SAESOL Tech(hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and relevant laws through the operation of the V2X RootCA. To ensure prompt and smooth handling of any concerns related to the information collected during certificate applications, the Company provides the following Privacy Policy.
The company processes personal information for the following purposes. Processed personal information will not be used for purposes other than those intended, and if the purpose of use changes, prior consent will be obtained.
2. Personal Information Collected
In accordance with Article 15, Paragraph 1, Item 1 of the Personal Information Protection Act, the Company collects the following minimum personal information, with consent, for the purpose of providing certificate issuance/management services.
The collected personal information is used solely for the following purposes
The Company retains personal information only for the minimum required period and securely destroys it without delay after the legally mandated retention period expires.
Item | Retention Period |
|---|---|
Certificate issuance and validation records | Certificate retention valid for 5 years from the expiration date |
Log log | Certificate retention valid for 5 years from the expiration date |
Other personal information | Immediately destroyed or anonymized after the purpose of collection is achieved |
The destruction method is as follows.
In principle, the company does not provide personal information to external parties without the user's consent, except in the following cases.
If necessary for certificate issuance tasks, the Company may entrust the processing to a trusted external vendor. In such cases, a separate consent form will be obtained or the user will be notified of the outsourcing.
Users may exercise the following rights regarding their personal information at any time.
Rights can be exercised in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, via writing, phone, or email, and may be carried out by a legal representative or an authorized person (agent), in which case a power of attorney must be submitted.
The user's right to request access to and suspension of processing of personal information may be restricted by Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
The Company implements the following security measures according to audit standards
To handle inquiries, complaints, and damage relief related to personal information protection, the Company designates the following officer