Privacy Policy
Effective: 2025-01-01 · Last revised: 2026-08-28
인사책 (InsaCheck), operated by BRIDDZZI, is a workforce attendance & HR platform for Korean employers and workers. We respect your privacy and comply with the Personal Information Protection Act (PIPA / PIPL) of the Republic of Korea and Google Play Data Safety requirements. This English document mirrors the authoritative Korean version at /privacy?lang=ko.
1. Information We Collect
Worker accounts
- Required: name, phone number, date of birth, email address, social-login subject ID, social provider (Kakao / Naver / Google / Apple), social email
- Optional: gender, profile picture
- Automatically collected: precise GPS coordinates & accuracy (only when you tap check-in / check-out), device info, IP address, User-Agent, OS
- Generated during use: affiliation requests (department, position, message), peer ratings & tags
Enterprise accounts
- Required: business type, company name, business registration number, manager name & email & phone, hashed password, company address
- Optional: business registration certificate file, corporate registration number, industry, postal code, signup survey answers
Website visits
- First-party analytics: anonymous session key, landing path, first-visit timestamp, UTM campaign values, and Naver ad keyword/ad identifiers.
- We do not store the raw Naver search query (
n_query), the raw conversion token (NaPm), or full referrer query strings.
2. How We Use Information
- Authenticate you via Kakao / Naver / Google / Apple Sign-In and prevent proxy attendance.
- Record and manage attendance check-ins and check-outs.
- Match workers to enterprises and manage employment history.
- Compute work-temperature scores and let prior employers leave references with the worker's consent.
- Improve the service through aggregate statistics and detect abuse.
- Send push notifications about HR events (affiliation approvals, seal request decisions, etc.).
3. Retention
- Account data (personal information): deactivated immediately on withdrawal request and permanently erased after a 14-day grace period. Records that Korean law requires us to keep are retained separately from your account for the periods below.
- Attendance records: 5 years, then deleted (the Korean Labour Standards Act requires 3 years; we retain longer to cover the wage-claim limitation period and labour-dispute defence).
- Payroll ledger & employment-contract records: 3 years, then deleted.
- Social-insurance enrollment/loss records: retained for the period required by law.
- Wage audit logs: 5 years, then deleted.
- Business registration certificates: 1 year after enterprise approval, then deleted.
- Access logs: 3 months (Telecommunications Privacy Act).
Retained records do not include the deleted account's personal information (name, contact, etc.).
4. Sharing With Third Parties
We do not sell personal data. Limited sharing happens only when:
- You explicitly consented in advance.
- You request affiliation with an enterprise — your basic info (name, phone, department, position) is shared with that enterprise's HR admin.
- An enterprise requests a reference check on your previous workplace, and you approve — peer ratings & tags are shared with the requesting enterprise.
- An enterprise has set up an external workplace-tool integration (Google Sheets, Slack, or Notion) — that enterprise's attendance records are forwarded to the tool it configured.
- Note: the electronic contract solution "SignDeal" is operated by BRIDDZZI Inc., the same operator as Insacheck. Transfers to SignDeal are therefore not third-party provision and remain covered by this policy.
- Required by Korean law enforcement under valid legal process.
5. Sub-processors
- Cloudflare, Inc. — Service hosting and data storage (Workers, D1 Database, R2 Storage)
- Kakao Corp. — Social login (Kakao Login API); postcode and road-name address lookup (Daum Postcode service — the keyword the user types into the widget is transmitted)
- Naver Corporation — Social login (Naver Login API)
- Google LLC — Google Sign-In, Firebase Cloud Messaging push notifications, optional Google Sheets export (configured by the enterprise)
- Apple Inc. — Sign in with Apple (iOS app)
- TossPayments Inc. (토스페이먼츠 주식회사) — Card registration, recurring billing, payment lookup and payment-method removal for paid storage subscriptions. Processed in Korea (no cross-border transfer). Card numbers are entered directly into the TossPayments checkout and never reach our servers; we store only the issuer name and a masked card number.
- Telegram Messenger — Delivery of new-inquiry notifications to our support channel. This is a cross-border transfer outside Korea; see §5-2 of the Korean policy for the exact fields transferred per inquiry channel.
6. Security Measures
- All passwords hashed with PBKDF2-SHA256 (310,000 iterations, OWASP recommendation).
- Session cookies marked HttpOnly + SameSite=Lax + Secure.
- All traffic encrypted in transit via HTTPS / TLS.
- All database queries use prepared statements (no string interpolation).
- IP-based rate limiting on auth-sensitive endpoints.
7. Your Rights
- Access, correct, restrict processing of, or delete your personal data at any time.
- You can delete your account in-app (Profile → 회원 탈퇴 / Withdraw) or via our public request page at https://insacheck.com/account-deletion. Your personal information is deactivated immediately and permanently erased after a 14-day grace period; certain records are retained separately under Korean law as described in §3 (Retention).
- Cookies can be blocked at the browser level — service may be limited if you do.
8. Privacy Officer
BRIDDZZI Privacy Team — privacy@briddzzi.com
If you live in Korea, you may also contact KISA's privacy infringement hotline at 118 or the Personal Information Dispute Mediation Committee at kopico.go.kr.
9. Changes
We post material changes here at least 7 days before they take effect. Continued use after the effective date constitutes acceptance.