Privacy Policy
GOLFZON Holdings Co., Ltd. hereinafter referred to as the “Company” values users’ personal information and makes every effort to comply with applicable laws and regulations, including the Personal Information Protection Act.
Through this Privacy Policy, the Company informs users of how the personal information they provide is used, for what purposes it is used, and what measures are taken to protect personal information.
The Company makes this Privacy Policy available on the main page of its website so that users can easily access it at any time. The Company has established procedures necessary for revising this Privacy Policy in order to continuously improve it. In the event of any revision, the Company will ensure that users can easily identify the revised matters.
1. Personal Information Collected, Purpose of Collection and Use, and Retention and Use Period
The Company collects the minimum amount of personal information necessary to provide smooth services. The items of personal information collected are as follows.
(1) Personal information processed without the user’s consent
- Legal basis: Article 15, Paragraph 1, Item 4 of the Personal Information Protection Act: conclusion and performance of a contract
- Purpose of collection and use: Sending Newsroom newsletters
- Items collected: Email address
- Retention and use period: Until withdrawal from the service
(2) Personal information processed with the user’s consent
There are no items of personal information processed with the user’s consent.
(3) Personal information collected during service use
During the use of the PC website, information such as device information, IP address, cookies, and service usage records may be automatically generated and collected.
2. Provision of Personal Information to Third Parties
In principle, the Company does not provide users’ personal information to external parties. However, exceptions may apply in the following cases:
- When separate consent has been obtained from the user
- When there are special provisions under other laws
- When it is deemed clearly necessary for the urgent interests of the life, body, or property of the data subject or a third party
- When it is necessary to achieve the clearly legitimate interests of the personal information controller
- When it is urgently necessary for public safety and well-being, including public health
3. Entrustment of Personal Information Processing
The Company entrusts the processing of personal information to external professional service providers only when necessary for service provision, as described below.
When entrusting the processing of personal information, the Company clearly stipulates obligations to comply with instructions related to personal information protection, confidentiality obligations regarding personal information, prohibition of provision to third parties, responsibility in the event of an incident, and obligations to return or destroy personal information after the entrustment period or upon completion of processing. The Company also supervises the entrusted service providers to ensure that personal information is processed securely.
If there is any change to the entrusted service provider or the details of the entrusted work, the Company will disclose such changes through this Privacy Policy.
- Entrusted and re-entrusted service provider: Stibee; re-entrusted service provider: AWS
- Details of entrusted work: Sending and managing Newsroom newsletters
4. Overseas Transfer of Personal Information
The Company transfers personal information collected from service users overseas as described below. In accordance with Article 28-8, Paragraph 2 of the Personal Information Protection Act, the Company provides the following information regarding overseas transfer.
If users refuse the overseas transfer of personal information, they may be unable to use the service. Users who do not wish to have their personal information transferred overseas may contact the department responsible for personal information matters listed in Section 10, “Department Responsible for Personal Information Protection.”
- Legal basis: Article 28-8, Paragraph 1, Item 3 of the Personal Information Protection Act: entrustment and storage of processing
- Items of personal information transferred: Email address
- Country of transfer: United States of America
- Timing and method of transfer: Transmitted through the information and communications network at the time of service use
- Recipient of transfer: AWS, Amazon Web Services, Inc.
- Purpose of use: Operation and management of cloud servers for service provision
- Retention and use period: Until withdrawal from the service or termination of the contract
5. Procedures and Methods for Destruction of Personal Information
The Company destroys personal information without delay when the personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose. The procedures and methods for destroying personal information are as follows.
(1) Destruction procedures
Users’ personal information is destroyed without delay once the purpose has been achieved.
However, if separate consent has been obtained from the user regarding the retention period of personal information, or if the Company is required by law to retain certain information for a specified period, the personal information will be securely retained for that period.
(2) Destruction methods
The Company deletes personal information stored in electronic file format using technical methods that prevent the records from being restored. Personal information printed on paper is destroyed by shredding or incineration.
6. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
The Company uses cookies, which store and retrieve usage information from time to time, in order to provide individualized customized services to users. Cookies are small pieces of information sent by the server used to operate a website to the user’s browser and are stored in the storage space of the user’s device.
The Company may use cookies to provide more convenient services suited to users and to provide optimized information to users.
Users may configure their browser options to allow all cookies, confirm each time a cookie is stored, or refuse the storage of all cookies. However, if users refuse the storage of cookies, they may be unable to use certain Company services that require cookie settings.
Allowing or Blocking Cookies in Web Browsers
- Chrome: Select the “⁝” icon at the top right of the browser > New Incognito Window shortcut: Ctrl+Shift+N
- Edge: Select the “…” icon at the top right of the browser > New InPrivate Window shortcut: Ctrl+Shift+N
Allowing or Blocking Cookies in Mobile Browsers
- Chrome: Select the “⁝” icon at the top right of the mobile browser > New Incognito Tab
- Safari: Mobile device settings > Safari > Advanced > Block All Cookies
- Samsung Internet: Select the “Tabs” icon at the bottom of the mobile browser > Turn on Secret Mode > Start
7. Rights of Users and Legal Representatives and How to Exercise Them
(1)
Users or their legal representatives, in the case of users under the age of 14, may at any time request the Company to allow access to, correct, delete, or suspend the processing of personal information by contacting the department responsible for personal information protection in writing, by telephone, or by email. Users may also directly view and modify their personal information through the website, and may request withdrawal of consent to modification, use, or provision, or request termination of membership.
However, the exercise of user rights may be restricted in accordance with applicable laws and regulations, including the Personal Information Protection Act.
(2)
If a user requests correction of an error in personal information, the Company will not use or provide the relevant personal information until the correction has been completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction result without delay so that the correction can be made.
The department that receives and handles requests for access to personal information and related matters is provided in Section 10, “Department Responsible for Personal Information Protection,” of this Privacy Policy.
8. Processing of Personal Information of Children Under the Age of 14
If the Company is required to obtain consent for the processing of personal information of children under the age of 14, it obtains consent from the legal representative of the relevant child.
When obtaining consent from the legal representative regarding the processing of personal information of children under the age of 14, the Company may request the child to provide the minimum necessary information, such as the name and contact information of the legal representative.
The Company verifies such consent by allowing the legal representative to indicate consent on the website where the consent details are posted, and by notifying the legal representative via mobile text message that the indication of consent has been confirmed.
9. Measures to Ensure the Security of Personal Information
The Company takes the following technical and administrative measures to securely manage users’ personal information.
(1) Establishment and operation of an internal management plan for personal information
The Company establishes and operates an internal management plan for personal information, including matters related to the organization and operation of the personal information protection structure, to ensure that users’ personal information is securely processed within the service.
(2) Encryption of important information
In accordance with applicable laws and regulations, the Company encrypts passwords, unique identification information, account numbers, and card numbers. Among these, member passwords are stored and managed through one-way encryption so that they cannot be decrypted.
(3) Measures against hacking and other threats
The Company makes every effort to prevent users’ personal information from being leaked or damaged due to hacking, computer viruses, or other threats. The Company regularly backs up data to prevent damage to personal information, uses the latest antivirus programs to prevent users’ personal information or data from being leaked or damaged, and ensures that personal information can be securely transmitted over networks through encrypted communications.
The Company also controls unauthorized external access by using intrusion prevention systems and strives to implement all technically feasible measures to secure its systems.
(4) Minimization and training of personnel handling personal information
Employees who handle personal information are limited to designated personnel. Separate passwords are assigned for this purpose and are regularly renewed. The Company also provides regular training on personal information protection obligations and security to all employees who process personal information.
10. Department Responsible for Personal Information Protection
The Company has designated the following department responsible for personal information protection in order to handle users’ complaints and provide remedies related to the processing of personal information.
Users may contact the responsible department for all inquiries, complaints, and requests for remedies related to personal information protection that may arise while using the Company’s services. The Company will respond to and process such matters without delay.
Department Responsible for Personal Information Protection
- Department: Brand Team, GOLFZON Holdings
- Telephone: 1577-4333
- Email: newsroom@golfzon.com
Users may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency, and other relevant institutions in order to seek remedies for personal information infringement. For other reports or consultations regarding personal information infringement, please contact the following institutions.
- Personal Information Dispute Mediation Committee: 1833-6972 without area code, https://www.kopico.go.kr
- Personal Information Infringement Report Center: 118 without area code, https://privacy.kisa.or.kr
- Korean National Police Agency: 182 without area code, https://ecrm.cyber.go.kr
11. Changes to This Privacy Policy
(1)
This Privacy Policy is effective as of July 6, 2026.
(2)
This Privacy Policy is version 1.0.