Privacy Policy — ClassI | Digiwill
Legal Document

Privacy Policy
for ClassI

Effective Date: June 16, 2026 Version 1.0 Digiwill Co., Ltd.
⚠ Data Handling at a Glance
The following summary is provided for transparency. Full details are described in each article below.
📥 Data Collected
Device info (name, IP)
Screen status & content
App / site access list
Screen control logs
AI conversation text
Email address (teacher & student)
Anonymous activity logs
Consent forms
🔒 How It's Stored
Monitor data: NOT stored
Control logs: 30 days
AI data: ≤ 3 months
Screen cast: NOT stored
Email: duration of account
Activity logs: anonymised
Consent forms: 2 years
🔄 How It's Used
Class management only
In-class hours only
No behavioral profiling
No advertising use
🌐 Data Sharing
NOT sold to 3rd parties
NOT shared with advertisers
Shared only with:
Maintenance vendors
Cloud operators
Authorities (legal)
Partners (aggregated only)
1
General Provisions

This Privacy Policy has been established by Digiwill Co., Ltd. (hereinafter "Digiwill"), the operator of ClassI — Next-Generation Classroom Management Solution (hereinafter "ClassI"), to comply with the Personal Information Protection Act (PIPA), the Framework Act on Education, the Elementary and Secondary Education Act, and other applicable laws and regulations.

ClassI enables teachers to remotely monitor and control student devices during classroom instruction. This Policy describes how personal information is collected, used, stored, and shared throughout that process.

This Privacy Policy covers the following software and services provided by Digiwill (collectively, "Services"):

ClassI — Next-Generation Classroom Management Solution
ClassI AI — AI-powered in-class assistant integrated within the ClassI platform
Digiwill collects the minimum personal information necessary and uses it solely within the scope of stated purposes, in accordance with Article 3 of the Personal Information Protection Act.
2
Data Collection — Categories and Methods

In accordance with the principle of minimal processing, Digiwill collects only the data strictly necessary to provide each software feature:

Feature 1 — Real-Time Student Device Monitoring
Data Collected
Device name · IP address · Current screen status · List of active websites / apps / programs · Network connection status
Collection Trigger
Automated real-time collection via software agent — active during class hours only
🛡 Minimal-Processing — Monitoring is DISABLED outside of class hours. Data is shown live on the teacher's screen only — it is NEVER written to disk or any database.
Feature 2 — Student Screen Control
Data Collected
Device control logs: timestamp of control action · type of action (lock / unlock / app restriction / screen switch) · target device identifier
Collection Trigger
Logged automatically each time the teacher explicitly issues a control command
🗓 Retention — Control logs are retained for a maximum of 30 days and are then automatically and permanently deleted.
Feature 3 — Student AI Conversation Data
Data Collected
Full AI conversation text (student questions + AI responses) · Timestamp of conversation · Student identifier (student ID or anonymised ID)
Collection Trigger
Automatically recorded whenever the student uses the in-app AI feature
🗓 Retention — Anonymised where student identification is not required. Destroyed within 3 months after the class concludes.
🔐 Sensitive Data Notice: AI conversation content may constitute sensitive personal information. Separate explicit notice and written consent will be obtained from guardians and students before collection begins.
Feature 4 — Student Screen Broadcast to Other Devices
Data Collected
Real-time screen data from the student's device (live streaming frames only)
Collection Trigger
Transmitted in real time when the teacher explicitly issues a broadcast command
🛡 Minimal-Processing — Screen data is transmitted as a live stream ONLY — it is NEVER captured, recorded, or stored on any device or server.
Feature 5 — Email Address Collection (Teacher & Student)
Data Collected
Email address of the teacher and registered student accounts (collected via Google account authentication)
Purpose
Account creation · User identity verification · Delivery of personalized educational features · Essential service communications (e.g., class invitations, deletion confirmations)
Collection Trigger
Collected at initial authentication (Google OAuth) when the teacher or student first signs in to the extension or app
Applies To
Classi AI 선생님 (Teacher Extension) · Classi AI 학생 (Student Extension) · Classi AI Android App
🗓 Retention — Retained for the duration of the active account. Deleted within 7 business days of account deletion request.
Feature 6 — Anonymous Usage Activity Logs
Data Collected
Anonymised interaction data: features accessed · frequency of use · session duration · error/crash events
Purpose
Diagnosing technical issues · Understanding user behaviour to improve extension functionality · Product improvement decisions
Collection Trigger
Automatically collected during active use of the extension or app
Applies To
Classi AI 선생님 (Teacher Extension) · Classi AI 학생 (Student Extension) · Classi AI Android App
🛡 Anonymised — This data does NOT contain email addresses, names, student IDs, or any directly identifying information.
Note: Aggregated, non-identifying demographic statistics derived from this data may be shared with trusted business partners and affiliates solely for product improvement purposes. No individual user can be identified from this shared data.
Teacher Data — ClassI AI Teacher Application

The following data is collected specifically from teachers when logging in and operating the ClassI AI Teacher application. This is separate from student data collection.

Account Data
Teacher account credentials (hashed password, registered email address / username used for authentication)
Session & Access Logs
Teacher IP address · Login / logout timestamps · Session duration · Device type, browser and OS information
Action Logs
Records of all teacher-initiated control commands: feature used, target device identifier, timestamp — retained for audit and accountability purposes
AI Usage Logs (ClassI AI)
Prompts entered by the teacher into ClassI AI · AI-generated responses · Timestamps — used to monitor appropriate use and improve educational quality
Collection Trigger
Automatically recorded upon login and during active use of the ClassI AI Teacher application
👤 Teacher-specific data — see Article 6 for AI data transmission details
  • Automated real-time collection via software agent (client program installed on student devices)
  • Automatic logging each time the teacher explicitly executes a control command
  • Submission of written or electronic consent forms by students and guardians

The following browser permissions are requested by each ClassI extension. All permissions are strictly necessary for the described classroom features and are not used for any other purpose.

📌 Classi AI 선생님 (Teacher Extension)
PermissionWhy It Is RequiredData Accessed
tabsRequired to monitor which browser tabs are open on student devices and block/close inappropriate tabs during classTab URLs and titles on student devices (during active class sessions only)
activeTabRequired to interact with the currently active tab to apply screen controls and URL restrictionsURL of the currently active tab
storageRequired to locally store session state, teacher preferences, and class configurationLocal configuration data — not transmitted externally
identityRequired to authenticate the teacher via Google account and load Google Classroom class/student dataTeacher's Google account email and Google Classroom course list
scriptingRequired to inject screen lock, URL block, and notification scripts into student browser windowsNo data read — scripts are executed only to apply controls
webRequest / declarativeNetRequestRequired to enforce URL allow/block lists during exam modeRequested URLs (compared against teacher-configured lists; content is not read)
notificationsRequired to send push notifications (messages, alerts) to student devicesNotification content composed by the teacher
Host permissions (digiwill.ai, server endpoints)Required to communicate with ClassI servers for real-time monitoring, control commands, and AI featuresEncrypted command/response payloads between teacher client and ClassI server
📌 Classi AI 학생 (Student Extension)
PermissionWhy It Is RequiredData Accessed
tabsRequired to send the current tab list to the teacher dashboard and to receive tab open/close commands from the teacherTab URLs and titles — transmitted to teacher's dashboard during class sessions only
storageRequired to store local session state, current class code, and student preferencesLocal session data — not transmitted externally
identityRequired to identify the student via their Google account to match them to the correct classStudent Google account email, used to join the class roster
scriptingRequired to apply teacher-sent controls: screen lock, forced URL navigation, notification displayNo data read — scripts execute control actions only
webRequest / declarativeNetRequestRequired to enforce URL restrictions and exam-mode allow/block lists set by the teacherRequested URLs compared against teacher-configured lists; page content is not read
desktopCapture / tabCaptureRequired to capture and transmit the student's screen to the teacher's monitoring dashboard (real-time streaming; not recorded)Screen pixel data — streamed in real time, never stored
Host permissions (digiwill.ai, server endpoints)Required to maintain the real-time connection to ClassI server for receiving teacher commandsEncrypted command/response payloads
Web Browsing Activity Notice: The student extension collects tab URLs and open tab lists. This constitutes "web browsing activity" under Chrome Web Store policy. This data is collected solely to enable the teacher's class management dashboard (a prominently described user-facing feature) and is never used for advertising, analytics, or any purpose unrelated to live classroom management.
3
Purpose of Data Use

Digiwill uses collected personal information only within the purposes listed below. Use beyond these purposes is strictly prohibited.

FeaturePurpose of UseLegal Basis (PIPA)
Real-Time MonitoringMonitor class engagement; block inappropriate content; maintain learning environmentArt. 15(1)(6) — Legitimate Interest
Screen ControlLock/unlock devices; restrict apps; support orderly instructionArt. 15(1)(6) — Legitimate Interest
AI Conversation DataAssess AI usage patterns; prevent inappropriate content; improve educational qualityArt. 15(1)(1) — Explicit Consent
Screen BroadcastSupport presentations, collaborative tasks, and teacher demonstrationsArt. 15(1)(6) — Legitimate Interest
Data is NEVER used for advertising, commercial profiling, or any purpose unrelated to in-class educational activities.
4
Data Processing — Storage, Retention & Destruction

This section describes the complete lifecycle of personal information from the point of collection through to permanent destruction. Digiwill retains data only for the minimum period necessary to fulfil the stated purpose, and destroys it without delay once that purpose is achieved.

① Collection

Data is collected automatically via the ClassI / ClassI AI software agent or through explicit teacher commands — only during active class sessions, only to the extent required for each feature.

② Processing & Use

Data is processed solely within the purposes listed in Article 3. No data is used for advertising, profiling, or any purpose unrelated to in-class educational activities. AI conversation data is anonymised where student identification is not required.

③ Storage & Access Control

Stored data is encrypted at rest and in transit. Access is granted on a strict least-privilege basis per account. Intrusion detection, firewall protection, and access-log retention (minimum 6 months) are applied at all times.

④ Destruction

Once the retention period ends or the collection purpose is achieved, data is transferred to an isolated database, held only as long as legally required, and then permanently destroyed using the methods below. Isolated data is never used for secondary purposes.

Retention Schedule
Data CategoryWhere StoredAccess ControlsRetention PeriodDestruction Method
Real-Time Monitoring Data Teacher's screen only
(RAM / display buffer)
Visible to assigned teacher only Not stored Discarded immediately after display — never written to disk
Screen Control Logs Internal server
(encrypted at rest)
Teacher & system admin only 30 days Automatic permanent deletion via scheduled job
AI Conversation Content
(ClassI AI)
Encrypted cloud storage
(if applicable)
Teacher & designated admin; anonymised where possible ≤ 3 months after class ends Irrecoverable deletion or full anonymisation
Screen Broadcast Data Not stored
(live stream only)
N/A Not stored N/A — stream is never captured or saved
Consent Forms & Records Secure internal archive Privacy Officer & designated admin only 2 years post-enrollment Physical shredding or certified electronic deletion
Destruction Methods
Electronic Files
Multi-pass overwriting and/or certified deletion software ensuring data is irrecoverable by any technical means
Printed / Paper Documents
Mechanically shredded using cross-cut shredders or incinerated under controlled conditions
Scheduled Auto-Deletion
Automated deletion jobs run on defined schedules (e.g., 30-day control logs) with audit trails maintained to confirm completion
All destruction activities are logged and verifiable. Records of destruction are retained for audit purposes in accordance with applicable regulations.
5
Security Measures

Pursuant to Article 29 of the Personal Information Protection Act, Digiwill implements the following technical, administrative, and physical safeguards to prevent loss, theft, leakage, alteration, or damage of personal information.

① Technical Safeguards
  • All communication between student device agents and teacher servers uses encrypted dedicated channels (TLS)
  • Access privileges follow the principle of least privilege, assigned per teacher / administrator account
  • Intrusion detection systems (IDS) and firewalls are operated; regular vulnerability assessments are performed
  • Access logs are retained for at least 6 months with tamper-prevention controls applied
② Administrative Safeguards
  • The number of personnel who handle personal information is kept to the minimum necessary
  • Mandatory periodic personal information protection training is provided to all handlers
  • Internal management plans are established and reviewed/updated annually
  • All handlers sign confidentiality agreements; access rights are revoked immediately upon role change or resignation
  • A Chief Privacy Officer (CPO) is designated to regularly supervise processing activities
③ Physical Safeguards
  • Servers and storage devices are maintained in access-controlled, locked facilities
  • External physical access to devices is prohibited; entry/exit records are maintained
6
AI Data Flows & Third-Party LLM Disclosure

This section discloses how data processed by the ClassI AI feature is handled, including whether and how it is transmitted to external AI service providers.

⚠ Important Disclosure: When a student or teacher interacts with the ClassI AI assistant, the text of that conversation (question + context) is transmitted to an external Large Language Model (LLM) API provider to generate a response. This constitutes a form of data sharing with a third-party sub-processor.
① External AI Provider
If Digiwill changes the AI provider, this Privacy Policy will be updated and advance notice will be given at least 30 days prior to the change taking effect.
② What Is NOT Transmitted to the AI Provider
  • Student names, student IDs, or any directly identifying information
  • Device names or IP addresses
  • Screen content, control logs, or broadcast data
  • Consent forms or any records outside the AI conversation context
③ Cross-Border Data Transfer

AI conversation prompt data is processed by OpenAI and Google on servers located primarily in the United States. This constitutes a cross-border transfer of personal information. Digiwill ensures that such transfers are governed by appropriate contractual protections (Data Processing Agreements) consistent with applicable data protection law, including PIPA Article 28-8.

Transfer DestinationLegal BasisProtective Mechanism
United States (OpenAI)Art. 28-8 PIPA — contractual transferData Processing Agreement (DPA) with OpenAI
United States (Google LLC)Art. 28-8 PIPA — contractual transferData Processing Agreement (DPA) with Google
7
Chief Privacy Officer and Contact Information

Digiwill has designated the following Chief Privacy Officer to protect user data and handle related complaints:

Chief Privacy Officer
Hong Seokhwan
Organisation
Digiwill Co., Ltd.
Phone
031-213-9280
Email
brick@digiwill.co.kr
Response Time
Within 10 business days of receipt

For personal information infringement reports or further enquiries, you may also contact:

Personal Information Infringement Report Centerprivacy.kisa.or.kr · ☎ 118
Supreme Prosecutors' Office — Cyber Crime Divisioncybercid.spo.go.kr · ☎ 1301
National Police Agency — Cyber Safety Bureaucyberbureau.police.go.kr · ☎ 182
8
Data Sharing — Third-Party Disclosure
Digiwill does NOT sell, rent, or trade user data. Student personal information is NEVER shared with advertisers, marketing companies, or any external commercial party.

Personal information is shared with third parties only in the following limited circumstances:

9
Data Processing Entrustment (Sub-Processors)

For software operation, maintenance, and AI functionality, Digiwill entrusts personal information processing to the following named entities. All agreements contain explicit data protection obligations compliant with PIPA, and each sub-processor is supervised to ensure safe processing.

Sub-Processor (Legal Name)CountryTasks EntrustedData AccessedRetention
Digiwill Co., Ltd.
In-house development team
Republic of Korea Software development, system operation, bug fixes, feature improvements, internal maintenance All system data — access strictly limited by role Duration of employment / contract
Amazon Web Services, Inc. (AWS)
aws.amazon.com
Republic of Korea
(ap-northeast-2 region)
Cloud infrastructure — encrypted hosting of application servers, databases, and AI conversation data storage Encrypted server and database contents; AWS has no access to plaintext data Duration of service agreement
OpenAI, L.L.C.
openai.com
United States LLM API — generates AI responses for ClassI AI feature (see Article 6) AI conversation prompt text only — no student IDs, names, or device info included in API calls Per OpenAI API data policy; data not used for model training
Google LLC
cloud.google.com
United States LLM API (Google Gemini) — supplements AI response generation for ClassI AI feature (see Article 6) AI conversation prompt text only — no student IDs, names, or device info included in API calls Per Google Cloud API data policy; data not used for model training
If any sub-processor changes or a new one is added, this Privacy Policy will be updated and advance notice will be provided via in-app announcement at least 30 days prior to the change.
10
Rights of Data Subjects (Students and Guardians)

Students and guardians (legal representatives) may exercise the following rights at any time:

  • Access — Request confirmation of what personal information is being processed
  • Correction / Deletion — Request correction of inaccurate data or deletion of unnecessary data
  • Processing Suspension — Request suspension of specific data processing activities
  • Withdrawal of Consent — Withdraw consent for collection and use at any time without penalty

Rights may be exercised by contacting the Chief Privacy Officer (Article 7) in writing, by phone, or by email. Requests will be processed and responded to within 10 business days.

Account Deletion & Data Erasure Procedure

When a teacher or school administrator requests account deletion, or when a student's enrollment ends, the following data erasure procedure applies:

StepActionTimeframe
1. Request submissionSubmit a deletion request to brick@digiwill.co.kr or via the in-app account settingsImmediately upon request
2. Identity verificationDigiwill verifies the requester's identity to prevent unauthorised deletionWithin 2 business days
3. Active data deletionAll personal data associated with the account (AI conversations, control logs, session data) is permanently deleted from active databasesWithin 7 business days of verification
4. Backup purgeResidual data in encrypted backup systems is overwritten in the next scheduled backup cycleWithin 30 days
5. ConfirmationA deletion confirmation notice is sent to the requester's registered email addressUpon completion
Exceptions: Consent forms and audit records required by law (e.g., under the Act on the Protection of Information of Educational Institutions) are retained for the legally mandated period (2 years post-enrollment) even after account deletion, then destroyed.
For students under the age of 14, the legal guardian may exercise all of the above rights on the student's behalf.
11
Amendments to This Privacy Policy

Digiwill will provide advance notice of any amendments to this Privacy Policy at least 7 days before they take effect, via in-app announcements or school newsletters. For material changes, at least 30 days' advance notice will be given.

Current Versionv1.0
Effective DateJune 16, 2026
Last ModifiedJune 15, 2026
This Privacy Policy has been established and published pursuant to Article 30 of the Personal Information Protection Act.
법적 문서

개인정보
처리방침

시행일자: 2026년 6월 16일 버전 1.0 주식회사 디지윌
⚠ 데이터 처리 한눈에 보기
아래 내용은 투명한 정보 제공을 위한 요약입니다. 상세 내용은 각 조항을 참고하세요.
📥 수집 항목
기기 정보 (기기명, IP)
화면 상태 및 내용
앱·사이트 접속 목록
화면 제어 로그
AI 대화 텍스트
이메일 주소 (교사·학생)
익명 활동 로그
동의서
🔒 저장 방식
모니터링 데이터: 저장 안 함
제어 로그: 30일
AI 데이터: 3개월 이내
화면 송출: 저장 안 함
이메일: 계정 보유 기간
활동 로그: 익명화
동의서: 2년
🔄 이용 방식
수업 관리 목적만 사용
수업 시간 중에만 수집
행동 프로파일링 없음
광고 목적 사용 없음
🌐 데이터 공유
제3자 판매 절대 없음
광고주 공유 없음
공유 대상 (제한적):
유지보수 업체
클라우드 운영사
수사기관 (법적 요청)
파트너사 (집계 데이터만)
1
총칙

본 방침은 미래형 수업 관리 솔루션 클래스아이(ClassI)를 운영하는 주식회사 디지윌(이하 '디지윌')가 「개인정보 보호법」, 「교육기본법」, 「초·중등교육법」 및 관련 법령을 준수하기 위하여 수립한 개인정보처리방침입니다.

본 클래스아이는 교사(이하 '선생님')의 기기에서 학생 기기를 원격으로 제어하고 수업에 활용하는 것을 목적으로 하며, 이 과정에서 발생하는 개인정보의 수집·이용·보관·파기에 관한 사항을 아래와 같이 명시합니다.

본 개인정보처리방침은 디지윌이 제공하는 다음의 소프트웨어 및 서비스(이하 통칭하여 '서비스')에 적용됩니다.

ClassI (클래스아이) — 미래형 수업 관리 솔루션
ClassI AI (클래스아이 AI) — ClassI 플랫폼에 통합된 AI 기반 수업 보조 서비스
디지윌은 개인정보 보호법 제3조(개인정보 보호 원칙)에 따라 개인정보를 최소한으로 수집하고, 수집된 목적 범위 안에서만 이용합니다.
2
수집하는 개인정보의 항목 및 수집 방법

디지윌은 최소처리 원칙에 따라 소프트웨어의 기능 제공에 필요한 최소한의 개인정보만을 수집하며, 수집 항목은 아래와 같습니다.

[기능 1] 학생 기기 실시간 모니터링
수집 항목
기기 식별정보(기기명, IP 주소), 현재 화면 상태, 접속 웹/앱/프로그램 목록, 네트워크 접속 현황
수집 목적
수업 집중도 확인, 부적절한 앱·사이트 사용 방지, 학습 환경 조성
수집 방법
소프트웨어 에이전트를 통한 실시간 자동 수집 (수업 시간 중에만 작동)
✓ 최소처리 준수 — 수업 시간 외 모니터링 비활성화. 저장 없이 교사 화면에만 실시간 표시
[기능 2] 학생 화면 제어
수집 항목
기기 제어 이력(제어 시간, 제어 유형, 대상 기기 식별 정보)
수집 목적
수업 진행을 위한 학생 기기 화면 잠금·해제, 앱 실행 제한, 화면 전환 등 교육적 제어
수집 방법
교사의 명시적 제어 명령 실행 시 자동 기록
✓ 최소처리 준수 — 제어 로그는 최대 30일 보관 후 자동 삭제
[기능 3] 학생 AI 대화 내용 수집
수집 항목
AI와의 대화 텍스트(질문 및 응답 내용), 대화 발생 일시, 학생 식별 정보(학번 또는 익명 ID)
수집 목적
수업 활용 현황 파악, 학습 지도 및 부적절한 콘텐츠 사용 방지, 교육 품질 개선
수집 방법
AI 기능 사용 시 자동 기록
✓ 최소처리 준수 — 식별 불필요 시 익명화 처리, 수업 종료 후 3개월 이내 파기
※ 안내: AI 대화 내용은 민감정보에 해당할 수 있으므로, 수집 전 보호자 및 학생에게 별도 고지 및 동의를 받습니다.
[기능 4] 학생 화면 다른 기기에 송출
수집 항목
학생 기기의 실시간 화면 데이터(스트리밍 데이터)
수집 목적
교사 또는 타 학생 기기로 화면 공유(발표, 협업 학습 지원)
수집 방법
교사의 명시적 송출 명령 실행 시 실시간 전송
✓ 최소처리 준수 — 실시간 스트리밍으로만 제공, 별도 저장하지 않음
② 개인정보 수집 방법
  • 소프트웨어 에이전트(클라이언트 프로그램)를 통한 자동 수집
  • 교사의 명시적 제어 명령 실행 시 자동 기록
  • 학생·보호자의 서면 또는 전자적 동의서 제출

아래는 각 ClassI 확장프로그램이 요청하는 브라우저 권한 목록입니다. 모든 권한은 명시된 수업 관리 기능에 필수적이며, 다른 용도로 사용되지 않습니다.

📌 Classi AI 선생님 (교사용 확장프로그램)
권한필요 이유접근 데이터
tabs학생 기기에서 열려 있는 브라우저 탭 목록 모니터링 및 부적절한 탭 차단·닫기수업 시간 중 학생 기기의 탭 URL 및 제목
activeTab현재 활성 탭에 화면 제어 및 URL 제한 적용현재 활성 탭의 URL
storage세션 상태, 교사 설정, 수업 구성 정보 로컬 저장로컬 설정 데이터 — 외부 전송 없음
identity구글 계정으로 교사 인증 및 Google Classroom 수업·학생 목록 불러오기교사 구글 계정 이메일, Google Classroom 수업 목록
scripting학생 브라우저에 화면 잠금·URL 차단·알림 스크립트 주입데이터 읽기 없음 — 제어 실행 목적으로만 스크립트 실행
webRequest / declarativeNetRequest시험 모드 중 URL 허용/차단 목록 적용요청된 URL(교사 설정 목록과 비교; 페이지 내용 미수집)
notifications학생 기기에 메시지·알림 푸시 발송교사가 작성한 알림 내용
호스트 권한 (digiwill.ai, 서버 엔드포인트)실시간 모니터링, 제어 명령, AI 기능을 위해 ClassI 서버와 통신교사 클라이언트 ↔ ClassI 서버 간 암호화된 명령/응답
📌 Classi AI 학생 (학생용 확장프로그램)
권한필요 이유접근 데이터
tabs현재 열린 탭 목록을 교사 대시보드에 전송하고, 교사 명령에 따라 탭 열기/닫기 실행수업 시간 중에만 탭 URL 및 제목을 교사 대시보드에 전송
storage로컬 세션 상태, 현재 수업 코드, 학생 설정 저장로컬 세션 데이터 — 외부 전송 없음
identity구글 계정으로 학생 식별 및 수업 명단 매칭학생 구글 계정 이메일 (수업 참여 목적)
scripting교사 지시에 따른 화면 잠금·URL 강제 이동·알림 표시 적용데이터 읽기 없음 — 제어 실행 목적으로만 스크립트 실행
webRequest / declarativeNetRequest교사가 설정한 URL 제한 및 시험 모드 허용/차단 목록 적용요청 URL(목록 비교 용도; 페이지 내용 미수집)
desktopCapture / tabCapture학생 화면을 교사 모니터링 대시보드에 실시간 스트리밍 (녹화 없음)화면 픽셀 데이터 — 실시간 스트리밍만, 저장 없음
호스트 권한 (digiwill.ai, 서버 엔드포인트)교사 명령 수신을 위해 ClassI 서버와 실시간 연결 유지암호화된 명령/응답 페이로드
웹 브라우징 활동 수집 안내: 학생용 확장프로그램은 탭 URL 및 열린 탭 목록을 수집합니다. 이는 크롬 웹스토어 정책상 '웹 브라우징 활동' 수집에 해당합니다. 해당 데이터는 교사의 수업 관리 대시보드(명시된 사용자 대면 기능) 제공에만 사용되며, 광고·분석·수업 외 목적으로는 절대 사용되지 않습니다.
[기능 5] 이메일 주소 수집 (교사 및 학생)
수집 항목
교사 및 등록된 학생 계정의 이메일 주소 (Google 계정 인증을 통해 수집)
수집 목적
계정 생성 · 사용자 신원 확인 · 개인화된 교육 기능 제공 · 필수 서비스 통신 (수업 초대, 삭제 확인 등)
수집 방법
교사 또는 학생이 처음 로그인할 때 Google OAuth 인증을 통해 수집
적용 대상
Classi AI 선생님 (교사용 확장프로그램) · Classi AI 학생 (학생용 확장프로그램) · Classi AI Android 앱
🗓 보유 기간 — 활성 계정 기간 동안 보유. 계정 삭제 요청 후 7영업일 이내 삭제.
[기능 6] 익명 사용 활동 로그
수집 항목
익명화된 상호작용 데이터: 접근한 기능 · 사용 빈도 · 세션 지속 시간 · 오류/충돌 이벤트
수집 목적
기술적 문제 진단 · 사용 행태 파악을 통한 기능 개선 · 제품 개선 의사결정
수집 방법
확장프로그램 또는 앱 사용 중 자동 수집
적용 대상
Classi AI 선생님 (교사용 확장프로그램) · Classi AI 학생 (학생용 확장프로그램) · Classi AI Android 앱
🛡 익명화 처리 — 이메일, 이름, 학번 등 직접 식별 가능한 정보를 포함하지 않습니다.
안내: 이 데이터에서 도출된 집계된 비식별 인구통계 통계는 제품 개선 목적으로 신뢰할 수 있는 비즈니스 파트너 및 계열사와 공유될 수 있습니다. 공유 데이터를 통해 특정 개인을 식별할 수 없습니다.
③ 교사 데이터 수집 (ClassI AI Teacher 앱)
교사 데이터 — ClassI AI Teacher 애플리케이션

아래 데이터는 교사가 ClassI AI Teacher 앱에 로그인하여 사용하는 과정에서 수집되며, 학생 데이터 수집과 별도로 구분됩니다.

계정 정보
교사 계정 자격증명 (해시된 비밀번호, 인증에 사용되는 이메일 주소 / 아이디)
세션·접속 로그
교사 IP 주소 · 로그인/로그아웃 일시 · 세션 지속 시간 · 기기 종류, 브라우저 및 OS 정보
제어 행위 로그
교사가 실행한 모든 제어 명령의 기록: 사용 기능, 대상 기기 식별정보, 타임스탬프 — 감사 및 책임 추적 목적으로 보관
AI 사용 로그 (ClassI AI)
교사가 ClassI AI에 입력한 프롬프트 · AI 생성 응답 · 타임스탬프 — 적절한 사용 여부 모니터링 및 교육 품질 개선에 활용
수집 방법
ClassI AI Teacher 앱 로그인 및 사용 중 자동 기록
👤 교사 전용 데이터 — AI 데이터 전송 상세 내용은 제6조 참고
3
개인정보의 수집 및 이용 목적

디지윌은 수집된 개인정보를 다음의 목적 범위 내에서만 이용하며, 목적 외 이용을 엄격히 금지합니다.

기능이용 목적이용 근거 (개인정보 보호법)
실시간 모니터링수업 집중도 확인, 부적절 사이트 차단, 학습 환경 조성제15조 제1항 제6호 (정당한 이익)
화면 제어교육적 목적의 기기 제어, 수업 진행 지원제15조 제1항 제6호 (정당한 이익)
AI 대화 수집학습 현황 파악, 부적절 사용 방지, 교육 품질 개선제15조 제1항 제1호 (동의)
화면 송출발표·협업 학습 지원, 교사 설명 보조제15조 제1항 제6호 (정당한 이익)
이메일 주소 수집계정 생성, 신원 확인, 개인화 기능 제공, 필수 서비스 통신제15조 제1항 제2호 (계약 이행)
익명 활동 로그기술 문제 진단, 사용 패턴 파악, 제품 기능 개선제15조 제1항 제6호 (정당한 이익)
수집된 데이터는 광고, 상업적 프로파일링, 수업 외 목적으로 절대 사용되지 않습니다.
4
개인정보의 처리 · 보유 · 파기

본 조에서는 개인정보의 수집 시점부터 최종 파기까지 전 생애주기를 설명합니다. 디지윌은 수집 목적이 달성된 개인정보를 지체 없이 파기하며, 법령상 보존 의무가 있는 경우에 한하여 정해진 기간 동안만 보관합니다.

① 수집

ClassI / ClassI AI 소프트웨어 에이전트를 통해 자동 수집되거나, 교사의 명시적 명령 실행 시에만 기록됩니다. 수업 진행 중, 각 기능에 필요한 최소 범위 내에서만 수집합니다.

② 처리 및 이용

수집된 개인정보는 제3조에 명시된 목적 범위 내에서만 처리됩니다. 광고, 상업적 프로파일링, 수업 외 목적의 이용은 엄격히 금지됩니다. AI 대화 데이터는 학생 식별이 불필요한 경우 익명화하여 처리합니다.

③ 저장 및 접근 통제

저장된 데이터는 전송 중 및 저장 상태 모두 암호화됩니다. 접근 권한은 계정별 최소 권한 원칙에 따라 엄격히 관리되며, 침입탐지 시스템(IDS), 방화벽, 접속 기록(최소 6개월 보관) 등 보안 장치가 상시 운영됩니다.

④ 파기

보유 기간이 도래하거나 수집 목적이 달성되면, 해당 개인정보를 별도 데이터베이스로 이관하여 법령상 의무 기간 동안만 보관한 후 아래 방법으로 복구 불가능하게 파기합니다. 이관된 정보는 법령에 의한 경우를 제외하고 다른 목적으로 이용되지 않습니다.

보유 기간 일람
구분저장 위치접근 통제보유 기간파기 방법
실시간 모니터링 데이터 교사 화면 전용
(RAM / 디스플레이 버퍼)
담당 교사에게만 표시 저장 없음 화면 표시 즉시 폐기 — 디스크 기록 없음
화면 제어 로그 내부 서버
(저장 암호화)
담당 교사 및 시스템 관리자 30일 스케줄 작업에 의한 자동 영구 삭제
AI 대화 내용
(ClassI AI)
암호화 클라우드 스토리지
(해당하는 경우)
교사 및 지정 관리자; 가능한 경우 익명화 수업 종료 후 3개월 이내 복구 불가 삭제 또는 완전 익명화
화면 송출 데이터 저장 없음
(실시간 스트리밍)
해당 없음 저장 없음 해당 없음 — 스트림 캡처·저장 불가
동의서 및 관련 기록 내부 보안 아카이브 개인정보 보호책임자 및 지정 관리자 재학 기간 종료 후 2년 물리적 분쇄 또는 인증된 전자적 삭제
파기 방법
전자 파일
멀티패스 덮어쓰기 및/또는 인증된 전용 삭제 소프트웨어를 사용하여 기술적으로 복구 불가능한 방법으로 영구 삭제
출력물 · 서면
크로스컷 분쇄기를 이용한 기계적 분쇄 또는 통제된 환경에서의 소각 처리
자동 파기 스케줄
화면 제어 로그(30일) 등 정해진 일정에 따라 자동 파기 작업이 실행되며, 파기 완료 여부는 감사 기록으로 확인 가능
모든 파기 활동은 기록되고 검증 가능합니다. 파기 기록은 관련 법령에 따라 감사 목적으로 보관됩니다.
5
개인정보의 안전성 확보 조치

디지윌은 개인정보 보호법 제29조에 따라 개인정보가 분실·도난·유출·변조·훼손되지 않도록 다음과 같은 기술적·관리적·물리적 안전조치를 시행합니다.

① 기술적 안전조치
  • 학생 기기 에이전트와 교사 서버 간 통신은 암호화된 전용 채널(TLS) 사용
  • 접근 권한은 최소 권한 원칙에 따라 교사·관리자 계정별로 세분화하여 부여
  • 침입 탐지 시스템(IDS) 및 방화벽 운영, 정기적 취약점 점검
  • 접속 기록(로그)을 6개월 이상 보관하며 위·변조 방지를 위한 보안 장치 적용
② 관리적 안전조치
  • 개인정보 취급 직원(담당자)을 최소화하고, 취급자에게 개인정보 보호 교육 정기 실시
  • 개인정보 내부관리계획 수립 및 매년 검토·갱신
  • 취급자는 보안서약서에 서명하고, 업무 변경·퇴직 시 접근 권한 즉시 회수
  • 개인정보 보호책임자(CPO)를 지정하여 처리 현황 정기 감독
③ 물리적 안전조치
  • 서버 및 저장 장치는 접근 통제 구역(잠금 장치 설치 공간)에 보관
  • 외부인의 기기 접근 차단 및 출입 기록 관리
6
AI 데이터 흐름 및 외부 LLM 제공자 공개

본 조는 ClassI AI 기능에서 처리되는 데이터가 어떻게 흐르는지, 특히 외부 AI 서비스 제공자에게 전송되는지 여부를 투명하게 공개합니다.

⚠ 중요 공개 사항: 학생 또는 교사가 ClassI AI 어시스턴트와 대화할 때, 해당 대화 텍스트(질문 + 맥락)는 응답 생성을 위해 외부 거대언어모델(LLM) API 제공자에게 전송됩니다. 이는 제3자 수탁업체와의 데이터 공유에 해당합니다.
① 외부 AI 제공자
AI 제공자가 변경될 경우, 개인정보처리방침을 즉시 업데이트하고 변경 적용 최소 30일 전에 사전 고지합니다.
② AI 제공자에게 전송되지 않는 정보
  • 학생 이름, 학번 등 직접 식별 가능한 정보
  • 기기명 또는 IP 주소
  • 화면 내용, 제어 로그, 화면 송출 데이터
  • 동의서 또는 AI 대화 맥락 외의 모든 기록
③ 국외 개인정보 이전

AI 대화 프롬프트 데이터는 주로 미국에 위치한 OpenAI 및 Google 서버에서 처리됩니다. 이는 개인정보의 국외 이전에 해당합니다. 디지윌은 개인정보 보호법 제28조의8을 포함한 관련 개인정보 보호법령에 따라 적절한 계약적 보호장치(데이터 처리 계약)를 통해 이전이 이루어지도록 합니다.

이전 대상 국가법적 근거보호 장치
미국 (OpenAI)개인정보 보호법 제28조의8 — 계약에 의한 이전OpenAI와의 데이터 처리 계약(DPA) 체결
미국 (Google LLC)개인정보 보호법 제28조의8 — 계약에 의한 이전Google과의 데이터 처리 계약(DPA) 체결
7
개인정보 보호책임자 및 담당 부서

디지윌은 이용자의 개인정보를 보호하고 관련 불만을 처리하기 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.

개인정보 보호책임자
홍석환
소속·직위
주식회사 디지윌
연락처(전화)
031-213-9280
연락처(이메일)
brick@digiwill.co.kr
처리 기간
접수 후 10일 이내 처리 및 회신

기타 개인정보 침해 관련 신고·상담은 아래 기관에 문의하실 수 있습니다.

개인정보침해 신고센터privacy.kisa.or.kr · ☎ 118 (국번없이)
대검찰청 사이버수사과cybercid.spo.go.kr · ☎ 1301 (국번없이)
경찰청 사이버안전국cyberbureau.police.go.kr · ☎ 182 (국번없이)
8
개인정보의 제3자 제공
디지윌은 이용자의 개인정보를 판매하거나 임대하지 않습니다. 학생 개인정보는 광고주, 마케팅사 등 외부 상업적 제3자에게 절대 제공되지 않습니다.

개인정보는 다음의 제한적인 경우에만 제3자에게 제공됩니다.

9
개인정보 처리 위탁 (수탁업체 실명 공개)

디지윌은 소프트웨어 운영, 유지보수 및 AI 기능 제공을 위해 아래의 수탁업체에 개인정보 처리를 위탁합니다. 모든 계약에는 개인정보 보호법에 따른 데이터 보호 의무가 명시되어 있으며, 각 수탁업체의 이행 여부를 감독합니다.

수탁업체 (법인명)소재 국가위탁 업무 내용접근 데이터보유 기간
주식회사 디지윌
자사 개발팀
대한민국 소프트웨어 개발, 시스템 운영, 버그 수정, 기능 개선, 내부 유지보수 모든 시스템 데이터 — 역할별 접근 권한 엄격 제한 고용·계약 기간 동안
Amazon Web Services, Inc. (AWS)
aws.amazon.com
대한민국
(ap-northeast-2 리전)
클라우드 인프라 — 애플리케이션 서버, 데이터베이스, AI 대화 데이터 저장소의 암호화 호스팅 암호화된 서버 및 데이터베이스 내용 (AWS는 평문 데이터에 접근 불가) 서비스 계약 기간 동안
OpenAI, L.L.C.
openai.com
미국 LLM API — ClassI AI 기능의 AI 응답 생성 (제6조 참고) AI 대화 프롬프트 텍스트만 (API 호출 시 학생 ID, 이름, 기기 정보 미포함) OpenAI API 데이터 정책에 따름; 모델 학습에 사용 안 함
Google LLC
cloud.google.com
미국 LLM API (Google Gemini) — ClassI AI 기능의 AI 응답 생성 보조 (제6조 참고) AI 대화 프롬프트 텍스트만 (API 호출 시 학생 ID, 이름, 기기 정보 미포함) Google Cloud API 데이터 정책에 따름; 모델 학습에 사용 안 함
수탁업체가 변경되거나 신규 수탁업체가 추가될 경우, 개인정보처리방침을 즉시 업데이트하고 변경 최소 30일 전에 앱 내 공지를 통해 사전 고지합니다.
10
정보주체(학생·보호자)의 권리와 행사 방법

학생 및 보호자(법정대리인)는 다음의 권리를 언제든지 행사할 수 있습니다.

  • 개인정보 열람 요청 — 처리 중인 개인정보의 확인
  • 개인정보 정정·삭제 요청 — 오류 정보의 수정 또는 불필요한 정보의 삭제
  • 개인정보 처리 정지 요청 — 특정 개인정보 처리의 중단
  • 동의 철회 — 수집·이용에 대한 동의를 언제든지 철회

위 권리 행사는 개인정보 보호책임자(제7조)에게 서면, 전화 또는 이메일로 요청하실 수 있으며, 접수 후 10일 이내에 처리 결과를 안내드립니다.

계정 삭제 및 데이터 파기 절차

교사·학교 관리자가 계정 삭제를 요청하거나, 학생의 재학 기간이 종료된 경우 아래 절차에 따라 데이터를 파기합니다.

단계처리 내용처리 기간
1. 삭제 요청 접수brick@digiwill.co.kr 또는 앱 내 계정 설정을 통해 삭제 요청 제출요청 즉시
2. 본인 확인무단 삭제 방지를 위해 요청자 본인 확인2영업일 이내
3. 활성 데이터 삭제계정에 연결된 모든 개인정보(AI 대화, 제어 로그, 세션 데이터)를 활성 데이터베이스에서 영구 삭제본인 확인 후 7영업일 이내
4. 백업 데이터 파기암호화된 백업 시스템의 잔여 데이터는 다음 정기 백업 주기에 덮어쓰기 방식으로 파기30일 이내
5. 파기 완료 통보등록된 이메일 주소로 파기 완료 확인 통보 발송파기 완료 즉시
예외 사항: 교육관련기관 정보보호법 등 법령에 따라 보존이 의무화된 동의서 및 감사 기록은 법정 보존 기간(재학 종료 후 2년) 동안 보관 후 파기합니다.
만 14세 미만 학생의 경우, 법정대리인(보호자)이 대신하여 권리를 행사할 수 있습니다.
11
개인정보처리방침의 변경

디지윌은 개인정보처리방침을 변경하는 경우, 최소 7일 전에 소프트웨어 내 공지사항 또는 가정통신문을 통해 사전 고지합니다. 중요한 사항이 변경되는 경우에는 최소 30일 전에 고지합니다.

현행 버전v1.0
시행일자2026년 6월 16일
최종 수정일2026년 6월 15일
본 개인정보처리방침은 「개인정보 보호법」 제30조에 따라 수립·공개되었습니다.

         



@Copyright 2022. All Right Reserved. Hosted by Imweb