1.Purposes of Processing Personal Information
The Company processes personal information for the following purposes. When purposes change, additional consent will be obtained as required by Article 18 of PIPA.
- ① Membership Management
- Service provision, identity verification, fraud prevention
- ② Learning Service Delivery
- English literacy assessment, content delivery, data analytics, progress tracking
- ③ Academy/Institution Operation
- Processing on behalf of academies for student learning management
- ④ Customer Support
- Inquiries, A/S, parent notifications
- ⑤ Legal Compliance
- Tax filing, dispute resolution, statutory obligations
2.Personal Information Collected · Collection Methods
2-1. Items Collected
- ① Required (Student)
- Name, grade, academy token, student token, learning voice recordings, learning results/scores, IP address
- ② Required (Parent — for under-14 consent)
- Parent name, parent email, consent timestamp, signature (typed/image)
- ③ Required (Academy Admin)
- Academy name, contact name, email, mobile, business registration number
- ④ Optional
- Parent mobile, notes, marketing consent
- ⑤ Auto-Collected
- IP, cookies, User-Agent, access logs, service usage records
2-2. Collection Methods
- When academy admin registers student information
- During student service usage (voice recording, answers, etc.)
- When parent signs and consents on the consent page
- When customer inquiries are submitted
- Via automatic web collection tools (cookies, logs)
3.Retention · Usage Periods
The Company processes and retains personal information within the period required by law or consented by the data subject.
- Member Information
- Until membership withdrawal or academy contract end (subject to mandatory retention below)
- Learning Data (voice/scores/progress)
- During enrollment + 1 year (EBS public institution standard)
- Parent Consent Records
- 5 years from consent date (dispute response)
- Customer Inquiries
- 3 years (E-Commerce Act §6)
- Access Logs
- 3 months (Communications Confidentiality Act §15-2)
- Payment/Contract Records
- 5 years (E-Commerce Act §6)
4.Third-Party Provision · Delegation
4-1. Third-Party Provision
The Company provides information to third parties only with data subject consent, legal obligation, or in emergencies where the data subject cannot express their will. There is currently no regular third-party provision.
4-2. Processing Delegation (Processors)
- Vercel Inc.
- Web hosting, CDNUnited States
- Cloudflare Inc.
- Database, file storage, DDoS protectionUnited States (some Korea region)
- OpenAI
- AI evaluation models (as needed)United States
- NHN Cloud
- Email deliveryRepublic of Korea
- Edupang / Global Kita
- Customer support · A/SRepublic of Korea
5.Rights of Data Subjects
Data subjects may exercise the following rights at any time (PIPA §35~37):
- ① Right to Access
- View your own personal information
- ② Right to Correction/Deletion
- Correct or delete inaccurate information (except where retention is legally required)
- ③ Right to Suspend Processing
- Temporarily suspend processing
- ④ Right to Withdraw Consent
- Withdraw previously given consent
Exercise rights via written request, email (help@mobyread.co.kr), or phone (+82-1644-1777). Additional verification may be requested for security. For under-14 minors, parents/legal guardians may exercise these rights.
6.Protection of Minors Under 14 ⭐
6-1. Consent Process
- Academy admin registers parent email
- Automatic consent request email sent (with token URL)
- Parent reviews policy + signs + consents on consent page
- Student account activated upon completion
- Consent records retained for 5 years (dispute response)
7.Security Measures
The Company implements the following security measures pursuant to PIPA §29:
- Administrative
- Internal management plan, regular staff training, minimum access rights
- Technical
- PBKDF2 100,000-iteration password hashing, HTTPS (TLS 1.3) end-to-end, access control, intrusion detection
- Physical
- Certified domestic/international data centers (Vercel, Cloudflare, NHN Cloud)
- Access Control
- Role-Based Access Control (RBAC) — super admin / academy admin / teacher / student separation
- Encryption
- One-way hashing for passwords and private post passwords, separate key for voice files
- Audit Trail
- Personal information processing activity logs maintained
8.Cookies and Automatic Collection
- Essential Cookies
- Session maintenance, login state — service limited if refused
- Analytics Cookies
- Anonymous usage analytics — can be refused via browser settings
9.Data Protection Officer (DPO)
- Data Protection Officer
- Joohee Jung (정주희)CEO
- Organization
- Global Kita Inc.
- help@mobyread.co.kr
- Customer Service
- +82-1644-1777Weekdays 10:00–18:00 KST
- Postal Address
- Daereung Post Tower 2 #308, 306 Digital-ro, Guro-gu, Seoul, Republic of Korea
External Remedies
- Personal Information Dispute Mediation Committee
- +82-1833-6972https://www.kopico.go.kr
- Privacy Violation Center (KISA)
- +82-118https://privacy.kisa.or.kr
- Supreme Prosecutors' Office Cyber Crime
- +82-1301https://www.spo.go.kr
- Korean National Police Cyber Bureau
- +82-182https://ecrm.cyber.go.kr
10.Policy Changes
This policy is effective from the effective date. Any additions, deletions, or modifications due to legal or company policy changes will be announced 7 days before taking effect.
· Effective Date: 2026-06-16
· Version: v2.0
· Previous versions: Maintained separately (provided upon request)