Privacy Policy

Privacy Policy

IOTRUST Co., Ltd. (the "Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of Korea, to protect the personal information of data subjects and to handle related grievances promptly. This Policy applies to the DCENT Enterprise introduction website operated by the Company (the "Site").

This English version is provided for reference only. In the event of any discrepancy, the Korean version prevails.

Article 1Personal Information Processed and Collection Methods

The Company processes the following personal information through the Site.

1. Product inquiries — entered directly by the data subject

TypeItemsCollection method
RequiredCompany name, contact person's name, email address, messageEntered directly in the Site's contact form
IncidentalInformation the data subject voluntarily includes in the message (phone number, job title, etc.)Same as above

Submitted content passes through the Company's server and is delivered to the Company's staff email; it is not separately stored on the server. Received emails are kept in the Company's business email system.

2. Automatically collected when visiting the Site

ItemsCollection methodPurpose
IP address, access time, request details, browser information (User-Agent)Generated automatically as web server access logsService stability, prevention of misuse, fulfillment of log-retention obligations
Cookie identifiers, pages visited and dwell time, referral path, device/browser/OS information, approximate access regionCollected automatically via Google Analytics 4Website usage statistics

Information collected by Google Analytics is not gathered for the purpose of directly identifying specific individuals; however, where it can identify a data subject in combination with cookie identifiers, it constitutes personal information under the Personal Information Protection Act. See Article 9 for how to refuse collection.

The Company does not collect resident registration numbers or sensitive information on the Site. The Site is not directed at children under 14, and no such information is collected.

Article 2Purposes and Legal Bases of Processing

CategoryPurposeLegal basis
Inquiry informationReceiving and responding to DCENT Enterprise inquiries, sharing related materials, managing consultation historyArticle 15(1)1 of the Personal Information Protection Act — consent of the data subject
Cross-border transfer of inquiry informationTransmission, receipt, and storage via the business email systemArticle 28-8(1)3 of the Act — outsourced processing/storage necessary for contract performance, disclosed in this Policy
Web server access logsStable service operation, prevention of misuse, fulfillment of log-retention obligationsArticle 15(1)6 of the Act and Article 15-2 of the Protection of Communications Secrets Act
Website analyticsUsage statistics and content improvementArticle 15(1)1 of the Act (cookie consent) and Article 28-8(1)3 (disclosure in this Policy)

The Company does not use personal information for purposes other than those above, and does not use collected email addresses for marketing such as newsletters or event announcements. Separate consent will be obtained if marketing use becomes necessary.

Article 3Processing and Retention Period

CategoryStorage locationRetention periodStarting point
Inquiry informationBusiness email system (not stored on server)1 yearEnd of the final consultation
Web server access logsCompany-operated server3 months
Retention period under the Protection of Communications Secrets Act
Date of log creation
Website analyticsGoogle Analytics14 months
GA4 data-retention setting
Date of collection

Personal information is destroyed without delay once the retention period expires or the processing purpose is achieved. It is destroyed immediately upon the data subject's deletion request.

Article 4Provision to Third Parties

The Company does not provide personal information collected on the Site to third parties. Exceptions are limited to cases under Articles 17 and 18 of the Personal Information Protection Act (separate consent of the data subject, statutory obligations, lawful requests by investigative agencies, etc.), in which case the procedures prescribed by law are followed.

Article 5Outsourcing of Personal Information Processing

The Company outsources the following processing tasks for smooth business operations.

ProcessorOutsourced taskItemsRetention
Google LLCOperation of the business email system (Google Workspace) — transmission, receipt, and storage of inquiry emailsCompany name, contact person's name, email address, messageUntil the outsourcing contract ends or the retention period in Article 3 expires
Google LLCWebsite usage analytics (Google Analytics)Cookie identifiers, visit records, device/browser information, access regionUntil the outsourcing contract ends or the retention period in Article 3 expires

The Site is served from servers in Korea operated directly by the Company; web hosting and inquiry-processing server operations are not outsourced.

When concluding outsourcing contracts, the Company specifies in writing, pursuant to Article 26 of the Act, prohibitions on processing beyond the outsourced purpose, technical and managerial safeguards, restrictions on sub-outsourcing, supervision of the processor, and liability for damages.

Any change to the outsourced tasks or processors will be disclosed through this Privacy Policy without delay.

Article 6Cross-Border Transfer of Personal Information

The Company transfers personal information abroad as follows.

1. Transmission, receipt, and storage of inquiry emails (Google Workspace)

RecipientGoogle LLC
Contact1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Destination countryUnited States
Time and methodTransmitted over telecommunications networks (Gmail API) when the data subject submits an inquiry
Items transferredCompany name, contact person's name, email address, message
PurposeProvision of email transmission/receipt services and data storage
RetentionUntil the outsourcing contract ends or the retention period in Article 3 expires

2. Website usage analytics (Google Analytics)

RecipientGoogle LLC
ContactSame as above
Destination countryUnited States
Time and methodTransmitted in real time over telecommunications networks when visiting the Site
Items transferredCookie identifiers, visit records, device/browser information, access region
PurposeProvision of website analytics services
RetentionUntil the retention period in Article 3 expires

3. How to refuse the transfer, and its effect

  • Inquiry-related transfer — If you contact us by phone (+82-2-1833-4022) instead of using the Site's contact form, no cross-border transfer of that information occurs. Recording and responding to your inquiry may be somewhat delayed in this case.
  • Analytics-related transfer — If you refuse cookies as described in Article 9, no cross-border transfer of that information occurs. Refusal does not restrict your use of the Site.

Web server access logs are kept on servers in Korea operated directly by the Company and are not transferred abroad.

Article 7Destruction Procedures and Methods

Procedure

Personal information whose retention period has expired or whose processing purpose has been achieved is classified for destruction without delay and destroyed with the approval of the Chief Privacy Officer. Where preservation is required by other statutes, it is stored separately for the required period.

Methods

  • Electronic files — Permanently deleted so the records cannot be restored; storage media are physically destroyed or degaussed upon disposal.
  • Information held in the email system — Permanently deleted from mailboxes and trash.
  • Paper documents — Shredded or incinerated.

Article 8Rights of Data Subjects and Legal Representatives, and How to Exercise Them

Data subjects may exercise the following rights against the Company at any time.

  1. Request to access personal information
  2. Request to correct errors
  3. Request to delete
  4. Request to suspend processing
  5. Withdraw consent for processing based on consent

Rights may be exercised in writing or by email to the Chief Privacy Officer or the department handling access requests under Article 11; the Company will act without delay (within 10 days of the request).

When a data subject requests correction or deletion of errors, the Company will not use or provide the relevant personal information until the correction or deletion is completed.

Rights may also be exercised through an agent, such as a legal representative or an authorized person; in this case, a power of attorney in the form prescribed by the Public Notice on Personal Information Processing Methods (Annex Form No. 11) must be submitted.

Article 9Installation, Operation, and Refusal of Automatic Collection Devices

The Company uses cookies to analyze how the Site is used.

PurposeUsage statistics (visitors, pages, referral paths) and content improvement
Cookies usedGoogle Analytics 4 cookies (_ga, _ga_<measurement ID>, etc.)
RetentionUp to 2 years (Google Analytics default)

The Company does not use targeted-advertising cookies for ad or marketing purposes.

How to refuse

  1. Browser settings — You can allow or block cookies directly in your web browser settings.
    • Chrome — Settings > Privacy and security > Third-party cookies
    • Edge — Settings > Cookies and site permissions
    • Safari — Preferences > Privacy
  2. Install the Google Analytics opt-out add-ontools.google.com/dlpage/gaoptout

Refusing cookies does not restrict your use of the Site.

Article 10Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of personal information.

1. Managerial measures

  • Establishment, implementation, and periodic review of an internal management plan
  • Minimization of personal information handlers and regular privacy training

2. Technical measures

  • Differentiated access rights to personal information processing systems
  • Access-control systems and retention of access logs for at least one year with periodic review
  • Encryption of transmission channels (HTTPS/TLS)
  • Encrypted storage of authentication credentials used for external service integration, with least-privilege principles
  • No-server-storage principle for inquiry content — the server only relays transmission and does not log message bodies
  • Installation and periodic updates of security software

3. Physical measures

  • Access control for server rooms and data storage areas

Article 11Chief Privacy Officer and Department Handling Access Requests

The Company designates the following Chief Privacy Officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies.

Chief Privacy Officer

Name / Title
Minho Yoo, Director
Phone
+82-2-1833-4022
Email
contact@iotrust.kr

Access Requests / Grievance Handling

Department
DCENT Customer Support Team
Phone
+82-2-1833-4022
Email
contact@iotrust.kr

Product inquiries may be sent to enterprise@iotrust.kr; however, privacy-related rights requests and grievances should be filed through the contacts above.

Article 12Remedies for Infringement of Rights

Data subjects may contact the following organizations (in Korea) for remedy and consultation regarding privacy infringements.

OrganizationPhoneWebsite
Personal Information Infringement Report Center
(Korea Internet & Security Agency)
118 (no area code)privacy.kisa.or.kr
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Supreme Prosecutors' Office, Cyber Investigation Division1301 (no area code)www.spo.go.kr
National Police Agency, Cyber Investigation Bureau182 (no area code)ecrm.police.go.kr

A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to requests under Articles 35 (access), 36 (correction/deletion), or 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act. (Central Administrative Appeals Commission: 110, www.simpan.go.kr)

Article 13Changes to This Privacy Policy

If this Privacy Policy is added to, deleted, or amended due to changes in laws, government policy, or the Company's internal policies, the reasons and details of the change will be announced on the Site from 7 days before the change takes effect (30 days for changes unfavorable to data subjects).

This Privacy Policy is the initial version (v1.0), effective from August 1, 2026.

This English translation is provided for the convenience of international visitors. In the event of any conflict or discrepancy between this translation and the Korean original, the Korean version shall prevail.