▲ LEGAL · PRIVACY POLICY

Privacy Policy

Kosmo's12 Inc. ("Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) of the Republic of Korea and other applicable laws to protect users' personal information and to handle related complaints promptly and effectively.
This policy applies to all services, including the company website and the mobile game Dynamite Blue.

Effective May 6, 2026 Last Revised May 6, 2026 Operator Kosmo's12 Inc.
SECTION_02 / PRIVACY_POLICY

[ ART. 01 ]Article 1. Purpose of Processing Personal Information

The Company processes personal information for the following purposes only and will not process personal information for any other purpose without the data subject's consent.

  1. Account Registration and Management — identification and authentication, maintenance and management of membership status, prevention of fraudulent use, and record retention for dispute resolution
  2. Service Provision — providing the Dynamite Blue game, content delivery, personalized services, identity verification, billing and settlement
  3. Marketing and Advertising — development of new services and personalized offerings, delivery of event and promotional information, frequency-of-access analysis
  4. CBT Pre-registration — sending launch notifications and pre-registration rewards
  5. Customer Support — responding to inquiries, handling complaints, sending notices
  6. Legal Obligations — fulfilling retention obligations under applicable law

[ ART. 02 ]Article 2. Items of Personal Information Collected and Methods

1. Company Website — CBT Pre-registration

▲ COLLECTED · WEBSITE

Required Name, email address

Auto-collected IP address, access date and time, browser information, cookies, service usage records

2. Mobile Game Dynamite Blue

▲ COLLECTED · GAME

Required Nickname, device identifier (ADID/IDFA, etc.), OS and device information, country code, language settings

Optional Email address (for account linking and recovery), SNS account identifier (Apple ID, Google account, etc., when linked)

Game Data Character information, level, gameplay progress, play history, in-game currency balance, friend list, in-game chat and inquiry content

Payment Data Payment method, date and time of payment, amount, receipts, refund records (individual card numbers and similar data are processed by the payment processor and not retained by the Company)

Auto-collected Device model, OS version, IP address, access logs, error logs, advertising identifiers, cookies, game client diagnostic data

3. Methods of Collection

  • When entering information in the website pre-registration form
  • When registering or linking accounts within the game
  • When using customer support (email, in-game 1:1 inquiries)
  • When participating in events or surveys
  • Automatically generated during service use (cookies, logs, device information)

[ ART. 03 ]Article 3. Processing and Retention Period

The Company processes and retains personal information within the retention and use period required by law or agreed to by the data subject at the time of collection.

CategoryRetention PeriodBasis
Member InformationUntil withdrawal of membershipUser Consent
CBT Pre-registration6 months after launch notificationUser Consent
Records of contracts or withdrawal of subscription5 yearsE-Commerce Act
Records of payment and supply of goods5 yearsE-Commerce Act
Records of consumer complaints or dispute resolution3 yearsE-Commerce Act
Records of advertising and labeling6 monthsE-Commerce Act
Access logs, IP and other communication records3 monthsCommunications Privacy Act
Records for fraud prevention1 yearUser Consent

[ ART. 04 ]Article 4. Provision of Personal Information to Third Parties

  1. The Company processes the data subject's personal information only within the scope specified in Article 1 (Purpose of Processing) and provides personal information to third parties only with the consent of the data subject or where specifically permitted by Articles 17 and 18 of the Personal Information Protection Act.
  2. The Company currently does not provide users' personal information to third parties. If third-party provision becomes necessary in the future, the Company will give prior notice to the data subject and obtain consent.

[ ART. 05 ]Article 5. Outsourcing of Personal Information Processing

To provide services smoothly, the Company may outsource the processing of personal information as follows.

Outsourced TaskService ProviderScope
Cloud InfrastructureAWS / Google Cloud, etc.Server hosting and data storage
Payment ProcessingApple, Google, etc.In-app purchase processing
Email / Push NotificationsEmail and push delivery service providersNotice and marketing notifications
Game Operations & AnalyticsGame operations tooling providersAccess log analysis, abuse detection
Customer SupportCustomer service system providers1:1 inquiry handling

Pursuant to Article 26 of the Personal Information Protection Act, when entering into outsourcing contracts, the Company specifies in the contract the prohibition of processing for purposes other than the outsourced task, technical and managerial protection measures, restrictions on re-outsourcing, supervision over the contractor, and liability for damages, and supervises whether the contractor handles personal information securely.

[ ART. 06 ]Article 6. Rights and Obligations of Data Subjects and Legal Guardians

  1. The data subject may exercise the following rights at any time.
    • Request to access personal information
    • Request to correct errors
    • Request to delete
    • Request to suspend processing
    • Withdrawal of consent
  2. The exercise of rights under Paragraph 1 may be made in writing, by email, or by fax in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
  3. If the data subject requests correction or deletion of erroneous personal information, the Company will not use or provide such personal information until correction or deletion is completed.
  4. The exercise of rights under Paragraph 1 may be made through a legal guardian or an authorized representative. In such cases, a power of attorney prepared in the form prescribed by Notice No. 2020-7 of the Personal Information Protection Commission must be submitted.

[ ART. 07 ]Article 7. Destruction of Personal Information

  1. The Company will destroy personal information without delay when the retention period has elapsed or the purpose of processing has been achieved.
  2. If retention is required under other laws despite expiration of the agreed retention period or achievement of the processing purpose, the Company will move the personal information to a separate database or storage location.
  3. The procedure and method of destruction are as follows.
    • Procedure — personal information for which destruction is required is identified and destroyed with approval of the Company's Data Protection Officer.
    • Method — electronic files are permanently deleted using technical methods that prevent recovery; paper documents are shredded or incinerated.

[ ART. 08 ]Article 8. Security Measures

The Company takes the following measures to ensure the security of personal information.

  • Administrative Measures — establishment and implementation of internal management plans, minimization and regular training of personnel handling personal information
  • Technical Measures — access control of the personal information processing system, installation of access control systems, encryption of unique identifying information, installation of security programs
  • Physical Measures — access control to data centers and document storage areas
  • Transmission Security — use of SSL/TLS encryption for transmitting personal information

[ ART. 09 ]Article 9. Installation, Operation, and Refusal of Cookies

  1. The Company uses "cookies" to store and retrieve usage information in order to provide individualized services.
  2. Cookies are small pieces of information sent by the website server (HTTP) to the user's browser and may be stored on the user's hard disk.
    • Purpose of Cookies — to identify visit and usage patterns of services, popular search terms, secure access status, and to provide users with optimized information
    • Refusing Cookies — users can refuse cookie storage through browser settings (e.g., Tools > Internet Options > Privacy)
    • Effect of Refusal — refusing cookies may make it difficult to use personalized services

[ ART. 10 ]Article 10. Personal Information of Children Under 14

  1. The Company obtains consent from a legal guardian when collecting personal information of children under the age of 14.
  2. The legal guardian may exercise the rights of the child to access, correct, delete, or suspend the processing of personal information.
  3. The Company does not collect personal information from children under 14 for the purpose of marketing communications.

[ ART. 11 ]Article 11. Installation, Operation, and Refusal of Auto-Collected Data

  1. The Company may automatically collect advertising identifiers (ADID/IDFA) and device information for service operation, fraud prevention, and statistical analysis.
  2. Users can refuse data collection for advertising purposes by enabling tracking restriction features in their device settings.
    • iOS — Settings > Privacy & Security > Tracking > Allow Apps to Request to Track
    • Android — Settings > Google > Ads > Delete advertising ID

[ ART. 12 ]Article 12. Data Protection Officer

The Company has designated a Data Protection Officer to oversee personal information processing and to handle complaints and remedies relating to personal information processing.

▲ DATA PROTECTION OFFICER

Name YOUNGZUN CHOI (Chief Executive Officer)

Role Data Protection Officer

Organization Kosmo's12 Inc.

Contact gaegu@kosmos12.com

Data subjects may direct any inquiries, complaints, or requests for remedies regarding personal information protection arising from use of the Services to the Data Protection Officer. The Company will respond and address such matters without delay.

[ ART. 13 ]Article 13. Remedies for Infringement of Rights

Data subjects may apply for dispute resolution or consultation with the following organizations to seek redress for personal information infringement.

OrganizationPhoneWebsite
Personal Information Dispute Mediation Committee+82-1833-6972www.kopico.go.kr
Privacy Infringement Report Center (KISA)118 (within Korea)privacy.kisa.or.kr
Cybercrime Investigation Division, Supreme Prosecutors' Office1301 (within Korea)www.spo.go.kr
National Police Agency Cyber Bureau182 (within Korea)ecrm.police.go.kr

[ ART. 14 ]Article 14. Changes to the Privacy Policy

  1. This Privacy Policy applies as of the effective date. If there are any additions, deletions, or modifications, they will be announced through notices at least 7 days before the change takes effect.
  2. For changes unfavorable to users, notice will be given at least 30 days in advance, and separate consent will be obtained where necessary.

[ ANNEX ]Annex

This Privacy Policy is effective as of May 6, 2026.

CompanyKosmo's12 Inc.
CEO / DPOYOUNGZUN CHOI
Address23, Eonnam 11-gil, Seocho-gu, Seoul, 2F, Republic of Korea
EstablishedFebruary 23, 2026
Contactgaegu@kosmos12.com
Note If a translated version of this Privacy Policy is provided in another language, in case of any conflict, the Korean version shall prevail.