Privacy Policy

v1.1 · Published on September 3, 2026 · Effective from September 10, 2026

1. General Provisions and Scope

Bonanza Lab Co., Ltd. (the "Company") complies with the Personal Information Protection Act ("PIPA") and other applicable laws and regulations of the Republic of Korea, and processes the personal information of data subjects lawfully and securely in the course of providing its services. In accordance with Article 30 of PIPA, the Company establishes and discloses this Privacy Policy (this "Policy") to inform data subjects of the procedures and standards for processing personal information and to handle related grievances promptly and smoothly.

This Policy applies commonly to the following websites and services operated by the Company. Matters that apply to a particular service only are identified by service name in the relevant section.

  • The Company website (bonanzalab.io, the "Website")
  • The Partner Portal (portal.dayfin.co, the "Portal")

2. Purposes of Processing, Items Processed, Retention Periods, and Legal Basis

In accordance with Articles 15 and 16 of PIPA, the Company processes only the minimum personal information necessary for the purposes of processing, and processes and retains personal information within the retention and use period prescribed by law or consented to by the data subject.

2.1 Receiving and Responding to Website Inquiries (Website)

Purposes of processing

  • Receiving and reviewing inquiries regarding data adoption, demo requests, partnerships, and similar matters
  • Responding to inquiries and conducting follow-up consultations

Items processed

  • Required: name, email address, inquiry details
  • Optional: company name, affiliation, position
  • Information generated automatically in the course of service use: date and time of submission, submission channel, language setting

Retention and use period

Destroyed without delay upon the lapse of three (3) years from the date of submission. However, where a consultation or dispute is in progress, the information is retained until the relevant procedure is concluded.

Legal basis

  • Required items: Article 15(1)4 of PIPA (taking measures at the request of the data subject in the course of entering into a contract)
  • Optional items: Article 15(1)1 of PIPA (consent of the data subject). An inquiry may be submitted without providing the optional items.

2.2 Receipt and Processing of License Applications (Portal)

Purposes of processing

  • Processing of license applications, including temporary saving, submission, review, acceptance/rejection of receipt, resubmission, examination, and final approval/rejection
  • Notification of application status (sending email notifications)

Items processed

  • Applicant (corporate representative) information: name, department/position, telephone number, email address
  • Authentication information: password (a six-digit numeric password set at the time of temporary saving; stored in encrypted form)
  • Information generated in the course of service use: receipt number, application date, application status

Retention and use period

  • Temporarily saved (unsubmitted) applications: deleted upon the lapse of 14 days from the date of first saving
  • Rejected applications (rejection of receipt / rejection of application): deleted upon the lapse of 30 days from the date of rejection
  • Applications approved and linked to contract creation: deleted within 7 days after contract creation is processed

Legal basis

Article 15(1)6 of PIPA (legitimate interests of the personal information controller). The Company has a legitimate interest in processing the business contact details of corporate representatives in order to enter into and perform license agreements with applicant companies. The Company limits the items processed to the minimum necessary for business communication and deletes them within the retention periods set out above, so that such information is processed only to the extent that the Company's legitimate interest manifestly takes precedence over the rights of the data subject.

2.3 Application Status Lookup and Identity Verification (Portal)

  • Purpose of processing: Lookup of application status and verification of the applicant using the business registration number, receipt number, and password
  • Items processed: business registration number, receipt number, password (stored in encrypted form)
  • Retention and use period: Same as the retention and use period set out in 2.2 above
  • Legal basis: Article 15(1)6 of PIPA (legitimate interests of the personal information controller)

2.4 Handling of Grievances, Inquiries, and Disputes (Common)

  • Purpose of processing: Responding to customer inquiries and grievances and handling disputes
  • Items processed: Information provided by the data subject in the course of the inquiry (name, contact details, email address, inquiry details, etc.)
  • Retention and use period: Three (3) years from the date on which the handling of the grievance is concluded (records concerning consumer complaints or dispute handling under Article 6 of the Enforcement Decree of the Framework Act on Consumers). Where a dispute is ongoing, until the relevant procedure is concluded
  • Legal basis: Article 15(1)2 of PIPA (compliance with statutory obligations) and Article 15(1)4 (taking measures at the request of the data subject)

3. Processing of Sensitive Information and Unique Identification Information

The Company does not collect or use sensitive information or unique identification information such as resident registration numbers. If such processing becomes necessary in the future on a statutory basis, it will be reflected in this Policy and disclosed.

4. Provision of Personal Information to Third Parties

The Company does not provide the personal information of data subjects to third parties.

Provided that the Company may exceptionally provide such information only where permitted under Articles 17 and 18 of PIPA (such as where the data subject has given separate consent, or where there are special provisions in applicable laws). In such cases, the Company gives the required notice and follows the lawful procedures prescribed by the relevant laws.

5. Entrustment of Personal Information Processing

The Company entrusts personal information processing tasks as follows in order to provide its services smoothly.

TrusteeScope of entrusted workApplicable serviceRetention and use period
Lovable Labs IncorporatedWebsite hosting and database operation and managementWebsiteUntil termination of the entrustment agreement or fulfillment of the processing purpose
Plus Five Five, Inc. (Resend)Sending inquiry notification emailsWebsiteUntil termination of the entrustment agreement or fulfillment of the processing purpose
Oracle Korea Ltd.Portal hosting and database infrastructure operation and management (Oracle Cloud Infrastructure, Korea region)PortalUntil termination of the entrustment agreement or fulfillment of the processing purpose

Lovable Labs Incorporated uses the services of SUPABASE PTE. LTD. (Singapore) as its database infrastructure (sub-entrustment). The Company does not transmit personal information directly to Supabase, and the current status of sub-entrustment is available at https://trust.lovable.dev/.

Personal information of the Portal (portal.dayfin.co) is stored in the Korea region of Oracle Cloud Infrastructure (OCI) and is not transferred overseas.

When entering into an entrustment agreement, the Company specifies in the agreement or other written document, in accordance with Article 26 of PIPA, matters such as the prohibition of processing personal information beyond the purpose of the entrusted work, technical and administrative safeguards, restrictions on sub-entrustment, supervision of the trustee, and liability including damages. The Company supervises whether the trustee processes personal information securely.

Any change in the scope of entrusted work or in the trustee will be disclosed without delay through this Policy.

6. Overseas Transfer of Personal Information

The Company transfers personal information overseas as set out below for the purpose of handling Website inquiries and sending notification emails. Such transfer constitutes a transfer for entrusted processing and storage under Article 28-8(1)3 of PIPA, and the relevant matters are disclosed in this Policy pursuant to Article 28-8(2) of PIPA.

ItemWebsite hosting and databaseNotification email delivery
TransfereeLovable Labs Incorporated (United States) Contact: privacy@lovable.dev Onward transfer: SUPABASE PTE. LTD. (Singapore) Contact: privacy@supabase.com * Lovable uses Supabase as its database infrastructure. The Company does not transmit information directly to Supabase, and the storage location remains the same United States (Oregon) region.Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, USA Contact: support@resend.com
Country of transferUnited States (AWS US West, Oregon region)Japan (Tokyo region) * The transferee is incorporated in the United States.
Time and method of transferTransmitted and stored via the information and communications network at the time an inquiry is submittedTransmitted via the information and communications network at the time an inquiry is submitted
Items transferredName, email address, inquiry details, company name/affiliation/position (where optionally provided), date and time of submission, submission channel, language setting, and access logs (IP address, date and time of access, browser and OS information)Name, email address, inquiry details, company name/affiliation/position (where optionally provided)
Purpose of use by the transfereeHosting and operation of the Website and databaseSending inquiry notification emails
Retention and use periodUntil termination of the entrustment agreement or fulfillment of the processing purposeUntil termination of the entrustment agreement or fulfillment of the processing purpose

The Portal (portal.dayfin.co) is operated in the Korea region of Oracle Cloud Infrastructure (OCI) and its notification emails are sent through domestic means. Accordingly, personal information collected in the course of using the Portal is not transferred overseas.

Rights of data subjects in relation to overseas transfer

A data subject may request suspension of the overseas transfer by contacting the Company at the details set out in Section 10 (Article 37 of PIPA). However, because the Website inquiry function is provided on the basis of the overseas services described above, a request for suspension may restrict the submission of inquiries through the Website. In such case, please contact the Company directly using the details in Section 10.

7. Rights and Obligations of Data Subjects and How to Exercise Them

Data subjects may at any time exercise their rights against the Company under Articles 35 through 37 of PIPA, including the rights to access, to correct or delete, to suspend processing, and to withdraw consent.

  • Such rights may be exercised by submitting a request to the Personal Information Protection Officer set out in Section 10 or to the responsible department set out in Section 11 in writing, by telephone, or by email. The Company takes action within ten (10) days from the date of receipt of the request.
  • Data subjects may also exercise their rights through a legal representative or a duly authorized agent. In such case, a power of attorney or other supporting document in the form prescribed in Attached Form No. 11 of the Enforcement Rules of PIPA must be submitted.
  • Requests for access and for suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA, and deletion may not be requested with respect to personal information that other laws specify as subject to collection.
  • The Company may verify whether the person requesting the exercise of rights is the data subject or a duly authorized agent.
  • Data subjects must not infringe upon the personal information or privacy of themselves or others processed by the Company in violation of PIPA or other applicable laws.

8. Destruction of Personal Information

Where personal information becomes unnecessary due to the lapse of the retention period, the fulfillment of the processing purpose, or similar reasons, the Company destroys such personal information without delay.

Where the retention period consented to by the data subject has elapsed or the processing purpose has been fulfilled, but personal information must continue to be preserved pursuant to other applicable laws, the Company transfers such personal information to a separate database or stores it in a different location, and does not use it for any purpose other than that prescribed by such laws.

Destruction procedure

The Company selects the personal information for which grounds for destruction have arisen and destroys it upon the approval of the Personal Information Protection Officer.

Destruction methods

  • Information in electronic file form: permanently deleted using technical methods that render recovery and reproduction impossible
  • Information recorded on paper documents: shredded or incinerated

9. Measures to Ensure the Security of Personal Information

In accordance with Article 29 of PIPA and the Standards for Measures to Ensure the Safety of Personal Information, the Company implements the following measures.

  • Administrative measures: establishment and implementation of an internal management plan, minimization and designation of personnel handling personal information, regular training, and supervision of trustees
  • Technical measures: management of access rights to the personal information processing system, access control, encrypted storage of authentication information such as passwords, limitation on the number of authentication attempts, retention of access records (for at least one year) and prevention of forgery or alteration, installation and updating of security programs, and encryption of transmission channels (TLS)
  • Physical measures: access control against unauthorized persons for server rooms and document storage rooms, and locking devices for document storage

10. Personal Information Protection Officer

The Company designates the following Personal Information Protection Officer to take overall responsibility for personal information processing and to handle complaints and provide remedies for damages in relation to personal information processing.

Personal Information Protection Officer

  • Name: Jinsook Choi
  • Position: Director
  • Telephone: +82-2-2632-7774
  • Email: contact@bonanza-lab.co.kr

Personal Information Protection Department

  • Department: Service Operations Team
  • Telephone: +82-2-2632-7774
  • Email: contact@bonanza-lab.co.kr

Data subjects may direct any inquiries, complaints, or requests for remedies relating to personal information protection that arise from their use of the Company's services to the Personal Information Protection Officer or the responsible department, and the Company will respond and take action without delay.

11. Department Receiving and Handling Requests for Access

Data subjects may file a request for access to their personal information under Article 35 of PIPA with the department below, and the Company endeavors to process such requests promptly.

  • Receiving and handling department: Service Operations Team
  • Telephone: +82-2-2632-7774
  • Email: contact@bonanza-lab.co.kr

12. Remedies for Infringement of Rights

In order to obtain relief from infringement of personal information, data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, and similar bodies. For other reports of, or consultations on, personal information infringement, please contact the organizations below.

  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
  • Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
  • Supreme Prosecutors' Office: 1301 (no area code) / www.spo.go.kr
  • Korean National Police Agency: 182 (no area code) / ecrm.cyber.go.kr

A person whose rights or interests have been infringed by a disposition or omission made by the head of a public institution in response to a request under Article 35 (access), Article 36 (correction or deletion), or Article 37 (suspension of processing) of PIPA may file an administrative appeal as prescribed by the Administrative Appeals Act (Central Administrative Appeals Commission, www.simpan.go.kr).

13. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

The Company does not install or operate automatic personal information collection devices such as cookies, or web analytics and marketing tools.

If the Company installs and operates such automatic collection devices for service operation purposes in the future, the purpose of installation and operation, the items collected, the retention period, and the method of refusal will be reflected in this Policy and disclosed.

Provided that the Company generates and stores minimal access logs to the extent necessary for service security and stable operation. In this process, the following information may be collected automatically.

  • Items collected: IP address, date and time of access, browser and operating system (OS) information
  • Purpose of use: service security (prevention of unauthorized use, incident response, and similar purposes) and stable operation
  • Retention period: one (1) year from the date of generation
  • Website access logs are stored in the hosting infrastructure (United States) described in Section 6.

14. Matters Concerning Automated Decisions

The Company does not make automated decisions under Article 37-2 of PIPA (decisions made by processing personal information through a fully automated system, including a system applying artificial intelligence technology). The review, examination, and approval or rejection of license applications on the Portal are carried out based on the judgment of the Company's personnel.

15. Amendment of this Privacy Policy

This Policy may be supplemented, deleted, or amended in accordance with changes in laws, policies, or security technologies. Any amendment, together with the reasons for and details of the change, will be announced through the notices sections of the Website and the Portal at least seven (7) days before the effective date (thirty (30) days in advance where the change materially affects the rights of data subjects).

Previous versions of this Privacy Policy are available from the "Previous versions" list at the top of this page.

Revision history

VersionPublishedEffectiveKey changes
v1.02026.03.092026.03.09Initial establishment (published on the Partner Portal)
v1.12026.09.032026.09.10Correction of the facts on overseas transfer (Resend, Japan); identification of the sub-processor and of the Portal infrastructure trustee; refinement of the legal bases; addition of provisions on automated decisions, the amendment procedure, and how to exercise rights; and clarification that the Policy applies to the Website

This Privacy Policy is provided in Korean and English. In the event of any discrepancy between the Korean and English versions, the Korean version shall prevail.