Privacy Policy
Article 1 (Purpose of processing personal information)
Algionics Inc. (the Company) processes personal information for the purposes below. Personal information will not be used for purposes other than those stated here. If the purpose changes, the Company will take measures required by applicable law, including obtaining additional consent where required.
Account creation and authentication
Supporting sign up and sign in through external identity providers
Identifying users and protecting accounts
Preventing unauthorized use and abuse
Service delivery and access management
Providing access to the Services and maintaining account status
Delivering essential operational notices and policy updates
Subscription and billing administration
Processing subscription requests through a payment processor
Handling cancellations, refunds, chargebacks, and billing related support
Customer support
Receiving inquiries and responding to requests
Verifying the requester where needed to protect user accounts
Security and service stability
Detecting security events, maintaining logs, responding to incidents, and improving reliability
Article 2 (Categories of personal information and collection methods)
Categories
Account and authentication data
Email address, external provider user identifier, and basic profile information provided by the user or the identity provider within the scope of the provider settingsSubscription and payment related data
Subscription status, transaction identifiers, billing status, and related metadata received from a payment processor
The Company does not store full payment card numbers on its systems. Payment credentials are handled by the payment processor.Support and communications data
Inquiry content, contact details provided by the user, and support historyService usage and device data
Access time, IP address, device and browser information, cookies or similar identifiers, usage logs, and security related logs
Collection methods
Information is collected through account and service use, user submitted forms or messages, customer support communications, and integrations with identity providers and payment processors. Some usage data is collected automatically when you access the Services.
Article 3 (Legal basis for processing)
The Company processes personal information based on one or more of the following legal bases, as applicable.
Consent from the data subject
Necessity for entering into or performing a contract with the data subject
Compliance with legal obligations
Legitimate interests
The Company may process data for legitimate interests such as security, fraud prevention, and stable service operations, only where such interests are not overridden by the rights of the data subject, and with appropriate safeguards.
Article 4 (Retention)
The Company retains personal information only for as long as necessary to achieve the purposes in Article 1 and deletes it without undue delay once the purpose is achieved, unless retention is required by applicable law.
Retention required by applicable laws The Company retains certain records for the statutory periods below where applicable.
Under the Act on Consumer Protection in Electronic Commerce
Records concerning display and advertisement: 6 months
Records concerning contracts or withdrawal of offers: 5 years
Records concerning payment settlement and supply of goods or services: 5 years
Records concerning consumer complaints or dispute resolution: 3 years
Under the Communications Secrets Protection Act
Service usage records such as access logs and IP related records: 3 months
Under the Electronic Financial Transactions Act
Records concerning electronic financial transactions: 5 years
Retention based on internal necessity The Company may retain limited logs and support records for a reasonable period to prevent abuse, ensure security, and resolve disputes, consistent with applicable law.
Destruction Procedures and Methods
Destruction Procedure: Once the purpose is achieved or the retention period expires, the information is selected for destruction and deleted under the supervision of the Personal Information Protection Officer.
Destruction Method: Personal information stored in electronic file format is permanently deleted using technical methods that prevent recovery.
Article 5 (Disclosure to third parties)
The Company does not disclose personal information to third parties in principle. This does not include processing by service providers acting on the Company’s behalf as described in Article 6.
The Company may disclose personal information only in the following cases.
Where the data subject has provided separate consent
Where disclosure is required or permitted by applicable law
Where a lawful request is made through valid legal process
Article 6 (Processing by service providers)
To provide the Services, the Company may use third-party service providers to process personal information on its behalf.
Website hosting and content delivery infrastructure
Identity and access management services
Authentication and data infrastructure
Email communication services
Payment processing services
Article 7 (International transfers)
Depending on where our service providers operate, personal information may be transferred to and processed in countries other than your country of residence. The Company will implement appropriate safeguards as required by applicable law. Relevant infrastructure locations include the following.
Website Hosting and Content Delivery: Netherlands
Authentication and Identity Management: United States
Global Communications and Support Systems: United States
Payment and Billing Infrastructure: United States
Article 8 (Your rights and choices)
You may have rights under applicable law, which may include the right to access, correct, delete, or restrict the processing of your personal information, and to withdraw consent where processing is based on consent. To exercise your rights, contact the Company using the contact details in Article 12. Some rights may be limited under applicable law.
Article 9 (Security measures)
The Company implements reasonable administrative, technical, and physical measures designed to protect personal information.
Administrative: Establishment and implementation of internal management plans and regular employee training.
Technical: Management of access rights to personal information processing systems, encryption of sensitive data, and installation of security programs.
Physical: Access control for computer rooms and data storage rooms where personal information is processed or stored.
Article 10 (Cookies)
The Company may use cookies and similar technologies for essential functions such as maintaining login sessions, security, and preserving necessary user flows. For details, see the Company’s Cookies Policy.
Article 11 (Children)
The Services are not intended for children under the age of 14. If the Company becomes aware that personal information of a child under 14 has been collected, the Company will take steps to delete it or obtain legally required consent.
Article 12 (Privacy Contact Information)
Algionics Inc. designates the following individual as its Data Protection Officer (DPO) / Data Protection Contact to act as the primary contact point for matters related to personal information processing, including inquiries, complaints, and data subject requests, in accordance with applicable data protection laws such as the GDPR, U.S. privacy regulations, and the Korean Personal Information Protection Act.
Data Protection Contact
Name: Hyejin Lee
Title: Director of Operations
Role: Oversight and coordination of personal information protection matters
Contact: +82 70 8098 2360
Email: alg@algionics.com
Privacy Department
Department Name: Operations Team
Role: Handling privacy related inquiries and complaints
Contact: +82 70 8098 2360
Email: alg@algionics.com
Users may contact the Data Protection Contact or the Privacy Department for any privacy related inquiries, complaints, or requests while using the Services.
Article 13 (Complaints and remedies)
Data Subjects may apply for dispute resolution or consultation to the following external organizations for relief from personal information infringement:
Personal Information Infringement Reporting Center (operated by KISA)
Purpose: Reporting personal information infringement, consultation application
Website: https://privacy.kisa.or.kr
Phone: +82 118
Address: (58324) 9 Jinheung-gil, Naju-si, Jeollanam-do, KISA
Personal Information Dispute Mediation Committee
Purpose: Dispute mediation application, collective dispute mediation (civil resolution)
Website: https://kopico.go.kr
Phone: +82 1833-6972
Address: (03171) 12F Government Seoul Complex, 209 Sejong-daero, Jongno-gu, Seoul
Supreme Prosecutors' Office Cyber Crime Investigation Division
Website: https://spo.go.kr
Phone: +82 1301
National Police Agency Cyber Bureau
Website: https://ecrm.police.go.kr
Phone: +82 182
Article 14 (Changes to this policy)
The Company may update this Privacy Policy from time to time to reflect changes in the Services, legal requirements, or security practices. Material changes will be posted on the website.