Privacy Policy
D-Omniverse Co., Ltd. (the "Company") complies with the Personal Information Protection Act ("PIPA") and other applicable laws, and establishes and publishes this Privacy Policy to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
In this Policy, "User" means the data subject in personal information processing, including the "Member" defined in the Terms of Service. The D-Omniverse platform is hereinafter referred to as the "Service".
1. Collection and Use of Personal Information
The Company collects and uses Users' personal information as set forth below, and does not use it for purposes other than those specified. Where the purpose of processing is changed, the Company shall take necessary measures including obtaining separate consent in accordance with Article 18 of PIPA.
1.1. Items, Purposes, and Retention Periods
| Category | Purpose | Items Collected | Retention Period |
|---|---|---|---|
| Required — Account Registration and Service Provision | Member identification and identity verification, age verification (blocking registration of those under 14), confirmation of registration and account deletion intent, restriction of use and sanctions against Members violating the Terms of Service or engaging in fraudulent use, delivery of notices, retention of records for grievance handling and dispute resolution, service provision and personalized service provision, development of new services, service effectiveness verification, service usage statistics, content recommendation based on demographic characteristics | Name, date of birth, mobile phone number, country, identity verification results (encrypted Connecting Information (CI), Duplicate-joining Verification Information (DI)) | Until User withdrawal (where retention is required under applicable laws, the period set forth in § 1.2) |
| Identity Verification — Users Unable to Complete Carrier Verification (Passport, with separate consent) | Verifying the identity of users (primarily non-Korean nationals) who cannot complete domestic mobile-carrier identity verification (confirming eligibility to apply for official D-Jam participation); sending identity verification results and guidance on D-Jam participation and payment | Full name, date of birth, nationality, passport photo (photo page, face side), reply email address (pursuant to Passport Identity Verification Consent; passport number and MRZ are not collected and are immediately destroyed even if submitted unmasked) | Destroyed immediately upon completion of identity verification (where retention is required under applicable laws, the period set forth in § 1.2) |
| Official D-Jam Jam Maker — Business Verification (limited to users seeking to operate as a Jam Maker) | Jam Maker business verification; registration, review, and operation of Official D-Jams | Business registration number, trade name (business name), contact person's email, contact person's phone number, business verification documents (business registration certificate, etc.) | Duration of Jam Maker business verification (where retention is required under applicable laws, the period set forth in § 1.2) |
| Marketing Use (with separate consent) | Provision of event and promotional information and participation opportunities | Items collected pursuant to Marketing Consent | Until consent is withdrawn |
| Automatic Collection — Device Information | Service compatibility and security check | Hardware model, operating system version, unique device identifier | Service use period |
| Automatic Collection — Cookies and Sessions | Maintaining login and session management | Cookies, sessions | Until session ends |
| Automatic Collection — Access Logs | Security, fraud prevention, legal compliance | IP address, access logs | At least 1 year (Notification on Standards for Measures to Secure Safety of Personal Information) |
| Automatic Collection — Usage Records | Service statistics and feature improvement | Service usage records, visit records | Until account deletion |
Marketing use is performed only where optional consent has been obtained pursuant to Marketing Consent.
1.2. Information Retained under Applicable Laws
The following information is retained for the periods specified under applicable laws, and is not used for any other purpose.
| Item Retained | Legal Basis | Retention Period |
|---|---|---|
| Records on display and advertising | Act on the Consumer Protection in Electronic Commerce | 6 months |
| Records on contracts, withdrawal of offers, payment, and supply of goods | Act on the Consumer Protection in Electronic Commerce | 5 years |
| Records on consumer complaints or dispute resolution | Act on the Consumer Protection in Electronic Commerce | 3 years |
| Records on collection, processing, and use of credit information | Credit Information Use and Protection Act | 3 years |
| Records on electronic financial transactions | Electronic Financial Transactions Act | 5 years |
| Communication confirmation data (access logs) | Protection of Communications Secrets Act | At least 3 months (retained for at least 1 year pursuant to the Automatic Collection — Access Logs row in § 1.1 of this Policy) |
1.3. Methods of Collection
The Company collects personal information through the following methods:
- Direct input in the application, email, customer inquiry channels, event participation
- Collection through generated-information collection tools
1.4. Processing of Personal Information of Children under 14
The Company does not provide the Service to children under the age of 14, and verifies age through date-of-birth input during registration. Where a User is verified to be under 14, registration is blocked; where a User is found to be under 14 after registration, the account shall be closed immediately and the relevant personal information shall be destroyed without delay.
2. Outsourcing of Personal Information Processing
The Company uses Users' personal information within the scope notified in § 1 of this Policy, and, except in the cases below, does not use it beyond such scope or, in principle, provide it to third parties or outsource its processing without the User's prior consent.
| Trustee | Outsourced Work |
|---|---|
| Amazon Web Services, Inc. | Service infrastructure operation and data storage |
| NHN Cloud Corp. | Sending of text messages |
| Payple Corp. | Provision of electronic payment services and payment settlement |
| Korea PortOne Corp. | Provision of integrated authentication service (mobile carrier identity verification) |
Sub-outsourcing of personal information processing:
| Trustee | Sub-trustee | Sub-trustee's Outsourced Work |
|---|---|---|
| Korea PortOne Corp. | KG Inicis Co., Ltd. | Mobile carrier identity verification |
The following cases are excepted:
- Where the User has given prior consent
- Where required pursuant to laws or by an investigative agency for investigative purposes in accordance with the procedures and methods prescribed by law
3. Provision of Personal Information to Third Parties
The Company processes the data subject's personal information only within the scope specified in § 1 of this Policy, and provides it to third parties only where the User's prior consent has been obtained or where there is a special provision under the relevant laws. Otherwise, the Company does not provide Users' personal information to third parties.
Where a User applies to participate in a D-Jam (event), the Company provides the User's personal information to the relevant D-Jam organizer (JamMaker) as set forth below. The JamMaker that receives such information bears responsibility, as a personal information controller, for processing it in compliance with the relevant laws. The legal basis for the provision of each item is as follows:
- Name and mobile phone number are items provided for the performance of the D-Jam (event) participation contract, and are notified and provided in this paragraph without separate consent pursuant to Article 17, Paragraph 4 of PIPA (additional provision within a scope reasonably related to the original purpose of collection).
- Additional question items set by the JamMaker are items that exceed the scope of the participation contract, and are provided after obtaining the User's prior consent pursuant to Article 17, Paragraph 1, Subparagraph 1 of PIPA at the additional-information input stage of the relevant D-Jam.
| Recipient | Purpose of Provision | Items Provided | Retention and Use Period |
|---|---|---|---|
| D-Jam organizer (JamMaker) | Identification of D-Jam (event) participants and event operation | Name, mobile phone number | Destroyed 3 months after the end of the D-Jam |
| D-Jam organizer (JamMaker) | Collection and use of additional question items set by the JamMaker (varies by D-Jam) | For D-Jams with additional question items, the additional question items set by the JamMaker | Destroyed 3 months after the end of the D-Jam |
The provision of name and mobile phone number is not subject to consent; the User may request suspension of processing of such provision pursuant to Article 37 of PIPA through the procedure set forth in § 6 of this Policy. The User may refuse consent to the provision of additional question items, in which case participation in the relevant D-Jam may be restricted.
4. Cross-border Transfer of Personal Information
The Company transfers personal information abroad pursuant to Article 28-8 of PIPA as set forth below. The User has the right to refuse such cross-border transfer, and refusal may result in restrictions on the User's use of the Service.
| Recipient | Country | Date and Method of Transfer | Items Transferred | Purpose | Retention and Use Period |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. (aws-korea-privacy@amazon.com) | United States | At the time of Service use, via network transmission | All items collected under § 1.1 of this Policy, including Member information, service usage records, and content | Service infrastructure operation and data storage | Until account deletion or termination of the outsourcing contract |
| Google LLC (googlekrsupport@google.com) | United States | At the time of Service use, via network transmission | Device identifier, push token | Push notification delivery (Firebase Cloud Messaging) and infrastructure operation (Google Cloud Platform) | Service use period |
| Google LLC (googlekrsupport@google.com) | United States | At the time of map display, via network transmission | IP address | Map display (Google Maps embed) | Processed only at the time of map display |
A User may request to refuse cross-border transfer through the Personal Information Protection Officer or the personal information protection department specified in § 8 of this Policy. Refusal may result in restrictions on the use of the relevant Service.
5. Procedures and Methods of Personal Information Destruction
The Company shall, in principle, destroy personal information without delay upon the expiration of the retention period or the achievement of the processing purpose. Notwithstanding the expiration of the retention period consented to by the data subject or the achievement of the processing purpose, where personal information must be retained pursuant to other applicable laws, such personal information shall be moved to a separate database (DB) or stored in a different storage location. Personal information moved to a separate DB shall not be used for any other purpose except as required by law.
The destruction procedures and methods are as follows.
5.1. Destruction Procedure
The Company shall select personal information for which a cause for destruction has occurred and shall destroy such information upon approval of the Company's Personal Information Protection Officer.
5.2. Destruction Methods
(1) Information recorded and stored in electronic file form shall be destroyed using technical methods that render the records irreproducible.
(2) Information recorded and stored on paper shall be destroyed by shredding or incineration.
6. Rights and Obligations of Users and Methods of Exercise
6.1 A User may at any time exercise rights including access, correction, deletion, and suspension of processing of his or her registered personal information.
6.2 To view or modify personal information, the User may, after completing identity verification through "Edit Personal Information" (or "Edit Member Information"), or for withdrawal of consent and account termination, through the "Account Deletion" procedure, directly view, correct, or delete the account. Alternatively, contacting the Personal Information Protection Officer in writing or by email shall result in action without delay. Requests for suspension of personal information processing are a separate right under Article 37 of PIPA and may be submitted to the Personal Information Protection Officer or the personal information protection department specified in § 8 of this Policy.
6.3 Unless the Company has another legal basis to retain the User's personal information, where the User withdraws consent, the collected personal information shall be deleted or de-identified without delay.
6.4 Where a User requests correction of an error in personal information, the relevant personal information shall not be used or provided until the correction is completed. Where erroneous personal information has already been provided to a third party, the result of the correction shall be notified to the third party without delay so that the correction may be made.
6.5 Rights may also be exercised through a User's legal representative or an authorized agent. In such case, a power of attorney in the form set forth in Annex 11 of the "Notification on Methods of Personal Information Processing (No. 2020-7)" shall be submitted.
6.6 Requests for access to and suspension of processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of PIPA.
6.7 Requests for correction or deletion of personal information cannot include a request for deletion where the relevant personal information is specified as a subject of collection under other applicable laws.
6.8 The Company shall verify whether the person making a request for access, correction, deletion, or suspension of processing is the data subject or a legitimate agent.
7. Measures to Secure the Safety of Personal Information
The Company implements the following administrative, technical, and physical measures to ensure that Users' personal information is safely managed and not lost, stolen, leaked, altered, or damaged.
7.1. Administrative Measures
The Company minimizes the number of employees handling personal information and conducts regular training and inspections under the supervision of the Personal Information Protection Officer (§ 8.1).
7.2. Technical Measures
Access rights to the personal information processing system are granted within the scope necessary for job performance, and are promptly changed or revoked upon personnel changes, resignation, or other relevant events. Important personal information is encrypted for storage, and encryption is also applied during transmission. Passwords are stored using one-way encryption, so the Company itself cannot view Users' passwords. Access logs are retained and managed for the minimum retention period prescribed in the Notification on Standards for Measures to Secure Safety of Personal Information (at least 1 year).
7.3. Physical Measures
Access control measures are applied to the locations where personal information is stored.
8. Personal Information Protection Officer and Responsible Department
The Company has designated a Personal Information Protection Officer responsible for collecting feedback on personal information and handling complaints, with the contact information set forth below. Users may inquire of the Personal Information Protection Officer or the responsible department regarding any matter related to personal information protection, including inquiries, complaints, and remedy of damages, arising in connection with use of the Company's Service. The Company shall respond to Users' inquiries promptly and sufficiently.
8.1. Personal Information Protection Officer
- Name: Heehyung Cho
- Position: Chief Executive Officer
- Department: Customer Support Team (Personal Information Protection)
- Contact: 070-8980-0218
8.2. Personal Information Protection Department
- Department: Customer Support Team
- Contact: support@d-omniverse.com
9. Remedies for Infringement of User Rights
A User may apply to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and similar bodies for dispute resolution or consultation in order to obtain remedies for personal information infringement. For other reports or consultations regarding personal information infringement, please contact the following institutions:
- Personal Information Dispute Mediation Committee (https://www.kopico.go.kr, 1833-6972)
- Korea Internet & Security Agency Personal Information Infringement Report Center (https://privacy.kisa.or.kr/main.do, 118 (toll-free))
- Supreme Prosecutors' Office (http://www.spo.go.kr, 1301 (toll-free))
- National Police Agency Cyber Crime Report System (https://ecrm.police.go.kr/minwon/main, 182 (toll-free))
10. Changes to the Privacy Policy
10.1 This Privacy Policy is permanently posted in a designated location within the application. Where the Privacy Policy is changed, the Company shall give notice within the application of the content and reason for the change at least 7 days prior to the effective date of the revised Privacy Policy, and the revised Policy shall apply from the effective date. However, where material matters such as purposes of collection or use of personal information or recipients of third-party provision are added, deleted, or modified, prior notice shall be given 30 days in advance, and the change shall take effect after the 30-day period.
10.2 This Privacy Policy shall take effect on June 15, 2026. However, the provisions related to identity verification and payment (the Payple Corp. row and the KG Inicis Co., Ltd. row in the § 2 outsourcing table) shall take effect on July 1, 2026.
11. Operation of Automatic Collection Devices (Cookies, etc.) and Refusal Thereof
The Company uses "cookies" that store and frequently retrieve usage information to provide personalized services to Users. Cookies are small information files sent by the Company's server to the User's browser and stored on the User's device.
A User may, through the options of the web browser in use, allow all cookies, confirm each time a cookie is stored, or refuse the storage of all cookies. On mobile or PC web browsers, the User may enable, disable, or delete cookies in accordance with the instructions of the web browser in use. However, refusing or deleting cookies may result in restrictions on the use of certain services that require login, and personal information for providing customized advertising experiences on the relevant device shall no longer be collected, used, shared, or processed.
The Company may collect behavioral information (service usage records, visit records, access IP, device information, etc.) to provide Users with optimized personalized services, and may use external analytics tools to analyze statistics and usage patterns. A User may refuse the collection of behavioral information by resetting the advertising identifier or disabling tracking permission in the device settings.