Privacy Policy

Article 1 (Purpose of Processing, Items Collected, and Retention/Use Period of Personal Information)

  1. 1. Baerae Co., Ltd. (hereinafter the "Company") provides procedures and standards for the processing of users' personal information in accordance with Article 31 of the Personal Information Protection Act, and collects and processes users' personal information for the following purposes.

  2. 2. Users' personal information shall not be used for purposes other than those listed below. If the purpose or items of use are changed, the Company will take necessary measures such as obtaining the user's separate consent in advance pursuant to Article 18 of the Personal Information Protection Act.

  3. 3. The Company processes and retains personal information within the processing/retention period set forth by applicable laws or within the processing/retention period agreed upon by the user when collecting personal information.

Personal information processed with the data subject's consent

TypePurposeItemsRetention and Use Period
Membership registration and managementIdentity verification, conclusion and performance of service use agreement, prevention of fraudulent use, customer supportEmail address, social login identifier (KakaoTalk, Google, Apple, etc.), phone number, passkey authentication information, records of improper use, information generated during customer supportUntil membership withdrawal or consent withdrawal (provided that information will be retained for the relevant period if retention is required by applicable laws)
Service use experience analysisService quality maintenance and improvement, error analysis, security managementAccess date and time, access logs, service use records, visit records, device information (OS, device model, app version, advertising identifier, IP address, cookies or similar identifiers), error logs, performance logs, push notification settings, records of improper use, information generated during customer support14 months (provided that information will be retained for the relevant period if retention is required by applicable laws)
Digital asset inquiry serviceProvision of digital asset exchange linking and asset status inquiry servicesName of digital asset exchange, access token information (token issue date and expiration), exchange connection status information (connection status, scheduled end date)Until membership withdrawal or consent withdrawal (provided that information will be retained for the relevant period if retention is required by applicable laws)
MarketingNotification of events and promotions, and provision of benefitsMarketing reception consent status, email address, social login identifier (KakaoTalk, Google, Apple, etc.), phone numberOne year from the event end date

Methods of collecting personal information

The Company collects users' personal information for service use through the following methods.

  1. 1. Information directly entered by the user for membership registration and service use

  2. 2. Social login identifiers and profile information received from third-party services with the Member's consent

  3. 3. Information collected/generated during consultations and customer complaint handling

  4. 4. Collection through online and offline events/surveys

  5. 5. Information automatically collected during service use

Information such as digital asset transaction records viewed and generated through the Service is not transmitted to or stored on the Company's servers, and is stored only on the user's device (app). Such information is not transmitted to external servers, and is immediately deleted from the device when the app is deleted.

Article 2 (Provision of Personal Information to Third Parties)

As a rule, the Company does not provide users' personal information to outside parties. However, the following cases are exceptions.

  1. 1. When the user has separately consented in advance

  2. 2. When there are special provisions in applicable laws or when there is a lawful request from related authorities such as investigative agencies or supervisory authorities

  3. 3. When provision is necessary for statistical compilation, academic research, or market research, in a form that cannot identify a specific individual

Article 3 (Outsourcing of Personal Information Processing)

  1. 1. The Company may outsource part of its personal information processing duties to external specialized companies for smooth service provision, and currently outsources personal information processing as follows for smooth handling of personal information.

Outsourced PartyDescription of Outsourced Work
Google LLCUser statistical analysis
  1. 1. The Company transfers personal information collected from users overseas as follows pursuant to Article 28-8(1)(3) of the Personal Information Protection Act (processing/storage outsourcing for contract performance). To refuse the overseas transfer of personal information during service use, you can download and install the add-on for your current web browser at tools.google.com/dlpage/gaoptout to opt out of Google's information processing.

  1. 1. Recipient and contact: Google LLC (https://analytics.google.com/)

  2. 2. Country of transfer : United States

  3. 3. Date and method of transfer : Transmission via network at the time of visitor service use within the website

  4. 4. Personal information items transferred : Cookies, device browser data, IP address, site/app activity collection (no personal identifying information transferred)

  5. 5. Purpose of recipient's use: For statistical measurement of user interactions, retention of user and event data

  6. 6. Retention and use period : 14 months

  1. 1. When concluding outsourcing contracts, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in the contract or other documents matters such as the prohibition of personal information processing for purposes other than the outsourced work, technical/managerial protection measures, restrictions on re-outsourcing, management and supervision of the outsourcee, and liability for damages, and supervises whether the outsourcee handles personal information safely. If the company changes, the Company will announce the changed company name on the privacy policy screen.

  2. 2. The contents of outsourced work and the outsourcee may change, and any changes will be announced through this policy or a separate notice.

Article 4 (Procedures and Methods for Destroying Personal Information)

  1. 1. The Company shall destroy personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.

  2. 2. Information in electronic file form is deleted in a manner that cannot be restored or reproduced, and personal information recorded or stored on paper documents is destroyed by shredding or incineration.

Article 5 (Rights of Users and How to Exercise Them)

  1. 1. Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information, and may withdraw their consent to matters they have agreed to.

  2. 2. Users may request to unlink an account, withdraw membership, or revoke marketing reception through in-app settings, the customer center, or other methods provided by the Company.

  3. 3. Requests for access to and suspension of processing of personal information may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

  4. 4. Requests to correct or delete personal information may not be made if the personal information is specified as a subject of collection by other laws.

Article 6 (Measures to Ensure the Security of Personal Information)

  1. 1. The Company takes the following managerial, technical, and physical measures to ensure the security of personal information.

    1. 1. Managerial measures: Establishment and implementation of personal information protection guidelines, operation of dedicated organizations, regular employee training

    2. 2. Technical measures: Access rights management for personal information processing systems, installation of access control systems, encryption of personal information, installation and updating of security programs

    3. 3. Physical measures: Access control through internal and cloud firewalls

  2. 2. The Company implements measures such as access rights management, establishment of internal management plans, retention of access records, encryption, operation of security programs, and minimum access control for authorized persons.

Article 7 (Installation and Operation of Cookies and Similar Automatic Collection Devices)

The Company may use cookies or similar technologies to provide more convenient services to users. Users may refuse the storage of cookies through the following browser or device settings, but in this case, some service use may be restricted.

  1. 1. Internet Explorer : Tools menu in the upper right of the web browser > Internet Options > Privacy > Settings > Advanced

  2. 2. Edge: Settings menu in the upper right of the web browser > Cookies and site permissions > Manage and delete cookies and site data

  3. 3. Chrome: Settings menu in the upper right of the web browser > Privacy and security > Cookies and other site data

Article 8 (Collection, Use, and Refusal of Behavioral Information)

  1. 1. The Company collects and uses behavioral information to provide optimized customized services and benefits to data subjects, online customized advertising, and similar services during service use.

  2. 2. The Company collects behavioral information as follows.

Items of Collected Behavioral InformationMethod of CollectionPurpose of CollectionRetention/Use Period and Subsequent Processing
User's web/app service access records and usage records such as clicks (app version, country, region, carrier, device information, device operating system, device language settings, etc.)Automatically collected and transmitted through generation information collection tools for major actions performed within the user's web/appService quality improvement and statistical purposesRetain until purpose is achieved, then delete
  1. 1. The Company collects and uses advertising identifiers for online customized advertising in mobile apps. The data subject can block or allow customized advertising in the app by changing the settings on the mobile device.

    Block/allow advertising identifier on smartphone

    1. 1. (Android) Settings → Privacy → Ads → Reset advertising ID or Delete advertising ID

    2. 2. (iPhone) Settings → Privacy → Tracking → Turn off 'Allow apps to request to track'

※ Menus and methods may differ slightly depending on the mobile OS version.

Article 9 (Personal Information Protection Officer and Contact)

The Company has designated and operates a personal information protection officer to take overall responsibility for personal information processing and to handle inquiries, complaints, and damage relief related to users' personal information.

  1. 1. Name: Junghyun Kim

  2. 2. Position: Information Security Officer

  3. 3. Contact: 010-4306-0030, privacy@baerae.com

Inquiries, complaints, and requests for damage relief related to personal information may be directed to the officer above.

Article 10 (Remedies for Infringement of Rights and Interests)

The Company guarantees the data subject's right to self-determination of personal information, and strives for consultation and damage relief due to personal information infringement. If you need to file a report or seek consultation, please contact the relevant department below.

CategoryPersonal Information Protection DepartmentContactEmail
ZKAPInformation Security Team010-4306-0030privacy@baerae.com

If you need damage relief or consultation regarding personal information infringement, you may contact the following organizations.

  1. 1. Personal Information Infringement Report Center (operated by Korea Internet & Security Agency)

    1. 1. Website : privacy.kisa.or.kr

    2. 2. Phone : 118 (without area code)

  2. 2. Personal Information Dispute Mediation Committee

    1. 1. Website : www.kopico.go.kr

    2. 2. Phone : 1833-6972 (without area code)

  3. 3. Supreme Prosecutors' Office

    1. 1. Website : www.spo.go.kr

    2. 2. Phone : 1301 (without area code)

  4. 4. Cyber Bureau of the National Police Agency

    1. 1. Website : ecrm.cyber.go.kr

    2. 2. Phone : 182 (without area code)

Article 11 (Changes to the Privacy Policy)

If the Company changes the privacy policy, it will continuously disclose the timing of the change and implementation and the changed contents, and will disclose changes by comparing before and after so that users can easily check the changed contents.

Addendum

This privacy policy shall apply from April 10, 2026.