TRUVIX veriD 개인정보처리방침

주식회사 넥스해치(이하 “당사”)는 TRUVIX VeriD(이하 “앱”) 이용자의 개인정보를 중요하게 생각하며, 앱에서 개인정보가 처리되는 방식과 처리 주체를 다음과 같이 안내합니다.
This app is an institutional authentication app introduced by companies, public institutions, and other organizations to provide mobile authentication functions to their affiliated users. The personal information processor for user, device, and authentication-related personal information processed using the app is the institution or company that introduces the app to provide authentication services (hereinafter referred to as the “Affiliated Institution”).
앱에서 입력되거나 생성되는 개인정보는 소속기관이 직접 운영하거나 지정한 인증서버로 전송됩니다.
해당 인증서버는 소속기관의 운영정책에 따라 소속기관 내부 전산환경, 데이터센터 또는 소속기관이 계약한 클라우드 환경 등에 설치될 수 있습니다.
We are responsible for the development, distribution, and technical support of the app software, and we do not operate a separate server to receive, store, or relay personal information or authentication information between the app and the affiliated institution's authentication server.

1. Subject and Role of Personal Information Processing

1.1 Affiliated Organization

The affiliated organization is a personal information processor that determines and manages the following matters.
– 앱 사용 대상자 및 사용자 계정
– 개인정보의 처리 목적과 처리 항목
– 인증서버의 설치·운영 환경
– 개인정보의 보유기간 및 파기기준
– 사용자 인증 및 단말 등록 정책
– 개인정보 처리위탁 및 제3자 제공
– 개인정보 열람·정정·삭제·처리정지 요청 처리
– 개인정보 보호를 위한 관리적·기술적·물리적 보호조치
– 소속기관별 개인정보 처리기준은 해당 소속기관의 개인정보처리방침과 내부 보안정책에 따릅니다.

1.2 Nexhatch Co., Ltd.

Our company performs the following tasks.
– TRUVIX VeriD 앱 개발 및 배포
– 앱 기능 개선 및 업데이트
– 앱 소프트웨어에 대한 기술지원
– 앱 자체 보안 기능 제공
– 앱 및 개인정보처리방침 관련 문의 대응
We do not operate servers that relay personal information or authentication information between the app and the affiliated institution's authentication server, nor do we directly collect or store user information, device information, or authentication history stored on the affiliated institution's authentication server.

2. Personal information that may be transmitted to the affiliated institution's authentication server via the app

The following information may be collected or generated during the use of the app and transmitted to an authentication server directly operated or designated by your affiliated organization. The actual items processed may vary depending on the functions and security policies applied by your affiliated organization.

2.1 User Identification Information

– 사용자 ID(소속기관이 발급하는 식별값)
– 소속기관 또는 서비스 식별정보
– 사용자 등록을 위해 발급된 등록코드 또는 QR 등록정보
처리 목적: 사용자 등록 및 계정 연계, 인증요청 대상자 식별, 사용자와 등록 단말의 연결, 소속기관 인증서비스 제공
The app does not collect or store login passwords for the affiliated organization's business system.

2.2 Device and App Identification Information

– Android ID 또는 앱에서 생성한 단말 식별값
– 앱 인스턴스 식별정보
– 단말 등록 식별정보
– 단말 모델명
– 운영체제 종류 및 버전
– 앱 버전
Processing Purpose: User device registration and identification, authentication using registered devices, prevention of duplicate or abnormal device registration, verification of app compatibility and security status, analysis of authentication failures

2.3 FIDO and Passkey Authentication Information

– FIDO 공개키
– Credential ID
– 인증기 식별정보
– 서명 검증에 필요한 정보
– 인증 수행 및 검증 결과
Processing Purpose: FIDO or Passkey authentication, verification of registered authenticators, digital signature verification, prevention of fraudulent authentication and reuse
FIDO 및 Passkey 인증에 사용되는 개인키는 단말의 보안영역(Android Keystore)에서 생성·보관되며, 당사 또는 소속기관 인증서버로 전송되지 않습니다.

2.4 Terminal Security and Integrity Diagnostic Information

– 루팅 탐지 결과
– 앱 위변조 탐지 결과
– 디버깅·후킹 탐지 결과
– 에뮬레이터 또는 비정상 실행환경 탐지 결과
– 단말 무결성 및 위험상태 코드
– 그 밖에 부정 인증 방지를 위해 필요한 보안 진단 결과
Purpose of Processing: Prevention of fraudulent authentication, blocking authentication using forged or tampered apps or devices, detection of abnormal authentication behavior, application of affiliated organization security policies, prevention and response to security incidents
앱은 인증 보안에 필요한 범위에서 단말 보안상태 또는 진단 결과를 처리하며, 사용자의 사진, 연락처, 문자메시지, 통화내용 또는 단말에 저장된 일반 파일의 내용을 수집하지 않습니다.

3. 푸시 알림 기능에서 처리되는 정보

앱은 소속기관의 인증요청 알림을 사용자 단말로 전달하기 위해 Google Firebase Cloud Messaging(FCM) 푸시 알림 서비스를 이용합니다.
The following information may be generated or processed during the use of the push notification service.
– FCM 등록 토큰
– 앱 및 앱 인스턴스 식별정보
– 단말 운영체제 및 앱 버전
– 푸시 메시지 전달상태
– 푸시 전송 오류 및 기술정보
푸시 토큰은 앱에서 발급받아 소속기관이 직접 운영하거나 지정한 인증서버로 전송될 수 있습니다.
We do not operate a separate server to receive or relay push tokens between the app and the affiliated organization's authentication server, nor do we separately collect or store individual users' push tokens.
푸시 알림 전달 과정에서 Google의 서비스와 네트워크가 이용될 수 있으며, 해당 서비스에서 이루어지는 정보 처리에 관한 사항은 Google의 개인정보처리방침 및 서비스 이용조건에 따릅니다.
If your organization does not use push notifications or applies a different notification method, the relevant information may not be processed.

4. 생체인증 정보의 처리

The app does not directly collect or store original biometric data, such as users' fingerprints or faces.
생체정보의 등록과 대조는 단말 운영체제가 제공하는 생체인증 기능과 보안영역에서 수행되며, 앱은 운영체제가 제공하는 생체인증 성공 또는 실패 결과만 이용합니다.
The following information is not transmitted to our company or the affiliated organization's authentication server.
– 지문 원본 또는 지문 특징정보
– 얼굴 이미지 또는 얼굴 특징정보
– 단말에 등록된 생체정보 원본
– 생체정보를 복원할 수 있는 데이터
생체정보의 등록·변경·삭제는 사용자가 단말 운영체제의 보안 또는 생체인증 설정에서 직접 수행할 수 있습니다.

5. 개인정보의 처리 목적

Personal information transmitted to the affiliated organization's authentication server via the app may be processed within the scope of the following purposes.
– 사용자 및 소속기관 확인
– 사용자 계정과 등록 단말 연결
– OTP, 푸시, FIDO 및 Passkey 인증 제공
– 인증요청 알림 전달
– 단말 등록·변경·해제
– 단말 보안 및 무결성 확인
– 부정 인증과 계정도용 방지
– 이상 접속 탐지 및 위험도 판단
– 인증이력 및 보안 감사기록 관리
– 보안정책 적용
– 장애 확인 및 서비스 안정성 확보
– 보안사고 조사 및 대응
The specific purpose of processing follows the personal information processing policy and security policy of the affiliated organization that introduced the app.

6. 개인정보의 보유 및 이용기간

앱을 통해 소속기관 인증서버로 전송된 개인정보는 소속기관이 정한 보유기간 동안 처리됩니다.
당사는 해당 개인정보를 직접 수신하거나 별도로 보유하지 않으므로, 사용자 계정정보, 단말 등록정보, 인증이력 및 보안 진단정보의 구체적인 보유기간과 삭제기준은 소속기관의 개인정보처리방침을 확인하시기 바랍니다.
단말 내부에 저장된 앱 관련 정보는 다음 사유가 발생한 경우 삭제될 수 있습니다.
– 앱에서 단말 등록을 해제한 경우
– 소속기관이 해당 단말의 등록을 해제한 경우
– 앱을 삭제한 경우
– 소속기관의 보안정책에 따라 단말 정보가 초기화된 경우
– 사용자 계정 또는 인증서비스 이용이 종료된 경우
다만 단말 운영체제의 백업·복원 기능, 소속기관의 보안정책 또는 관련 법령에 따라 실제 삭제 시점과 방법이 달라질 수 있습니다.

7. 개인정보의 제3자 제공 및 처리위탁

앱을 통해 소속기관 인증서버로 전송된 개인정보의 제3자 제공 및 처리위탁 여부는 소속기관이 결정합니다.
소속기관이 인증서버를 외부 데이터센터, 클라우드 또는 전문 운영업체를 통해 운영하는 경우 해당 사업자에 대한 개인정보 처리위탁, 재위탁 및 국외 이전 등에 관한 사항은 소속기관의 개인정보처리방침에 따릅니다.
We do not arbitrarily decide which third parties to provide or entrust the processing of personal information handled by affiliated organizations.
앱의 푸시 알림 전달을 위해 Google Firebase Cloud Messaging이 이용되며, 구체적인 서비스 구성과 계약관계는 소속기관의 적용 환경에 따라 달라질 수 있습니다.

8. 개인정보의 파기

소속기관 인증서버에 저장된 개인정보의 파기 절차, 파기 시점 및 파기 방법은 소속기관의 개인정보처리방침과 관련 법령에 따릅니다.
당사가 직접 보유하지 않는 사용자 정보, 단말 정보 및 인증이력은 당사가 직접 파기할 수 없습니다.
단말 내부에 저장된 앱 관련 정보는 앱 등록 해제, 단말 등록 해제 또는 앱 삭제 등의 방법으로 삭제할 수 있습니다.
사용자가 앱만 삭제하더라도 소속기관 인증서버에 저장된 사용자 계정, 단말 등록정보 또는 인증이력이 자동으로 삭제되지 않을 수 있습니다. 서버에 저장된 정보의 삭제를 원하는 경우 해당 소속기관에 요청해야 합니다. 구체적인 계정·데이터 삭제 요청 절차는 별도 “데이터 삭제 안내” 페이지를 참고하시기 바랍니다.

9. 정보주체의 권리와 행사방법

Users may exercise the following rights regarding their personal information.
– 개인정보 열람 요구
– 개인정보 정정 또는 삭제 요구
– 개인정보 처리정지 요구
– 사용자 계정 또는 등록 단말 해제 요구
– 개인정보 처리에 대한 문의 및 이의제기
As user account information, device registration information, authentication history, and security diagnostic information are managed by the affiliated organization, you must request the exercise of rights regarding such information from the personal information protection department or service manager of the organization that adopted the app.
앱은 일반 사용자가 당사에 직접 가입하여 별도의 계정을 생성하는 서비스가 아닙니다. 사용자는 소속기관으로부터 발급받은 등록코드, QR 코드 또는 그 밖의 등록수단을 이용하여 앱을 등록합니다.
따라서 사용자 계정의 삭제, 인증서비스 이용 종료 또는 소속기관 인증서버에 저장된 정보의 삭제는 소속기관에 요청해야 합니다.
You may contact us with inquiries regarding the operation of the app software, information on the processing of personal information within the app, or this Privacy Policy.

10. 개인정보의 안전성 확보조치

We apply the following security features to ensure the safety of information processed in the app.
– 앱과 소속기관 인증서버 간 TLS 기반 암호화 통신
– 푸시 서비스와의 암호화 통신
– 단말 내 보호대상 정보의 암호화 저장
– Android Keystore 등 운영체제 보안 저장영역 활용
– 지원되는 단말에서 하드웨어 기반 보안기능(StrongBox 등) 활용
– FIDO 또는 Passkey 개인키의 단말 보안영역 내 생성·보관
– 루팅 및 앱 위변조 탐지
– 디버깅·후킹 및 비정상 실행환경 탐지
– 앱 무결성 검증
– 인증정보의 위조·변조 및 재사용 방지
– 앱 및 보안모듈의 지속적인 업데이트
Administrative, technical, and physical protection measures for the affiliated organization's authentication server, database, cloud, and network environment are in accordance with the organization's personal information protection policy and security policy.

11. 자동으로 생성되는 정보 및 광고 관련 사항

The following technical information may be automatically generated during the app launch, user registration, authentication, and push notification delivery processes.
– 앱 및 단말 식별정보
– 단말 모델과 운영체제 정보
– 앱 버전
– 인증처리 결과
– 오류 및 보안 진단정보
– FCM 등록 토큰
The app does not provide personalized advertisements and does not process users' personal information for the purpose of providing advertisements.
The app does not sell users' personal information to advertising businesses or provide it for advertising purposes.

12. 아동의 개인정보 처리

This app is an institutional app designed for companies, public institutions, and other organizations to provide authentication services to their affiliated users, and it does not provide membership registration services to general consumers.
If an affiliated institution provides an app to users under the age of 14, necessary procedures, such as the processing of personal information and consent from a legal representative, are carried out in accordance with the institution's responsibilities and privacy policy.

13. 소속기관 개인정보처리방침 확인

사용자 정보, 단말 등록정보, 인증이력 및 보안 진단정보의 개인정보처리자는 사용자가 소속된 기관입니다.
사용자는 다음 경로 또는 소속기관이 제공하는 안내를 통해 소속기관의 개인정보처리방침과 담당자 정보를 확인할 수 있습니다.
– 소속기관 홈페이지
– 소속기관 업무포털 또는 인증서비스 화면
– 앱 등록 안내문
– 소속기관 개인정보 보호 담당부서
– 앱에 표시되는 소속기관 정보 또는 개인정보처리방침 연결 화면
If you are unable to verify your organization's privacy policy or identify the person in charge, please contact your organization's information protection or personal information protection department or the app operations manager.

14. 개인정보 관련 문의처 및 신고기관

Inquiries regarding app software and this Privacy Policy
– 회사명: 주식회사 넥스해치
– 담당부서: 앱 개발 및 개인정보 보호 담당부서(개인정보처리 담당자)
– 이메일: appdev@nexhatch.co.kr
– 전화번호: 02-349-1117
당사는 앱 소프트웨어와 본 개인정보처리방침에 관한 문의를 처리합니다.
다음 사항은 개인정보를 실제로 처리하는 소속기관에 문의해야 합니다.
– 사용자 계정 조회 및 삭제
– 등록 단말 변경 또는 해제
– 인증이력 열람 및 삭제
– 개인정보의 정정·삭제·처리정지
– 계정 이용 종료
– 개인정보 보유기간
– 개인정보 제3자 제공 및 처리위탁
– 소속기관 인증서버의 보안 및 운영

그 밖에 개인정보 침해와 관련한 신고나 상담이 필요하신 경우 아래 기관에 문의하실 수 있습니다.
– 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
– 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
– 대검찰청 사이버수사과: (국번없이) 1301 (www.spo.go.kr)
– 경찰청 사이버수사국: (국번없이) 182 (ecrm.police.go.kr)

15. 개인정보처리방침의 변경

This Privacy Policy may be amended in accordance with changes in relevant laws, app features, data processing methods, or service operation policies.
개인정보처리방침이 변경되는 경우 앱, 당사 웹사이트 또는 앱스토어의 개인정보처리방침 페이지를 통해 변경 내용과 시행일을 안내합니다.
In the event of changes to matters that significantly affect users' rights, such as the items of personal information processed, the purpose of processing, or the processing entity, we provide notice to ensure that the details of the changes can be clearly verified.

Addenda

– 공고일: 2026년 7월 31일
– 시행일: 2026년 8월 1일

Scroll to Top