LEGAL
Privacy Policy
Legal
MMJ GROUP Co., Ltd. (hereinafter the ‘Company’) establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
Article 1 (Purposes of Processing Personal Information)
- Consultation and inquiry response · Confirming the content of inquiries, replying, and managing consultation history
- Review of partner and expert registration · Confirming the content of proposals, assessing collaboration potential, and negotiating terms
- Provision of education and services · Confirming applications, delivering schedules and guidance, and managing completion and usage records
- Contract performance and settlement · Concluding service contracts, billing and settling payments, and retaining legally required supporting documents
The Company does not use personal information for any purpose other than those stated above, and when the purpose of use changes, it takes necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
Article 2 (Items of Personal Information Processed)
The Company collects only the information that data subjects directly enter or submit, and does not collect unique identifying information including resident registration numbers, or sensitive information as defined in Article 23 of the Personal Information Protection Act.
| Collection Channel | Required Items | Optional Items |
|---|---|---|
| Consultation request form | Company or organization name, contact person's name, email, inquiry content | Phone number, business area of interest, current stage, desired start date |
| Partner · expert proposal | Name or organization name, email, proposed field, proposal content | Phone number, career and track-record materials |
| Inquiries via email, etc. | Sender's email address, inquiry content | Information voluntarily provided by the inquirer |
| Automatically generated during service use | Access IP address, access date and time, browser and device type | - |
Users may decline to enter optional items; in that case, the accuracy of consultation may decrease, but the use of the service will not be restricted.
Article 3 (Processing and Retention Period of Personal Information)
- The Company processes and retains personal information within the retention and use period stipulated by law or the retention and use period consented to by the data subject.
- The retention period for each processing purpose is as follows.
| Category | Retention Period | Basis |
|---|---|---|
| Consultation and inquiry records | 1 year after processing is completed | Responding to re-inquiries and preparing for disputes (consent) |
| Partner · expert registration information | Registration period and 1 year after registration is terminated | Managing collaboration history (consent) |
| Contract and settlement documents | 5 years after contract termination | Commercial Act, Framework Act on National Taxes, and other relevant laws |
| Automatically generated access logs | 3 months | Protection of Communications Secrets Act |
Personal information whose retention period has elapsed or whose processing purpose has been achieved is destroyed without delay in accordance with Article 6.
Article 4 (Provision of Personal Information to Third Parties)
- The Company processes personal information only within the scope specified in Article 1, and does not provide it to third parties except where the data subject has given prior consent or where Articles 17 and 18 of the Personal Information Protection Act apply.
- When carrying out a project entrusted by a public institution, the Company may provide the list of participants and completion information that the institution requires for project management purposes; in such cases, the Company informs the data subject of the items provided, the purpose, and the retention period, and obtains prior consent.
- The Company does not transfer personal information abroad.
Article 5 (Outsourcing of Personal Information Processing)
- The Company may outsource personal information processing tasks as follows to ensure smooth business operations.
| Contractor | Outsourced Task | Retention and Use Period |
|---|---|---|
| Cloud infrastructure provider | Data storage and server management for service operation | Until the outsourcing contract ends |
| Email delivery service provider | Sending guidance and reply emails | Until the outsourcing contract ends |
- When concluding an outsourcing contract, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in the contract matters such as the prohibition of processing personal information for purposes other than performing the outsourced task, technical and managerial protective measures, restrictions on re-outsourcing, supervision of the contractor, and liability including compensation for damages, and supervises whether the contractor processes personal information safely.
- If the content of the outsourced task or the contractor changes, the Company discloses this through this privacy policy without delay.
Article 6 (Procedures and Methods for Destroying Personal Information)
- When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, or similar reasons, the Company destroys the relevant personal information without delay.
- If personal information must continue to be preserved under other laws even though the retention period consented to by the data subject has elapsed, the Company moves the relevant personal information to a separate database or preserves it in a different storage location.
- Destruction procedure · The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Personal Information Protection Officer.
- Destruction method · Personal information recorded and stored in electronic file form is permanently deleted in a manner that makes recovery and reproduction impossible, and personal information recorded and stored on paper is shredded with a shredder or incinerated.
Article 7 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)
- Data subjects may, at any time, request the Company to access, correct, delete, suspend the processing of, or withdraw consent for their personal information.
- Rights may be exercised via email or in writing using the contact information in Article 10, and the Company will act on such requests without delay.
- If a data subject requests the correction or deletion of personal information due to an error or similar reason, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
- Rights may be exercised through the data subject's legal representative or an authorized agent; in such cases, a power of attorney in the form of Attached Form No. 11 of the Public Notice on the Methods of Processing Personal Information must be submitted.
- Requests to access and suspend the processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.
- Requests to correct or delete personal information cannot be made where such personal information is specified as a subject of collection under other laws.
Article 8 (Measures to Ensure the Security of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following measures to ensure security.
- Administrative measures · Establishing and implementing an internal management plan, minimizing the number of personnel handling personal information, and providing regular training for such personnel
- Technical measures · Managing access rights to the personal information processing system, access control, applying encryption of transmission sections (HTTPS), and installing and periodically updating security programs
- Physical measures · Using locking devices for storage areas of documents and storage media, and controlling access
Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
- For the convenience of users, the Company's website uses the browser's local storage function to save the display mode (light · dark) setting. This value is information that cannot identify an individual, is stored only in the user's browser, and is not transmitted to the Company's servers.
- The Company does not use tracking cookies intended to collect advertising or behavioral information.
- Users may delete the stored value at any time from the browser's settings menu, and doing so will not restrict their use of the website.
Article 10 (Personal Information Protection Officer and Department Receiving Access Requests)
The Company designates a Personal Information Protection Officer as follows to take overall responsibility for tasks related to personal information processing and to handle complaints from data subjects and provide remedies for damages in connection with personal information processing.
| Category | Details |
|---|---|
| Personal Information Protection Officer | CEO Jeong Myeong-hoon |
| jssacademy1@naver.com | |
| Location | 10th Floor, Unit 1001, 1449 Jungang-ro, Ilsanseo-gu, Goyang-si, Gyeonggi-do (Juyeop-dong, Hyowon Major) |
Data subjects may direct any inquiries, complaints, or requests for remedies related to personal information protection that arise while using the Company's services to the Personal Information Protection Officer. The Company will respond to and handle data subjects' inquiries without delay.
Article 11 (Remedies for Infringement of Rights)
To obtain remedies for personal information infringement, data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and similar bodies.
| Organization | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center | 118 | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 | www.spo.go.kr |
| National Police Agency Cybercrime Reporting System | 182 | ecrm.police.go.kr |
Furthermore, a person whose rights or interests have been infringed by a disposition made or an omission by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
Article 12 (Changes to the Privacy Policy)
- This privacy policy takes effect from its effective date.
- In the event of any addition, deletion, or correction of changes in accordance with laws and policies, the Company will provide notice through the website starting 7 days before the changes take effect. In the case of changes disadvantageous to users, notice will be provided starting 30 days in advance.
Announcement date August 1, 2026
Effective date August 1, 2026