Quick
Privacy Policy
Privacy Policy

NJ Coslab Co., Ltd. (Brand: BYTHEQUALITY, the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act of the Republic of Korea and related laws, in order to protect users' personal information and to handle related grievances promptly and smoothly.

  • Company name: NJ Coslab Co., Ltd. · CEO: Sanghyun Kim · Business registration no.: 384-81-01172
  • Address: Rooms 201, 203 and 204, 46 Daehak-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea · Tel: +82-70-4233-3347 · Email: bythequality@gmail.com
Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information is not used for any purpose other than those stated below, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent.

  1. Membership registration and management — confirming intent to join, identification and authentication, maintaining membership, restricting registration by children under 14, preventing fraudulent use, notices and notifications
  2. Business member screening and transactions — verifying business qualifications (review of business registration certificates and licenses), opening wholesale accounts, issuing tax invoices, paying settlement amounts
  3. Provision of goods and services — product orders, payment and delivery, seminar and training registration and operation, online courses, issuing certificates of completion
  4. Settlement and accounting — payments and refunds, receivables management, issuing electronic tax invoices and cash receipts, bookkeeping
  5. Marketing and advertising — announcements of new products and events (email, SMS, KakaoTalk) only to members who have consented, statistical analysis of service usage
  6. Service improvement — analyzing access frequency and visit/usage records (for statistical purposes)
Article 2 (Items of Personal Information Collected and Collection Methods)

1. Items collected

  • General membership (required) — name, email, mobile phone number, address, login ID and password, identity verification information (CI), IP address at sign-up
  • Social sign-up: Kakao, Naver, Google (required) — name, email, social account identifier, mobile phone number, address, identity verification information (CI), IP address at sign-up
  • Business members, additionally (required) — company name, representative name, business registration number, business type and category, business contact number, settlement bank account (bank, account number, account holder), copies of business registration certificate, bankbook and license
  • Orders and delivery (required) — names of orderer and recipient, contact number, delivery address, delivery requests
  • Seminar and training registration (required) — participant name and contact number
  • Marketing (optional) — consent status per channel (email, SMS, KakaoTalk)
  • Automatically collected — access IP, browser and device information, cookies, visit and page-usage records, access date and time

The Company does not collect resident registration numbers or gender. Information such as date of birth received from the certification agency in the identity verification process is used only for identity verification and is not stored separately. Payment information such as card numbers and bank account numbers is collected directly by the payment gateway (Toss Payments) and is not stored by the Company.

2. Collection methods

Website sign-up, order and inquiry forms; social login integration; authentication through an identity verification agency; automatic collection in the course of using the service

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention period required by law or agreed upon at the time of collection, and information whose period has expired is destroyed (de-identified) without delay through an automated daily procedure.

  • Member information (general, business and administrator accounts) — 5 years after withdrawal (account deletion) (E-Commerce Act: records of contracts and payments, 5 years; employee accounts kept to identify actors for accounting/tax records)
  • Login information (ID, password, social linkage) — 30 days after withdrawal (recovery grace period) (destroyed upon fulfillment of purpose; kept to handle recovery requests within the grace period)
  • Records of contracts, orders, payments and delivery — 5 years (Enforcement Decree of the E-Commerce Act, Article 6)
  • Records related to outstanding receivables — 10 years (Commercial Act, Article 33; extinctive prescription of commercial claims)
  • Seminar and training participant information — 5 years (records of contract performance)
  • Records of consumer complaints and dispute handling (inquiries, consultations) — 3 years (Enforcement Decree of the E-Commerce Act, Article 6)
  • Records concerning labeling and advertising — 6 months (Enforcement Decree of the E-Commerce Act, Article 6)
  • Access logs (records of administrator actions) — 1 year (Standards for Ensuring the Safety of Personal Information, Article 8)
  • Service usage and visit records (IP, device information) — 1 year (internal policy: fraud prevention and statistics)
  • External integration communication records (payment, delivery, tax documents) — 1 year (internal policy: incident response and dispute verification)
  • Identity verification information (CI) — 5 years after withdrawal (internal policy: prevention of fraudulent re-registration)
  • One-time authentication tokens such as password reset tokens — immediately upon fulfillment of purpose (up to 1 day)
Article 4 (Procedures and Methods of Destruction)
  1. The Company destroys personal information whose retention period has expired without delay through a destruction procedure that runs automatically every day.
  2. Destruction methods
    • Electronic files: deleted using irreversible methods, or de-identified (anonymized) so that individuals can no longer be recognized. Anonymized statistical and aggregated transaction data does not constitute personal information under Article 58-2 of the Personal Information Protection Act and may continue to be retained for business analysis purposes.
    • Attached document files (business registration certificate, bankbook copy, license): the original files are deleted from storage media when the retention period expires.
  3. Information that must be preserved under other laws is managed separately for the applicable preservation period and destroyed immediately thereafter.
  4. The time of destruction is recorded in the system as evidence of destruction.
Article 5 (Provision of Personal Information to Third Parties)

The Company processes personal information only within the scope of the purposes in Article 1, and provides it to third parties only in the following cases.

  • National Tax Service — Purpose: issuance of electronic tax invoices and cash receipts (legal obligation) / Items: business registration number, company name, representative name, address, email, cash receipt identification number (mobile phone) / Retention: as prescribed by applicable laws
  • Referring business members (BUYDEUK DAY selling partners) — Purpose: order confirmation and settlement for BUYDEUK DAY events / Items: orderer name, order information (product, quantity, amount) / Retention: 5 years after the end of the transaction

※ BUYDEUK DAY is a joint-sales event conducted through referring business members. When you make a purchase, your name and order information are provided to the referring business member. This is stated on the payment screen, and proceeding with the purchase constitutes consent to this provision.

Article 6 (Entrustment of Personal Information Processing)

The Company entrusts personal information processing tasks as follows for smooth service provision. Entrustment contracts stipulate compliance with privacy laws, restrictions on re-entrustment and liability for incidents, and the Company manages and supervises the trustees.

  • Cafe24 Corp. — server hosting (infrastructure operation)
  • Toss Payments Co., Ltd. — payment processing, settlement payout agency
  • PortOne Co., Ltd. — mobile phone identity verification
  • CJ Logistics Co., Ltd. — product delivery and return collection
  • Popbill (Linkhub) — issuance of electronic tax invoices and cash receipts
  • Daou Tech Inc. (BizTalk) — KakaoTalk notification and SMS sending
  • Ecount Inc. — inventory and accounting management (ERP)
  • Google LLC — email sending (SMTP)
Article 7 (Overseas Transfer of Personal Information)

The Company stores and processes personal information overseas as follows, to the extent necessary for service provision. Data subjects may refuse the overseas transfer by contacting the Chief Privacy Officer, in which case use of the relevant service may be restricted.

  • Cafe24 Corp. / Japan — Purpose: service server operation (hosting) / Items: all personal information collected in the course of using the service / Time and method: network transmission and storage during service use / Retention: same as the retention periods in this policy
  • Google LLC / United States — Purpose: email sending / Items: email address, message content / Time and method: transmitted when mail is sent / Retention: until sending is completed
  • VdoCipher / India — Purpose: online course video streaming and piracy prevention / Items: viewer email (watermark), access IP / Time and method: transmitted while watching a course / Retention: until the viewing session ends
Article 8 (Rights and Obligations of Data Subjects and How to Exercise Them)
  1. Data subjects may at any time request the Company to access, correct, delete, or suspend the processing of their personal information.
  2. Rights may be exercised directly on the My Page menu, or by written or email request to the Chief Privacy Officer in Article 11, and the Company will take action without delay.
  3. Membership withdrawal: you may withdraw directly on My Page. However, if there are orders in progress, pending claims or unsettled amounts, withdrawal is available after they are completed.
  4. Recovery after withdrawal: within 30 days of withdrawal you may request account recovery through customer service. After 30 days, login information is destroyed, recovery is impossible, and you must register again.
  5. Children under the age of 14 may not register as members.
Article 9 (Measures to Ensure the Safety of Personal Information)
  1. Passwords stored with one-way encryption (original cannot be viewed)
  2. Identity verification information (CI) stored as a one-way hash (SHA-256)
  3. Password reset via a one-time token valid for 15 minutes, with email notification upon completion
  4. Attached documents (business registration certificate, bankbook copy, license) are kept private with access control — viewable only by the member and authorized administrators
  5. Access logs retained (1 year) and inspected for administrator processing of personal information
  6. Blocking of unauthorized access, including account lockout after consecutive failed logins
  7. Continuous operation of automated destruction and anonymization batches for information past its retention period
Article 10 (Installation, Operation and Refusal of Automatic Collection Devices)
  1. The Company operates cookies and visit-record collection tools for convenient service provision and statistical analysis.
  2. Items collected: access IP, browser and device information, pages visited and dwell time, inflow path
  3. Collected visit records have their personally identifiable elements (IP, device information) deleted after 1 year and are kept only as statistical data.
  4. Users may refuse cookies through browser settings; however, some services such as login may be restricted.
  5. Naver Analytics is used for web log analysis.
Article 11 (Chief Privacy Officer)
  • Chief Privacy Officer: Minkyung Kim, Manager
  • Contact: +82-10-2021-5034 · kmk@bythequality.com

Data subjects may direct privacy-related inquiries, complaints and requests for remedy to the contact above, and the Company will respond and act without delay.

Article 12 (Remedies for Infringement of Rights)

If you need to report or consult on a personal information infringement, you may contact the following organizations (Republic of Korea).

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • National Police Agency: 182 (ecrm.cyber.go.kr)
Article 13 (Changes to this Privacy Policy)
  1. This Privacy Policy applies from July 28, 2026.
  2. If this policy changes, notice will be given via website announcements from 7 days before the effective date (30 days for material changes).
  3. Previous versions of this policy are available upon request to the Chief Privacy Officer.