Privacy policy
Effective April 21, 2024
Splab Inc. Privacy Policy
Last updated: 2024-04-22
Splab Co., Ltd. (the "Company") values the information of users who use Sendtime and Umoh services (the "Service") and complies with applicable personal information protection laws, including the Act on Promotion of Information and Communications Network Utilization and Information Protection and the Personal Information Protection Act.
The Company establishes and complies with this Privacy Policy. This policy may change due to amendments to applicable laws or policy changes in our Service. Please review this policy periodically when visiting our Service.
1. Purpose of Processing Personal Information
During sign-up, users can click checkboxes to consent to terms, collection/use of personal information, and third-party provision. By clicking, users are deemed to have consented.
The Company processes personal information for the following purposes and does not use it for other purposes:
- confirming intent to join, user identification/authentication, maintaining/managing membership, service use and support, delivering notices, processing payments, and supplying/improving services.
The Company provides means to cancel/withdraw previously given consent to collection and use. If consent is withdrawn, use of the Service may be restricted.
2. Processing and Retention Period
Personal information is processed and retained within the period agreed by users at collection or as required by law. Information is destroyed without delay when the purpose is achieved (e.g., account withdrawal) or upon consent withdrawal, unless retention is required by applicable laws.
Retention by law may include:
-
Under Article 6 of the Act on the Consumer Protection in Electronic Commerce:
- records on contracts/cancellation: 5 years
- records on payment and supply of goods/services: 5 years
- records on consumer complaints/dispute resolution: 3 years
-
Under Article 15 of the Protection of Communications Secrets Act: records of access logs: 1 year.
Destruction method:
- electronic files are deleted using technical methods that prevent restoration;
- printed records are shredded or incinerated.
Dormant members (no service use for 12 months) may lose membership after notice under applicable law. Dormant-member information is separately stored and managed and destroyed after legal retention periods. If requested by the user before destruction, information may be restored when service use resumes.
3. Items of Personal Information Processed
(1) The Company processes personal information as follows:
| Category | Type | Items Collected/Used | Purpose | Retention |
|---|---|---|---|---|
| User information | User identification (sign-up) | Name, affiliation (company name), job title, mobile phone number, age, email, self-introduction, photo, SNS information, Google Calendar schedule information, messaging/meeting request history and details when using Sendtime, and related service usage records. | User identification/authentication, fraud detection and prevention, service provision/operation, notices and support, complaint handling. | Up to 5 years from consent; immediate deletion on account withdrawal; fraud-prevention records (ID/bad-use records) deleted 6 months after withdrawal; complaint/dispute records retained 3 years under consumer protection law. |
| Order/payment | Depending on payment method: card issuer/partial card number (credit card), bank name/depositor name (bank transfer), mobile number (cash receipt), and e-tax invoice email/business registration number/business registration certificate copy (tax invoice issuance). | Payment/refund processing, notice of contract and order details, fraud detection and prevention. | Immediate deletion on account withdrawal; CI/DI for fraud prevention deleted 6 months after withdrawal; payment, cancellation, refund, and delivery records retained 5 years as required by law. | |
| Refund | Account holder name, bank name, account number | |||
| Service usage records | Device information (OS, screen size, device ID, phone model), IP address, cookies, visit date/time, abuse records, service usage records, and location information. | Quality management through usage statistics, legal compliance for consumer protection, fraud prevention, dispute coordination, and confirmation of shipping information for prize delivery. | Immediate deletion on account withdrawal; service usage records retained 3 months (communications secrecy law); safe-number voice records retained 1 month. |
(2) Collection methods
- users directly enter information after checking "agree" to collection/use/third-party provision;
- users consent when accessing through third-party platforms (e.g., Facebook, Kakao, Google) for Service use;
- inquiries through customer center (site, phone, email, fax, written forms);
- participation in online/offline Company or partner events.
4. Third-Party Provision of Personal Information
The Company does not use or provide users' personal information beyond the scope disclosed in Section 1, except where permitted by law (e.g., user consent, specific legal provisions under Articles 17 and 18 of the Personal Information Protection Act).
Exceptions may include:
- requests from competent authorities for investigative purposes;
- provision in a non-identifiable form for statistics, academic research, or market research;
- other requests under applicable law.
Current third-party provision status: None
5. Entrustment of Personal Information Processing
To provide better services, the Company may entrust processing of personal information to external specialized entities.
When entrusting processing, the Company discloses entrusted tasks and processors in a manner easily accessible to data subjects and, where required by law, provides notice via written/electronic means. Changes are disclosed in the same manner.
The Company enters into contracts with processors that include required safeguards (purpose/scope, prohibition of use beyond purpose, re-entrustment limits, technical/administrative measures, access control, supervision, and liability for violations).
[Current entrusted processors]
| Processor | Items Provided | Purpose | Retention/Use Period |
|---|---|---|---|
| AWS (Amazon Web Services) | Customer activity information during service use | Infrastructure management for service provision/analysis | Until withdrawal, service termination, or contract end |
| Google Analytics | Customer activity information during service use | Usability and usage analysis support | Until withdrawal, service termination, or contract end |
| Biztalk Co., Ltd. | Name, contact information | Sending AlimTalk notification messages | Until withdrawal, service termination, or contract end |
6. Rights of Data Subjects and Legal Representatives
Users, as data subjects, may exercise rights such as access, correction, deletion, and suspension of processing.
For access/correction requests, please contact customer support by written request, phone, or email. We will act without delay. Consent to collection/use/provision can be withdrawn at any time, and if personal information is destroyed accordingly, users will be notified without delay.
7. Automatic Collection Device (Cookies): Installation, Operation, and Refusal
The Company uses cookies to store and retrieve usage information in order to provide personalized services.
Cookie purpose: to analyze visit/use patterns, popular search terms, and secure-access status across services/websites for optimized information delivery.
Users may refuse cookie storage via browser settings (Tools > Internet Options > Privacy). Refusing cookies may limit access to personalized services.
8. Measures to Ensure Security of Personal Information
In accordance with Article 29 of the Personal Information Protection Act, the Company applies technical and administrative safeguards.
Technical measures
- Access rights are managed to control unauthorized external access, and critical data is securely stored/managed through encryption.
- Security programs are periodically updated and inspected to prevent leakage/damage by hacking or malware.
- Security devices are adopted for safe transmission of personal information over networks, including during payment processing.
- Intrusion prevention systems (firewalls) and other technical controls are used to block unauthorized access.
Administrative measures
- When handling personal information (e.g., password-related requests), the Company makes best efforts to verify identity and process information safely.
- Access rights are restricted to personnel with unavoidable job needs, including the privacy officer, and internal training is provided regularly.
Users must also protect their own credentials and personal information from exposure or leakage. The Company is not liable for leakage caused by user negligence.
9. User Responsibilities
Users should provide accurate and up-to-date information. Users are responsible for incidents caused by inaccurate information, and entering false information (including misuse of third-party data) may result in suspension or loss of membership.
Responsibility for maintaining the confidentiality of account ID and password lies with each user. Please be careful not to disclose passwords to others.
Users have both rights and obligations regarding personal data protection and must not infringe others' information.
10. Policy for Children Under 14
The Company does not accept membership registrations from children under 14 years of age who require legal guardian consent.
11. Privacy Contact
The Company designates a privacy officer to protect user personal information and handle related complaints:
- Name: Minseung Seon
- Phone: 1644-4138
- Email: ceo@splab.dev
For privacy infringement reports/consultation, users may contact relevant external agencies:
- KISA Privacy Protection: http://privacy.kisa.or.kr / 118
- Korean National Police Agency Cyber Bureau: http://cyberbureau.police.go.kr / 182
- Supreme Prosecutors' Office Cyber Investigation Division: http://spo.go.kr / 02-3480-3570
- Privacy Infringement Report Center (KISA): http://privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: http://www.kopico.go.kr / 1833-6972
12. Changes to this Privacy Policy
- This policy applies from its effective date. If there are additions, deletions, or corrections due to legal/policy changes, we will notify users at least 7 days before implementation. For material changes affecting user rights (e.g., items collected or purposes), we will provide at least 30 days' prior notice.
The notice and effective dates are as follows:
- Announcement date: 2024-03-19
- Effective date: 2024-04-22
- If a user objects to this revision, the user may request account withdrawal within one month from receipt of this notice. If no separate expression of intent is made during that period, the user is deemed to have agreed to the revision.
Revision History
Privacy Policy (2022.06.01)
https://splab-inc.notion.site/2022-06-01-4a389fcfd697482ea4f216d450131bb3?pvs=4