Operational pilot CA (pre–Trust List) · legal drafts
CA Privacy Policy
Effective: 2026-07-30 · XenLook Inc. (주식회사 젠룩)
These documents are operational drafts for the XenLook C2PA Certification Authority. They do not constitute legal advice. Final interpretation rests with competent courts.
Data controller
XenLook Inc. · CEOs Hoyeon Nam, Giyeon Nam · BRN 251-81-04199 · [email protected]
This Policy covers CA/RA activities only, alongside the platform Privacy Policy at https://xenlook.com/privacy.
Data collected
Legal entity name, contact email, product name, country code, CSR subject, notes, audit logs, consent records (version/timestamp), minimal technical logs (IP/User-Agent for security).
Purposes
RA identity verification, issuance/revocation, subscriber communication, legal/C2PA duties, transparency, dispute handling.
Retention
Minimum 7 years after certificate expiry per CPS and audit requirements.
Processors and transfers
GCP Cloud KMS (Seoul), Cloudflare (edge TLS), self-hosted CA service. Google LLC (US) under DPA/standard terms.
Personal data of Japan subscribers is processed by the CA Operator in the Republic of Korea. Cross-border transfer notice under APPI (to Korea) is obtained via separate consent at application.
Data subject rights
Access, correction, deletion, restriction: [email protected] · response within 30 days. Legal retention may limit deletion.
Legal body: Korean · English · Japanese. Portal UI: 12 languages. Service: Korea · Japan.