HyperCal
Platform
Solutions
IBNR Reserving Pricing Models Audit and Compliance
Security
Pricing
Blog
Sign In Request Access
Platform
Solutions IBNR Reserving Pricing Models Audit and Compliance
Security Pricing Blog
Sign In Request Access
Legal

Privacy Policy

Last updated: 2026-05-14

HyperCal Co., Ltd. ("the Company," "we," "us," or "our") (10 Gukjegeumyung-ro, Yeongdeungpo-gu, 21F, Seoul 04524, South Korea) operates the HyperCal platform at hypercai.org -- an AI actuarial engine that automates reserving and pricing models for insurance carriers. This Privacy Policy explains how the Company collects, uses, and protects personal information in connection with the platform and this website.

The Company is established under the laws of the Republic of Korea. This policy reflects our obligations under Korea's Personal Information Protection Act (PIPA) and international good-practice standards applicable to a B2B financial-technology service. Where HyperCal processes personal information on behalf of a carrier client under a service agreement, the carrier operates as the data controller for that processing and the Company acts as data processor. This policy addresses personal information the Company collects independently as a controller -- primarily from website visitors, prospective customers, and platform account holders.

1. Who We Are and What This Policy Covers

HyperCal Co., Ltd. ("the Company") provides actuarial automation software to insurance carriers, enabling actuarial and finance teams to run IBNR reserving, pricing models, and compliance-reporting workflows without rebuilding them manually each quarter. The platform processes actuarial datasets -- development triangles, loss runs, premium registers, and model outputs -- submitted by carrier clients. This policy covers:

  • Personal information collected via the hypercai.org website (contact forms, access requests, and browsing data);
  • Account and platform-access information for named users at carrier organisations;
  • Communications between the Company and individuals at client organisations.

Actuarial and insurance modeling datasets submitted by carrier clients to the HyperCal platform are governed by the applicable Data Processing Agreement between the Company and that carrier, not by this policy. Client data is processed only to deliver the contracted service; the Company does not use client actuarial data for any purpose outside of service delivery.

2. Information We Collect

The Company collects personal information in the following categories:

  • Contact and identity data: name, business email address, job title, and employer organisation submitted through our contact or access-request forms.
  • Account credentials: username, hashed password, and authentication tokens for platform account holders at carrier clients.
  • Platform usage data: model run logs, session timestamps, feature-access records, and export activity associated with named user accounts -- maintained as part of the audit trail that carriers require for regulatory compliance.
  • Communication records: email and support-ticket content exchanged between the Company and carrier personnel.
  • Technical and browsing data: IP address, browser type, referring URL, and page-visit records collected automatically via server logs and analytics when you visit hypercai.org.

The Company does not collect sensitive personal information (as defined under PIPA Article 23) about website visitors or platform users in the ordinary course of operations. Sensitive actuarial fields within client datasets -- such as individual policyholder health or claims data -- are processed strictly on behalf of the carrier controller under separate contractual terms and are not within scope of this policy.

3. How We Use Personal Information

The Company uses personal information for the following purposes, each supported by a lawful basis under applicable law:

  • Service delivery and account management: to provision and operate platform access for named users at carrier clients, authenticate sessions, and maintain user-level audit logs required by carrier compliance obligations.
  • Responding to inquiries: to reply to access requests, demo inquiries, and support tickets submitted via hypercai.org.
  • Security and fraud prevention: to detect unauthorised access, maintain the integrity of the audit-trail infrastructure, and protect carrier data.
  • Product improvement: to analyse aggregate, anonymised usage patterns to improve platform performance and reliability. This analysis does not involve individual-level profiling of carrier personnel for any purpose outside of service quality.
  • Legal and regulatory compliance: to meet obligations under Korean law, including financial-services and data-protection statutes, and to respond to lawful requests from Korean supervisory authorities.

The Company does not use any personal information -- including website analytics, platform usage logs, or client actuarial datasets -- to train machine-learning models without the explicit written consent of the data subject or, where applicable, the carrier client.

4. Sharing and Disclosure

The Company shares personal information only in these circumstances:

  • Service providers: infrastructure and cloud hosting partners who process data on behalf of the Company under written data-processing agreements restricting use to service delivery. All hosting infrastructure is located in South Korea.
  • Carrier clients: platform usage logs and audit records for users at a given carrier organisation may be shared with that carrier's administrators as part of the contracted service -- consistent with the carrier's role as controller for its own data.
  • Legal obligations: when disclosure is required by Korean law, a court order, or a request from the Financial Supervisory Service, Financial Services Commission, or Personal Information Protection Commission.
  • Business transfers: in the event of a merger, acquisition, or asset sale, personal information may be transferred as part of the transaction; affected individuals will be notified in advance where feasible.

The Company does not sell personal information. Personal information is not shared with third parties for marketing or advertising purposes.

5. Data Residency and International Transfers

All personal information collected and processed by the Company is stored on servers physically located in South Korea. The Company does not transfer personal information to servers outside the Republic of Korea without a specific legal basis, contractual safeguard, or your prior consent. For Korean insurance carriers subject to Financial Services Commission guidance on data localisation, this architecture is designed to meet those requirements as a baseline operational constraint rather than an optional configuration.

Where a small number of third-party service tools (such as an email delivery provider) process contact data outside Korea, the Company maintains written contracts requiring those processors to apply protections equivalent to Korean PIPA requirements.

6. Retention

The Company retains personal information only as long as necessary for the purpose for which it was collected, or as required by applicable law. Retention periods for principal categories:

  • Platform account data: retained for the duration of the active carrier service agreement, then purged within 90 days of contract termination, unless Korean financial regulation requires a longer minimum period.
  • Audit trail records: retained for a minimum of five years following the model run, consistent with the record-keeping expectations of the Financial Supervisory Service and standard actuarial documentation practice. These records are part of the contracted service deliverable and are deleted or returned to the carrier upon agreement termination.
  • Contact and inquiry data: retained for up to two years from the date of last contact, or until you withdraw consent.
  • Website analytics data: anonymised or aggregated after 13 months; raw server logs retained for up to 12 months.

7. Security

The Company implements administrative, technical, and physical safeguards appropriate for financial-services data, including role-based access controls, encrypted data transit (TLS 1.2 minimum), and immutable audit logging of access and modification events. The platform's audit-trail architecture -- designed to meet actuarial regulatory-reporting standards -- also governs how personnel can interact with stored data. Security documentation is available to carrier clients on request as part of vendor due diligence.

8. Your Rights Under Korean Law (PIPA)

Under the Personal Information Protection Act (PIPA) of the Republic of Korea, you have the right to:

  • Access: request confirmation that the Company holds your personal information and receive a copy.
  • Correction: request correction of inaccurate or incomplete personal information.
  • Deletion: request deletion of personal information where the purpose of collection has been fulfilled or consent has been withdrawn, subject to legal retention obligations.
  • Suspension of processing: request that the Company suspend further processing of your personal information in defined circumstances.
  • Withdrawal of consent: where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact the Company's designated Personal Information Protection Manager at [email protected]. The Company will respond within 10 business days. You also have the right to lodge a complaint with the Personal Information Protection Commission (PIPC) at pipc.go.kr or the Korea Internet and Security Agency (KISA) privacy complaint hotline (118).

9. Cookies

The Company uses cookies and similar technologies on hypercai.org. See our Cookie Policy for full details. The cookie banner on this site operates on a notice-only basis consistent with the Korean PIPA framework applicable to cookies on B2B websites.

10. Changes to This Policy

The Company may update this Privacy Policy to reflect changes in the platform, in applicable law, or in our data practices. Material changes will be communicated via email to active account holders and will be reflected in the "Last updated" date above. Continued use of the platform after the effective date of a material change constitutes acceptance of the updated policy.

11. Contact

Questions or requests relating to this Privacy Policy should be directed to the Company's Personal Information Protection Manager:

HyperCal Co., Ltd.
10 Gukjegeumyung-ro, Yeongdeungpo-gu, 21F
Seoul 04524, South Korea
Email: [email protected]
Phone: +82 2 6952 3400
HyperCal

AI actuarial engine for insurance carriers. IBNR reserving, pricing calibration, and regulator-ready audit trails.

10 Gukjegeumyung-ro, Yeongdeungpo-gu, 21F
Seoul, 04524, Korea
+82 2 6952 3400
[email protected]

Product

  • Platform
  • IBNR Reserving
  • Pricing Models
  • Audit and Compliance
  • Security
  • Pricing

Company

  • About
  • Customers
  • Blog
  • Contact

© 2026 HyperCal Co., Ltd.

Privacy Policy Terms of Service Cookie Policy Cookie preferences