This English text is provided for convenience. Signox is operated from the Republic of Korea and this Policy is established under the Korean Personal Information Protection Act (“PIPA”). In the event of any discrepancy, the Korean version prevails.
TwentyOz Inc. (“Company”) establishes and discloses this Privacy Policy pursuant to Article 30 of PIPA, in order to protect the personal data of data subjects and to handle related grievances promptly.
This Policy applies to Signox (“Service”), the software licensing service provided by the Company.
1. Purposes of Processing
The Company processes personal data for the purposes below. Where a purpose changes, the Company will obtain separate consent or take other measures required under Article 18 of PIPA.
| Purpose | Details |
|---|---|
| Membership and account management | Identity verification, maintenance of membership, prevention of misuse, notices |
| Provision of the Service | License issuance, validation and renewal; license portal; team and member management |
| Billing | Payment for paid plans, invoicing and refunds, issuance of payment documentation |
| Customer support | Receiving and answering enquiries, incident response, retention of dispute records |
| Service improvement | Analysis of usage to improve features and develop new services |
| Security | Detection of abnormal access, retention of access logs, audit logging |
2. Categories of Personal Data Processed
Pursuant to Article 31(1)1 of the PIPA Enforcement Decree, the Company processes the following categories.
a. Members (businesses or individuals issuing licenses through the Service)
- Required: email address, name, password (stored as a one-way hash)
- Where signing up with a social account: the account identifier and email address provided by that service
- Where using a paid plan: payment method identifier (a billing key or other transaction identifier issued by the processor), payment date, amount and result, billing information
- Optional: team name, team logo image
b. End Users (persons using licenses issued by a Member)
- Email address, name
- License activation data (activation timestamp, device fingerprint)
End User personal data is entered or generated in the Service by a Member for the purpose of managing that Member’s own customers. With respect to such data, the Member is the controller and the Company is the processor. End Users should direct enquiries about the processing of their personal data to the relevant Member in the first instance.
c. Data generated automatically through use of the Service
- IP address, browser and device information (User-Agent), access timestamps, session identifiers
- Service usage records, API call records, audit logs
- Landing-page visits and primary start-button clicks; sign-up, team, product and policy creation; first license issuance and activation; and activation failures (random visitor identifier, internal user and team identifiers, page path, language, referring host,
utm_source,utm_medium,utm_campaign, CTA placement, and normalized activation error code). Advertising identifiers, email addresses, license keys, raw hwid values, and free-form payloads are not stored in these analytics records.
3. Processing and Retention Periods
The Company processes and retains personal data within the period prescribed by law or consented to by the data subject.
| Category | Retention period | Basis |
|---|---|---|
| Member data | Until withdrawal of membership | Performance of the agreement |
| Records on contracts or withdrawal of subscription | 5 years | E-Commerce Act |
| Records on payment and supply of goods or services | 5 years | E-Commerce Act |
| Records on consumer complaints or dispute resolution | 3 years | E-Commerce Act |
| Records on labelling and advertising | 6 months | E-Commerce Act |
| Service access logs | 3 months | Protection of Communications Secrets Act |
| Funnel events for service improvement | 3 months from collection | Service improvement |
| End User data | Until deleted by the Member or the Member’s agreement terminates | Performance of the processing agreement |
4. Provision to Third Parties
The Company processes personal data only within the purposes stated in Section 1, and provides it to third parties only where Articles 17 and 18 of PIPA apply, such as with the data subject’s consent or under a specific statutory provision.
The Company currently does not provide personal data to any third party. Should provision become necessary, the Company will disclose the recipient, purpose, categories, and retention period in advance and obtain consent.
5. Outsourcing of Processing
The Company entrusts the following processing activities in order to provide the Service.
| Processor | Entrusted work | Retention |
|---|---|---|
| Polar Software, Inc. | Processing payments for paid plans, storing payment methods, and calculating, reporting and invoicing transaction taxes | Until the processing agreement ends |
- When entering into a processing agreement, the Company specifies in the contract, pursuant to Article 26 of PIPA, the prohibition on processing outside the scope of the entrusted work, technical and administrative safeguards, restrictions on sub-processing, supervision of the processor, and liability for damages, and supervises whether the processor handles personal data securely.
- Any change to the entrusted work or the processor will be disclosed through this Policy without delay.
- Payment credentials such as card numbers are collected and stored directly by the processor; the Company does not store them. The Company retains only the transaction identifiers issued by the processor and the payment results.
- Payments for paid plans are processed by the processor acting as Merchant of Record, and the processor may therefore appear as the seller on the checkout page and on receipts. The Company nonetheless remains the counterparty to the service agreement and bears responsibility for providing the Service.
- The processor may engage sub-processors, such as payment gateways, for the purpose of processing payments; the current list is available from the sub-processor list published by the processor.
6. Cross-Border Transfers
The Company transfers personal data outside the Republic of Korea for the purpose of processing payments for paid plans, as set out below.
This falls under Article 28-8(1)3 of PIPA — entrustment of processing necessary for the conclusion and performance of a contract with the data subject (the paid plan agreement). Accordingly, the Company effects the transfer without separate consent by disclosing the matters listed in Article 28-8(2) in this Policy.
| Item | Details |
|---|---|
| Recipient | Polar Software, Inc. |
| Contact | privacy@polar.sh |
| Destination country | United States |
| Date and method of transfer | Transmitted over the network at the time the Member proceeds with payment for a paid plan |
| Categories transferred | Email address, name, billing information (country, address, etc.), payment method details entered by the Member on the checkout page, and order and payment records |
| Purpose of use | Processing payments for paid plans, storing payment methods, calculating and reporting transaction taxes, issuing receipts, and preventing fraudulent transactions |
| Retention period | Until the processing agreement ends, or for such longer period as required by applicable law |
How to refuse the transfer: A Member may refuse the cross-border transfer by not using a paid plan. A Member already on a paid plan may request refusal by the means set out in Section 8, in which case the Company will explain the subscription cancellation procedure.
Effect of refusal: If the transfer is refused, payment for a paid plan cannot be processed, and the paid plan and its features therefore cannot be used. Free plans remain available. Payment and transaction records subject to statutory retention obligations will be retained for the applicable period notwithstanding the refusal.
7. Destruction Procedures and Methods
- Where the retention period has elapsed or the purpose of processing has been achieved so that personal data is no longer necessary, the Company destroys it without delay (within 5 days of the triggering event).
- Where retention is required by other legislation, such data is stored in a separate database or storage location.
- Method: electronic files are permanently deleted by means that make restoration impossible; printed records are shredded or incinerated.
8. Rights of Data Subjects and Legal Representatives
- Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal data, and may withdraw consent.
- Membership termination and other data-subject rights may be requested by email to private@twentyoz.kr. The Company will act without delay and notify the requester of the outcome after verifying that the requester is the data subject or a legitimate representative, including control of the registered email address.
- Where a data subject requests correction of an error, the Company will not use or provide the personal data concerned until the correction is complete.
- Rights may be exercised through a legal representative or a duly authorized agent, in which case a power of attorney in the form prescribed by the Notification on Personal Information Processing Methods must be submitted.
- The Company verifies that the person making a request is the data subject or a legitimate representative.
- Requests for access and suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA, and deletion may not be requested where the personal data is expressly designated for collection under other legislation.
9. Automatic Collection Devices (Cookies)
- The Company uses cookies to maintain a user’s signed-in state.
- The cookies used are strictly necessary cookies for authentication and security; they are not used to collect behavioural data for advertising.
- The landing page stores a random visitor identifier in browser local storage to analyse the visit funnel without double counting. When a visitor opens registration, the identifier is passed as a URL parameter, immediately removed from the URL on page entry, and kept temporarily in session storage. On completed sign-up it is linked to an internal user identifier and deleted from browser session storage; later product steps are linked by internal user and team identifiers. It is not shared with third-party advertising or tracking services and contains no member data such as an email address.
- Users may delete or block cookies and local storage through their browser settings. Refusing strictly necessary cookies may make it difficult to use features that require signing in.
- Browser settings → Privacy and security → Cookies and other site data
10. Security Measures
Pursuant to Article 29 of PIPA and Article 30 of its Enforcement Decree, the Company implements:
- Administrative measures: establishment and implementation of an internal management plan; minimisation of personnel handling personal data and regular training
- Technical measures
- Passwords are stored using a one-way hashing algorithm that cannot be reversed.
- Sensitive credentials such as payment method data are stored encrypted.
- TLS encryption is applied to all communication channels.
- Access rights are granted on a role basis, and material processing actions are recorded in audit logs.
- Two-factor authentication (TOTP) is applied to administrator accounts.
- Physical measures: access control over the facilities where data is stored
11. Privacy Officer
The Company designates the following privacy officer, who is responsible for personal data processing and for handling grievances and remedies of data subjects.
| Item | Details |
|---|---|
| Privacy Officer | Yongseok Lee |
| Phone | +82-70-4353-1190 |
| private@twentyoz.kr |
Data subjects may direct all enquiries, complaints, and remedy requests concerning personal data protection arising from use of the Service to the privacy officer, and the Company will respond without delay.
12. Remedies for Infringement of Rights
Data subjects may apply to the following bodies for dispute resolution or consultation:
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Centre: 118 / privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division: 1301 / www.spo.go.kr
- National Police Agency, Cyber Bureau: 182 / ecrm.police.go.kr
A person whose rights or interests are infringed by the Company’s disposition or omission under Articles 35, 36, or 37 of PIPA may request an administrative appeal under the Administrative Appeals Act.
13. Changes to this Policy
- This Policy applies from its effective date.
- Where content is added, deleted, or amended due to changes in law, policy, or security technology, the Company will give notice through the Service at least 7 days before the change takes effect, or at least 30 days before where the change materially affects data subjects’ rights.
- Previous versions of this Policy are available on request.
14. Governing Law and Language
- This Policy is established under the Korean Personal Information Protection Act and related legislation, and is governed by and construed in accordance with the laws of the Republic of Korea.
- The Korean text of this Policy is the authentic version. Where a translation provided by the Company for convenience differs from the Korean text, the Korean text prevails.
Addendum
- (Effective date) This Privacy Policy takes effect on 4 August 2026.
- (Amendment) This Privacy Policy as amended on 5 August 2026 takes effect on the same date. The amendment aligns the wording of the processing purposes in Section 1 with what is actually processed.
- (Scheduled amendment) The Policy taking effect on 16 August 2026 discloses the full first-party funnel, acquisition fields, internal identifiers, normalized error codes, retention period, and browser-storage use for service improvement.
- (Correction) On 9 August 2026, the Company clarified that membership termination and data-subject rights requests use the email intake and identity-verification procedure currently provided. This corrects the description of the current procedure without changing processing purposes, data categories, or retention periods.