Legal

Privacy Policy

Effective Date: January 1, 2026

Last Updated: March 29, 2026

IQHub Co., Ltd. (hereinafter 'Company') establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than the following, and if the purpose of use changes, necessary measures such as obtaining separate consent will be taken in accordance with Article 18 of the Personal Information Protection Act.

1.
Service Consultation and Inquiry Handling: Processing consultation requests, receiving and responding to inquiries, and providing service information
2.
Contract Performance and Service Delivery: Providing consulting services, concluding and managing contracts, issuing invoices, and receiving payments
3.
Marketing and Advertising: Providing information about new services, events, and promotions (only with separate consent)

2. Retention Period of Personal Information

The Company processes and retains personal information within the retention and use period stipulated by law or agreed upon when collecting personal information from data subjects.

PurposeRetention Period
Consultation and Inquiry Handling3 years after completion
Contract Performance and Service Delivery5 years after contract termination (Commercial Act, Art. 33)
E-commerce Records5 years (E-Commerce Act, Art. 6)
Consumer Complaints and Dispute Resolution3 years (E-Commerce Act, Art. 6)

3. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information) and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.

The Company currently does not provide personal information of data subjects to third parties.

4. Entrustment of Personal Information Processing

The Company entrusts personal information processing as follows for smooth personal information business processing.

TrusteeEntrusted Tasks
Amazon Web Services, Inc.Cloud server operation and data storage
Email Service ProviderEmail delivery services

When concluding entrustment contracts, the Company specifies in documents such as contracts the prohibition of processing personal information for purposes other than the entrusted tasks, technical and administrative protective measures, restrictions on re-entrustment, supervision and management of trustees, and liability for damages, in accordance with Article 26 of the Personal Information Protection Act, and supervises whether trustees process personal information safely.

5. Rights of Data Subjects and How to Exercise Them

Data subjects may exercise the following personal information protection rights against the Company at any time.

  • Request to access personal information
  • Request for correction if there are errors
  • Request for deletion
  • Request to suspend processing

Rights may be exercised against the Company in writing, by email, or by fax in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.

If a data subject requests correction or deletion of personal information due to errors, the Company will not use or provide the personal information until the correction or deletion is completed. Rights may also be exercised through a legal representative or an authorized agent. In this case, a power of attorney in accordance with Annex Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.

6. Categories of Personal Information Processed

The Company processes the following categories of personal information.

PurposeRequired ItemsOptional Items
Consultation Requests and InquiriesName, email address, phone number, company namePosition, inquiry content
Service Contracts and DeliveryName, email address, phone number, company name, business registration numberDepartment, position
Automatically Collected (Website Use)IP address, cookies, visit date/time, service usage records-

7. Destruction of Personal Information

When personal information becomes unnecessary due to the expiration of the retention period or achievement of the processing purpose, the Company destroys the personal information without delay.

Destruction Procedure

The Company selects personal information for which a reason for destruction has arisen and destroys it with the approval of the Company's Personal Information Protection Officer.

Destruction Method

  • Personal information recorded and stored in electronic file format: Destroyed using methods such as low-level formatting so that records cannot be reproduced
  • Personal information recorded and stored in paper documents: Destroyed by shredding or incineration

8. Measures to Ensure Security of Personal Information

The Company takes the following technical, administrative, and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act.

Minimization and Training of Personal Information Handling Staff

The Company designates staff who handle personal information and limits them to those in charge, implementing measures to minimize personal information management.

Establishment and Implementation of Internal Management Plans

The Company establishes and implements internal management plans for the safe processing of personal information.

Technical Measures Against Hacking

To prevent personal information leakage and damage caused by hacking or computer viruses, the Company installs security programs, performs periodic updates and inspections, installs systems in areas with controlled external access, and technically and physically monitors and blocks unauthorized access.

Encryption of Personal Information

Users' personal information passwords are encrypted for storage and management, so only the user knows them. Important data uses separate security functions such as encrypting files and transmitted data or using file locking functions.

Retention and Prevention of Falsification of Access Records

Records of access to personal information processing systems are retained and managed for at least one year. However, if processing personal information of 50,000 or more data subjects, or processing unique identification information or sensitive information, records are retained and managed for at least two years.

Restriction of Access to Personal Information

The Company takes necessary measures for access control to personal information through granting, changing, and revoking access rights to database systems that process personal information, and uses intrusion prevention systems to control unauthorized external access.

9. Installation, Operation, and Opt-out of Automatic Data Collection Devices

The Company uses 'cookies' that store and retrieve usage information to provide personalized services to users.

What are Cookies?

Cookies are small pieces of information sent by the server (http) operating the website to the user's computer browser and may be stored on the hard disk of the user's PC.

Purpose of Cookie Use

Cookies are used to understand the visit and usage patterns of each service and website visited by users, popular search terms, and whether secure connections are used, in order to provide users with optimized information.

Cookie Installation, Operation, and Opt-out

Users have the right to choose whether to install cookies. Therefore, users can allow all cookies, go through confirmation each time a cookie is saved, or refuse to save all cookies by setting options in their web browser.

Refusing to save cookies may cause difficulties in using personalized services.

How to set (Internet Explorer): Tools at the top of the web browser > Internet Options > Privacy

10. Personal Information Protection Officer

The Company designates a Personal Information Protection Officer as follows to take overall responsibility for personal information processing and to handle complaints and remedy damages related to personal information processing by data subjects.

Personal Information Protection Officer

Name: IQHub Representative

Position: Chief Executive Officer

Email: contact@iqhub.co

Data subjects may contact the Personal Information Protection Officer and the relevant department for all personal information protection-related inquiries, complaints, and damage remedies arising from the use of the Company's services (or business). The Company will respond and take action without delay.

11. Remedies for Infringement of Rights

Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, etc. to receive relief for personal information infringement. For other reports and consultations on personal information infringement, please contact the following agencies.

AgencyPhoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Information Infringement Report Center (KISA)118privacy.kisa.or.kr
Supreme Prosecutors' Office Cyber Crime Investigation Unit02-3480-3573www.spo.go.kr
National Police Agency Cyber Safety Bureau182cyberbureau.police.go.kr

12. Changes to This Privacy Policy

This Privacy Policy is effective from January 1, 2026. Previous versions of the Privacy Policy can be found below.

View Previous Version (N/A)