← Back to SOVISS

Privacy Policy

Effective Date: December 12, 2025
Last Updated: December 12, 2025
Version: 1.0 (English — Master Version)


Important Notice

This English version is the master version of this Privacy Policy. Translations into other languages (including Korean) are provided for convenience only. In case of any discrepancy or conflict between the English version and any translation, the English version shall prevail.


1. Overview

This Privacy Policy describes how [Company Name] ("soviss", "we", "our", or "us") collects, uses, stores, and shares personal information when you use soviss.com, our authentication hub service.

soviss.com itself is a Unified Account and single sign-on (SSO) service. It does not host content or process payments. Each Subdomain Service (e.g., movis.soviss.com, seo.soviss.com, apost.soviss.com, music.soviss.com) has its own Privacy Policy that supplements this one with service-specific information.

We are committed to protecting your personal information and your right to privacy. This Policy is designed to comply with:


2. Data Controller

The data controller responsible for your personal information is:

For users in the EEA and UK, please see Section 14 for our Data Protection Officer (DPO) and EU Representative information.


3. Information We Collect

Because soviss.com is purely an authentication hub, the personal information we collect is limited and minimal.

3.1 Information You Provide Directly

Examples
Account credentialsEmail address, password (hashed), display nameRequired for registration
Profile informationProfile picture, contact preferencesOptional
CommunicationsInquiries, support tickets, feedbackProvided when you contact us

3.2 Information Collected Automatically

When you use the Service, we automatically collect:

Examples
Authentication dataLogin timestamps, session tokens, device identifiersAccount security, session management
Technical dataIP address, browser type, operating system, language preferenceService operation, security, fraud prevention
Usage dataPages visited on soviss.com, click events related to authentication flowService improvement, analytics
CookiesSee Section 11 (Cookies)See Section 11

3.3 Information from Subdomain Services

When you use a Subdomain Service, that service collects additional information governed by its own Privacy Policy. soviss.com itself does not receive content or behavioral data from those services unless required for authentication.

3.4 We Do Not Collect

soviss.com does not collect:


4. How We Use Your Information

We use your personal information for the following purposes, based on the legal grounds described in Section 5:

Account creation and managementVerifying your identity, enabling SSO login
Service operationProviding authentication across Subdomain Services
SecurityPreventing unauthorized access, detecting fraud and abuse
CommunicationSending account-related notifications (e.g., password resets, security alerts)
Legal complianceComplying with applicable laws and responding to lawful requests
Service improvementUnderstanding usage patterns to improve the Service
We do not:

5. Legal Bases for Processing (GDPR)

If you are in the EEA, UK, or Switzerland, we process your personal information on the following legal bases under Article 6 of the GDPR:

Creating and managing your Unified AccountContract performance (Art. 6(1)(b))
Providing SSO authenticationContract performance (Art. 6(1)(b))
Securing the Service and preventing abuseLegitimate interests (Art. 6(1)(f))
Sending essential service notificationsContract performance (Art. 6(1)(b))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))
Optional marketing or product updatesConsent (Art. 6(1)(a)) — withdrawable at any time

6. How We Share Your Information

We share your personal information only as described below:

6.1 Service Providers (Processors)

We share information with trusted service providers that help us operate the Service. These providers act under contract and may only use your information for the purposes we specify.

Examples
Cloud infrastructureAWS, Google Cloud, or similarHosting, data storage
Email deliveryTransactional email providersSending account emails (verification, password reset)
Security and fraud preventionAuthentication and bot-detection servicesAccount security
AnalyticsPrivacy-respecting analytics toolsAggregated usage analysis
Customer supportHelpdesk toolsResponding to your inquiries

6.2 Subdomain Services

When you use a Subdomain Service, your Unified Account credentials and basic profile information are shared with that service to enable authentication. Each Subdomain Service's Privacy Policy describes any additional sharing.

6.3 Legal and Safety

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to:

6.4 Business Transfers

If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you in advance of any such transfer that would change how your information is handled.

6.5 With Your Consent

We may share information for any other purpose with your explicit consent.

6.6 No Sale of Personal Information

We do not sell your personal information for monetary or other valuable consideration, as defined under the CCPA/CPRA. We also do not "share" your information for cross-context behavioral advertising.


7. International Data Transfers

We are based in the Republic of Korea, and we use service providers located in various countries. As a result, your personal information may be transferred to, stored, and processed in countries other than your own.

When we transfer personal information out of the EEA, UK, or Switzerland, we use one or more of the following safeguards:

You can request a copy of the safeguards used by contacting support@soviss.com.


8. Data Retention

We retain your personal information only as long as necessary for the purposes described in this Policy, or as required by applicable law.

Active Unified Account dataUntil you delete your account
Account data after deletion requestDeleted within 30 days, except where law requires longer retention
Authentication logsUp to 12 months
Customer support recordsUp to 3 years
Records required by Korean e-commerce or tax lawAs required by law (typically 5 years)
BackupsUp to 90 days after deletion from primary systems

9. Your Privacy Rights

9.1 Rights Available to All Users

Regardless of where you live, you have the following rights:

To exercise these rights, log into your account settings or email support@soviss.com. We will respond within 30 days.

9.2 Additional Rights for EEA, UK, and Swiss Residents (GDPR)

If you are in the EEA, UK, or Switzerland, you also have the right to:

9.3 Additional Rights for California Residents (CCPA / CPRA)

If you are a California resident, you have the following additional rights under the CCPA/CPRA:

To submit a CCPA request, email support@soviss.com with the subject "CCPA Request." We may verify your identity before responding. Authorized agents may submit requests on your behalf with proper documentation.

9.4 Additional Rights for Korean Residents (PIPA)

Korean residents have rights under the Personal Information Protection Act, including the right to access, correct, delete, and suspend processing of their personal information. To exercise these rights, contact support@soviss.com or use the controls in your account settings. You may also file a complaint with the Personal Information Protection Commission (privacy.go.kr) or the Korea Internet & Security Agency Privacy Center (privacy.kisa.or.kr / call 118).


10. Security

We implement administrative, technical, and physical safeguards designed to protect your personal information, including:

However, no method of transmission or storage is 100% secure. If you have reason to believe your account is no longer secure, please contact us immediately at support@soviss.com.


11. Cookies and Tracking Technologies

soviss.com uses a minimal set of cookies necessary for the Service to function:

Purpose
Strictly NecessaryAuthentication, session management, securityRequired
FunctionalRemembering your language and display preferencesOptional
AnalyticsAggregated usage analysis (no individual tracking)Optional
We do not use cookies for cross-site advertising or third-party behavioral tracking on soviss.com.

You can manage cookies through your browser settings. Disabling strictly necessary cookies will prevent the Service from functioning correctly.

For users in the EEA, UK, or jurisdictions requiring consent, we display a cookie consent banner on first visit allowing you to accept or reject non-essential cookies.


12. Children's Privacy

The Service is not intended for users below the minimum age stated in Section 3 of our Terms of Service:

We do not knowingly collect personal information from children below these ages. If we learn that we have collected personal information from a child without verified parental consent, we will delete that information promptly. Parents and guardians who believe their child has provided personal information to us should contact support@soviss.com.


13. Automated Decision-Making

We do not use your personal information for automated decision-making that produces legal effects or similarly significant effects on you, as defined under GDPR Article 22.

We do use automated systems for fraud detection and security purposes (e.g., detecting suspicious login patterns), but these systems do not make final decisions affecting your rights without human review.


14. Data Protection Contacts

14.1 Data Protection Officer

For privacy questions, please contact:

14.2 EU/UK Representative

If we appoint an EU representative or UK representative under GDPR Article 27 / UK GDPR, their details will be listed here. As of the effective date of this Policy, we have evaluated our processing activities and do not believe we meet the threshold requiring formal appointment. Users in the EEA or UK may contact support@soviss.com directly for any privacy matter.

14.3 Korean Privacy Officer

In compliance with Article 31 of PIPA, our designated privacy officer is:


15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

If you do not agree to the updated Policy, you should stop using the Service and may close your account.


16. Contact Us

For any questions or requests regarding this Privacy Policy or our data practices:

We aim to respond to all privacy requests within 30 days.


Version History

Effective Date
1.02025-12-12Initial release