[PRIVACY POLICY]


Starship Entertainment Co., Ltd. is committed at all times to protecting the personal information of its users.

 

1.       Privacy Policy

2.       Purposes of Processing Personal Information

3.       Period of Processing and Retention of Personal Information

4.       Categories of Personal Information Processed

5.       Outsourcing of Personal Information Processing

6.       Procedures and Methods for Destruction of Personal Information

7.       Rights and Obligations of Users and Legal Guardians and Methods for Exercising Them

8.       Measures to Ensure the Security of Personal Information

9.       Installation, Operation, and Right to Refuse Automatic Personal Information Collection Devices

10.    Department Responsible for Personal Information Protection

11.    Remedies for Infringement of User Rights and Interests

12.    Miscellaneous

13.    Amendments to This Privacy Policy

 

1.     Privacy Policy

 

Starship Entertainment Co., Ltd. (“the Company”) complies with the Personal Information Protection Act and other applicable laws and regulations to protect the freedom and rights of its users, and lawfully processes and securely manages personal information. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses this Privacy Policy to inform users of the Company’s services about the procedures and standards applied to the processing of personal information, and to ensure that any related grievances can be addressed promptly and smoothly.

 

2.     Purposes of Processing Personal Information

 

The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those described below, and if the purpose of use changes, the Company will take the necessary measures, such as notifying users in advance or obtaining separate consent, as required.

 

l  Membership Registration and Management

Personal information is processed for the purposes of confirming intent to register as a member, maintaining and managing membership status, preventing fraudulent use of the service, providing various notices and notifications, and handling complaints.

 

l  Provision of Goods or Services

Personal information is processed for the purposes of providing services, providing content, providing customized recommendation services, and providing fan club benefits.

 

l  Use in Marketing and Advertising

Personal information is processed for the purposes of providing event and promotional information and opportunities to participate, understanding access frequency, and compiling statistics on members’ use of the service.

 

l  Service Enhancement

Personal information is processed for the purpose of improving existing services and developing new services.

 

The Company may use personal information or provide it to third parties without the users consent, to the extent reasonably related to the original purpose of collection and as permitted by law, after comprehensively considering whether doing so would unfairly infringe upon the users interests, whether the additional use or provision is reasonably foreseeable, and whether necessary safeguards, such as encryption, have been implemented.

 

 

3.     Period of Processing and Retention of Personal Information

 

In principle, the Company retains and uses personal information for the period for which separate consent has been obtained from, or notice has been given to, the user, and destroys the personal information without delay once the purpose of its collection and use has been achieved. Notwithstanding the foregoing, the Company may retain personal information for a certain period in accordance with applicable laws and Company policy even after the purpose of collection and use has been achieved.

 

l  Records Relating to Contracts or Withdrawal of Subscription

- Basis for retention: Article 6 of the Act on the Consumer Protection in Electronic Commerce

- Retention period: 5 years

 

l  Records Relating to Payment and Supply of Goods

- Basis for retention: Article 6 of the Act on the Consumer Protection in Electronic Commerce

- Retention period: 5 years

 

l  Records Relating to Consumer Complaints or Dispute Resolution

- Basis for retention: Article 6 of the Act on the Consumer Protection in Electronic Commerce

- Retention period: 3 years

 

l  Books and Supporting Documents Relating to All Transactions as Required by Tax Law

- Basis for retention: Article 85-3 of the Framework Act on National Taxes, Article 116 of the Corporate Tax Act

- Retention period: 5 years

 

l  Login Records Relating to Service Use

- Basis for retention: Article 15-2 of the Protection of Communications Secrets Act

- Retention period: 3 months

 

 

4.     Categories of Personal Information Processed

 

The Company collects only the minimum personal information necessary to provide its services.

 

[Methods of Collecting Personal Information]

When collecting personal information, the Company always informs users in advance and obtains consent where necessary. Personal information is collected through the following methods.

l  Where a user directly enters personal information in the course of membership registration or use of the service

l  Where personal information is received from an affiliated service or organization

l  Where personal information is received through a webpage, email, telephone, or other means in the course of consultation through the customer service center

l  Where a participant directly enters personal information in connection with an online or offline event or other activity

 

[Personal Information Collected With the Users Consent]

In the course of membership registration and use of the service, the Company collects the following minimum personal information with the users consent, and does not collect sensitive information without the users consent.

 

Member Type

Purpose of Collection

Items Collected

Retention and Use Period

Legal Basis

Member

(general members, paid fan club members, etc.)

Providing event and promotional information

-       Mobile phone number, email address

Until consent is withdrawn or membership is terminated

Article 15(1)(i) of the Personal Information Protection Act (consent of the data subject)

Fraud Prevention

-       Name, ID, mobile phone number, email address, and fraud records of any person found to have engaged in fraudulent conduct

1 year from the date of fraudulent use

Article 15(1)(iv) of the Personal Information Protection Act (conclusion and performance of a contract) / Article 15(1)(vi) (achievement of a legitimate interest)

 

[Personal Information Collected Without the Users Consent]

Pursuant to the Personal Information Protection Act and other applicable laws, the Company collects users personal information without consent as set out below.

Member Type

Purpose of Collection

Items Collected

Retention and Use Period

Legal Basis

Member

(general members, paid fan club members, etc.)

Membership registration

-       Name, ID, password, mobile phone number, email address, gender, date of birth

Until membership is terminated

Article 15(1)(iv) of the Personal Information Protection Act (conclusion and performance of a contract)

Responding to customer inquiries

-       Name, mobile phone number (or email address)

      Additional personal information, such as membership details, may be collected depending on the type of inquiry

5 years

 

In addition, the following information is automatically generated or collected during use of the service:

l  IP address, cookies, access time, service usage records, device information, authentication tokens, and the like

 

 

5.     Outsourcing of Personal Information Processing

 

The Company outsources certain tasks necessary for the provision of its services to outside vendors as set out below, and supervises and manages such vendors to ensure they do not violate applicable laws and regulations.

Name of Service Provider

Description of Outsourced Task

Pixelround

Development and operation

Connectwave

Establishment and maintenance of IT systems

 

 

6.     Procedures and Methods for Destruction of Personal Information

 

The Company destroys personal information without delay once it becomes unnecessary, such as upon membership termination, expiration of the retention period, or achievement of the purpose of processing. Notwithstanding the foregoing, where retention is required under applicable laws or Company policy, the Company retains the personal information for the period disclosed in Section 3, Period of Processing and Retention of Personal Information, before destroying it. The procedures and methods for destruction of personal information are as follows.

 

[Destruction Procedure]

The Company destroys personal information without delay once the grounds for destruction have arisen.

 

[Destruction Method]

Personal information recorded and stored in electronic file form is destroyed using methods that render the records unrecoverable, and personal information recorded and stored on paper is destroyed by shredding or incineration.

 

 

7.     Rights and Obligations of Users and Legal Guardians and Methods for Exercising Them

 

Users and legal guardians may exercise the following rights and obligations at any time.

 

l  Users may, at any time, exercise their rights to access, correct, delete, or suspend the processing of their personal information, or to withdraw consent, by contacting the Company.

l  In the case of a child under the age of 14, the childs legal guardian may exercise the rights to access, correct, delete, suspend the processing of, or withdraw consent regarding the childs personal information.

l  Users may withdraw their consent to the collection, use, and provision of personal information at any time through the Member Withdrawal function within the service.

l  If it is difficult for a user to directly correct or delete (i.e., member withdrawal) personal information due to unavoidable circumstances, the user may contact the customer service center by mail, telephone, or email, as made available by the Company, and the Company will address the request without delay.

l  If a request to correct an error in personal information is made, the Company will not use or provide such personal information until the correction has been completed.

l  Such rights may be exercised through an authorized representative, including a users legal guardian or other duly appointed agent. In such cases, a power of attorney in the form set out in Appendix Form No. 11 of the Notification on the Methods of Processing Personal Information must be submitted.

l  Where access to personal information is prohibited or restricted by law, or where there is a risk of harm to the life or body of another person or unjust infringement of another persons property or other interests, the Company may notify the user of the reason and limit or refuse the request for access.

l  Where a request to suspend the processing of personal information is made, the Company may notify the user of the reason and refuse the request for suspension where there is a special provision of law, where suspension is unavoidable to comply with a legal obligation, where there is a risk of harm to the life or body of another person or unjust infringement of another persons property or other interests, or where suspension would make it difficult to perform a contract, such as where the Company would be unable to provide a service agreed upon with the user, and the user has not clearly expressed an intention to terminate the contract.

l  A request to correct or delete personal information may not be granted if the personal information is required to be collected under other applicable laws.

l  When a user requests access, correction, deletion, suspension of processing, or withdrawal of consent in the exercise of the users rights, the Company verifies whether the requester is the user in question or a legitimate representative.

 

 

8.     Measures to Ensure the Security of Personal Information

 

The Company makes the following efforts to protect users valuable personal information.

 

l   Technical safeguards: access controls for systems that process personal information, encryption of personal information during transmission and storage, and installation and updating of security programs

l   Administrative safeguards: establishment and implementation of an internal management plan, minimization of personnel authorized to handle personal information, and regular training

l   Physical safeguards: operation of systems in areas with controlled access from outside, and establishment and operation of secure access control procedures

 

 

9.     Installation, Operation, and Right to Refuse Automatic Personal Information Collection Devices

 

The Company uses cookies, which store and periodically retrieve usage information, in order to provide individually customized services to users.

 

[What Are Cookies?]

Cookies are small files stored on a users computer hard disk by a website when the user first visits that website, and are a technology used to enable convenient use of web-based services.

 

[Purpose of Use]

l  To support users in using the website easily and conveniently by maintaining their usage environment

l  To provide differentiated information based on individual areas of interest (e.g., targeted marketing and exposure to related services based on areas of interest)

l  To provide personalized services and information and to improve the service through analysis of users visit records and usage patterns

 

[How to Refuse the Collection of Cookies]

Cookies do not store information that identifies an individual, such as a name or telephone number, and users have the option of whether to allow the installation of cookies. Accordingly, users may, by adjusting the settings in their web browser, allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if a user refuses to allow the installation of cookies, the user may experience difficulty using the website and certain services that require login.

 

[Allowing/Blocking Cookies in a Web Browser]

l  Chrome: Select the ‘⋮’ icon in the upper right corner of the browser > New Incognito Window (shortcut: Ctrl+Shift+N)

l  MS Edge: Select the ... icon in the upper right corner of the browser > New InPrivate Window (shortcut: Ctrl+Shift+N)

 

[Allowing/Blocking Cookies in a Mobile Browser]

l  Chrome: Select the ‘⋮’ icon in the upper right corner of the mobile browser > New Incognito Tab

l  Safari: Mobile device settings > Safari > Advanced > Block All Cookies

l  Samsung Internet: Select the Tabs icon at the bottom of the mobile browser > Turn on Secret Mode > Start

 

10.  Department Responsible for Personal Information Protection

 

The Company designates a Chief Privacy Officer to handle all inquiries, complaints, and requests for relief relating to personal information protection that arise in connection with the use of the service, and the Company will do its best to listen to users and provide prompt and adequate responses.

 

[Department and Contact Information for Personal Information Protection]

l  Department: Management Support Office

l  Contact: privacy@starship-ent.com

 

 

11.  Remedies for Infringement of User Rights and Interests

 

Users and legal guardians of children under the age of 14 may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agencys Personal Information Infringement Report Center, and other relevant organizations to obtain relief for infringement of personal information. For other reports of, or consultation regarding, infringement of personal information, please contact the organizations listed below.

 

l  Personal Information Dispute Mediation Committee: 1833-6972 (kopico.go.kr)

l  Personal Information Infringement Report Center: +82 118 (privacy.kisa.or.kr)

l  Identity Verification Support Center: 1433-25 (identity.kisa.or.kr)

l  Supreme Prosecutors’ Office: 1301 (spo.go.kr)

l  National Police Agency: 182 (ecrm.police.go.kr)

 

 

12.  Miscellaneous

 

[Linked Sites]

l  The Companys website may provide members with links to the websites or materials of other companies. In such cases, the Company is not responsible for, and does not guarantee, the usefulness of any services or materials provided by such external sites.

l  If a user clicks on a link contained on the Companys website and is directed to a page on another site, this Privacy Policy of the Company no longer applies to the use of that other site.

 

 

13.  Amendments to This Privacy Policy

 

This Privacy Policy may be amended to reflect changes in applicable laws or in the service. If this Privacy Policy is amended, the Company will post notice of the changes, and the amended Privacy Policy will take effect as of the date it is posted.

This Privacy Policy is effective as of July 01, 2026.

 

The Companys prior Privacy Policy may be found below.

 

Previous Privacy Policy(2018.07.19 ~ 2026-06-30)