SYINNOVATION SYINNOVATION
Privacy Policy

Privacy Policy

SYINNOVATION Co., Ltd. (the “Company”) complies with the Personal Information Protection Act (PIPA) of the Republic of Korea and related laws to protect the personal information of data subjects.

Effective date: August 24, 2026 · Last updated: August 24, 2026

SYINNOVATION Co., Ltd. values your privacy and is committed to protecting the personal information of everyone who visits our website and uses our services. This Privacy Policy explains what personal information we collect, why we collect it, how we use and retain it, and the rights available to you. Because the Company is established in the Republic of Korea, this Policy is governed by the Personal Information Protection Act (PIPA) and related Korean legislation.

Contents

  1. Purposes of Processing
  2. Personal Information We Collect
  3. Retention Period
  4. Provision to Third Parties
  5. Outsourcing of Processing
  6. Your Rights and How to Exercise Them
  7. Destruction of Personal Information
  8. Security Measures
  9. Cookies
  10. Privacy Officer
  11. Remedies for Rights Infringement
  12. Changes to This Policy

01Purposes of Processing

The Company processes personal information for the purposes set out below and does not use it beyond these purposes. Where the purpose of use changes, we take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.

  • Inquiries and consultation: receiving website inquiries (consultation requests), verifying the sender, and responding to and following up on inquiries.
  • Service delivery and performance of contracts: proposing, concluding, and performing agreements for our security solutions (Trust CA, Trust Gateway) and IT services (PI consulting, full-stack development, global outsourcing), and settling payments.
  • Customer management: maintaining business relationships, after-care, delivering notices, and handling complaints.
  • Marketing (only with your consent): providing information about new services, events, and activities.

02Personal Information We Collect

The Company collects the following personal information through the inquiry (consultation request) feature on the website.

CategoryItems collectedMethod
Website inquiryCompany name, contact person name, email or phone number, inquiry type, message contentWebsite inquiry form
Contract / transaction (where applicable)Contact person name and title, phone, email, business registration details (for tax invoicing)Provided via email, in writing, or during contracting
Automatically generated dataAccess IP address, cookies, service usage records, browser/device informationAutomatically collected during use of the service
The Company does not, as a rule, collect sensitive information (as defined in Article 23 of PIPA) such as beliefs, health, or political opinions, nor unique identifiers such as resident registration numbers.

03Retention Period

The Company processes and retains personal information within the retention period required by law or the period consented to by the data subject.

  • Website inquiries / consultation: retained for 3 years after the inquiry is completed, then destroyed (if the inquiry leads to a contract, the periods below apply).
  • Records related to contracts and transactions: retained in accordance with applicable laws (e.g., the Act on Consumer Protection in Electronic Commerce, the Framework Act on National Taxes):
    • Records on contracts or withdrawal of offers: 5 years
    • Records on payment and the supply of goods/services: 5 years
    • Tax-related documents such as invoices: 5 years

Personal information is destroyed without delay once the retention period expires or the purpose of processing is achieved.

04Provision to Third Parties

The Company processes personal information only within the scope of the purposes stated in Section 1, and provides personal information to third parties only where permitted under Articles 17 and 18 of PIPA, such as with the data subject's consent or under specific legal provisions. The Company does not currently provide personal information to any third party.

Should provision to a third party become necessary in the future, we will notify you in advance of the recipient, the purpose, the items provided, and the retention period, and obtain your consent before doing so.

05Outsourcing of Processing

To provide services smoothly, the Company may outsource parts of its personal information processing as set out below. When outsourcing, the Company stipulates and supervises the matters necessary for the safe management of personal information through outsourcing agreements, in accordance with Article 26 of PIPA.

Outsourced processorScope of outsourced work
[Website hosting provider]Website server hosting and operation
[Inquiry form / email delivery service]Transmission of website inquiries and email replies

If the scope of outsourced work or the processor changes, we will disclose it without delay through this Privacy Policy.

06Your Rights and How to Exercise Them

As a data subject, you may exercise the following rights with respect to the Company at any time:

  • the right to request access to your personal information;
  • the right to request correction of any errors;
  • the right to request deletion;
  • the right to request suspension of processing.

You may exercise these rights by contacting the Company in writing or by email, and we will act without delay. Where you request correction or deletion of an error, we will not use or provide the relevant personal information until the correction or deletion is completed. These rights may also be exercised through a legal representative or a duly authorized agent.

07Destruction of Personal Information

The Company destroys personal information without delay once it is no longer needed, such as when the retention period has elapsed or the purpose of processing has been achieved.

Procedure

Information entered by a user is stored for a certain period in accordance with internal policy and relevant laws after the purpose is achieved, or is destroyed immediately. Where retention is required under other laws, the information is transferred to a separate database or storage location.

Method

Personal information stored in electronic file form is deleted using technical methods that render it unrecoverable, and personal information printed on paper is shredded or incinerated.

08Security Measures

In accordance with Article 29 of PIPA, the Company takes the following technical, administrative, and physical measures necessary to ensure security:

  • Administrative: establishing and implementing an internal management plan, minimizing the number of staff handling personal information, and providing regular training.
  • Technical: managing access rights to the personal information processing system, installing access-control systems, encrypting data in transit (SSL/TLS), and installing and regularly reviewing security software.
  • Physical: controlling access to the systems and materials where personal information is stored.

09Cookies

The Company may use “cookies” that store and retrieve usage information to provide individually tailored services. A cookie is a small piece of information that the website server sends to your browser and stores on your device.

You may refuse the storage of cookies through your web browser settings. However, if you refuse cookies, you may experience difficulties in using some services.

Example (Chrome): Settings > Privacy and security > Cookies and other site data.

10Privacy Officer

The Company has designated a Privacy Officer as set out below to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.

Name / Title[Name] / [Title]
ContactTel +82-70-4236-9504 · Email jamesgong@syinnovation.net
AddressSeoul FinTech Lab2, 78 Mapo-daero, Mapo-gu, Seoul, Republic of Korea

You may direct any questions, complaints, or requests for remedy relating to personal information that arise while using our services to the Privacy Officer. We will respond and act without delay.

11Remedies for Rights Infringement

To obtain remedies for infringement of your personal information rights, you may apply to the following bodies for dispute resolution or consultation:

  • Personal Information Dispute Mediation Committee: +82-1833-6972 / www.kopico.go.kr
  • Personal Information Infringement Report Center (KISA): (dial 118 within Korea) / privacy.kisa.or.kr
  • Supreme Prosecutors' Office, Cyber Investigation Division: (dial 1301 within Korea) / www.spo.go.kr
  • National Police Agency, Cyber Bureau: (dial 182 within Korea) / ecrm.police.go.kr

12Changes to This Policy

This Privacy Policy applies from its effective date. Where there are additions, deletions, or corrections due to changes in law or policy, we will announce them through a notice on the website at least 7 days before the changes take effect.

  • Notice date: August 17, 2026
  • Effective date: August 24, 2026
SYINNOVATION
Co., Ltd. · Business Reg. No. 439-88-02733 · Seoul FinTech Lab2, 78, Mapo-daero, Mapo-ku, Seoul, KOREA
Privacy Policy Terms of Use © 2026 SYINNOVATION