MindwareWorks Co., Ltd. (the “Company”) establishes and publishes this Privacy Policy under Article 30 of Korea's Personal Information Protection Act to protect data subjects and handle related concerns promptly. This policy applies to services the Company provides to individuals and businesses. This English version is provided for convenience; the Korean version governs if the versions differ.
1. Purpose of processing
The Company processes the minimum personal information necessary to provide its services.
2. Personal information collected
① The Company collects the minimum personal information and service-usage history required for each service and related feature.
[TouchHub]
[Required for registration] Name, contact information and address
[Optional sender/customer information] Name, contact information and address
[CogInsight]
[Required for registration] Email (account information), name or nickname and password
[Optional for registration] Contact information
[Homepage]
[Required for inquiries] Company, department, name, position, contact information, email and inquiry details
[Required for training registration] Company, department, name, position, role, contact information, email and whether the applicant will join hands-on exercises
[Optional for marketing and advertising] Company, department, name, position, contact information and email
[Required for job applications] Name, email, contact information, role applied for, career information, referral source, résumé and attachments
[Optional for job applications] Career description, portfolio and other information submitted by the applicant
[forum.CogInsight]
[Required for registration] Email, account, name or nickname and password
② Device information (including operating system and browser), IP address, cookies, visit time and service-usage records may be generated and collected automatically when web, mobile-web or app services are used.
③ Collection methods include registration and customer-support interactions through webpages, email, telephone and fax.
3. Use of personal information
The Company uses the minimum information necessary for membership administration, service delivery and improvement, and new-service development, including:
- User identification and prevention of unauthorized use
- New-service development, service delivery, inquiry and complaint handling, and notices
- Billing settlement and tax-invoice issuance
- Prevention and restriction of conduct that disrupts service operations, including account theft and misuse
- Usage statistics, privacy-oriented service environments and service improvement
- Applicant identification, recruitment, result notification, inquiry response and recruitment administration
4. Provision and outsourcing
① The Company processes personal information within the stated collection and use purposes and does not use it beyond those purposes or provide it to a third party without prior consent, except when:
- The data subject provides separate consent
- Another law specifically permits or requires it
- Consent cannot be obtained because the data subject or legal representative cannot express intent or cannot be reached, and processing is clearly necessary to protect the urgent life, physical safety or property interests of the data subject or a third party
- Information is required for statistics or academic research and is provided in a form that cannot identify an individual
- A public institution cannot perform duties prescribed by law without the out-of-purpose use or third-party provision and the Personal Information Protection Commission has reviewed and approved it
- It is necessary for criminal investigation or prosecution
- It is necessary for a court to conduct judicial duties
- It is necessary to execute a sentence, custody or protective disposition
- It is necessary for taxation or another measure under applicable law
② The Company outsources some processing required to deliver services and reviews the providers' privacy policies.
| Service provider | Entrusted work | Privacy policy | Retention period |
|---|---|---|---|
| Twilio SendGrid | Email delivery | View details | Until the outsourcing agreement ends |
| SK Broadband | Text-message delivery | View details | Until the outsourcing agreement ends |
| Salesforce | Customer database management for service delivery | View details | Until the outsourcing agreement ends |
③ The Company outsources and stores personal information abroad for email delivery and customer-relationship management. A data subject may object through the privacy contacts below, but related services may be restricted. Transfers are based on Article 28-8(1)(1) or 28-8(1)(3) of Korea's Personal Information Protection Act, as applicable.
| Transferred data | Country | Recipient and contact | Purpose | Retention period |
|---|---|---|---|---|
| All fields submitted with an inquiry | United States | Twilio SendGrid (https://sendgrid.com / privacy@twilio.com) | Email delivery and customer-inquiry response | Until the outsourcing agreement ends |
| All fields submitted with an inquiry | United States | Salesforce (https://www.salesforce.com / privacy@salesforce.com) | Customer database management and marketing | Until the outsourcing agreement ends |
5. Retention and destruction
① Personal information is processed within its stated purpose and retained in accordance with the Personal Information Protection Act and other applicable laws.
② The Company destroys personal information without delay after its purpose is fulfilled, unless another law requires retention.
| Information | Reason | Retention period | Service |
|---|---|---|---|
| Account (email) | User verification and inquiry response | 3 months after account closure | CogInsight |
| Chatbot conversation history | Usage and billing records | 12 months | CogInsight |
| Audit logs | Service administration history | 24 months | CogInsight |
| Clean log | Usage history | 12 months | CogInsight |
| User information | User verification | 3 months after the last access | TouchHub |
| Purchases | Payment and supply; contract withdrawal; complaint and dispute handling; delivery information | 5 years; 5 years; 3 years; 3 months after delivery | TouchHub |
| Marketing information | Inquiry response and marketing or advertising | Until consent is withdrawn or messages are declined | Common (Salesforce) |
| Job-application information | Recruitment and result notification | 1 year after recruitment ends | Homepage |
| Account information | User verification and inquiry response | 3 months after account closure | forum.CogInsight |
| Inquiry and consultation information | Inquiry and complaint history | 1 year after completion | Homepage |
| Training-registration information | Registration and program administration | 1 year after training ends | Homepage |
Destruction procedure
Unnecessary personal information and files are destroyed under the responsibility of the privacy officer and the Company's internal procedures. Information whose retention period has expired is destroyed without delay. A personal-information file is destroyed when its purpose is fulfilled, the service is discontinued, the business ends or the file otherwise becomes unnecessary.
Destruction method
Electronic information is destroyed using a technical method that prevents recovery. Printed records are shredded or incinerated.
6. Security measures and data-subject rights
① The Company applies the following safeguards:
Minimization and training
Only personnel who require access are designated and managed, and they receive training on secure handling.
Access restrictions
Access rights are granted, changed and revoked as necessary, and intrusion-prevention systems control unauthorized external access.
Access logs
Access to personal-information processing systems is retained and managed for at least one year.
Encryption
Personal information is stored and managed securely, including encryption of important data in storage and transit.
Security software and physical controls
Security software is installed, updated and inspected regularly. Physical locations that store personal-information systems are separately controlled.
② Users and legal representatives may request access or correction, withdraw consent, or request account closure at any time.
Remedies
Data subjects may request dispute resolution or counseling from the Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr), KISA Privacy Infringement Report Center (118, privacy.kisa.or.kr), Supreme Prosecutors' Office Cyber Investigation Division (1301, privacy@spo.go.kr, www.spo.go.kr), or Korean National Police Agency Cyber Bureau (182, cyberbureau.police.go.kr). Administrative appeals may be filed as permitted by law; see the Central Administrative Appeals Commission at www.simpan.go.kr.
7. Cookies and automatic collection
The Company uses cookies to provide personalized service and improve website convenience.
① Cookies may be used for service analytics and statistics (including Google Analytics), customer-relationship management and marketing (including Salesforce), and security and service operations.
② Users may allow all cookies, request confirmation whenever a cookie is stored, or reject all cookies in their browser settings. In Chrome, see Settings > Privacy and security; in Edge, see Settings > Cookies and site permissions. Rejecting cookies may limit services that require sign-in.
8. Privacy contacts and access requests
Requests under Article 35 of Korea's Personal Information Protection Act may be submitted to:
Chief Information Security Officer: Executive Director Seongguk Moon
Privacy contact: Principal Engineer Cheolho Yoo
Telephone: 070-4042-6752
Email: thc@mindwareworks.com
9. Notice of changes
Additions, deletions and revisions will be announced through the Company's notices or Privacy Policy page at least seven days before they take effect. Material changes affecting user rights, including collection, use or third-party provision, will be announced at least 30 days in advance.
Effective August 18, 2026.