Privacy Policy
Seongjun Kim (the "Operator"), who operates LoL Codex (the "Service"), establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly.
Article 1 (Purposes of Processing Personal Information)
The Operator processes personal information for the following purposes. The personal information processed is not used for any purpose other than the following, and where the purpose of use is changed, the Operator will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
1. Provision of the message board service
Publishing articles and comments, displaying authors, tallying upvotes and poll results, and enabling Users to view the Posts they have created
2. Operation of the Service and protection of Users
Preventing spam and abusive use, receiving and handling reports, and handling restrictions on use and objections thereto
3. Operation of tiers and points
Calculating points and tiers based on activity and on advertisement viewing, and managing records of point usage
4. Sending notifications
Sending notifications for comments, replies, mentions, upvotes, and poll closings, only where the User has enabled them
The Operator does not use the above personal information for advertising or marketing purposes.
Article 2 (Categories of Personal Information Processed)
1. Items generated automatically when the Service is used
Account identification number, six-digit unique code, nickname (generated automatically by the Service), and date and time of registration
2. Items generated or entered in the course of a User's use of the Service
One-line introduction (where entered), the content of Posts and comments, poll participation records, upvote records, points and tier and purchased cosmetic items, block list, report records, photos attached to Posts (where attached), notification settings, and device notification token (where notifications have been permitted)
3. Items generated or collected automatically in the course of use of the Service
Access IP address and access date and time (generated as security logs of the Service operating infrastructure; the Operator does not separately collect or retain them)
The Operator does not collect email addresses, phone numbers, names, dates of birth, gender, location information, contacts, or payment information. Summoner names looked up in match history search and favorited champions are stored only on the User's device and are not transmitted to the server.
Article 3 (Personal Information of Children Under 14)
1. Only persons aged 14 or older may use the Service, and the Operator does not process the personal information of children under 14.
2. The Operator confirms that the User is aged 14 or older on the Terms of Service consent screen shown on first launch of the app, and a person who does not so agree cannot use the Service.
3. Where the Operator becomes aware that a child under 14 has used the Service, it destroys that account and the personal information concerned without delay.
4. The Operator does not collect children's behavioral information for the purpose of targeted advertising and does not serve targeted advertising to children.
Article 4 (Period of Processing and Retention of Personal Information)
The Operator processes and retains personal information within the retention and use period prescribed by law or the period agreed upon when the personal information was collected from the data subject.
1. Account information, Posts, comments, photos, upvote and poll records, points and tier, and block list: until account deletion
2. Posts and comments deleted by the User: thirty days from the time of deletion. This period is for recovery from inadvertent deletion and for the handling of reports.
3. Report records: one year from the date of receipt; provided that reports concerning obscene material and illegal information are retained for three years
4. Notification records: ninety days from the date of sending
5. Device notification token: sixty days from the date of last use
6. Records of points awarded for watching advertisements: one year from the date of award
Article 5 (Procedure and Method for the Destruction of Personal Information)
1. Where personal information becomes unnecessary, such as upon expiry of its retention period or upon achievement of the purpose of processing, the Operator destroys that personal information without delay.
2. Destruction procedure
Personal information whose retention period has expired is destroyed automatically by the server in the early morning of each day (at approximately 4 a.m. Korea Standard Time), without any separate human judgment. Where a request for account deletion is made, the information is destroyed immediately upon the request.
3. Method of destruction
Personal information stored in the form of electronic files is permanently deleted from the database and the storage so that it cannot be recovered or reproduced. The Operator does not retain personal information in paper documents.
4. As to aggregate figures remaining on other Users' Posts (poll counts and upvote counts), only the figures remain after the information by which it could be identified who participated has been destroyed.
Article 6 (Provision of Personal Information to Third Parties)
1. The Operator processes the personal information of data subjects only within the scope specified in Article 1, and provides it to third parties only where Article 17 or Article 18 of the Personal Information Protection Act applies, such as where the data subject has consented or where there is a special provision of law.
2. The Operator does not sell personal information or provide it to third parties for commercial purposes.
3. The Operator may provide personal information only where an investigative agency requests it in accordance with the lawful procedures prescribed by law.
Article 7 (Outsourcing of Personal Information Processing)
In order to provide the Service smoothly, the Operator outsources personal information processing tasks as follows.
1. Trustee: Supabase, Inc.
Outsourced tasks: operation of the database and file storage, and authentication processing
Retention and use period: until termination of the outsourcing agreement or until destruction
2. Trustee: Apple Inc.
Outsourced tasks: delivery of notification messages (APNs), and storage of account identification information through the iCloud Keychain
Retention and use period: until termination of the outsourcing agreement or until destruction
When entering into an outsourcing agreement, the Operator stipulates in the document the matters concerning the safe management of personal information, and supervises whether the trustee processes personal information safely. Where the content of the outsourced tasks or the trustee changes, the Operator will disclose this through this Privacy Policy.
Article 8 (Cross-Border Transfer of Personal Information)
Pursuant to Article 28-8(1)3(a) of the Personal Information Protection Act, the Operator discloses the following matters and transfers personal information abroad as outsourced processing and storage of personal information necessary for the performance of a contract with the data subject and for the promotion of the data subject's convenience.
1. Transferee: Supabase, Inc. (support@supabase.io)
Country of transfer: the United States
Date and method of transfer: transmission and storage over a network when the Service is used
Items transferred: all of the items processed under Article 2
Purpose of use: operation of the database and storage, and technical support
Retention and use period: until termination of the outsourcing agreement or until destruction
(Data is stored in the Amazon Web Services Seoul region and may be accessed from outside Korea in the course of technical support.)
2. Transferee: Apple Inc. (https://www.apple.com/kr/privacy/)
Country of transfer: the United States
Date and method of transfer: transmission over a network when notifications are sent and when account identification information is synchronized
Items transferred: device notification token, notification content, and account identification information
Purpose of use: delivery of notifications, and iCloud Keychain synchronization
Retention and use period: until the purpose of providing the Service is achieved
A data subject may refuse the cross-border transfer of personal information. However, a data subject who refuses the cross-border transfer cannot use the functions that rely on the server, such as the message board, and may express such refusal by deleting their account or through the contact information in Article 12. Refusal of the delivery of notifications may be effected by turning notifications off in the in-app settings.
Article 9 (Installation and Operation of Devices for Automatic Collection, and Refusal Thereof)
1. For the purpose of displaying advertisements, Google's advertising software development kit (the Google Mobile Ads SDK) is installed in the Service.
2. That kit uses the device's advertising identifier and records of advertisement impressions and views for the purpose of displaying and measuring advertisements.
3. The Operator does not identify Users and does not collect or retain behavioral information for targeted advertising. The Service does not request App Tracking Transparency (ATT) permission.
4. A data subject may refuse the use of the advertising identifier through the device settings.
iPhone: Settings → Privacy & Security → Tracking → turn off Allow Apps to Request to Track
In addition, targeted advertising can be turned off under Settings → Privacy & Security → Apple Advertising.
5. The Operator does not collect sensitive behavioral information such as ideology or beliefs, political opinions, health, or sex life.
Article 10 (Behavioral Information Collected by Third Parties)
The information collected by the third-party devices for automatic collection installed in the Service is as follows. The information below is collected by the relevant operator directly from the User's device; it does not pass through the Operator's server, nor is it retained by the Operator.
· Name of the collection device: Google Mobile Ads SDK
· Type of the collection device: mobile app SDK
· Collecting operator: Google LLC
· Items collected: advertising identifier, device information, IP address, records of advertisement impressions and views, app usage records, and error records
· Purpose of collection: displaying advertisements, measuring advertising performance, and preventing click fraud
· Retention and use period: in accordance with the privacy policy of the relevant operator
· Method of refusal: changing the device settings under Article 9(4)
Matters concerning Google's processing of personal information can be found in the Google Privacy Policy (https://policies.google.com/privacy) and in the additional information for residents of Korea.
The Operator does not provide advertising operators with information that Users have entered in the Service, such as Posts, nicknames, or points.
Article 11 (Automated Decisions)
1. In order to protect Users promptly, the Operator operates automated processing without human intervention as follows.
· Where reports from three or more persons are received with respect to the same Post, that Post is hidden automatically.
· The registration of Posts, comments, and nicknames containing prohibited words is restricted.
2. A data subject may demand an explanation of, or refuse, the above measures through the in-app objection function or through the contact information in Article 12, and the Operator will have a person re-examine the matter directly and will notify the data subject of the outcome.
Article 12 (Rights and Obligations of Data Subjects and Their Legal Representatives, and How to Exercise Them)
1. A data subject may at any time request the Operator to grant access to their personal information, to correct or delete it, to suspend its processing, or to withdraw consent.
2. These rights may be exercised directly through the in-app functions.
· Access: the My Information, My Posts, and My Comments screens, and the block list screen in Settings
· Correction: changing the nickname, editing the one-line introduction, and editing Posts
· Deletion: deleting Posts and comments, and deleting the account on the Settings screen
· Suspension of processing: turning off the receipt of each type of notification on the Settings screen
3. A request that cannot be handled through the in-app functions may be submitted by email, and the Operator will take action within ten days from the date of receiving the request.
4. A data subject has an obligation to keep their personal information accurate and up to date, and must not post the personal information of another person.
5. Nicknames and one-line introductions are disclosed to other Users, so please take care not to enter information by which an individual can be identified.
Article 13 (Measures to Ensure the Safety of Personal Information)
Pursuant to Article 29 of the Personal Information Protection Act and Article 30 of the Enforcement Decree of that Act, the Operator takes the following measures to ensure safety.
1. Minimization of the persons who handle personal information
The persons who handle personal information are limited to the Operator alone.
2. Management of access rights
Row-level security policies are applied to the database so that information other than the data subject's own information cannot be accessed.
3. Retention of access records
Access records generated by the Service infrastructure are retained so that unauthorized access attempts can be identified.
4. Encryption of personal information
All communications between the app and the server are encrypted in transit, and stored data is encrypted at the storage-medium level.
5. Technical measures against hacking and similar threats
Excessive creation of accounts from the same IP address is restricted, and access rights to the Service are managed.
Article 14 (Privacy Officer, and Department Receiving and Handling Access Requests)
1. The Operator takes overall responsibility for the tasks concerning the processing of personal information and, in order to handle data subjects' complaints and provide remedies in relation to the processing of personal information, has designated a Privacy Officer as follows.
Privacy Officer
· Name: Seongjun Kim
· Position: Operator (individual developer)
· Contact: 7577ksj@gmail.com
2. A data subject may submit a request for access to personal information to the following. The Operator will endeavor to ensure that data subjects' access requests are handled promptly.
Receipt and handling of requests for access to personal information
· Person in charge: Seongjun Kim (concurrently serving as the Privacy Officer)
· Contact: 7577ksj@gmail.com
3. A data subject may direct to the above contact any matter concerning personal information protection arising in the course of using the Service, including inquiries, complaints, and requests for remedy, and the Operator will respond within ten days from the date of receipt.
Article 15 (Remedies for Infringement of the Rights and Interests of Data Subjects)
In order to obtain a remedy for an infringement of personal information, a data subject may apply to the organizations below for dispute resolution, consultation, or the like.
· Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
· Personal Information Infringement Report Center (KISA): 118 (no area code) (privacy.kisa.or.kr)
· Supreme Prosecutors' Office Cyber Investigation Division: 1301 (no area code) (www.spo.go.kr)
· Korean National Police Agency Cyber Bureau: 182 (no area code) (ecrm.police.go.kr)
A person whose rights or interests have been infringed by a disposition made or an omission committed by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may request an administrative appeal as provided by the Administrative Appeals Act.
Article 16 (Information That Is Not Processed)
1. The Operator does not process sensitive information under Article 23 of the Personal Information Protection Act.
2. The Operator does not process pseudonymized information under Articles 28-2 and 28-3 of the same Act.
3. The Operator does not operate any fixed or mobile visual data processing device.
4. The Operator, being an individual domiciled in Korea, is not subject to the designation of a domestic agent under Article 31-2 of the same Act.
Article 17 (Changes to the Privacy Policy)
1. This Privacy Policy applies from the effective date set out below.
2. Where content is added, deleted, or modified as a result of a change in law, policy, or security technology, the Operator will announce the reason for and the content of the change through the in-app notices from seven days before the effective date of the amended Privacy Policy.
3. Where a change is unfavorable to data subjects, the Operator will give notice from thirty days before the effective date and will present a clear comparison of the content before and after the change.
4. The Operator will post the amended Privacy Policy continuously in the app and on its website, and previous versions may be reviewed through the contact address.