Privacy Policy
Minimal collection · Minimal retention
Company: Rozin Solution
Representative: Sangtae Jeong
Business Reg. No.: 392-24-00040
Email: oxy@rozinmatch.com
Privacy Officer: Sangtae Jeong
Account deletion ≠ Full data erasure
Server access logs are retained for 3 months per telecommunications law. Sensitive health data is deleted immediately upon account deletion. For full erasure, send a 'Data Deletion Request' to the email below.
Consent management & withdrawal
Review and withdraw your sensitive data processing and guardian consents.
Go to Consent Management (members)RozinMatch follows a minimal collection · minimal retention principle. Recommendations are available without sign-up; saving is optional.
1) Information We Collect
- Input data: Health checkup / blood test values entered by users
- Account info (optional): Email or OAuth identifier upon sign-in
- Technical info: Minimal identifiers for service operation (e.g., session ID, cookies)
※ We do not collect unnecessary personal information such as real names, addresses, or national ID numbers.
2) Purpose of Use
- Generating and displaying recommendations
- Saving/loading results when chosen by the user
- Anonymous statistics for service improvement (not for personal identification)
3) Retention Period
| Data Type | Period | Basis |
|---|---|---|
| Health-related sensitive data (checkup values, diagnoses, symptoms, medications) | Deleted without delay upon consent withdrawal, account deletion, or purpose fulfillment | Internal policy |
| Minor health data | Deleted without delay upon consent withdrawal, account deletion, or purpose fulfillment | Internal policy |
| Guest health input session | Deleted upon session expiry or after the set retention period | Internal policy |
| Account info (email) | Deleted upon account deletion | No legal obligation; internal policy |
| Consent proof metadata | Retained for 3 years from consent withdrawal or account deletion, then deleted | Consent record proof |
| Server access logs | 3 months | Telecommunications Privacy Act |
| Abuse records | 1 year | Internal operations policy |
3-1) Consent to Collection and Use of Sensitive Health Data
RozinMatch collects and uses health-related sensitive data for personalized nutrition recommendations, and obtains separate consent before collection and use.
- Items collected/used: Test values entered by the user (e.g., hemoglobin, ferritin, vitamin D/B12, lipids, blood glucose, liver/kidney-related values), health-related items entered by the user (e.g., diagnosed conditions, medication, allergies, pregnancy/lactation status, symptoms, dietary restrictions), age group/sex and guardian self-attestation needed for minor recommendations, and input session information needed to generate recommendations.
- Purpose of use: Determining nutrient suitability by age/sex/health status, dose limits based on upper-level standards, suitability and safety assessment for minors, generating and re-viewing recommendations, and processing consent/withdrawal/deletion requests.
- Retention and use period: Health-related sensitive data is deleted without delay upon account deletion, consent withdrawal, or purpose fulfillment. However, minimal consent proof metadata (consent item, document version, consent time, withdrawal time, consent status, policy language, and session key or internal identifier only) is retained for 3 years from consent withdrawal or account deletion and then deleted. Consent metadata does not include health values themselves or a guardian's real name, relationship, or contact details.
- Right to refuse: You may refuse consent. If you do, some personalized features based on health status (such as conditional recommendations or minor-tailored recommendations) may not be provided.
3-2) Legal Guardian Consent for Children Under 14
For children under 14, consent from a legal guardian is obtained when processing the child's personal information and health-related sensitive data. To minimize personal data, the guardian's real name, relationship, contact details, and identity verification information are not collected; guardian consent is recorded only via a self-attestation check, document version, consent time, consent status, and session key or internal identifier.
3-3) Withdrawal of Consent
You may withdraw consent to the collection and use of sensitive data at any time; for children under 14, the legal guardian may withdraw it. Upon withdrawal, related health-related sensitive data is deleted without delay, and health-based personalized features stop. Minimal consent proof metadata is retained for 3 years from the withdrawal date and then deleted. Withdrawal does not affect the lawfulness of processing carried out before it. You can request withdrawal under My Page > Consent Management; guests can request it in the consent management area on this page.
4) Deletion Request
You may request data deletion at any time by contacting the email below.
5) Third-Party Disclosure
We do not sell or provide personal health data to third parties. Events such as affiliate link clicks may only be processed as anonymous statistics.
6) Security Measures
- Encryption in transit: TLS 1.2+ (HTTPS)
- Access control: Principle of least privilege, restricted to authorized personnel
- Minimized handlers: Managed solely by the representative
- Server security: AWS Lightsail infrastructure security policies applied
7) Data Processing Delegation
| Processor | Delegated Task | Retention |
|---|---|---|
| Google LLC | OAuth social login authentication | Upon account deletion |
| Amazon Web Services Inc. | Web hosting, DB, server operation (AWS Lightsail) | Duration of contract |
※ Changes to processors will be announced in advance through this policy.
8) Data Protection Officer
| Name | Sangtae Jeong |
| Title | CEO |
| oxy@rozinmatch.com |
For inquiries, access, correction, or deletion requests regarding personal information, please contact us via the email above. We aim to respond within 3 business days.
9) Reporting Agencies
You may file complaints with the following agencies regarding personal data disputes or breaches.
| Agency | Website | Phone |
|---|---|---|
| PIPC | www.pipc.go.kr | 182 |
| KISA Privacy Center | privacy.kisa.or.kr | 118 |
| Supreme Prosecutors' Office | www.spo.go.kr | 1301 |
| Cyber Investigation Bureau | ecrm.cyber.go.kr | 182 |
10) Contact
Contact: oxy@rozinmatch.com
Effective: 2026-03-27