# Privacy Policy of PrestoWorks.ai

**Last Updated: May 16, 2025**

#

PIXTREE Inc. (hereinafter referred to as the "Company") complies with the Personal Information Protection Act and relevant laws to protect the freedom and rights of data subjects, and lawfully processes and safely manages personal data. Pursuant to Article 30 of the Personal Information Protection Act, this Privacy Policy is established and disclosed to inform data subjects of the procedures and standards regarding the processing and protection of personal information, and to facilitate the prompt and smooth resolution of related grievances.

---

## Article 1 (Purpose of Collecting and Using Personal Information)

The Company processes personal information for the following purposes. The processed personal information shall not be used for purposes other than those specified below, and should the purpose of use change, the Company will obtain separate consent pursuant to Article 18 of the Personal Information Protection Act.

1. Membership Registration and Management

   To verify membership intent, identify and authenticate users for membership-based services, maintain and manage membership, prevent fraudulent use of services, provide notifications, and handle customer inquiries.

2. Provision of Services

   To operate and improve the services, send contracts and invoices, provide content and customized services, perform email verification, and facilitate billing and payment.

---

## Article 2 (Items of Personal Information Collected and Method of Collection, Processing, and Retention)

The Company collects and uses the minimum necessary personal information for service provision, in accordance with the Personal Information Protection Act.

1. Items processed without the data subject's consent

   | Purpose                      | Legal Basis                                          | Collected Items                                                                      |
   | ---------------------------- | ---------------------------------------------------- | ------------------------------------------------------------------------------------ |
   | Membership Service Operation | Article 15(1)4 of the PIPA ("Contractual necessity") | ID (email address), password                                                         |
   | Customer Support (A/S)       | Article 15(1)4 of the PIPA                           | Service usage history                                                                |
   | Order and Payment Processing | Article 15(1)4 of the PIPA                           | ID, order history, payment information (credit card data managed by payment gateway) |
   | User Data                    | Article 15(1)4 of the PIPA                           | Uploaded video files, processed output files, metadata (collected during use)        |

---

## Article 3 (Processing of Personal Information of Children Under 14)

The Company restricts membership registration by individuals under the age of 18. During registration, users must confirm that they are over 18, and if not, the registration process cannot proceed.

_However, users must accurately enter their age, and all legal liabilities arising from misrepresentation of age rest with the user._

---

## Article 4 (Destruction of Personal Information)

1. The Company shall promptly destroy personal information when the retention period has expired or the processing purpose has been fulfilled.
2. If retention is required under other laws despite the expiration of the consented retention period or fulfillment of the processing purpose, such information shall be stored in a separate database or storage location. (See Article 2 for details.)

**Procedures and Methods of Destruction:**

- **Procedure:** Personal data subject to destruction is selected and destroyed upon approval from the Personal Information Protection Officer.
- **Method:** Personal data in electronic form is irreversibly deleted; paper documents are shredded or incinerated.

---

## Article 5 (Provision of Personal Information to Third Parties)

1. The Company does not provide personal information to third parties unless consent is obtained or it is permitted under Articles 17 and 18 of the Personal Information Protection Act.
2. Exceptions include:
   - Where required by law
   - For payment processing (provided to payment gateways)
3. In emergencies such as disasters, infectious diseases, or imminent threats to life or property, the Company may provide personal information to relevant authorities without the user's consent.
4. Overseas transfers are outlined in Article 7.

---

## Article 6 (Criteria for Additional Use or Provision Without Consent)

Pursuant to Article 15(3) or Article 17(4) of the Personal Information Protection Act and Article 14-2 of the Enforcement Decree, the Company may process or provide personal information without consent by considering the following:

| Recipient       | Country       | Items               | Purpose            | Timing and Method        | Retention Period                                               |
| --------------- | ------------- | ------------------- | ------------------ | ------------------------ | -------------------------------------------------------------- |
| Payment Gateway | United States | Credit card details | Payment processing | As needed over a network | Until cancellation of service subscription or account deletion |

The data subject can reasonably expect this based on the nature of subscription-based services.

---

## Article 7 (Cross-border Collection and Transfer of Personal Information)

The Company collects and transfers personal information to the following overseas entities for the operation of PrestoWorks.ai:

1. **Legal Basis :** Article 28-8(1)3(a) of the PIPA (outsourcing or storing for contractual performance)
2. **Items :** Email (ID), password, user data (uploads, results), service logs, credit card information
3. **Country :** United States
4. **Method :** Transferred via network during service use
5. **Recipients :**
   - Amazon Web Services, Inc. (aws.amazon.com)
   - Payment gateway provider (to be specified)
6. **Purpose :** Cloud-based processing and billing
7. **Retention :** As detailed in Article 2
8. **Right to Refuse :** Refusal to allow overseas transfer will result in inability to use the service. Users may withdraw via My Account > Delete Account or by contacting support@pixtree.com

---

## Article 8 (Measures to Ensure Security of Personal Information)

The Company takes the following measures to secure personal data:

1. **Administrative:** Internal management plans, dedicated teams, regular training
2. **Technical:** Access control, access logs, data encryption
3. **Physical:** Restricted access to server rooms

_Note: Internet-based data transmission is inherently insecure. The Company implements best-effort safeguards but cannot guarantee absolute security. Users are advised to use strong, unique passwords and refrain from account sharing._

---

## Article 9 (Rights of Data Subjects and Legal Representatives)

1. Data subjects may request access, correction, deletion, restriction, withdrawal of consent, or explanations regarding automated decisions at any time.
2. Requests can be made via writing, email, or fax in accordance with Article 41(1) of the Enforcement Decree.
   - Users may view, modify, or delete their information via My Account on prestoworks.ai or request access via support@pixtree.com.
   - Withdrawal of consent is available via the Delete Account feature.
3. Rights may be exercised by an authorized agent with a signed power of attorney (Form No. 11 under the Notice on Personal Data Processing Methods).
4. Requests for access or restriction may be limited per Articles 35(4) and 37(2) of the PIPA.
5. Deletion cannot be requested where required by law.
6. Automated decisions cannot be refused if consented or contractually notified; however, explanations may still be requested.
7. The Company verifies the identity of requesters.

**Contact for Rights Requests:**

- **Department:** Marketing Department
- **Address:** #509, 20 Digital-ro 31-gil, Guro-gu, Seoul, Korea
- **Tel:** +82-2-2007-7580
- **Email:** shson@pixtree.com
- **Fax:** +82-2-564-7845

---

## Article 10 (Personal Information Protection Officer)

The Company designates the following individual as the Personal Information Protection Officer responsible for overseeing privacy matters:

- **Name :** Sehoon Son
- **Position :** Department Head
- **Tel :** +82-2-2007-7580
- **Email :** shson@pixtree.com
- **Fax :** +82-2-564-7845

**Privacy Inquiry Department:**

- **Department :** Marketing Department
- **Email :** support@pixtree.com

---

## Article 11 (Remedies for Infringement of Rights)

Data subjects may contact the following agencies for redress or consultation in case of personal data infringement:

1. Personal Information Dispute Mediation Committee: (Republic of Korea) 1833-6972 / www.kopico.go.kr
2. Personal Information Infringement Report Center: (Republic of Korea) 118 / privacy.kisa.or.kr
3. Supreme Prosecutors' Office: (Republic of Korea) 1301 / www.spo.go.kr
4. Cyber Bureau, National Police Agency: (Republic of Korea) 182 / ecrm.cyber.go.kr

You may also contact our internal department for any concerns:

- **Department :** Marketing Department
- **Tel :** +82-2-2007-7580
- **Email :** support@pixtree.com
- **Fax :** +82-2-564-7845

---

## Article 12 (Changes to the Privacy Policy)

1. This Privacy Policy is effective as of May 23, 2025.
2. It may be amended due to legal or policy changes. Amendments will be notified in advance on the website.
3. Previous versions :

   \- None
