EOND Co., Ltd. (the "Company") operates EOND SEO (https://seo.eond.com, the "Service") and, in accordance with the Personal Information Protection Act and other applicable laws, maintains this Privacy Policy to protect users' personal information and to handle related complaints promptly.
1. Purposes of processing personal information
- Membership registration and login, identity verification, and member management
- Providing the Service: generating, saving, and editing carousel code, managing daily usage, and the SEO Debug tool
- Payment and settlement for paid plans, subscription management, and refund processing
- Receiving and answering inquiries, and delivering notices
- Preventing fraudulent use and maintaining security (limiting login attempts, reviewing access records)
- Analyzing and improving Service usage statistics
2. Personal information items processed
| Category | Items | Collection method |
|---|---|---|
| Membership registration (required) | Email, password (stored with one-way encryption), username | Sign-up screen |
| Profile (optional) | Company name, website, bio | My Profile screen |
| Inquiry | Name, email, inquiry type, subject, and message, phone number (optional) | Contact screen |
| Paid payment | Plan, payment amount and date/time, payment processor transaction number and subscription number (payment method information such as card numbers is handled by the payment processor and is not retained by the Company) | Payment process |
| Business payment (if applicable) | Business registration number, business type (corporation or sole proprietor) | Payment screen |
| Automatic collection | IP address, access and login records, browser information (User-Agent), Service usage records (number of carousels created, etc.), cookies | Generated automatically while using the Service |
Carousel content created by members (titles, descriptions, URLs, image addresses, etc.) is stored as the member's content and can be viewed only by the member and by administrators for Service operation purposes.
3. Retention period of personal information
Personal information is destroyed without delay upon membership withdrawal or when the purpose of processing has been fulfilled. However, where applicable laws require retention, it is kept for the periods below.
- Records of contracts or withdrawal of orders: 5 years (Act on the Consumer Protection in Electronic Commerce)
- Records of payment and supply of goods: 5 years (same Act)
- Records of consumer complaints or dispute resolution: 3 years (same Act)
- Service access records (login records, IP): 3 months (Protection of Communications Secrets Act)
- Inquiry content: 3 years after the reply is completed (for dispute handling)
- Login sessions: up to 30 days; failed login records: 7 days (for security; deleted automatically afterward)
4. Procedure and method for destroying personal information
Personal information whose retention period has expired is destroyed without delay. Electronic files are deleted using methods that make recovery impossible, and paper documents are shredded or incinerated. Information retained under applicable laws is stored separately from other information.
5. Provision of personal information to third parties
The Company does not provide users' personal information to third parties, except where the user has consented or where laws specifically provide otherwise (such as lawful requests from investigative agencies).
6. Outsourcing of personal information processing and overseas transfer
| Recipient | Tasks and items | Country and method | Retention period |
|---|---|---|---|
| SteppPay | Recurring payment processing / payment information | Republic of Korea · transmitted at payment | Until the end of the outsourcing contract or for the statutory retention period |
| Google LLC (Google Analytics) | Usage statistics analysis / cookie identifiers, pages visited and usage behavior, device and browser information, IP address (processed according to Google's policies) | United States · transmitted over the network when a page is visited | Data retention period configured in Google Analytics |
If you do not want Google Analytics to collect data, you can block browser cookies or use the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).
7. Rights of data subjects and how to exercise them
Users may at any time request access to, correction, deletion, or suspension of processing of their personal information. You can edit it directly on the My Profile screen, or send a request by email or phone to the Chief Privacy Officer below, and it will be handled without delay. Requests may also be made through a legal representative or an authorized agent, in which case a power of attorney must be submitted.
8. Measures to ensure the security of personal information
- Passwords are stored with one-way encryption (bcrypt), and even the Company cannot know the original password.
- Login sessions are maintained with secure cookies (HttpOnly, Secure) that browser scripts cannot read, and only a hash of the value is stored on the server.
- All communications are encrypted with HTTPS.
- Access to personal information on the server is limited to the member and administrators.
- Repeated failed login attempts are limited to prevent brute-force attacks.
- The database runs only inside the server and cannot be accessed directly from outside.
9. Installation, operation, and refusal of cookies
- Login cookie: A required cookie that keeps you logged in. If blocked, features that require login cannot be used.
- Analytics cookie (Google Analytics): A cookie used for visit and usage statistics.
- You can refuse or delete cookies in your browser settings (e.g., Chrome Settings › Privacy and security › Third-party cookies).
10. Chief Privacy Officer
- Chief Privacy Officer
- EOND Privacy Officer
- Phone
- 0507-1433-0311
- eond@eond.com
Inquiries, complaints, and requests for remedies regarding personal information can be submitted using the contact details above or via Contact.
11. Remedies for infringement of rights
- Personal Information Dispute Mediation Committee: (no area code) 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center: (no area code) 118, privacy.kisa.or.kr
- Supreme Prosecutors' Office: (no area code) 1301, www.spo.go.kr
- Korean National Police Agency: (no area code) 182, ecrm.police.go.kr
12. Notification obligation
This Privacy Policy applies from October 5, 2026. If any content is added, deleted, or modified, notice will be given through Service announcements starting 7 days before it takes effect (30 days for changes significantly affecting users' rights).