Privacy Policy
Updated: July 29, 2026
1. Who are we?
We, UVIFY Co., Ltd. ("UVIFY"), are a company incorporated in the Republic of Korea with its registered office at 5th Floor, 1933, Nambusunhwan-ro, Gwanak-gu, Seoul. We operate this website to introduce our drone show software and to receive and respond to inquiries from prospective and existing customers. For these purposes, we have to process your personal data. This Privacy Policy (hereinafter – the "Policy") explains how we process (collect, store, disclose) your personal data. Where we process personal data of individuals who are in the European Union or the European Economic Area, we do so in accordance with Regulation (EU) 2016/679 (the "GDPR"), which applies to such processing pursuant to Article 3(2) of the GDPR.
In addition, as a company incorporated in the Republic of Korea, we comply with the Personal Information Protection Act of Korea (the "PIPA") and other applicable Korean laws, and this Policy also serves as our privacy policy under Article 30 of the PIPA.
2. Why do we process your data?
We process your personal data in compliance with the General Data Protection Regulation (GDPR) in order to ensure lawfulness, fairness, and transparency of processing. We process your personal data for the following main purposes and on the following legal bases: (i) we receive, handle and respond to inquiries submitted through this website on the basis of our legitimate interests in responding to inquiries addressed to us or, where your inquiry relates to a prospective contract, in order to take steps at your request prior to entering into a contract; (ii) we process your personal data as necessary to perform a contract in order to provide a product or service to you; (iii) we process your personal data as necessary to comply with legal obligations to which we are subject, such as bookkeeping and tax requirements; and (iv) where we ask for your consent for a specific purpose (for example, optional cookies), we process your personal data on the basis of that consent, which you may withdraw at any time.
3. What categories of data are processed and what are purposes of a processing?
We process the following categories of personal data:
- Your first name (name);
- Your last name (surname);
- Your country of residence;
- Your phone number;
- Your email address;
- Your company name (where you provide it);
- The content and history of your inquiry.
We have to process your name and surname in order to identify you.
We need to process your country of residence to make sure our services are not limited or restricted in your country. We will inform you if any limitation is in place.
Our websites ("Websites", "Website") are integrated with Google Analytics service for web analytics. These services process the information collected from cookies and IP address. Where required by applicable law, cookies and similar technologies that are not strictly necessary are used only with your consent, which you may withdraw at any time. You may also refuse or delete cookies through your web browser settings; in that case, your use of the Website may be partly limited.
Your data that we collect is not shared with any third parties not specified in this Privacy Policy. Your data is processed in accordance with the rule of law, fairness, and full transparency, as well as for the purpose specified in Clause 2 hereof.
4. Who can access your personal data?
Officials (police, tax officers, etc.) will be given access to your personal data only if so required by law. Our lawyers will examine any official request very closely beforehand. We will not disclose your personal data before we are 100% sure that officials have firm legal grounds to receive your personal data. In addition, we may share your personal data with service providers that process personal data on our behalf under Article 28 of the GDPR (such as IT hosting, e-mail and communication, customer relationship management and web analytics providers), with our professional advisers, and with our affiliates, in each case only to the extent necessary for the purposes described in this Policy.
In addition, in accordance with Article 26 of the PIPA, when entering into an outsourcing contract we set out in writing the matters necessary for the safe processing of personal data by the outsourcee and supervise the outsourcee. The personal data processing tasks currently outsourced and the outsourcees are as follows, and any change to the outsourced tasks or the outsourcees will be disclosed through this Policy without delay.
| Outsourcee | Outsourced tasks |
|---|---|
| Webflow, Inc. | Operation of the website hosting and content management platform |
| Microsoft Corporation | Operation of e-mail and communication systems |
| HubSpot, Inc. | Receipt and management of customer inquiries; operation of customer relationship management (CRM) systems |
| Google LLC | Web log analytics (Google Analytics) |
| Atlassian Corporation | Operation of the customer support ticketing system |
5. How long your personal data will be stored?
We will keep your personal data until you stop using our Product or Service or revoke your consent. Please keep in mind that the storage term depends on the Product or Service of your choice. To know exactly for how long we are going to keep your personal data, based on Products and Services of your choice, feel free to ask any question you may have via email. In particular, personal data submitted through inquiry channels on this website will be kept as follows: (i) where no contract is concluded with you, for two years from the date of the last communication concerning your inquiry (whether sent by you or by us, whichever is later); and (ii) where a contract is concluded with you, for the duration of the contract and for three years after its termination, in each case unless a longer retention period is required by applicable law (for example, bookkeeping or tax requirements) or is necessary for the establishment, exercise or defence of legal claims.
However, we will not keep your personal data longer than required by law or the purpose specified in Clause 2 of this Policy.
In addition, under Article 21 of the PIPA, personal data whose retention period has expired or whose purpose of processing has been achieved will be destroyed without delay in a manner that prevents its recovery or restoration (printed materials will be shredded or incinerated), and information that must be preserved under other laws {for example, books and supporting records of transactions required to be kept for five years under Korean tax laws} will be stored separately and destroyed once the required period expires.
6. What are your rights in regards to your personal data?
The GDPR stands tall since May 25, 2018 and, starting from this date, you have rights in regards to your personal data:
You have the right to access. You can request from us whether or not your personal data are being processed by us. You can ask for detailed information, which categories (such as name, surname, email address etc.) of your personal data are processed, who can access your personal data, for how long we are going to store your personal data. You can request us to provide a copy of your personal data.
You have the right to rectification. In case you have seen a mistake in your personal data (for instance, your name is misspelled in our email), you can request for a correction of inaccurate personal data.
You have the right to erasure of your personal data. You can request erasure of your personal data, when you withdraw your consent to the processing or when you stop using our Products or Services. However, please keep in mind that we cannot erase data required to be kept by law.
You have the right to restrict processing of your personal data. You can restrict to process your personal data when you think we process your personal data without any ground.
You have the right to object. Where we process your personal data on the basis of our legitimate interests, you have the right to object at any time, on grounds relating to your particular situation, to such processing. Where personal data are processed for direct marketing purposes, you have the right to object at any time to such processing, in which case we will no longer process your personal data for such purposes.
You have the right to withdraw your consent for the processing of your personal data at any time. However, please keep in mind that such withdrawal will not retrospectively affect the lawfulness of processing conducted before.
You have the right to portability. You have the right to receive your personal data from us in a structured form in order to transfer these data to another company. If technically possible, you can request us to transfer your personal data directly to another company.
You have the right to complain. In case, you think we are violating your rights, you can complain to a supervisory authority, in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.
Where the PIPA applies, you may also exercise the corresponding rights under Articles 35 through 37 of the PIPA — access, correction and deletion, suspension of processing, and withdrawal of consent — in writing, by telephone or by e-mail, or through an agent, in accordance with Article 41(1) of the Enforcement Decree of the PIPA, and we will act on your request without delay. Requests for access or for suspension of processing may be restricted under Articles 35(4) and 37(2) of the PIPA.
7. What will we do when you are performing your rights regarding rectification or erasure of personal data, as well as restrict processing of your personal data?
When you are requesting to perform the access, editing or erasure of your personal data, we will comply with your request and we will perform the requested action, except where we are permitted or required to refuse or restrict your request under applicable law (including Articles 35(4), 36(1) and 37(2) of the PIPA). If you ask for editing, erasure or restrict to process your personal data, we will notify of your request any third party to which we provided your personal data. We will respond to your request without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension and the reasons for it. Any such notification to third-party recipients will be made unless it proves impossible or involves disproportionate effort. Where the PIPA applies, we will provide access to your personal data or take necessary measures such as correction, deletion or suspension of processing (or notify you of the grounds for any refusal or restriction and how you may appeal) within 10 days of receipt of your request, in accordance with Articles 41 through 44 of the Enforcement Decree of the PIPA.
8. What if you don’t want to provide personal data to us?
In case the processing of personal data (such as name, surname, and email) is required for concluding a contract and you are not willing to share these personal data with us, we won't be able to identify you as a contracting party and thus comply with the accounting and anti-money laundering legislation. Therefore, we won't be able to sign a contract with you and provide you a Service or Product. If you choose not to provide the personal data requested in our inquiry forms, we may not be able to handle or respond to your inquiry.
We strive to protect the integrity of your personal data, apply standard information security procedures, and ensure observance of your rights to and lawful interests in data we provide to our partners.
9. Do we transfer your personal data to third countries?
Yes, we transfer your data to third countries (outside of the European Union). As we are located in the Republic of Korea, personal data collected through this website will be processed in the Republic of Korea, and your personal data may also be transferred to service providers located in other third countries. The European Commission has decided that the Republic of Korea ensures an adequate level of protection for personal data transferred from the European Union (adequacy decision under Article 45(3) of the GDPR, Commission Implementing Decision (EU) 2022/254). Where we transfer your personal data to recipients in third countries that are not covered by an adequacy decision, we rely on appropriate safeguards under Article 46 of the GDPR, in particular the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) or, in the case of recipients in the United States certified under the EU-U.S. Data Privacy Framework, the adequacy decision for that framework (Commission Implementing Decision (EU) 2023/1795). You may obtain a copy of the relevant safeguards by contacting us using the contact details set out in Clause 14 below. Statements by certain of our partners on their compliance with the GDPR are available here:
For purposes of the PIPA, we transfer personal data abroad in the form of overseas outsourcing or storage as set out in the table below. You may refuse the cross-border transfer of your personal data by raising an objection with our privacy officer (see Clause 14); provided that, in such case, your use of the services requiring such transfer may be limited.
| Legal basis | Recipient (contact) | Country | Items transferred | Time and method of transfer | Purpose of use | Retention period |
|---|---|---|---|---|---|---|
| Article 28-8(1)3 of the PIPA | Google LLC (https://support.google.com/policies/answer/9581826) | United States | Service usage records | Transmitted over networks at the time of service use | Web log analytics | Until termination of the outsourcing contract |
| Article 28-8(1)3 of the PIPA | Webflow, Inc. (privacy@webflow.com) | United States | Personal data submitted through the Website (name, contact details, company name and contents of inquiry) | Transmitted over networks at the time of submission through the Website | Operation of the website hosting and content management platform | Until termination of the outsourcing contract |
| Article 28-8(1)3 of the PIPA | HubSpot, Inc. (https://preferences.hubspot.com/) | United States | Personal data submitted through the Website (name, contact details, company name and contents of inquiry) | Transmitted over networks at the time of service use | Receipt and management of customer inquiries; operation of CRM systems | Until termination of the outsourcing contract |
| Article 28-8(1)3 of the PIPA | Microsoft Corporation (https://www.microsoft.com/ko-kr/privacy/privacy-support-requests) | United States | E-mail address and contents of e-mail correspondence | Transmitted over networks at the time of service use | Operation of e-mail and communication systems | Until termination of the outsourcing contract |
| Article 28-8(1)3 of the PIPA | Atlassian Corporation (privacy@atlassian.com) | Australia | Contact details and contents of customer support inquiries | Transmitted over networks at the time of service use | Operation of the customer support ticketing system | Until termination of the outsourcing contract |
10. At what age you can use our Products and Services?
If you are in the European Union or the European Economic Area, you may use our Products and Services if you reached the age of 16 (or such other age of digital consent as applies under the law of your EU Member State, which may not be below 13). You have to testify you are eligible to use our Products and Services, by expressing your consent with this Privacy Policy.
We do not knowingly collect or store personal data of minors and children under the applicable age of digital consent (or, in the case of children residing in the Republic of Korea, under the age of 14) without the consent required under applicable law. If you are a parent or a legal guardian of children or minors and you are aware that your ward has provided us with Personal Data, please contact us immediately via email: inhan.yeo@uvify.com. If we become aware that Personal Data from a person under the applicable age of digital consent are in our possession without verification of parental consent, we will take immediate steps to erase the data from our servers. If you reside in the Republic of Korea, the age limit of 16 above does not apply to you, and you may use our Products and Services if you are 14 years of age or older. Where consent required under the PIPA is needed to process the personal data of a child under the age of 14, we will obtain the consent of the child’s legal representative and verify that such consent has been given, as required under Article 22-2 of the PIPA. In any notice regarding the processing of personal data addressed to a child under the age of 14, we will use clear and plain language that is easy to understand (Article 22-2(3) of the PIPA).
11. What will we do in case of a data breach?
In the case of a personal data breach, we will notify the competent supervisory authority of the breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. We will notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms.
Where the PIPA applies, however, we will notify you of the breach within 72 hours of becoming aware of the loss, theft or leakage, regardless of the level of risk (unless urgent measures such as blocking access paths are required to prevent further leakage or damage, or other justifiable grounds under Article 39 of the Enforcement Decree of the PIPA exist, in which case we will notify you without delay after such grounds cease to exist) and, where required under the PIPA, report the breach to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) within 72 hours (as required where the breach concerns 1,000 or more data subjects, involves sensitive information or unique identification information, or results from unlawful external access; Article 40 of the Enforcement Decree of the PIPA), in accordance with Article 34 of the PIPA.
12. How can you protect your rights?
If a dispute arises, we will do our best to settle it by negotiations. We are always ready to hear from you and look for the best solution for all of us. In any case, you may complain to a competent supervisory authority (in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement) or seek the help of a court to protect your rights.
In case of a personal data breach, we shall notify you so that you can get a full understanding of the problem and the measures taken to solve it.If a personal data breach puts the rights and freedoms of our users at risk, we shall also notify the state authorities responsible for supervision of GDPR within 72 hours. Our notification will include the following information:
(a) description of the nature of the personal data breach, including, if possible, the category and approximate number of data subjects, category and approximate number of personal data records
(b) surname and contact details of the personal data protection inspector or other coordination center to receive more detailed information from
(c) description of the possible consequences of a personal data breach
(d) description of the measures taken or planned by the controller to cure the breach, including, where appropriate, measures to mitigate a possible negative impact
13. References to other internet-resources
Our Services may contain links to other websites not administered or operated by us. If you proceed with a third party link, you will be directed to a third-party website. We strongly advise you to review a Privacy Policy of every website you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party websites or services.
14. Legal and Contact Information
Company Name: UVIFY Co., Ltd., registration number 110111-5367952 (business registration number: 119-86-85613), official (legal) address: 5th Floor, 1933, Nambusunhwan-ro, Gwanak-gu, Seoul, Republic of Korea. Contact details: Inhan Yeo, Director of Operations (name and title), +82-70-4257-1240 (telephone), inhan.yeo@uvify.com (e-mail).
In addition, in accordance with Article 31 of the PIPA, we have designated a privacy officer who is responsible for the overall management of personal data processing and for handling complaints and remedying damages of data subjects in relation to the processing of personal data. Privacy Officer: Inhan Yeo, Director of Operations, Telephone: +82-70-4257-1240, E-mail: inhan.yeo@uvify.com.
15. How do we protect the security of your personal data?
In accordance with Article 29 of the PIPA and its Enforcement Decree, we implement the technical, administrative and physical measures necessary to secure the safety of personal data, including establishing and implementing an internal management plan, managing and controlling access rights to personal data, encrypting personal data, installing and updating security programs, and controlling physical access to storage locations.
16. How will we notify you of changes to this Policy?
If we amend this Policy, we will announce the changes through this website at least seven days before the amended Policy takes effect. In such case, we will continuously disclose the amended content together with the date and the effective date of the amendment and, where the PIPA applies, we will also publish a comparison of the Policy before and after the amendment so that you can easily identify the changes. This Policy applies from July 29, 2026.
