Privacy Policy

Privacy Policy

[Required] StemExOne Privacy Policy

Consent to Collection and Use of Personal Information

※ This English translation is provided for convenience only. In the event of any discrepancy or conflict between the Korean original and the English translation, the Korean original shall prevail.

You have the right to refuse consent to the collection of personal information below. However, if you refuse, your use of Customer Inquiries (Contact Us) may be restricted. For more details, please refer to the [Privacy Policy].

Swipe left or right to view.

1. Purpose of Collection and Use 2. Items of Personal Information Collected 3. Retention and Use Period
Receipt and processing of customer inquiries [Required] Name, Email, Contact Number, Company Name, Inquiry Content Destroyed after 3 months of retention upon completion of inquiry processing
Service quality improvement and marketing [Required] Access IP information, Cookies, Service usage records, Access logs Destroyed immediately upon achieving the collection purpose

Privacy Policy
StemExOne (hereinafter referred to as the "Company"), which operates the StemExOne website (hereinafter referred to as the "Website"), establishes this Privacy Policy in accordance with the Personal Information Protection Act to protect the personal information of the data subject (hereinafter referred to as the "User") and to handle related grievances promptly and smoothly. This Privacy Policy applies to the website operated by the Company, and explains the Company's method of processing personal information provided by the User to us. Terms used in this Privacy Policy shall follow relevant laws and our Terms of Use, and other matters shall be governed by general commercial practices.

Article 1. Purpose of Processing Personal Information
  1. The Company collects and uses personal information for the following purposes:
    1. Processing Website Customer Inquiries (Contact Us)
      • Checking customer inquiries, contacting/notifying for factual investigation, notifying processing results, etc.
    2. Service Improvement and Marketing
      • Providing information on new services (products) and customized services, determining the frequency of website access, and statistics on service use, etc.
  2. The collected and used personal information will not be used for purposes other than those specified. If the purpose of use is changed, necessary measures will be taken, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
Article 2. Processing and Retention Period of Personal Information
  1. The Company processes personal information necessary for using the website services for the following purposes, and collects and uses only the personal information consented to. The processed personal information will not be used for purposes other than the following, and if the purpose of use changes, necessary measures will be taken.

Swipe left or right to view.

Purpose Category Collected Items Processing and Retention Period
Customer Inquiry General [Required]
Name, Email, Contact Number, Company Name, Inquiry Content
Destroyed after 3 months of retention upon completion of inquiry processing
Product Inquiry Domestic [Required]
Name, Email, Contact Number, Company Name, Position, Inquiry Content
Destroyed after 3 months of retention upon completion of inquiry processing
Overseas [Required]
Name, Email, Country, Company Name, Position, Inquiry Content
Destroyed after 3 months of retention upon completion of inquiry processing
Partnership/Cooperation Corporate [Required]
Name, Contact Number, Email, Company Name, Proposal Content
Destroyed after 3 months of retention upon completion of review
Individual [Required]
Name, Contact Number, Email, Proposal Content
Destroyed after 3 months of retention upon completion of review
Other Consultation Product AS [Required]
Name, Contact Number, Email, Purchase Information, Detailed Symptoms
Destroyed after 3 months of retention upon completion of processing
General [Required]
Name, Contact Number, Email, Inquiry Content
Destroyed after 3 months of retention upon completion of processing
  1. During the service use or personal information processing, the following information may be automatically generated and collected, and used for the following purposes:
    • Access IP information, cookies, service usage records, access logs, etc.
Article 3. Provision of Personal Information to Third Parties and Entrustment of Processing
  1. The Company uses the User's personal information only within the scope specified in the Terms of Use and the Purpose of Processing Personal Information of this Privacy Policy, and does not use it beyond this scope or provide it to others or other companies. However, exceptions are made when there is consent from the User during the use of website services or when information is requested according to procedures set by laws, in which case personal information may be used and provided with caution.
  2. The Company may entrust some of the tasks necessary for providing services to external companies, and strictly regulates and supervises entrusted companies to ensure they process personal information safely in accordance with the Personal Information Protection Act.

Swipe left or right to view.

Service Category Entrusted Company Provided Personal Information Items
StemExOne Website Maintenance Ones Interactive Co., Ltd. Customer inquiry (name, mobile phone number, company name, email, etc.) data and website usage records
Cloud Server and Hosting Infrastructure Operation Gabia Inc. Name, contact info, inquiry content, access logs (IP), other online submission input info
Email/SMS Dispatch Service Daou Technology Inc. Name, contact info (mobile phone number), email, info necessary for confirming inquiries and guiding results
Article 4. Procedure and Method of Destroying Personal Information
  1. The Company shall destroy the personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.
  2. The procedure and method of destroying personal information are as follows:
    1. Destruction Procedure: Information entered by the user is transferred to a separate DB (or a separate document for paper) after the purpose is achieved, and is stored for a certain period according to internal policies and other relevant laws, or immediately destroyed. Personal information transferred to the DB will not be used for any other purpose except as required by law.
    2. Destruction Method: Information in the form of electronic files uses technical methods that prevent the records from being reproduced. Personal information printed on paper is destroyed by shredding or incineration.
Article 5. Processing of Personal Information of Children Under 14

We do not collect information on children under the age of 14, which requires the consent of a legal representative.

Article 6. Rights, Obligations, and Exercise Methods of Users
  1. Users may exercise their rights to request access, correction, deletion, or suspension of processing of their personal information at any time from the Company.
  2. The exercise of rights under Paragraph 1 can be done by the user through writing, email, fax, etc., in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
Article 7. Chief Privacy Officer
  1. The Company implements the technical, managerial, and physical measures necessary to ensure safety in accordance with Article 29 of the Personal Information Protection Act.
  2. The Company is responsible for the overall processing of personal information and has designated a Chief Privacy Officer as follows to handle complaints and remedy damages of data subjects related to personal information processing:
    • Email : contact@stemexone.com
Article 8. Operation and Management of Video Information Processing Devices
  1. The Company installs and operates video information processing devices as follows for facility safety and fire prevention.
  2. Filming time and processing method of video information
    • Filming time : 24-hour continuous filming
    • Retention period : Within 30 days from the filming date
  3. Measures for data subject's request to access video information
    • Applications must be made through a request form for accessing/confirming the existence of personal video information, and access is permitted only when the data subject themselves are filmed or when it is clearly necessary for the life, physical, or property interests of the data subject.
  4. Technical, managerial, and physical measures to protect video information
    • Encryption measures, access control and restriction of access rights, application of safe storage and transmission technology for video information, retention of processing records and measures to prevent forgery/alteration, provision of storage facilities, and installation of locking devices, etc.
Article 9. Remedies for Infringement of Data Subject's Rights
  1. Users may contact the following institutions for damage relief and consultation regarding personal information infringement:
    • Personal Information Dispute Mediation Committee : (No area code) 1833-6972 (www.kopico.go.kr)
    • Personal Information Infringement Report Center : (No area code) 118 (privacy.kisa.or.kr)
    • Supreme Prosecutors' Office Cyber Investigation Division : (No area code) 1301 (www.spo.go.kr)
    • National Police Agency Cyber Investigation Bureau : (No area code) 182 (cyberbureau.police.go.kr)
Article 10. Measures to Ensure the Safety of Personal Information

The Website operated by the Company takes the following measures to ensure the safety of personal information.

  1. Minimization and Training of Staff Handling Personal Information : We designate employees who handle personal information, limit them to the persons in charge, and conduct regular training.
  2. Restriction of Access to Personal Information : We take necessary measures to control access to personal information by granting, modifying, and canceling access rights to the database system that processes personal information.
  3. Retention of Access Records and Prevention of Forgery/Alteration : We retain and manage the records of access to the personal information processing system, and use security features to prevent access records from being forged, altered, stolen, or lost.
  4. Encryption of Personal Information : User's personal information is encrypted, stored, and managed so that only the user can know it. For important data, we use separate security features such as encrypting files and transmitted data or using a file lock function.
  5. Installation and Periodic Update of Security Programs : To prevent personal information leakage and damage caused by hacking or computer viruses, we install security programs and conduct periodic updates and inspections.
  6. Access Control for Unauthorized Persons : We have a separate physical storage location where personal information is kept, and establish and operate access control procedures for it.
  7. Establishment and Implementation of Internal Management Plan : We establish and implement an internal management plan for the safe processing of personal information.
Article 11. Duty to Notify
  1. If there are any additions, deletions, or modifications to the current Privacy Policy, we will notify you through the Website's initial screen or notice board at least 7 days before implementation. However, when a significant change in the rights of data subjects occurs, such as a change in the items of personal information collected or the purpose of use, we will notify you at least 30 days in advance, and may obtain the data subject's consent again if necessary.
    • Announcement Date : March 1, 2026
    • Effective Date : March 1, 2026