1. Privacy Policy

ZTACOM Co., Ltd. (the “Company”) values users’ personal information in providing this Service (the “Service”) and establishes and discloses this Privacy Policy to process and protect personal information safely in accordance with applicable laws.

This Policy applies to devices, mobile applications, web services, customer support, affiliated services, and related ancillary services provided by the Company.

Article 1 (Basic Principles for Processing Personal Information)

The Company processes personal information within the minimum scope necessary to provide the Service and, when the processing purpose is achieved or the retention period expires, destroys it without delay in accordance with applicable laws and internal policies.

The Company does not sell personal information or health-related information that can identify a user to any third party without the user’s consent.

The Company may anonymize or pseudonymize personal information and use it within the scope permitted by applicable laws for service quality improvement, statistical analysis, research, AI model improvement, new service development, and data-based business.

Article 2 (Items of Personal Information Collected and Methods of Collection)

The Company may collect the following information in the course of account registration, service use, device linkage, customer consultation, payment, delivery, and use of affiliated services. Actual required and optional items are separately indicated on the service screen, consent screen, or application form.

CategoryItems Collected/ProcessedNotes
Account registration and account managementName, email address, mobile phone number, ID, password or simple-login identifier, year of birth or age group, gender, etc.Some items may be optional depending on the service structure.
Health profileHeight, weight, gender, age group, wearing information, goal-setting information, etc.For health analysis and report provision.
Measurement informationHeart rate, heart rate variability, blood oxygen saturation, skin temperature change, activity level, steps, sleep-related information, wearing status, battery status, abnormal-signal detection information, etc.Health-related information requiring separate protection.
App and device informationMobile device model, OS version, app version, device identifier, Bluetooth connection information, access logs, error logs, usage records, etc.For service stabilization and troubleshooting.
Location informationLocation information collected from the mobile device when using location-based functions such as SOS, guardian alerts, or device finding.Subject to the Location-Based Service Terms.
Payment, points, and delivery informationPayment history, point accrual/use history, refund request history, shipping address, recipient information, etc.When using paid services, point mall, or affiliated products.
Customer support informationInquiry details, consultation history, email address, phone number, attachments, etc.For customer support and dispute response.

Article 3 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. If the processing purpose changes, the Company will provide necessary notices or obtain consent in accordance with applicable laws.

  • User identification, account creation and management, identity verification, and service provision
  • Device linkage, health data measurement, analysis, report provision, and alerts
  • Provision of personalized health information and AI-based guidance on sleep, stress, recovery, activity, etc.
  • Safety-management support functions such as abnormal-signal alerts, SOS, and guardian/managing-organization alerts
  • Point accrual/use, paid services, affiliated content, delivery, and refund handling
  • Customer inquiries, complaint handling, troubleshooting, prevention of unauthorized use, and service security
  • Service improvement, statistical analysis, research, AI model improvement, new service development, and data-based business
  • Compliance with legal obligations, dispute response, audits, and record retention

Article 4 (Processing of Health-Related Information and Sensitive Information)

Due to the nature of the Service, the Company may process health-related information such as heart rate, heart rate variability, blood oxygen saturation, skin temperature change, sleep information, activity information, and abnormal-signal detection information.

The Company processes such information within the scope of service provision, health reports, personalized guidance, abnormal-signal alerts, guardian/managing-organization alerts, service improvement, and data use permitted by applicable laws.

The Company protects health-related information at a higher level than ordinary personal information and obtains separate consent through the service screen or consent screen where separate consent is required by law.

Health information, AI guidance, and reports provided through the Service are reference materials for health management and do not replace diagnosis, treatment, prescription, or emergency rescue systems of medical institutions.

Article 5 (Use of Pseudonymized Information, Anonymized Information, and Data-Based Business)

The Company may anonymize or pseudonymize user information and use it within the scope permitted by applicable laws for service quality improvement, statistical analysis, scientific research, AI algorithm improvement, product performance validation, new service development, market analysis, and data-based business.

“Anonymized Information” means information that cannot identify a specific individual and is reasonably unlikely to identify a specific individual even when combined with other information. The Company may use Anonymized Information or statistical information for data analysis, research, validation, partnerships, licensing, data platform linkage, or transactions.

“Pseudonymized Information” means information processed so that a specific individual cannot be identified without the use or combination of additional information. The Company may process or provide Pseudonymized Information to third parties within the purposes and procedures permitted by applicable laws, such as statistical compilation, scientific research, service improvement, AI algorithm improvement, and product validation.

When processing Pseudonymized Information or Anonymized Information, the Company takes necessary protective measures such as prevention of re-identification, access control, separate storage, and processing record management.

The Company does not sell personal information or health-related information that directly identifies a user to data platforms, research institutions, partners, insurers, pharmaceutical companies, medical institutions, or other third parties without the user’s consent. However, Anonymized Information, statistical information, or Pseudonymized Information lawfully processed under applicable laws may be used within the scope of the purposes set forth in this Article.

Article 6 (Retention and Use Period of Personal Information)

The Company destroys personal information without delay when the purpose of collection or use is achieved, or when the user withdraws membership, withdraws consent, or requests deletion. However, where necessary for legal retention obligations, dispute response, prevention of unauthorized use, settlement, disaster recovery, or backup operation, the Company may separately retain the information for the period necessary for such purposes.

Major retention periods under applicable laws are as follows. Actual applicability and periods may vary depending on applicable laws and the service operation model.

Retained ItemRetention PeriodReason for Retention
Records on contracts or withdrawal of offers5 yearsAct on Consumer Protection in Electronic Commerce, etc.
Records on payment and supply of goods/services5 yearsAct on Consumer Protection in Electronic Commerce, etc.
Records on consumer complaints or dispute handling3 yearsAct on Consumer Protection in Electronic Commerce, etc.
Access logs and other service security recordsPeriod required under applicable laws or internal policiesPrevention of unauthorized use, security, and troubleshooting.
Health data and service usage recordsDuring the service period and until the purpose is achieved. After withdrawal, such information may be separately retained only when necessary for laws, disputes, settlement, backups, etc.Service provision, troubleshooting, dispute response, and legal compliance.

Anonymized information or statistical information may be separately retained and used within a scope that does not identify a specific individual.

Article 7 (Provision of Personal Information to Third Parties)

In principle, the Company does not provide users’ personal information to outside parties. However, where the user has consented, where there is a legal basis, or where necessary to provide the Service, the Company may provide personal information to third parties within the necessary scope.

Where third-party provision is necessary, the Company may notify the user of the recipient, purpose of provision, items provided, retention and use period, right to refuse consent, and disadvantages of refusal through the app, web, application form, or separate consent screen.

The following are types of third-party provision that may occur during service operation. Actual provision and items may vary depending on the functions selected by the user and the content of separate consent.

RecipientPurpose of provisionItems providedRetention and use period
Guardian, family member, or managing organization designated by the userAbnormal-signal alerts, SOS alerts, health status confirmation, and care service provisionName or nickname, alert time, alert type, necessary health information, wearing/battery status, and location information when the relevant function is usedUntil linkage is terminated, service ends, or consent is withdrawn
Emergency contact target or rescue, counseling, or safety-management organizationEmergency contact requested by the user, safety confirmation, and assistance with rescue requestsName, contact information, location information, alert details, and necessary health status informationUntil the purpose is achieved or for the period required under applicable laws or institutional standards
Point mall, delivery company, payment company, affiliated content providerPoint use, product purchase, delivery, payment, refund, and affiliated service provisionName, contact information, shipping address, payment/order/point information, and information necessary for the affiliated serviceUntil the transaction ends and for the legally required retention period, or until the purpose is achieved
Affiliated medical institution, company, insurer, or health-management service providerProvision of affiliated health-management services requested by the userMember information, health reports, measurement data, consultation information, etc. consented to by the userUntil the affiliated service ends, consent is withdrawn, or the separately notified period expires
Data platform operator, research institution, analytics partner, etc.Statistical analysis, research, AI improvement, product validation, data platform linkage, dataset licensing or transactionsIn principle, anonymized information or statistical information. Pseudonymized information may be provided within the scope permitted by applicable laws. Separately consented identifiable information if applicablePeriod under applicable laws, contracts, and separate notices

Article 8 (Entrustment of Personal Information Processing)

The Company may entrust part of its personal information processing work to external specialists to provide the Service smoothly. The Company takes protective measures such as necessary contracts, management and supervision, and access control so that processors process personal information safely.

Processors and entrusted work may change depending on service operation status, and important changes will be notified through this Policy or service notices.

Type of ProcessorEntrusted WorkRetention and Use Period
Cloud and server operation provider (e.g., Google Cloud Platform)Service server operation, data storage, backup, security, and troubleshootingUntil member withdrawal, termination of the entrustment contract, or achievement of the processing purpose
App infrastructure and notification provider (e.g., Google Firebase)Push notifications, app error logs, app analytics, and authentication supportUntil member withdrawal, termination of the entrustment contract, or achievement of the processing purpose
Payment gateway, app market, settlement providerPaid service payment, refund, settlement, and payment record managementLegally required retention period or until the purpose is achieved
Delivery company, point mall operator, customer support providerProduct delivery, exchange/return, customer consultation, and inquiry responseUntil the purpose is achieved or for the legally required retention period
Data processing, AI analysis, security, and quality validation partnerData cleansing, analytical support, algorithm validation, security inspection, and service quality improvementPeriod under the entrustment contract and applicable laws

Article 9 (Cross-Border Transfer of Personal Information)

The Company may store, process, access, or transfer personal information overseas where necessary for service provision and operation, including cloud services, app infrastructure, overseas affiliated services, and global data platform linkage.

Where cross-border transfer of personal information is necessary, the Company will notify the user of the items of personal information transferred, country of transfer, timing and method of transfer, recipient, purpose of use, retention and use period, and method of refusing transfer through this Policy, app, web, or separate consent screen, or obtain consent where required by applicable laws.

The Company operates the Service in consideration of privacy-related laws of the countries or regions where the Service is provided, and may provide additional notices or supplemental policies to relevant users where separate notices, consent, rights procedures, or supplemental policies are required.

Article 10 (User Rights and How to Exercise Them)

Users may request access, correction, deletion, suspension of processing, withdrawal of consent, and membership withdrawal regarding their personal information at any time.

Users may exercise their rights through the app settings, customer center, email, or other methods provided by the Company, and the Company will take action without delay in accordance with applicable laws.

However, some requests may be restricted where there is a legal retention obligation or a legitimate reason such as service provision, dispute response, prevention of unauthorized use, or settlement.

If a user requests deletion of personal information or withdrawal of consent, all or part of the Service may be restricted.

Article 11 (Destruction of Personal Information)

The Company destroys personal information without delay when the retention period expires or the processing purpose is achieved.

Personal information in electronic file format is deleted by technical methods so that recovery or reproduction is difficult, and paper documents are shredded or incinerated.

Backup data may be separately retained for service stability, disaster recovery, and security purposes and will be sequentially destroyed according to internal retention cycles and backup policies.

Article 12 (Measures to Ensure the Security of Personal Information)

The Company implements reasonable technical, managerial, and physical safeguards to protect personal information, including access control, encryption, access log retention, security program operation, network security, internal training, and processor management.

The Company restricts access rights to information requiring higher protection, such as health-related information, location information, and pseudonymized information, and, where necessary, conducts separate storage and processing record management.

Article 13 (Personal Information Protection Officer and Contact)

The Company designates a Personal Information Protection Officer as follows to handle inquiries, complaints, and damage relief regarding personal information processing.

Personal Information Protection Officer: In-Gyu Lee

Department/Position: Management Administration / Manager

Contact: 02-6736-9990

Email: info@ztacom.com

Article 14 (Changes to this Privacy Policy)

The Company may revise this Policy due to changes in laws, service content, or personal information processing status.

When revising this Policy, the Company will notify users of the effective date, changes, and reasons for changes through the app, website, or service notices.

For changes that materially affect users’ rights or obligations, the Company may provide prior notice or obtain separate consent in accordance with applicable laws.

Supplementary Provision

This Privacy Policy takes effect on June 30, 2026.