Privacy Policy

Janytree Inc. (hereinafter referred to as the “Company”) complies with the personal information protection provisions under applicable laws and regulations that information and communications service providers are required to observe, including the Protection of Communications Secrets Act, the Telecommunications Business Act, and the Act on Promotion of Information and Communications Network Utilization and Information Protection. The Company has established this Privacy Policy in accordance with applicable laws and makes every effort to protect users’ rights and interests.

1. Items and Methods of Personal Information Collection

A. Items of Personal Information Collected

The Company collects the following personal information for purposes such as membership registration, consultation, content purchases, and service applications.

Required information: ID, password, password recovery question and answer, email address, nickname
Optional information: name, phone number
In addition, the following information may be automatically generated and collected in the course of service use or business processing:
IP address, cookies, access logs, service usage records, records of improper use, and payment records.

B. Methods of Personal Information Collection

The Company collects personal information through the following methods:

Website membership registration, consultation boards, email, event applications, and delivery requests
Provision from partner companies
Collection through tools for collecting automatically generated information

2. Purpose of Collecting and Using Personal Information

A. Performance of contracts related to service provision and settlement of fees for service provision
Provision of content, purchase and payment processing, and collection of fees

B. Member management
Identity verification and personal identification for the use of membership services and the limited identity verification system; prevention of fraudulent use by improper members and unauthorized use; confirmation of intent to register; restriction of registration and number of registrations; confirmation of legal guardian consent when collecting personal information from children under the age of 14; subsequent verification of the legal guardian’s identity; retention of records for dispute resolution; handling of complaints and other civil petitions; and delivery of notices.

C. Use for new service development, marketing, and advertising
Development and customization of new services or products; analysis of access frequency or statistics on members’ service use; and delivery of promotional information such as events.

3. Sharing and Provision of Personal Information

The Company uses users’ personal information within the scope notified in “2. Purpose of Collecting and Using Personal Information” and, in principle, does not use such information beyond that scope or disclose users’ personal information externally without the user’s prior consent. However, exceptions may apply in the following cases:

  • Where the user has given prior consent to disclosure
  • Where disclosure is required under applicable laws and regulations, or where an investigative agency requests disclosure for investigative purposes in accordance with the procedures and methods prescribed by law

4. Outsourcing of Personal Information Processing

The Company does not outsource the processing of users’ personal information to external companies without users’ consent. If such outsourcing becomes necessary in the future, the Company will notify users of the outsourced party and the details of the outsourced work, and will obtain prior consent where necessary.

5. Retention and Use Period of Personal Information

In principle, users’ personal information is destroyed without delay once the purpose of collection and use has been achieved. However, the following information is retained for the periods specified below for the reasons stated.

A. Reasons for retaining information under the Company’s internal policy

  • Records of improper use
  • Reason for retention: prevention of improper use
  • Retention period: 1 year

B. Reasons for retaining information under applicable laws and regulations

Where it is necessary to retain member information pursuant to applicable laws and regulations, including the Commercial Act and the Act on Consumer Protection in Electronic Commerce, Etc., the Company retains such information for the period prescribed by the relevant laws and regulations. In such cases, the Company uses the retained information only for the purpose of retention, and the retention periods are as follows.

Records related to commercial transactions
Reason for retention: Act on Consumer Protection in Electronic Commerce, Etc.
Retention period:
Records on contracts or withdrawal of offers: 5 years
Records on payment and supply of goods, etc.: 5 years
Records on consumer complaints or dispute resolution: 3 years

Records on identity verification
Reason for retention: Act on Promotion of Information and Communications Network Utilization and Information Protection
Retention period: 6 months
Records of visits
Reason for retention: Protection of Communications Secrets Act
Retention period: 3 months

6. Procedures and Methods for Destroying Personal Information

In principle, users’ personal information is destroyed without delay once the purpose of collection and use has been achieved.
The Company’s procedures and methods for destroying personal information are as follows.

A. Destruction procedure
Information entered by users for membership registration or similar purposes is transferred to a separate database after the relevant purpose has been achieved (or, in the case of paper documents, to a separate filing cabinet), stored for a certain period in accordance with internal policies and other information protection reasons under applicable laws and regulations (see the retention and use period), and then destroyed.
Such personal information is not used for any purpose other than retention, except as required by law.

B. Destruction method
Personal information printed on paper is destroyed by shredding or incineration.
Personal information stored in electronic file format is deleted using technical methods that make the records irrecoverable.

7. Rights of Users and Legal Guardians and How to Exercise Them

Users and legal guardians may, at any time, view or modify their own registered personal information or the personal information of a child under the age of 14, and may also request membership withdrawal.
To view or modify the personal information of a user or a child under the age of 14, the user may click “View Member Information” (or “Edit Member Information,” etc.). To withdraw from membership or withdraw consent, the user may click “Withdrawal” to directly view, correct, or withdraw.

If a user requests correction of an error in personal information, the Company will not use or provide the relevant personal information until the correction is completed. If incorrect personal information has already been provided to a third party, the Company will promptly notify the third party of the correction results so that the correction can be made.

The Company processes personal information that has been terminated or deleted at the request of a user or legal guardian in accordance with “5. Retention and Use Period of Personal Information” and ensures that such information cannot be viewed or used for any other purpose.

8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

The Company uses cookies, which store and retrieve user information from time to time, in order to provide personalized and customized services. Cookies are very small text files sent by the server used to operate the website to the user’s browser and are stored on the hard disk of the user’s computer.

A. Purpose of using cookies
Cookies are used to identify users’ visit and usage patterns for each service and website they visit, popular search terms, whether secure access is used, news editing, user scale, and other information, in order to provide optimized information to users.

B. Installation, operation, and refusal of cookies
Users have the option to accept or reject the installation of cookies. Accordingly, users may configure their web browser options to allow all cookies, to be prompted each time a cookie is stored, or to reject the storage of all cookies.
However, if a user refuses to store cookies, it may be difficult to use some services that require login.

9. Technical and Administrative Measures for Protecting Personal Information

In handling users’ personal information, the Company implements the following technical and administrative measures to ensure security and to prevent personal information from being lost, stolen, leaked, altered, or damaged.

A. Technical measures
Members’ personal information is protected by passwords, and important data is protected through separate security functions by encrypting files and transmitted data or using file lock functions.
The Company takes measures to prevent damage caused by computer viruses by using antivirus programs. The antivirus programs are updated periodically, and when a new virus appears unexpectedly, the Company applies the vaccine as soon as it becomes available to prevent personal information from being compromised.
The Company adopts security devices, such as SSL or SET, that use encryption algorithms to transmit personal information securely over networks.
To prevent personal information from being leaked due to hacking or similar incidents, the Company uses devices that block external intrusion and installs intrusion detection systems on major servers to monitor intrusions 24 hours a day.

B. Administrative measures
In addition to the efforts described above, members should take care not to disclose their passwords or similar information to third parties. In particular, members should always be careful to ensure that passwords are not leaked through computers installed in public places. Members’ IDs and passwords should be used only by the members themselves, and it is recommended that passwords be changed frequently.
The Company strictly limits employees who handle personal information to those who perform personal information management duties or whose work unavoidably requires the handling of personal information. The Company emphasizes compliance with this policy through regular training for responsible employees and verifies the implementation of this policy and employees’ compliance through inspections by the security department. If any issues are identified, corrective measures are taken immediately.

10. Contact Information of the Personal Information Management Officer

Users may report any personal information protection-related complaints that arise while using the Company’s services to the Personal Information Management Officer.
The Company will provide prompt and sufficient responses to users’ reports.

Personal Information Management Officer
Telephone: 02-868-1921
Email: intomedi@janytree.com

If users need to report or consult on any other personal information infringement, they may contact the following institutions.
Privacy Infringement Report Center (www.cyberprivacy.or.kr / 1336)
Internet Crime Investigation Center, Supreme Prosecutors’ Office (http://sppo.go.kr / 02-3480-3600)
Cyber Terror Response Center, National Police Agency (www.ctrc.go.kr / 02-392-0330)

11. Duty of Notification

If any content is added to, deleted from, or amended in this Privacy Policy, the Company will provide notice through the “Notice” section of the website at least seven days before the amendment takes effect.

Date of notice: January 20, 2025
Effective date: January 20, 2025
Date of amendment: December 20, 2025