Legal
Privacy Policy
SARTEXO Inc. (the "Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly. This is an English translation provided for convenience; in the event of any discrepancy, the Korean version shall prevail.
Company Information
- Company
- SARTEXO Inc. (주식회사 사르텍소)
- Representative
- Cheol Hoon Park
- Address
- Room 212, Bldg. S8, 156 Gajeongbuk-ro, Yuseong-gu, Daejeon, Republic of Korea
- Contact
- admin@sartexo.com
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information processed shall not be used for any purpose other than those listed below, and where the purpose of use changes, the Company will take necessary measures such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
- Receiving and responding to website inquiries (Contact)
- Receiving and consulting on pilot program requests
- Receiving and answering inquiries posted on the Q&A board
- Consultation on product adoption and field validation, and provision of related information
Article 2 (Processing and Retention Period)
The Company processes and retains personal information within the retention and use period prescribed by law or within the period consented to by the data subject at the time of collection.
- Personal information related to website inquiries (Contact): 3 years from the date the inquiry is received
- Personal information related to the Q&A board: 3 years from the date the inquiry is received
Personal information for which the retention period has elapsed or the purpose of processing has been achieved is destroyed without delay.
Article 3 (Categories of Personal Information Processed)
The Company processes the following categories of personal information.
- Website inquiry (Contact) — Required: name, email address / Optional: affiliation (company or institution name)
- Pilot program request — Required: company or institution name, contact name, email address, current pain points / Optional: phone number, industry, number of participants, main task types, preferred timing
- Q&A board: author name, password (stored encrypted)
- Automatically collected: IP address, cookies, service usage records, access logs
Article 4 (Provision of Personal Information to Third Parties)
The Company processes personal information only within the scope specified in Article 1 and, as a rule, does not provide personal information to third parties. The following are exceptions.
- Where separate consent has been obtained from the data subject
- Where there are special provisions in law, or where an investigative agency makes a request in accordance with the procedures and methods prescribed by law
Article 5 (Outsourcing of Personal Information Processing)
The Company outsources personal information processing as follows in order to provide its services smoothly. Because the servers of the processors below are located outside the Republic of Korea, personal information is transferred abroad.
| Processor | Outsourced Task | Country (Server Location) | Retention Period |
|---|---|---|---|
| Supabase Inc. | Storage and operation of the inquiry and Q&A database | Japan (Tokyo) | Until termination of the outsourcing agreement or the end of the period in Article 2 |
| Resend, Inc. | Sending inquiry notification emails | United States | Until termination of the outsourcing agreement or fulfillment of the sending purpose |
| Vercel Inc. | Website hosting and access log processing | United States | Until termination of the outsourcing agreement or the end of the period in Article 2 |
The personal information transferred consists of the categories listed in Article 3 and is transmitted over the network at the time of service use. When entering into outsourcing agreements, the Company specifies in the contract the prohibition of processing personal information beyond the purpose of the outsourced task, technical and administrative safeguards, and restrictions on sub-outsourcing, pursuant to Article 26 of the Personal Information Protection Act, and supervises whether the processor handles personal information safely. Data subjects may refuse the cross-border transfer of their personal information; in such case, the use of certain services, such as submitting inquiries, may be restricted.
Article 6 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
Data subjects may exercise the following rights regarding the protection of personal information against the Company at any time.
- Request to access personal information
- Request to correct personal information in the event of errors
- Request to delete personal information
- Request to suspend processing
These rights may be exercised by email to admin@sartexo.com or in writing, and the Company will act on such requests without delay. Where a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the personal information in question until the correction or deletion is complete. Rights may also be exercised through a legal representative or an authorized agent, in which case a letter of authorization must be submitted.
Article 7 (Procedures and Methods for Destroying Personal Information)
The Company destroys personal information without delay when it becomes unnecessary, such as when the retention period has elapsed or the purpose of processing has been achieved.
- Destruction procedure: The Company identifies the personal information for which grounds for destruction have arisen and destroys it upon approval of the Chief Privacy Officer.
- Destruction method: Personal information recorded and stored in electronic file form is permanently deleted from the database so that it cannot be recovered or reproduced; personal information recorded on paper is shredded or incinerated.
Article 8 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
- Administrative measures: establishment and implementation of an internal management plan, minimization and training of personnel handling personal information
- Technical measures: access control for the personal information processing system, one-way encryption (SHA-256) of passwords, encryption of data in transit via HTTPS
- Physical measures: access control for systems where personal information is stored
Article 9 (Installation and Operation of Automatic Collection Devices, and Refusal Thereof)
The Company may use "cookies" that store and retrieve usage information in order to provide individually tailored services to users.
- Purpose of cookies: to provide convenience in using the website, such as retaining the selected language setting
- Installation, operation, and refusal: Users may refuse the storage of cookies through the option settings under Tools > Internet Options > Privacy in their web browser.
If you refuse the storage of cookies, you may experience difficulty using some services.
Article 10 (Chief Privacy Officer)
The Company designates a Chief Privacy Officer as follows, who takes overall responsibility for personal information processing and handles complaints and remedies of data subjects related to such processing.
| Item | Details |
|---|---|
| Name | Cheol Hoon Park |
| Position | Chief Executive Officer |
| Contact | admin@sartexo.com |
Data subjects may direct any inquiries, complaints, or requests for remedy relating to personal information protection arising from the use of the Company's services to the Chief Privacy Officer. The Company will respond and take action without delay.
Article 11 (Remedies for Infringement of Rights)
Data subjects may apply to the following organizations for dispute resolution or consultation in order to obtain remedies for personal information infringement.
| Organization | Phone | Website |
|---|---|---|
| Privacy Infringement Report Center (KISA) | 118 | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Cyber Investigation Division, Supreme Prosecutors' Office | 02-3480-3573 | www.spo.go.kr |
| National Office of Investigation Cyber Bureau, Korean National Police Agency | 182 | ecrm.police.go.kr |
In addition, any person whose rights or interests have been infringed by a disposition taken or an omission made by the head of a public institution in response to a request under Articles 35 (access to personal information), 36 (correction or deletion of personal information), or 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
Article 12 (Changes to this Privacy Policy)
This Privacy Policy takes effect on August 17, 2026. Where content is added, deleted, or amended due to changes in laws, policies, or security technologies, the Company will announce the changes through the website notices at least 7 days before the changes take effect.
Effective date: August 17, 2026