Privacy Policy
Effective Date: 2026-05-26
Wavena Co., Ltd. (hereinafter the "Company") complies with the Personal Information Protection Act and related laws to protect the freedom and rights of data subjects, lawfully processing and safely managing personal information.
Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following privacy policy to inform data subjects of the procedures and standards for processing personal information and to enable the prompt and smooth handling of related grievances.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than those listed below, and if the purpose of use changes, the Company will implement necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
- Inquiry response and consultation: Responding to various inquiries regarding adoption, demos, partnerships, media, and recruitment; arranging follow-up meetings and sending materials
- Pre-contract review: Preliminary discussions for adoption/partnership contracts, sending quotes and proposals
- Recruitment: Evaluating job applicants and managing the talent pool, guiding applicants through the hiring process and notifying results
- Statistical analysis: Statistical analysis for service improvement in a form that cannot identify individuals
Article 2 (Items of Personal Information Collected and Collection Methods)
- Inquiry form (required): name, affiliation, contact number (mobile), email, inquiry type, consent to collection/use of personal information / (optional): role/position, inquiry details
- Job application (email) (required): name, email, information in resume / (optional): portfolio and other materials
- Automatically collected: cookies, access logs, IP address, device/browser information
Collection methods: input via the website inquiry form, direct email submission, automatic collection during service use.
Article 3 (Period of Processing and Retention of Personal Information)
The Company processes and retains personal information within the retention/use period required by law or the retention/use period consented to by the data subject at the time of collection.
- Inquiry response: 1 year after the response is completed (with data subject's consent)
- Pre-contract review: 1 year after the review is completed; retained separately if a contract is concluded (with data subject's consent)
- Job applicant information: 1 year after the recruitment process ends; 3 years with consent for the talent pool (with data subject's consent)
- Access logs: 3 months (Protection of Communications Secrets Act)
Article 4 (Provision of Personal Information to Third Parties)
The Company processes data subjects' personal information only within the scope of the purposes specified in Article 1, and does not process it beyond that scope or provide it to third parties without the data subject's prior consent.
However, exceptions apply in cases falling under Articles 17 and 18 of the Personal Information Protection Act.
Article 5 (Outsourcing of Personal Information Processing)
The Company outsources the following personal information processing tasks to ensure smooth service delivery.
- Recipient: Vercel Inc. (USA) / Outsourced task: Website hosting / Outsourcing period: Until the outsourcing contract ends
- Recipient: Resend Inc. (USA) / Outsourced task: Email sending service / Outsourcing period: Until the outsourcing contract ends
When entering into an outsourcing contract, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act, matters such as the prohibition of processing personal information for purposes other than the outsourced task, technical/administrative protection measures, restrictions on re-outsourcing, management and supervision of the recipient, and liability for damages, and supervises whether the recipient safely processes personal information.
Article 6 (Rights, Obligations, and Methods of Exercise for Data Subjects and Legal Representatives)
Data subjects may exercise the following personal information protection rights against the Company at any time.
- Request to suspend processing of personal information
- Request to access personal information
- Request to correct or delete personal information
- Withdrawal of consent to processing
Rights may be exercised in writing, by email, or through other means directed to the Company, and the Company will take action without delay.
Article 7 (Destruction of Personal Information)
When personal information becomes unnecessary, such as through the expiration of the retention period or the achievement of the processing purpose, the Company destroys the personal information without delay.
- Electronic files: permanently deleted in a manner that prevents recovery
- Paper documents: shredded or incinerated
Article 8 (Measures to Ensure the Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures: establishing and implementing an internal management plan, regular employee training
- Technical measures: managing access rights to personal information processing systems, installing access control systems, encrypting personal information (TLS for data in transit), installing and updating security programs
- Physical measures: access control for data storage rooms, etc.
Article 9 (Operation and Refusal of Cookies)
The Company may use cookies to provide personalized services to users.
Purpose of using cookies: analyzing users' access frequency, visit duration, etc., and improving services.
Installation, operation, and refusal of cookies: users may refuse to allow cookies to be stored by adjusting their web browser's settings. However, refusing to store cookies may limit the use of some services.
Article 10 (Chief Privacy Officer)
The Company designates the following Chief Privacy Officer, who is responsible for overseeing personal information processing and handling data subjects' complaints and remedies related to personal information processing.
- Name: Kim Yong-cheol
- Position: CEO
- Contact: manager.wavena@gmail.com
Article 11 (Remedies for Infringement of Rights)
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and other such bodies to seek remedies for personal information infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Investigation Division: 02-3480-3573 (www.spo.go.kr)
- National Police Agency Cyber Bureau: 182 (cyberbureau.police.go.kr)
Article 12 (Changes to the Privacy Policy)
This privacy policy applies from its effective date.
If there are additions, deletions, or corrections to this policy due to changes in laws or company policy, notice will be given through announcements starting 7 days before the changes take effect.
Company Information
Wavena Co., Ltd.
6th Floor, Building 651, Seoul National University Hospital Biomedical Research Institute, 214 Yulgok-ro, Jongno-gu, Seoul, Republic of Korea
Business Registration No.: 179-86-04290
Corporate Registration No.: 110111-0947891
CEO: Kim Yong-cheol