Personal InformationHandling Policy

Swiss Approval Korea (hereinafter referred to as the "Company") values the personal information of its users and complies with applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection.
The Company has established this Privacy Policy to protect users' rights and interests and to ensure that personal information is processed lawfully, fairly, and securely.
This Privacy Policy explains how the Company collects, uses, stores, and protects users' personal information, as well as the purposes for which such information is processed and the measures taken to safeguard it.
The Company may revise this Privacy Policy from time to time in accordance with applicable laws, regulations, or internal policies. Any changes will be announced through this website or by other appropriate means.

1. Processing of Personal Information Items and Purpose

Company processes Personal Information within the minimum necessary range to provide services.

① Processing Items

  • 1) Inquiry Processing Items upon Registration: Name, Contact Number, Email, Access Logs, Cookies, Access IP Information
  • 2) Items Automatically Generated and Processed During Website Usage: Access IP Information, Service Usage Records, Access Logs

② Processing Purpose

  • 1) User Identification, Response to User Inquiries, Complaint Processing such as Suggestions, Complaints, A/S Processing
  • 2) Understanding Access Frequency and Service Usage Statistics Processing for User Service Usage Analysis for Stable Service Operation and Quality Improvement

2. Provision of Personal Information to Third Parties

Company uses Personal Information within the scope of the purposes for which it was processed, and does not use Personal Information beyond that scope or provide it to third parties.

3. Processing and Retention Period of Personal Information, Destruction Procedures and Methods

After the purpose of processing and use is achieved, Personal Information will be destroyed without delay. However, for the following information, it will be retained for the specified period for the reasons listed below, and consent from the data subject will be obtained when necessary.

① Inquiry Processing Items upon Registration

  • 1) Retention Period: 2 years
  • 2) Reason for Retention: User Identification, Response to User Inquiries, Complaint Processing, Announcement Information Delivery

② Items Automatically Generated and Processed During Website Usage

  • 1) Retention Period: 1 year
  • 2) Reason for Retention: Understanding Access Frequency and Service Usage Statistics Processing

③ Destruction of Personal Information

  • 1) Destruction Procedure
    1. - When the retention period of Personal Information expires or the purpose of processing is achieved, Personal Information that is no longer necessary will be destroyed without delay.
    2. - Even after the retention period of Personal Information agreed by the data subject has elapsed or the processing purpose has been achieved, other Personal Information must be retained in accordance with other applicable laws. In such cases, the relevant Personal Information will be transferred to a separate database (DB) or stored in a different location to ensure continued retention.
  • 2) Destruction method
    1. - Personal Information recorded and saved in electronic file form will be deleted using technical methods that prevent record reproduction.
    2. - Personal Information recorded and saved in paper form will be shredded or incinerated.

4. Entrustment of Personal Information Processing

For smooth business processing, the company entrusts personal information processing to the following entities, and in accordance with related legislation, ensures that personal information is safely managed through entrustment contracts.

  • Entrustment Name (trustee): Gabia CNS
  • Entrustment Content: Website maintenance and system management, etc.
  • Personal Information Retention and Use Period: Until the end of the stated retention period and reason

5. Rights, Obligations and Exercise Methods of Users and Legal Representatives

① Data subjects can exercise their rights to access, correct, delete, and request the processing of their personal information at any time.

② Rights under Section ① above are exercised in accordance with Attached Form No. 8 of the Personal Information Protection Act Enforcement Rules and can be filed in writing, via email, or by fax, and we will take measures without delay.

③ Rights under Section ① above may be exercised through a legal representative or authorized agent of the data subject. In this case, a power of attorney must be submitted in accordance with Form No. 11 of the Personal Information Protection Act Enforcement Rules.

④ Requests for Personal Information disclosure and processing suspension are under Personal Information Protection Act Article 35 Paragraph 4, Article 37 Paragraph 2, and the rights of the data subject may be restricted.

⑤ Requests for correction and deletion of Personal Information are subject to other laws regarding that Personal Information, and if it is specified as a processing target, the deletion cannot be requested.

⑥ When requesting disclosure, correction, deletion, or stop processing of Personal Information pursuant to the rights of the data subject, we verify whether the requestor is the data subject or a legitimate representative.

6. Installation, Operation and Refusal of Automatic Personal Information Processing Devices

To provide personalized services for each item of the data subject, we do not use cookies to save and retrieve information.

7. Personal Information Privacy Officer

To protect Personal Information and handle complaints related to Personal Information processing, we have appointed the following: Personal Information Privacy Officer and related departments are designated as follows.

① Personal Information Privacy Officer

  • Name:
  • Position:
  • Contact Number:
  • Email:

② Department Responsible for Personal Information Protection

  • Department:
  • Contact Number:
  • Email:

8. Remedies for Rights Violations

① Data subjects can seek remedies for Personal Information violations through the Personal Information Dispute Resolution Committee, Korea Internet & Security Agency Personal Information Infringement Report Center etc. They can apply for dispute resolution or consultation. In addition, for other Personal Information infringement reports or consultations, please inquire at the following institutions.

② For requests from data subjects regarding disclosure, correction, deletion, or stop processing of Personal Information, actions taken by heads of public institutions may be subject to administrative trial if the rights or interests of the affected party are infringed.

9. Personal Information Security Measures

To ensure the security of Personal Information, we take the following measures:

  • Administrative Measures: Establishment and implementation of internal management plans, regular staff training, etc.
  • Technical Measures: Installation of access control systems, encryption of important information, prevention of computer virus damage using antivirus programs, network security using encryption algorithms, Personal Information transmission security devices (SSL), intrusion prevention system operation, etc.
  • Physical Measures: Access control to computer rooms, data storage rooms, etc.

10. Changes to Privacy Policy

This Privacy Policy is effective from April 30, 2026. (Initial notice)