Privacy policy
Effective 22 September 2026. This policy explains how Zafara, operating from 346, Hyoryeong-ro, Seocho-gu, Seoul, 06775, handles information when you visit this editorial site. It applies to readers, contributors and people who contact the publication. The site is designed for information and learning, not financial services.
1. Scope
This document covers pages, forms, cookies and ordinary correspondence. It does not govern third-party sites linked from an article. Those services publish their own notices. We ask readers not to send sensitive financial credentials through the contact form.
2. Information collected
We may receive a name, email address and message when a reader contacts us. Our hosting environment may record an IP address, browser type, time and requested page. We do not ask for wallet keys, passwords or payment details. Optional information is provided by choice.
3. Legal basis
We process correspondence to respond to an enquiry and administer editorial work. We rely on legitimate interests for security and basic audience measurement where permitted. Consent is used for optional cookies. You may withdraw consent by changing your cookie choice or contacting us.
4. Retention
Contact correspondence is normally retained for 24 months after the last meaningful exchange. Security logs are retained for up to 90 days. Correction records may remain with the published article for accountability. When a period ends, information is deleted or aggregated.
5. Cookies
Essential session functions may use a session cookie that expires when the browser closes. The cookieChoice preference is stored for 180 days. Optional analytics identifiers, if enabled, have a maximum lifespan of 13 months. Details appear on the cookies page.
6. Processors
Hosting, security and email infrastructure providers may process limited data on our instructions. Providers are selected for appropriate contractual and technical safeguards. We do not sell reader information. A processor may change as the publication's technical needs change.
7. International transfers
Some infrastructure providers may operate outside the Republic of Korea. Where information crosses borders, we seek contractual safeguards and limit the data shared. We retain only what is needed for the stated purpose. Contact us for the current provider categories.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or an explanation of processing. You may object to certain legitimate-interest processing. Requests should identify the relevant correspondence without sending identity documents by email unless requested securely. We aim to respond within 30 days.
9. Complaints and contact
Questions can be sent to +82-2-7143-6987 or by post to 346, Hyoryeong-ro, Seocho-gu, Seoul, 06775. We will investigate and explain the outcome. You may also contact the relevant Korean privacy authority. We do not retaliate against a privacy complaint.
10. Changes
This policy was reviewed on 22 September 2026. Future material changes will be dated at the top of this page. Older versions may be requested for a reasonable period. Continued use after a change does not remove rights that apply under law.
Operational details and reader rights
For clarity, ordinary browsing may produce technical request data such as an IP address, device category, referrer and approximate access time. We use this information to deliver pages, investigate abuse and understand whether links function correctly. We do not use it to infer wallet ownership, asset balances or investment intent. A contact message is reviewed only by people who need it for correspondence or editorial administration.
In Korea, requests are handled with reference to applicable privacy requirements, including the Personal Information Protection Act where relevant. A reader may ask what personal information is held, request correction, ask for deletion where retention is not required, or object to a particular use. Requests should include enough detail to locate the record, but should not include passwords, private keys or identity documents unless a lawful verification step is specifically agreed.
We normally acknowledge a privacy request within seven business days and aim to provide a substantive response within 30 days. A more complex request may require an additional period, in which case we explain the reason and expected timing. Identity checks are proportionate and are used to prevent disclosure to the wrong person. A reader may also contact the Personal Information Protection Commission of Korea if the concern is not resolved.
Service providers and transfers
Zafara may rely on a hosting provider, email delivery service, security logging provider and limited analytics provider. Each provider receives only the information needed for its documented function and is expected to protect it under a written or equivalent contractual arrangement. Providers may process information outside Korea, including in regions where their infrastructure operates. Where information leaves Korea, we consider applicable transfer requirements and use contractual, technical and organizational safeguards.
We do not sell personal information. We do not exchange contact messages for advertising lists. If a legal request, safety incident or dispute requires preservation, relevant records may be retained beyond the ordinary period while that matter is active. The retained material is restricted and deleted when the reason for preservation ends.
Updates and contact
This policy was published on 22 September 2026 and may be reviewed when the site, vendors or legal requirements change. The effective date at the top will identify the current version, while material changes will be described in the revision record. Questions can be sent to the Zafara editorial desk at 346, Hyoryeong-ro, Seocho-gu, Seoul, 06775, or by phone at +82-2-7143-6987.
For practical purposes, technical data is collected when a browser requests a page, loads a stylesheet or submits a form. This may include an IP address, browser family, operating system, referring page and approximate time. These details help identify failed requests, abusive traffic and broken links, but they are not used to infer wallet ownership, asset balances or investment intent. A reader who sends a message may choose a name and email address, while a telephone number is not required unless the reader elects to provide it.
The legal basis depends on the purpose and the context of the activity. Responding to a voluntary enquiry is necessary for correspondence, while security processing supports the legitimate interest of keeping the publication available and protecting forms. Optional audience measurement is used only where the reader has made an informed choice. A withdrawal of consent affects future optional processing and does not invalidate processing that occurred before withdrawal.
Records are kept for defined periods rather than indefinitely. Contact correspondence is normally deleted 24 months after the last meaningful exchange, security records are normally deleted after 90 days, and a correction record may remain with a published article while the article remains part of the archive. A legal hold, complaint or security incident may require a limited record to be preserved longer. When the reason ends, the retained material is deleted or irreversibly aggregated.
Requests to access, correct or delete information may be sent to 346, Hyoryeong-ro, Seocho-gu, Seoul, 06775, or by phone at +82-2-7143-6987. We normally acknowledge a request within seven business days and aim to respond within 30 days, explaining any lawful delay or limitation. We may request proportionate information to verify identity, but readers should not send passwords, private keys or complete identity documents through an ordinary form.
Hosting, email delivery, security logging and limited measurement may be supplied by contracted processors. A processor receives only the information needed for its service and is expected to maintain access controls, confidentiality and deletion procedures. Some infrastructure may operate outside the Republic of Korea, so applicable cross-border safeguards and contractual protections are considered before use. Zafara does not sell personal information or exchange contact messages for advertising lists.
This policy was reviewed on 22 September 2026. A material change to collection, purpose, retention, processor use or reader rights will be dated on the page and described in the revision record. Questions about a response may be escalated to the Personal Information Protection Commission of Korea or another competent authority where applicable.