Friends Club Plus

Privacy Policy

Last updated: 2026-07-28

Effective date: 2026-08-01

General Provisions

WooriIBook Co., Ltd. (the "Company") values users' personal information and complies with the Republic of Korea's Personal Information Protection Act (PIPA) and related laws. Through this Privacy Policy, the Company explains for what purposes and by what means users' personal information is processed in "Friends Club Plus" and related services (the "Service"), and what measures are taken to protect personal information.

Friends Club Plus is provided under agreements with educational institutions such as schools and academies (each an "Institution"), and User accounts (for teachers, students, etc.) are, as a rule, issued or granted by the Institution or its designated Administrator. In such cases, the Institution warrants that it has fulfilled the procedures required under applicable law — including obtaining consent for the collection of Users' personal information (and, for Children under 14, the consent of a legal guardian). The roles and responsibilities regarding personal information processing between the Company and the Institution (including whether processing is entrusted) shall be as provided by applicable law and the separate agreement.

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information is not used for purposes other than those below, and where the purpose of use changes, the Company will take necessary measures in accordance with applicable law.

  1. User authentication and account management — identification of members and Users, verification of identity and age, account issuance and use management, verification of legal guardian consent for children's accounts.
  2. Service provision — provision of learning content, grading and feedback, management of learning status and achievement, class management tools and personalized learning features.
  3. Service operation — operational notices and service update announcements, handling of inquiries.
  4. Security and quality management — prevention of unauthorized access and misuse, service quality improvement and error detection, statistical analysis.
  5. Compliance with legal obligations and handling of disputes.

2. Personal Information Items Processed and Methods of Collection

(1) Items collected and purposes

CategoryItems collectedPurposeRetention period
Account·Authentication (required)Account ID, password, display name, role (teacher/student/administrator), affiliated institution·grade·classIdentification and authentication of users, account managementUntil termination of the service agreement (withdrawal); statutory retention exceptions apply
Teacher account (optional)Email, phone numberAccount management, operational notices and inquiry handlingUntil termination of the service agreement
Service use (auto-collected)Login history, access IP, device·browser information, service usage·activity recordsService provision, security, misuse prevention, quality improvement1 year from collection, or until termination of the service agreement
Learning data (required)Learning records (progress·achievement), learning activities and submissions (assignments, answers, handwriting, etc.)Provision of learning content, grading·feedback, learning-status managementUntil termination of the service agreement (or as otherwise provided by law·contract)
Children (under 14)Name, grade·class, profile photo (optional), learning activities and submissionsProvision of learning, grading·feedback, learning-status managementAs per the legal guardian's consent (see Appendix)
Customer inquiries (optional)Email, inquiry content (including text·images)Handling and recording of inquiries3 years (consumer dispute resolution standard)

Note: The Company collects only the minimum personal information necessary to provide the Service. Sensitive information and resident registration numbers are not collected in principle; where unavoidable, they are processed only with a legal basis and separate consent.

(2) Methods of collection

  • Account issuance and User information registration by the Institution or Administrator
  • Direct entry by the User upon registration/login
  • Automatic collection during service use (logs, cookies, device information, etc.)
  • Collection upon inquiry to customer support (email, etc.)

3. Retention and Use Period

  1. As a rule, the Company retains and uses personal information during the User's service usage period.
  2. Upon account deletion, termination of the service agreement, or discontinuation of the Service, the Company destroys the relevant personal information without delay (no later than within 30 days), except as otherwise provided by applicable law.
  3. Where retention is required under applicable law, the information is retained for the relevant period, and the legal basis and items are separately disclosed.

4. Provision to Third Parties

As a rule, the Company does not provide users' personal information to third parties. The following are exceptions:

  1. Where the User (or legal guardian) has given explicit consent;
  2. Where there is a special provision in law, or where necessary to comply with legal obligations such as a lawful request from an investigative authority.

Where provision is necessary, the Company will give prior notice of the recipient, purpose, items, and retention·use period, and obtain consent.

5. Entrustment of Personal Information Processing

To provide a stable service, the Company may entrust part of its personal information processing to external specialized providers. When entrusting, the Company discloses the trustee and the scope of entrusted work in this policy in accordance with applicable law, and ensures safe management of personal information through contracts.

TrusteeScope of entrusted work
Supabase, Inc.Operation of backend infrastructure (database, authentication, storage) and data storage·processing (Seoul region)
Vercel, Inc.Frontend (web) application hosting and deployment

Note: Where personal information is stored or processed overseas due to entrustment, the Company will separately disclose, in accordance with applicable law, the overseas recipient, destination country, items transferred, date·method of transfer, retention·use period, and how to refuse.

6. Protection of Children's Personal Information

  1. The Service may be used by Children (students) under 14 years of age, and the collection and use of a Child's personal information requires the consent of a legal guardian.
  2. Where accounts are issued through an Institution such as a school or academy, the Institution warrants that it has fulfilled all consents and procedures required under applicable law, including the consent of legal guardians, with respect to Child Users.
  3. The Company protects Children's personal information with special care in accordance with applicable law; the specific items and consent matters for Children's personal information are governed by the [Appendix] Consent to Collection and Use of Children's Personal Information at the end of this policy.
  4. A legal guardian may at any time request access to, correction, deletion, or suspension of processing of the Child's personal information, and may withdraw consent.

7. Rights of Data Subjects and Legal Guardians, and How to Exercise Them

  1. A User (or, for Children under 14, the legal guardian) may at any time request access, correction·deletion, suspension of processing, transfer of personal information, and withdrawal of consent with respect to their (or the Child's) personal information.
  2. Rights may be exercised through the Administrator of the affiliated Institution or through the Chief Privacy Officer·department indicated in the Service, and the Company will act without delay.
  3. Where there is a legitimate ground for refusal, the Company will explain the ground and how to object. When rights are exercised through an agent, the Company may verify the delegation.
  4. Users must keep their personal information up to date; the User bears responsibility for entering inaccurate information.

8. Notice on Automated Processing

  1. To support learning, the Service may provide certain features — such as grading and feedback — in a partially automated (assistive) manner. However, the results are reviewed and finalized by a teacher, and the Company does not make decisions producing legal or similarly significant effects on users solely by automated processing.
  2. Users (or legal guardians) may request an explanation, raise an objection, and request human involvement regarding such processing.

9. Installation·Operation of Automatic Collection Devices such as Cookies, and Refusal

  1. The Company may use automatic collection devices such as cookies for service provision, user convenience, and security.
  2. Users may refuse or delete cookie storage through their web browser or device settings; in this case, some features of the Service may be limited.

10. Procedures and Methods of Destruction

  1. When personal information becomes unnecessary — for example, upon expiration of the retention period or achievement of the processing purpose — the Company destroys it without delay.
  2. Information in electronic file form is permanently deleted by technical means that make recovery·reproduction impossible; paper documents are shredded or incinerated.

11. Measures to Ensure the Security of Personal Information

The Company implements the following technical, administrative, and physical measures to protect personal information from unauthorized access, leakage, alteration, or destruction:

  1. Establishment and implementation of an internal management plan and regular staff training;
  2. Minimization of access rights to personal information, role-based access control, and retention·review of access logs;
  3. Encryption of personal information (passwords and important data) and encrypted data transmission (TLS);
  4. Installation·updating of security programs and regular security inspection·monitoring;
  5. Use of secure server infrastructure managed by certified cloud providers and physical access control;
  6. Imposition of confidentiality obligations on personnel who access personal information.

12. Chief Privacy Officer (CPO) and Responsible Department

The Company designates a Chief Privacy Officer and responsible department to oversee personal information processing and to handle related inquiries, complaints, and remedies:

  • Chief Privacy Officer (CPO): Sim Seung-hwan Contact: info@ownabee.com
  • Complaints and access-request department: Customer Support Team Contact: info@ownabee.com

13. Remedies for Infringement of Rights

Data subjects may apply for counseling or dispute mediation to the following organizations to obtain relief for personal information infringement:

  • Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972)
  • Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
  • Supreme Prosecutors' Office Cyber Investigation Division (www.spo.go.kr / 1301)
  • National Police Agency Cybercrime Reporting System (ecrm.police.go.kr / 182)

14. Notification and Reporting of Personal Information Breaches

If a personal information breach occurs, the Company will, within the period prescribed by applicable law, notify the affected data subjects (including legal guardians in the case of Children under 14) and the affiliated Institution, and will report to the relevant authorities where the case meets the legal thresholds.

15. Changes to the Privacy Policy

This policy may be revised in accordance with changes in law or the Service. When revised, the Company will announce the effective date and reason for the change at least 7 days in advance (30 days in advance for changes that are unfavorable or material to users). The revision history will be disclosed at the bottom of the policy or through a separate notice.