Privacy Policy

CHAPTER 1 GENERAL PROVISIONS

Article 1 (Purpose) These Guidelines prescribe the standards and procedures necessary for Uriseed Co., Ltd. (the “Company”) to process personal information lawfully and securely in accordance with the Personal Information Protection Act (the “Act”) and other applicable laws, together with the responsibilities of employees and detailed measures for preventing and responding to personal information infringements.

Article 2 (Definitions)

1. “Company” means Uriseed Co., Ltd. and includes the uriseed.com website, the Company’s places of business, departments, and research institute.

2. “Processing” means the collection, generation, connection, interlocking, recording, storage, retention, alteration, editing, retrieval, output, rectification, recovery, use, provision, disclosure, destruction, or any similar operation performed on personal information.

3. “Data subject” means an individual who is identifiable by the information processed and is the subject of that information.

4. “Personal information file” means a collection of personal information arranged or organized according to a prescribed rule so that the information can be readily searched.

5. “Chief Privacy Officer” or “CPO” means the person who has overall responsibility for the Company’s processing of personal information.

6. “Personal information handler” means an officer, employee, dispatched worker, part-time worker, or other person who processes personal information under the direction and supervision of the Company.

7. “Personal information processing system” means a systematically organized system capable of processing personal information, including the online-store administrator, membership and order databases, and human resources, payroll, and accounting systems.

Article 3 (Scope of Application) These Guidelines apply to personal information concerning customers, website members, purchasers and recipients, persons requesting quotations, business-contact persons, employees, job applicants, and visitors that the Company processes in the course of business, and to all personal information files in electronic, image, printed, written, or other form.

Article 4 (Principles of Personal Information Protection)

1. The Company shall clearly specify the purpose of processing and shall lawfully and fairly collect only the minimum personal information necessary for that purpose.

2. The Company shall process personal information appropriately within the necessary scope and shall not use it for any unrelated purpose.

3. The Company shall maintain accuracy and currency within the necessary scope and prevent unauthorized alteration or damage caused intentionally or negligently.

4. The Company shall securely manage personal information through appropriate technical, managerial, and physical safeguards corresponding to the likelihood and severity of infringement of data-subject rights.

5. The Company shall disclose its Privacy Policy and provide reasonable procedures and methods for the exercise of data-subject rights, including access rights.

6. Even when processing is lawful, the Company shall minimize intrusion into privacy.

7. Where a purpose can be achieved using anonymous or pseudonymized information, the Company shall use anonymous information where possible and otherwise use pseudonymized information.

8. The Company shall observe and faithfully perform all statutory responsibilities and duties and endeavor to earn the trust of data subjects.

Article 5 (Relationship with Other Rules) Any other Company policy, work manual, or agreement addressing personal information shall conform to applicable law and these Guidelines. If another rule conflicts with these Guidelines, the stricter privacy-protective standard shall apply to the extent permitted by law.

CHAPTER 2 PERSONAL INFORMATION PROCESSING STANDARDS

SECTION 1 PROCESSING OF PERSONAL INFORMATION

Article 6 (Collection and Use)

1. “Collection” includes not only obtaining names, addresses, telephone numbers, and other information directly from a data subject, but also acquiring personal information concerning a data subject in any form.

2. The Company shall collect and use personal information only where a lawful basis under the Act exists, such as consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a statutory duty, or pursuit of a legitimate interest that clearly takes precedence over the data subject’s rights.

3. When relying on consent, the Company shall inform the data subject of all legally required matters and obtain freely given, specific, informed, and unambiguous consent.

4. The Company shall not refuse services merely because a data subject declines to provide optional information not essential to the service.

Article 7 (Provision of Personal Information)

1. “Provision” includes physical transfer of storage media, printouts or books containing personal information; network transmission; granting a third party access; sharing; or otherwise placing information in a state of transfer or joint use.

2. A transfer within the same Company under the authority of the same controller is an internal use, but disclosure to an independent third party constitutes provision.

3. Before providing personal information, the Company shall verify a lawful basis and comply with notice, consent, recordkeeping, and protective-measure requirements.

Article 8 (Use or Provision for Purposes Other Than the Original Purpose)

1. Where personal information is used or provided for another purpose under Article 18(2) of the Act, the Company shall restrict the recipient’s purpose, method, period, and form of use and require necessary safeguards.

2. The Company shall document the legal basis, purpose, items, recipient, date, approval, and safeguards for each use or provision outside the original purpose.

3. Public-authority exceptions available only to public institutions shall not be relied upon by the Company.

Article 9 (Notice of Source of Collection)

1. When the Company processes personal information collected from someone other than the data subject, it shall, upon request and without justifiable delay, notify the data subject of the source, purpose, and right to request suspension of processing, except where a statutory exception applies.

2. Where the statutory scale or conditions requiring proactive notice are met, the Company shall provide such notice without waiting for a request.

3. A record of the notice and any applicable exception shall be retained.

Article 10 (Destruction Methods and Procedures)

1. When the retention period expires, the purpose is achieved, the pseudonymization period expires, a service is discontinued, or the business ends, the Company shall destroy the information without undue delay and, absent justifiable grounds, within five days.

2. Electronic files shall be permanently deleted using a method that prevents recovery or reproduction. Paper and other media shall be shredded, incinerated, or otherwise destroyed beyond restoration.

3. The responsible department shall select the information for destruction, obtain the required approval, and record the result.

Article 11 (Retention Required by Law) Where information must be retained under law notwithstanding Article 10, it shall be physically or technically separated from information in active use, access shall be restricted, and it shall not be used for any other purpose.

Article 12 (Method of Obtaining Consent)

1. Separate consent shall be obtained for each legally distinct matter, with required and optional matters clearly distinguished and expressed in plain language.

2. Important matters, including sensitive information, unique identification information, third-party provision, overseas transfer, and marketing, shall be conspicuously presented.

3. Consent may be obtained in writing, electronically, by telephone with a recorded confirmation, or by another legally recognized method.

4. The Company bears the burden of proving that valid consent was obtained.

Article 13 (Consent of a Legal Representative)

1. When processing personal information of a child under 14, the Company shall obtain consent from the child’s legal representative and collect only the minimum information needed to verify that consent.

2. The child shall be informed of the Company’s identity and contact details and why the legal representative’s information is required.

3. The legal representative may exercise the child’s rights under the Act.

Article 14 (Where Prior Consent Cannot Be Obtained) If the Company processes personal information without prior consent to protect the life, body, or property of a data subject or third party in an urgent situation, it shall stop such processing immediately when the grounds cease and notify the data subject as required by law.

Article 15 (Supervision of Personal Information Handlers)

1. The Company shall keep the number of handlers and their processing scope to the minimum necessary for their duties.

2. Access rights shall be granted, changed, and revoked according to job responsibilities and shall be periodically reviewed.

3. Handlers shall receive regular privacy and security training and shall comply with confidentiality obligations during and after employment.

SECTION 2 OUTSOURCING OF PERSONAL INFORMATION PROCESSING

Article 16 (Selection of Processors) When selecting a processor, the Company shall consider staffing, facilities, financial and technical capabilities, security controls, accountability, past incidents, and the processor’s ability to protect personal information.

Article 17 (Processor’s Duty to Protect Personal Information)

1. A processor shall implement the managerial, technical, and physical safeguards required by the Standards for Measures to Ensure the Safety of Personal Information.

2. The outsourcing agreement shall state the purpose and scope, prohibition of processing outside the outsourced purpose, safeguards, supervision, restrictions on sub-processing, return or destruction, and liability.

3. The Company shall disclose the processor and outsourced work in its Privacy Policy and supervise performance through documentation, inspection, or audit.

SECTION 3 PREPARATION OF THE PRIVACY POLICY

Article 18 (Drafting Standards) The Privacy Policy shall separately and expressly state every item required by Article 30 of the Act and Article 31 of its Enforcement Decree, using clear, specific, and easy-to-understand language.

Article 19 (Required Matters) The Privacy Policy shall include the purposes, categories, and retention periods; third-party provision; outsourcing; destruction; rights and methods of exercise; CPO information; automated collection devices; security measures; overseas transfers; remedies for infringement; and all other matters required by law.

Article 20 (Publication)

1. The Privacy Policy shall be continuously posted on the Company website under the title “Privacy Policy” and shall be readily distinguishable and accessible.

2. If online publication is impracticable, it shall be made available by another method permitted by law.

3. Mobile and other service environments shall provide a readily accessible link or menu.

Article 21 (Changes) When changing the Privacy Policy, the Company shall continuously disclose the effective date and changes and enable data subjects to readily compare the previous and revised versions. Material changes affecting data-subject rights shall be announced in advance.

SECTION 4 CHIEF PRIVACY OFFICER

Article 22 (Disclosure of the CPO)

1. When appointing or changing the CPO, the Company shall disclose the appointment, name, department, telephone number, and other contact information.

2. The disclosed contact point shall be capable of actually receiving and handling complaints and inquiries. The Company may also disclose the contact details of a privacy manager.

Article 23 (Education of the CPO) CPO education may cover privacy laws and institutions, performance of statutory duties, incident response, risk management, internal controls, and any other matter necessary for protecting personal information at the Company.

Article 24 (Training Plan and Implementation)

1. The CPO shall establish an annual privacy-training plan and provide training to personal information handlers at least once each year.

2. New employees and persons newly assigned to processing duties shall be trained before performing those duties.

3. Training shall cover applicable laws and these Guidelines, Company procedures, access and password management, email and document security, and incident reporting and response.

4. Training dates, participants, content, and attendance records shall be retained for three years.

SECTION 5 NOTIFICATION AND REPORTING OF PERSONAL INFORMATION BREACHES

Article 25 (Personal Information Breach) A breach means loss, theft, or unauthorized disclosure that causes personal information to leave the Company’s management and control and become known or available to an unauthorized third party, other than by law or the Company’s lawful intent.

Article 26 (Timing and Contents of Notice)

1. Upon becoming aware of a breach, the Company shall notify affected data subjects within 72 hours of the categories breached, time and circumstances, measures available to minimize harm, the Company’s response and remedies, and the reporting department and contact details.

2. Notice may be delayed only where urgent action is required to prevent further disclosure, remediate vulnerabilities, or recover or delete the information, or where a force-majeure event makes timely notice difficult.

3. If all details cannot be confirmed promptly, known facts shall be notified first and additional facts supplied without delay.

Article 27 (Method of Notice)

1. Notice shall be provided individually in writing, by email, text message, or another reliable method.

2. Where individual notice is impracticable because contact details are unknown or a large number of data subjects are affected, the Company may use website publication or another legally permitted substitute, while continuing reasonable efforts to provide individual notice.

Article 28 (Regulatory Reporting)

1. Where a breach meets a statutory reporting threshold, including the scale, sensitive or unique identification information, or unlawful external access specified by law, the Company shall report to the Personal Information Protection Commission or the Korea Internet & Security Agency within 72 hours.

2. An initial report may be supplemented as facts are confirmed. The Company shall promptly report material changes and completion of response measures.

Article 29 (Incident Response Manual)

1. The Company shall maintain a written breach-response manual where required by law or where the scale or nature of its processing warrants one.

2. The manual shall cover detection, internal escalation, containment, preservation of evidence, risk assessment, notice and reporting, customer response, remediation, recurrence prevention, and communication responsibilities.

3. Contact lists and response procedures shall be tested and updated periodically.

Article 30 (Handling Infringement Reports) A person whose rights or interests are infringed by the Company’s processing may report the matter to the Personal Information Infringement Report Center. The Company shall also maintain an internal channel, promptly investigate reports, protect reporters from retaliation, and provide an appropriate response.

SECTION 6 GUARANTEE OF DATA-SUBJECT RIGHTS

Article 31 (Expiry of Grounds for Deferring Access) If access has been deferred under Article 35(3) of the Act and the grounds cease, the Company shall, absent justifiable grounds, provide access within ten days after cessation.

Article 32 (Rectification and Erasure)

1. Upon receiving a request under Article 36 of the Act, the Company shall investigate and, absent justifiable grounds, rectify or erase the information within ten days and notify the requester of the result.

2. Information whose collection is required by another law may not be erased merely upon request; the Company shall explain the legal grounds for refusal.

3. If incorrect information was provided to a third party, the Company shall notify that party of the correction or erasure without delay.

Article 33 (Suspension of Processing)

1. Upon a request under Article 37 of the Act, the Company shall, absent a statutory ground for refusal, suspend all or part of the processing within ten days.

2. Information no longer needed following suspension shall be destroyed or otherwise handled as required by law.

3. Any refusal shall be notified with the grounds and a method of objection.

Article 34 (Methods and Procedures for Exercising Rights)

1. The Company shall provide a method at least as easy as the method used to collect the information and shall not demand unnecessary evidence.

2. Rights may be exercised personally or through a duly authorized representative. The Company may take reasonable steps to verify identity and authority.

3. Requests and responses shall be recorded, securely managed, and processed within statutory periods.

CHAPTER 3 REGISTRATION AND MANAGEMENT OF COMPANY PERSONAL INFORMATION FILES

SECTION 1 GENERAL PROVISIONS

Article 35 (Application) This Chapter applies to all files continuously or repeatedly managed by Company departments, including membership, orders and delivery, quotation requests, customer service, business partners, employees and applicants, payroll and accounting, access and visitors.

Article 36 (Exclusions) Information collected for a one-time task and immediately destroyed without separate storage, and information retained by an individual for non-business purposes may be excluded. Information used for Company business or shared with others shall be registered.

SECTION 2 REGISTRATION SUBJECTS AND PROCEDURES

Article 37 (Responsibility for Registration)

1. The head of a department creating or operating a file shall register it with the CPO.

2. The CPO shall centrally maintain the Company register of personal information files.

Article 38 (Application for Registration or Change)

1. Before creating a file, a handler shall obtain department-head approval and apply to the CPO for registration.

2. The application shall include the file name, department, purpose and legal basis, categories of data subjects and information, collection method, users and recipients, processors, retention period, storage location, access rights, destruction method, and access-request department.

3. Changes shall be reported without delay.

Article 39 (Review) The CPO shall review the legality of the purpose, data minimization, retention, access rights, outsourcing, provision, and safeguards and may require corrections before approval.

Article 40 (Standard File List) The CPO may establish standard lists and controls for recurring functions, including membership, ordering and delivery, quotations and customer service, business partners, HR and payroll, accounting and tax, and access and visual data.

Article 41 (Destruction of Files)

1. A file shall be destroyed without delay when its retention period expires or purpose is achieved, unless retention is required by law.

2. The handler shall document the target, grounds, method, and date and obtain approval from the department head and CPO.

3. The result shall be recorded in the destruction log.

Article 42 (Removal from Register) After destruction, the handler shall request deletion or closure of the registration entry. The CPO shall verify destruction and update the register.

Article 43 (Corrective Measures) If a file is excessive, unregistered, retained beyond its period, contains unnecessary items, or has inappropriate access rights, the CPO may require suspension, reduction, destruction, revocation of rights, or another corrective measure.

SECTION 3 MANAGEMENT AND DISCLOSURE OF FILES

Article 44 (File Register) One register entry shall be maintained for each file. Files operated for the same purpose and containing the same categories may be consolidated within a reasonable scope.

Article 45 (Management of Use and Provision) For use outside the original purpose or third-party provision, the responsible person shall verify the legal basis and appropriateness and record the recipient, purpose, categories, date, method, approver, and safeguards in the use and provision log.

Article 46 (Determination of Retention Period)

1. The period shall be the minimum necessary from collection through deletion to achieve the purpose.

2. A statutory period shall control. If no period is prescribed, the department and CPO shall consider operational necessity, possible disputes, and data-subject rights.

3. Information shall not be retained permanently or indefinitely merely because the appropriate period is unclear.

Article 47 (Status Inspection and Reflection in Privacy Policy) At least annually, the CPO shall inspect the status of registration, changes, and destruction and ensure that purposes, categories, retention periods, third-party provision, outsourcing, and other matters requiring public disclosure are accurately reflected in the Privacy Policy.

Article 48 (Periodic Review) At least annually, the CPO shall review the adequacy of these Guidelines in light of changes in law, organization, business, and processing systems and shall revise them as necessary.

ADDENDUM

Article 1 (Effective Date) These Guidelines shall take effect on July 23, 2026.

Article 2 (Transitional Measures) Personal information files, outsourced processing processing devices already in operation on the effective date shall complete registration and inspection under these Guidelines within three months after that date.