KOR|ENG

LEGAL

Privacy Policy

Legal

MMJ GROUP Co., Ltd. (hereinafter the ‘Company’) establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

Article 1 (Purposes of Processing Personal Information)

  1. Consultation and inquiry response · Confirming the content of inquiries, replying, and managing consultation history
  2. Review of partner and expert registration · Confirming the content of proposals, assessing collaboration potential, and negotiating terms
  3. Provision of education and services · Confirming applications, delivering schedules and guidance, and managing completion and usage records
  4. Contract performance and settlement · Concluding service contracts, billing and settling payments, and retaining legally required supporting documents

The Company does not use personal information for any purpose other than those stated above, and when the purpose of use changes, it takes necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

Article 2 (Items of Personal Information Processed)

The Company collects only the information that data subjects directly enter or submit, and does not collect unique identifying information including resident registration numbers, or sensitive information as defined in Article 23 of the Personal Information Protection Act.

Collection ChannelRequired ItemsOptional Items
Consultation request formCompany or organization name, contact person's name, email, inquiry contentPhone number, business area of interest, current stage, desired start date
Partner · expert proposalName or organization name, email, proposed field, proposal contentPhone number, career and track-record materials
Inquiries via email, etc.Sender's email address, inquiry contentInformation voluntarily provided by the inquirer
Automatically generated during service useAccess IP address, access date and time, browser and device type-

Users may decline to enter optional items; in that case, the accuracy of consultation may decrease, but the use of the service will not be restricted.

Article 3 (Processing and Retention Period of Personal Information)

  1. The Company processes and retains personal information within the retention and use period stipulated by law or the retention and use period consented to by the data subject.
  2. The retention period for each processing purpose is as follows.
CategoryRetention PeriodBasis
Consultation and inquiry records1 year after processing is completedResponding to re-inquiries and preparing for disputes (consent)
Partner · expert registration informationRegistration period and 1 year after registration is terminatedManaging collaboration history (consent)
Contract and settlement documents5 years after contract terminationCommercial Act, Framework Act on National Taxes, and other relevant laws
Automatically generated access logs3 monthsProtection of Communications Secrets Act

Personal information whose retention period has elapsed or whose processing purpose has been achieved is destroyed without delay in accordance with Article 6.

Article 4 (Provision of Personal Information to Third Parties)

  1. The Company processes personal information only within the scope specified in Article 1, and does not provide it to third parties except where the data subject has given prior consent or where Articles 17 and 18 of the Personal Information Protection Act apply.
  2. When carrying out a project entrusted by a public institution, the Company may provide the list of participants and completion information that the institution requires for project management purposes; in such cases, the Company informs the data subject of the items provided, the purpose, and the retention period, and obtains prior consent.
  3. The Company does not transfer personal information abroad.

Article 5 (Outsourcing of Personal Information Processing)

  1. The Company may outsource personal information processing tasks as follows to ensure smooth business operations.
ContractorOutsourced TaskRetention and Use Period
Cloud infrastructure providerData storage and server management for service operationUntil the outsourcing contract ends
Email delivery service providerSending guidance and reply emailsUntil the outsourcing contract ends
  1. When concluding an outsourcing contract, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in the contract matters such as the prohibition of processing personal information for purposes other than performing the outsourced task, technical and managerial protective measures, restrictions on re-outsourcing, supervision of the contractor, and liability including compensation for damages, and supervises whether the contractor processes personal information safely.
  2. If the content of the outsourced task or the contractor changes, the Company discloses this through this privacy policy without delay.

Article 6 (Procedures and Methods for Destroying Personal Information)

  1. When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, or similar reasons, the Company destroys the relevant personal information without delay.
  2. If personal information must continue to be preserved under other laws even though the retention period consented to by the data subject has elapsed, the Company moves the relevant personal information to a separate database or preserves it in a different storage location.
  3. Destruction procedure · The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Personal Information Protection Officer.
  4. Destruction method · Personal information recorded and stored in electronic file form is permanently deleted in a manner that makes recovery and reproduction impossible, and personal information recorded and stored on paper is shredded with a shredder or incinerated.

Article 7 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)

  1. Data subjects may, at any time, request the Company to access, correct, delete, suspend the processing of, or withdraw consent for their personal information.
  2. Rights may be exercised via email or in writing using the contact information in Article 10, and the Company will act on such requests without delay.
  3. If a data subject requests the correction or deletion of personal information due to an error or similar reason, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
  4. Rights may be exercised through the data subject's legal representative or an authorized agent; in such cases, a power of attorney in the form of Attached Form No. 11 of the Public Notice on the Methods of Processing Personal Information must be submitted.
  5. Requests to access and suspend the processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.
  6. Requests to correct or delete personal information cannot be made where such personal information is specified as a subject of collection under other laws.

Article 8 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following measures to ensure security.

  1. Administrative measures · Establishing and implementing an internal management plan, minimizing the number of personnel handling personal information, and providing regular training for such personnel
  2. Technical measures · Managing access rights to the personal information processing system, access control, applying encryption of transmission sections (HTTPS), and installing and periodically updating security programs
  3. Physical measures · Using locking devices for storage areas of documents and storage media, and controlling access

Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

  1. For the convenience of users, the Company's website uses the browser's local storage function to save the display mode (light · dark) setting. This value is information that cannot identify an individual, is stored only in the user's browser, and is not transmitted to the Company's servers.
  2. The Company does not use tracking cookies intended to collect advertising or behavioral information.
  3. Users may delete the stored value at any time from the browser's settings menu, and doing so will not restrict their use of the website.

Article 10 (Personal Information Protection Officer and Department Receiving Access Requests)

The Company designates a Personal Information Protection Officer as follows to take overall responsibility for tasks related to personal information processing and to handle complaints from data subjects and provide remedies for damages in connection with personal information processing.

CategoryDetails
Personal Information Protection OfficerCEO Jeong Myeong-hoon
Emailjssacademy1@naver.com
Location10th Floor, Unit 1001, 1449 Jungang-ro, Ilsanseo-gu, Goyang-si, Gyeonggi-do (Juyeop-dong, Hyowon Major)

Data subjects may direct any inquiries, complaints, or requests for remedies related to personal information protection that arise while using the Company's services to the Personal Information Protection Officer. The Company will respond to and handle data subjects' inquiries without delay.

Article 11 (Remedies for Infringement of Rights)

To obtain remedies for personal information infringement, data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and similar bodies.

OrganizationPhoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Information Infringement Report Center118privacy.kisa.or.kr
Supreme Prosecutors' Office Cyber Investigation Division1301www.spo.go.kr
National Police Agency Cybercrime Reporting System182ecrm.police.go.kr

Furthermore, a person whose rights or interests have been infringed by a disposition made or an omission by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.

Article 12 (Changes to the Privacy Policy)

  1. This privacy policy takes effect from its effective date.
  2. In the event of any addition, deletion, or correction of changes in accordance with laws and policies, the Company will provide notice through the website starting 7 days before the changes take effect. In the case of changes disadvantageous to users, notice will be provided starting 30 days in advance.

Announcement date August 1, 2026

Effective date August 1, 2026

Main Home Everyone's Startup Services Partner & Expert Registration KakaoTalk 1:1 Chat Contact Us