Service operator
Consulting Zoom Co., Ltd. (컨설팅줌(주)), represented by CUI LIHUA, business registration no. 246-86-03228, 7F, Unit 702-CS02, 129-1 Bongeunsa-ro, Gangnam-gu, Seoul, Republic of Korea
1. Controller
Consulting Zoom Co., Ltd. (컨설팅줌(주)), represented by CUI LIHUA, business registration no. 246-86-03228, 7F, Unit 702-CS02, 129-1 Bongeunsa-ro, Gangnam-gu, Seoul, Republic of Korea (the “Company”) is the controller of personal information processed through KBEAUTALK.
The KBEAUTALK Operations Team handles privacy and complaints. Requests to access, correct, delete, restrict processing, or withdraw consent may be submitted through the website contact form or by calling 010-7611-8294 (weekdays, 10:00–18:00 KST).
2. Purposes, data, and retention
| Context | Purpose and information | Retention |
|---|---|---|
| Public inquiries | To receive, answer, and follow up: name, email, phone, company/industry, product or service links, budget range, and inquiry or campaign details. | 6 months after consultation ends. If an agreement or dispute follows, the applicable record period applies. |
| Client registration and account | To register, verify email, authenticate, create an organization, and manage an account: login ID, email, contact name, mobile number, company name, password authentication data, OIDC identifier, accepted Terms/Policy versions and time. | Access-restricted for up to 3 years after closure for disputes, abuse prevention, and consent evidence, then deleted; longer where law requires. |
| Creator registration and profile | To register, sign in by email, assess campaign fit, and perform work: email, nickname/name, phone, country/language, channel accounts and links, follower/engagement metrics, categories, portfolio, and accepted versions/time. | Access-restricted for up to 3 years after closure for disputes, abuse prevention, and consent evidence, then deleted. Agreement and settlement records follow legal or contractual periods. |
| Campaigns and support | To review requests, propose work, issue instructions, share progress, submit/review/revise/report, and support users: requests, messages, feedback, schedules, deliverables, files, public account activity, and assigned staff information. | 3 years after the campaign or support ends. Agreement, payment, or dispute records follow the periods below. |
| Agreements, billing, and settlement | To enter into and perform agreements, bill, meet tax duties, process Client payments, and settle Creator compensation: party/contact information, necessary bank/tax information, and agreement, invoice, and payment records. | As required by law. Where Korean e-commerce retention applies: contract/withdrawal and payment/supply records for 5 years; consumer complaint/dispute records for 3 years. |
| Security and access logs | For authentication, sessions, access control, incident/abuse response, and audit: IP address, access time, device/browser data, session and CSRF identifiers, request and audit logs. | Normally 1 year. Records needed for an incident, audit, or dispute are access-restricted until the reason ends. |
3. Legal basis and required information
- Information needed for registration, login, and campaigns is processed to perform or prepare a contract at the user’s request, or based on consent.
- Agreement, tax, and dispute records may be processed to meet legal duties. Security logs are processed as necessary for the Company’s legitimate interests in secure operation and abuse prevention.
- Users may refuse required information, but the Company may then be unable to create or verify an account or provide the requested service. Optional information is not required for basic account functions.
5. Processing and overseas transfer
Staging currently uses Google LLC’s Gmail SMTP to send registration verification and password-reset emails. Recipient email addresses, message content, time, and related transmission metadata may be transferred over an encrypted network to Google systems in the United States. The purpose is transactional email delivery. Retention depends on the Company sending-account settings and applicable Google policies.
Core, Creator, Identity (Keycloak), session storage, and object storage are currently operated by the Company on approved staging infrastructure. Before a new cloud, email, payment, or analytics processor is used in a formal environment—or the transfer arrangement changes—the Company will publish the processor/recipient, country, data, purpose, timing/method, retention, and refusal method and complete legally required procedures.
6. Deletion
- Personal information is deleted without undue delay when its retention period ends or its purpose is achieved. Information that must be retained by law is segregated with restricted access.
- Electronic files are erased in a manner designed to prevent recovery, and paper is shredded or destroyed. Backups are overwritten on the defined rotation and restricted to recovery use.
- Before formal registration opens, the Company will assign an owner and finalize a periodic deletion and verification process for the periods above.
7. Data subject rights
Data subjects may request access, portability, correction, deletion, restriction, or withdrawal of consent through an account function or the privacy contact. The Company will verify the requester or lawful representative and respond within the period required by law.
A request may be limited where law requires retention or another person’s rights would be harmed; the reason will be explained. Registration is not offered to anyone under 19.
9. Security safeguards
- Least-privilege access control based on role, organization, operations group, resource ownership, and state
- TLS in transit, HttpOnly/Secure session cookies, and dedicated Identity management for passwords and authentication data
- Private storage and authorized download for sensitive files, audit logs, security review, backup, and recovery procedures
- Restricted staff and processor access, confidentiality, incident response, and privacy training
10. Complaints and remedies
For additional reporting or consultation in Korea, contact the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), or Korean National Police Agency (182).
11. Policy changes
The effective date and changes will be announced in the Service. A material change to rights or duties will normally be announced at least 30 days in advance, and separate consent will be obtained where required by law. Prior versions are retained under their version identifiers.