Sierra BASE Co., Ltd. (hereinafter the “Company”) complies with the Personal Information Protection Act and other applicable laws and regulations to protect the rights and freedoms of data subjects, and processes personal information lawfully and securely. Pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses this Privacy Policy to provide information on the procedures and standards for processing personal information and to promptly and effectively handle complaints and inquiries related to personal information.
The Company processes only the minimum personal information necessary for the following purposes. Personal information will not be used for any purpose other than those specified below. If the purpose of processing changes, the Company will take the necessary measures in accordance with the Personal Information Protection Act.
The Company does not use website visit statistics for marketing, personalized advertising, or tracking user behavior.
1. Personal information processed with the consent of the data subject
| Processing Activity | Purpose | Personal Information Processed | Legal Basis | Retention Period |
|---|---|---|---|---|
| Handling and consultation of service inquiries | Reviewing and responding to inquiries, providing follow-up consultation, and managing inquiry processing history | Required: company name, contact person’s name, position, phone number, email address, and inquiry details / Optional: attachment | Article 15(1)(1) of the Personal Information Protection Act (consent of the data subject) | 3 years from the date the inquiry is received |
Data subjects have the right to refuse consent to the collection and use of their personal information. However, if consent to the required items is not provided, submission of a service inquiry may be restricted. An inquiry may still be submitted without providing the optional attachment.
If a data subject withdraws consent or requests deletion of personal information, the Company will destroy the relevant personal information without delay unless retention is required under other applicable laws.
2. Personal information processed without the consent of the data subject
| Processing Activity | Purpose | Personal Information Processed | Legal Basis | Retention Period |
|---|---|---|---|---|
| Website visit statistics | Preventing duplicate visits, analyzing website traffic and referral sources, and improving website operation | Randomly generated visitor identifier, date and time of visit, referring domain | Article 15(1)(6) of the Personal Information Protection Act (legitimate interests pursued by the Company) | 1 year from the date the original visit record is collected |
| Limiting repeated inquiry submissions | Preventing abnormal or excessive repeated inquiry submissions | One-time hash value generated from the access IP address, request count, and restriction expiration time | Article 15(1)(6) of the Personal Information Protection Act (legitimate interests pursued by the Company) | 10 minutes from the time the hash value is generated |
| Limiting failed administrator login attempts | Preventing abnormal login attempts and attacks | One-time hash value generated from the access IP address, number of failed login attempts, and restriction expiration time | Article 15(1)(6) of the Personal Information Protection Act (legitimate interests pursued by the Company) | 15 minutes from the time the hash value is generated |
The Company does not store users’ original IP addresses in website visit statistics data or in the application database.
The Company processes a limited amount of visit information for the stable operation of the website and analysis of website usage. Such information is not used to directly identify individuals or to provide marketing or personalized advertising.
3. Retention of anonymized statistics
Even after the original personal information has been destroyed, the Company may retain the following statistical information, which cannot be used to identify an individual, for the duration of the service operation.
The above statistics do not include any information that can identify an individual, including names, phone numbers, email addresses, inquiry details, attachments, or visitor identifiers.
The Company’s website and service inquiry functions are intended for businesses and business personnel and are not directed at children under the age of 14.
The Company does not intentionally collect personal information from children under the age of 14. If the Company becomes aware during the inquiry process that an individual submitting an inquiry is under the age of 14, the relevant personal information will not be used for consultation or any other purpose and will be destroyed without delay.
Accordingly, the Company does not provide a service inquiry procedure based on consent from the legal representative of a child under the age of 14.
The Company does not provide personal information of data subjects to third parties.
However, the Company may provide personal information within the scope permitted under the Personal Information Protection Act in any of the following circumstances.
The review and processing of inquiry details by the Company’s employees in the course of performing their duties does not constitute the provision of personal information to a third party.
When a service inquiry is received, the Company sends a notification email containing the company name, contact person’s name, and phone number to notify the responsible staff member of the inquiry. Inquiry details and attachments are not included in the email and may only be viewed through the administrator page or a separately authenticated link. Information sent by email is managed separately in the recipient’s mailbox, and the automatic destruction of information under the retention periods set forth in this Privacy Policy applies to records stored in the Company’s system (database).
If the Company provides personal information to a third party in the future, it will disclose the recipient, purpose of provision, personal information provided, and retention and use period in this Privacy Policy, and will obtain the data subject’s consent where required.
| Service Provider | Outsourced Services | Retention and Use Period |
|---|---|---|
| Amazon Web Services Korea LLC | Provision of cloud infrastructure for website operation, storage of databases and attachments, and sending service inquiry notification emails through Amazon SES | Until termination of the outsourcing agreement |
| DOUZONE BIZON Co., Ltd. | Provision of corporate email services and storage of service inquiry notification emails | Until termination of the outsourcing agreement |
When outsourcing the processing of personal information, the Company specifies the following matters in a contract or other written document in accordance with Article 26 of the Personal Information Protection Act.
The Company manages and supervises service providers to ensure that personal information is processed securely. Any changes to service providers or outsourced services will be disclosed through this Privacy Policy.
The Company does not transfer personal information outside the Republic of Korea.
The Company destroys personal information without delay when the applicable retention period has expired, the purpose of processing has been achieved, or the personal information is otherwise no longer necessary.
1. Personal Information Subject to Destruction and Timing
2. Destruction Procedure
The Company identifies personal information for which grounds for destruction have arisen and destroys such information in accordance with internal procedures. Personal information whose retention period has expired is deleted through periodic destruction procedures. If an error occurs during the destruction process, the Company reprocesses the deletion and verifies the result.
3. Destruction Method
4. Backup Data
The Company does not currently create or retain separate backup copies of data containing personal information.
① Data subjects may exercise the following rights regarding their personal information at any time.
② These rights may be exercised in writing, by email, by telephone, or by other means. After verifying the identity of the requester, the Company will take the necessary measures without delay in accordance with the procedures prescribed by applicable laws.
③ A data subject may exercise these rights through a legal representative or authorized agent. In such cases, the Company may request documentation, such as a power of attorney, to verify the representative relationship.
④ If the Company confirms that personal information of a child under the age of 14 has been processed, the child’s legal representative may request access to, correction or deletion of, or suspension of processing of the personal information.
⑤ If a data subject requests correction or deletion of personal information, the Company will not use or provide the relevant personal information until the correction or deletion has been completed. However, such requests may be restricted under applicable laws, in which case the Company will inform the data subject of the reason for the restriction and how to raise an objection.
⑥ Data subjects must provide accurate and up-to-date personal information and must not misuse another person’s personal information or provide false information.
⑦ The following department is responsible for receiving and processing requests to exercise rights related to personal information protection.
Responsible Department: Development Team 1
Email: admin@sierrabase.co.kr
Phone: +82-52-269-0617
① The Company uses the following cookies to calculate website visit statistics and prevent duplicate counting of the same visitor.
| Cookie Name | Purpose | Information Stored | Retention Period |
|---|---|---|---|
| visitor_id | Calculating the number of unique visitors | Randomly generated visitor identifier (UUID) | 1 year from the date of creation |
| visit_session | Preventing duplicate visit counting within a short period | A value indicating whether a visit session exists | 30 minutes from the date of creation |
② The Company does not use the above cookies for member identification, marketing, personalized advertising, or tracking user behavior across other websites.
③ The cookies do not store names, phone numbers, email addresses, or IP addresses.
④ The HttpOnly and SameSite=Lax attributes are applied to the cookies, and the Secure attribute is applied in the production environment where HTTPS communication is used.
⑤ Data subjects may allow or block cookies through their web browser settings. Even if cookies are blocked, the main functions of the website remain available, although website visit statistics may not be accurately calculated.
⑥ Cookies already stored may be deleted using the cookie and site data deletion functions provided by the web browser.
① The Company does not analyze individuals’ interests, preferences, or usage behavior, or provide behavioral information to third parties, for the purpose of providing online personalized advertising.
② Website visit statistics collected by the Company are used only to understand website usage, prevent duplicate visit counting, and improve services.
③ The Company does not use the collected website visit statistics to track the behavior of specific individuals or create individual user profiles.
The Company implements the following administrative, technical, and physical safeguards to prevent personal information from being lost, stolen, leaked, forged, altered, or damaged.
1. Administrative Measures
The Company grants access to personal information processing systems only to personnel who require such access for their duties. Access records for each administrator account, including login date and time, viewing of inquiries, downloading and deletion of attachments, creation, modification and deletion of administrator accounts, and access IP addresses, are recorded, retained for 1 year, and periodically reviewed. Access through email authentication links is recorded in the same manner.
2. Technical Measures
3. Physical Measures
The Company operates its personal information processing systems in a professional cloud service environment. Physical access controls and other physical security measures provided by the cloud service provider are applied to the facilities in which personal information is stored.
① The Company designates the following Chief Privacy Officer and responsible department to oversee matters relating to personal information processing and to handle complaints, requests for relief, and other matters related to the protection of personal information.
Chief Privacy Officer
Name: In-Hyeok Kang
Position: Team Leader
Email: admin@sierrabase.co.kr
Phone: +82-52-269-0617
Department Responsible for Personal Information Protection
Department: Development Team 1
Contact Person: In-Hyeok Kang
Email: admin@sierrabase.co.kr
Phone: +82-52-269-0617
② Data subjects may contact the Chief Privacy Officer or the responsible department regarding personal information inquiries, complaints, requests for relief, or the exercise of rights arising from the use of the Company’s services. The Company will respond to and process such requests without delay.
① The Company handles inquiries, complaints, and requests for relief relating to personal information through the Chief Privacy Officer or the department responsible for personal information protection.
② If a data subject is dissatisfied with the Company’s handling of a personal information complaint or request for relief, or requires further assistance, the data subject may contact the following organizations.
① This Privacy Policy takes effect on September 3, 2026.
② If the Company revises this Privacy Policy, it will disclose the changes and effective date on the website before the revised policy takes effect.
③ If any change materially affects the rights of data subjects, including changes to the purposes of processing, personal information processed, retention periods, provision to third parties, or international transfers, the Company will provide clear notice so that data subjects can readily identify the changes.
④ Previous versions of this Privacy Policy will be made available on the website.
Notice Date: September 3, 2026
Effective Date: September 3, 2026
Previous Privacy Policy: View Previous Privacy Policy