MonitorDog

MonitorDog Privacy Policy

sPresto Co., Ltd.

sPresto Co., Ltd. (the “Company”) complies with applicable laws and regulations, including the Personal Information Protection Act, and hereby establishes and discloses this Privacy Policy as follows to protect the personal information of users of the MonitorDog service (the “Service”).

Article 1 (Purpose and Disclosure)

1.“Personal information” means information relating to a living individual that identifies a particular individual by his or her full name, resident registration number, image, etc.; information which, even if it by itself does not identify a particular individual, may be easily combined with other information to identify a particular individual; and information which has been pseudonymized so that the particular individual cannot be identified without the use or combination of additional information necessary to restore such information to its original state.2.The Company makes this Privacy Policy available through its website, app, the first screen of the Service, or a page linked thereto so that users can easily review it.3.This Privacy Policy may be amended due to changes in applicable laws and regulations, the Service, or the manner in which personal information is processed. Any such amendment will be disclosed in accordance with Article 14.

Article 2 (Purposes of Processing, Categories of Personal Information, and Retention Periods)

1.The Company processes personal information as set forth below. Personal information processed by the Company will not be used for purposes other than those specified below. If the purpose of use changes, the Company will take the measures required under Article 18 of the Personal Information Protection Act and other applicable laws and regulations.1)Personal Information Processed without the Data Subject’s Consent
CategoryPurpose of ProcessingPersonal Information ProcessedRetention and Use Period
Member and Contract InformationService registration; conclusion and performance of contracts and provision of the Service; identification and authentication; maintenance and administration of membership status; billing; handling inquiries, complaints, and grievances; delivery of notices and informationEmail addressDestroyed within 30 days from the date a request for membership withdrawal is made. However, where retention is necessary for handling inquiries or complaints, settlement and refunds, or pursuant to applicable laws and regulations, the information will be retained to the extent necessary until the relevant purpose is achieved or for the statutory retention period.
Service Usage and Technical InformationProvision and stable operation of the Service; maintenance of security; prevention of illegal or unauthorized useDevice ID, Service usage records, IP address, access logs, device operating system and version, device model, browser versionDestroyed within 30 days from the date a request for membership withdrawal is made. However, where retention is necessary for handling inquiries or complaints, settlement and refunds, or pursuant to applicable laws and regulations, the information will be retained to the extent necessary until the relevant purpose is achieved or for the statutory retention period.
2)Personal Information Processed with the Data Subject’s Consent
CategoryPurpose of ProcessingPersonal Information ProcessedRetention and Use Period
Service Feature Usage InformationProvision of Service features; statistical analysis of Service usage; improvement of Service quality; prevention of illegal or unauthorized usePC monitor screen, PC webcam image, MAC address, SSID, list of programs running on the PCDestroyed within 30 days from the date a request for membership withdrawal is made. However, where retention is necessary for handling inquiries or complaints, settlement and refunds, or pursuant to applicable laws and regulations, the information will be retained to the extent necessary until the relevant purpose is achieved or for the statutory retention period.
Optional InformationIdentification of users within the Service; improvement of Service quality; provision of customized informationName, profile photo, mobile phone number, nationality, department/job title/position within the workplace, employee ID number, work/home address, employment statusUntil consent is withdrawn or membership withdrawal is requested
Optional Usage Analytics InformationProvision of device-specific information; analysis of Service usage patterns; improvement of the ServiceAdvertising identifierUntil consent is withdrawn or collection of the relevant information is refused
2.During use of the Service, information such as device ID, Service usage records, IP address, access logs, device operating system and version, device model, and browser version may be automatically generated and collected. Advertising identifiers are processed only with the user’s consent, and the specific purposes of processing and retention and use periods are as set forth in paragraph 1.3.The Company does not designate sensitive information under Article 23 of the Personal Information Protection Act as a separate category of personal information to be collected and processed. If it becomes necessary to process sensitive information, the Company will comply with the requirements and procedures prescribed by applicable laws and regulations.4.Users have the right to refuse consent to the processing of personal information where processing is based on consent. However, if a user refuses the processing of information necessary to provide the Service, registration or use of certain Service features may be restricted.

Article 3 (Methods of Collection and Legal Bases for Processing)

1.The Company processes personal information with the consent of the data subject in accordance with applicable laws and regulations. However, the Company may process personal information without the data subject’s consent to the extent necessary where special provisions exist in statutes or processing is unavoidable due to obligations under statutes or regulations; where it is necessary to take measures at the request of the data subject in the course of performing a contract concluded with the data subject or concluding a contract; where it is manifestly necessary to protect the life, bodily or property interests of the data subject or a third party from imminent danger; where it is necessary to attain the Company’s legitimate interests and such interests are manifestly superior to the rights of the data subject; or where any other requirements under Article 15 (1) of the Personal Information Protection Act or other applicable laws and regulations are satisfied.2.The Company may collect personal information through the following methods:1)Information entered directly by the user during website registration or use of the Service;2)Information received from affiliated services, organizations, or similar sources;3)Information provided through webpages, apps, email, fax, telephone, or similar means in the course of customer service consultations; and4)Information provided through online or offline events and promotions.3.The Company may use personal information without the data subject’s consent within the scope reasonably related to the initial purpose of collection, pursuant to Article 15 (3) of the Personal Information Protection Act and other applicable laws and regulations, taking into account whether such use may cause disadvantages to the data subject and whether measures necessary to ensure security have been taken.

Article 4 (Retention of Personal Information Pursuant to Applicable Laws and Regulations)

1.The Company destroys personal information without delay when the retention period has expired or the purpose of processing has been achieved. However, where applicable laws and regulations require retention for a specified period, the Company retains the information for the period prescribed by such laws and regulations.2.Where the Act on the Consumer Protection in Electronic Commerce applies, the retention periods for transaction records are as follows:
Records RetainedRetention PeriodLegal Basis
Records related to marks and advertisements6 monthsAct on the Consumer Protection in Electronic Commerce and the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce
Records related to cancellation of contracts or subscriptions, etc.5 yearsSame as above
Records related to payment for and supply of goods, etc.5 yearsSame as above
Records related to resolution of consumer complaints or disputes3 yearsSame as above
3.Where any other retention obligation applies under applicable laws and regulations, the Company retains the relevant information within the scope and for the period prescribed by such laws and regulations.

Article 5 (Provision of Personal Information to Third Parties)

1.The Company processes personal information within the scope of the purposes of processing and does not provide personal information to any third party without the data subject’s consent or another legal basis.2.Where the Company provides personal information to a third party, it informs the data subject of the matters required by applicable laws and regulations, including the recipient, purpose of provision, categories of personal information provided, and retention and use period, and follows the lawful procedures under Articles 17 and 18 of the Personal Information Protection Act and other applicable laws and regulations.

Article 6 (Entrustment of Personal Information Processing)

1.The Company entrusts the following personal information processing activities to third parties for the provision of the Service.
Entrusted Service ProviderEntrusted Services
Google Cloud Korea LLCStorage and processing of all data used in the Service
Twilio Inc.Sending emails to members
2.When entrusting the processing of personal information, the Company provides in the relevant entrustment agreement or other document, in accordance with applicable laws and regulations, for matters including prohibition on processing personal information for purposes other than performing the entrusted work, measures to ensure the security of personal information, restrictions on re-entrustment, management and supervision of the person entrusted, and liability for damages, and manages and supervises the person entrusted to ensure that personal information is processed securely.3.Any change to a person entrusted or the details of the entrusted work will be disclosed through this Privacy Policy.4.Where the Company entrusts the promotion of goods or services or the solicitation of sales thereof, it will notify data subjects of the details of the entrusted work and the person entrusted by such means as writing, electronic mail, telephone, text message, or other methods prescribed by applicable laws and regulations. The same applies where the details of the entrusted work or the person entrusted are changed. However, if the Company is unable to provide such notice without negligence on its part, the relevant matters will be posted on the Company’s website for at least 30 days.

Article 7 (Cross-Border Transfer of Personal Information)

1.Where the Company transfers personal information across borders, it will have a lawful basis under Article 28-8 of the Personal Information Protection Act and other applicable laws and regulations and will take the necessary safeguards.2.If a cross-border transfer occurs, the Company will disclose or notify the data subject of the matters required by applicable laws and regulations, including the categories of personal information transferred, the country to which the information is transferred, the timing and method of transfer, the recipient and its contact information, the purpose of transfer, the retention and use period, and the methods and procedures for refusing the transfer and the effects of such refusal.

Article 8 (Installation and Operation of Automatic Data Collection Tools and Opt-Out)

1.The Company may use cookies, which store and retrieve information about users from time to time, in the course of use of the website and the Service. Cookies may be used to identify a user’s browser or device.2.Through cookies and similar technologies, the Company may process advertising identifiers, device IDs, and similar information to provide device-specific information, analyze Service usage patterns, and improve the Service.3.Users may allow or block the storage of cookies and delete stored cookies through the privacy or cookie settings of the web browser or device they use.

Article 9 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)

1.To the extent permitted by applicable laws and regulations, a data subject may request access to, correction or deletion of, suspension of processing of, or withdrawal of consent to the processing of his or her personal information.2.A data subject may directly access or correct personal information through the “Users” menu in the program. Other rights may be exercised by making a request in writing, by telephone, or by email to the Privacy Officer or Privacy Administrator. The Company will take the necessary measures without delay in accordance with applicable laws and regulations.3.A data subject may exercise his or her rights through a legal representative or an authorized agent, and the Company may verify the identity of the data subject or representative where necessary.4.If a data subject requests correction of an error in his or her personal information, the Company will investigate the relevant personal information without delay, take necessary measures such as correction, and notify the data subject of the result. The Company will not use or provide the relevant personal information until the correction is completed.5.A data subject may withdraw consent to the processing of personal information at any time. If consent is withdrawn, the Company will, without delay, take necessary measures such as destroying the relevant personal information so that it cannot be restored or reproduced, and will notify the data subject of the result. However, where the Company is permitted under applicable laws and regulations not to take measures following withdrawal of consent, the Company will notify the data subject of the reason without delay.6.Where applicable laws and regulations permit the Company to restrict or deny a request for access, correction or deletion, or suspension of processing, the Company may restrict the exercise of such rights to that extent and will notify the data subject of the reason in accordance with applicable laws and regulations.7.The Company will establish methods and procedures for the exercise of data subject rights that are no more difficult than the methods and procedures used to collect personal information. If a data subject objects to any measure taken by the Company, including the denial of a request for access, correction or deletion, suspension of processing, or withdrawal of consent, the data subject may submit an objection to the Privacy Officer or Privacy Administrator.

Article 10 (Procedures and Methods for Destruction of Personal Information)

1.The Company destroys personal information without delay when it becomes unnecessary, including when the retention period has expired or the purpose of processing has been achieved.2.Where personal information must continue to be retained under applicable laws and regulations, the Company stores and manages such personal information separately from other personal information and destroys it without delay upon expiration of the statutory retention period.3.Personal information printed on paper is destroyed by shredding, incineration, or a similar method, and personal information in electronic file format is deleted using a secure method so that it cannot be restored or reproduced.

Article 11 (Measures to Ensure the Security of Personal Information)

1.The Company takes the following security measures in accordance with applicable laws and regulations to prevent personal information from being lost, stolen, divulged, forged, altered, or damaged.1)Technical measures: password protection; encryption or locking of important data; protection of network transmission channels; prevention of malicious software; intrusion prevention; vulnerability assessments; and similar measures;2)Managerial measures: minimizing access privileges to personal information; employee security undertakings; operation of internal procedures for personal information protection; management of handover of personal information processing duties; and audits of personal information processing practices; and3)Physical measures: access controls for locations where personal information is stored and other protective measures required by applicable laws and regulations.2.In the event of a personal information breach or similar incident, the Company will take the measures required by applicable laws and regulations and notify data subjects in accordance with the prescribed procedures and methods. Where the incident is subject to a statutory reporting requirement, the Company will report it to the Personal Information Protection Commission or other relevant authorities.

Article 12 (Obligations of Users)

1.Users must keep their personal information accurate and up to date and must not misappropriate another person’s information or enter false information.2.Users must appropriately manage their account information, including passwords, to prevent disclosure and must not use the Service to infringe another person’s personal information or other rights.

Article 13 (External Links)

1.The Company may provide links to websites or materials of other businesses through its website or the Service. The processing of personal information by an external website is governed by that website’s privacy policy, and users are advised to review the privacy policy of the relevant external website.

Article 14 (Privacy Officer and Handling of Complaints)

1.The Company has designated the following Privacy Officer and Privacy Administrator to have general supervision over personal information processing and to handle complaints and provide remedies in connection with personal information processing.
RoleNameTelephoneEmail
Privacy Officer박지수 (Park Ji-su)02-6954-1013contact@spresto.net
Privacy Administrator박성환 (Park Seong-hwan)02-6954-1013contact@spresto.net
2.Requests concerning personal information, the exercise of rights, complaints, or remedies may be submitted to the Customer Service Center (Telephone: 02-6954-1013; Email: contact@spresto.net) or to the persons listed above.3.For reports or consultations regarding personal information infringements, or for dispute mediation, the following institutions may be contacted:1)Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency (KISA)): 118 (no area code), privacy.kisa.or.kr2)Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr3)Supreme Prosecutors’ Office: 1301 (no area code), www.spo.go.kr4)Korean National Police Agency: 182 (no area code), ecrm.police.go.kr

Article 15 (Amendments to this Privacy Policy and Interpretation between Language Versions)

1.If the Company amends this Privacy Policy, it will disclose the amendments through its website, app, the first screen of the Service, or a page linked thereto, and will make the changes before and after the amendment readily available for users to review.2.If there is any discrepancy in content or interpretation between the Korean version and the English translation of this Privacy Policy, the Korean version will prevail.Date of Announcement: September 11, 2026Effective Date: September 11, 2026
プライバシーポリシー | MonitorDog