Privacy Policy

This English version of the PLAYBOARD Privacy Policy is a translation based on the original Korean version of the PLAYBOARD Privacy Policy. If there is any conflict between these two versions, the original Korean version of the PLAYBOARD Privacy Policy shall prevail. The relationship between you and PLAYBOARD in relation to the PLAYBOARD Terms of Service or PLAYBOARD Services shall be governed by the laws of Republic of Korea, and any dispute arising between you and PLAYBOARD arising out of or in connection with the PLAYBOARD Privacy Policy or PLAYBOARD Services, shall be resolved in accordance with the procedures set out in the Civil Procedure Act of Republic of Korea.
DIFF., Inc. (hereinafter the “Company”) establishes and discloses the following Privacy Policy in accordance with Article 30 of the 「Personal Information Protection Act」 in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances. This Privacy Policy is effective from July 14, 2026.

Article 1 (Purpose)

The purpose of DIFF., Inc.’s personal information protection management regulation (hereinafter the “Regulation”) is to establish matters concerning the technical, administrative, and physical safeguards necessary to ensure security so that personal information is not lost, stolen, leaked, forged, altered, or damaged in the course of processing, in accordance with Article 29 of the 「Personal Information Protection Act」, Article 30 of its Enforcement Decree, and the “Standards for Measures to Ensure the Safety of Personal Information” (notice of the Ministry of the Interior and Safety), among others.

Article 2 (Definitions)

The meanings of the terms used in this Regulation are as follows.
  • “Personal information” means information relating to a living individual, such as name, resident registration number, and images, through which the individual can be identified (including information that alone cannot identify a specific individual but can be readily combined with other information to do so).
  • “Processing” means the collection, generation, linkage, interconnection, recording, storage, retention, editing, searching, output, correction, recovery, use, provision, disclosure, and destruction of personal information, and other similar acts.
  • “Data subject” means a person who is identifiable by the processed information and who is the subject of that information.
  • “Personal information file” means a set of personal information systematically arranged or organized according to certain rules for easy retrieval.
  • “Personal information controller” means a public institution, corporation, organization, individual, etc. that processes personal information directly or through another person to operate personal information files for business purposes.
  • “Chief Privacy Officer” means the person who takes overall responsibility for the controller’s personal information processing, as provided under Article 32(2) of the Enforcement Decree of the Personal Information Protection Act.
  • “Privacy manager” means the person who handles and manages the controller’s personal information.
  • “Field-specific Chief Privacy Officer” means the person who takes overall responsibility for personal information processing limited to a unit (field) classified by the “Company”.
  • “Field-specific privacy manager” means the person who handles and manages personal information limited to a unit (field) classified by the “Company”.
  • “Personal information handler” means a person who processes personal information under the direction and supervision of the controller, including employees, dispatched workers, and part-time workers.
  • “Personal information processing system” means a system, such as a database system, systematically organized to process personal information.
  • “Password” means a unique string of characters that a data subject or handler must enter together with an identifier when accessing a processing system, work computer, or network, so that the system can verify a legitimate access right; it is information not disclosed to others.
  • “Information and communications network” means an information and communications system that collects, processes, stores, searches, transmits, or receives information using telecommunications facilities under Article 2(2) of the Framework Act on Telecommunications, or by utilizing computers and computer technology together with such facilities.
  • “Open wireless network” means a network through which an unspecified number of people can access the internet via a wireless access point (AP).
  • “Mobile device” means a portable device used to process personal information, such as a PDA, smartphone, or tablet PC that can use a wireless network (not limited thereto).
  • “Biometric information” means information about physical or behavioral characteristics that can identify an individual, such as fingerprints, face, iris, veins, voice, or handwriting, including information processed or generated therefrom.
  • “Auxiliary storage medium” means a medium that can store data and be easily connected to or separated from a processing system or personal computer, such as a portable hard disk, USB memory, CD, or DVD (not limited thereto).
  • “Internal network” means a segment where access from the internet is controlled or blocked by physical network separation, an access control system, etc.
  • “Access records” means electronic records of the work performed by a handler upon accessing the processing system, including the handler’s account, access date and time, access location information, information of the data subject processed, and work performed. Here, “access” means a state in which data transmission or reception is possible through connection to the processing system.
  • “Management terminal” means a terminal that directly accesses the processing system for the purpose of managing, operating, developing, or securing the system.
  • “User” means a person who uses the information and communications services provided by the Company.
  • “Authentication information” means information used to verify the identity of an identifier requested by the processing system or the system managing the network.

Article 3 (Scope of Application)

This Regulation applies to the Company’s processing of personal information and to any entrustee that processes personal information on behalf of the Company.

Article 4 (Establishment and Approval of the Regulation)

  • The Chief Privacy Officer shall establish this Regulation through internal decision-making procedures so that the Company complies with laws and regulations related to personal information protection.
  • The Chief Privacy Officer shall immediately reflect and amend any material changes to the provisions of this Regulation.
  • When establishing or amending this Regulation under paragraphs 1 and 2, the Chief Privacy Officer shall obtain approval such as internal sign-off from the CEO and shall retain and manage the related records.
  • The Company may prepare and implement various guidelines for the detailed implementation of this Regulation, in which case paragraph 3 of this Article shall also apply.
  • The Chief Privacy Officer shall inspect and manage the implementation status of this Regulation at least once a year and take appropriate measures based on the results.

Article 5 (Publication of the Internal Management Plan)

  • The Chief Privacy Officer shall notify all employees and relevant parties of this Regulation, as approved under Article 4(3), so that they comply with it.
  • This Regulation shall be disclosed in a manner that allows employees to review it at any time, and any changes shall be announced.

Article 6 (Designation of the Chief Privacy Officer)

Pursuant to Article 31 of the 「Personal Information Protection Act」 and Article 32 of its Enforcement Decree, the Company designates the CEO as the Chief Privacy Officer who takes overall responsibility for personal information processing. Inquiries regarding personal information protection may be directed to the following.
  • Department: Privacy Protection
  • Email: hello@playboard.co
  • Phone: 1668-3054

Article 7 (Roles and Responsibilities of the Chief Privacy Officer)

  • The Chief Privacy Officer performs the following duties.
    • Establishing and implementing a personal information protection plan
    • Regularly investigating and improving the status and practices of personal information processing
    • Handling complaints and providing remedies related to personal information processing
    • Building an internal control system to prevent leakage, misuse, and abuse of personal information
    • Establishing and implementing a privacy education plan
    • Protecting and supervising personal information files
    • Establishing, amending, and implementing the Privacy Policy under Article 30 of the 「Personal Information Protection Act」
    • Managing personal information protection materials
    • Destroying personal information whose purpose has been achieved or retention period has expired
    • Overseeing responses to personal information breach or leakage incidents
  • In performing the duties in paragraph 1, the Chief Privacy Officer may, where necessary, investigate the processing status and system at any time or receive reports from relevant parties.
  • Upon becoming aware of any violation of this Act or other relevant laws in relation to personal information protection, the Chief Privacy Officer shall immediately take corrective measures.
  • The field-specific Chief Privacy Officer has the same roles and responsibilities as set forth in this Article, limited to the unit (field) classified by the “Company”.

Article 8 (Roles and Responsibilities of the Privacy Manager)

  • The privacy manager may perform the roles and responsibilities of the Chief Privacy Officer set forth in Article 7 on his/her behalf.
  • The field-specific privacy manager has the same roles and responsibilities as set forth in this Article, limited to the unit (field) classified by the “Company”.

Article 9 (Roles and Responsibilities of Personal Information Handlers)

  • A personal information handler is a person who, under the direction and supervision of the Company, processes the following duties, including employees, contract workers, dispatched workers, part-time workers, and entrusted processing companies (including their employees) under contract.
    • Processing personal information
    • Privacy-related duties delegated by the Chief Privacy Officer
    • Applying to register personal information (files) with the Chief Privacy Officer
    • Destroying personal information (files)
    • Requesting the Chief Privacy Officer to delete the registration record upon destruction of personal information (files)
    • Participating in personal information protection activities
    • Complying with and implementing this Regulation
    • Implementing the technical and administrative protection standards for personal information
  • The handler shall comply with this Regulation and related laws so that personal information is managed safely in the course of processing.
  • The handler shall inspect for any unlawful or improper infringement of personal information by staff or third parties. When a new hire or transferee joins a department, the department head shall educate and guide them on security compliance in consideration of the nature of the work.

Article 10 (Education of the Chief Privacy Officer and Managers)

The Company provides education related to personal information protection to the Chief Privacy Officer at least once a year.

Article 11 (Education of Personal Information Handlers)

  • To ensure the proper handling of personal information, the Chief Privacy Officer shall establish and implement a privacy education plan for handlers, specifying the following.
    • Education purpose and target
    • Education content
    • Education schedule and method
  • The Chief Privacy Officer records and retains the results of the privacy education (certificates of completion, attendance, etc.) or related supporting materials.

Article 12 (Management of Access Rights)

  • The Company grants access rights to the processing system differentially according to the person in charge, within the minimum scope necessary for the performance of duties.
  • When a handler changes due to transfer, resignation, or other personnel changes, the Company shall promptly change or revoke access rights to the processing system.
  • The Company records the granting, change, or revocation of rights under paragraphs 1 and 2 and retains such records for at least five years.
  • When issuing user accounts that can access the processing system, the Company shall issue a separate account for each handler and ensure that accounts are not shared with other handlers.
  • The Company applies the following so that handlers or data subjects set secure passwords on the processing system, website, etc.
    • Composed of at least 10 characters combining two or more of uppercase letters, lowercase letters, numbers, and special characters, or at least 8 characters combining three or more types
    • Avoiding easily guessable passwords such as consecutive numbers, birthdays, phone numbers, or passwords similar to the ID
    • Setting a password validity period and changing it at least once per quarter
  • The Company shall take necessary technical measures, such as restricting access to the processing system when account information or a password is entered incorrectly a certain number of times, so that only authorized handlers can access the system.

Article 13 (Access Control)

  • To prevent unauthorized internal/external illegal access and breach incidents through the information and communications network, the Company takes measures including the following.
    • Restricting access to the processing system by IP (Internet Protocol) address, etc., to limit unauthorized access
    • Analyzing IP addresses that accessed the processing system to detect and respond to illegal leakage attempts
  • When a handler accesses the processing system externally through the network, the Company applies a secure access method such as a virtual private network (VPN) or a leased line, or applies a secure authentication method.
  • The Company takes measures such as access control on the processing system, work computers, mobile devices, and management terminals so that personal information being handled is not disclosed or leaked to unauthorized persons through websites, P2P, sharing settings, or open wireless networks.
  • The Company inspects for vulnerabilities at least once a year and takes necessary supplementary measures so that unique identification information is not leaked, altered, or damaged through websites that process such information.
  • To prevent illegal access to the processing system and breach incidents, the Company ensures that system access is automatically blocked when a handler does not perform work for a certain period.
  • Where the Company processes personal information using a work computer or mobile device rather than a separate processing system, paragraph 1 may not apply, in which case the access control functions provided by the operating system (OS) or security programs of the device may be used.
  • The Company takes protective measures such as setting a password on work mobile devices so that personal information is not leaked due to loss or theft of the device.

Article 14 (Encryption of Personal Information)

  • The Company shall encrypt unique identification information, passwords, and biometric information when transmitting them over the network or delivering them via auxiliary storage media.
  • When transmitting or receiving users’ personal information and authentication information over the network, the Company shall encrypt it through measures such as building a secure server. The secure server shall have one of the following functions.
    • Installing an SSL (Secure Socket Layer) certificate on the web server to encrypt transmitted information for sending and receiving
    • Installing an encryption application on the web server to encrypt transmitted information for sending and receiving
  • The Company shall store passwords and biometric information in encrypted form. However, passwords shall be stored using one-way encryption (hash function) so that they cannot be decrypted.
  • The Company shall encrypt unique identification information when storing it in the internet zone or in the DMZ (Demilitarized Zone) between the internet zone and the internal network.
  • The Company shall encrypt unique identification information when storing it in the internal network.
  • When encrypting personal information under paragraphs 1 to 5 of this Article, the Company shall use a secure encryption algorithm for storage.
  • The Company establishes and implements procedures for the secure generation, use, storage, distribution, and destruction of encryption keys to safely store encrypted personal information.
  • The Company shall encrypt users’ personal information when storing it on computers, mobile devices, and auxiliary storage media. In particular, when storing and managing unique identification information on a work computer or mobile device, it shall be encrypted using commercial encryption software or a secure encryption algorithm before storage.

Article 15 (Retention and Inspection of Access Records)

  • The Company retains and manages handlers’ access records to the processing system for at least one year. However, for systems that process the personal information of 50,000 or more data subjects, or that process unique identification information or sensitive information, records are retained and managed for at least two years.
    • Handler identification information (account information such as ID)
    • Access date and time (date and time)
    • Access location information (the accessor’s device information or IP address)
    • Information of the data subject processed (name, ID, etc.)
    • Work performed (viewing, editing, deletion, printing, input, etc.)
  • To respond to loss, theft, leakage, forgery, alteration, or damage of personal information, the Company inspects the processing system’s access records at least once a month. In particular, if a download of personal information is detected, the Company shall verify the reason as provided in this Regulation.
  • The Company shall safely store access records on a separate physical storage device and perform regular backups so that the records are not forged, altered, stolen, or lost.

Article 16 (Prevention of Malicious Programs)

The Company shall install and operate security programs such as antivirus software that can prevent and treat malicious programs, and shall comply with the following.
  • Keeping the software up to date by using automatic update functions or updating at least once a day
  • Immediately applying updates when a malicious-program alert is issued or when the maker of an application or operating system software in use announces a security update
  • Taking response measures such as deleting detected malicious programs

Article 17 (Safeguards for Management Terminals)

To prevent personal information breaches such as leakage, the Company takes the following safeguards for management terminals.
  • Measures to prevent unauthorized persons from accessing and arbitrarily manipulating management terminals
  • Measures to prevent use for purposes other than intended
  • Applying security measures to prevent malicious-program infection

Article 18 (Establishment and Operation of the Privacy Organization)

  • For the safe processing of personal information, the Company shall establish and operate a privacy organization including the following.
    • Designation of the Chief Privacy Officer
    • Designation of managers who support the Chief Privacy Officer’s work under the CPO’s direction and supervision
    • Designation of the department that handles personal information
  • The establishment, change, and abolition of the privacy organization are determined with the CEO’s approval.
  • The handling department shall process personal information in sufficient consultation and coordination with the privacy organization.
  • The privacy organization shall perform the duties under Article 7 and may perform other matters deemed necessary by the Company to ensure the safety of personal information.

Article 19 (Response to Personal Information Leakage Incidents)

  • The Company establishes and implements a leakage incident response plan to promptly respond to and minimize damage from personal information leakage incidents.
  • The response plan under paragraph 1 includes emergency measures, leakage notification/inquiry and reporting procedures, customer complaint response measures, measures to minimize on-site congestion, measures to relieve customer anxiety, and remedies for victims.
  • In carrying out damage-recovery measures following a leakage, the Company endeavors to minimize inconvenience and economic burden to data subjects.

Article 20 (Risk Analysis and Response)

  • The Company performs risk analysis and prepares response measures, such as applying necessary security measures, so that personal information is not lost, stolen, leaked, forged, altered, or damaged.
  • The risk analysis under paragraph 1 may be performed using personal information risk analysis criteria or by identifying and evaluating risk factors.

Article 21 (Management and Supervision of Entrustees)

  • When entrusting personal information processing, the Company educates the entrustee and supervises whether it processes personal information safely, specifying the following.
    • Education and supervision targets
    • Education and supervision content
    • Education and supervision schedule and method
  • The Company keeps records of the education and supervision of entrustees under paragraph 1 and takes necessary security measures if problems are found.
  • When entrusting processing, the Company relies on a document containing the following.
    • Purpose and scope of the entrusted work
    • Period of the entrusted work
    • Matters concerning restrictions on re-entrustment
    • Matters prohibiting processing beyond the purpose of the entrusted work
    • Matters concerning security measures such as access restrictions to personal information
    • Matters concerning supervision, such as inspecting the management status of retained personal information
    • Matters concerning liability such as damages if the entrustee violates its obligations
  • When entrusting processing, the Company discloses the content of the entrusted work and the entrustee on its website.

Article 22 (Physical Safeguards)

  • Where the Company maintains a separate physical storage location for personal information, it shall establish and operate access control procedures for it.
  • The Company stores documents and auxiliary storage media containing personal information in a secure location with a locking device.
  • The Company shall prepare security measures to control the carrying in/out of auxiliary storage media containing personal information. However, this may not apply where personal information is processed using a work computer or mobile device rather than a separate processing system.

Article 23 (Safeguards for Disasters and Emergencies)

  • The Company prepares and regularly inspects response procedures such as a crisis response manual to protect the processing system in the event of disasters such as fire, flood, or power outage.
  • The Company prepares a plan for backing up and recovering the processing system in the event of a disaster or emergency.

Article 24 (Destruction of Personal Information)

  • When destroying personal information, the Company takes one of the following measures.
    • Complete destruction (incineration, shredding, etc.)
    • Deletion using a dedicated degaussing device
    • Initialization or overwriting so that data cannot be restored
  • When destroying only part of the personal information, where destruction by the methods in paragraph 1 is difficult, the Company shall take the following measures.
    • Electronic files: managing and supervising so that the information cannot be recovered or reproduced after deletion
    • Records, printouts, documents, and other media other than item 1: deleting the relevant portion by masking, perforation, etc.
  • Each handler shall periodically check whether personal information managed on the processing system or work devices such as PCs is subject to destruction due to the expiration of the retention period or achievement of the processing purpose, destroy it, and report the results to the team or department head at least once a month.
  • Each team or department head who receives a report under paragraph 3 shall verify and consolidate the destruction details and report them to the Chief Privacy Officer.

Article 25 (Designation of a Pseudonymized/Additional Information Manager)

  • For the efficient management and protection of pseudonymized information, the Company designates the CEO as the pseudonymized information manager.
  • The pseudonymized information manager performs the following roles.
    • Establishing and implementing an internal management plan for pseudonymized information
    • Inspecting and managing the implementation status of the internal management plan
    • Managing pseudonymization and adequacy review status
    • Managing and supervising pseudonymized and additional information
    • Managing the processing status and related records of pseudonymized information
    • Establishing and implementing an education plan for those who process pseudonymized information
    • Managing and supervising pseudonymization and the entrustment of pseudonymized information processing (where applicable)
    • Monitoring re-identification of pseudonymized information and establishing/implementing measures upon re-identification
    • Other matters concerning the protection of pseudonymized information processing

Article 26 (Separate Storage of Pseudonymized and Additional Information)

  • Once pseudonymization is complete, pseudonymized information shall be stored separately from the pre-pseudonymization personal information.
  • Additional information generated during pseudonymization shall be stored separately from the pseudonymized information.
  • Pre-pseudonymization personal information, pseudonymized information, and additional information shall in principle be stored physically separately; where physical separation is difficult, logical separation may be implemented.
  • Where stored logically separately, strict access control shall be applied.

Article 27 (Separation of Access Rights to Pseudonymized and Additional Information)

  • Once pseudonymization is complete, access rights to pseudonymized or additional information shall be strictly controlled with the minimum personnel and granted differentially according to duties.
  • Access rights to additional information and to pseudonymized information shall be managed separately.
  • Records of granting, changing, or revoking access rights to pseudonymized or additional information shall be kept, and such records shall be retained for at least three years.

Article 28 (Safeguards for Pseudonymized and Additional Information)

  • Pseudonymized and additional information shall be subject to the safeguards required under the Personal Information Protection Act and its Enforcement Decree.
  • Unless there is a special reason, additional information shall be deleted immediately upon generation. However, where additional information is needed for reasons such as time-series analysis, it shall be encrypted when stored.

Article 29 (Education of Those Who Process Pseudonymized Information)

  • The pseudonymized information manager shall establish and implement an education plan for the protection of pseudonymized information for those who process it.
  • The education shall include the following.
    • Matters concerning the basis for processing pseudonymized information
    • Matters concerning safeguards for pseudonymized and additional information
    • Matters concerning the prohibition of re-identification
  • Education for those who process pseudonymized information may be conducted together with privacy education, and the results or supporting materials shall be recorded and retained.

Article 30 (Preparation and Retention of Pseudonymized Information Processing Records)

  • When processing pseudonymized information, the following shall be recorded and retained in a pseudonymized information processing register.
    • Matters concerning the basis for processing pseudonymized information
    • Items of personal information pseudonymized
    • Use history of pseudonymized information
    • Recipients when provided to third parties
    • Other matters designated and announced by the Personal Information Protection Commission as necessary to manage the processing of pseudonymized information

Article 31 (Disclosure in the Privacy Policy)

  • The following matters concerning the processing of pseudonymized information shall be included and disclosed in the Privacy Policy.
    • Purpose of processing pseudonymized information
    • Processing period of pseudonymized information (optional)
    • Matters concerning provision of pseudonymized information to third parties (where applicable)
    • Matters concerning entrustment of pseudonymized information processing (where applicable)
    • Items of pseudonymized information processed
    • Matters concerning safeguards for pseudonymized information

Article 32 (Prohibition of Re-identification of Pseudonymized Information)

  • Any act of re-identifying pseudonymized information by those who process it is strictly prohibited.
  • If a specific individual is re-identified while processing pseudonymized information, processing shall be stopped immediately, the pseudonymized information manager shall be notified, and measures shall be taken immediately according to the established re-identification response plan.

Article 33 (Use/Provision of Personal Information Beyond the Purpose)

In principle, the Company shall not use or provide personal information beyond the scope of the original collection purpose. However, in any of the following cases, except where there is a risk of unfairly infringing the interests of a data subject or a third party, the Company may use personal information beyond the purpose or provide it to a third party.
  • Where separate consent is obtained from the data subject
  • Where there is a special provision in another law
  • Where it is clearly necessary for the life, body, or property interests of the data subject or a third party
  • Where the duties under the jurisdiction of another law cannot be performed without such use or provision, subject to deliberation and resolution by the Protection Commission
  • Where necessary to provide to a foreign government, etc. to implement a treaty or international agreement
  • Where necessary for the investigation of a crime and the institution and maintenance of a prosecution
  • Where necessary for a court’s trial-related duties
  • Where necessary for the execution of a sentence, custody, or protective disposition

Article 34 (Processing of Personal Information for Sign in with Google)

This Article sets out matters concerning the processing of personal information when a user signs in to Playboard (playboard.co), operated by the Company, using “Sign in with Google”, and complies with the Google API Services User Data Policy.
  • (Data collected and purpose of use) Through Google OAuth, the Company receives the user’s name, email address, profile picture, and Google account unique identifier, and uses them for account creation and sign-in authentication, user identification, and displaying the user’s profile within the service. The Company requests only the minimum information necessary for sign-in and does not access any other Google data such as Gmail, Google Drive, or contacts.
  • (Limitation of use) The Company uses the data in item 1 solely to provide and improve the service.
  • (Limitation of provision and sharing) The Company does not sell the data in item 1 to third parties, and does not provide or disclose it to third parties except where it is provided to an entrustee that processes personal information under contract for service operation, where required by applicable law, or where the user has given separate consent. Details of entrustment and use beyond the purpose follow Articles 21 and 33.
  • (Retention and destruction) The Company retains the data in item 1 while the user’s account remains active, and destroys it when it becomes unnecessary, such as upon deletion of the user’s account or achievement of the processing purpose. The procedures and methods of destruction follow Article 24.
  • (User control) The Company protects the data in item 1 through measures such as encryption in transit (SSL/TLS) and access control; other technical, administrative, and physical safeguards follow Articles 12 to 24 of this Policy. Users may revoke the service’s access to their Google Account at any time on the Google Account permissions page, and may request access to, correction of, or deletion of their personal information. Inquiries may be directed to the contact set out in Article 6.

Addendum

This personal information protection management regulation applies from July 14, 2026.