Privacy Policy
Bitsensing Inc. establishes this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of the Republic of Korea, to protect the personal information and rights of users. This policy complies with ISO/IEC 27001:2022 and operates within the company's Information Security Management System.
1. Purpose & types of personal information
The company processes personal information for the following six purposes. Each purpose is limited to the items necessary to fulfill it.
- Service enrollment & AI learning — name, date of birth, gender, contact details, usage records
- Usage statistics & analysis — age, region, gender, records, access logs
- Contracts & billing — name, address, phone, email, payment / banking details
- User management — name, ID, password, email, usage records, IP address
- Service improvement — name, email, usage records, cookies, IP address, logs
- Marketing & advertising — name, email, usage records, cookies, logs
2. Retention & processing periods
The company retains personal information for the periods required by internal policy and by applicable law.
| Category | Period |
|---|---|
| Misuse records (internal) | 1 year post-withdrawal |
| Complaint records (internal) | 1 year post-withdrawal |
| Contracts / cancellations (legal) | 5 years |
| Payment / goods records (legal) | 5 years |
| Consumer complaints (legal) | 3 years |
| Advertising records (legal) | 6 months |
| Identity verification (legal) | 6 months |
| Website visits (legal) | 3 months |
| Financial transactions (legal) | 5 years |
3. Third-party information sharing
The company may share personal data with third parties only where the user has consented, or where the information is provided within the scope of the stated purposes. Users are notified of the recipient's identity, the purpose of use, the data shared, the retention period, and their right to consent.
Cross-border transfers require the user's explicit consent and comply with PIPA requirements. Disclosure without consent may occur only in exceptional circumstances permitted by law — including legal requirements, criminal investigation, court proceedings, imminent danger to life or property, and protection of the public interest.
4. User rights & access
Under Article 35 of PIPA, users may request access to their processed personal information, and the company provides access promptly. Access may be limited where it is prohibited or restricted by law, where it could harm a third party, or where it may significantly hinder the operations of a public institution.
5. Data destruction
The company destroys personal information within five (5) days after the retention period expires. Electronic files are permanently erased so that they cannot be restored; physical documents are shredded or incinerated. Records that must be retained by law are stored separately from other information.
6. Security measures
The company implements technical, managerial, and physical safeguards, including:
- Internal management plans
- Access control mechanisms
- Encryption technology (at rest and in transit)
- Login record retention
- Security software and updates
- Physical storage protections
7. Cookies usage
Cookies store user preferences to provide customized services and to analyze visit and usage patterns. Users can control cookie acceptance through their browser settings; refusing cookies may limit service personalization.
8. Privacy officer / contact
- Privacy Officer: Jae Hyun Kim, CISO
- Email: privacy@bitsensing.com
- Information Protection Team: privacy@bitsensing.com
9. Remedies for rights infringement
Users may contact the following agencies for reports and counseling on privacy infringement:
- Personal Information Dispute Mediation Committee — 1833-6972
- Personal Information Infringement Report Center — 118
10. Policy changes
Any changes to this policy are announced through this page at least 7 days before they take effect. This policy is effective as of September 1, 2023.