For Pro Inc. uses the account email of users who separately opt in to send forpro-remote product news, events, and offers. This optional choice is separate from required signup confirmations, business details, and analytics consent, and is unchecked by default. Declining does not affect signup or use of the service.
Marketing use of the email continues until withdrawal or account deletion. We record the current choice, its timestamp, and the notice version. Signed-in users may change this preference in My Page → Settings. Withdrawal excludes the email from future marketing mailings; necessary account authentication and security notices are handled separately.
1. Controller and scope
For Pro Inc. (주식회사 포프로) is the controller for the forpro-remote website and its account, device and remote connection management service. This policy covers a service intended primarily for Korean users aged 14 or older and is separate from policies for other services.
Representative: 변지석. Registration: 669-88-02294. Address: Room 404, 109 Beodeunaru-ro, Yeongdeungpo-gu, Seoul, Republic of Korea. General contact: [email protected].
2. Basic registration and email verification
Basic registration requires an email and password. We use the email for account identification, verification, recovery and necessary service notices, and the password for authentication. Passwords are stored as one-way hashes. This minimum processing is necessary to establish and perform the service contract; an account cannot be created without it.
A requested six-digit email code is valid for 10 minutes. We process its verification hash, attempt count and sending time rather than storing the plain code. Hashed identifiers derived from the email and request IP, with rate-limit records, prevent sending abuse. No member account is created before email verification.
We record verification status, registration IP, the accepted document version and confirmation timestamps, and the confirmation of age 14 or older. Basic signup does not request a birth date, national identification number or identity document. Login IP and time, authentication sessions and any user-enabled two-factor credentials support authentication and abuse prevention.
3. Optional business information
Only users who select “I plan to use this for work” are asked for a name and team or organization. We use these details to understand business use, answer questions about adopting the service and provide support. Processing relies on separate optional consent, not advertising consent.
We retain these details until account closure or withdrawal of that consent. You may decline, omit this information and continue personal Free registration. Deselecting business use excludes the fields from the signup request. Contact [email protected] to withdraw consent without losing basic account access.
4. Information from service use
Devices and sharing: account and device identifiers, computer names and hostnames, OS and app versions, device MAC addresses, authentication keys and certificate fingerprints, ownership, sharing and team permissions, public/private IPs and ports, and online status support identification, access control and connections.
Diagnostics: connection participants and start/end times, route and NAT state, latency, resolution, codec, bitrate, frame/packet counts and errors support connection diagnosis. The backend does not relay or store screen content, file contents, speech or keystroke contents. Authorized peers receive information needed for a direct connection; choose recipients carefully.
Inquiries: names, email addresses, organizations, messages and response records submitted through forms or email are used to handle the request. Please do not include passwords or sensitive personal data.
Operations and security: request IPs, paths, times, results, errors and email delivery results are logged for abuse prevention and troubleshooting. These operational logs may contain IPs separately from optional aggregate analytics.
5. Retention
Account details, consent/confirmation records and account-linked devices, permissions and connection history are retained until account closure is processed. Optional business details are retained until closure or consent withdrawal. Any records requiring longer retention by law are managed separately with their legal basis and period.
Registration codes expire after 10 minutes. Verification and sending-limit records are retained for 24 hours after their last processing and expired records are purged hourly, allowing up to one additional hour for removal.
Inquiries are retained until their handling purpose is fulfilled. Records that qualify as consumer complaints or disputes under Korean electronic commerce law are retained for 3 years. If a separate paid transaction occurs, statutory retention is 5 years for contract/cancellation and payment/supply records, and 6 months for display/advertising records. Free signup alone does not collect payment details.
Operational and security logs currently follow system-specific rotation settings. A common 30-day automatic deletion limit has not yet been applied to all logs; this policy will be updated after those settings are implemented. Contact the privacy team for access or deletion requests and details of current retention. Records needed for an ongoing incident investigation or legal preservation duty are separately restricted and deleted when that reason ends. Recovery backups rotate on a 14-day basis, with up to one additional day between scheduled runs.
Aggregate totals by date, language and event that cannot distinguish individuals may be retained for service analysis. Lawful dispute or investigation holds are limited to their relevant records and period.
6. Disclosures and connection recipients
We do not sell personal data or ordinarily disclose it outside its collection purpose. Where separate consent or a legal basis permits disclosure, we provide the required recipient, purpose, data and retention information and follow applicable procedures.
When you request device sharing, team participation or a remote connection, authorized recipients receive account identifiers, shared device names/status and network information needed to fulfill the connection. You may revoke sharing permissions. Avoid placing private information in device names.
7. Processors and storage location
Servers, databases, cache and backups run on servers in Vultr’s Seoul (ICN) region. Processor: Vultr (The Constant Company, LLC). Task: server infrastructure and hosting. Data: account, device, connection and inquiry data needed for operation. Duration: until the processing contract or relevant data retention period ends. Databases and cache use internal connections.
Verification and recovery emails are sent through the company-domain mail server, mail.forpro.co.kr, to the address you enter. Only the recipient address and required verification or notice content are used; your chosen email provider receives and processes delivery.
We manage processor scope, purpose restrictions, safeguards and subprocessing conditions and update this policy when providers change. Use of a foreign provider’s Korean region is distinguished from actual cross-border transfer. Before adding processing involving overseas storage or access, we will disclose the country, recipient/contact, data, purpose, timing/method, duration, refusal method and impact, and establish the required legal basis.
8. Erasure
When a retention period ends or a purpose is fulfilled, responsible personnel check any legal preservation requirement and erase the data without undue delay. Legally retained data is separated from normal service use with restricted purposes and access.
Electronic data is deleted using methods designed to prevent recovery; any paper records are shredded or incinerated. Closure includes handling associated authentication sessions, sharing access and personal data, rather than merely hiding the account. Residual backup copies are access-restricted for recovery and removed by rotation. After restoring a backup, we must reapply previously completed deletion and consent-withdrawal requests.
9. Your rights
You may request access, correction, deletion, processing restriction, withdrawal of optional consent or account closure. Use available account controls or contact [email protected]. Email requests are available even where no automatic closure screen exists.
After proportionate identity checks, we act without undue delay and report the result. Authorized representatives may act for you with proof of authority. If a request is lawfully restricted, we explain the basis, reason and appeal route. Withdrawing optional consent does not limit basic Free use; deleting data essential to account operation may end the service agreement.
10. Cookies, local storage and optional analytics
An HttpOnly access_token cookie maintains web authentication. Its default lifetime is 7 days and may be renewed. Browser settings can delete or block cookies, but blocking required cookies can prevent login and account management.
Analytics are off by default. Only after consent in the footer’s Analytics settings do we count pricing views, download clicks, signups, inquiries and checkout starts by date and language on our own server. The metrics table contains no email, user ID or individual visitor identifier. We use no advertising-tracking cookies or third-party advertising analytics. Transmission-related operational logs follow sections 4 and 5.
Local storage retains the analytics preference until changed or cleared, and may hold an internal post-login return route valid for up to 15 minutes. You can disable analytics at any time. See Cookie Settings for controls.
11. Security measures
We restrict personal data access to work-related needs and manage server access and database connections. Website/API traffic uses HTTPS, passwords are hashed, and one-time verification codes and request limits help protect authentication.
We review access, retention, backups and logs to address unauthorized access or leakage and act on detected security issues. Incidents are handled with notifications, reports and user protection measures required by applicable law.
12. Privacy contact
Privacy officer: 조희진. Role: information security lead (정보보안책임). Department: information security team (정보보안팀). Email: [email protected].
Postal address: Privacy team, For Pro Inc., Room 404, 109 Beodeunaru-ro, Yeongdeungpo-gu, Seoul, Republic of Korea.
Contact this team for privacy questions, rights requests or complaints. General support is also available at [email protected].
13. Children, sensitive data and automated decisions
We do not accept registrations from children under 14. Registration requires a declaration of being at least 14, without collecting a birth date. If information from a child under 14 is identified, the privacy team takes appropriate measures and erases unnecessary data.
Basic registration does not collect sensitive data or statutory unique identifiers, nor provide a feature for making them public. We do not operate fully automated AI decisions with significant effects on your rights or obligations, personalized advertising, or pseudonymized research processing. Appropriate notice and rights procedures will precede changes to those practices.
14. External remedies
For unresolved Korean privacy complaints, contact the Personal Information Infringement Report Center (118 in Korea, privacy.kisa.or.kr) or the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr). Criminal or urgent unauthorized-access incidents may be reported to the police at 112 in Korea.
15. Policy changes
Document version: 2026-09-27, applicable from publication. Previous versions and reasons for changes will accompany revisions. Material changes to purposes, data categories or disclosures will be notified in advance, with renewed consent where required. Korean is the primary explanatory text; translation differences do not restrict statutory rights.