TRAK
TRAK
Theodore Roosevelt Association Korea
Back to the service

Privacy Policy

TRAK Room Reservation · Effective August 6, 2026
Governing language. This English text is provided for the convenience of users who do not read Korean. The Korean version is the official and controlling text; in the event of any discrepancy or difference in interpretation between the two, the Korean version prevails.

Theodore Roosevelt Association Korea (the “Association”) treats the personal data of users of the TRAK Room Reservation service (the “Service”) with care and complies with the Personal Information Protection Act of the Republic of Korea and other applicable laws. This Policy explains what personal data the Association collects and why, how it is used, and when it is destroyed.

Article 1 (Personal Data Collected and How It Is Collected)

The Service collects only the minimum information necessary to reserve a meeting room. Resident registration numbers are never collected.

CategoryData collectedWhen collected
Sign-up
(required)
Email address, password, name (display name) When signing up by email
Social login
(optional)
· Kakao: nickname, profile image, Kakao account (email)
· Google: name, email address, profile picture
Only the items the user consents to on each provider’s consent screen are received.
When logging in with a social account
Use application
(required)
Affiliated organisation, job title, contact number (mobile) When applying for reservation rights
Reservation Meeting name, number of attendees, contact number for the day, reservation date, time and venue When creating a reservation
Notifications
(optional)
Web push subscription details (identifier and keys issued by the browser), device operating system When consenting to receive notifications
Automatically collected IP address, access date and time, browser and device information, service usage records, cookies Generated automatically while using the Service

Data is collected either because the user enters it directly on the Service, because it is provided by a social login provider with the user’s consent, or because it is generated automatically in the course of using the Service.

Article 2 (Purposes of Processing)

  1. Member identification and authentication — sign-up, login, identity verification and maintaining the logged-in state
  2. Review of use approval — verifying affiliation, job title and contact details in order to grant or refuse the right to reserve meeting rooms
  3. Provision of the reservation service — accepting, confirming, changing and cancelling reservations, preventing double booking, and providing usage guidance
  4. Facility operation — understanding usage, giving notice of closures and maintenance, and contacting users about their use
  5. Sending notifications — reservation confirmation, change and cancellation notices, and reminders before the start of use
  6. Ensuring the stability of the Service — preventing misuse, responding to incidents and handling enquiries

Article 3 (Retention and Use Period)

The Association destroys personal data without delay once the purpose of processing has been achieved. Data is retained for the periods below.

ItemRetention periodBasis
Member account informationUntil withdrawal of membership Member identification and authentication
Use application information
(affiliation, job title, contact)
Until withdrawal of membership Management of use rights
Reservation records1 year from the date of reservation Facility operation and handling of usage disputes
Web push subscription informationUntil notifications are turned off or membership is withdrawn Sending notifications
Access records (IP, timestamp)3 months Protection of Communications Secrets Act

On withdrawal, account information is destroyed immediately. However, where a confirmed reservation remains, the relevant data is destroyed after that reservation has ended in accordance with the periods above; and where there is a record of misuse, the minimum information necessary to prevent recurrence may be stored separately.

Article 4 (Provision to Third Parties)

The Association does not provide users’ personal data to third parties, except:

Article 5 (Outsourcing of Processing)

The Association outsources personal data processing as set out below in order to operate the Service, and in each outsourcing contract stipulates and supervises the matters necessary for personal data to be managed securely.

ProcessorOutsourced work
Neoulsoft Inc. Development, operation and maintenance of the service system (managing partner)
NAVER Cloud Corp.Operation of cloud infrastructure (servers, databases)

Article 6 (Overseas Transfer)

The Association does not transfer personal data overseas. All personal data is stored and processed on servers located in the Republic of Korea.

With social login, the user logs in directly with Kakao or Google, and the Association stores the information received as a result on its domestic servers. Processing of personal data by those providers is governed by their own privacy policies.

Article 7 (Procedure and Method of Destruction)

Article 8 (Users’ Rights and How to Exercise Them)

Users may exercise the following rights at any time:

You can view, amend and withdraw directly on the Settings screen of the Service, or you may make a request in writing or by email to support@nskit.io or to the personal data protection officer below. Requests may also be made through a legal representative or an authorised agent. The Association handles such requests without delay.

Article 9 (Children Under 14)

The Service is intended for adults who use the Association’s facilities, and does not accept sign-ups from children under 14 years of age.

Article 10 (Automatic Collection Devices — Cookies)

The Service uses only the cookies necessary to provide the Service, such as maintaining the logged-in state. No third-party cookies are used for advertising or behavioural analysis.

CookiePurposeRetention
Authentication tokensMaintaining the logged-in state Access 12 hours / refresh 30 days
Language and platformRemembering the display language and screen mode Up to 1 year

You may refuse cookies in your browser settings, but in that case features that require login (such as making reservations) cannot be used.

Article 11 (Security Measures)

Article 12 (Personal Data Protection Officer)

Please use the contacts below for enquiries, complaints or remedies relating to the processing of personal data. The Association will respond without delay.

ItemDetails
Data protection officer Kihu Kwon (Neoulsoft Inc. · managing partner)
Emailaloepigeon@nskit.io
Phone010-5720-9835
Service enquiries support@nskit.io
Operating organisation Theodore Roosevelt Association Korea
4F, 34 Seongnae-ro 6-gil, Gangdong-gu, Seoul, Republic of Korea
Representative Soonwoo Kwon · 070-4255-6825 · mvp-no1@daum.net

The personal data controller is the Theodore Roosevelt Association Korea; system development and operation are carried out by Neoulsoft Inc. as the managing partner. The data protection officer and the enquiry channel are handled by the managing partner.

Article 13 (Remedies for Infringement)

If you need help regarding an infringement of your personal data, you may contact the following bodies in the Republic of Korea:

Article 14 (Changes to this Policy)

Where this Policy is amended, notice will be given through announcements within the Service from 7 days before the amendment takes effect. Amendments that materially affect users’ rights will be notified 30 days in advance.

Addendum — This Policy takes effect on August 6, 2026.

Terms of Service · Privacy Policy · TRAK Room Reservation
한국어

Theodore Roosevelt Association Korea · 4F, 34 Seongnae-ro 6-gil, Gangdong-gu, Seoul, Republic of Korea
Contact support@nskit.io