Privacy Policy

Intelligence Technology Standard Inc. handles your personal data with care and complies with the applicable laws of the Republic of Korea.

Effective / last revised: 18 August 2026

This is an English translation provided for your convenience. The Korean version is the binding original. If the two differ, the Korean version prevails. View the Korean original →

1. What we collect, why, and for how long

WhereWhat we collectWhyHow long
Certification quote requestCompany name, contact person’s name and title, phone, email, region, number of employees, standards of interestTo work out audit days and fees, and to reply with a quotation1 year after our reply
Customer feedbackName, phone, email, messageTo handle complaints and appeals and reply with the outcome3 years after the case is closed
Social sign-in (optional)Email address and name from your Google or Kakao account. We do not receive your gender, date of birth, phone number or friend list. The provider also sends a profile photo, which we do not store.Identifying you at sign-up and sign-inUntil you close your account
Sign-up and sign-inEmail, name, organisation (optional), password (stored encrypted)Identity verification, member services, administrator permissionsDeleted immediately when the account is closed
Member details by member type (company · auditor · staff)All: phone, department and job title, organisation. Company members: company name, business registration number. Auditors and staff: profile photograph, date of birth with a single sex digit (7 digits), postcode and address (for sending business cards), qualifications and standards, signature imageTo confirm and approve the member type, manage auditor qualifications, issue certificates and business cards, and sign undertakingsDeleted immediately when the account is closed (qualification and audit records are retained separately as required by ISO/IEC 17021)
Consent and undertaking recordsThe document and version consented to, the full text as shown at that time, the date and time, the connecting IP address and device informationTo evidence that consent and undertakings were given (accreditation assessment · ISO/IEC 17021-1 §5.2 and §8.4)3 years after the account is closed
Auditor qualification and registration applicationStandards and grade applied for, name in Korean and English, date of birth, sex, address, phone, email, facial photograph, highest education (school, major, degree), training completed, career history (employer, department, period, duties, job description), requested audit scope (IAF codes) and the evidence for each; supporting documents — diploma, certificate of employment, training certificate, professional licencesTo review and approve auditor competence, register the auditor and grant the audit scope (codes), issue the auditor certificate and registration certificate, and respond to accreditation assessmentRegistered auditors — 3 years after the qualification expires; rejected or withdrawn applications — 6 months
Auditor fee payment detailsBank name, account number, account holder, tax status (whether registered as a business)To pay audit fees and withhold tax3 years after the qualification expires (payment evidence is retained for the period required by tax law)
Audit record and consultancy historyAudit log (date, audited company, standard, certification scope, IAF code, audit duration in man-days, role in the audit) and the annual consultancy reportTo confirm that qualification maintenance requirements are met (3-year renewal) and to confirm impartiality of audits (ISO/IEC 17021-1 §5.2)3 years after the qualification expires
Bug reportReport text, page address, device information, reply email (optional)To find the cause, fix it, and reply if needed1 year after the case is closed
Promotional item requestCompany name, certificate number, contact name, phone, email, delivery address, notesTo produce and deliver plaques, certificate copies and similar items1 year after delivery
Satisfaction survey (audit · training)Company name, name, email, ratings, commentsTo improve our certification and training services (ISO/IEC 17021 requirement)3 years
Training enquiry (HRD Centre)Name, phone, email, messageTo advise on courses and reply1 year after the case is closed
Access logs (security)Sign-in and permission-change records, IP address, device informationTo detect unauthorised access and respond to security incidents (ISO/IEC 27001)1 year
Certification contract and auditContact details, information about the organisation being auditedTo carry out the audit and to issue and maintain the certificateFor the period required by law and by our accreditation bodies after certification ends

ITS does not collect resident registration numbers. We do not use the data we collect for any purpose other than those above; if the purpose changes, we ask for your consent separately.

2. Sharing with third parties

We do not share your personal data with third parties, except in the following cases.

  • · Where you have given prior consent
  • · Where it is necessary for an accreditation assessment or surveillance by our accreditation bodies (IAS · UAF), and only to that extent
  • · Where required by law

3. Social sign-in (Google · Kakao)

Instead of signing up with an email address, you may sign in with a Google or Kakao account. If you do, we receive the following from that provider.

  • · What we use — email address, name (nickname)
  • · What we do not receive — gender, date of birth, phone number, friend list
  • · Profile photo — the provider sends one alongside your name, but we do not store it. Your member photo is only what you upload yourself.
  • · Purpose — identifying you at sign-up and sign-in
  • · Retention — until you close your account

Social sign-in is optional. You can sign up and use every feature with an email address instead, at no disadvantage.

We never post to your Google or Kakao account and never read your friend list. You can disconnect at any time in your Google or Kakao account settings under connected services; afterwards you can sign in with your email and password.

⚠️ Data received this way is used only on this site (ITS Certification). We do not link your account with any affiliated service.

4. Processors we use

We use the processors below to run this service. Our contracts with them require that your data is kept secure.

ProcessorPurposeData
Channel Corp. (Channel Talk)In-app chat supportName · email · conversation
Supabase Inc.Storage of accounts and enquiries, storage of application documents and certificatesName · email · phone · enquiry text · supporting documents · photograph · signature image
Vercel Inc.Website hostingAccess logs · IP address
Resend Inc.Sending notification emailEmail address

⚠️ Some of these processors host data outside Korea. Data is processed only for the stated purpose and is destroyed without delay when the contract ends.

4-1. Use of artificial intelligence

ITS uses generative AI to help our staff handle enquiries faster. We set out below exactly where and how.

  • · Where we use it — to summarise and classify enquiries, complaints and bug reports, and to draft replies.
  • · Model used — Gemini, by Google LLC
  • · 🔴 AI does not decide anything. Whether to reply, and what to say, is always decided by a person. Anything AI drafts goes out only after our staff have checked and edited it.
  • · 🔴 We do not use AI for auditor competence decisions, certification decisions or appeals. A person’s qualification and a certification outcome are judged by people (ISO/IEC 17021-1).
  • · What we never send — names, phone numbers, email addresses, resident registration numbers, and bank or payment details are not sent to AI.
  • · Not used for training — we do not use your enquiries to train AI models.
  • · Objecting — you may object at any time to processing that involved AI, using the contact details below.

5. Destruction

When the retention period ends or the purpose is fulfilled, we destroy the data without delay. Electronic files are deleted in a way that cannot be recovered; paper documents are shredded or incinerated. Where a law requires us to keep something, we store it separately for that period only.

6. Your rights

You may at any time ask us to access, correct, delete or stop processing your personal data. Contact us at the address in section 7 and we will act without delay. We do not knowingly collect data from children under the age of 14.

7. How we keep your data safe

  • · Access to personal data is limited to the fewest possible staff.
  • · Personal data travels only over encrypted connections (HTTPS).
  • · Access logs are retained and protected against tampering.
  • · Staff receive security training on a regular basis.
  • · Supporting documents, photographs and signature images are held in private storage that only you and the reviewing officer can open. Knowing the web address is not enough to open them.
  • · Only the last four digits of a bank account number are shown on screen.

7-1. Privacy management system (ISO/IEC 27701)

ITS Certification Body maintains its privacy management system in line with ISO/IEC 27701. What follows is what we actually do.

  • · We state our role. For the personal data of members and enquirers, ITS is the controller; the companies that send our mail and store our files are processors. Each is named in §4.
  • · We fix the purpose first and stay inside it. What we collect, why, and when we delete it is set out item by item in the table in §1.
  • · We ask only for what we need. Forms do not ask for data we will not use. Resident registration numbers are shown masked, and bank accounts only as the last four digits.
  • · Consent is separate, and can be withdrawn. Optional consents (such as marketing) are never bundled. You can withdraw at any time from “My page”, and we stop from that moment.
  • · We act on your requests. How to ask for access, correction, deletion or restriction is in §6 and §8.
  • · We keep records. Access logs record who read or changed what, and when (§1, §7). If something goes wrong, those records are how we work out what was exposed and tell you.
  • · We delete when the period ends. Retention is set per item (§1) and destruction follows (§5).
  • · AI does not decide. We do not use AI for auditor qualification or certification decisions (§4-1).

⚠️ ITS Certification Body is not certified to ISO/IEC 27701; we operate a management system in line with it. As we are a body that certifies others against this standard, we do not use the word “certified” about ourselves.

8. Data protection officer

Officer
박민우
Department
Certification Administration Office
Phone
+82-2-786-9242 (02-786-9242)
Email
info@itscert.or.kr

If you need advice or wish to report a privacy infringement, you may also contact the Korean authorities below.

  • · Privacy Infringement Report Centre (privacy.kisa.or.kr / 118)
  • · Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
  • · Supreme Prosecutors’ Office, Cyber Investigation (spo.go.kr / 1301)
  • · National Police Agency, Cyber Bureau (ecrm.police.go.kr / 182)

9. Changes to this policy

If this policy changes, we will post a notice on this website at least 7 days before it takes effect. Where a change materially affects your rights, we will give 30 days’ notice.