Privacy Policy

CJ ENM Co., Ltd Entertainment Division (hereinafter “Company”) actively protects the personal information of users (“Users”) and has established, and is in compliance with, the Company’s privacy policy (hereinafter “Privacy Policy”) for the purpose of complying with all personal information-related laws and regulations. Through the Privacy Policy set forth below, the Company informs Users of the purpose and method of use of personal information provided by Users and the measures being taken to protect their personal information.

This Privacy Policy is published on the Company’s website and is easily accessible at any time. The Privacy Policy includes the following subject matters.

  1. 1. Personal Information Items to be Collected and Purpose of Collection and Use
  2. 2. Retention Period of Personal Information
  3. 3. Procedure and Method for the Destruction of Personal Information
  4. 4. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
  5. 5. Users' Rights to Personal Information and Methods of Exercise
  6. 6. Chief Privacy Officer and Customer Support Department
  7. 7. Consent for Providing and Sharing Personal Information with Third Parties
  8. 8. Consignment of Personal Information Processing
  9. 9. Information on the Collection of Personal Information of Children Under the Age of 14
  10. 10. Measures for the Protection of Personal Information
  11. 11. Duty to Notify
1. Personal Information Items to be Collected and Purpose of Collection and Use
  1. (1)The Company collects and uses only the minimum personal information necessary to provide its services. Additionally, the collected personal information will not be used for any purpose other than those for which consent was obtained. If the purpose of use changes after consent is given, the Company will take necessary measures, such as obtaining additional consent.
    CategoryCollected ItemsPurpose of Collection and UseRetention and Usage Period
    Contact Us (Required) Name, Email Address, Mobile Phone Number
    (Optional) Affiliation(Company), Country
    Use of the Contact Us service, receipt and handling of inquiries, notification of processing resultsWithin one (1) month from the completion of the request processing, or within five (5) days from the date of the data subject's withdrawal request.
  2. (2)In addition, the following information may be generated and collected in the process of service use or handling inquiries to provide personalized services:
    1. Frequency of use, service usage time, and usage records
    2. Access log and access IP information, cookies, usage records, session information
  3. (3)The Company collects personal information through the following methods:
    1. Collection of information through the use of PC web and mobile web services
    2. Collection of personal information through online consent to the collection and use of personal information
    3. Collection of generated information through log analysis programs
    4. Collection of information via cookies
  4. (4)The Company may process personal information in a pseudonymized manner for purposes such as statistical analysis, scientific research, and public record preservation.
2. Retention Period of Personal Information
  1. (1)The Company processes and retains personal information within the retention and usage period agreed upon by the data subject at the time of collection. However, if the user has given separate consent for a different retention period, or if laws and regulations impose an obligation to retain information for a certain period, the Company will securely store the personal information for the specified period.
  2. (2)In cases where retention is required by applicable laws and regulations, the Company will retain member information for the period stipulated by the relevant laws, as outlined below.
    Relevant LawRetained ItemsRetention Period
    Telecommunications Privacy Protection ActService visit records3 months
3. Procedure and Method for the Destruction of Personal Information
  1. The Company promptly destroys personal information when the retention period expires or when the purpose of processing has been fulfilled, rendering the data no longer necessary. However, if the Company has obtained separate consent from the Customer or if applicable laws require continued retention, the relevant personal information will be transferred to a separate database (DB) or stored in a different location for preservation.
    • Personal information recorded or printed on paper: Shredded or incinerated
    • Personal information stored in electronic files (e.g., database): Permanently deleted using technical methods that prevent data recovery
4. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
  1. (1)Cookies, records of service usage, and information accessed from the connected device may be generated automatically and collected in the process of using Company services and handling user inquiries. Cookies are data that websites send to the users’ web browsers (Edge, Chrome, Firefox, etc.). When a user visits the Company's website and uses its service through a cookie, the Company reads the details of the cookies stored in the user’s PC and analyzes information such as visit records and services used, service connection time and frequency, and information generated or provided (entered) in the process of using the service to improve services, prevent illegal use, and check user errors. You may refuse the use of cookies by adjusting your web browser settings. However, if you choose to disable cookies, some features or services may not function properly or may be unavailable.
  2. (2)Right to decline cookies
    1. For Chrome: Click the ‘⋮’ icon in the upper-right corner of the browser > Select New Incognito Window (Shortcut: Ctrl+Shift+N)
    2. For Microsoft Edge: Click the ‘⋮’ icon in the upper-right corner of the browser > Select New Incognito Window (Shortcut: Ctrl+Shift+N)
5. Users' Rights to Personal Information and Methods of Exercise
  1. (1)Users may exercise their rights (hereinafter referred to as “Exercise of Rights”) at any time to request access, correction, deletion, restriction of processing, or withdrawal of their personal information. If you wish to exercise your rights, please contact our Customer Service Center. Upon verification by our Chief Privacy Officer and the relevant department, we will process your request without undue delay.
  2. (2)Rights Exercise may also be carried out through a delegate. In such cases, the delegate must submit a power of attorney (POA) in accordance with Annex No. 11 of the “Public Notice on the Methods of Processing Personal Information.”
  3. (3)Requests for access to or suspension of processing personal information may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act. Additionally, requests for correction or deletion of personal information may not be granted if the information is designated for mandatory collection under other laws and regulations.
  4. (4)The Company operates a dedicated customer service center to handle related inquiries and consultations. We will review inquiries submitted through our Customer Service Center in coordination with our Chief Privacy Officer and the relevant department and respond without undue delay.
6. Chief Privacy Officer and Customer Support Department
  1. (1)The Company has designated a Chief Privacy Officer and a department in charge as provided below and operates a consultation counter for smooth communication with users in relation to personal information inquiries and requests.
    1. Chief Privacy Officer
      • Department/Name: CJ ENM Entertainment Division, Information Security Officer, Jihoon Kim
      • Contact: +82-2-371-5501
    2. Personal Information Protection Department
      • Department: CJ ENM Customer Center
      • Contact: +82-2-371-5501
  2. Please contact the Chief Privacy Officer or contact any of the institutions below for any advice on, or to report any instance of, infringement of personal information.

    Name of institutionsURLContact information
    KISA Personal Information Infringement Report Centerhttps://privacy.kisa.or.kr118 without area code
    Supreme Prosecutor's Office Cyber Crime Investigation Teamhttps://www.spo.go.kr1301 without area code
    Korean National Police Agency Cyber Bureauhttps://ecrm.police.go.kr182 without area code
    Personal Information Dispute Mediation Committeehttps://kopico.go.kr1833-6972 without area code
7. Consent for Providing and Sharing Personal Information with Third Parties

The Company uses a user’s personal information only within the scope specified in the Privacy Policy and does not use personal information beyond the specified scope nor provide it to a third party. However, personal information may be provided in exceptional cases such as when the user gives prior consent or when a request is made pursuant to the provisions and procedures set forth by related laws and regulations.

8. Consignment of Personal Information Processing

The Company consigns personal information processing work to the consignment companies listed below for purposes including the operation and maintenance of services and provision and management of user convenience. The Company manages the consignment companies by entering into service agreements which require the consignment companies to be and remain in compliance with related laws, regulations, and guidelines, protect personal information and comply with confidentiality provisions, and return and destroy personal information immediately upon the expiration or termination of the service agreement.

ContractorPurpose of Entrustment
CJ Olivenetworks Inc.System development, operation/management, maintenance and Contact Center Operations (Outsourced system development and operation: DIware)
9. Information on the Collection of Personal Information of Children Under the Age of 14
  1. (1)In principle, the Company does not collect personal information of children under the age of 14. However, in the inevitable case of collecting personal information for the purpose of providing services, the Company requests the consent of the LAR (legally authorized representative) of the child as a mandatory procedure.
  2. (2)When obtaining consent from the legal guardian (such as a parent) for the processing of the personal information of a child under the age of 14, the Company may request the minimum personal information necessary from the child, such as the legal guardian's name and contact information. The Company verifies the legal guardian's consent through mobile phone identity verification.
  3. (3)A legal guardian (such as a parent) may request access to, correction, or deletion of the child's personal information. If you wish to exercise these rights on behalf of the child, please contact our Customer Service Center. Upon verification by our Chief Privacy Officer and the relevant department, we will process your request without undue delay.
10. Measures for the Protection of Personal Information

The Company is preparing the following technical and administrative safety measures to ensure that users’ personal information is not lost, stolen, leaked, altered, or damaged.

  1. (1)Technical protection measures
    1. Personal information is protected by a password, and important data is protected by using separate security features such as encrypting files and transmitted data or setting a lock on the file.
    2. The Company is taking measures to prevent damage caused by computer viruses by using an antivirus program. Antivirus programs are updated regularly, and in the event a virus unexpectedly appears, the Company applies the antivirus program immediately to prevent infringement of personal information.
    3. The Company uses a Secure Sockets Layer (SSL) device to safely transmit personal information in the network.
    4. The Company has installed the antivirus program in an area where access is restricted from outside users and is using a device that blocks attacks and unauthorized access to prevent leakage of users’ personal information from events such as hacking.
  2. (2)Administrative protection measures
    1. The Company has prepared the necessary procedures for managing and accessing users’ personal information so that officers and employees become familiar and comply with such procedures. The Company periodically conducts compliance checks to ensure compliance of such procedures.
    2. The Company limits the number of people who can process users’ personal information to a minimum and manages access rights, and ensures compliance with laws and policies through internal trainings. The people who process users’ personal information is as follows.
      • Person whose work involves direct or indirect communication with users
      • Person whose work involves the management and protection of personal information, such as the Chief Privacy Officer
      • Person whose work involves inevitable access to personal
    3. The Company prevents any leakage of information (including personal information) by requiring new hires and employees to sign the information protection pledge, reminding them of their obligations to protect personal information as often as necessary, and preparing internal procedures for compliance auditing.
    4. The handover of work by the personal information manager is carried out securely, and the responsibility of each onboarding and offboarding employee for any case of personal information infringement is clearly provided in the Company’s internal policy.
  3. (3)Physical Safeguards
    1. The Company stores documents and auxiliary storage media containing personal information in secure locations equipped with locking devices.
    2. The Company designates computer rooms and records storage rooms as restricted areas and operates access control systems for such areas.
11. Duty to Notify

In the event of any amendments to this Privacy Policy due to changes in Company policies, government policies, or security technology, the Company post a notice on the website prior to such amendment.

  • Current Privacy Policy Version: v1.4 (See previous policy)
  • Notification date: JULY 31, 2026 / Implementation date: AUGUST 7, 2026