top of page

Privacy Policy

​Notice Date: June 22, 2026

'Skylabs Co., Ltd.' (hereinafter "Company") values the personal information of users and strives to comply with the Personal Information Protection Act and other relevant laws and regulations.

Through this Privacy Policy (hereinafter "Policy"), the Company informs users of how personal information collected from users in the course of providing the CART BP Pro service (hereinafter "Service") is used and what measures are taken to protect personal information.

1. Purpose of Processing Personal Information

The Company processes personal information for the following purposes. The personal information being processed will not be used for any purpose other than the following, and if the purpose of use changes, necessary measures such as obtaining separate consent will be taken in accordance with Article 18 of the Personal Information Protection Act.

1) Hospital Registration and Management

Personal information is processed for the purpose of verifying hospital physicians at the time of registration, and subsequently for hospital identification, hospital account creation, and maintenance of service eligibility.

2) Service Provision

Personal information is processed for the purpose of providing patient measurement results, supporting medical staff in patient monitoring, and operating the service.

3) Customer Support and Complaint Handling

Personal information may be processed for the purpose of responding to inquiries, handling failures, delivering notices, resolving disputes, and providing service operation-related support.

4) Service Security and Stability

Service usage records and log information may be processed for the purpose of preventing unauthorized use, detecting unauthorized access, managing access records, conducting system security inspections, and analyzing and recovering from failures.

5) Research and Service Improvement

Collected information may be processed after pseudonymization for the purpose of statistical compilation, scientific research, internal algorithm advancement, and service quality improvement.

2. Legal Basis, Items, and Retention Period for Processing Personal Information

The Company processes and retains personal information within the personal information retention and use period stipulated by law or the personal information retention and use period agreed upon at the time of collection from the data subject.

2-1. Personal Information Processed with Consent of the Data Subject

The company is processing the following personal information with the consent of the user.

Processing Purpose

Hospital Registration

and Processing

Service Provision

Items Processed

  • Email address

General Personal Information

  • Patient ID

  • Patient Date of Birth

  • Patient mobile phone number

Sensitive Information

  • Medical visit time data

  • PPG biometric measurement data (blood pressure, pulse rate, irregular pulse)

  • Acceleration sensor data collected from CART Ring

  • Cuff-type blood pressure monitor data (for blood pressure calibration)

  • Sleep time entered by the user

Retention/Use Period

  • Until the hospital's service termination date

  • Until hospital's service termination date

CART-Ring Connection

(BLE Connection)

CART-Ring Information

  • Device Name

  • MAC Address

  • Firmware Version

  • Log

Location Information

  • Location of mobile device with app installed (precise location, always allow)

  • Until the hospital's service termination date
    * Location information is not stored and is used solely for CART Ring connection purposes.

2-2. Personal Information Processed Without Consent of the Data Subject

The Company may process personal information without the consent of the data subject in accordance with relevant laws and regulations, including each subparagraph of Article 15(1) of the Personal Information Protection Act, in the following cases.

Category

Service Operation and Security

Customer

Inquiry Response

Purpose of Processing

Service access control, anomaly detection, failure response, system protection, access record management

Confirmation of inquiry content, response, dispute prevention

Processing Items

  • Access date and time

  • Service usage records

  • Device OS information

  • App version

  • Error logs

  • Name

  • Email

  • Contact information

  • Inquiry content (information provided by the user)

Retention and use period

Period pursuant to relevant laws or internal policy

Period required after completion of inquiry processing pursuant to relevant laws

Legal Basis

Performance of contract, compliance with legal obligations, legitimate interests

Performance of contract or legitimate interests

3. Detailed Description of Personal Information Items Processed

Personal information processed by the Company may be categorized as general personal information, sensitive information, and device/log information.

General Personal Information: Email address, patient number, date of birth, mobile phone number, hospital contact person information, etc.

1. Sensitive Information: Medical visit time data related to health status and biometric signals, blood pressure, pulse rate, irregular pulse, blood pressure calibration measurement data, sleep time, etc.

2. Device/Log Information: Device Name, MAC address, firmware version, app/system logs, access IP, access date and time, device model name, OS information, error logs, etc.

When processing sensitive information such as health data, the Company processes only the minimum amount necessary, either by obtaining separate consent pursuant to Article 23 of the Personal Information Protection Act or only where permitted by law.

4. Methods of Collecting Personal Information

The Company may collect personal information through the following methods:

  • Direct input by the user or hospital contact person during the course of using the service

  • Submission via document, email, telephone, or message during hospital registration, customer inquiries, technical support, contracts, or service operations

  • Automatic collection of log information generated during service access and use

5. Provision of Personal Information to Third Parties

The Company processes the personal information of data subjects only within the scope specified for the purpose of processing personal information. Personal information is provided to third parties only in cases falling under Article 17 and Article 18 of the 「Personal Information Protection Act」, such as with the data subject's consent or under special provisions of law. Personal information is not provided to third parties for any other purposes.

The Company will obtain the data subject's consent and provide personal information only to the minimum necessary extent in the following cases to ensure smooth service provision.

6. Provision of Personal Information to Third Parties

The Company processes personal information of data subjects only within the scope specified in the purposes of processing personal information, and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as the consent of the data subject or special provisions of law.

The Company provides information only to the minimum extent necessary with the consent of the data subject when required for the smooth provision of services.

Currently, the Company does not, in principle, sell or provide for commercial purposes the personal information of patients and hospital contact persons to external third parties. If third-party provision becomes necessary with the consent of the data subject in the future, the recipient, purpose of provision, items provided, and retention and use period will be specifically disclosed in the Privacy Policy or a separate consent form.

In cases where personal information is processed and provided in a form that cannot identify a specific individual for the purpose of statistical compilation, scientific research, or preservation of records in the public interest, it may be processed within the scope permitted by relevant laws.

7. Entrustment of Personal Information Processing

The Company entrusts personal information processing to external specialized companies as follows. Entrustment of personal information processing is carried out for each individual service only to the extent necessary for its fulfillment. If the content of entrusted work or the trustee changes, such changes will be disclosed through this Privacy Policy without delay.

Name of Trustee

MetaM Co., Ltd.

NAVER Cloud

Content of Entrusted Work

Customer center CS response and processing

Cloud services and web service provision for the Company's service delivery

8. Cross-Border Transfer of Personal Information

The Company processes personal information within the Republic of Korea in principle and does not transfer personal information overseas without a legal basis or separate consent of the data subject.

However, if cross-border transfer occurs in the course of technical operation of cloud or collaborative infrastructure used by the Company, the recipient, country of transfer, date and method of transfer, items transferred, purpose of transfer, retention and use period, and methods for the data subject to refuse will be separately disclosed in accordance with relevant laws, and prior consent will be obtained where necessary.

9. Procedures and Methods for Destruction of Personal Information

The Company destroys personal information without delay when it becomes unnecessary, such as when the purpose of collection and use of personal information is achieved or when a user withdraws membership. However, if personal information must continue to be retained pursuant to relevant laws after the purpose is achieved, the personal information will be moved to a separate DB or stored in a different location.

Destruction Procedure

Destruction Method

Personal information collected during the service use process is immediately destroyed when the purpose of processing is achieved or the retention period pursuant to relevant laws has elapsed.

Personal information stored in electronic file format is deleted using technical methods that prevent the reproduction of records. Personal information printed on paper is destroyed by shredding or incineration.

9-1. Retention Pursuant to Relevant Laws

Legal Basis

Act on Consumer Protection in Electronic Commerce

Act on Consumer Protection in Electronic Commerce

Items Retained

Records related to consumer complaints or dispute resolution

Records related to labeling and advertising

Retention Period

​3 years

6 months

Protection of Communications Secrets Act

Access records including login records

​3 months

9-2. Retention Pursuant to Internal Policy

The Company may separately retain certain information for a certain period pursuant to internal policy, to the extent not contrary to relevant laws, for the purpose of service stability, user protection, complaint response, and security inspection. In such cases, the purpose, items, and period of retention are determined and operated to the minimum extent necessary.

10. Rights and Obligations of Users, Methods of Exercise, and Related Precautions

Access · Correction · Deletion · Suspension of Processing

Withdrawal of Consent Regarding Personal Information

Precautions for Users Regarding Personal Information

Users may at any time access, correct, delete, or request suspension of processing of their personal information collected and used by the Company. If a user wishes to access, correct, delete, or request suspension of processing of their personal information, they may contact the Company's Personal Information Protection Officer in writing, by telephone, or by email, and the Company will take action without delay. Users may also exercise their rights through a legal representative or an authorized agent. In such cases, a power of attorney in accordance with Annex Form No. 11 of the "Notice on Methods of Processing Personal Information" must be submitted. If a user has requested correction of errors in their personal information, the Company will not use the relevant personal information until the correction is completed. However, the Company may refuse access or correction in any of the following cases:

  • Where there is a significant risk of harm to the life, body, property, or interests of the user or a third party

  • Where there is a significant risk of interference with the Company's business operations

  • Where it is contrary to law

Users may withdraw their consent to the collection, use, and provision of personal information at any time. If you contact the Personal Information Protection Officer in writing, by telephone, or by email, the Company will take necessary measures such as destroying your personal information without delay. The Company will take necessary measures to make withdrawal of consent to the collection of personal information easier than the method of collecting personal information.

Users have the right to have their personal information protected, as well as the obligation to protect themselves and not to infringe upon the information of others. Users are requested to enter their personal information accurately and keep it up to date to prevent unexpected incidents. Responsibility for incidents caused by inaccurate information entered by the user lies with the user themselves, and there may be disadvantages for entering false information such as misappropriating another person's information. Please be careful not to damage the personal information of others, including posts.

11. Measures to Ensure the Safety of Personal Information
1) In processing users' personal information, the Company takes the following technical, administrative, and physical measures to ensure safety against loss, theft, leakage, alteration, or damage:

(1) Administrative Measures: Establishment and implementation of internal management plans, operation of dedicated organizations, regular employee training

(2) Technical Measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of personal information, installation and updating of security programs

(3) Physical Measures: Access control for server rooms, data storage rooms, etc.

2) In addition to the matters stipulated by law, the Company carries out the following activities to ensure the safety of personal information:

(1) Acquisition of domestic and international personal information protection certifications: ISO/IEC 27701

12. Installation and Operation of Automatic Personal Information Collection Devices and Opt-Out

The Company does not operate devices that automatically collect user information within the service.

13. Processing of Pseudonymized Information

The Company may process collected personal information after pseudonymization so that specific individuals cannot be identified, for the purpose of statistical compilation, scientific research, and preservation of records in the public interest. Entrustment of pseudonymized information processing and provision to third parties will not be carried out.

Pseudonymized information is separately stored and managed to prevent re-identification, records of pseudonymized information processing are prepared and retained, and necessary technical, administrative, and physical protective measures are taken, such as access control for server rooms and data storage rooms where pseudonymized information is stored.

Category

Research for Service Improvement

Purpose of Processing

Algorithm advancement for internal service research

Processing Items

Sensitive Information

  • PPG biometric measurement data (blood pressure, pulse rate, irregular pulse)

  • Acceleration sensor data collected from CART Ring

  • Cuff-type blood pressure monitor data (for blood pressure calibration)

  • Sleep time entered by the user

Retention and use period

Until the research purpose is achieved

14. Personal Information Protection Officer

The Company has designated a Personal Information Protection Officer as follows to protect users' personal information and handle complaints related to personal information.

Personal Information Protection Officer

Name

Position

Contact

Acdress

Email

Minsoo Jang

Executive Director

1599-3402

703, 58, Pangyo-ro 255beon-gil, Bundang-gu, Seongnam-si, Gyeonggi-do

Users may report all personal information protection-related complaints arising from the use of the Company's services to the Personal Information Protection Officer. The Company will provide prompt responses to users' reports.

15. Requests for Access to Personal Information

Data subjects may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the following department. The Company will endeavor to process data subjects' requests for access to personal information promptly.

Privacy Officer

Name

Position

Contact

Email

Sangyoon Park

-

1599-1921

16. Remedies for Infringement of Personal Information Rights

Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, etc. to receive relief for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following organizations.

Personal Information Dispute Mediation Committee

Personal Information Infringement Report Center

Supreme Prosecutors' Office Online Civil Affairs Office

National Police Agency Cyber Safety Bureau

Website

Contact

Website

Contact

Website

Contact

Website

Contact

1833-6972

118

1301

182

17. Other Personal Information Processing-Related Policies

Link Site Provision Policy

Policy on Refusal of Unauthorized Collection of Email Addresses

Transmission of Advertising Information

Changes to This Policy

The Company may provide links to websites or materials provided by other companies through the service. In this case, as the Company has no control over external sites and materials, it cannot be held responsible for or guarantee the usefulness of services or materials provided therefrom. If you click a link posted on the Company's service and move to another website, the personal information of that site is processed in accordance with a separate privacy policy unrelated to the Company, so please review the policy of that site.

The Company refuses the unauthorized collection of posted email addresses using email collection programs or other technical devices.

The Company does not transmit commercial advertising information contrary to the explicit refusal of users to receive such information. If a user has consented to the transmission of emails such as product information notices and newsletters, the Company will take measures to ensure that the user can easily identify this in the subject line and body of the email.

This Policy was revised on June 22, 2026, and content may be added, deleted, or modified in accordance with changes in laws, policies, or security technologies. In the event of additions, deletions, or modifications, the reasons for and content of changes to the Privacy Policy will be announced through the website at the time of implementation. In the event of important changes such as changes to third-party provision of personal information, changes to the purpose of collection and use, or changes to the retention period, consent will also be obtained from users in addition to the announcement.

This Policy shall take effect from June 22, 2026.
bottom of page