LAST REVIEW: 22 SEPTEMBER 2026
Privacy Policy
This policy explains how Tymbra handles information when you visit this educational publication. It applies to pages hosted under the Tymbra name and to correspondence sent through the contact page. Tymbra is based at 45 Seolleung-ro, Gangnam-gu, Seoul 06149, Republic of Korea. We aim to collect only what is needed to operate, secure, and improve the publication.
It covers information received directly from a visitor and limited technical information generated when pages are requested. Reading an article does not require registration, an account, or a payment. We do not intentionally build profiles about a reader’s interests across unrelated services. Where a third party is used, its role is limited by contract and applicable law.
1. Scope
This document covers visitors, correspondents, and people who submit accessibility or correction requests. It does not govern third-party websites linked from our pages. Those services publish their own notices.
The scope includes the public archive, contact form, accessibility feedback, correction requests, and communications about this notice. It does not extend to a browser, device, email provider, or external site after a reader follows a link away from Tymbra. A link is provided for research convenience and does not transfer responsibility for another service’s handling of data. Questions about scope can be sent to the address at the end of this page.
2. Information collected
We may receive a name, email address, and message when you contact us. Basic server logs may include an IP address, browser type, requested URL, and timestamp. We do not intentionally request sensitive personal categories.
Contact forms may also record the time of submission, the page from which the form was sent, and a response status. Please omit passwords, recovery phrases, private keys, identity documents, health details, and unrelated confidential material. Server logs are used to diagnose failed requests, abuse patterns, and availability issues rather than to identify reading habits. If a message contains unnecessary sensitive information, we may delete that portion or the entire message.
3. Legal basis
We process correspondence to respond to a request, maintain legitimate editorial operations, protect the site, and comply with applicable law. Where consent is required for optional measurement cookies, we ask through the banner.
For a message you send, the practical basis is taking steps to respond and maintaining a responsible publication. Security processing is based on legitimate operational interests, balanced against the limited impact on ordinary visitors. Legal obligations may require preservation of a record for a defined period. Optional analytics are not activated where a visitor declines the relevant choice, and withdrawal does not affect earlier lawful processing.
4. Retention
Contact messages are normally retained for 24 months after the last meaningful exchange, then deleted or anonymised. Security logs are retained for up to 90 days. Cookie choices remain in the browser until cleared or replaced.
A correction request may be retained with the published change record when necessary to explain why an article was amended. Backups can retain deleted records for up to 35 additional days before routine rotation. A legal hold may suspend deletion when a record is reasonably needed for a dispute or legal duty. At the end of the applicable period, information is securely deleted, aggregated, or stripped of direct identifiers.
5. Rights
Subject to applicable Korean privacy law, you may request access, correction, deletion, restriction, or an explanation of processing. Send the request to the contact address and describe the record sufficiently for us to locate it.
We may ask for reasonable verification so information is not disclosed to the wrong person. We normally acknowledge a rights request within seven calendar days and aim to provide a substantive response within 30 days, subject to lawful extensions. A request may be limited where fulfilment would disclose another person’s information or conflict with a legal retention duty. You may also contact the relevant Korean privacy authority if you believe a concern remains unresolved.
6. Processors
Hosting, email delivery, security, and analytics providers may process limited information on our behalf. They receive only data needed for their ...
Typical categories include the hosting provider serving page requests, an email service routing contact replies, a security provider filtering malicious traffic, and an optional measurement provider if consent is active. These providers act only for stated operational purposes and are expected to apply access controls, confidentiality duties, and deletion procedures. Provider locations and subprocessors can change, so material changes will be reflected in a future notice update. We do not sell contact details or permit processors to use them for unrelated advertising.
7. International transfers
Some infrastructure may process information outside the Republic of Korea. Where this occurs, Tymbra uses contractual, technical, or other safeguards appropriate to the transfer and the sensitivity of the information. A transfer can involve encrypted transmission to a support or hosting region. Readers may ask for general information about the relevant safeguard without requesting confidential security details.
8. Security
Access to correspondence is limited to people who need it for publication operations. Transport encryption, restricted administrative access, and routine updates are used where available. No internet transmission can be described as completely secure, so readers should choose the minimum information needed for a message.
9. Changes
This policy was reviewed on 22 September 2026. Earlier versions are not intended to reduce rights that applied when information was collected. Future material changes will show a new review date and a short description of what changed.
10. Contact
For privacy questions, rights requests, or concerns, contact Tymbra at 45 Seolleung-ro, Gangnam-gu, Seoul 06149, Republic of Korea · +82 2-3486-7153. Please include the subject of the request and a safe reply address. We aim to acknowledge ordinary privacy correspondence within seven calendar days.
Operational details and reader requests
For practical administration, Tymbra records the minimum information needed to answer a message, investigate a security concern, or process a correction request.
A typical contact record may include the sender’s name, email address, message, submission time, and the page identified in the request. Contact records are normally retained for 24 months after the matter is closed, unless a longer period is needed to resolve a dispute or meet a legal obligation. Security logs are normally retained for up to 90 days and then deleted or aggregated. We do not sell contact details or use them to build advertising audiences. Requests about access, correction, deletion, restriction, or objection may be sent to 45 Seolleung-ro, Gangnam-gu, Seoul 06149, Republic of Korea, or through the contact page. Tymbra aims to acknowledge a request within 7 business days and provide a substantive response within 30 days, subject to identity and complexity checks.
Service providers may process limited information for hosting, form delivery, email transport, security monitoring, and aggregate measurement. Their access is restricted to the service they provide and is governed by contractual or equivalent confidentiality duties. Data may be transferred outside the Republic of Korea where a provider operates internationally; in those cases Tymbra considers contractual safeguards, access controls, and the provider’s published privacy terms. If a request cannot be fulfilled, the response will explain the reason and identify any available complaint route.
Revision record
This policy was reviewed on 22 September 2026. Earlier wording may remain available in internal records for accountability, while the current page governs future processing from its publication date.