생태제작소 STstudio
Work Editorial & Web About
contact@ststudio.co.kr

생태제작소(STstudio) 개인정보 처리방침

시행일 2026년 9월 17일 · 제2판 (제1판 보기)

생태제작소(STstudio, 대표 옥이랑, 이하 “스튜디오”)는 「개인정보 보호법」 제30조와 EU 「일반 개인정보 보호법(GDPR)」 제13조에 따라, 웹사이트 www.ststudio.co.kr과 문의 양식, 이메일 contact@ststudio.co.kr을 통해 처리하는 개인정보의 처리 기준과 보호 조치를 다음과 같이 공개합니다. 스튜디오는 필요한 최소한의 개인정보만 처리하며, 광고를 하지 않고 개인정보를 판매하지 않습니다. 이 방침은 한국어와 영어로 제공하며, 두 판의 내용이 다를 경우 「개인정보 보호법」에 관해서는 한국어판을, GDPR에 관해서는 영어판을 따릅니다.

  1. 개인정보처리자
  2. 처리 목적·항목·법적 근거
  3. 보유 기간
  4. 파기 절차와 방법
  5. 제3자 제공
  6. 처리 업무의 위탁
  7. 국외 이전
  8. 쿠키 등 자동 수집 장치와 거부 방법
  9. 외부 서비스가 직접 받는 정보
  10. 안전성 확보 조치
  11. 정보주체의 권리와 행사 방법
  12. 개인정보 보호책임자
  13. 권익침해 구제 방법
  14. 그 밖의 사항
  15. 처리방침의 변경

1. 개인정보처리자

  • 상호: 생태제작소(STstudio) — 네덜란드 개인사업자(eenmanszaak), 대한민국 개인사업자
  • 대표: 옥이랑(Yirang Ok)
  • 네덜란드 사업장: · KvK 98086030 · VAT ID(btw-id) NL005307209B29
  • 대한민국 사업장: · 사업자등록번호 398-55-00964
  • 이메일: contact@ststudio.co.kr

스튜디오는 네덜란드와 대한민국에서 개인정보를 처리하며, 대한민국 「개인정보 보호법」과 EU GDPR을 함께 지킵니다. GDPR 제37조의 지정 요건에 해당하지 않아 별도의 데이터 보호 책임자(DPO)는 두지 않았으며, 개인정보 관련 문의는 제12항의 보호책임자가 받습니다.

2. 처리 목적·항목·법적 근거

스튜디오는 아래 목적으로만 개인정보를 처리하며, 목적이 바뀌면 「개인정보 보호법」 제18조에 따라 필요한 조치를 먼저 합니다.

가. 동의 없이 처리하는 개인정보

처리 업무처리하는 항목목적법적 근거
프로젝트·협업 문의
(문의 양식, 이메일)
필수: 이름, 이메일 주소, 문의 유형, 메시지
선택: 회사·기관명, 작업 종류, 일정, 예산 범위
이메일로 문의한 경우: 보낸 사람 이름·주소, 메일 본문과 첨부파일
문의 양식 전송 시 자동 생성: 전송 시각, IP 주소, 유입 페이지(리퍼러)
문의 확인과 답변, 작업 범위·일정·견적 협의 「개인정보 보호법」 제15조제1항제4호(계약 체결 과정에서 정보주체가 요청한 조치) · GDPR 제6조제1항 (b)
그 밖의 문의
(문의 양식, 이메일)
위와 같음 보내 주신 문의에 답변 수집·이용: 같은 법 제15조제1항제6호(보내 주신 메시지에 답할 정당한 이익) · GDPR 제6조제1항 (f). 국외 이전: 제7항
스팸 확인 문의 양식 전송 시 IP 주소, 이메일 주소, 전송 시각 자동 발송 스팸 차단 같은 법 제15조제1항제6호(스팸을 막을 정당한 이익) · GDPR 제6조제1항 (f)
계약과 세무 기록
(문의가 계약으로 이어진 경우)
이름, 소속, 연락처, 주고받은 메일, 견적·계약·청구 기록 계약 이행, 청구와 세무 신고, 법령에 따른 기록 보존 같은 법 제15조제1항제4호·제2호(법령상 의무) · GDPR 제6조제1항 (b)·(c)
웹사이트 접속 기록
(서버 로그)
IP 주소, 접속 일시, 요청한 페이지 주소, 응답 코드, 유입 페이지(리퍼러), 브라우저·기기 정보(user-agent) 웹사이트 제공, 비정상 접근 탐지·차단, 장애 대응 같은 법 제15조제1항제6호(웹사이트를 안전하게 운영할 정당한 이익) · GDPR 제6조제1항 (f)
오늘의 방문자 표시
(홈 화면의 점)
IP 주소를 서버 비밀키로 변환한 해시값(IP 주소 자체는 저장하지 않음), 그날 첫 방문 시각, 무작위로 고른 색 오늘 방문자 수를 홈 화면에 점으로 표시(같은 방문자는 하루 한 번만 셈). 화면에는 방문자마다 색만 보여 주며, 해시값·방문 시각은 서버 밖으로 나가지 않습니다 같은 법 제15조제1항제6호(홈 화면의 작은 자체 디자인 요소를 보여 줄 정당한 이익) · GDPR 제6조제1항 (f), 네덜란드 전기통신법(Telecommunicatiewet) 제11.7a조제3항 (b)
방문 기록
(스튜디오 자체 집계)
IP 주소, 방문 일시, 본 페이지 주소, 유입 페이지(리퍼러), 브라우저·기기 정보(user-agent), 브라우저 언어 설정 어느 작업이 얼마나 읽히는지, 방문자가 어디를 거쳐 오는지 주 단위로 파악해 웹사이트와 작업 공개 방식을 개선. 집계 결과는 주 1회 대표에게 메일로만 보내며 외부에 공개하지 않습니다 같은 법 제15조제1항제6호(자기 웹사이트의 이용 현황을 파악할 정당한 이익) · GDPR 제6조제1항 (f)

방문 기록은 Google Analytics와 별개이며, 쿠키를 쓰지 않고 방문자의 기기에 아무것도 저장하지 않습니다. 서버가 자기 웹사이트의 요청을 기록하는 것이어서 쿠키 동의 창의 대상이 아니지만(네덜란드 전기통신법 제11.7a조는 기기에 저장·접근하는 행위에 적용됩니다), 이 처리에는 제11항에 따라 언제든 반대하실 수 있습니다. 브라우저에서 JavaScript를 끄면 이 기록은 만들어지지 않습니다.

정당한 이익을 근거로 하는 처리는 스튜디오의 정당한 이익이 정보주체의 권리보다 명백히 우선하고, 그 정당한 이익과 상당한 관련이 있으며 합리적인 범위를 넘지 않는 경우에만 합니다. 이 처리에는 제11항에 따라 언제든 반대(처리정지 요구)할 수 있습니다.

나. 동의를 받아 처리하는 개인정보

처리 업무처리하는 항목목적법적 근거
방문 통계
(Google Analytics 4)
쿠키 식별자(_ga, _ga_H1B3D5BHY9), 방문한 페이지 주소와 제목, 유입 경로(리퍼러), 방문 일시, 스크롤 같은 이용 이벤트, 브라우저·운영체제·화면 크기·언어, IP 주소(Google이 대략적 위치(국가·도시)를 추정하는 데만 쓰고 폐기) 어떤 페이지와 작업이 얼마나 보이는지 통계 수집·이용: 「개인정보 보호법」 제15조제1항제1호(동의) · GDPR 제6조제1항 (a), 네덜란드 전기통신법 제11.7a조제1항
국외 이전: 같은 법 제28조의8제1항제1호(별도 동의)
그 밖의 문의의 국외 이전
(문의 양식)
이름, 이메일 주소, 소속, 메시지, IP 주소 문의를 스튜디오에 전달 같은 법 제28조의8제1항제1호(문의 양식의 동의 확인란)

Google Analytics는 쿠키 동의 창에서 ‘수집·이용’과 ‘국외 이전’에 각각 동의한 뒤 ‘허용’을 누른 경우에만 불러오며, 그 전에는 Google에 아무 정보도 보내지 않습니다. 동의 창은 동의 전에 항목, 받는 곳과 국가, 전송 방법, 보유 기간을 보여 줍니다. 거부해도 사이트 이용에는 제한이 없습니다. 스튜디오는 Google 신호(기기 간 추적)와 광고 개인화 기능을 쓰지 않습니다.

3. 보유 기간

개인정보보유 기간
계약으로 이어지지 않은 문의(스튜디오 메일함)마지막 연락일로부터 1년(같은 분이 다시 문의할 때 이전 논의를 확인하기 위함), 이후 파기
문의 양식 처리사(Web3Forms) 서버의 사본Web3Forms 기본 정책에 따라 제출일로부터 최대 3년 후 자동 삭제. 계약으로 이어지지 않은 문의도 이 기간 동안 남을 수 있으며, 삭제를 요청하시면 스튜디오가 Web3Forms에 삭제를 요청합니다
메일 전달 기록(Cloudflare)보낸 사람·받는 사람 주소, 제목, 처리 결과를 31일 보관. 메일 본문은 저장하지 않음
계약·청구 관련 기록해당 거래의 법정신고기한이 지난 날부터 7년(대한민국 「국세기본법」 제85조의3제2항: 5년, 역외거래 7년 · 네덜란드 「국세 일반법(AWR)」 제52조: 7년)
서버 접속 기록호스팅사 fortrabbit이 IP 주소와 접속 기록을 30일을 넘겨 보관하지 않는다고 밝힌 기간
오늘의 방문자 표시 해시값다음에 방문이 기록되는 날(보통 다음 날)의 첫 방문 때 이전 날짜의 기록을 자동 삭제
방문 기록(스튜디오 자체 집계)12개월. 달 단위 파일로 저장하며, 기간이 지난 달은 서버가 자동 삭제합니다
Google Analytics 통계쿠키 식별자와 연결된 방문자·이벤트 단위 데이터는 최대 14개월(Google Analytics 보관 설정). 개인을 알아볼 수 없는 집계 통계(페이지별 방문 수 등)는 더 오래 남을 수 있습니다. _ga 쿠키는 동의한 날부터 90일
기기에 저장되는 설정(언어, 쿠키 선택)방문자가 브라우저에서 지울 때까지. 쿠키 선택은 365일이 지나면 다시 묻습니다

4. 파기 절차와 방법

보유 기간이 지나거나 처리 목적을 이룬 개인정보는 지체 없이 파기합니다. 스튜디오가 직접 보관하는 메일과 문서는 대표가 파기할 대상을 확인해, 전자 파일은 휴지통 비우기를 포함해 복구할 수 없게 삭제하고 출력물은 분쇄합니다. 서버 접속 기록, 방문자 표시 기록, 메일 전달 기록, 문의 양식 처리사의 사본은 제3항의 기간이 지나면 각 시스템에서 자동 삭제됩니다. 다른 법령에 따라 보존해야 하는 계약·청구 기록은 다른 개인정보와 분리해 보관합니다.

5. 제3자 제공

스튜디오는 개인정보를 제3자에게 제공하지 않습니다. 다만 법률에 특별한 규정이 있는 경우처럼 「개인정보 보호법」 제17조·제18조가 허용하는 경우는 예외이며, 계약이 체결되면 세금계산서 발급·세무 신고를 위해 법령에 따라 세무 당국(대한민국 국세청, 네덜란드 국세청 Belastingdienst)에 거래처의 상호·대표자 성명·사업자등록번호 또는 VAT 번호·거래 금액을 제공합니다(「개인정보 보호법」 제17조제1항제2호).

6. 처리 업무의 위탁

수탁자위탁 업무
Web3Creative(Web3Forms 운영, 인도)문의 양식 수신, 스팸 확인, 스튜디오 메일로 전달
재위탁: Amazon Web Services, Inc.(호스팅·메일 발송), Cloudflare, Inc.(네트워크 보안), Hetzner Online GmbH(서버), CleanTalk Inc.·Automattic Inc.(Akismet)(스팸 확인), Microsoft Corporation(Clarity, 관리 화면 이용 기록), SparrowDesk(고객 지원)
Cloudflare, Inc.(미국)contact@ststudio.co.kr로 온 메일의 수신·전달(메일 본문은 저장하지 않음)
재위탁: cloudflare.com/gdpr/subprocessors
Google(Gmail — Google LLC, 계정 소재지에 따라 Google Ireland Limited)문의 메일 보관
fortrabbit GmbH(독일, 서버는 아일랜드의 Amazon Web Services)웹사이트 호스팅, 서버 접속 기록, 방문자 표시 기록, 방문 기록 저장
재위탁: fortrabbit.com/legal/data-protection/sub-processors
Google Ireland Limited(아일랜드)·Google LLC(미국)방문 통계(Google Analytics, 동의한 경우에만)
재위탁: business.safety.google/subprocessors

Web3Forms, Cloudflare, fortrabbit, Google Analytics는 데이터 처리 약관에 따라 목적 외 처리 금지, 안전성 확보 조치, 재위탁 제한, 손해배상 책임 같은 사항을 지킵니다. Gmail은 Google의 일반 이용약관에 따라 이용합니다. 수탁자가 바뀌면 이 처리방침에 알립니다.

7. 국외 이전

스튜디오는 네덜란드에서도 업무를 하며, 위탁 업무를 위해 아래와 같이 개인정보를 국외로 이전합니다. 모든 이전은 인터넷을 통한 암호화 전송(HTTPS/TLS)입니다.

이전받는 자(연락처)국가항목시기목적·보유 기간근거
Web3Creative — Web3Forms
support@web3forms.com
인도, 미국, 독일, 핀란드 및 Cloudflare 데이터센터 소재국(cloudflare.com/network)문의 양식의 모든 항목, IP 주소, 전송 시각, 리퍼러문의 양식 전송 즉시문의 수신·스팸 확인·전달 / 제출일로부터 최대 3년프로젝트·협업 문의: 「개인정보 보호법」 제28조의8제1항제3호 · 그 밖의 문의: 같은 조 제1항제1호(문의 양식의 동의)
Cloudflare, Inc.
dpo@cloudflare.com
미국 및 Cloudflare 데이터센터 소재국(cloudflare.com/network)보낸 사람 이름·주소, 받는 사람 주소, 제목, 메일 본문(전달하는 동안만), 처리 결과메일 수신 즉시메일 전달 / 본문은 저장하지 않음, 전달 기록 31일프로젝트·협업 문의: 같은 조 제1항제3호 · 그 밖의 문의(문의 양식): 같은 조 제1항제1호
Google — Gmail
support.google.com/policies/troubleshooter/7575787
미국 및 Google 데이터센터 소재국(datacenters.google/locations)문의 메일 전체메일 전달 즉시문의 메일 보관 / 제3항의 보유 기간프로젝트·협업 문의: 같은 조 제1항제3호 · 그 밖의 문의(문의 양식): 같은 조 제1항제1호
fortrabbit GmbH
info@fortrabbit.com
아일랜드(EU)서버 접속 기록, 방문자 표시 해시값, 방문 기록웹사이트 접속 시마다호스팅 / 접속 기록 최대 30일, 해시값은 다음 방문일 첫 방문 때 삭제, 방문 기록 12개월같은 조 제1항제5호(개인정보보호위원회의 EU 동등성 인정)
Google Ireland Limited·Google LLC — Google Analytics
support.google.com/policies/troubleshooter/7575787
아일랜드, 미국 및 Google 데이터센터 소재국(datacenters.google/locations)제2항 나목의 방문 통계 항목두 가지 동의 후 페이지를 볼 때마다방문 통계 / 방문자 단위 데이터 최대 14개월(집계 통계 제외)같은 조 제1항제1호(별도 동의)

국외 이전을 거부하는 방법과 효과.

  • Google Analytics: 쿠키 동의 창에서 동의하지 않거나 ‘거부’를 누르면 이전되지 않으며 불이익은 없습니다.
  • 문의 양식: ‘그 밖의 문의’는 양식의 국외 이전 동의 확인란에 동의해야 보낼 수 있습니다. 동의하지 않거나 문의 양식을 쓰고 싶지 않으면 contact@ststudio.co.kr로 직접 메일을 보내 Web3Forms(인도 등)로의 이전을 피할 수 있습니다. 메일도 Cloudflare·Google(미국)을 거치므로, 이 이전까지 원하지 않으면 네덜란드 사업장 주소로 우편을 보내 주세요.
  • 웹사이트 호스팅(fortrabbit, 아일랜드): 페이지를 제공하는 데 꼭 필요해 따로 거부할 수 없습니다. 원하지 않으면 웹사이트를 이용하지 않고 우편으로 연락하실 수 있습니다. 방문자 표시 기록은 브라우저에서 JavaScript를 끄면 만들어지지 않습니다.

EU 밖으로의 이전에는 EU 집행위원회의 EU–미국 데이터 프라이버시 프레임워크 적정성 결정(Cloudflare, Google, fortrabbit의 하청사 Amazon Web Services)과 표준계약조항(Web3Forms)을 적용합니다. fortrabbit은 웹사이트 데이터를 선택한 EU 지역(아일랜드)에 저장하며, 하청사 Amazon Web Services(미국 법인)가 일부 처리에 관여하는 경우 위 적정성 결정에 따라 보호합니다. 보호 조치의 사본은 contact@ststudio.co.kr로 요청하실 수 있습니다.

8. 쿠키 등 자동 수집 장치와 거부 방법

쿠키는 웹사이트가 브라우저에 저장하는 작은 파일이고, 로컬 스토리지(localStorage)는 브라우저에 설정을 저장하는 비슷한 기술입니다. 스튜디오 웹사이트가 쓰는 것은 다음과 같습니다.

이름종류·제공자목적기간동의
_ga, _ga_H1B3D5BHY9쿠키 · Google Analytics방문 통계(방문자 구분, 세션 유지)동의한 날부터 90일두 가지 동의 후에만 저장
consent.analytics로컬 스토리지 · 스튜디오(브라우저가 로컬 스토리지를 막아 두면 같은 이름의 쿠키)쿠키 선택(두 가지 동의 여부)과 날짜를 기억365일 후 다시 물음필수 기능이라 동의 불필요
lang로컬 스토리지 · 스튜디오직접 고른 언어(KO/EN)를 기억지울 때까지필수 기능이라 동의 불필요
player_clearance, cf_clearance, __cf_bm, _cfuvid쿠키 · Vimeo(제9항)영상 플레이어 보안(자동화 공격 차단)7일, 1년, 30분, 세션보안에 필수라 동의 불필요

로컬 스토리지의 값은 방문자의 기기에만 남고 스튜디오 서버로 보내지 않습니다. 오늘의 방문자 표시와 서버 접속 기록에는 쿠키를 쓰지 않습니다.

거부·철회 방법. 통계 쿠키는 처음 방문할 때 뜨는 창에서 동의하지 않거나 ‘거부’를 누르면 되고, 모든 페이지 하단의 ‘쿠키 설정’에서 언제든 동의를 철회할 수 있습니다. 철회하면 _ga 쿠키를 지우고, 쿠키 설정 창에 내 방문자 식별자를 보여 줍니다. 이미 수집된 통계의 파기를 원하시면 이 식별자를 contact@ststudio.co.kr로 보내 주세요. 요청을 받은 날부터 10일 이내에 Google Analytics의 사용자 삭제 기능으로 파기합니다.

브라우저 설정으로 쿠키와 사이트 데이터를 지우거나 막을 수도 있습니다(버전에 따라 메뉴 이름이 다를 수 있습니다).

  • Chrome: 설정 › 개인정보 보호 및 보안 › 서드 파티 쿠키, 인터넷 사용 기록 삭제
  • Edge: 설정 › 쿠키 및 사이트 권한 › 쿠키 및 사이트 데이터 관리 및 삭제
  • Safari(macOS): 설정 › 개인정보 보호 › 웹사이트 데이터 관리
  • Safari(iPhone): 설정 › 앱 › Safari › 방문 기록 및 웹사이트 데이터 지우기
  • Firefox: 설정 › 개인 정보 및 보안 › 쿠키 및 사이트 데이터
  • 삼성 인터넷: 설정 › 개인정보 보호 및 보안 › 인터넷 사용 기록 삭제

쿠키를 막아도 사이트는 그대로 이용할 수 있습니다.

9. 외부 서비스가 직접 받는 정보

아래 서비스에는 스튜디오가 개인정보를 넘기지 않습니다. 페이지를 여는 순간 방문자의 브라우저가 서체나 영상을 받아 오면서 해당 회사에 직접 정보를 보내며, 각 회사는 자신의 개인정보 처리방침(adobe.com/privacy/policies/adobe-fonts.html, vimeo.com/privacy)에 따라 처리합니다. 스튜디오는 이 정보를 받지 않고, 방문자를 식별하거나 광고에 쓰지 않습니다. GDPR에 따라, 페이지를 열 때 이 정보가 수집·전송되는 부분에 대해서는 스튜디오와 해당 회사가 공동으로 책임지며(작업물을 의도한 서체와 영상으로 보여 줄 정당한 이익, GDPR 제6조제1항 (f)) 이에 관한 권리는 스튜디오나 해당 회사 어느 쪽에든 행사할 수 있습니다. 그 이후의 처리는 각 회사가 책임집니다.

서비스(회사, 국가)불러오는 곳회사가 받는 정보목적
Adobe Fonts(Adobe Systems Software Ireland Limited, 아일랜드 · 처리 국가 미국·인도 포함)
DPO@adobe.com
모든 페이지IP 주소, 브라우저 정보, 페이지 도메인, 사용한 서체와 웹 프로젝트 ID, 그리고 한글 서체를 필요한 글자만 받기 위해 페이지에 필요한 글자 정보(동적 서브셋). 문의 양식에 입력 중인 글자도 보내기 전에 여기에 반영될 수 있으나, Adobe는 글자 묶음 번호만 받고 입력한 문장은 받지 않습니다. Adobe는 이 서비스에서 쿠키를 쓰지 않고 IP 주소를 저장하지 않는다고 밝힙니다.한글 서체(210 MGothic) 제공
Vimeo(Vimeo.com, Inc., 미국)
privacy@vimeo.com
작업 목록(/op/), 모든 작업 페이지(하단 ‘More projects’의 웹 프로젝트 미리보기 영상), Editorial & Web(/editorial-web/), 홈 화면에서 작업을 옆 패널로 열 때IP 주소, 대략적 위치, 브라우저·기기 정보, 사이트 주소. 추적 안 함(dnt=1)으로 설정해 Vimeo가 새 분석용 쿠키를 설정하거나 세션 데이터를 기록하지 않으며, 제8항의 보안 쿠키만 설정될 수 있습니다. 다만 전에 vimeo.com을 방문해 브라우저에 남아 있는 쿠키는 Vimeo로 전송될 수 있습니다.웹 프로젝트 영상·미리보기 재생

이 서비스가 원하지 않으면 브라우저 확장 프로그램 등으로 차단할 수 있습니다. 이 경우 일부 서체나 영상이 보이지 않을 수 있습니다. 두 회사는 EU–미국 데이터 프라이버시 프레임워크 인증을 받았습니다.

10. 안전성 확보 조치

  • 관리적 조치: 개인정보에 접근할 수 있는 사람을 대표 한 명으로 한정하고, 보유 기간이 지난 개인정보를 파기합니다.
  • 기술적 조치: 웹사이트와 문의 양식은 HTTPS로 암호화해 전송합니다. 방문자 표시는 IP 주소를 비밀키로 변환한 해시값만 저장하고, 방문 기록과 함께 외부에서 접근할 수 없게 막은 폴더에 둡니다. 방문 기록은 방문자 표시 해시값과 연결하지 않습니다. 외부 전송을 줄이기 위해 서체(Jost, Space Mono)와 스크립트(three.js)를 스튜디오 서버에서 직접 제공하며, 통계 도구는 동의 전에 불러오지 않습니다.

11. 정보주체의 권리와 행사 방법

정보주체는 언제든 자신의 개인정보에 대해 다음을 요구할 수 있습니다.

  • 열람, 정정·삭제, 처리정지(「개인정보 보호법」 제35조~제37조)와 동의 철회
  • GDPR에 따른 접근, 정정, 삭제, 처리 제한, 반대(정당한 이익을 근거로 한 처리에 대해), 이동(문의 양식·이메일·프로젝트 진행 중 직접 제공한 정보)과 동의 철회 — 스튜디오가 네덜란드에 사업장을 두고 있어 거주 국가와 관계없이 적용됩니다

권리는 contact@ststudio.co.kr로 이메일을 보내 행사할 수 있으며, 요구를 받은 날부터 10일 이내에 조치하고 결과를 알려 드립니다. 요구한 분이 본인이거나 정당한 대리인인지 확인하는 데 필요한 정보를 요청할 수 있습니다. 법정대리인이나 위임받은 사람도 「개인정보 처리 방법에 관한 고시」의 위임장을 갖추어 요청할 수 있습니다. 서버 접속 기록과 방문자 표시 기록은 이름 없이 저장되어, 해당 기록을 찾으려면 접속한 날짜와 IP 주소를 알려 주셔야 합니다. 법률에 따라 요구가 제한되는 경우에는 그 사유와 이의를 제기하는 방법을 함께 알려 드립니다. 통계 쿠키 동의는 사이트 하단 ‘쿠키 설정’에서 바로 철회할 수 있습니다.

12. 개인정보 보호책임자

개인정보 처리에 관한 업무를 총괄하고, 개인정보 관련 문의·불만·피해 구제와 열람 청구를 처리합니다.

  • 개인정보 보호책임자: 옥이랑(대표)
  • 연락처: contact@ststudio.co.kr · 우편:

13. 권익침해 구제 방법

개인정보 침해에 대한 분쟁 조정이나 신고·상담이 필요하면 아래 기관에 문의할 수 있습니다.

  • 개인정보 분쟁조정위원회: (국번 없이) 1833-6972, www.kopico.go.kr
  • 개인정보침해 신고센터(한국인터넷진흥원): (국번 없이) 118, privacy.kisa.or.kr
  • 대검찰청: (국번 없이) 1301, www.spo.go.kr
  • 경찰청 사이버범죄 신고시스템: (국번 없이) 182, ecrm.police.go.kr
  • 네덜란드 개인정보 감독기관(Autoriteit Persoonsgegevens): Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl — EU·EEA에 있는 분은 거주·근무하는 국가의 감독기관에도 민원을 낼 수 있습니다.

14. 그 밖의 사항

  • 개인정보 제공은 의무가 아닙니다. 다만 문의에 답하려면 이름, 이메일 주소, 문의 유형, 메시지가 필요하며, 이메일 주소가 없으면 답할 수 없습니다.
  • 스튜디오 웹사이트는 만 14세 미만 아동을 대상으로 하지 않으며, 아동의 개인정보를 알면서 수집하지 않습니다.
  • 민감정보와 고유식별정보는 처리하지 않습니다.
  • 「개인정보 보호법」 제28조의2에 따른 가명정보 처리(동의 없이 통계·연구 목적으로 쓰는 처리)는 하지 않으며, 자동화된 결정이나 프로파일링을 하지 않습니다.

15. 처리방침의 변경

이 개인정보 처리방침은 2026년 9월 17일부터 적용되는 제2판입니다. 같은 날 공개한 제1판을 다음과 같이 보완했습니다: Google Analytics 수집·이용과 국외 이전 동의를 나눠 받음, ‘그 밖의 문의’의 국외 이전 동의 추가, 보유 기간(세무 기록, 메일 전달 기록, 통계, 문의 양식 사본)과 국외 이전 근거·거부 방법을 구체화, 방문자 표시에서 방문 시각 공개 중단, 외부 서비스(Adobe Fonts, Vimeo)의 설명 보완. 내용이 바뀌면 시행 전에 이 페이지에 알리고, 바뀐 내용과 이전 판을 함께 공개합니다.

STstudio Privacy Policy

Effective 17 September 2026 · Version 2 (see version 1)

This policy explains how STstudio, run by Yirang Ok (“the studio”, “we”), handles personal data through the website www.ststudio.co.kr, its contact form and the address contact@ststudio.co.kr. It is written to meet Article 13 of the EU General Data Protection Regulation (GDPR) and Article 30 of the Korean Personal Information Protection Act (PIPA). We process only the data we need, we do not advertise, and we do not sell personal data. This policy is published in Korean and English; if they differ, the Korean text prevails for the Korean PIPA and the English text for the GDPR.

  1. Who is responsible
  2. What we process, why, and on what legal basis
  3. How long we keep it
  4. How we delete it
  5. Sharing with third parties
  6. Service providers (processors)
  7. Transfers outside the EU and Korea
  8. Cookies and similar storage
  9. Information external services receive directly
  10. Security
  11. Your rights
  12. Privacy contact
  13. Complaints
  14. Other information
  15. Changes to this policy

1. Who is responsible

  • Controller: Yirang Ok (옥이랑), trading as STstudio (생태제작소) — a sole proprietorship (eenmanszaak) in the Netherlands and an individual business (개인사업자) in Korea
  • Netherlands: · KvK 98086030 · VAT ID NL005307209B29
  • Korea: · business registration no. 398-55-00964
  • Email: contact@ststudio.co.kr

We work from the Netherlands and Korea and follow both the GDPR and the Korean PIPA. We have not appointed a data protection officer, because the GDPR (Article 37) does not require one for a studio of this kind; the privacy contact in section 12 handles all privacy questions.

2. What we process, why, and on what legal basis

We use personal data only for the purposes below. If a purpose changes, we will first take the steps the law requires.

a. Processing that does not rely on consent

ActivityDataPurposeLegal basis
Project and collaboration enquiries
(contact form, email)
Required: name, email address, enquiry type, message
Optional: organisation, project type, timeline, budget range
If you email us: your name and address, the message and any attachments
Created when the form is sent: time of sending, IP address, referring page
Reading and answering your enquiry; discussing scope, schedule and an estimate Steps taken at your request before a contract — GDPR Art. 6(1)(b); PIPA Art. 15(1)4
Other enquiries
(contact form, email)
As above Answering your message Collection and use: our legitimate interest in answering messages sent to us — GDPR Art. 6(1)(f); PIPA Art. 15(1)6. Transfer abroad: section 7
Spam screening IP address, email address and time when the form is sent Blocking automated spam Legitimate interest in keeping spam out — GDPR Art. 6(1)(f); PIPA Art. 15(1)6
Contract and tax records
(if an enquiry becomes a project)
Name, organisation, contact details, correspondence, estimates, contracts and invoices Carrying out the contract, invoicing and tax filing, keeping the records the law requires Contract and legal obligation — GDPR Art. 6(1)(b) and (c); PIPA Art. 15(1)4 and 15(1)2
Server access logs IP address, date and time, requested address, response code, referring page, browser and device information (user agent) Delivering the website, detecting and blocking abusive requests, fixing faults Legitimate interest in a working, secure website — GDPR Art. 6(1)(f); PIPA Art. 15(1)6
Today’s visitors
(the dots on the home page)
A hash of your IP address made with a secret server key — the IP address itself is not stored — the time of your first visit that day, and a randomly chosen colour Showing today’s number of visitors as dots on the home page, counting each visitor once a day. The page shows only a colour per visitor; hashes and visit times never leave the server Legitimate interest in this small, first-party design element — GDPR Art. 6(1)(f); no consent is needed under Dutch Telecommunicatiewet Art. 11.7a(3)(b); PIPA Art. 15(1)6
Visit records
(our own count)
IP address, date and time, the page viewed, referring page, browser and device information (user agent), browser language Seeing weekly which projects are read and where visitors come from, so we can improve the site and how we publish work. The summary goes by email to the owner once a week and is never published Legitimate interest in understanding how our own website is used — GDPR Art. 6(1)(f); PIPA Art. 15(1)6

These visit records are separate from Google Analytics. They use no cookies and store nothing on your device, so the cookie banner does not cover them — Dutch Telecommunicatiewet Art. 11.7a applies to storing or reading data on your device. You can object to this processing at any time (section 11), and turning JavaScript off in your browser stops the record being made.

Where we rely on legitimate interest, we do so only where that interest clearly outweighs your rights, is substantially connected to the processing, and stays within a reasonable scope. You can object to it at any time (section 11).

b. Processing based on your consent

ActivityDataPurposeLegal basis
Visit statistics
(Google Analytics 4)
Cookie identifiers (_ga, _ga_H1B3D5BHY9), pages visited and their titles, referring page, time of visit, usage events such as scrolling, browser, operating system, screen size and language, IP address (used by Google only to derive approximate location — country and city — then discarded) Seeing which pages and projects people look at Collection and use: consent — GDPR Art. 6(1)(a) and Dutch Telecommunicatiewet Art. 11.7a(1); PIPA Art. 15(1)1
Transfer abroad: separate consent — PIPA Art. 28-8(1)1
Transfer abroad of other enquiries
(contact form)
Name, email address, organisation, message, IP address Delivering your enquiry to us Consent box on the contact form — PIPA Art. 28-8(1)1

Google Analytics is loaded only after you tick both “collection and use” and “transfer abroad” in the cookie notice and press “Allow”; until then nothing is sent to Google. Before you choose, the notice shows the data, the recipient and countries, how it is sent, and how long it is kept. Declining does not limit your use of the site in any way. We have switched off Google signals (cross-device tracking) and ad personalisation.

3. How long we keep it

DataRetention
Enquiries that do not lead to a project (our mailbox)One year after the last message, so we can see an earlier conversation if you write again; then deleted
The copy held by our form provider (Web3Forms)Deleted automatically at most three years after submission, under Web3Forms’ default policy. Enquiries that do not lead to a project may remain there for that time; if you ask, we ask Web3Forms to delete yours
Email delivery records (Cloudflare)Sender and recipient addresses, subject and result kept 31 days; message bodies are not stored
Contract and invoice recordsSeven years from the statutory filing deadline for the transaction (Korean Framework Act on National Taxes Art. 85-3(2): 5 years, 7 for cross-border transactions · Dutch Algemene wet inzake rijksbelastingen Art. 52: 7 years)
Server access logsThe period our host fortrabbit states: it does not store visitors’ IP addresses or access data for more than 30 days
Today’s-visitor hashesEarlier days are deleted automatically at the first visit recorded on a later day (usually the next day)
Visit records (our own count)12 months. They are kept in monthly files, and the server deletes a month once it falls outside that window
Google Analytics statisticsVisit- and event-level data linked to the cookie identifier: at most 14 months (Google Analytics retention setting). Aggregated statistics that identify no one, such as visits per page, may be kept longer. The _ga cookies expire 90 days after consent
Settings stored on your device (language, cookie choice)Until you clear them in your browser; we ask for your cookie choice again after 365 days

4. How we delete it

When data reaches the end of its retention period or is no longer needed, it is deleted without delay. Email and documents we hold ourselves are identified and deleted by the owner: electronic files are deleted so they cannot be recovered, including emptying the trash, and printouts are shredded. Server logs, today’s-visitor records, email delivery records and the form provider’s copy are deleted automatically by those systems at the end of the periods in section 3. Records the law requires us to keep are stored separately from other personal data.

5. Sharing with third parties

We do not give personal data to third parties, except where the law requires or specifically permits it (Korean PIPA Articles 17 and 18; GDPR Article 6(1)(c)). When a contract is signed, tax law requires us to report transactions to the tax authorities (Korea’s National Tax Service, the Dutch Belastingdienst), including the client’s trade name, representative’s name, business registration or VAT number and the amount.

6. Service providers (processors)

ProviderWhat they do for us
Web3Creative, operator of Web3Forms (India)Receives the contact form, screens it for spam and emails it to us
Sub-processors: Amazon Web Services, Inc. (hosting, email delivery), Cloudflare, Inc. (network security), Hetzner Online GmbH (servers), CleanTalk Inc. and Automattic Inc. / Akismet (spam checks), Microsoft Corporation (Clarity, dashboard usage recording), SparrowDesk (customer support)
Cloudflare, Inc. (USA)Receives and forwards email sent to contact@ststudio.co.kr; message bodies are not stored
Sub-processors: cloudflare.com/gdpr/subprocessors
Google (Gmail — Google LLC, or Google Ireland Limited depending on the account)Stores enquiry emails
fortrabbit GmbH (Germany; servers at Amazon Web Services in Ireland)Hosts the website, keeps server access logs, stores the today’s-visitor records and the visit records
Sub-processors: fortrabbit.com/legal/data-protection/sub-processors
Google Ireland Limited (Ireland) and Google LLC (USA)Visit statistics (Google Analytics), only with your consent
Sub-processors: business.safety.google/subprocessors

Web3Forms, Cloudflare, fortrabbit and Google Analytics are bound by data processing terms, which limit use to our instructions, require appropriate security, restrict further sub-processing and set out liability. Gmail is used under Google’s standard terms. If a provider changes, we update this policy.

7. Transfers outside the EU and Korea

Because we work from both the Netherlands and Korea and use the providers above, personal data is transferred across borders as follows. Every transfer is an encrypted transmission over the internet (HTTPS/TLS).

Recipient (contact)CountriesDataWhenPurpose · retentionSafeguard / basis
Web3Creative — Web3Forms
support@web3forms.com
India, USA, Germany, Finland and the countries of Cloudflare’s data centres (cloudflare.com/network)All contact-form fields, IP address, time sent, referring pageWhen the form is sentReceiving, spam screening, forwarding · at most 3 yearsGDPR: EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in Web3Forms’ DPA · PIPA: project and collaboration enquiries Art. 28-8(1)3; other enquiries Art. 28-8(1)1 (consent on the form)
Cloudflare, Inc.
dpo@cloudflare.com
USA and the countries of Cloudflare’s data centres (cloudflare.com/network)Sender name and address, recipient address, subject, message body (only while forwarding), delivery resultWhen an email arrivesForwarding email · bodies not stored; delivery records 31 daysGDPR: EU–U.S. Data Privacy Framework (Art. 45) · PIPA: project and collaboration enquiries Art. 28-8(1)3; other enquiries via the form Art. 28-8(1)1
Google — Gmail
support.google.com/policies/troubleshooter/7575787
USA and the countries of Google’s data centres (datacenters.google/locations)The full enquiry emailWhen the email is forwardedStoring enquiry emails · as in section 3GDPR: EU–U.S. Data Privacy Framework (Art. 45) · PIPA: project and collaboration enquiries Art. 28-8(1)3; other enquiries via the form Art. 28-8(1)1
fortrabbit GmbH
info@fortrabbit.com
Ireland (EU)Server access logs, today’s-visitor hashes, visit recordsOn every visitHosting · logs at most 30 days; hashes deleted at the first visit of a later day; visit records 12 monthsGDPR: within the EU · PIPA Art. 28-8(1)5 (Korean PIPC recognition of the EU)
Google Ireland Limited and Google LLC — Google Analytics
support.google.com/policies/troubleshooter/7575787
Ireland, the USA and the countries of Google’s data centres (datacenters.google/locations)The visit-statistics data in section 2bOn each page view after you give both consentsVisit statistics · visitor-level data at most 14 months (aggregates excluded)GDPR: EU–U.S. Data Privacy Framework (Art. 45; Google LLC is certified) · PIPA Art. 28-8(1)1 (separate consent)

How to refuse, and what happens.

  • Google Analytics: leave the consents unticked or press “Decline” and nothing is transferred, with no disadvantage.
  • Contact form: “Something else” enquiries can be sent only after ticking the form’s consent to the transfer abroad. If you do not want to, or prefer not to use the form, email contact@ststudio.co.kr directly — nothing then goes to Web3Forms (India etc.). Email passes through Cloudflare and Google (USA); if you do not want that either, write to our Netherlands address by post.
  • Website hosting (fortrabbit, Ireland): needed to deliver the pages, so it cannot be refused separately; if you prefer, contact us by post instead of using the website. Today’s-visitor records are not created if JavaScript is switched off in your browser.

For transfers outside the EU we rely on the European Commission’s EU–U.S. Data Privacy Framework adequacy decision (Cloudflare, Google, and Amazon Web Services as fortrabbit’s subcontractor) and on Standard Contractual Clauses (Web3Forms). fortrabbit stores the website’s data in the EU region we chose (Ireland); where its subcontractor Amazon Web Services (a US company) takes part in processing, the same adequacy decision applies. You can ask us for a copy of the safeguards at contact@ststudio.co.kr.

8. Cookies and similar storage

A cookie is a small file a website stores in your browser; local storage (localStorage) is a similar way to keep a setting in your browser. This site uses:

NameType · providerPurposeLifetimeConsent
_ga, _ga_H1B3D5BHY9Cookie · Google AnalyticsVisit statistics (telling visitors apart, keeping a session)90 days from consentSet only after both consents
consent.analyticsLocal storage · STstudio (a first-party cookie of the same name where the browser blocks local storage)Remembers your cookie choices (both consents) and when you made themAsked again after 365 daysNot needed — strictly necessary
langLocal storage · STstudioRemembers the language (KO/EN) you pickedUntil you clear itNot needed — strictly necessary
player_clearance, cf_clearance, __cf_bm, _cfuvidCookies · Vimeo (section 9)Security of the video player (blocking automated attacks)7 days, 1 year, 30 minutes, sessionNot needed — strictly necessary for security

Local-storage values stay on your device and are never sent to our server. The today’s-visitor dots, the visit records and the server logs use no cookies.

Refusing or withdrawing. Leave the consents unticked or press “Decline” in the notice on your first visit, and withdraw at any time with “Cookie settings” at the bottom of every page. Withdrawing deletes the _ga cookies and shows your Analytics identifier in the cookie settings; send it to contact@ststudio.co.kr and we delete the statistics already collected with Google Analytics’ user-deletion tool within 10 days of your request. Withdrawal does not affect the lawfulness of processing before it.

You can also delete or block cookies and site data in your browser settings (menu names vary by version): Chrome — Settings › Privacy and security; Edge — Settings › Cookies and site permissions; Safari on Mac — Settings › Privacy › Manage Website Data; Safari on iPhone — Settings › Apps › Safari › Clear History and Website Data; Firefox — Settings › Privacy & Security › Cookies and Site Data; Samsung Internet — Settings › Privacy and security › Delete browsing data. The site keeps working if you block cookies.

9. Information external services receive directly

We do not pass personal data to these services. When a page opens, your browser fetches a typeface or video from them and in doing so sends them some information directly; each company handles it under its own privacy policy (adobe.com/privacy/policies/adobe-fonts.html, vimeo.com/privacy). We do not receive that information and do not use it to identify you or for advertising. Under the GDPR we are jointly responsible with each company for collecting and transmitting it when the page loads (our legitimate interest in showing the work with its intended typefaces and videos, Art. 6(1)(f)), and you can exercise your rights about it with us or with them; for anything they do afterwards, they alone are responsible.

Service (company, country)Where it loadsWhat the company receivesPurpose
Adobe Fonts (Adobe Systems Software Ireland Limited, Ireland; processing also in the USA and India)
DPO@adobe.com
Every pageIP address, browser information, the site’s domain, the fonts and web-project ID used, and — so that only the Hangul glyphs a page needs are delivered — which characters the page needs (dynamic subsetting). Characters being typed into the contact form can count towards this before it is sent, but Adobe receives only the numbers of glyph groups, not the text. Adobe states that this service sets no cookies and does not store the IP address.Serving the Korean typeface (210 MGothic)
Vimeo (Vimeo.com, Inc., USA)
privacy@vimeo.com
The work index (/op/), every project page (the “More projects” previews of web projects), Editorial & Web (/editorial-web/), and the home page when a project is opened in its side panelIP address, approximate location, browser and device information, the site’s address. The player runs with “do not track” (dnt=1), so Vimeo sets no new analytics cookies and records no session data; only the security cookies in section 8 may be set. Cookies your browser already holds from earlier visits to vimeo.com may still be sent to Vimeo.Playing web-project videos and previews

If you prefer, you can block these services with a browser extension; some typefaces or videos may then not appear. Adobe and Vimeo are certified under the EU–U.S. Data Privacy Framework.

10. Security

  • Organisational: only the owner has access to personal data, and data past its retention period is deleted.
  • Technical: the website and the contact form are served over HTTPS. The today’s-visitor feature stores only a keyed hash of the IP address, in a folder that cannot be reached from the web. To reduce transfers, the Jost and Space Mono typefaces and the three.js script are served from our own server, and the statistics tool is not loaded before consent.

11. Your rights

You can ask us at any time to:

  • give you access to your personal data, correct it, delete it, or restrict its processing;
  • stop processing that relies on legitimate interest (objection);
  • give you the data you provided to us — through the contact form, by email or for a project — in a structured, commonly used, machine-readable format, or send it to another organisation where technically feasible;
  • and you can withdraw consent at any time.

Email contact@ststudio.co.kr. We act on your request and tell you the result within 10 days of receiving it; if we need to confirm that you are the person concerned or their authorised representative, we ask for what we need within that time. Server logs and today’s-visitor records carry no names, so to find them we need the date of your visit and your IP address. If the law limits a request, we tell you why and how to challenge the decision. Statistics consent can be withdrawn immediately under “Cookie settings”.

12. Privacy contact

Yirang Ok, owner, is responsible for personal data at the studio and handles questions, complaints and access requests: contact@ststudio.co.kr · post: .

13. Complaints

You can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl), or to the authority in the EU/EEA country where you live or work. In Korea you can contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the Privacy Infringement Report Center at KISA (118, privacy.kisa.or.kr), the Supreme Prosecutors’ Office (1301, spo.go.kr) or the National Police Agency’s cyber crime reporting system (182, ecrm.police.go.kr).

14. Other information

  • Nobody is required to give us personal data. To answer an enquiry we need a name, an email address, the enquiry type and a message; without an email address we cannot reply.
  • The website is not aimed at children under 14, and we do not knowingly collect their data.
  • We do not process special categories of data or national identification numbers.
  • We do not process pseudonymised data under the special regime of PIPA Article 28-2, and we make no automated decisions and build no profiles.

15. Changes to this policy

This is version 2, effective 17 September 2026. It revises version 1, published the same day: separate consents for Google Analytics’ collection and its transfer abroad; a transfer consent for “Something else” enquiries; more precise retention periods (tax records, email delivery records, statistics, the form provider’s copy) and transfer bases and refusal options; visit times no longer published by the today’s-visitor feature; clearer information on Adobe Fonts and Vimeo. If it changes again, we will announce the change on this page before it takes effect and publish what changed together with the previous version.

Work Editorial & Web About Contact Privacy Policy개인정보 처리방침 Cookie settings쿠키 설정

© 2026 STstudio

STstudio생태제작소(STstudio) · Owner Yirang Ok대표 옥이랑 · contact@ststudio.co.kr

· KvK 98086030 · VAT IDVAT ID(btw-id) NL005307209B29

· KR business reg. no.사업자등록번호 398-55-00964