This document reflects the current Service and applicable laws of the Republic of Korea.
1. Scope
B2BB2G processes personal data lawfully and securely under the Korean Personal Information Protection Act and other applicable laws. This Policy describes collection, use, retention, disclosure, processing, deletion and data-subject rights.
2. Data We Process
| Context | Data | Collection method |
|---|---|---|
| Registration | Email, authentication data, registration path, invitation and referral data, agreement to the required terms | Entered by the member or generated during verification |
| Profile | UID, company, contact person, introduction, photo and contact details | Entered in profile and contact settings |
| Service use | Content, media, files, video links, inquiries, replies, comments, badge applications and evidence | Submitted while using features |
| Marketing (optional) | Marketing-consent state and the consent / withdrawal timestamp | Chosen at sign-up or in notification settings |
| Push (optional) | Browser push subscription (endpoint and keys), device and language | Generated when the member enables push notifications |
| Security | IP or masked IP, timestamps, browser and device information, login and security events, two-factor / app-lock settings, cookies | Generated automatically during use |
| Paid services | Application, payment confirmation and processing records | Submitted by the member or generated operationally |
3. Purposes
- Identity, email verification, invitation registration, login and account security
- Profiles, listings, projects, sourcing requests, events and network feeds
- Inquiry delivery, message review, notifications and member support
- Sending marketing messages (offers and news) by email / SMS to members who opted in (never sent to members who did not opt in)
- Badge and membership verification, abuse prevention and policy enforcement
- Reliability, access analysis, incident response and legal compliance
- Complaints, disputes, rights requests and infringement response
4. Retention
Data is deleted without undue delay when its purpose is complete, unless retention is required by law or reasonably necessary for disputes and fraud prevention.
| Data or record | Retention period |
|---|---|
| Account, profile and contacts | Until withdrawal; minimum authentication and dispute records may be restricted for up to 3 years |
| Content, inquiries and messages | During service; author identifiers are removed after withdrawal and records may remain for continuity and disputes |
| Invitation and referral records | Up to 3 years after expiry, revocation or use for abuse and dispute response |
| Marketing-consent records | Until consent is withdrawn or the account closes; kept for the minimum period needed to evidence delivery and handle disputes |
| Badge and membership evidence | During verification and up to 3 years after the relationship ends, unless law requires longer |
| Login and security events | Configured operating period, currently 90 days by default; incident records until investigation closes |
| Advertising records | 6 months where Korean e-commerce retention rules apply |
| Contract, cancellation, payment and supply records | 5 years where Korean e-commerce retention rules apply |
| Complaint and dispute records | 3 years where Korean e-commerce retention rules apply |
5. Third-Party Disclosure
B2BB2G does not ordinarily disclose personal data to third parties. Disclosure may occur with prior consent, where required by law, or to protect urgent life, safety or property interests as permitted by law.
If a member joined through a referring coordinator, that coordinator may access registered contact details or inquiry status within configured permissions for member support. The member may request that Operations stop such access.
6. Processors
| Processor | Processing service |
|---|---|
| Supabase, Inc. | Database, authentication, storage and infrastructure |
| Resend, Inc. | Authentication and transactional email delivery |
| Intuition Machines, Inc. (hCaptcha) | Automated abuse and bot detection |
7. International Processing
Transfers occur over encrypted networks when the relevant service is used. Refusing optional processing does not affect essential features, but refusing authentication email or security verification may prevent registration, login or certain functions.
| Recipient and location | Data and purpose | Period |
|---|---|---|
| Supabase, Inc. / selected project region (Republic of Korea) | Account, profile, content, inquiries and files for hosting and authentication | Until service termination or deletion |
| Resend, Inc. / United States | Email address, notification content and delivery metadata | For delivery, error handling and the provider's applicable log period |
| Intuition Machines, Inc. / United States and distributed infrastructure | IP, browser and device signals and challenge result for security | For real-time verification and necessary security processing |
8. Deletion
- Expired data is separated from legally retained data and deleted without undue delay.
- Electronic files are deleted using methods designed to prevent practical recovery, and paper documents are shredded or destroyed.
- Public profile and contact data are de-identified on withdrawal; legally retained records are restricted and later deleted.
9. Your Rights
You may request access, correction, deletion, restriction, withdrawal of consent or account closure through profile and security settings or the in-service inquiry channel.
You can withdraw marketing consent at any time. Turning off the 'Marketing messages' setting on the Notifications screen (/notifications) takes effect immediately and stops further marketing messages; you can also opt in there even if you did not agree at sign-up. Service messages needed for authentication, security and transactions are sent regardless of marketing consent.
B2BB2G may verify authority for representative requests. A request may be limited where necessary to protect another person's rights or comply with law, and the reason will be explained.
10. Children
B2BB2G is a business service and does not permit registration by children under 14. If such data is identified, appropriate steps will be taken under applicable law.
11. Security Measures
- Role-based and least-privilege access, multi-factor authentication for administrators and access logging
- Encrypted transport, secure authentication handling and restricted access to sensitive data
- Security-event and suspicious-login detection, vulnerability checks, backup and incident response
- Privacy obligations for staff and processors
13. Privacy Contact
Privacy requests and complaints may be submitted to B2BB2G Operations through the in-service inquiry channel. Requests are handled after identity verification in accordance with applicable law.
14. Korean Privacy Remedies
- KISA Privacy Infringement Center: 118 (privacy.kisa.or.kr)
- Personal Information Dispute Mediation Committee: 1833-6972 (kopico.go.kr)
- Supreme Prosecutors' Office: 1301 (spo.go.kr)
- Korean National Police Cyber Bureau: 182 (ecrm.police.go.kr)
15. Changes to This Policy
Changes will be announced with their effective date and reason. Material changes affecting data-subject rights will generally be announced at least 30 days in advance and other changes at least 7 days in advance.