Privacy Policy
Effective date · To be set after legal review
This document is a draft. It will be published in final form, with an effective date, after legal review.
The Korean original is the legally binding version of this document; the Japanese and English versions are reference translations.
HOLOFLEX treats personal data with care and complies with the Personal Information Protection Act and other applicable law. This policy explains what personal data the Service processes, for what purposes, and for how long it is retained.
1. Personal data collected and how it is collected
The Service collects data entered by the user during registration, purchase and enquiry submission. Other items may be generated or collected automatically in the course of using the Service.
| Context | Data | Purpose |
|---|---|---|
| Registration (required) | Email address, password (stored encrypted), display name, account type | Identifying the account and providing the Service |
| Purchase | Depositor name, order amount and commission rate, order and approval history | Payment and supply of content, purchase history |
| Enquiries (including without sign-in) | Name, email address, message | Responding to enquiries and replying with the outcome |
| Collected automatically | IP address, browser information, access timestamps | Operating the Service and preventing abuse |
2. Purposes of processing
- Confirming intent to register and maintaining the account
- Performing the sale and purchase of content and settling payments
- Issuing and managing download entitlements
- Handling enquiries and complaints and replying with the outcome
- Meeting obligations under applicable law
3. Retention period
Personal data is destroyed without delay once its purpose has been achieved. Records that applicable law requires to be preserved are kept for the periods below.
| Records | Period | Basis |
|---|---|---|
| Contracts and withdrawal of purchase | 5 years | E-Commerce Act |
| Payment and supply of goods | 5 years | E-Commerce Act |
| Consumer complaints and dispute resolution | 3 years | E-Commerce Act |
| Labelling and advertising | 6 months | E-Commerce Act |
| Access logs | 3 months | Protection of Communications Secrets Act |
4. Disclosure to third parties
The Service does not disclose personal data to third parties, except where there is a specific provision of law or where an investigative authority makes a request under the procedures and methods prescribed by law.
5. Processors
Processing is entrusted to the parties below to the extent needed to operate the Service. They are supervised so that personal data is not processed for purposes beyond the entrusted work.
| Processor | Entrusted work |
|---|---|
| Supabase Inc. | Database, authentication and file storage |
| Vercel Inc. | Web hosting and request handling |
6. Transfer of personal data abroad
Personal data is transferred abroad as set out below. A user may decline the transfer, in which case registration and use of the Service are not available.
| Item | Supabase Inc. | Vercel Inc. |
|---|---|---|
| Recipient | Supabase Inc. (a US company) | Vercel Inc. (a US company) |
| Country of transfer | Japan (Tokyo) | Japan (Tokyo) |
| Time and method of transfer | Transmitted over the network at the time the Service is used | Transmitted over the network at the time the Service is used |
| Data transferred | Email address, password (encrypted), display name, account type, order and enquiry data, uploaded files, access logs | The items above, as handled while processing requests |
| Recipient’s purpose | Operating the database, authentication and file storage | Running the web application and handling requests |
| Retention period | Until the account is closed or the processing agreement ends | Until the account is closed or the processing agreement ends |
7. Destruction of personal data
Personal data is destroyed without delay once the retention period has passed or the purpose has been achieved. Data held electronically is deleted so that it cannot be recovered.
8. Your rights and how to exercise them
A user may at any time request access to, correction of, deletion of, or suspension of the processing of their personal data. Requests can be made through the contact below and are acted on without delay once verified.
10. Security measures
- Passwords are stored using a one-way encryption scheme that cannot be reversed.
- Purchased source files are held in private storage and served only through time-limited links to users whose entitlement has been verified.
- Row-level access control is applied in the database so that a user can reach only their own records.
- Administrative screens that handle personal data are reachable only by authorised accounts.
11. Data protection officer
A data protection officer is appointed to oversee the processing of personal data and to handle user complaints.
- Name
- Yoon Jeongwook
- Role
- CEO / Business Administration
- Phone
- 010-9909-8075
- cs@theface.link
12. Remedies
For advice about or to report an infringement of personal data rights, the following bodies can be contacted.
- Personal Information Dispute Mediation Committee (1833-6972 / www.kopico.go.kr)
- Privacy Infringement Report Centre (118 / privacy.kisa.or.kr)
- Supreme Prosecutors’ Office, Cyber Investigation Division (1301 / www.spo.go.kr)
- National Police Agency, Cyber Bureau (182 / ecrm.police.go.kr)
13. Changes to this policy
Where this policy changes, the change and its effective date are announced on the Service.