a consumer are not excluded or limited by these terms.
(2) The company receives and handles your views and complaints about use of the service at the contact in Article 33.
(3) You may use an external dispute-resolution procedure provided by applicable law, including statutory consumer dispute mediation, in respect of a dispute with the company. Article 12 of the privacy policy names the bodies to which a personal-data complaint may be brought, with their contact details.
(4) The company provides information about the service faithfully and accurately.
Article 33 (Notices)
(1) A notice to the company is given by e-mail to contact@decisionproof.io.kr.
(2) A notice to you is given by an announcement on the service and to the e-mail address you registered.
(3) A notice under paragraph (2) takes effect when the period ordinarily required for arrival has passed from the time it was sent to the e-mail address you registered. Where sending fails, it takes effect when the announcement on the service is posted.
(4) You must update your registered contact details without delay when they change, and the company is not responsible for a disadvantage arising from a failure to update them. This does not apply to any part arising from the company's wilful misconduct or gross negligence.
IMPORTANTArticle 34 (Governing law)
(1) These terms and a use contract under them are governed by the law of the Republic of Korea.
(2) Paragraph (1) does not exclude the protection of a mandatory rule of the law of your habitual residence where you are a consumer.
(3) Where the Korean version of these terms and a version in another language coexist, the Korean version prevails for a use contract governed by the law of the Republic of Korea. The Korean version is published at /ko/terms.html. This English document is a version in another language for the purposes of this paragraph.
Article 35 (Jurisdiction)
(1) Jurisdiction over a dispute relating to these terms is as applicable law provides.
(2) In addition to paragraph (1), a dispute may also be brought before the court having jurisdiction over the location of the company's head office. This is not an exclusive jurisdiction agreement.
(3) Where you are a consumer, your right to bring a claim before the court having jurisdiction over your address or your place of residence is not restricted by this Article.
(4) Either party may seek injunctive or equitable relief before any court of competent jurisdiction to protect intellectual property rights or confidential information.
Article 36 (Partial invalidity and severability)
(1) Where part of these terms is invalid or unenforceable, that provision loses effect only to that extent and the remaining provisions continue in force.
(2) The company endeavours to replace a provision that has lost effect under paragraph (1) with a valid provision closest to its purpose, to the extent applicable law permits.
Addenda
Article 1 (Effective date) These terms take effect on 2026-08-20.
Article 2 (Version) The version identifier of these terms is checking….
Article 3 (Scope of application) These terms apply to a use contract concluded on or after the effective date.