96한국어日本語English

Apgujeong 96 Privacy Policy

Document version: 2026-10-03


Effective date: the day the Service opens · Version: 2026-10-03

timoworks Inc. (the Company), at 522, 135 Gasan digital 2-ro, Geumcheon-gu, Seoul, Republic of Korea, processes personal data to provide Apgujeong 96 as described below. Contact contact@timo.work or 02-6177-7325 about privacy. The Company is based in South Korea and also processes Japanese users' information. Rights under applicable Korean and Japanese personal data protection laws are respected.

1 Data purposes and legal bases

1.1 Processing needed for the basic service

Category Data Purpose Basis under Korean law
Registration and account Email, member identifier, sex, birth year, age-eligibility result and verification date, profile photo, chosen city or district Account, identity and age checks, profiles and matching PIPA Article 15(1)(4), necessary steps to enter into or perform the contract
Identity and age check Masked identity image; name, birth date, photo and document type visible during review; result and date Verify identity and minimum age Article 15(1)(4); a statutory-obligation basis only to the extent that a specific obligation applies
Conversations and meetings Recipient identifiers, message text and attachments, transmission times, meeting dates and places, responses, cancellation and attendance Deliver requested conversations, manage meetings and statistics Article 15(1)(4); disclosure to other members is subject to Section 4 consent
Purchases and refunds Random purchase-link identifier, product and transaction IDs, payment, expiry, cancellation and refund status; necessary transaction times, amounts and currencies Pass management, payment verification and refunds Article 15(1)(4) and statutory retention under Article 15(1)(2)
Use and security Access times, OS, device model, app version, session/authentication status, interest, block and feature records, push tokens, reports, evidence, measures and appeals Service provision, account security and report handling Necessary contract performance under Article 15(1)(4); separate retention only where the legitimate-interest conditions below are met
Access IP and infrastructure logs We keep administrator access logs for two years and then delete them. Holding them longer is a risk, not protection. To keep a record of administrators viewing or handling member information, so we can tell who saw what and when Access-log retention required by Korea’s safeguards standard for personal data

Data comes from user input and uploads, messages and reports from the member or another person, service-generated records and Apple transaction notifications. Sign-in uses a code sent by email and does not require a phone number. If you optionally register your own number for Hide people you know, we process it for that feature. If an alternative repayment requires bank information, the minimum data, purpose, period and basis are explained before collection.

Verification uses 신분증 등 공적 증명서. National identification, resident registration, passport, driving-licence and similar document numbers are not requested and must be masked. The submission screen distinguishes necessary birth-date and other verification details from information to conceal. If an unmasked file is discovered, its use is stopped and deletion and resubmission are arranged. For age-verification documents, we do not retain the legal name or full date of birth as separate fields; we retain the birth year, eligibility result and verification date. For male members’ income or asset verification, we retain the initially verified legal name with the account to compare the ownership of later documents. The legal name is not disclosed to other members and is deleted on account closure. Section 3 separately describes re-registration restriction identifiers. No CI/DI identity-agency service is used. A submitted file is held temporarily only while review is pending, and is deleted as soon as it is judged or after up to 24 hours from submission, whichever comes first — reviewed or not.

Viewing and temporarily storing an image is processing personal data even if its contents are not extracted into separate fields. The Company does not describe that temporary processing as non-collection.

1.2 Additional checks and optional features

Feature Data Purpose and basis Effect of refusing or withdrawing
Optional profile Introduction, preferences, desired frequency and exclusions, interests, available days, height/build Optional profile creation and sharing, with separate collection/use and disclosure consent Only those fields are unavailable or hidden
Income/asset checks and optional employment checks Necessary parts of masked documents, names and income/asset amounts visible during review, legal name for document ownership comparison, job category or financial band, check date Consent to the requested document check; separate consent to disclosure Male profiles are not listed and new Pass purchases are restricted until income or assets are checked. Female members are not asked for income/asset documents. Declining employment checks only removes the employment verification display
Hide people you know Own mobile number, HMAC matching values generated from address-book numbers, identifiers/status needed for mutual hiding Optional activation; consent for the member's own number; other people's data only with a verified lawful basis Only this feature stops
Fill area from current location Device coordinates and derived city/district name Area entry with device permission; coordinates stay on-device and only the chosen area name reaches the server Manual area selection remains available
Translation Selected message text, source/target language codes, output and consent status Optional translation, with separate international-transfer consent in Section 6 Translation only is unavailable; original conversations and meetings remain available
AI writing suggestions for profile answers Display language, the selected question, the selected words, the user's notes (up to 120 characters after anything that looks like contact details is removed), daily usage count Generating the suggested sentences the user asks for, with international-transfer consent for each request in Section 6 Starting sentences made on the device keep working
Plan-sharing link and check-in Sharing member's identifier; the shared meeting's start time, estimated duration, city/district area and venue name; a hash of the link token; link creation, expiry and closing times; the check-in status the member taps ("I've arrived", "All done") and its time Letting the person who receives a link the member created check the meeting plan. Optional feature the member turns on If you don't share, or close the link, only this feature is unused; conversations and meetings continue as normal
Voice introduction Recorded audio (up to 30 seconds, re-encoded on our server with file metadata removed), its length, the text alternative the member writes (up to 300 characters), review status, reason, review time and reviewer (automated tool or staff member) Showing the voice introduction the member chooses on their profile. Before it is shown, it is reviewed using automated tools (AI), and a staff member checks it where needed. Review results are not sent as separate notifications; you can see the status on your own screen. Optional feature the member turns on If you don't add one, or delete it, only the voice introduction is not shown; everything else continues as normal
In-app voice and video calls Per-conversation call settings (voice and video separately), call records (caller and callee member IDs, call type, ring/answer/end times, end-reason code), live audio during a call and live video when the member turns the camera on, and the IP address, network and device information needed to connect Connecting calls between members who have already exchanged messages, enforcing call length and frequency limits, and reviewing reports. Optional feature each member turns on per conversation; the international transfer for relaying calls is described in Section 6.4 If you do not turn calls on, or turn them off, only calls in that conversation are unavailable; conversations, meetings and other features continue as normal

Address-book names, photos and emails are not transmitted. Matching values derived from phone numbers may still be personal data. The server does not store the raw address book and deletes matching values immediately after comparison. Necessary hiding relationships are deleted when the feature is disabled or the account closes. We validate the format of a registered number but do not verify ownership through SMS or an equivalent method. The number is used only for matching, not for sign-in, advertising or contact disclosure. Complete accuracy or hiding from every acquaintance is not guaranteed. The feature does not disclose matching identities, membership status or counts.

Possessing someone's number or granting device permission does not itself establish the Company's legal basis for processing it. This feature is offered only within a verified lawful basis and safeguards that cover non-members as well.

A plan-sharing link does not include the other member's name, photos or profile, conversation content, the meeting's one-line note, the venue address or any location data. We do not read your address book; you choose the recipient yourself in your device's share sheet, and we do not know who receives the link. Our service database does not store the link token itself, only its hash. Check-in is optional, and we do not monitor check-ins or notify anyone about them.

A voice introduction plays only after approval, and only for members who can open your profile details. Playback addresses are valid for a short time only; there is no public address. Because a voice can identify a person, audio is kept in private storage and only staff authorised for review or report handling can listen to it. When you delete or re-record, the previous audio is deleted without delay. Audio cited in a report is kept, shown to no one, until that report is resolved, and then deleted.

In-app calls are never recorded, and the Company does not store call audio or video on its servers. Video calls start with the camera off, and video is sent only after the member turns it on. Microphone and camera access is requested only when placing or answering a call, or when turning the camera on. Your phone number is not shared with the other person.

1.3 Information not requested and free-form content

Marriage/family documents, education, religion, political opinions, health and sex-life data are not requested as profile fields. Information voluntarily included in messages, reports or free text may nevertheless be processed. Do not enter another person's private data, identification numbers or unnecessary sensitive data. Separate processing of sensitive categories requires its own lawful basis or consent.

The Company does not collect IDFA/AAID, track for advertising or send marketing messages. While you use the service we automatically record sign-in times and your device and app version. We do not collect advertising identifiers. Necessary account, security and billing notices are distinct from marketing.

2 Visibility and processing principles

  1. Profile visibility follows the screen reviewed by the member and Section 4 consent. Legal names, email, mobile numbers and original verification documents are not shown to other members.
  2. Profile-view records identify viewer, viewed member and date. Only a count is shown to the profile owner; repeat visits by the same person on a day count once. Viewer lists are not disclosed.
  3. Only authorized personnel may access data needed for reports, troubleshooting or lawful requests. Continuous unrestricted access to conversations is not permitted.
  4. For safety-related legitimate-interest retention, the Company assesses the lawful purpose, necessity, alternatives, impact and safeguards. PIPA Article 15(1)(6) is used only where the interest clearly outweighs the individual's rights and remains reasonably related and proportionate. Merely labelling retention as criminal defence does not justify keeping everything.

3 Retention

Data is deleted earlier where its purpose ends or a valid deletion request or other event removes the basis for retention. Statutory retention and a specific lawful case hold apply only to segregated relevant records.

Record Maximum period or deletion trigger
Account, profile, photos, verification results, legal name used to compare document ownership, active sessions, interest, notices, own number and ordinary hiding relationships Without delay on closure or end of purpose; optional data earlier on withdrawal/deletion
Pending identity and supporting files Earliest of decision, 24 hours after submission or account closure
Conversations and attachments While providing the conversation; when either member's closure ends it, no more than 30 days after that end, or earlier if legally required
Company translation cache Earliest of original deletion or withdrawal of that conversation's translation consent; processor retention is separate in Section 6
AI writing suggestions daily usage record (date, member, count) 7 days from that date. What is sent and the suggestions returned are not stored
Call records Deleted 90 days after the call ends. Records left unfinished (still ringing or in progress) are deleted 90 days after the call was placed. Audio and video content is not stored. Deleted without delay when either member closes their account. Per-conversation call settings are deleted on account closure or with that conversation. Processor retention is listed separately in Section 6.4
Meeting and attendance records Up to 1 year from completion/cancellation; on either member's closure, the earlier of 30 days after closure or the existing expiry
Plan-sharing links and check-in records A link closes automatically 6 hours after the meeting's scheduled end, and the member can close it at any time. Closed or expired links and their check-in records are deleted 1 day later. Links close immediately if the meeting is cancelled or the sharing member closes their account; on account closure the records are deleted without delay
Ordinary report, measure and appeal evidence Up to 180 days after case closure, limited to necessary evidence; unresolved cases reviewed at least every 90 days
Voice introductions (audio, text alternative, review record) Without delay when the member deletes, re-records or closes their account. Rejected ones are deleted 30 days after the decision. Ones cited in a report stay hidden and are deleted together with that report record under the "Ordinary report, measure and appeal evidence" period
Confirmed serious-violation re-registration matching key Earlier of 1 year after the final measure or removal of the restriction; routine lookup or attempted re-registration does not reset the clock
Photo-access records Up to 90 days from the event; necessary extracts may be segregated as incident evidence
Profile-view records 30 days from the event
Minimum investigation records for expired sessions 30 days after expiry
Administrator data-access logs 2 years from the event; legal retention and internal audit purposes managed separately
Access IP, infrastructure and automatic-collection logs Individual periods disclosed in Section 1
Terms and privacy consent/withdrawal evidence Contract evidence up to 5 years after contract end; privacy consent evidence for the necessary period up to 3 years after the relevant processing ends; no original messages or identity documents in consent evidence
Advertising/display records subject to Korean e-commerce retention 6 months
Contract, withdrawal, payment and supply records subject to Korean e-commerce retention 5 years
Consumer complaint/dispute records subject to Korean e-commerce retention 3 years

The final three periods are calculated from creation of the relevant transaction or processing record under the applicable statute. Providing a Japanese-language service does not itself impose a blanket seven-year Japanese tax retention period on all records. Any additional applicable statutory duty is disclosed by item, legal basis and period.

Post-closure conversation retention is limited to the other participant's access, evidence preservation and report handling for up to 30 days. Profile links are removed, but the content may still identify people and is not considered anonymous. Deletion or restriction requests are assessed individually against the lawful basis and other participants' rights; 30 days is not an unconditional minimum.

A re-registration key combines verified name/birth-year information with a secret key as an HMAC. It is protected as personal data because it enables matching, even though it is not a plain-text name. Keys and source data are separated. A name/birth-year match alone does not establish identity or wrongdoing; re-verification and appeal are available. Unverified reports and ordinary closure do not justify a one-year block. A minor-status finding alone requires a separately assessed minimum period for eligibility re-verification.

A specific investigation, court case, dispute or valid preservation order may require an additional hold. The Company records its legal basis, scope, end condition and review date, restricts access and preserves only relevant data. It does not automatically retain every record until limitation periods expire. Data is deleted without delay when the basis ends.

4 Disclosure to members and other recipients

4.1 Member-selected sharing

Recipient Data Purpose Duration and refusal effect
Age-verified members within the selected visibility settings Profile photo, sex/age derived from birth year, city/district, selected optional profile, verification and attendance statistics, and the approved voice introduction with its text alternative Finding people and matching Until visibility withdrawal, closure or the permitted relationship ends; refusing prevents profile discovery/matching, not Support or rights requests
Selected conversation/meeting participant Messages, attachments, date/place, responses and attendance confirmation Conversation and meetings Section 3 periods and permitted access; refusal affects only that communication/meeting
Individually permitted photo recipient Private photo Selected private sharing Until permission withdrawal or account closure; optional
The person the member chooses in the device share sheet (may not be a member) Meeting date, time, estimated duration, city/district area, venue name; check-in status and time Letting someone the member trusts know the plan Until the link is closed or expires. Not sharing does not affect any other feature

Separate consent identifies recipient scope, fields, purpose, period and refusal effects. Optional profile, verification and private photos are limited to the consented selection. Recipients must not reuse or save/distribute information without permission, but copies already made outside the Service cannot be fully recovered technically.

4.2 App Store

Purchases, renewals and refunds use Apple's App Store. The Company sends a random appAccountToken and product ID and receives signed transaction, expiry, cancellation and refund data. Apple directly processes Apple Account and payment-method data under its own policy; the Company does not receive those details.

In-app payments go through the App Store. We receive only the result of receipt validation (product, period, transaction identifier). We never receive card numbers or other payment details. Where required, separate consent is obtained before purchase. International transfers are separately described in Section 6. See also Apple's Privacy Policy.

4.3 Lawful requests

Disclosure is limited to necessary data after verifying statutory grounds, valid warrants/orders or other lawful conditions. An authority's request alone is not sufficient. Statutory notice duties are observed. Additional notice is given where lawful and consistent with victim safety, others' rights and a lawful investigation. Any deferral or restriction is documented.

5 Processors

Processor Work Countries and details
Amazon Web Services, Inc. Hosting and storage Amazon Web Services, Inc. — server operation and data storage (photos and documents, email delivery), in the Seoul region (ap-northeast-2).
Google LLC (Firebase Cloud Messaging) Push notifications Google LLC (Firebase Cloud Messaging) and Apple Inc. — delivering notifications
OpenAI OpCo, LLC (1) Suggested sentences for profile answers (only when the user asks, with consent for each request) (2) Separately consented conversation translation (3) (if introduced) Assistive notes for identity and income document review Section 6.2
LiveKit, Inc. Real-time relay of in-app voice and video calls (only when the member has turned calls on in that conversation) Section 6.4
Other processors and subprocessors Google LLC — venue search (your search term and area are sent) and Android receipt validation / Apple Inc. — App Store receipt validation Countries, tasks and entities identified in that disclosure

Contracts address purpose limits, safeguards, subprocessors, retention/deletion, incident response and supervision. The Company oversees compliance. International outsourcing can be both entrusted processing and an international transfer, and both sets of requirements apply.

6 International transfers

Overseas access or processing can be a transfer even if the server remains in Korea. Information Japanese users provide directly to the Korean Company is distinguished from onward disclosure to another entity or member.

6.1 Core infrastructure and payment

Recipient: OpenAI OpCo, LLC · Country: United States · Items: (1) the profile question, picked words and notes for an AI writing suggestion you request (2) the original text of messages you ask to translate · Purpose: (1) generating suggested sentences (2) translation · When: each time you make the request (details in Section 6.2) / Recipient: LiveKit, Inc. · Country: United States (processed in LiveKit data centers in Japan, Singapore, the United States and elsewhere) · Items: call audio and video, connection IP address and device information, participant values and room names that differ for every call · Purpose: relaying in-app calls · When: from the moment the callee answers until the call ends (details in Section 6.4)

Each route identifies fields, country, timing/method, recipient entity/contact, purpose, retention, legal basis and refusal method/effects. Necessary international entrusted processing/storage for contract performance may use statutory disclosure/notification procedures. That exception is not a blanket basis for third-party disclosure or all optional features. Consent-based transfers require separate consent and renewed consent for changes where required by law.

6.2 AI writing suggestions, conversation translation and document-review assistance (if introduced) using OpenAI

Below, (1) is AI writing suggestions for profile answers, (2) is optional conversation translation, and (3) is assistance with identity and income document review. (3) has not been introduced and nothing is sent for it today.

Item Details
Data (1) Display language, the selected profile question, the selected words (up to 3) and the user's notes (up to 120 characters after anything that looks like an email address, phone number, link or social media ID is removed) (2) Selected message text and language codes. Names/contact details written in the text may be included (3) Not introduced. For no purpose are member ID, legal name, phone number, photos, age or similar separate fields, or information about the other person in a conversation, sent
Recipient and contact OpenAI OpCo, LLC / 1455 3rd Street, San Francisco, CA 94158, USA · privacy@openai.com
Countries United States
Timing and method (1) Sent only for the request where the user taps "Get AI suggestions" and chooses "Send this once" on the consent screen; consent is asked again for each request (2) Sent on a translation request only while both participants have valid consent, and only for messages written after that consent (3) If introduced, this table is updated beforehand and the required notice and consent steps are taken. In every case data is sent at the moment the user makes the request, over an encrypted network (TLS); no background pre-transfer or bulk transfer of earlier history
Purpose (1) Generating suggested sentences for profile answers (2) Requested translation (3) (if introduced) Assistive notes shown to the reviewer; a person makes the final decision. No advertising or model-training use permitted
Processor retention OpenAI does not use data received through its API to train models. Abuse-monitoring logs are kept for up to 30 days and then deleted, unless the law requires longer. We do not use zero data retention, and we send requests with store:false so OpenAI’s response-storage feature is not used.
Subprocessing and safeguards Under the OpenAI Data Processing Addendum (DPA) and the subprocessor list OpenAI publishes. Data is sent over an encrypted network (TLS).
Company retention (1) What is sent and the suggestions returned are not stored; only a daily-limit counter (date, member, count) is kept for 7 days (2) Translations until original deletion or withdrawal of the conversation's translation consent, whichever is earlier
Basis Separate consent under Korean PIPA Article 28-8(1)(1) ((1) per request, (2) per conversation); Article 26 also applies to entrusted processing
Refusal/withdrawal (1) Do not tap "Get AI suggestions", or choose "Do not send" on the consent screen (2) Decline at the consent screen or withdraw in conversation translation settings, privacy settings or through Support
Effect (1) Starting sentences made on the device keep working (2) Only translation stops. Original messaging and meetings continue. Either person's withdrawal stops new transfers and deletes the Company's cache for that conversation; processor-held data follows the disclosed period and lawful deletion procedure. In no case is any other feature restricted

Output is labelled machine translation and the original remains available. Hiding translation display is distinguished from withdrawing transfer consent. Remove other persons' private information or sensitive data before requesting translation; sensitive data is not sent without a separate lawful basis. AI writing suggestions are only a draft placed in the answer box; they appear on the profile only after the user edits and saves them.

Information on foreign legal systems and recipient safeguards for Japanese-law purposes (APPI Article 28): Country: United States. For the US system for protecting personal information, see the United States section of the survey of foreign personal-information protection systems published by Japan’s Personal Information Protection Commission (the US has no comprehensive federal privacy law; protection comes from sector-specific federal laws and state laws). Recipient’s measures: OpenAI OpCo, LLC does not use data received through its API to train models, and keeps abuse-monitoring logs for up to 30 days before deleting them, unless the law requires longer. Handling follows the OpenAI Data Processing Addendum (DPA) and its published subprocessor list, and data is sent over an encrypted network (TLS).

6.3 Cross-border matching

Current availability and countries: Cross-border matching is not open yet. Today what members write leaves the country in only two cases, AI writing suggestions for profile answers (consent for each request) and message translation (optional consent), and only if you agree. In-app voice and video calls, which you turn on per conversation, pass call audio and video through call relay servers run by LiveKit, Inc. (United States) while the call lasts (Section 6.4).

If you turn translation on, the original text of the messages you ask to translate is sent to OpenAI in the United States. Nothing is sent if you leave it off, and nothing further is sent once you turn it off. If you use AI writing suggestions for profile answers, the question, the words you picked and your notes are sent to OpenAI in the United States each time, after you agree. Nothing is sent if you do not use them. In-app voice and video calls are available only if you turn on "Receive voice calls" or "Receive video calls" in that conversation. During a call, your audio (and, in a video call, your video once you turn the camera on) reaches the other person through data centers of LiveKit, Inc. (United States) in Japan, Singapore, the United States or elsewhere. Nothing is sent if you leave calls off or do not place or answer a call.

Before offering this feature, the Company identifies countries, recipient scope/contact route, data, purpose, transfer timing/method, retention and refusal effects, and obtains required third-party disclosure and international-transfer consents separately. Merely selecting a preferred country is not a substitute. Refusal limits that overseas visibility only; same-country features remain available.

6.4 In-app voice and video calls using LiveKit

In-app calls are an optional feature each member turns on per conversation. The data below is sent only after the callee answers, and the Company does not record calls.

Item Details
Data Live audio during a call, live video when the member turns the camera on, connection IP address, network information, device/app information (SDK type and version, operating system and similar), participant values and room names that differ for every call and do not reveal member IDs or names, and connect and disconnect times. Member names, phone numbers, profile photos and member IDs are not sent
Recipient and contact LiveKit, Inc. / see LiveKit’s privacy policy for contact details
Countries United States (where the recipient, LiveKit, Inc., is based). Calls are actually relayed through the LiveKit data center nearest each participant; processing locations are Japan (Tokyo, Osaka), Singapore, the United States and others. Calls between members in Korea and Japan usually go through a data center in Japan, but because we have not pinned a processing region they can also pass through Singapore, the United States or elsewhere.
Timing and method From the moment the callee answers until the call ends, sent in real time over encrypted connections (TLS, DTLS-SRTP). Nothing is sent while the call is ringing
Purpose Relaying calls between two members only. The Company does not turn on recording or transcription
Processor retention Audio and video are only passed to the other person during the call and are not recorded or stored (we do not turn on recording). Retention of connection logs and other records the processor keeps follows the processor’s own policy.
Subprocessing and safeguards Data is sent over encrypted connections (TLS, DTLS-SRTP). We create a room for at most two people only after the callee answers, and give access only to the two people on that call, valid for the call’s remaining time (with no permission to record, send data or share screens). When the call ends we delete the room, and if LiveKit notifies us that an ended call’s room has been re-created or that someone other than the two people has joined, we delete the room or remove that participant. The subprocessors LiveKit uses are listed in LiveKit’s subprocessor list.
Company retention Call records (times, type, end reason and similar) for 90 days after the call ends, under Section 3. Audio and video are not stored
Basis Entrusted processing necessary to provide the call feature the member turns on, with the items in this table disclosed in this Policy (Korean PIPA Article 28-8(1)(3)); Article 26 also applies to entrusted processing
Refusal/withdrawal Do not turn on, or turn off, "Receive voice calls" / "Receive video calls" in that conversation's call settings. Even with calls on, nothing is sent unless you place or answer a call. You can also contact Support
Effect Only calls in that conversation become unavailable. Conversations, meetings and other core features continue, and no other feature is restricted

Information on foreign legal systems and recipient safeguards for Japanese-law purposes (APPI Article 28): Country: United States (where the recipient, LiveKit, Inc., is based); calls are relayed in LiveKit data centers near the participants, such as in Japan, Singapore and the United States. For the US system for protecting personal information, see the United States section of the survey of foreign personal-information protection systems published by Japan’s Personal Information Protection Commission (the US has no comprehensive federal privacy law; protection comes from sector-specific federal laws and state laws). For Singapore, see the Singapore section of the same survey (Singapore has the Personal Data Protection Act, the PDPA). Recipient’s measures: calls are relayed over encrypted connections (TLS, DTLS-SRTP), and audio and video are only passed on, not recorded or stored. We give no recording permission, create a room for each call that only those two people can join, and delete the room when the call ends. Retention of connection logs and similar records follows the recipient’s own policy.

7 Deletion and backups

Electronic data is deleted using methods that prevent practical recovery; paper is shredded or incinerated. Statutorily retained records are separated from operational data and accessible only for that purpose.

The decision/24-hour verification deadline also applies to storage, temporary files and processing queues. Reviewers must not download or make separate copies. When you delete, the data goes from the live database immediately. Copies in recovery backups fall away as those backups age out, and are used for recovery only in the meantime. Deletion records are applied to restored backups so erased data is not republished.

8 Rights and requests

Members may request access, correction, deletion, restriction, withdrawal of consent and, where applicable, disclosure-record access. Use privacy settings, contact@timo.work or 02-6177-7325; lawful representatives may act. Verification uses minimum necessary information.

Korean-law access requests are normally handled within 10 days; statutory extensions are explained with a timetable. Correction, deletion, restriction and other requests follow their own legal deadlines without delay. Japanese-law disclosure, correction and cessation requests concerning retained personal data are handled under the applicable conditions. Full or partial refusals are explained with their legal basis.

Withdrawing an optional consent does not automatically end the basic service. If stopping essential processing makes the contract impossible to perform, the specific impact and closure/refund options are explained. Deletion can be limited to the extent required by statutory retention.

9 Security

Measures include least-privilege access, training, internal procedures, access-log review, appropriate transmission/storage encryption, key separation, vulnerability management and processor supervision. Physical protection matches the Company's and processors' actual facilities. Foreign legal environments and necessary safeguards are assessed for international processing.

Incidents trigger containment and investigation, and user notices and regulator reports follow applicable thresholds, content, deadlines and procedures. Passing tests or having no dedicated identifier field does not guarantee that leaks are impossible or data anonymous.

10 Age limits and automated decisions

The minimum age is 19. Additional information for Japanese users: In Japan the service is for people aged 18 and over. In Korea it is 19 and over. Higher applicable statutory standards prevail. Reasonable doubts about age may lead to necessary temporary restrictions, re-verification and appeal.

We use automated checks to assist photo and document review. A person makes the final decision — we do not make decisions adverse to you on automated processing alone. Statutory explanation, objection and review rights are respected where applicable.

11 Contacts

Data protection officer: 타무라 코지 / 대표 / contact@timo.work / 02-6177-7325

External advice and dispute-resolution bodies:

  • 개인정보침해신고센터 (privacy.kisa.or.kr / 118)
  • 개인정보 분쟁조정위원회 (kopico.go.kr / 1833-6972)
  • 경찰청 사이버수사국 (ecrm.police.go.kr / 182)

Privacy advice and supervisory authority: 개인정보보호위원회 / privacy.go.kr

12 Changes

Ordinary changes are notified 7 days in advance and material changes 30 days in advance. Where immediate legal compliance is required, the Company explains and notifies without delay. Publishing or amending this Policy does not replace separate consent; required new consent precedes processing. Earlier versions are available on request at contact@timo.work.