Lomin Inc. (hereinafter referred to as the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to promptly and smoothly handle related grievances. If the Company amends this Privacy Policy, it will provide notice through its website.
Table of Contents
1. Personal Information Collected, Purposes of Collection and Use, and Processing and Retention Period
2. Procedures and Methods for Destroying Personal Information
3. Provision of Personal Information to Third Parties
4. Outsourcing of Personal Information Processing
5. Rights of Users and Legal Representatives and How to Exercise Them
6. Installation/Operation of Automatic Personal Information Collection Devices and Refusal Thereof
7. Measures to Ensure the Security of Personal Information
8. Personal Information Protection Officer and Grievance Handling Department
9. Remedies for Infringement of Rights
10. Changes to the Privacy Policy
1. Personal Information Collected, Purposes of Collection and Use, and Processing and Retention Period
The Company collects personal information for the following purposes. The personal information collected will not be used for any purpose other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
a. Items collected: Basic information of service users
① Consultation/quotation inquiry
I. Company/organization name
II. Industry category
III. Name
IV. Position/title
V. Department/team name
VI. Job function
VII. Email
VIII. Landline phone
IX. Mobile phone
X. Payment method
XI. Referral source
② Service operation
I. User name
II. Email address
III. Password
③ Service improvement
I. Provision of AI services and performance improvement
II. Service consultation and provision
III. Provision of content
IV. Provision of customized services
V. Use for marketing and advertising
④ Service promotion and sales solicitation (optional: upon consent to receive SMS and emails)
I. Use for marketing and advertising
· Name
· Date of birth
· Address
· Phone number
· Email address
b. Retention and maintenance period: For the duration of service use (until membership withdrawal)
c. In the course of using other services, the following items may be collected automatically.
① Items collected
I. Documents uploaded by service users
II. Items entered by service users
III. Service usage records
IV. Access logs, cookies
V. IP and MAC addresses
VI. Records of improper use
VII. Customer inquiry records
VIII. Event participation records
d. If additional personal information is collected, the Company will notify service users of the personal information items collected, the purposes of collection and use, and the retention period at the time of collection, and will obtain consent.
2. Procedures and Methods for Destroying Personal Information
a. In principle, the Company destroys personal information without delay once the purposes of collection and use have been achieved.
b. However, when the purpose of collection or the purpose for which the personal information was provided has been achieved, when separate consent has been obtained for the retention of personal information, when retention is necessary under applicable laws, or when it is necessary to prevent improper use and prepare for unintended membership withdrawal, the Company may retain members’ personal information. If personal information must be retained, the relevant personal information will be transferred to a separate database (DB) or retained in another storage location.
c. The procedures and methods for destroying personal information are as follows.
① The Company selects personal information for which a reason for destruction has occurred and destroys it after storing it for a certain period in accordance with internal policies and applicable laws, or destroys it immediately.
② Personal information recorded/stored in electronic file format is destroyed using a method that prevents the records from being restored, and personal information recorded/stored in paper documents is destroyed by shredding or incineration.
d. Retention period of personal information
① Act on the Consumer Protection in Electronic Commerce, etc.
I. Records on contracts or withdrawal of offers, etc.: 5 years
II. Records on payment and supply of goods, etc.: 5 years
III. Records on consumer complaints or dispute resolution: 3 years
② Framework Act on Electronic Documents and Transactions
I. Records on electronic document distribution through certified electronic addresses: 10 years
II. Records on electronic financial transactions: 5 years
③ Records on labeling and advertising: 6 months
④ Protection of Communications Secrets Act
I. Service usage records, access logs, cookies, IP and MAC addresses: 3 months
e. Destruction method
① Personal information whose purposes of collection and use have been achieved is destroyed in a manner that makes restoration impossible.
② In the case of paper documents, such as printed or written documents, personal information is destroyed by shredding, incineration, or similar methods.
③ In the case of electronic files, personal information is destroyed using technical methods that prevent recovery and restoration.
3. Provision of Personal Information to Third Parties
a. The Company uses service users’ personal information within the scope notified for the purposes of collection and use, and does not provide service users’ personal information without the consent of the data subject except in the following cases.
① Where separate consent has been obtained from the data subject
② Where there are special provisions in other laws
③ Where it is clearly deemed necessary for the urgent interests of the life, body, or property of the data subject or a third party
④ Where it is urgently necessary for public safety and welfare, such as public health
4. Outsourcing of Personal Information Processing
a. The Company outsources personal information processing to external professional service providers as follows for the smooth provision of services and processing of personal information.
b. Status of outsourced personal information processing
| Recipient | Details of outsourced work |
|---|---|
| PortOne Co., Ltd., Daou Data Corp. | Processing and agency services for service fee payments |
| informs.io(inblog Inc.) | Provision of homepage contact form solution and processing of submitted information (provision of collection, storage, and delivery functions) |
5. Rights of Users and Legal Representatives and How to Exercise Them
a. Users may at any time request the Company to allow access to, transfer, correct, delete, suspend processing of, or withdraw consent to personal information.
b. Rights may be exercised with the Company in writing, by phone, by email, by facsimile (FAX), or by other means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
c. Rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney in the form prescribed in Appendix Form No. 11 of the Enforcement Decree of the Personal Information Protection Act must be submitted.
d. The right to request access to, correction, deletion, or suspension of processing of personal information may be restricted under Article 35(4) and Article 27(2) of the Personal Information Protection Act.
e. If other laws specify that the relevant personal information must be collected, the Company may refuse a request for correction or deletion of personal information.
f. The Company verifies whether the person exercising the rights is the data subject or a legitimate representative.
g. The Company does not provide services to children under the age of 14 and does not collect their personal information.
6. Installation/Operation of Automatic Personal Information Collection Devices and Refusal Thereof
a. The Company uses cookies as follows to provide users with better services and customized services.
① Purpose of using cookies
I. Provision of customized services for users: The Company stores users’ service usage patterns (visit records, visit types, usage history, access paths, searches, etc.) and settings so that users can use the service quickly and conveniently on subsequent visits without having to reset them.
II. Service improvement and analysis: The Company uses Google Analytics, a web log analysis tool, to analyze users’ service usage patterns (visit records, visit types, usage history, access paths, searches, etc.) and uses the results to improve and optimize the service.
② Methods for installing/operating and refusing cookies
I. Users have the right to choose whether to allow the installation of cookies. Therefore, users may configure options in their web browser to allow all cookies, confirm each time a cookie is stored, or refuse the storage of all cookies.
· How to allow/block cookies (Google Chrome)
· Open Chrome and go to Settings: Click the More icon (⋮) in the upper right corner → select [Settings].
· Select Privacy and security: Click [Privacy and security] in the left menu.
· Access Site settings: Click [Site settings].
· Select cookie options: Click [Cookies and other site data].
· Configure allow/block settings: Select the desired option.
· How to allow/block cookies (Microsoft Edge)
· Open Edge and go to Settings: Click the Settings and more icon (···) in the upper right corner → select [Settings].
· Select Cookies and site permissions: Click [Cookies and site permissions] in the left menu.
· Manage cookies and data: Click [Manage and delete cookies and site data].
· Configure allow/block settings: Select the desired option (e.g., “Allow sites to save and read cookie data,” “Block third-party cookies,” etc.).
7. Measures to Ensure the Security of Personal Information
a. The Company takes the following measures to ensure the security of personal information.
① Management of personnel handling personal information
I. Establishment/implementation of an internal management plan, regular employee training, operation of a dedicated organization, and minimization of personnel handling personal information
② Restriction of access to personal information
I. Control through granting, changing, and deleting access rights to database systems that process personal information
II. Placement of personal information processing systems in a private network area where external access is blocked, and application of a network access control method that permits communication only between authorized systems
III. Detection and blocking of unauthorized external access and intrusion attempts through a web firewall security solution
③ Installation and operation of antivirus programs
I. Prevention of infringement caused by malicious programs such as computer viruses and spyware by installing antivirus programs on information devices used by personal information handlers to process personal information
II. The Company uses the automatic update function of security programs or performs updates at least once per day to use the latest antivirus programs
④ Encryption of personal information
I. Application of TLS 1.3 encrypted communication across all network communication sections to safely transmit and receive personal information over the network
II. Passwords are stored using a one-way encryption (hashing) method that cannot be decrypted
III. Personal information such as names and contact information, as well as document processing results, are stored after encryption using a secure encryption algorithm (AES-256), and encryption keys are securely managed through a separate key management system (KMS)
IV. Other important data concerning service users is stored in a cloud environment with separate security functions applied
⑤ Access control for unauthorized persons
I. Personal information processing systems are operated in domestic cloud data centers where physical protection facilities and access control procedures are applied
⑥ Retention of access records and prevention of forgery or alteration
I. Records of access to personal information processing systems are retained and managed for at least the period prescribed by applicable laws, and access records are collected and stored through a separate log management system to prevent forgery, alteration, theft, or loss
⑦ Storage of non-electronic media
I. Personal information and general data are logically separated, and documents or auxiliary storage media containing personal information are stored in a secure public cloud storage with locking mechanisms
⑧ Obligations of service users
I. In addition to the above protective measures, the Company provides guidance so that users’ account information (email addresses, passwords, etc.) can be managed securely, and the Company is not responsible for personal information leakage incidents caused by users’ own negligence
II. Users must appropriately manage and be responsible for their own email addresses and passwords to protect their personal information
8. Personal Information Protection Officer and Grievance Handling Department
a. The Company has designated a Personal Information Protection Officer as follows to take responsibility for personal information processing and to handle complaints and provide remedies for damages.
Personal Information Protection Officer and department in charge
· Name: Seungjun Sung
· Position: CPO
· Department: PMO/Information Security Team
· Contact: 02-6289-0501
· Email: [contact@lomin.ai](mailto:contact@lomin.ai)
b. Users may contact the Personal Information Protection Officer and department in charge regarding inquiries, complaint handling, remedies for damages, and other matters related to personal information protection, and the Company will respond promptly and sufficiently to users’ inquiries.
9. Remedies for Infringement of Rights
a. Users may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, and other institutions to seek remedies for personal information infringement. For other reports or consultations regarding personal information infringement, please contact the following institutions.
① Personal Information Dispute Mediation Committee: 1833-6972 without area code ([www.kopico.go.kr](http://www.kopico.go.kr))
② Personal Information Infringement Report Center: 118 without area code (privacy.kisa.or.kr)
③ Korean National Police Agency: 182 without area code (ecrm.police.go.kr)
b. A person whose rights or interests have been infringed due to a disposition or omission by the head of a public institution regarding requests under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), and Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act. For more information on administrative appeals, please refer to the website of the Central Administrative Appeals Commission ([www.simpan.go.kr](http://www.simpan.go.kr)).
10. Changes to the Privacy Policy
a. This Privacy Policy applies from May 29, 2026.
b. Previous versions of the Privacy Policy can be found below.
· Version: v1.0 (Mar. 01, 2023 ~ May 28, 2026)