Surearly Privacy Policy

Surearly Privacy Policy

Sugentech, Inc. (“the Company”) complies with all applicable privacy protection laws, including the Personal Information Protection Act of the Republic of Korea. To ensure the safe and responsible management of users’ personal information, the Company has established and publicly discloses this Privacy Policy as follows. This Policy applies to the Surearly service.

1. Items of Personal Information Collected

The Company collects the following personal information in order to provide its services.
Category
Items Collected
Account Registration
Email address, nickname, date of birth
Service Usage Records
Height, weight, body temperature, menstrual cycle and period, symptoms, hospital visit records, medication records, exercise records, expected date of delivery, hormone test results
Customer Inquiries
Email address
Sensitive Information
Health and psychological information such as postpartum depression assessments (*Collected and managed separately based on a separate “Sensitive Information Processing Policy,” and only upon obtaining explicit consent.)

2. Purpose of Collecting and Using Personal Information

Purpose
Items Used
Details
Account Registration and Management
Email address, nickname, date of birth
To verify registration intent and user identity, prevent unauthorized or fraudulent use of the service, provide notifications and announcements, handle inquiries and complaints, and deliver age-appropriate information.
Health Management Services
Height, weight, body temperature, menstrual cycle and period, symptoms, hospital visit records, medication records, exercise records, expected date of delivery
To track ovulation, provide body temperature stability information during pregnancy, manage PMS, maintain medical visit history, manage medication and exercise records, and provide guidance based on expected delivery date and gestational week.
Testing and Analysis Services
Hormone test results
To provide personalized condition analysis, hormone pattern insights, new product development, and use for statistical research.
Marketing and Promotion (with separate optional consent)
Email address, nickname
To conduct satisfaction surveys, deliver personalized content and product recommendations, and provide information on events and advertisements (*Consent is obtained separately within the app. Refusal to consent will not result in any disadvantage.)

3. Retention and Destruction of Personal Information

3.1. The Company will promptly destroy personal information once the purpose of collection and use has been fulfilled or when the user withdraws their membership.
3.2. However, certain information may be retained for a specified period in accordance with internal policies and applicable laws before being deleted.
Category
Items Retained
Retention Period
Internal Policy (Prevention of Service Misuse)
Records of fraudulent or unauthorized service use
3 years after membership withdrawal
Internal Policy (Prevention of Identity Theft)
Nickname
1 year after membership withdrawal
Internal Policy (Customer Support and Notification Emails)
Encrypted email address
1 year after membership withdrawal
Republic of Korea – Electronic Commerce Act
Records of consumer complaints and dispute resolution
3 years
Republic of Korea – Protection of Communications Secrets Act
Service access logs
3 months
3.3. Methods of Destruction
Electronic files: Permanently deleted using technical methods that render recovery impossible.
Paper documents: Destroyed by shredding or incineration.

4. Provision and Entrustment of Personal Information to Third Parties

4.1. The Company does not provide users’ personal information to any third party without their consent, except as required by law.
4.2. To provide services, the Company may entrust the processing of personal information as follows:
Entrusted Party
Entrusted Task
Country of Transfer
Amazon Web Services (AWS)
Cloud server storage and management
Republic of Korea
Vespexx Co., Ltd.
Service operation and customer support
Republic of Korea

5. User Rights and Methods of Exercise

5.1. Users may exercise the following rights at any time:
Request to access or obtain copies of personal information
Request correction, addition, or deletion of personal information
Request suspension of use or deletion of personal information
Request to suspend provision of personal information to third parties
Withdraw consent
5.2. Methods of exercising rights:
Through the in-app customer service center
By email: surearly@sugentech.com
By phone: 070-8889-5505
5.3. The Company will take necessary action without delay. If there are any legal grounds for restriction, the Company will notify the user of such reason.

6. Measures to Ensure the Security of Personal Information

Technical Measures: Data encryption, SSL encrypted communication, access control, and log monitoring
Administrative Measures: Designation and training of personal information handlers, minimization of access privileges
Physical Measures: Secure network segmentation and restricted access to servers
Authentication Measures: Use of PIN (“simple password”) and third-party authentication (Google, Apple, etc.)

7. Overseas Transfer of Personal Information

The Company stores overseas users’ personal information on AWS cloud servers located in the Republic of Korea.
Country of Transfer: Republic of Korea
Items Transferred: All personal information collected (including data generated during account registration and service use)
Time and Method of Transfer: Transmitted over the network during service use
Storage Location: AWS Seoul Region Data Center (ISO/IEC 27018 Certification)
Security Measures: Encrypted transmission and storage, restricted access, and regular security audits

8. Personal Information Protection Officer and Contact Person

The Company designates the following individuals to oversee personal information protection and handle related inquiries or complaints.
Personal Information Protection Officer
Personal Information Manager
- Name: Sujin Koo - Position: Quality Assurance Manager - Email: surearly@sugentech.com
- Name: Kyungsoon Lee - Position: Quality Management Team Lead - Email: surearly@sugentech.com
For reports or consultations regarding personal information infringement, please contact the following organizations:
Personal Information Infringement Report Center: https://privacy.kisa.or.kr, 118
Supreme Prosecutors’ Office Cybercrime Investigation Department: https://www.spo.go.kr, 1301
National Police Agency Cyber Bureau: https://ecrm.police.go.kr, 182

9. Duty of Notification

If any additions, deletions, or modifications are made to this Privacy Policy, the Company will notify users through in-app announcements or other appropriate means at least 7 days prior to implementation.
For material changes, users will be notified at least 30 days in advance.