Privacy Policy
EDEUN Inc. (the "Company") complies with the Personal Information Protection Act and other applicable laws of the Republic of Korea, and has established and discloses this Privacy Policy to safely process users' personal information.
1. Purpose of Processing Personal Information
The Company processes personal information for the following purposes. The information is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
- Membership registration and management: identity verification for member services, personal identification, prevention of fraudulent use, confirmation of intent to join, age verification, complaint handling, and delivery of notices
- Provision of goods or services: delivery of goods, service provision, sending of contracts and invoices, provision of content, personalized services, identity verification, and billing/settlement
- Complaint handling: identity verification of complainants, confirmation of complaints, contact and notice for fact-finding, and notification of processing results
- Marketing and advertising: development of new services and provision of customized services, provision of events and promotional information and opportunities to participate, provision of services and advertising based on demographic characteristics, and analysis of access frequency (only where consent has been given)
2. Items of Personal Information Processed
The Company processes the following items of personal information.
① At membership registration
- Required: name, password, and at least one of email address or mobile phone number
- Optional: date of birth, gender, consent to receive marketing communications
② When ordering and delivering goods or services
- Required: recipient name, delivery address, contact number, payment information (such as payment approval information — the payment service provider processes and the Company does not retain original card data)
③ The following information may be automatically generated and collected in the course of using the Services.
- IP address, cookies, visit date and time, service usage records, records of improper use, device information (OS, browser type, etc.)
3. Retention Period of Personal Information
① The Company processes and retains personal information within the retention and use period required by law or consented to by the data subject at the time of collection.
② The specific processing and retention periods are as follows.
- Membership registration information: until withdrawal of membership (or until conclusion of any related investigation in case of a violation of applicable law)
- Records of contracts, withdrawal of subscription, payment, and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records of consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
- Records of labeling and advertising: 6 months (Act on Consumer Protection in Electronic Commerce)
- Books and documentary evidence concerning transactions as required under tax law: 5 years (Framework Act on National Taxes)
- Website visit records: 3 months (Protection of Communications Secrets Act)
4. Provision of Personal Information to Third Parties
The Company processes personal information only within the scope stated in Section 1 above, and provides personal information to third parties only where the data subject has consented or as otherwise permitted under Articles 17 and 18 of the Personal Information Protection Act. To process payments, the Company provides the following payment-related information to its payment service provider (PG), which independently processes such information under its own payment services license — this is a third-party provision rather than an outsourcing arrangement.
| Recipient | Purpose | Items Provided | Retention Period |
|---|---|---|---|
| Toss Payments Corp. | Payment processing and settlement | Payment approval information, order information | Retention period under the Act on Consumer Protection in Electronic Commerce |
5. Outsourcing of Personal Information Processing
The Company outsources the following personal information processing tasks to ensure smooth handling of personal information.
- Contracted courier/delivery company: delivery of goods
- Email delivery service provider: order/delivery notices and responses to customer inquiries
When entering into an outsourcing agreement, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act, matters such as the prohibition on processing personal information for purposes other than the outsourced task, technical and managerial safeguards, restrictions on re-outsourcing, supervision of the contractor, and liability for damages, and supervises whether the contractor processes personal information safely.
6. Rights and Obligations of Data Subjects
① A data subject may exercise the following rights regarding personal information protection against the Company at any time.
- Request to access personal information
- Request for correction in case of errors
- Request for deletion
- Request to suspend processing
② The rights under Paragraph 1 may be exercised against the Company in writing, by email, or by fax, and the Company will act on such requests without delay.
③ Where a data subject requests correction or deletion of an error in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
④ The rights under Paragraph 1 may be exercised through a data subject's legal representative or an authorized agent. In such case, a power of attorney in the form prescribed under the Enforcement Rules of the Personal Information Protection Act must be submitted.
7. Destruction of Personal Information
① The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved and the information is no longer necessary.
② Where personal information must be retained under other applicable law even after the consented retention period has elapsed or the purpose of processing has been achieved, the Company transfers such personal information to a separate database or stores it in a separate location.
③ The procedure and method for destroying personal information are as follows.
- Procedure: The Company selects personal information subject to a reason for destruction and destroys it upon approval of the Company's Data Protection Officer.
- Method: Personal information recorded and stored in electronic file form is securely deleted using methods that prevent recovery or reproduction, and personal information recorded and stored on paper is destroyed by shredding or incineration.
8. Measures to Ensure the Safety of Personal Information
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures: establishment and implementation of an internal management plan, and minimization of and access control for personnel handling personal information
- Technical measures: access control over personal information processing systems, encrypted storage of passwords, and use of secure communications (HTTPS)
- Physical measures: servers storing personal information are operated in a secure, access-controlled data center environment
9. Installation, Operation, and Rejection of Cookies
① The Company uses "cookies," which store and periodically retrieve usage information, to provide individually customized services to users.
② A cookie is a small piece of data sent to a user's browser by the server operating the website and may be stored on the hard disk of the user's computer.
- Purpose of use: cookies are used to identify visit and usage patterns for the Services and websites visited by users, popular search terms, and secure connection status, in order to provide optimized information to users.
- Rejecting cookies: users may allow or refuse the storage of cookies through the settings menu of the web browser they use, and specific instructions can be found in the help documentation of that browser (e.g. Chrome, Safari, Edge). However, refusing cookies may cause difficulty in using customized services.
10. Data Protection Officer
① The Company designates the following Data Protection Officer, who is responsible for overall personal information processing and handling complaints and remedies for data subjects.
Data Protection Officer: Sehyun Kim (CEO)
Email: help@laorkorea.com
Phone: +82-2-6953-7897
② Data subjects may direct any inquiries, complaints, or requests for remedies related to personal information protection arising from use of the Company's Services to the Data Protection Officer. The Company will respond to and process such inquiries without delay.
11. Requests to Access Personal Information
Data subjects may file a request to access personal information under Article 35 of the Personal Information Protection Act with the department below. The Company will make its best efforts to process such requests promptly.
Department handling requests to access personal information: LAOR Customer Care (also serves as Data Protection Officer)
Contact: Sehyun Kim
Email: help@laorkorea.com
Phone: +82-2-6953-7897 (ext. 2)
12. Remedies for Infringement of Rights
Data subjects may seek dispute resolution or consultation regarding infringement of personal information from the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Privacy Infringement Report Center, and similar bodies. For other reports of or consultation on personal information infringement, please contact the following agencies.
- Personal Information Dispute Mediation Committee: 1833-6972 (privacy.kr)
- Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Investigation Division: 1301 (spo.go.kr)
- National Police Agency Cyber Bureau: 182 (cyberbureau.police.go.kr)
13. Changes to this Privacy Policy
Where there are additions, deletions, or amendments to this Privacy Policy due to changes in law, policy, or security technology, the Company will announce such changes on the Site at least 7 days before the amendment takes effect.
This Privacy Policy is effective as of July 19, 2026.

