Skip to content

Legal

Privacy Policy

Last updated: Applies to hanapartskorea.com

This policy explains how Hanaparts Co., Ltd. handles personal data when you register as a corporate buyer, use the restricted catalog and quote process, or submit a public contact inquiry. Information about a company may also be personal data when it identifies an individual representative or proprietor.

Draft — pending business approval

These documents require business review and sign-off before launch. Company registration details, privacy contact arrangements and retention schedules remain to be confirmed.
01

Who is responsible and where information comes from

Hanaparts Co., Ltd. determines the purposes and means of processing described here and acts as the controller where that concept applies. Use the contact at the end of this page for privacy questions and requests, including if you cannot sign in.

We obtain information from you, representatives acting for your company, your use of the service and operators handling company checks and requests. Operator review records may include observations and information used to check your company, such as its website or business registration information.

02

Company, identity and contact information

For registration and company verification, we collect your corporate email, full name, company name, country and company registration or tax identification number. We also keep the country-specific label associated with that number, so the record shows what identification was requested.

We collect your phone number and international dialing code, and any website and messenger details you provide. Supported messenger types are WhatsApp, WeChat, Telegram, Zalo, Line and Viber. Messenger identifiers may be handles or phone numbers. We also keep language preferences, email verification information, the time you agreed to the terms, account status and account creation, update and last-login timestamps.

Required fields support account creation, contact and company verification. If you do not provide them, we may be unable to create or verify your account or handle a request. Fields marked optional can be left blank.

03

Quote carts, RFQs and uploaded commercial documents

We store quote cart and RFQ line items, part identifiers and descriptions, quantities and notes. An RFQ also includes a snapshot of the contact name, corporate email, company, country and phone submitted with that request, plus shipment volume, payment-method preference, Incoterm, destination and remarks. Changing your profile does not automatically change previously submitted RFQ contact snapshots.

Bulk RFQ spreadsheets and other uploaded commercial documents are stored as files. We record their filenames, file types, sizes, storage references, upload times and parsing results or errors, together with extracted item data. Documents may contain personal or confidential commercial information that you include in them. We also store issued quotation documents and request status history.

Provide only information needed to assess and quote your request. Do not include passwords, payment card details, identity documents or unrelated sensitive personal data in spreadsheets, remarks or messages. A payment-method preference in an RFQ is not payment card processing.

04

Contact inquiries, authentication and operator records

Public contact submissions contain your name, company, email, country, inquiry type and message. We also record the submission's IP address and user agent for abuse investigation, and a member reference when associated with an account. Handling status, operator assignment, internal notes and handling timestamps are retained with the inquiry.

Authentication records include credential hashes, session tokens and records, session expiry, IP addresses and user agents, email verification and password-reset one-time code records and their expiry. Password credentials are stored as hashes. One-time codes and sessions have validity limits; expiry does not necessarily mean the underlying database record has already been deleted.

Operators record review notes about your company, account approval or suspension decisions, the reviewer and review time, and account and RFQ status histories. Audit records can include the actor, changed fields, affected record, action, time and IP address. Additional account metadata may contain signup IP, referrer or campaign information where captured.

05

Why we process information and the bases we rely on

We use information to create and secure accounts, verify corporate buyer eligibility, provide catalog access, maintain quote carts, review RFQs, prepare formal quotations, answer inquiries and send account or request-related messages.

Where data protection law requires a legal basis, the basis depends on the activity and your relationship with us. Processing necessary to take steps at your request or perform a contract applies where you are the contracting individual. For employees and other representatives of corporate buyers, our legitimate interests include managing the business relationship, verifying companies and responding to procurement requests, subject to your rights and interests.

We process necessary records to comply with applicable legal obligations, including trade compliance and lawful recordkeeping requirements. Security monitoring, abuse prevention and proportionate audit trails support our legitimate interests in protecting buyers and the service. Where consent is legally required for an optional activity, we must obtain it separately; agreeing to the terms does not supply consent for every processing purpose.

Company verification involves operator review. Country eligibility checks and anti-bot checks can automatically prevent registration or submission. If you believe a restriction is mistaken, contact us to request human review; we cannot waive applicable trade restrictions.

06

Service providers and other recipients

Authorized Hanaparts personnel use information as needed for company review, sales handling, support and security. The platform uses the following providers for the stated functions. Their own terms describe their processing and any further service providers they use.

We may disclose necessary information to professional advisers or competent authorities where needed to meet legal obligations, handle claims or protect the service. If you choose to communicate through a messenger service, that provider handles those communications under its own terms.

  • Supabase provides managed database hosting and object storage for account and operational records, uploaded commercial documents and quotation files. Authentication is handled by the application's Better Auth integration; this platform does not use Supabase Auth.
  • Resend delivers transactional emails, including verification or recovery messages and inquiry or quotation notifications. It processes recipient addresses, message content and delivery information needed to provide that service.
  • Cloudflare Turnstile helps protect the public contact form from bots. It processes technical signals such as IP address, user agent, TLS fingerprint and the site associated with the challenge. Cloudflare acts as a processor when providing protection for us and as a controller when using signals to improve Turnstile's bot detection, as explained in its privacy addendum.
07

International processing and transfers

Hanaparts serves buyers internationally. Information may be accessed or processed outside your country by Hanaparts and its hosting, storage, mail and security providers. Provider infrastructure, support and subprocessors may operate in countries with different data protection laws from your own; the database region alone does not describe every processing location.

Where applicable law restricts a transfer, the transfer requires the applicable safeguards, such as a recognized adequacy decision or approved contractual clauses with any necessary supplementary measures. Provider agreements describe available contractual mechanisms, but do not by themselves establish that every Hanaparts transfer meets local requirements.

Contact us to request information about the locations, recipients and safeguards relevant to your data, including a copy or description of applicable safeguards subject to permitted redactions.

08

Retention and deletion

Retention is determined by the purpose of each record, whether an account or request remains active, applicable recordkeeping duties, and the need to resolve disputes or investigate abuse. Fixed retention periods and scheduled deletion arrangements are awaiting business confirmation in this draft.

Account and verification records are needed while assessing eligibility and providing account access. RFQs, contact snapshots, uploaded spreadsheets, quotations and related correspondence may need to remain after account closure to complete requests, meet legal obligations or address claims. Review notes and audit histories need a separate assessment of their compliance and security purpose.

Sessions and one-time codes have expiry times that limit their use. Expired records, security logs and contact-form IP and user-agent data require periodic review and removal when no longer necessary; this policy does not claim that expiry automatically purges them.

A deletion request must consider account records, RFQ copies, stored files, operational notes, audit records and provider-held copies. Closing an account alone does not delete all of these. Backups may persist until their applicable rotation period ends. Where retention is legally necessary, we will explain the reason and applicable period or criteria, and restrict further use as appropriate.

09

Sessions, browser storage and protection

Authentication uses session identifiers and associated records to keep you signed in. Cookies or equivalent browser storage support these account functions. Blocking them may prevent sign-in or use of the restricted service. Turnstile evaluates browser and network signals for bot protection as described above.

Access controls, credential hashing and verification checks help protect information, but no system can guarantee absolute security. Keep your sign-in details private and contact us if you suspect unauthorized access. Any additional analytics, advertising or optional tracking would need its own assessment, notice and consent where required before use.

10

Your rights and how to make a request

Depending on the law that applies to you, you may request access to your personal data, correction, deletion, restriction of processing or a portable copy. You may also object to processing based on legitimate interests and withdraw consent for activities relying on consent without affecting earlier lawful processing. These rights can be subject to lawful exceptions.

Email the contact below with your account email, company name and the request you want us to address. You do not need to sign in or keep an active account to make a request. If relevant, include an RFQ ticket so we can locate copied contact information or attachments. Do not send your password or one-time codes.

We may ask for proportionate information to verify your identity and authority before disclosing or changing records. We will respond within the deadline required by applicable law and explain any permitted extension or refusal. Deletion may be limited by trade, accounting, dispute or other lawful retention requirements.

You may raise concerns with the data protection authority competent for your location or our processing. You can also ask us to explain an account restriction or the safeguards used for an international transfer.

11

Changes to this policy

We will update this policy when the information collected, purposes, providers or handling arrangements change. The date at the top identifies the current revision. Material changes will be communicated as required by applicable law, and new processing that requires consent will not rely solely on publishing an updated policy.