Privacy Policy
Privacy Policy (English Translation)
This English translation is provided for the convenience of international visitors. In the event of any discrepancy, the Korean version shall prevail.
Innopoiesis co., Ltd ("INNOPOIESIS", the "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea ("PIPA") to protect the personal information of data subjects and to handle related grievances promptly.
Article 1 (Personal Information on This Website)
(1) The Company does not operate member registration or any input forms that collect personal information on this website (innopoiesisit.com). The "Contact" button only copies the Company's representative email address to the visitor's clipboard; no personal information of the visitor is transmitted to the Company through this function.
(2) The Company does not use visitor analytics or advertising tracking tools, and does not use cookies for analytics or advertising purposes.
(3) However, in the course of stable operation, security-threat mitigation, and troubleshooting of the website, access information such as IP address, access time, browser/device information, requested URL, and security events may be automatically generated and processed by the web server or the security service (Cloudflare). Where Cloudflare's security features operate, cookies strictly necessary for security may be set. Such information is not used to identify visitors or for advertising.
Article 2 (Purposes, Items, and Legal Bases of Processing)
The Company processes personal information voluntarily provided by inquirers via email, and access information automatically generated in the course of operating the website, as follows.
[Business / product / partnership inquiries]
- Purpose: Reviewing inquiries, responding, discussing quotations and partnerships
- Items: Sender's email address, name, affiliation, department/title, phone number, inquiry content, and information contained in attachments
- Legal basis: PIPA Art. 15(1)4 (conclusion and performance of a contract) [Recruitment inquiries / applications]
- Purpose: Identifying applicants, reviewing applications, notifying results
- Items: Email address, name, contact details, education, career history, qualifications, portfolio, and other information submitted by the applicant
- Legal basis: PIPA Art. 15(1)4 [Website operation and security]
- Purpose: Blocking security threats, analyzing failures, preventing misuse
- Items: IP address, access time, browser/device information, requested URL, security events
- Legal basis: PIPA Art. 15(1)6 (legitimate interests) * Please do not send sensitive information unnecessary for review (e.g., resident registration numbers, health information) in inquiries or applications. The Company may delete such information immediately upon identification. Article 3 (Retention Period) (1) Personal information in business/product/partnership inquiries is retained for one (1) year after the inquiry has been handled, and then destroyed. (2) Recruitment-related personal information is retained for six (6) months after the relevant recruitment process ends, and then destroyed. (3) Access information is processed for the period necessary for security purposes; processing by the processor is governed by Article 5. (4) Where an inquiry leads to a contract or transaction, only the information necessary for the performance of that contract/transaction and compliance with applicable laws may be retained separately; where retention is required under applicable laws, the information is retained for the period prescribed therein. Article 4 (Provision to Third Parties) The Company does not provide personal information to third parties, except where specifically required by law. Article 5 (Outsourcing and Cross-Border Transfer) (1) For the stable operation and security of the website and for its representative email service, the Company outsources processing as follows, in the course of which personal information is transferred abroad (disclosed pursuant to PIPA Article 28-8(1)3(a)). [Cloudflare, Inc.]
- Recipient: Cloudflare, Inc. (United States) · [email protected] · www.cloudflare.com
- Items transferred: Website access information (IP address, access time, browser/device information, requested URL, security events)
- Country, timing, method: Countries where Cloudflare's global network is located, including the United States / at each website visit / encrypted transmission via telecommunications networks
- Purpose of use: Content delivery (CDN) and website security (DDoS mitigation, bot detection, etc.)
- Retention period: Until the purpose of the outsourced processing is achieved (minimum period under Cloudflare's privacy policy) [Google LLC]
- Recipient: Google LLC (United States) · policies.google.com/privacy · workspace.google.com
- Items transferred: Personal information contained in email sent to or from the Company's representative address (name, email address, contact details, affiliation, inquiry content, and information contained in attachments)
- Country, timing, method: Countries where Google's data centres are located, including the United States / whenever email is sent or received / encrypted transmission via telecommunications networks
- Purpose of use: Provision and storage of business email (Google Workspace)
- Retention period: For the retention periods set out in Article 3 (2) Data subjects may object to the cross-border transfer via the contact in Article 9; however, refusal may make normal access to the website and provision of security services difficult, and may make it impossible to respond to inquiries by email. Article 6 (Destruction) Personal information whose retention period has expired or whose processing purpose has been achieved is destroyed without delay. Electronic files (including emails and attachments) are deleted irreversibly, and paper documents are shredded or incinerated. Article 7 (Rights of Data Subjects and How to Exercise Them) Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal information via the contact in Article 9, and the Company will take necessary measures without delay. Rights may also be exercised through a legal representative or an authorized agent. Article 8 (Security Measures)
- Limiting personnel who may process personal information to the minimum necessary and managing access rights
- Applying secure authentication to the representative email and website administration accounts
- Applying encrypted communication (HTTPS) across the entire website
- Applying safeguards against malware, phishing, and malicious attachments
- Regularly reviewing and deleting emails and attachments past their retention period Article 9 (Privacy Officer and Responsible Department)
- Chief Privacy Officer: Kyu Back Lee, CEO
- Responsible staff: Jaehyun Kim, IT Team Lead
- Contact: [email protected] / +82-2-6223-8040 Article 10 (Remedies for Infringement)
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118 / privacy.kisa.or.kr
- National Police Agency Cyber Investigation Bureau: 182 / ecrm.police.go.kr Article 11 (Changes to This Policy) (1) This Privacy Policy takes effect on August 28, 2026. (2) When this Policy is amended, the effective date and key changes will be disclosed on the website; where an amendment materially affects the rights of data subjects, notice will be given at least seven (7) days before it takes effect. Business Information
- Company: Innopoiesis co., Ltd
- Representative: Kyu Back Lee
- Address: Room 602-3, TechnoComplex Building, Korea University, 145 Anam-ro, Seongbuk-gu, Seoul 02841, Republic of Korea
- Tel / Email: +82-2-6223-8040 / [email protected]