Skip to main content

Privacy Policy

GrowBridge values your personal data and collects, uses and manages it under the standards below.

Effective : 2026.09.19

1장 General

We handle personal data with care and follow the procedures set by law. This policy explains what we collect, why we collect it, how long we keep it, and what rights you may exercise and how. Each chapter below opens on its own, and its contents are updated as law and our services change. For questions, please contact the team named in the final chapter.

Personal data means information about a living individual, namely:

가.Information that identifies a person on its own, such as a name.

나.Information not identifying on its own but easily combined with other data.

다.Pseudonymised forms of the above that cannot identify anyone without extra data.

We comply with the Personal Information Protection Act and related legislation.

This policy is amended as law or internal standards change, and amendments are posted without delay.

Earlier versions remain available separately, and you may request access, correction, deletion or suspension at any time.

See the delegation list for the list of processors.

2장 Purposes, items collected and retention periods

We process personal data only for the purposes listed below, and we ask for consent again if a purpose changes. We do not collect anything outside this table.

Once a retention period ends we destroy the data without delay. Where a law requires us to keep records, we separate and keep only the items that law names, for the period it sets.

Items collected and retention periods
ContextItemsPurposeRetention
EnquiriesEnquiry type, name, company, email, phone, subject, message (optional: department, budget range, attachments)Answering the enquiry and keeping a record3 years from receipt
Ethics reportsReport type, information about the person reported, when it occurred, title and body, attachments, a password for checking the outcome (for named reports, name and email or phone)Contacting you to verify, and notifying the outcome3 years from closure
Job applicationsName, email, phone, cover letter, résumé file (optional: portfolio URL)Running the hiring process and notifying the result1 year after the process ends
Access records (collected automatically)Time of access, address requested, IP address, browser and device detailsDiagnosing faults and blocking abusive access1 year from collection

3장 How consent to collection and use is obtained

Before collecting personal data we tell you the purpose, the items collected, how long we keep them, and that you may refuse — together with what happens if you do. We then ask for your consent.

Consent is taken in the consent box on each form, where you can open the full notice before choosing. Declining does not affect your use of the general pages such as the company or business sections.

Where the law allows processing without consent — to meet a legal obligation, or to protect someone's life, body or property in an emergency — we state the basis and process only what is necessary.

4장 Delegated processing

We delegate parts of the processing needed to run the service, as set out below. Each contract contains the terms required by Article 26 of the Act, and we supervise how the processor handles the data.

If the delegated work or the processor changes, we update this policy to say so.

Delegated processing
ProcessorDelegated workRetention
Amazon Web ServicesRunning servers and storage, and sending notification mail (Seoul region)Until the contract ends
Google LLCRunning the company mailboxUntil the contract ends

5장 Provision of data to third parties

We do not provide your personal data to third parties.

The exceptions are where a law specifically requires it, or where an investigative authority requests it through the procedure the law prescribes. Even then we check the basis and scope of the request and provide only the minimum required.

We do not transfer personal data overseas. Should that change, we will tell you who receives it, to which country, which items, when and how, for what purpose and for how long — and ask for your consent first.

6장 Destruction procedure and method

We destroy personal data without delay once its retention period ends or its purpose is met. Data due for destruction is kept apart from other data until an internal check confirms it, and is then destroyed.

Electronic files are deleted so that they cannot be recovered; anything printed on paper is shredded or incinerated.

Where a law requires retention, only the items that law names are kept apart for that period and are then destroyed in the same way.

7장 Automatic collection tools, their operation and refusal

As it serves your requests, our web server records the time, the address requested, your IP address and your browser and device details. This is to diagnose faults and to block abusive access.

This site does not set cookies to analyse visitors or to serve advertising. Cookies that identify a user are used only where the service requires them, such as signing in to the admin console.

You can block or delete cookies in your browser settings, and doing so does not affect your use of the general pages on this site. Server access records are not something a browser setting can refuse.

8장 Behavioural data: collection, use and refusal

We do not collect behavioural data on this site. We have not installed any tool that builds a profile of your interests from your browsing, or that uses it for targeted advertising.

There is therefore nothing you need to do to refuse it. If we ever adopt such a tool, we will first set out in this chapter what is collected, why, for how long, and how to refuse.

9장 Data sent through external service integrations, how it is handled and how to refuse

Some pages embed a view supplied by an outside provider — the map on the Location page and the introductory video.

Loading such a view may pass your IP address and browser details to that provider. We do not receive that information, and its handling is governed by that provider's own privacy policy.

If you would rather this did not happen, you can avoid those pages or use your browser's content-blocking. The rest of the site remains fully usable.

10장 Rights of data subjects and legal representatives

You, or your legal representative, may at any time ask to see your personal data, to correct or delete it, or to have its processing stopped. You may also withdraw your consent.

Requests may be made in writing or by email to the contact in Chapter 12, and we act on them without delay. Data subject to a correction or deletion request is neither used nor provided until the request has been carried out.

Data that a law requires us to collect cannot be deleted on request; in that case we tell you the basis. A representative acting for you must provide a document evidencing that authority.

11장 Measures to secure personal data

We take the following measures so that personal data is not lost, stolen, leaked, forged, altered or damaged.

Administrative — we keep the number of people who handle personal data to the minimum necessary and grant access according to role. Access is withdrawn without delay when a role changes.

Technical — we manage access rights, encrypt data in transit (HTTPS), and keep access logs. Servers are not reachable directly from outside; administration goes through a separate channel.

Physical — equipment holding personal data sits in facilities run by our processor, under that facility's access controls.

12장 Protection officer and contact

We have appointed the officer below to take overall charge of how personal data is processed and to handle enquiries, complaints and remedies.

Personal data protection officer — Yeonjung Koo, Chief Executive Officer of GrowBridge Co., Ltd. Requests to access personal data are received at the same place. Email contact@growbridge.co.kr, phone +82-10-2930-5574.

Please send any question about our handling of personal data to the contact above and we will reply without delay.

13장 Remedies for infringement

If you need help with an infringement of your personal data, you may consult the bodies below or apply to them to resolve a dispute.

Personal Information Dispute Mediation Committee 1833-6972 (www.kopico.go.kr) · Privacy Infringement Report Centre 118 (privacy.kisa.or.kr) · Supreme Prosecutors' Office 1301 (www.spo.go.kr) · National Police Agency 182 (ecrm.police.go.kr)

If a controller refuses or neglects a request made under Articles 35, 36 or 37 of the Act and your rights are harmed as a result, you may seek administrative appeal under the Administrative Appeals Act.

14장 Notice of changes

When this policy changes we post notice on this page at least seven days before it takes effect — thirty days if the change is to your disadvantage.

Earlier versions are kept together with their effective dates, and the “Effective” line above tells you which version is currently in force.

Revision history
RevisionEffectiveMain change
Enacted19 Sep 2026First version
Contact us