> For the complete documentation index, see [llms.txt](https://docs.contiple.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.contiple.com/eng/privacypolicy/2024-11-4.md).

# November 4, 2024

## **NHN Privacy Policy**

NHN Corporation (hereinafter the "Company") complies with the laws of the Republic of Korea and the personal information protection regulations that a personal information controller is required to observe, and has established this Privacy Policy in accordance with the applicable laws in order to protect the rights and interests of its users.

The Contiple Privacy Policy covers the following:

1. Personal Information Collected and Methods of Collection
2. Purposes of Collection and Use of Personal Information
3. Sharing and Provision of Personal Information
4. Consignment of Personal Information Processing
5. Retention and Use Period of Personal Information
6. Procedures and Methods for Destruction of Personal Information
7. Rights of Users and Legal Representatives and How to Exercise Them
8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
9. Measures to Ensure the Security of Personal Information
10. Contact Information of the Chief Privacy Officer
11. Scope of Application of This Privacy Policy
12. Duty of Notification

***

### **1. Personal Information Collected and Methods of Collection**

**A. Personal information collected**

* The following personal information is collected in the course of 1:1 inquiries.
  * (Required) Name, phone number, email address, inquiry details, and additional information collected for adoption inquiries (company name, department, job title)
  * (Optional) Attachments
* The following personal information is collected in the course of adoption inquiries.
  * (Required) Name, email address, phone number, company/organization name, department, job title, inquiry details

**B. Methods of collection**

* The Company collects personal information through the following method.
  * Website

***

### **2. Purposes of Collection and Use of Personal Information**

The Company uses the personal information it collects for the following purposes.

* To provide the services promised to users, to process purchases and payments, to deliver billing statements, and to provide content.
* To respond to inquiries and handle complaints.
* To protect users and operate the services, including restricting the use of the services by members who violate laws or the terms of use; preventing and sanctioning fraudulent use, acts that interfere with the smooth operation of the services, and unauthorized activities; preventing account theft and fraudulent transactions; delivering notices; and retaining records for dispute resolution.
* To provide services based on demographic characteristics, analyze access frequency, improve features, compile statistics on service use, and develop new services that reflect analysis of users' purchasing and service usage patterns, interests, and usage history based on service analysis and statistics.

***

### **3. Sharing and Provision of Personal Information**

The Company uses users' personal information only within the scope disclosed in "2. Purposes of Collection and Use of Personal Information," and does not use it beyond that scope or, as a general rule, provide it to third parties without the user's prior consent. The following cases are exceptions.

* Where the user has given prior consent
* Where required by law, or where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by law

***

### **4. Consignment of Personal Information Processing**

To improve its services, the Company consigns the processing of personal information as set out below, and stipulates the matters necessary to ensure that personal information is managed securely when entering into consignment agreements, in accordance with applicable laws. The Company's consignees and the scope of the consigned work are as follows.

| **Consignee**         | **Consigned work**                                            | **Retention and use period**                   |
| --------------------- | ------------------------------------------------------------- | ---------------------------------------------- |
| NHN Cloud Corporation | Provision and operation of infrastructure                     | Until termination of the consignment agreement |
| BRIDGETEC             | Development and operation of the customer consultation system | Until termination of the consignment agreement |

***

### **5. Retention and Use Period of Personal Information**

As a general rule, the Company retains personal information until the point of time consented to by the user.

***

### **6. Procedures and Methods for Destruction of Personal Information**

As a general rule, a user's personal information is destroyed without delay once the purpose of its collection and use has been achieved.\
The procedures and methods for destruction are as follows.

**A. Destruction procedures**

Information entered by a user for purposes such as membership registration is, once its purpose has been achieved, transferred to a separate database (or to a separate filing cabinet in the case of paper documents), stored for a certain period in accordance with internal policies and information protection grounds under other applicable laws (see the retention and use period), and then destroyed. Such personal information is not used for any purpose other than retention unless required by law.

**B. Destruction methods**

Personal information printed on paper is destroyed by shredding or incineration.\
Personal information stored in electronic file form is deleted using technical methods that render the records irreproducible.

***

### **7. Rights of Users and Legal Representatives and How to Exercise Them**

Users and their legal representatives may at any time view or modify the registered personal information of themselves or of a child under the age of 14 under their care, and may request withdrawal of membership if they do not agree to the Company's processing of personal information. In such cases, however, use of some or all of the services may become unavailable.\
To view or modify the personal information of a user or of a child under the age of 14, use "Change Personal Information" (or "Edit Member Information"). To withdraw membership (withdraw consent), contact the operations team; after identity verification, the user may directly view, correct, or withdraw.\
Alternatively, users may contact the Chief Privacy Officer in writing, by telephone, or by email, and the Company will take action without delay.\
Where a user requests correction of an error in their personal information, the Company will not use or provide the relevant personal information until the correction is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction without delay so that the correction is made.\
Personal information that has been terminated or deleted at the request of a user or legal representative is handled as specified in "5. Retention and Use Period of Personal Information," and is processed so that it cannot be accessed or used for any other purpose.

***

### **8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices**

**A. What cookies are**

The Company uses "cookies" to store and retrieve user information from time to time in order to provide personalized and customized services. A cookie is a very small text file sent by the server operating a website to the user's browser and stored on the hard disk of the user's computer.

**B. Purpose of using cookies**

The Company uses cookies to analyze which of its services users have used and how they have used them, in order to provide each user with optimized, customized information.

**C. Installation, operation, and refusal of cookies**

Users have the right to choose whether to allow cookies. Accordingly, by adjusting the options in their web browser, users may allow all cookies, be prompted for confirmation each time a cookie is stored, or refuse the storage of all cookies.

However, if a user refuses the storage of cookies, some of the Company's services that require login may be difficult to use.

**How to specify whether to allow cookies**

* Chrome web browser
  * Menu at the top right > \[Settings] > \[Privacy and security] > \[Third-party cookies]
* Edge web browser
  * Menu at the top right > \[Settings] > \[Cookies and site permissions] > \[Manage and delete cookies and site data]

**D. Installation and operation of cookies in mobile services**

In order to provide an internet environment in its mobile services that is the same as or similar to the PC environment, the Company may also use "cookies" on mobile devices (e.g., smartphones, tablet PCs). However, the Company does not arbitrarily collect third-party cookies containing personal information without the user's explicit consent. On mobile devices as well, users can choose whether to allow cookies through their web browser settings. Although the specifics may vary somewhat depending on the mobile device's operating system and web browser, in most cases users can decide whether to allow cookies or delete all existing cookies through the mobile web browser's settings. If a user refuses the storage of cookies, however, use of some services that require login may be inconvenient.

**How to specify whether to allow cookies**

* Chrome web browser
  * Menu at the top right > \[Settings] > \[Advanced] > \[Site settings] > \[Third-party cookies]
* Safari web browser
  * Mobile device \[Settings] > \[Safari] > \[Advanced] > \[Block All Cookies]

***

### **9. Measures to Ensure the Security of Personal Information**

In processing users' personal information, the Company takes the following technical and administrative measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged.

**A. Encryption of personal information**

The Company encrypts personal information such as passwords and payment methods in accordance with the standards required by law, and protects users' personal information by taking additional security measures, including encrypting files and transmitted data for important data.

**B. Measures against hacking and similar threats**

The Company makes every effort to prevent members' personal information from being leaked or damaged by hacking, computer viruses, or similar threats. To guard against damage to personal information, the Company backs up data regularly, uses the latest anti-virus software to prevent users' personal information and data from being leaked or damaged, and enables personal information to be transmitted securely over networks through measures such as encrypted communication. The Company also controls unauthorized external access using an intrusion prevention system, and strives to equip itself with every technical device available to ensure systemic security.

**C. Minimization and training of processing staff**

The Company limits the staff who handle personal information to designated personnel, grants them separate passwords that are updated regularly, and consistently emphasizes compliance with the Company's Privacy Policy through ongoing training.

**D. Operation of a dedicated privacy protection organization**

Through an in-house dedicated privacy protection organization and similar means, the Company verifies the implementation of its Privacy Policy and compliance by responsible personnel, and works to correct and remedy any issues discovered immediately.\
However, the Company assumes no liability whatsoever for problems arising from the leakage of personal information such as IDs and passwords due to the user's own negligence or to issues on the internet.

***

### **10. Contact Information of the Chief Privacy Officer**

The Company has designated a Chief Privacy Officer responsible for gathering opinions on personal information and handling related complaints. You may report any privacy-related complaints arising from your use of the Company's services to the contact information of the Chief Privacy Officer below. The Company will provide prompt and sufficient responses to users' reports.

> **Chief Privacy Officer**
>
> * Name: Hwang Sun-young
> * Department/Title: Legal Policy Group / Director
> * Email: <nhn.privacy@nhn.com>
> * Phone: 1588-3810

> **If you need to report or consult about a personal information infringement, please contact the following organizations.**
>
> * Personal Information Dispute Mediation Committee ([www.kopico.go.kr](http://www.kopico.go.kr), 1833-6972 without area code)
> * Privacy Infringement Report Center (privacy.kisa.or.kr, 118 without area code)
> * Supreme Prosecutors' Office Cyber Investigation Division ([www.spo.go.kr](http://www.spo.go.kr), 1301 without area code)
> * Korean National Police Agency Cyber Investigation Bureau (ecrm.cyber.go.kr, 182 without area code)

***

### **11. Scope of Application of This Privacy Policy**

Please note that this Privacy Policy does not apply to the collection of personal information by web pages linked from the services provided by the Company.

***

### **12. Duty of Notification**

Any addition, deletion, or modification to this Privacy Policy will be announced through the "Notices" section of the website at least 7 days prior to the effective date of the amendment.

***

* Version: v1.0
* Effective date: November 4, 2024
