Privacy Policy

GinnoLab · Privacy Policy - based on Korea's Personal Information Protection Act (amended 14 March 2023, effective 15 September 2023) and its Enforcement Decree

KO

GinnoLab (the Company) establishes and publishes this Privacy Policy under Article 30 of Korea's Personal Information Protection Act to protect personal data and promptly and effectively handle related concerns.

Company / RepresentativeGinnoLab / Jinho Yoon
AddressRoom 203, 22 Sicheong-ro, Wonju-si, Gangwon State, Republic of Korea
IndustryManufacturing (small workplace with four regular employees)
Publication MethodPermanently linked from the website footer and displayed on the workplace noticeboard
Effective Date / RevisionEffective 24 August 2026 / Rev.0 (initial issue)

Article 1. Purposes of Processing

The Company processes personal data for the purposes below and does not use it for other purposes. If purposes change, it takes required measures, including separate consent, under Article 18 of the Personal Information Protection Act.

CategoryPurpose
Human Resources and Labor ManagementRecruitment, employment contracts, payroll and social insurance, attendance and service administration, training records, separation and severance settlement, and statutory recordkeeping
Business Partner ManagementIdentify contacts; conclude and perform contracts; manage orders, deliveries and inspections; invoice and settle payments; communicate transaction matters; resolve disputes
Inquiry HandlingConfirm and respond to product inquiries, quotation requests, complaints and grievances received through the website, telephone or email
Statutory CompliancePrepare, retain and submit records required by tax, labor, occupational safety and health, and other applicable laws

Article 2. Personal Data Processed

Anonymous Grievances & Suggestions: Anonymous submission formdoes not require login, name, email or telephone number. It stores the category, title, message, receipt number, submission time and processing status, accessible only to designated personnel. Do not include unnecessary personal information in your message. IP addresses and browser information are not separately stored with reports, although hosting-provider security and access logs may be generated. The contact fields required for general website inquiries below do not apply to the anonymous form.

The Company processes the following data. As a small workplace, it does not operate public membership registration and limits data to what is necessary for its work.

Data SubjectData CollectedCollection MethodBasis for Collection
Employees
(including job applicants)
Required: name, date of birth, contact details, address, email, bank account, education and work history
Legally required: resident registration number, solely for payroll and statutory social insurance reporting
Optional: qualifications, emergency contact and family relationships where relevant to family allowances or year-end tax settlement
Job applications and paper or electronic documents submitted when employment contracts are concluded Article 15(1)(1), (2) and (4) (consent, statutory obligations and contract performance)
Resident registration number: Article 24-2(1)(1)
Business partner contacts Required: company, department and position, contact person's name, telephone and email
Optional: fax number
Contracts, business cards, orders, quotations and received emails Article 15(1)(4) (necessary to conclude or perform a contract)
Website inquirers Required: name or company name, telephone or email, and inquiry content
Automatically generated: access IP address and date/time
Website inquiry form Article 15(1)(1) (consent)
The Company generally does not process sensitive data such as beliefs, union membership, political opinions, health or sexual-life information. Where processing is unavoidable, such as legally required medical examination results, obtain separate consent and store the information separately.

Article 3. Processing and Retention Periods

The Company processes and retains data for the period prescribed by law or consented to at collection. The periods for each activity are listed below.

Processing ActivityRetention PeriodLegal Basis
Human Resources and Labor Management3 years after employment endsArticle 42, Labor Standards Act (retention of employment records)
Payroll and withholding tax records5 years after the filing deadlineArticle 85-3, Framework Act on National Taxes
Eligibility acquisition and loss for the four statutory social insurance programs3 yearsNational Pension Act, Employment Insurance Act and related laws
Occupational safety and health records, including training and medical examination results3 years generally; 5 years for medical examination resultsEnforcement Rule of the Occupational Safety and Health Act
Business partner contact information5 years after the business relationship endsArticle 33, Commercial Act; Article 85-3, Framework Act on National Taxes
Transaction evidence, including tax invoices5 yearsArticle 71, Value-Added Tax Act
Website inquiry records1 year after handling is completedIndividual consent
Unsuccessful job applicant information3 months after recruitment ends; 1 year with separate retention consentArticle 11, Fair Hiring Procedure Act
Personal data system access logs1 year (2 years when processing data of 50,000 or more individuals)Article 8, Standards for Ensuring the Safety of Personal Information

Article 4. Third-Party Disclosure

RecipientPurpose of DisclosureData DisclosedRetention and Use Period
National Health Insurance Service, National Pension Service, Korea Workers' Compensation & Welfare Service, and competent tax officeStatutory obligations including social insurance reporting and reconciliation and withholding taxName, resident registration number, address, contact details and remunerationPeriod required by applicable law
Company-appointed payroll transfer bankSalary and expense transfersName and bank account numberUntil the transfer is completed
Company-appointed medical examination providerMedical examinations under the Occupational Safety and Health ActName, date of birth, affiliation and contact details5 years after the medical examination
If other third-party disclosure is needed, give advance notice of the recipient, purpose, data, retention period, right to refuse consent and consequences of refusal, and obtain separate consent.

Article 5. Outsourced Processing

The Company outsources the following personal data processing activities for efficient operations.

Processor (service provider)Outsourced WorkProcessing Term
Kim Seunghyeon Tax & Accounting OfficePayroll calculation, statutory social insurance reporting and tax filing servicesUntil the service contract ends
Website maintenance provider
(name disclosed upon appointment)
Website operation and maintenance and inquiry-board managementUntil the service contract ends
Document shredding contractor
(name disclosed upon appointment)
Destruction of paper documents containing personal dataUntil destruction is completed

Article 6. Deletion Procedures and Methods

1. Deletion Procedure The privacy officer identifies data due for deletion and deletes it with the approval of the CEO, who also serves as Chief Privacy Officer. Record deletion results in the Personal Data Deletion Register and retain them for three years.

2. Deletion Methods

Storage FormatDeletion Method
Electronic filesPermanently delete using dedicated deletion software so recovery is impossible. When disposing of media, physically destroy it by drilling or incineration, or degauss it.
Paper and printed documentsShred or incinerate. Obtain a destruction certificate when using a contractor.

Article 7. Individual and Representative Rights, Duties and Procedures

RightResponse DeadlineHow to Submit
Access requestWithin 10 days of receiptVisit the business address, call +82 10-9201-2448,
Email ceo@ginnolab.com; fax +82 504-958-1746
Identity verification, such as an identification document check, is required upon receipt.
Correction or deletion requestWithin 10 days of receipt
Processing-suspension requestWithin 10 days of receipt
Withdrawal of consentImmediately upon request

Article 8. Security Safeguards

The Company takes the following safeguards under Article 29 of the Personal Information Protection Act and the Standards for Ensuring the Safety of Personal Information.

CategoryAction
Organizational Measures· Establish and implement an internal personal data management plan and review implementation annually
· Limit authorized personal data handlers to the minimum necessary for work
· Train personal data handlers at least annually and obtain confidentiality pledges
Technical Measures· Differentiate access permissions to personal data systems, including PCs, and keep records of permission changes and revocations
· Set account passwords of at least eight characters combining letters, numbers and special characters, and change them every six months
· Encrypt unique identifiers, passwords and account numbers in storage and apply safeguards during transmission
· Retain system access logs for at least one year, review monthly and protect against alteration
· Install and automatically update anti-malware software
· Set work PC screensavers to activate after 10 minutes and prohibit internet-sharing settings
Physical Measures· Store documents and media containing personal data in locked cabinets
· Control office access and lock the premises outside working hours
· Require prior approval before removing personal data from the workplace

Article 9. Automatic Collection Technologies and Opt-Out

Article 10. Pseudonymized Information

The Company does not currently process pseudonymized data for statistics, scientific research or public-interest archiving. If it does so in future, it will disclose the purposes, data, use periods, third-party provision and safeguards in this policy under Articles 28-2 through 28-7 of the Personal Information Protection Act.

Article 11. Privacy Officers and Grievance Contact

The Company appoints the following Chief Privacy Officer to oversee processing and handle privacy complaints and remedies. As a small workplace with four regular employees, CEO Jinho Yoon also serves as Chief Privacy Officer under Article 32(2) of the Enforcement Decree of the Personal Information Protection Act.

CategoryName / PositionContactResponsibilities
Chief Privacy OfficerJinho Yoon / CEOTelephone +82 10-8965-7458
Email ceo@ginnolab.com
Overall privacy management, policy establishment and revision, safeguard implementation review, and breach response oversight
Privacy Officer
(Grievance contact)
Gibeom Kwon / ESG OfficerTelephone +82 10-9201-2448
Email coo@ginnolab.com
Receive access, correction, deletion and suspension requests; handle privacy concerns; support staff training; review access logs

Contact the Chief Privacy Officer or responsible department for privacy inquiries, complaints or remedies arising from Company services. The Company will respond and act without delay.

Article 12. Domestic Representative

As a business with an address or place of business in Korea, the Company is not subject to the domestic representative requirement in Article 31-2 of the Personal Information Protection Act.

Article 13. Remedies for Privacy Infringements

Individuals may seek dispute resolution or advice from the Personal Information Dispute Mediation Committee or KISA Privacy Infringement Report Center. Other privacy-related reports and consultations may be directed to the organizations below.

OrganizationResponsibilitiesTelephoneWebsite
Personal Information Dispute Mediation CommitteePersonal data dispute mediation and collective dispute mediation (civil remedies)1833-6972www.kopico.go.kr
Privacy Infringement Report Center (Korea Internet & Security Agency)Report privacy infringements and request advice118 (within Korea, no area code)privacy.kisa.or.kr
Supreme Prosecutors' Office Cyber Investigation DivisionInvestigation and consultation on personal data-related crimes1301 (within Korea, no area code)www.spo.go.kr
Korean National Police Agency Cyber Investigation BureauInvestigation and reporting of personal data-related crimes182 (within Korea, no area code)ecrm.police.go.kr
A person whose rights or interests are infringed by an act or omission of a public institution concerning requests under Articles 35, 36 or 37 of the Personal Information Protection Act may seek administrative review under the Administrative Appeals Act. Central Administrative Appeals Commission: 110 within Korea, www.simpan.go.kr.

Article 14. Changes to This Policy

Supplementary Provisions
Article 1. Effective Date: this Privacy Policy takes effect on 24 August 2026.
Article 2. Transitional Provision: this policy also applies to personal data collected and retained before its effective date.
· Announcement: 24 August 2026 · Effective: 24 August 2026
24 August 2026Jinho Yoon, CEO of GinnoLab
Document No. GL-S-4-51-01 · Revision Rev.0 (initial issue) · GinnoLab