Privacy Policy
Personal data processing and protection at Lawmadi OS
Purpose of Processing
Art. 15Lawmadi OS (hereinafter referred to as the "Service") processes personal information for the following purposes. Personal information collected will not be used for purposes other than those stated below. Prior consent will be obtained if the purpose of processing changes.
- Providing AI legal information services — To analyze user queries and search, analyze, and organize legal information through AI
- Providing attorney search services — To enable users to search for attorneys by specialty, region, and other criteria, and display attorney profiles and advertisements
- Service security and stability — Detecting abnormal access, preventing service abuse, fraud prevention (device identification), and maintaining system stability
- Service improvement and statistical analysis — Improving service quality and features through usage pattern analysis
Credit usage: Free credits are granted one time upon login (email verification) as 3 credits, with no recurring top-up or daily reset. The 1:1 Leader Chat offers 5 free chats per account on login, after which 2 credits are charged per 5 additional chats. For details, please refer to the Terms of Service, Pricing, and Refund Policy.
Data Collected
The Service collects the following personal information:
| Category | Data Collected | Collection Method |
|---|---|---|
| Required | Query text, IP address, visit time | Automatically collected during use |
| Service usage | Conversation history, uploaded documents | Automatically collected during use |
| Credit payment | Payment email address | Entered by user during checkout |
| Email verification (OTP) | Email address, verification code (SHA-256 hash) | Entered by user / system-generated |
| Session management | Session token (encrypted), expiration date | Auto-generated upon authentication |
| Auto-collected | Browser information, access logs | Automatically generated by system |
| Device identification | Device fingerprint (canvas/screen-based hash), device token (UUID) | Auto-generated by system (stored in localStorage) |
| Attorney search | Search criteria (specialty, region, etc.), search and view history | Automatically collected during Attorney Search Service use |
| User reviews/feedback | Review text, consultation/engagement verification materials | Directly entered by user |
Retention Period
Art. 21The Service will destroy personal information without delay once the purpose of collection and use has been fulfilled. Electronic files are permanently deleted using methods that prevent recovery, and any printed materials are shredded or incinerated (PIPA Enforcement Decree, Art. 16). The retention period for each item is as follows:
| Item | Retention Period | Basis |
|---|---|---|
| Conversation history | 1 year | Service quality improvement |
| Saved answers (bookmarks) | Until the user deletes them (removed immediately on account deletion) | Saved at the user's own request |
| Uploaded documents | 7 days | Auto-deleted after analysis |
| Answers stored against a retry-safe key | 24 hours (auto-deleted on expiry) | Prevents double billing when the same request is retried |
| Visit statistics | 1 year | Service operation and statistics |
| Payment email | 1 year after credits used or refunded | E-Commerce Act, Article 6 |
| OTP verification code | 5 minutes after issuance (auto-deleted on expiry) | Authentication purpose fulfilled |
| Session token | 30 days (immediately deleted on logout) | Login session maintenance |
| Device identification | Non-logged-in: daily reset (KST 00:00) / Logged-in: deleted on withdrawal | Fraud prevention |
| Attorney search history | 1 year | Service improvement |
| User reviews/feedback | Duration of posting + 30 days after deletion | Service operation and dispute resolution |
Cookies and Automatic Collection
The Service uses the following cookies.
| Cookie | Type | Purpose | Expiry |
|---|---|---|---|
| __session | Essential | Maintaining login status after email verification, credit usage | 30 days |
| _ga, _ga_* | Analytics (optional) | Service usage statistics via Google Analytics | 2 years |
- Essential cookies (__session) are only created after the user completes email verification (OTP) and are protected with the HttpOnly attribute. They are immediately deleted upon logout.
- Analytics cookies (Google Analytics) are only activated with the user's explicit consent. You can accept or decline via the cookie consent banner at the bottom of the page.
- You may block cookies in your browser settings, but blocking essential cookies may limit access to credit-based services.
Third-Party Sharing
The Service integrates with the following external services for legal information analysis. Personal information is processed only to the minimum extent necessary for service provision.
Each external service provider processes data according to their own privacy policy. Only query text is sent to the Claude API and Vertex AI Search, only payment email to Paddle, and only anonymized usage statistics to Google Analytics.
Cross-border Transfer of Personal Data
The Service transfers personal data overseas for legal analysis and payment processing (PIPA Art. 28-8):
| Recipient | Country | Data Transferred | Safeguards |
|---|---|---|---|
| Anthropic (Claude API) | United States | Query text | Anthropic DPA, SOC 2 Type II, ISO 27001 |
| Google (Vertex AI Search) | United States | Query text | Google Cloud DPA, SOC 2/3, ISO 27001 |
| Google (Analytics) | United States | Anonymized usage statistics | Google DPA, IP anonymization applied |
| Paddle | UK/US | Payment email | Paddle DPA, PCI DSS compliant |
Attorney Search Service — Third-Party Sharing (coming soon — not yet available)
As of the effective date of this policy the Attorney Search Service is not provided, so none of the sharing below actually takes place. This table applies from the service launch date (same as Chapter 3 of the Terms).
| Recipient | Purpose | Data Provided | Basis |
|---|---|---|---|
| Korean Bar Association / Local bar associations | Notification of confirmed name-lending or unauthorized consultation | Attorney identification info, violation details | Attorney Search Service Guidelines Art. 15(2) |
Profile information provided by member attorneys (name, office address, local bar association, specialties, contact information, etc.) is disclosed to users through search results and profile pages. Member attorneys retain the right to access, rectify, delete, and withdraw their information as data subjects.
Data Subject Rights
Art. 35-37Users (data subjects) may exercise the following rights under the Personal Information Protection Act:
Right of Access
Request to view personal data processing status
Right to Rectification
Request correction of inaccurate personal data
Right to Erasure
Request deletion of personal data
Right to Suspend Processing
Request suspension of personal data processing
These rights may be exercised through the following channels. Processing results will be notified within 10 days of receipt:
- Email request: Contact admin@lawmadi.com for access, rectification, erasure, or suspension requests
- Analytics cookie consent withdrawal: Decline via the cookie consent banner at the bottom of the page, or delete cookies in browser settings
- Account deletion: Delete your account yourself from the account menu, or request it via email. Personal data (session, conversation history, saved answers, device identifiers) is deleted without delay. However, payment records subject to a statutory retention duty under Article 6 of the Act on Consumer Protection in Electronic Commerce are retained for the periods set out in the retention table above (billing email: 1 year after credits are used up or refunded). During that period the account record is pseudonymised so the individual cannot be identified, and it is destroyed once the period expires.
Member Attorney Rights: Member attorneys registered with the Attorney Search Service may also exercise their data subject rights to access, rectify, delete, and withdraw their profile information (name, office address, specialties, contact info, etc.). Requests are processed through the same channel (email).
Security Measures
The Service implements the following technical and administrative measures to ensure the security of personal information:
CORS Restrictions
API access limited to authorized domains only
API Key Authentication
All external API requests are authenticated
Security Headers
XSS, CSRF and other attack defense headers applied
- Encrypted communication via HTTPS
- Server access log recording and monitoring
- Regular security vulnerability assessments
Children Under 14
Art. 22The Service is not intended for children under the age of 14, and we do not knowingly collect personal information from children under 14.
- If we become aware that personal information of a child under 14 has been collected, we will promptly delete such information.
- Legal guardians may request access to, rectification of, or deletion of a child's personal information.
- Contact: admin@lawmadi.com
Privacy Officer
A Privacy Officer has been designated to oversee personal information processing and to handle data subject complaints and remedies.
Privacy Officer: Choe Jainam
Inquiries, access/correction/deletion requests, and complaint handling regarding personal information
Contact: admin@lawmadi.com
Effective Date