Legal

Privacy Policy

Effective Date: July 3, 2026

Software Creation Studio (hereinafter referred to as "the Company") has established and disclosed this Privacy Policy in compliance with the Personal Information Protection Act and related laws to protect users' personal information. This Privacy Policy applies to all online services provided by the Company (including PolyBot, PolyGlot, and other digital services).

1. Applicable Laws of This Policy

This service targets users in South Korea, the European Economic Area (EEA), and the United Kingdom, and this privacy policy applies in conjunction with South Korea's Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, as well as the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Details regarding cookies and similar tracking technologies are specified in a separate 'Cookie Policy,' which constitutes part of this privacy policy.

2. Personal Information Collection Items and Collection Methods

The company may collect the following personal information.

  • [Required Collection Items] Company Name, Name, Mobile Phone Number, Email, Password
  • [Mandatory Collection Items] When inquiring about a project: Project Type, Project Description, etc., entered directly by the user
  • [Automatically Collected Items] IP address, device information (browser, OS), cookies, visit date and time, usage logs, access records
  • [Optional Collection Items] When participating in surveys or events: Name, Contact Information, Other Input Information
  • [Optional Collection Items] If consent is given for receiving marketing information: Email, SMS reception information

2-1. Methods of Personal Information Collection

  • Website Registration and Service Usage Process
  • Customer Service Inquiries (Phone, Email, Inquiry Form)
  • Automatic collection through cookies and log analysis tools

3. Purpose of Collection and Use of Personal Data and Legal Basis for Processing

The company processes personal information for the purposes outlined below, and specifies the legal basis for processing under Article 6 of GDPR/UK GDPR for users in the EEA and the UK.

  • Service Provision: Inquiry reception and response, consultation process (Basis: Fulfillment of contract - GDPR Article 6, Paragraph 1 (b))
  • Member Management: Identity verification, delivery of announcements, record management (Basis: Fulfillment of contract and legitimate interests - Article 6, Paragraph 1 (b), (f))
  • Service Improvement: Statistics and Analysis, Quality Improvement (Basis: Legitimate Interest or Consent - Article 6(1)(f) or (a))
  • Marketing Use (with Consent): Events, Advertising, Benefits (Basis: Consent - Article 6(1)(a))
  • Compliance with Laws: Dispute resolution and legal obligation fulfillment (Basis: Compliance with legal obligations - Article 6, Paragraph 1 (c))

4. Retention and Use Period of Personal Data

The company retains personal information until the purpose of collection is achieved and will delete it without delay after achieving the purpose. However, it may be retained for the period specified by relevant laws.

  • Service Usage Record: 3 years
  • Contract and Payment Records: 5 years
  • Consumer Dispute Record: 3 years
  • Access Log Retention: 3 months
  • Upon membership withdrawal: Information will be destroyed without delay, but information subject to retention obligations under relevant laws will be stored separately from other personal information for the required period before destruction.

5. Provision of Personal Information to Third Parties

The Company generally does not provide personal information to external parties. However, it may be provided in the following cases.

  • If the user has given prior consent
  • When requested by law
  • When there is a lawful request from investigative authorities

6. Outsourcing of Personal Information Processing

The Company entrusts personal information processing tasks as follows to ensure smooth service provision and conducts management and supervision for safe processing during outsourcing.

  • Amazon Web Services, Inc. - Cloud infrastructure operation and data storage
  • Google LLC - Service Usage Analysis (Google Analytics 4) and Advertising
  • Meta Platforms, Inc. - Advertising and Performance Measurement
  • Cloudflare, Inc. - Security and CDN (Content Delivery)
  • In cases where additional outsourcing occurs, such as for sending other messages or payment processing (PG), the details will be notified in advance through this policy or the website.

7. International Transfer of Personal Data

The company transfers personal data abroad as described below for service operation and applies appropriate safety measures in accordance with Article 28-8 of the Personal Information Protection Act and Chapter 5 of the GDPR/UK GDPR. Users may refuse the international transfer, and refusal may limit access to certain services.

  • Recipient: Amazon Web Services, Inc. / Transfer Country: United States / Transferred Items: All personal information generated during service use / Transfer Purpose: Cloud infrastructure operation / Retention Period: Until service termination
  • Recipient: Google LLC / Transfer Country: United States / Transferred Items: Cookies, Usage Logs, Device Identifiers / Purpose of Transfer: Analysis, Advertising / Retention Period: Up to 24 months
  • Recipient: Meta Platforms, Inc. / Transfer Country: United States / Transferred Items: Cookies, Advertising Identifiers / Purpose of Transfer: Advertising Targeting / Retention Period: Up to 3 months
  • Recipient: Cloudflare, Inc. / Transfer Country: United States / Transferred Items: IP address and access information / Transfer Purpose: Security and CDN / Retention Period: Up to 12 months
  • When transferring personal information of EEA and UK users abroad, the European Commission's Standard Contractual Clauses (EU Standard Contractual Clauses, SCC) or the UK's International Data Transfer Agreement (IDTA)/UK Addendum to EU SCC will be applied as the basis for transfer. Copies of related contracts can be requested and reviewed through the contact information in Article 14.

8. Rights of Users and Legal Representatives

Users may request the following at any time.

  • Access to Personal Information
  • Correction and Deletion
  • Request for Processing Suspension
  • Withdrawal of Consent
  • Request for Account Deletion and Withdrawal
  • (EEA and UK Users) Right to Data Portability and Rights Related to Automated Decision-Making

8-1. Application for Rights Remedy to Supervisory Authorities

Users also have the right to directly file complaints or seek dispute resolution with the following supervisory authorities.

  • South Korea: Personal Information Protection Commission (privacy.go.kr / 182 without area code), Personal Information Infringement Reporting Center (privacy.kisa.or.kr / 118 without area code), Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • European Economic Area (EEA): Supervisory authority (Data Protection Authority) of the member state where the user resides
  • United Kingdom: Information Commissioner's Office (ICO) (ico.org.uk)

9. Procedures and Methods for Destruction of Personal Data

Personal data will be destroyed without delay upon the expiration of the retention period or upon achieving the purpose of processing.

  • Electronic Files: Permanently deleted using unrecoverable technical methods
  • Paper Documents: Shredding or incineration

10. Cookie Usage and Refusal Guidance

The company uses cookies and similar tracking technologies to provide customized services. Functional, analytical, and marketing cookies, except for essential cookies, will only be activated after obtaining prior consent (Opt-in) from the user, and consent can be changed or withdrawn at any time through the 'Cookie Settings' at the bottom of the website. Details regarding the types, purposes, retention periods, third parties, and international transfers of cookies are specified in a separate 'Cookie Policy.'

How to refuse cookies: Browser settings → Privacy → Block cookies. Some services may be restricted if cookies are refused.

11. Measures to Ensure the Security of Personal Information

The Company implements the following measures to protect personal information.

  • Administrative Measures: Establishment and Implementation of Internal Management Plans, Regular Employee Training, Access Rights Management
  • Technical Measures: Encryption of transmission segments (TLS 1.2 or higher), encryption of stored data (AES-256), firewalls and security programs, Zero Trust-based access control
  • Physical Measures: Access control to server rooms and data storage rooms

11-1. Data Protection Measures Specialized for AI Services

Details regarding AI-specific data protection measures such as de-identification of personally identifiable information (PII) during the use of AI services (PolyBot, PolyGlot, etc.), isolation of conversation session memory, and prohibition of re-learning customer data are stipulated in Article 1 of the 'AI Service Operation Policy'.

12. Protection of Minors' Personal Information

  • South Korea: The company's services are not intended for individuals under the age of 14. If it is recognized that personal data of children under 14 has been collected without consent, immediate deletion measures will be taken.
  • European Economic Area (EEA): According to Article 8 of the GDPR, consent for the processing of children's personal data can generally be given by individuals aged 16 and older, and for those under 16, consent must be obtained from a parent or legal guardian. If a member state has set a lower age limit (at least 13 years), that standard will apply.
  • United Kingdom: In accordance with the Age Appropriate Design Code from the UK Information Commissioner's Office (ICO), marketing and analytical cookies for profiling will be disabled by default for users estimated to be under 18 years old, and the highest level of privacy settings will be applied.

13. EU and UK Representative

The Company is located in South Korea and does not have business establishments in the European Economic Area (EEA) or the United Kingdom. In accordance with Article 27 of the GDPR and Article 27 of the UK GDPR (UK DPA 2018, Schedule 21), the Company designates the following representative.

  • EU Representative: Peter Cho (Email: governance@softwarecreation.studio)
  • UK Agent: Peter Cho (Email: governance@softwarecreation.studio)

14. Personal Information Protection Officer and Contact Information

Users can request inquiries, complaint handling, and damage relief related to personal information from the personal information protection officer below.

  • Personal Information Protection Officer: Peter Cho (Software Creation Studio)
  • Phone: 010-2069-1670
  • Email: governance@softwarecreation.studio
  • Address: 100 Cheonggyecheon-ro, Jung-gu, Seoul, Signature Tower West, 9th Floor
  • EU Representative / UK Representative: Peter Cho (governance@softwarecreation.studio)

15. Notice of Changes to the Privacy Policy

This privacy policy may be revised in response to changes in laws, technological developments, or service improvements, and any changes will be announced in advance on our website along with the reasons and details.