Effective: 8 August 2026
Version: 1.0
This English document is a convenience translation. If it differs from the Korean Privacy Policy, the Korean text governs.
Taemachim Co., Ltd. (the “Company”) processes personal information through its corporate website and public email channels as set out below.
1. Purpose, data, legal basis and retention
Email enquiries
| Item | Details |
|---|---|
| Purpose | Responding to general and project enquiries, pre-contract discussions, proposal and quotation discussions, and maintaining a record of the request |
| Data | Sender email address; name, organisation and telephone number supplied by the sender; message and attachments; transmission metadata such as sending and receiving time |
| Legal basis | Steps requested by the data subject before entering a contract under Article 15(1)(4) of the Personal Information Protection Act; for other general enquiries, the Company’s legitimate interest in responding and preventing disputes under Article 15(1)(6) |
| Retention | General enquiry without a contract: 180 days after the final reply. Proposal or quotation discussion: one year after the last contact. Privacy-right request or security report: three years after closure. |
If a paid contract is entered, records needed for performance, tax and accounting are separated from website enquiry records and managed under the contract and applicable law.
The Company does not ask for passwords, authentication credentials, Korean resident registration numbers or other unique identifiers, payment data, sensitive information or raw customer data by email. If unnecessary information is received, it is deleted without delay after any required protective step, and the sender may be asked to resend the message without it.
Website delivery and security
| Item | Details |
|---|---|
| Purpose | Delivering web content, maintaining availability, diagnosing faults, and detecting or blocking malicious traffic and attacks |
| Data | IP address, request time, requested URL or path, browser and device information contained in the user agent, response status and security events |
| Legal basis | The Company’s legitimate interest in reliable and secure delivery under Article 15(1)(6) of the Personal Information Protection Act |
| Retention | The Company does not separately collect HTTP request logs or store them through Logpush. Service-operating and security records processed by Cloudflare may be retained for the periods set out in the applicable service contract and published policies. |
The website has no accounts, sign-in, contact form, orders, payment, advertising, visitor-behaviour analytics or session replay.
2. Children
The website is not directed to children under 14 and does not intentionally collect their personal information. Information identified as belonging to a child under 14 is deleted without delay after any required protective step.
3. Disclosure to third parties
The Company does not disclose personal information to third parties. An exception may apply where the data subject gives separate consent or a specific law requires disclosure.
4. Processors
| Processor | Processing service |
|---|---|
| Cloudflare, Inc. | Public-site hosting and delivery, and the security features enabled in the actual deployment |
| Microsoft Corporation and the Microsoft 365 contracting provider for the Company | Email transmission and storage, spam and malware defence, service operation and support |
The Company applies purpose limitation, security, subprocessor management, return and deletion terms through the relevant service contracts. Current subprocessor lists are available from the official sources below.
- Cloudflare subprocessors: https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/
- Microsoft Online Services subprocessors: https://servicetrust.microsoft.com/Search?keyword=Subprocessors+List
5. Overseas processing
Personal information may be processed outside Korea for website delivery and email. The basis is Article 28-8(1)(3) of the Personal Information Protection Act, because the entrusted processing and storage are necessary to provide the website requested by the user or to take requested pre-contract steps.
Cloudflare
| Item | Details |
|---|---|
| Recipient | Cloudflare, Inc. and the published subprocessors used for the service |
| Contact | privacyquestions@cloudflare.com |
| Countries | Cloudflare network locations near the visitor and countries where published subprocessors operate. The current countries and providers follow the official subprocessor list above. |
| Time and method | Encrypted network transmission when a user accesses the website |
| Data | IP address, request time and path, user agent, response status and security event |
| Purpose | Content delivery, hosting, availability, DDoS and malicious-traffic protection |
| Retention | The Company does not separately retain HTTP request logs and does not use a Logpush job. Cloudflare operating and security records may be retained for the periods set out in the applicable service contract and published policies. |
| Refusal and effect | A user may refuse by not accessing the site. Web content will then be unavailable. The Chief Privacy Officer contact details are listed in section 11. |
Cloudflare’s South Korea PIPA information: https://www.cloudflare.com/trust-hub/south-korea-pipa/
Microsoft 365
| Item | Details |
|---|---|
| Recipient | Microsoft Corporation and published Microsoft Online Services subprocessors |
| Contact | https://aka.ms/privacyresponse |
| Countries | The Microsoft 365 data region where the Company tenant is provisioned and countries where published subprocessors support service security, operation and support |
| Time and method | Encrypted network transmission when a user emails the Company or the Company replies |
| Data | Sender address; name, organisation and telephone number supplied by the sender; message and attachments; transmission metadata |
| Purpose | Receiving, replying to and retaining an enquiry; spam and malware defence; email service operation and support |
| Retention | The Company deletes active-mailbox enquiry records under the 180-day, one-year and three-year periods in section 1. Deleted items may remain in a recovery area for a period determined by Microsoft 365 recovery and retention settings and any applicable legal hold. |
| Refusal and effect | A user may choose not to email. Email replies and file exchange will then be unavailable. Other contact options are listed on the Contact page. |
Microsoft provides the actual Exchange Online data location through the Microsoft 365 admin centre and its service commitments. The Company does not state an unverified country of storage in this Policy and manages the service against Microsoft’s data-location commitments and published subprocessor list.
6. Deletion
The Company regularly identifies and deletes personal information when its purpose is fulfilled or its retention period ends. Electronic files are removed using the account and service deletion functions; any paper output is shredded or incinerated. The Chief Privacy Officer reviews the deletion target and result.
After deletion from the active mailbox, any item remaining in a provider recovery area is restricted from ordinary access and is removed when the provider’s deletion cycle or an applicable retention obligation ends.
7. Data-subject rights
A data subject may request access, correction, deletion, suspension of processing or withdrawal of consent. A legal representative or authorised agent may make the request.
Requests may be made by email using the Chief Privacy Officer contact in section 11 or by calling the main telephone shown in the site footer. The Company verifies the requester or authorised representative and responds within the time and manner required by law. A request may be limited where another law requires retention or where it would infringe another person’s rights; the Company will explain the reason.
8. Security measures
The Company applies measures proportionate to the information and risk, including:
- Restricting access to people who need it for their work and reviewing that access periodically
- Strong authentication and account protection for administrators and email
- Encrypted transmission such as HTTPS
- Updates and vulnerability remediation for systems, tools and dependencies
- Malicious-traffic protection and security-event review
- Oversight of processors and subprocessor changes
- Scheduled deletion and processing records
9. Cookies and automatic collection
The website authored by the Company does not use cookies, localStorage or tracking pixels for visitor analytics, advertising or personalisation.
Cloudflare may set a cookie strictly necessary to block malicious traffic or perform a security check. It is not used for analytics or advertising. A browser may block cookies, but access can be limited when a security check is required.
Cloudflare cookie information: https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/
10. Automated decisions
The Company does not use this website to make an automated decision that has legal or similarly significant effects on an individual.
11. Chief Privacy Officer
- Name and position: 안지수, Representative
- Email: privacy@taemachim.com
- Address: (06158) 서울특별시 강남구 테헤란로79길 6, 3층 브이1439(삼성동, 제이에스타워), Republic of Korea
12. Remedies
- Personal Information Dispute Mediation Committee: +82 1833-6972, https://www.kopico.go.kr
- Personal Information Infringement Report Center: 118 within Korea, https://privacy.kisa.or.kr
- Korean National Police Cybercrime Report System: 182 within Korea, https://ecrm.police.go.kr
13. Changes
The Company publishes a change and its effective date on the website before it takes effect. A change that materially affects data-subject rights will be announced with reasonable notice.
- Version: 1.0
- Published: 8 August 2026
- Effective: 8 August 2026