Privacy Notice for
Vulnerability Reporting
APR Co., Ltd. ("APR") processes personal data submitted in connection with vulnerability reports for the purpose of receiving, reviewing, responding to, and managing reports of security vulnerabilities affecting APR products and services.
An email address is required to receive and handle vulnerability reports. Except for the required email address, reporters are encouraged not to include personal data unless it is reasonably necessary to demonstrate the reported vulnerability.
Personal data relating to third parties should only be included where strictly necessary for that purpose.
Personal Data We Process
When you submit a vulnerability report, APR may process the following personal data.
Required Information- Email address
Your email address is used to receive your vulnerability report and to communicate with you regarding its review and handling.
Information Voluntarily Provided by the Reporter (if applicable)- Name
- Organization or affiliation
- Personal data voluntarily provided by the reporter in the vulnerability report or supporting materials
- Technical information necessary to review and respond to the reported vulnerability
Purpose of Processing
Personal data is processed solely for the following purposes:
- Receiving and managing vulnerability reports
- Verifying and reproducing reported vulnerabilities, where necessary
- Communicating with the reporting party regarding the reported vulnerability
- Investigating, assessing, and responding to reported security vulnerabilities
- Complying with applicable legal and regulatory obligations, where required
Legal Basis
Where the GDPR applies, personal data is processed on the basis of APR's legitimate interests in maintaining the security of its products and services and, where necessary, to comply with applicable legal obligations.
Where the Personal Information Protection Act of the Republic of Korea applies, personal data is processed where necessary to pursue legitimate interests that clearly outweigh the rights of the data subject or to comply with applicable legal obligations.
Recipients of Personal Data
Personal data may be accessed by authorized personnel responsible for privacy, cybersecurity, product security, software development, legal compliance, and vulnerability response, only to the extent necessary to review and handle the report.
Where necessary, personal data may also be processed by service providers supporting email, cloud infrastructure, security, or other systems used to receive and manage vulnerability reports.
Processing Location
Vulnerability reports are received and managed by APR in the Republic of Korea. Personal data submitted through the vulnerability reporting channel is processed in the Republic of Korea.
Retention
Personal data submitted in connection with vulnerability reports will be retained only for as long as necessary to assess, investigate, respond to, and document the reported vulnerability, or as otherwise required by applicable law.
Data Subject Rights
Where applicable, data subjects may exercise their rights under applicable data protection laws, including the right to access, rectify, erase, restrict processing, object to processing, and lodge a complaint with a competent supervisory authority.
Contact
For questions regarding the processing of personal data in connection with vulnerability reporting, to exercise your rights as a data subject, or to report a security vulnerability, please contact:
Security contact : age-r_security@apr-in.com