PRIVACY POLICY

< Personal information processing policy>



Effective date: March 23, 2020



Luca Corporation (hereinafter referred to as the "Company") values your personal information and complies with the Act on Promotion of Information and Communication Network Use and Information Protection.

Through the Personal Information Processing Policy, the company will inform you about the use and method of personal information you provide, and what measures are being taken to protect personal information.



■ Items and methods of collecting personal information

A. Items in your personal information that you collect

o The company collects the following personal information for membership registration, consultation, and service application.

- When signing up for membership: Name, date of birth, gender, login ID, password, home phone number, mobile phone number, e-mail, information of legal representative for subscribers under 14 years of age

- When applying for service: Address and payment information



o Service usage records, access logs, cookies, access IPs, payment records, and bad usage records can be generated and collected during the service use or business processing process.



B. Collection method

- Collection through website, written form, bulletin board, e-mail, event entry, delivery request, telephone, fax, creation information collection tool.



■ Purpose of collecting and using personal information

The company utilizes the personal information it collects for the following purposes:

o Implementation of contracts for service delivery and settlement of charges for service delivery

Contents provision, purchase and payment of charges, shipment of goods, or billing, financial transaction identification and financial services

o Management of members

Identification, personal identification, prevention of illegal use and unauthorized use of members, confirmation of intention to join, confirmation of age, confirmation of consent from legal representatives, and delivery of complaints.

o Utilize for marketing and advertising

Communication of advertising information, such as events, identification of frequency of access, or statistics on the use of services by members



■ Retention and use of personal information period

In principle, after the purpose of collecting and using personal information is achieved, the information is destroyed without delay. However, the following information is retained for the period specified for the following reasons:



A. Reasons for holding information according to the company's internal policy

Even if a member withdraws, the member's information may be retained for one year from the date of termination of the service contract in order to prevent the recurrence of fraudulent use of the defective member, resolve disputes, and cooperate at the request of the investigative agency.



B. Reasons for Information Retention under Related Acts and subordinate statutes

If it is necessary to preserve it in accordance with the regulations of the relevant statutes, such as the Act on the Protection of Consumers in Electronic Commerce, etc., the company shall keep the member information for a certain period prescribed by the relevant statutes.

o Records of withdrawal of contracts or subscriptions, etc.

- Reason for Conservation: The Act on the Protection of Consumers in Electronic Commerce, etc.

- Preservation period: 5 years

o Records on payment and supply of goods, etc.

- Reason for Conservation: The Act on the Protection of Consumers in Electronic Commerce, etc.

- Preservation period: 5 years

o Records on the handling of consumer complaints or disputes

- Reason for Conservation: The Act on the Protection of Consumers in Electronic Commerce, etc.

- Preservation period: 3 years

o Log history

- Reason for Conservation: Communication Secret Protection Act

- Preservation period: 3 months



■ Procedure and method for destroying personal information

In principle, the company shall destroy such information without delay after the purpose of collecting and using personal information is achieved. The destruction procedure and methods are as follows.

o Destruction procedure

The information you enter for membership is transferred to a separate DB after the purpose is achieved (in case of paper, separate filing boxes) and is stored for a certain period of time according to the internal policy and other related laws.

Personal information transferred to a separate DB is not used for any purpose other than to be retained unless it is under law.

o Destruction method

Personal information stored in an electronic file format is deleted using a technical method that cannot play the recording.



■ Personal information provided

In principle, the company does not provide users' personal information to the outside world. However, the following cases are not applicable cases below.

o Users agree in advance

o Where there is a request from an investigative agency in accordance with the provisions of the Act or in accordance with the procedures and methods prescribed by the Act for the purpose of investigation;



■ Consignment of personal information collected

The company entrusts the operation to an external specialized company for the service implementation of the service as follows.

o Persons subject to entrustment: Creama Factory Co., Ltd.

o Contents of consignment work: DM delivery and product recommendation services, order-related information, simple review/ preparation management and notification-related affairs



o Subject to entrustment: Inicis Co., Ltd.

o Contents of consignment work: Payment agency work



o Subject to entrustment: Café 24 Co., Ltd.

o Contents of entrusted work: Establishment and maintenance of hosting system



o Subcontractor : Cellmate

o Contents of consignment work: information related to logistics delivery and orders



■ Rights of users and legal representatives and their methods of exercise

o Users can inquire or modify their personal information registered at any time or request to unsubscribe.

o In order to view and modify personal information of users, you can click "Membership withdrawal" to unsubscribe (e.g., withdrawal of membership information) to view, correct, or withdraw personal information.

o If you contact the person in charge of personal information protection by writing, calling or e-mail, we will take action without delay.

o If you request correction of personal information errors, you will not use or provide such personal information until the correction is completed. In addition, if the wrong personal information is already provided to a third party, the correction result will be notified to a third party without delay so that the correction will be made.

o The company processes personal information that has been revoked or deleted at the request of the user as specified in the "Holding and Use Period of Personal Information Collected by the company" and does not allow perusal or use for other purposes.



■ Matters concerning the installation, operation, and refusal of personal information automatic collection devices;

The company operates a "cookie" that stores and retrieves your information from time to time. Cookies are tiny text files that the server used to run the website sends to your browser and are stored on your computer's hard disk.

The company uses cookies for the following purposes:

o Purpose of use, such as cookies

1. Target marketing and personalized services are provided by analyzing the frequency and time of access between members and non-members, identifying user tastes and interests, tracking the number of events, and identifying the number of visits.

2. You have the option of installing cookies. Therefore, you can allow all cookies by setting options in your web browser, go through verification every time the cookies are saved, or refuse to save all cookies.

o How to reject cookie settings

1. By choosing the option in your web browser, you can allow all cookies, check each time you save cookies, or deny all cookies.

2. Example of setting up (for Internet Explorer): Tools at the top of a web browser > Internet Options > Personal Information

3. However, if you refuse to install cookies, you may have difficulty providing the service.



■ Civil service for personal information

The company designates related departments and personal information protection managers to protect customers' personal information and handle complaints related to personal information as follows:

o Person in charge of personal information protection

Name: Park Jung-min

Affiliated: Management Strategy Headquarters

Phone Number: 02-3665-1333

Email: luca@lucacorp.co.kr



o Person in charge of personal information protection

Name: Park Jung-min

Affiliated: Management Strategy Headquarters

Phone Number: 02-3665-1333

Email: luca@lucacorp.co.kr



o You may report any complaints related to personal information protection caused by using the company's services to the person in charge of personal information protection or to the department in charge.

o The company will quickly and fully respond to users' reports.

o If you need to report or consult about other personal information breaches, please contact the institution below.

Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)

Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)

Supreme Prosecutors' Office Cyber Investigation Department (spo.go.kr / Area Code + 1301)

National Police Agency Cyber Security Administration (cyberbureau.police.go.kr / 182)