Privacy Policy
Effective date: September 1, 2026 · This is a courtesy translation. The Korean version is authoritative.
JinaZen (the "Company") establishes and discloses this privacy policy pursuant to Article 30 of the Personal Information Protection Act of Korea, to protect the personal information of data subjects and to handle related grievances promptly.
· Website (jinazen.com): the Company collects and stores personal information. (Part 1)
· App "JinaZen Fortune Graph": the Company does not collect personal information; data is stored only on the user's device. (Part 2)
Part 1 · Website (jinazen.com)
Article 1 (Purposes of processing)
- Enquiries and grievance handling — identity verification, confirming the matter, contact for fact-finding, notifying results
The website offers no membership registration, and no goods or services are sold or paid for on the website.
Article 2 (Items processed)
- Enquiries and grievance handling — whatever the enquirer chooses to write when contacting us (name, email address or phone number, and the content of the enquiry). The Company does not request specific fields.
- Automatically generated — IP address, access date and time, and other service access logs
The Company collects neither passwords nor payment information on the website.
Article 3 (Retention periods)
- Enquiries and grievance handling: 3 years after the matter is resolved
- Access logs: 3 months (the retention period for internet logs and access tracking data under the Protection of Communications Secrets Act)
Information is destroyed without delay once the period ends, except where an investigation into a violation of law is ongoing, in which case it is retained until that investigation concludes.
Article 4 (Provision to third parties)
① The Company processes personal information only within the scope of Article 1 and provides it to third parties only with the data subject's consent or where Articles 17 and 18 of the Personal Information Protection Act apply.
② The Company currently provides no personal information to any third party. Should that change, it will be disclosed through this policy without delay.
Article 5 (Outsourcing)
Outsourcing contracts specify prohibition of processing beyond the entrusted purpose, technical and managerial safeguards, restrictions on re-outsourcing, supervision, and liability. Changes to the scope or processor will be disclosed through this policy without delay.
Transfers of personal information abroad are as follows.
Countries: the United States and other countries where Cloudflare operates data centres
Timing and method: transmitted over the network as visitors access the website
Items: IP address, access date and time, and other service access logs
Purpose: website hosting and content delivery
Retention: until the outsourcing contract ends
Contact: privacy@cloudflare.com
Kakao Corp. is a domestic provider, and that outsourcing involves no transfer abroad.
Article 6 (Cookies)
The Company does not use cookies on the website. It installs no automatic collection device that stores or retrieves information in the user's browser, and uses no advertising or analytics tracking tools.
The access logs in Article 2(2) are generated automatically by the web server in the course of providing the service. Should cookies be introduced, their purpose and how to refuse them will be stated in this policy and disclosed without delay.
Part 2 · The App "JinaZen Fortune Graph"
Article 7 (The Company collects no personal information in the app)
- All information entered in the app is stored only inside the user's device.
- It is not transmitted to the Company's servers, and the Company cannot access it.
- The Company does not collect, store, or use users' consultation records or client information.
Article 8 (Information users enter in the app)
Users (consultants) may enter: client information (name, gender, date of birth, time of birth, topics of interest) and consultation records (notes, session history). The data controller for this information is the user (the consultant or their business). The Company merely provides the tool; responsibility for collection, use, storage, and destruction rests with the user, who must obtain necessary consent from clients and manage the data safely under applicable law.
Article 9 (Storage and destruction)
- Entered information is kept in the device's internal storage and is not transmitted externally.
- Deleting a client in the app deletes that information; uninstalling the app deletes all stored information.
- If the backup feature is used, custody and management of backup files are the user's responsibility.
Article 10 (Purchase information)
The app is sold through Google Play; payment and purchase verification are handled by Google. The Company does not collect or store payment credentials. The app communicates with Google Play for purchase verification, and no personal information is transferred to the Company in that process.
Part 3 · Common Provisions
Article 11 (Rights of data subjects)
Data subjects may at any time request access, correction, deletion, or suspension of processing, in writing or by email, and the Company will act without delay. Where correction or deletion is requested, the data will not be used or provided until completed. Rights may be exercised through a legal representative or authorized agent. For client information entered in the app, requests must be directed to the user (consultant) who entered it; the Company does not hold that information and cannot process such requests on their behalf.
Article 12 (Destruction)
Personal information is destroyed without delay when it becomes unnecessary. Where retention is required by other laws, it is kept separately. Electronic files are destroyed irrecoverably; paper records are shredded or incinerated.
Article 13 (Safeguards)
- Managerial: internal management plans
- Technical: access-rights management, access control, security software
- Physical: access control of storage locations
Article 14 (Privacy officer)
Article 15 (Requests for access)
Article 16 (Remedies)
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.police.go.kr/minwon/main)
Article 17 (Business information)
Address: 14F #1403, 36 Kkotmaeul-ro, Deogyang-gu, Goyang-si, Gyeonggi-do, Republic of Korea
Email: jina@jinazen.com
Article 18 (Effective date and changes)
① This policy applies from September 1, 2026.
② It supersedes the previous policy (effective August 19, 2026). A copy of the previous policy is available on request through the contact below.
③ Reason for amendment: the website was settled as an information-and-enquiry site with no membership or payment, so items never actually processed (passwords, payment information) and retention periods that do not apply (e-commerce records) were removed, and the outsourcing and overseas-transfer entries were updated for the change of hosting provider to Cloudflare. The current absence of cookies is now stated explicitly.