UBIX Therapeutics Co., Ltd. Privacy Policy
UBIX Therapeutics Co., Ltd. (hereinafter the “Company”) processes personal information lawfully and manages it safely in compliance with the Personal Information Protection Act (“PIPA”) and other relevant laws, in order to protect the freedom and rights of data subjects. In accordance with Article 30 of the PIPA, the Company hereby establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for the processing and protection of personal information, and to ensure that related grievances can be handled promptly and smoothly.
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those listed below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the PIPA.
- Membership Registration and Management: Confirming intent to register as a member, identity verification/authentication for membership services, maintaining/managing membership status, preventing fraudulent use of services, verifying legal guardian consent when processing personal information of children under 14, various notices/announcements, and handling complaints
- Provision of Goods or Services: Delivery of goods, service provision, sending contracts/invoices, providing content, providing personalized recommendation services, identity verification, age verification, and fee payment/settlement
- Service Improvement and Analysis: Analysis of service use, demographic analysis, and service improvement
- Service Development: Development of new services separate from existing services
2. Personal Information Items Processed
A. Personal Information Processed Without Consent
① Membership Service Operation
- Legal basis: PIPA Article 15(1)(4) (Conclusion/performance of a contract)
- Items processed: Name, date of birth, ID, password, mobile phone number, email address, Connecting Information (CI)
② After-Sales Service (A/S) Consultation for Purchased Products
- Legal basis: PIPA Article 15(1)(4) (Conclusion/performance of a contract)
- Items processed: Name, mobile phone number, purchase history
③ Order and Payment Processing
- Legal basis: PIPA Article 15(1)(4) (Conclusion/performance of a contract)
- Items processed: ID, order history, card name, card number
④ Identity Verification for Electronic Signature Certification Provider (Processed without consent pursuant to other laws)
- Legal basis: PIPA Article 15(1)(2) (Compliance with legal obligations); Article 14 of the Enforcement Decree of the Digital Signature Act (Processing of Connecting Information)
- Items processed: Name, date of birth, mobile phone number, Connecting Information (CI)
⑤ Simple/Social Login (Personal information received from a party other than the data subject)
- Legal basis: PIPA Article 15(1)(4) (Conclusion/performance of a contract)
- Items processed: Connecting Information (CI) received, email, name, date of birth
⑥ On-Device Processed Information
- Certain personal information is processed directly on the user\'s device and is not transmitted to an external server. Such information is immediately deleted from the device when the relevant feature is turned off or the app is deleted.
B. Personal Information Processed With Consent
① Service Promotion and Marketing
- Legal basis: PIPA Article 15(1)(1) (Consent)
- Items processed: Name, date of birth, address, mobile phone number, email, product interest history
② Provision of Health Management Services (Sensitive Information)
- Legal basis: PIPA Article 23(1)(1) (Consent)
- Items processed: Oxygen saturation, blood glucose information, blood pressure, heart rate, height, weight
3. Period of Processing and Retention of Personal Information
- Website Membership Registration and Management: Until withdrawal of membership. However, in the following cases, until the relevant reason ends:
- Where an investigation is underway due to a violation of relevant laws: until the investigation concludes
- Where a claim/obligation relationship remains from use of the website: until such claim/obligation is settled
- Provision of Goods or Services: Until completion of supply of goods/services and completion of fee payment/settlement. However, the Company retains the following records for the stated periods pursuant to relevant laws:
- Records concerning contracts or withdrawal of subscription: 5 years (Article 6(1)(2) of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce)
- Records concerning payment and supply of goods, etc.: 5 years (Article 6(1)(3) of the same Enforcement Decree)
- Records concerning consumer complaints or dispute resolution: 3 years (Article 6(1)(4) of the same Enforcement Decree)
- Records concerning display/advertising: 6 months (Article 6(1)(1) of the same Enforcement Decree)
- Retention of Communication Confirmation Data: Computer communication and internet log records, access location tracking data — 3 months (Article 15-2(2) of the Protection of Communications Secrets Act)
4. Procedures and Methods for Destruction of Personal Information
- The Company destroys personal information without delay once it becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose.
- Where the retention period consented to by the data subject has expired or the processing purpose has been achieved, but retention is still required under other laws, the Company transfers the relevant personal information to a separate database (DB) or stores it in a different location.
- Destruction Procedure: The Company selects personal information subject to destruction and destroys it upon approval of the Company\'s Chief Privacy Officer.
- Destruction Method: Personal information recorded and stored in electronic file form is destroyed using methods that render the records unrecoverable, and personal information recorded and stored on paper documents is destroyed by shredding or incineration.
5. Provision of Personal Information to Third Parties
The Company does not provide personal information to third parties without the consent of the data subject.
6. Outsourcing of Personal Information Processing
Trustee | Outsourced Task |
Appgrida Co., Ltd. | Server hosting |
- When entering into an outsourcing agreement, the Company specifies in the contract, in accordance with Article 26 of the PIPA, matters such as the prohibition on processing personal information for purposes other than the outsourced task, technical/managerial protection measures, restrictions on re-outsourcing, supervision/management of the trustee, and liability for damages, and supervises whether the trustee processes personal information safely.
- In the event of re-outsourcing, the Company obtains consent pursuant to Article 26(6) of the PIPA and discloses the re-trustee and the re-outsourced task through this Privacy Policy.
- If the content of the outsourced task or the trustee changes, the Company will disclose this without delay through this Privacy Policy.
- Where personal information processing tasks are outsourced overseas, the Company provides separate notice regarding the relevant cross-border transfer matters.
7. Measures to Secure the Safety of Personal Information
- Administrative Measures: Establishment and implementation of an internal management plan, regular employee training, operation of a dedicated organization
- Technical Measures: Management of access rights to personal information processing systems, installation of access control systems, internet network blocking measures, encryption of personal information, storage and inspection of access records, installation/operation/updating of security programs, inspection and remediation of vulnerabilities in personal information processing systems
- Physical Measures: Access control for computer rooms and data storage rooms, storage of documents and auxiliary storage media in secure locations with locking devices, safety measures against disasters, and control over the movement of auxiliary storage media in and out of the premises
8. Collection, Use, Provision, and Refusal of Behavioral Information
- Tools used: Google Analytics, Google Tag Manager, etc.
- Items collected: Cookie identifiers, pages visited, time spent, IP address (de-identified), etc.
- Purpose of collection: Analysis of website usage statistics, service improvement
- Recipient: Google (involves an overseas transfer — see note below)
- Retention period: 2 months from the date of collection
- Method of refusal: Change browser cookie settings, or use the Google Analytics Opt-out Browser Add-on
Note: Because this data is transferred to Google (a company located overseas), the Company recommends separately specifying the destination country, the recipient, the date/method of transfer, and the recipient\'s purpose of use and retention period for the overseas transfer.
9. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
- The Company uses “cookies” that store and periodically retrieve usage information in order to provide individually tailored services and convenience to data subjects.
- A cookie is a small piece of information sent by the server (http) operating the website to the data subject\'s browser; it is stored on the data subject\'s computer or mobile device and is automatically transmitted back to the server from the data subject\'s browser when the website is accessed.
- Data subjects may refuse the storage of cookies by adjusting their browser settings.
How to Block Cookies in a Web Browser
- Chrome: Click ‘⁝’ in the upper right corner → New Incognito Window (Ctrl+Shift+N)
- Edge: Click ‘…’ in the upper right corner → New InPrivate Window (Ctrl+Shift+N)
How to Block Cookies on a Mobile Browser
- Chrome: Tap ‘⁝’ in the upper right corner → New Incognito Tab
- Safari: Settings → Apps → Safari → Advanced → Block All Cookies
- Samsung Internet: Tap the ‘Tabs’ icon at the bottom → Turn on Secret Mode → Start
10. Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Rights
- Data subjects may, at any time, request the Company to view, transmit, correct, delete, or suspend the processing of, or withdraw consent to, their personal information (hereinafter “Exercise of Rights”).
- For children under 14 years of age, the exercise of rights must be made directly by their legal representative. Data subjects who are minors aged 14 or older may exercise their rights themselves or through a legal representative.
- The exercise of rights may be made in writing, by telephone, email, fax, the internet, etc., pursuant to Article 41(1) of the Enforcement Decree of the PIPA, and the Company will take action without delay.
- Data subjects may directly view, modify, delete, suspend processing of, or withdraw consent to their personal information via ‘My Info > Member Information’ on the website, or request access via ‘Contact Us’.
- Data subjects may request transmission of their personal information to themselves via ‘My Info > Request Self-Transmission’ on the website, and check the transmission status and history.
- Requests for transmission to a third party may be made through the service operated by the intended recipient of the information; the status of such recipients and third-party transmission requests can be checked on the Personal Information Transmission Support Platform (OnMyData, OnMydata.go.kr).
- Data subjects may request refusal of and an explanation regarding automated decisions via ‘My Info > Member Information > Contact Us’ on the website.
- The exercise of rights may also be made through a data subject\'s legal representative or an authorized agent. In such cases, a power of attorney in the form prescribed by the “Notice on Methods of Processing Personal Information” must be submitted.
- The right to request access to and suspension of processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the PIPA.
- Deletion may not be requested for personal information that is designated as subject to collection under other laws.
- The Company verifies whether the person exercising rights is the data subject or a legitimate agent thereof.
- The Company will respond within 10 days of receiving a request to exercise rights (without delay in the case of transmission requests).
Department for Receiving and Processing Requests to Exercise Personal Information Rights
- Department: Management Support Office
- Address: C-dong, 1401, 7, Beopwon-ro 11-gil, Munjeong-dong, Songpa-gu, Seoul, Republic of Korea
- Contact: +82-2-6335-2475
11. Chief Privacy Officer
Chief Privacy Officer
- Name: Sanghyun Park
- Title: Executive Director
- Contact: +82-2-6335-2475
Department in Charge of Personal Information Protection
- Department: Management Support Office
- Contact: +82-2-6335-2475
Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from their use of the Company\'s services (or business) to the above officer/department, and the Company will respond and take action without delay.
12. Changes to the Privacy Policy
- This Privacy Policy is effective as of August 1, 2026.
- Previous versions of the Privacy Policy can be found below.
- (Insert link to previous version)