Cookie Policy
Effective Date: July 3, 2026
The Software Creation Studio (hereinafter referred to as "the Company") uses cookies and similar tracking technologies to provide users with a reliable, secure service and a personalized experience while operating its website and services (including PolyBot, PolyGlot, and other digital services). This cookie policy is part of the Company's privacy policy. Software Creation Studio
1. Applicable laws for this policy
This service targets users in South Korea, the European Economic Area (EEA), and the UK, so this cookie policy applies in conjunction with South Korea's Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Article 22-2, as well as the EU General Data Protection Regulation (GDPR), EU ePrivacy Directive Article 5(3) (Directive 2002/58/EC, Art. 5(3)), UK General Data Protection Regulation (UK GDPR), UK Data Protection Act (Data Protection Act 2018), and Privacy and Electronic Communications Regulations (PECR) 2003.
2. What are Cookies?
Cookies are small text files that are stored in a user's browser when they visit a website. While cookies do not directly identify users, they can contain information such as:
- Login Status and Session Information
- Language and UI settings
- Visit duration and page navigation path
- Device and browser information
- Advertising and analytics identifiers
3. Purpose of cookie usage and legal basis for processing
The company categorizes cookies for specific purposes and specifies the legal basis for processing in each category (GDPR/UK GDPR Article 6).
3.1 Strictly Necessary Cookies
These cookies are essential for the website to function properly. They are used without prior consent as they are necessary for providing the service. Legal basis: Necessary measures for providing information and communication services (PECR Reg 6(4) exception), contract fulfillment, and legitimate interests (GDPR/UK GDPR Article 6(1) (b), (f))
- Maintain login status and handle user authentication
- Session Management and User Request Maintenance
- Defense against security attacks such as CSRF and session hijacking
- Maintaining server stability and traffic distribution
3.2 Functional Cookies
We remember your settings to provide a personalized experience. Since this does not fall under strictly necessary cookies, it will only be activated after obtaining your prior consent (Opt-in) in accordance with PECR Regulation 6 and EU ePrivacy Directive Article 5(3). Legal basis: Consent (GDPR/UK GDPR Article 6(1)(a))
- Maintain language settings
- Remember UI themes and settings
- Minimize repetitive input
3.3 Analytics Cookies
We analyze user visit patterns to improve service quality. Google Analytics 4 (GA4) may be used and will only be activated with the user's explicit consent. Legal basis: Consent (GDPR/UK GDPR Article 6(1)(a))
- Visitor count and traffic patterns
- Page navigation flow and user behavior paths
- Frequency of feature usage and points for service improvement
3.4 Marketing Cookies
Used for interest-based advertising and performance analysis. Meta Pixel, Google Ads, etc. may be used, and explicit consent (Opt-in) from the user is required. Legal basis: Consent (GDPR/UK GDPR Article 6(1)(a))
- Providing interest-based advertising
- Analysis of ad clicks and conversion rates
- Running Retargeting Campaigns
3.5 Security Cookies
Used for detecting abnormal access and protecting services. Security infrastructure providers like Cloudflare may use this. Legal basis: Legitimate interests (GDPR/UK GDPR Article 6(1)(f))
- Detection and blocking of bot traffic
- DDoS attack defense
- Detection of abnormal login attempts
4. Google Consent Mode v2
The company applies Google Consent Mode v2 to automatically adjust the scope of data collection based on the user's consent status.
- ad_storage: Whether to store advertising data
- analytics_storage: Whether to store analytics data
- functionality_storage: Whether to store functionality data
- security_storage: Whether to store security data
5. IAB TCF 2.2
The company complies with the IAB Transparency & Consent Framework 2.2 to ensure transparency in digital advertising.
- Store user consent status in a standardized Consent String
- Separation of data processing purposes for advertising
- Management and limitation of advertising vendors
6. Consent Record Storage (Cookie Consent Log)
The company securely stores all cookie consent and rejection records for auditing and regulatory compliance purposes.
- Cookie consent status (Full consent / Partial consent / Refusal)
- Consent or rejection timestamp
- Browser and device information
- IP address (anonymized where possible)
- Selected Cookie Category Information
7. Use of Third-Party Cookies
Cookies from the following third parties may be used to provide services.
- Google - Analytics, Ads (policies.google.com/privacy)
- Meta - Facebook / Instagram advertising (facebook.com/privacy/policy/)
- AWS - Cloud Infrastructure Operations (aws.amazon.com/privacy/)
- Cloudflare - Security and CDN (cloudflare.com/privacypolicy/)
8. International Transfer of Personal Data
To operate our services, we may transfer personal information abroad as outlined below, applying appropriate safety measures required by each jurisdiction during the transfer.
- Amazon Web Services, Inc. (USA) - Cloud infrastructure (until service termination). EU users: European Commission Standard Contractual Clauses (EU SCC) apply / UK users: UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs apply
- Google LLC (USA) - Analytics and advertising (up to 24 months). The same previous mechanisms (EU SCC / UK IDTA or UK Addendum) apply
- Meta Platforms, Inc. (USA) - Ad targeting (up to 3 months). The same previous mechanisms (EU SCC / UK IDTA or UK Addendum) apply
- Cloudflare, Inc. (USA) - Security and CDN (processing IP addresses, etc. during bot traffic detection and DDoS defense, up to 12 months). The same previous mechanisms (EU SCC / UK IDTA or UK Addendum) apply
- A copy of the previous contract can be accessed upon request through the contact information provided in Article 16.
9. Cookie Retention Period
- Session cookies - automatically deleted upon browser closure
- Essential cookies - up to 12 months
- Functional cookies - up to 12 months
- Analytics cookies - up to 24 months
- Marketing Cookies - Up to 3 Months
- Secure cookies - up to 12 months
10. How to Manage Cookies
- Website settings: You can change or withdraw your consent at any time through the "Cookie Settings" link at the bottom. The initial consent banner provides "Accept All" and "Reject All" buttons of the same size, color, and prominence, ensuring that users do not face additional clicks or disadvantages when choosing to reject (according to ICO cookie guidelines).
- Browser settings: You can block, delete, or limit cookies in browsers like Chrome, Safari, Edge, and Firefox.
- If you refuse cookies: You may experience limitations in maintaining login sessions, saving personalization settings, and some service functionalities may be restricted.
11. Rights of the Data Subject
Users can request access, correction, deletion, or suspension of processing of personal information collected through cookies. Please direct your requests to the personal information protection officer listed in Article 16.
Users also have the right to file complaints directly with the following supervisory authorities.
- South Korea: Personal Information Protection Commission (privacy.go.kr / 182 without area code)
- European Economic Area (EEA): Supervisory authority (Data Protection Authority) of the member state where the user resides
- United Kingdom: Information Commissioner's Office (ICO) (ico.org.uk)
12. Data Security
- Encrypted communication with TLS 1.2 or higher
- AES-256 data encryption
- Zero Trust-based Access Control
- Real-time security log monitoring
13. Protection of Minors
South Korea: Our services are not intended for individuals under the age of 14. If we become aware that information from children under 14 has been collected without consent, we will take immediate deletion action.
European Economic Area (EEA): According to Article 8 of the GDPR, consent for the processing of children's personal data can generally be given by individuals aged 16 and older, and for those under 16, consent must be obtained from a parent or legal guardian. If the member state where the user resides has a lower age limit (minimum 13 years), that standard applies.
UK: In accordance with the Age Appropriate Design Code by the UK Information Commissioner's Office (ICO), marketing and analytics cookies for profiling are disabled by default for users estimated to be under 18, and the highest level of privacy settings is applied.
14. EU and UK Representative
The Company is located in South Korea and does not have business establishments in the European Economic Area (EEA) or the United Kingdom. In accordance with Article 27 of the GDPR and Article 27 of the UK GDPR (UK DPA 2018, Schedule 21), the Company designates the following representative.
- EU Representative: Peter Cho (Email: governance@softwarecreation.studio)
- UK Agent: Peter Cho (Email: governance@softwarecreation.studio)
15. Policy Changes
This cookie policy may be updated due to changes in laws, technological advancements, or service improvements, and significant changes will be announced in advance through the website.
16. Contact
Software Creation Studio (Software Creation Studio)
Email: governance@softwarecreation.studio
Address: 9th Floor, Signature Tower West, 100 Cheonggyecheon-ro, Jung-gu, Seoul
Data Protection Officer: Peter Cho (Phone: 010-2069-1670 / Email: governance@softwarecreation.studio)
EU Representative: Peter Cho (governance@softwarecreation.studio)
UK representative: Peter Cho (governance@softwarecreation.studio)