Legal · dpa

한국어

Data Processing Addendum (DPA)

Effective 2026-10-05

Article 1 (Purpose and Roles)

This DPA governs the personal information the Company processes on behalf of customers while providing E.D.1.T.H under the Terms of Service. The Company acts as a processor under the Korean Personal Information Protection Act; the customer remains the controller of data it stores inside instances.

Article 2 (Scope and Purpose)

  • Account and authentication records: providing service access (submitted by the customer at signup)
  • Usage records: metering, credit deduction, and service operation
  • Access records: security, incident response, statutory retention

Article 3 (Security Measures)

  1. Encryption in transit (TLS 1.2+) and at rest
  2. Access to personal information restricted to the minimum number of staff, with access logging
  3. Complete wipe of storage media when an instance is returned
  4. In the event of a breach, notification to the customer within 72 hours and compliance with PIPA procedures

Article 4 (Sub-processing)

The Company sub-processes only for payments (PG) and hosting (CDN), and informs customers of the purpose, duration, and scope of sub-processing. The trustee list in Privacy Policy Article 5 covers this.

Article 5 (Data Subject Rights)

Requests from the customer’s end users (access, correction, deletion, suspension) are received through the customer, and the Company acts on the customer’s request without delay.