Liberta

Privacy Policy

Version 1.2 · Effective September 29, 2026

LIBERTA ENM Co., Ltd. (the "Company") establishes and discloses this Privacy Policy in order to protect the personal information of users of the Liberta website and mobile app (the "Service") in accordance with the Personal Information Protection Act (「개인정보 보호법」) and other applicable laws, and to promptly handle any related complaints.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information is not used for any other purpose, and where a purpose changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act. 1. Membership registration and management: confirming the intent to register, email verification, social login, member identification, confirming that the user is aged 14 or over, preventing misuse, and sending notices 2. Provision of goods and services: selling products, receiving orders, payment, delivery, and processing cancellations, returns, exchanges, refunds, pickups and inspections 3. Event operation: fansign entries, draws and winner notices; issuing video-call tickets and notifying session schedules 4. Customer support: receiving and handling 1:1 inquiries, and handling consumer complaints and disputes 5. Service notifications: order, delivery, draw result and other service notices by email and app push 6. Marketing (only with optional consent): notices of new products and events, and newsletters 7. Service security and record keeping: managing key usage records such as log-ins and consent changes, preventing misuse, and retaining transaction records as required by law

Article 2 (Personal Information Processed and Collection Methods)

(1) The Company processes the following personal information at each stage of using the Service. 1. Sign-up with email - Required: email address, password, nickname - Optional: mobile phone number - The Company confirms at sign-up that the user is aged 14 or over, and does not collect date of birth. 2. Social login (where chosen by the user) - Google: unique identifier, email address, name - Apple: unique identifier, email address - Naver: unique identifier, email address, name or nickname - Where a social account does not provide an email address, the Company generates an arbitrary address to identify the account. 3. Orders and delivery - Required: recipient name, phone number, country, postal code, address, detailed address (city, for overseas delivery) - Generated during ordering: order number, payment ID, ordered items and amounts, courier and tracking number, reasons for and history of cancellations, returns and exchanges, refund history, and consents given at purchase - Payment: the buyer's name, phone number and email address are passed to the payment window of the payment gateway (PG). Payment details such as card numbers are processed directly by the payment gateway, and the Company does not store them. 4. Event participation - Fansign entries (number of entries), draw results and wins, video-call tickets, session schedules and access codes 5. 1:1 inquiries - Inquiry type, subject, message, related order (optional) 6. Mobile app - Device token for app push notifications (push token), device operating system, device language, push notification settings 7. Information automatically generated or collected while using the Service - Service usage records (dates and times of log-ins, withdrawal, changes to marketing consent, etc.), consent history for the Terms and this Privacy Policy (date/time and document version), notification history, and access records (access date/time, IP address, etc.) (2) Personal information is collected in the following ways. 1. Entered directly by the user on Service screens such as sign-up, orders and inquiries 2. Received from the social login provider where the user chooses social login 3. Automatically generated or collected while using the Service (cookies, app push registration, access records, etc.) (3) Users may sign up for and use the Service without providing optional items or consenting to marketing.

Article 3 (Processing and Retention Periods)

(1) The Company destroys personal information without delay upon withdrawal from membership or once the purpose of processing has been achieved. However, the following information is retained for the periods stated, for the reasons below. 1. Retention required by law - Records of contracts or withdrawal of offers: 5 years (Act on the Consumer Protection in Electronic Commerce, etc. (「전자상거래 등에서의 소비자보호에 관한 법률」)) - Records of payment and supply of goods: 5 years (same Act) - Records of consumer complaints or dispute handling: 3 years (same Act) - Records of labelling and advertising: 6 months (same Act) - Service access records (log records, IP addresses, etc.): 3 months (Protection of Communications Secrets Act (「통신비밀보호법」)) 2. Retention under the Company's internal policy - Consent history for the Terms, this Privacy Policy and marketing: 5 years after withdrawal, as proof of consent - Fansign entry and win history and video-call ticket history: 5 years, together with the transaction records of the related order - 1:1 inquiry history: 3 years, as records of consumer complaints and dispute handling - Service usage records (log-ins, consent changes, etc.) and records of administrators' access to personal information: 1 year, to prevent misuse and protect personal information - Information for restricting re-registration: a hash of the withdrawn email address (a transformed value, not the original) is kept for 48 hours after withdrawal and then deleted - Email verification codes: valid for 5 minutes and deleted 30 days after expiry - Notification history: deleted 1 year after sending (2) Where there is an ongoing order or an open cancellation, return or exchange, the user may withdraw once that transaction has been completed, so that it can be fulfilled.

Article 4 (Procedure and Method of Destruction)

(1) The Company destroys personal information without delay when it is no longer needed, for example when the retention period has expired or the purpose of processing has been achieved. (2) Where personal information must be kept under applicable laws, the Company stores and manages it separately and destroys it without delay once the retention period expires. (3) Procedure: upon withdrawal, social login links, shipping addresses, push tokens and verification data are deleted immediately, and the account's email address, password, nickname and phone number are anonymized so that they cannot be restored. Information with a set retention period is destroyed through a daily automated process, starting with the information whose period has expired. (4) Method: information in electronic files is deleted using technical methods that prevent recovery or reproduction, and personal information printed on paper is shredded or incinerated.

Article 5 (Provision of Personal Information to Third Parties)

(1) The Company processes personal information only within the scope set out in Article 1, and provides it to third parties only in the cases set out in Articles 17 and 18 of the Personal Information Protection Act, such as with the user's consent or under special provisions of law. (2) The Company does not currently provide personal information to third parties. Information required for event operation, such as lists of fansign and video-call winners, is managed directly by the Company and is not provided to artists or their agencies.

Article 6 (Entrustment of Processing)

(1) The Company entrusts the processing of personal information as follows to provide the Service smoothly. - Toss Payments Co., Ltd.: payment processing, and payment approval, cancellation and refund - Korea PortOne Co., Ltd.: payment integration and relaying payment look-ups and cancellations - Amazon Web Services, Inc.: servers, databases and file storage for operating the Service (Seoul region, Republic of Korea), and sending email (Amazon SES) - Couriers (CJ Logistics, Korea Post parcel service, or the courier used for each order): delivery of products - 650 Industries, Inc. (Expo), Google LLC (Firebase Cloud Messaging) and Apple Inc. (Apple Push Notification service): sending app push notifications (2) When entering into an entrustment contract, the Company specifies in the contract or other documents, in accordance with Article 26 of the Personal Information Protection Act, the prohibition of processing beyond the entrusted work, technical and managerial safeguards, restrictions on re-entrustment, the management and supervision of the entrustee, and liability such as compensation for damages, and supervises whether the entrustee processes personal information securely. (3) If the entrusted work or the entrustee changes, the Company will disclose it through this Privacy Policy without delay.

Article 7 (Transfer of Personal Information Overseas)

(1) The Company transfers personal information overseas as follows to send push notifications in the mobile app. This is an entrustment necessary to perform the service contract with the user, under Article 28-8(1)3 of the Personal Information Protection Act. - Recipients: 650 Industries, Inc. (Expo) / Google LLC / Apple Inc. - Country: United States - Items transferred: push token, device operating system, notification content - Time and method: transmitted over the network when push notifications are registered in the app and when notifications are sent - Purpose: sending app push notifications - Retention period: until the purpose of sending the notification is achieved (in accordance with each company's policy) (2) Users may refuse the overseas transfer by turning off push notifications in My Page or revoking the app's notification permission. In that case they will not receive app push notifications, but other use of the Service is not affected. (3) The Service's servers, databases and files are stored in the Republic of Korea (Amazon Web Services Seoul region).

Article 8 (Rights and Obligations of Users and Legal Representatives, and How to Exercise Them)

(1) Users may at any time request the Company to provide access to, correct, delete or suspend the processing of their personal information, or withdraw their consent. (2) Users may exercise their rights directly in My Page as follows. - View and edit member information: change nickname, email address and password - View, add and delete shipping addresses - Give or withdraw marketing consent, and set app push notifications - View order, entry, video-call, notification and inquiry history - Withdraw from membership (withdrawal of consent) (3) Other rights may be exercised by request in writing, by email or otherwise through 1:1 Inquiry or to the privacy officer in Article 12. The Company will act within the period set by the Enforcement Decree of the Personal Information Protection Act (10 days from receipt of the request) and notify the user of the result. (4) Rights may be exercised through a representative, such as the user's legal representative or a person authorized by the user. In that case, a power of attorney in the form of Annex 11 of the Notice on Methods of Processing Personal Information must be submitted. (5) Requests for access and suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act, and deletion may not be requested for personal information that other laws specify must be collected. (6) The Company verifies that the person making a request is the user or a legitimate representative. (7) Users may opt out of advertising emails such as newsletters at any time through the unsubscribe link at the bottom of the email or the marketing settings in My Page.

Article 9 (Personal Information of Children Under 14)

The Company does not accept membership registration from children under 14 and confirms at sign-up that the user is aged 14 or over. If the Company becomes aware that personal information of a child under 14 has been collected, it will destroy that information without delay.

Article 10 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act. 1. Managerial measures: minimizing personal information handling rights, and managing access rights by administrator role 2. Technical measures: one-way encryption of passwords, encrypted communication across the Service (HTTPS), managing access rights to and keeping access records of the personal information processing system, locking accounts after repeated failed log-ins, separate permission for bulk download of personal information, and storing app log-in data in the device's secure storage 3. No storage of payment details: payment details such as card numbers are processed by the payment gateway and are not stored by the Company.

Article 11 (Installation, Operation and Refusal of Automatic Collection Tools)

(1) The Company uses one cookie (liberta_token, valid for 30 days) to keep users logged in. The mobile app stores log-in data in the device's secure storage to keep users logged in. (2) The Company does not use cookies or tracking tools for advertising or behavioural analysis (such as Google Analytics or advertising pixels), and does not collect, use or provide behavioural information for personalized advertising. (3) Users may refuse or delete cookies in their web browser settings (e.g. Chrome: Settings > Privacy and security > Third-party cookies; Safari: Settings > Privacy). If the log-in cookie is refused, services that require log-in may be difficult to use.

Article 12 (Privacy Officer)

The Company designates the following privacy officer, who is responsible for overseeing the processing of personal information and for handling users' complaints and remedies related to it. - Name: Seungnam Kim - Contact: music@libertaenm.com Users may contact the privacy officer or use 1:1 Inquiry in My Page for any inquiry, complaint or remedy relating to the protection of personal information arising from use of the Service, and the Company will respond and act without delay.

Article 13 (Remedies for Infringement of Rights)

Users may apply to the following bodies for dispute resolution or counselling regarding infringement of personal information. - Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr) - Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr) - Supreme Prosecutors' Office: 1301 (www.spo.go.kr) - Korean National Police Agency: 182 (ecrm.police.go.kr)

Article 14 (Changes to this Privacy Policy)

(1) This Privacy Policy applies from 1 October 2026. (2) Where this Policy is added to, deleted or amended, the Company will give notice through Service announcements or the Privacy Policy page from 7 days before the effective date, or from 30 days before where the change significantly affects users' rights. (3) Previous versions of this Privacy Policy can be found in the revision history on the Privacy Policy page.

Previous versions

  • Version 1.1 · Effective September 29, 2026
  • Version 1.0 · Effective September 3, 2026