Cookie Policy
Effective Date: July 3, 2026
This translation is provided for convenience only. In case of any discrepancies between this translation and the original in Korean, the original in Korean shall prevail.
Software Creation Studio (hereinafter referred to as the "Company") uses cookies and similar tracking technologies while operating its websites and services (including PolyBot, PolyGlot, and other digital services) to provide a stable and secure experience, offer personalized interactions, and continuously improve service quality. This Cookie Policy is part of the Company's Privacy Policy.
1. Applicable Legislation
Since this service is aimed at users in the Republic of Korea, as well as the European Economic Area (EEA) and the United Kingdom, this Cookie Policy is governed by the Personal Information Protection Act of Korea, Article 22-2 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, the EU General Data Protection Regulation (GDPR), Article 5(3) of the EU ePrivacy Directive (Directive 2002/58/EC), the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act of 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
2. What are cookies?
A cookie is a small text file that a website stores in your browser when you visit it. Cookies do not directly identify you, but they may contain or refer to the following.
- Login status and session information
- Language and user interface settings
- Visit time and navigation path through pages
- Device and browser information
- Advertising and analytics identifiers
3. Purposes of using cookies and legal basis for processing
The Company classifies and uses cookies for the following purposes, along with the legal basis for processing each category (Article 6 of the GDPR/UK GDPR).
3.1 Strictly necessary cookies
These cookies are essential for the website to function properly. As they are indispensable for providing the service, they are used without prior consent. Legal basis: a necessary measure for providing an information society service (exemption under Reg. 6(4) of the PECR); performance of a contract and legitimate interest (GDPR/UK GDPR art. 6(1)(b), (f)).
- Maintaining login status and processing user authentication
- Session management and persistence of user requests
- Defense against CSRF, session hijacking, and other security attacks
- Server stability and load balancing
3.2 Functional cookies
These cookies remember your settings to provide a more personalized experience. As they are not considered strictly necessary cookies, they are only activated after obtaining your prior opt-in consent, in accordance with Regulation 6 of the PECR and Article 5(3) of the EU ePrivacy Directive. Legal basis: consent (GDPR/UK GDPR art. 6(1)(a)).
- Maintaining language settings
- Remembering user interface theme and preference settings
- Minimizing repeated data entry
3.3 Analytics cookies
These cookies analyze your visit patterns to help us improve service quality. Google Analytics 4 (GA4) may be used and is only activated with your explicit consent. Legal basis: consent (GDPR/UK GDPR art. 6(1)(a)).
- Analyzing the number of visitors and traffic patterns
- Navigation flow through pages and user behavior paths
- Frequency of feature usage and information for service improvement
3.4 Marketing cookies
These cookies are used for interest-based advertising and performance analysis. Meta Pixel, Google Ads, and similar tools may be used, and they require your explicit opt-in consent. Legal basis: consent (GDPR/UK GDPR art. 6(1)(a)).
- Interest-based advertising
- Analyzing ad clicks and conversion rates
- Retargeting campaigns
3.5 Security cookies
These cookies are used to detect anomalous access and protect the service. Security infrastructure providers like Cloudflare may use them. Legal basis: legitimate interest (GDPR/UK GDPR art. 6(1)(f)).
- Detecting and blocking bot traffic
- Defense against DDoS attacks
- Detecting anomalous login attempts
4. Google Consent Mode v2
The Company applies Google Consent Mode v2 to automatically adjust the scope of data collection based on your consent status.
- ad_storage: if advertising data can be stored
- analytics_storage: if analytics data can be stored
- functionality_storage: if functional data can be stored
- security_storage: if security data can be stored
5. IAB TCF 2.2
The Company complies with the IAB Transparency and Consent Framework (TCF) 2.2 to ensure transparency in digital advertising.
- Storage of the user's consent status as a standardized Consent String
- Separation of data processing purposes for advertising purposes
- Management and restriction of advertising providers
6. Cookie consent logging
The Company securely stores all records of cookie consent and rejection for audit and regulatory compliance purposes.
- Cookie consent status (accept all / partial consent / reject)
- Timestamp of consent or rejection
- Browser and device information
- IP address (anonymized where possible)
- Information on the selected cookie category
7. Third-party cookies
Cookies from the following third parties may be used to provide the service.
- Google - Analytics, Ads (policies.google.com/privacy)
- Meta - Advertising on Facebook / Instagram (facebook.com/privacy/policy/)
- AWS - Cloud infrastructure operations (aws.amazon.com/privacy/)
- Cloudflare - Seguridad y CDN (cloudflare.com/privacypolicy/)
8. Transferencias internacionales de información personal
La Empresa podrá transferir información personal al extranjero de la siguiente manera para las operaciones del servicio, aplicando las garantías adecuadas exigidas en cada jurisdicción.
- Amazon Web Services, Inc. (EE. UU.) - Infraestructura en la nube (hasta la finalización del servicio). Usuarios de la UE: se aplican las Cláusulas Contractuales Tipo (CCT) de la Comisión Europea / Usuarios del Reino Unido: se aplica el Acuerdo Internacional de Transferencia de Datos del Reino Unido (IDTA) o el Anexo del Reino Unido a las CCT de la UE
- Google LLC (EE. UU.) - Análisis y publicidad (hasta 24 meses). Se aplica el mismo mecanismo de transferencia (CCT de la UE / IDTA del Reino Unido o Anexo del Reino Unido) que el anterior
- Meta Platforms, Inc. (EE. UU.) - Segmentación de anuncios (hasta 3 meses). Se aplica el mismo mecanismo de transferencia (CCT de la UE / IDTA del Reino Unido o Anexo del Reino Unido) que el anterior
- Cloudflare, Inc. (EE. UU.) - Seguridad y CDN (trata direcciones IP y otros datos para la detección de tráfico de bots y la defensa frente a DDoS, hasta 12 meses). Se aplica el mismo mecanismo de transferencia (CCT de la UE / IDTA del Reino Unido o Anexo del Reino Unido) que el anterior
- Los interesados pueden solicitar una copia del acuerdo de transferencia a través de los datos de contacto que figuran en la Sección 16.
9. Períodos de conservación de las cookies
- Cookies de sesión - Se eliminan automáticamente cuando se cierra el navegador
- Cookies estrictamente necesarias - Hasta 12 meses
- Cookies funcionales - Hasta 12 meses
- Cookies de análisis - Hasta 24 meses
- Cookies de marketing - Hasta 3 meses
- Cookies de seguridad - Hasta 12 meses
10. Gestión de las cookies
- Configuración del sitio web: Puede cambiar o retirar su consentimiento en cualquier momento a través del enlace "Configuración de cookies" en la parte inferior del sitio web. El banner de consentimiento inicial presenta los botones "Aceptar todo" y "Rechazar todo" con el mismo tamaño, color y en el mismo paso, de modo que los usuarios no incurran en clics adicionales ni en desventaja alguna al optar por rechazarlas (conforme a las directrices sobre cookies de la ICO).
- Configuración del navegador: La mayoría de los navegadores (Chrome, Safari, Edge, Firefox, etc.) le permiten bloquear, eliminar o restringir las cookies.
- Efectos del rechazo: La persistencia del inicio de sesión puede verse restringida, la configuración personalizada no puede guardarse y algunas funciones del servicio pueden verse limitadas.
11. Derechos de los interesados
Puede solicitar el acceso, la rectificación, la supresión o la restricción del tratamiento de su información personal recopilada a través de cookies. Dirija dichas solicitudes al Delegado de Protección de Datos que figura en la Sección 16.
También tiene derecho a presentar una reclamación directamente ante las siguientes autoridades de control.
- República de Corea: Comisión de Protección de Información Personal (privacy.go.kr / 182, línea gratuita)
- Espacio Económico Europeo (EEE): La autoridad de control competente (Autoridad de Protección de Datos) de su Estado miembro de residencia
- Reino Unido: Oficina del Comisionado de Información (ICO) (ico.org.uk)
12. Seguridad de los datos
- Comunicaciones cifradas con TLS 1.2 o superior
- Almacenamiento de datos cifrado con AES-256
- Control de acceso basado en Zero Trust
- Supervisión en tiempo real de los registros de seguridad
13. Protección de menores
República de Corea: Nuestros servicios no están dirigidos a menores de 14 años. Si tenemos conocimiento de que se ha recopilado información de un menor de 14 años sin consentimiento, adoptaremos medidas inmediatas para suprimirla.
Espacio Económico Europeo (EEE): En virtud del artículo 8 del RGPD, el consentimiento para el tratamiento de la información personal de un menor puede, por lo general, ser otorgado directamente por el menor a partir de los 16 años y, cuando el menor sea menor de 16 años, el consentimiento debe obtenerse de un progenitor o tutor legal. Cuando el Estado miembro de residencia de un usuario establezca por ley una edad inferior (un mínimo de 13 años), se aplicará dicho umbral.
Reino Unido: De conformidad con el Código de Diseño Apropiado a la Edad de la Oficina del Comisionado de Información del Reino Unido (ICO), cuando se presuma que un usuario es menor de 18 años, las cookies de marketing y de análisis utilizadas para la elaboración de perfiles se desactivan de forma predeterminada, y la configuración de privacidad se aplica en el nivel de protección más elevado (configuración predeterminada de alta privacidad).
14. Representantes en la UE y el Reino Unido
La Empresa está ubicada en la República de Corea y no dispone de un establecimiento en el Espacio Económico Europeo (EEE) ni en el Reino Unido. De conformidad con el artículo 27 del RGPD y el artículo 27 del UK GDPR (Anexo 21 de la UK DPA 2018), la Empresa ha designado a los siguientes representantes.
- Representante en la UE: Peter Cho (correo electrónico: governance@softwarecreation.studio)
- Representante en el Reino Unido: Peter Cho (correo electrónico: governance@softwarecreation.studio)
15. Cambios en la Política
Esta Política de Cookies podrá actualizarse en respuesta a cambios en la legislación, la tecnología o mejoras del servicio. Los cambios sustanciales se anunciarán con antelación en el sitio web.
16. Contacto
Software Creation Studio
Correo electrónico: governance@softwarecreation.studio
Dirección: 100 Cheonggyecheon-ro, Jung-gu, Seúl, Signature Tower West, 9F
Delegado de Protección de Datos: Peter Cho (Teléfono: 010-2069-1670 / Correo electrónico: governance@softwarecreation.studio)
Representante en la UE: Peter Cho (governance@softwarecreation.studio)
Representante en el Reino Unido: Peter Cho (governance@softwarecreation.studio)