GLEAP

Privacy Policy

Privacy Policy

SNU College of Natural Sciences GLEAP processes personal information only to the extent necessary to operate its website and member services. This policy explains how that information is handled and protected.

Effective · August 30, 2026Beta policy · Updated whenever the actual processing structure changes.

1. Controller and privacy contact

Operator: SNU College of Natural Sciences GLEAP

Privacy and grievance contact: GLEAP Operations · snucnsgleap@gmail.com

This section will be updated first whenever the name of the privacy officer or the responsible team and contact details change.

2. Information, purposes and retention

CategoryInformationPurposeRetention
Public member profileName, cohort, department, role, photo, consented email and linksIntroduce members and activitiesFor the consented publication period or until withdrawal
Account and approvalName, email, hashed password, approval status and role, sign-up and update timestampsMember verification, sign-in and access controlUntil account deletion or membership approval ends; longer only when retention is required by law
Member profile and communityBio, interests, optional social links, posts, comments and reactionsMember directory and communityUntil deleted by the member or account deletion
Session and securitySession token, IP address, User-Agent, access and update timestampsAuthentication, security and abuse preventionUntil session expiry or account deletion
Operational activityMember identifier, administrative action, target type and identifier, timestampReview access changes and operational actionsNormally one year from creation, followed by periodic deletion by the operators
Email inquiriesSender email, inquiry, attachments and reply historyReceive and answer inquiries and respond to disputesOne year after resolution or until an earlier deletion request; longer only when legally required

Plain-text passwords are not stored; the authentication system retains only one-way hashed values. Optional fields are not required to use the core member functions.

3. Sources and legal basis

  • Information needed for member services and account management is provided directly during sign-up, sign-in and profile editing.
  • Public member information and event photos are posted only after the data subject's consent or another valid permission has been confirmed.
  • Sign-in sessions and security records may be created automatically while the service is used.
  • You may decline to provide required information, but GLEAP may then be unable to provide sign-in or member-only functions.

4. Third-party disclosure

GLEAP does not provide personal information to third parties unless the data subject has separately consented or disclosure is permitted by law. If disclosure becomes necessary, GLEAP will provide advance notice of the recipient, purpose, information involved, retention period and the right to refuse.

5. Processors and cloud services

ProviderServiceScope
Vercel Inc.Hosting, deployment, security and server logs; administrator image storage when enabledRequest data, access/error logs and uploaded images
Neon, Inc.PostgreSQL database hostingAccounts, profiles, community and operational records

Authentication is handled on GLEAP servers using Better Auth software, while account and session information is stored in the Neon database described above. No separate email delivery provider is currently connected to production. Before Gmail, Resend or another provider is activated, the processor and international-transfer sections of this policy will be updated.

6. International processing

Vercel and Neon are global cloud providers based outside Korea. During service operation, the information described in the processor table may therefore be transmitted over encrypted networks and processed on overseas servers. Transfer occurs continuously over the network while the service is used, and retention lasts for the periods stated in Section 2 or until the applicable service contract ends.

The operators must confirm the actual data-storage country and region, as well as the legal basis for international transfer under Korean privacy law, in the Vercel and Neon consoles and contracts. Before a region or processor changes, this policy will be revised and any required notice or consent process will be completed.

7. Cookies and analytics

  • An essential gleap_session cookie is used for administrator authentication, and an essential member session cookie is used for member sign-in.
  • Blocking essential cookies may prevent sign-in.
  • The current code does not include advertising cookies or third-party behavioral analytics.
  • Vercel may process platform access and error logs for security and reliability.

8. Your rights

You or your lawful representative may request access, correction, deletion, restriction of processing, withdrawal of consent or account deletion at snucnsgleap@gmail.com. GLEAP may request the minimum information needed to verify identity and will process the request without undue delay in accordance with applicable law.

When removal of a publicly displayed name, photograph or email address is requested, GLEAP will first remove it from the public page. The information may remain in backups or caches for a short period when technically necessary.

9. Deletion and safeguards

  • Personal information is deleted without undue delay and in a manner that makes recovery difficult when its purpose has been achieved or its retention period ends.
  • Account and administrative privileges are limited to the minimum number of people, and the administrator and member areas are separated.
  • GLEAP uses HTTPS, one-way password hashing, protected session cookies and access-record reviews.
  • Printed documents and separate consent forms, if any, are kept in a locked location and shredded when their retention period ends.

10. Remedies and inquiries

  • GLEAP privacy contact: snucnsgleap@gmail.com
  • Privacy Infringement Report Center: 118 (without an area code in Korea)
  • Personal Information Dispute Mediation Committee: 1833-6972

11. Effective date and revision history

First effective date: August 30, 2026

Revision history: Beta policy adopted on August 30, 2026

Material changes will be announced on the website before they take effect. Previous versions will be retained by the operators and made available upon request.

Official references