Privacy Policy This Privacy Policy (hereafter the “Policy”) explains the way of treatment of the information which is provided or collected in the websites on which this Policy is posted. In addition the Policy also explains the information which is provided or collected in the course of using the applications of the Company which exist in the websites or platforms of other company. Through this Policy, the Company regards personal information of the users as important and inform them of the purpose and method of Company's using the personal information provided by the users and the measures taken by the Company for protection of those personal information.

This Policy will be effective on the 10th day of May, 2017 and, in case of modification thereof, the Company will make public notice of it through posting it on the bulletin board of Company's website.

1. Information to be collected and method of collection

(1) Personal information items to be collected

Personal information items to be collected by the Company are as follows:

Information provided by the users
The Company may collect the information directly provided by the users:
Name, email address

Information collected while the users use services
Besides of information directly provided by the users, the Company may collect information in the course that the users use the service provided by the Company:
Log data, use time, search word input by users, internet protocol address

(2) Method of collection

The Company collects the information of users in a way of the followings:
Webpage, tools for collection of created information

2. Use of collected information

The Company uses the collected information of users for the following purposes:

• Member management and identification
• To detect and deter unauthorized or fraudulent use of or abuse of the Service
• Performance of contract and service fee settlement regarding provision of services demanded by the users

The Company agrees that it will obtain consent from the users, if the Company desires to use the information other than those expressly stated in this Policy.

3. Sharing collected information

Except for the following cases, the Company will not share personal information with a 3rd party:

• When the users consent the sharing in advance
• When the sharing is required by the laws:
If required to be disclosed by the laws and regulations or if required to be disclosed by the investigative agencies for detecting crimes in accordance with the procedure and method as prescribed in the laws and regulations

4. Cookies, Beacons and Similar Technologies

The Company will not collect collective and impersonal information through 'cookies' or 'web beacons'.

5. Users' right to access and option

The users or their legal representatives, as main agents of the information, may exercise the following options regarding the collection, use and sharing of personal information by the Company:

• exercise right to access to personal information
• make corrections or deletion
• make temporary suspension of treatment of personal information or
• request the withdrawal of their consent provided before

If, in order to exercise the above options, you, as an user, contact the Company by using representative telephone or sending a document or e• mails, or using telephone to the responsible department (or person in charge of management of personal information), the Company will take measures without delay: Provided that the Company may reject the request of you only to the extent that there exists either proper cause as prescribed in the laws or equivalent cause.

6. Security

The Company regards the security of personal information of uses as very important. The company constructs the following security measures to protect the users' personal information from any unauthorized access, release, use or modification.

• Encryption of personal information
- Transmit users' personal information by using encrypted communication zone
- Store important information such as passwords after encrypting it

• Countermeasures against hacking
- Install a system in the zone the external access to which is controlled so as to prevent leakage or damage of users1 personal information by hacking or computer virus

• Establish and execute internal management plan
• Install and operate access control system
• Take measures to prevent forging or alteration of access record


7. Modification of Privacy Protection Policy

The Company has the right to amend or modify this Policy from time to time and, in such case, the Company will make a public notice of it through bulletin board of its website (or through individual notice such as written document, fax or e-mail) and obtain consent from the users if required by relevant laws.

8. Others

Considering it engages in global businesses, the Company may provide the users1 personal information to the companies located in other countries for the purpose as expressly stated in this Policy. For the places where the personal information is transmitted, retained or processed, the Company takes reasonable measures for protecting that personal information.

In addition, when the personal information obtained from the European Union is used or disclosed, the Company may have to comply with safe harbor principle as required by the Commerce Department of USA, take other measures or obtain consent from users so far as those complies with the regulations of EU so as to use a standardized agreement provision approved by executing organizations of EU or securing proper safe measures.

If the user resides in California, certain rights may be given. The Company prepares preventive measures necessary for protecting personal information of members so that the Company can comply with online privacy protection laws of California.

In case of leakage of personal information, a user may request the Company to check the leakage. In addition, all the users in the website of the Company, can modify their information at any time by using the menu for changing information by connecting their personal account.

Moreover, the Company does not trace the visitors of its website nor use any signals for 'tracing prevent'. The Company will not collect and provide any personal identification information through ad services without consent of users.

The Company guides several additional matters to be disclosed as required by the information network laws and personal information protection laws in the Republic of Korea

9. Responsible department of Company

The Company designates the following department and person in charge of personal information in order to protect personal information of customers and deal with complaints from customers:

• Department responsible for privacy protection and customer service:

Address :194, Yulgok-ro, Jongno-gu, Seoul, 03127, Korea
Tel.:82-2-3706-6017
E-mail:hwy@hmm21.com

The latest update date:14th, May, 2018