Privacy Policy
The eosatom Operations Team (the "Operator") has established this Privacy Policy under Article 30 of the Personal Information Protection Act of the Republic of Korea to protect users' personal information and to handle related complaints promptly. The Korean version of this policy is the official version; this English version is provided for convenience.
1. Purposes of Processing Personal Information
The Operator processes personal information only for the following purposes. If a purpose changes, the Operator will take the necessary steps, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
- Membership registration and management: confirming the intent to join, identifying members, keeping members signed in, preventing account theft and misuse, processing withdrawals, and sending account emails such as password resets
- Providing the service: posting and displaying posts and comments, real-time chat (LIVE_TALK), likes and scraps, notifications (on-site notifications and notification emails), and My Page features
- Handling reports and disputes: handling reports on posts and comments, usage restrictions and appeals, and takedown requests for infringing posts
- Responding to inquiries: reviewing and answering email inquiries
- Improving the service: visit statistics and trending search terms (used only in a form that cannot identify individuals)
2. Personal Information Processed
| Category | Items | How collected |
|---|---|---|
| Sign-up (required) | Email, name, password | Entered directly on the sign-up page |
| Profile (optional) | Nickname, profile photo, bio | Entered directly on My Page |
| Generated automatically while using the service | IP address, browser and device information, access and sign-in times, service usage records, IP address when writing posts and comments, time and IP address of consent to the Terms | Generated automatically during use |
| Real-time chat (LIVE_TALK) | Chat messages and time written (shown in the chat with the member's name) | Entered directly in the chat |
| Email inquiries | Email address, content of the inquiry | Inquiry email |
| Takedown requests | Name, contact details, documents proving the right | Takedown request email |
Search terms are not linked to member information and are used only to compile trending search terms. The session identifier used to show the number of current visitors is stored only in a converted (hashed) form from which the original value cannot be recovered, and it cannot identify an individual on its own.
3. Processing and Retention Periods
The Operator keeps personal information only for the period required by law or consented to by the user, and destroys it without delay when that period ends.
| Item | Retention period | Basis |
|---|---|---|
| Member information (email, name, profile) | Until the member withdraws. However, to prevent misuse such as re-registering to avoid usage restrictions, the email and name are kept for 30 days after withdrawal and then destroyed | User consent, prevention of misuse |
| Record of consent to the Terms | Until the member withdraws | User consent |
| Access logs (IP address, access time, etc.) | 3 months | Protection of Communications Secrets Act |
| IP address used to write posts and comments | Until the post or comment is deleted (including posts remaining after withdrawal) | Handling reports, responding to lawful requests from investigative agencies |
| Real-time chat (LIVE_TALK) messages and chat report records | 7 days after writing (destroyed automatically every day after that) | Providing the service, handling reports |
| Inquiry and takedown request records | 1 year after handling is completed | Dispute response |
4. Provision of Personal Information to Third Parties
The Operator does not provide users' personal information to third parties, except where the user has consented in advance, where the law specifically requires it, or where an investigative agency requests it following procedures set by law.
5. Outsourcing of Personal Information Processing
To provide the service smoothly, the Operator outsources the following personal information processing.
| Outsourcee | Outsourced task | Retention period |
|---|---|---|
| Cloudflare, Inc. | Sending emails on the Operator's behalf (account emails such as password resets, notification emails) | Sending records are deleted after about 30 days; destroyed without delay when the outsourcing contract ends |
Through the outsourcee's terms of service, including its Data Processing Addendum (DPA), the Operator sets out the prohibition of processing personal information beyond the outsourced task, security measures, restrictions on re-outsourcing, management and supervision, and liability for damages, and supervises whether the outsourcee processes personal information securely. If the outsourced task or the outsourcee changes, the Operator will notify users through this Privacy Policy without delay.
6. Transfer of Personal Information Overseas
In outsourcing email delivery, the Operator transfers personal information overseas as follows. This is a transfer for outsourcing under Article 28-8(1)(3) of the Personal Information Protection Act, and the required details are disclosed in this Privacy Policy.
| Item | Details |
|---|---|
| Recipient | Cloudflare, Inc. (privacy inquiries: [email protected]) |
| Country of transfer | United States (may pass through Cloudflare data centers in other countries) |
| Time and method of transfer | Sent over an encrypted network (TLS) each time an email is sent |
| Items transferred | Recipient's email address, name (nickname) included in the email, email subject and content |
| Purpose of transfer | Sending emails on the Operator's behalf |
| Retention period | Sending records are deleted after about 30 days; destroyed without delay when the outsourcing contract ends |
| How to refuse and consequences | You may refuse the overseas transfer by emailing the Privacy Officer below. However, if you refuse, you will not be able to use features that require email, such as password resets, or receive notification emails. |
7. Procedure and Method of Destruction
- Personal information whose retention period has ended or whose purpose has been achieved is destroyed without delay.
- Electronic files are deleted in a way that cannot be recovered, and paper documents are shredded or incinerated.
- Personal information that must be kept by law is stored separately from other personal information and used only for that purpose.
8. Rights of Data Subjects and How to Exercise Them
- Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information, or withdraw their consent.
- Profile information can be viewed and edited directly on My Page, where you can also withdraw your membership. For other requests, please email the Privacy Officer below.
- Rights may also be exercised through a legal representative or an authorized person, who must submit a power of attorney.
- The Operator will act within 10 days of receiving a request and notify you of the result. If the request is refused as permitted by law, the Operator will tell you the reason.
9. Personal Information of Children Under 14
The Operator does not accept membership registrations from children under 14. If the Operator learns that a child under 14 has registered, the account and personal information will be deleted without delay.
10. Automatic Collection Tools and How to Refuse Them
- To keep users signed in, the Operator stores a sign-in token in the browser's local storage and uses session cookies. Convenience settings, such as display preferences, are also stored in the browser.
- The Operator does not use cookies for advertising or behavioral tracking.
- Users can delete cookies and site data or block them in their browser settings. However, you may then not stay signed in.
11. Security Measures
- Administrative measures: limiting the people who handle personal information to a minimum, and establishing and implementing an internal management plan.
- Technical measures: storing passwords with one-way encryption, locking accounts after repeated failed sign-in attempts, controlling access by separating administrative permissions by role, encrypting transmission (HTTPS), and applying security updates.
- Physical measures: controlling access to the servers and equipment that store personal information.
12. Privacy Contact
To oversee personal information processing and to handle related complaints and remedies, the Operator has designated the following department to handle personal information protection and related grievances. Please send any privacy inquiries, complaints or requests for remedies to the contact below; we will respond and act on them without delay.
| Item | Details |
|---|---|
| Department | eosatom Operations Team (Privacy) |
| Contact | [email protected] |
13. Remedies for Infringement
To seek remedies for infringement of personal information, you may apply for dispute resolution or counseling to the following organizations (Korea).
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
14. Changes to This Privacy Policy
- This Privacy Policy takes effect on October 1, 2026.
- When it changes, the Operator will give notice at least 7 days before the effective date, and at least 30 days before for important changes such as changes to the items collected or the purposes of use.