1. Introduction
Spinamic is a companion application for the Spinamic scoliosis orthosis. It helps wearers and their guardians monitor brace wear time, posture data, and device status. We comply with applicable data protection laws, including the Personal Information Protection Act (PIPA) of the Republic of Korea and other relevant regulations. This Policy describes what data we collect, why we collect it, and the choices you have.
2. Information We Collect
We collect the following categories of information when you create an account, use the Service, or pair your Spinamic device.
(1) Account Information
- Required: name, email address, password (stored as a salted hash)
- Optional: user role (wearer or guardian), profile details
(2) Automatically Collected Information
- Device information: OS version, device model, advertising identifier (IDFA / AAID)
- Service usage logs: access timestamps, IP address, in-app activity
- Push notification token (only if you opt in to notifications)
(3) Spinamic Device Data
- Bluetooth device identifier and pairing information
- Wear-time data, posture readings, and sensor measurements
- Device status: firmware version, battery level, connectivity state
We do not collect sensitive personal information (such as political opinions, religious beliefs, or biometric identifiers beyond what is required by the device) or government-issued ID numbers.
3. Purpose of Collection and Use
We use the information we collect only for the following purposes.
- Creating and managing your account, verifying identity, preventing fraud
- Pairing your Spinamic device and collecting wear-time and posture data
- Providing core features such as dashboards, reports, and notifications
- Improving the Service, developing new features, and producing aggregate analytics
- Responding to support inquiries and delivering important service announcements
- Complying with legal obligations and resolving disputes
4. Retention and Use Period
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy or as required by law.
- Account information: until you delete your account, unless a longer retention period is required by law
- Wear-time and device data: until account deletion or upon your deletion request
- Access logs: 3 months (as required by the Protection of Communications Secrets Act)
- E-commerce records (if applicable): up to 5 years (as required by the Act on Consumer Protection in Electronic Commerce)
5. Disclosure to Third Parties
We do not sell your personal information. We do not share your personal information with third parties except in the following limited circumstances:
- When you have given us your explicit prior consent
- When required by law, court order, or a lawful request from a government authority
- To protect our rights, property, or safety, or that of our users or the public
6. Processing Entrustment
We engage trusted service providers to process personal information on our behalf so that we can operate the Service. We require these providers to handle data in accordance with this Policy and applicable laws.
| Service Provider | Purpose |
|---|---|
| Amazon Web Services, Inc. | Cloud server hosting and data storage |
| Google LLC (Firebase) | Push notification delivery and usage analytics |
| Expo, Inc. | Mobile app builds and over-the-air (OTA) updates |
7. Your Rights and How to Exercise Them
You have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete information
- Deletion: request that we delete your personal information
- Restriction: request that we suspend processing of your information
- Withdrawal of consent: withdraw any consent you previously provided and close your account
You can exercise these rights through the in-app settings menu or by contacting us at the email address listed below. We will respond to verified requests without undue delay.
8. Destruction of Personal Information
When personal information is no longer needed for the purposes for which it was collected, we destroy it without delay.
- Procedure: information whose retention purpose has been achieved is moved to a separate database and destroyed after any legally mandated retention period
- Electronic files: permanently deleted using methods that prevent recovery
- Printed materials: shredded or incinerated
9. App Permissions
The Spinamic app requests the following device permissions. Required permissions are essential for core functionality. Optional permissions can be denied without affecting other features.
Required Permissions
- Bluetooth (BLUETOOTH_SCAN / BLUETOOTH_CONNECT): to discover and connect to your Spinamic device
- Foreground Service (FOREGROUND_SERVICE / FOREGROUND_SERVICE_CONNECTED_DEVICE): to maintain a continuous connection with the device
- Background Bluetooth (iOS bluetooth-central background mode): to continue receiving wear data while the app is in the background
Optional Permissions
- Notifications (POST_NOTIFICATIONS): to deliver wear reminders, charging alerts, and other notifications
You can change permission settings at any time through your device's system settings.
10. Security Measures
We implement administrative, technical, and physical safeguards designed to protect your personal information.
- Administrative: internal data protection policies and regular employee training
- Technical: access control for personal information systems, encryption of passwords and sensitive fields, deployment of security software, and monitoring for unauthorized access
- Physical: restricted access to server rooms and physical storage of records
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
11. Children's Privacy
The Spinamic device is commonly prescribed to adolescent wearers. When the user is under 14 years of age, we collect personal information only with verifiable consent from a parent or legal guardian. Parents or legal guardians may review, correct, or request deletion of their child's personal information at any time by contacting us at the address below.
12. Privacy Officer and Contact
We have designated a Privacy Officer responsible for handling privacy-related questions, requests, and complaints.
Company: VNTC Co., Ltd. (Value and Trust Company)
Business Registration No.: 215-88-00371
Email: paul@spinamic.me
Phone: +82-2-6447-9124
If you reside in the Republic of Korea, you may also contact the following authorities for privacy-related complaints:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Korea Internet & Security Agency, Privacy Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation: 1301 (www.spo.go.kr)
- National Police Agency Cyber Bureau: 182 (ecrm.police.go.kr)
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you at least 7 days before the changes take effect, by posting the updated Policy in the app and on our website. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
Published: May 27, 2026 / Effective: May 27, 2026
