Kebijakan Privasi

Tanggal berlaku: 1 August 2026

ExpandGlobal (the "Company") treats the personal data of data subjects as important and complies with the Personal Information Protection Act and other applicable law. This policy sets out, and makes public, what personal data the Company processes and for what purpose, how long it is kept, to whom it is entrusted and where it is sent.

1. Personal Data Processed

The Company processes the items below at each point of use. At sign-up it takes only the items needed to open an account; the items needed to register a brand are taken separately at the registration stage.

a. Prospective-owner sign-up

CategoryItems
RequiredEmail address, password, name, telephone number, country of residence, target country, start-up budget amount and currency (USD or KRW), industries of interest, time of consent to the Terms of Service and to the processing of personal data, time of consent to provision to third parties, display language
OptionalTarget city, business or franchise experience

b. Franchise sign-up

CategoryItems
RequiredEmail address, password, time of consent to the Terms of Service and to the processing of personal data, display language

c. Brand registration (franchise members)

CategoryItems
RequiredContact name, contact email address, contact telephone number, copy of the business registration certificate
OptionalContact position, company website address

The brand name, industry, brand description, main products, logo and store photographs, number of domestic stores, investment range, franchise type, target countries and overseas expansion history are information about a corporation and a brand and are not included in the tables above. Where such information is registered with content by which an individual can be identified, that part is likewise treated as personal data and processed under this policy.

d. Inquiries (available to non-members as well)

CategoryItems
RequiredName, email address, inquiry content, consent to the processing of personal data
OptionalTelephone number, country
Generated automaticallyTime of receipt, processing state (received, the Company's review outcome, whether a reply was sent), a hash of the connecting IP address and, where the inquiry was sent while logged in, the identifier of that account

e. Information generated automatically during use

  • An authentication cookie that keeps the user logged in. It is issued by the authentication service and expires on logout or when its validity period passes.
  • A language cookie that remembers the display language
  • Records kept per account by the authentication service, such as the time of sign-up and the time of the most recent login
  • A hash of the connecting IP address, generated when an inquiry is received. The original IP address is not stored. Section 6 sets this out in detail.
  • The time and content of any error, recorded in the server operation log

The Company has not placed any separate analytics tool in the Service that collects advertising identifiers or behavioural data.

2. Purposes of Processing

PurposeItems used
Identifying members and managing accounts, email verification, password resetEmail address, password, name, telephone number, time of consent
Recommending brands that match the conditions given and returning search resultsCountry of residence, target country and city, budget, industries of interest, experience
Reviewing franchise member eligibility and business statusCopy of the business registration certificate, contact name and contact details
Receiving inquiries and relaying them to the brand concerned, blocking unsuitable inquiries, replying to consultationsThe inquirer's name, email address, telephone number, country and inquiry content, and the brand contact's email address
Blocking repeat submissions and spamEmail address, hash of the connecting IP address, time of receipt
Evidencing consent, responding to disputes, identifying the cause of service failuresTime of consent, receipt records, error logs
Retaining the display languageLanguage setting

The Company does not use personal data beyond the purposes above, and where a purpose changes it obtains separate consent.

3. Retention Periods and Destruction

SubjectRetention period
Member account information and profile items entered by the memberUntil withdrawal of membership or termination of the service agreement
Brand contact informationUntil the brand registration is deleted or the service agreement is terminated
Copy of the business registration certificate submitted for reviewUntil the brand registration is deleted or the service agreement is terminated
Inquiry recordsThree years from the date of receipt. This is the retention period for records of consumer complaints or dispute handling under the Act on the Consumer Protection in Electronic Commerce.
Hash of the connecting IP addressKept together with the inquiry record. Only records from within one hour of receipt are used for the spam-blocking assessment.
Records of the time of consentThe same period as member account information

Where applicable law requires retention for a set period, the data is kept for the period that law prescribes and is not used for any purpose other than retention during that period.

When a member account is deleted, the profile, registered brands and saved-brand records linked to that account are deleted with it. Inquiry records already received are not deleted; they remain with the link to the sender's account identifier and to the brand severed.

The method of destruction is as follows. Information held in the database is deleted as a record; files such as business registration certificates and photographs are deleted from storage. Copies held in backups operated by an entrusted provider are removed progressively according to that provider's backup cycle.

4. Provision to Third Parties

As a rule the Company does not provide personal data to third parties. Given the nature of the Service, however, it provides data in the two cases below with the consent of the data subject.

a. Provision to the brand an inquiry names

The provision below occurs at the moment an inquiry is received.

RecipientPurposeItems providedWhen providedRetention and use period
The franchise business operator that registered the brand the inquiry is addressed toReplying to the inquiry and franchise consultationThe inquirer's name, email address, telephone number, country and inquiry contentAt the moment the inquiry is received. It is provided immediately, without a separate approval step by the Company.In accordance with the recipient business operator's own personal-data practices. The Company is not involved in processing after the relay.

An inquiry is relayed to the business operator that registered the brand as soon as it is received. The Company does not operate a step in which it reviews the content first and approves the relay, because naming a particular brand in an inquiry is itself a request to contact that brand. The scope of the relay is not a promise in prose but a database access rule, so an inquiry cannot be retrieved from the account of any business operator other than the one that registered the brand named in it.

Provision is limited to brands whose registration the Company has approved. An inquiry addressed to a brand that is under review or has been rejected is not relayed to that brand's business operator.

The Company may block a received inquiry that is spam or does not fit the purpose of the Service. A blocked inquiry can no longer be retrieved from the brand operator's account from that moment on, although content already relayed before the block is not recalled. Whether or not an inquiry is blocked, the record of receipt is kept for the retention period in section 3.

At the moment of receipt the same notification also goes to the Company's operations staff. That is internal processing and does not constitute provision to a third party. The sending of that notification email is entrusted as set out in section 5.

The notification email sent to the brand business operator does not carry the inquirer's contact details. The inquiry content, including contact details, is viewed by that business operator after signing in to their own account.

A general inquiry that does not name a particular brand is relayed only to the Company's operational address, and no provision to a third party occurs.

b. Provision to partner companies

The Company issues viewing accounts to partner companies that support overseas expansion consulting and local execution. A partner company can see only the items the Company has designated for that account. That scope is not a promise in prose but a database query rule, so items that have not been designated cannot be retrieved at all.

RecipientPurposeItems providedWhen providedRetention and use period
Partner companies to which the Company has issued an accountOverseas expansion consulting and support for execution such as local incorporation and marketingLimited to the items the Company designates per account. These may include a prospective owner's name, email address and telephone number, and may also include country of residence, target country and city, start-up budget, industries of interest and business experience.At the moment the Company designates those items for that partner companyIn accordance with the recipient partner company's own personal-data practices. The Company may withdraw the designation to stop further viewing, but content already viewed is not recalled.

A partner company may ask the Company to add items, and those items open only where the Company approves. A request alone opens nothing, and the decision and its time are kept as a record.

Items by which an individual can be identified and contacted directly, such as name, email address and telephone number, are designated only where the data subject has consented. Those items are not provided to partner companies for a data subject who has not consented.

The Company may provide personal data to the extent required where an investigative authority or similar body requests it through lawful procedure under applicable law.

5. Entrustment of Processing

The Company entrusts the processing of personal data as set out below in order to operate the Service. Each entrustment agreement includes provisions on the safe management of personal data, and the Company manages its processors so that they do not process personal data beyond the entrusted purpose.

ProcessorEntrusted workItems entrustedStatus
Supabase, Inc.Database operation, member authentication and verification email delivery, file storageAll personal data covered by this policyIn use
Resend, Inc.Sending inquiry notification emailsThe inquirer's name, email address, telephone number, country and inquiry contentIn use
Google LLCMachine translation of registered content and interface textThe text of registered content such as brand descriptions. Non-public items such as contact details and business registration certificates are not included.Planned. Not currently in use.
Vercel Inc.Web service hosting and retention of server operation logsAccess records, error logsThe hosting provider has not been finalised. This entry must be completed once it is.

Where the content of the entrusted work or the processor changes, the Company gives notice through this policy.

6. Overseas Transfer of Personal Data

Every system provider the Company uses is headquartered outside Korea. Using the Service therefore transfers personal data overseas as set out below. A data subject may refuse this transfer, but on refusal cannot use the main functions of the Service, such as signing up and sending inquiries.

a. Supabase, Inc.

ItemDetail
RecipientSupabase, Inc.
ContactThe contact point for personal-data matters can be found at https://supabase.com/privacy.
Country of transferThe United States. The servers on which data is stored are, however, in the Amazon Web Services Asia Pacific (Seoul) region (ap-northeast-2). Storage is therefore domestic, but the processor is a United States corporation that may access the data from outside Korea for operational and technical support purposes, so it is notified here as an overseas transfer.
Time and method of transferTransmitted over an encrypted connection at the moment the Service is used, such as signing up, logging in, registering a brand or submitting an inquiry.
Items transferredAll personal data set out in section 1 of this policy
Purpose of transferDatabase operation, member authentication and verification email delivery, storage of business registration certificate and photograph files
Retention and use periodUntil the end of the retention period in section 3 of this policy, or until the entrustment agreement ends

b. Resend, Inc.

ItemDetail
RecipientResend, Inc.
ContactThe contact point for personal-data matters can be found at https://resend.com/legal/privacy-policy.
Country of transferThe United States
Time and method of transferTransmitted as a request to send a notification email at the moment an inquiry is received.
Items transferredThe inquirer's name, email address, telephone number, country and inquiry content, and the recipient email address
Purpose of transferSending inquiry notification emails
Retention and use periodUntil the sending purpose is fulfilled. Sending records are kept according to the processor's own log retention practices.

c. Google LLC (planned, not currently in use)

The Company plans to introduce machine translation so that registered content and interface text can be offered in several languages. That feature is not yet in use on the Service, so the transfer described below does not currently occur. This policy will be amended to give notice of the date it takes effect before the feature is applied.

ItemDetail
RecipientGoogle LLC
ContactThe contact point for personal-data matters can be found at https://policies.google.com/privacy.
Country of transferThe United States and other countries in which that provider operates servers
Time and method of transferTransmitted as a translation request the first time untranslated content is viewed. The translated result is stored on the Service and reused.
Items transferredThe text of registered content such as brand descriptions and main products, and marketing interface text. Contact details, business registration certificates and member account information are not included.
Purpose of transferMachine translation for multilingual display
Retention and use periodThe period required to carry out the translation

Once the hosting provider is finalised, the overseas transfer relating to that provider must also be added to this section.

7. Automatically Collected Information and Cookies

The Company uses cookies to keep users logged in and to retain the display language. A data subject may refuse the storage of cookies in their browser settings, but on refusing the authentication cookie cannot use features that require a login.

When an inquiry is received, the Company does not store the connecting IP address as it is. It combines the IP address with a random string held only on the server, produces a one-way hash and stores only that value. The value is used solely to check whether repeat requests come from the same place, and the original IP address cannot be recovered from the stored value. The Company does not accept more than three inquiries per hour from the same email address or the same hash value.

The Company has not placed any third-party tracking tool for advertising or behavioural analysis in the Service. Should one be introduced, this policy will be amended to give notice.

8. Rights of the Data Subject and How to Exercise Them

A data subject may exercise the following rights against the Company at any time.

  1. Request access to personal data
  2. Request correction where there is an error
  3. Request deletion
  4. Request suspension of processing
  5. Withdraw consent to the processing of personal data

Rights may be exercised by writing to nick.choi@expandglobal.kr or through the inquiry form on the Service. The Company acts within ten days of receiving a request and reports the outcome. Where action is delayed, it gives notice of the reason and the expected period.

A data subject may also exercise these rights through a legal representative or a duly authorised agent. In that case the Company may request a written document evidencing the authorisation.

On receiving a request for access, correction or deletion, the Company verifies that the person making the request is the data subject or a legitimate representative. Where the law restricts access, or where there is a risk of unduly infringing the life or property of another person, the Company may restrict the request and gives notice of the reason.

Withdrawing consent or requesting deletion may restrict use of the Service or terminate the account.

9. Personal Data of Children Under 14

This Service is aimed at business operators and adults preparing to start a business, and does not accept sign-ups from children under 14. The sign-up process does not currently collect a date of birth or age, so no separate age-verification step is in place. Where the Company confirms that the personal data of a child under 14 has been collected without the consent of a legal representative, it destroys that data without delay.

10. Measures to Secure Personal Data

The Company takes the following measures to secure personal data. Only measures currently in place are listed below.

  • Minimising access rights. Permissions are divided in the database at the item level and the record level, so the items non-members and members can each view are restricted at the database level. The name and contact details of a brand contact, the storage path of a business registration certificate and the review state are granted to no user role and are reachable only by the server.
  • A record-level security policy is applied so that a member's own account information can be retrieved only by that member and by administrators.
  • Business registration certificates and store photographs are held in storage that is not public and are served only to users with viewing rights, through addresses valid for a limited time. A business registration certificate may be viewed only by the member who submitted it and by administrators.
  • Passwords are converted one-way by the authentication service before storage, so not even the Company can know the original password. Passwords must be at least eight characters and must combine letters, digits and special characters.
  • For the connecting IP address recorded when an inquiry is received, only the hash is stored, not the original.
  • Communication between the user's browser and the server takes place only over an encrypted connection.
  • Administrator rights required for review and operations are granted through a separate role. The review state and the time of approval are controlled in the database so that only administrators can change them.
  • A record-level security policy is applied so that a received inquiry can be read only by the Company and by the business operator that registered the brand named in it. That business operator cannot itself change the handling state or the content of an inquiry addressed to it, and the database enforces that restriction immediately before writing.

Encryption at the storage level and backup management follow the measures provided by the entrusted providers.

12. Data Protection Officer and Access Request Channel

The Company has designated a data protection officer to oversee work relating to the processing of personal data and to handle inquiries and complaints from data subjects.

ItemDetail
NameJinho CHOI
PositionChief Executive
Telephone(+82) 10-8891-6417
Emailnick.choi@expandglobal.kr

A data subject may submit matters relating to the processing of personal data, complaint handling and remedy for harm to the channel above. The Company responds to submissions without delay.

13. Remedies for Infringement of Rights

To obtain a remedy for infringement of personal data rights, a data subject may apply to the bodies below for dispute mediation or advice. These bodies are separate from the Company and may be used where the data subject is not satisfied with the Company's handling or needs more detailed help.

BodyTelephoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Privacy Infringement Report Centre118 (no area code)privacy.kisa.or.kr
Supreme Prosecutors Office, Cyber Investigation Division1301 (no area code)www.spo.go.kr
National Police Agency, Cyber Investigation Bureau182 (no area code)ecrm.police.go.kr

Where a right or interest has been infringed by the disposition or omission of a public authority in respect of a request under Articles 35 to 37 of the Personal Information Protection Act, an administrative appeal may be brought under the Administrative Appeals Act.

14. Changes to this Privacy Policy

This Privacy Policy applies from 1 August 2026.

Where the content of this policy is added to, deleted or corrected in line with changes in the law or in the Service, the change and its effective date are announced on the Service from seven days before that date. Where a change materially affects the rights of data subjects, such as a change to the items collected, the purposes of use, entrustment or overseas transfer, the announcement is made from thirty days before the effective date and, where necessary, consent is obtained again.

The Company keeps a revision history so that earlier versions of this policy can be consulted.

15. Business Information

ItemDetail
Business nameExpandGlobal
RepresentativeJinho CHOI
Business registration number603-15-28553
Business address#500-18, 20-38 Mugunghwa-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, Republic of Korea
Inquiriesnick.choi@expandglobal.kr