Privacy Policy
Intelligence Technology Standard Inc. handles your personal data with care and complies with the applicable laws of the Republic of Korea.
Effective / last revised: 18 August 2026
This is an English translation provided for your convenience. The Korean version is the binding original. If the two differ, the Korean version prevails. View the Korean original →
1. What we collect, why, and for how long
| Where | What we collect | Why | How long |
|---|---|---|---|
| Certification quote request | Company name, contact person’s name and title, phone, email, region, number of employees, standards of interest | To work out audit days and fees, and to reply with a quotation | 1 year after our reply |
| Customer feedback | Name, phone, email, message | To handle complaints and appeals and reply with the outcome | 3 years after the case is closed |
| Social sign-in (optional) | Email address and name from your Google or Kakao account. We do not receive your gender, date of birth, phone number or friend list. The provider also sends a profile photo, which we do not store. | Identifying you at sign-up and sign-in | Until you close your account |
| Sign-up and sign-in | Email, name, organisation (optional), password (stored encrypted) | Identity verification, member services, administrator permissions | Deleted immediately when the account is closed |
| Member details by member type (company · auditor · staff) | All: phone, department and job title, organisation. Company members: company name, business registration number. Auditors and staff: profile photograph, date of birth with a single sex digit (7 digits), postcode and address (for sending business cards), qualifications and standards, signature image | To confirm and approve the member type, manage auditor qualifications, issue certificates and business cards, and sign undertakings | Deleted immediately when the account is closed (qualification and audit records are retained separately as required by ISO/IEC 17021) |
| Consent and undertaking records | The document and version consented to, the full text as shown at that time, the date and time, the connecting IP address and device information | To evidence that consent and undertakings were given (accreditation assessment · ISO/IEC 17021-1 §5.2 and §8.4) | 3 years after the account is closed |
| Auditor qualification and registration application | Standards and grade applied for, name in Korean and English, date of birth, sex, address, phone, email, facial photograph, highest education (school, major, degree), training completed, career history (employer, department, period, duties, job description), requested audit scope (IAF codes) and the evidence for each; supporting documents — diploma, certificate of employment, training certificate, professional licences | To review and approve auditor competence, register the auditor and grant the audit scope (codes), issue the auditor certificate and registration certificate, and respond to accreditation assessment | Registered auditors — 3 years after the qualification expires; rejected or withdrawn applications — 6 months |
| Auditor fee payment details | Bank name, account number, account holder, tax status (whether registered as a business) | To pay audit fees and withhold tax | 3 years after the qualification expires (payment evidence is retained for the period required by tax law) |
| Audit record and consultancy history | Audit log (date, audited company, standard, certification scope, IAF code, audit duration in man-days, role in the audit) and the annual consultancy report | To confirm that qualification maintenance requirements are met (3-year renewal) and to confirm impartiality of audits (ISO/IEC 17021-1 §5.2) | 3 years after the qualification expires |
| Bug report | Report text, page address, device information, reply email (optional) | To find the cause, fix it, and reply if needed | 1 year after the case is closed |
| Promotional item request | Company name, certificate number, contact name, phone, email, delivery address, notes | To produce and deliver plaques, certificate copies and similar items | 1 year after delivery |
| Satisfaction survey (audit · training) | Company name, name, email, ratings, comments | To improve our certification and training services (ISO/IEC 17021 requirement) | 3 years |
| Training enquiry (HRD Centre) | Name, phone, email, message | To advise on courses and reply | 1 year after the case is closed |
| Access logs (security) | Sign-in and permission-change records, IP address, device information | To detect unauthorised access and respond to security incidents (ISO/IEC 27001) | 1 year |
| Certification contract and audit | Contact details, information about the organisation being audited | To carry out the audit and to issue and maintain the certificate | For the period required by law and by our accreditation bodies after certification ends |
ITS does not collect resident registration numbers. We do not use the data we collect for any purpose other than those above; if the purpose changes, we ask for your consent separately.
2. Sharing with third parties
We do not share your personal data with third parties, except in the following cases.
- · Where you have given prior consent
- · Where it is necessary for an accreditation assessment or surveillance by our accreditation bodies (IAS · UAF), and only to that extent
- · Where required by law
3. Social sign-in (Google · Kakao)
Instead of signing up with an email address, you may sign in with a Google or Kakao account. If you do, we receive the following from that provider.
- · What we use — email address, name (nickname)
- · What we do not receive — gender, date of birth, phone number, friend list
- · Profile photo — the provider sends one alongside your name, but we do not store it. Your member photo is only what you upload yourself.
- · Purpose — identifying you at sign-up and sign-in
- · Retention — until you close your account
Social sign-in is optional. You can sign up and use every feature with an email address instead, at no disadvantage.
We never post to your Google or Kakao account and never read your friend list. You can disconnect at any time in your Google or Kakao account settings under connected services; afterwards you can sign in with your email and password.
⚠️ Data received this way is used only on this site (ITS Certification). We do not link your account with any affiliated service.
4. Processors we use
We use the processors below to run this service. Our contracts with them require that your data is kept secure.
| Processor | Purpose | Data |
|---|---|---|
| Channel Corp. (Channel Talk) | In-app chat support | Name · email · conversation |
| Supabase Inc. | Storage of accounts and enquiries, storage of application documents and certificates | Name · email · phone · enquiry text · supporting documents · photograph · signature image |
| Vercel Inc. | Website hosting | Access logs · IP address |
| Resend Inc. | Sending notification email | Email address |
⚠️ Some of these processors host data outside Korea. Data is processed only for the stated purpose and is destroyed without delay when the contract ends.
4-1. Use of artificial intelligence
ITS uses generative AI to help our staff handle enquiries faster. We set out below exactly where and how.
- · Where we use it — to summarise and classify enquiries, complaints and bug reports, and to draft replies.
- · Model used — Gemini, by Google LLC
- · 🔴 AI does not decide anything. Whether to reply, and what to say, is always decided by a person. Anything AI drafts goes out only after our staff have checked and edited it.
- · 🔴 We do not use AI for auditor competence decisions, certification decisions or appeals. A person’s qualification and a certification outcome are judged by people (ISO/IEC 17021-1).
- · What we never send — names, phone numbers, email addresses, resident registration numbers, and bank or payment details are not sent to AI.
- · Not used for training — we do not use your enquiries to train AI models.
- · Objecting — you may object at any time to processing that involved AI, using the contact details below.
5. Destruction
When the retention period ends or the purpose is fulfilled, we destroy the data without delay. Electronic files are deleted in a way that cannot be recovered; paper documents are shredded or incinerated. Where a law requires us to keep something, we store it separately for that period only.
6. Your rights
You may at any time ask us to access, correct, delete or stop processing your personal data. Contact us at the address in section 7 and we will act without delay. We do not knowingly collect data from children under the age of 14.
7. How we keep your data safe
- · Access to personal data is limited to the fewest possible staff.
- · Personal data travels only over encrypted connections (HTTPS).
- · Access logs are retained and protected against tampering.
- · Staff receive security training on a regular basis.
- · Supporting documents, photographs and signature images are held in private storage that only you and the reviewing officer can open. Knowing the web address is not enough to open them.
- · Only the last four digits of a bank account number are shown on screen.
7-1. Privacy management system (ISO/IEC 27701)
ITS Certification Body maintains its privacy management system in line with ISO/IEC 27701. What follows is what we actually do.
- · We state our role. For the personal data of members and enquirers, ITS is the controller; the companies that send our mail and store our files are processors. Each is named in §4.
- · We fix the purpose first and stay inside it. What we collect, why, and when we delete it is set out item by item in the table in §1.
- · We ask only for what we need. Forms do not ask for data we will not use. Resident registration numbers are shown masked, and bank accounts only as the last four digits.
- · Consent is separate, and can be withdrawn. Optional consents (such as marketing) are never bundled. You can withdraw at any time from “My page”, and we stop from that moment.
- · We act on your requests. How to ask for access, correction, deletion or restriction is in §6 and §8.
- · We keep records. Access logs record who read or changed what, and when (§1, §7). If something goes wrong, those records are how we work out what was exposed and tell you.
- · We delete when the period ends. Retention is set per item (§1) and destruction follows (§5).
- · AI does not decide. We do not use AI for auditor qualification or certification decisions (§4-1).
⚠️ ITS Certification Body is not certified to ISO/IEC 27701; we operate a management system in line with it. As we are a body that certifies others against this standard, we do not use the word “certified” about ourselves.
8. Data protection officer
- Officer
- 박민우
- Department
- Certification Administration Office
- Phone
- +82-2-786-9242 (02-786-9242)
- info@itscert.or.kr
If you need advice or wish to report a privacy infringement, you may also contact the Korean authorities below.
- · Privacy Infringement Report Centre (privacy.kisa.or.kr / 118)
- · Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- · Supreme Prosecutors’ Office, Cyber Investigation (spo.go.kr / 1301)
- · National Police Agency, Cyber Bureau (ecrm.police.go.kr / 182)
9. Changes to this policy
If this policy changes, we will post a notice on this website at least 7 days before it takes effect. Where a change materially affects your rights, we will give 30 days’ notice.
