Article 1 (Overview)
HUBB1E Inc. (the “Company”) operates the E.D.1.T.H service (the “Service”) in compliance with the Personal Information Protection Act of Korea (PIPA) and publishes this policy to protect users’ personal information.
This policy explains what personal information the Service processes and why, how long it is kept, whom it is entrusted to, and how users can exercise their rights.
Article 2 (Information Processed)
Only the minimum personal information necessary to provide the Service is processed:
- The Company does not continuously collect or inspect data inside instances, commands executed by customers, or build artifacts. Access is limited to the minimum scope required by law or incident response.
- Account information: email address, name (or company and contact name), country, password (hashed)
- Payment information: payment method identifier (card brand, last four digits), amount and time, billing address — full card numbers are handled by the payment gateway (PG) and never stored by the Company
- Usage records: instance creation/return times, allocated card specs, usage duration, credit top-ups and deductions
- Access records: source IP, timestamps, authentication outcomes (for security and abuse prevention)
Article 3 (Purposes)
- Service provision: account management, instance allocation and metering, credit management
- Payments and billing: charging, refunds, tax invoices and receipts, fraud prevention
- Security: intrusion detection, abuse prevention, records required by law
- Notices: changes to terms, maintenance, incident announcements
Article 4 (Retention and Destruction)
Personal information is destroyed without delay once the purpose is achieved, except where statutes require retention:
- Account information: destroyed immediately on account deletion; a minimal set of identifiers may be kept for 3 years to handle commercial disputes.
- E-commerce records: contracts, invoices, payments, and advertising records for 5 years under the Act on Consumer Protection in Electronic Commerce.
- Access records: 3 months under the Communications Secrets Protection Act.
- Instance storage: wiped beyond recovery when an instance is returned.
Article 5 (Third Parties and Trustees)
The Company does not provide personal information to third parties without consent, except for payment processing entrusted as follows:
- Payment gateway (Toss Payments and successors): card payment, settlement, and refund processing; only information necessary for payment is transmitted.
- Hosting and infrastructure (Cloudflare and successors): site delivery and security; access logs may be processed.
Article 6 (User Rights)
Users may request access, correction, deletion, or suspension of processing of their personal information. Requests to privacy@ed1th.dev are handled without delay and the result is notified.
Privacy officer: the representative director of HUBB1E Inc. Contact: privacy@ed1th.dev, +82-70-5227-4560.
Article 7 (Cross-border Transfer)
The Service runs on equipment located in the Republic of Korea. Global CDN delivery (Cloudflare) may process access logs outside Korea; safeguards under PIPA Article 39-12 apply.