Privacy Policy
This document is a translation of the original Korean version and is provided for your convenience. If there is any inconsistency between this translation and the Korean version, the Korean version will prevail, except to the extent otherwise required by applicable mandatory law. View the original Korean version
RozinMatch is not subject to this Policy — it operates under a separate membership system and a separate Privacy Policy.
1. Personal Information We Process
Common — Rich Unified Membership Account
Sign-Up / Account Management (Required)
Email address Password (stored as a one-way hash that cannot be restored)
Automatically Generated and Collected During Service Use
Access IP address · browser and OS information · access date/time Login success/failure history
Terms and Consent History
Internal identifier (a cryptographic transformation value stored in place of the raw email address; kept separate from account information) Action type (terms consent / privacy notice / optional consent, withdrawal, reconfirmation) · purpose of consent Document ID · version · basis for processing · time of occurrence · IP address (removed after 6 months)
Processed to verify the history of terms consent, privacy notices, and optional consents, and to respond to disputes. This internal identifier is not anonymous information — because the Company can recompute it with a secret key to link it back to the same individual, it is treated as personal information and is subject to separate access controls.
Items Not Collected as Mandatory at Sign-Up
Name · phone number · address · date of birth · gender
When Contacting Customer Support (Email) — the Company may process the email address, the content of the inquiry, and any contact information or attachments the user has voluntarily provided, for the purpose of handling the inquiry. When submitting an inquiry, please refrain from including a resident registration number, sensitive information, or original documents that are not necessary to resolve the inquiry.
When Sending an Inquiry From Within a Product — where a product has a feature for sending inquiries, improvement requests, or bug reports, the following information may be processed for the purpose of handling the inquiry, but only where the user chooses to send it directly. If you do not send it, nothing is transmitted.
Inquiry content Text entered directly by the user
Reply-to address Optional. Your inquiry is accepted even if left blank; if you
contacted us through your account and leave this blank, the
reply is sent to the address registered to your account
Time received · access IP · product · app version · installation type
Diagnostic information
and execution log Optional, off by default. Sent only if the user turns it
on — app/OS/runtime version, CPU model, component
installation status, license status, the name of the
connected scanner device, and the final portion of the
execution log left by the app. Because the execution log
may include the paths of files the user has handled, you
can review the full content before it is sent
The in-product inquiry feature does not include a function to attach original documents, scanned images, recognized text, or screen captures. Any text you enter directly into the inquiry field is transmitted as written, so please do not include personal information or document content that is unnecessary to resolve the inquiry.
Processing by Product
Data flows differently for each product. To avoid applying one product's characteristics across the board, each is described separately.
RichBinder (Desktop App) — what automatically communicates with the Company's servers is license and update information.
License ID or account ID · installation identifier · hash of the device identifier · PC name · app version · OS version Activation/deactivation time · trial start/end time · update entitlement expiration date
PC Name is simply the computer name set in Windows, transmitted as-is so that users can identify and deactivate activated devices from the account screen. If you have used your real name as the device name, that name is transmitted as-is; if you do not want this, please change the computer name in Windows settings before activating.
The RichBinder app does not automatically transmit original documents, scanned images, file names, file paths, OCR text, vendor names/amounts/dates, form samples, extracted metadata, or search terms to the Company's servers. What is automatically exchanged is the minimum information needed for license activation and update checks. However, where a user directly submits an inquiry or bug report, the inquiry content entered by the user and any diagnostic information the user has chosen to send may be transmitted to the Company and processed within the scope of handling that inquiry.
RichConvert Online Demo — uploaded files are not processed in the browser; they are transmitted to and stored on the Company's servers, then converted.
Uploaded original · conversion result · preview
→ stored in a private storage location on servers operated directly by the
Company (server-generated random file names)
→ no third-party cloud storage or external conversion service is used
→ expires 1 hour after upload; a cleanup job running every minute deletes them
→ password-protected PDFs have their protection removed once at upload, and are
stored for the retention period; the password entered is not itself stored or
logged
Job records (database)
→ original file name · internal server storage path · size · format ·
resolution · page count · conversion options · processing status and time ·
an anonymous identifier generated by the browser
→ does not include the file's content (pixels/document text). Records older
than 30 days are purged daily
Authentication Usable without sign-up or login. An anonymous identifier
(localStorage) used to distinguish job ownership, or, where that is not
transmitted, a session cookie (JSESSIONID) serving the same purpose
External No advertising or tracking tools are used. Visit statistics (Google
Analytics) operate only where consent has been given — see Sections 7 and 8.
Cloudflare Turnstile is not currently in use
The RichConvert Imaging SDK for Java runs directly within the customer's own environment and does not transmit original images, results, file names, or metadata externally. The above applies only to the online demo.
RichApiSim (Evaluation/Demo) — an API mock tool in which the server stores the request/response bodies entered by the user and returns them as-is.
Mock definitions (request path · request body · response headers · response body ·
webhook settings)
→ stored as plaintext JSON in a server file. No automatic expiration —
retained until the user deletes it from the admin screen
Incoming request records (access IP/port · full request headers · request body ·
response body)
→ the most recent 500 entries, held in server memory. Not stored on disk and
erased on restart
→ can be deleted entirely and immediately from the admin screen
Web server access records (IP · request path · browser information)
The admin console is used via Rich Unified Membership login. However,
the /mock/ path, used for machine-to-machine integration, uses a
separate access account (HTTP Basic) issued by the Company; this credential exists
only on the web server and is not linked to the Unified Membership account.
Stored data is not encrypted, and there is no change history (audit log) or backup. Because this is an evaluation/demo-only service, please do not enter actual personal information or trade secrets (Article 7 of the Terms of Service). If a user directly enters a webhook or integration URL into a mock, that request body and the content of incoming requests will be transmitted to the external address the user has designated. This is a transmission made according to the user's own configuration, not something the Company provides to a third party. No analytics or statistics tools are used.
2. Purpose and Legal Basis for Processing
| Purpose of Processing | Items | Legal Basis |
|---|---|---|
| Member identification/authentication, service provision | Email, password hash | Conclusion and performance of a contract (Article 15(1)(4) of the Personal Information Protection Act) |
| License issuance, device management | License ID, installation identifier, device hash, PC name, app/OS version | Performance of a contract |
| Notices/inquiry response (customer support) | Email, inquiry content, voluntarily provided information | Performance of a contract. The 3-year retention of records of transaction-related consumer complaints and dispute handling is performance of a statutory obligation under Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6(1)(4) of its Enforcement Decree (Article 15(1)(2) of the Personal Information Protection Act). Retention outside the scope reached by the statutory period is based solely on legitimate interest for dispute response purposes (Article 15(1)(6)), for the period set out in Section 3 |
| Retention of terms/consent history | Internal identifier, document version, time, IP | While membership continues = evidence of contract conclusion/performance. Retention for 5 years after withdrawal = legitimate interest for dispute response and the exercise/defense of legal rights (Article 15(1)(6)), kept to a minimum scope (IP removed after 6 months) |
| Prevention of fraudulent use, response to security incidents | IP, access records, login history | Legitimate interest (Article 15(1)(6)) — retained for 6 months |
| Product news/marketing | Consent (optional — may be withdrawn at any time) |
The Company does not use personal information for purposes other than those above. Where the purpose of processing changes, the Company will take the measures required under applicable law and reflect them in this Privacy Policy, and will obtain the data subject's consent where separate consent is required.
3. Retention/Use Period and Destruction
Principle: upon membership withdrawal, account personal information is destroyed without delay. Only the minimum information retained under a separate lawful basis in the table below, or for which another statute provides a retention ground, is kept separately for the period set for that purpose.
| Category | Period | Note |
|---|---|---|
| Member account information | Destroyed without delay upon withdrawal | A separate "account deactivation" feature is provided for cases requiring recovery |
| Login/user security logs | 6 months | Legitimate interest |
| Personal information handler/administrator access records | 2 years | Applies the safety-measure standard proactively |
| Terms/consent history | Duration of membership + 5 years after withdrawal | While active = evidence of contract / after withdrawal = legitimate interest. IP removed after 6 months |
| Deletion ledger | Destroyed without delay after the maximum backup retention period elapses | For the purpose of preventing restoration of personal information remaining in backups. Not retained permanently |
| General customer support inquiry records | 30 days after completion of processing | Technical inquiries, bug reports, feature questions, etc. Destroyed without delay once the purpose of processing has been fulfilled (Article 21(1) of the Personal Information Protection Act) |
| Records of transaction-related consumer complaints/dispute handling | 3 years | Records of complaints/disputes concerning transactions such as purchase, payment, subscription, cancellation, and refund. This is the statutory retention period under Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6(1)(4) of its Enforcement Decree, retained to perform a statutory obligation (Article 15(1)(2) of the Personal Information Protection Act). Not the entire inquiry is retained for 3 years — only the minimum scope needed to identify the matter, the result of processing, and the related transaction is kept |
| Inquiry attachments/diagnostic data | Deleted within 30 days after completion of processing | Includes raw diagnostic logs and diagnostic bundles. Not automatically folded into the 3-year record above |
| Login transactions/one-time codes | Deleted immediately upon use or expiration | |
| Expired/terminated sessions | Deleted after a maximum of 30 days | |
| RichConvert demo uploaded files | 1 hour after upload | Deleted by the cleanup job after expiration |
| RichConvert demo job records | 30 days | A destruction job runs daily |
| Database backups | Rotated at a maximum of 30 days | Fixed to the Seoul region |
Relationship Between Backup and Destruction. Members' personal information in the production database is deleted without delay upon withdrawal. Copies included in disaster-recovery backups are automatically deleted on a rotation cycle of up to 30 days, and are not used for general business purposes during that period. When a backup is restored, the deleted status is reapplied so that personal information that has already been withdrawn/deleted is not reactivated within the service.
Method of Destruction. Electronic files are deleted using a method that prevents recovery, and printed materials, where any exist, are shredded.
4. Provision to Third Parties
The Company does not provide users' personal information to third parties, except in the following cases.
- Where the user has given prior consent
- Where required by law, or requested by an investigative authority under the procedures prescribed by law
Paid Payment and Paddle
Payment for paid products is processed by Paddle. Paddle acts as the Authorized Reseller of the Company's products, entering into the sales contract directly with the purchaser and processing payment, while the Company acts as the supplier providing the product and the right to use it.
The entity to which the Company sends personal information is Paddle.com Market Limited (United Kingdom) or Paddle.com Inc. (United States), depending on the purchaser's location. Each entity's address, privacy contact, and the items/purpose/retention period of the transfer are set out in Section 7 below. The Paddle entity with which the purchaser actually enters into the sale contract may differ from this (see Section 7).
When initiating payment, the Company does not provide Paddle with the member's directly identifying information, such as email, name, address, or account identifier. What the Company sends to Paddle when opening the payment window is the order identifier · the product (plan) being purchased · the quantity (number of devices). The order identifier is a value used to tie that order together afterward and to recover it in the event of an error. The Company treats these three items as personal information. This is because the Company keeps this number linked to the member's account, and because, on the receiving side as well, it is stored together with the purchaser's information once payment is made. For this reason, the Company obtains consent as described below before initiating payment.
Information needed for payment (email, payment method, billing information, and business information where applicable) is not provided in advance by the Company; the purchaser enters it directly on Paddle's payment screen. Paddle collects and processes that information under its own responsibility, and that processing is governed by Paddle's own Privacy Policy.
Once payment is complete, the Company receives from Paddle the transaction result needed to grant the entitlement — the transaction/subscription/ payment-processor customer identifier, the product purchased, the amount and currency, the payment status, and the billing period. The Company does not store payment method information or the purchaser's email/name/address, and removes those items from the received record before storage.
However, "not stored" does not mean "cannot be seen." In its capacity as a seller, the Company can access Paddle's seller dashboard, and on that screen, within the scope necessary for order processing, inquiry handling, and refund processing, the Company may view information the purchaser has entered into Paddle (e.g., payment email, billing country/address). The Company does not copy this into the Company's own database for storage, and does not use it outside the purposes above.
Before initiating payment, the Company separately obtains two distinct consents — consent to provision to a third party (Article 17 of the Act) and consent to overseas transfer (Article 28-8(1)(1) of the Act). The two consents are presented separately, not bundled together, and payment will not begin if either is declined. Consent may be withdrawn even after being given, and withdrawal is effective for the future. The items sent and the recipients are set out in Section 7 below.
The email used for payment may differ from your member account email. The entitlement you purchase is linked to the member account that initiated the purchase, not to the payment email. The payment email is used as the address for receipts and payment-related notices.
5. Processing Entrustment
| Processor | Entrusted Task | Note |
|---|---|---|
| Zoho Corporation | Sign-up verification · password reset · sending/receiving service operation and customer support emails | This constitutes an overseas transfer — see Section 7 below |
| Amazon Web Services | Server infrastructure operation | Key customer data such as the account database is stored in South Korea (Seoul region), and no cross-region replication is used |
| Google LLC | Website visit statistics measurement/analysis (Google Analytics) | This constitutes an overseas transfer — see Section 7 below. Operates only where consent has been given |
The Company maintains an internal ledger of processors, entrusted tasks, processed data, countries of processing, and whether re-entrustment occurs, and reviews it periodically. This Privacy Policy is updated when the entrustment arrangement changes.
The payment processor (Paddle) is not included in this table. This is because it is not a processor entrusted with and performing the Company's business on its behalf, but a reseller that contracts directly with the purchaser and processes payment information under its own responsibility. See Section 4, "Paid Payment and Paddle," above.
6. User Rights and How to Exercise Them
Users may exercise the following rights at any time.
Request to access personal information · request for correction/deletion · request to suspend processing · withdrawal of consent
You can view, correct, or withdraw directly on the account screen, and you may withdraw consent to receive promotional information at any time, either from the account screen or via the unsubscribe link in a promotional email. You may also make a request to support@rozinsol.com. The Company will process the request and notify you of the result within 10 days of receipt.
These rights may also be exercised through a legal representative or an authorized agent, in which case documentation proving the authorization must be submitted.
7. Overseas Transfer
The Company uses Zoho Corporation's mail service for sign-up verification, password reset, and service operation/customer support emails. Accordingly, personal information may be processed and stored overseas, limited to information necessary in the course of sending and receiving email.
| Recipient | Zoho Corporation (Privacy Officer contact: dpo@zohocorp.com) |
|---|---|
| Recipient Country | United States |
| Items Transferred | Email address, email subject/body, files attached by the user |
| Purpose of Transfer | Member authentication · password reset · sending/receiving service operation and customer support emails |
| Time/Method of Transfer | Transmission over the network when sending/receiving email |
| Retention Period | The period under Zoho Mail's data retention policy and the Company's email retention policy |
| Legal Basis for Transfer | Article 28-8(1)(3)(a) of the Personal Information Protection Act — overseas processing entrustment/storage necessary for the conclusion and performance of a contract with the data subject, with the statutory matters under paragraph (2) of the same article disclosed in this Privacy Policy |
| Method/Procedure/Effect of Refusing Transfer | If you do not wish for an overseas transfer to occur, you may choose not to proceed with sign-up, or discontinue use of the account service (withdrawal). However, the Company will then be unable to provide the email services needed for account operation, such as email verification and password reset, and sign-up or certain account features may be limited. |
Scope Limitation. The scope of overseas transfer through Zoho Mail is limited to information necessary for the email service. The account database · password hashes · device information, RichBinder's document/OCR/form data, and RichConvert demo upload files are not included in the overseas transfer through Zoho Mail. Server infrastructure (including the account database) is configured to be stored in the AWS Seoul region (South Korea), and no cross-region replication is used.
Promotional emails are not emails for the performance of a contract and are therefore not grouped under the transfer basis above. When the Company begins sending promotional emails, it will separately determine the sending channel and the basis for overseas transfer and update this Policy.
| Recipient | Paddle.com Market Limited (purchasers outside the United States) 30 Old Bailey, London, EC4M 7AU, United Kingdom Paddle.com Inc. (U.S. purchasers) 3811 Ditmars Blvd, #1071 Astoria, New York, NY 11105-1803, USA Privacy inquiries: privacy@paddle.com |
|---|---|
| Recipient Country | United Kingdom · United States Under its agreements, Paddle assigns sales related to U.S. purchasers to Paddle.com Inc., and all other sales to Paddle.com Market Limited. Because the purchaser's location may not yet be determined at the time consent is obtained, both entities are disclosed. |
| Items Transferred | Order identifier · product (plan) being purchased · quantity (number of devices) Account email · name · address · payment method are not sent in advance — that information is entered directly by the user on the payment screen. |
| Purpose of Transfer | Payment · order processing, and failure recovery |
| Time/Method of Transfer | After the user completes consent prior to initiating payment, sent via HTTPS when creating a transaction with the payment processor |
| Retention Period | For as long as the relationship with Paddle continues, and for the period required or permitted by applicable law (including the applicable statute-of-limitations period and the subsequent administrative processing period, and, where a claim, investigation, or dispute is ongoing, until its conclusion) |
| Legal Basis for Transfer | Article 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent. Consent to overseas transfer is obtained separately from this Privacy Policy before payment is initiated. |
| Method/Procedure/Effect of Refusing Transfer | You may decline on the consent screen before initiating payment. If you decline, you will not be able to use payment through Paddle. Declining has no effect on sign-up or free use. Consent may also be withdrawn after being given, and withdrawal is effective for the future. |
The Selling Entity Plays a Different Role. The above identifies the party to which the Company sends personal information; which entity the purchaser actually contracts with for the sale is separately determined by Paddle's Buyer Terms (depending on the purchaser's location, a Canadian entity may be the selling entity). The two are not combined in the same table.
The Company also uses Google Analytics (GA4) to measure visit statistics. It operates only where consent has been given via the consent banner at the bottom of the screen, and if you do not consent, this tool does not run at all. Declining has no effect on using the introduction, login, inquiries, or other services.
| Recipient | Google LLC (United States) |
|---|---|
| Recipient Country | United States |
| Items Transferred | Access device/browser information, pages visited, approximate location (city level), a non-identifying client identifier (cookie) |
| Purpose of Transfer | Website visit statistics measurement/analysis |
| Time/Method of Transfer | Transmission over the network at the time of accessing the website, where consent has been given |
| Retention Period | The period under Google Analytics' data retention settings (up to 14 months) |
| Legal Basis for Transfer | Article 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent |
| Method/Procedure/Effect of Refusing Transfer | Select [Decline] on the consent banner at the bottom of the screen, and this tool will not be loaded. Even where consent has already been given, you may change your choice to Decline at any time from "Change Analytics Consent" at the bottom of the landing page. Changing to Decline clears the analytics cookies and reloads the page, and no further data is sent to Google from that point on. Statistics already transmitted remain with Google for its retention period (up to 14 months) — withdrawal is effective only for the future. You may also withdraw at any time using the Google Analytics Opt-out Browser Add-on or by clearing your browser storage. Declining or withdrawing has no negative effect whatsoever on your use of the service. |
Personally identifying information such as name or email is never sent to Google Analytics in any case, and no advertising- or tracking-purpose tools are used. RichBinder's document/OCR/form data and RichConvert demo upload files are also not included.
8. Automatically Collected Devices (Cookies) and Analytics Tools
The Company uses cookies necessary for login/authentication and cookies for measuring visit statistics. Cookies for advertising or behavioral-information collection purposes are not used.
To measure visit statistics for the websites (rozinsol.com · richbinder.com · richconvert.com · richapisim.com · the payment screen of account.rozinsol.com), the Company uses Google Analytics (GA4). It operates only where consent has been given via the consent banner at the bottom of the screen, and if you do not consent, this tool does not run at all. Where consent has been given, the following information is transmitted to its operator, Google LLC (United States). This constitutes an overseas transfer, and the statutory disclosure items are set out together in Section 7 above.
| Operator | Google LLC (United States) |
|---|---|
| Information Transmitted | Access device/browser information, pages visited, approximate location (city level), a non-identifying client identifier issued by Google (cookie) |
| Purpose | Website visit statistics measurement/analysis |
| Retention Period | The period under Google Analytics' data retention settings (up to 14 months) |
| Legal Basis | Article 28-8(1)(1) of the Personal Information Protection Act — the data subject's separate consent (overseas processing entrustment) |
| How to Decline | Select [Decline] on the consent banner. Where consent has already been given, you may also withdraw from "Change Analytics Consent" at the bottom of the landing page, or using the Google Analytics Opt-out Browser Add-on or by clearing your browser storage. Statistics already transmitted remain for the retention period. Declining has no effect on your use of the service — it is not used for login or service provision. |
Personally identifying information such as name or email, User-ID, or advertising-purpose data is not sent to Google Analytics, and Google Signals or ad-linking features are not used. RichBinder's document/OCR/form data and RichConvert demo upload files are also not included.
| Cookie | Purpose | Retention |
|---|---|---|
__Host-rich_sso | Maintains unified login state | Until session expiry or logout |
__Host-rich_session | Maintains the authentication state for each Rich product | Until session expiry or termination |
__Host-rich_txn | Verification during the login process (CSRF prevention) | Expires within a few minutes |
_ga / _ga_* | Distinguishes Google Analytics visitors (non-identifying). Created only where consent has been given | Up to 2 years |
The analytics tool does not run where [Decline] is selected on the
consent banner, so the _ga cookie is also not created. You may also
decline cookie storage in your browser settings. Declining
__Host-rich_* cookies will prevent you from using features that
require login; declining the analytics tool will only exclude you from visit
statistics measurement, while other features such as login remain usable.
Whether you have consented is remembered as the value
rs_analytics_consent in your browser's storage (localStorage), and
this value is not transmitted to the server. You may change this value at any
time from "Change Analytics Consent" at the bottom of the
landing page; changing to Decline also clears the analytics cookies.
9. Measures to Ensure Safety
Passwords stored as a one-way hash (Argon2id) that cannot be restored Encryption in transit (HTTPS) Minimization of access privileges and retention of access records Limiting the number of failed login attempts and temporary lockout Access control over personal information processing systems
10. Personal Information Protection Officer
Officer SangTae Jeong (Representative) Contact support@rozinsol.com
Users may submit inquiries, complaints, and requests for relief related to personal information protection to the above contact. The Company will respond and process such matters without delay.
Other Reporting/Consultation Bodies
Personal Information Infringement Report Center privacy.kisa.or.kr / 118 (no area code) Personal Information Dispute Mediation Committee kopico.go.kr / 1833-6972 Supreme Prosecutors' Office Cyber Investigation Division spo.go.kr / 1301 (no area code) National Police Agency Cyber Investigation Bureau ecrm.police.go.kr / 182 (no area code)
11. Changes to This Privacy Policy
This Privacy Policy applies from August 10, 2026. Changes and their effective date will be disclosed on the service screen before they take effect. Where a change has a material effect on the rights or obligations of data subjects, or where applicable law requires separate consent or notice, the relevant procedure will be followed. Previous versions of this Privacy Policy can be found on the Legal Notices page.
| Version | Revision Date | Changes |
|---|---|---|
| 1.3.0 | 2026-09-24 | Added "Change Analytics Consent" at the bottom of the landing page as a further method for withdrawing consent to the analytics tool (Google Analytics), and noted that changing to Decline clears the analytics cookies and that statistics already transmitted remain for the retention period (withdrawal is effective for the future). |
| 1.2.0 | 2026-09-15 | Reflected the in-product inquiry feature in Section 1. (1) The RichBinder section had flatly stated that "the only thing communicating with the Company's servers is license/update information." Once a feature for sending inquiries, improvement requests, or bug reports from within the product exists, that statement is no longer accurate, so it was revised to "what is automatically exchanged is license/update information," and inquiries sent directly by users were separately disclosed. (2) Added to Section 1 the items processed for in-product inquiries (inquiry content, the optional reply address, the time/IP/product/version received, and diagnostic information and execution logs sent only where the user has turned them on). Attaching original documents, scanned images, recognized text, or screen captures is not a function that exists at all. (3) Split out the "customer support inquiry records" line in the retention-period table in Section 3. Previously, 3 years had been applied to all inquiries. The 3-year period is the transaction- record retention period set under the E-Commerce Act, but the scope that law actually covers is records of consumer complaints/dispute handling related to transactions, so to avoid applying 3 years to general technical inquiries and bug reports, it was split into general inquiries: 30 days · transaction-related complaint/ dispute records: 3 years · attachments and diagnostic data: 30 days, with each basis stated. The legal-basis column in Section 2 was aligned on the same basis. This is not a shortening or lengthening of any retention period — it is a correction to accurately scope where the statutory period applies. |
| 1.1.6 | 2026-09-01 | A consistency correction aligning Section 4 with Section 7. Nothing new is collected or provided. (1) Section 4 had listed only one payment-processor location (the United Kingdom), while Section 7 listed two recipients (UK · US) — an inconsistency within the same document. Both are now listed together, and it is noted that the Paddle entity with which the purchaser actually contracts for the sale may differ. (2) Corrected a passage that had described the order identifier as "a value that cannot by itself identify a person." Because the Company keeps this number linked to the member's account, and because it is also stored together with the purchaser's information on the receiving side, the order identifier · product · quantity are now treated as personal information — this is the reason the Company obtains consent before payment. Also corrected the header's "Last Revised" date, which had been out of step with the 1.1.5 revision date (08-28) |
| 1.1.5 | 2026-08-28 | Added Paddle's overseas transfer to Section 7. Although Section 4 describes the payment flow, Section 7 (Overseas Transfer) had not mentioned Paddle, creating an inconsistency in which the consent screen shown before payment disclosed two recipients (UK · US) while this Policy did not mention that transfer. The items sent, recipient, purpose, timing, retention period, basis, and effect of refusal were recorded as required by law. The basis differs from Zoho's — Article 28-8(1)(3)(a) (processing entrustment/storage necessary for contract performance) does not apply to Paddle, because the Company does not direct or supervise Paddle, and Paddle contracts with the purchaser in its own name. For that reason the basis here is Article 28-8(1)(1) (separate consent). This was not a new transmission that began — it records in this Policy a transfer for which consent was already being obtained. |
| 1.1.4 | 2026-08-25 | Ahead of the start of paid sales, reflected the payment flow in Section 4 — payment is processed by Paddle as a reseller; the Company does not provide members' personal information to Paddle when initiating payment, and the purchaser enters it directly on Paddle's screen. Also recorded the scope of the transaction results the Company receives afterward, and that payment method, email, name, and address are not stored. Section 5 added why the payment processor is not a processor entrusted with the Company's business. This was not a new collection that began — it corrected a flow that had not previously been disclosed. (Same-day wording correction — narrowed "does not provide personal information" to "does not provide directly identifying information," and clarified the nature of the order identifier sent along with it. A sentence asserting a legal characterization outright was also changed to a factual description.) |
| 1.1.3 | 2026-08-15 | Corrected Sections 1 and 2 to match the items actually transmitted by RichBinder account linkage — added installation identifier · PC name. This was not a new collection that began; it corrected an omission in the disclosure of items already being transmitted. Also added guidance in Section 1 noting that the PC name may contain the user's real name, and the measure available in that case |
| 1.1.2 | 2026-08-12 | Added the payment screen of account.rozinsol.com to the scope of the analytics tool in Section 8 (instrumentation for measuring the start of payment). Processing content and legal basis are the same as in 1.1.0 |
| 1.1.1 | 2026-08-12 | Added richapisim.com to the scope of the analytics tool in Section 8 (that site converted to a public introduction page and applies the same consent gate). Processing content and legal basis are the same as in 1.1.0 |
| 1.1.0 | 2026-08-11 | Reflected the introduction of Google Analytics (GA4). Treating this as overseas processing entrustment, added Google LLC to the entrustment table in Section 5, recorded the statutory overseas-transfer disclosure items (recipient, items, purpose, method, retention period, basis, method of refusal) in Section 7, and newly disclosed Section 8 (Automatically Collected Devices and Analytics Tools). The basis for transfer is Article 28-8(1)(1) (separate consent of the data subject), and the analytics tool is not loaded before consent is given |
| 1.0.0 | 2026-08-10 | Initial enactment |