Kampung Korea Privacy Policy (Individual Members)
Effective date: 1 August 2026
Globalkorea (hereinafter the “Company”) establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) of the Republic of Korea, in order to protect the personal information of data subjects and to handle related complaints promptly and smoothly. This Policy is the standard the Company observes so that users can use the Kampung Korea mobile app and all related services (the “Service”) with confidence. Kampung Korea is a service for the Indonesian and Southeast Asian community residing in Korea. In case of any discrepancy, the Korean-language version of this Policy prevails.
Article 1. Purposes of Processing, Items Collected, and Retention/Use Period
The Company processes personal information for the following purposes and does not use it for any purpose other than those listed below. If the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.
| Service | Purpose of collection | Items collected |
|---|---|---|
| Sign-up | Confirming intent to join, identifying and verifying the member, providing and managing member services, preventing fraudulent use, and sending notices and alerts | Email, password, name (username), nationality, gender, date of birth |
| Social (SNS) sign-up | Same as above | SNS account email, name (username), nationality, gender, date of birth |
| Profile and community activity | Building your profile and providing services such as forums, communities, and events | Profile photo, bio, and posts (articles, comments, community listings, uploaded photos) |
| Location-based services (optional) | Calculating prayer times and sorting nearby mosques, halal restaurants, and attractions and similar location-based features | Approximate location (device location) |
| Home location saving (optional) | Providing information tailored to your residence (viewable only by you; not shown to other users) | Address, map coordinates |
| Paid / marketplace services | Purchasing and paying for goods, order processing, and settlement of charges | Payment information (payment-related information processed through the payment gateway (PG)), order history |
| Customer inquiries and support | Verifying identity, confirming the inquiry, contacting/notifying for fact-finding, and communicating the outcome | Name, contact, email, inquiry content |
| Automatically collected during use | Access management, providing the usage environment, understanding usage, sending push notifications, error diagnosis and service stabilization, and providing customized information | IP address, cookies, visit date/time, service usage records, mobile device information, push token, error/diagnostic (crash) information |
The retention and use period for each item follows Article 4.
Article 2. Provision of Personal Information to Third Parties
1. The Company processes personal information only within the scope specified in Article 1 and does not provide personal information to third parties except with the consent of the data subject or where Articles 17 and 18 of PIPA apply.
2. The Company currently does not provide personal information to third parties. For recruitment/job listings, the Company does not forward an applicant’s personal information to the hiring company; users apply directly to that company through the external application link or email shown in each listing (the Company neither stores nor relays that information).
3. In accordance with the government’s joint “Rules on Processing and Protecting Personal Information in Emergencies,” the Company may provide personal information to relevant authorities without the data subject’s consent in emergencies such as disasters, infectious diseases, incidents posing imminent danger to life or body, or imminent property loss.
Article 3. Consignment (Outsourcing) of Personal Information Processing
1. For the smooth provision of the Service, the Company consigns personal information processing tasks as follows.
| Consignee | Consigned task | Retention/use period |
|---|---|---|
| Supabase Inc. | Database, authentication, and file storage operation | Until the end of the consignment contract or member withdrawal |
| Google (Firebase Cloud Messaging, Crashlytics) | Push notification delivery, error/crash diagnostics | Until the end of the consignment contract |
| OneSignal | Push notification delivery | Until the end of the consignment contract |
| Tawk.to | In-app customer support | Until the end of the consignment contract |
| Korea Cyber Payment (KCP), PortOne | Payment processing (credit card, KakaoPay and other easy payments) | Until the end of the consignment contract |
2. When entering into a consignment contract, the Company specifies in the contract, in accordance with Article 26 of PIPA, matters such as the prohibition of processing personal information beyond the purpose of the consigned work, technical and administrative safeguards, restrictions on re-consignment, management and supervision of the consignee, and liability including damages, and supervises whether the consignee processes personal information safely.
3. If the content of the consigned work or the consignee changes, the Company will disclose it through this Policy without delay.
Article 3-2. Overseas Transfer of Personal Information
To provide the Service, the Company transfers (consigns) personal information overseas as follows. The transferred personal information consists of the items generated/collected in the course of using the Service, and the method of transfer is transmission over the information and communications network at the time of use.
| Transferee | Country | Items transferred | Purpose · Retention period |
|---|---|---|---|
| Supabase Inc. (AWS infrastructure) | United States and other countries where the service infrastructure is located | Items collected under Article 1 | Database/authentication/storage / until member withdrawal |
| Google LLC | United States and others | Push token, device/error diagnostic information | Push delivery/crash diagnostics / until the end of the consignment |
| OneSignal | United States | Push token, device information | Push delivery / until the end of the consignment |
Under Article 28-8 of PIPA, the data subject may refuse the overseas transfer of personal information; if refused, use of some services may be restricted.
Article 4. Retention and Use Period of Personal Information
1. The Company processes and retains personal information within the retention/use period required by law or consented to by the data subject.
2. The processing and retention period of each type of personal information is as follows.
- Membership sign-up and management: until member withdrawal
- Profile/community activity information: until member withdrawal or deletion of the post
- Paid/marketplace services: until completion of service provision (subject to the statutory retention periods below)
- Customer support and inquiries: 1 year from the date of processing
- Automatically collected information: until member withdrawal
3. Notwithstanding paragraph 2, the following information is retained for the corresponding period pursuant to relevant laws.
- Records on contracts or withdrawal of subscription, payment, and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records on consumer complaints or dispute handling: 3 years (same Act)
- Records on labeling/advertising: 6 months (same Act)
- Records on transactions such as tax invoices and receipts: 5 years (Value-Added Tax Act, Framework Act on National Taxes)
- Records of computer communications/internet logs and access-location tracking data: 3 months (Protection of Communications Secrets Act)
4. The Company converts the personal information of users who have not used the Service for one year into a dormant account and stores it separately; except where relevant laws specifically provide otherwise, it does not use or provide such information. At least 30 days before dormancy conversion, the Company notifies the user by email or similar means of the fact of separate storage, the scheduled date, and the items. Normal service is restored upon login before conversion or after conversion.
Article 5. Procedure and Method of Destroying Personal Information
1. When personal information becomes unnecessary due to the expiry of the retention period, achievement of the processing purpose, etc., the Company destroys it without delay.
2. Where personal information must be retained under other laws, the Company moves it to a separate database or stores it in a different location.
3. Destruction procedure and method:
- Procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the personal information protection officer.
- Method: Electronic files are deleted using technical methods that make them unrecoverable; paper documents are shredded or incinerated.
Article 6. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
1. Data subjects may at any time request access to, correction, deletion, or suspension of processing of their personal information, and may directly view/edit their information or manage location/notification permissions from the profile screen in the app.
2. Rights may be exercised in writing, by email, etc. pursuant to Article 41(1) of the Enforcement Decree of PIPA, and the Company will act without delay.
3. Rights may be exercised through a representative, in which case a power of attorney must be submitted.
4. Requests for access to or suspension of processing of personal information may be restricted under Articles 35(4) and 37(2) of PIPA, and deletion may not be requested for personal information that other laws specify as a collection target.
5. The Company verifies whether the person making a request for access, correction, deletion, or suspension of processing is the data subject or a legitimate representative.
Article 7. Measures to Ensure the Safety of Personal Information
- Administrative measures: establishing and implementing an internal management plan, minimizing access privileges, and regular training
- Technical measures: managing access privileges to and controlling access to the personal information processing system, encrypting personal information, and installing/updating security programs
- Physical measures: access control to the systems where personal information is stored
Article 8. Installation, Operation, and Refusal of Automatic Collection Devices (Cookies, etc.)
1. The Company may use cookies, similar technologies, and device identifiers to provide customized services to users.
2. Users may refuse the storage of cookies/identifiers through device or browser settings, or limit customized features through the app’s permission settings; in that case, use of some customized services may be restricted.
Article 9. Personal Information Protection Officer
The Company designates a personal information protection officer as follows to take overall responsibility for personal information processing and to handle complaints and remedy damages of data subjects.
- Personal Information Protection Officer: RAMLI FERRY FERDINAL (Representative of Globalkorea)
- Contact: [email protected]
Data subjects may direct any privacy-related inquiries, complaints, or damage-relief requests arising from use of the Service to the contact above, and the Company will respond and act without delay.
Article 10. Requests for Access to Personal Information
Data subjects may file a request for access to personal information under Article 35 of PIPA with the following, and the Company will strive to process it promptly.
- Receipt and processing: Personal Information Protection Officer ([email protected])
Article 11. Remedies for Infringement of Rights
Data subjects may apply for dispute resolution or counseling to the following organizations to obtain relief from personal information infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.cyber.go.kr)
A person whose rights or interests have been infringed by a disposition or omission made by the head of a public institution regarding a request under Articles 35, 36, and 37 of PIPA may file an administrative appeal under the Administrative Appeals Act (Central Administrative Appeals Commission: 110, simpan.go.kr).
Article 12. Changes to This Privacy Policy
1. This Privacy Policy is effective as of 1 August 2026.
2. Content may be added, deleted, or changed in accordance with changes in laws, policies, or security technology. In such cases, the Company will announce the reason and content of the change through the app or website at least 7 days in advance. However, where there is a material change to users’ rights, such as a change to the items collected or the purpose of use, the Company will give notice at least 30 days in advance.
- Company name: Globalkorea (글로벌코리아)
- Representative: RAMLI FERRY FERDINAL
- Address: 903, 42-11 Gyeongwon-daero 1367beon-gil, Bupyeong-gu, Incheon, Republic of Korea
- Business registration number: 669-20-01150
- Mail-order business registration number (통신판매업): 2026-Incheon Bupyeong-1235
- Contact: 010-2923-1379 / [email protected]