Antpocket - Privacy Policy

Antpocket (the "Company") has established the following processing policy in accordance with the Personal Information Protection Act, in order to protect users' personal information and rights and to handle users' grievances related to personal information smoothly.

If Pparkso, Inc. amends the Company's Privacy Policy, it will announce the amendment through a website notice (or an individual notice).

This policy takes effect on January 1, 2023.


Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. The processed personal information will not be used for purposes other than the following, and if the purpose of use changes, the Company will obtain prior consent.

1. Website membership registration and management

The Company processes personal information for the purposes of confirming intent to register, identifying and authenticating individuals for the provision of member-based services, maintaining and managing membership, verifying identity under the limited identity verification system, preventing fraudulent use of the Service, and providing various notices and communications.

2. Handling of civil complaints

The Company processes personal information for the purposes of verifying the identity of the complainant, confirming the complaint, contacting and notifying for fact-finding, and notifying of the results of processing.

3. Provision of goods or services

The Company processes personal information for the purposes of providing services, providing content, providing customized services, payment and settlement of fees, and debt collection.

Article 2 (Personal Information Collected and Retention Period)

1. The Company processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period consented to by the data subject at the time of collection.

Personal information collected: email, name (nickname), profile picture, service usage records, access logs. Method of collection: application and membership registration on the website and mobile application

2. The processing and retention period for each item of personal information is as follows.

Basis for retention: smooth maintenance of the Service

Retention period: 1 year (however, the retention period is renewed while the Service is in use)

Relevant laws:

1) Records on payment and supply of goods, etc.: 5 years

2) Records on contracts or withdrawal of subscription, etc.: 5 years

Article 3 (Provision of Personal Information to Third Parties)

The Company processes the data subject's personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases falling under Article 17 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.

Article 4 (Rights and Obligations of the Data Subject and Legal Representative, and Method of Exercise)

As a data subject, a user may exercise the following rights.

1. The data subject may exercise, at any time, the rights to request access to, correction of, deletion of, or suspension of processing of personal information, with respect to the Company.

2. The exercise of rights under paragraph 1 may be done with respect to the Company in writing, by email, or by facsimile (FAX) in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on it without delay.

3. The exercise of rights under paragraph 1 may be done through an agent, such as the data subject's legal representative or a delegated person. In this case, you must submit a power of attorney in the form of Appendix No. 11 of the Enforcement Rules of the Personal Information Protection Act.

4. The right to request access to and suspension of processing of personal information may be restricted pursuant to Article 35(5) and Article 37(2) of the Personal Information Protection Act.

5. A request for correction or deletion of personal information cannot demand the deletion of personal information where it is specified as a subject of collection in other laws.

6. When there is a request for access, correction or deletion, or suspension of processing pursuant to the data subject's rights, the Company verifies whether the person who made the request is the data subject themselves or a legitimate agent.

Article 5 (Destruction of Personal Information)

The procedure, deadline, and method of destruction, and the user's request for destruction, are as follows.

When a user withdraws their membership, the user's personal information is handled as follows.

1. Destruction procedure

Information entered by a user is, after the purpose is achieved, moved to a separate database (or a separate document in the case of paper) and stored for a certain period in accordance with internal policy and other relevant laws, or destroyed immediately. Personal information moved to the database is not used for any other purpose unless required by law.

2. Destruction deadline

A user's personal information is destroyed within 5 days from the end of the retention period where the retention period has elapsed, and within 5 days from the date on which the processing of the personal information is deemed unnecessary — such as upon the user's request for destruction, achievement of the purpose of processing, discontinuation of the relevant service, or termination of business — where the personal information has become unnecessary.

3. Destruction method

Information in the form of electronic files is destroyed using a technical method that renders the records unrecoverable.

4. User's request for destruction

A user may request destruction of their personal information by withdrawing their membership from the Service or by contacting the Company directly. In this case, the relevant user's personal information is destroyed immediately.

Article 6 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

The Company may use cookies to provide web-based services.

Cookies are used to support faster and more convenient use.

1. A cookie is a very small text file sent to the user's browser by the server used to operate the Company's website, and is stored on the user's computer.

2. Cookies are used to keep the user logged in and to provide better services. When a user visits the website, the website server reads the contents of the cookies stored on the user's device to maintain the user's preferences and provide optimized services.

3. Cookies do not store personally identifying information such as name or phone number, and users have the choice regarding cookie installation. Accordingly, by setting options in the web browser, a user may allow all cookies, go through a confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if a user refuses to install cookies, there may be difficulties in providing the Service.

Article 7 (Amendment of the Privacy Policy)

When there are additions, deletions, or modifications to the content of this Privacy Policy, the Company will announce it through the website "Notices" at least 7 days before the amendment. However, where there is an important change to users' rights, such as the collection and use of personal information or provision to third parties, the Company will announce it at least 30 days in advance.

Article 8 (Measures to Ensure the Safety of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative, and physical measures necessary to ensure safety.

1. Technical measures against hacking, etc.

The Company does its utmost to prevent personal information from being leaked or damaged by hacking, computer viruses, and the like. To prepare against the damage of personal information, the Company backs up data from time to time, uses the latest anti-virus programs to prevent users' personal information or data from being leaked or damaged, and ensures that personal information can be transmitted safely over the network through encrypted communication.

In addition, the Company controls unauthorized access from outside using an intrusion prevention system, and strives to equip itself with all possible technical devices to secure system-level security.

2. Retention of access records and prevention of forgery/alteration

The Company retains and manages records of access to the personal information processing system for at least 6 months, and uses security functions to prevent access records from being forged, altered, stolen, or lost.

3. Restriction of access to personal information

The Company takes the measures necessary to control access to personal information by granting, changing, and revoking access rights to the database system that processes personal information, and controls unauthorized access from outside using an intrusion prevention system.