Privacy Policy

Effective date2026.07.23

K-VOICE INTEGRATED ACCOUNT GLOBAL PRIVACY POLICY

For Users in the European Union, European Economic Area, United Kingdom, United States, Australia, Canada and Russia

KY Entertainment Co., Ltd. (“KY Entertainment,” the “Company,” “we,” “us” or “our”) respects the privacy of Users of the K-VOICE integrated account service.

The Company processes personal data in accordance with applicable privacy and data protection laws, including, where applicable, the Personal Information Protection Act of the Republic of Korea, the EU General Data Protection Regulation, the UK General Data Protection Regulation, applicable United States federal and state privacy laws, the Australian Privacy Act 1988 and Australian Privacy Principles, the Personal Information Protection and Electronic Documents Act and applicable provincial laws of Canada, and Federal Law No. 152-FZ on Personal Data of the Russian Federation.

This Privacy Policy explains how the Company collects, uses, stores, discloses, transfers, protects and deletes personal data in connection with K-VOICE.

Article 1. Purposes of Processing Personal Data

The Company processes personal data for the following purposes. Personal data shall not be used for an incompatible purpose unless permitted by law or the Company provides the required notice and obtains consent where necessary.

1. Integrated Account Registration and Management

The Company may process personal data to:

  • confirm the User’s intention to register;
  • identify and authenticate the User;
  • process registration and sign-in;
  • maintain and manage account status;
  • provide simplified registration and sign-in through Google or Kakao accounts;
  • confirm and process account deletion requests;
  • prevent fraudulent use, unauthorised use, duplicate registration and account theft;
  • provide notices and Service-related information; and
  • maintain account security.

2. Provision and Management of the Service

The Company may process personal data to:

  • connect supported K-VOICE functions between Smart TV and mobile applications;
  • enable use through an integrated K-VOICE account;
  • verify passes, pricing plans, recurring payments and subscription status;
  • manage Service settings and connected devices;
  • diagnose errors and technical problems;
  • respond to technical failures; and
  • maintain and improve Service functionality, quality and security.

3. Paid Services, Payments and Settlement

The Company may process personal data to:

  • process purchases, payments, cancellations and refunds;
  • verify payment records and grant purchased passes;
  • manage subscription renewal, expiration and cancellation;
  • prevent fraudulent payments and abnormal transactions;
  • perform accounting, settlement and tax-related processing; and
  • retain transaction records as required by law.

4. Customer Support and Complaint Handling

The Company may process personal data to:

  • respond to enquiries, complaints, error reports and requests;
  • verify the identity of the person making a request;
  • communicate the outcome of the request;
  • manage customer-support records;
  • resolve disputes; and
  • establish, exercise or defend legal claims.

5. Marketing and Promotions

Where the User has given consent or another lawful basis applies, the Company may process personal data to:

  • send information about events, benefits, promotions and new services;
  • measure promotional effectiveness; and
  • provide marketing content according to the User’s preferences.

The User may withdraw marketing consent at any time.

Article 2. Categories of Personal Data and Collection Methods

The Company collects and processes only personal data reasonably necessary to provide and operate the Service.

1. Integrated Account Registration

Required information may include:

  • email address;
  • login ID;
  • nickname;
  • password;
  • registration date; and
  • country, region or nationality information.

This information is used for registration, authentication, identification and account management.

Optional information may include:

  • marketing communication preferences;
  • event participation information; and
  • other information clearly identified as optional at the time of collection.

Failure to provide required information may prevent account creation or use of essential functions. Failure to provide optional information will not prevent use of the core Service.

2. Google or Kakao Account Integration

Where the User registers or signs in using a Google or Kakao account, the Company may receive information authorised by the User.

For a Google account, this may include:

  • Google account unique identifier;
  • email address; and
  • profile information authorised by the User.

For a Kakao account, this may include:

  • Kakao account unique identifier;
  • email address;
  • nickname; and
  • profile information authorised by the User.

Google and Kakao may process personal data under their own privacy policies and legal obligations.

3. Payments and Subscriptions

Depending on the payment method, the Company may process:

Credit or Debit Card Payment

  • payment transaction identifier;
  • recurring-subscription identifier;
  • payment date and time;
  • payment amount; and
  • payment status.

Mobile Phone Payment

  • payment transaction identifier;
  • payment date and time;
  • payment amount; and
  • payment status.

Kakao Pay or Naver Pay, Where Available

  • payment transaction identifier;
  • payment date and time;
  • payment amount; and
  • payment status.

PayPal

  • payment transaction identifier;
  • recurring-subscription identifier;
  • order number;
  • PayPal User Unique ID;
  • payer email address, where provided;
  • payment date and time;
  • payment amount; and
  • payment status.

App Marketplace or Smart TV Platform

  • order number;
  • receipt or purchase-verification information;
  • subscription product name;
  • subscription start date;
  • renewal date;
  • expiration date;
  • subscription status; and
  • platform payment identifier.

The Company does not normally receive or directly store complete credit card numbers, bank account numbers or complete payment credentials.

Payment information may be collected directly by the relevant payment service, app marketplace or platform under its own privacy policy.

4. Information Collected Automatically

The following information may be generated or collected during use of the Service:

  • Service usage records;
  • login and activity logs;
  • fraudulent or abnormal-use records;
  • IP address;
  • approximate access country or region;
  • language settings;
  • operating system and version;
  • application version;
  • device model;
  • device or platform identifier;
  • crash and error information;
  • access date and time; and
  • information relating to connected Smart TV or mobile devices.

Non-essential advertising identifiers, analytics tools or tracking technologies will be used only after consent where applicable law requires consent.

5. Existing K-araoke or Gabang Information

Existing K-araoke or Gabang accounts are not automatically linked to K-VOICE.

The Company may process limited existing-service account, pass or payment information only where:

  • the User voluntarily provides the information;
  • the User requests customer support concerning an existing service;
  • verification is necessary to resolve duplicate payments or account issues; or
  • a separate linkage is lawfully implemented after providing notice and obtaining consent where required.

6. Collection Methods

The Company may collect personal data through:

  • the K-VOICE registration page;
  • Google, Kakao or another social sign-in service;
  • automatic collection during Service use;
  • payment and subscription processes;
  • communications with customer support;
  • event or promotion participation;
  • payment providers, app marketplaces and platform operators; and
  • another third party where the User has authorised disclosure or another lawful basis applies.

7. Sensitive or Special Category Data

The Company does not intentionally request or collect sensitive or special category personal data through ordinary use of the Service.

Users should not submit health information, biometric information, political opinions, religious beliefs, sexual orientation, racial or ethnic origin or other sensitive information unless specifically requested for a lawful purpose and appropriate safeguards have been provided.

Article 3. Legal Bases and Grounds for Processing

Depending on the applicable law, the Company processes personal data on one or more of the following grounds.

1. Performance of a Contract

Processing may be necessary to:

  • create and manage an account;
  • authenticate the User;
  • provide mobile and Smart TV functions;
  • process purchases, subscriptions, cancellations and refunds;
  • provide customer support; and
  • perform obligations under the Service agreement.

2. Compliance With Legal Obligations

Processing or retention may be necessary to comply with:

  • accounting and tax requirements;
  • transaction-record obligations;
  • consumer protection laws;
  • legally valid requests from public authorities;
  • fraud-prevention obligations; and
  • other legal requirements.

3. Legitimate Interests or Reasonable Business Purposes

Where permitted by law, the Company may process personal data to:

  • maintain account and Service security;
  • prevent fraud, abuse and unauthorised access;
  • protect the Company, Users and third parties;
  • diagnose errors and improve performance;
  • maintain business and transaction records;
  • respond to legal claims and disputes; and
  • ensure Service reliability and integrity.

The Company shall not rely on legitimate interests where the User’s rights and interests override those interests.

4. Consent

The Company relies on consent where required for:

  • marketing communications;
  • non-essential cookies and analytics;
  • advertising identifiers;
  • optional profile information;
  • certain social-account permissions; and
  • other activities for which applicable law requires consent.

Consent may be withdrawn at any time. Withdrawal does not affect processing carried out lawfully before withdrawal.

5. Other Grounds Permitted by Local Law

Where the concepts of contractual necessity, legitimate interests or consent are applied differently under local law, the Company shall process personal data only on a ground permitted by the applicable law.

Article 4. Personal Data of Children and Minors

  1. The Service is not directed to children under fourteen, and the Company does not knowingly accept registrations from children under fourteen.
  2. In the United States, the Company does not knowingly collect personal information online from a child under thirteen without verifiable parental consent where required by law.
  3. A User who has not reached the applicable age for independent consent or contract formation must obtain consent from a parent or legal guardian where required.
  4. The applicable age may differ depending on the User’s country or region.
  5. Where parental or guardian consent is required, the Company may request reasonable information to verify:

(a) the child’s age;

(b) the identity of the parent or guardian; and

(c) the validity of the consent.

  1. If the Company learns that personal data has been collected without legally required consent, it shall delete or restrict the data without undue delay unless retention is required by law.

Article 5. Retention of Personal Data

The Company retains personal data only for as long as necessary for the stated purposes or for the period required by law.

1. Internal Retention Periods

Integrated Account Information

Retained until account deletion, unless a longer period is required by law.

Google or Kakao Account-Connection Information

Retained until the connection is removed or the K-VOICE account is deleted.

Existing K-araoke or Gabang Information

Where lawfully processed for support or verification, retained until the relevant issue is resolved, the existing account is deleted or the relevant Service is discontinued, subject to legal retention requirements.

Pass, Subscription and Payment Information

Retained until the end of the Service relationship and thereafter for the period required by transaction, tax, accounting and consumer-protection laws.

Customer Support and Complaint Records

Normally retained for three years after completion of the relevant enquiry or complaint, unless a different period is required or justified by law.

Marketing Consent Records

Retained until consent is withdrawn or the account is deleted.

Evidence of consent and withdrawal may be retained for an additional period where necessary to demonstrate compliance.

Service Usage and Access Logs

Normally retained for three months from collection.

Information necessary for security, fraud prevention, incident investigation or legal claims may be retained for a longer period, but only for as long as reasonably necessary.

Fraud-Prevention Records

Normally retained for one year after account deletion, unless a different period is necessary and proportionate due to the nature of the incident or a legal requirement.

2. Records Retained Under Korean Law

As a company established in the Republic of Korea, the Company may be required to retain:

  • records concerning contracts or withdrawal: five years;
  • records concerning payment and supply of services: five years;
  • records concerning consumer complaints or disputes: three years;
  • records concerning advertising and representations: six months;
  • access logs or communication-confirmation records: three months; and
  • tax and accounting records: for the period required by law.

Information retained solely to comply with a legal obligation will be separated or access-restricted and will not be used for unrelated purposes.

3. Retention Criteria

In determining retention periods, the Company considers:

  • the nature and sensitivity of the information;
  • the purposes of processing;
  • the duration of the contractual relationship;
  • fraud and security risks;
  • possible complaints or disputes;
  • applicable limitation periods; and
  • legal, accounting and regulatory obligations.

Article 6. Storage and International Transfers

  1. The Company is established in the Republic of Korea, and personal data is generally transferred to, stored in and processed in the Republic of Korea.
  2. Personal data may also be processed by service providers or platform operators in other countries where necessary to provide the Service and permitted by applicable law.

1. European Union and European Economic Area

Transfers from the EU or EEA to the Republic of Korea may rely on an applicable European Commission adequacy decision.

Where an adequacy decision does not cover a particular transfer, the Company shall use an appropriate transfer mechanism, including Standard Contractual Clauses or another legally permitted safeguard.

2. United Kingdom

Transfers from the United Kingdom to the Republic of Korea may rely on applicable UK adequacy regulations.

Where necessary, the Company shall use an appropriate safeguard, including the UK International Data Transfer Agreement, the UK Addendum or another lawful mechanism.

3. United States

Personal data collected from Users in the United States may be transferred to and processed in the Republic of Korea.

The Company shall provide the notices, contractual protections, security measures and User rights required by applicable federal and state laws.

4. Australia

Where Australian privacy law applies, the Company shall take reasonable steps regarding overseas recipients and cross-border disclosures as required by the Australian Privacy Principles.

5. Canada

Where Canadian privacy law applies, the Company remains accountable for personal information transferred to a service provider for processing and shall use contractual or other measures designed to provide a comparable level of protection.

6. Russia

Where Russian personal-data law applies, the Company shall comply with all applicable localisation requirements.

This may include using databases located within the Russian Federation for the collection, recording, systematisation, accumulation, storage, clarification, updating and retrieval of personal data of Russian citizens.

Any subsequent cross-border transfer shall be carried out only where permitted by Russian law and after any required assessment, notification or approval procedure, including notification to the competent Russian authority where required.

If the Company cannot satisfy a mandatory Russian localisation or transfer requirement, the relevant collection or Service may be restricted or unavailable in Russia.

7. Overseas Payment Services

Where the User independently selects an overseas payment service such as PayPal, the payment provider may collect payment information directly and process it under its own privacy policy.

For payment verification, access provision, refunds and settlement, the Company may receive:

  • payer email address;
  • transaction amount;
  • transaction or order number; and
  • payment or subscription status.

8. Transfer Information

The User may contact the Company to request information about the transfer mechanism applicable to their personal data, subject to applicable law and reasonable confidentiality restrictions.

Article 7. Disclosure to Third Parties

  1. The Company processes personal data only within the scope described in this Privacy Policy and does not sell personal data for monetary consideration.
  2. The Company may disclose personal data where:

(a) the User has provided consent;

(b) disclosure is necessary to perform a contract requested by the User;

(c) disclosure is required by law;

(d) a court, law-enforcement agency or competent authority makes a valid request;

(e) disclosure is necessary to protect the rights, safety or property of the Company, Users or third parties;

(f) disclosure is connected with a merger, restructuring or transfer of the relevant business, subject to law; or

(g) another valid legal ground applies.

  1. Where consent is relied upon, the Company shall provide information about:

(a) the recipient or category of recipient;

(b) the purpose of disclosure;

(c) the categories of data disclosed; and

(d) the applicable retention period.

  1. Payment providers, social sign-in providers and app marketplaces may act as independent controllers or businesses for processing they determine independently.
  2. Where applicable United States state law defines “sale,” “sharing” or targeted-advertising disclosure more broadly than a monetary sale, the Company shall provide any legally required notice and opt-out mechanism.
  3. The Company shall not discriminate against a User for exercising a privacy right protected by applicable law.

Article 8. Processors and Service Providers

  1. The Company may appoint external providers to process personal data on its behalf.
  2. Categories of providers may include:
  • cloud hosting and storage providers;
  • authentication and account-management providers;
  • payment and subscription processors;
  • email, notification and customer-support providers;
  • security, fraud-prevention and monitoring providers;
  • analytics, crash-reporting and Service-improvement providers;
  • accounting and professional advisers; and
  • app marketplaces and Smart TV platform operators.
  1. Where required, the Company shall enter into a written data-processing agreement with the provider.
  2. Providers acting on the Company’s behalf shall be required to:
  • process personal data only on documented instructions;
  • maintain confidentiality;
  • implement appropriate security measures;
  • assist with privacy-rights requests;
  • comply with applicable international-transfer requirements; and
  • delete or return information when the service ends unless retention is legally required.
  1. Information about current providers or categories of providers may be made available through the Service, website or upon request, subject to reasonable security and confidentiality restrictions.

Article 9. Deletion and Destruction

The Company deletes or anonymises personal data without undue delay when:

  • the retention period expires;
  • the processing purpose has been achieved;
  • consent is withdrawn and no other lawful ground applies;
  • a valid objection is made and no overriding lawful ground exists;
  • the information has been unlawfully processed; or
  • deletion is otherwise required by law.

1. Deletion Procedure

The Company identifies information eligible for deletion and deletes it in accordance with internal procedures under the supervision or approval of the person responsible for privacy management.

2. Electronic Records

Electronic information is securely deleted or overwritten using a method designed to prevent practical recovery or reconstruction.

3. Paper Records

Paper records are destroyed by shredding, pulping, incineration or another secure disposal method.

4. Legally Required Retention

Where retention is legally required, the relevant information shall be separated, access-restricted or otherwise protected and shall not be used for an unrelated purpose.

Article 10. User Privacy Rights

Subject to applicable law, Users may have the following rights:

  1. the right to be informed about processing;
  2. the right to access and receive a copy of personal data;
  3. the right to correct inaccurate or incomplete data;
  4. the right to request deletion or erasure;
  5. the right to request restriction, blocking or suspension of processing;
  6. the right to data portability where applicable;
  7. the right to object to processing based on legitimate interests or similar grounds;
  8. the right to withdraw consent;
  9. the right to object to direct marketing;
  10. the right to opt out of the sale or sharing of personal data or targeted advertising where provided by applicable United States state law;
  11. the right to limit certain uses of sensitive personal information where provided by law;
  12. the right to appeal a refusal of a privacy request where provided by applicable United States state law;
  13. the right to challenge the accuracy or completeness of personal information under applicable Canadian law;
  14. the right to access and correct personal information and make a privacy complaint under applicable Australian law;
  15. the right to request correction, blocking or deletion of inaccurate, unlawfully processed or unnecessary personal data under applicable Russian law;
  16. the right not to be subject to certain decisions based solely on automated processing where applicable; and
  17. the right to lodge a complaint with a competent supervisory or regulatory authority.

Exercising Rights

The User may exercise rights through:

  • the K-VOICE account-management menu;
  • email;
  • telephone;
  • written request; or
  • another method designated by the Company.

Account deletion may be requested through:

K-VOICE Account Management → Delete Account

Account deletion does not automatically cancel a subscription managed by PayPal, an app marketplace or another external payment provider.

The Company may request reasonable information to verify the identity and authority of the requester.

The Company shall respond within the period required by applicable law. A response period may be extended where legally permitted due to the complexity or number of requests.

Requests are normally handled free of charge. A reasonable fee may be charged or a request may be refused only where permitted by law, including where a request is manifestly unfounded or excessive.

The Company shall not retaliate against or unlawfully discriminate against a User for exercising a privacy right.

Article 11. Cookies and Similar Technologies

  1. The Company may use cookies, mobile advertising identifiers, software development kits, local storage, analytics tools and similar technologies.
  2. These technologies may be used to:
  • maintain sign-in status;
  • retain Service and language settings;
  • analyse access frequency and usage time;
  • understand usage patterns;
  • diagnose errors and improve quality;
  • prevent fraud and maintain security;
  • record event participation;
  • measure advertising effectiveness; and
  • provide personalised content or advertising where permitted.
  1. Technologies strictly necessary to provide a requested Service, maintain security, process sign-in or retain essential settings may be used without consent where permitted by law.
  2. Analytics, advertising, personalisation or other non-essential technologies shall be activated only after valid consent where applicable law requires consent.
  3. The User may withdraw or modify consent through cookie settings, privacy settings or another consent-management function made available by the Company.
  4. Users may also restrict cookies or identifiers through:
  • web-browser cookie settings;
  • Android privacy or advertising-ID settings;
  • iOS Privacy & Security, Tracking or Apple Advertising settings;
  • Smart TV privacy or advertising settings; and
  • K-VOICE privacy-preference settings, where available.
  1. Restricting essential technologies may prevent certain sign-in, payment or Service functions from operating correctly.

Article 12. Security and Personal Data Breaches

  1. The Company implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
  2. Organisational measures may include:
  • internal privacy and security policies;
  • minimisation of authorised personnel;
  • privacy and security training;
  • role-based access controls;
  • access-permission reviews;
  • processor supervision; and
  • incident-response procedures.
  1. Technical measures may include:
  • access-control systems;
  • encryption or secure hashing of passwords;
  • secure communications;
  • access logging and monitoring;
  • protection against alteration of logs;
  • malware and intrusion protection;
  • vulnerability management;
  • security updates;
  • backup and recovery controls; and
  • systems designed to prevent unauthorised access.
  1. Physical measures may include:
  • access controls for data-storage locations;
  • secure storage of documents and media; and
  • secure disposal procedures.
  1. Where a personal-data breach occurs, the Company shall assess the incident and notify affected Users, supervisory authorities or other competent authorities where and within the time required by applicable law.

Article 13. Controller and Privacy Contacts

1. Data Controller

Company: KY Entertainment Co., Ltd.
Country of Establishment: Republic of Korea
Department: Information Team
Telephone: +82-2-6105-7554
Email: support@kyentertainment.kr

2. Person Responsible for Privacy Management

Privacy Officer: Jongmin Choi
Position: Deputy General Manager
Department: Information Team
Telephone: +82-2-6105-7554
Email: support@kyentertainment.kr

The designation “Privacy Officer” does not mean that the person has been formally appointed as a statutory Data Protection Officer unless the Company separately confirms such appointment.

3. EU or EEA Representative

Where Article 27 of the EU GDPR or another applicable law requires the Company to appoint an EU or EEA representative, the Company shall appoint a representative and publish the representative’s name, address and contact details through the Service or Company website.

4. United Kingdom Representative

Where the UK GDPR requires the Company to appoint a UK representative, the Company shall appoint a representative and publish the representative’s name, address and contact details through the Service or Company website.

5. Other Local Contacts

Where local law requires a local representative, agent or privacy contact in the United States, Australia, Canada or Russia, the Company shall appoint the required person and publish the applicable contact details.

Article 14. Complaints and Remedies

  1. Users may first contact the Company or the applicable local representative concerning a privacy issue.
  2. Users in the EU or EEA may lodge a complaint with a competent data-protection supervisory authority, particularly in the country of habitual residence, place of work or alleged infringement.
  3. Users in the United Kingdom may lodge a complaint with the UK Information Commissioner’s Office.
  4. Users in the United States may contact the competent state attorney general, the California Privacy Protection Agency where applicable, the Federal Trade Commission or another competent authority.
  5. Users in Australia may lodge a complaint with the Office of the Australian Information Commissioner where applicable.
  6. Users in Canada may lodge a complaint with the Office of the Privacy Commissioner of Canada or a competent provincial privacy authority.
  7. Users in Russia may contact Roskomnadzor or another competent Russian authority.
  8. Users may also contact competent Korean privacy or dispute-resolution authorities where applicable.
  9. A complaint to an authority does not prevent the User from exercising another administrative or judicial remedy available under law.

Article 15. Changes to This Privacy Policy

  1. The Company may amend this Privacy Policy to reflect changes in:
  • applicable law or regulatory guidance;
  • the Service or its functions;
  • the categories or purposes of processing;
  • service providers or recipients;
  • international-transfer arrangements; or
  • security and operational practices.
  1. The Company shall provide notice through the Service, website, application screen, email or another appropriate method.
  2. Where a change materially affects User rights or significantly changes processing purposes, data categories, disclosures or retention periods, the Company shall normally provide at least thirty days’ advance notice unless a different period is required by law.
  3. Other changes shall normally be announced at least seven days before the effective date.
  4. Where consent is required for a new processing activity, the Company shall obtain consent before beginning that processing.

Article 16. Mandatory Local Privacy and Data Protection Laws

Nothing in this Privacy Policy excludes, restricts or limits any privacy or data-protection right, remedy, protection or statutory guarantee that cannot lawfully be excluded, restricted or limited under the laws applicable in the country where the User habitually resides.

If any provision of this Privacy Policy conflicts with the EU GDPR, UK GDPR, applicable United States federal or state privacy law, the Australian Privacy Act or Australian Privacy Principles, Canadian federal or provincial privacy law, Russian personal-data law, electronic communications or cookie law, consumer protection law or any other mandatory law applicable in the User’s country, the applicable mandatory law shall prevail to the extent of the conflict.

The Company shall process personal data and respond to privacy-rights requests in accordance with the mandatory privacy and data-protection laws applicable to the relevant User.

Publication Date: 24 July 2026
Effective Date: 24 July 2026

KY Entertainment Co., Ltd.

Keumyoung Entertainment Co., Ltd.

Address: #1701, 1702, 1703, 1714, 1715, 17F, 143, Gasan digital 2-ro, Geumcheon-gu, Seoul, Korea (Gasan-dong, Gasan Urban Work II)

CEO: Suk Hyun Lee|Company No.: 221-88-00319

E-commerce Registration No.: 2025-Seoul Geumcheon-1355

Customer Center: +82 02-6105-7550

(Business Days: 09:00-18:00 KST)