Privacy Policy
Last updated · 2026-09-26 · 한국어판 (Korean version)
2026-09-24 시행된 개정
이 문서는 2026-08-25에 게시되어 2026-09-24부터 시행 중입니다. 아래 본문이 개정된 내용입니다.
개정 사유: 결제 제공사의 지위를 실제 계약·처리 구조에 맞게 바로잡고(수탁자 → 등록판매자이자 독립된 개인정보처리자), 국외 이전 항목에 이전받는 자의 상호·연락처·소재지·보유기간·이전 시기와 방법을 명시합니다.
제4조 처리 위탁 및 제3자 제공
개정 전 결제 처리: 회사가 지정한 해외 결제 제공사 — 등록판매자(Merchant of Record)로서 결제·청구·세금 처리를 자체 개인정보처리방침에 따라 수행합니다. … 회사는 법령에 근거하거나 이용자의 동의가 있는 경우를 제외하고 개인정보를 제3자에게 제공하지 않습니다.
개정 후 (위탁 목록에서 결제 처리를 뺍니다.) 회사는 결제 처리를 위해 Dodo Payments Inc.(연락처: [email protected])에 주문 식별자·상품 코드를 제공합니다. 동 제공사는 등록판매자(Merchant of Record)이자 독립된 개인정보처리자로서 결제·청구·세금 처리를 자체 개인정보처리방침에 따라 수행합니다. 이용자가 결제 화면에서 직접 입력하는 카드번호·청구 정보는 동 제공사가 직접 수집·처리하며, 회사는 이를 수집하거나 저장하지 않습니다. 회사는 위 결제 제공사에 대한 제공, 법령에 근거한 경우 및 이용자의 동의가 있는 경우를 제외하고 개인정보를 제3자에게 제공하지 않습니다.
제5조 개인정보의 국외 이전 — 결제 제공사 항목
개정 전 해외 결제 제공사(결제 처리 · 국외): 결제·청구 정보 — 등록판매자인 해당 제공사의 보유 정책에 따름
개정 후 Dodo Payments Inc.(결제 처리 · 미국 델라웨어주 법인 · 제공사가 이용하는 국외 데이터센터 소재 국가 포함 · 연락처: [email protected]): 회사가 전달하는 주문 식별자·상품 코드 — 결제·청구·세금 처리 목적으로 결제 요청 시 정보통신망을 통해 전송 — 해당 제공사의 보유 정책(관련 법정 시효기간에 2개월을 더한 기간, 청구가 제기된 경우 그 처리에 필요한 기간)에 따름. 이용자가 제공사의 결제 화면에서 직접 입력하는 결제·청구 정보는 동 제공사가 독립된 개인정보처리자로서 자체 방침에 따라 직접 수집·처리합니다.
2026-09-02 시행된 개정
이 문서는 2026-09-01에 게시되어 2026-09-02부터 시행 중입니다. 아래 본문이 개정된 내용입니다.
개정 사유: 1:1 문의 창구를 새로 열면서, 그 창구로 받는 개인정보의 수집 항목과 보유기간, 회원 탈퇴 시의 처리와 분리 보관을 처리방침에 명시합니다. 기존에 하던 처리는 바뀌지 않습니다.
사전 예고 기간을 두지 않는 이유: 이 개정은 아직 열지 않은 1:1 문의 창구를 새로 여는 «신설 고지»입니다. 기존에 하던 처리는 하나도 바뀌지 않고, 새로 받는 항목은 이용자가 그 창구를 직접 이용하며 별도 동의를 한 경우에만 수집되므로, 사전 예고 기간을 두지 않고 시행합니다.
제1조 수집하는 개인정보 항목
개정 전 이용자가 직접 업로드·입력한 데이터(예: 장비 데이터, 이미지) … 회사는 만 14세 미만 아동의 개인정보를 수집하지 않으며, 만 14세 미만은 회원가입할 수 없습니다.
개정 후 이용자가 직접 업로드·입력한 데이터(예: 장비 데이터, 이미지) … 1:1 문의: 이름, 이메일 주소, 소속(입력한 경우), 연락처(입력한 경우), 문의 분류·제목·내용, 첨부파일(붙인 경우), 문의 시점의 동의 기록(동의 시각, 동의한 문구의 판(본문 해시), 요청 IP 주소, 브라우저 정보, 화면 언어), 로그인한 상태로 보낸 경우 회원 식별자. 1:1 문의는 회원이 아니어도 보낼 수 있으며, 이때 수집하는 정보는 위 항목에 한합니다. 첨부파일은 문의 처리 목적으로만 관리자 화면에서 열람하며, 파일 형식은 이미지·PDF·압축파일·텍스트로 제한하고 이용자가 지정한 파일 이름은 화면 표시에만 사용합니다. … 회사는 만 14세 미만 아동의 개인정보를 수집하지 않으며, 만 14세 미만은 회원가입할 수 없습니다.
제3조 보유 및 이용 기간·파기
개정 전 파기 시 전자적 파일은 복구할 수 없는 방법으로 삭제하고, 출력물은 분쇄 또는 소각합니다.
개정 후 1:1 문의로 접수한 정보는 다음 기간 동안 보관한 뒤 본문과 첨부파일을 모두 지체 없이 파기합니다. 결제·환불 등 분쟁과 관련된 문의로 분류되었거나 관리자가 분쟁 기록으로 표시한 문의는 전자상거래법에 따른 소비자 불만·분쟁처리 기록으로서 그 처리가 끝난 날부터 3년, 그 밖의 문의는 접수일부터 1년입니다. 처리가 끝나지 않은 분쟁 관련 문의는 처리가 끝날 때까지 보관하며, 처리가 끝난 날부터 다시 3년을 계산합니다. 회원이 탈퇴하면 그 회원이 보낸 1:1 문의는 계정과 함께 파기합니다. 다만 위 분쟁 관련 문의는 법령상 보존 의무에 따라 남기며, 이때 연락처, 소속, 요청 IP 주소, 브라우저 정보, 회원 식별자는 지우고 분쟁 처리에 필요한 범위(이름, 이메일 주소, 문의 내용, 첨부파일, 처리 경과)만 남깁니다. 남긴 기록은 다른 개인정보와 분리된 저장 공간에 따로 보관하며, 위 보존기간이 지나면 지체 없이 파기합니다. … 파기 시 전자적 파일은 복구할 수 없는 방법으로 삭제하고, 출력물은 분쇄 또는 소각합니다.
제5조 개인정보의 국외 이전 — Fly.io 항목
개정 전 Fly.io(서버 호스팅 · 일본 등): 계정 정보, 서비스 이용 데이터 및 IP 주소별 방문 원장의 보관·처리 — 계정·이용 데이터는 서비스 제공 기간 동안, 방문 원장은 제3조의 보유기간(마지막 접속일부터 90일)에 따름
개정 후 Fly.io(서버 호스팅 · 일본 등): 계정 정보, 서비스 이용 데이터, 1:1 문의 내용·첨부파일 및 IP 주소별 방문 원장의 보관·처리 — 계정·이용 데이터는 서비스 제공 기간 동안, 문의 자료는 제3조의 보유기간, 방문 원장은 제3조의 보유기간(마지막 접속일부터 90일)에 따름
Quantum Materials Inc. (the 'Company') values your personal data and complies with applicable data-protection laws, including the Personal Information Protection Act of Korea. This Policy explains how personal data is collected, used and protected in the Semi Process Lab service.
1. Data we collect
- Sign-up and sign-in: username, password (stored encrypted), email address, display name, affiliation (institution or company), purpose of use, referrer username (if provided), country/region (and identifiers received from your social-login provider)
- Sign-up consent record: time of consent, the version of each consented document (notice date and body hash), request IP address and browser information
- Paid services: payment approval details (sensitive payment data such as card numbers is handled by the payment provider and is never stored by the Company)
- Service usage: access logs (including IP address), usage history (such as credit consumption), browser and device information
- 1:1 inquiries: name, email address, affiliation (if entered), contact number (if entered), inquiry category, subject and message, attached file (if any), and the consent record made at the time of the inquiry (time of consent, the edition of the consent text you were shown (its body hash), request IP address, browser information, display language), plus your member identifier if you were signed in
- Data you upload or enter yourself (for example equipment data or images)
Access logs are combined and accumulated into a per-IP-address visit ledger. Each ledger records the IP address, access country (where determinable), first and most-recent access times, visit count, per-path visit counts (excluding URL query strings), the last visited path, and a referral classification (direct, internal or external). This visit ledger is viewed and searched only in an administrator-only dashboard, for detecting and responding to abnormal access and misuse and for service security, and is destroyed without undue delay once 90 days have elapsed since the last access (see Section 3).
Anyone may send an inquiry without being a member, and we collect nothing beyond the items above. Attachments are opened only in the administrator screen for handling the inquiry; permitted formats are images, PDF, archives and text, and the file name you supply is used only for display.
The Company does not collect personal data of children under 14, and children under 14 may not create an account.
2. Purposes of use
- Providing and operating the Service, identifying and authenticating members, processing and settling paid services
- Responding to inquiries, improving the Service and preventing fraudulent use
- Administrator review of and response to misuse and abnormal access, and service security (the per-IP-address visit ledger is viewed and searched in an administrator-only dashboard). General access statistics such as visit trends, countries and referrals are aggregated separately, without IP addresses.
3. Retention and destruction
Personal data is destroyed without delay once the purpose of collection and use is achieved. Where required by law, it is retained for the prescribed period (for example: 5 years for records of contracts, withdrawals and payments under Korean e-commerce law; 3 years for records of consumer complaints and dispute handling; 3 months for access logs under the Protection of Communications Secrets Act).
The retention period of the per-IP-address visit ledger is 90 days from the last access; once that period elapses, it is destroyed without undue delay through a periodic purge. However, if you revisit within 90 days, the visit is accumulated into the existing ledger, and the retention period of the whole ledger is recalculated from the most-recent access date.
When you sign up, a record of your confirmation that you are 14 years of age or older and of your consent to the Terms of Service and to the collection and use of personal data is stored together with your account. The record contains the time of consent, the version of each consented document (notice date and body hash), the request IP address and browser information, and is used to verify after the fact which version of the terms and policy was agreed to at sign-up. Because it is stored on the account, it is destroyed together with the account when you close your membership; no separate retention period applies.
When a paid transaction is initiated, a record of the user's consent to the terms of service, privacy policy and refund policy is retained. The record contains the member identifier, server timestamp, version of each consented document (notice date and body hash), request IP address and browser information, and is used to verify after the fact which version of the terms was agreed to at the time of payment. Where the consent led to an actual payment, the record is retained for the same period as the corresponding transaction record (5 years under Korean e-commerce law). Where the consent did not lead to a payment, it is destroyed through a periodic purge after 30 days. Upon membership withdrawal, consent records not linked to a payment are destroyed together with the account; consent records linked to a payment are retained alongside the transaction record until the statutory retention period expires and are then destroyed.
Information received through 1:1 inquiries is kept for the periods below, after which the message and any attachment are destroyed without delay. An inquiry classified as payment- or refund-related, or marked by an administrator as a dispute record, is a consumer complaint and dispute-handling record under the Electronic Commerce Act and is kept for three years from the day its handling ends; every other inquiry is kept for one year from the day it was received. A dispute-related inquiry whose handling has not ended is kept until it does, and the three years are counted from that day.
When a member deletes their account, the inquiries they sent are destroyed together with the account. Dispute-related inquiries are retained where the law requires it; in that case we erase the contact number, affiliation, request IP address, browser information and member identifier, and keep only what is needed to handle the dispute (name, email address, the message, any attachment, and the handling history). What we keep is stored separately from other personal data and destroyed without delay once the retention period above has passed.
Electronic files are deleted irrecoverably; printed materials are shredded or incinerated.
4. Processors and third-party provision
The Company entrusts the following processing to provide the Service; each processor handles data only within the scope of the entrusted purpose.
- Email delivery: Resend
- Hosting and infrastructure: Fly.io, Cloudflare
- AI answer and image generation: overseas AI cloud providers — when you use AI features, the conversations, prompts and attachments you enter are transmitted only within the scope of processing, and are not used to train AI models. Account identifiers such as your name, email address and affiliation are not included in the transmission; only the content you entered is sent, it is used solely to generate the response, and it is not stored beyond the provider’s short-term abuse-monitoring retention.
For payment processing, the Company provides order identifiers and product codes to Dodo Payments Inc. (contact: [email protected]). As Merchant of Record and an independent data controller, that provider processes checkout, billing and tax data under its own privacy policy. Card and billing details entered by users on that provider’s checkout form are collected and processed directly by the provider; the Company neither collects nor stores them. Except for the provision to that payment provider, the Company does not provide personal data to third parties except where required by law or with your consent.
5. Cross-border transfers
The Service runs on overseas cloud infrastructure, so personal data is transferred and stored abroad as follows in order to perform the service contract. The transferred items are the minimum necessary for each task among the items in Section 1, and retention follows Section 3.
- Fly.io (server hosting · Japan and other regions): storage and processing of account data, service-usage data, 1:1 inquiry messages and attachments, and the per-IP-address visit ledger — account and usage data for the duration of service provision; inquiry material per the retention period in Section 3; the visit ledger per the retention period in Section 3 (90 days from the last access)
- Cloudflare (security and delivery network · United States and global): transmission during connection handling — at the time of transmission
- Resend (email delivery · United States): email address and message content — until the delivery purpose is achieved
- Dodo Payments Inc. (payment processing · a Delaware, United States corporation · including the countries where the provider’s data centres are located · contact: [email protected]): order identifiers and product codes sent by the Company — for checkout, billing and tax processing, transmitted over the network at the time of each payment request — retained per that provider’s policy (the applicable limitation period plus two months, and for as long as needed to handle any claim brought). Payment and billing details entered by users on the provider’s checkout form are collected and processed directly by that provider as an independent data controller under its own policy.
- AI cloud providers (United States): content you enter when using AI features (excluding account identifiers) — until processing is complete
You may object to cross-border transfers via the contact below; however, because these transfers are essential to providing the Service, use of the Service may be restricted if you object.
6. Cookies and similar technologies
The Service uses only the minimum cookies and browser storage needed for operation, such as keeping you signed in and remembering your language setting. No advertising or tracking cookies are used. You can refuse cookies in your browser settings, but some features such as sign-in may then be limited.
In addition, the Service automatically collects a per-IP-address visit ledger (Section 1) via a visit-logging script when you load a page. This is not for advertising or tracking but for preventing misuse and for security, and it cannot be individually turned off while you use the Service. To access or delete the collected visit ledger, or for related inquiries, you may contact us via Sections 7 and 10.
7. Your rights and remedies
You may at any time request access to, correction or deletion of, or suspension of processing of your personal data. Requests are received at the contact below and handled without delay. You may refuse consent where consent is required, but sign-up or use of the Service may then be limited.
In Korea, you may report or seek advice on privacy infringements at the Personal Information Infringement Report Center (privacy.kisa.or.kr · 118) and apply for dispute mediation to the Personal Information Dispute Mediation Committee (www.kopico.go.kr · 1833-6972).
8. Notice for international users (EEA/UK and others)
If you use the Service from the European Economic Area, the United Kingdom or other regions, the rights granted by the applicable data-protection law (such as GDPR/UK GDPR — access, rectification, erasure, portability, restriction of processing and objection) may apply. Please direct related inquiries to the contact below.
9. Security measures
- Access-permission management and access control; encryption in transit and at rest
- Minimization of personal-data processing and management of access records
10. Data protection officer and contact
For privacy inquiries or to exercise your rights, please contact:
- Data Protection Officer: Hwanyeol Park (CEO, Quantum Materials Inc.)
- Email: [email protected] · Phone: +82-70-7609-1376
11. Changes to this Policy
This Policy may be revised to reflect changes in law or the Service; revisions are announced within the Service.
