GRAMPUS Inc. Privacy Policy


1. Information We Collect

We collect only the information necessary to provide the Services. Where we collect optional information, we do so separately and with notice.

1.1 When you link an account through an external authentication service

1.2 When you participate in an event

We obtain separate consent before collecting this information.

1.3 When you use a paid service

1.4 When a user below the applicable minimum age links an account

1.5 When you contact customer support

1.6 Information generated automatically in the course of using the Services

1.7 How we collect information


2. How We Use Information

We process this information in order to perform our agreement with you, to comply with legal obligations, on the basis of your consent where consent is requested, and on the basis of our legitimate interests in operating and securing the Services.


3. Advertising and Personalised Advertising

  1. We display advertising within the Services in order to fund their operation. In this process, advertising providers may collect information through cookies and advertising identifiers. The providers concerned are listed in Section 5.
  2. Where we provide a Service whose primary audience is children, only contextual, non-personalised advertising is served in that Service.
  3. You can refuse the collection of information for advertising purposes as follows:
    • Browser settings: refuse the storage of cookies
    • Android: Settings → Google → Ads → reset or delete your advertising ID
    • iOS: Settings → Privacy & Security → Tracking
  4. Where you move to an external site through an advertisement, the processing of your information on that site is governed by that site’s privacy policy, for which we are not responsible.

4. Sharing Information with Third Parties

We do not use your information beyond the purposes notified in Section 2, and do not provide it to third parties, except:


5. Processors

We engage the following processors in order to provide the Services. In each case we enter into a contract containing the terms required by applicable law, and we supervise their handling of personal data.


6. International Transfers

We use infrastructure and services operated by providers outside the Republic of Korea, and personal data is transferred and processed outside the Republic of Korea in this process.

The countries of transfer may change according to each provider’s data centre policy and the need to maintain service quality. Where they change, we will disclose the change through this Policy.


7. Retention

We destroy personal data without delay once the purpose of collection and use has been achieved, except where we retain it for the periods below.

7.1 Under our internal policy

7.2 Under applicable law

7.3 Event and marketing information

7.4 Inactive users

Where a user has not accessed the Services for one year from the date of last access, we may store their personal data separately or destroy it. We notify the user 30 days before doing so.


8. Destruction


9. Your Rights

  1. You may at any time request access to, correction of, deletion of, or restriction of the processing of your personal data, and you may withdraw consent where processing is based on consent.
  2. You may request a copy of your personal data in a structured, commonly used and machine-readable format, and request that it be transmitted to another controller, where applicable law provides such a right.
  3. You may object to processing carried out on the basis of our legitimate interests, and you may object at any time to processing for direct marketing purposes.
  4. To exercise these rights, use the settings screen within the Services or contact privacy@grampus.co. We will verify your identity and act without undue delay.
  5. Where we must decline a request for a legitimate reason, we will notify you and explain the reason.
  6. Where an account is deleted, data you have generated and accumulated while using the Services may be deleted together with your personal data.
  7. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.
  8. You have the right to lodge a complaint with a supervisory authority in your country of residence.

10. Cookies and Similar Technologies

  1. We use cookies and browser storage (such as Local Storage) in order to provide the Services and improve convenience.
  2. You can allow or refuse the storage of cookies and site data through your browser settings:
    • Chrome: Settings → Privacy and security → Third-party cookies / Site data
    • Safari: Settings → Privacy → Cookies and website data
    • Edge: Settings → Cookies and site permissions
  3. If you refuse the storage of cookies and site data, some parts of the Services may be restricted.

11. Device Permissions

  1. Where the Services require access to information or functions on your device, we distinguish between required and optional permissions, clearly explain each item and the reason for it, and obtain your consent.
  2. Declining an optional permission does not prevent you from using the Services.
  3. You can withdraw or reset a permission you have already granted at any time, using the functions provided by your device’s operating system or browser.

12. Security

We take the following measures to protect personal data against loss, theft, leakage, alteration and damage.

Technical measures

Organisational measures

Physical measures

We are not responsible for problems arising from your own actions, such as loss of a device or deletion of data stored in your browser, where we have fulfilled the obligations above.


13. Children

  1. The Services are not directed to children below the minimum age at which a person may consent to the processing of personal data under the law of their country of residence.
  2. Where we become aware that we have collected personal data from a child below that age without the consent of a legal guardian, we delete that data without delay.
  3. Where we collect a child’s personal data with the consent of a legal guardian, we use the guardian’s information solely to confirm that consent and to handle requests for access to, correction of or deletion of the child’s personal data.
  4. We encourage legal guardians to supervise their children’s use of the Services. If you believe a child has provided us with personal data, contact privacy@grampus.co.

14. Privacy Officer and Contact

Privacy Officer

Responsible department

You may report any privacy-related complaint arising from your use of the Services to the contacts above.


15. External Links

We may provide links to other companies’ websites or materials. We have no control over those external sites and materials and are not responsible for the services or materials they provide. Where you move to another site through a link, please review that site’s privacy policy.


16. Changes to this Policy

Where applicable law or our internal policy changes, we will give notice of the change and the reason for it within the Services or on our website at least 7 days before it takes effect (30 days before, where the change materially affects your rights).


Addendum

This Policy takes effect on 10 September 2026.