Privacy Policy

Privacy Policy

Nearthlab values your privacy and processes personal information in compliance with applicable laws.

Nearthlab Inc. ("the Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the purposes set out below. Personal information being processed will not be used for any purpose other than those stated, and where the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

  • Inquiries and consultations: responding to product and service inquiries, quotation and demo requests, and media inquiries, and managing inquiry records
  • Service provision: delivering products and services, and concluding, performing, and settling contracts
  • Marketing and promotion: sending information on new services, newsletters, and events, only where separate consent has been obtained
  • Website operation: measuring access frequency, statistical analysis of service usage, and service improvement

Article 2 (Categories of Personal Information Processed)

The Company processes the following categories of personal information.

  • Website inquiry form: (required) company name, name and job title, phone number, email address, inquiry details / (optional) how you heard about us, reason for inquiry
  • Job applications: (required) name, phone number, email address, education and work experience, and information provided in the application
  • Information automatically generated and collected during service use: IP address, cookies, visit date and time, service usage records, device and browser information

Article 3 (Processing and Retention Period)

The Company processes and retains personal information within the retention and use period prescribed by law or the period consented to by the data subject at the time of collection.

The processing and retention periods are as follows.

  • Inquiry and consultation records: 3 years after the inquiry is resolved
  • Job application information: 1 year after the recruitment process ends (destroyed without delay upon the applicant’s request)
  • Records on contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
  • Records on payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
  • Records on consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
  • Website visit records: 3 months (Protection of Communications Secrets Act)

Article 4 (Provision of Personal Information to Third Parties)

The Company processes personal information only within the scope specified in Article 1, and provides personal information to third parties only where it falls under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.

The Company does not currently provide personal information to third parties. Should such provision become necessary, the Company will give prior notice of the recipient, purpose, categories of information, and retention period, and obtain consent.

Article 5 (Outsourcing of Personal Information Processing)

For smooth business operations, the Company outsources personal information processing tasks as follows.

  • Cloud infrastructure operation and data storage: domestic and overseas cloud service providers
  • Website operation and usage analytics: web hosting and analytics service providers
  • Email delivery and customer inquiry management: mailing and CRM solution providers

Article 6 (Rights and Obligations of Data Subjects and How to Exercise Them)

Data subjects may at any time request access to, correction of, deletion of, or suspension of processing of their personal information, and may withdraw consent.

Such rights may be exercised in writing or by email, and the Company will act on such requests without delay.

Where a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.

Rights may also be exercised through a legal representative or an authorized agent, in which case a power of attorney in the form prescribed by the applicable notification must be submitted.

Article 7 (Procedures and Methods for Destroying Personal Information)

When personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose, the Company destroys it without delay.

Where personal information must continue to be retained under other laws despite the expiry of the consented retention period or the achievement of the processing purpose, the Company transfers it to a separate database or stores it in a different location.

Method of destruction: electronic files are deleted using technical methods that make recovery impossible, and personal information recorded on paper is shredded or incinerated.

Article 8 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

  • Administrative measures: establishment and implementation of an internal management plan, and regular training for personnel handling personal information
  • Technical measures: access control for personal information processing systems, installation of access control systems, encryption of personal information, and installation and updating of security programs
  • Physical measures: access control for server rooms and document storage areas

Article 9 (Installation and Operation of Automatic Collection Devices, and Refusal Thereof)

The Company uses cookies to store and retrieve usage information in order to provide personalized services to users.

Cookies are small pieces of information sent by the server operating the website to the user’s browser, and may be stored on the user’s hard disk.

Users may refuse the storage of cookies through their web browser settings. However, refusing cookies may cause difficulties in using some services.

Article 10 (Personal Information Protection Officer)

The Company designates a Personal Information Protection Officer as follows, who is responsible for overseeing personal information processing and for handling complaints and remedying damages related to personal information processing.

  • Personal Information Protection Officer: Executive in charge of Corporate Support
  • Contact: +82-2-566-1574 / privacy@nearthlab.com
  • Address: 3F, 9, Jeongui-ro 8-gil, Songpa-gu, Seoul, 05836, Republic of Korea

Article 11 (Remedies for Infringement of Rights)

Data subjects may apply for dispute resolution or consultation with the following organizations to seek remedies for personal information infringement.

  • Personal Information Dispute Mediation Committee: +82-1833-6972 (www.kopico.go.kr)
  • Korea Internet & Security Agency Privacy Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors’ Office Cybercrime Investigation Division: 1301 (www.spo.go.kr)
  • National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)

Article 12 (Changes to This Privacy Policy)

This Privacy Policy takes effect on the effective date below. Where there are additions, deletions, or corrections due to changes in laws or policy, the Company will give notice through the website at least 7 days before the changes take effect.

Effective date: January 1, 2026