Privacy Policy

DEAR SOOA Co., Ltd. (hereinafter referred to as the "Company") complies with the Personal Information Protection Act and other applicable laws and regulations. The Company establishes and discloses this Privacy Policy as follows to protect users' personal information and to promptly and effectively handle related inquiries and complaints.

Article 1. Personal Information Collected and Methods of Collection

  1. The Company collects the following personal information to provide services such as membership registration, order processing, payment, delivery, and customer support.
    1. Upon membership registration: Name, email address, password, and contact information
    2. Upon ordering and payment: Name, contact information, email address, shipping address, and information required for payment
    3. Upon contacting customer support: Name, contact information, email address, and details of the inquiry
    4. Information automatically generated and collected while using the services: Access logs, cookies, IP address, and device information
  2. Payment information required for payment processing, such as card numbers, is processed by payment gateway providers ("PG providers"), and the Company does not generally store such information.

Article 2. Purposes of Collecting and Using Personal Information

  1. Membership management: Providing membership services, verifying identity, preventing unauthorized use, handling inquiries and complaints, and delivering notices
  2. Provision of products and services: Processing orders and payments, delivering products, performing contracts, and settling charges
  3. Processing cancellations, exchanges, returns, and refunds, and providing customer support
  4. Improving services, developing new services, and analyzing usage statistics
  5. Providing marketing and promotional information only where the user has given consent

Article 3. Retention and Use Period of Personal Information

  1. The Company destroys personal information without delay once the purposes for which it was collected and used have been fulfilled. However, where retention is required under applicable laws and regulations, the information will be retained for the periods specified below.
    1. Records relating to contracts or cancellations: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
    2. Records relating to payments and the supply of goods or services: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
    3. Records relating to consumer complaints or dispute resolution: 3 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
    4. Records relating to labeling and advertising: 6 months (Act on the Consumer Protection in Electronic Commerce, Etc.)
    5. Records relating to access, including login records: 3 months (Protection of Communications Secrets Act)
  2. Upon withdrawal from membership, personal information will be destroyed without delay unless it is subject to a statutory retention obligation described above.

Article 4. Provision of Personal Information to Third Parties

  1. The Company does not use personal information beyond the scope specified in this Policy or provide it to third parties.
  2. Exceptions may apply in the following circumstances:
    1. Where the user has provided prior consent
    2. Where disclosure is required by law or requested through a lawful procedure by an investigative authority
    3. Where the minimum information necessary for delivery, including the recipient's information, shipping address, and contact information, is provided to a delivery service provider

Article 5. Outsourcing of Personal Information Processing

  1. The Company may outsource personal information processing operations to external service providers to ensure the effective provision of its services.
    1. Payment processing: Payment gateway providers and Shopify payment services
    2. Product delivery: Domestic and international delivery and logistics providers
    3. Online store operations and data storage: Shopify Inc.
  2. When entering into outsourcing agreements, the Company specifies the matters required under applicable laws and regulations and manages and supervises service providers to ensure that personal information is securely handled.

Article 6. Overseas Transfer of Personal Information

The Company uses the e-commerce platform provided by Shopify Inc. In the course of providing the services, personal information may be stored and processed outside the Republic of Korea in countries where the relevant service providers' servers are located. The Company takes the measures required under applicable laws and regulations to ensure that users' personal information is securely protected.

Article 7. Rights of Users and Legal Representatives and How to Exercise Them

  1. Users may request access to, correction or deletion of, or suspension of the processing of their personal information at any time.
  2. Users may exercise their rights by contacting customer support by email or telephone, and the Company will take the necessary measures without delay.
  3. Personal information of children under the age of 14 is collected with the consent of their legal representative. The legal representative may request access to, correction of, or deletion of the child's personal information.

Article 8. Procedures and Methods for Destroying Personal Information

  1. Personal information stored in electronic files is permanently deleted using technical methods that prevent its recovery or restoration.
  2. Personal information printed on paper is destroyed by shredding or incineration.

Article 9. Use and Rejection of Cookies

  1. The Company may use cookies to provide users with customized services.
  2. Users may refuse the storage of cookies through their web browser settings. However, doing so may restrict access to certain services.

Article 10. Measures to Ensure the Security of Personal Information

The Company implements the following measures to ensure the secure processing of personal information.

  1. Administrative measures: Establishing and implementing internal management plans, limiting the number of authorized personnel, and providing relevant training
  2. Technical measures: Managing access privileges to personal information processing systems, retaining access records, and operating security programs
  3. Physical measures: Controlling access to locations where personal information is stored

Article 11. Chief Privacy Officer

The Company has appointed the following Chief Privacy Officer to oversee matters relating to personal information processing and to handle users' inquiries, complaints, and requests for relief regarding personal information.

  • Chief Privacy Officer: Kim Jayeon (CEO)
  • Company: DEAR SOOA Co., Ltd. (DDUDDI DDUDDI)
  • Email: dearsooa8@gmail.com
  • Contact number: +82-10-7640-3740
  • Address: 1F, 8-7, Seoulsup 2-gil, Seongdong-gu, Seoul, Republic of Korea

Article 12. Remedies for Infringement of Rights

Users may contact the following organizations for dispute resolution or consultation regarding personal information infringement.

  • Personal Information Dispute Mediation Committee: 1833-6972, without an area code (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118, without an area code (privacy.kisa.or.kr)
  • Cyber Investigation Division of the Supreme Prosecutors' Office: 1301, without an area code (www.spo.go.kr)
  • Cyber Bureau of the Korean National Police Agency: 182, without an area code (ecrm.police.go.kr)

Article 13. Changes to the Privacy Policy

This Privacy Policy will take effect on July 8, 2026. If any provision is added, deleted, or amended due to changes in applicable laws, policies, or services, the Company will provide notice through the Online Store before the changes take effect.