Privacy Policy
Privacy Policy
ChangSoft Global Co., Ltd.
Published: July 1, 2026 · Effective: July 1, 2026
ChangSoft Global Co., Ltd. (the "Company") complies with the Personal Information Protection Act and other applicable laws, and establishes and discloses the following Privacy Policy to protect users' personal information in connection with the use of the Company's installed software products such as BuilderHub-R and BuilderHub-C, along with the accompanying license authentication system and technical support services (the "Services").
Article 1 (Purposes of Processing Personal Information)
The Company processes the minimum necessary personal information for the following purposes. Processed personal information is not used for any purpose other than those below, and if the purpose changes, the Company will provide prior notice or obtain separate consent in accordance with applicable laws.
- Issuance, authentication, and activation management of installed software licenses
- Creation of Customer Portal accounts and provision of license usage status
- Sending license issuance and expiration notification emails
- User identification and technical support (inquiry response, error analysis, bug handling)
- License security management and prevention of unauthorized use
- Receiving website inquiries and customer response
- Maintenance, updates, and delivery of notices
- Fulfillment of legal and contractual obligations
Article 2 (Personal Information Items Processed)
The Company may process the following personal information to provide the Services.
1. Information provided directly by the user
a. Collected via the inquiry form (website)
- Name
- Company name
- Email address
- Contact (phone number)
- Inquiry type and content
b. Collected via the license application form
- Company name (Japanese/English)
- Contact person's name (Japanese/English)
- Department and position
- Contact
- Email address
- Company address
- Customer Portal login email (ID)
- Consent to email receipt (license issuance/expiration notices)
2. Automatically collected information
For software license authentication and security management, the Company may automatically collect and record the following information through the Cryptlex license authentication system.
- License authentication and activation history (success/failure, activation limit exceeded, re-authentication requests, and other event logs)
- License Key
- Hardware ID and Device Fingerprint
- Product ID
- Hostname
- Access IP address and approximate IP-based location
- Access date and time
- Operating system information
- Software version information
3. Information provided during technical support
The Company does not automatically collect or store work data such as BIM models, drawings, project files, or design data during the use of installed software. However, in the course of technical support or bug inquiry handling through the online service desk, the Company may temporarily receive related materials such as drawings and BIM models of the relevant project for the purpose of problem analysis and resolution, at the user's request or with explicit consent. In such cases, the Company observes the following principles.
- Provided materials are used solely for technical support and error analysis.
- Provided materials are not disclosed to third parties or used for other purposes without separate consent.
- Upon completion of problem resolution, such materials are deleted without delay or returned to the user.
Article 3 (Processing and Retention Period of Personal Information)
The Company retains and uses personal information according to the following criteria.
| Purpose | Retained items | Retention period | Basis |
|---|---|---|---|
| License application form information | Name, company name, department/position, contact, email, address, Customer Portal login email | 5 years after contract termination | Act on Consumer Protection in Electronic Commerce, etc. |
| Technical support, inquiries, error analysis, dispute response | Inquiry content, contact person information, technical support history | Up to 3 years after completion of processing | Dispute response and service quality improvement |
| License authentication and access records | IP address, authentication logs, access date/time | Automatically deleted within 60 days (based on Cryptlex server retention) | Protection of Communications Secrets Act |
| Inquiry form information | Name, company name, email, contact, inquiry content | 1 year after completion of processing | Maintaining customer service quality and dispute response |
Personal information whose retention period has elapsed or whose purpose of processing has been achieved is destroyed without delay.
Article 4 (Provision of Personal Information to Third Parties)
In principle, the Company does not provide users' personal information to third parties. However, the following are exceptions.
- When the user has consented in advance
- When provision is required by law
Article 5 (Outsourcing of Processing and Overseas Transfer)
1. Outsourcing status
To ensure the stability of service operation, the Company outsources part of its personal information processing to external specialized providers. The Company concludes outsourcing contracts in accordance with Article 26 of the Personal Information Protection Act and supervises the trustees so that they do not process personal information for purposes other than intended.
| Trustee | Outsourced work | Purpose | Location |
|---|---|---|---|
| Cryptlex LLP | Issuance, authentication, and activation management of software licenses | Operation of the license authentication system and prevention of unauthorized use | United Kingdom |
| Vercel Inc. | Operation of the website (changsoft-global.com) server and processing of inquiry form data | Stable website operation and inquiry reception | United States |
| Kakao (Daum Smartwork) | Receipt and storage of inquiry emails | Forwarding website inquiries by email and customer communication | Republic of Korea |
2. Overseas transfer notice
Among the above trustees, Cryptlex LLP (United Kingdom) and Vercel Inc. (United States) are located overseas. Transfers of personal information to these companies are made under protective measures pursuant to Article 28-8 of the Personal Information Protection Act, and the transferred personal information is limited to license authentication data and website inquiry data.
- Cryptlex LLP: ISO/IEC 27001 certified, GDPR compliant
- Vercel Inc.: Operated on AWS infrastructure, with encrypted transmission and storage of data
3. Important notice regarding outsourcing
- Outsourcing contracts include prohibition of processing for other purposes, protective measures, restrictions on re-outsourcing, management and supervision, and liability for damages.
- If the outsourced work or the trustee changes, it will be disclosed through this Privacy Policy.
Article 6 (Rights of Data Subjects and How to Exercise Them)
Users may exercise the following rights against the Company at any time.
- Request to access personal information
- Request to correct or delete personal information
- Request to suspend processing of personal information
Rights may be exercised in writing or by email (admin@changsoft-global.com), and the Company will take action without delay in accordance with applicable laws.
Article 7 (Procedures and Methods for Destroying Personal Information)
When the retention period has elapsed or the purpose of processing has been achieved, the Company destroys personal information by the following methods.
- Electronic files: permanently deleted in an unrecoverable manner
- Paper documents: shredded or incinerated
Article 8 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
1. Administrative measures
- Establishment and implementation of an internal personal information management plan
- Minimization of personnel handling personal information and regular training
- Access authority management and change history management
2. Technical measures
- Access control for the personal information processing system (Cryptlex)
- Retention of access records and measures to prevent forgery/alteration
- Encryption of personal information during transmission and storage
- Installation and operation of security and antivirus programs
3. Physical measures
- Access control to the computer room and server room
- Restricted access to personal information storage areas
Article 9 (Personal Information Protection Officer)
| Category | Details |
|---|---|
| Personal Information Protection Officer | Park Jong-eun |
| Affiliation | ChangSoft Global Co., Ltd. |
| admin@changsoft-global.com | |
| Website | www.changsoft-global.com |
Article 10 (Changes to the Privacy Policy)
This Privacy Policy may be revised in accordance with changes in applicable laws, service policies, or the security environment. In the event of any change, the Company will provide notice by reasonable means, such as a notice on the website (www.changsoft-global.com) or within the software.
Published: July 1, 2026 Effective: July 1, 2026
