Sarazim Company (CEO Taewoon Choi; the “Company”) treats users’ personal information and case information as seriously as life itself. This policy explains the scope and principles under which the Company collects, uses, stores and destroys personal information through its website (sarazim.io), consultation channels and case handling. The Company complies with Korea’s Personal Information Protection Act and Information and Communications Network Act, and puts the protection of its clients first.
Personal information we collect
The Company collects only the minimum information necessary to provide its services. Given the nature of the cases, clients’ sensitive information may be included, and all information is stored encrypted.
1.1 Information collected at the consultation and request stage
- Contact information · name (a pseudonym is acceptable), phone number or email, preferred contact channel
- Case information · type of harm, URLs where content was spread, when it was spread, evidence voluntarily provided by the client
- Contract information · contract, signature, business details (for corporate clients)
- Payment information · payment method and receipt-related information (processed by a payment service provider; the Company does not store card numbers)
1.2 Information generated while handling a case
- Forensic evidence · hash values (SHA-256) of original files, timestamps, metadata analysis results
- Notice records · legal notices sent to each platform, responses, proof of removal
- Monitoring logs · URLs detected during re-upload monitoring and their status history
1.3 Information collected automatically when you visit the website
- IP address, browser type and version, operating system, pages visited, time on page, referring path
- Cookies (only to maintain sessions; no third-party advertising cookies are used)
Purposes of use
Personal information collected is used only for the following purposes; any other use is strictly prohibited except where required by law.
- Consultation and quotes — understanding the type and scope of harm, assessing feasibility, explaining costs
- Case handling — platform notices, building legal evidence, forensic analysis, removal verification
- Re-upload monitoring — tracking designated URLs and related search terms during the contract period
- Contract performance and billing — drafting contracts, processing payments, issuing tax invoices
- Legal compliance — responding to requests from investigative authorities, internal audits, legal disputes
- Service quality improvement — anonymised statistical analysis of case outcomes
The Company does not use users’ personal information for advertising or marketing purposes, nor as machine-learning training data. It does not sell or rent personal information to third parties.
Retention and destruction
The Company retains each type of information only for the minimum period needed to achieve its purpose and destroys it immediately once that period has passed.
On destruction, electronic files are permanently deleted in a way that cannot be recovered (DoD 5220.22-M or an equivalent standard), and paper documents are shredded and then incinerated.
Provision to third parties and outsourcing
As a rule, the Company does not provide clients’ personal information to third parties. However, given the nature of the service, the minimum necessary information may be shared only in the following cases.
4.1 Sharing that is unavoidable for case handling
- Platform operators · the URLs and the copyright/privacy grounds needed to send removal notices. The client’s real name and contact details are not shared.
- External legal counsel · where a partner attorney takes part in reviewing a case, information is provided under an NDA with the client’s prior consent.
- Investigative authorities · where a case leads to a criminal complaint, evidence is provided at the client’s request.
4.2 Outsourced processing
Security measures
The Company implements technical and administrative security measures to protect client information.
5.1 Technical measures
- Encryption at rest · AES-256-based storage · each client’s files encrypted with an individual key
- Encryption in transit · TLS 1.3 · PGP available for email when needed
- Access control · multi-factor authentication (MFA) required · role-based permissions
- Audit logs · every file access, view and change recorded · automatic alerts for abnormal access
- Isolated work environment · sensitive files opened only in an environment separated from external networks
5.2 Administrative measures
- NDAs signed by all staff · confidentiality obligations continue after employment ends
- Regular privacy training and internal audits
- Least-privilege access by role · only the assigned case manager can view a case
- Breach protocol: report to the authorities and notify clients within 72 hours of a data breach
Despite these measures, no transmission or storage of electronic information can be guaranteed to be 100% secure. The Company exercises reasonable care and, if an incident occurs, responds transparently in accordance with the law.
Your rights
Clients may exercise the following rights over their personal information.
- Access · confirm what types of your information the Company holds and how they are used
- Correction and deletion · correct or delete inaccurate or unnecessary information
- Suspension of processing · immediate destruction of information the Company has no legal obligation to retain
- Withdrawal of consent · withdraw optional consents, such as for marketing or publishing reviews
- Data portability · request your information in electronic form
You may exercise these rights by email (hello@sarazim.com) or in writing, and we will act within 10 business days. If deleting information during a case would make the work impossible, we will explain why and agree on a solution with you.
Cookies and tracking technologies
The Company uses cookies only to maintain sessions and improve the service.
- Essential cookies · login sessions, temporary saving of consultation requests — the service cannot be used if refused
- Analytics cookies · anonymous statistics such as visit paths and time on page — can be refused in your browser settings
The Company does not take part in third-party ad networks, retargeting or cross-site tracking. External analytics tools such as Google Analytics are used only with IP anonymisation enabled.
Changes to this policy
This policy may be revised to reflect changes in law, the service or security policies. Material changes are announced at least 7 days before they take effect on the website and by individual email to existing clients.
If a client does not agree to the changes, they may stop using the service and request destruction of their information. Continued use is deemed acceptance of the changes.
Previous versions of this policy are available on request.