PRIVACY POLICY
Privacy Policy
BY4M STUDIO Co., Ltd. (“the Company”) values the protection of users’ personal information and complies with the Personal Information Protection Act and other applicable laws and regulations.
This Privacy Policy explains how the Company collects, uses, stores, and processes users’ personal information and informs users of their rights and obligations related to the use of our services.
1. Items of Personal Information Collected and Methods of Collection
1) Items of Personal Information Collected
The Company collects the following personal information in order to provide services.
① Mandatory information
- When using the game service
- Nickname, Google/Apple account identifier, guest account identifier
- Device information (OS version, app version, language, and country)
- Service usage records (nickname, login ID, purchase history, access IP, access logs)
- In-game chat records
- When contacting customer support
- Required: Email address
- Optional: Nickname, login ID, purchase history
② Optional information
- Behavioral data for advertising and analytics
- Advertising identifiers (AAID, IDFA), general location information (country/city)
- The Company does not store payment method information; however, it may process minimal transaction verification data such as transaction ID, date, and amount for payment confirmation.
2) Methods of Collection
- Automatically collected during account registration and service use
- Collected during customer inquiries or event participation
- Automatically collected through advertising and analytics services
- Collected from social login services (Apple, Google, etc.) with minimal authentication data from each platform
2. Purpose of Collection and Use of Personal Information
The Company uses users’ personal information for the following purposes:
- Identity verification and account linkage
- Responding to customer inquiries and handling complaints
- Service operation and prevention of misuse
- Providing advertisements and promotional offers
- Retaining data to comply with legal obligations
- Improving service quality and functionality
- Security management, account protection, and fraud prevention
- Statistical and analytical purposes for service improvement
The Company processes personal information in accordance with applicable privacy laws,
including the Personal Information Protection Act of the Republic of Korea, the GDPR,
and other relevant regulations, based on consent, contract performance,
legal obligations, or legitimate interests.
3. Retention and Use Period of Personal Information
① The Company destroys personal information without delay once the purpose of collection and use has been achieved.
② However, certain information is retained for a specific period as required by applicable laws.
| Information Retained | Retention Period | Legal Basis |
|---|---|---|
| Records of contracts and withdrawal of subscriptions | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records of payment and supply of goods | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records of customer complaints and dispute resolution | 3 years | Act on Consumer Protection in Electronic Commerce |
| Service usage records | 3 months | Protection of Communications Secrets Act |
4. Provision and Entrustment of Personal Information
1) Provision to Third Parties
The Company does not provide users’ personal information to external parties by default.
However, personal information may be provided without consent in the following cases:
- When required by law
- When requested by a court or investigative agency through lawful procedures
2) Entrustment of Personal Information Processing
The Company may entrust the processing of personal information to the following entities to operate its services.
| Entrusted Company | Purpose of Entrustment |
|---|---|
| Plaium Co., Ltd. | Game user database management |
5. Overseas Transfer of Personal Information
The Company may transfer personal information overseas for service operation and data storage.
| Recipient | Country | Data Transferred | Purpose of Use | Retention Period |
|---|---|---|---|---|
| - | - | - | - | - |
6. Procedures and Methods of Personal Information Destruction
① Personal information will be destroyed immediately once the retention period has expired or the purpose of processing has been achieved.
② Electronic files: Deleted using technical methods that prevent recovery.
③ Paper documents: Shredded or incinerated.
7. Users’ Rights and Exercise Methods
① Users may request access, correction, or deletion of their personal information.
② Request methods:
- By contacting the customer support email (customerservice@plaium.com)
- By contacting the Data Protection Officer (DPO)
③ Users also have the following additional rights:
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
④ The Company will respond to such requests within 30 days of receipt.
⑤ Identity verification procedures may be required to confirm the requester’s identity.
8. Automatic Collection of Personal Information and Refusal Methods
① The Company may use cookies and advertising identifiers for user convenience.
② Users may disable interest-based advertising by adjusting device settings.
- Android: Settings > Google > Ads > Delete Advertising ID or Opt out of interest-based ads
- iOS: Settings > Privacy & Security > Tracking > Turn off “Allow Apps to Request to Track”
9. Protection and Security Measures
① Establishing internal security policies and employee training
② Encrypting data and restricting access
③ Operating security systems to prevent hacking and viruses
④ Minimizing access rights and conducting regular audits
10. Protection of Children’s Personal Information
① The Company does not collect personal information from children under 13 years old (or under 16 years old in some regions such as the EU) without the consent of a legal guardian.
② If such collection is confirmed, the Company will promptly delete the information.
③ Where guardian consent is required, the Company will verify it through lawful procedures before processing.
11. Additional Regional Notices
- EU/EEA/UK: Users have the right to lodge a complaint with a Data Protection Authority (DPA). When personal data is transferred overseas, the Company applies appropriate safeguards under the GDPR Standard Contractual Clauses (SCC).
- United States (California, etc.): Users have the right to access, delete, and opt out of the sharing of personal information, and the Company will not discriminate for exercising such rights.
- Brazil: Users may exercise their rights under the LGPD by contacting the Company’s Data Protection Officer.
12. Data Protection Officer
The Company designates the following person as the Data Protection Officer (DPO) responsible for protecting personal information and handling related complaints.
- Data Protection Officer: Kwangteak Mo
- Email: kwangteak.mo@by4m.co.kr
- Tel: 070-4161-5111
Users may report any privacy-related issues arising from the use of the Company’s services to the DPO.
For further inquiries or complaints regarding privacy infringement, users may contact the following authorities:
- Personal Information Infringement Report Center: 118 (without area code) (privacy.kisa.or.kr)
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Supreme Prosecutors’ Office Online Civil Service Center: 1301 (without area code) (https://www.spo.go.kr/site/spo/01/10102020100002018120702.jsp)
- Korean National Police Agency Cybercrime Reporting System: 182 (without area code) (https://ecrm.police.go.kr/minwon/main)
13. Miscellaneous
① This Privacy Policy shall take effect on Date of Implementation: 2026-07-06.
② Any changes to this Policy will be announced at least 7 days in advance, and significant changes will be announced 30 days in advance.
Privacy Policy Version: 2026.07.06
Effective Date: 2026.07.06