ROZIN Solution — Software & Imaging Solutions

Privacy Policy

This document is a translation of the original Korean version and is provided for your convenience. If there is any inconsistency between this translation and the Korean version, the Korean version will prevail, except to the extent otherwise required by applicable mandatory law. View the original Korean version

Version 1.3.0 Effective Date August 10, 2026 Last Revised September 24, 2026
ROZIN Solution (hereinafter the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act in order to protect users' personal information and promptly handle related grievances. This Policy applies to Rich Unified Membership and to RichBinder · RichConvert · RichApiSim.

RozinMatch is not subject to this Policy — it operates under a separate membership system and a separate Privacy Policy.

1. Personal Information We Process

Common — Rich Unified Membership Account

Sign-Up / Account Management (Required)

Email address
Password      (stored as a one-way hash that cannot be restored)

Automatically Generated and Collected During Service Use

Access IP address · browser and OS information · access date/time
Login success/failure history

Terms and Consent History

Internal identifier (a cryptographic transformation value stored in place of the raw
email address; kept separate from account information)
Action type (terms consent / privacy notice / optional consent, withdrawal,
reconfirmation) · purpose of consent
Document ID · version · basis for processing · time of occurrence · IP address
(removed after 6 months)

Processed to verify the history of terms consent, privacy notices, and optional consents, and to respond to disputes. This internal identifier is not anonymous information — because the Company can recompute it with a secret key to link it back to the same individual, it is treated as personal information and is subject to separate access controls.

Items Not Collected as Mandatory at Sign-Up

Name · phone number · address · date of birth · gender

When Contacting Customer Support (Email) — the Company may process the email address, the content of the inquiry, and any contact information or attachments the user has voluntarily provided, for the purpose of handling the inquiry. When submitting an inquiry, please refrain from including a resident registration number, sensitive information, or original documents that are not necessary to resolve the inquiry.

When Sending an Inquiry From Within a Product — where a product has a feature for sending inquiries, improvement requests, or bug reports, the following information may be processed for the purpose of handling the inquiry, but only where the user chooses to send it directly. If you do not send it, nothing is transmitted.

Inquiry content        Text entered directly by the user
Reply-to address       Optional. Your inquiry is accepted even if left blank; if you
                       contacted us through your account and leave this blank, the
                       reply is sent to the address registered to your account
Time received · access IP · product · app version · installation type

Diagnostic information
and execution log       Optional, off by default. Sent only if the user turns it
                        on — app/OS/runtime version, CPU model, component
                        installation status, license status, the name of the
                        connected scanner device, and the final portion of the
                        execution log left by the app. Because the execution log
                        may include the paths of files the user has handled, you
                        can review the full content before it is sent

The in-product inquiry feature does not include a function to attach original documents, scanned images, recognized text, or screen captures. Any text you enter directly into the inquiry field is transmitted as written, so please do not include personal information or document content that is unnecessary to resolve the inquiry.

Processing by Product

Data flows differently for each product. To avoid applying one product's characteristics across the board, each is described separately.

RichBinder (Desktop App) — what automatically communicates with the Company's servers is license and update information.

License ID or account ID · installation identifier · hash of the device identifier ·
PC name · app version · OS version
Activation/deactivation time · trial start/end time · update entitlement expiration
date

PC Name is simply the computer name set in Windows, transmitted as-is so that users can identify and deactivate activated devices from the account screen. If you have used your real name as the device name, that name is transmitted as-is; if you do not want this, please change the computer name in Windows settings before activating.

The RichBinder app does not automatically transmit original documents, scanned images, file names, file paths, OCR text, vendor names/amounts/dates, form samples, extracted metadata, or search terms to the Company's servers. What is automatically exchanged is the minimum information needed for license activation and update checks. However, where a user directly submits an inquiry or bug report, the inquiry content entered by the user and any diagnostic information the user has chosen to send may be transmitted to the Company and processed within the scope of handling that inquiry.

RichConvert Online Demo — uploaded files are not processed in the browser; they are transmitted to and stored on the Company's servers, then converted.

Uploaded original · conversion result · preview
   → stored in a private storage location on servers operated directly by the
     Company (server-generated random file names)
   → no third-party cloud storage or external conversion service is used
   → expires 1 hour after upload; a cleanup job running every minute deletes them
   → password-protected PDFs have their protection removed once at upload, and are
     stored for the retention period; the password entered is not itself stored or
     logged

Job records (database)
   → original file name · internal server storage path · size · format ·
     resolution · page count · conversion options · processing status and time ·
     an anonymous identifier generated by the browser
   → does not include the file's content (pixels/document text). Records older
     than 30 days are purged daily

Authentication  Usable without sign-up or login. An anonymous identifier
      (localStorage) used to distinguish job ownership, or, where that is not
      transmitted, a session cookie (JSESSIONID) serving the same purpose
External  No advertising or tracking tools are used. Visit statistics (Google
      Analytics) operate only where consent has been given — see Sections 7 and 8.
      Cloudflare Turnstile is not currently in use

The RichConvert Imaging SDK for Java runs directly within the customer's own environment and does not transmit original images, results, file names, or metadata externally. The above applies only to the online demo.

RichApiSim (Evaluation/Demo) — an API mock tool in which the server stores the request/response bodies entered by the user and returns them as-is.

Mock definitions (request path · request body · response headers · response body ·
webhook settings)
   → stored as plaintext JSON in a server file. No automatic expiration —
     retained until the user deletes it from the admin screen

Incoming request records (access IP/port · full request headers · request body ·
response body)
   → the most recent 500 entries, held in server memory. Not stored on disk and
     erased on restart
   → can be deleted entirely and immediately from the admin screen

Web server access records (IP · request path · browser information)

The admin console is used via Rich Unified Membership login. However, the /mock/ path, used for machine-to-machine integration, uses a separate access account (HTTP Basic) issued by the Company; this credential exists only on the web server and is not linked to the Unified Membership account.

Stored data is not encrypted, and there is no change history (audit log) or backup. Because this is an evaluation/demo-only service, please do not enter actual personal information or trade secrets (Article 7 of the Terms of Service). If a user directly enters a webhook or integration URL into a mock, that request body and the content of incoming requests will be transmitted to the external address the user has designated. This is a transmission made according to the user's own configuration, not something the Company provides to a third party. No analytics or statistics tools are used.

2. Purpose and Legal Basis for Processing

Purpose of ProcessingItemsLegal Basis
Member identification/authentication, service provisionEmail, password hash Conclusion and performance of a contract (Article 15(1)(4) of the Personal Information Protection Act)
License issuance, device managementLicense ID, installation identifier, device hash, PC name, app/OS version Performance of a contract
Notices/inquiry response (customer support)Email, inquiry content, voluntarily provided information Performance of a contract. The 3-year retention of records of transaction-related consumer complaints and dispute handling is performance of a statutory obligation under Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6(1)(4) of its Enforcement Decree (Article 15(1)(2) of the Personal Information Protection Act). Retention outside the scope reached by the statutory period is based solely on legitimate interest for dispute response purposes (Article 15(1)(6)), for the period set out in Section 3
Retention of terms/consent historyInternal identifier, document version, time, IP While membership continues = evidence of contract conclusion/performance. Retention for 5 years after withdrawal = legitimate interest for dispute response and the exercise/defense of legal rights (Article 15(1)(6)), kept to a minimum scope (IP removed after 6 months)
Prevention of fraudulent use, response to security incidentsIP, access records, login history Legitimate interest (Article 15(1)(6)) — retained for 6 months
Product news/marketingEmail Consent (optional — may be withdrawn at any time)

The Company does not use personal information for purposes other than those above. Where the purpose of processing changes, the Company will take the measures required under applicable law and reflect them in this Privacy Policy, and will obtain the data subject's consent where separate consent is required.

3. Retention/Use Period and Destruction

Principle: upon membership withdrawal, account personal information is destroyed without delay. Only the minimum information retained under a separate lawful basis in the table below, or for which another statute provides a retention ground, is kept separately for the period set for that purpose.

CategoryPeriodNote
Member account informationDestroyed without delay upon withdrawal A separate "account deactivation" feature is provided for cases requiring recovery
Login/user security logs6 monthsLegitimate interest
Personal information handler/administrator access records2 years Applies the safety-measure standard proactively
Terms/consent historyDuration of membership + 5 years after withdrawal While active = evidence of contract / after withdrawal = legitimate interest. IP removed after 6 months
Deletion ledgerDestroyed without delay after the maximum backup retention period elapses For the purpose of preventing restoration of personal information remaining in backups. Not retained permanently
General customer support inquiry records30 days after completion of processing Technical inquiries, bug reports, feature questions, etc. Destroyed without delay once the purpose of processing has been fulfilled (Article 21(1) of the Personal Information Protection Act)
Records of transaction-related consumer complaints/dispute handling3 years Records of complaints/disputes concerning transactions such as purchase, payment, subscription, cancellation, and refund. This is the statutory retention period under Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6(1)(4) of its Enforcement Decree, retained to perform a statutory obligation (Article 15(1)(2) of the Personal Information Protection Act). Not the entire inquiry is retained for 3 years — only the minimum scope needed to identify the matter, the result of processing, and the related transaction is kept
Inquiry attachments/diagnostic dataDeleted within 30 days after completion of processing Includes raw diagnostic logs and diagnostic bundles. Not automatically folded into the 3-year record above
Login transactions/one-time codesDeleted immediately upon use or expiration
Expired/terminated sessionsDeleted after a maximum of 30 days
RichConvert demo uploaded files1 hour after upload Deleted by the cleanup job after expiration
RichConvert demo job records30 daysA destruction job runs daily
Database backupsRotated at a maximum of 30 daysFixed to the Seoul region

Relationship Between Backup and Destruction. Members' personal information in the production database is deleted without delay upon withdrawal. Copies included in disaster-recovery backups are automatically deleted on a rotation cycle of up to 30 days, and are not used for general business purposes during that period. When a backup is restored, the deleted status is reapplied so that personal information that has already been withdrawn/deleted is not reactivated within the service.

Method of Destruction. Electronic files are deleted using a method that prevents recovery, and printed materials, where any exist, are shredded.

4. Provision to Third Parties

The Company does not provide users' personal information to third parties, except in the following cases.

  1. Where the user has given prior consent
  2. Where required by law, or requested by an investigative authority under the procedures prescribed by law

Paid Payment and Paddle

Payment for paid products is processed by Paddle. Paddle acts as the Authorized Reseller of the Company's products, entering into the sales contract directly with the purchaser and processing payment, while the Company acts as the supplier providing the product and the right to use it.

The entity to which the Company sends personal information is Paddle.com Market Limited (United Kingdom) or Paddle.com Inc. (United States), depending on the purchaser's location. Each entity's address, privacy contact, and the items/purpose/retention period of the transfer are set out in Section 7 below. The Paddle entity with which the purchaser actually enters into the sale contract may differ from this (see Section 7).

When initiating payment, the Company does not provide Paddle with the member's directly identifying information, such as email, name, address, or account identifier. What the Company sends to Paddle when opening the payment window is the order identifier · the product (plan) being purchased · the quantity (number of devices). The order identifier is a value used to tie that order together afterward and to recover it in the event of an error. The Company treats these three items as personal information. This is because the Company keeps this number linked to the member's account, and because, on the receiving side as well, it is stored together with the purchaser's information once payment is made. For this reason, the Company obtains consent as described below before initiating payment.

Information needed for payment (email, payment method, billing information, and business information where applicable) is not provided in advance by the Company; the purchaser enters it directly on Paddle's payment screen. Paddle collects and processes that information under its own responsibility, and that processing is governed by Paddle's own Privacy Policy.

Once payment is complete, the Company receives from Paddle the transaction result needed to grant the entitlement — the transaction/subscription/ payment-processor customer identifier, the product purchased, the amount and currency, the payment status, and the billing period. The Company does not store payment method information or the purchaser's email/name/address, and removes those items from the received record before storage.

However, "not stored" does not mean "cannot be seen." In its capacity as a seller, the Company can access Paddle's seller dashboard, and on that screen, within the scope necessary for order processing, inquiry handling, and refund processing, the Company may view information the purchaser has entered into Paddle (e.g., payment email, billing country/address). The Company does not copy this into the Company's own database for storage, and does not use it outside the purposes above.

Before initiating payment, the Company separately obtains two distinct consents — consent to provision to a third party (Article 17 of the Act) and consent to overseas transfer (Article 28-8(1)(1) of the Act). The two consents are presented separately, not bundled together, and payment will not begin if either is declined. Consent may be withdrawn even after being given, and withdrawal is effective for the future. The items sent and the recipients are set out in Section 7 below.

The email used for payment may differ from your member account email. The entitlement you purchase is linked to the member account that initiated the purchase, not to the payment email. The payment email is used as the address for receipts and payment-related notices.

5. Processing Entrustment

ProcessorEntrusted TaskNote
Zoho Corporation Sign-up verification · password reset · sending/receiving service operation and customer support emails This constitutes an overseas transfer — see Section 7 below
Amazon Web Services Server infrastructure operation Key customer data such as the account database is stored in South Korea (Seoul region), and no cross-region replication is used
Google LLC Website visit statistics measurement/analysis (Google Analytics) This constitutes an overseas transfer — see Section 7 below. Operates only where consent has been given

The Company maintains an internal ledger of processors, entrusted tasks, processed data, countries of processing, and whether re-entrustment occurs, and reviews it periodically. This Privacy Policy is updated when the entrustment arrangement changes.

The payment processor (Paddle) is not included in this table. This is because it is not a processor entrusted with and performing the Company's business on its behalf, but a reseller that contracts directly with the purchaser and processes payment information under its own responsibility. See Section 4, "Paid Payment and Paddle," above.

6. User Rights and How to Exercise Them

Users may exercise the following rights at any time.

Request to access personal information · request for correction/deletion · request
to suspend processing · withdrawal of consent

You can view, correct, or withdraw directly on the account screen, and you may withdraw consent to receive promotional information at any time, either from the account screen or via the unsubscribe link in a promotional email. You may also make a request to support@rozinsol.com. The Company will process the request and notify you of the result within 10 days of receipt.

These rights may also be exercised through a legal representative or an authorized agent, in which case documentation proving the authorization must be submitted.

7. Overseas Transfer

The Company uses Zoho Corporation's mail service for sign-up verification, password reset, and service operation/customer support emails. Accordingly, personal information may be processed and stored overseas, limited to information necessary in the course of sending and receiving email.

RecipientZoho Corporation (Privacy Officer contact: dpo@zohocorp.com)
Recipient CountryUnited States
Items TransferredEmail address, email subject/body, files attached by the user
Purpose of TransferMember authentication · password reset · sending/receiving service operation and customer support emails
Time/Method of TransferTransmission over the network when sending/receiving email
Retention PeriodThe period under Zoho Mail's data retention policy and the Company's email retention policy
Legal Basis for TransferArticle 28-8(1)(3)(a) of the Personal Information Protection Act — overseas processing entrustment/storage necessary for the conclusion and performance of a contract with the data subject, with the statutory matters under paragraph (2) of the same article disclosed in this Privacy Policy
Method/Procedure/Effect of Refusing TransferIf you do not wish for an overseas transfer to occur, you may choose not to proceed with sign-up, or discontinue use of the account service (withdrawal). However, the Company will then be unable to provide the email services needed for account operation, such as email verification and password reset, and sign-up or certain account features may be limited.

Scope Limitation. The scope of overseas transfer through Zoho Mail is limited to information necessary for the email service. The account database · password hashes · device information, RichBinder's document/OCR/form data, and RichConvert demo upload files are not included in the overseas transfer through Zoho Mail. Server infrastructure (including the account database) is configured to be stored in the AWS Seoul region (South Korea), and no cross-region replication is used.

Promotional emails are not emails for the performance of a contract and are therefore not grouped under the transfer basis above. When the Company begins sending promotional emails, it will separately determine the sending channel and the basis for overseas transfer and update this Policy.

RecipientPaddle.com Market Limited (purchasers outside the United States)
30 Old Bailey, London, EC4M 7AU, United Kingdom
Paddle.com Inc. (U.S. purchasers)
3811 Ditmars Blvd, #1071 Astoria, New York, NY 11105-1803, USA
Privacy inquiries: privacy@paddle.com
Recipient CountryUnited Kingdom · United States
Under its agreements, Paddle assigns sales related to U.S. purchasers to Paddle.com Inc., and all other sales to Paddle.com Market Limited. Because the purchaser's location may not yet be determined at the time consent is obtained, both entities are disclosed.
Items TransferredOrder identifier · product (plan) being purchased · quantity (number of devices)
Account email · name · address · payment method are not sent in advance — that information is entered directly by the user on the payment screen.
Purpose of TransferPayment · order processing, and failure recovery
Time/Method of TransferAfter the user completes consent prior to initiating payment, sent via HTTPS when creating a transaction with the payment processor
Retention PeriodFor as long as the relationship with Paddle continues, and for the period required or permitted by applicable law (including the applicable statute-of-limitations period and the subsequent administrative processing period, and, where a claim, investigation, or dispute is ongoing, until its conclusion)
Legal Basis for TransferArticle 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent. Consent to overseas transfer is obtained separately from this Privacy Policy before payment is initiated.
Method/Procedure/Effect of Refusing TransferYou may decline on the consent screen before initiating payment. If you decline, you will not be able to use payment through Paddle. Declining has no effect on sign-up or free use. Consent may also be withdrawn after being given, and withdrawal is effective for the future.

The Selling Entity Plays a Different Role. The above identifies the party to which the Company sends personal information; which entity the purchaser actually contracts with for the sale is separately determined by Paddle's Buyer Terms (depending on the purchaser's location, a Canadian entity may be the selling entity). The two are not combined in the same table.

The Company also uses Google Analytics (GA4) to measure visit statistics. It operates only where consent has been given via the consent banner at the bottom of the screen, and if you do not consent, this tool does not run at all. Declining has no effect on using the introduction, login, inquiries, or other services.

RecipientGoogle LLC (United States)
Recipient CountryUnited States
Items TransferredAccess device/browser information, pages visited, approximate location (city level), a non-identifying client identifier (cookie)
Purpose of TransferWebsite visit statistics measurement/analysis
Time/Method of TransferTransmission over the network at the time of accessing the website, where consent has been given
Retention PeriodThe period under Google Analytics' data retention settings (up to 14 months)
Legal Basis for TransferArticle 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent
Method/Procedure/Effect of Refusing TransferSelect [Decline] on the consent banner at the bottom of the screen, and this tool will not be loaded. Even where consent has already been given, you may change your choice to Decline at any time from "Change Analytics Consent" at the bottom of the landing page. Changing to Decline clears the analytics cookies and reloads the page, and no further data is sent to Google from that point on. Statistics already transmitted remain with Google for its retention period (up to 14 months) — withdrawal is effective only for the future. You may also withdraw at any time using the Google Analytics Opt-out Browser Add-on or by clearing your browser storage. Declining or withdrawing has no negative effect whatsoever on your use of the service.

Personally identifying information such as name or email is never sent to Google Analytics in any case, and no advertising- or tracking-purpose tools are used. RichBinder's document/OCR/form data and RichConvert demo upload files are also not included.

8. Automatically Collected Devices (Cookies) and Analytics Tools

The Company uses cookies necessary for login/authentication and cookies for measuring visit statistics. Cookies for advertising or behavioral-information collection purposes are not used.

To measure visit statistics for the websites (rozinsol.com · richbinder.com · richconvert.com · richapisim.com · the payment screen of account.rozinsol.com), the Company uses Google Analytics (GA4). It operates only where consent has been given via the consent banner at the bottom of the screen, and if you do not consent, this tool does not run at all. Where consent has been given, the following information is transmitted to its operator, Google LLC (United States). This constitutes an overseas transfer, and the statutory disclosure items are set out together in Section 7 above.

OperatorGoogle LLC (United States)
Information TransmittedAccess device/browser information, pages visited, approximate location (city level), a non-identifying client identifier issued by Google (cookie)
PurposeWebsite visit statistics measurement/analysis
Retention PeriodThe period under Google Analytics' data retention settings (up to 14 months)
Legal BasisArticle 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent (overseas processing entrustment)
How to DeclineSelect [Decline] on the consent banner. Where consent has already been given, you may also withdraw from "Change Analytics Consent" at the bottom of the landing page, or using the Google Analytics Opt-out Browser Add-on or by clearing your browser storage. Statistics already transmitted remain for the retention period. Declining has no effect on your use of the service — it is not used for login or service provision.

Personally identifying information such as name or email, User-ID, or advertising-purpose data is not sent to Google Analytics, and Google Signals or ad-linking features are not used. RichBinder's document/OCR/form data and RichConvert demo upload files are also not included.

CookiePurposeRetention
__Host-rich_ssoMaintains unified login state Until session expiry or logout
__Host-rich_sessionMaintains the authentication state for each Rich product Until session expiry or termination
__Host-rich_txnVerification during the login process (CSRF prevention) Expires within a few minutes
_ga / _ga_*Distinguishes Google Analytics visitors (non-identifying). Created only where consent has been givenUp to 2 years

The analytics tool does not run where [Decline] is selected on the consent banner, so the _ga cookie is also not created. You may also decline cookie storage in your browser settings. Declining __Host-rich_* cookies will prevent you from using features that require login; declining the analytics tool will only exclude you from visit statistics measurement, while other features such as login remain usable.

Whether you have consented is remembered as the value rs_analytics_consent in your browser's storage (localStorage), and this value is not transmitted to the server. You may change this value at any time from "Change Analytics Consent" at the bottom of the landing page; changing to Decline also clears the analytics cookies.

9. Measures to Ensure Safety

Passwords stored as a one-way hash (Argon2id) that cannot be restored
Encryption in transit (HTTPS)
Minimization of access privileges and retention of access records
Limiting the number of failed login attempts and temporary lockout
Access control over personal information processing systems

10. Personal Information Protection Officer

Officer   SangTae Jeong (Representative)
Contact   support@rozinsol.com

Users may submit inquiries, complaints, and requests for relief related to personal information protection to the above contact. The Company will respond and process such matters without delay.

Other Reporting/Consultation Bodies

Personal Information Infringement Report Center    privacy.kisa.or.kr / 118 (no area code)
Personal Information Dispute Mediation Committee    kopico.go.kr / 1833-6972
Supreme Prosecutors' Office Cyber Investigation Division    spo.go.kr / 1301 (no area code)
National Police Agency Cyber Investigation Bureau    ecrm.police.go.kr / 182 (no area code)

11. Changes to This Privacy Policy

This Privacy Policy applies from August 10, 2026. Changes and their effective date will be disclosed on the service screen before they take effect. Where a change has a material effect on the rights or obligations of data subjects, or where applicable law requires separate consent or notice, the relevant procedure will be followed. Previous versions of this Privacy Policy can be found on the Legal Notices page.

VersionRevision DateChanges
1.3.02026-09-24 Added "Change Analytics Consent" at the bottom of the landing page as a further method for withdrawing consent to the analytics tool (Google Analytics), and noted that changing to Decline clears the analytics cookies and that statistics already transmitted remain for the retention period (withdrawal is effective for the future).
1.2.02026-09-15 Reflected the in-product inquiry feature in Section 1. (1) The RichBinder section had flatly stated that "the only thing communicating with the Company's servers is license/update information." Once a feature for sending inquiries, improvement requests, or bug reports from within the product exists, that statement is no longer accurate, so it was revised to "what is automatically exchanged is license/update information," and inquiries sent directly by users were separately disclosed. (2) Added to Section 1 the items processed for in-product inquiries (inquiry content, the optional reply address, the time/IP/product/version received, and diagnostic information and execution logs sent only where the user has turned them on). Attaching original documents, scanned images, recognized text, or screen captures is not a function that exists at all. (3) Split out the "customer support inquiry records" line in the retention-period table in Section 3. Previously, 3 years had been applied to all inquiries. The 3-year period is the transaction- record retention period set under the E-Commerce Act, but the scope that law actually covers is records of consumer complaints/dispute handling related to transactions, so to avoid applying 3 years to general technical inquiries and bug reports, it was split into general inquiries: 30 days · transaction-related complaint/ dispute records: 3 years · attachments and diagnostic data: 30 days, with each basis stated. The legal-basis column in Section 2 was aligned on the same basis. This is not a shortening or lengthening of any retention period — it is a correction to accurately scope where the statutory period applies.
1.1.62026-09-01 A consistency correction aligning Section 4 with Section 7. Nothing new is collected or provided. (1) Section 4 had listed only one payment-processor location (the United Kingdom), while Section 7 listed two recipients (UK · US) — an inconsistency within the same document. Both are now listed together, and it is noted that the Paddle entity with which the purchaser actually contracts for the sale may differ. (2) Corrected a passage that had described the order identifier as "a value that cannot by itself identify a person." Because the Company keeps this number linked to the member's account, and because it is also stored together with the purchaser's information on the receiving side, the order identifier · product · quantity are now treated as personal information — this is the reason the Company obtains consent before payment. Also corrected the header's "Last Revised" date, which had been out of step with the 1.1.5 revision date (08-28)
1.1.52026-08-28 Added Paddle's overseas transfer to Section 7. Although Section 4 describes the payment flow, Section 7 (Overseas Transfer) had not mentioned Paddle, creating an inconsistency in which the consent screen shown before payment disclosed two recipients (UK · US) while this Policy did not mention that transfer. The items sent, recipient, purpose, timing, retention period, basis, and effect of refusal were recorded as required by law. The basis differs from Zoho's — Article 28-8(1)(3)(a) (processing entrustment/storage necessary for contract performance) does not apply to Paddle, because the Company does not direct or supervise Paddle, and Paddle contracts with the purchaser in its own name. For that reason the basis here is Article 28-8(1)(1) (separate consent). This was not a new transmission that began — it records in this Policy a transfer for which consent was already being obtained.
1.1.42026-08-25 Ahead of the start of paid sales, reflected the payment flow in Section 4 — payment is processed by Paddle as a reseller; the Company does not provide members' personal information to Paddle when initiating payment, and the purchaser enters it directly on Paddle's screen. Also recorded the scope of the transaction results the Company receives afterward, and that payment method, email, name, and address are not stored. Section 5 added why the payment processor is not a processor entrusted with the Company's business. This was not a new collection that began — it corrected a flow that had not previously been disclosed. (Same-day wording correction — narrowed "does not provide personal information" to "does not provide directly identifying information," and clarified the nature of the order identifier sent along with it. A sentence asserting a legal characterization outright was also changed to a factual description.)
1.1.32026-08-15 Corrected Sections 1 and 2 to match the items actually transmitted by RichBinder account linkage — added installation identifier · PC name. This was not a new collection that began; it corrected an omission in the disclosure of items already being transmitted. Also added guidance in Section 1 noting that the PC name may contain the user's real name, and the measure available in that case
1.1.22026-08-12 Added the payment screen of account.rozinsol.com to the scope of the analytics tool in Section 8 (instrumentation for measuring the start of payment). Processing content and legal basis are the same as in 1.1.0
1.1.12026-08-12 Added richapisim.com to the scope of the analytics tool in Section 8 (that site converted to a public introduction page and applies the same consent gate). Processing content and legal basis are the same as in 1.1.0
1.1.02026-08-11 Reflected the introduction of Google Analytics (GA4). Treating this as overseas processing entrustment, added Google LLC to the entrustment table in Section 5, recorded the statutory overseas-transfer disclosure items (recipient, items, purpose, method, retention period, basis, method of refusal) in Section 7, and newly disclosed Section 8 (Automatically Collected Devices and Analytics Tools). The basis for transfer is Article 28-8(1)(1) (separate consent of the data subject), and the analytics tool is not loaded before consent is given
1.0.02026-08-10Initial enactment