YKK - Little Parts. Big Difference.

ETC

YKK KOREA Co. Ltd Privacy Policy

[YKK KOREA Co. Ltd] ( hereinafter referred to as the “ Company ” ) To protect the freedom and rights of data subjects, we process personal information lawfully and manage it securely in compliance with the Personal Information Protection Act and related laws. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, we have established and are disclosing the following Personal Information Processing Policy to inform data subjects of the procedures and standards regarding the processing of personal information and to handle related grievances promptly and smoothly.

This Privacy Policy is effective as of June 1 , 2026 .

In the event of an amendment to the Privacy Policy, we plan to notify users through website announcements (or individual notifications), and the history of previous changes will also be provided so that data subjects can easily check the changes.

Article 1 (Purpose of Personal Information Processing)

The Company processes personal information for the following purposes and does not use it for purposes other than those specified. In the event that the purpose of using personal information changes, the Company plans to take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act. The personal information processor must state the purpose of processing personal information in a specific and detailed manner.



1. Website Operation and Management

◦ Identifying access frequency, analyzing user website usage patterns, and utilizing statistics for service restructuring and UI/UX improvement.


2. Security and Stability

◦ Blocking Abnormal Access and Establishing a Secure Website Environment.

Article 2 (Processing and Retention Period of Personal Information)

① The Company processes and retains personal information in accordance with the retention and usage period agreed upon by the data subject or relevant laws and regulations.


② The processing and retention periods for each type of personal information are as follows.


Personal information processed : Website visit history

◦ Basis for retention : Article 15-2 of the Protection of Communications Secrets Act and Article 41 of the Enforcement Decree of the same Act.

◦ Reason for Exception : If an investigation or inquiry is in progress due to a violation of relevant laws and regulations, the information will be retained until the completion of such investigation or inquiry.

◦ Relevant Law : Protection of Communications Secrets Act.

◦ Retention Period: 3 months.

Article 3 (Provision of Personal Information to Third Parties)

The company does not provide the personal information of data subjects to third parties or entrust its processing to external parties.

Article 4 (Outsourcing of Personal Information Processing Tasks)

The company We do not outsource personal information processing tasks.

Article 5 (Rights, Obligations, and Method of Exercise of Data Subjects)

① The data subject may exercise the following rights related to personal information protection (hereinafter referred to as “Exercise of Rights”) against the Company at any time.

1. Request for access to personal information

2. Request correction if there is an error

3. Request for deletion

4. Request to stop processing

5. Request for withdrawal of consent

6. (If applicable) Request for transmission of personal information

7. (If applicable) Rejection of automated decisions and request for explanation


② You may exercise your rights pursuant to Paragraph 1 against the Company in writing, by phone (02-3705-7900), or by email (ykkkorea@ykk.com ) , and the Company will take action without delay.


③ If a data subject requests the correction or deletion of personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.


④ The exercise of rights pursuant to Paragraph 1 may also be carried out through the data subject's legal representative or an authorized agent. In this case, a power of attorney in accordance with Form No. 11 of the Enforcement Rule of the Personal Information Protection Act must be submitted. * Information on children under the age of 14 is not collected.


⑤ Data subjects must not infringe upon their own or others' personal information or privacy in violation of relevant laws and regulations, such as the Personal Information Protection Act.


⑥ Requests for access to and suspension of processing of personal information may be restricted pursuant to Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.


⑦ If the relevant personal information is specified as a subject of collection in other laws, you cannot request the deletion of personal information.


⑧ The Company verifies whether the person exercising the rights is the principal or a legitimate agent.

Article 6 (Items of Personal Information Processed)

The Company processes the following items of personal information. The personal information processor collects only the minimum amount of personal information necessary for the purpose of processing, and this must be consistent with the actual processing status.



Automatically collected items

◦ IP address, cookies, service usage records (date of visit, accessed pages, etc.), connected device information (OS, browser type, etc.)

Article 7 (Destruction of Personal Information)

① When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, etc., the Company shall, without delay (within 10 business days) Destroy the relevant information.


③ The procedures and methods for the destruction of personal information are as follows.

1. Destruction Procedure

◦ Automatically collected information is destroyed immediately after the purpose is achieved.


2. Destruction Period

◦ Users' personal information is automatically destroyed after the retention period expires.


3. Method of destruction

◦ Personal information stored in the form of electronic files is permanently deleted using technical methods that make the records unrecoverable, such as Low Level Format.

◦ Personal information printed on paper is destroyed by shredding or incineration.

Article 8 (Measures to Ensure the Safety of Personal Information)

The Company takes the following measures to ensure the safety of personal information.



1. Conducting Regular Internal Audits : To ensure the safety of personal information processing, we conduct regular internal audits once a year.


2. Minimization and Training of Employees Handling Personal Information : We designate and limit employees who handle personal information to take measures to minimize the handling of personal information, and we conduct employee training.


3. Establishment and Implementation of Internal Management Plan : We establish and implement an internal management plan for the safe processing of personal information.


4. Technical measures against hacking, etc .: To prevent the leakage and damage of personal information caused by hacking and computer viruses, we install security programs and periodically update and check them . In addition, we install systems in areas controlled from the outside and monitor and block them technically and physically.


5. Personal Information Encryption : Users' personal information is encrypted and stored and managed, and important data is made known only to the user by using separate security features such as file and transmission data encryption or file locking functions.


6. Personal Information Access Control : We take necessary measures to control access to personal information by granting, modifying, or deleting access rights to database systems that process personal information, and we control unauthorized access from the outside using intrusion prevention systems.


7. Use locking devices for document security : Store documents and auxiliary storage media containing personal information in a secure place with a locking device.


8. Restriction on unauthorized access : Set up a separate physical storage space for personal information and establish access control procedures.

Article 9 (Matters concerning the installation, operation, and refusal of automatic personal information collection devices)

The company uses 'cookies' that store and frequently retrieve usage information to provide personalized services to users.



1. of using cookies

◦ To provide an optimized web environment by tracking the number of website visitors and analyzing browser environments.


2. of Cookies

◦ Users have the right to choose regarding the installation of cookies. By configuring their web browser options, users can choose to allow all cookies, be prompted for confirmation whenever a cookie is saved, or refuse the storage of all cookies.


3. setup method

◦ Chrome : Web browser top right menu > Settings > Privacy and security > Clear browsing history.

◦ Edge : Web browser top right menu > Settings > Cookies and site permissions > Manage and delete cookies and site data.

Article 10 (Personal Information Protection Officer)

① The Company assumes overall responsibility for business related to the processing of personal information and designates a Personal Information Protection Officer as follows to handle complaints and provide relief for damages to data subjects regarding the processing of personal information.

1. Chief Privacy Officer

◦ Name : Urushihara Wataru

◦ Position : CISO/CPO

◦ Contact : Phone: 02-3705-7900, Email: ykkkorea@ykk.com


2. Personal Information Department

◦ Name : Inkyoung Hong

◦ Position : Center Director

◦ Contact: Phone: 02-3705-7900, Email: ykkkorea@ykk.com



② Data subjects may contact the Chief Privacy Officer and the Personal Information Department regarding all inquiries, complaint handling, and damage relief matters related to personal information protection arising during the use of the Company's services (or business). The Company will respond to and process the data subject's inquiries without delay.

Article 11 (Request for Access to Personal Information)

Data subjects may request access to their personal information from the following departments in accordance with Article 35 of the Personal Information Protection Act. The Company will endeavor to process data subjects' requests for access to personal information promptly.



Department handling requests for access to personal information

◦ Name : Inkyoung Hong

◦ Position : Center Director

◦ Contact : Phone: 02-3705-7900, Email: ykkkorea@ykk.com

Article 12 (Methods for Remedying Infringement of Rights)

Data subjects may apply for dispute resolution or consultation with specialized agencies, such as the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency's Personal Information Infringement Reporting Center, to seek relief for personal information infringement. In addition, inquiries regarding other reports and consultations on personal information infringement may be made to the following agencies.



1. Personal Information Dispute Mediation Committee : 1833-6972 ( without area code ) (www.kopico.go.kr)

2. Personal Information Infringement Report Center : 118 ( privacy.kisa.or.kr )

3. National Police Agency Cybercrime Reporting Center : 182 ( without area code )(ecrm.police.go.kr)

Article 13 (Change to Personal Information Processing Policy)

① This Privacy Policy is effective from June 1 , 2026 .


② The previous Privacy Policy can be viewed at the following link .

Go to Top