← Back to home

Privacy Policy

Potatonet Co., Ltd. (hereinafter referred to as the “Company”) establishes and discloses the following personal information processing policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to promptly and smoothly process complaints related thereto.
This Privacy Policy is effective as of January 20, 2025.

Article 1 (Purpose of Use of Personal Information)

The personal information used by the Company will not be used for any purpose other than the following purposes, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

Sign up and manage your homepage

Handling complaints

We use personal information for the purpose of identifying the identity of the complainant, verifying the complaint, contacting and notifying the complainant for fact-finding, and notifying the result of processing.

Providing goods or services

We use personal information for the purpose of providing services, identification, age verification, payment and settlement, and debt collection.

Leverage marketing and advertising

We use personal information for purposes such as verifying the validity of the Service and statistics on members' use of the Service.

Article 2 (Use and Retention Period of Personal Information)

The Company shall use and store personal information within the period of retention and use of personal information in accordance with laws and regulations or within the period of retention and use of personal information agreed upon when collecting personal information from the information subject. We use and retain your personal information for the following periods:

Article 3 (Items of Personal Information We Collect)

We use personal information for the purpose of identifying the identity of the complainant, verifying the complaint, contacting and notifying the complainant for fact-finding, and notifying the result of processing.

The following information is collected when you register on our website:

The following information may be collected during the course of your use of the Service:

We collect the following information when you use our paid services:

Article 4 (Consignment of Personal Information Processing)

The Company consigns personal information processing as follows to ensure smooth personal information processing.

Custodians Country Items of personal information we outsource What we do Retention and Usage Period
NicePayments United Kingdom Card number, expiration date, 6-digit date of birth, password Payment gateways Retention periods in accordance with applicable law

In accordance with Article 26 of the Personal Information Protection Act, when entering into an outsourcing contract, the Company specifies in documents such as contracts the prohibition of using personal information for purposes other than the performance of outsourced tasks, technical and administrative protection measures, restrictions on re-consignment, management and supervision of the outsourcer, and liability for damages, and supervises whether the outsourcer handles personal information safely.

If the content of the consignment or the trustee changes, we will disclose it through this privacy policy without delay.

Article 5 (Procedure and Method of Destruction of Personal Information)

The Company shall destroy personal information without delay when it becomes unnecessary, such as the expiration of the personal information retention period or the achievement of the purpose of use.

If the personal information retention period agreed to by the information subject has expired or the purpose of processing has been achieved, but the personal information must continue to be retained in accordance with other laws and regulations, the personal information shall be moved to a separate database (DB) or stored in a different place.

Destruction Procedures

The Company will select the personal information for destruction and destroy the personal information with the approval of the Company's Privacy Officer.

Destruction methods

Article 6 (Rights and Obligations of Information Subjects and Legal Representatives and Methods of Exercising Them)

Article 7 (Measures to secure the safety of personal information)

The Company takes the following measures to ensure the safety of personal information.

Conduct regular self-audits

We conduct self-audits on a regular basis (once a quarter) to ensure stability in the handling of personal information.

Minimize and train privacy staff

We take measures to manage personal information by designating employees who handle personal information and minimizing it by limiting it to those in charge.

Develop and implement an internal control plan

We have established and implemented an internal management plan for the safe handling of personal information.

Technical measures against hacking and more

The Company installs security programs, periodically updates and inspects them, installs systems in areas with controlled access from the outside, and monitors and blocks them technically and physically to prevent leakage and damage of personal information due to hacking or computer viruses.

Encryption of personal information

Your personal information is stored and managed in encrypted form so that only you know your password, and for sensitive data, we use additional security features such as encrypting file and transmission data or using file locks.

Archiving and tamper-proofing access records

We keep and manage records of access to the personal information processing system for at least one year, but if we add personal information about 50,000 or more information subjects or process unique identification information or sensitive information, we keep and manage it for at least two years. In addition, we use security functions to prevent access records from being falsified, stolen, or lost.

Restrict access to personal information

We take necessary measures to control access to personal information by granting, changing, and canceling access rights to the database system that processes personal information, and control unauthorized access from the outside using an intrusion prevention system.

Use locks for document security

We keep documents, secondary storage media, etc. containing personal information in a secure, locked location.

Control access for unauthorized users

We have a separate physical storage location for personal information and have established and operated access control procedures for it.

Article 8 (Installation and operation of devices that automatically collect personal information and rejection thereof)

The Company uses 'cookies' that store and retrieve usage information from time to time to provide individualized services to users.

Cookies are small amounts of information sent to your computer's browser by the server used to run the website and are sometimes stored on your PC's hard disk.

Article 9 (Collection, Use, Provision, and Rejection of Behavioral Information)

We do not collect, use, or provide behavioral information for online personalized advertising or otherwise.

Article 10 (Privacy Officer)

The Company is responsible for the overall handling of personal information, and designates a personal information protection officer and a personal information protection manager as follows to handle complaints and damage relief from information subjects related to the handling of personal information.

Privacy Officer

Privacy Officer

The information subject may inquire about all personal information protection-related inquiries, complaints, damage relief, etc. arising from the use of the Company's services (or business) to the person in charge of personal information protection and the department in charge. The Company will respond to and handle inquiries from information subjects without delay.

Article 11 (Department to receive and process requests for access to personal information)

The information subject may make a request for access to personal information pursuant to Article 35 of the Personal Information Protection Act to the following departments.

The Company will endeavor to promptly process requests for access to personal information from information subjects.

Privacy Officer

Article 12 (Remedies for infringement of the rights and interests of the information subject)

The information subject may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of the Korea Internet & Security Agency to receive relief from personal information infringement. For other reports and consultations on personal information infringement, please contact the following organizations.

A person whose rights or interests have been infringed by an action or omission taken by the head of a public institution in response to a request pursuant to the provisions of Articles 35 (Access to Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.

For more information about administrative appeals, please visit the website of the Central Administrative Appeals Commission (www.simpan.go.kr).

Article 13 (Changes to the Privacy Policy)

This Privacy Policy is effective as of January 20, 2025.

Our previous Privacy Policy can be found below (blank if no previous entry)