Privacy Policy


SAESOL Tech(hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and relevant laws through the operation of the V2X RootCA. To ensure prompt and smooth handling of any concerns related to the information collected during certificate applications, the Company provides the following Privacy Policy.

1. Purpose

The company processes personal information for the following purposes. Processed personal information will not be used for purposes other than those intended, and if the purpose of use changes, prior consent will be obtained.

  • Identity verification: Processed to identify the entity who requested certificate issuance.
  • Service provision: Processed for the purpose of analyzing and improving the provision (use) of services.
  • Contract Execution and Execution: Contracts are sent and processed for cost settlement purposes during contract signing and execution.
  • Inquiry (Grievance) Handling: Handled for the purpose of collecting inquiries arising from service use.
  • Incident response and operation: Handles issues during service use for the purpose of receiving and responding to them.

2. Personal Information Collected

In accordance with Article 15, Paragraph 1, Item 1 of the Personal Information Protection Act, the Company collects the following minimum personal information, with consent, for the purpose of providing certificate issuance/management services.

  • Name
  • Date of birth
  • Contact information (E-mail, Phone number or mobile phone number)
  • Resident registration certificate
  • Copy of ID (Resident Registration Card or Driver's License)
  • Agent Information (Power of Attorney) (if necessary)
  • Business Registration Certificate
  • Certified copy of corporate registry
  • Company name and proof of employment or employment confirmation

3. Purpose of Use of Personal

The collected personal information is used solely for the following purposes

  • Verification of the certificate application identity and authority
  • Provision of PKI services such as certificate issuance and revocation
  • Ensuring secure communication and integrity within the V2X network
  • Prevention of misuse and detection of anomalies
  • Record retention for compliance with legal obligations and despite resolution

4. Retention and destruction of Personal Information

The Company retains personal information only for the minimum required period and securely destroys it without delay after the legally mandated retention period expires.

Item
Retention Period

Certificate issuance and validation records

Certificate retention valid for 5 years from the expiration date

Log log

Certificate retention valid for 5 years from the expiration date

Other personal information

Immediately destroyed or anonymized after the purpose of collection is achieved

The destruction method is as follows.

  • Electronic files: Permanently deleted using technical methods that prevent recovery
  • Documents : Physically destroyed by shredding or incineration

5. Provision of Personal Information to Third Parties

In principle, the company does not provide personal information to external parties without the user's consent, except in the following cases.

  • When required by law or at the request of investigative agencies
  • When certificate information is published in public repositories for validation and CRL (Certificate Revocation List) checking (Note: Personal information is not included)

6. Entrustment of Personal Information Processing

If necessary for certificate issuance tasks, the Company may entrust the processing to a trusted external vendor. In such cases, a separate consent form will be obtained or the user will be notified of the outsourcing.

7. Rights of Information Subjects and How to Exercise Them

Users may exercise the following rights regarding their personal information at any time.

  • Requests for viewing, correction, or deletion of personal informationR
  • Request to suspend processing or withdrawal of consentR
  • Request to discard certificates or update personal information

Rights can be exercised in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, via writing, phone, or email, and may be carried out by a legal representative or an authorized person (agent), in which case a power of attorney must be submitted.

The user's right to request access to and suspension of processing of personal information may be restricted by Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

8. Protection Measures for Personal Information

The Company implements the following security measures according to audit standards

  • Technical Measures
  • Encryption of sensitive information and prevention of unauthorized access
  • Regular backup and secure storage of authentication and audit logs
  • Administrative Measures
  • Designation of a personal information protection officer and regular training
  • Minimization and separation of access privileges
  • Internal security inspections and external audits
  • Physical Measures
  • Operation of a data center with access control systems
  • Restricted access to secure areas and dual locking systems

9. Personal Information Protection Officer and Grievance Handling

To handle inquiries, complaints, and damage relief related to personal information protection, the Company designates the following officer

  • Name: Youngok Hwang
  • E-mail: bailey.hwang@saesol.tech