Privacy Policy
Article 1 (Purpose)
INPLAB Co., Ltd. (the “Company”) establishes this Privacy Policy (the “Policy”) to protect the information (the “Personal Information”) of individuals who use the services the Company intends to provide (the “Company Services”) (each such individual, a “User” or “Individual”). To this end, the Company complies with applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection (the “Network Act”), and seeks to ensure that Users’ privacy-related concerns are handled promptly and efficiently.
Article 2 (Principles for Processing Personal Information)
In accordance with applicable privacy laws and this Policy, the Company may collect Users’ Personal Information. Personal Information collected by the Company may be provided to a third party only with the Individual’s consent. However, where disclosure is lawfully required under applicable laws or regulations, the Company may provide a User’s Personal Information to a third party without the Individual’s prior consent.
Article 3 (Disclosure of This Policy)
1. The Company makes this Policy available on the main page of its website or through a linked page so that Users may easily review it at any time.
2. When disclosing this Policy under Paragraph 1, the Company uses appropriate font sizes, colors, and other formatting to make the Policy easy for Users to read.
Article 4 (Amendments to This Policy)
1. This Policy may be amended in response to changes in privacy-related laws, regulations, guidelines, or public notices, or changes to government policies, the Company’s policies, or the Company Services.
2. If the Company amends this Policy under Paragraph 1, it will provide notice by one or more of the following methods:
1. Posting a notice in the notice section on the main page of the Company’s website or in a separate pop-up window; or
2. Notifying Users in writing, by fax, by email, or by a similar method.
3. The Company will provide the notice described in Paragraph 2 at least seven days before the amended Policy takes effect. However, if an amendment materially affects Users’ rights, the Company will provide notice at least 30 days in advance.
Article 5 (Information Collected for Membership Registration)
The Company collects the following information to enable Users to register for the Company Services:
1. Required information: email address, password, name, nickname, date of birth, and mobile phone number.
Article 6 (Information Collected for Identity Verification)
The Company collects the following information to verify a User’s identity:
1. Required information: mobile phone number, email address, name, date of birth, and gender.
Article 7 (Information Collected to Provide the Company Services)
The Company collects the following information to provide the Company Services to Users:
1. Required information: user ID, email address, name, date of birth, and contact information.
Article 8 (Information Collected to Analyze Service Use and Improper Use)
The Company collects the following information to generate statistics and analyses concerning Users’ use of the Company Services and to identify and analyze improper use. “Improper use” includes repeatedly withdrawing from and re-registering for membership, repeatedly canceling purchases after buying products, improperly or unlawfully obtaining financial benefits such as discount coupons or promotional benefits offered by the Company, engaging in conduct prohibited by the Terms of Use, identity theft, and other improper or unlawful acts.
1. Required information: service usage records, cookies, access-location information, and device information.
Article 9 (Methods of Collecting Personal Information)
The Company collects Users’ Personal Information through the following methods:
1. A User enters Personal Information on the Company’s website.
2. A User enters Personal Information through an application or another service provided by the Company outside the Company’s website.
Article 10 (Use of Personal Information)
The Company uses Personal Information for the following purposes:
1. To carry out Company operations, including delivering notices;
2. To improve services for Users, including responding to inquiries and handling complaints;
3. To provide the Company Services;
4. To restrict the use of the Company Services by members who violate applicable laws or the Company’s terms and conditions, and to prevent and impose sanctions for improper use or other conduct that interferes with the proper operation of the Company Services;
5. To develop new services; and
6. For marketing purposes, including providing information about events and promotions.
Article 11 (Provision of Personal Information Based on Prior Consent)
1. Notwithstanding the general prohibition against providing Personal Information to third parties, the Company may provide Personal Information to a third party if the User has made the information public in advance or has consented to the following. Even in such cases, the Company provides only the minimum Personal Information permitted under applicable laws and regulations.
1. Provision of Personal Information to the Korea Designated Driver Cooperative (한국대리운전협동조합) for the purpose of providing services.
2. If there is a change to, or termination of, the third-party provision relationship described in the preceding paragraph, the Company will notify Users and obtain their consent through the same procedure.
Article 12 (Retention and Use Period of Personal Information)
1. The Company retains and uses Users’ Personal Information for the period necessary to achieve the purposes for which it was collected and used.
2. Notwithstanding the preceding paragraph, the Company retains records of improper use for up to one year from the date of membership withdrawal in accordance with its internal policy, for the purpose of preventing improper registration and use.
Article 13 (Retention and Use Periods Required by Law)
The Company retains and uses Personal Information as follows in accordance with applicable laws and regulations:
1. Information and retention periods under the Act on Consumer Protection in Electronic Commerce, Etc.
1. Records concerning contracts or cancellation of orders: five years;
2. Records concerning payment and the supply of goods or services: five years;
3. Records concerning consumer complaints or dispute resolution: three years; and
4. Records concerning labeling and advertising: six months.
2. Information and retention periods under the Protection of Communications Secrets Act:
1. Website access logs: three months.
3. Information and retention periods under the Electronic Financial Transactions Act:
1. Records concerning electronic financial transactions: five years.
4. Information and retention periods under the Act on the Protection and Use of Location Information:
1. Records concerning personal location information: until the rollover accident detection device is deactivated (at least six months).
Article 14 (Principle of Destruction of Personal Information)
As a general rule, the Company destroys Personal Information without delay when it is no longer necessary, including when the purpose of processing the Personal Information has been achieved or the applicable retention and use period has expired.
Article 15 (Procedures for Destroying Personal Information)
1. Information entered by a User for membership registration or a similar purpose is transferred to a separate database after the purpose of processing the Personal Information has been achieved (or, in the case of paper records, to a separate filing cabinet), retained for a prescribed period in accordance with the Company’s internal policies and other applicable laws for information-protection purposes (see the applicable retention and use periods), and then destroyed.
2. When grounds for destruction arise, the Company destroys the relevant Personal Information after obtaining approval from the Chief Privacy Officer.
Article 16 (Methods of Destroying Personal Information)
The Company deletes Personal Information stored in electronic files using technical methods that prevent the records from being restored or reproduced. Personal Information printed on paper is destroyed by shredding, incineration, or a similar method.
Article 17 (Measures Concerning the Transmission of Advertising Information)
1. The Company obtains a User’s express prior consent before transmitting commercial advertising information through an electronic transmission medium. However, prior consent is not required in any of the following cases:
1. If the Company directly collected the recipient’s contact information through a transaction involving goods or services and, within six months from the date the transaction ended, intends to transmit commercial advertising information concerning the same type of goods or services that the Company processed and transacted with the recipient; or
2. If a telemarketer under the Door-to-Door Sales, Etc. Act verbally informs the recipient of the source from which the Personal Information was collected and makes a sales solicitation by telephone.
2. Notwithstanding the preceding paragraph, if a recipient indicates that they do not wish to receive such information or withdraws their prior consent, the Company will not transmit commercial advertising information and will notify the recipient of the result of processing the opt-out or withdrawal.
3. If the Company transmits commercial advertising information through an electronic transmission medium between 9:00 p.m. and 8:00 a.m. on the following day, it will obtain separate prior consent from the recipient, notwithstanding Paragraph 1.
4. When transmitting commercial advertising information through an electronic transmission medium, the Company clearly states the following information in the advertising message:
1. The Company’s name and contact information; and
2. Information on how to opt out or withdraw consent to receive the information.
5. When transmitting commercial advertising information through an electronic transmission medium, the Company does not take any of the following actions:
1. Taking measures to evade or interfere with a recipient’s refusal to receive advertising information or withdrawal of consent;
2. Automatically generating a recipient’s contact information, such as a telephone number or email address, by combining numbers, symbols, or letters;
3. Automatically registering telephone numbers or email addresses for the purpose of transmitting commercial advertising information;
4. Concealing the identity of the sender or the source of the advertising transmission; or
5. Deceiving a recipient to induce a response for the purpose of transmitting commercial advertising information.
Article 18 (Protection of Children’s Personal Information)
1. To protect the Personal Information of children under the age of 14, the Company permits membership registration only by Users who are at least 14 years old.
Article 19 (Users’ Obligations)
1. Users must keep their Personal Information accurate and up to date. Users are responsible for problems arising from inaccurate information they provide.
2. A User who registers for membership by misappropriating another person’s Personal Information may lose eligibility to use the Company Services or be subject to penalties under applicable privacy laws.
3. Users are responsible for maintaining the security of their email addresses, passwords, and other credentials and may not transfer or lend them to a third party.
Article 20 (The Company’s Management of Personal Information)
When processing Users’ Personal Information, the Company implements necessary technical and administrative safeguards to protect it against loss, theft, leakage, alteration, or damage.
Article 21 (Handling of Deleted Information)
Personal Information terminated or deleted at the request of a User or the User’s legal representative is handled in accordance with the retention and use periods specified in this Policy and is protected against access or use for any other purpose.
Article 22 (Password Encryption)
Users’ passwords are stored and managed using one-way encryption. Personal Information may be reviewed or changed only by the relevant User who knows the password.
Article 23 (Measures Against Hacking and Similar Threats)
1. The Company uses its best efforts to prevent Users’ Personal Information from being leaked or damaged as a result of hacking, computer viruses, or other intrusions into information and communications networks.
2. The Company uses up-to-date antivirus software to prevent Users’ Personal Information or data from being leaked or damaged.
3. The Company uses intrusion-prevention systems and applies appropriate security measures in preparation for possible incidents.
4. If the Company collects and retains sensitive Personal Information, it uses encrypted communications and other safeguards to securely transmit the Personal Information over networks.
Article 24 (Minimization of Personal Information Processing and Training)
The Company limits the number of personnel responsible for processing Personal Information to the minimum necessary and emphasizes compliance with applicable laws and internal policies through administrative measures, including training for personnel who process Personal Information.
Article 25 (Measures in the Event of a Personal Information Breach)
If the Company becomes aware that Personal Information has been lost, stolen, or leaked (collectively, a “Breach”), it will notify the affected Users of all the following matters without delay and report the Breach to the Korea Communications Commission or the Korea Internet & Security Agency:
1. The categories of Personal Information affected by the Breach;
2. When the Breach occurred;
3. Measures Users may take;
4. The response measures taken by the information and communications service provider or other relevant party; and
5. The department and contact information through which Users may submit inquiries or request assistance.
Article 26 (Exceptions to Measures Concerning Personal Information Breaches)
Notwithstanding the preceding Article, if there is a legitimate reason that makes direct notification impracticable, such as the Company being unable to identify a User’s contact information, the Company may substitute the notice required under the preceding Article by posting the notice on its website for at least 30 days.
Article 27 (Installation and Operation of, and Opt-Out from, Automatic Personal Information Collection Tools)
1. The Company uses automatic Personal Information collection tools known as cookies to store and retrieve usage information from time to time in order to provide Users with personalized services. Cookies are small pieces of information sent by the server that operates a website (HTTP) to a User’s web browser, including browsers on PCs and mobile devices, and may be stored on the User’s device.
2. Users may choose whether to allow cookies. Users may configure their web-browser settings to accept all cookies, request confirmation whenever a cookie is stored, or reject all cookies.
3. If a User rejects cookies, the User may experience difficulty using certain Company Services that require login.
Article 28 (How to Configure Cookie Settings)
Users may allow or block cookies by changing their web-browser settings.
1. Microsoft Edge: Settings menu in the upper-right corner of the browser > Cookies and site permissions > Manage and delete cookies and site data.
2. Google Chrome: Settings menu in the upper-right corner of the browser > Privacy and security > Cookies and other site data.
3. Naver Whale: Settings menu in the upper-right corner of the browser > Privacy > Cookies and other site data.
Article 29 (Designation of the Company’s Chief Privacy Officer)
1. To protect Users’ Personal Information and handle privacy-related complaints, the Company designates the following department and Chief Privacy Officer:
1. Chief Privacy Officer
1. Name: Youngjun Ham (함영준)
2. Title: Managing Director
3. Telephone: +82-54-434-7278
4. Email: inplab@inplab.com
2. Department Responsible for Personal Information Protection
1. Department: Solution Business Team
2. Contact Person: Hyeongeun Ji (지현근)
3. Telephone: +82-54-434-7278
4. Email: sales@inplab.com
Article 30 (Remedies for Infringement of Rights)
1. A data subject may request dispute resolution or consultation from the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, or another relevant institution to obtain relief for an infringement of Personal Information. For other reports or consultations concerning infringements of Personal Information, please contact the following institutions:
1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code), www.kopico.go.kr
2. Personal Information Infringement Report Center: 118 (no area code), privacy.kisa.or.kr
3. Supreme Prosecutors’ Office: 1301 (no area code), www.spo.go.kr
4. Korean National Police Agency: 182 (no area code), ecrm.cyber.go.kr
2. The Company endeavors to guarantee data subjects’ right to informational self-determination and to provide consultation and remedies for damages arising from infringements of Personal Information. If you need to file a report or request consultation, please contact the responsible department specified in Paragraph 1.
3. A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing, Etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
1. Central Administrative Appeals Commission: 110 (no area code), www.simpan.go.kr
Addendum
Article 1 (Effective Date)
This Policy takes effect on December 9, 2025.
Article 2 (Previous Privacy Policy)
The previous Privacy Policy is available below:
- January 2, 2024–December 8, 2025