Please enter a prompt
We use cookies or similar technologies as specified in our privacy policy to enhance your experience.
If you would like to learn more about how we use cookies, click "Privacy Policy".
Privacy Policy
VUNO Inc. (hereinafter referred to as the “Company”) hereby adopts and publishes this Privacy Policy in accordance with applicable data protection laws to safeguard the personal information and privacy rights of individuals and to address privacy-related inquiries and concerns in a prompt and appropriate manner.
※ Effective Date: 23 March 2026
Article 1. Purpose of Processing, Categories of Personal Information Collected, and Retention Period
When the Company processes Personal Information, it provides advance notice of the purpose of collection, categories of Personal Information collected, and applicable retention period through this Privacy Policy and/or a separate Notice and Consent Form, in accordance with applicable data protection laws.
The Company may collect and use Personal Information where one or more of the following legal bases applies, and will process such information solely within the scope of the disclosed purpose:
The Company processes Personal Information for the following purposes and categories:
|
Category |
Purpose |
Required/Optional |
Categories of Personal Information Collected |
Retention Period |
|
[VUNO Website] Submit Inquiries |
Responding to inquiries, handling complaints, and managing disputes |
Required |
Name, region, affiliated organization, job title, phone number; email address, country of affiliation, and inquiry details |
3 years from the date the inquiry is submitted |
|
Sending newsletters and providing promotional information about the Company’s products, services, and events |
Optional |
email address |
3 years from the date of consent |
|
|
[Hativmall] Account Registration |
Performance of a contract for the provision of services, billing and payment processing, and account administration |
Required |
Name, date of birth, login ID, email address, password, payment information, and nationality (if a foreign national) |
Until the account is deleted or membership is terminated |
|
Required |
[Unique Identifiers] foreigner registration number (e.g., alien registration number or passport number), if applicable to foreign nationals |
|||
|
Marketing and Advertising |
Optional |
email address, phone number |
||
|
Performance of a Contract for Service Provision and Account Administration |
Optional |
phone number, address |
||
|
[VUNO Careers] Apply for a Job Posting |
Providing recruitment-related communications and notices; contacting applicants regarding the recruitment process and use of the careers website; evaluating candidate qualifications; using application materials for resume screening and interviews; and maintaining a talent database for future opportunities |
Required |
name, phone number, email |
3 years from the date of application submission
|
|
Optional |
date of birth, mailing address, cover letter, resume/CV, education history, photograph, video, certifications or licenses, employment history, portfolio, detailed work experience statement, position applied for, desired salary, most recent salary, references, source of application, and any other information voluntarily entered or uploaded by the applicant (including via attachments) that may identify the individual |
|||
|
[Company-Hosted Events] Event Registration |
Event administration and participant communications |
Required |
name (in Korean and/or English), affiliated organization, contact information, email address |
90 days from the event end date
|
|
Administration of and related communications for VUNO-hosted events |
Optional |
name (Korean and/or English), affiliated organization, contact information, email address |
5 years from the date of consent
|
|
|
[Advisory] Medical Advisory Services |
Verification of advisory board member identity and payment of advisory fees |
Required |
name, date of birth, affiliated organization, contact information, email address, bank account number, advisory service date, and advisory fee amount |
5 years from the date of collection
|
|
Evaluating future advisory engagements and conducting product-related marketing activities |
Optional |
photograph, education history, employment history, research experience, fax number |
||
|
[Government-Funded Projects] Performance of National R&D Projects |
Submission of required documentation for the performance of government-funded R&D projects |
Required |
name, affiliated organization, email address, contact information, education history, graduation year |
For the period specified in the applicable National R&D Project RFP (which may vary by project) |
|
[Clinical Trials] Records and Documentation Relating to the Conduct of Clinical Trials |
Verification of researcher qualifications |
Required |
name, title, position, phone number, email address, resume/CV (education history, employment history, license number, training records, clinical trial participation information) |
3 years from the date of completion of the clinical trial; if separate consent has been obtained, for the period specified in the applicable Personal Information Collection and Use Consent Form (which may vary by study) |
|
Collection of clinical trial data |
Required |
age, gender, and other subject clinical information (which may vary by study) |
||
|
[VUUC] User Management Service |
Administration and management of users of VUNO products |
Required |
affiliated institution, name, email address |
Until the service is terminated |
|
Optional |
phone number, address |
|||
|
[Hativ Care] Account Registration |
Account registration; measurement and analysis; processing of service applications and consultation activities; and scientific research purposes |
Required |
name, phone number, encrypted user identification value (CI), date of birth, gender |
Until the account is deleted or membership is terminated |
|
Account registration; measurement and analysis; and processing of service applications and consultation activities |
Optional |
|
||
|
Measurement and analysis; processing of service applications and consultation activities; and scientific research purposes |
Required |
[Sensitive Personal Information] electrocardiogram (ECG) measurement data, average heart rate, measurement time |
||
|
Optional |
[Sensitive Personal Information] height, weight, blood pressure, blood glucose level, body temperature, other symptoms (discomfort, palpitations, dizziness, shortness of breath, chest pain), and notes |
The Company processes patient information on behalf of healthcare institutions in connection with the provision of its AI-based medical device services.
In providing AI-based medical device services to healthcare institutions, the Company processes patient information entered into the system by healthcare providers, solely as a service provider acting on behalf of such institutions and only for the purpose of delivering the contracted medical device services, as described below:
|
Category |
Purpose |
Required/Optional |
Categories of Personal Information Collected |
Retention Period |
|
[Medical Device] DeepCARS |
Analysis of patient electrocardiogram (ECG) measurement data |
Required |
name, gender, date of birth, patient identification number(PID), electrocardiogram(ECG) measurement data |
Until termination of service use
|
|
[Medical Device] Chest X-ray |
Interpretation of patient chest X-ray images
|
Required |
name, gender, date of birth, patient identification number(PID), chest X-ray images |
5 years from the date the patient information is stored |
|
[Medical Device] Fundus AI |
Interpretation of patient fundus images |
Required |
name, date of birth, patient identification number(PID), fundus images |
5 years from the date the patient information is stored |
The Company may retain Personal Information beyond the originally disclosed retention period, to the extent necessary, until the applicable period expires or the relevant condition is satisfied, in the following circumstances:
|
Applicable Law |
Categories of Personal Information Collected |
Retention Period |
|
Commercial Act |
Personal information included in key business records of the Company |
10 years |
|
Act on Consumer Protection in Electronic Commerce, etc |
Personal information included in records relating to contracts or withdrawal of offers (including cancellation or rescission) |
5 years |
|
Personal information included in records relating to payment of consideration and the supply of goods or services |
5 years |
|
|
Personal information included in records relating to consumer complaints or dispute resolution |
5 years |
|
|
Personal information included in records relating to labeling and advertising |
6 months |
|
|
Protection of Communications Secrets Act |
Personal information included in website access logs |
3 months |
|
Medical Device Act |
Personal information included in clinical trial protocols and records and materials relating to the conduct of clinical trials |
3 years |
|
Digital Medical Products Act |
Personal information included in clinical trial protocols and records and materials relating to the conduct and management of clinical trials |
3 years |
|
Bioethics and Safety Act |
Personal information included in records relating to human subject research |
3 years |
Article 2. Personal Information of Children Under 14
When collecting Personal Information from a child under the age of 14, the Company obtains verifiable consent from the child’s parent or legal guardian and collects only the minimum Personal Information necessary to provide the relevant services.
In connection with such collection, the Company may request limited information from the child, such as the name and contact information of the parent or legal guardian, for the purpose of obtaining and verifying parental consent. The Company verifies that valid consent has been provided by the parent or legal guardian through one of the following methods:
Article 3. Data Retention and Secure Disposal
The Company securely disposes of Personal Information without undue delay once the purpose for which it was collected and used has been fulfilled or the applicable retention period has expired, unless continued retention is required pursuant to the individual’s consent, applicable terms of service, or relevant laws and regulations.
Personal Information maintained in paper form is destroyed by shredding or incineration. Personal Information stored in electronic form is permanently deleted using secure technical methods designed to prevent recovery or reconstruction of the data.
If, due to technical limitations, complete deletion is not reasonably feasible, the Company will take appropriate measures to irreversibly anonymize the information so that it can no longer be used to identify an individual, taking into account reasonable considerations of time, cost, and available technology.
Article 4. Disclosure of Personal Information to Third Parties
The Company processes Personal Information only within the scope of the purposes described in this Privacy Policy. The Company discloses Personal Information to third parties only where (i) the individual has provided prior consent, or (ii) such disclosure is required or expressly permitted under applicable law. Except as described herein, the Company does not disclose Personal Information to third parties.
The Company discloses Personal Information to the following third parties for the purposes described below:
|
Category |
Recipient |
Purpose of Disclosure |
Categories of Personal Information Disclosed |
Retention Period |
|
Customer(Healthcare Professional) Information |
Ahngook, Bijutech, PuzzleAI, Maihub, Corelinesoft, SangsinMedical, UniMedical, MIK, MediMac, Olin, Sonamu, MAI, SmartOnHealthcare, YeosamInter, MDCompany |
Responding to purchase inquiries regarding medical devices, providing product information, and performing maintenance services |
institution name, name, field of specialty, email address, phone number |
Until the purpose of use has been fulfilled |
|
Researcher Information |
Korea Medical Devices Industry Association |
Reviewing quarterly reporting compliance and adherence to lecture/advisory fee caps under the Medical Device Fair Competition Code |
name, affiliated organization, lecture/advisory service date, lecture/advisory fee amount |
Until 5 years from January 1 of the year following the year in which the lecture or advisory service was provided |
|
Small and Medium Business Administration, Korea Industrial Complex Corporation, Korea Institute of Startup & Entrepreneurship Development, Korea Health Industry Development Institute, Korea International Cooperation Agency, Korea Health Industry Development Institute, Korea Institute of Industrial Technology Evaluation and Planning, National IT Industry Promotion Agency, Ministry of Science and ICT, Korea Institute for Advancement of Technology, Korea Software Industry Association, Institute for Information & Communications Technology Planning & Evaluation, Ministry of SMEs and Startups, Korea Technology Venture Foundation, Ministry of Food and Drug Safety, Ministry of Health and Welfare, and other government agencies responsible for national R&D projects |
Submission of agreements and related documentation for the performance of government-funded R&D projects |
name, affiliated organization, email address, contact information, education history, graduation year |
Until the period specified in the applicable National R&D Project RFP (which may vary by project) |
|
|
Shareholder Information |
Financial Supervisory Service, Korea Exchange |
Disclosure of shareholder personal information for the purpose of fulfilling statutory disclosure obligations |
name of major shareholder, ownership percentage, number of shares held |
Until the retention period required under applicable laws and regulations |
|
Adverse Event Information |
Ministry of Food and Drug Safety and other health regulatory authorities in countries where the Company’s products have obtained marketing authorization or regulatory approval. |
Reporting adverse reactions in accordance with applicable laws and regulations |
initials of name, gender, date of birth, age, height, weight, and other health-related information |
Until the retention period required under applicable laws and regulations |
|
Records and materials relating to the conduct of clinical trials |
Institutional Review Board(IRB)/Ethics Committee(EC), Ministry of Food and Drug Safety, and other health regulatory authorities in countries where the Company’s products have obtained marketing authorization or regulatory approval |
Verification of clinical trial procedures and data integrity, and obtaining marketing authorization/manufacturing approval |
researcher information (name, title, position, phone number, email address, CV, clinical trial participation information), subject clinical information (which may vary by study), and safety information including adverse events |
Until the purpose of use has been fulfilled, or for the retention period required under applicable laws and regulations, whichever is longer |
Article 5. Criteria for Ongoing Additional Use or Disclosure
Where the Company engages in ongoing additional use or disclosure of Personal Information, it will do so only to the extent reasonably related to the original purpose of collection and consistent with applicable data protection laws. In making this determination, the Company considers, among other factors, whether the additional use or disclosure could result in material harm or disadvantage to the individual and whether appropriate safeguards (e.g., encryption) have been implemented.
In particular, the Company will carefully evaluate the totality of circumstances, including: the purpose of the use or disclosure; the manner in which the Personal Information will be used or disclosed; the categories of Personal Information involved; whether the individual has consented to, been notified of, or could reasonably expect such use or disclosure; the potential impact on the individual; and the safeguards in place to protect the information.
Key factors include:
Article 6. Engagement of Service Providers
To facilitate efficient operations and provide improved services and user convenience, the Company engages third-party service providers to process Personal Information on its behalf.
When entering into agreements with such service providers, the Company requires, in accordance with applicable data protection laws, that the service provider: (i) process Personal Information solely for the specified and authorized business purpose; (ii) implement appropriate technical and organizational safeguards to protect Personal Information; (iii) refrain from further subcontracting without authorization; and (iv) assume contractual responsibility, including indemnification and liability, for the protection of Personal Information. These requirements are set forth in written agreements, and the Company oversees and monitors its service providers to ensure that Personal Information is processed securely and in compliance with applicable law.
The Company engages the following service providers to process Personal Information on its behalf:
|
Service Provider |
Categories of Outsourced Processing Activities |
Sub-Processor (Subcontracted Processing Activities) |
|
Doodlin |
Recruitment website and applicant management services |
Channel Corporation(Consultation services) |
|
NHN Cloud(Mobile messaging services) |
||
|
Twilio(Email transmission services) |
||
|
Goorm |
Coding assessment service for job applicants |
- |
|
Sinaforyou |
Booth fabrication, installation, rental, dismantling, and storage services, as well as storage and delivery of promotional materials |
- |
|
KB Kookmin Bank |
Securities transfer agency services, including account registration for securities, issuance of securities, and administration of dividend and bond principal/interest payments |
- |
|
Samsung Securities |
Electronic voting management services |
- |
|
Synex |
Clinical trial data management and statistical analysis services |
CSRcube(Electronic Case Report Form (eCRF) services) |
|
Promedis |
CSRcube(Electronic Case Report Form (eCRF) services) |
|
|
Digital2s |
CSRcube(Electronic Case Report Form (eCRF) services) |
|
|
JNPMEDI |
- |
|
|
C&K INSIGHT |
|
|
|
CSRcube |
|
|
|
Amazon Web Services |
Cloud infrastructure services |
- |
|
Google LLC |
Service usage tracking and evaluation |
- |
|
NICE Information Service |
Identity verification services |
- |
|
NAVER Cloud Corp |
Mobile messaging services |
|
|
Korea Post(Postal Parcel Service) |
Product delivery services |
- |
|
CJ Logistics Corporation |
Product delivery services |
- |
|
Mau Communications |
Management of symposium pre-registrants |
- |
|
S-1 Corporation |
Maintenance of video surveillance systems |
- |
Article 7. Cross-Border Transfers of Personal Information
The Company does not transfer Personal Information overseas.
Article 8. Information Security Safeguards
The Company implements commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, acquisition, disclosure, alteration, or destruction. In addition, the Company has obtained objective certifications—such as information security management system certifications—from independent third-party assessors for its major systems and facilities.
The Company has implemented the following measures:
To prevent loss, theft, unauthorized disclosure, alteration, or damage to Personal Information, the Company applies the following technical measures:
Article 9. Processing of Pseudonymized Information
The Company processes pseudonymized information for purposes including clinical trials, AI software development, and related research activities.
The medical data used for these purposes does not include direct identifiers such as name, contact information, or other information that would directly identify a specific individual. The Company uses such data solely for scientific research and product development purposes and does not process pseudonymized information for the purpose of re-identifying any individual.
Details regarding the Company’s processing of pseudonymized information are as follows:
|
Service |
Purpose of Processing |
Categories of Processed |
Retention Period |
|
Clinical trials |
Conduct of medical device clinical trials and obtaining manufacturing and marketing authorization |
age, gender, and other clinical information (which may vary by study) |
3 years from the date of completion of the clinical trial; if separate consent has been obtained, for the period specified in the applicable Personal Information Collection and Use Consent Form (which may vary by study) |
|
Hativcare |
Research and development of medical diagnostic algorithms |
login ID, year and month of birth, weight, height, electrocardiogram(ECG) data |
Until completion of the research (no later than December 31, 2026) |
In addition to the safeguards described in Article 8 (Information Security Safeguards), the Company implements the following additional measures to ensure the security of pseudonymized information:
Article 10. Cookies and Similar Technologies
The Company uses cookies and similar tracking technologies to collect and store certain information about users and to retrieve such information as needed.
A cookie is a small text file that is placed on a user’s computer or mobile device by a web server when the user accesses a website. Cookies are transmitted back to the Company’s servers when the user revisits the website and are used to support website functionality, enhance user experience, and analyze site usage.
Users have the option to control the use of cookies. Most web browsers allow users to manage cookie preferences through their browser settings, including the ability to accept all cookies, reject all cookies, or receive a notification when a cookie is set. Please note that disabling cookies may affect the availability or functionality of certain features of the website.
|
Browser |
How to Block Cookies |
|
Chrome |
Select the three-dot menu (⋮) in the upper-right corner → New Incognito Window (or New Incognito Tab) |
|
Microsoft Edge |
Select the three-dot menu (…) in the upper-right corner → New InPrivate Window |
|
Safari(iOS) |
Settings → Safari → Advanced → Block All Cookies |
|
Samsung Internet |
Tap the Tabs icon at the bottom → Turn on Secret mode → Start |
Article 11. Rights of Individuals and Legal Representatives; How to Exercise Those Rights
Individuals may exercise the following rights with respect to their Personal Information, subject to applicable law:
Article 12. Installation and Operation of Fixed Video Surveillance Systems (CCTV)
The Company installs and operates fixed video surveillance systems (CCTV) as described below:
|
Location of Installation |
Number of Cameras Installed |
Area Monitored |
Location of Footage Storage |
|
Sinnonhyeon Tower B2F |
8 |
entrance, warehouse area, server room |
Server room |
|
Sinnonhyeon Tower 8F |
1 |
entrance |
Server room |
|
Sinnonhyeon Tower 9F |
1 |
entrance |
Server room |
|
Sinnonhyeon Tower 10F |
1 |
entrance |
Server room |
|
Sinnonhyeon Tower 11F |
1 |
entrance |
Server room |
|
Hativ Warehouse |
7 |
entrance, warehouse area |
Server room |
|
Category |
Department |
Title |
|
Responsible Manager |
General Affairs Team |
Team Manager |
|
Authorized Personnel |
Corporate Management Division |
Head of Division |
|
IT Security Infrastructure Team |
Team Manager |
|
|
Human Resources Team |
Team Manager |
|
|
Authorized Personnel(Warehouse) |
Hativ Team |
Logistics and Packaging Staff |
Article 13. Additional Efforts to Protect Personal Information
|
Category |
ISO/IEC 27001:2022
|
ISO/IEC 27701:2019
|
|
Scope of Certification |
The provision of Medical Services including the development and supply of solutions and SaaS |
The provision of Medical Services including the development and supply of solutions and SaaS as both PII Controller and PII Processor |
|
Certification Period |
November 24, 2025 – November 23, 2028 |
November 24, 2025 – November 23, 2028 |
Article 14. Chief Privacy Officer
The Company has designated a Chief Privacy Officer who is responsible for overseeing the Company’s Personal Information processing activities and for handling inquiries, complaints, and requests for redress relating to privacy and data protection matters.
Article 15. Remedies for Infringement of Privacy Rights
If you have any complaints or concerns regarding the protection of your Personal Information arising from your use of the Company’s services, you may contact the Company’s designated privacy response department:
If you require additional assistance or wish to report a privacy-related concern, you may contact the following authorities:
|
Agency Name |
Website |
Contact Number |
|
Personal Information Dispute Mediation Committee |
www.kopico.go.kr |
+82-1833-6972 |
|
Personal Information Infringement Report Center |
privacy.kisa.or.kr |
118(Korea only) |
|
Supreme Prosecutors’ Office Cyber Investigation Division |
www.spo.go.kr |
1301(Korea only) |
|
National Police Agency Cyber Bureau |
ecrm.police.go.kr |
182(Korea only) |
Article 16. Changes to This Privacy Policy