Legal

Privacy Policy

Effective date: July 3, 2026

This translation is provided for convenience only. If there is any discrepancy between this translation and the Korean original, the Korean original prevails.

Software Creation Studio (hereinafter the "Company") complies with the Personal Information Protection Act and related laws and, in order to protect users' personal information, establishes and discloses the following Privacy Policy. This Privacy Policy applies to all online services provided by the Company (including PolyBot, PolyGlot, and other digital services).

1. Applicable Law

Because this service is directed at users in the Republic of Korea as well as the European Economic Area (EEA) and the United Kingdom, this Privacy Policy is governed by the Korean Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilisation and Information Protection, together with the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018. Details regarding cookies and similar tracking technologies are set out in a separate Cookie Policy, which forms part of this Privacy Policy.

2. Personal Information Collected and Methods of Collection

The Company may collect the following personal information.

  • [Required Information] Company name, name, mobile phone number, email, password
  • [Required Information] When submitting a project inquiry: project type, project description, and other information entered directly by the user
  • [Automatically Collected Information] IP address, device information (browser, OS), cookies, date and time of visit, usage logs, access records
  • [Optional Information] Name, contact details, and other entered information provided when participating in surveys or events
  • [Optional Information] Email and SMS subscription details provided when consenting to receive marketing information

2-1. Methods of Collecting Personal Information

  • During website sign-up and use of the services
  • Through customer support inquiries (phone, email, inquiry form)
  • Automatic collection via cookies and log analysis tools

3. Purposes of Collecting and Using Personal Information, and Legal Basis for Processing

The Company processes personal information for the purposes below, and for EEA and UK users also specifies the legal basis under Article 6 of the GDPR/UK GDPR.

  • Service provision: receiving and responding to inquiries, and conducting consultations (Basis: performance of a contract - GDPR Art. 6(1)(b))
  • Member management: identity verification, delivery of notices, and record management (Basis: performance of a contract and legitimate interests - Art. 6(1)(b), (f))
  • Service improvement: statistics and analysis, and quality improvement (Basis: legitimate interests or consent - Art. 6(1)(f) or (a))
  • Marketing use (with consent): provision of events, advertising, and benefits (Basis: consent - Art. 6(1)(a))
  • Legal compliance: dispute resolution and fulfillment of legal obligations (Basis: compliance with a legal obligation - Art. 6(1)(c))

4. Retention and Use Period of Personal Information

The Company retains personal information until the purpose of collection is achieved and deletes it without delay once that purpose has been achieved. However, the Company may retain it for the periods set out below in accordance with applicable laws.

  • Service usage records: 3 years
  • Contract and payment records: 5 years
  • Consumer dispute records: 3 years
  • Access log records: 3 months
  • Upon withdrawal of membership: destroyed without delay, except that information subject to a statutory retention obligation is stored separately from other personal information for the required period before destruction

5. Provision of Personal Information to Third Parties

As a rule, the Company does not provide personal information to external parties. However, it may be provided in the following cases.

  • Where the user has given prior consent
  • Where requested in accordance with applicable laws
  • Where there is a request from an investigative authority through lawful procedure

6. Outsourcing of Personal Information Processing

To ensure the smooth provision of services, the Company outsources personal information processing tasks as described below, and exercises management and supervision to ensure secure processing when doing so.

  • Amazon Web Services, Inc. - Cloud infrastructure operations and data storage
  • Google LLC - Service usage analytics (Google Analytics 4) and advertising
  • Meta Platforms, Inc. - Advertising and performance measurement
  • Cloudflare, Inc. - Security and CDN (content delivery)
  • Where additional outsourcing arises, such as SMS delivery agencies or payment gateway (PG) providers, the details will be announced in advance through this Policy or the website.

7. International Transfers of Personal Information

The Company transfers personal information overseas as follows for service operations, applying appropriate safeguards in accordance with Article 28-8 of the Personal Information Protection Act and Chapter V of the GDPR/UK GDPR. Users may refuse international transfers, and refusal may restrict the use of some services.

  • Recipient: Amazon Web Services, Inc. / Destination country: USA / Items transferred: personal information generated in the course of using the service / Purpose: cloud infrastructure operations / Retention period: until service termination
  • Recipient: Google LLC / Destination country: USA / Items transferred: cookies, usage logs, device identifiers / Purpose: analytics and advertising / Retention period: up to 24 months
  • Recipient: Meta Platforms, Inc. / Destination country: USA / Items transferred: cookies, advertising identifiers / Purpose: ad targeting / Retention period: up to 3 months
  • Recipient: Cloudflare, Inc. / Destination country: USA / Items transferred: IP address, access information / Purpose: security and CDN / Retention period: up to 12 months
  • For international transfers of personal information belonging to EEA and UK users, the European Commission Standard Contractual Clauses (SCC) or the UK International Data Transfer Agreement (IDTA) / UK Addendum to the EU SCCs is applied as the transfer basis. A copy of the relevant agreement may be requested and reviewed through the contact details in Section 14.

8. Rights of Users and Legal Representatives

Users may request the following at any time.

  • Access to personal information
  • Correction and deletion
  • Request to suspend processing
  • Withdrawal of consent
  • Request to withdraw membership and delete the account
  • (EEA and UK users) The right to data portability and rights related to automated decision-making

8-1. Right to Lodge a Complaint with Supervisory Authorities

Users also have the right to lodge a complaint or request dispute resolution directly with the following supervisory authorities.

  • Republic of Korea: Personal Information Protection Commission (privacy.go.kr / 182, toll-free), Privacy Infringement Report Center (privacy.kisa.or.kr / 118, toll-free), Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • European Economic Area (EEA): The competent supervisory authority (Data Protection Authority) of your member state of residence
  • United Kingdom: Information Commissioner's Office (ICO) (ico.org.uk)

9. Procedures and Methods for Destroying Personal Information

Personal information is destroyed without delay once the retention period has elapsed or the purpose of processing has been achieved.

  • Electronic files: permanently deleted using technical methods that make recovery impossible
  • Paper documents: shredded or incinerated

10. Use of Cookies and How to Refuse Them

The Company uses cookies and similar tracking technologies to provide customised services. Functional, analytics, and marketing cookies other than strictly necessary cookies are activated only after obtaining the user's prior opt-in consent, and consent may be changed or withdrawn at any time via "Cookie Settings" at the bottom of the website. Details on the types, purposes, retention periods, and third-party and international transfers of cookies are set out in a separate Cookie Policy.

How to refuse cookies: browser settings → privacy → block cookies. If you refuse cookies, the use of some services may be restricted.

11. Measures to Ensure the Security of Personal Information

The Company implements the following measures to protect personal information.

  • Administrative measures: establishing and implementing an internal management plan, regular employee training, and access privilege management
  • Technical measures: encryption of data in transit (TLS 1.2 or higher), encryption of stored data (AES-256), firewalls and security programs, and Zero Trust-based access control
  • Physical measures: access control to server rooms and data storage areas

12. Protection of Minors' Personal Information

  • Republic of Korea: Our services are not directed at children under the age of 14. If we become aware that a child under 14's personal information has been collected without consent, we will take immediate steps to delete it.
  • European Economic Area (EEA): Under Article 8 of the GDPR, consent for processing a child's personal information may generally be given directly by the child from age 16, and where the child is under 16, consent must be obtained from a parent or legal guardian. Where a member state sets a lower age by law (a minimum of 13), that threshold applies.
  • United Kingdom: In accordance with the UK Information Commissioner's Office (ICO) Age Appropriate Design Code, where a user is presumed to be under 18, marketing and analytics cookies used for profiling are disabled by default, and privacy settings are applied at the highest protection level.

13. EU and UK Representatives

The Company is located in the Republic of Korea and does not have an establishment in the European Economic Area (EEA) or the United Kingdom. In accordance with Article 27 of the GDPR and Article 27 of the UK GDPR (Schedule 21 to the UK DPA 2018), the Company has appointed the following representatives.

  • EU Representative: Peter Cho (email: governance@softwarecreation.studio)
  • UK Representative: Peter Cho (email: governance@softwarecreation.studio)

14. Data Protection Officer and Contact

Users may direct inquiries, complaints, and requests for remedy relating to personal information to the Data Protection Officer below.

  • Data Protection Officer: Peter Cho (Software Creation Studio)
  • Phone: 010-2069-1670
  • Email: governance@softwarecreation.studio
  • Address: 100 Cheonggyecheon-ro, Jung-gu, Seoul, Signature Tower West, 9F
  • EU Representative / UK Representative: Peter Cho (governance@softwarecreation.studio)

15. Notification of Changes to the Privacy Policy

This Privacy Policy may be updated in response to changes in law, technology, or service improvements. In the event of changes, the reasons and details will be announced on the website in advance.