Privacy Policy
Effective Date: July 3, 2026
This translation is provided for convenience only. In case of discrepancies between this translation and the original Korean, the original Korean prevails.
Software Creation Studio (hereinafter referred to as the 'Company') complies with the Korean Personal Information Protection Act and related laws, and to protect users' personal information, establishes and publishes the following Privacy Policy. This Privacy Policy applies to all online services provided by the Company (including PolyBot, PolyGlot, and other digital services).
1. Applicable Law
Since this service is aimed at users located in the Republic of Korea as well as in the European Economic Area (EEA) and the United Kingdom, this Privacy Policy is governed by the Korean Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, as well as the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Details regarding cookies and similar tracking technologies are outlined in a separate Cookie Policy, which is an integral part of this Privacy Policy.
2. Personal Information Collected and Methods of Collection
The Company may collect the following personal information.
- [Mandatory Information] Company name, name, mobile phone number, email, password
- [Mandatory Information] When submitting a project request: project type, project description, and other information entered directly by the user
- [Automatically Collected Information] IP address, device information (browser, operating system), cookies, date and time of visit, usage logs, access records
- [Optional Information] Name, contact details, and other information provided during participation in surveys or events
- [Optional Information] Email and SMS subscription details provided when consenting to receive marketing information
2-1. Methods of Collecting Personal Information
- When registering on the website and using the services
- Through requests to customer support (phone, email, request form)
- Automatic collection via cookies and log analysis tools
3. Purposes of Collecting and Using Personal Information and Legal Basis for Processing
The Company processes personal information for the purposes below and, for users in the EEA and the UK, also specifies the legal basis under Article 6 of the GDPR / UK GDPR.
- Service provision: receiving and responding to requests, and conducting consultations (Basis: performance of a contract - GDPR art. 6, § 1, point b)
- Member management: identity verification, sending notifications, and managing records (Basis: performance of a contract and legitimate interests - art. 6, § 1, points b and f)
- Service improvement: statistics and analysis, and quality enhancement (Basis: legitimate interests or consent - art. 6, § 1, point f or a)
- Marketing purposes (with consent): offering events, advertising, and benefits (Basis: consent - art. 6, § 1, point a)
- Legal compliance: resolving disputes and fulfilling legal obligations (Basis: compliance with a legal obligation - art. 6, § 1, point c)
4. Retention and Use Period of Personal Information
The Company retains personal information until the purpose of collection is achieved and deletes it promptly once that purpose is fulfilled. However, the Company may retain it for the periods indicated below, in accordance with applicable laws.
- Service usage records: 3 years
- Contract and payment records: 5 years
- Consumer dispute records: 3 years
- Access logs: 3 months
- In the event of membership termination: destroyed promptly, except for information subject to a legal retention obligation, which is stored separately from other personal information for the required duration before destruction
5. Disclosure of Personal Information to Third Parties
In general, the Company does not disclose personal information to external third parties. However, it may be disclosed in the following cases.
- When the user has given prior consent
- When required by applicable laws
- When requested by an investigative authority in the course of legal proceedings
6. Outsourcing of Personal Information Processing
To ensure the proper provision of services, the Company outsources personal information processing tasks as described below and exercises management and supervision to ensure secure processing in this regard.
- Amazon Web Services, Inc. - Cloud infrastructure operation and data storage
- Google LLC - Service usage analysis (Google Analytics 4) and advertising
- Meta Platforms, Inc. - Advertising and Performance Measurement
- Cloudflare, Inc. - Security and CDN (Content Delivery Network)
- In the case of additional outsourcing, such as to SMS sending agencies or payment gateway providers (PG), details will be announced in advance through this Policy or the website.
7. International Transfers of Personal Information
The Company transfers personal information abroad as follows for the operation of the service, applying appropriate safeguards in accordance with Article 28-8 of the Personal Information Protection Act and Chapter V of the GDPR / UK GDPR. Users may refuse international transfers, and such refusal may restrict the use of certain services.
- Recipient: Amazon Web Services, Inc. / Destination Country: United States / Transferred Items: personal information generated during the use of the service / Purpose: operation of cloud infrastructure / Retention Period: until the end of the service
- Recipient: Google LLC / Destination Country: United States / Transferred Items: cookies, usage logs, device identifiers / Purpose: analysis and advertising / Retention Period: up to 24 months
- Recipient: Meta Platforms, Inc. / Destination Country: United States / Transferred Items: cookies, advertising identifiers / Purpose: advertising targeting / Retention Period: up to 3 months
- Recipient: Cloudflare, Inc. / Destination Country: United States / Transferred Items: IP address, access information / Purpose: security and CDN / Retention Period: up to 12 months
- For international transfers of personal information belonging to users in the EEA and the UK, the European Commission's Standard Contractual Clauses (SCC) or the UK International Data Transfer Agreement (IDTA) / the UK addendum to the EU SCCs are applied as the transfer basis. A copy of the relevant agreement can be requested and reviewed through the contact information provided in Section 14.
8. User Rights and Legal Representatives
Users may request the following at any time.
- Access to personal information
- Correction and deletion
- Request for suspension of processing
- Withdrawal of consent
- Request for termination of membership and account deletion
- (Users in the EEA and the UK) The right to data portability and rights related to automated decision-making
8-1. Right to lodge a complaint with supervisory authorities
Users also have the right to lodge a complaint or request dispute resolution directly with the following supervisory authorities.
- République de Corée : Commission de protection des informations personnelles (privacy.go.kr / 182, numéro gratuit), Centre de signalement des atteintes à la vie privée (privacy.kisa.or.kr / 118, numéro gratuit), Comité de médiation des litiges relatifs aux informations personnelles (kopico.go.kr / 1833-6972)
- Espace économique européen (EEE) : L'autorité de contrôle compétente (autorité de protection des données) de votre État membre de résidence
- Royaume-Uni : Information Commissioner's Office (ICO) (ico.org.uk)
9. Procédures et méthodes de destruction des informations personnelles
Les informations personnelles sont détruites sans délai une fois la durée de conservation écoulée ou la finalité du traitement atteinte.
- Fichiers électroniques : supprimés définitivement à l'aide de méthodes techniques rendant la récupération impossible
- Documents papier : déchiquetés ou incinérés
10. Utilisation des cookies et modalités de refus
La Société utilise des cookies et des technologies de suivi similaires pour fournir des services personnalisés. Les cookies fonctionnels, d'analyse et de marketing autres que les cookies strictement nécessaires ne sont activés qu'après l'obtention du consentement préalable (opt-in) de l'utilisateur, et le consentement peut être modifié ou retiré à tout moment via les « Paramètres des cookies » en bas du site web. Les détails relatifs aux types, aux finalités, aux durées de conservation et aux transferts à des tiers et internationaux des cookies sont exposés dans une Politique relative aux cookies distincte.
Comment refuser les cookies : paramètres du navigateur → confidentialité → bloquer les cookies. Si vous refusez les cookies, l'utilisation de certains services peut être restreinte.
11. Mesures visant à garantir la sécurité des informations personnelles
La Société met en œuvre les mesures suivantes pour protéger les informations personnelles.
- Mesures administratives : établissement et mise en œuvre d'un plan de gestion interne, formation régulière du personnel et gestion des privilèges d'accès
- Mesures techniques : chiffrement des données en transit (TLS 1.2 ou supérieur), chiffrement des données stockées (AES-256), pare-feu et programmes de sécurité, et contrôle d'accès fondé sur le Zero Trust
- Mesures physiques : contrôle d'accès aux salles de serveurs et aux zones de stockage des données
11-1. Mesures de protection des données spécifiques aux services d'IA
Les détails relatifs aux mesures de protection des données spécifiques à l'IA lors de l'utilisation des services d'IA (tels que PolyBot et PolyGlot), notamment l'anonymisation des informations personnelles identifiables (PII), l'isolement de la mémoire des sessions de conversation et l'interdiction d'utiliser les données des clients à des fins de réentraînement, sont exposés à l'article 1 de la Politique d'exploitation des services d'intelligence artificielle (IA).
12. Protection des informations personnelles des mineurs
- République de Corée : Nos services ne s'adressent pas aux enfants de moins de 14 ans. Si nous prenons connaissance du fait que les informations personnelles d'un enfant de moins de 14 ans ont été collectées sans consentement, nous prendrons des mesures immédiates pour les supprimer.
- Espace économique européen (EEE) : En vertu de l'article 8 du RGPD, le consentement au traitement des informations personnelles d'un enfant peut généralement être donné directement par l'enfant à partir de l'âge de 16 ans, et lorsque l'enfant a moins de 16 ans, le consentement doit être obtenu d'un parent ou d'un tuteur légal. Lorsqu'un État membre fixe par la loi un âge inférieur (au minimum 13 ans), ce seuil s'applique.
- Royaume-Uni : Conformément au Age Appropriate Design Code de l'Information Commissioner's Office (ICO) britannique, lorsqu'un utilisateur est présumé avoir moins de 18 ans, les cookies de marketing et d'analyse utilisés à des fins de profilage sont désactivés par défaut, et les paramètres de confidentialité sont appliqués au niveau de protection le plus élevé.
13. Représentants pour l'UE et le Royaume-Uni
La Société est établie en République de Corée et ne dispose pas d'établissement dans l'Espace économique européen (EEE) ni au Royaume-Uni. Conformément à l'article 27 du RGPD et à l'article 27 du UK GDPR (annexe 21 du UK DPA 2018), la Société a désigné les représentants suivants.
- Représentant pour l'UE : Peter Cho (e-mail : governance@softwarecreation.studio)
- Représentant pour le Royaume-Uni : Peter Cho (e-mail : governance@softwarecreation.studio)
14. Délégué à la protection des données et contact
Les utilisateurs peuvent adresser leurs demandes, réclamations et demandes de recours relatives aux informations personnelles au délégué à la protection des données ci-dessous.
- Délégué à la protection des données : Peter Cho (Software Creation Studio)
- Téléphone : 010-2069-1670
- E-mail : governance@softwarecreation.studio
- Adresse : 100 Cheonggyecheon-ro, Jung-gu, Séoul, Signature Tower West, 9e étage
- Représentant pour l'UE / Représentant pour le Royaume-Uni : Peter Cho (governance@softwarecreation.studio)
15. Notification des modifications de la Politique de confidentialité
La présente Politique de confidentialité peut être mise à jour en réponse aux évolutions de la loi, de la technologie ou aux améliorations du service. En cas de modification, les motifs et les détails seront annoncés à l'avance sur le site web.