Privacy policy
Effective 22 September 2026. This policy explains how Iridia, operating from 15 Teheran-ro, Gangnam-gu, Seoul 06130, Republic of Korea, handles information when you read the site or contact the editorial desk.
Scope and controller
Scope and controller: This policy applies to pages, forms and ordinary communications operated under the Iridia name. It does not govern third-party websites linked from our articles. The responsible editorial contact is the Seoul desk at +82 2 7981 3546. Iridia acts as the publisher and contact point for this processing. The policy covers visitors in the Republic of Korea and readers elsewhere who access the English-language site. It does not cover data held independently by a linked protocol, hosting service or advertiser. Questions about responsibility can be sent by phone or through the contact page.
Information collected
Information collected: Server logs may contain IP address, browser type, requested page, referrer and time. A contact message may contain your name, email address and any details you choose to provide. We do not ask for sensitive financial credentials. A message may also include an email address, subject line, attachment or correction source if voluntarily supplied. Do not include wallet keys, passwords, identity numbers or account credentials. Basic technical data is collected automatically when a page loads, while contact data is collected only when a visitor submits it.
Purpose and legal basis
Purpose and legal basis: Technical logs support security and availability. Contact details support replies and correction handling. Where applicable, processing is based on legitimate interests in operating a publication, consent for optional cookies, or steps requested by the person contacting us. Iridia limits each use to the stated publishing or service purpose. Consent can be withdrawn for optional cookies without changing the lawfulness of earlier use. A person may decline to provide contact details, although the desk may then be unable to reply. We do not use correspondence to make individualized financial or promotional decisions.
Retention
Retention: Security logs are normally retained for 30 days, contact correspondence for 24 months after the matter closes, and correction records for the life of the relevant article. Longer retention may apply where needed for a legal claim. Routine deletion is performed through ordinary hosting and mailbox controls. If a correction remains relevant to an archived article, the minimum factual record may remain with the article. Legal, fraud-prevention or accounting obligations can require a longer period. Data no longer needed is deleted, anonymized or securely restricted.
Cookies
Cookies: The site may use cookieChoice, a first-party preference cookie stored for 180 days, and aggregate analytics identifiers where enabled, generally limited to 13 months. Rejecting optional cookies does not prevent reading. The preference record stores a choice rather than a profile of reading interests. Session technologies may expire when the browser closes, while security records may have shorter technical lifespans. Optional analytics are disabled where a visitor rejects them. Cookie details and controls are described in the cookie policy.
Processors
Processors: Hosting, security, email and analytics providers may process limited information under contractual instructions. They are not authorized to use editorial correspondence for unrelated advertising. Typical roles include website hosting, malware protection, transactional email and aggregated audience measurement. Iridia shares only the fields needed for the relevant task. Providers must apply access controls and confidentiality obligations appropriate to their role. A provider may retain technical backup copies for a limited operational period.
International transfers
International transfers: Some service providers may process data outside the Republic of Korea. Iridia uses contractual and organizational safeguards appropriate to the service and considers the destination, access controls and transfer necessity. A transfer does not change the purposes described in this policy. Readers may ask which category of provider is involved and what safeguards are available. Iridia does not intentionally sell contact correspondence to third parties.
Rights and requests
Rights and requests: Subject to applicable law, a person may ask for access, correction, deletion, restriction or information about processing. Requests should identify the relevant contact channel without sending passwords or wallet credentials. Iridia will acknowledge a request within 7 calendar days and aims to respond within 30 days, subject to identity and complexity checks. If a request cannot be fully accepted, the desk will explain the applicable reason. A person may also raise a concern with the Personal Information Protection Commission of Korea or another competent authority.
Security
Security: Iridia uses ordinary administrative, technical and physical measures suited to a small editorial publication, including limited account access, transport encryption where supported and review of unusual requests. No internet transmission can be described as completely secure. Visitors should use a current browser and avoid placing confidential credentials in forms. Suspected privacy incidents should be reported promptly to the Seoul desk.
Changes and contact
Changes and contact: This policy was effective on 22 September 2026. Material revisions will show a new effective date and a short change note on this page. The current version governs processing from its stated date. For questions or requests, contact Iridia at 15 Teheran-ro, Gangnam-gu, Seoul 06130, Republic of Korea, or +82 2 7981 3546.
For clarity, Iridia generally receives only the information needed to operate an editorial website and respond to a reader. Hosting logs are normally retained for up to 30 days for security review, while a correspondence record may be retained for up to 24 months after the matter is closed. A correction request may be kept longer where necessary to preserve the publication history or address a legal request. Access is limited by role, and routine exports are avoided where the same purpose can be met in the site system.
Iridia may use hosting, form-delivery, email and security providers acting on documented instructions. These providers may process technical metadata in countries where their systems operate, including outside the Republic of Korea. Contractual confidentiality, access controls and deletion instructions are used where available, and Iridia does not sell reader contact details. A provider may retain a minimal backup copy for a limited disaster-recovery cycle before automatic deletion.
Individuals may ask what personal information is held, request correction, ask for deletion where no retention duty applies, or object to a use based on legitimate interests. Requests should identify the relevant email address and page or message, but should not include passwords, wallet keys or identity numbers. Iridia aims to acknowledge a request within 7 calendar days and provide a substantive response within 30 days, subject to lawful extensions or verification where needed. A concern may also be raised with the relevant Korean privacy authority.
Optional analytics are considered only in aggregate and may be declined through the cookie choice mechanism. Essential security records may still be created because they support safe delivery of the site. If a breach affecting personal information is suspected, Iridia will assess the incident, preserve relevant logs and follow applicable notification duties. This policy was reviewed on 22 September 2026; material changes will be dated in the page history and will not silently alter the stated purposes.