Date of Announcement: 07 27, 2026 / Effective Date: 07 27, 2026

This English translation is provided for convenience only. In the event of any discrepancy between the Korean version and this English translation, the Korean version shall prevail.

Paprika Data Lab Inc. (the “Company”) complies with the Personal Information Protection Act of the Republic of Korea (“PIPA”) and other applicable laws and regulations to protect the freedom and rights of data subjects, and processes personal information lawfully and manages it safely. In accordance with Article 30 of PIPA, the Company hereby establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for processing personal information, and to ensure that related complaints are handled promptly and smoothly.

Article 1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of PIPA.

  1. Membership registration and management : confirming the intent to register, identifying and authenticating members for membership-based services, maintaining and managing membership status, preventing fraudulent use of the Service, sending notices, and handling complaints

  2. Service provision : providing services including creation, distribution, response collection, and analysis of surveys (forms); providing content and personalized services; identity verification (including phone number verification); fee payment and settlement; issuing contracts and invoices; and debt collection

  3. Complaint handling : receiving and processing inquiries and error reports, and notifying the results. In this process, the Company’s staff may access relevant personal information only to the minimum extent necessary.

  4. Marketing and advertising : providing information on new services and events and opportunities to participate (only where the data subject has opted in to receive such communications), compiling statistics on service usage, and verifying the effectiveness of the Service

  5. Promotion of customer cases : where a member has publicly conducted or is conducting surveys using Walla, promoting the fact that the member is a Walla user

  6. Statistical use : statistical use of information processed in a form that does not identify any individual

Article 2. Processing and Retention Periods of Personal Information

The Company processes and retains personal information within the retention and use periods prescribed by law or agreed upon when collecting the personal information from the data subject. The respective processing and retention periods are as follows.

  1. Membership registration and management : until withdrawal of membership; provided, however, that where any of the following applies, until the relevant cause ceases to exist:

    • Where an investigation or inquiry into a violation of applicable laws is in progress: until the conclusion of such investigation or inquiry

    • Where claims or obligations arising from the use of the Service remain: until such claims or obligations are settled

  2. Provision of goods or services : until the supply of goods or services is completed and payment and settlement are completed; provided, however, that records falling under the following are retained for the period specified below:

Purpose of retention

Governing law

Retention period

Records on display and advertising

Act on Consumer Protection in Electronic Commerce

6 months

Records on contracts, withdrawal of offers, payment, and supply of goods

Act on Consumer Protection in Electronic Commerce

5 years

Records on consumer complaints and dispute resolution

Act on Consumer Protection in Electronic Commerce

3 years

Internet log records and access location data

Protection of Communications Secrets Act

3 months

Records on the collection, processing, and use of credit information

Credit Information Use and Protection Act

3 years

  1. Phone number verification : until the verification is completed (verification codes automatically expire and are destroyed shortly after being sent)

Article 3. Categories of Personal Information Processed

The Company processes the following categories of personal information.

Membership registration and management

Sign-up method

Information collected

Google account sign-up

Google account email address, nickname, profile picture

Email sign-up

Email address, password (stored encrypted), nickname

Enterprise SSO sign-up

Email address, name (nickname), and profile information provided by the organization’s SSO provider

Optional

Organization information

  • Collection method: entered by the user on the site, or provided by an authentication provider (Google or the organization’s SSO) with the user’s consent

Information collected automatically during use of the Service

  • IP address, cookies, date and time of visit, service usage records, records of fraudulent use

  • Collection method: automatically generated and collected in the course of using the Service

When paying for paid services

  • Payment history, payment amount, partial payment method information (e.g., approval results)

  • The Company does not store sensitive payment information such as credit card numbers; such information is collected and processed directly by the payment gateway (PG) provider.

Notice regarding survey response data

The party that collects and uses response data gathered through a survey is the user who created and distributed that survey (the “survey creator”). The Company’s role is to provide survey creators with features for creating surveys, collecting, storing, and analyzing responses, and safely collecting and managing respondents’ personal information, such as phone number verification.

The Company does not access or use response data for its own purposes, and accesses it only to the minimum extent necessary for providing and maintaining the Service, handling inquiries and errors at the request of survey creators, preventing fraudulent use, and complying with legal obligations. The categories and purposes of personal information included in response data are governed by the notice provided in each survey.

Notice regarding Google user data

‘Walla’, the service operated by the Company, complies with the Google API Services User Data Policy, including the Limited Use requirements, with respect to the use of information received from Google APIs and its transfer to any other app.

  • Access and use : Information retrieved from your Google account, such as email, nickname, and profile picture, is used only for providing the core functions of the Service, such as membership registration, profile creation, and login, with your explicit consent.

  • Storage : Information received from your Google account is securely stored on Google Cloud Platform (GCP).

  • Sharing : Google user data is not provided to third parties without your consent, except where necessary to provide the Service.

Notice regarding AI features

When you use the ‘Create with AI’ feature, the content you enter into that feature is transmitted to and processed by OpenAI, L.L.C. to generate a survey draft. In all other use of the Service, your personal information is not transmitted to OpenAI. For details, see Article 7 (Cross-Border Transfer of Personal Information).

Article 4. Processing of Personal Information of Children Under 14

The Company does not provide services intended to collect personal information from children under the age of 14, and does not collect personal information from children under 14 as a matter of principle. If the Company becomes aware that personal information of a child under 14 has been collected, it will take necessary measures, including destroying such information without delay.

Article 5. Provision of Personal Information to Third Parties

  1. The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only where it falls under Articles 17 and 18 of PIPA, such as with the data subject’s consent or under special provisions of law. Otherwise, the Company does not provide personal information to third parties.

  2. In the event of an emergency such as a disaster, infectious disease, an incident posing imminent danger to life or body, or imminent property loss, the Company may provide personal information to the competent authorities without the data subject’s consent, in accordance with applicable laws.

  3. Any person who handles or has handled personal information for the provision of the Company’s services shall not engage in any of the following acts, in accordance with Article 59 (Prohibited Acts) of PIPA:

    • Acquiring personal information or obtaining consent to its processing by deceit or other unlawful means or methods

    • Divulging personal information obtained in the course of business, or providing it for use by others without authority

    • Damaging, destroying, altering, forging, or leaking another person’s personal information without lawful authority or beyond the authorized scope

Article 6. Entrustment of Personal Information Processing

  1. For the smooth handling of personal information processing, the Company entrusts personal information processing as follows.

Entrusted task

Retention and use period

Operation of cloud servers and data storage for the provision of the Service

Until membership withdrawal, termination of the Service, or termination of the entrustment agreement



  1. Entrustment to overseas service providers is governed by Article 7 (Cross-Border Transfer of Personal Information).

  2. When entering into an entrustment agreement, the Company specifies in the agreement or other documents, in accordance with Article 26 of PIPA, matters such as the prohibition of processing personal information for purposes other than the entrusted task, technical and managerial safeguards, restrictions on sub-entrustment, supervision of the processor, and liability for damages, and supervises whether the processor processes personal information safely.

  3. If the content of the entrusted task or the processor changes, the Company will disclose such changes through this Privacy Policy without delay.

Article 7. Cross-Border Transfer of Personal Information

In accordance with Article 28-8(1)(iii) of PIPA (entrustment or storage of personal information necessary for the conclusion and performance of a contract with the data subject), the Company transfers personal information processing tasks to overseas service providers as follows, to the extent necessary to provide the Service. Each item of personal information is transferred only in the specific circumstances described in the table below, and is not transferred if you do not use the relevant feature.

Recipient (contact)

Country

When and how the transfer occurs

Personal information transferred

Purpose of use

Retention and use period

Stripe, Inc. ([email protected])

United States

Only when you pay subscription fees for paid plans — transmitted over encrypted networks at the time of payment or subscription renewal

Email address, payment history and amount (card information is collected directly by Stripe)

Processing of subscription fee payments (PG)

Until membership withdrawal, termination of the Service, or termination of the entrustment agreement (statutory retention periods apply separately)

Cloudflare, Inc. ([email protected])

United States

Transmitted over encrypted networks whenever you access the Service

IP address, access records

Operation of content delivery and security (CDN / edge proxy)

Until termination of the entrustment agreement

OpenAI, L.L.C. ([email protected])

United States

Only when you use the ‘Create with AI’ feature — transmitted over encrypted networks at the time of the request

Content you enter when using the feature

Generating AI-based survey drafts (transferred data is not used to train AI models)

Processed and then destroyed in accordance with OpenAI’s API data retention policy

Data subjects may refuse the cross-border transfer of their personal information by contacting the Chief Privacy Officer ([email protected]). However, if you refuse the cross-border transfer, your use of the relevant features (such as payment, phone number verification, and AI survey generation) or all or part of the Service may be restricted.

Article 8. Destruction of Personal Information

  1. The Company destroys personal information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose.

  2. Where personal information must continue to be retained under other laws despite the expiration of the agreed retention period or the achievement of the processing purpose, the Company moves such personal information to a separate database (DB) or stores it in a different location.

  3. The procedures and methods for destroying personal information are as follows:

    • Destruction procedure : The Company selects the personal information for which grounds for destruction have arisen, and destroys it with the approval of the Company’s Chief Privacy Officer.

    • Destruction method : Personal information recorded and stored in electronic files is destroyed so that the records cannot be reproduced, and personal information recorded and stored in paper documents is shredded or incinerated.

Article 9. Rights of Data Subjects and Legal Representatives, and How to Exercise Them

  1. Data subjects may exercise the following rights against the Company at any time:

    • Request to access their personal information

    • Request correction of errors

    • Request deletion

    • Request suspension of processing

  2. These rights may be exercised against the Company in writing, by email, or by facsimile (FAX) in accordance with Article 41(1) of the Enforcement Decree of PIPA, and the Company will take action without delay.

  3. These rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney in the form prescribed in Annex Form No. 11 of the Notification on Personal Information Processing Methods must be submitted.

  4. Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA.

  5. A request for correction or deletion cannot be made where the personal information is expressly required to be collected under other laws.

  6. When a data subject exercises the right to access, correct, delete, or suspend processing, the Company verifies that the person making the request is the data subject or a lawful representative.

  7. Rights regarding survey response data may be exercised against the survey creator, who is the party that collects and uses such data. If such a request is received by the Company, the Company will cooperate as necessary, including by forwarding the request to the survey creator.

Article 10. Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of personal information:

  1. Managerial measures : establishing and implementing an internal management plan, minimizing and designating staff handling personal information, conducting regular employee training, and conducting regular self-audits (once per quarter)

  2. Technical measures : managing access rights to personal information processing systems (granting, changing, revoking), installing access control systems, encrypting personal information (important data such as passwords is encrypted in storage and transmission), and installing and regularly updating security programs

  3. Retention and integrity of access records : Access records to personal information processing systems are retained and managed for at least one (1) year, and security functions are used to prevent forgery, alteration, theft, or loss of access records.

  4. Physical measures : installing systems in areas with controlled access and monitoring and blocking access technically and physically

Article 11. Automatic Collection Devices (Cookies) and How to Refuse Them

  1. The Company may use ‘cookies’, which store and retrieve usage information, to provide individualized services to users.

  2. Cookies are small pieces of information sent by the server (http) operating the website to the user’s browser, and may be stored on the user’s device.

    • Purpose of use : maintaining login status and identifying usage patterns and secure access status for each service visited, in order to provide optimized information to users

    • Installation, operation, and refusal : You may refuse the storage of cookies through your web browser settings.

      • Chrome : Settings → Privacy and security → Cookies and other site data

      • Edge : Settings → Cookies and site permissions → Manage and delete cookies and site data

      • Safari : Preferences → Privacy → Cookies and website data

  3. If you refuse the storage of cookies, you may experience difficulties in using some services, such as services requiring login.

Article 12. Collection, Use, and Refusal of Behavioral Information

  1. The Company collects and uses behavioral information as follows for the purpose of analyzing service usage statistics and improving the Service.

Category

Details

Behavioral information collected

Website visit history, service usage records (page navigation, clicks, etc.)

Collection method

Collected automatically via Google Analytics (GA4) and Google Tag Manager when you visit and use the website

Purpose of collection

Analyzing service usage statistics and improving the Service

Retention and use period

Retained and then destroyed in accordance with Google Analytics data retention settings

How to refuse

Block cookies in your web browser settings, or install the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout)

  1. Survey creators may connect their own Meta Pixel or Google Analytics (GA4) to surveys they create. In such cases, behavioral information such as visits to the survey page and response submissions is transmitted to Meta Platforms, Inc. and Google as designated by the survey creator, and the party collecting such behavioral information is the survey creator. Details are governed by each survey creator’s notices and privacy policy, and data subjects may block such tracking through their web browser’s cookie settings and tracking prevention features.

  2. The Company does not collect sensitive behavioral information that may clearly infringe on individuals’ rights, interests, or privacy, such as thoughts, beliefs, family and kinship relations, education, medical history, or other social activity history.

Article 13. Criteria for Additional Use or Provision of Personal Information

In accordance with Articles 15(3) and 17(4) of PIPA and Article 14-2 of its Enforcement Decree, the Company may additionally use or provide personal information without the data subject’s consent. In such cases, the Company comprehensively considers the following:

  • Whether the additional use or provision is related to the original purpose of collection

  • Whether the additional use or provision is foreseeable in light of the circumstances of collection or processing practices

  • Whether the additional use or provision unfairly infringes on the interests of the data subject

  • Whether measures necessary to ensure security, such as pseudonymization or encryption, have been taken

Article 14. Processing of Sensitive Information and Pseudonymized Information

  1. The Company does not collect sensitive information of data subjects (information concerning thoughts or beliefs, health, sexual life, etc.) for the operation of the Service. Information included in survey response data is governed by the ‘Notice regarding survey response data’ in Article 3.

  2. The Company does not process pseudonymized information. If the Company processes pseudonymized information in the future, it will disclose the purposes, categories, retention periods, and security measures through this Privacy Policy.

Article 15. Chief Privacy Officer

  1. The Company designates a Chief Privacy Officer as follows, who is responsible for overseeing personal information processing and for handling data subjects’ complaints and remedying damages related to personal information processing.

    Chief Privacy Officer

  2. Data subjects may direct all inquiries, complaints, requests for remedies, and access requests related to personal information protection arising from the use of the Service to the Chief Privacy Officer. The Company will respond to and process such inquiries without delay.

Article 16. Remedies for Infringement of Data Subjects’ Rights

  1. Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Privacy Infringement Report Center, and other organizations to obtain relief from personal information infringement:

  2. A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information) of PIPA may file an administrative appeal in accordance with the Administrative Appeals Act:

Article 17. Changes to This Privacy Policy

  1. This Privacy Policy applies from 07 27, 2026.

  2. The Company may amend this Privacy Policy to the extent that it does not violate applicable laws.

  3. When the Company amends this Privacy Policy, it will specify the reasons for the amendment, make both the current and amended versions available, announce the amendment through the Service’s notice board from seven (7) days before the effective date until the day before the effective date, and send the amended contents to each member’s email address seven (7) days before the effective date.

  4. If a data subject does not express an objection to the Company from seven (7) days before the effective date until the day before the effective date, the data subject is deemed to have consented to the amended Privacy Policy.

  5. Previous versions of this Privacy Policy are available below:

Paprika Data Lab Inc.

  • Business Registration Number : 660-88-02002

  • E-Commerce Registration Number : 2022-Seoul-Gwanak-0879

  • Address : 3F, 557 Yeoksam-ro, Gangnam-gu, Seoul, Republic of Korea