This English version is provided for reference. In case of any discrepancy, the Korean original prevails.
CONNECT IN Corp. (주식회사 커넥트인) — Tradex Privacy Policy
Last updated: August 19, 2026
Effective date: August 26, 2026
CONNECT IN Corp. (the "Company") processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act and other applicable laws in order to protect the freedom and rights of data subjects. In accordance with Article 30 of the Personal Information Protection Act, the Company establishes and publishes this Privacy Policy to inform data subjects of the procedures and standards for the processing and protection of personal information and to handle related grievances promptly and smoothly. This Privacy Policy applies to the Tradex service provided by the Company (website and mobile service, the "Service").
Table of Contents
- Purposes of Processing Personal Information
- Personal Information Processed and Collection Methods
- Processing and Retention Period of Personal Information
- Processing of Personal Information of Children Under 14
- Procedures and Methods for Destruction of Personal Information
- Outsourcing of Personal Information Processing
- Cross-Border Transfer of Personal Information
- Criteria for Additional Use and Provision of Personal Information
- Measures to Ensure the Security of Personal Information
- Installation, Operation and Refusal of Automatic Collection Devices (Cookies)
- Collection, Use and Refusal of Behavioral Information
- Automated Decisions
- Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
- Personal Information Protection Officer and Responsible Department
- Remedies for Infringement of Data Subjects' Rights
- Changes to the Privacy Policy
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed is not used for any purpose other than the following, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
- Membership registration and management: confirming the intention to register, identifying and authenticating the user for membership services (including email verification), maintaining and managing membership status, preventing fraudulent use of the Service, confirming whether the user is a child under 14, various notices and notifications, handling grievances, and preserving records for dispute resolution.
- Provision and operation of the Service: providing paid services, providing content, concluding and performing contracts, identity verification, processing fee payments, settlement and subscription renewals (payments via Paddle, the Merchant of Record), sending receipts, and handling customer support and inquiries.
- Provision of AI-based trading analysis services: analyzing prompts entered by the user (text, voice, images, attachments) and trading data to provide personalized market analysis, trading-principle recommendations, chart analysis and strategy/risk analysis results (content), and using natural-language understanding and processing technology to improve the accuracy and relevance of responses.
- Provision of the automatic trading journal: automatically retrieving, recording and analyzing trading history using the exchange API keys registered by the user, and providing it in the form of a trading journal.
- Service improvement and development of new services: analyzing service usage records and access frequency, using statistical data, verifying the effectiveness of the Service, improving AI model performance (in which case the Company will obtain prior consent from the data subject or provide an opt-out procedure under Article 8 of this Policy), developing new features, and providing personalized services.
- Marketing and advertising: developing new services (products) and providing customized services, providing events and advertising information and opportunities to participate, providing services and placing advertisements according to demographic characteristics, verifying the effectiveness of the Service, and compiling statistics on access frequency or members' use of the Service (marketing and advertising use is limited to cases where the data subject's separate consent has been obtained).
Article 2 (Personal Information Processed and Collection Methods)
1. Personal information processed without the data subject's consent
The Company processes the following personal information without the data subject's consent.
| Category | Legal basis | Purpose | Items collected |
|---|---|---|---|
| Membership registration and management | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Confirming the intention to register, identifying and authenticating the user, maintaining membership status | Email address, username, password (stored as a hash), service preferences (language, display currency, time zone) |
| Social login | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Providing simplified login | Email, username, profile photo, unique identifier (social ID) and provider identifier received from social login providers such as Google, Apple and Kakao |
| Paid service payment and subscription management | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Paid subscription payment and settlement, subscription renewal and plan changes, refund processing | Customer ID, subscription ID and transaction ID issued by the Merchant of Record (Paddle), subscription plan and billing cycle, payment amount and currency, payment status and date, refunded amount (payment-method details such as card number, CVC and expiry date are collected and processed directly by Paddle, the Merchant of Record, at checkout; the Company neither receives nor stores them) |
| Use of the AI analysis service | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Providing AI-based market analysis and trading-principle, strategy and risk analysis results | Text (questions and instructions), voice, images and attachments entered by the user in the chat (input) window, outputs generated by the Service (answers, analysis results, etc.), AI credit usage history |
| Automatic trading journal | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Automatically collecting, recording and analyzing trading history via exchange integration | Exchange API key, secret key, passphrase (for Bitget), exchange trading history (fills, balances, positions, entry and exit prices, PnL, trade times, order information, etc.) |
| Trading journal and chart analysis | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Storing the user's trade rationale and review notes, managing attached images | Trade rationale, review notes, trading principles, trading rules, chart screenshot image files (stored in AWS S3 with per-user path isolation) |
| Automatically generated and collected during use of the Service | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Service operation, prevention of fraudulent use, statistics and analysis, security, incident response | Service usage records (access time, features used, activity history), access logs, cookies, IP address, device information (OS, browser type and version, device identifier), trace ID, HTTP method and request path, communication confirmation data under the Protection of Communications Secrets Act |
| Issuance of authentication tokens | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) | Keeping the user logged in, session management, password reset | Access token linked to the user identifier (JWT, 15-minute expiry), refresh token (random token; 14 days if 'keep me signed in' is selected, otherwise 1 day; absolute expiry 90 days), password reset token (UUID, 1-hour expiry) |
2. Personal information processed with the data subject's consent
The Company processes the following personal information with the data subject's consent.
| Category | Legal basis | Purpose | Items collected |
|---|---|---|---|
| Receipt of marketing information | Article 15(1)1 of the Personal Information Protection Act (consent) | Notices of new services, events and benefits; sending advertising information | Email address, mobile phone number, username |
| Profile information (optional) | Article 15(1)1 of the Personal Information Protection Act (consent) | Displaying a profile photo and providing a personalized user experience | Profile photo image (stored in AWS S3) |
※ You may use the essential Service even if you refuse consent; only the receipt of marketing information and the profile photo feature are restricted.
3. Collection methods
- Direct input during membership registration, use of the Service and the payment process (including the checkout provided by Paddle, the Merchant of Record) on the website (web, mobile web or app)
- Collection through email and inquiry consultations via customer support
- Provision by social login providers (Google, Apple, Kakao, etc.)
- Automatic collection of trading data via the APIs of exchanges connected by the user (Binance, Bybit, Bitget, etc.)
- Automatic collection through cookies, log analysis tools (PostHog, Google Analytics, etc.), service usage analysis tools and other tools that collect generated information
4. Notes on information you enter
※ In free-text areas such as the AI chat window and trading journal fields, please take special care not to enter sensitive information about yourself or others (ideology or beliefs, health or medical information, sex life, race or ethnicity, genetic information, criminal records, etc.) or unique identification information (resident registration number, passport number, driver's license number, alien registration number).
Article 3 (Processing and Retention Period of Personal Information)
The Company processes and retains personal information within the retention and use period prescribed by law, the period necessary for concluding and performing the contract, or the retention and use period to which the data subject consented at the time of collection.
The processing and retention periods are as follows.
| Category | Retention period | Legal basis |
|---|---|---|
| Membership registration and management | Until withdrawal | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| AI conversation history (prompts and outputs) | 30 days from the last conversation, or immediately upon deletion by the user. Destroyed immediately upon withdrawal | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| Exchange API keys and other credentials | Destroyed immediately upon deletion by the user or upon withdrawal | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| Exchange trading history, trading journal, chart screenshots | Until withdrawal (the user may delete them directly; attached screenshots are deleted together with the journal entry) | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| Authentication tokens (access and refresh tokens, password reset token) | Destroyed immediately upon token expiry or withdrawal (refresh token up to 14 days, absolute expiry 90 days; reset token 1 hour) | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| Subscription and payment identifiers (Paddle customer ID, subscription ID, transaction ID, subscription plan and billing interval, payment amount and currency, payment status and timestamp, refunded amount) | Until withdrawal (payment records are stored separately for the statutory retention period in the table below and then destroyed) | Article 15(1)4 of the Personal Information Protection Act (conclusion and performance of a contract) |
| Receipt of marketing information | Until consent is withdrawn or the member withdraws | Article 15(1)1 of the Personal Information Protection Act (consent) |
However, in the following cases, the information is retained until the relevant reason ceases to exist.
- Where an investigation or inquiry into a violation of applicable laws is in progress: until the investigation or inquiry is concluded
- Where claims or obligations arising from use of the Service remain: until they are settled
Information that must be retained under applicable laws is as follows.
| Item retained | Retention period | Applicable law |
|---|---|---|
| Records on contracts or withdrawal of offers | 5 years | Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. and Article 6 of its Enforcement Decree |
| Records on payment and supply of goods, etc. | 5 years | Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. and Article 6 of its Enforcement Decree |
| Records on consumer complaints or dispute resolution | 3 years | Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. and Article 6 of its Enforcement Decree |
| Records on labeling and advertising | 6 months | Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. and Article 6 of its Enforcement Decree |
| Records on electronic financial transactions | 5 years | Article 22 of the Electronic Financial Transactions Act and Article 12 of its Enforcement Decree |
| Website visit records (login records, etc.) | 3 months | Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree |
| Books and supporting documents for all transactions prescribed by tax law | 5 years | Article 85-3 of the Framework Act on National Taxes |
Article 4 (Processing of Personal Information of Children Under 14)
- In principle, the Company does not allow children under the age of 14 to register as members. The Service deals with information and analysis related to virtual-asset trading and is not primarily intended for children under 14.
- The Company checks whether a user is under 14 by means such as date of birth at the time of registration, and restricts registration where the user is confirmed to be under 14.
- If the Company becomes aware that the personal information of a child under 14 has been collected without the consent of a legal representative, the Company will destroy that personal information without delay. The legal representative of a child under 14 may contact the Personal Information Protection Officer below to request deletion of the child's personal information.
Article 5 (Procedures and Methods for Destruction of Personal Information)
When personal information becomes unnecessary — for example when the retention period expires or the purpose of processing is achieved — the Company destroys it without delay after approval by the Personal Information Protection Officer.
Where personal information must continue to be preserved under other laws despite the expiry of the retention period consented to by the data subject or the achievement of the processing purpose, the personal information or personal information file is moved to a separate database (DB) or stored in a different location. The items, legal basis and retention periods of personal information preserved under other laws are set out in "Article 3 (Processing and Retention Period of Personal Information)".
Destruction procedure
The Company selects the personal information for which a reason for destruction has arisen and destroys it with the approval of the Personal Information Protection Officer. The destruction methods for personal information held directly by the Company and for personal information stored by third-party processors under Article 6 are as follows.
Destruction of personal information held directly by the Company
- Electronic files: records are deleted from database (DB) records and file systems using technical methods that make the records irrecoverable (secure deletion, low-level formatting, etc.). Information that was stored with encryption keys (exchange API keys, secrets, passphrases, etc.) is processed together with key destruction so that the plaintext cannot be recovered.
- Paper documents: shredded or incinerated.
Destruction of personal information stored by processors
For personal information stored by processors to which the Company has outsourced processing under Articles 6 and 7 — cloud infrastructure (AWS), AI processing (OpenAI), statistics and analytics (PostHog, Google Analytics), payment and merchant-of-record services (Paddle), email delivery (Gmail SMTP), push notifications (Firebase, APNs), customer consultation (Channel Talk), etc. — the Company destroys the information or requests the processor to destroy it by the following methods.
- Using the administrator privileges held by the Company, the relevant personal information objects and records are immediately deleted from the processor's storage (AWS S3, RDS, CloudWatch Log Groups, etc.), and backup copies are allowed to expire automatically after the backup retention cycle guaranteed by the processor.
- For data held by processors themselves that the Company cannot delete directly (for example, transaction records retained by the Merchant of Record (Paddle) under statutory retention obligations, or short-term logs of the AI processor), the Company ensures destruction in accordance with the outsourcing agreement and the processor's published data-processing policy, and verifies compliance through management and supervision of the processor.
- If a processor's specific destruction method or period changes due to a change in the processor's policy, the Company reflects the change in this Privacy Policy immediately and publishes it.
Article 6 (Outsourcing of Personal Information Processing)
The Company outsources personal information processing as follows for the smooth handling of personal information.
| Processor | Outsourced work | Retention and use period |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure operation, database and storage (S3) hosting, system log (CloudWatch) storage (data is stored in the Seoul, Republic of Korea region, ap-northeast-2) | Until withdrawal or termination of the outsourcing agreement (system logs: 3 months from collection) |
| OpenAI, L.L.C. | Providing generative AI (LLM)-based conversation and analysis features (analysis of user prompts and the trading records being analyzed, generation of answers, generation of embeddings for trading journal search) | Destroyed immediately after the answer is generated (not used for the processor's own model training; controlled through the OpenAI API policy or an enterprise agreement) |
| PostHog, Inc. | Service usage statistics, behavioral analytics and error (exception) diagnosis | Until termination of the outsourcing agreement or withdrawal |
| Google LLC (Google Tag Manager, Google Analytics) | Marketing tag management, service usage statistics and log analysis | 26 months from collection |
| Google LLC (Firebase Cloud Messaging, Firebase Analytics) | Sending web and app push notifications, app usage analytics | Until push consent is withdrawn or the member withdraws |
| Apple Inc. (APNs) | Delivering push notifications to iOS devices | Short-term retention after delivery in accordance with the processor's policy, then destroyed |
| Telegram (Telegram FZ-LLC) | Sending notification messages only where the user has enabled Telegram notifications | Until the notification link is disabled or the member withdraws |
| Channel Corporation (Channel Talk) | Operating the customer consultation channel (receiving and responding to inquiries) | Until termination of the outsourcing agreement or withdrawal |
| Meta Platforms, Inc. | Advertising performance (conversion) measurement (email and phone number are SHA-256 hashed before transmission) | Retained in accordance with the processor's policy, then destroyed |
| Slack Technologies, LLC / GitHub, Inc. | Real-time alerting and tracking of system error logs (for incident response, only when an error occurs) | Destroyed once the operational purpose is achieved |
| Paddle.com Market Limited (United Kingdom) / Paddle.com Inc. (United States) (Paddle) | Merchant of Record for paid services: payment processing, subscription billing and renewal, tax calculation, issuance of receipts, refund processing (payment-method details are collected and processed directly by Paddle) | Until the end of the retention period under Paddle's privacy policy and applicable laws after the transaction ends |
| Google LLC (Gmail SMTP) | Sending transactional and system emails such as password resets and notifications | Destroyed immediately after delivery |
In accordance with Article 26 of the Personal Information Protection Act, when concluding an outsourcing agreement the Company specifies in the contract or other document matters such as the prohibition of processing personal information for purposes other than the outsourced work, technical and managerial protective measures, restrictions on sub-outsourcing, management and supervision of the processor, and liability for damages, and supervises whether the processor processes personal information securely.
For outsourced processing that uses external generative AI services such as OpenAI, the Company ensures through API policies or enterprise agreements that no information entered by users in the chat window is used without authorization to train the processor's own large language models (LLMs). The Company likewise does not use users' prompts and outputs as training data for its own AI models, and if it wishes to do so in the future, it will provide a prior-consent or opt-out procedure in accordance with Article 8.
If the outsourced work, the processor, the processor's retention and use period, or the processor's personal information processing policy (for example, the processor's own terms or privacy policy) changes, the Company monitors the change and reflects it in this Privacy Policy without delay.
Cases in which personal information processing is outsourced overseas are described collectively in "Article 7 (Cross-Border Transfer of Personal Information)".
External exchanges (Binance, Bybit, Bitget, etc.) for which users enter and register their own account information are not processors of the Company; they are handled under a separate contractual relationship between the user and the exchange. The Company takes technical measures (AES-256-GCM encrypted storage) to store and use the exchange API keys registered by users securely.
Article 7 (Cross-Border Transfer of Personal Information)
To provide the Service, manage data stably and process payments for paid services, the Company transfers personal information overseas as follows (outsourced processing and storage, and provision to the Merchant of Record), and provides the following notice on cross-border transfers in accordance with Article 28-8(2) of the Personal Information Protection Act.
| Recipient (contact) | Country | Time and method of transfer | Personal information transferred | Purpose of use | Retention and use period |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. (aws-privacy@amazon.com) | Stored in the Republic of Korea (Seoul region, ap-northeast-2). However, the data may be accessed from overseas, including the United States, in the course of the processor's global infrastructure operation and technical support | Transmitted over the network with encryption (TLS) at the time of Service use | All data necessary for Service operation, including member information, trading data, AI conversation history, trading journals and chart screenshots, and system logs (MDC) | Cloud infrastructure operation, data storage, system log storage (outsourced processing and storage) | Until withdrawal or termination of the outsourcing agreement (system logs: 3 months) |
| OpenAI, L.L.C. (privacy@openai.com) | United States | Transmitted over the network with encryption (TLS) when AI features are used | Prompt data such as text, images and attachments entered by the user in the chat window, trading records being analyzed (positions, fills, ledger entries), trading journal text, chart images | Generating and returning AI answers (outputs) at the user's request, generating embeddings for trading journal search (outsourced processing) | Destroyed immediately after the answer is generated |
| PostHog, Inc. (privacy@posthog.com) | United States | Transmitted automatically during Service use | Pseudonymized user identifier, subscription status, service usage records, trade metadata (symbol, side, leverage, win/loss — amounts excluded), error (exception) information, cookies, device information | Service usage statistics, behavioral analytics and error diagnosis (outsourced processing) | Until termination of the outsourcing agreement or withdrawal |
| Google LLC (Google Tag Manager, Google Analytics) (googlekrsupport@google.com) | United States | Transmitted automatically during Service use | Service usage records, cookies, IP address, device information, member identifier | Marketing tag management, service usage statistics and log analysis (outsourced processing) | 26 months from collection |
| Google LLC (Firebase Cloud Messaging, Firebase Analytics) (googlekrsupport@google.com) | United States | Transmitted automatically upon push consent and when notifications are sent | Push registration token, notification title and body, app usage events, device information | Sending web and app push notifications, app usage analytics (outsourced processing) | Until push consent is withdrawn or the member withdraws |
| Apple Inc. (APNs) | United States | Transmitted over the network with encryption when iOS push notifications are sent | Device push token, notification title and body | Delivering push notifications to iOS devices (outsourced processing) | Short-term retention after delivery in accordance with the processor's policy, then destroyed |
| Telegram (Telegram FZ-LLC) | United Arab Emirates and other countries where the processor's infrastructure is located | Transmitted when notifications are sent, where the user has enabled Telegram notifications | Telegram chat identifier (chat_id), notification title and body | Sending Telegram notification messages (outsourced processing, only at the user's election) | Until the notification link is disabled or the member withdraws |
| Meta Platforms, Inc. (privacy@fb.com) | United States | Transmitted when conversion events such as sign-up or payment occur | SHA-256 hashed email, phone number and member identifier, payment amount, advertising identifier cookies (_fbp/_fbc), IP address, browser information | Advertising performance (conversion) measurement (outsourced processing) | Retained in accordance with the processor's policy, then destroyed |
| Slack Technologies, LLC / GitHub, Inc. | United States | Transmitted automatically when a system error occurs | Error log body (may include the member identifier; personal information fields are masked) | Real-time alerting and tracking of system errors and incident response (outsourced processing) | Destroyed once the operational purpose is achieved |
| Google LLC (Gmail SMTP) (googlekrsupport@google.com) | United States | Transmitted over the network with encryption (TLS) when emails are sent | Email address, email body such as password reset links | Sending transactional and system emails (outsourced processing) | Destroyed immediately after delivery |
| Paddle.com Market Limited (United Kingdom) / Paddle.com Inc. (United States) (privacy@paddle.com) | United Kingdom, United States | Transmitted over the network with encryption (TLS) at the time of paid-service payment, subscription change or refund | Email address, member identifier, country and IP address (for tax calculation), subscription plan, payment amount and currency, payment-method details (card number, etc. — entered by the user directly in the Paddle checkout and not stored by the Company) | Merchant of Record for paid services: payment processing, tax calculation and remittance, issuance of receipts, refund processing | Until the end of the retention period under Paddle's privacy policy and applicable laws after the transaction ends |
Legal basis for cross-border transfer: Article 28-8(1)3 of the Personal Information Protection Act (where outsourced processing or storage of personal information is necessary to conclude and perform a contract with the data subject). The transfer to the Merchant of Record (Paddle) is made to the extent necessary to conclude and perform the paid-service contract (payment processing).
Right to refuse cross-border transfer: the data subject may refuse the cross-border transfer. The consequence of refusal depends on the purpose of the transfer. (i) Refusing a transfer that is essential to the core infrastructure and features of the Service (cloud infrastructure such as AWS, authentication, notifications, etc.) makes use of the Service impossible; in that case you may request withdrawal through the in-Service withdrawal menu (Settings > Account > Delete account) or customer support (justin@tradex.so). (ii) The transfer to the Merchant of Record (Paddle) is required only for paid-service payments; if you refuse it, only the purchase and renewal of paid plans are restricted while the free Service remains available.
Follow-up on changes to overseas processors' policies: if the terms, privacy policy or security policy of any overseas processor above changes, the Company continuously monitors the change, reflects it in this Privacy Policy immediately, and, where the change materially affects the rights of data subjects, gives individual notice in accordance with Article 16.
Article 8 (Criteria for Additional Use and Provision of Personal Information)
Under Articles 15(3) and 17(4) of the Personal Information Protection Act, the Company may additionally use or provide personal information without the data subject's consent, taking into account the matters set out in Article 14-2 of the Enforcement Decree of the Personal Information Protection Act.
Accordingly, the criteria the Company considers for additional use or provision are as follows.
- Whether it is related to the original purpose of collection
- Whether the additional use or provision is foreseeable in light of the circumstances in which the personal information was collected or processing practices
- Whether it unfairly infringes the interests of the data subject
- Whether measures necessary to ensure security, such as pseudonymization or encryption, have been taken
The Company currently does not use prompts (conversation content) entered by users or outputs generated by the Service as training data for its own AI models without the data subject's consent. If the Company wishes to use them as training data in the future for purposes such as improving AI model performance or fine-tuning, it will obtain the data subject's separate consent in advance or specify the items, purposes, period and opt-out method in this Policy, apply security measures such as pseudonymization or anonymization at the training stage, and only then proceed. From the time such training use begins, data subjects will be able to opt out of training data use directly in the in-Service settings (Settings > Account > AI training data use).
Article 9 (Measures to Ensure the Security of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act and the Standards for Measures to Ensure the Security of Personal Information (notice of the Personal Information Protection Commission), the Company takes the following managerial, technical and physical measures to ensure the security of personal information.
- Managerial measures: establishing and implementing an internal management plan for personal information, minimizing and regularly training staff who handle personal information, operating dedicated personal-information-protection personnel, and regularly inspecting and improving personal information processing practices.
- Technical measures
- Passwords: stored encrypted with a one-way hash function (bcrypt); the plaintext cannot be recovered
- Exchange API keys, secret keys and passphrases: stored encrypted with AES-256-GCM, with keys managed separately through a Key Management System
- Communications: TLS (HTTPS) encryption across the entire Service
- Authentication and sessions: JWT-based token authentication (access token 15 minutes), refresh token expiry policy (up to 14 days, absolute expiry 90 days, immediate session revocation on reuse detection), limits on concurrent sessions, short-lived password reset tokens (1 hour), monitoring of abnormal access
- Access control: differentiated privileges for personal information processing systems, installation of access control systems, operation of intrusion prevention and detection systems, storage and tamper-proofing of access records (MDC logging)
- Security inspections: installation, operation and updating of security programs, and inspection and remediation of vulnerabilities in personal information processing systems
- Physical measures: the Company does not operate its own server room and uses a cloud service (AWS), relying on the physical access controls and disaster preparedness measures of the data centers provided by the processor. Work PCs and documents are kept in secure, lockable locations.
- Protection of payment information: the Company does not collect or store original credit card payment information (full card number, CVC, expiry date, etc.); it is collected and processed directly by Paddle, the Merchant of Record, in its own checkout. The Company stores only the Paddle customer ID, subscription ID and transaction ID and payment result information (subscription plan, payment amount, currency, status, date, refunded amount), and that information is not used for any purpose other than payment processing, refunds and customer identification.
- Additional protection of exchange credentials: in addition to encrypted storage of the exchange API keys registered by users, the Company does not recommend registering API keys with withdrawal permissions, checks the permission scope of registered keys, and monitors for abnormal access. Users may delete their API keys at any time from the settings menu.
- Protection of information stored on the client: authentication tokens used to keep the user logged in are stored only in secure cookies (HttpOnly, Secure) that cannot be accessed by scripts, and are not stored in browser local storage (localStorage, etc.). Tokens are protected by short expiry policies and tamper verification, and users may invalidate them immediately by logging out or withdrawing. Please be sure to log out when using a shared PC.
Article 10 (Installation, Operation and Refusal of Automatic Collection Devices (Cookies))
The Company uses 'cookies' and similar technologies (local storage, session storage, etc.) that store and retrieve usage information in order to provide individualized services and convenience to data subjects.
A cookie is a small piece of information sent by the server (http) used to operate the website to the data subject's browser; it is stored on the data subject's computer or mobile device and automatically sent from the browser to the server when the website is accessed.
Purposes of cookies:
- Keeping the user logged in and authenticating the user (session management)
- Improving the Service by analyzing users' access frequency, usage time and usage patterns
- Saving user preferences (theme, language, etc.) and providing personalized services
- Service usage statistics and security
Installation, operation and refusal of cookies: data subjects may allow or block cookies through their web browser settings. However, refusing cookies may cause difficulties in using the Service (some features such as automatic login may be restricted).
▶ How to block cookies in a web browser
- Chrome: select '⁝' at the top right of the browser > Settings > Privacy and security > Cookies and other site data
- Edge: select '…' at the top right of the browser > Settings > Cookies and site permissions > Manage and delete cookies and site data
- Safari: Safari menu > Preferences > Privacy > Manage Website Data
▶ How to block cookies in a mobile browser
- Chrome: select '⁝' at the top right of the mobile browser > Settings > Site settings > Cookies
- Safari: device Settings > Apps > Safari > Advanced > Block All Cookies
- Samsung Internet: select the 'Tabs' icon at the bottom of the mobile browser > Turn on Secret mode > Start
Article 11 (Collection, Use and Refusal of Behavioral Information)
To provide data subjects with optimized services and benefits in the course of using the Service, the Company processes behavioral information as follows using analytics and advertising tools such as PostHog, Google Tag Manager (Google Analytics) and the Meta pixel.
Collection and use of behavioral information
| Items collected | Collection method | Purpose | Retention and use period |
|---|---|---|---|
| Web and app visit and usage history, event information such as clicks, page views and dwell time, device/browser information, IP address (pseudonymized or anonymized), advertising identifier cookies (_fbp/_fbc) | Collected automatically when the user uses the Service | Service usage statistics, service quality improvement, user experience improvement, advertising performance (conversion) measurement | Google Analytics: 26 months from collection / PostHog: until termination of the outsourcing agreement or withdrawal / Meta: retained in accordance with the processor's policy, then destroyed |
The Company does not collect sensitive behavioral information that could infringe individual rights, interests or privacy, such as ideology, beliefs, political opinions, trade union membership, or health or sex-life information.
The Company does not provide behavior-based personalized advertising to children under 14 and does not collect children's behavioral information for the purpose of personalized advertising.
How to refuse the collection of behavioral information: data subjects may refuse the collection of behavioral information by changing their web browser's cookie settings or by the following methods.
- Install the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
- Opt out of personalized ads in Meta ad settings: https://www.facebook.com/adpreferences
- Change your web browser's cookie settings or use private mode (see Article 10)
- Block the smartphone advertising identifier (Android: Settings > Privacy > Ads > Reset or delete advertising ID / iPhone: Settings > Privacy & Security > Tracking > turn off Allow Apps to Request to Track)
Data subjects may contact the Personal Information Protection Officer (justin@tradex.so) with questions about behavioral information, to exercise their right to refuse, or to report harm.
Article 12 (Automated Decisions)
In accordance with Article 37-2 of the Personal Information Protection Act, the Company provides the following information on automated decisions.
The fact that automated decisions are made, their purpose, and the scope of data subjects concerned
The Company processes personal information through systems applying artificial intelligence (AI) technology to automatically provide users with market analysis results, trading-principle recommendations, chart analysis, and strategy/risk analysis results. However, all analysis results and recommendations provided by the Company are supplementary materials for informational purposes, and the Company does not automatically make decisions that have a direct legal effect on users' rights or obligations (such as refusing to conclude a contract or revoking eligibility). Final decisions on trading, investment and the like, and the responsibility for them, rest entirely with the user.
Main types of personal information used in automated decisions and their relationship to the decisions
- Prompts entered by the user (text, voice, images, attachments)
- Trading history, balance and position information collected via exchange integration
- Trading principles and trading journals registered by the user
- Service usage records and analysis history
The above information is used as input for the AI model to understand the user's trading patterns and the context of the request and to generate corresponding analysis results.
Considerations in the automated decision process and the procedure by which main personal information is processed
The AI analysis system processes the information provided by the user as input and generates an answer (output). To minimize risks such as inaccurate information, bias and hallucination, the Company performs regular model reviews and output verification, and provides a procedure for reporting and objecting to inappropriate answers within the Service (chat response reporting feature) and through customer support (justin@tradex.so). However, due to the nature of AI, the accuracy, completeness and timeliness of outputs are not guaranteed, and users should use AI analysis results as reference material only.
Whether sensitive information or personal information of children under 14 is processed
The Company does not process sensitive information or the personal information of children under 14 in the automated decision process.
Data subjects' rights regarding automated decisions and how to exercise them
Where an automated decision by the Company materially affects a data subject's rights or obligations, the data subject may refuse it or request an explanation or review of the automated decision (however, where refusal is not recognized by law, only an explanation or review may be requested). The procedure for exercising these rights is as follows.
- Method: submit a request to refuse, or for an explanation or review of, an automated decision to the Personal Information Protection Officer (justin@tradex.so)
- Procedure: receipt of request → review of the request → reply with the outcome (within 30 days where measures are taken; within 10 days where grounds for refusal apply; notice of extension where unavoidable)
Opting out of AI training data use
In accordance with Article 8 of this Policy, the Company currently does not use users' prompts and outputs to train its own AI models. When such training use begins in the future, the Company will guarantee data subjects' right to opt out through the following procedure.
- Turn training data use ON/OFF directly in the in-Service settings menu (Settings > Account > AI training data use)
- After opting out, future inputs are not used for AI training, and with respect to training use of previous inputs, users may request deletion of their information from the training data.
- Inquiries about the opt-out procedure: justin@tradex.so
※ A request to refuse or for an explanation of an automated decision may be denied where there are justifiable grounds, such as a risk of unfairly infringing the life, body, property or other interests of another person.
Article 13 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
Data subjects (including legal representatives) may exercise the following personal-information-protection rights against the Company at any time.
- Request access to personal information
- Request correction where there are errors
- Request deletion
- Request suspension of processing
- Request withdrawal of consent
- Request transmission of personal information (where applicable)
- Request refusal of, or an explanation of, automated decisions (see Article 12)
These rights may be exercised against the Company in writing, by email, by fax or other means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
Data subjects may directly view, edit and delete their personal information or withdraw membership (withdraw consent) through the 'Settings > Account' menu in the Service, and may also request access through 'Customer Support / Contact us'.
Rights may also be exercised through an agent such as the data subject's legal representative or an authorized person. In that case, a power of attorney in the form of Attachment 11 of the Notice on the Methods of Processing Personal Information must be submitted.
Where a data subject requests correction or deletion of errors in personal information, the Company does not use or provide that personal information until the correction or deletion is completed.
The data subject's right to request access to and suspension of processing of personal information may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act, and deletion may not be requested for personal information specified as subject to collection under other laws.
When a data subject requests access, correction, deletion or suspension of processing, the Company verifies that the person exercising the right is the data subject or a legitimate agent.
Data subjects may exercise their rights through the department below, and the Company will respond within 10 days of receiving the request (without delay in the case of a transmission request).
Article 14 (Personal Information Protection Officer and Responsible Department)
The Company designates the following Personal Information Protection Officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.
Personal Information Protection Officer
- Name: Oh Jeong-gil (오정길)
- Position: Officer in charge
- Email: justin@tradex.so
Personal Information Protection Department / Department receiving and handling requests to exercise rights
- Department: Personal Information Protection Team
- Email: justin@tradex.so
- Address: 63, Buldang 36-gil, Seobuk-gu, Cheonan-si, Chungcheongnam-do, Republic of Korea, #304-26 (충청남도 천안시 서북구 불당36길 63, 304호-26)
Data subjects may direct all inquiries, complaints and requests for remedies related to personal information protection arising from use of the Service to the Personal Information Protection Officer and the responsible department. The Company will respond to and handle data subjects' inquiries without delay.
Article 15 (Remedies for Infringement of Data Subjects' Rights)
Data subjects seeking dispute resolution, consultation or other remedies for infringement of personal information may file a report or request consultation with the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
- Personal Information Infringement Report Center (KISA): 118 (no area code) / privacy.kisa.or.kr
- Supreme Prosecutors' Office Cyber Investigation Department: 1301 (no area code) / www.spo.go.kr
- National Police Agency Cyber Bureau: 182 (no area code) / ecrm.police.go.kr
A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Articles 35 (access to personal information), 36 (correction and deletion of personal information) or 37 (suspension of processing of personal information) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act (Central Administrative Appeals Commission: 110 (no area code), www.simpan.go.kr).
Article 16 (Changes to the Privacy Policy)
- This Privacy Policy applies from August 26, 2026.
- Where content is added, deleted or amended due to changes in laws, policies or security technology, the Company will give notice of the reasons for and content of the change through in-Service announcements at least 7 days before the amended Privacy Policy takes effect. However, matters that materially affect data subjects' rights, such as changes to the items of personal information collected or the purposes of use, will be announced 30 days before taking effect, with a before-and-after comparison provided separately, and the Company will obtain data subjects' consent again where necessary.
- Minor changes with a low likelihood of infringing data subjects' rights, such as a change of processor performing the same work, may be collected and announced periodically over a set period (up to 4 weeks).