Privacy Policy

Privacy Policy

Privacy Policy

Memebox Corporation (hereinafter referred to as the “Company”) establishes and discloses the following Privacy Policy in accordance with the Personal Information Protection Act and relevant laws and regulations to protect users' personal information and to promptly and smoothly handle related grievances.

Article 1 (Purpose of Personal Information Processing)

The Company processes the minimum amount of personal information necessary for the following purposes. The personal information being processed will not be used for any purpose other than those specified below; should the purpose of use change, the Company will implement necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

Website Inquiry Submissions and Responses: User identification, verification of inquiry details, contact and notification for fact-finding, notification of processing results, and other related purposes.

Newsletter Service Provision: Confirmation of subscription requests, dispatch of newsletter content, and subscriber management.

Web Analytics and Service Improvement: Analysis of website visit statistics and enhancement of user experience.

Article 2 (Categories of Personal Information Processed)

The Company processes the following categories of personal information:

Website Inquiry (Required): Name, email address, mobile phone number, company name, subject, and content.

Newsletter Subscription (Required): Name (or nickname) and email address.

Automatically Generated Information: Cookies, IP address, service usage records, device information, visit records, etc.

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention and usage period prescribed by law or the period agreed upon by the data subject at the time of collection.

Website Inquiry Data: 1 year from the date of receipt in accordance with internal policies

Newsletter Subscription Information: Until the user cancels their subscription (immediately destroyed upon cancellation)

Web Analytics Data (GA4): 2 months for event data, 14 months for user data

Web Analytics Data (Clarity): 30 days for Session Playback, up to 9 months for other data

Article 4 (Provision of Personal Information to Third Parties)

The Company processes personal information of data subjects within the scope specified in Article 1 and, in principle, does not provide personal information to third parties.

However, exceptions apply where the provision of personal information is permitted under relevant laws and regulations—such as the Personal Information Protection Act—including cases where there is separate consent from the data subject or where there are special provisions in the law.

Article 5 (Outsourcing and Overseas Transfer of Personal Information Processing)

To ensure the smooth provision of services, the Company entrusts the processing of personal information to external specialized service providers as follows. When entering into such entrustment agreements, the Company implements necessary protective measures and exercises supervision over the service providers to ensure the safe management of personal information, in accordance with Article 26 of the Personal Information Protection Act.

① Outsourcing of Personal Information Processing

Trustee (Entrusted Party)

Entrusted Task

Framer B.V.

Website operation, provision of inquiry forms, and data storage

Maily

Dispatch of newsletters, subscriber management, and unsubscribe list management

Google LLC

Visitor statistics and website usage behavior analysis using Google Analytics

Microsoft Corporation

Website usage behavior and user experience analysis using Microsoft Clarity

② Overseas Transfer of Personal Information

The Company transfers personal information overseas as follows for website operation, newsletter dispatch, and usage behavior analysis.

Recipient & Contact Information

Categories of Transferred Personal Information

Destination Country

Transfer Timing & Method

Purpose of Transfer

Retention & Use Period

Legal Basis for Transfer

Name, email address, phone number, company name, and inquiry details entered by the inquirer, as well as IP address, access logs, and device/browser information generated during the use of the service.

Netherlands, United States

Transmitted via encrypted network upon website visit or inquiry form submission

Website operation, inquiry processing, and data retention

Until the purpose of processing is achieved or the entrustment contract terminates. However, if retention is required by relevant laws and regulations, until the corresponding period.

Article 28-8, Paragraph 1, Item 3 of the Personal Information Protection Act (Outsourcing and retention necessary for the execution and fulfillment of a contract)

Email address, newsletter subscription information, encrypted internal identifier, terminal identification information

United States

Transmitted via encrypted network upon newsletter subscription or service usage

Data retention and infrastructure operation for the Maily service

Until subscription cancellation or termination of the entrustment contract

Article 28-8, Paragraph 1, Item 3 of the Personal Information Protection Act (Outsourcing and retention necessary for the execution and fulfillment of a contract)

Cookie identifier, IP address, access date/time, visited pages, usage logs such as clicks and scrolls, device, operating system, and browser information

United States

Transmitted via encrypted network when a user who consented to analytics cookies uses the website

Visitor statistics and website usage behavior analysis using Google Analytics

Up to 14 months (as set in Google Analytics) or until withdrawal of consent

Article 28-8, Paragraph 1, Item 1 of the Personal Information Protection Act (Separate consent of data subject)

Cookie identifier, IP address, access date/time, visited pages, usage logs such as clicks, scrolls, and mouse movements, device, operating system, and browser information

United States

Transmitted via encrypted network when a user who consented to analytics cookies uses the website

Website usage behavior and user experience analysis using Microsoft Clarity

30 days for session playback data, up to 9 months for clicks, heatmaps, labels, and favorited session data, or until withdrawal of consent

Article 28-8, Paragraph 1, Item 1 of the Personal Information Protection Act (Separate consent of data subject)

Data subjects may refuse the overseas transfer of personal information via Google Analytics and Microsoft Clarity by declining the installation of optional analytical cookies or by blocking cookies in their browser settings. Refusing this does not restrict basic use of the website; however, the information will not be used for service improvements based on the analysis of usage patterns.

The overseas transfer of personal information is essential for processing inquiry forms or sending newsletters. Data subjects may refuse such transfer by choosing not to submit an inquiry form or subscribe to the newsletter; however, doing so may restrict the ability to submit and receive responses to inquiries or to receive the newsletter.

The Company implements necessary protective measures during the overseas transfer of personal information, such as encrypted communication, restrictions on access rights, management and supervision of entrusted service providers, and the handling of grievances regarding personal information breaches.

Article 6 (Procedures and Methods for Personal Information Destruction)

The Company shall destroy the relevant personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the purpose of processing. The procedures and methods for destruction are as follows.

* Destruction Procedure: The Company selects personal information subject to destruction and destroys it upon obtaining approval from the Company's Chief Privacy Officer.

* Disposal Method: Information in electronic file format is deleted using technical methods that render the records unrecoverable, while personal information recorded on paper documents is destroyed by shredding or incineration.

Article 7 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

* Data subjects may exercise their rights—such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information—against the Company at any time.

You may exercise your rights by contacting the Company via written notice, email, or fax, and the Company will take action without delay.

You may exercise your rights through a representative, such as a legal representative or an authorized agent. In such cases, you must submit a power of attorney in accordance with Form No. 11 of the "Notice on Personal Information Processing Methods."

Article 8 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

Administrative Measures: Establishment and implementation of internal management plans, minimization and training of personnel handling personal information

Technical Measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs

Physical Measures: Access control to server rooms, data storage rooms, etc.

Article 9 (Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)

The Company uses cookies to ensure smooth website operation and to analyze usage status.

The cookies used by the company are categorized into essential cookies, which enable the website's basic functions, and analytical cookies, which are used to analyze users' website usage patterns.

The Company uses Google Analytics 4 (GA4) and Microsoft Clarity to analyze website usage. Analytical cookies are activated only if the user has provided prior consent via CookieYes; no data is collected prior to such consent.

The Company manages user consent regarding cookies via CookieYes, and users may decline the use of analytics cookies or withdraw their existing consent at any time through the cookie settings.

Article 10 (Data Protection Officer)

The Company bears overall responsibility for personal information processing tasks and has designated a Chief Privacy Officer as follows to handle related complaints and provide remedies for damages.

Name: Dino

Article 11 (Remedies for Rights Infringement)

Data subjects may contact the organizations listed below for consultation or to seek redress regarding personal information infringements. [The organizations listed below are separate from the Company.]

Personal Information Infringement Report Center: (Toll-Free) 118, privacy.kisa.or.kr

Personal Information Dispute Mediation Committee: (Toll-Free) 1833-6972, www.kopico.go.kr

Supreme Prosecutors' Office Cyber Crime Investigation Division: (Toll-Free) 1301, www.spo.go.kr

National Police Agency Cyber Bureau: (Toll-Free) 182, ecrm.cyber.go.kr

Article 12 (Notice on Personal Information Processing Related to Recruitment)

The company provides a link via the ‘Careers’ menu on its official website (mbx.co) that directs users to ‘Ninehire,’ an external recruitment management system. Details regarding the processing of personal information collected and used during the application process are outlined separately in the Recruitment Privacy Policy.

Recruitment Privacy Policy:

Article 13 (Amendments to the Privacy Policy)

This Privacy Policy shall take effect on August 21, 2026.

You can view the previous Privacy Policy below.