> For the complete documentation index, see [llms.txt](https://docs.contiple.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.contiple.com/eng/privacypolicy/2026-8-11.md).

# August 11, 2026

## **NHN Privacy Policy**

NHN Corporation (hereinafter the "Company") complies with the relevant laws of the Republic of Korea and the personal information protection regulations that personal information controllers must observe, and establishes this Privacy Policy in accordance with applicable laws to protect the rights and interests of users.

The Privacy Policy of Contiple covers the following:

1. Personal Information Collected: Items, Purposes, and Methods of Collection
2. Sharing and Provision of Personal Information
3. Outsourcing of Personal Information Processing
4. Overseas Transfer of Personal Information
5. Retention and Use Period of Personal Information
6. Procedures and Methods for Destroying Personal Information
7. Rights of Users and Legal Representatives and How to Exercise Them
8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
9. Measures to Ensure the Security of Personal Information
10. Contact Information of the Chief Privacy Officer
11. Scope of Application of This Privacy Policy
12. Duty of Notification

***

### 1. Personal Information Collected: Items, Purposes, and Methods of Collection

**A. Items and Purposes of Personal Information Collected**\
**The Company processes the following personal information items without the consent of the data subject, pursuant to Article 15(1)4 and Article 15(1)6 of the Personal Information Protection Act.**

<table data-header-hidden><thead><tr><th valign="top">Text</th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Legal Basis</td><td valign="top">Personal Information Items</td><td valign="top">Purpose</td></tr><tr><td valign="top">Personal Information Protection Act, Article 15(1)4 (Conclusion and performance of a contract)</td><td valign="top"><p><strong>At sign-up</strong></p><p>- Email (ID), password, name, country code, mobile phone number, sign-up IP, member type</p><p></p><p><strong>When changing member type</strong></p><p>- Sole Proprietor: business registration number, business name, representative's name, business type/category, business address, business registration certificate, representative's identification / (Optional) business phone number</p><p>- Corporation: business registration number, business name, representative's name, business type/category, business address, business registration certificate, identification of the representative if the member is the corporate representative, certificate of employment and power of attorney if the member is an employee of the corporation / (Optional) business phone number</p><p>- Overseas Business: Tax ID, trade name, representative's name, business address, business verification documents</p><p>* However, attached files such as the business registration certificate, representative's identification, certificate of employment, and power of attorney are destroyed immediately if the application is rejected.</p><p></p><p><strong>When adding a payment method</strong></p><p>- Credit card: card issuer name, credit card number (masked)</p><p>- Bank transfer (tax invoice): contact person information (email, name, phone number)</p><p></p><p><strong>At identity verification</strong></p><p>- Name, date of birth, gender, nationality status (domestic/foreign), mobile carrier, mobile phone number, Connecting Information (CI), Duplicate Joining Verification Information (DI), IP address</p><p>* This information is not stored by the Company and is processed by NHN KCP Corp., which has been entrusted with the relevant work.</p><p></p><p><strong>When requesting billing statement delivery</strong></p><p>- Email address for receiving statements</p><p></p><p><strong>During service use</strong></p><p>- IP address, cookies, date and time of visit, service usage records, records of improper use, device information (manufacturer, model name, device environment information), payment and purchase records</p></td><td valign="top"><p>- To provide the services agreed with the user, to verify identity in connection with service provision, to process purchases and payments, to deliver billing statements, and to provide content.</p><p>- To confirm the intent to sign up, to verify and identify the user, to confirm the intent to withdraw membership, and to handle inquiries or complaints.</p><p>- To restrict the use of services by members who violate laws or the terms of use; to prevent and sanction improper use and other acts that interfere with the smooth operation of the services as well as unauthorized acts; to prevent account theft and fraudulent transactions; to deliver notices; and to retain records for dispute resolution — for the protection of users and the operation of the services.</p><p>- To provide services based on demographic characteristics, analyze access frequency, improve features, compile statistics on service use, and provide new services reflecting analysis of users' purchasing and service usage tendencies, interests, and usage records based on service analysis and statistics.</p><p>- To provide event information and promotional information for the purposes of events and promotions. (However, separate consent is obtained for the delivery of marketing information.)</p></td></tr><tr><td valign="top"><p>Personal Information Protection Act, Article 15(1)4 (Conclusion and performance of a contract),</p><p>Article 15(1)6 (Pursuit of legitimate interests)</p></td><td valign="top">- Email (ID)</td><td valign="top">- To ensure stable service operation by preventing indiscriminate re-registration after membership withdrawal.</td></tr></tbody></table>

**The Company processes the following personal information items with the consent of the data subject, pursuant to Article 15(1)1 of the Personal Information Protection Act.**

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Legal Basis</td><td valign="top">Personal Information Items</td><td valign="top">Purpose</td></tr><tr><td valign="top">Personal Information Protection Act, Article 15(1)1 (Consent of the data subject)</td><td valign="top"><p><strong>For sales inquiries</strong></p><p>- Name, email, phone number, company/organization name, department, job title, inquiry details</p><p></p><p><strong>For 1:1 inquiries</strong></p><p>- Common: name, email, phone number, inquiry details / (Optional) attached files</p><p>- Additional information collected for sales inquiries: company name, department, job title</p></td><td valign="top">- To respond to inquiries.</td></tr><tr><td valign="top">Personal Information Protection Act, Article 15(1)1 (Consent of the data subject)</td><td valign="top"><p><strong>When consenting for marketing purposes</strong></p><p>- Email (ID), name, mobile phone number, member type, business name</p></td><td valign="top">- To send marketing information such as events and promotions.</td></tr></tbody></table>

**B. Methods of Collecting Personal Information**\
The Company collects personal information through the following methods:\
\- Website, mobile devices, written forms, fax, telephone, inquiry boards, and email

***

### 2. Sharing and Provision of Personal Information

The Company uses users' personal information within the scope notified in "1. Personal Information Collected: Items, Purposes, and Methods of Collection," and in principle does not use personal information beyond that scope or provide it to third parties without the user's prior consent. The following cases are exceptions:

\- Where the user has given prior consent\
\- Where required by the provisions of applicable laws, or where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for investigative purposes

***

### 3. Outsourcing of Personal Information Processing

To improve its services, the Company outsources the processing of personal information as set out below. In accordance with applicable laws, the Company stipulates the necessary matters in the outsourcing agreements to ensure that personal information is managed securely. The Company's outsourcing service providers and the scope of the outsourced work are as follows. (Companies marked with an asterisk (\*) are sub-processors.)

| Service Provider                                                  | Outsourced Work                                                   | Retention and Use Period                                                    |
| ----------------------------------------------------------------- | ----------------------------------------------------------------- | --------------------------------------------------------------------------- |
| NHN Cloud Co., Ltd.                                               | Infrastructure provision and operation, message delivery services | Upon membership withdrawal or upon termination of the outsourcing agreement |
| \*Hyundai Futurenet Co., Ltd., \*KT Co., Ltd., \*Gemtec Co., Ltd. | Message delivery services                                         | Upon membership withdrawal or upon termination of the outsourcing agreement |
| Infobank Co., Ltd.                                                | Consultation Talk message delivery                                | Upon membership withdrawal or upon termination of the outsourcing agreement |
| Bridgetec                                                         | Development and operation of the customer support system          | Upon membership withdrawal or upon termination of the outsourcing agreement |
| NHN KCP Co., Ltd.                                                 | Credit card payment processing                                    | Upon membership withdrawal or upon termination of the outsourcing agreement |

***

### 4. Overseas Transfer of Personal Information

The Company transfers personal information collected from customers overseas as set out below. If you refuse the overseas transfer, you will not be able to use the related services. If you do not wish your information to be transferred overseas, you may withdraw your consent or terminate your use of the services, or submit a request through the help center.

※ Personal Information Protection Act, Article 28-8(1)3 (Outsourcing of processing or storage for the performance of a contract)

| Transferee (Processor)                                                                                                                        | Country of Transfer | Personal Information Items Transferred (Outsourced)   | Timing and Method of Transfer                                                                 | Purpose of Use             | Retention and Use Period                                            |
| --------------------------------------------------------------------------------------------------------------------------------------------- | ------------------- | ----------------------------------------------------- | --------------------------------------------------------------------------------------------- | -------------------------- | ------------------------------------------------------------------- |
| <p>Sub-processor of NHN Cloud Corp.</p><p>Vonage Holdings Corp<br>(<a href="mailto:Privacy@vonage.com"><Privacy@vonage.com></a>)</p>          | United States       | Sender number, recipient number, text message content | Transmitted over a secure network when personal information is required for business purposes | International SMS delivery | Processing permitted until termination of the outsourcing agreement |
| <p>Sub-processor of NHN Cloud Corp.</p><p>Infobip<br>(data-protection-<br><a href="mailto:officer@infobip.com"><officer@infobip.com></a>)</p> | Singapore           | Sender number, recipient number, text message content | Transmitted over a secure network when personal information is required for business purposes | International SMS delivery | Processing permitted until termination of the outsourcing agreement |

***

### 5. Retention and Use Period of Personal Information

In principle, the Company retains a user's personal information until the user withdraws membership. (Where separate consent has been obtained, the information is retained for the period consented to.) In addition, the following information is retained even after membership withdrawal, for the periods and reasons specified below.

**A. Grounds for Retention under the Company's Internal Policy**\
\- Email (ID)\
Reason for retention: To ensure stable service operation by preventing indiscriminate re-registration after membership withdrawal\
Retention period: 90 days. However, for members whose service agreement has been terminated under the terms of use, 3 years

**B. Grounds for Retention under Applicable Laws**\
Where retention is required under applicable laws such as the Commercial Act and the Act on the Consumer Protection in Electronic Commerce, Etc., the Company retains member information for the period prescribed by those laws. In such cases, the Company uses the retained information solely for the purpose of retention. The retention periods are as follows:

\- Log records relating to service use\
Reason for retention: Protection of Communications Secrets Act, Article 15-2(2)\
Retention period: 3 months

\- Records on consumer complaints or dispute resolution\
Reason for retention: Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, Etc., Article 6(1)4\
Retention period: 3 years

\- Records on contracts or withdrawal of subscription\
Reason for retention: Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, Etc., Article 6(1)2\
Retention period: 5 years

\- Records on payment and the supply of goods\
Reason for retention: Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, Etc., Article 6(1)3\
Retention period: 5 years

\- Records on the issuance of tax invoices, limited to users of the electronic tax invoice service\
Reason for retention: Public Notice on Matters to Be Observed by Businesses Establishing and Operating Electronic (Tax) Invoice Systems and on Standard Certification, Article 6(3)\
Retention period: 3 years

***

### 6. Procedures and Methods for Destroying Personal Information

In principle, a user's personal information is destroyed without delay once the purpose of its collection and use has been achieved.\
The procedures and methods for destroying personal information are as follows.

**A. Destruction Procedure**\
Information entered by a user for purposes such as sign-up is, once its purpose has been achieved, transferred to a separate database (or a separate filing cabinet in the case of paper documents), stored for a certain period in accordance with the Company's internal policy and the grounds for information protection under applicable laws (see Retention and Use Period), and then destroyed. Such personal information is not used for any purpose other than retention, except as required by law.

**B. Destruction Method**\
Personal information printed on paper is destroyed by shredding or incineration.\
Personal information stored in electronic file format is deleted using technical methods that render the records unrecoverable.

***

### 7. Rights of Users and Legal Representatives and How to Exercise Them

Users and their legal representatives may at any time request the Company to allow access to, correct, delete, or suspend the processing of their personal information, or to withdraw their consent. However, in such cases, some or all of the services may become unavailable.

Users may view and modify their personal information directly at any time under "My Page," and may terminate their membership (withdrawing consent or deleting their personal information) through "Withdraw Membership."

Alternatively, if you contact the Chief Privacy Officer in writing, by telephone, or by email, we will take action without delay.

If a user requests correction of an error in their personal information, the Company will not use or provide that personal information until the correction is completed. If the incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction results without delay so that the correction is made.

Personal information for which the Company has received a request for withdrawal of consent or deletion from a user or legal representative is processed as specified in "5. Retention and Use Period of Personal Information," and is handled so that it cannot be accessed or used for any other purpose.

***

### 8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

**A. What Are Cookies**\
To provide personalized and customized services, the Company uses "cookies," which store and retrieve user information from time to time. A cookie is a very small text file sent by the server operating a website to the user's browser and stored on the hard disk of the user's computer.

**B. Purpose of Using Cookies**\
The Company uses cookies to analyze which of its services users have used and how they have used them, in order to provide optimized, customized information to users.

**C. Installation, Operation, and Refusal of Cookies**\
Users have the option to decide whether to allow cookies. Accordingly, users may configure their web browser options to allow all cookies, to be prompted each time a cookie is stored, or to refuse the storage of all cookies.\
\
However, if you refuse the storage of cookies, you may experience difficulty using some of the Company's services that require login.\
How to specify whether to allow the installation of cookies\
\
\- Chrome web browser\
Menu at the top right \[Settings] > \[Privacy and security] > \[Third-party cookies]\
\
\- Edge web browser\
Menu at the top right \[Settings] > \[Privacy, search, and services] > \[Cookies]

**D. Installation and Operation of Cookies in Mobile Services**\
To provide an internet environment in its mobile services that is the same as or similar to the PC environment, the Company may also use "cookies" on mobile devices (e.g., smartphones, tablet PCs). However, the Company does not arbitrarily collect third-party cookies containing personal information without the user's explicit consent. On mobile devices as well, you can choose whether to allow cookies through your web browser settings. Although the specifics may vary somewhat depending on the mobile device's operating system and web browser, in most cases you can decide whether to allow cookies or delete all existing cookies through the mobile web browser's settings. However, if you refuse the storage of cookies, you may experience inconvenience when using some services that require login.

How to specify whether to allow the installation of cookies

\- Chrome web browser\
Menu at the top right \[Settings] > \[Advanced] > \[Site settings] > \[Third-party cookies]

\- Safari web browser\
Mobile device \[Settings] > \[Safari] > \[Advanced] > \[Block All Cookies]

***

### 9. Measures to Ensure the Security of Personal Information

In processing users' personal information, the Company takes the following technical and administrative measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged.

**A. Encryption of Personal Information**\
The Company encrypts personal information such as passwords and payment methods in accordance with the standards required by law. For important data, the Company takes additional security measures, such as encrypting files and transmitted data, to protect users' personal information.

**B. Measures Against Hacking and Similar Threats**\
The Company makes every effort to prevent members' personal information from being leaked or damaged by hacking, computer viruses, or similar threats. The Company backs up data regularly in preparation for damage to personal information, uses the latest anti-virus programs to prevent users' personal information and data from being leaked or damaged, and enables personal information to be transmitted securely over networks through encrypted communications. The Company also controls unauthorized external access using intrusion prevention systems, and strives to equip itself with every possible technical device to secure its systems.

**C. Minimizing and Training Personnel Who Handle Personal Information**\
The Company limits personnel who handle personal information to designated staff, assigns them separate passwords that are updated regularly, and continually emphasizes compliance with the Company's Privacy Policy through frequent training for those staff.

**D. Operation of a Dedicated Privacy Protection Body**\
Through an in-house dedicated privacy protection body, the Company verifies the implementation of its Privacy Policy and staff compliance, and works to correct any issues immediately upon discovery.\
However, the Company assumes no responsibility for problems arising from the leakage of personal information such as IDs and passwords due to the user's own negligence or issues on the internet.

***

### 10. Contact Information of the Chief Privacy Officer

The Company designates a Chief Privacy Officer responsible for gathering opinions on personal information and handling complaints. You may report any privacy-related grievances arising from your use of the Company's services to the Chief Privacy Officer using the contact information below. The Company will respond promptly and fully to reports from users.

<table data-header-hidden><thead><tr><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><p>- Chief Privacy Officer</p><p>Name: Sunyoung Hwang<br>Department/Title: Legal &#x26; Policy Group / Director<br>Email: nhn.privacy@nhn.com<br>Phone: 1544-6859</p></td></tr></tbody></table>

If you need to report or consult on other matters concerning infringement of personal information, please contact the following organizations:

\- Personal Information Dispute Mediation Committee ([www.kopico.go.kr](http://www.kopico.go.kr), 1833-6972 without area code)\
\- Privacy Infringement Report Center (privacy.kisa.or.kr, 118 without area code)\
\- Cybercrime Investigation Division, Supreme Prosecutors' Office ([www.spo.go.kr](http://www.spo.go.kr), 1301 without area code)\
\- Cyber Bureau, Korean National Police Agency (ecrm.cyber.go.kr, 182 without area code)

***

### **11. Scope of Application of This Privacy Policy**

Please note that this Privacy Policy does not apply to the collection of personal information by websites linked from the services provided by the Company.

***

### **12. Duty of Notification**

Any additions, deletions, or modifications to this Privacy Policy will be announced through the "Notices" section of the website at least 7 days before the revision takes effect.

***

\
Date of announcement: August 4, 2026\
Effective date: August 11, 2026
