Privacy Policy
Effective: 2025-01-01 · Last revised: 2026-10-03
인사책 (InsaCheck), operated by BRIDDZZI, is a workforce attendance & HR platform for Korean employers and workers. We respect your privacy and comply with the Personal Information Protection Act (PIPA / PIPL) of the Republic of Korea and Google Play Data Safety requirements. This English document mirrors the authoritative Korean version at /privacy?lang=ko.
1. Information We Collect
Worker accounts
- Required: name, phone number, date of birth, email address, social-login subject ID, social provider (Kakao / Naver / Google / Apple), social email
- Optional: gender, profile picture
- Automatically collected: precise GPS coordinates & accuracy (only when you tap check-in / check-out), device info, IP address, User-Agent, OS
- Generated during use: affiliation requests (department, position, message), peer ratings & tags
Enterprise accounts
- Required: business type, company name, business registration number, manager name & email & phone, hashed password, company address
- Optional: business registration certificate file, corporate registration number, industry, postal code, signup survey answers
Website visits
- First-party analytics: anonymous session key, landing path, first-visit timestamp, UTM campaign values, and Naver ad keyword/ad identifiers.
- We do not store the raw Naver search query (
n_query), the raw conversion token (NaPm), or full referrer query strings.
Business purchase orders
- Orderer: company name, contact person name, contact person phone number
- Recipient: name, phone number, delivery address
- Funeral wreaths: obituary link, funeral-hall details, photos
- Business cards: name, mobile number and email of the employee printed on the card
- X-banners: banner artwork
- Payment: payment method name and receipt address (card numbers and expiry dates are not collected)
2. How We Use Information
- Authenticate you via Kakao / Naver / Google / Apple Sign-In and prevent proxy attendance.
- Record and manage attendance check-ins and check-outs.
- Match workers to enterprises and manage employment history.
- Compute work-temperature scores and let prior employers leave references with the worker's consent.
- Improve the service through aggregate statistics and detect abuse.
- Send push notifications about HR events (affiliation approvals, seal request decisions, etc.).
- Produce, deliver, take payment for and support business-purchase orders (business cards, X-banners, funeral wreaths).
3. Retention
- Account data (personal information): deactivated immediately on withdrawal request and permanently erased after a 14-day grace period. Records that Korean law requires us to keep are retained separately from your account for the periods below.
- Attendance records: 5 years, then deleted (the Korean Labour Standards Act requires 3 years; we retain longer to cover the wage-claim limitation period and labour-dispute defence).
- Payroll ledger & employment-contract records: 3 years, then deleted.
- Social-insurance enrollment/loss records: retained for the period required by law.
- Wage audit logs: 5 years, then deleted.
- Order inputs for business purchases (obituary links, funeral-hall photos, banner artwork, recipient, phone numbers, addresses): automatically erased, including the original files, 30 days after delivery (7 days after creation for unpaid orders, 30 days after cancellation). Order and payment transaction records: 5 years under the E-Commerce Act, then deleted.
- Copies of failed attendance submissions: if saving an attendance record temporarily fails, a copy of that request (the same fields as the attendance record) is kept in separate storage (Cloudflare R2) for recovery and deleted 30 days after it was stored.
- Business registration certificates: 1 year after enterprise approval, then deleted.
- Access logs: 3 months (Telecommunications Privacy Act).
Retained records do not include the deleted account's personal information (name, contact, etc.).
4. Sharing With Third Parties
We do not sell personal data. Limited sharing happens only when:
- You explicitly consented in advance.
- You request affiliation with an enterprise — your basic info (name, phone, department, position) is shared with that enterprise's HR admin.
- An enterprise requests a reference check on your previous workplace, and you approve — peer ratings & tags are shared with the requesting enterprise.
- An enterprise has set up an external workplace-tool integration (Google Sheets, Slack, or Notion) — that enterprise's attendance records are forwarded to the tool it configured.
- Note: the electronic contract solution "SignDeal" is operated by BRIDDZZI Inc., the same operator as Insacheck. Transfers to SignDeal are therefore not third-party provision and remain covered by this policy.
- Required by Korean law enforcement under valid legal process.
5. Sub-processors
- Cloudflare, Inc. — Service hosting and data storage (Workers, D1 Database, R2 Storage)
- Kakao Corp. — Social login (Kakao Login API); postcode and road-name address lookup (Daum Postcode service — the keyword the user types into the widget is transmitted)
- Naver Corporation — Social login (Naver Login API)
- Google LLC — Google Sign-In, Firebase Cloud Messaging push notifications, optional Google Sheets export (configured by the enterprise)
- Apple Inc. — Sign in with Apple (iOS app)
- TossPayments Inc. (토스페이먼츠 주식회사) — Payment approval, cancellation and lookup when a business-purchase order (business cards, X-banners, funeral wreaths) is paid. Processed in Korea (no cross-border transfer). Card numbers are entered directly into the TossPayments checkout and never reach our servers; we store only the payment method name and the receipt address.
- (주)비씨모빌리티 — Production and delivery of business-purchase orders — printing and production of business cards and X-banners; production and delivery of funeral wreaths. Processed in Korea (no cross-border transfer). Data shared: recipient name, phone number and delivery address; name, mobile number and email of the employee printed on business cards; banner artwork; obituary link, funeral-hall details and photos. Retention: the same as "Business purchase orders" in section 3 (Retention), then deleted.
- Telegram Messenger — Delivery of new-inquiry notifications to our support channel. This is a cross-border transfer outside Korea; see §5-2 of the Korean policy for the exact fields transferred per inquiry channel.
- Amazon Web Services, Inc. — Company mail service — storage of mail accounts, mailbox listings and sending records (Seoul region) and mail delivery (Amazon SES, Seoul region). Applies only to companies that use company mail. For storage of mail bodies and attachments, see the Cloudflare R2 item below.
- Cloudflare, Inc. (R2 storage for company mail) — Company mail bodies and attachments are stored in Cloudflare R2 with an Asia-Pacific location that is not fixed to Korea, which is a cross-border transfer. They are transferred over the network when mail is received or sent, and kept until deleted under the mailbox retention settings chosen by the company administrator. To avoid this transfer, do not use company mail; mail then cannot be sent or received through company mail.
- Cloudflare, Inc. (D1 database) — All service records (accounts, attendance, leave, payroll, approvals and other personal data listed in section 1) are stored in Cloudflare D1, whose primary database runs in Western North America (Cloudflare location hint WNAM); Cloudflare may also keep read replicas in data centers in other countries or regions. This is a cross-border transfer. Data is transferred over the network whenever the service is used and kept for the periods in section 3. To avoid this transfer, do not sign up or request account deletion; the service then cannot be used.
- Cloudflare, Inc. (R2 file storage) — Files you upload (business registration certificates, approval and inquiry attachments, certificates, company seal and logo images, business-purchase order files, and recovery copies of attendance records that failed to save) are stored in Cloudflare R2 in Asia-Pacific (Cloudflare location hint APAC), which is not fixed to Korea. This is a cross-border transfer. Files are transferred over the network when uploaded and kept for the periods in section 3. To avoid this transfer, do not upload files; features that need files then cannot be used.
- Cloudflare, Inc. (KV storage) — Login-state, request rate-limit and phone-verification records (IP addresses, phone numbers used for rate limits, phone-verification progress, member and administrator identifiers) are stored in Cloudflare KV on the Cloudflare global network (not fixed to any country). This is a cross-border transfer. Each record is deleted automatically after its set time (mostly 3 minutes to 2 days; administrator session-revocation records at most 90 days). To avoid this transfer, do not sign up for or use the service.
6. Security Measures
- All passwords hashed with PBKDF2-SHA256 (310,000 iterations, OWASP recommendation).
- Session cookies marked HttpOnly + SameSite=Lax + Secure.
- All traffic encrypted in transit via HTTPS / TLS.
- All database queries use prepared statements (no string interpolation).
- IP-based rate limiting on auth-sensitive endpoints.
7. Your Rights
- Access, correct, restrict processing of, or delete your personal data at any time.
- You can delete your account in-app (Profile → 회원 탈퇴 / Withdraw) or via our public request page at https://insacheck.com/account-deletion. Your personal information is deactivated immediately and permanently erased after a 14-day grace period; certain records are retained separately under Korean law as described in §3 (Retention).
- Cookies can be blocked at the browser level — service may be limited if you do.
8. Privacy Officer
BRIDDZZI Privacy Team — privacy@briddzzi.com
If you live in Korea, you may also contact KISA's privacy infringement hotline at 118 or the Personal Information Dispute Mediation Committee at kopico.go.kr.
9. Changes
We post material changes here at least 7 days before they take effect. Continued use after the effective date constitutes acceptance.