1. Scope and privacy roles
The operator determines how information is handled for the official website, evaluation access, contracts, account authentication, support, and security. For employee and business records entered by an organization, that organization is the data controller and the operator acts on its documented instructions. A self-hosted installation is controlled by the party that operates it.
2. Information and purposes
Depending on the service in use, information may include workspace and administrator details, authentication and security events, support requests, and organization-provided work records. It is used to provide accounts and workflows, secure the service, answer requests, and meet contractual or legal obligations.
The current public landing does not collect account, company-record, upload, or payment information through an input form.
4. Individual rights and security
Individuals may request access, correction, deletion, suspension, or withdrawal where applicable, usually through their organization first. OORT applies role-based access, credential hashing, encrypted transport, audit records, and backup and recovery checks appropriate to the service stage.
No current feature makes a fully automated decision that has a significant legal or similarly important effect on an individual.
5. Retention, deletion, and contact
Information is retained only for the applicable service, security, contractual, dispute, or legal period and is deleted or separated when that period ends. During the private evaluation, contact the project channel through which access was granted or your workspace administrator. Full request and remedy details are in the Korean Privacy Policy.