SantaCruise Company is the first digital undertaker in Korea. Since 2013 we have removed personal records from the open internet for people whose lives were being decided by a search result — and, without exception, free of charge for every minor who asked.
That work taught us something an engineer rarely learns: data is born but never dies. Everything we build now follows from that.
For fourteen years our business was the service: find the record, prove the right, get it taken down. It works, and it will always be needed. But it is downstream of the real problem — systems are built to retain, and nothing in them knows how to die.
Under Korea's 2025 data-portability regime, personal data now moves between institutions on the subject's instruction, while the right to erasure is still exercised one holder at a time. Copies outrun deletion. The gap is structural, not procedural.
So we are building the other half: an architecture in which personal data is separated at intake, expires on a clock, destroys itself without an administrator, and leaves cryptographic proof that it is gone. We call it Dual-Vault. It is the subject of our patent portfolio.
All filings are held by SantaCruise Company Co., Ltd. unless noted. Every number below is a real filing with the Korean Intellectual Property Office and is stated here exactly as it appears on the certificate.
Filed 27 March 2013 — the year the company was founded, when this work had no name in Korea. Granted 4 July 2014. The claims define, as a system, the procedure of locating an individual's records across the open internet and requesting their removal from portal operators; they also cover clearing the digital traces of the deceased and filtering abusive comments. Protected until 27 March 2033.
Filed 11 April 2023 (40-2023-0064099), registered 2 September 2024. Class 42, covering development of computer programs for data processing and 19 related services. Registration gives us a direct remedy against operators trading under our name — the most practical defence against impersonation in this industry.
The backbone of Dual-Vault. Personal data is split at intake into identity and attributes; identity is returned to the subject's own device, while the server keeps only de-identified attributes. Attributes carry an expiry timestamp and are destroyed automatically by a background process with no administrator in the loop. Only the hash of the deletion log is written to a blockchain — no personal data ever touches the chain. 21 claims; examination requested and in progress.
A different virtual identifier is issued per channel, so two recipients comparing their records cannot tell they hold the same person. When the validity period ends or the subject asks for erasure, the mapping and the distribution-history edges are severed together — a chained destruction that prevents the familiar failure where the original is deleted and the copies survive.
Each channel's payload carries a differently derived channel identifier. If that data later surfaces somewhere it should not, the system determines which channel it leaked from without ever accessing the recipient's systems. The finding is recorded in tamper-evident form, usable as the evidentiary basis for enforcement.
Incident reports are classified by an AI model, but identifying details are replaced with substitution tokens before the model sees anything. If the model's response contains tokens that do not correspond to any issued token, the system flags a re-identification risk. The consultation assistant running on our own site is an implementation of these claims.
One patent and one trademark are registered; four patent applications are pending. KR 10-1418475 and KR 40-2242711 can be looked up today at patent.go.kr. The four pending applications were filed with KIPO in 2026; the 22 May filing has had examination requested and is under examination.
The four pending applications are not granted patents. Whether they issue is for the examiner to decide. We state only that they were filed, and we will publish grant numbers if and when they issue. We do not describe pending applications as granted.
A Korean patent application is not publicly searchable until it is laid open, eighteen months after filing. Finding nothing today is the expected result. We will send the filing-receipt notices on request — santacruise@santacruise.co.kr
Identity and attributes are stored apart — physically and logically. Neither store alone can re-identify a person, and the key that joins them is temporary by construction.
Name, contact details, email — held encrypted, or returned to the subject's own device. Each record carries a time-to-live. On expiry it is destroyed automatically and the destruction is recorded on-chain, so the data provider receives proof of erasure without anyone having to remember to delete anything.
Age band, region, usage pattern, interests — pseudonymised. Only an identifier-free attribute token leaves the store. Matching happens on the user's device and the joined result is discarded immediately: zero-disclosure by design. Business value survives the deletion of identity.
He said about half of his clients are underage youth, whose monthly data-removal requests surged to 192 in May from 29 in September last year.
Reported in 2014, in the first years of the company. A decade later the proportion has not meaningfully changed — which is why removal for minors has stayed free, in every single case, for fourteen years.
This industry has a credibility problem, and claims that cannot be checked are part of it. Everything below is independently verifiable.
We are preparing a Series A to commercialise Dual-Vault and extend the patent portfolio, and we are open to partnerships with platforms, telecoms, data intermediaries and law firms operating across the Korea–Japan–US corridor.
santacruise@santacruise.co.kr
+82-2-3446-8775 · Gwacheon Pentawon G, 117 Gwacheondae-ro 12-gil, Gwacheon-si, Gyeonggi-do, Republic of Korea