Privacy Policy
This document is a draft prepared based on the Personal Information Protection Commission's Guidelines for Drafting Privacy Policies and open-source policy documents. Business information and processor names marked with ○○will be replaced with actual values before official launch, and the document is intended to be reviewed by a legal professional before taking effect.
YOUTHON (the “Company”) complies with the Personal Information Protection Act and other applicable laws and establishes and publishes this Privacy Policy to safely protect personal information of user organizations and their administrators. The Company collects and uses only the minimum personal information necessary to provide services such as software procurement, Google Workspace provisioning and operations, quotations, and payments.
1. Personal Information We Collect
The Company collects the following information during organization registration, login, quotation/payment, and inquiry processes.
| Category | Collected items | Collection point |
|---|---|---|
| Organization information | Organization name, organization type, organization domain, business registration number | Organization registration · quotation |
| Administrator information | Administrator name, email address, contact number | Organization registration · login |
| Verification documents | Business registration certificate, unique-number certificate, evidence of nonprofit or youth-organization eligibility | Organization verification application |
| License recipient | Name · email address · affiliation of the user receiving the license | License provisioning request |
| Transaction information | Purchase and quotation history, payment method type, payment approval/cancellation records, tax invoice information | Quotation · payment |
| Automatically generated | Service usage records, access logs, cookies, browser · device information, IP address | During service use |
For card payments, payment instrument information such as card number, expiration date, and password is collected and processed directly by the payment gateway (PG). The Company does not receive or store it. The Company stores only the minimum information needed to confirm transactions, such as payment method (card/bank transfer/deferred), authorization number, approved amount, and timestamp.
The Company does not collect information such as ideology or beliefs, labor-union membership, political opinions, health information, or information about sexual life — sensitive information is not collected. The Company also does not collect unique identification information such as resident registration numbers. A business registration number identifies a corporation or organization and is not treated as unique identification information.
2. Purposes of Collection and Use
- Organization verification · member management — verify organization eligibility (apply youth organization · nonprofit pricing), identify administrators, prevent misuse
- Service provision — provision and apply software licenses, create and migrate accounts, issue quotations, provision and operate Google Workspace
- Payment · settlement — process purchase and renewal payments, issue tax invoices and transaction documents
- Notices · support — expiration and renewal guidance, service notices, inquiries and incident response
- Service improvement — improve functionality by analyzing usage statistics (processed after removing identifying information)
3. Retention and Use Period
The Company destroys personal information without delay once the collection/use purpose has been achieved. However, the following information is retained for the periods required by applicable law.
| Retained item | Retention period | Legal basis |
|---|---|---|
| Records concerning contracts or withdrawal | 5 years | Electronic Commerce Act |
| Records concerning payment and supply of goods/services | 5 years | Electronic Commerce Act |
| Records concerning consumer complaints or dispute resolution | 3 years | Electronic Commerce Act |
| Records concerning labeling and advertising | 6 months | Electronic Commerce Act |
| Transaction evidence such as tax invoices | 5 years | Framework Act on National Taxes · Value-Added Tax Act |
| Service access records | 3 months | Protection of Communications Secrets Act |
| Member (organization) information | Until membership withdrawal | Data-subject consent |
4. Provision of Personal Information to Third Parties
The Company does not use personal information beyond the purposes stated in this Policy or provide it to third parties, except in the following cases:
- The data subject has separately consented in advance
- License provisioning request to a software Vendor — due to the nature of procurement, the email address of the user receiving the license and the organization name are provided to the relevant Vendor. The provided items, purpose, and retention period are disclosed by product when the quotation is finalized. If the data subject does not consent, provisioning of that product may be restricted.
- Where specifically permitted by law or requested by an investigative authority in accordance with procedures and methods prescribed by law
5. Outsourcing of Personal Information Processing
The Company outsources personal information processing as follows to provide Services smoothly and specifies responsibilities for secure management, restrictions on sub-processing, damages, and related matters in outsourcing agreements.
| Processor | Outsourced work | Retention · use period |
|---|---|---|
| ○○ (Payment Gateway) | Card-payment approval/cancellation, auto-payment (recurring billing), settlement | Until termination of the outsourcing agreement |
| ○○ (Cloud Infrastructure) | Data storage and processing for service operations | Until termination of the outsourcing agreement |
| ○○ (Email · Notification Delivery) | Sending registration, authentication, expiration, and renewal notices | Until termination of the outsourcing agreement |
Changes to processors or outsourced work will be disclosed through this Policy.
6. Overseas Transfers of Personal Information
Many software products handled by the Company are supplied by overseas businesses. Personal information may be transferred overseas as follows for license provisioning.
| Recipient | Transferred items | Destination country · purpose | Retention period |
|---|---|---|---|
| Google LLC and other overseas software Vendors | User email address, name, organization name | United States and other Vendor locations · license provisioning and account creation | Until license use ends or according to Vendor policy |
| ○○ (Cloud Infrastructure) | Service usage records, access logs | ○○ · service operations · storage | Until termination of the outsourcing agreement |
The recipient's legal name and contact information, destination country, transfer timing, and transfer method are specifically disclosed by product at the quotation stagewhen the purchased product is finalized. Data subjects may refuse overseas transfer. However, refusal may make it impossible to provision a license for the relevant product. In accordance with Article 28-8 of the Personal Information Protection Act, the Company ensures through contracts and other measures that recipients implement necessary protections for personal information.
7. Personal Information of Children Under 14
The Company does not directly collect personal information of children under 14 from the data subject. However, organizations using the Youth Organization Edition may request account provisioning for program participants (youth). In such cases, the following standards apply.
- Responsibility for obtaining consent to collect and use participant personal information rests with the relevant organization. For children under 14, the organization must obtain consent from a legal representative in advance.
- The Company processes only the minimum information required for account provisioning (name or identification ID, affiliated organization) and does not separately collect information beyond the roster submitted by the organization.
- When an account is no longer needed because a program has ended or for another reason, the Company deletes the account and related information without delay at the organization's request.
- Legal representatives may request access, correction, deletion, or suspension of processing of the child's personal information.
8. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
Data subjects may exercise the following rights regarding their personal information at any time:
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
Rights may be exercised in writing or by email (privacy@youthon.kr), and the Company will act without delay. Requests may also be made through a legal representative or authorized agent. However, requests may be restricted where information must be retained by law or where the request may unjustly infringe another person's life, body, or property; in such cases, the Company will promptly notify the data subject of the reason. After logging in to My Page, users can directly view and delete organization/administrator information, issued quotation history, and organization verification status.
9. Destruction Procedures and Methods
- Destruction procedure — personal information whose processing purpose has been fulfilled or retention period has expired is destroyed through procedures established by internal policy and applicable law. Where retention is required by law, the information is moved to a separate database or stored in a different location.
- Destruction method — electronic files are permanently deleted in a manner that prevents recovery or restoration, and paper documents are shredded or incinerated.
10. Measures to Ensure Security of Personal Information
- Administrative measures — establish and implement internal management plans, minimize personnel handling personal information and provide regular training, manage access permissions
- Technical measures — access control for personal information systems, encryption in transit and at rest, retention and tamper prevention for access logs, installation and operation of antivirus and security software
- Physical measures — access control for data-storage systems and physical document-storage locations
11. Cookies and Other Automatic Collection Technologies
The Company uses cookies to maintain service state and understand usage statistics. Cookies are small pieces of information stored in the browser. Users can refuse or delete cookies through browser settings. However, refusing cookies may make some functions difficult to use, including maintaining cart and quotation state.
The Company does not collect behavioral information for personalized advertising and does not use third-party tracking tools for advertising purposes.
12. Automated Decisions
The Company does not use personal information to make automated decisions that have legal effects or similarly significant effects on data subjects. If such decisions are introduced in the future, the Company will disclose in advance the criteria, procedures, and methods for refusing or requesting an explanation through this Policy.
13. Privacy Officer and Access Requests
The Company designates the following privacy officer to oversee personal information processing and handle complaints and remedies relating to personal information.
| Category | Details |
|---|---|
| Privacy officer | Name ○○○ · Title ○○ · Email privacy@youthon.kr · Tel. 00-0000-0000 |
| Department receiving and processing personal-information access requests | YOUTHON Operations Team · Email privacy@youthon.kr |
Data subjects may contact the privacy officer regarding any privacy-related inquiry, complaint, or request for remedy arising from use of the Services, and the Company will respond and act without delay.
14. Remedies for Rights Violations
Data subjects may request dispute resolution or counseling from the following organizations for remedies relating to personal-information infringement.
| Organization | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | 118 without area code | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 without area code | www.spo.go.kr |
| Korean National Police Agency Cyber Investigation Bureau | 182 without area code | ecrm.police.go.kr |
In addition, if rights or interests are infringed by an administrative disposition or omission of a personal-information controller, an administrative appeal may be filed under the Administrative Appeals Act.
15. Changes to This Privacy Policy
This Policy applies from its effective date. If additions, deletions, or amendments are made because of changes in law, policy, or security technology, notice will be provided at the top of this page and to registered administrator emails beginning 7 daysbefore the effective date of the change ( 30 daysbefore changes that materially affect data-subject rights). Previous versions will be retained and made available on request.
The structure and required items in this Policy were prepared based on the Personal Information Protection Commission's Guidelines for Drafting Privacy Policiesand the statutory requirements of Article 30 of the Personal Information Protection Act.
Sentence structure and drafting style also reference open-source policy documents — Basecamp Policies(CC BY 4.0, “Adapted from the Basecamp open-source policies / CC BY 4.0”), GitHub Site Policy(CC0 1.0).
The licenses in the referenced source materials remain with their respective copyright holders, and this Policy has been modified and rewritten for YOUTHON. Review by a legal professional is required before actual implementation.