VEXPLOR Logic Studio — Privacy Policy
Effective date: October 6, 2026
1. Who we are and what this policy covers
This policy explains how WACE Inc. ("WACE", "we") handles personal information in VEXPLOR Logic Studio (the "Service"), a multi-tenant manufacturing operations service hosted on Microsoft Azure. It applies to people who sign in to the Service and to personal information contained in data our customers store in it. Our website vexplor.com has its own privacy policy.
2. Our role
- Customer data. Business records a customer stores in the Service (for example work orders, quality records or employee names in those records) belong to the customer. We process them only on the customer's instructions and only to provide the Service. The customer decides what is stored and is responsible for having a lawful basis for it.
- Account and contract data. For contact and billing information of the people who sign our contract, we decide how it is used, as described below.
3. Information we collect
- Account information: email address, name, role (owner, admin, user or viewer), and, if the customer sets them, department code and employee number. Passwords and PINs are stored only as one-way (scrypt) hashes; we never store them in readable form.
- Sign-in records: sign-in time, failed sign-in count and temporary lock time.
- Session records: a hash of the session token, IP address and browser information (user agent).
- Usage records: which screen was opened and from where (menu, search, favorites and similar), favorites and recently used screens, and in-app notifications.
- Customer data: whatever the customer enters or connects. We do not ask for sensitive categories of personal information and the Service is not designed to hold them.
- Contact: information you send us by email, such as your name, company and message.
4. How we use it
- To sign you in, keep your session and enforce what your role may do.
- To run the Service: show screens, store records, search them and send notifications.
- To keep the Service secure: detect repeated failed sign-ins and investigate incidents.
- To improve the Service: find screens and buttons that are hard to reach, using usage records in aggregate.
- To reply to inquiries and manage our contract with the customer.
We do not sell personal information and do not use customer data to train AI models. We do not provide personal information to third parties except to the subprocessors listed in section 6 or where the law requires it.
5. AI answers
The search layer works without a language model. If the customer turns on AI answers, only the evidence found by the search, with fields marked as sensitive masked, is sent to the language model service configured for that customer (Azure OpenAI Service). Whole records are not sent. If no evidence is found, the model is not called.
6. Where data is stored and who processes it for us
- Data is stored in Microsoft Azure, Korea Central region (Republic of Korea), in a managed PostgreSQL database and application service operated by Microsoft Corporation on our behalf.
- When AI answers are on: Azure OpenAI Service, operated by Microsoft Corporation, in the region configured for the customer.
For customer data, we use subprocessors only as agreed with the customer in the service contract, and we list any new subprocessor on this page and notify customer administrators before we use it.
- International transfer. Today all Service data is stored in the Republic of Korea. If a customer turns on AI answers and the configured model region is outside Korea, we will list here, before the transfer starts, the items transferred, the destination country, when and how it is transferred, the recipient and its contact, its purpose and retention period, and how to refuse it.
7. How we separate customers
Every table is protected by database row-level security. A user of one company cannot read or change another company's rows; the database refuses the request. This is checked automatically on every deployment.
8. How long we keep it
- Account, usage and customer data: for the term of the customer's contract.
- Session records: deleted 7 days after the session expires.
- Database backups: kept for 7 days, then removed automatically.
- Email inquiries: 1 year after the inquiry is closed.
Records we must keep by law are kept separately for the period the law requires, and only the items the law names.
When the retention period ends or the purpose is achieved, we delete personal information without delay. Electronic records are deleted so that they cannot be restored; paper records are shredded.
9. Deletion when a customer leaves
When a contract ends, the customer's tenant is first suspended and then deleted. Deletion removes the customer's data from every table and the customer's accounts, sessions, notifications and usage records, and produces a deletion record listing what was removed. Copies in backups disappear when the 7-day backup period ends. A customer can ask for its data to be exported before deletion.
10. Security
- Encrypted connections (HTTPS) for all traffic.
- Row-level security on every table; the application connects with a role that cannot bypass it.
- Passwords and PINs stored only as hashes; session tokens stored only as hashes.
- Accounts are locked temporarily after repeated failed sign-ins.
- Access to production systems is limited to staff who need it.
11. Your rights
You, or your legal representative, can ask to see, correct or delete your personal information, or to stop its processing. If your account was created by your employer (our customer), please contact your company's administrator first; we will help the customer respond. You may also have rights under the law of the country where you live. Contact us at the address below and we will reply within the period the law requires.
12. Cookies
The Service uses one cookie (vc_session) to keep you signed in. It does not use advertising or analytics cookies. You can block or delete cookies in your browser settings; if you do, you cannot stay signed in to the Service.
13. Contact
WACE Inc., Management Support Department (privacy officer)
150, Dongtanyeongcheon-ro, Building A, Units 1332–1335, Dongtan-gu, Hwaseong-si, Gyeonggi-do 18462, Republic of Korea
Email: contact@wace.me · Phone: +82 70-4730-0629
If you are in Korea, you can also contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr) or the KISA Privacy Infringement Report Center (118, privacy.kisa.or.kr).
14. Children
The Service is a business service and is not intended for children under 14. We do not knowingly collect their personal information.
15. Changes
If we change this policy, we post the new version and its effective date on this page. For material changes we also notify customer administrators before the change takes effect.