Date of Announcement: 07 27, 2026 / Effective Date: 07 27, 2026
This English translation is provided for convenience only. In the event of any discrepancy between the Korean version and this English translation, the Korean version shall prevail.
Paprika Data Lab Inc. (the “Company”) complies with the Personal Information Protection Act of the Republic of Korea (“PIPA”) and other applicable laws and regulations to protect the freedom and rights of data subjects, and processes personal information lawfully and manages it safely. In accordance with Article 30 of PIPA, the Company hereby establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for processing personal information, and to ensure that related complaints are handled promptly and smoothly.
Article 1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of PIPA.
Membership registration and management : confirming the intent to register, identifying and authenticating members for membership-based services, maintaining and managing membership status, preventing fraudulent use of the Service, sending notices, and handling complaints
Service provision : providing services including creation, distribution, response collection, and analysis of surveys (forms); providing content and personalized services; identity verification (including phone number verification); fee payment and settlement; issuing contracts and invoices; and debt collection
Complaint handling : receiving and processing inquiries and error reports, and notifying the results. In this process, the Company’s staff may access relevant personal information only to the minimum extent necessary.
Marketing and advertising : providing information on new services and events and opportunities to participate (only where the data subject has opted in to receive such communications), compiling statistics on service usage, and verifying the effectiveness of the Service
Promotion of customer cases : where a member has publicly conducted or is conducting surveys using Walla, promoting the fact that the member is a Walla user
Statistical use : statistical use of information processed in a form that does not identify any individual
Article 2. Processing and Retention Periods of Personal Information
The Company processes and retains personal information within the retention and use periods prescribed by law or agreed upon when collecting the personal information from the data subject. The respective processing and retention periods are as follows.
Membership registration and management : until withdrawal of membership; provided, however, that where any of the following applies, until the relevant cause ceases to exist:
Where an investigation or inquiry into a violation of applicable laws is in progress: until the conclusion of such investigation or inquiry
Where claims or obligations arising from the use of the Service remain: until such claims or obligations are settled
Provision of goods or services : until the supply of goods or services is completed and payment and settlement are completed; provided, however, that records falling under the following are retained for the period specified below:
Purpose of retention | Governing law | Retention period |
|---|---|---|
Records on display and advertising | Act on Consumer Protection in Electronic Commerce | 6 months |
Records on contracts, withdrawal of offers, payment, and supply of goods | Act on Consumer Protection in Electronic Commerce | 5 years |
Records on consumer complaints and dispute resolution | Act on Consumer Protection in Electronic Commerce | 3 years |
Internet log records and access location data | Protection of Communications Secrets Act | 3 months |
Records on the collection, processing, and use of credit information | Credit Information Use and Protection Act | 3 years |
Phone number verification : until the verification is completed (verification codes automatically expire and are destroyed shortly after being sent)
Article 3. Categories of Personal Information Processed
The Company processes the following categories of personal information.
Membership registration and management
Sign-up method | Information collected |
|---|---|
Google account sign-up | Google account email address, nickname, profile picture |
Email sign-up | Email address, password (stored encrypted), nickname |
Enterprise SSO sign-up | Email address, name (nickname), and profile information provided by the organization’s SSO provider |
Optional | Organization information |
Collection method: entered by the user on the site, or provided by an authentication provider (Google or the organization’s SSO) with the user’s consent
Information collected automatically during use of the Service
IP address, cookies, date and time of visit, service usage records, records of fraudulent use
Collection method: automatically generated and collected in the course of using the Service
When paying for paid services
Payment history, payment amount, partial payment method information (e.g., approval results)
The Company does not store sensitive payment information such as credit card numbers; such information is collected and processed directly by the payment gateway (PG) provider.
Notice regarding survey response data
The party that collects and uses response data gathered through a survey is the user who created and distributed that survey (the “survey creator”). The Company’s role is to provide survey creators with features for creating surveys, collecting, storing, and analyzing responses, and safely collecting and managing respondents’ personal information, such as phone number verification.
The Company does not access or use response data for its own purposes, and accesses it only to the minimum extent necessary for providing and maintaining the Service, handling inquiries and errors at the request of survey creators, preventing fraudulent use, and complying with legal obligations. The categories and purposes of personal information included in response data are governed by the notice provided in each survey.
Notice regarding Google user data
‘Walla’, the service operated by the Company, complies with the Google API Services User Data Policy, including the Limited Use requirements, with respect to the use of information received from Google APIs and its transfer to any other app.
Access and use : Information retrieved from your Google account, such as email, nickname, and profile picture, is used only for providing the core functions of the Service, such as membership registration, profile creation, and login, with your explicit consent.
Storage : Information received from your Google account is securely stored on Google Cloud Platform (GCP).
Sharing : Google user data is not provided to third parties without your consent, except where necessary to provide the Service.
Notice regarding AI features
When you use the ‘Create with AI’ feature, the content you enter into that feature is transmitted to and processed by OpenAI, L.L.C. to generate a survey draft. In all other use of the Service, your personal information is not transmitted to OpenAI. For details, see Article 7 (Cross-Border Transfer of Personal Information).
Article 4. Processing of Personal Information of Children Under 14
The Company does not provide services intended to collect personal information from children under the age of 14, and does not collect personal information from children under 14 as a matter of principle. If the Company becomes aware that personal information of a child under 14 has been collected, it will take necessary measures, including destroying such information without delay.
Article 5. Provision of Personal Information to Third Parties
The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only where it falls under Articles 17 and 18 of PIPA, such as with the data subject’s consent or under special provisions of law. Otherwise, the Company does not provide personal information to third parties.
In the event of an emergency such as a disaster, infectious disease, an incident posing imminent danger to life or body, or imminent property loss, the Company may provide personal information to the competent authorities without the data subject’s consent, in accordance with applicable laws.
Any person who handles or has handled personal information for the provision of the Company’s services shall not engage in any of the following acts, in accordance with Article 59 (Prohibited Acts) of PIPA:
Acquiring personal information or obtaining consent to its processing by deceit or other unlawful means or methods
Divulging personal information obtained in the course of business, or providing it for use by others without authority
Damaging, destroying, altering, forging, or leaking another person’s personal information without lawful authority or beyond the authorized scope
Article 6. Entrustment of Personal Information Processing
For the smooth handling of personal information processing, the Company entrusts personal information processing as follows.
Entrusted task | Retention and use period |
|---|---|
Operation of cloud servers and data storage for the provision of the Service | Until membership withdrawal, termination of the Service, or termination of the entrustment agreement |
Entrustment to overseas service providers is governed by Article 7 (Cross-Border Transfer of Personal Information).
When entering into an entrustment agreement, the Company specifies in the agreement or other documents, in accordance with Article 26 of PIPA, matters such as the prohibition of processing personal information for purposes other than the entrusted task, technical and managerial safeguards, restrictions on sub-entrustment, supervision of the processor, and liability for damages, and supervises whether the processor processes personal information safely.
If the content of the entrusted task or the processor changes, the Company will disclose such changes through this Privacy Policy without delay.
Article 7. Cross-Border Transfer of Personal Information
In accordance with Article 28-8(1)(iii) of PIPA (entrustment or storage of personal information necessary for the conclusion and performance of a contract with the data subject), the Company transfers personal information processing tasks to overseas service providers as follows, to the extent necessary to provide the Service. Each item of personal information is transferred only in the specific circumstances described in the table below, and is not transferred if you do not use the relevant feature.
Recipient (contact) | Country | When and how the transfer occurs | Personal information transferred | Purpose of use | Retention and use period |
|---|---|---|---|---|---|
Stripe, Inc. ([email protected]) | United States | Only when you pay subscription fees for paid plans — transmitted over encrypted networks at the time of payment or subscription renewal | Email address, payment history and amount (card information is collected directly by Stripe) | Processing of subscription fee payments (PG) | Until membership withdrawal, termination of the Service, or termination of the entrustment agreement (statutory retention periods apply separately) |
Cloudflare, Inc. ([email protected]) | United States | Transmitted over encrypted networks whenever you access the Service | IP address, access records | Operation of content delivery and security (CDN / edge proxy) | Until termination of the entrustment agreement |
OpenAI, L.L.C. ([email protected]) | United States | Only when you use the ‘Create with AI’ feature — transmitted over encrypted networks at the time of the request | Content you enter when using the feature | Generating AI-based survey drafts (transferred data is not used to train AI models) | Processed and then destroyed in accordance with OpenAI’s API data retention policy |
Data subjects may refuse the cross-border transfer of their personal information by contacting the Chief Privacy Officer ([email protected]). However, if you refuse the cross-border transfer, your use of the relevant features (such as payment, phone number verification, and AI survey generation) or all or part of the Service may be restricted.
Article 8. Destruction of Personal Information
The Company destroys personal information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose.
Where personal information must continue to be retained under other laws despite the expiration of the agreed retention period or the achievement of the processing purpose, the Company moves such personal information to a separate database (DB) or stores it in a different location.
The procedures and methods for destroying personal information are as follows:
Destruction procedure : The Company selects the personal information for which grounds for destruction have arisen, and destroys it with the approval of the Company’s Chief Privacy Officer.
Destruction method : Personal information recorded and stored in electronic files is destroyed so that the records cannot be reproduced, and personal information recorded and stored in paper documents is shredded or incinerated.
Article 9. Rights of Data Subjects and Legal Representatives, and How to Exercise Them
Data subjects may exercise the following rights against the Company at any time:
Request to access their personal information
Request correction of errors
Request deletion
Request suspension of processing
These rights may be exercised against the Company in writing, by email, or by facsimile (FAX) in accordance with Article 41(1) of the Enforcement Decree of PIPA, and the Company will take action without delay.
These rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney in the form prescribed in Annex Form No. 11 of the Notification on Personal Information Processing Methods must be submitted.
Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA.
A request for correction or deletion cannot be made where the personal information is expressly required to be collected under other laws.
When a data subject exercises the right to access, correct, delete, or suspend processing, the Company verifies that the person making the request is the data subject or a lawful representative.
Rights regarding survey response data may be exercised against the survey creator, who is the party that collects and uses such data. If such a request is received by the Company, the Company will cooperate as necessary, including by forwarding the request to the survey creator.
Article 10. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information:
Managerial measures : establishing and implementing an internal management plan, minimizing and designating staff handling personal information, conducting regular employee training, and conducting regular self-audits (once per quarter)
Technical measures : managing access rights to personal information processing systems (granting, changing, revoking), installing access control systems, encrypting personal information (important data such as passwords is encrypted in storage and transmission), and installing and regularly updating security programs
Retention and integrity of access records : Access records to personal information processing systems are retained and managed for at least one (1) year, and security functions are used to prevent forgery, alteration, theft, or loss of access records.
Physical measures : installing systems in areas with controlled access and monitoring and blocking access technically and physically
Article 11. Automatic Collection Devices (Cookies) and How to Refuse Them
The Company may use ‘cookies’, which store and retrieve usage information, to provide individualized services to users.
Cookies are small pieces of information sent by the server (http) operating the website to the user’s browser, and may be stored on the user’s device.
Purpose of use : maintaining login status and identifying usage patterns and secure access status for each service visited, in order to provide optimized information to users
Installation, operation, and refusal : You may refuse the storage of cookies through your web browser settings.
Chrome : Settings → Privacy and security → Cookies and other site data
Edge : Settings → Cookies and site permissions → Manage and delete cookies and site data
Safari : Preferences → Privacy → Cookies and website data
If you refuse the storage of cookies, you may experience difficulties in using some services, such as services requiring login.
Article 12. Collection, Use, and Refusal of Behavioral Information
The Company collects and uses behavioral information as follows for the purpose of analyzing service usage statistics and improving the Service.
Category | Details |
|---|---|
Behavioral information collected | Website visit history, service usage records (page navigation, clicks, etc.) |
Collection method | Collected automatically via Google Analytics (GA4) and Google Tag Manager when you visit and use the website |
Purpose of collection | Analyzing service usage statistics and improving the Service |
Retention and use period | Retained and then destroyed in accordance with Google Analytics data retention settings |
How to refuse | Block cookies in your web browser settings, or install the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout) |
Survey creators may connect their own Meta Pixel or Google Analytics (GA4) to surveys they create. In such cases, behavioral information such as visits to the survey page and response submissions is transmitted to Meta Platforms, Inc. and Google as designated by the survey creator, and the party collecting such behavioral information is the survey creator. Details are governed by each survey creator’s notices and privacy policy, and data subjects may block such tracking through their web browser’s cookie settings and tracking prevention features.
The Company does not collect sensitive behavioral information that may clearly infringe on individuals’ rights, interests, or privacy, such as thoughts, beliefs, family and kinship relations, education, medical history, or other social activity history.
Article 13. Criteria for Additional Use or Provision of Personal Information
In accordance with Articles 15(3) and 17(4) of PIPA and Article 14-2 of its Enforcement Decree, the Company may additionally use or provide personal information without the data subject’s consent. In such cases, the Company comprehensively considers the following:
Whether the additional use or provision is related to the original purpose of collection
Whether the additional use or provision is foreseeable in light of the circumstances of collection or processing practices
Whether the additional use or provision unfairly infringes on the interests of the data subject
Whether measures necessary to ensure security, such as pseudonymization or encryption, have been taken
Article 14. Processing of Sensitive Information and Pseudonymized Information
The Company does not collect sensitive information of data subjects (information concerning thoughts or beliefs, health, sexual life, etc.) for the operation of the Service. Information included in survey response data is governed by the ‘Notice regarding survey response data’ in Article 3.
The Company does not process pseudonymized information. If the Company processes pseudonymized information in the future, it will disclose the purposes, categories, retention periods, and security measures through this Privacy Policy.
Article 15. Chief Privacy Officer
The Company designates a Chief Privacy Officer as follows, who is responsible for overseeing personal information processing and for handling data subjects’ complaints and remedying damages related to personal information processing.
Chief Privacy Officer
Name : Youngbum Kim
Title : CTO
Contact : [email protected]
Data subjects may direct all inquiries, complaints, requests for remedies, and access requests related to personal information protection arising from the use of the Service to the Chief Privacy Officer. The Company will respond to and process such inquiries without delay.
Article 16. Remedies for Infringement of Data Subjects’ Rights
Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Privacy Infringement Report Center, and other organizations to obtain relief from personal information infringement:
Personal Information Dispute Mediation Committee : 1833-6972 (www.kopico.go.kr)
KISA Privacy Infringement Report Center : 118 (privacy.kisa.or.kr)
Supreme Prosecutors’ Office : 1301 (www.spo.go.kr)
National Police Agency : 182 (ecrm.cyber.go.kr)
A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information) of PIPA may file an administrative appeal in accordance with the Administrative Appeals Act:
Central Administrative Appeals Commission : 110 (www.simpan.go.kr)
Article 17. Changes to This Privacy Policy
This Privacy Policy applies from 07 27, 2026.
The Company may amend this Privacy Policy to the extent that it does not violate applicable laws.
When the Company amends this Privacy Policy, it will specify the reasons for the amendment, make both the current and amended versions available, announce the amendment through the Service’s notice board from seven (7) days before the effective date until the day before the effective date, and send the amended contents to each member’s email address seven (7) days before the effective date.
If a data subject does not express an objection to the Company from seven (7) days before the effective date until the day before the effective date, the data subject is deemed to have consented to the amended Privacy Policy.
Previous versions of this Privacy Policy are available below:
Paprika Data Lab Inc.
Business Registration Number : 660-88-02002
E-Commerce Registration Number : 2022-Seoul-Gwanak-0879
Address : 3F, 557 Yeoksam-ro, Gangnam-gu, Seoul, Republic of Korea
