The separate notice above applies to the collection and use of personal information for the newsletter. Version 1.4 below applies to sign-up and the core service. The description of the newsletter as not yet launched in the original text reflects the position when that document was published.
View the full Privacy Policy v1.4 for sign-up and the core service
011. Basic principles for processing personal information
1. The Company processes only the minimum personal information necessary to provide the Service.
2. Declining to provide optional information or to receive marketing communications places no restriction on the core Service beyond the optional feature concerned.
3. Because the Service does not currently provide artwork transactions, payment, shipping or settlement, we do not collect payment information, order and shipping information or tax invoice information.
4. The Company destroys personal information without delay once its processing purpose has been achieved or its retention period has ended. However, the minimum information necessary to meet legal obligations, handle disputes or maintain the reliability of authentication records already issued may be retained on a separate legal basis and for a defined period.
022. Purposes, categories, legal bases and retention periods
| Type | Purpose | Categories processed | Legal basis | Retention period |
|---|
| Email sign-up | Account creation, login, identification, essential notifications | Email address, name or nickname, password verifier, member type, versions of the terms and policy accepted and the time of acceptance | Conclusion and performance of a contract (Personal Information Protection Act, Article 15(1)(4)) | Until membership ends. Passwords are never stored in plain text |
| Google and Kakao login | Sign-up and login using an external account | Provider identifier, email address, name or nickname, profile image (where provided or selected), login provider | Conclusion and performance of a contract | Until membership ends |
| Consent and contract records | Evidencing consent, handling disputes | Versions of the terms and policy, time of consent or withdrawal, confirmation of being aged 14 or over, account identifier, identifiers of the screen and wording shown at the time | Legitimate interests of the Company, the data subject or a third party (Article 15(1)(6)) | 3 years after termination or withdrawal |
| Artist Member application | Identity and activity verification, review, prevention of fraudulent applications | Name, professional name, email address, profile, activity history, portfolio and website, application content and submitted materials | Performance of a contract, or steps taken at the applicant’s request before entering into a contract | Until membership ends where approved; 6 months from the decision date where not approved or withdrawn |
| Artwork registration and authentication | Artwork identification, authentication review, status records and lookups, prevention of forgery and alteration, management of correction records. COA issuance only where shown as available on the Service | Artist attribution details, title, year, medium, dimensions, description and images, submitted materials, serial numbers, and review, issuance, correction and status records | Performance of a contract while membership is active. After issuance, legitimate interests in the reliability of authentication records and the protection of third-party rights | While membership is active. The minimum records for an issued COA are retained for as long as needed for authentication lookups and dispute handling, with the need for retention reviewed periodically |
| Ownership History verification | Ownership requests and confirmations where shown as available on the Service, rights disputes, and prevention of unauthorized changes | Applicant’s name and email address, artwork identification details, evidence of ownership, and the times and statuses of requests, confirmations and changes | Performance of a contract and the legitimate interests of the Company and third parties | 3 years from the date of confirmation or change. Published history linked to a COA may be retained alongside the authentication record after the owner’s identifying details are removed |
| Saved and followed | Save works you like and follow artists | Account, artwork and artist identifiers, saved or followed status, time of change | Performance of a contract | Until deletion is requested or membership ends |
| Inquiries and exercise of rights | Replying to inquiries, handling complaints and rights requests | Name, email address, content of the inquiry or request, attachments, handling records | Performance of a contract, or legitimate interests | 3 years after the matter is closed |
| Service and security logs | Incident response, security, prevention of misuse | IP address, device and browser details, access and request times, request paths, error and security events, cookie or session identifiers | Legitimate interests in operating the Service securely | 3 months as a rule. Records relating to security incidents or disputes, up to 3 years after resolution |
| Marketing communications | News, events and feature announcements | Email address, name or nickname, records of consent and withdrawal | Optional consent (Article 15(1)(1)) | Until consent is withdrawn or membership ends. Records evidencing consent and withdrawal, 3 years |
Where processing is based on “legitimate interests”, the Company weighs the necessity of processing against its impact on data subjects and their reasonable expectations. It applies safeguards such as restricting public visibility, removing links to accounts, and applying access controls. Data subjects may object or request restriction of processing under Article 10.
Where a separate retention obligation arises under law, the Company stores that information separately from other information and only for the statutory period. If transaction features are introduced, the categories of payment and transaction information and their statutory retention periods will be added to this policy before any such processing.
The newsletter and marketing email features are not currently open. When they are provided, separate optional consent and unsubscribe procedures will be put in place and this policy will be updated to reflect the actual scope of processing.
033. Provision of personal information to third parties
The Company does not provide personal information to third parties except with the data subject’s separate consent or where there is a specific legal basis. Where information is provided in response to a lawful request from an investigative authority or a court, the Company verifies the basis and scope of the request and provides only the minimum information necessary.
Should the Company begin providing information to third parties, it will give advance notice of the recipient, purpose, categories, retention period and the consequences of declining, and obtain any necessary consent.
044. Outsourcing of personal information processing
To provide a stable service, the Company outsources personal information processing as follows.
| Processor | Outsourced work |
|---|
| Supabase, Inc. | Member authentication, database and file storage, security and backup infrastructure |
| Vercel Inc. | Web service hosting and deployment, server request handling, incident and security log operations |
| Plus Five Five, Inc. (Resend) | Sending email verification, password reset, security and essential service emails, and handling delivery and bounce status |
Through its processing agreements, the Company sets out prohibitions on processing beyond the stated purpose, security measures, management of sub-processing, incident notification and supervision, and manages and supervises its processors. Any change of processor or of the outsourced work is disclosed through this policy.
Google LLC and Kakao Corp. are not processors for the Company; they are external login providers that members may choose. Where a member chooses an external login, the Company collects from that provider the information the member has agreed to share, such as the provider identifier, email address, name or nickname and profile image. If a member does not choose that login, the Company collects no information from that provider.
055. Overseas transfers of personal information
The Company may process personal information outside Korea as set out below to enter into and perform the service agreement, and to outsource the processing and storage of personal information. The primary data processing region for Supabase and Vercel is set to Seoul, Republic of Korea. However, operations, security and support staff at each provider’s US headquarters may access the information or process related operational information to the extent necessary under the contract. For this reason, both the Republic of Korea and the United States are listed.
| Recipient and contact | Destination country | Categories transferred | Purpose of transfer | Timing and method of transfer | Retention and use period |
|---|
| Supabase, Inc. / privacy@supabase.com | Republic of Korea (Seoul region), United States | Account, member, artwork, authentication, ownership history and inquiry information, files, and the service and security logs needed for the outsourced work | Authentication, database and file storage, backups, security and support | Transmitted over encrypted networks when the Service is used, data is stored or support is requested, or accessed remotely under access controls | The periods set out per category in the table above, or until the processing agreement ends or the data is deleted |
| Google LLC / https://policies.google.com/privacy | United States and other processing regions notified by Google | Google provider identifier, email address, name or nickname, profile image (where provided) | Google login authentication chosen by the member | Transmitted over encrypted networks when Google login is chosen | Until the connection is removed or membership ends. Google’s own independent processing is governed by Google’s policies |
| Vercel Inc. / privacy@vercel.com | Republic of Korea (Seoul region), United States | IP address, device and browser details, request times and paths, error and security logs, and information needed to handle server requests | Web hosting and deployment, request handling, incident and security response, and support | Transmitted over encrypted networks when the Service is accessed, deployed or supported, or accessed remotely under access controls | 3 months as a rule. Records relating to incidents or disputes, up to 3 years after resolution or for the period required under the processing agreement |
| Plus Five Five, Inc. (Resend) / privacy@resend.com | United States | Recipient email address, sender, subject, body and verification link content, and message metadata such as sending, delivery, bounce and complaint records | Reliable sending of email verification, password reset, security and essential service emails, and handling of delivery status | Transmitted over encrypted networks when authentication and essential service emails are sent | Email data for 30 days as a rule. On termination of the service agreement, any remaining customer data is deleted within 90 days (except where retention is required by law) |
Members who do not wish to use Google login may choose email or Kakao login. Supabase, Vercel and Resend currently provide infrastructure needed for basic member features and service delivery. Refusing these transfers may prevent the use of related member features, but public pages remain available without login. To refuse an overseas transfer or request further information, contact contact@jnjohn.comfor assistance.
The Company applies the safeguards required by Article 28-8 of the Personal Information Protection Act and its Enforcement Decree, including contracts, encryption, access controls, management of sub-processing and supervision. Where there is a material change to the processing country, the processor or the content of a transfer, the Company amends and announces this policy in advance and obtains separate consent where required.
066. Automatic collection and cookies
1. The Company may use cookies and session storage necessary to keep members logged in, for security, and to preserve service state.
2. We do not currently use advertising cookies or third-party analytics cookies for targeted advertising or behavioral tracking.
3. Members can delete or block cookies in their browser settings. Blocking essential cookies may prevent login and some features from working properly.
4. Should the Company introduce advertising or analytics tools, the tool name, categories collected, purpose, retention period and how to opt out will be added to this policy before use, and any necessary consent obtained.
077. Sensitive information, unique identifiers and children’s information
1. As a rule the Company does not collect unique identifiers such as resident registration numbers, passport numbers, driver’s license numbers or alien registration numbers, or sensitive information such as health, ideology or beliefs.
2. During artist or ownership verification, we ask for copies with the relevant parts redacted so that materials containing sensitive information or unique identifiers are not submitted. Exceptionally, where there is a legal basis or separate consent is required, the purpose and retention period are notified separately.
3. The Service is not directed at children under the age of 14 and does not permit them to sign up. If we become aware of such an account, we restrict it and delete the related information without delay.
088. Security measures
To prevent the loss, theft, leakage, forgery, alteration or damage of personal information, the Company grants access rights only to the minimum number of staff who need them for their work and reviews these regularly, and applies encryption in transit, one-way password verifier storage, appropriate encryption of important information, strengthened administrator authentication, retention and review of access logs, detection of abnormal access, separation of development and operational environments, vulnerability and dependency checks, backup and recovery, processor audits and incident response procedures.
In the event of an incident such as a personal information breach, the Company notifies and reports to data subjects and the relevant authorities in accordance with applicable law and takes measures to minimize the harm.
099. Destruction of personal information and minimum retention of authentication records
1. Personal information whose retention period has ended or whose processing purpose has been achieved is destroyed without delay.
2. Electronic files are deleted by secure means that make recovery difficult, and paper documents are shredded or incinerated. Backups are deleted according to their rotation cycle and are not used for any purpose other than recovery.
3. When a member terminates their membership, information that is no longer needed — such as email address, external login identifiers, account profile and account link details — is deleted.
4. Artwork identification details, artist attribution details, images, serial numbers and issuance, correction and cancellation statuses that are necessary to verify the authenticity of COAs already issued, to maintain correction records, and to protect third-party rights and handle disputes may be retained after account links are removed and publication is minimized. This does not mean that all such information is made anonymous; where artist attribution details and artwork images constitute personal information, the Company periodically reviews the necessity of its legitimate interests against the rights of the data subject.
5. Public Ownership History screens do not show owners’ names or contact details; only the minimum information, such as verification status, sequence and timing, is retained.
6. Where a data subject requests deletion, unpublication or restriction of processing, the Company weighs its legal obligations, the rights of third parties who have relied on the records, the reliability of authentication records and the rights of the data subject, and informs them of the outcome and the reasons.
1010. Data subject rights and how to exercise them
1. Data subjects may request access to their personal information, its correction or deletion, suspension of its processing, withdrawal of consent, and may object to processing based on legitimate interests.
2. Requests may be submitted through the account features in the service or to contact@jnjohn.comThe Company verifies the identity of the individual or their authorized representative and provides the result within the period required by law.
3. Where a request would infringe another person’s rights or trade secrets, or where a statutory ground for restricting access applies, all or part of the request may be restricted; the Company will explain the basis and how to object.
4. Members may also remove the ARKPIA connection from their Google or Kakao account settings. Removing the connection alone may not automatically close the ARKPIA account, so full account deletion must be requested through the termination feature in the Service or directly from the Company.
5. The Company does not currently use personal information to make fully automated decisions that produce legal effects or similarly significant effects on individuals. Should such a feature be introduced, the relevant details will be disclosed and statutory rights guaranteed before it is applied.
1111. Data protection officer and contact
For inquiries about the Company’s processing of personal information, the exercise of rights, complaints and remedies, please contact us below.
Data Protection Officer: Choi Jungwoon, Chief Executive Officer
Department: ARKPIA Operations Team
Email: contact@jnjohn.com
Address: 6F, 818 Seolleung-ro, Gangnam-gu, Seoul, Republic of Korea (Cheongdam-dong)
On receiving an inquiry, the Company verifies the requester’s identity and the facts and replies within a reasonable period.
1212. Remedies for infringement of rights
If a data subject disagrees with the Company’s decision, or needs advice or a remedy regarding a personal information infringement, they may contact the Personal Information Infringement Report Center (https://privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (https://www.kopico.go.kr, 1833-6972), the National Police Agency Cybercrime Reporting System (https://ecrm.police.go.kr, 182) or the Supreme Prosecutors’ Office (https://www.spo.go.kr, 1301). These bodies are independent of the Company.
If an organization’s name, address or contact details change, please follow the latest guidance on the Personal Information Protection Commission’s privacy portal (https://www.privacy.go.kr).
1313. Changes to this Privacy Policy
1. The Company may amend this policy in line with changes in law, the Service or its processors.
2. Material changes are announced at least 30 days before they take effect, and other changes at least 7 days beforehand, on the Service’s legal notices screen or by email. Urgent security responses or changes in law are announced as promptly as is possible.
3. The Company makes the policy in force, together with the effective dates and principal changes of previous versions, available on the legal notices screen.
4. Where a change involves processing that requires separate consent, the Company obtains that consent rather than relying on notice of this policy alone.
1414. Consents on the sign-up screen
The sign-up screen shows acceptance of the Terms of Service (required), consent to the collection and use of personal information (required) and confirmation of being aged 14 or over (required) as separate items. Consent to receive marketing communications will be shown separately as an optional item when the sending feature opens.
The required consent screen for the collection and use of personal information summarizes the purpose, the categories collected, the retention period and the consequences of declining, and links to the full policy. Optional consents are never pre-ticked and can be withdrawn at any time.
Required consent 1 [Required] I accept the ARKPIA Terms of Service. (v1.4) | Read in full
Required consent 2 [Required] I consent to the collection and use of my personal information. (v1.4) | Learn more
Required confirmation [Required] I am 14 years of age or older.
15Supplementary Provisions
1. This Privacy Policy takes effect on September 3, 2026.
2. v1.4 is the first version of the Privacy Policy in force for the ARKPIA Public Premiere.