隱私權政策

네이플 ('naple.co.kr', hereinafter '네이플' or 'the Company') is committed to protecting the personal data of all users worldwide in compliance with the Korea Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. This Privacy Policy outlines how we collect, use, store, and protect your personal data.
○ This Privacy Policy is effective as of March 2, 2026.

Article 1 (Scope)

  1. This Policy applies to all users worldwide who access the Company's website (naple.co.kr) and related services.
  2. Depending on your region of residence, additional rights may apply as set forth in Article 9 (Region-Specific Rights).

Article 2 (Purposes of Processing Personal Data)

The Company processes personal data only for the following purposes. Personal data will not be used beyond these purposes, and any change in purpose will be subject to separate consent or other measures required by applicable law.

1. Account Registration and Management

Identity verification, account maintenance, fraud prevention, notices, and complaint resolution.

2. Orders and Payments

Order processing, payment settlement, and provision of custom print services.

3. Delivery

Domestic and international shipping, delivery status notifications.

4. Design Proof Approval and Dispute Resolution

Creation and retention of design proof approval records, chargeback dispute resolution, and fraud prevention.

5. Customer Inquiries

Identity verification of the inquirer, investigation, and notification of results.

6. Marketing

Development of new services, promotional information, and service usage statistics. Marketing communications are sent only with the user's separate consent.

Article 3 (Personal Data Collected)

The Company collects and processes the following categories of personal data.

1. Account Registration

Required: email, password, name, phone number, company name

2. Orders and Payments

Order number, payment records, card information (processed directly by payment service providers)

3. Delivery

Recipient name, shipping address, contact number

4. Design Proof Approval and Dispute Resolution

Proof approval records (consent text, timestamp), IP address, device identifiers, service usage logs

5. Automatically Collected

IP address, cookies, access timestamps, browser information, service usage logs

Article 4 (Retention and Destruction of Personal Data)

  1. The Company will destroy personal data without delay when a user requests account deletion.
  2. However, the following data will be retained in a separate, isolated database (Legal Vault) for the periods specified below, after which it will be automatically destroyed.
Data Retained Retention Period Legal Basis
Payment and order snapshot (order number, proof approval log, shipping address, tracking number) 540 days from the date of delivery completion International card network (Visa/Mastercard) chargeback dispute period
Contracts and subscription withdrawal records 5 years Korea Electronic Commerce Act
Payment and supply records 5 years Korea Electronic Commerce Act
Consumer complaint and dispute records 3 years Korea Electronic Commerce Act
Access logs 1 year Korea Protection of Communications Secrets Act
  1. Destruction procedure: Personal data that has exceeded its retention period is automatically destroyed upon approval by the Data Protection Officer.
  2. Destruction method: Electronic files are deleted using irreversible technical methods. Paper documents are shredded or incinerated.

Article 5 (Disclosure of Personal Data to Third Parties)

  1. The Company does not disclose personal data to third parties as a general rule.
  2. Exceptions are made only with the user's consent, where required by law, or where essential for service fulfillment (payment and delivery).

Article 6 (Data Processing Partners)

  1. The Company engages the following partners for data processing in connection with its services.
Service Partner Scope
Domestic payments Toss Payments Co., Ltd. Payment processing
International payments Airwallex International card and digital payment processing
Printing and production Partner print facilities (varies by order) Product manufacturing and domestic shipping
Domestic delivery CJ Logistics, Hanjin, Lotte Global Logistics Parcel delivery
International delivery DHL International shipping
  1. The Company ensures that all processing partners are contractually bound to process personal data only for the agreed purposes, implement appropriate technical and organizational safeguards, and comply with applicable data protection laws.
  2. Any changes to processing partners or the scope of processing will be promptly disclosed through this Policy.

Article 7 (International Data Transfers)

  1. The Company processes personal data on servers located in the Republic of Korea.
  2. Personal data may be transferred outside Korea in connection with international payment processing (Airwallex) and international shipping (DHL).
  3. For international transfers, the Company applies appropriate safeguards such as EU Standard Contractual Clauses (SCCs) to protect your personal data.
  4. When delivery is completed to a freight forwarder designated by the user, the Company's delivery obligations are considered fulfilled. The Company is not responsible for any disputes arising from international shipping after delivery to the freight forwarder.

Article 8 (Your Rights)

  1. You may exercise the following rights at any time.
  • 1. Right to access your personal data
  • 2. Right to correction or deletion of your personal data
  • 3. Right to restrict processing
  • 4. Right to data portability (where applicable under your local law)
  • 5. Right to withdraw consent
  1. You may exercise your rights by contacting us in writing or by email at cs@naple.co.kr. The Company will respond without undue delay.
  2. Rights may be exercised through an authorized representative.
  3. The right to deletion or restriction of processing may be limited where retention is necessary for the establishment, exercise, or defense of legal claims (e.g., chargeback dispute resolution), in accordance with applicable law.

Article 9 (Region-Specific Rights)

All users may exercise the rights set forth in Article 8. In addition, the following rights are available based on your region of residence.

① South Korea

Under Articles 35 through 37 of the Personal Information Protection Act (PIPA), you have the right to request access, correction, deletion, and suspension of processing of your personal data.

② EEA/UK (GDPR)

  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Erasure ('Right to be Forgotten'): You have the right to request deletion of your personal data. This right may be limited where the Company needs to retain data for the establishment, exercise, or defense of legal claims (e.g., chargeback defense).
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority.
  • Legal Bases for Processing: Performance of a contract, compliance with legal obligations, legitimate interests (fraud prevention and legal claim defense).

③ California, USA (CCPA/CPRA)

  • The Company does not sell or share your personal information.
  • You have the right to request deletion of your personal data and will not be discriminated against for exercising your rights.

④ Other Regions

Additional rights may be available under the data protection laws of your region of residence (such as Brazil's LGPD, Japan's APPI, or Mexico's LFPDPPP). To exercise any such rights, please contact us at cs@naple.co.kr.

Article 10 (Design Proof Approval Records)

  1. Due to the nature of our custom print services, the Company creates the following records when a user reviews and approves a design proof for printing.
  • Consent text (approval statement)
  • Timestamp of approval
  • IP address at the time of approval
  • Approved proof image filename
  1. These records serve as key evidence in the event of a payment dispute (chargeback) and are retained for 540 days from the date of delivery completion, in accordance with Article 4, after which they are automatically destroyed.
  2. The legal bases for processing these records are as follows.
  • Korea: Record retention obligations under the Electronic Commerce Act
  • GDPR: Article 6(1)(f) — Legitimate interests (fraud prevention and defense of legal claims)
  • CCPA: Processing necessary for business purposes

Article 11 (Cookie Policy)

  1. The Company uses cookies to provide personalized services to users.
  2. Purpose of cookies: To analyze user visit and usage patterns, verify secure connections, and provide optimized services.
  3. Managing cookies: You may refuse cookie storage through your web browser settings.
  4. Refusing cookies may limit access to certain personalized features of the service.
  5. For users in the EEA/UK, non-essential cookies are installed only with prior consent.

Article 12 (Security Measures)

The Company implements the following measures to ensure the security of personal data.

1. Regular Internal Audits

The Company conducts internal audits on a quarterly basis to ensure the security of personal data handling.

2. Minimization of Staff with Access

Access to personal data is restricted to designated personnel only.

3. Internal Management Plans

The Company has established and implements internal management plans for the secure processing of personal data.

4. Technical Safeguards

Security software is installed and regularly updated to prevent data breaches caused by hacking or malware. Systems are installed in access-controlled zones and monitored continuously.

5. Encryption

User passwords are encrypted for storage and management. Critical data is protected through file and transmission encryption.

6. Access Log Retention

Access logs to personal data processing systems are retained for a minimum of one year.

7. Access Controls

Access to database systems containing personal data is controlled through the granting, modification, and revocation of access rights. Intrusion prevention systems are used to block unauthorized external access.

8. Isolated Storage of Dispute Resolution Data

Snapshot data retained for dispute resolution purposes after account deletion is stored in a separate, isolated database (Legal Vault) accessible only to authorized legal, compliance, and fraud prevention personnel.

Article 13 (Data Protection Officer)

  1. The Company has designated the following Data Protection Officer (DPO) to oversee all matters relating to personal data protection and to handle complaints and remedies.
  • ▶ Data Protection Officer (DPO)
  • Name: Junkyu Lee
  • Title: CEO
  • Phone: 02.6677.7330
  • Email: cs@naple.co.kr
  • Fax: +82-2-6677-7331
  1. You may contact the DPO regarding any personal data protection inquiries, complaints, or remedies arising from your use of the service. The Company will respond without undue delay.

Article 14 (Data Access Requests)

You may submit a request to access your personal data to the department below. The Company will make every effort to process your request promptly.
  • ▶ Data Access Request Department
  • Department: Administration
  • Contact Person: Junkyu Lee
  • Phone: 02.6677.7330
  • Email: cs@naple.co.kr
  • Fax: +82-2-6677-7331

Article 15 (Remedies for Rights Violations)

If you believe your personal data rights have been violated, you may seek resolution through the following channels.

South Korea

  • 1. Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • 2. Personal Information Infringement Report Center (KISA): 118 (privacy.kisa.or.kr)
  • 3. Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • 4. National Police Agency: 182 (cyberbureau.police.go.kr)

EEA/UK

You may lodge a complaint with the Data Protection Authority in your country of residence. A list of supervisory authorities is available on the EDPB website.

Other Regions

Please contact the relevant data protection authority in your region of residence, or reach out to us at cs@naple.co.kr.

Article 16 (Changes to This Policy)

  1. This Privacy Policy is effective as of March 2, 2026.
  2. Any changes to this Policy will be announced on the website at least 7 days prior to the effective date. Changes that materially affect user rights will be announced at least 30 days in advance.
  3. Previous versions of this Policy can be found below.
  • - August 25, 2021 – March 1, 2026 (Previous version)

NAPLE

  • 公司 : NAPLE, 客服中心 : +82-2-6677-7330
  • 地址 : B-324, 70 Dusan-ro, Geumcheon-gu, Seoul 08584, Korea (Hyundai Knowledge Industry Center)
  • 代表人 : Jun-Kyu Lee
  • 統一編號 : 119-17-28654
  • 銷售許可證 : 2022-SEOULGEUMCHEON-2287
  • 個資保護負責人 : Jun-Kyu Lee, 電子郵件 : cs@naple.co.kr

Copyrightⓒ2021 (C)NAPLE All Rights Reserved.