Privacy Policy

Last revised 2026.03.28

1. Purpose of Processing Personal Information

Yiyol ('Yiyol', 'yiyol.com', hereinafter referred to as 'Yiyol') processes personal information for the following purposes and does not use it for purposes other than the following.

  • To confirm customer intention to sign up, to provide services to customers, to identify and authenticate customers, to maintain and manage membership, to process payments for goods or services, and to supply and deliver goods or services.

2. Period of Processing and Retaining Personal Information

Yiyol processes and retains personal information within the period agreed upon when collecting personal information from the data subject or within the period prescribed by law.

The specific period of personal information processing and retention is as follows:

  • Customer registration and management: Until service use contract or membership termination. However, if there are remaining obligations or liabilities, until their settlement.
  • Records of contract, withdrawal of subscription, payment, and supply of goods in e-commerce: 5 years.

3. Rights and Obligations of the Data Subject and Legal Representative

As a personal information subject, the user can exercise the following rights:

  1. Request access to personal information
  2. Request correction if there is an error
  3. Request deletion
  4. Request suspension of processing

4. Items of Personal Information Processed

Yiyol processes the following personal information items:

  • Email, service usage records, access IP information, payment records.

5. Destruction of Personal Information

In principle, Yiyol will immediately destroy personal information once the purpose of processing is achieved. The procedures, time limit, and method of destruction are as follows:

  • Destruction procedure

    The information entered by the user is transferred to a separate DB (in the case of paper, a separate document) after achieving its purpose and stored for a certain period or immediately destroyed according to internal policies and other relevant laws. The transferred personal information is not used for purposes other than those authorized by law.

  • Destruction period

    The user's personal information will be destroyed within 5 days from the end of the retention period or within 5 days from the date it is deemed unnecessary due to achieving the processing purpose, discontinuing the service, or ending the business.

6. Matters Concerning the Installation, Operation, and Rejection of Automatic Personal Information Collection Devices

Yiyol does not use cookies that store and retrieve user information from time to time.

7. Personal Information Protection Officer

Yiyol has designated a personal information protection officer as follows to take responsibility for the overall processing of personal information, handle complaints, and provide remedies for data subjects related to personal information processing:

Personal Information Protection Officer

  • Name: Youngdo Lee
  • Position: CEO
  • Rank: CEO
  • Contact: yiyol@yiyol.com

Data subjects can inquire about all personal information protection-related matters, complaints, and remedies related to the use of Yiyol's services (or business) to the personal information protection officer and department. Yiyol will respond and process inquiries without delay.

8. Changes to the Privacy Policy

This Privacy Policy applies from the date of implementation, and in the event of additions, deletions, or modifications in accordance with laws and policies, such changes will be notified through the announcement 7 days before implementation.

9. Measures to Ensure the Safety of Personal Information

Yiyol takes the following technical, managerial, and physical measures to ensure the safety of personal information in accordance with Article 29 of the Personal Information Protection Act:

  1. Regular self-audit

    A regular self-audit (once a quarter) is conducted to secure stability related to personal information processing.

  2. Access restriction to personal information

    Access control is provided by granting, changing, and deleting access rights to the personal information processing database system. An intrusion prevention system is used to control unauthorized access from outside.

  3. Control of unauthorized access

    A separate physical storage location for personal information is established, and access control procedures are implemented and operated.