Hanco Lab Privacy Policy

Applicable Version: 2026.09.07
Enacted: March 23, 2026
Effective: September 7, 2026


Hanco Lab (the “Company”) complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws and regulations in order to protect the freedoms and rights of data subjects, and processes personal information lawfully and manages it securely. Pursuant to Article 30 of the Personal Information Protection Act, the Company hereby establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards governing the processing of personal information and to promptly and effectively address related grievances.

This Policy applies to the custom software development and implementation services provided by the Company and to the related consultation, quotation, contracting, payment, development, installation, testing and acceptance, delivery, maintenance, and customer-support activities.


1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. The Company uses personal information within the scope of the disclosed purposes, and if a purpose changes, the Company shall take necessary measures under applicable law, including obtaining additional consent and amending and disclosing this Privacy Policy.

  1. Consultation, quotation, and contract formation: The Company processes personal information to respond to Customer inquiries, confirm requirements, assess whether the Services can be provided, prepare quotations and proposals, draft Project Specifications, identify the contracting party and person in charge, and enter into an Individual Agreement.

  2. Custom software development and implementation: The Company processes personal information to review Customer-Provided Materials, analyze requirements, develop programs and systems, integrate data and External Services, configure development environments, install and deploy Deliverables, and manage project progress.

  3. Technical testing and acceptance: The Company may process test environments, logs, and account or API access information within the scope expressly approved by the Customer in order to install Deliverables, verify operation, reproduce and analyze errors, debug, conduct quality assurance (QA), perform acceptance, and deliver Deliverables.

  4. Support for installation, configuration, and integration in Customer-Managed Environments and Customer-Used External Services: To install, configure, or integrate Deliverables or verify their technical operation in PCs, servers, cloud services, networks, and other infrastructure for running programs that is managed by the Customer or an entity to which the Customer belongs (the “Customer-Managed Environment”), or in securities companies, exchanges, brokers, charting or automation platforms, data or API services, and other third-party services selected, contracted for, and managed directly by the Customer (the “Customer-Used External Services”), the Company may temporarily process remote-access information, device and server information, External Service account information, and API and other access information within the scope approved by the Customer.

  5. Payment, settlement, and issuance of supporting documents: The Company processes personal information to verify, cancel, refund, and settle payments made by bank transfer, escrow through a third-party intermediary platform, or card or simplified payment through a payment gateway (“PG”) provider to be introduced in the future; to issue legally recognized supporting documents such as cash receipts and tax invoices; and to retain transaction records as required by applicable law.

  6. Operation and retention of customer-support channels, maintenance, and dispute response: The Company may retain and process Customer identification information, conversations, attachments, and handling records in order to receive, relay, and respond to inquiries by email, telephone, or customer-support channels; maintain continuity of consultations; send notices concerning contracts, schedules, and delivery; provide free Maintenance and paid technical support; handle inquiries, complaints, and disputes; respond to the exercise of rights; and establish or defend contractual or legal claims.

  7. Security and service-quality management: The Company processes personal information to prevent, detect, and respond to misuse of account or authentication information, unauthorized use, and security incidents; review access records; analyze failures and errors; and improve service quality, stability, and security.

  8. Internal statistics and portfolio use: The Company may sufficiently de-identify and aggregate personal information and Confidential Information so that an individual, Customer, or project cannot reasonably be identified or inferred, and then use such information for internal analysis and improvement of service quality, security, and operations. If the Company publishes an identifiable Customer name, trade name, trademark, project material, screen of a Deliverable, or actual operational or performance data as a use case, or uses it in promotional or marketing materials, the Company shall obtain the Customer’s separate consent.


2. Categories, Methods of Collection, and Retention Periods of Personal Information

The Company processes personal information as set forth below to the extent necessary to provide the Services. The Company does not necessarily collect every item listed below for every project and processes only the items necessary in light of the payment, integration, and testing methods selected by the Customer and the applicable Individual Agreement.

Legal Basis

Category

Method of Collection

Items Processed

Retention and Use Period

Article 15(1)4 of the Personal Information Protection Act (measures requested by the data subject in the course of entering into a contract) and subparagraph 6 (legitimate interests in managing consultation history and responding to disputes)

Consultation, quotation, and contracting

Provided directly by the Customer by email, telephone, messenger, consultation or inquiry channel, electronic document, or third-party intermediary platform

Name or name of person in charge, company or organization name, department and title, telephone number, email address, messenger or platform identifier, consultation and communication details, requirements, quotation and contract records, and history of consent to terms

If no contract is formed, retained for one year from the date of the last consultation and then destroyed. In such cases, only the minimum contact information, consultation details, requirements, quotation or proposal, and communication records necessary to verify the consultation history, respond to duplicate inquiries, and prevent or respond to disputes are retained; account passwords, API Keys, Secret Keys, access tokens, and other Important Authentication Information are not retained. If a contract is formed, destroyed without delay after termination of the contract; however, transaction records required by law are separately retained for the periods specified in Section 8

Article 15(1)4 of the Personal Information Protection Act

Development, implementation, and project management

Provided directly by the Customer, contained in electronic documents exchanged between the parties, or generated during development, testing, and acceptance

Customer representative information, Project Specifications, Customer-Provided Materials, project documents, development and change history, testing and acceptance materials, error and consultation records, and personal information contained in Deliverables and work files

For a project that has completed final acceptance, until 30 days after the end of the free Maintenance period; for a project terminated before completion of acceptance, until 30 days after completion of contract termination and settlement. Materials required for a dispute or by law may be retained until the relevant basis for retention ceases to exist

Article 15(1)4 of the Personal Information Protection Act (processing necessary to perform a contract, subject to the Customer’s express request and approval)

Testing and acceptance using an actual account or API

Temporary access through a test environment separately provided or approved by the Customer

Account identifiers and account information for securities companies, exchanges, brokers, or similar entities; API Keys, Secret Keys, access tokens, permitted IP and permission information; order, execution, balance, and position information visible during testing; and test logs

Until the earliest of completion of testing, achievement of the purpose, or withdrawal of access by the Customer. Authentication information held by the Company is securely deleted without delay after the purpose is achieved. Testing and acceptance records from which authentication information has been removed are subject to the retention period for project materials

Article 15(1)4 of the Personal Information Protection Act and the Customer’s express approval

Support for installation, configuration, and integration in Customer-Managed Environments and Customer-Used External Services

Temporary access through a remote-access tool, device or server account, External Service account, API, or other access method provided or run by the Customer

Remote-access identifiers; device, server, and External Service account identifiers; login information, one-time authentication codes, API Keys, Secret Keys, access tokens; device and server IP addresses; operating-system, network, and runtime-environment information; SSH Keys and passwords; integration permissions; and configuration and log information visible during installation, configuration, and integration

Until the earliest of completion of installation, configuration, integration, or remote support; achievement of the purpose; or withdrawal of access by the Customer. Authentication information held by the Company is securely deleted without delay thereafter

Article 15(1)4 of the Personal Information Protection Act and applicable law

Bank-transfer payment and refund

Bank deposit records and information provided directly by the Customer

Depositor name, financial institution, payment and deposit date and time, amount, transaction identifier, and, if a refund is required, account holder and refund-account information

Records concerning payment and supply of services are retained for five years. Information not required as a statutory record, including refund-account information, is destroyed without delay after completion of the refund

Article 15(1)4 of the Personal Information Protection Act and applicable law

Payment and transactions through third-party intermediary platforms

Provided through a platform selected by the Customer and generated during transactions

Platform member and order identifiers, name or nickname, contact details, messages and request details, order and contract information, and payment, escrow, purchase-confirmation, cancellation, and refund status

Records concerning contracts, payments, and supply of services are retained for five years, and records concerning consumer complaints and disputes for three years. The platform’s own retention period is governed by its privacy policy

Article 15(1)4 of the Personal Information Protection Act and applicable law

Card and simplified payments after introduction of a PG provider

Entered directly by the Customer on the PG payment page, with the payment result provided to the Company

Name, order and transaction identifiers, type of payment method, payment amount, date and time, status, approval number, and cancellation and refund information. The Company does not directly store complete card numbers, expiration dates, CVCs, or payment passwords

Records concerning payment and supply of services are retained for five years. Before introduction, the Company shall disclose in this Policy the actual items processed and retention period based on the selected PG provider’s standards

Article 15(1)2 of the Personal Information Protection Act (compliance with legal obligations)

Issuance of tax invoices, cash receipts, and other supporting documents

Provided directly by the Customer and obtained from the processing results of relevant authorities

Name or trade name, business registration number, mobile-phone number, email address, supply value, tax amount, transaction date, and other information necessary to issue supporting documents

Retained for five years after the statutory filing deadline for the applicable national tax. Books and evidentiary documents concerning offshore transactions are retained for seven years, or for a longer period if required by applicable tax law

Article 15(1)4 or 6 of the Personal Information Protection Act (performance of a contract or legitimate interests)

Operation and retention of customer-support channels, Maintenance, and dispute handling

Email, telephone, customer-support channels or relay bots on cloud-based messengers, third-party intermediary platforms, other online consultation channels, electronic documents, and direct provision by the Customer

Name and contact details; contract and project identifiers; messenger or platform user and account identifiers; username, display name, nickname, and public profile information transmitted to a customer-support channel or bot; conversations, inquiries, and complaints; message, chat, and channel identifiers; transmission and receipt times; attachments; logs; screenshots; operation videos; error, order, and execution records; and relay, consultation, and handling history

General inquiry, consultation, and technical-support records are retained for one year after completion of handling; consumer complaint and dispute-handling records for three years after completion of handling; and records relating to an ongoing dispute until its conclusion. A messenger or platform provider’s own retention period is governed by its privacy policy

Article 15(1)6 of the Personal Information Protection Act (legitimate interests)

Website and online-channel security and incident response

May be automatically generated and collected while using the website or an online inquiry channel

IP address, access date and time, browser, operating system and other usage-environment information, session and cookie information, and access, error, and security logs

Up to one year from collection or until the security or incident-response purpose is achieved

Article 15(1)1 of the Personal Information Protection Act (separate consent)

Identifiable portfolio and promotional use (optional)

Customer consent in writing or by electronic document

Name, trade name, trademark, service name, project description, screens of Deliverables, interviews, testimonials, or operational or performance data within the scope consented to by the Customer

For the period specified in the consent or until consent is withdrawn. Consent records required by law are retained for the applicable statutory period

  1. Logs, data, screens, videos, documents, or accounts provided by the Customer may contain personal information of third parties, including the Customer’s officers, employees, end users, and counterparties. The Customer shall secure the lawful basis, authority, and any consent necessary to provide such information to the Company and permit the Company to process it in performing an Individual Agreement. The Company shall not use such information beyond the scope necessary to perform the contract.

  2. If the Customer includes unnecessary personal information, legally defined sensitive information, resident registration numbers, or authentication information granting withdrawal or fund-transfer authority in any material, the Company may request that such information be masked, substituted, deleted, or minimized.

  3. The Company does not collect optional marketing or advertising information as information required for the Services. If the Company introduces receipt of promotional information or optional marketing in the future, it shall obtain separate optional consent and amend this Policy.

  4. If an Individual Agreement includes entrusting the Company with the processing of personal information of the Customer’s officers, employees, end users, or other third parties, the Customer may be the entrusting party and the Company may be the entrusted processor within that scope. In such case, pursuant to Article 26 of the Personal Information Protection Act, the parties shall specify the purpose and scope of the entrustment, prohibition on processing for other purposes, security measures, sub-entrustment, management and supervision, and return and destruction in the Individual Agreement or a separate personal-information processing entrustment document. The Company shall not use such personal information for its own independent purposes beyond the Customer’s documented instructions and the scope necessary to perform the contract.

  5. If the Company uses personal information or project materials after de-identifying or statistically aggregating them, it shall remove direct identifiers and assess whether a particular individual or Customer could reasonably be re-identified or inferred from a combination of indirect identifiers, rare characteristics, screens, numerical values, or contextual information. Information that has not been sufficiently de-identified shall not be used in published use cases or promotional or marketing materials without the Customer’s separate consent.


3. Provision of Personal Information to Third Parties

  1. As a general rule, the Company does not provide a data subject’s personal information to third parties. The Company may, however, provide personal information to the extent permitted by applicable law, including where the data subject has separately consented, where a law specifically so provides, or where an investigative agency, court, or administrative authority requests it through lawful procedures.

  2. The Company may provide the National Tax Service or another relevant authority with a name or trade name, business registration number, mobile-phone number, email address, and transaction information to the extent necessary to perform legal obligations such as issuing cash receipts or tax invoices and filing taxes. The relevant authority retains and processes the information in accordance with applicable law.

  3. In a transaction through a third-party intermediary platform, the platform processes information concerning membership registration, payment and escrow, purchase confirmation, cancellation and refund, and dispute handling under its separate agreement with the Customer and its own privacy policy. The Company may receive from the platform, or exchange with the Customer through the platform, order, contact, and payment-status information necessary to perform the contract.

  4. If the Company begins to provide personal information to a third party continuously or in a standardized manner, it shall inform data subjects in advance of the recipient, purpose of provision, items provided, retention and use period, legal basis, and, where applicable, the right to refuse consent and the consequences of refusal, and shall amend this Policy.

  5. If the Company intends to disclose identifiable personal information of a Customer or third party on a website, in a proposal or video, on social media, or in another medium accessible to an unspecified number of persons, it shall specify the items, purpose, medium, and period of disclosure and obtain the data subject’s separate consent. The use of information that has been sufficiently de-identified so that an individual or Customer can no longer reasonably be identified is governed by Article 7 of the Terms of Use and the de-identification standards in this Policy.


4. Entrustment of Personal Information Processing and Payment Service Providers

  1. If the Company entrusts personal information processing to an external service provider, it shall, pursuant to Article 26 of the Personal Information Protection Act, specify in the entrustment agreement matters such as prohibition on processing for purposes other than the entrusted purpose, security measures, restrictions on sub-entrustment, management and supervision of the entrusted processor, and damages, and shall manage and supervise the entrusted processor.

    Entrusted Processor

    Entrusted Services

    Personal Information Processed

    Retention and Use Period

    Framer B.V.

    Publication and hosting of the Company website and processing of web requests

    Website visitors’ IP addresses, access dates and times, browsers, operating systems and other usage-environment information, web-request and security logs, and request information when the inquiry function is used

    Until termination of the entrustment agreement or achievement of the processing purpose

    Zoho Corporation and its affiliates

    Transmission, receipt, storage, security, and spam prevention for the Company’s business email

    Sender and recipient names and email addresses, email subjects, bodies and attachments, transmission and receipt times and status, and security logs

    Until termination of the entrustment agreement or achievement of the applicable processing purpose under Section 2

    Oracle Corporation and its affiliates (Oracle Cloud Infrastructure)

    Server hosting for online customer-support channels and relay bots, storage and backup of customer-support records, and server security and incident response

    Messenger or platform user and account identifiers; username, display name, nickname, and public profile information transmitted to the customer-support channel or bot; conversation and inquiry details; message, chat, and channel identifiers; transmission and receipt times; attachments; relay, consultation, and handling history; and server access, error, and security logs

    Until termination of the entrustment agreement or achievement of the customer-support or dispute-handling purpose under Section 2

  2. A cloud-based messenger that the Customer directly registers for and uses processes the Customer’s account information and cloud chats under its own terms of use and privacy policy. If the Customer uses a customer-support channel or relay bot operated by the Company through such a messenger, the Company may collect the information stated in Section 2 to provide customer support and separately store it on a server operated by the Company. The messenger provider’s independent processing is distinct from the Company’s collection and retention through its customer-support channel or relay bot. Before the Customer uses the channel or bot, the Company shall provide an accessible route to this Policy in the channel or bot notice or by another reasonable method.

  3. Financial institutions used for bank transfers and third-party intermediary platforms for which the Customer directly registers process personal information under their respective terms of use and privacy policies. Processing arising from the direct service relationship between the Customer and such provider is distinct from personal information processing entrusted by the Company.

  4. The Company is reviewing agreements to select a PG provider for credit-card, debit-card, and simplified payments. As of the effective date of this Policy, the Company does not entrust personal information processing to, or transfer payment information to, any unconfirmed PG provider. Before selecting a PG provider and commencing actual payment processing, the Company shall disclose the following matters in this Policy and complete any notice or consent procedures required by applicable law:

    1. the name of the entrusted processor or payment service provider receiving personal information;

    2. the nature of processing services, including payment approval, cancellation, refund, settlement, and fraud detection;

    3. the categories and retention and use periods of personal information processed; and

    4. any overseas processing or sub-entrustment.

  5. Even after introducing PG payments, the Company shall not directly store complete card numbers, expiration dates, CVCs, or payment passwords, and shall process only the minimum result information necessary to verify, cancel, refund, and settle payments and retain statutory transaction records.


5. Overseas Transfer of Personal Information

  1. Pursuant to Article 28-8(1)3 of the Personal Information Protection Act, the Company may transfer and store personal information with overseas entrusted processors as set forth below to operate business email, the website, and online customer-support channels and relay bots necessary to enter into and perform contracts with data subjects.

    Recipient and Contact

    Country of Transfer

    Timing and Method

    Items Transferred

    Purpose of Transfer

    Retention and Use Period

    How to Refuse and Consequences of Refusal

    Framer B.V. (legal@framer.com)

    Netherlands and United States

    Transmitted via encrypted communications when accessing the Company website or using its inquiry function

    IP address, access date and time, browser, operating system and other usage-environment information, web-request and security logs, and inquiry-request information

    Publication and hosting of the Company website and processing of web requests

    Until termination of the entrustment agreement with Framer or achievement of the processing purpose

    The data subject may stop using the website and make an inquiry through another channel, such as email. In that case, access to information and inquiries through the website may be restricted

    Zoho Corporation and its affiliates (privacy@zohocorp.com)

    United States and countries in which Zoho affiliates process information in the course of service operation and technical support, including India

    Transmitted via encrypted communications when an inquiry or material is sent to the Company’s email address or when the Company replies

    Sender and recipient names and email addresses, email subject, body and attachments, transmission and receipt times and status, and security logs

    Transmission, receipt, storage, security, and spam prevention for the Company’s business email

    Until termination of the entrustment agreement with Zoho or achievement of the applicable processing purpose under Section 2

    The Customer may use a third-party intermediary platform used by the Customer or another agreed channel instead of email. This may restrict how the project is conducted and how communications are made

    Oracle Corporation and its affiliates (Oracle Cloud Infrastructure, Privacy Inquiry)

    Japan (OCI region selected by the Company)

    Transmitted and stored via encrypted communications when the Customer sends a message to an online customer-support channel or relay bot

    Messenger or platform user and account identifiers; username, display name, nickname, and public profile information transmitted to the customer-support channel or bot; conversation and inquiry details; message, chat, and channel identifiers; transmission and receipt times; attachments; relay, consultation, and handling history; and server access, error, and security logs

    Operation of online customer-support channels and relay bots; receipt, relay, and response to inquiries and technical-support requests; record retention; maintenance of consultation continuity; security and incident response; and dispute handling

    General inquiry, consultation, and technical-support records are retained for one year after completion of handling; consumer complaint and dispute-handling records for three years after completion of handling; and records relating to an ongoing dispute until its conclusion

    The Customer may contact the Company by email or another agreed channel without using the applicable online customer-support channel. In that case, customer support through that channel will be unavailable

  2. The Company periodically verifies the data center assigned to its actual account, the service-providing entity, and the countries in which technical-support processing occurs. If any information in the above table changes, the Company shall amend and disclose this Policy before commencing the changed processing.

  3. If a Customer enters membership, payment, or access information directly into an overseas securities company, exchange, broker, charting or automation platform, cloud-computing service, data or API service, remote-access service, or other External Service selected and contracted for by the Customer, the provider’s direct collection of personal information from the Customer is distinct from the Company’s overseas transfer of personal information held by the Company. The provider processes personal information under its own terms of use and privacy policy, and the Customer shall review the processing country, items processed, retention period, and method of exercising rights before use.

  4. If, at the Customer’s express request and with its approval, the Company accesses an overseas server or Customer-Used External Service directly contracted for and managed by the Customer and directly enters, uploads, stores, or integrates personal or account identifiers, account-related information, API Keys, Secret Keys, access tokens, test materials, or other personal information received from and held for the Customer, or enables an overseas provider to access such information, the processing may constitute an overseas transfer of personal information even if the server or service contract is in the Customer’s name. Before the transfer, the Company shall determine the lawful basis, including whether it is an entrustment or storage necessary to perform a contract with the data subject or requires separate consent, and shall disclose or notify the data subject of, or obtain any consent required by applicable law for, the actual recipient, country, items, purpose, timing and method, retention period, and method and consequences of refusing the transfer.

  5. Except for paragraph 1, as of the effective date of this Policy, the Company does not operate on the assumption that project materials of custom-development Customers will be uniformly stored in overseas External Services contracted for by the Company. If the Company later uses an overseas server, platform, remote-access service, or business tool contracted for by the Company to provide, entrust, or store personal information overseas, it shall include the following information and the basis for transfer under Article 28-8 of the Personal Information Protection Act in this Policy before the processing begins:

    1. the recipient and its contact information;

    2. the country, timing, and method of transfer;

    3. the categories and purpose of the personal information transferred;

    4. the retention and use period; and

    5. the method and procedure for refusing the transfer and the consequences of refusal.

  6. If project materials contain a third party’s personal information, the Customer shall secure the lawful basis and any notice and consent necessary to transfer, store, or integrate that information in an overseas server, region, or External Service selected by the Customer. The Company does not assume the Customer’s legal obligations as a personal information controller beyond the scope of technical installation, configuration, and integration support.


6. Support for Installation, Configuration, and Integration in Customer-Managed Environments and Customer-Used External Services

  1. The Company may provide Deliverables by installing them in a Customer-Managed Environment or configuring and integrating them with Customer-Used External Services. The Customer selects and manages the providers, devices, accounts, access methods, operating systems, regions, plans, payment methods, and terms of use for the Customer-Managed Environment and Customer-Used External Services.

  2. If the Customer directly selects, contracts for, or runs a securities company, exchange, broker, charting or automation platform, server or cloud-computing service, data or API service, remote-access tool, or other Customer-Used External Service, the provider may process personal information under its own terms of use and privacy policy. Section 5 applies if use of such service results in an overseas transfer.

  3. If, at the Customer’s request, the Company supports installation, configuration, integration, or inspection by accessing a Customer-Managed Environment or Customer-Used External Service remotely, on site, through an API, or by another agreed method, the Company shall access only the devices, accounts, servers, services, periods, purposes, and permissions approved by the Customer. Where practicable, the Company shall use temporary accounts created or activated by the Customer, one-time authentication information, one-time remote-access sessions, separately issued API Keys, restricted permissions, or access limited to specific IP addresses. The Company shall discontinue access and delete authentication information in its possession without delay upon the earliest of completion of support, achievement of the purpose, or withdrawal of access.

  4. Using access rights provided by the Customer, the Company may directly enter, register, or integrate API Keys, Secret Keys, access tokens, account identifiers, webhook addresses, or other configuration information in a Customer-Managed Environment or Customer-Used External Service approved by the Customer. The Company shall use such information only for the installation, configuration, integration, testing, or acceptance purposes and within the scope approved by the Customer and, where practicable, shall not store a separate copy outside the Customer-Managed Environment or Customer-Used External Service. If temporarily stored in the Company’s work environment for the task, the copy and access information shall be securely deleted without delay upon the earliest of completion of support, achievement of the purpose, or withdrawal of access. Section 5 also applies if the destination is an overseas server or External Service.

  5. During installation, configuration, integration, or inspection, the Company shall not access, copy, or use files, screens, communications, transaction information, or personal information stored in or displayed through a Customer-Managed Environment or Customer-Used External Service beyond what is necessary for the approved support purpose. If logs, screens, or materials must be retained for error analysis or a similar purpose, the Company shall minimize or mask them to the extent necessary and apply the applicable retention period under Section 2.

  6. The Company does not request or separately store a Customer’s complete card number, CVC, or payment password to provide installation, configuration, or integration support. If registration for or purchase of a Customer-Managed Environment or Customer-Used External Service, or registration of a payment method, is required, the Customer shall, as a general rule, enter the information directly on the relevant provider’s screen.


7. Processing of Sensitive Information, Unique Identification Information, and Important Authentication Information

  1. As a general rule, the Company does not request or intentionally collect sensitive information under Article 23 of the Personal Information Protection Act, such as ideology or beliefs, political opinions, health, or sexual life, or unique identification information such as resident registration numbers, for the custom software development and implementation services.

  2. Account identifiers, financial-transaction and asset-holding information, API Keys, Secret Keys, access tokens, passwords, and server-access information are Important Authentication Information that may cause financial harm if disclosed or misused. Although such information does not invariably constitute sensitive information under the Personal Information Protection Act, the Company treats it as requiring a higher level of protection than ordinary contact information.

  3. The Company processes the minimum necessary Important Authentication Information only if testing cannot reasonably be accomplished using a simulated account, sandbox, read-only permission, or similar method and the Customer expressly consents to or requests testing using an actual account or API. Such information is used solely for installation, operation verification, error reproduction and analysis, debugging, testing, or acceptance approved by the Customer, and not for discretionary investment management, asset management, independent order decisions, or any other purpose.

  4. Where possible, the Customer shall use authentication information issued separately or exclusively for testing, exclude withdrawal and fund-transfer authority, and configure minimum permissions, duration, accounts, and permitted IP addresses. The Company does not record Important Authentication Information in source code, public repositories, ordinary logs, Deliverables, or project documents intended for long-term retention.

  5. The Company discontinues use of the applicable access rights and securely deletes without delay API Keys, Secret Keys, access tokens, passwords, and other Important Authentication Information in its possession upon the earliest of completion of testing, achievement of the purpose, or withdrawal of access by the Customer. If testing results must be retained, the Company retains only the minimum records from which authentication information has been removed or masked, for the retention period specified in Section 2.

  6. If materials provided by the Customer unavoidably contain legally defined sensitive information or unique identification information and the Company must process it, the Company shall confirm the necessity, items, purpose, and legal basis before processing and complete any procedures and additional security measures required by applicable law, including separate consent. If no lawful basis is confirmed or the information is unnecessary for the Services, the Company may refuse to receive it or request its deletion or masking.

  7. The Company does not disclose Important Authentication Information, including API Keys, Secret Keys, access tokens, and passwords, or identifiable account and transaction information in a portfolio, promotional or marketing materials, or a medium accessible to an unspecified number of persons. If the Company uses screens of Deliverables, general system configurations, technical features, or use cases for promotional or marketing purposes, Section 1(8) and Section 3(5) of this Policy apply. Accordingly, information sufficiently de-identified so that an individual, Customer, or project cannot reasonably be identified or inferred may be used without separate consent, while identifiable information may be used only within the scope separately consented to by the Customer and, where necessary, the relevant data subject.


8. Destruction of Personal Information

  1. The Company destroys personal information without delay when it is no longer necessary due to expiration of the retention period, achievement of the processing purpose, termination of the contract, or a lawful request by the data subject. Records required to be retained under applicable law are stored separately from other personal information and destroyed without delay upon expiration of the relevant period.

    Purpose of Retention

    Governing Law

    Retention Period

    Scope Retained

    Records concerning labeling and advertising

    Act on the Consumer Protection in Electronic Commerce

    6 months

    Labeling and advertising records applicable to the transaction

    Records concerning contracts, cancellation of orders, and similar matters

    Act on the Consumer Protection in Electronic Commerce

    5 years

    Minimum information necessary to establish the transaction, including contracting-party and contact information, quotations and contracts, consent to terms, and contract amendment, termination, and cancellation records

    Records concerning payment and supply of goods or services

    Act on the Consumer Protection in Electronic Commerce

    5 years

    Payment, deposit, cancellation, refund, settlement, delivery, and service-supply records

    Records concerning consumer complaints or dispute handling

    Act on the Consumer Protection in Electronic Commerce

    3 years

    Complaint or dispute details, related communications, and handling results

    Tax invoices, cash receipts, and tax-related records

    Framework Act on National Taxes, Value-Added Tax Act, and other applicable laws

    5 years after the statutory filing deadline for the applicable national tax (7 years for offshore transactions), or a longer period if required by applicable tax law

    Transaction and identification information necessary to issue supporting documents and file taxes

  2. Statutory records retained under paragraph 1 do not, as a general rule, include Important Authentication Information such as API Keys, Secret Keys, access tokens, passwords, or SSH Keys. Important Authentication Information is destroyed without delay after achievement of the purpose in accordance with Section 7.

  3. Personal information in electronic-file form is securely deleted in a manner designed to make recovery or reproduction difficult, and storage media are physically destroyed or initialized or erased by a method that makes recovery impossible. Paper documents are shredded or incinerated.

  4. If information scheduled for deletion remains in a backup maintained for security or recovery purposes, it is progressively deleted within a maximum of 30 days according to the applicable backup cycle and is not restored or used during that period except for disaster-recovery purposes. Backups managed by a Customer or external provider rather than the Company are governed by that Customer’s or provider’s policies.

  5. The Customer shall back up delivered Deliverables, source code, configuration files, data, and documents under the Customer’s own control. If the Company lawfully destroys project materials in accordance with the Terms of Use and this Policy, subsequent re-provision or recovery may be impossible.


9. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them

  1. A data subject may exercise the following rights against the Company to the extent provided by applicable law:

    1. request confirmation of whether personal information is processed and access thereto;

    2. request correction or deletion of inaccurate personal information;

    3. request suspension of processing;

    4. withdraw consent; and

    5. request transmission of personal information.

  2. A data subject may exercise these rights by emailing the Personal Information Protection and Grievance-Handling Department specified in Section 12. If a legal representative or duly authorized agent exercises a right, the Company may request the minimum information or documentation necessary to verify identity and authority under applicable law.

  3. The Company handles requests to exercise rights in accordance with the procedures and periods prescribed by applicable law. If a statutory ground for restriction applies, including a legal retention obligation or a risk of unjustly infringing another person’s life, body, property, or rights and interests, the Company may restrict or deny all or part of a request or defer processing, in which case it shall explain the reason and how to raise an objection.

  4. If personal information is subject to a correction or deletion request, the Company does not use or provide that personal information until the correction or deletion is completed. Processing necessary to comply with a legal obligation or protect rights is governed by applicable law.

  5. The Customer shall provide accurate and current personal information and shall not provide another person’s personal information without authorization or use another person’s account, payment method, or authentication information.

  6. If the Customer provides the Company with personal information of a corporate or organizational representative, officer, employee, end user, or other third party, the relevant data subject may exercise rights through the Customer or directly with the Company. The Company and the Customer shall cooperate as necessary to handle the request in accordance with their respective legal status and processing scope.

  7. The Company does not provide the Services to children under 14 years of age or intentionally collect their personal information. If the Company becomes aware that it has processed the personal information of a child under 14 without the consent of a legal representative, it shall take necessary measures without delay.

  8. The Company currently does not make decisions that materially affect a data subject’s rights or obligations solely by automated means. If the Company introduces such automated decisions in the future, this Policy shall explain the data subject’s rights under applicable law, including rights to refuse or request an explanation, and how to exercise them.


10. Measures to Ensure the Security of Personal Information

The Company implements the following technical, administrative, and physical measures appropriate to the nature and risks of the information processed in order to ensure the security of personal information:

  • operating a personal-information protection framework, establishing internal management standards, and minimizing the number of persons handling personal information;

  • granting minimum privileges for personal information and project materials, controlling access, and periodically reviewing privileges;

  • encrypting data in transit and encrypting important information that must be stored, or applying equivalent safeguards;

  • prohibiting Important Authentication Information such as API Keys, Secret Keys, and passwords from being recorded in source code, public repositories, or ordinary logs;

  • using test-only or temporary authentication information and minimum permissions with withdrawal authority removed;

  • preventing malware, applying security updates, checking vulnerabilities, responding to breaches, and managing necessary backups;

  • retaining and reviewing access records and monitoring abnormal access for error and security-incident analysis;

  • restricting network access to online customer-support channels, relay bots, and customer-support record repositories; authenticating administrators; minimizing privileges; and reviewing access and error logs;

  • applying physical and logical access controls to paper documents, business devices, and storage media; and

  • destroying authentication information and unnecessary project personal information without delay after achievement of the processing purpose.


11. Installation and Operation of Automatic Personal Information Collection Technologies and Methods of Refusal

  1. While using a website or online inquiry channel operated by the Company, cookies, IP addresses, access dates and times, browser and operating-system information, and access logs necessary to provide the service, maintain sessions, ensure security, and analyze errors may be automatically generated and collected.

  2. As of the effective date of this Policy, the Company does not collect behavioral information for customized or user-specific advertising as information required for the custom-development services.

  3. A data subject may allow or block the storage of cookies through web-browser settings. Blocking essential cookies or session information may restrict inquiries, security, or certain functions of the website. Detailed instructions are available in the help or privacy and security settings of the browser being used.

  4. Information automatically collected by a third-party intermediary platform, messenger, securities company, exchange, broker, charting or automation platform, cloud service, data or API service, or other External Service while the Customer uses that provider’s website or application is governed by the provider’s privacy policy and cookie policy.

  5. If the Company later introduces customized advertising, optional analytics, or a technology for a third party to collect online behavioral information, the Company shall provide any notice, consent, or refusal mechanism required by applicable law and amend this Policy.


12. Personal Information Protection and Grievance-Handling Department

  1. The Company operates the department below to oversee personal-information processing and handle data-subject inquiries, complaints, and requests for relief concerning personal information.

    Category

    Department

    Contact

    Personal Information Protection and Grievance-Handling Department

    Hanco Lab Customer Support

    contact@hancolab.com

  2. A data subject may contact the department above to request access to, correction or deletion of, or suspension of processing of personal information; withdraw consent; report a personal-information breach; or make another privacy-related inquiry. The Company shall handle the request within the procedures and periods prescribed by applicable law.


13. Remedies for Infringement of Data-Subject Rights

A data subject may contact or apply for dispute mediation or other relief from the following authorities regarding a personal-information infringement. These authorities are separate from the Company, and the Company endeavors to handle data-subject inquiries and grievances in the first instance.

  • Personal Information Infringement Report Center: 118 without area code / privacy.kisa.or.kr

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr

  • Supreme Prosecutors’ Office: 1301 without area code / www.spo.go.kr

  • Korean National Police Agency Cybercrime Reporting System: 182 without area code / ecrm.police.go.kr


14. Amendments to this Privacy Policy

  1. If the Company adds, deletes, or amends this Policy, it shall announce the effective date and principal changes on the Company website, through a customer-support channel, or by another reasonable method.

  2. As a general rule, a change materially affecting data-subject rights shall be announced at least 30 days before its effective date, and any other change at least seven days before its effective date. If applicable law requires a longer period, separate notice, or consent, that requirement shall apply.

  3. The Company retains and discloses prior versions of this Privacy Policy so that data subjects may review them.

  4. If a PG provider, External Service, platform, or business tool directly contracted for by the Company, or the structure of an overseas transfer of personal information, is confirmed or changed, the Company shall include the relevant provider and processing details in this Policy before the processing begins.

  5. The Company may provide an English or Japanese translation of this Policy. If there is any difference in meaning or interpretation between a translation and the Korean version, the Korean version shall prevail. However, this shall not limit any mandatory rights of data subjects under applicable law.


This Policy applies from its effective date.

이전 버전 문서 보기

Hanco Lab is strictly a software development and provision company, not a licensed financial investment firm. All software, algorithms, backtesting results, and statistical data provided by us are merely the outcomes of specific logical structures implemented through programming methodologies, or the results of mathematical and statistical calculations. Under no circumstances should they be construed as investment advice, consultation, or a guarantee of profits. Due to the nature of financial markets, past performance and data do not guarantee future results, and we assume no legal liability for any direct or indirect losses arising from the use of our programs. All decisions regarding investment activities and the subsequent financial responsibilities rest entirely with the user (investor).

Hanco Lab

Business Registration Number: 879-02-03256 | CEO: Jimin CHEON
Hosted by : Framer B.V. | Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
(16335) 425-1201, 40, Jeongjacheon-ro 189beon-gil, Jangan-gu, Suwon-si, Gyeonggi-do, Republic of Korea 

Hanco Lab is strictly a software development and provision company, not a licensed financial investment firm. All software, algorithms, backtesting results, and statistical data provided by us are merely the outcomes of specific logical structures implemented through programming methodologies, or the results of mathematical and statistical calculations. Under no circumstances should they be construed as investment advice, consultation, or a guarantee of profits. Due to the nature of financial markets, past performance and data do not guarantee future results, and we assume no legal liability for any direct or indirect losses arising from the use of our programs. All decisions regarding investment activities and the subsequent financial responsibilities rest entirely with the user (investor).

Hanco Lab

Business Registration Number: 879-02-03256 | CEO: Jimin CHEON
Hosted by : Framer B.V. | Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
(16335) 425-1201, 40, Jeongjacheon-ro 189beon-gil, Jangan-gu, Suwon-si, Gyeonggi-do, Republic of Korea 

ハンコラボ(Hanco Lab)は金融投資業者ではなく、純粋なソフトウェア開発および提供業者です。当社が提供するすべてのソフトウェア、アルゴリズム、バックテスト結果、および統計データは、特定の論理構造をプログラミング的手法で実装した結果、または数学的・統計的演算の結果にすぎず、いかなる場合においても投資助言、コンサルティング、あるいは収益の確約として解釈されるものではありません。金融市場の特性上、過去のデータや実績は将来の結果を保証するものではなく、当社はプログラムの使用に起因して発生したいかなる直接的または間接的な損失についても、一切の法的責任を負いかねます。すべての投資行為に関する決定権およびそれに伴う財務的責任は、全面的にユーザー(投資家)ご自身に帰属します。

Hanco Lab

事業者登録番号 : 879-02-03256 | 代表者 : チョン・ジミン
ホスティングサービス : Framer B.V. | Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
(16335) 425-1201, 40, Jeongjacheon-ro 189beon-gil, Jangan-gu, Suwon-si, Gyeonggi-do, Republic of Korea 

ハンコラボ(Hanco Lab)は金融投資業者ではなく、純粋なソフトウェア開発および提供業者です。当社が提供するすべてのソフトウェア、アルゴリズム、バックテスト結果、および統計データは、特定の論理構造をプログラミング的手法で実装した結果、または数学的・統計的演算の結果にすぎず、いかなる場合においても投資助言、コンサルティング、あるいは収益の確約として解釈されるものではありません。金融市場の特性上、過去のデータや実績は将来の結果を保証するものではなく、当社はプログラムの使用に起因して発生したいかなる直接的または間接的な損失についても、一切の法的責任を負いかねます。すべての投資行為に関する決定権およびそれに伴う財務的責任は、全面的にユーザー(投資家)ご自身に帰属します。

Hanco Lab

事業者登録番号 : 879-02-03256 | 代表者 : チョン・ジミン
ホスティングサービス : Framer B.V. | Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
(16335) 425-1201, 40, Jeongjacheon-ro 189beon-gil, Jangan-gu, Suwon-si, Gyeonggi-do, Republic of Korea 

© 2025-2026 Hanco Lab. All Rights Reserved.

© 2025-2026 Hanco Lab. All Rights Reserved.