Privacy Policy

Crosshub Inc. establishes this Privacy Policy to protect Users’ personal information and rights in accordance with the Personal Information Protection Act of Korea (PIPA).
This Privacy Policy explains how the Company collects, uses, retains, and protects personal information.

Article 1 (Purpose of Processing Personal Information)

Crosshub Inc. (“the Company”) complies with the Personal Information Protection Act of Korea (“PIPA”) and all applicable laws and regulations in order to protect the personal information of individuals (“Users”) who use the Company’s website and related services (“Services”). The Company processes personal information lawfully and safely, and establishes and discloses this Privacy Policy (“Policy”) pursuant to Article 30 of PIPA to inform Users of the procedures and standards for the processing of personal information and to ensure prompt and smooth handling of Users’ rights.

Article 2 (Processing and Retention Period of Personal Information)

① The Company collects and uses personal information only to the minimum extent necessary to provide its Services, in accordance with relevant laws and this Policy.

② The Company does not provide collected personal information to any third party without the User’s consent, except where required by law.

③ The Company does not, in principle, collect personal information from children under the age of 14.

④ Personal information collected based on User consent is processed only within the scope of the stated purposes, and if the purpose of use changes, the Company will obtain separate consent pursuant to Article 18 of PIPA.

Article 3 (Disclosure of This Policy)

① The Company discloses this Policy on the main page of the website or through a link to ensure that Users can access it at any time.

② When disclosing the Policy, the Company uses appropriate font size, color, and formatting to ensure clarity and readability.

Article 4 (Amendments to This Policy)

① This Policy may be amended due to changes in laws, regulations, guidelines, or Company policies.

② When amendments occur, the Company will provide prior notice through one or more of the following methods.

1. Posting on the main page of the website

2. Pop-up notifications or separate modal windows

3. Individual notices via email

③ Amendments will be announced at least 7 days prior to their effective date, and if changes significantly affect Users’ rights, notice will be provided at least 30 days in advance.

Article 5 (Purpose of Processing, Items Collected, and Retention Period)

① The Company collects and uses personal information based on User consent for the purpose of handling inquiries.

② Personal information is processed and retained only for the period notified to Users and as required under PIPA.

1. Handling of Inquiries

Purpose of Collection and Use: To verify inquiries, provide responses, conduct follow-up consultations, and manage inquiry history

Items Collected: Company name, name, position, phone number, email address, and inquiry details

Legal Basis: Article 15(1)(1) of PIPA (Consent)

Retention Period: Retained for 1 year after inquiry resolution, then destroyed without delay

※ Personal information will be deleted immediately upon User request.

Article 6 (Methods of Collecting Personal Information)

The Company collects personal information through the following methods.

1. When a User enters and submits information through the inquiry form on the Company’s website

2. When a User provides personal information in response to the Company’s email guidance

3. When a User submits inquiry details during the use of Services

※ The Company does not use cookies or any automated collection tools.

※ The Company does not use cookies or any automated collection tools.

Article 7 (Provision of Personal Information to Third Parties)

① The Company does not provide Users’ personal information to third parties.

② However, personal information may be provided without User consent in the following cases:

1. When required by law

2. When requested by investigative agencies through lawful procedures

③ If third-party provision occurs, the Company will notify Users in advance of all legally required matters, including the recipient, purpose, items provided, retention period, and any disadvantages resulting from refusal, and obtain consent as required.

Article 8 (Outsourcing of Personal Information Processing)

① For efficient operation of its Services, the Company outsources the processing of personal information to external professional service providers as follows:

1. Email Transmission for Inquiry Handling

Outsourced Service Provider: EmailJS (emailjs.com, United States)

Details of Outsourced Tasks: Transmitting the content of inquiries entered by Users to the Company’s internal email system

Retention and Use Period: Until the outsourcing contract ends or the purpose of processing is achieved

※ EmailJS may temporarily process the User’s message for the purpose of email transmission. The Company regularly inspects the storage period and security level of the service provider.

② In accordance with Article 26 of PIPA, the Company includes the following items in outsourcing contracts and supervises the service providers:

・ Compliance with personal information–related laws

・ Implementation of technical and administrative safeguards

・ Restrictions on re-outsourcing

・ Liability provisions for incidents

Article 9 (Principles of Personal Information Destruction)

① The Company will destroy personal information without delay when the retention period expires, the purpose of processing is achieved, consent is withdrawn, or personal information is no longer necessary.

② If the Company is required by law to retain certain information, such information will be stored separately in a secure location or separate database.

Article 10 (Procedures for Destruction of Personal Information)

① Personal information entered by Users is transferred to a separate storage location after the processing purpose is achieved and is destroyed after the retention period expires.

② When a reason for destruction occurs, the Company destroys personal information with the approval of the Chief Privacy Officer (CPO).

Article 11 (Methods of Destroying Personal Information)

・ Electronic files: Permanently deleted using technical methods that render recovery impossible

・ Email data: Permanently deleted from the mailbox

・ Paper documents: Shredded or incinerated

Article 12 (Protection of Children’s Personal Information)

① The Company does not, in principle, collect personal information from children under the age of 14.

② If it is confirmed that a child has submitted an inquiry form, the Company will verify the consent of the legal representative and, if consent is not provided, destroy the information immediately.

Article 13 (Rights and Obligations of Data Subjects and Methods of Exercise)

① 이Users may exercise the following rights at any time with respect to the Company:

1. Request for access to personal information

2. Request for correction or deletion

3. Request for suspension of processing

4. Withdrawal of consent and objection to the collection, use, or provision of personal information

② Users may exercise their rights through written requests, email, or the Company’s inquiry page (inquiry form), and the Company will take prompt action.

③ When a User requests access, correction, deletion, or suspension of processing, the Company may verify whether the requester is the User or a legitimate representative.

④ Legal representatives may exercise the rights listed above with respect to the personal information of children under the age of 14.

⑤ Users are responsible for providing and maintaining accurate and up-to-date personal information. The User shall be liable for any issues arising from the provision of inaccurate information or unauthorized use of another person’s information.

Article 14 (Technical, Administrative, and Physical Measures for the Protection of Personal Information)

The Company implements the following measures to protect personal information:

(1) Administrative Measures

· Establishment and implementation of internal management plans

· Minimization of personnel authorized to handle personal information

· Regular security training

(2) Technical Measures

· Access control and authority management for personal information processing systems

· Operation of access control systems

· Installation of security programs

(3) Physical Measures

· Access control for data storage facilities

· Prevention of unauthorized external access

Article 15 (Measures in Case of Personal Information Breach)

If any loss, theft, or leakage of personal information is confirmed, the Company will promptly notify the affected Users and report the incident to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA). Notification will include:

1. Items of personal information breached

2. Time and circumstances of the breach

3. Measures Users can take

4. Measures taken by the Company

5. Contact information for the responsible department

Article 16 (Exceptions to Notification of Personal Information Breach)

If the User’s contact information cannot be identified or other legitimate reasons exist, the Company may substitute notification by posting a notice on the Company’s website for at least 30 days.

Article 17 (Details Regarding Overseas Transfer of Personal Information)

① In connection with inquiry handling, the Company outsources the processing of personal information to an overseas service provider as follows:

1. Overseas Outsourcing of Personal Information Processing

・ Legal Basis: Articles 26 and 28-8(1)(3) of the Personal Information Protection Act

・ Items Transferred: Company name, name, position, contact information (telephone number), email address, and inquiry details

・ Destination Country: United States

・ Timing and Method of Transfer: Upon submission of the inquiry form, transmitted to EmailJS servers through encrypted communication channels (HTTPS)

・ Recipient (Service Provider): EmailJS (emailjs.com)

・ Purpose of Transfer: To deliver the User’s inquiry contents to the relevant Company personnel

・ Retention and Use Period: Until the outsourcing contract ends or the processing purpose is achieved

② The Company supervises the overseas service provider through contractual agreements to ensure secure handling of personal information. Users may withdraw their consent to overseas transfer at any time through the methods specified in Article 13.

※ ※ This overseas transfer constitutes “overseas processing outsourcing” under Article 28-8(1)(3) of the Personal Information Protection Act, and separate consent is not required.

Article 18 (Installation and Operation of Automated Collection Tools and Refusal)

The Company does not use cookies or any similar automated data collection technologies based on User Service activity.

Article 19 (Personal Information Protection Officer)

To protect personal information and handle related inquiries, the Company designates the following Personal Information Protection Officer and department:

▶ Personal Information Protection Officer (CPO)

Name:Jinwoo Lee

Position: CISO

Contact: +82-02-780-9930

Email: contact@Crosshub.kr

▶ Personal Information Protection Department

Department: Business Management Division

Contact: +82-2-780-9930

Email: contact@Crosshub.kr

※ The above contact leads to the Personal Information Protection Department.

Users may contact the above personnel for any inquiries, complaints, or requests for remedies related to personal information protection while using the Company’s Services. The Company will respond promptly.

Article 20 (Remedies for Infringement of Rights)

Users may contact the following institutions for consultation or dispute resolution regarding personal information infringement:

1. Personal Information Dispute Mediation Committee

・ Dispute mediation, class action dispute mediation

・ Website: www.kopico.go.kr

・ Phone: 1833-6972

2. Personal Information Infringement Report Center (KISA)

・ Reporting and consultation regarding personal information infringement

・ Website: http://privacy.kisa.or.kr

・ Phone: 118 (toll-free)

3. Supreme Prosecutors’ Office Cyber Crime Division

・ Website: http://www.spo.go.kr

・ Phone: 1301

4. National Police Agency Cyber Bureau

・ Website: http://cyberbureau.police.go.kr

・ Phone: 182

Article 21 (Changes to the Privacy Policy)

① This Policy may be amended due to changes in laws or internal policies, and the Company will notify Users at least 7 days prior to the effective date through the website notice board.

② When amendments materially affect User rights, the Company will notify Users at least 30 days in advance.

③ The effective date of this Policy is as follows..