Article 1 (Purpose and Roles)
This DPA governs the personal information the Company processes on behalf of customers while providing E.D.1.T.H under the Terms of Service. The Company acts as a processor under the Korean Personal Information Protection Act; the customer remains the controller of data it stores inside instances.
Article 2 (Scope and Purpose)
- Account and authentication records: providing service access (submitted by the customer at signup)
- Usage records: metering, credit deduction, and service operation
- Access records: security, incident response, statutory retention
Article 3 (Security Measures)
- Encryption in transit (TLS 1.2+) and at rest
- Access to personal information restricted to the minimum number of staff, with access logging
- Complete wipe of storage media when an instance is returned
- In the event of a breach, notification to the customer within 72 hours and compliance with PIPA procedures
Article 4 (Sub-processing)
The Company sub-processes only for payments (PG) and hosting (CDN), and informs customers of the purpose, duration, and scope of sub-processing. The trustee list in Privacy Policy Article 5 covers this.
Article 5 (Data Subject Rights)
Requests from the customer’s end users (access, correction, deletion, suspension) are received through the customer, and the Company acts on the customer’s request without delay.