개인정보처리방침 — Hermes OS

운영사: AINOWAX · 서비스: Hermes OS · 시행일: 2026-06-15 · 문의: privacy@ainowax.com

AINOWAX(이하 "회사")는 BYO-GCP(고객 소유 Google Cloud) 방식으로 고객 전용 워크스페이스를 프로비저닝·운영하는 Hermes OS를 제공합니다. 본 방침은 회사가 Google OAuth 동의를 통해 위임받는 권한과, 그 과정에서 처리하는 정보를 설명합니다.

1. Google 계정 권한(OAuth)으로 무엇을 위임받나요

고객(워크스페이스 관리자)이 본인 Google 계정으로 동의하면, 회사는 고객 본인의 Google Cloud 프로젝트에 한해 다음 작업을 고객을 대신해 수행합니다: 전용 프로젝트 생성, 고객 결제 계정 연결, 필요한 API 사용 설정, 워크스페이스 배포(Cloud Run · Firestore · GCE VM).

요청하는 범위(scope)와 사용 목적:

위 범위는 고객 클라우드의 프로비저닝·운영 목적으로만 사용되며, 이 범위로 고객 직원의 콘텐츠(문서·대화 등)에 접근하지 않습니다.

2. 어떤 정보를 보관하나요

3. 고객 콘텐츠는 어디에 있나요 (데이터 분리·상주)

워크스페이스의 고객 콘텐츠(위키·대화 등)는 고객 본인의 Google Cloud(서울 리전 등 고객 리소스)에 저장되며, 회사 측으로 반출하지 않습니다. 이는 BYO-GCP 격리 설계 및 개인정보 보호법(예: §17 제3자 제공 제한, §28-8 국외이전 규율) 준수를 위한 것입니다.

4. 제3자 제공·공유

회사는 위 정보를 판매하거나 마케팅 목적으로 제3자에 제공하지 않습니다. Google Cloud 등 서비스 제공에 필수적인 인프라 제공자에 한해, 서비스 운영에 필요한 범위에서만 처리가 이루어집니다. Google API로 수신한 정보의 사용은 Google API Services User Data Policy(Limited Use 요건 포함)를 준수합니다.

5. 보관 기간·파기

OAuth 갱신 토큰 및 위 정보는 고객과의 서비스 계약이 유효한 동안 보관하며, 고객이 권한을 철회하거나 서비스가 종료(오프보딩)되면 지체 없이 파기합니다.

6. 동의 철회(권한 해제)

고객은 언제든 Google 계정 → 보안 → 타사 액세스에서 Hermes OS 권한을 해제할 수 있습니다. 철회 시 회사는 더 이상 고객 프로젝트에서 작업을 수행할 수 없으며, 이후 운영을 위해서는 재동의가 필요할 수 있습니다.

7. 보안

전송 구간 TLS 암호화, 토큰의 Secret Manager 보관, control-plane의 운영자 인증 게이트, 고객 런타임의 사설(IAM-private) 접근 등 합리적인 기술적·관리적 보호조치를 적용합니다.

8. 변경

본 방침이 변경되면 본 페이지에 갱신된 시행일과 함께 게시합니다.

9. 문의

개인정보 관련 문의: privacy@ainowax.com


Privacy Policy — Hermes OS

Operator: AINOWAX · Service: Hermes OS · Effective: 2026-06-15 · Contact: privacy@ainowax.com

AINOWAX ("we") provides Hermes OS, which provisions and operates a dedicated workspace inside each customer's own Google Cloud (BYO-GCP). This policy explains the access we receive via Google OAuth and the information we process.

1. What the Google OAuth grant authorizes

When a customer (workspace admin) consents with their own Google account, we act on their behalf only within the customer's own Google Cloud project: create a dedicated project, link the customer's billing account, enable required APIs, and deploy the workspace (Cloud Run, Firestore, a GCE VM).

These scopes are used solely to provision and operate the customer's cloud deployment and are not used to access the content of the customer's end users.

2. Information we store

3. Where customer content lives (data isolation & residency)

Workspace customer content (wiki, conversations, etc.) is stored in the customer's own Google Cloud (e.g., Seoul region resources) and is not exported to us — consistent with the BYO-GCP isolation design and applicable privacy law (e.g., Korea PIPA §17 / §28-8).

4. Sharing

We do not sell this information or share it for advertising. Google API data is handled in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

5. Retention

The refresh token and the information above are retained while the service relationship is active and are deleted promptly upon revocation or offboarding.

6. Revoking access

Customers may revoke Hermes OS access at any time at Google Account → Security → Third-party access. After revocation we can no longer operate the customer's project, and re-consent may be required to resume operations.

7. Security

We apply reasonable technical and organizational safeguards, including TLS in transit, Secret Manager token storage, an operator-auth gate on the control plane, and IAM-private access to customer runtimes.

8. Changes

If this policy changes, we post the updated version and effective date on this page.

9. Contact

Privacy inquiries: privacy@ainowax.com