Privacy Policy
Ebook Banana (the “Company”) establishes this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of Korea (PIPA) in order to protect the personal information and rights of data subjects and to handle related complaints promptly and smoothly.
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. It does not use the information for any other purpose, and if the purpose changes, it will take necessary measures under PIPA, such as obtaining separate consent.
- Member registration and management: identifying and authenticating Members, managing accounts and ebook sites, verifying identity for use of the Service, preventing misuse, and delivering notices
- Handling production requests: receiving requests, providing quotations, carrying out production and delivering results, and communicating progress
- Inquiries and support: checking and answering inquiries and managing support records
- Fee payment and settlement: confirming payment for Paid Services (such as confirming deposits) and processing refunds
- Service operation and security: reviewing access logs, managing traffic, responding to service failures, and preventing abnormal use
2. Personal Information We Process
| Category | Items processed | How collected |
|---|---|---|
| Registration and use | (Required) account ID, password (stored encrypted), email (Optional) company name, representative name, business registration number, address, phone and fax numbers and email that a Member enters as ebook site basic information | Sign-up application and entries in the admin screen |
| Production requests | (Required) contact person’s name, phone, email, and company (or organization) name (Optional) company address, company phone, email and website, request details, attached files (PDF, etc.) | Production request form |
| Inquiries and support | Name (or company name), phone, email, inquiry details and other items entered by the User | Contact form |
| Payment | Depositor name, payment amount and date. For card payments, card information is processed by the payment service provider and is not stored by the Company. | Payment confirmation process |
| Automatically collected | IP address, access date and time, browser and device information, service usage records (traffic usage), cookies | Generated automatically while using the Service |
The Company does not collect unique identification information such as resident registration numbers or sensitive information, and does not collect personal information of children under 14.
3. Processing and Retention Periods
The Company processes and retains personal information within the retention and use period required by law or the period to which the data subject consented at collection.
| Category | Retention period |
|---|---|
| Member information | Until withdrawal (end of the contract). The minimum information needed to prevent misuse is kept for 6 months after the contract ends |
| Production request information | Up to 1 year after the request is completed (or closed) |
| Inquiry and support records | Up to 1 year after the inquiry is resolved |
The following information is kept for the periods required by law.
| Record | Legal basis | Period |
|---|---|---|
| Records of contracts, withdrawal of offers, payment and supply of goods or services | Act on the Consumer Protection in Electronic Commerce | 5 years |
| Records of consumer complaints or dispute handling | Act on the Consumer Protection in Electronic Commerce | 3 years |
| Records of labeling and advertising | Act on the Consumer Protection in Electronic Commerce | 6 months |
| Service access records | Protection of Communications Secrets Act | 3 months |
4. Provision to Third Parties
The Company processes personal information only within the scope of the purposes in Section 1 and does not provide it to third parties unless there is consent of the data subject or a case under Articles 17 and 18 of PIPA, such as a special provision of law. The Company does not currently provide personal information to third parties.
5. Outsourcing of Processing
As a rule, the Company does not outsource the processing of personal information. If outsourcing becomes necessary, the Company will disclose the processor and the outsourced work in this Policy and supervise the processor under Article 26 of PIPA. When you pay by card, the payment service provider processes the payment under its own policy.
6. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
- Data subjects may at any time ask the Company to access, correct or delete their personal information, suspend its processing, or withdraw consent (PIPA Articles 35, 36, 37, etc.).
- You can make such a request to the Company in writing, by email or similar means, and the Company will act without delay. Members can also view and edit their own information directly in the admin screen.
- Rights may also be exercised through an agent, such as a legal representative or a person authorized by the data subject; in that case a power of attorney must be submitted.
- You cannot request deletion of personal information whose collection is required by other laws.
- When a data subject makes a request, the Company verifies that the person is the data subject or a legitimate representative.
7. Destruction of Personal Information
- The Company destroys personal information without delay once it is no longer needed, for example when the retention period has passed or the purpose of processing has been achieved.
- Information that must be preserved under law is stored separately from other personal information even after the reason for destruction arises, and is destroyed when the preservation period ends.
- Electronic files are permanently deleted by a method that makes recovery or reproduction impossible; printed personal information is shredded or incinerated.
8. Measures to Ensure Security
In accordance with Article 29 of PIPA, the Company takes the following measures to ensure security.
- Administrative measures: limiting the number of people who handle personal information to the minimum, and providing training and internal management procedures for them.
- Technical measures: access rights management and access control, encrypted storage of passwords, encryption in transit (HTTPS), retention and review of access records, and regular backups.
- Physical measures: controlling access to storage devices, such as servers, where personal information is stored.
9. Cookies (Automatic Collection Devices)
- The Company uses only the minimum cookies needed to provide the Service, such as keeping you logged in, and does not use advertising cookies that track user behavior.
- You can refuse or delete cookies in your web browser settings. If you refuse cookies, services that require login may be difficult to use.
e.g. Chrome: Settings > Privacy and security > Third-party cookies / Edge: Settings > Cookies and site permissions
10. Privacy Officer
The Company has designated a privacy officer who oversees the handling of personal information and is responsible for handling complaints and remedying damage of data subjects, as follows.
| Role | Privacy officer |
|---|---|
| Name | Lee Sang-hoon (CEO) |
| Contact | Email master@e-webmake.com / Phone 01035273314 |
Data subjects may contact the above for any privacy-related inquiry, complaint or remedy arising from use of the Service, and the Company will respond and act without delay.
11. Remedies for Infringement of Rights
To seek remedies for infringement of personal information, data subjects may apply to the following organizations for dispute resolution or counseling.
- Personal Information Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr / dial 118 (within Korea)
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972 (within Korea)
- Supreme Prosecutors’ Office Cyber Crime Division: www.spo.go.kr / dial 1301 (within Korea)
- National Police Agency Cyber Bureau: ecrm.police.go.kr / dial 182 (within Korea)
12. Changes to This Privacy Policy
This Privacy Policy applies from September 30, 2026. If content is added, deleted or modified, the Company will announce it on the Service at least 7 days before it takes effect, and at least 30 days before for significant changes affecting data subjects’ rights.