SMK (hereinafter referred to as the “Company”) respects the privacy and personal data protection rights of its users. The Company processes personal data in accordance with applicable privacy and data protection laws, including the Personal Information Protection Act of the Republic of Korea and, where applicable, the European Union General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
This Privacy Policy applies to services and applications operated or provided by the Company (collectively, the “Services”). It explains what personal data may be collected, why it is processed, how it is protected, how long it may be retained, and the rights available to users.
For privacy-related questions, requests, or complaints, users may contact the Company using the email address above.
Where applicable law requires the appointment of a formal Data Protection Officer (DPO), the Company will provide the relevant DPO contact information through the applicable privacy notice or official policy page.
Depending on the Services used and the user's interaction with the Company, the Company may process the following categories of personal data:
The Company does not intentionally collect sensitive personal data unless such processing is necessary and permitted under applicable law.
Personal data may be collected through:
Depending on the functionality of a particular application, the Company may request access to certain device permissions.
Required permissions may include information necessary for application operation, such as device or application identifiers and storage access where required to save or manage content.
Optional permissions may include location information and push notifications. Users may generally deny optional permissions; however, certain features may not function correctly without the relevant permission.
The Company will request permissions in accordance with applicable platform requirements and applicable privacy laws.
The Company may process personal data for the following purposes:
For users in the European Union or European Economic Area, the Company relies on one or more lawful bases under GDPR Article 6, depending on the specific processing activity.
Where processing is based on consent, users may withdraw their consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The Company may use cookies, local storage, SDKs, or similar technologies where necessary to operate, secure, analyze, or improve the Services.
Where applicable law requires consent for non-essential cookies or similar technologies, the Company will obtain the required consent before using them and will provide appropriate controls for managing consent.
Users may also control certain cookies through their browser or device settings. Disabling certain technologies may affect the functionality of some Services.
The Company does not sell users' personal data.
The Company may disclose or provide personal data to third parties only where permitted or required by applicable law and where necessary for legitimate business or service purposes, including:
Where a third party processes personal data on behalf of the Company, the Company will take appropriate measures to require the processor to process personal data only in accordance with applicable law and the Company's instructions.
Depending on the location of the user and the service providers used by the Company, personal data may be processed or transferred outside the country in which the user resides, including outside the EU/EEA.
For EU/EEA users, where personal data is transferred to a country outside the European Economic Area, the Company will use an applicable lawful transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses approved by the European Commission, or another lawful safeguard recognized under GDPR.
Information concerning applicable transfer safeguards may be requested by contacting privacy@smk-dev.com.
The Company retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
Retention periods may vary depending on the type of data, the purpose of processing, legal obligations, dispute resolution requirements, security needs, and limitation periods for potential legal claims.
When personal data is no longer necessary, the Company will delete, anonymize, or otherwise securely dispose of the data in accordance with applicable law.
The Company takes reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, destruction, or other unlawful processing.
Depending on the nature and risk of the processing, such measures may include access controls, authentication, encryption or pseudonymization where appropriate, security monitoring, restricted access, backup procedures, and internal security policies.
No method of transmission or storage can be guaranteed to be completely secure. The Company therefore continuously reviews and improves its security measures where reasonably necessary.
If the Company becomes aware of a personal data breach, it will assess the incident and take appropriate containment, investigation, remediation, and notification measures in accordance with applicable law.
For EU/EEA users, where GDPR applies and a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the Company will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless an applicable exception applies.
Where GDPR requires communication of a high-risk breach to affected individuals, the Company will provide such notification without undue delay, subject to applicable law.
Depending on the applicable law and circumstances, users may have rights concerning their personal data, including:
These rights are not absolute and may be subject to legal exceptions or limitations.
Users may submit privacy-related requests by contacting the Company at privacy@smk-dev.com or through an available in-app inquiry function.
The Company may request reasonable information necessary to verify the identity of the requester and protect personal data from unauthorized disclosure.
The Company will respond to valid requests within the period required by applicable law. For EU/EEA requests, GDPR generally requires a response without undue delay and, in principle, within one month of receiving the request, subject to applicable extensions and exceptions.
EU/EEA users have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU/EEA country where they normally reside, work, or where an alleged infringement occurred.
Users in Korea may also contact the relevant Korean privacy protection authorities or dispute-resolution bodies in accordance with applicable Korean law.
The Services are generally intended for users who meet the applicable minimum age requirements for the relevant Service.
The Company does not knowingly collect personal data from children in violation of applicable law. Where applicable law requires parental or guardian consent for the processing of a child's personal data, the Company will implement appropriate measures to obtain or verify such consent where required.
If the Company becomes aware that personal data has been collected from a child in circumstances where such collection or processing is not permitted, the Company will take reasonable steps to delete or otherwise appropriately handle the information in accordance with applicable law.
The Company does not intend to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on users unless such processing is permitted under applicable law and appropriate safeguards are provided.
Where GDPR Article 22 applies, users may have rights relating to human intervention, expressing their point of view, and contesting certain automated decisions.
The Services may contain links to or integrations with third-party services, including application stores, payment providers, analytics services, or other platforms.
Third-party services operate under their own privacy policies and terms. The Company is not responsible for the privacy practices of third parties that independently determine how they process personal data.
For example, information concerning Google services may be found in Google's privacy policy, and information concerning Apple services may be found in Apple's applicable privacy policy.
The Company may update this Privacy Policy when necessary to reflect changes in the Services, applicable laws, regulatory requirements, or the Company's data-processing practices.
Material changes will be communicated through appropriate means where required by applicable law. The updated policy will be published on the official policy page and will take effect on the effective date stated in the updated version.
For privacy inquiries, data subject requests, complaints, or questions regarding this Privacy Policy, please contact the Company using the email address above.
Effective Date: February 12, 2024