Cookie Policy
Effective date: July 3, 2026
This translation is provided for convenience only. If there is any discrepancy between this translation and the Korean original, the Korean original prevails.
Software Creation Studio (hereinafter the "Company") uses cookies and similar tracking technologies when operating its websites and services (including PolyBot, PolyGlot, and other digital services) in order to provide a stable, secure experience, deliver personalised interactions, and continuously improve service quality. This Cookie Policy forms part of the Company's Privacy Policy.
1. Applicable Law
Because this service is directed at users in the Republic of Korea as well as the European Economic Area (EEA) and the United Kingdom, this Cookie Policy is governed by the Korean Personal Information Protection Act, Article 22-2 of the Act on Promotion of Information and Communications Network Utilisation and Information Protection, the EU General Data Protection Regulation (GDPR), Article 5(3) of the EU ePrivacy Directive (Directive 2002/58/EC), the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
2. What Are Cookies?
A cookie is a small text file that a website stores in your browser when you visit it. Cookies do not directly identify you, but may contain or reference the following.
- Login status and session information
- Language and UI settings
- Visit time and page navigation path
- Device and browser information
- Advertising and analytics identifiers
3. Purposes for Using Cookies and Legal Basis for Processing
The Company categorises and uses cookies for the following purposes, together with the legal basis for processing each category (Article 6 of the GDPR/UK GDPR).
3.1 Strictly Necessary Cookies
These cookies are essential for the website to function properly. As they are indispensable to service delivery, they are used without prior consent. Legal basis: a necessary measure for providing an information society service (exemption under PECR Reg 6(4)); performance of a contract and legitimate interests (GDPR/UK GDPR Art. 6(1)(b), (f)).
- Maintaining login status and processing user authentication
- Session management and user request persistence
- Defence against CSRF, session hijacking, and other security attacks
- Server stability and load balancing
3.2 Functional Cookies
These cookies remember your settings to deliver a more personalised experience. As they do not qualify as strictly necessary cookies, they are activated only after obtaining your prior opt-in consent, in accordance with PECR Regulation 6 and Article 5(3) of the EU ePrivacy Directive. Legal basis: consent (GDPR/UK GDPR Art. 6(1)(a)).
- Maintaining language settings
- Remembering UI theme and preference settings
- Minimising repeated data entry
3.3 Analytics Cookies
These cookies analyse your visit patterns to help us improve service quality. Google Analytics 4 (GA4) may be used and is activated only with your explicit consent. Legal basis: consent (GDPR/UK GDPR Art. 6(1)(a)).
- Visitor count and traffic pattern analysis
- Page navigation flow and user behaviour paths
- Feature usage frequency and service improvement insights
3.4 Marketing Cookies
These cookies are used for interest-based advertising and performance analysis. Meta Pixel, Google Ads, and similar tools may be used and require your explicit opt-in consent. Legal basis: consent (GDPR/UK GDPR Art. 6(1)(a)).
- Interest-based advertising
- Ad click and conversion rate analysis
- Retargeting campaigns
3.5 Security Cookies
These cookies are used to detect abnormal access and protect the service. Security infrastructure providers such as Cloudflare may use them. Legal basis: legitimate interests (GDPR/UK GDPR Art. 6(1)(f)).
- Detecting and blocking bot traffic
- DDoS attack defence
- Detecting abnormal login attempts
4. Google Consent Mode v2
The Company applies Google Consent Mode v2 to automatically adjust the scope of data collection based on your consent status.
- ad_storage: whether advertising data may be stored
- analytics_storage: whether analytics data may be stored
- functionality_storage: whether functional data may be stored
- security_storage: whether security data may be stored
5. IAB TCF 2.2
The Company complies with the IAB Transparency & Consent Framework 2.2 to ensure transparency in digital advertising.
- Storing user consent status as a standardised Consent String
- Separating data processing purposes by advertising purpose
- Managing and restricting advertising vendors
6. Cookie Consent Log
The Company securely stores all cookie consent and refusal records for audit and regulatory compliance purposes.
- Cookie consent status (accept all / partial consent / refusal)
- Timestamp of consent or refusal
- Browser and device information
- IP address (anonymised where possible)
- Selected cookie category information
7. Third-Party Cookies
The following third parties' cookies may be used to provide the service.
- Google - Analytics, Ads (policies.google.com/privacy)
- Meta - Facebook / Instagram advertising (facebook.com/privacy/policy/)
- AWS - Cloud infrastructure operations (aws.amazon.com/privacy/)
- Cloudflare - Security and CDN (cloudflare.com/privacypolicy/)
8. International Transfers of Personal Information
The Company may transfer personal information overseas as follows for service operations, applying appropriate safeguards required under each jurisdiction.
- Amazon Web Services, Inc. (USA) - Cloud infrastructure (until service termination). EU users: European Commission Standard Contractual Clauses (SCC) apply / UK users: the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs applies
- Google LLC (USA) - Analytics & advertising (up to 24 months). The same transfer mechanism (EU SCC / UK IDTA or UK Addendum) applies as above
- Meta Platforms, Inc. (USA) - Ad targeting (up to 3 months). The same transfer mechanism (EU SCC / UK IDTA or UK Addendum) applies as above
- Cloudflare, Inc. (USA) - Security and CDN (processes IP addresses and other data for bot traffic detection and DDoS defence, up to 12 months). The same transfer mechanism (EU SCC / UK IDTA or UK Addendum) applies as above
- A copy of the transfer agreement is available upon request from data subjects through the contact details listed in Section 16.
9. Cookie Retention Periods
- Session cookies - Deleted automatically when the browser is closed
- Strictly necessary cookies - Up to 12 months
- Functional cookies - Up to 12 months
- Analytics cookies - Up to 24 months
- Marketing cookies - Up to 3 months
- Security cookies - Up to 12 months
10. Managing Cookies
- Website settings: You can change or withdraw your consent at any time via the "Cookie Settings" link at the bottom of the website. The initial consent banner presents "Accept All" and "Reject All" buttons in the same size, colour, and step, so that users incur no additional clicks or disadvantage when choosing to refuse (per ICO cookie guidance).
- Browser settings: Most browsers (Chrome, Safari, Edge, Firefox, etc.) let you block, delete, or restrict cookies.
- Effects of refusing: Login persistence may be restricted, personalised settings cannot be saved, and some service features may be limited.
11. Data Subject Rights
You may request access to, correction of, deletion of, or restriction of processing of your personal information collected via cookies. Please direct such requests to the Data Protection Officer listed in Section 16.
You also have the right to lodge a complaint directly with the following supervisory authorities.
- Republic of Korea: Personal Information Protection Commission (privacy.go.kr / 182, toll-free)
- European Economic Area (EEA): The competent supervisory authority (Data Protection Authority) of your member state of residence
- United Kingdom: Information Commissioner's Office (ICO) (ico.org.uk)
12. Data Security
- TLS 1.2 or higher encrypted communications
- AES-256 encrypted data storage
- Zero Trust-based access control
- Real-time security log monitoring
13. Protection of Minors
Republic of Korea: Our services are not directed at children under the age of 14. If we become aware that a child under 14's information has been collected without consent, we will take immediate steps to delete it.
European Economic Area (EEA): Under Article 8 of the GDPR, consent for processing a child's personal information may generally be given directly by the child from age 16, and where the child is under 16, consent must be obtained from a parent or legal guardian. Where a user's member state of residence sets a lower age by law (a minimum of 13), that threshold applies.
United Kingdom: In accordance with the UK Information Commissioner's Office (ICO) Age Appropriate Design Code, where a user is presumed to be under 18, marketing and analytics cookies used for profiling are disabled by default, and privacy settings are applied at the highest protection level (high-privacy default).
14. EU and UK Representatives
The Company is located in the Republic of Korea and does not have an establishment in the European Economic Area (EEA) or the United Kingdom. In accordance with Article 27 of the GDPR and Article 27 of the UK GDPR (Schedule 21 to the UK DPA 2018), the Company has appointed the following representatives.
- EU Representative: Peter Cho (email: governance@softwarecreation.studio)
- UK Representative: Peter Cho (email: governance@softwarecreation.studio)
15. Policy Changes
This Cookie Policy may be updated in response to changes in law, technology, or service improvements. Material changes will be announced on the website in advance.
16. Contact
Software Creation Studio
Email: governance@softwarecreation.studio
Address: 100 Cheonggyecheon-ro, Jung-gu, Seoul, Signature Tower West, 9F
Data Protection Officer: Peter Cho (Phone: 010-2069-1670 / Email: governance@softwarecreation.studio)
EU Representative: Peter Cho (governance@softwarecreation.studio)
UK Representative: Peter Cho (governance@softwarecreation.studio)