Privacy Policy
Effective 22 September 2026 · Kijoli, 330 Dosan-daero, Gangnam-gu, Seoul, 06040, Republic of Korea, publishes this policy for visitors to its English-language editorial website.
1. Scope
This policy explains how Kijoli handles information supplied through contact forms and information generated when the site is visited. It applies to kijoli pages, resources, and communications operated from the stated office. It does not govern third-party websites linked from our pages. Those services publish their own notices.
2. Information collected
We may receive a name, email address, and message when a visitor contacts the editorial desk. Server logs may record an IP address, browser type, requested page, referrer, and timestamp for security and reliability. We do not request wallet keys, recovery phrases, financial account details, or sensitive identity documents. Please do not include them in a message.
3. Purpose and legal basis
Contact details are used to answer correspondence, assess corrections, and protect the service. The basis is consent where a visitor submits a form and legitimate interest where limited logs are needed to prevent abuse and maintain security. A visitor may withdraw consent by contacting us, although withdrawal does not affect earlier lawful processing. We do not use editorial correspondence for automated eligibility decisions.
4. Retention
Routine contact messages are retained for 24 months after the last meaningful exchange, then deleted or anonymised. Security logs are normally retained for 90 days unless a longer period is necessary to investigate abuse or comply with a lawful request. Correction records may remain with an article for as long as the article is published because they explain its history. We review retention each January.
5. Cookies
The site uses a cookie-choice item named cookieChoice in local browser storage to remember whether a visitor selected Accept or Reject. It has no server-side account function. If optional analytics are enabled in a future deployment, the service and lifespan will be named in this policy before activation. Essential session technology, if introduced for a form, will expire when the session ends or within 24 hours.
6. Processors
Hosting, security, email delivery, and analytics providers may process limited technical information on Kijoli’s instructions. Providers receive only what is needed for their service and are expected to apply confidentiality and security controls. Kijoli does not sell contact information. We do not permit processors to use correspondence for unrelated advertising.
7. International transfers
Because hosting and technical providers may operate across borders, information can be processed outside the Republic of Korea. Kijoli assesses the provider’s safeguards and contractual terms before using a service. Visitors may request information about the relevant processing location. We seek to limit transfer to data necessary for the stated purpose.
8. User rights
Subject to applicable law, a person may request access, correction, deletion, restriction, or a copy of personal information. Requests should identify the relevant message and be sent through contact.php or to the office phone +82 (0)2 6178 9032. We may ask for reasonable verification to prevent disclosure to the wrong person. We aim to respond within 30 days and explain any lawful extension.
9. Children
Kijoli is general editorial media and is not directed at children under the age applicable in their jurisdiction. We do not knowingly collect children’s personal information. If a parent or guardian believes a child sent information, they may contact us for review and deletion. We do not use age-sensitive profiling.
10. Security
We use access controls, updates, limited retention, and provider review to reduce risk. No online transmission can be guaranteed completely secure. If Kijoli identifies a material incident, it will assess notification duties under applicable law. Visitors should never send secrets or recovery phrases through the contact form.
11. Complaints
Questions should first be sent to Kijoli at the listed address or phone. A person may also contact the relevant Korean privacy authority or another competent regulator in their place of residence. We will cooperate with lawful inquiries and keep a record of the issue, response, and any corrective action. Complaints do not affect a person’s ability to use the public site.
12. Changes
This policy was published on 22 September 2026. The next scheduled review is 22 September 2027, or earlier if the site introduces a new data practice. Changes will show a new effective date and a short change note. The current version remains available from the footer.
Additional privacy details
Kijoli uses the minimum information reasonably needed to operate an editorial website and respond to readers. A contact message may include the sender’s name, email address, subject, message text, and any file intentionally attached, although attachments are not required. Please avoid including information about another person unless you have a lawful reason to share it. If a message contains a recovery phrase, private key, payment credential, or identity document by mistake, we will restrict access to it and delete it during the next privacy review, where practicable.
For correspondence, the practical legal basis is consent provided by the sender through a voluntary request, while service security relies on legitimate operational interests under applicable Korean privacy principles. We may use a contracted hosting, email, or security provider to deliver the page and protect the form, with access limited to the service required. We do not sell contact information or use it to create advertising audiences. We do not make decisions about a visitor solely by automated processing.
Contact messages are normally removed 24 months after the last meaningful exchange, and temporary security records are normally removed after 90 days. If a matter concerns a correction, complaint, legal request, or security incident, limited records may be retained for up to five years where needed to document the response or meet a legal obligation. Retention is reviewed in January and records are deleted, anonymised, or reduced when the stated purpose ends. Backup copies may remain for up to 35 days before routine cycling.
Visitors may ask what personal information Kijoli holds, request correction of an inaccurate detail, request deletion where no overriding duty applies, or object to a processing activity based on legitimate interest. Requests should identify the relevant email address and subject without sending sensitive credentials. We aim to acknowledge a request within five business days and provide a substantive response within 30 days, subject to identity and complexity checks. A person may contact the Personal Information Protection Commission of Korea if they believe a concern has not been addressed.
Some service providers may process limited technical information outside the Republic of Korea, depending on hosting, email delivery, or security configuration. Where that occurs, Kijoli expects contractual confidentiality, access controls, and safeguards appropriate to the service. A transfer does not authorize a provider to use correspondence for its own advertising. Visitors may ask for the current categories of processors and the purpose of a transfer.
Revision history: this policy became effective on 22 September 2026. The first scheduled review is 22 September 2027, with earlier review if the contact form, storage practice, or applicable requirement changes. Material changes will be shown by a new effective date and described in the notice. Questions can be sent to Kijoli at 330 Dosan-daero, Gangnam-gu, Seoul, 06040, Republic of Korea, or +82 (0)2 6178 9032.
Further privacy detail
The scope above includes information visible to the site when a page is requested, information a visitor voluntarily places in a form, and limited information needed to answer a communication. It does not include information held by an external destination merely because Kijoli links to it. For example, opening a documentation link may create a record with that destination under its own policy. Kijoli does not receive that record simply because the link appears on an article.
Technical records may include approximate location inferred from an IP address, status codes, response times, and basic device characteristics. These records are used for security, troubleshooting, and aggregate reliability checks, not for creating a profile of reading interests. A short-lived security record may be reviewed when repeated requests suggest automated abuse or an attempt to disrupt the archive. Access is limited to people or providers who need it for the stated purpose.
Where consent is the basis for a contact request, the visitor can withdraw it by identifying the message or email address concerned. Withdrawal does not require a reason and does not affect processing already completed lawfully. Where processing is necessary for security or compliance, an objection may be considered alongside that necessity. We may ask for a reasonable confirmation of identity before disclosing or deleting information.
Our ordinary retention schedule is 24 months for contact correspondence, 90 days for routine security logs, and up to five years for a documented complaint, correction dispute, or incident where a longer record is reasonably needed. Backups may remain in a protected cycle for up to 35 days and are not restored for ordinary use. Records are shortened or anonymised when a full identity is no longer needed. A legal hold may pause deletion for the limited material covered by it.
Service providers may include a hosting provider, form delivery provider, email provider, and security or abuse-prevention provider. Their access is limited by contract and operational necessity, and they are not authorised to use Kijoli correspondence for independent advertising. Some providers may process data outside Korea; Kijoli expects appropriate confidentiality, access controls, and transfer safeguards. A current processor-category request can be made through the address below.
Requests, complaints, and correction questions may be sent to 330 Dosan-daero, Gangnam-gu, Seoul, 06040, Republic of Korea, or +82 (0)2 6178 9032. We aim to acknowledge requests within five business days and respond within 30 days, with an extension explained where a request is complex. A visitor may also contact Korea’s Personal Information Protection Commission or another competent authority. This policy is effective 22 September 2026 and is scheduled for review on 22 September 2027.