**Pleasure Co., Ltd. (hereinafter referred to as "the Company") complies with personal information protection regulations under relevant laws that information and communication service providers must observe, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, Telecommunications Business Act, and Protection of Communications Secrets Act. The Company establishes a privacy policy in accordance with relevant laws and does its best to protect user rights. Pleasure Co., Ltd.'s privacy policy contains the following:**

### **Article 1 General Provisions**

1. Personal information refers to information about a living individual, including codes, characters, voices, sounds, images, etc., that can identify the individual through names, resident registration numbers, etc., contained in the information (including information that cannot identify a specific individual by itself but can be easily combined with other information for identification).
2. Pleasure Co., Ltd. (hereinafter referred to as "the Company") places great importance on protecting users' personal information and complies with personal information protection-related laws and subordinate statutes, including the "Personal Information Protection Act" and the "Act on Promotion of Information and Communications Network Utilization and Information Protection."
3. Through this privacy policy, the Company informs users about the purposes and methods for which personal information provided by users is used and what measures are being taken to protect personal information. The Company makes the privacy policy easily accessible by posting it on the homepage's main page.
4. The Company establishes procedures necessary for continuous improvement and revision of the privacy policy and may change the privacy policy to meet the Company's needs and social changes.

### **Article 2 Items and Collection Methods of Personal Information**

① The Company allows free access to most content without a separate membership registration process. However, if you wish to use the membership services provided by the Company, you must enter the following information.

1. Required Items
   - Individual members: Email address, password, nickname, phone number (mobile phone), date of birth, CI (connected information), DI (duplicate subscription information)
   - Individual/Corporate business operators: Company/organization name, business registration number, contact person name, bank account copy, email address, password, phone number (mobile phone), CI (connected information), DI (duplicate subscription information)
2. Optional Items
   - Credit card information, bank account information, mobile phone information, and other information necessary for payment
   - When registering as a member, additional information can be selected and provided if desired by the member. For orders and acceptance of some goods or services, additional information is required for accurate order identification and smooth ordering, payment, and delivery.
3. Scope of personal information that may be collected during service use and business processing
   - Last access date, access IP information, cookies, purchase logs, event logs
4. Non-member Customers
   - The Company requests only the personal information necessary for delivery, payment, order history inquiry, purchase confirmation, and identity verification for non-member customer orders. In this case, the information is not used for any purpose other than payment and product delivery.
   - The Company protects non-members' personal information at the same level as members.
5. Personal Information of Children Under 14
   - The Company does not accept membership registration for children under 14 who require legal guardian consent.
6. The Company collects personal information through the following methods.
7. Website, written forms, fax, phone, consultation board, email, event participation, delivery requests
8. Provision from partner companies
9. Collection of generated information through log analysis programs
10. Consent to Personal Information Collection
    1. The Company provides a procedure for users to click "Agree" or "Disagree" buttons regarding the contents of the Company's privacy policy and terms of use. Clicking "Agree" is considered consent to personal information collection.

### **Article 3 Purpose of Personal Information Collection and Use**

1. The Company collects the minimum personal information necessary for the following purposes.
   1. ID, password, name, date of birth: Used for identity verification procedures in using membership services
   2. Email address (newsletter subscription status): Securing smooth communication channels for delivering notices, confirming user intentions, handling complaints, and providing guidance on new services, new products, or latest information such as events
   3. Address, phone number: Securing accurate delivery address for shopping product delivery
   4. Other optional items: Data for providing personalized services
   5. Statistics on member service use: Statistical data preparation related to business and service development
   6. Use in marketing and advertising

### **Article 4 Personal Information Sharing and Provision**

1. The Company does not provide customers' personal information to third parties or use it for purposes other than those stated in Article 3 (Purpose of Personal Information Collection and Use) without prior customer consent or except as provided by law.
2. In the following cases, the Company may provide or share customers' personal information with third parties to provide customer convenience or improve services.
3. When customers consent in advance
4. When required by law or when requested by investigative agencies according to procedures and methods established by law for investigative purposes
5. When providing personal information, customers are notified in advance individually through written documents, email, phone, etc., about the third party receiving personal information, items of personal information provided, purpose of personal information provision, period and method of protection and management of provided personal information, matters previously consented to by customers, rights not to consent and methods of expressing intent, and other matters necessary to obtain customer consent. If customers do not consent, information is not provided to third parties.

### **Article 5 Personal Information Processing Consignment**

1. The Company consigns minimum personal information for service provision, customer consultation, and service payment.
   - Inicis Payple: Payment information transmission, payment agency services
   - KSNET: Payment information transmission, payment agency services
   - Allineun Saramdeul Co., Ltd.: SMS, MMS text message sending services
2. When concluding consignment contracts, the Company specifies in documents such as contracts matters related to prohibition of personal information processing other than consignment work performance purposes, technical and managerial protective measures, re-consignment restrictions, management and supervision of trustees, and liability for damages in accordance with Article 25 of the Personal Information Protection Act, and supervises whether trustees safely process personal information.
3. If consignment work contents or trustees change, we will promptly disclose this through this privacy policy.

### **Article 6 Personal Information Retention and Use Period**

1. Users' personal information is destroyed when the purpose of personal information collection or provision is achieved as follows.
   1. Member registration information: When membership is withdrawn or member is expelled
   2. Payment information: When payment is completed or statute of limitations for debt expires
   3. Delivery information: When goods, services, or products are delivered or provided
   4. Information collected for temporary purposes such as surveys and events: When the survey or event ends
2. However, despite the principle of immediate destruction upon achieving personal information collection purposes, when necessary to retain information for a certain period for reasons such as confirming transaction-related rights and obligations, information is retained for a certain period based on provisions of relevant laws such as the "Act on Consumer Protection in Electronic Commerce, Etc." and "Framework Act on National Taxes."
   1. Records on contracts or withdrawal of subscription: 5 years
   2. Records on payment and supply of goods: 5 years
   3. Records on consumer complaints or dispute resolution: 3 years
   4. Website visit records: 3 months
3. When users request to view transaction information retained with user consent, the Company takes measures to allow viewing and confirmation without delay.

### **Article 7 Dormant Policy for Long-term Inactive Customers**

1. Personal information of customers (long-term inactive members) with no usage records for one year after last using Pleasure services is separately separated and safely managed. Target persons are notified via email address at least 30 days before the separation storage processing date. Separately stored personal information is stored for 5 years and then destroyed without delay. However, if necessary to preserve information according to provisions of relevant laws such as the Protection of Communications Secrets Act and Act on Consumer Protection in Electronic Commerce, Etc., customers' personal information is retained for the prescribed period.
2. If you do not wish to convert to a dormant account, log in to the service before dormant account conversion. Also, even if converted to a dormant account, if you log in, the dormant account can be restored with user consent and normal services can be used.

### **Article 8 Personal Information Destruction Procedures and Methods**

1. In principle, the Company destroys such information without delay after personal information collection and use purposes are achieved. The Company's personal information destruction procedures and methods are as follows.
   1. Destruction Procedure
      - Information entered by users for membership registration, etc., is stored for a certain period according to internal policies and information protection reasons under other relevant laws (see Article 6 Personal Information Retention and Use Period) after purposes are achieved, then destroyed. Such personal information is not used for any other purpose except as provided by law.
   2. Destruction Method
      - Personal information printed on paper: Destroyed by shredding with a shredder or incineration
      - Personal information stored in electronic file format: Deleted using technical methods that cannot reproduce records
2. Users' personal information is destroyed within 5 days from the end date of the retention period when the personal information retention period has expired, and within 5 days from the date when personal information processing is recognized as unnecessary, such as achievement of personal information processing purposes, abolition of the service, or termination of business.

### **Article 9 Customer Rights and Obligations**

1. Customer Rights
   1. Users can view or correct their registered personal information at any time. To view and correct personal information, click My Page on the homepage to directly view or correct, or contact the personal information manager by mail/email/fax and phone, and we will take action without delay after identity verification procedures.
   2. When the Company receives a request in the preceding paragraph, it responds to the request within the statutory deadline and does not use the personal information until correction is completed. However, if there is a legitimate reason for not being able to respond within that period, the Company informs users of the reason and may postpone, and responds without delay when the reason disappears.
   3. Users can withdraw consent to personal information collection, use, and provision at any time. Consent withdrawal can be done by directly deleting on My Page on the homepage or by contacting the personal information manager by mail/email/fax and phone, and we will take necessary measures such as deleting personal information without delay after identity verification procedures. However, for online sites, all information except purchase history necessary for statistical data preparation is deleted upon withdrawal.
   4. Legal guardians of users under 14 years old may exercise all the above rights.
2. Customer Obligations

Customers have an obligation to protect their personal information, and the Company is not responsible for problems arising from leakage of personal information due to transfer, loan, loss of ID (email address), password, access media, etc., or leaving while logged in, which are the customer's carelessness without the Company's fault, or methods or technologies that cannot be blocked by security measures under relevant laws, such as hacking using technologies that the Company cannot control despite considerable care, or Internet problems. Customers must keep their personal information up to date, and customers are responsible for problems arising from inaccurate information entry. Member registration using another person's personal information or payment processing using stolen IDs may result in loss of customer status and punishment according to relevant laws. Customers are responsible for maintaining security of IDs and passwords and cannot transfer or lend them to third parties. Customers have an obligation to cooperate in periodic activities for security according to the Company's personal information protection policy.

### **Article 10 Installation/Operation and Refusal of Automatic Personal Information Collection Devices**

1. Cookies
   1. The Company uses 'cookies' that can store and retrieve information about users. Cookies are small amounts of information that websites send to users' computer browsers. When users access the website, the Company's computer reads cookie contents in users' browsers and finds users' additional information on users' computers to provide services without additional input of names, etc., for access. Cookies identify users' computers but do not personally identify users.
   2. The Company uses personal information of users collected through cookies that provide and frequently retrieve user information to provide specialized customized services to users. The Company can provide services (including advertisements) specialized to customers' tastes and interests by analyzing information about visited services, shopping cart history, service access time and frequency, information generated or provided (entered) during service use.
   3. Users have the right to choose cookie installation. Therefore, users can allow all cookies, go through confirmation each time cookies are stored, or refuse storage of all cookies in web browser options.
      1. For Internet Explorer
         - Select [Internet Options] from [Tools] menu → Click [Privacy] → Click [Advanced] → Select whether to allow cookies
      2. For Safari
         - Select [Preferences] from [Safari] in the top left menu bar of MacOS → Move to [Security] in [Preferences] window and select whether to allow cookies
2. Customized Advertising

To provide customized advertising to customers, Pleasure collects and uses 'cookies' in web browsers and advertising identifiers (ADID) in mobile apps. Pleasure automatically collects customers' service usage history through cookies and advertising identifiers and provides them to Facebook and Google. Facebook and Google use this to conduct customer-customized advertising. Cookies and advertising identifiers collected by Pleasure are not linked to other personal information and do not identify individuals. Also, Facebook and Google do not identify individuals using information provided by Pleasure.

### **Article 11 Technical/Managerial Protection Measures for Personal Information**

Pleasure does its best to safely manage users' personal information and protects personal information at a level higher than required by the Personal Information Protection Act. The Company also complies with technical and managerial measures under the "Personal Information Protection Act" and "Act on Promotion of Information and Communications Network Utilization and Information Protection."

1. **Technical Measures**

In handling users' personal information, the Company implements the following technical measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged.

1. Important data such as users' passwords among personal information are encrypted and stored, and personal information is safely kept in the safe zone of double firewalls. The Company also safely transmits and receives personal information on networks through encrypted communication.
2. To prevent leakage of users' personal information, devices that block intrusions from outside are used, and intrusion detection systems are installed on each server to monitor intrusions 24 hours a day.
3. Records of personal information handlers' access to personal information processing systems are retained and managed, and access records are regularly checked to prevent misuse, abuse, loss, forgery, or alteration of personal information, and access records of personal information handlers are safely stored to prevent forgery, alteration, theft, or loss.
4. Data is backed up periodically to prepare for personal information damage, and the latest vaccine programs are used to prevent users' personal information or data from being leaked or damaged.
5. **Managerial Measures**
   1. The Company limits personal information handling staff to those in charge and assigns separate passwords for this purpose, regularly updates them, and emphasizes compliance with the privacy policy through occasional training of those in charge.
   2. Work handovers of personal information handling personnel are thoroughly conducted in a secure state, and responsibility for personal information incidents after joining and leaving the company is clarified.
   3. Users should not inform others of their IDs and passwords and should be sure to log out after logging in to the homepage and finishing use. The Company assumes no responsibility for problems arising from leakage of personal information due to user carelessness or Internet problems.
   4. If personal information is lost, leaked, altered, or damaged due to mistakes by internal managers or technical management incidents, the Company will immediately inform users of the facts and take appropriate measures and compensation.
6. If customers suffer damages due to Pleasure's intentional or negligent actions while using Pleasure services, Pleasure compensates for customers' damages according to relevant laws. However, Pleasure does not bear responsibility for damages arising from inability to provide services due to natural disasters or equivalent force majeure, or inability to use services due to intentional or negligent actions of suppliers (companies) or users.
7. If disputes occur between suppliers (companies) of reservation products sold on Pleasure and consumers, the Company is not responsible if there is no fault.
8. The Company may subdivide member grades according to internal policies to provide smooth services and differentiate use.
9. In addition, materials with content inconsistent with the service provision purpose during service use cause inconvenience to other users' normal service use and further interfere with the Company's smooth service provision, so partners' reservation product posting may be restricted.

### **Article 12 Contact Information of Personal Information Manager and Person in Charge**

1. The Company designates a personal information manager as follows to protect users' personal information and handle complaints and inquiries related to personal information. [Personal Information Manager]
   - Name: Director Won Robin
   - Phone: 02-6952-6961 (Customer phone consultation not provided, please inquire via app > My Page > 1:1 consultation)
   - Email: [email protected]
2. Data subjects can make personal information viewing requests in accordance with Article 35 of the Personal Information Protection Act to the department below. Pleasure will strive to promptly process data subjects' personal information viewing requests. [Department for Personal Information Viewing Request Reception and Processing]
   - Name: Director Won Robin
   - Phone: 02-6952-6961 (Customer phone consultation not provided, please inquire via app > My Page > 1:1 consultation)
   - Email: [email protected]
3. If you need to report or consult about other personal information infringements, please contact the organizations below.
   - Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without area code)
   - Information Protection Mark Certification Committee (www.eprivacy.or.kr / 02-580-0534)
   - Supreme Prosecutors' Office Advanced Crime Investigation Division (www.spo.go.kr / 02-3480-2000)
   - National Police Agency Cyber Safety Bureau (cyberbureau.police.go.kr / 182 without area code)

### **Article 13 Duty of Notification**

**The current privacy policy was revised on July 21, 2021, and additions, deletions, and modifications to the content according to government policy or security technology changes will be notified through the homepage at least 7 days before revision.**

**Article 14 Use and Processing of Location Information**

1. The Company may utilize users' location information to provide better services. However, location information is not stored or retained without users' explicit consent.

2. Location information is used only in the following cases:

• Recommending nearby tennis courts and facilities

• Distance-based filtering between users in matching services

• Tournament venue and court location guidance

3. When the Company uses location information, it follows the following methods:

• GPS or network-based location information can be collected from users' devices, and such information is used only for real-time service provision.

• Collected location information is not stored and is immediately destroyed upon user session termination or service termination.

4. Users can block location information provision at any time in device settings.

5. The Company may provide detailed policies on protection and use of location information so that users can easily check them through settings menus or notices within services.

### **<Addendum>**

**These terms are effective from July 28, 2021. Terms implemented from April 15, 2015, are replaced by these terms.**