Privacy
Privacy notice
This notice explains how Reshenie Co., Ltd. processes personal information through its website, business checkout, administration, and privacy-request services.
Effective and last updated: 10 July 2026
At a glance
- Reshenie sells industrial and educational products to businesses, schools, institutions, and professional organizations.
- Order information is used to quote, sell, deliver, install, support, and account for products. Optional analytics and marketing are based on your choice.
- We do not sell personal information. Google Analytics does not load until analytics consent is granted.
- Privacy requests can be submitted online. An order is disclosed or changed only after a single-use verification link is confirmed through the email stored on that order.
1. Controller and contact
Controller: Reshenie Co., Ltd. (business registration number 149-86-02229), represented by Yongkwan Lee. Address: Room 601, Gwanggyo Flex Desian, 50 Changnyong-daero 256beon-gil, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea.
Personal information protection officer: Yongkwan Lee, Representative. Contact: info@reshenie.co.kr or +82 070-8285-2269.
Questions, complaints and rights requests may be submitted through the privacy request form or these contact details.
2. Processing purposes, information and retention
The table below describes the processing currently performed by this website and shop. Information retained only for law, tax, accounting, disputes or security is separated from ordinary sales and marketing use.
What we process and why
| Activity | Purpose | Personal information | Basis | Retention | Required or optional |
|---|---|---|---|---|---|
| Business checkout and order fulfillment | Create and verify orders; process payment; deliver, install and support products; handle returns, accounting and disputes. | Name, business email, phone if provided, organization, postal code, address, order lines and configuration, business-use acknowledgement, payment provider, transaction or receipt ID, payment and delivery status, timestamps. | Steps requested and performance of the business transaction; compliance with commerce, tax, accounting and dispute obligations. | Order records: 5 years from creation. Complaint and dispute material may be retained for 3 years or the longer period required for an unresolved legal claim. | Name, email, organization, postal code, address and business-use acknowledgement are required for checkout. The order cannot be completed without them. Phone and address detail are optional unless needed for delivery. |
| Authentication and administration | Authenticate member checkout and administrators; control access; investigate changes and security events. | Identity subject ID, email, name, username, role, session ID, IP address, user agent, referrer, request path, and relevant before/after change records. | Operation and security of the service; protection of Reshenie, customers and systems; applicable security and recordkeeping obligations. | Identity sessions follow authentication-system settings. Admin access logs: 1 year. Admin changes and export records: 3 years. | Automatically processed when protected member or administrator functions are used. |
| Optional marketing consent and withdrawal | Record whether email or SMS marketing is permitted and prevent messages after refusal or withdrawal. | Email or phone, channel, consent/refusal/withdrawal status, consent text, related order number where applicable, IP address, user agent and timestamp. | Optional consent; withdrawal and suppression records are retained to respect the opt-out. | 3 years from the consent event, unless longer evidence is needed for an unresolved complaint or legal obligation. | Optional. Refusal does not affect purchasing, delivery, installation or support. |
| Privacy rights requests | Receive, verify, respond to and document access, correction, deletion, suspension, withdrawal and objection requests. | Name, email, phone if provided, order number if relevant, request type and detail, verification and authority records, response and action history, IP address and user agent. Verification tokens are stored only as one-way hashes. | Compliance with privacy-law duties and establishment, exercise or defense of legal claims. | Request, event and delivery evidence: 3 years, after which personal fields are deleted or redacted under the retention process. | A valid email is required to submit the form. An order number is required when the request asks us to disclose or alter that order. Additional authority evidence may be required for a representative. |
| Security and incident response | Prevent, detect, contain, investigate and document security or personal-information incidents and required notices. | Relevant account, order and contact data; affected data categories; event facts; timestamps; IP and device metadata; response actions; recipients and reporting evidence where an incident occurs. | Security and breach-response duties; protection of rights, systems and legal claims. | Incident records and notification evidence: 5 years, with personal fields redacted when their retention period expires. | Collected only where necessary for security, investigation or legal response. |
| Optional Google Analytics 4 | Measure page use and shop interactions and improve site usability. | Page path, event name, product and category identifiers, cart/checkout event details, order number, amount, currency, and Google cookie or device identifiers. Checkout name, email, phone, organization and postal address are not sent. | Optional analytics consent. | The property is configured for 2-month event-data retention and 14-month user-data retention; Google may retain aggregated reports separately under its service controls. | Optional and denied by default. Refusal does not affect purchasing or core site functions. |
3. How information is collected
We collect information directly from checkout, consent, withdrawal and privacy-request forms; from authenticated identity sessions; from payment-status responses; and automatically from security logs or consented analytics. A business customer may provide its employee or representative's contact details for a transaction.
Please do not submit resident registration numbers, complete card numbers, passwords, health information, biometric information, political or religious views, union membership, or information about children under 14. Unnecessary sensitive information may be blocked, masked or deleted.
4. Processors, recipients and disclosures
We do not sell personal information or disclose it for another party's independent marketing. Data is provided to the current providers below only as needed for payment or consented analytics, or when consented to, legally required, or necessary to protect rights and safety.
Core application, database and identity services are operated by Reshenie and are not listed as external processors. Planned integrations are not treated as current processing and will be added before activation.
Current processors and service recipients
| Provider | Role | Purpose | Data | Location | Retention |
|---|---|---|---|---|---|
| Bootpay | Payment service provider | Payment window, transaction verification, settlement, fraud prevention and payment support. | Order number, amount, currency, customer name, email, phone if supplied, transaction or receipt ID, payment method and status. | Republic of Korea; the selected card network, acquirer or payment method may involve additional financial institutions. | According to statutory commerce, tax, settlement and dispute periods applicable to the payment service. |
| Google LLC | Consent-gated analytics processor/service provider | Google Analytics 4 measurement after analytics consent. | Page and event data, ecommerce fields, order number, amount, currency, cookie or device identifiers; no checkout contact or address fields. | United States and Google global infrastructure. | Configured retention described above, subject to Google Analytics service controls. |
International transfer
| Recipient | Country | Timing and method | Data | Purpose | Basis / refusal | Retention |
|---|---|---|---|---|---|---|
| Google LLC | United States and other locations where Google operates infrastructure | Encrypted network transfer when Google Analytics loads and events are sent after analytics consent. | Page and event information, ecommerce fields, order number, amount, currency and cookie/device identifiers. | Consent-based website and shop analytics. | Optional consent. You can refuse or withdraw through Privacy settings; refusal does not restrict purchasing. | 2-month event-data and 14-month user-data settings, subject to Google service controls. |
5. Cookies, local storage and analytics
Necessary browser storage remembers the cart, display currency, language and privacy choice. Authentication also uses session cookies. Blocking necessary storage may prevent those functions from working.
Google Analytics is denied by default and its script is not loaded until analytics consent is granted. You can reject optional processing or change the choice through the Privacy settings control in the footer. The site does not currently use Google advertising personalization or remarketing features.
6. Retention and destruction
When a retention period expires or processing is no longer necessary, personal fields are deleted or irreversibly redacted unless another law or unresolved claim requires continued restricted retention. Electronic data is deleted or overwritten so it cannot be restored through ordinary means; paper records, if any, are shredded or incinerated.
Korean ecommerce records are retained for the applicable statutory periods, including five years for contracts, withdrawal, payment and goods supply; three years for complaints and disputes; and six months for display or advertising records where such records exist.
7. Your rights and request verification
You may request access, correction, deletion, processing suspension, consent withdrawal or objection through /privacy/requests, email or phone. We may refuse or limit a request where retention is legally required, identity cannot be verified, another person's rights would be affected, or another lawful exception applies, and will explain the reason where required.
An order number or submitted email is only an unverified claim. For order data, we send a 30-minute, single-use link to the email already stored on that order. Only orders linked by successful verification can be exported, corrected or redacted. A representative must also provide sufficient authority evidence.
Complaints may also be directed to the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee (+82 1833-6972).
8. Security measures
We use role-based access restrictions, administrator authentication, session and payment verification, encrypted transport, protected secrets, database restrictions, audit logs, export records, retention cleanup and incident-response procedures. Access is limited to personnel who need it for sales, fulfillment, support, accounting, legal, security or incident response.
9. International business contacts
Reshenie is a Korean B2B seller and does not specifically direct this website to consumers in the EEA or United Kingdom. We may nevertheless respond to unsolicited enquiries or accept orders from businesses there. Business contact data remains personal information.
If EU or UK data-protection law applies to a particular processing activity, we will provide and honor the rights and safeguards required for that activity, including applicable access, correction, erasure, restriction, objection, complaint and transfer requirements.
10. Changes to this notice
This notice is effective from the date shown above. Material changes to purposes, data, recipients, international transfers or rights will be announced before or when they take effect as required by applicable law. Previous versions may be requested through the privacy contact.