Service availability: Signox is preparing for launch, and payment integration is being verified in a test environment. Live paid services will become available after Toss Payments and payment-method reviews are complete and availability is announced. Test payments do not result in real charges.
This English text is provided for convenience. Signox is operated from the Republic of Korea and this Policy is established under the Korean Personal Information Protection Act (“PIPA”). In the event of any discrepancy, the Korean version prevails.
TwentyOz Inc. (“Company”) establishes and discloses this Privacy Policy pursuant to Article 30 of PIPA, in order to protect the personal data of data subjects and to handle related grievances promptly.
This Policy applies to Signox (“Service”), the software licensing service provided by the Company.
1. Purposes of Processing
The Company processes personal data for the purposes below. Where a purpose changes, the Company will obtain separate consent or take other measures required under Article 18 of PIPA.
| Purpose | Details |
|---|---|
| Membership and account management | Identity verification, maintenance of membership, prevention of misuse, notices |
| Provision of the Service | License issuance, validation and renewal; license portal; team and member management |
| Billing | Payment for paid plans, invoicing and refunds, issuance of payment documentation |
| Customer support | Receiving and answering enquiries, incident response, retention of dispute records |
| Service improvement | Analysis of usage to improve features and develop new services |
| Security | Detection of abnormal access, retention of access logs, audit logging |
2. Categories of Personal Data Processed
Pursuant to Article 31(1)1 of the PIPA Enforcement Decree, the Company processes the following categories.
a. Members (businesses or individuals issuing licenses through the Service)
- Email address and name (as provided for the sign-up method)
- Password hash (where a password is set), authentication and session information
- Where signing up with a social account: the account identifier and email address provided by that service
- Where using a paid plan: payment-method identifiers (billing key and customer identifier), masked card number and card-issuer information, and order/payment/cancellation timestamps, amounts and results
- Optional: team name, team logo image
b. End Users (persons using licenses issued by a Member)
- Email address, name
- Customer portal password hash (where password login is used), authentication and session information
- License ownership and activation data (request ID, installation identifier and credential hashes, device name, OS and architecture, device-protection public keys and fingerprints, issuance and application acknowledgements)
- Device recovery and transfer reasons, previous and new registration identifiers, reviewer, decision reasons and timestamps
- Device-protection private keys are never sent to or stored on the server. Windows uses the OS protected key store; macOS retains only Secure Enclave-wrapped, device-specific key handles in the application’s private state directory.
The Company distinguishes customer-management data supplied by a Member from portal account and authentication data supplied directly by an End User. End Users may contact the Company about portal accounts and authentication, and the relevant Member about purchased application rights, ownership and transfer policies.
c. Data generated automatically through use of the Service
- IP address, browser and device information (User-Agent), access timestamps, session identifiers
- Service usage records, API call records, audit logs
- Landing-page visits and primary start-button clicks; sign-up, team, product and policy creation; first license issuance and activation; and activation failures (random visitor identifier, internal user and team identifiers, page path, language, referring host,
utm_source,utm_medium,utm_campaign, CTA placement, and normalized activation error code). Advertising identifiers, email addresses, license keys, raw hwid values, and free-form payloads are not stored in these analytics records.
3. Processing and Retention Periods
The Company processes and retains personal data within the period prescribed by law or consented to by the data subject.
| Category | Retention period | Basis |
|---|---|---|
| Member data | Until withdrawal of membership | Performance of the agreement |
| Records on contracts or withdrawal of subscription | 5 years | E-Commerce Act |
| Records on payment and supply of goods or services | 5 years | E-Commerce Act |
| Records on consumer complaints or dispute resolution | 3 years | E-Commerce Act |
| Records on labelling and advertising | 6 months | E-Commerce Act |
| Service access logs | 3 months | Protection of Communications Secrets Act |
| Funnel events for service improvement | 3 months from collection | Service improvement |
| Customer portal account and authentication data | Until account withdrawal; legally required records are retained separately for the applicable period | Performance of the portal agreement |
| Customer, license and device registration data managed for Members | Until deletion or termination of the relevant Member agreement; dispute-related and legally required records may be retained separately for the applicable period | License management |
4. Customer Data and Disclosure to Third Parties
The Company distinguishes customer-management data entered by Members from account and authentication data supplied directly by End Users. When an End User registers a license or requests device activation or transfer for a product, the issuing Member may view the customer name and email, license and device registration information, request reasons and results needed for that task. Customer portal passwords and session credentials are not disclosed to Members.
The Company uses personal data within the stated purposes. Where separate consent is required for disclosure, it explains the recipient, purpose, categories, retention period, right to refuse and consequences before obtaining consent. Disclosures required or permitted by law follow the relevant scope and procedures. End Users can also consult the issuing Member’s privacy information for the application they purchased.
5. Payment Processing and Outsourcing
The Company is preparing card recurring payments through Toss Payments Co., Ltd. Integration is currently being tested. Live payments will be offered after the relevant reviews are complete and availability is announced.
| Payment processor | Processing activities | Processing and retention |
|---|---|---|
| Toss Payments Co., Ltd. | Payment-method authentication, card payments and cancellations, transaction results and card receipts | Payment information is retained until its processing purpose is fulfilled, with records required by law kept for the applicable statutory period. The categories and periods for the payment method actually offered are described in its consent screen and Toss Payments’ Privacy Policy. |
Full card numbers, expiry dates and card authentication passwords are handled in Toss Payments’ payment window. The Company does not store full card numbers or card authentication passwords. It retains payment-method identifiers (billing key and customer identifier), masked card details, and order/payment/cancellation results. Section 3 governs information retained by the Company.
When outsourcing processing, the Company manages the contractor’s scope and protective measures. Applicable outsourcing and disclosure arrangements will be finalised and communicated before live payments are offered, and changes will be reflected in this Policy. Direct collection, use and disclosure of payment information are also explained in the payment window and Toss Payments’ Privacy Policy.
6. Overseas Transfers
Before transferring personal data overseas, the Company explains the recipient and contact details, country, categories, purpose, timing and method, retention period, legal basis, and refusal procedure and consequences. It establishes the consent or other lawful basis required by applicable law. Features requiring new overseas transfers are offered after the required notice and procedures have been completed.
Information processed directly in a payment provider’s window is subject to the notices and privacy policy for that payment method. A provider’s complete list of contractors or overseas processing activities does not necessarily apply to every Company transaction. Users should consult the notices for the payment method they use. The Company does not infer the absence of overseas processing merely from a payment provider being based in Korea.
7. Destruction Procedures and Methods
- Where the retention period has elapsed or the purpose of processing has been achieved so that personal data is no longer necessary, the Company destroys it without delay (within 5 days of the triggering event).
- Where retention is required by other legislation, such data is stored in a separate database or storage location.
- Method: electronic files are permanently deleted by means that make restoration impossible; printed records are shredded or incinerated.
8. Rights of Data Subjects and Legal Representatives
- Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal data, and may withdraw consent.
- Membership termination and other data-subject rights may be requested by email to private@twentyoz.kr. The Company will act without delay and notify the requester of the outcome after verifying that the requester is the data subject or a legitimate representative, including control of the registered email address.
- Where a data subject requests correction of an error, the Company will not use or provide the personal data concerned until the correction is complete.
- Rights may be exercised through a legal representative or a duly authorized agent, in which case a power of attorney in the form prescribed by the Notification on Personal Information Processing Methods must be submitted.
- The Company verifies that the person making a request is the data subject or a legitimate representative.
- Requests for access and suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA, and deletion may not be requested where the personal data is expressly designated for collection under other legislation.
9. Automatic Collection Devices (Cookies)
- The Company uses cookies to maintain a user’s signed-in state.
- The cookies used are strictly necessary cookies for authentication and security; they are not used to collect behavioural data for advertising.
- The landing page stores a random visitor identifier in browser local storage to analyse the visit funnel without double counting. When a visitor opens registration, the identifier is passed as a URL parameter, immediately removed from the URL on page entry, and kept temporarily in session storage. On completed sign-up it is linked to an internal user identifier and deleted from browser session storage; later product steps are linked by internal user and team identifiers. It is not shared with third-party advertising or tracking services and contains no member data such as an email address.
- Users may delete or block cookies and local storage through their browser settings. Refusing strictly necessary cookies may make it difficult to use features that require signing in.
- Browser settings → Privacy and security → Cookies and other site data
10. Security Measures
Pursuant to Article 29 of PIPA and Article 30 of its Enforcement Decree, the Company implements:
- Administrative measures: establishment and implementation of an internal management plan; minimisation of personnel handling personal data and regular training
- Technical measures
- Passwords are stored using a one-way hashing algorithm that cannot be reversed.
- Sensitive credentials such as payment method data are stored encrypted.
- TLS encryption is applied to all communication channels.
- Access rights are granted on a role basis, and material processing actions are recorded in audit logs.
- Two-factor authentication (TOTP) is applied to administrator accounts.
- Physical measures: access control over the facilities where data is stored
11. Privacy Officer
The Company designates the following privacy officer, who is responsible for personal data processing and for handling grievances and remedies of data subjects.
| Item | Details |
|---|---|
| Privacy Officer | Yongseok Lee |
| Phone | +82-70-4353-1190 |
| private@twentyoz.kr |
Data subjects may direct all enquiries, complaints, and remedy requests concerning personal data protection arising from use of the Service to the privacy officer, and the Company will respond without delay.
12. Remedies for Infringement of Rights
Data subjects may apply to the following bodies for dispute resolution or consultation:
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Centre: 118 / privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division: 1301 / www.spo.go.kr
- National Police Agency, Cyber Bureau: 182 / ecrm.police.go.kr
A person whose rights or interests are infringed by the Company’s disposition or omission under Articles 35, 36, or 37 of PIPA may request an administrative appeal under the Administrative Appeals Act.
13. Changes to this Policy
- This Policy applies from its effective date.
- Where content is added, deleted, or amended due to changes in law, policy, or security technology, the Company will give notice through the Service at least 7 days before the change takes effect, or at least 30 days before where the change materially affects data subjects’ rights.
- Previous versions of this Policy are available on request.
14. Governing Law and Language
- This Policy is established under the Korean Personal Information Protection Act and related legislation, and is governed by and construed in accordance with the laws of the Republic of Korea.
- The Korean text of this Policy is the authentic version. Where a translation provided by the Company for convenience differs from the Korean text, the Korean text prevails.
Application of this revision
The document version and effective date appear at the top of this page. This revision describes payment processing and customer activation for the service being prepared for launch. Unfavourable changes are not applied retroactively to existing transactions. Availability of live paid services will be announced separately.