Privacy Policy

Chips&Media, Inc. (the "Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

The Company does not operate a membership service or e-commerce. Personal information is collected and used only for inquiries submitted through this website and for job applications.

This Policy takes effect on August 28, 2026.

1. Personal Information Collected

The Company collects the following personal information.

A. Online inquiries (General / Product / IR)
- Items collected : Name, e-mail address, phone number, company name, inquiry title and content

B. Job applications
- Items collected : Name, e-mail address, phone number, information contained in the application documents you submit (resume, career description, etc.), and the external resume link

C. Information generated and collected automatically while using the service
- Items collected : IP address, date and time of access, service usage records, browser and OS information, cookies

The Company does not collect sensitive information such as ideology, beliefs, health or trade union membership, nor unique identifiers including resident registration numbers. The Company does not collect personal information from children under the age of 14.

2. Purpose of Processing Personal Information

The Company uses the collected personal information only for the purposes below. If the purpose changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

  • - Online inquiries : Receiving and responding to inquiries, and managing consultation records
  • - Job applications : Conducting the recruitment process and notifying applicants of the result
  • - Automatically collected information : Ensuring service stability and preventing misuse or intrusion attempts

3. Retention and Use Period

The Company retains and uses personal information within the periods below, and destroys it without delay once the period expires or the purpose of processing is achieved.

  • - Online inquiries : 6 months from the date of inquiry
  • - Job applications : 6 months after the recruitment process ends
  • - Automatically collected information : 1 year from the date of collection

Even within the above periods, the Company destroys personal information without delay once the purpose of processing is achieved. In particular, the original content of inquiries and applications submitted through the website is automatically destroyed from the web server within 30 days of receipt, and thereafter is retained only in the e-mail delivered to the person in charge, for the retention period stated above.

If a data subject requests deletion of their personal information, it will be destroyed without delay regardless of the above periods.

The Company does not sell goods or services to consumers, and therefore the transaction record retention obligations under the Act on the Consumer Protection in Electronic Commerce do not apply. Where other statutes require retention, the Company retains the information for the period prescribed by that statute.

4. Procedure and Method of Destruction

Procedure
The Company selects the personal information for which grounds for destruction have arisen, and destroys it with the approval of the Privacy Officer.

Method
Personal information stored in electronic file form is deleted using a technical method that renders the records irrecoverable. Personal information recorded on paper is shredded or incinerated.

The content of inquiries and applications received through the website is not stored in a database in its original form. It is retained in encrypted form for 30 days only, for delivery confirmation and re-sending purposes, and is then deleted automatically.

5. Provision of Personal Information to Third Parties

The Company processes personal information only within the scope of the purposes specified in Article 2, and provides it to third parties only where Articles 17 and 18 of the Personal Information Protection Act apply, such as with the consent of the data subject or under special provisions of law.

The Company does not currently provide personal information to any third party on a regular basis.

6. Outsourcing of Personal Information Processing

The Company outsources personal information processing tasks as follows.

  • - Trustee : Microsoft
  • - Scope of work : Operation of the e-mail service (Microsoft 365), including transmission, receipt and storage of inquiry and application e-mails

When entering into an outsourcing agreement, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act, the prohibition of processing personal information for purposes other than performing the outsourced work, technical and administrative safeguards, restrictions on re-outsourcing, and supervision of the trustee. Any change to the outsourced work or the trustee will be disclosed through this Policy.

Website hosting and system operation are performed directly by the Company on its own servers and are not outsourced.

7. Transfer of Personal Information Overseas

In connection with its use of an e-mail service, the Company transfers personal information overseas as set out below. By disclosing the following matters through this Policy pursuant to Article 28-8(1)3 of the Personal Information Protection Act, the Company carries out the overseas outsourcing and storage of personal information without separate consent from the data subject.

  • - Recipient : Microsoft (Microsoft Corporation and its affiliates)
  • - Contact of the recipient : https://www.microsoft.com/en-us/concern/privacy
  • - Items transferred : Name, e-mail address, phone number, company name, inquiry title and content, and information contained in application documents submitted for job applications
  • - Countries of transfer : Republic of Korea (mailbox storage), Asia Pacific region (spam and malware filtering)
  • - Time and method of transfer : Transmitted over the information and communications network at the time an inquiry or application is submitted
  • - Purpose of use by the recipient : Transmission, receipt and storage of e-mail, and security filtering
  • - Retention and use period of the recipient : Same as the retention period stated in Article 3

How to refuse the overseas transfer, and its effect
Data subjects may refuse the transfer of their personal information overseas. To do so, please contact us using the details in Article 11. However, because the Company receives and responds to inquiries and conducts recruitment via e-mail, refusing will restrict the handling of your inquiry and your job application by e-mail, and you will need to use another means such as the telephone.

8. Rights and Obligations of Data Subjects and How to Exercise Them

Data subjects may exercise the following rights against the Company at any time.

  • - Request access to personal information
  • - Request correction of errors
  • - Request deletion
  • - Request suspension of processing

These rights may be exercised in writing, by telephone or by e-mail using the contact details in Article 11 below, and the Company will act on such requests without delay.

Where a data subject requests correction of an error in personal information, the Company will not use or provide that personal information until the correction is completed.

These rights may also be exercised through an agent, such as a legal representative or a duly authorised person. In such a case, a power of attorney in the form prescribed by the applicable notification must be submitted.

9. Measures to Ensure the Security of Personal Information

Pursuant to Article 29 of the Personal Information Protection Act, the Company takes the following measures.

Administrative measures
- The number of personnel handling personal information is limited to the minimum necessary for business purposes.
- Regular training is provided to personnel who handle personal information.

Technical measures
- Access rights to the personal information processing system are granted on a differentiated basis, and accessible IP addresses are restricted.
- Access records are retained and reviewed, and unauthorised access is controlled through an access control system.
- A secure server (HTTPS) is applied across the entire website to encrypt personal information in transit.
- Personal information that must be stored is encrypted using a secure algorithm (AES-256).
- Security programs are installed and periodically updated and inspected.

Physical measures
- Servers holding personal information are kept in a controlled location with managed access.

10. Installation and Operation of Automatic Collection Devices, and Refusal Thereof

The Company uses "cookies" that store and retrieve usage information in order to provide services to users. A cookie is a small piece of information sent by the server operating the website to the user's browser and stored on the user's device.

Purpose of using cookies
Cookies are used to maintain the user's session and to verify security tokens, so that the service can function normally. The Company does not collect behavioural information for advertising purposes and does not carry out online customised advertising.

How to refuse cookies
Users may allow all cookies, be prompted each time a cookie is stored, or refuse the storage of all cookies by configuring the options in their web browser.
Example (Chrome) : Settings > Privacy and security > Third-party cookies
However, refusing to store cookies may cause difficulties in using some services.

11. Privacy Officer and Department Handling Access Requests

The Company has designated a Privacy Officer as set out below, who is responsible for overseeing personal information processing and for handling complaints and remedying damage in relation to the processing of personal information.

Privacy Officer
Department : IT Team
Tel : +82-2-568-3767
E-mail : info@chipsnmedia.com
Department handling access requests
Department : IT Team
Tel : +82-2-568-3767
E-mail : info@chipsnmedia.com

Data subjects may direct any inquiries, complaints or requests for remedy relating to personal information protection arising from the use of the Company's services to the Privacy Officer. The Company will respond to and handle such inquiries without delay.

12. Remedies for Infringement of Rights

Data subjects may apply for dispute resolution or consultation to the following organisations in order to obtain relief from infringement of personal information rights.

  • - Personal Information Infringement Report Centre (privacy.kisa.or.kr / 118)
  • - Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972)
  • - Supreme Prosecutors' Office, Cyber Investigation Division (www.spo.go.kr / 1301)
  • - National Police Agency, Cyber Bureau (ecrm.police.go.kr / 182)

In addition, a person whose rights or interests have been infringed by a disposition or omission by the head of a public institution in response to a request under Articles 35 (access), 36 (correction or deletion) or 37 (suspension of processing) of the Personal Information Protection Act may request an administrative appeal as prescribed by the Administrative Appeals Act.

13. Changes to This Privacy Policy

This Privacy Policy takes effect on August 28, 2026.

If there are additions, deletions or modifications due to changes in laws, policies or security technology, the Company will announce the reasons for and details of the change through a notice on the website at least 7 days before the effective date of the change.