Appendix of Privacy Policy

<1-1> Items of personal information
Title of service Items to be collected(examples)
Internet membership service

Name, email address, ID, telephone number, address, national information,encoded identification information (CI), identification information of overlapped membership (DI)

For minors, information of legal representatives (name, birth date, CI and DI of legal representatives)

Online payment service

Name, address, telephone number, and email address

Payment information including account number and card number

Delivery information including delivery address, name and contact information of recipient

Information of bid, purchase and sales

Social network service

Name, email address, ID, telephone number, address, national information, address list (acquaintance)

Information of place of taking pictures and date of creation of files

Information of service use of members such as the type of contents watched or used by members, frequencies and period of activities of members

<1-2> Items of personal information
Lists Items to be collected(examples)
Equipment information

Equipment identifier, operation system, hardware version, equipment set-up and telephone number

Log information

Log data, use time, search word input by users, internet protocol address, cookie and web beacon

Location information

Information of device location including specific geographical location detected through GPS, Bluetooth or Wi-Fi (limited to the region permissible under the laws)

Other information

Preference, advertisement environment, visited pages regarding service use of users

<2> Method of collection

webpage, written form, fax, telephone calling, e-mailing, tools for collection of created information

provided by partner companies

<3> Use of collected information

Member management and identification

To detect and deter unauthorized or fraudulent use of or abuse of the Service

Performance of contract and service fee settlement regarding provision of services demanded by the users

Improvement of existing services and development of new services

Making notice of function of company sites or applications or matters on policy change

To help you connect with other users you already know and, with your permission, allow other users to connect with you

To make statistics on member’s service usage, to provide services and place advertisements based on statistical characteristics

To provide information on promotional events as well as opportunity to participate

To comply with applicable laws or legal obligation

Use of information with prior consent of the users (for example, utilization of marketing advertisement)

<4-1> Sharing of collected information

When the Company's affiliates, partners and service providers carry out services such as bill payment, execution of orders, products delivery and dispute resolution (including disputes on payment and delivery) for and on behalf of the Company

<4-2> Sharing of collected information

when the user selects to be provided by the information of products and services of certain companies by sharing his or her personal information with those companies

when the user selects to allow his or her personal information to be shared with the sites or platform of other companies such as social networking sites

other cases where the user gives prior consent for sharing his or her personal information

<5> Collecting cookies
Category Reasons for using cookies and additional information
strictly necessary cookies

This cookie is a kind of indispensable cookie for the users to use the functions of website of the Company. Unless the users allow this cookie, the services such as shopping cart or electronic bill payment cannot be provided. This cookie does not collect any information which may be used for marketing or memorizing the sites visited by the users (Examples of necessary cookies)

Memorize the information entered in an order form while searching other pages during web browser session

For the page of products and check-out, memorize ordered services

Check whether login is made on website

Check whether the users are connected with correct services of the website of the Company while the Company changes the way of operating its website

Connect the users with certain application or server of the services

performance cookies

This cookie collects information how the users use the website of the Company such as the information of the pages which are visited by the users most. This data helps the Company to optimize its website so that the users can search that website more comfortably. This cookie does not collect any information of the users. Any and all the information collected by this cookie will be processed collectively and the anonymity will be guaranteed. (Examples of performance cookies)

Web analysis : provide statistical data on the ways of using website

Advertisement response fee : check the effect of advertisement of the Company

Tracing affiliated companies; one of visitors of the Company provides anonymously feedback to the affiliated companies

Management of error : measure an error which may occur so as to give a help for improving website

Design testing : test other design of the website of Company

functionality cookies

This cookie is used for memorizing the set-ups so that the Company provides services and improves visit of users. Any information collected by this cookie does not identify the users individually. (Examples of functionality cookies)

Memorize set-ups applied such as layout, text size, basic set-up and colors

Memorize when the customer respond to a survey conducted by the Company

targeting cookies or advertising cookies

This cookie is connected with the services provided by a 3rd party such as the buttons of 'good' and 'share'. The 3rd party provides these services by recognizing that the users visit the website of the Company. (Examples of targeting cookies or advertising cookies)

carry out PR to the users as targets in other websites by connecting through social networks and these networks use the information of users' visit

provide the information of users' visit to ad agencies so that they can suggest an ad which may attract the interest of the users

<6> Security measures

Encryption of personal information
- Transmit users' personal information by using encrypted communication zone
- Store important information such as passwords after encrypting it

Countermeasures against hacking
- Install a system in the zone the external access to which is controlled so as to prevent leakage or damage of users' personal information by hacking or computer virus

Establish and execute internal management plan

Install and operate access control system

Take measures to prevent forging or alteration of access record

<7> Data transmission

Considering it engages in global businesses, the Company may provide the users' personal information to the companies located in other countries for the purpose as expressly stated in this Policy. For the places where the personal information is transmitted, retained or processed, the Company takes reasonable measures for protecting that personal information. (If used in the US, additional security measures may be available) In addition, when the personal information obtained from the European Union is used or disclosed, the Company may have to comply with safe harbor principle as required by the Commerce Department of USA, take other measures or obtain consent from users so far as those complies with the regulations of EU so as to use a standardized agreement provision approved by executing organizations of EU or securing proper safe measures.

<8> 3rd party's sites and services

The website, product or service of the Company may include the links to the ones of a 3rd party and the privacy protection policy of the site of 3rd party may be different. Thus, it is required for the users to check additionally that policy of a 3rd party site linked to the site of the Company.

<9> Guide for users residing in California

If the user resides in California, certain rights may be given. The Company prepares preventive measures necessary for protecting personal information of members so that the Company can comply with online privacy protection laws of California.

In case of leakage of personal information, a user may request the Company to check the leakage. In addition, all the users in the website of the Company, can modify their information at any time by using the menu for changing information by connecting their personal account.

Moreover, the Company does not trace the visitors of its website nor use any signals for 'tracing prevent'. The Company will not collect and provide any personal identification information through ad services without consent of users.

<10> Guide for users residing in Korea

The Company guides several additional matters to be disclosed as required by the information network laws and personal information protection laws in the Republic of Korea as follows :

<10-1> Information collected

Examples of required information

Title of service Items to be collected(examples)
Internet membership service

Name, email address, ID, telephone number, address, national information, encoded identification information (CI), identification information of overlapped membership (DI)

For minors, information of legal representatives (name, birth date, CI and DI of legal representatives)

Online payment service

Name, address, telephone number, and email address

For payment with credit card : name of card company, number and expiration of card

For small sum payment charged on the mobile phone : mobile phone number,payment approval number

For payment by remittance : name of bank, account number and password of account

For deposit without a bankbook : name of remitter, contact information

Delivery information including delivery address, name and contact information of recipient

Information of bid, purchase and sales

Social network service

Name, email address, ID, telephone number, address, national information, address list (acquaintance)

Information of place of taking pictures and date of creation of files

Information of service use of members such as the type of contents watched or used by members, frequencies and period of activities of members

Examples of optional items
The user may reject the collection and use of optional items and, even in case of rejection, there is no limit on use of services

Purpose of collection Items to be collected(examples)
User analysis

The reason for membership, occupation, marriage status, wedding anniversary, interest category and SNS account information

Provision of customized ad

Contents and result of marketing activities and event participation

Provision of customized ad

Contents and result of marketing activities and event participation

urgent notice management of other agreements and event participation
Marketing

Preference, advertisement environment, visited pages regarding service use of users

Additional procedure for collection of sensitive information
If collection of sensitive information is indispensable, the Company may collect it by going through lawful procedure in accordance with relevant laws and regulations. The sensitive information which may be collected by the Company is as follows :

Thoughts and belief

Membership of and withdrawal from labor union or political party

Political opinions

Information of health and sexual life

Genetic information obtained from the result of gene test

Information of criminal record including announcement, exemption and suspension of sentences, care and custody, protective custody, treatment and custody, probation, lapse of suspension of sentence and cancellation of suspension of execution.

<10-2> Commission for collected personal information

For carrying out services, the Company commissions external professional companies (subcontractors) to process personal information as follows. This commissioned works for processing personal information is carried out by each subcontractor and service only if necessary for providing that service.

In commissioning process of personal information, in order to secure safety of personal information , the Company supervises and ensure to expressly state in the agreement with subcontractors so that those subcontractors will safely process personal information by strictly complying with directions regarding personal information protection, keeping personal

information secret, not disclosing it to a 3rd party and being liable for accidents and returning or destructing personal information upon termination of the commission or process.

Name of subcontractors Description of commissioned works (services)
AAA Customer service
<10-3>Details of provision of personal information to 3rd party

Except for the following cases, the Company does not disclose or provide personal information of the users to a 3rd party :

Recipients of information Purpose of use of recipient Items to be provided Period of retention and use of recipient
BBB Provision of service tie-up ID, Name and age Until the date when the purpose of use is achieved or period as required by the laws
<10-4>Period for retention and use of personal information

In principle, the Company destructs personal information of users without delay when : the purpose of its collection and use has been achieved; the legal or management needs are satisfied; or users request : Provided that, if it is required to retain the information by relevant laws and regulations, the Company will retain member information for certain period as designated by relevant laws and regulations. The information to be retained as required by relevant laws and regulations are as follows :

Record regarding contract or withdrawal of subscription : 5 years (The Act on Consumer Protection in Electronic Commerce)

Record on payment and supply of goods : 5 years (The Act on Consumer Protection in Electronic Commerce)

Record on consumer complaint or dispute treatment : 3 years (The Act on Consumer Protection in Electronic Commerce)

Record on collection/process, and use of credit information : 3 years (The Act on Use and Protection of Credit Information)

Record on sign/advertisement : 6 months(The Act on Consumer Protection in Electronic Commerce)

Log record of users such as internet/data detecting the place of user connection : 3 months(The Protection of Communications Secrets Act)

Other data for checking communication facts : 12 months (The Protection of Communications Secrets Act)

<10-5>Procedure and method of destruction of personal information

In principle, the Company destructs the information immediately after the purposes of its collection and use have been achieved without delay : Provided that, if any information is to be retained as required by relevant laws and regulations, the Company retain it for the period as required by those laws and regulations before destruction and, in such event, the personal information which is stored and managed separately will never be used for other purposes. The Company destructs : hard copies of personal information by shredding with a pulverizer or incinerating it; and delete personal information stored in the form of electric file by using technological method making that information not restored.

<10-6>Technical, managerial and physical measures for protection of personal information

In order to prevent the loss, theft, leakage, alteration or damage of personal information of the users, the Company takes technical, managerial and physical measures for securing safety as follows :

Items Examples
Technical measures

Utilize security servers for transmitting encryption of personal information

Take measures of encryption for confidential information

Install and operate access control devices and equipments

Establish and execute internal management plan

Managerial measures

Appoint a staff responsible for protecting personal information

Provide education and training for staffs treating personal information

Establish and execute internal management plan

Establish rules for writing passwords which is hard to be estimated

Ensure safe storage of record of access to personal information processing system

Classify the level of authority to access to personal information processing system

Physical measures

Establish and operate the procedure for access control for the facilities for storing personal information

Store documents and backing storage containing personal information in safe places which have locking device

<10-7>Staff responsible for managing personal information

The staff of the Company responsible for managing personal information is as follows :

Name of staff responsible for managing personal information :
- Dept. :
- Tel :
- Contact :