Ravenbe

LEGAL

Privacy Policy

Ravenbe Corp. (“the Company”) establishes and discloses the following privacy policy pursuant to Article 30 of the Personal Information Protection Act of Korea (PIPA), in order to protect the personal data of data subjects and to handle related grievances promptly.

Effective 2026-09-16 · Version 1.0

This English version is provided for convenience only. In the event of any discrepancy in interpretation, the Korean version prevails.

1. Purpose of processing

The Company processes personal data for the purposes below. Data is not used for any other purpose, and if the purpose changes, the Company takes the separate measures required by Article 18 of PIPA.

  • Receiving and responding to inquiries — reviewing and replying to submissions made through the website inquiry form
  • Consultation and contract review — service consultation following the inquiry, and assessment of whether to enter into a contract

The Company does not send marketing messages, build marketing profiles, or make automated decisions using personal data.

2. Categories of personal data processed

TypeItemsHow it is collected
RequiredName, email address, inquiry contentEntered by the user in the inquiry form
OptionalCompany name, area of interestEntered by the user in the inquiry form
Generated automaticallyIP address, browser information (User-Agent), access timestampRecorded by the web server during service use

Optional fields may be left blank with no effect on the inquiry. The Company does not collect sensitive data (PIPA Article 23) or unique identifying information (Article 24).

3. Legal basis for processing

The Company processes personal data for responding to inquiries without separate consent. The basis is PIPA Article 15(1)4 — where processing is necessary to take measures at the request of the data subject in the course of entering into a contract — supplemented by Article 15(1)6 (legitimate interests of the controller). Submitting the inquiry form is, on its plain terms, a request by the data subject, and contact details are indispensable for replying.

This disclosure is made under PIPA Article 22(3), which requires a controller to disclose the categories and legal basis of personal data processed without consent, separately from data processed on the basis of consent. The Company currently processes no personal data on the basis of consent.

As no consent is obtained, there is no consent withdrawal procedure. Data subjects may instead request suspension of processing or deletion at any time using the method in Section 11, and the Company will act without delay.

4. Retention and use period

TypeRetention periodReason
Inquiry submissions1 year from the date of receiptReviewing response history and follow-up consultation
Web server access logs14 daysService operations and incident response

Data is destroyed without delay before the end of these periods if the data subject requests deletion, or once the purpose of processing has been achieved.

5. Provision to third parties

The Company does not provide personal data to third parties. Data may be provided only where specifically required by law or lawfully requested by an investigative authority, and in such cases only to the minimum extent necessary.

6. Outsourcing of processing

The Company outsources the following processing in order to deliver inquiry notification email.

ProcessorOutsourced workRetention period
NAVER Cloud Corp.Sending inquiry notification email (Cloud Outbound Mailer)Until termination of the outsourcing agreement

In accordance with PIPA Article 26, the outsourcing agreement covers the prohibition of processing beyond the stated purpose, technical and administrative safeguards, restrictions on sub-processing, supervision of the processor, and liability for damages. Any change to the outsourced work or the processor will be disclosed through this policy.

7. Transfer of personal data abroad

The Company does not transfer personal data outside Korea. The servers and mail delivery infrastructure used by this website are located in Korea, and static assets including web fonts are served from the Company's own servers without calling third-party services.

8. Destruction procedure and method

When personal data is no longer needed — because the retention period has expired or the purpose of processing has been achieved — the Company destroys it without delay.

  • Procedure — data whose retention period has expired or whose purpose has been achieved is identified and destroyed following confirmation by the privacy officer.
  • Method — electronic files are deleted by a method that makes the records unrecoverable, including copies remaining in mailboxes and in backups.

The Company does not print or retain inquiry submissions in paper form.

9. Automatic collection devices and how to refuse them

The Company does not use cookies for advertising or behavioural analytics. This website currently uses exactly one cookie.

NamePurposeHow to refuse, and the effect
NEXT_LOCALERemembers the display language chosen by the visitor (Korean / English)Cookies can be refused in your browser settings. If refused, your language choice is not retained and must be selected on each visit.

This cookie is strictly necessary for the service and does not identify individuals. If the Company adopts analytics tools in future, this policy will be amended and announced under Section 12 before they are deployed.

10. Security measures

The Company takes the following measures to keep personal data secure.

  • Encryption in transit — HTTPS is applied across the entire website and HSTS is configured, so unencrypted connections are refused.
  • Least-privilege access — access to systems that process personal data is limited to the minimum number of people required.
  • Access logging — server access logs are retained and reviewed for anomalies.
  • Data minimisation — only the minimum items needed to answer an inquiry are collected, and inquiry content, email addresses and names are not written to server logs.

11. Rights of data subjects and legal representatives

Data subjects may exercise the following rights against the Company at any time.

  • Request access to personal data (PIPA Article 35)
  • Request correction of errors (Article 36)
  • Request deletion (Article 36)
  • Request suspension of processing (Article 37)

Rights may be exercised in writing or by email using the contact in Section 12, and the Company will act without delay. Where correction or deletion is requested, the Company will not use or provide the data concerned until the correction or deletion is complete. Rights may also be exercised through a legal representative or an authorised agent.

To seek remedy for infringement of personal data rights, you may apply to the following bodies for dispute resolution or counselling.

BodyPhoneWebsite
Personal Information Dispute Mediation Committee+82-1833-6972www.kopico.go.kr
Privacy Infringement Report Centre (KISA)+82-118privacy.kisa.or.kr
Supreme Prosecutors' Office, Cybercrime Division+82-1301www.spo.go.kr
National Police Agency, Cyber Bureau+82-182ecrm.police.go.kr

12. Privacy officer and changes to this policy

The Company has designated the following department to take overall responsibility for personal data processing and to handle complaints and remedy requests from data subjects. Under PIPA Article 31(2), where no separate privacy officer is designated, the owner or representative of the business becomes the privacy officer.

ItemDetail
DepartmentPrivacy Office
Contactsh.lee@ravenbe.com

Data subjects may direct any inquiry, complaint or remedy request relating to personal data arising from use of the Company's services to the contact above. The Company will respond and act without delay.

This privacy policy applies from its effective date. Where content is added, removed or corrected due to changes in law, policy or security technology, the change will be announced on this website at least seven days before it takes effect.