> For the complete documentation index, see [llms.txt](https://creco-1.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://creco-1.gitbook.io/docs/guide/en/support/privacy.md).

# Privacy Policy

{% hint style="warning" %}
This is a reference translation. The Korean original is the authoritative version.
{% endhint %}

> NEXT LEVEL Studio Inc (hereinafter the "Company") complies with the personal information protection provisions of applicable laws, including the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter the "Network Act") and the Personal Information Protection Act, and does its utmost to protect the rights and interests of users.
>
> This Privacy Policy applies to all services provided by the "Company", including the web, and contains the following.

### Purposes of Using Personal Information

The "Company" processes personal information for the following purposes and does not use it for any other purpose. Where personal information is processed for a purpose other than the following, or the purpose of use is changed, the "Company" takes the necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

<table data-header-hidden data-search="false"><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Membership registration and management</strong></td><td>The Company processes members' information for the purposes of confirming intent to register and withdraw membership, identity verification in connection with providing membership-based services, age verification, consent of a legal representative, maintaining and managing membership status, preventing improper use of the service, various notices and communications, grievance handling, preventing and sanctioning acts that impede service operation (violations of laws and the terms of service, improper use, account misappropriation, fraudulent transactions, and the like), retaining records for dispute mediation, and delivering announcements.</td></tr><tr><td><strong>Use of the service</strong></td><td>The Company processes members' information for the purposes of operating and providing the service, analyzing service usage records and access frequency, analyzing service usage statistics (including demographic analysis), maintaining and managing the service and improving quality (including the user interface experience), discovering and improving new service elements, identity verification, age verification, payment and settlement, and confirming transaction history.</td></tr><tr><td><strong>Grievance handling and other complaint consultation</strong></td><td>The Company processes members' information for the purpose of user protection, including identity verification of members, confirming the content of complaints, contacting and notifying members for fact-finding, and notifying members of the results of handling.</td></tr><tr><td><strong>Events, promotions, and the like (optional)</strong></td><td><p>The Company processes members' information for marketing and promotional purposes, such as providing members with event information and opportunities to participate and providing advertising information. In such cases, however, members must give separate, optional consent. The Company does not transmit advertising information for commercial purposes without the user's prior consent, and where such content is transmitted, it complies with the methods prescribed by applicable laws and takes the necessary measures.</p><p><br></p></td></tr></tbody></table>

### Personal Information Collected and Methods of Collection

The "Company" collects and uses the following information upon membership registration and when providing the service, with the explicit consent of the data subject.

<table data-search="false"><thead><tr><th>Legal basis for collection</th><th>Purpose of collection</th><th>Items collected</th></tr></thead><tbody><tr><td>Personal Information Protection Act, Article 15 (1) 1</td><td><strong>Registration for, management of, and provision of the Creco service</strong></td><td><p>(Required) Name, email address, password, nickname, mobile phone number</p><p>(Optional) Thumbnail image</p></td></tr><tr><td>Personal Information Protection Act, Article 15 (1) 1</td><td><strong>Payment of service fees</strong></td><td><p>(Required) Card number, expiry date, first two digits of the password</p><p>(Optional) Billing contact email, billing address (country, state/province, city/county/district, detailed address, postal code)</p></td></tr><tr><td>Personal Information Protection Act, Article 15 (1) 1</td><td><strong>Grievance handling</strong></td><td>(Required) ID, email, name, nickname</td></tr><tr><td>Personal Information Protection Act, Article 15 (1) 1</td><td><strong>Marketing and advertising (checking event and promotion statistics, providing tailored information)</strong></td><td>(Optional) Name, email address, mobile phone number, cookies, IP, date and time of visit, service usage records</td></tr></tbody></table>

The "Company" collects and uses the following information on a lawful basis other than the data subject's consent when providing the service.

<table data-search="false"><thead><tr><th>Legal basis for collection</th><th>Purpose of collection</th><th>Items collected</th></tr></thead><tbody><tr><td>Personal Information Protection Act, Article 15 (1) 4</td><td><p><strong>Management and provision of the Creco service</strong></p><p><strong>(Service usage statistics, access management, providing a per-user environment, understanding activity information)</strong></p></td><td>Cookies, IP, date and time of visit, service usage records, device information: device_id, OS type and version, device type, and the like</td></tr></tbody></table>

### Entrustment of Personal Information Processing

The "Company" entrusts work relating to the processing of personal information as follows.

<table data-search="false"><thead><tr><th>Entrusted company</th><th>Entrusted work</th></tr></thead><tbody><tr><td><p>Toss Payments Co., Ltd.</p><p><a href="https://pages.tosspayments.com/terms/homepage/privacy/policy">(Click for the privacy policy</a>)</p></td><td>Electronic payment service</td></tr></tbody></table>

When entering into an entrustment agreement with an entrusted company, the "Company" specifies in the contract or other document, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information beyond the purpose of performing the entrusted work, technical and administrative protection measures, restrictions on re-entrustment, management and supervision of the entrusted party, liability including damages, and the like; supervises whether the entrusted party processes personal information safely; and, in accordance with Article 26 (6) of the Personal Information Protection Act, obtains the Company's consent where the entrusted party re-entrusts the "Company's" personal information processing work. Where the entrustment details change, we will inform you of that fact through this Privacy Policy.

Where personal information processing work is entrusted overseas, this is explained in the '**Cross-Border Transfer of Personal Information**' section below.

### Provision of Personal Information to Third Parties

As a rule, the "Company" does not provide users' personal information to third parties. However, in accordance with Articles 17 and 18 of the Personal Information Protection Act, where a user consents to provision to a third party for the performance of a transaction, only the minimum personal information necessary for providing the service, identifying the user, verifying identity, and the like may be provided to the service provider.

Users may decline to consent to the provision of personal information to third parties and may withdraw their consent at any time. However, use of some related services based on provision to third parties may be restricted. (The membership registration service remains available.)

### Criteria for Additional Use and Provision of Personal Information

In accordance with Article 15 (3) and Article 17 (4) of the Personal Information Protection Act, the "Company" may additionally use and provide personal information without the user's consent, taking into account the matters set out in Article 14-2 of the Enforcement Decree of the Personal Information Protection Act. The matters the "Company" specifically considers are as follows, and the "Company" will carefully determine whether to additionally use or provide personal information by comprehensively considering all circumstances, including applicable laws such as the Personal Information Protection Act, the purpose of using or providing the personal information, the manner in which the personal information is used or provided, the items of personal information to be used or provided, the content of any consent given by the user or any matters notified or disclosed to the user, the effect on the user of such use or provision, and the measures taken to protect the information concerned.

1. Whether it is related to the original purpose of collection
2. Whether the additional use or provision of the personal information is foreseeable in light of the circumstances of collection or processing practices
3. Whether it unfairly infringes the interests of the data subject
4. Whether measures necessary to ensure safety, such as pseudonymization or encryption, have been taken

### Cross-Border Transfer of Personal Information

The "Company" transfers personal information collected from service users overseas as follows, and provides the following information regarding cross-border transfers in accordance with Article 28-8 (2) of the Personal Information Protection Act.

If you refuse the cross-border transfer, you cannot use the service. If you do not wish the cross-border transfer to take place, you may withdraw your membership on the website or on mobile, or request withdrawal through customer support.

**Legal basis: Personal Information Protection Act, Article 28-8 (1) 3 (a) (entrustment of processing or storage for the performance of a contract, disclosed in the privacy policy)**

<table data-search="false"><thead><tr><th>Recipient and contact</th><th>Destination country</th><th>Date, time, and method of transfer</th><th>Items transferred</th><th>Purpose of use</th><th>Retention and use period</th></tr></thead><tbody><tr><td><p>Amazon Web</p><p>Services Inc.</p><p>(<a href="mailto:aws-korea-privacy@amazon.com">aws-korea-privacy@amazon.com</a>)</p></td><td>United States</td><td>Transmitted over an encrypted network at the time of service use</td><td>Data entered by users within the Creco service</td><td>Provision of the Creco service</td><td>Upon termination of the service or expiry of the retention period</td></tr><tr><td><p>Google LLC</p><p>(<a href="https://www.naver.com/">googlekrsupport@google.com</a>)</p></td><td>United States</td><td>Transmitted over an encrypted network at the time of service use</td><td>Data entered by users within the Creco service</td><td>Provision of the Creco service</td><td>Upon termination of the service or expiry of the retention period</td></tr></tbody></table>

### Rights and Obligations of the Data Subject and How to Exercise Them

Members may exercise the following rights as data subjects of personal information.

1. Members may exercise the following personal information protection rights with respect to the personal information processed by the "Company" at any time.
   * Request to access personal information
   * Request for correction where there are errors
   * Request for deletion
   * Request to suspend processing
   * Request to withdraw consent
2. Members may exercise their rights toward the "Company" in writing, by email, by facsimile (FAX), or by other means in accordance with Article 41 (1) of the Enforcement Decree of the Personal Information Protection Act, and the "Company" will take action without delay.
3. Where a data subject requests correction or deletion of errors in personal information, the "Company" does not use or provide the personal information concerned until the correction or deletion is completed.
4. Members may view, correct, and delete their own personal information using features on the website.
   * Data subjects may view, correct, and delete their personal information directly at any time under 'My Info -> Settings' on the website, and may exercise their rights through customer support.
5. Members may exercise their rights through a representative, such as the data subject's legal representative or a person duly authorized by them. In this case, a power of attorney in the form of Appendix 11 of the "Notice on Methods of Personal Information Processing" must be submitted.

### Procedure and Method for Destroying Personal Information

As a rule, members' personal information is destroyed without delay once the purpose of processing the personal information has been achieved. However, information that must be retained under other laws is stored separately for the period prescribed by those laws and then destroyed. The procedure, deadline, and method of destruction are as follows.

**Destruction procedure**

Information entered by a member is destroyed without delay after the purpose is achieved. Where it must be retained under applicable laws, it is moved to a separate database (or to separate documents in the case of paper), stored safely for a certain period in compliance with internal policies and other applicable laws, and then destroyed without delay. Personal information moved to such a database is not used for any other purpose except as provided by law.

**Destruction method**

Information in the form of electronic files is completely deleted using technical methods that make recovery and reproduction impossible.

Personal information printed on paper is destroyed by shredding or incineration.

**Destruction deadline**

Where the retention period for a member's personal information has elapsed, or where the personal information has become unnecessary because the purpose of processing has been achieved, the service concerned has been discontinued, or the business has ended, the personal information is destroyed immediately on the day such a ground is deemed to have arisen.

### Automatically Collected Personal Information and How to Refuse It

The "Company" installs and operates cookies in order to provide members with personalized services and the like. The purposes of using cookies and how to refuse them are as follows.

**What cookies are**

A cookie is a small amount of information sent by the server (http) used to operate a website to the data subject's browser. It is stored on the data subject's computer or mobile device and is automatically transmitted from the member's browser to the server when the website is accessed.

**Purposes of using cookies**

Cookies are used to understand members' access management, provide a per-member environment, understand member activity information, check event and promotion statistics, and thereby provide optimized, personalized services.

**Installing, operating, and refusing cookies**

Members have the option of whether to allow cookies to be installed. By setting options in their web browser, members may allow all cookies, be asked for confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if a member refuses cookies, there may be difficulties in providing the service. The methods for allowing or blocking cookies in each web browser are as follows.

\[Allowing/blocking cookies in a web browser]

* Chrome : Select the '⋮' icon at the top right of the browser > New Incognito window (shortcut: Ctrl+Shift+N)
* Edge : Select the '…' icon at the top right of the browser > New InPrivate window (shortcut: Ctrl+Shift+N)
* Safari: Preferences menu > Privacy tab > Set the level for cookies and website data
* Firefox: Options menu → Privacy → History → Use custom settings → Set the cookie level

\[Allowing/blocking cookies in a mobile browser]

･ Chrome : Select the '⋮' icon at the top right of the mobile browser > New Incognito tab

･ Safari : Mobile device Settings > Safari > Advanced > Block All Cookies

･ Samsung Internet : Select the 'Tabs' icon at the bottom of the mobile browser > Turn on Secret mode > Start

### Measures to Ensure the Safety of Personal Information

In accordance with applicable laws such as the Personal Information Protection Act, the "Company" takes the following technical, administrative, and physical measures necessary to ensure safety.

**Technical measures**

Managing access rights to personal information processing systems and the like, installing access control systems, encrypting unique identifying information and the like, installing security programs, and so on

**Administrative measures**

Establishing and implementing an internal management plan, providing regular staff training, and so on

**Physical measures**

Controlling access to server rooms, document storage rooms, and the like

### Personal Information Protection Officer

The "Company" has designated a personal information manager and a department responsible for personal information protection, as set out below, to take overall responsibility for work relating to the processing of personal information and to handle data subjects' complaints and provide remedies in connection with the processing of personal information.

* Personal Information Protection Officer
  * Name: Park SungIn
  * Title and position: Personal Information Protection Officer
  * Contact: 070-8801-6988, <official@creco.so>
* Department responsible for personal information protection
  * Department: Software Department
  * Contact: 070-8801-6988, <official@creco.so>

Members may contact the Company's department responsible for personal information protection regarding all matters relating to personal information protection inquiries, complaint handling, remedies, and the like arising while using the "Company's" services. The "Company" will respond to and handle data subjects' inquiries without delay.

### How Changes to the Privacy Policy Are Announced or Notified

Where content is added to, deleted from, or amended in the current Privacy Policy, the reason for the change and its content will be announced on the service web page.

Where the "Company" wishes to obtain a member's additional consent in order to use the member's personal information beyond the scope consented to by the member, or to provide it to a third party, the "Company" will notify the member individually in advance in writing, by email, by telephone, or otherwise, or will post the matter on a web page.

Where the "Company" entrusts the collection, storage, processing, use, provision, management, destruction, or the like of personal information to a third party, it notifies members of that fact through the Privacy Policy.

### How to Obtain Remedies for Infringement of Rights

Members may contact the following organizations to inquire about remedies, consultation, and the like regarding personal information infringement. These organizations are separate from the "Company". Please contact them if you are not satisfied with the results of the "Company's" own handling of personal information complaints and remedies, or if you need more detailed assistance.

* Personal Information Dispute Mediation Committee: [www.kopico.go.kr](http://www.kopico.go.kr/), 1833-6972
* Privacy Infringement Report Center: [privacy.kisa.or.kr](http://privacy.kisa.or.kr/), 118
* Supreme Prosecutors' Office Cyber Investigation Division: [www.spo.go.kr](http://www.spo.go.kr/), 02-3480-3570
* National Police Agency Cyber Bureau: [cyberbureau.police.go.kr](http://cyberbureau.police.go.kr/), 182

### Changes to the Privacy Policy

This Privacy Policy applies from its effective date, and where content is added, deleted, or corrected due to changes in applicable laws or policy, we will announce this through the announcements section.

***

* Announced: May 1, 2026
* Effective: May 16, 2026

<details>

<summary>Privacy Policy prior to May 16, 2026</summary>

### Article 1 (Users' Rights and How to Exercise Them)

1. Users may exercise their rights as data subjects at any time (accessing, correcting, withdrawing consent to, and deleting their own registered personal information), and may request access to, provision of, correction of, withdrawal of consent to, deletion of (withdrawal from membership), suspension of processing of, and objection to the following.
   * The user's personal information held by the "Company"
   * The status of the "Company's" use of the user's personal information or provision of it to third parties
   * The status of the user's consent to the collection, use, and provision of personal information
2. Users may request the "Company" to correct errors in their personal information.
3. Users may have requests for access to, correction or deletion of, or suspension of processing of personal information made on their behalf by a representative (the user's legal representative or a person duly authorized by the user). In this case, the representative must submit a power of attorney to the "Company".
4. The legal representative of a child under the age of 14 may request the "Company" to grant access to, correct or delete, or suspend the processing of that child's personal information.
5. The "Company" has appointed a Personal Information Protection Officer, and will take action without delay if you contact us by email or telephone for consultation or inquiries.

### **Article 2 (Users' Obligations)**

1. Users have an obligation to protect their own personal information, and the "Company" is not liable for problems arising from a user's carelessness — such as sharing an ID or password, or leaving a device unattended while logged in — where there is no intent, negligence, or other reason attributable to the "Company".
2. Users must keep their personal information up to date, and users themselves are responsible for problems arising from entering inaccurate information.
3. As a rule, a user's ID and password must be used only by the user and may not be transferred or lent to third parties. Where membership registration is made by misappropriating another person's personal information, or a purchase is made by misappropriating an ID or the like, membership may be revoked and penalties may be imposed under applicable laws.
4. After using the "Company's" services in a shared environment, users must log out of their account and close the web browser program.

### Article 3 (Automatic Collection of Personal Information **and How to Refuse It)**

1. A "cookie" is a very small text file sent by the server used to operate a website to the user's browser, which is stored and operated on the user's computer.
2. The "Company" installs and operates cookies in order to provide users with personalized services and the like.
3. The "Company" uses cookies to provide individually tailored services, such as target marketing, by analyzing users' access frequency and visit times, understanding usage patterns and areas of interest, tracking activity, gauging participation in various events, and determining the number of visits.
4. Users have the option of whether to allow cookies to be installed, and may allow or refuse all cookies, or be asked for confirmation each time a cookie is stored, by selecting options in each web browser. The methods for specifying whether to allow cookie installation are as follows. However, if a user refuses the storage of cookies, use of some services, such as those requiring login, may be restricted.
   * Chrome: Settings menu → Show advanced settings → Privacy - Content settings → Set the cookie level
   * Edge: Settings menu → Cookies and site permissions → Manage and delete cookies and site data
   * Safari: Preferences menu > Privacy tab > Set the level for cookies and website data
   * Firefox: Options menu → Privacy → History → Use custom settings → Set the cookie level

### Article 4 (Purposes of Collecting and Using Personal Information)

1. The "Company" collects personal information with the user's consent within the minimum scope necessary to provide the service, and does not refuse to provide the service on the ground that the user has not provided personal information beyond the necessary minimum. All personal information collected is used only within the scope of the notified purposes, and personal information is collected and used as follows depending on the type of service provided by the "Company".

**\[ Membership registration and use of the service ]**

<table data-search="false"><thead><tr><th>Member type</th><th>Collection method</th><th>Items collected</th><th>Retention period</th></tr></thead><tbody><tr><td>General</td><td>Membership registration</td><td>[Required] ID (email), password, nickname</td><td>Upon withdrawal of membership or achievement of the purpose of use</td></tr><tr><td>General</td><td>Profile settings</td><td>[Optional] Thumbnail image</td><td>Upon withdrawal of membership or achievement of the purpose of use</td></tr><tr><td>General</td><td>Registering a payment method</td><td>[Optional] Card number, expiry date, first two digits of the password</td><td>Upon deletion of the payment method or withdrawal of membership (however, transaction records such as payments and refunds are retained in accordance with applicable laws)</td></tr><tr><td>General</td><td>Entering invoice information</td><td>[Optional] Billing contact email, billing address (country, state/province, city/county/district, detailed address, postal code)</td><td>Upon withdrawal of membership or achievement of the invoicing purpose (however, transaction and settlement records may be retained in accordance with applicable laws)</td></tr></tbody></table>

**\[ Information automatically collected and generated through use of the service ]**

| Items collected                                                                                                                                                           | Purpose                                                                                                                                                                                    | Retention period                                                   |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------ |
| <p>Usage information: cookies, IP, date and time of visit, service usage records</p><p>Device information: device\_id, OS type and version, device type, and the like</p> | Service usage statistics, access management, providing a per-user environment, understanding activity information, checking event and promotion statistics, providing tailored information | Upon withdrawal of membership or achievement of the purpose of use |

2. The "Company" may collect personal information by the following methods, and where personally identifiable personal information is collected, consent is obtained from the user. Where a user clicks the consent button, or enters and saves additional personal information collected through actions such as editing member information, the user is deemed to have consented to the collection of personal information.
   1. Website, mobile app, in writing, fax, telephone, customer support inquiries, event entries
   2. Automatic collection through a generated-information collection tool

### Article 5 (Provision of Personal Information to Third Parties)

1. The "Company" uses personal information only within the scope notified in "4. Purposes of Collecting and Using Personal Information" and, as a rule, does not provide users' personal information to third parties. The following, however, are exceptions.
   * Where a user consents to provision to a third party for the performance of a transaction, only the minimum personal information necessary for providing the service, identifying the user, verifying identity, and the like may be provided to the service provider.
   * Where Articles 17 and 18 of the Personal Information Protection Act apply, such as where there are special provisions in a statute
   * Where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for the purpose of investigation or inquiry
   * Where information is provided to advertisers, partners, research institutions, and the like in a form that cannot identify a specific individual, for the purpose of compiling statistics, academic research, or market research
2. Users may decline to consent to the provision of personal information to third parties and may withdraw their consent at any time. However, use of some related services based on provision to third parties may be restricted. (The membership registration service remains available.)

### Article 6 (Entrustment of Personal Information Processing)

The "Company" entrusts work relating to the processing of personal information as follows, and takes the measures necessary under applicable laws so that the personal information processed under entrustment is managed safely. The personal information processed under entrustment is also limited to the minimum scope necessary to provide the service.

**\[ Domestic entrustment ]**

<table data-search="false"><thead><tr><th>Entrusted company</th><th>Entrusted work</th><th>Retention and use period</th></tr></thead><tbody><tr><td>Toss Payments Co., Ltd.</td><td>Payment processing (registering a payment method, payment, cancellation)</td><td><a href="https://pages.tosspayments.com/terms/homepage/privacy/policy">In accordance with the operating policy of Toss Payments Co., Ltd.</a></td></tr></tbody></table>

**\[ Overseas entrustment ]**

<table data-search="false"><thead><tr><th>Recipient</th><th>Destination country</th><th>Date, time, and method of transfer</th><th>Retention and use period</th></tr></thead><tbody><tr><td>Amazon Web Services Inc.</td><td>United States</td><td>Transferred over the information and communications network immediately upon membership registration, and from time to time as required by the work</td><td>Upon withdrawal of membership or achievement of the purpose of use</td></tr><tr><td>Google LLC</td><td>United States</td><td>Transferred from time to time whenever a feature provided by Google is used</td><td><a href="https://ai.google.dev/gemini-api/docs/logs-datasets?hl=ko">In accordance with the operating policy of Google LLC<br></a>("Stored temporarily in memory by default, but retained for up to 55 days for monitoring inappropriate use")</td></tr></tbody></table>

### **Article 7 (Retention and Use Period of Personal Information)**

1. The "Company" retains users' personal information in accordance with the matters notified and consented to, until the purpose of collection and use is achieved or until the user requests withdrawal. However, where retention is required by law, the information is stored separately in a database or table isolated from external access.

**\[ Grounds for retaining information under applicable laws ]**

| Applicable law                           | Purpose                                                                | Items collected                                      | Retention period |
| ---------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------- | ---------------- |
| Protection of Communications Secrets Act | Provided when an investigative agency requests it with a court warrant | Log records, IP, service visit records, and the like | 3 months         |

### **Article 8 (Procedure and Method for Destroying Personal Information)**

1. As a rule, the "Company" destroys users' personal information without delay once the purpose of collecting and using the personal information has been achieved. However, where it must be retained under other laws as specified in "7. Retention and Use Period of Personal Information", it is moved to a separate database, stored safely for a certain period in compliance with internal rules and applicable laws, and then destroyed without delay. Such personal information is not used for any other purpose except as provided by law.
2. The "Company" destroys personal information by the destruction methods defined below.
   * Information in the form of electronic files is completely deleted using technical methods that make recovery and reproduction impossible.
   * Personal information printed on paper is destroyed by shredding or incineration.

### **Article 9 (Matters Concerning Protective Measures for Personal Information)**

1. In processing users' personal information, the "Company" devises technical and administrative protective measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged, in accordance with applicable laws that information and communications service providers must observe, such as the "Network Act" and the "Personal Information Protection Act".
2. The "Company" stores passwords and other information for which encryption is required by law in encrypted form. Only the user knows their password, and checking and changing personal information is likewise possible only for the person who knows the password. Please therefore take particular care to ensure that your password is not disclosed to others.

### **Article 10 (Personal Information Protection Officer and Handling of User Grievances)**

1. You may contact the Personal Information Protection Officer and customer support regarding all matters relating to personal information protection complaints, complaint handling, and the like arising while using the "Company's" services, and the Company will respond to users' inquiries promptly and in good faith.
   * Contact person: Information Protection Management Department
   * Contact person's phone: 070-88018-6988
   * Contact person's email: <official@creco.so>
2. If you need to report or consult about other personal information infringement, please contact the following organizations.

**\[ Organizations related to personal information infringement ]**

<table data-search="false"><thead><tr><th>Organization</th><th>URL</th><th>Contact</th></tr></thead><tbody><tr><td>Privacy Infringement Report Center</td><td><a href="https://privacy.kisa.or.kr">https://privacy.kisa.or.kr</a></td><td>118 (no area code)</td></tr><tr><td>Supreme Prosecutors' Office Cybercrime Investigation Team</td><td><a href="https://www.spo.go.kr">https://www.spo.go.kr</a></td><td>1301 (no area code)</td></tr><tr><td>National Police Agency Cyber Bureau</td><td><a href="https://cyberbureau.police.go.kr">https://cyberbureau.police.go.kr</a></td><td>182 (no area code)</td></tr></tbody></table>

### **Article 11 (Obligation to Announce the Privacy Policy)**

This Privacy Policy applies from the date of registration or amendment, and where content is added, deleted, or corrected due to changes in applicable laws or "Company" policy, we will give advance notice through the website or by email.

***

* Announced: January 15, 2026
* Effective: February 15, 2026

</details>
