Decasight Co., Ltd.
Decasight Co., Ltd. (주식회사 데카사이트, hereinafter the “Company”) hereby establishes and discloses the following Privacy Policy (hereinafter this “Policy”) pursuant to Article 30 of the Personal Information Protection Act (PIPA), in order to protect the freedom and rights of data subjects, to explain the procedures and standards applicable to the processing of personal information, and to handle related grievances promptly and smoothly.
This Policy applies to all processing of personal information arising in connection with the use of the products and services provided by the Company (including the CLOVEE product line) and of the Company’s website.
The Company processes personal information to the minimum extent necessary for the following purposes. Personal information that has been processed shall not be used for any purpose other than those set out below, and where the purpose is changed, the Company shall take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Act.
Conclusion and performance of product purchase contracts: Processed for the conclusion of purchase contracts for products sold by the Company (including the CLOVEE product line), shipment of products, billing and receipt of payment, and performance of contractual rights and obligations. [Legal basis: Article 15(1)4 of the Act (conclusion and performance of a contract)]
Issuance, activation, and management of licenses: Processed for the issuance of software license keys, verification of license validity (including transmission to the lmsapi.decasight.com server), management of registered devices, and prevention of license violations. [Legal basis: Article 15(1)4 of the Act (performance of a contract)]
Customer inquiries (including pre-purchase inquiries such as product consultations and demo requests), technical support (after-sales service), and warranty handling: Processed for responding to pre-purchase inquiries such as product consultations and demo requests, responding to technical inquiries, handling product defects, and providing warranty services such as returns, exchanges, and repairs. [Legal basis: Article 15(1)4 of the Act (measures taken at the data subject's request in the process of concluding a contract, and performance of a contract)]
Collection of diagnostic data and product improvement: For the purposes of software error analysis and product quality improvement, the Company intends to process diagnostic data in the future solely where separate opt-in consent has been obtained from the user. The Company shall separately request such consent before the relevant function is activated.
Performance of statutory obligations: Processed in order to perform legal obligations, such as the retention of transaction records, under relevant statutes including the Act on the Consumer Protection in Electronic Commerce. [Legal basis: Article 15(1)2 of the Act (compliance with statutory obligations)]
Website operation and assurance of service stability: Processed for the analysis of website access logs, content delivery optimization (CDN), detection of security threats, and similar purposes. [Legal basis: Article 15(1)6 of the Act (legitimate interests)]
The Company processes the following items of personal information.
| Item | Purpose of Collection |
|---|---|
| Name | Verification of the contracting party |
| Affiliated institution / company name | Verification of the contracting party |
| Email address | Contract and license guidance, delivery of notices |
| Contact information (telephone number) | Delivery, after-sales service, and response to inquiries |
| License key | License issuance, verification of the authenticity of registration requests, and verification and management of license validity |
| Delivery address | Product delivery and receipt of returned or repaired items |
| Refund account information | Refund of payment upon withdrawal of subscription or return (only where payment was made by bank transfer) |
The Company processes the items below solely with respect to inquiries received by email or telephone.
| Item | Purpose of Collection |
|---|---|
| Name | Identification of the inquirer |
| Affiliated institution / company name | Identification of the party consulted, provision of quotations and demonstrations |
| Email address | Response to inquiries and notification of the results |
| Content of the inquiry | Technical support and after-sales service handling |
During software installation and license activation, the following items are automatically transmitted to the Company’s activation server (lmsapi.decasight.com). The processing of these items constitutes mandatory processing that is indispensable for license activation (legal basis: Article 15(1)4 of the Act — where necessary for the performance of a contract). As this is technical processing essential to the provision of the service, it is carried out without a separate consent procedure, and this fact is notified at the time of installation.
| Item | Purpose of Collection | |
|---|---|---|
| Hardware identifier (HWID) | Identification of the device registered to the license | |
| Camera device identifier (VID/PID) | Verification of the validity of the registered hardware | |
| Country information | Identification of the region in which an activation error occurs | |
| Time zone | Identification of the time at which an activation error occurs | |
| License module version | Validity verification by version | |
| Product activation information (activation code) | License activation and binding to the registered device, periodic revalidation, and detection of misuse and unauthorized use | |
| IP address | Identification of the device making the activation request, security monitoring | |
| Operation history (type, stage, result, and time of occurrence of operations such as registration, verification, deregistration, and execution) | Verification of license usage status, analysis of misuse and error causes | |
| Client information (User-Agent) | Identification of the client making the activation request, analysis of error causes | |
Note. The Company processes the above items solely for the purposes of license activation and the resolution of related disputes, and prohibits any use for other purposes. Execution history generated while offline is temporarily stored on the user’s device and is then automatically transmitted to the Company’s activation server at the time of the next online authentication, after which it is deleted from the device. In addition, during license authentication the Company generates a one-time password (OTP) and sends it to the user’s email address. The value is stored only as a one-way hash and is deleted immediately upon successful authentication or reissuance; the sending record is included in the “Operation history” above.
The Company intends to collect the following diagnostic data for the purposes of software error analysis and product quality improvement. These items are subject to opt-in consent; the Company separately requests consent upon the first execution of the software and collects such data solely where consent has been given. Even if consent is not given, the user shall suffer no disadvantage whatsoever in using the core functions of the software (license activation, tracking, data recording, and the like). Users may withdraw their consent at any time from the settings menu of the software, and upon withdrawal collection ceases immediately and the data already collected is destroyed.
(Legal basis: Article 15(1)1 of the Act — consent of the data subject)
| Item | Purpose of Collection |
|---|---|
| Crash dumps (Crashpad) | Analysis of the causes of software errors |
| Application logs | Error reproduction and quality improvement |
| Software version information | Error analysis by version |
| OS environment information | Error analysis by environment |
For the purposes of website operation and security, the Company automatically collects the following items when a user accesses the website. [Legal basis: Article 15(1)6 of the Act (legitimate interests)]
| Item | Purpose of Collection |
|---|---|
| IP address, access logs | Prevention of unauthorized use, detection of security threats |
| Cookies, browser information | Optimization of website content, verification of the access environment |
The above items are retained for three months from the date of collection and are thereafter destroyed, and may be processed through overseas operators (such as Cloudflare) for the purposes of content delivery optimization (CDN) and security. For further details, please refer to Article 3 (Processing and Retention Periods of Personal Information), Article 6 (Overseas Transfer of Personal Information), and Article 10 (Installation, Operation, and Refusal of Devices that Automatically Collect Personal Information).
The Company processes and retains personal information within the retention and use period prescribed by statute or the retention and use period consented to by the data subject at the time of collection, and destroys such personal information without delay once the relevant period has elapsed or the purpose of processing has been achieved.
| Relevant Statute | Retained Information | Retention Period |
|---|---|---|
| Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc. and Article 6 of its Enforcement Decree | Records on labelling and advertising | 6 months |
| Ditto | Records on contracts or withdrawal of subscription | 5 years |
| Ditto | Records on payment and the supply of goods | 5 years |
| Ditto | Records on consumer complaints or dispute resolution | 3 years |
| Article 85-3 of the Framework Act on National Taxes | Books and supporting documents on all transactions prescribed by tax law | 5 years |
| Processing Item | Retention Period | Basis |
|---|---|---|
| License activation and usage logs (registration, verification, deregistration, and execution history) | 3 years from the date of collection (the date the log was generated) | Dispute resolution and license management |
| Customer inquiry and after-sales service records | 3 years from the date of completion of handling | Resolution of consumer complaints and disputes |
| Diagnostic data (opt-in) | 1 year from the date of consent, following the commencement of collection | Consent of the data subject |
| Website access logs (IP addresses, access date and time, browser information, etc.) | 3 months | Prevention of misuse and security |
The Company retains and analyses website access logs for three months for the purpose of detecting and preventing abnormal access attempts and misuse, in order to provide a secure service environment. Such processing is carried out to pursue the legitimate interests of the Company under Article 15(1)6 of the Personal Information Protection Act. The Company has weighed the likelihood of infringement of the rights of data subjects against its own legitimate interests and has confirmed that its legitimate interests reasonably prevail, and such processing is carried out only to the minimum extent necessary to achieve that purpose.
Notice on the commencement of diagnostic data collection. At the time the diagnostic data collection pipeline is established and actual collection commences, the Company shall separately request consent from users. The retention period for data collected following such consent is one year from the date of consent, and the Company shall give notice as to renewal before expiry. Where renewed consent is not given or no response is received, the data shall be destroyed immediately. Consent may be withdrawn at any time from the settings menu of the software, and the data shall be destroyed immediately upon withdrawal.
The Company processes the personal information of data subjects only within the scope specified in Article 1 and does not provide it to third parties without the consent of the data subject. The following cases, however, shall constitute exceptions.
Where the data subject has given prior consent
Where there are special provisions in a statute or where it is unavoidable in order to comply with statutory obligations (for example, a lawful request from an investigative agency)
Where it is deemed necessary for the urgent life, bodily, or property interests of the data subject or a third party
The Company entrusts part of the work necessary for the provision of its services to external providers, and stipulates in writing the matters necessary to ensure that the entrusted party processes personal information safely in accordance with the Personal Information Protection Act, and supervises the same. Personal information entrusted to a trustee is retained until the purpose of the entrusted work is achieved or the entrustment agreement is terminated.
| Trustee | Location | Scope of Entrusted Work |
|---|---|---|
| Cloudflare, Inc. | U.S.A. | Relay of website and license activation traffic, content delivery optimization (CDN), and detection and blocking of security threats such as DDoS |
| Microsoft Corporation | U.S.A. | Transmission, receipt and storage of customer inquiry email; sending of license authentication notification emails (authentication codes and security alerts) |
Where a data subject does not use a service corresponding to the “Scope of Entrusted Work” set out below, no personal information is provided to the relevant trustee.
| Trustee | Location | Scope of Entrusted Work |
|---|---|---|
| Korea Post (Korea Post Parcel Service) | Republic of Korea | Delivery of products |
| CJ Logistics Corporation | Republic of Korea | Delivery of products |
When entering into an entrustment agreement, the Company stipulates in the agreement, in accordance with Article 26 of the Personal Information Protection Act, the prohibition of processing personal information beyond the purpose of performing the entrusted work, technical and managerial protective measures, and the prohibition of re-entrustment without the Company’s consent, and supervises whether the trustee processes personal information safely.
Overseas trustees may engage their own sub-processors for the provision of their services. The relevant lists are published by each provider and may be found at the following:
For further details on the transfer of personal information to overseas trustees, please refer to Article 6 (Overseas Transfer of Personal Information).
In the course of providing its services, the Company entrusts the processing of personal information to the overseas providers set out below. As this constitutes a case where the entrustment or storage of personal information is necessary for the conclusion and performance of a contract with the data subject, the Company discloses the following matters pursuant to Article 28-8(1)3(a) of the Personal Information Protection Act.
A data subject may refuse the overseas transfer of personal information. Such transfer can be avoided by not using the website, or by making inquiries by telephone (+82-2-851-1272) or by post instead of by email; a data subject may also notify the personal information protection officer designated in Article 12 of a refusal in writing or by email. Where a data subject refuses the overseas transfer, use of services that necessarily entail such transfer — including use of the website and the handling of inquiries by email — may be restricted, in which case the same inquiry or consultation may be made by telephone or by post.
| Country of transfer | U.S.A. (Cloudflare operates data processing locations worldwide; the full list is available at https://www.cloudflare.com/en-gb/network/) |
|---|---|
| Time and method of transfer | Transmitted over the information and communications network at the time the website and the license activation service are used |
| Contact of the transferee | [email protected] / 101 Townsend St. San Francisco, CA 94107, USA (Attn: Data Protection Officer) |
| Personal information transferred | IP address, access logs, cookies and other browser information / license activation data (hardware identifier (HWID), camera device identifier, product activation information, operation history, client information (User-Agent)) |
| Purpose of transfer | Relay of website and license activation traffic, content delivery optimization (CDN), and detection and blocking of security threats such as DDoS |
| Retention and use period | Until termination of the entrustment agreement |
| Country of transfer | U.S.A. |
|---|---|
| Time and method of transfer | Transmitted over the information and communications network at the time customer inquiry email is sent or received and at the time license authentication notifications are sent |
| Contact of the transferee | Microsoft Privacy, One Microsoft Way, Redmond, WA 98052, USA / +1 (425) 882-8080 Domestic representative in Korea: Microsoft Korea, Inc. (12F, Tower A, The K Twin Towers, 50 Jong-ro 1-gil, Jongno-gu, Seoul / +82-2-722-7725 / [email protected]) |
| Personal information transferred | Name, email address, affiliated institution / company name, contact number, content of the inquiry, and license authentication number (OTP) and authentication notification records |
| Purpose of transfer | Transmission, receipt and storage of customer inquiry email; sending of license authentication notification emails |
| Retention and use period | Until termination of the entrustment agreement |
The Company does not collect the personal information of children under the age of 14. The products and services provided by the Company (including the CLOVEE product line) and the Company’s website are medical devices and software for research and development, intended for professional use, and are not directed at children under the age of 14. Where the Company becomes aware that the personal information of a child under the age of 14 has been collected, it shall destroy such personal information without delay.
The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved. However, where personal information must be preserved pursuant to other statutes, the Company transfers such personal information to a separate database (DB) or stores it separately in a different storage location. In such case, the grounds for preservation and the items of personal information preserved are as set out in Article 3 (Processing and Retention Periods of Personal Information).
Destruction procedure: Upon expiry of the retention period or achievement of the purpose of processing, the Company identifies the personal information subject to destruction and destroys it upon the approval of the Chief Privacy Officer. However, items for which a retention period is fixed, such as website access logs, are destroyed periodically through an automated process. Personal information contained in backups is automatically deleted once the backup retention cycle (up to 14 days) has elapsed.
Destruction method: Electronic files are permanently deleted by technical methods that render recovery or reproduction impossible, and paper printouts are shredded or incinerated.
Data subjects may exercise the following rights against the Company at any time.
Request for access to personal information
Request for correction or deletion of personal information
Request for suspension of the processing of personal information
Withdrawal of consent to the processing of personal information
Request to refuse an automated decision, or for an explanation thereof
Method of exercise: The above rights may be exercised by submitting a request to the personal information protection officer designated in Article 12 by email ([email protected]), by telephone (+82-2-851-1272) or in writing. The Company will reply with the outcome within 10 days from the date of the request. Where there is a justifiable reason why the request cannot be handled within that period, the Company will notify the data subject of the reason and may postpone the handling, and will handle the request without delay once that reason ceases to exist.
These rights may also be exercised through the data subject’s legal representative or a duly authorized agent. In such case, a power of attorney in the form prescribed in Annex Form No. 11 of the Public Notice on the Methods of Processing Personal Information must be submitted. The Company verifies whether the person exercising the right is the data subject or a duly authorized agent.
The Company may restrict or refuse access, after notifying the data subject of the reason, in the following cases.
Where the personal information concerned is expressly required to be collected by other statutes, its deletion may not be requested; in such case the Company will notify the data subject of that fact without delay.
A request for suspension of processing or a withdrawal of consent may be refused where a ground prescribed by statute applies, such as where performance of the contract would become difficult; in such case the Company will notify the data subject of the reason without delay.
Where a data subject requests the correction of an error in personal information, the Company will not use or provide the personal information concerned until the correction has been completed.
Where a data subject objects to a refusal or other measure taken by the Company, the data subject may raise an objection with the personal information protection officer designated in Article 12. Upon receipt of an objection, the Company will review it without delay and reply with the outcome; the data subject may also apply for dispute mediation or other relief with the institutions listed in Article 13 (Remedies for Infringement of Rights).
The Company does not make automated decisions that have a material effect on the rights or obligations of data subjects, such as credit assessment or recruitment screening. However, software license activation is carried out through an automated process; as this constitutes processing necessary for the performance of a contract with the data subject, it is not subject to the right of refusal under the proviso to Article 37-2(1) of the Personal Information Protection Act. A data subject may request an explanation of the activation outcome at any time, and the items and purposes of the personal information processed in the activation process are disclosed in Article 2.
The above rights may be exercised in the same manner in respect of personal information transferred overseas under Article 6, and the Company will require the relevant trustees to take the measures necessary to give effect to them.
The Company may install and operate cookies in order to provide a convenient website experience to users. A cookie is a very small text file sent by the server operating a website to the user’s browser and stored on the user’s device.
Functions essential to the provision of the service, such as maintaining a session while the website is in use
Analysis of usage statistics and service improvement, such as counting visitors
Retention of display settings selected by the user, such as text size
Remembering whether notice pop-ups have been dismissed (e.g. a “do not show today” selection)
Security, such as blocking automated or abnormal traffic
| Name | Purpose | Retention period |
|---|---|---|
| PHPSESSID | Maintaining a session while the website is in use | Until the browser is closed |
| ck_visit_ip | Preventing duplicate counting of visitors | 24 hours |
| ck_font_resize_add_class ck_font_resize_rmv_class |
Retaining the text size selected by the user | 24 hours |
| hd_pops_* | Remembering a “do not show” selection for notice pop-ups | As configured for each pop-up |
| cf_clearance | Security, such as blocking automated or abnormal traffic (set by Cloudflare, Inc. — see Article 6) | 1 year |
※ Some cookies are stored in the browser under hashed names. In addition, on pages that include third-party services such as maps, those services may set their own cookies.
※ Where the Company introduces a new device that automatically collects personal information, it shall reflect the type and purpose of that device in this Policy and give prior notice in accordance with Article 14 (Amendment of the Privacy Policy).
Users have the right to choose whether to allow cookies. Through browser settings, users may allow cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies, and may also delete cookies that have already been stored.
Chrome (PC): Settings > Privacy and security > Third-party cookies
Edge (PC): Settings > Cookies and site permissions > Manage and delete cookies and site data
Safari (Mac): Safari > Settings > Privacy
Chrome (mobile): Settings > Site settings > Third-party cookies
Safari (iOS): Settings > Safari > Advanced > Block All Cookies
Samsung Internet: Settings > Internet history > Cookies and site data
※ Menu names and paths may differ depending on the browser version.
Effect of refusal: Even if the storage of cookies is refused, there is no impediment to viewing information on the website. However, the use of functions that require a session may be limited, and settings selected by the user — such as text size or a “do not show” selection for pop-ups — may not be retained.
The Company implements the following measures in order to ensure the safety of personal information.
Minimization and training of personnel: The Company limits the number of employees who process personal information to the minimum and provides training on personal information protection to personal information handlers.
Management of access rights: Access rights to the personal information processing system are limited to the minimum scope necessary to perform duties. Where responsible personnel change or leave the Company, their access rights are changed or revoked without delay.
Access control: The Company installs and operates access control devices to block access by unauthorized persons to its personal information processing systems, and external connections are permitted only through secure access methods.
Encryption of personal information: SSL/TLS encryption is applied to transmission and reception over information and communications networks. License keys and hardware identifiers (HWID) are encrypted or one-way hashed when stored. In addition, names, email addresses, telephone numbers, and license keys recorded in logs are automatically masked at the time of storage.
Retention and review of access records: The Company retains and manages records of access by personal information handlers to the personal information processing system, and takes measures to prevent such access records from being forged, altered, stolen, or lost.
Prevention of malicious programs: The Company installs security programs, such as anti-malware software, and updates and reviews them periodically.
Physical safety measures: The personal information processing system is operated within facilities directly managed and controlled by the Company, and physical access by unauthorized persons to the location where servers and storage media are kept is controlled.
Response to personal information breaches: Where a personal information breach occurs or is highly likely to occur, the Company shall notify data subjects without delay and report the matter to the relevant authorities. (Article 34 of the Act)
The Company designates a Chief Privacy Officer as set out below, who assumes overall responsibility for matters relating to the processing of personal information and handles complaints and remedies for data subjects in connection with the processing of personal information.
| Item | Details |
|---|---|
| Name | Park Byung-jun |
| Position | Chief Executive Officer |
| Telephone | +82-2-851-1272 |
| [email protected] | |
| Address | Rm 805, 8F, Hanshin IT Tower 2, 47 Digital-ro 9-gil, Geumcheon-gu, Seoul 08511, Republic of Korea |
Data subjects may direct to the Chief Privacy Officer identified above any exercise of the rights set out in Article 9, as well as any other grievance concerning infringement of personal information. The Company will respond to and handle inquiries from data subjects without delay. The Chief Privacy Officer performs these duties together with the team in charge of security affairs.
Data subjects may apply to the following institutions for dispute resolution, consultation, or other assistance in order to obtain remedies for infringement of personal information.
| Institution | Website | Telephone |
|---|---|---|
| Personal Information Protection Commission | pipc.go.kr | 02-2100-3025 |
| Privacy Infringement Report Center | privacy.kisa.or.kr | 118 (no area code) |
| Personal Information Dispute Mediation Committee | www.kopico.go.kr | 1833-6972 |
| Supreme Prosecutors’ Office | www.spo.go.kr | 1301 (no area code) |
| Korean National Police Agency | ecrm.police.go.kr | 182 (no area code) |
Where the Company adds to, deletes from, or amends this Policy, it shall give notice of the amended content and the effective date at least 7 days prior to the effective date through the Company’s website (https://www.decasight.com/en/), a notice within the software, or email.
In the case of an amendment that materially affects the rights of data subjects or is disadvantageous to them, the Company shall clearly notify that fact and give such notice at least 30 days prior to the effective date.
Data subjects may view previous versions of this Privacy Policy at any time by selecting the Effective date at the top of this page.
Date of announcement: September 4, 2026
Effective date: September 4, 2026