Nu-Logos
Contact

Privacy Policy Personal Information Processing Policy

Effective date October 5, 2026. This English translation is provided for convenience; if it differs from the Korean version, the Korean version prevails.

Nu-Logos Corporation (the "Company") establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act to protect data subjects' personal information and to handle related complaints promptly and smoothly.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information is not used for any other purpose, and if the purpose changes, the Company will take the necessary measures, such as obtaining separate consent, under Article 18 of the Personal Information Protection Act.

1. Receiving and responding to inquiries: reviewing, answering, and following up on inquiries received by email about pilot projects, technology partnerships, careers, and other matters

2. Operating and improving the website: providing the website, maintaining security, and analyzing visit statistics

Legal basis: Receiving and responding to inquiries is based on Article 15(1)4 of the Personal Information Protection Act (measures requested by the data subject in the course of concluding a contract); operating and improving the website is based on Article 15(1)6 of the same Act (legitimate interests of the personal information controller).

Article 2 (Personal Information Processed)

The Company processes the following personal information.

Category Items Collection method
Inquiries Email address; name, organization, contact details, and inquiry content if provided by the data subject Email sent by the data subject
Website use Non-identifying visit statistics such as pages visited, referrers, browser and device type, and country, and access records generated when the website is accessed (such as IP addresses) Automatically generated and collected when the website is used

Article 3 (Processing and Retention Period)

① The Company processes and retains personal information within the retention and use period prescribed by law or consented to by the data subject at the time of collection.

② Personal information related to inquiries is retained for three years from the date the inquiry is resolved and then destroyed. However, where relevant laws require retention, it is retained for the period those laws prescribe.

③ Visit statistics from website use are retained for six months from collection, and access records are retained by the contractor (Cloudflare) for as long as needed for website operation and security.

Article 4 (Provision to Third Parties)

The Company processes personal information only within the scope specified in Article 1 and provides it to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the data subject's consent or under special provisions of law. The Company currently does not provide personal information to third parties.

Article 5 (Outsourcing of Processing)

① The Company outsources personal information processing as follows to handle it smoothly.

Contractor Outsourced task
Google LLC Sending, receiving, and storing email (Google Workspace)
Cloudflare, Inc. Website hosting and visit statistics

② When entering into an outsourcing contract, the Company specifies in the contract or other documents, under Article 26 of the Personal Information Protection Act, the prohibition of processing for purposes other than the outsourced task, safety measures, restrictions on re-outsourcing, management and supervision of the contractor, and liability such as damages, and supervises whether the contractor processes personal information securely.

③ If the outsourced tasks or contractors change, the Company will promptly disclose the changes through this Privacy Policy.

Article 6 (Overseas Transfer of Personal Information)

The Company transfers personal information overseas as follows.

ItemEmailWebsite
Recipient (contact)Google LLC
(googlekrsupport@google.com)
Cloudflare, Inc.
(dpo@cloudflare.com)
Destination countryUnited States and other countries where Google data centers are locatedUnited States, European Economic Area (EEA), and others
Items transferredEmail address, name, organization, contact details, and inquiry content in inquiry emailsAccess records (such as IP addresses) and visit statistics
Timing and methodTransmitted over the network when an inquiry email is receivedTransmitted over the network when the website is accessed
Purpose and retention periodSending, receiving, and storing email, for the period set out in Article 3Website operation, security, and visit statistics, for the period set out in Article 3
Legal basisArticle 28-8(1)3(a) of the Personal Information Protection Act (disclosure in the privacy policy)
How to refuse and its effectYou may contact us by post (head office address) instead of email; replies may take longer.This processing is necessary to access the website, so refusing it means not using the website.

Article 7 (Destruction Procedures and Methods)

① The Company destroys personal information without delay when it is no longer needed, such as when the retention period expires or the purpose of processing has been achieved.

② Where personal information must be kept under other laws even after the retention period ends or the purpose has been achieved, it is stored separately.

③ Information in electronic files is deleted in a way that cannot be recovered or reproduced, and personal information recorded on paper is shredded or incinerated.

Article 8 (Rights and Obligations of Data Subjects and Legal Representatives)

① Data subjects may at any time exercise their rights to request access to, correction or deletion of, or suspension of processing of their personal information.

② These rights may be exercised in writing, by email, or by other means under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on such requests without delay.

③ These rights may also be exercised through a representative, such as a legal representative or a person delegated by the data subject. In this case, a power of attorney must be submitted.

④ Requests for access and suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ Deletion cannot be requested where other laws specify the personal information as subject to collection.

⑥ When the Company receives a request for access, correction, deletion, or suspension of processing, it verifies that the requester is the data subject or a legitimate representative.

Article 9 (Measures to Ensure Safety)

The Company takes the following measures to ensure the safety of personal information.

1. Administrative measures: minimizing the number of people who handle personal information

2. Technical measures: managing access rights to email accounts and other systems containing personal information, and access controls such as passwords and two-step verification

3. Physical measures: controlling access to devices and documents containing personal information

Article 10 (Installation, Operation, and Refusal of Automatic Collection Devices)

The Company does not use cookies that store and retrieve user information. Visit statistics are collected with a cookieless web analytics tool (Cloudflare Web Analytics).

Article 11 (Privacy Officer)

① The Company designates the following privacy officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to it.

Name Changmin Yoon
Title CEO
Email contact@nu-logos.com
Phone +82-70-8065-4781

② Data subjects may contact the privacy officer about any inquiries, complaints, or remedies related to personal information protection arising from their use of the Company's website.

Article 12 (Remedies for Infringement of Rights)

To seek remedies for personal information infringement, data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, and others. For other reports or consultations on personal information infringement, please contact the agencies below.

  • Personal Information Dispute Mediation Committee(no area code) 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center(no area code) 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office(no area code) 1301 (www.spo.go.kr)
  • Korean National Police Agency(no area code) 182 (ecrm.police.go.kr)

Article 13 (Changes to This Privacy Policy)

① This Privacy Policy applies from October 5, 2026.

② If this Privacy Policy changes, the Company will announce the changes and their effective date on its website.