TEEMSTONE Corp. (hereinafter referred to as the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to promptly and effectively address any related inquiries or complaints.

Article 1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information will not be used for purposes other than those specified below. If the purpose of processing changes, the Company will take the necessary measures, including obtaining separate consent where required, in accordance with Article 18 of the Personal Information Protection Act.

Website inquiries

To receive and process inquiries submitted through the website, verify inquiry details, provide responses, and communicate with customers.

Marketing and advertising

To send newsletters and provide information about products, services, events, seminars, and other promotional content, only where the data subject has separately consented to receive such communications.

Article 2. Personal Information Collected and Methods of Collection

Personal information collected

Required information: Name, email address, company/organization name, contact information, and inquiry details.

② When using the Company's online services, certain information may be automatically generated and collected, including IP address, cookies, service usage records, date and time of access, browser information, and device information.

Methods of collection

  • Information submitted through the Contact Us form on the Company's website
  • Information automatically generated and collected while using the website or related services

Article 3. Processing and Retention Period of Personal Information

① The Company processes and retains personal information for the period prescribed by applicable laws and regulations or for the period agreed to by the data subject at the time the information is collected.

② The applicable retention periods are as follows:

  • Website inquiries: 3 years after the inquiry has been fully processed, for purposes such as maintaining inquiry history and responding to potential disputes, in accordance with the Company's internal policy
  • Marketing and promotional communications, including newsletters: Until consent is withdrawn or for 3 years, whichever occurs first

Article 4. Procedures and Methods for Destruction of Personal Information

① When personal information is no longer necessary, such as when the applicable retention period has expired or the purpose of processing has been fulfilled, the Company will destroy the information without undue delay.

② The procedures and methods for destruction are as follows:

Destruction procedure:

Once the retention period has expired or the purpose of processing has been fulfilled, the relevant personal information may be transferred to a separate database where retention is required under internal policies or applicable laws. It will be retained for the required period and subsequently destroyed.

Destruction method:

Personal information stored electronically is permanently deleted using technical methods that prevent the information from being restored or recovered.

Article 5. Provision of Personal Information to Third Parties

The Company provides personal information to third parties only where permitted under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or where otherwise permitted or required by law.

The Company currently does not provide personal information to third parties.

Article 6. Outsourcing of Personal Information Processing

The Company does not currently outsource the processing of personal information.

If the Company outsources personal information processing in the future, it will enter into the necessary agreements and implement appropriate safeguards in accordance with Article 26 of the Personal Information Protection Act.

Article 7. Rights of Data Subjects and How to Exercise Them

① Data subjects may request access to, correction or deletion of, or suspension of the processing of their personal information, and may withdraw their consent where applicable.

② These rights may be exercised in writing, by email, or through other methods permitted under Article 41 of the Enforcement Decree of the Personal Information Protection Act. The Company will respond to such requests without undue delay.

③ Data subjects may also exercise these rights through a legal representative or duly authorized agent. In such cases, a power of attorney must be submitted in the form prescribed under Annex No. 11 of the applicable regulations on personal information processing.

④ Requests for access to or suspension of personal information processing may be restricted in circumstances permitted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

Article 8. Use of Cookies and Other Automatic Data Collection Technologies

① The Company may use cookies to provide customized services and analyze website usage.

② Cookies are small data files sent by a website server to a user's browser and stored on the user's device.

③ Users may configure their browser settings to block or delete cookies. However, disabling cookies may limit the availability or functionality of certain services.

Article 9. Measures to Protect Personal Information

The Company takes the following administrative, technical, and physical measures to protect personal information in accordance with Article 29 of the Personal Information Protection Act.

Administrative measures

  • Establishment and implementation of internal management plans
  • Limitation of personnel authorized to process personal information
  • Regular privacy and security training

Technical measures

  • Management of access permissions to personal information processing systems
  • Maintenance of access logs
  • Installation and operation of security software, including antivirus software

Physical measures

  • Access controls for computer rooms, data storage facilities, and other locations where personal information is stored

Article 10. Personal Information Protection Officer

The Company has designated the following person as the Personal Information Protection Officer responsible for overseeing matters related to the processing and protection of personal information.

Personal Information Protection Officer

Beomsik Lee, CEO

Email: sales@ontune.co.kr

Tel: +82-2-2057-7393

Data subjects may contact the Personal Information Protection Officer regarding any questions, complaints, requests for remedies, or other matters relating to personal information protection.

Article 11. Remedies for Infringement of Personal Information Rights

Data subjects may contact the following organizations for consultation, dispute resolution, or other assistance regarding infringement of personal information rights:

  • Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
  • Personal Information Infringement Report Center: 118 / privacy.kisa.or.kr
  • Supreme Prosecutors' Office: 1301 / www.spo.go.kr
  • National Police Agency: 182 / ecrm.police.go.kr

Article 12. Changes to This Privacy Policy

The Company may amend this Privacy Policy to reflect changes in applicable laws, regulations, or Company policies.

Any changes will be announced on the Company's website at least 7 days before the effective date, and the revised Privacy Policy will take effect on the date specified in the relevant notice.

Supplementary Provision

This Privacy Policy is effective as of September 1, 2026.