Privacy

Policy

Collection of

General Information

Grievance Handling Department

Remedies for Infringement of Rights

Purpose of Personal Information Processing

Retention Period of Personal Information

Destruction

Procedures and Methods

Changes to the

Privacy Policy

Entrustment of

Personal Information

JYP Entertainment Corporation (hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and related laws to protect the freedom and rights of data subjects. The Company lawfully processes personal information and manages it securely.

In accordance with Article 30 of the 「Personal Information Protection Act」, this Privacy Policy has been established and disclosed to inform data subjects of the procedures and standards for personal information processing, and to promptly and smoothly handle related grievances. Changes to personal information collection items or entrusted processors will be disclosed through the website's notice (or individual notification).

1. Purpose, Items, and Retention Period of Personal Information Processing

1) The Company collects personal information based on the data subject’s consent in accordance with Article 15(1)(1) of the 「Personal Information Protection Act」 for the purposes of site use, service proposals, inquiries, and reports

Purpose

Items

Retention Period

Advertising inquiries, business partnerships, partner feedback, corporate ethics reporting

[Required]: Name, Email[Optional]: Contact Number

12 months

2) The company receives the following personal information from sources other than the data subject.

Purpose

Items

Service name

Provider

Basis for processing

Providing affiliate services to FANS paid membership members

Name, email, mobile phone number, date of birth, membership sign-up date, membership number, membership benefit usage history, residential area (country or region), KakaoTalk ID, shipping address

Event in progress

Blue Garage

Article 17, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act

2. Processing of Personal Information of Children Under 14

The Company does not collect personal information from children under the age of 14. In cases where it is necessary to collect such information, the consent of a legal guardian will be obtained, and only the minimum information required for the service will be collected. Legal rights of the guardian will be ensured.

3. Procedures and Methods for the Destruction of Personal Information

1) The Company promptly destroys personal information without delay once its retention period has expired or the purpose of processing has been achieved.

2) The procedures and methods for destroying personal information are as follows:

Destruction Procedure

Destruction Method

The Company selects the personal information subject to destruction and obtains approval from the Chief Privacy Officer before proceeding with destruction.

Personal information stored in electronic file format is permanently deleted using a method that prevents recovery or reproduction. Information recorded or stored in paper documents is shredded or incinerated.

3) If certain data must be retained according to other laws despite expiration of retention period or fulfillment of processing purpose, it will be stored in a separate database or stored in a different location.

Retained Information

Retention Period

Legal Basis

Website and app visit records

3 months

Article 15-2 (2) of the Protection of Communications Secrets Act

4. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope specified for the purpose of collection and does not provide personal information to third parties without the data subject’s consent, except in cases permitted under applicable laws such as Article 17 and 18 of the Personal Information Protection Act.

5. Additional Use and Provision of Personal Information

Under Articles 15(3) and 17(4) of the Personal Information Protection Act and Article 14-2 of its Enforcement Decree, the Company may use or provide personal information without the data subject’s consent, considering the following:

① Relevance to the original purpose of collection

② Predictability based on collection circumstances or processing practices

③ Whether the data subject’s interests are unfairly infringed

④ Implementation of safety measures such as pseudonymization or encryption

If such additional use/provision occurs frequently, the Company will disclose the assessment criteria and monitor compliance with those standards.

6. Entrustment of Personal Information

1) The Company outsources certain tasks to process personal information more efficiently.

Entrusted Party

Task

Blue Garage

Reflection of restricted participants in the event

Purplecow

Performance planning and operation

Amazon Web Services (AWS) Cloud Services

System Operation and Data Storage via

Microsoft Corporation Cloud Services

System Operation and Data Storage via

Google LLC(Google Workspace)

Cloud storage and archiving of event winners' personal information (spreadsheets, etc.)

2) The company operates by subcontracting personal information processing tasks to a specialized company as follows.

Entrusted Party

Task

Soldout

Performance CS-related identity verification

New-partner

Performance CS-related identity verification

3) When entering into an outsourcing contract, the Company specifies in the agreement or other written document matters concerning the prohibition of personal information processing beyond the scope of the entrusted tasks, technical and managerial protective measures, restrictions on sub-outsourcing, management and supervision of the entrusted party, and liability for damages, under Article 26 of the 「Personal Information Protection Act」. The Company also supervises the entrusted party to ensure that personal information is handled safely.

7. Transfer of Personal Information Overseas

The Company transfers personal information overseas as follows, in accordance with Article 28-8, Paragraph 1, Subparagraph 3 of the Personal Information Protection Act, for the purpose of entrusting the processing and storage of personal information. If a data subject does not wish for their personal information to be transferred overseas, they may refuse the transfer by contacting the Chief Privacy Officer; in this case, the use of related

Recipient (Contact Information)

line

Country of Transfer

line

Date and Method of Transfer

line

Items Transferred

line

Retention & Usage Period

line

Google LLC

(Contact Privacy Officer: googlekrsupport@google.com)

line

Countries where Google data centers are located, such as the United States (cloud.google.com/about/locations?hl=ko)

line

Frequent transmission via network when using the service

line

Event winners' personal information via Google Drive spreadsheets

line

Until the end of the event

8. Measures to Ensure the Safety of Personal Information

Category

Details

Administrative Measures

Establishment and implementation of internal management plans, operation of a dedicated department, regular employee training

Technical Measures

Access control for personal information processing systems, installation of access control systems, encryption of personal information, installation and updates of security programs, regular vulnerability assessments and remediation of personal information processing systems

Physical Measures

Access control for computer rooms, data storage rooms, etc.

9. Matters Concerning the Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof

1) The Company permits the collection and processing of behavioral information from online personalized advertising providers as follows to identify user inflow/conversion patterns and track user errors/performance.

Advertising business operators intending to collect and process behavioral information

line

Methods for collecting behavioral information

line

Items of behavioral information collected and processed

line

Retention/Usage Period

line

Google

(Google Analytics 4)

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

line

DataDog

(Datadog RUM (Real User Monitoring))

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

2) The Company collects and uses advertising identifiers to identify user acquisition/conversion patterns and track user errors/performance within the mobile app. Data subjects can block or allow personalized advertisements in the app by changing the settings on their mobile devices.

[Allowing/Blocking Cookies in Web Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the web browser > New Incognito Window (Shortcut: Ctrl+Shift+N)
  • Edge: Select the ‘...’ icon in the top right corner of the web browser > New InPrivate Window (Shortcut: Ctrl+Shift+N)

[Allowing/Blocking Cookies in Mobile Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the mobile browser > New Incognito Tab
  • Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
  • Samsung Internet: Select the ‘Tab’ icon at the bottom of the mobile browser > Turn on Incognito Mode > Start

10. Rights of Data Subjects and How to Exercise Them

1) Data subjects may exercise their rights at any time with respect to their personal information, including requests for access, correction, deletion, suspension of processing, or withdrawal of consent.

2) These rights may be exercised by submitting the designated form in writing, by email, or by other means in accordance with Article 41(1) of the Enforcement Decree of the 「Personal Information Protection Act」. The Company will take prompt action upon receiving such requests.

No. 8 from the Notice on Personal Information Processing Methods (No. 2023-12).pdf

3) These rights may also be exercised by the data subject’s legal representative or authorized agent. In such cases, a power of attorney in the format of Form No. 11 from the same notice must be submitted.

4) The rights to request access to or suspension of personal information may be restricted in accordance with Articles 35(4) and 37(2) of the Personal Information Protection Act.

5) Requests for correction or deletion cannot be granted if the relevant personal information is specified as mandatory under other laws.

6) The Company verifies whether the person requesting access, correction/deletion, or suspension of processing in accordance with the rights of the data subject is the data subject themselves or a legitimate representative.

11. Chief Private Officer and Access RequestGrievance Handling Department

1) The Company designates the following individual as the Chief Privacy Officer, who is responsible for overseeing all matters related to personal information processing and for handling complaints and providing relief for data subjects.

2) Data subjects may submit requests for access to their personal information under Article 35 of the Personal Information Protection Act to the above department. The Company will make every effort to process such requests promptly.

Category

Chief Private Officer (CPO)

Department in charge of Access Requests

Name

Shin Jungcheol

-

Title / Department

Director

Technology Strategy Team

Phone Number

+82-2-2225-8100

+82-2-2225-8100

Email

privacy@jype.com

privacyit@jype.com

12. Remedies for Infringement of Rights

The data subject may seek dispute resolution or consultation by applying to institutions such as the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of the Korea Internet & Security Agency in order to obtain relief for any infringement of personal information. For reporting or consultation regarding other personal information infringements, please contact the institutions listed below.

① Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)

② Korea Internet & Security Agency (KISA) Personal Information Infringement Center: 118 (privacy.kisa.or.kr)

③ Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)

④ National Police Agency: 182 (ecrm.police.go.kr)

13. Changes to the Privacy PolicyChanges to the Privacy Policy

1) This Privacy Policy will take effect on September 1, 2026.

2) Previous versions of this Privacy Policy can be accessed below:

  • 2025.08.29 - 2026.08.31 (View)
  • 2025.07.01 - 2025.08.28 (View)
  • 2025.04.10 - 2025.06.30 (View)
  • 2024.07.20 - 2025.04.09 (View)
  • 2023.01.03 - 2024.07.19 (View)
  • 2022.10.28 - 2023.01.02 (View)

© JYP ENTERTAINMENT Corp. All rights reserved.

Privacy Policy

Grievance Handling Department

Collection of

General Information

Changes to the

Privacy Policy

Remedies for Infringement of Rights

Purpose of Personal Information Processing

Retention Period of Personal Information

Destruction

Procedures and Methods

Entrustment of

Personal Information

JYP Entertainment Corporation (hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and related laws to protect the freedom and rights of data subjects. The Company lawfully processes personal information and manages it securely.

In accordance with Article 30 of the 「Personal Information Protection Act」, this Privacy Policy has been established and disclosed to inform data subjects of the procedures and standards for personal information processing, and to promptly and smoothly handle related grievances. Changes to personal information collection items or entrusted processors will be disclosed through the website's notice (or individual notification).

1. Purpose, Items, and Retention Period of Personal Information Processing

1) The Company collects personal information based on the data subject’s consent in accordance with Article 15(1)(1) of the 「Personal Information Protection Act」 for the purposes of site use, service proposals, inquiries, and reports

Purpose

Items

Retention Period

Advertising inquiries, business partnerships, partner feedback, corporate ethics reporting

[Required]: Name, Email[Optional]: Contact Number

12 months

2) The company receives the following personal information from sources other than the data subject.

Purpose

Items

Service name

Provider

Basis for processing

Providing affiliate services to FANS paid membership members

Name, email, mobile phone number, date of birth, membership sign-up date, membership number, membership benefit usage history, residential area (country or region), KakaoTalk ID, shipping address

Event in progress

Blue Garage

Article 17, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act

2. Processing of Personal Information of Children Under 14

The Company does not collect personal information from children under the age of 14. In cases where it is necessary to collect such information, the consent of a legal guardian will be obtained, and only the minimum information required for the service will be collected. Legal rights of the guardian will be ensured.

3. Procedures and Methods for the Destruction of Personal Information

1) The Company promptly destroys personal information without delay once its retention period has expired or the purpose of processing has been achieved.

2) The procedures and methods for destroying personal information are as follows:

Destruction Procedure

Destruction Method

The Company selects the personal information subject to destruction and obtains approval from the Chief Privacy Officer before proceeding with destruction.

Personal information stored in electronic file format is permanently deleted using a method that prevents recovery or reproduction. Information recorded or stored in paper documents is shredded or incinerated.

3) If certain data must be retained according to other laws despite expiration of retention period or fulfillment of processing purpose, it will be stored in a separate database or stored in a different location.

Retained Information

Retention Period

Legal Basis

Website and app visit records

3 months

Article 15-2 (2) of the Protection of Communications Secrets Act

4. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope specified for the purpose of collection and does not provide personal information to third parties without the data subject’s consent, except in cases permitted under applicable laws such as Article 17 and 18 of the Personal Information Protection Act.

5. Additional Use and Provision of Personal Information

Under Articles 15(3) and 17(4) of the Personal Information Protection Act and Article 14-2 of its Enforcement Decree, the Company may use or provide personal information without the data subject’s consent, considering the following:

① Relevance to the original purpose of collection

② Predictability based on collection circumstances or processing practices

③ Whether the data subject’s interests are unfairly infringed

④ Implementation of safety measures such as pseudonymization or encryption

If such additional use/provision occurs frequently, the Company will disclose the assessment criteria and monitor compliance with those standards.

6. Entrustment of Personal Information

1) The Company outsources certain tasks to process personal information more efficiently.

Entrusted Party

Task

Blue Garage

Reflection of restricted participants in the event

Purplecow

Performance planning and operation

Amazon Web Services (AWS) Cloud Services

System Operation and Data Storage via

Microsoft Corporation Cloud Services

System Operation and Data Storage via

Google LLC(Google Workspace)

Cloud storage and archiving of event winners' personal information (spreadsheets, etc.)

2) The company operates by subcontracting personal information processing tasks to a specialized company as follows.

Entrusted Party

Task

Soldout

Performance CS-related identity verification

New-partner

Performance CS-related identity verification

3) When entering into an outsourcing contract, the Company specifies in the agreement or other written document matters concerning the prohibition of personal information processing beyond the scope of the entrusted tasks, technical and managerial protective measures, restrictions on sub-outsourcing, management and supervision of the entrusted party, and liability for damages, under Article 26 of the 「Personal Information Protection Act」. The Company also supervises the entrusted party to ensure that personal information is handled safely.

7. Transfer of Personal Information Overseas

The Company transfers personal information overseas as follows, in accordance with Article 28-8, Paragraph 1, Subparagraph 3 of the Personal Information Protection Act, for the purpose of entrusting the processing and storage of personal information. If a data subject does not wish for their personal information to be transferred overseas, they may refuse the transfer by contacting the Chief Privacy Officer; in this case, the use of related

Recipient (Contact Information)

line

Country of Transfer

line

Date and Method of Transfer

line

Items Transferred

line

Retention & Usage Period

line

Google LLC

(Contact Privacy Officer: googlekrsupport@google.com)

line

Countries where Google data centers are located, such as the United States (cloud.google.com/about/locations?hl=ko)

line

Frequent transmission via network when using the service

line

Event winners' personal information via Google Drive spreadsheets

line

Until the end of the event

8. Measures to Ensure the Safety of Personal Information

Category

Details

Administrative Measures

Establishment and implementation of internal management plans, operation of a dedicated department, regular employee training

Technical Measures

Access control for personal information processing systems, installation of access control systems, encryption of personal information, installation and updates of security programs, regular vulnerability assessments and remediation of personal information processing systems

Physical Measures

Access control for computer rooms, data storage rooms, etc.

9. Matters Concerning the Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof

1) The Company permits the collection and processing of behavioral information from online personalized advertising providers as follows to identify user inflow/conversion patterns and track user errors/performance.

Advertising business operators intending to collect and process behavioral information

line

Methods for collecting behavioral information

line

Items of behavioral information collected and processed

line

Retention/Usage Period

line

Google

(Google Analytics 4)

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

line

DataDog

(Datadog RUM (Real User Monitoring))

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

2) The Company collects and uses advertising identifiers to identify user acquisition/conversion patterns and track user errors/performance within the mobile app. Data subjects can block or allow personalized advertisements in the app by changing the settings on their mobile devices.

[Allowing/Blocking Cookies in Web Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the web browser > New Incognito Window (Shortcut: Ctrl+Shift+N)
  • Edge: Select the ‘...’ icon in the top right corner of the web browser > New InPrivate Window (Shortcut: Ctrl+Shift+N)

[Allowing/Blocking Cookies in Mobile Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the mobile browser > New Incognito Tab
  • Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
  • Samsung Internet: Select the ‘Tab’ icon at the bottom of the mobile browser > Turn on Incognito Mode > Start

10. Rights of Data Subjects and How to Exercise Them

1) Data subjects may exercise their rights at any time with respect to their personal information, including requests for access, correction, deletion, suspension of processing, or withdrawal of consent.

2) These rights may be exercised by submitting the designated form in writing, by email, or by other means in accordance with Article 41(1) of the Enforcement Decree of the 「Personal Information Protection Act」. The Company will take prompt action upon receiving such requests.

No. 8 from the Notice on Personal Information Processing Methods (No. 2023-12).pdf

3) These rights may also be exercised by the data subject’s legal representative or authorized agent. In such cases, a power of attorney in the format of Form No. 11 from the same notice must be submitted.

4) The rights to request access to or suspension of personal information may be restricted in accordance with Articles 35(4) and 37(2) of the Personal Information Protection Act.

5) Requests for correction or deletion cannot be granted if the relevant personal information is specified as mandatory under other laws.

6) The Company verifies whether the person requesting access, correction/deletion, or suspension of processing in accordance with the rights of the data subject is the data subject themselves or a legitimate representative.

11. Chief Private Officer and Access RequestGrievance Handling Department

1) The Company designates the following individual as the Chief Privacy Officer, who is responsible for overseeing all matters related to personal information processing and for handling complaints and providing relief for data subjects.

2) Data subjects may submit requests for access to their personal information under Article 35 of the Personal Information Protection Act to the above department. The Company will make every effort to process such requests promptly.

Category

Chief Private Officer (CPO)

Department in charge of Access Requests

Name

Shin Jungcheol

-

Title / Department

Director

Technology Strategy Team

Phone Number

+82-2-2225-8100

+82-2-2225-8100

Email

privacy@jype.com

privacyit@jype.com

12. Remedies for Infringement of Rights

The data subject may seek dispute resolution or consultation by applying to institutions such as the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of the Korea Internet & Security Agency in order to obtain relief for any infringement of personal information. For reporting or consultation regarding other personal information infringements, please contact the institutions listed below.

① Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)

② Korea Internet & Security Agency (KISA) Personal Information Infringement Center: 118 (privacy.kisa.or.kr)

③ Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)

④ National Police Agency: 182 (ecrm.police.go.kr)

13. Changes to the Privacy PolicyChanges to the Privacy Policy

1) This Privacy Policy will take effect on September 1, 2026.

2) Previous versions of this Privacy Policy can be accessed below:

  • 2025.08.29 - 2026.08.31 (View)
  • 2025.07.01 - 2025.08.28 (View)
  • 2025.04.10 - 2025.06.30 (View)
  • 2024.07.20 - 2025.04.09 (View)
  • 2023.01.03 - 2024.07.19 (View)
  • 2022.10.28 - 2023.01.02 (View)

© JYP ENTERTAINMENT Corp. All rights reserved.

Privacy Policy

Collection of

General Information

Grievance Handling Department

Changes to the

Privacy Policy

Remedies for Infringement of Rights

Purpose of Personal Information Processing

Retention Period of Personal Information

Destruction

Procedures and Methods

Entrustment of

Personal Information

JYP Entertainment Corporation (hereinafter referred to as the “Company”) complies with the Personal Information Protection Act and related laws to protect the freedom and rights of data subjects. The Company lawfully processes personal information and manages it securely.

In accordance with Article 30 of the 「Personal Information Protection Act」, this Privacy Policy has been established and disclosed to inform data subjects of the procedures and standards for personal information processing, and to promptly and smoothly handle related grievances. Changes to personal information collection items or entrusted processors will be disclosed through the website's notice (or individual notification).

1. Purpose, Items, and Retention Period of Personal Information Processing

1) The Company collects personal information based on the data subject’s consent in accordance with Article 15(1)(1) of the 「Personal Information Protection Act」 for the purposes of site use, service proposals, inquiries, and reports

Purpose

Items

Retention Period

Advertising inquiries, business partnerships, partner feedback, corporate ethics reporting

[Required]: Name, Email[Optional]: Contact Number

12 months

2) The company receives the following personal information from sources other than the data subject.

Purpose

Items

Service name

Provider

Basis for processing

Providing affiliate services to FANS paid membership members

Name, email, mobile phone number, date of birth, membership sign-up date, membership number, membership benefit usage history, residential area (country or region), KakaoTalk ID, shipping address

Event in progress

Blue Garage

Article 17, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act

2. Processing of Personal Information of Children Under 14

The Company does not collect personal information from children under the age of 14. In cases where it is necessary to collect such information, the consent of a legal guardian will be obtained, and only the minimum information required for the service will be collected. Legal rights of the guardian will be ensured.

3. Procedures and Methods for the Destruction of Personal Information

1) The Company promptly destroys personal information without delay once its retention period has expired or the purpose of processing has been achieved.

2) The procedures and methods for destroying personal information are as follows:

Destruction Procedure

Destruction Method

The Company selects the personal information subject to destruction and obtains approval from the Chief Privacy Officer before proceeding with destruction.

Personal information stored in electronic file format is permanently deleted using a method that prevents recovery or reproduction. Information recorded or stored in paper documents is shredded or incinerated.

3) If certain data must be retained according to other laws despite expiration of retention period or fulfillment of processing purpose, it will be stored in a separate database or stored in a different location.

Retained Information

Retention Period

Legal Basis

Website and app visit records

3 months

Article 15-2 (2) of the Protection of Communications Secrets Act

4. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope specified for the purpose of collection and does not provide personal information to third parties without the data subject’s consent, except in cases permitted under applicable laws such as Article 17 and 18 of the Personal Information Protection Act.

5. Additional Use and Provision of Personal Information

Under Articles 15(3) and 17(4) of the Personal Information Protection Act and Article 14-2 of its Enforcement Decree, the Company may use or provide personal information without the data subject’s consent, considering the following:

① Relevance to the original purpose of collection

② Predictability based on collection circumstances or processing practices

③ Whether the data subject’s interests are unfairly infringed

④ Implementation of safety measures such as pseudonymization or encryption

If such additional use/provision occurs frequently, the Company will disclose the assessment criteria and monitor compliance with those standards.

6. Entrustment of Personal Information

1) The Company outsources certain tasks to process personal information more efficiently.

Entrusted Party

Task

Blue Garage

Reflection of restricted participants in the event

Purplecow

Performance planning and operation

Amazon Web Services (AWS) Cloud Services

System Operation and Data Storage via

Microsoft Corporation Cloud Services

System Operation and Data Storage via

Google LLC(Google Workspace)

Cloud storage and archiving of event winners' personal information (spreadsheets, etc.)

2) The company operates by subcontracting personal information processing tasks to a specialized company as follows.

Entrusted Party

Task

Soldout

Performance CS-related identity verification

New-partner

Performance CS-related identity verification

3) When entering into an outsourcing contract, the Company specifies in the agreement or other written document matters concerning the prohibition of personal information processing beyond the scope of the entrusted tasks, technical and managerial protective measures, restrictions on sub-outsourcing, management and supervision of the entrusted party, and liability for damages, under Article 26 of the 「Personal Information Protection Act」. The Company also supervises the entrusted party to ensure that personal information is handled safely.

7. Transfer of Personal Information Overseas

The Company transfers personal information overseas as follows, in accordance with Article 28-8, Paragraph 1, Subparagraph 3 of the Personal Information Protection Act, for the purpose of entrusting the processing and storage of personal information. If a data subject does not wish for their personal information to be transferred overseas, they may refuse the transfer by contacting the Chief Privacy Officer; in this case, the use of related

Recipient (Contact Information)

line

Country of Transfer

line

Date and Method of Transfer

line

Items Transferred

line

Retention & Usage Period

line

Google LLC

(Contact Privacy Officer: googlekrsupport@google.com)

line

Countries where Google data centers are located, such as the United States (cloud.google.com/about/locations?hl=ko)

line

Frequent transmission via network when using the service

line

Event winners' personal information via Google Drive spreadsheets

line

Until the end of the event

8. Measures to Ensure the Safety of Personal Information

Category

Details

Administrative Measures

Establishment and implementation of internal management plans, operation of a dedicated department, regular employee training

Technical Measures

Access control for personal information processing systems, installation of access control systems, encryption of personal information, installation and updates of security programs, regular vulnerability assessments and remediation of personal information processing systems

Physical Measures

Access control for computer rooms, data storage rooms, etc.

9. Matters Concerning the Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof

1) The Company permits the collection and processing of behavioral information from online personalized advertising providers as follows to identify user inflow/conversion patterns and track user errors/performance.

Advertising business operators intending to collect and process behavioral information

line

Methods for collecting behavioral information

line

Items of behavioral information collected and processed

line

Retention/Usage Period

line

Google

(Google Analytics 4)

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

line

DataDog

(Datadog RUM (Real User Monitoring))

line

Automatically collected upon web access and usage

line

Webpage access and usage history

(Personal identification not possible)

line

3 months from collection

2) The Company collects and uses advertising identifiers to identify user acquisition/conversion patterns and track user errors/performance within the mobile app. Data subjects can block or allow personalized advertisements in the app by changing the settings on their mobile devices.

[Allowing/Blocking Cookies in Web Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the web browser > New Incognito Window (Shortcut: Ctrl+Shift+N)
  • Edge: Select the ‘...’ icon in the top right corner of the web browser > New InPrivate Window (Shortcut: Ctrl+Shift+N)

[Allowing/Blocking Cookies in Mobile Browsers]

  • Chrome: Select the ‘⋮’ icon in the top right corner of the mobile browser > New Incognito Tab
  • Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
  • Samsung Internet: Select the ‘Tab’ icon at the bottom of the mobile browser > Turn on Incognito Mode > Start

10. Rights of Data Subjects and How to Exercise Them

1) Data subjects may exercise their rights at any time with respect to their personal information, including requests for access, correction, deletion, suspension of processing, or withdrawal of consent.

2) These rights may be exercised by submitting the designated form in writing, by email, or by other means in accordance with Article 41(1) of the Enforcement Decree of the 「Personal Information Protection Act」. The Company will take prompt action upon receiving such requests.

No. 8 from the Notice on Personal Information Processing Methods (No. 2023-12).pdf

3) These rights may also be exercised by the data subject’s legal representative or authorized agent. In such cases, a power of attorney in the format of Form No. 11 from the same notice must be submitted.

4) The rights to request access to or suspension of personal information may be restricted in accordance with Articles 35(4) and 37(2) of the Personal Information Protection Act.

5) Requests for correction or deletion cannot be granted if the relevant personal information is specified as mandatory under other laws.

6) The Company verifies whether the person requesting access, correction/deletion, or suspension of processing in accordance with the rights of the data subject is the data subject themselves or a legitimate representative.

11. Chief Private Officer and Access RequestGrievance Handling Department

1) The Company designates the following individual as the Chief Privacy Officer, who is responsible for overseeing all matters related to personal information processing and for handling complaints and providing relief for data subjects.

2) Data subjects may submit requests for access to their personal information under Article 35 of the Personal Information Protection Act to the above department. The Company will make every effort to process such requests promptly.

Category

Chief Private Officer (CPO)

Department in charge of Access Requests

Name

Shin Jungcheol

-

Title / Department

Director

Technology Strategy Team

Phone Number

+82-2-2225-8100

+82-2-2225-8100

Email

privacy@jype.com

privacyit@jype.com

12. Remedies for Infringement of Rights

The data subject may seek dispute resolution or consultation by applying to institutions such as the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of the Korea Internet & Security Agency in order to obtain relief for any infringement of personal information. For reporting or consultation regarding other personal information infringements, please contact the institutions listed below.

① Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)

② Korea Internet & Security Agency (KISA) Personal Information Infringement Center: 118 (privacy.kisa.or.kr)

③ Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)

④ National Police Agency: 182 (ecrm.police.go.kr)

13. Changes to the Privacy PolicyChanges to the Privacy Policy

1) This Privacy Policy will take effect on September 1, 2026.

2) Previous versions of this Privacy Policy can be accessed below:

  • 2025.08.29 - 2026.08.31 (View)
  • 2025.07.01 - 2025.08.28 (View)
  • 2025.04.10 - 2025.06.30 (View)
  • 2024.07.20 - 2025.04.09 (View)
  • 2023.01.03 - 2024.07.19 (View)
  • 2022.10.28 - 2023.01.02 (View)