NotiDrop

NotiDrop Privacy Policy

Effective Date: December 29, 2025

We're Bridge (hereinafter referred to as "the Company") complies with the Personal Information Protection Act and related laws to lawfully process and securely manage personal information for the protection of data subjects' freedoms and rights. In accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for processing and protecting personal information and to promptly and smoothly handle related complaints.

Chapter 1: General Provisions

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than those stated below, and if the purpose of use changes, necessary measures will be taken in accordance with Article 18 of the Personal Information Protection Act, such as obtaining separate consent.

Membership registration and management: Member identification, authentication, maintenance of membership status, prevention of unauthorized use, delivery of service-related notices

Notification synchronization and integrated service provision: Collection, encryption, synchronization, and integrated management of push notification messages (including title, content, sender app information, etc.) across multiple devices (mobile phones, tablets, PCs, etc.) registered by users

Implementation of personalized features and enhanced convenience: Providing user-configured features such as Do Not Disturb mode, push message formatting, notification preview, incoming call notifications, etc.

Service quality improvement and stability assurance: New feature development, service effectiveness verification, error detection and access frequency analysis, service optimization and quality enhancement

Article 2 (Categories of Personal Information Processed and Collection Methods)

The Company collects the following personal information to provide services and processes only the minimum information necessary for the purpose of use.

Categories of Personal Information Collected

Category Processing Purpose Collected/Processed Information
Required Information for Membership Confirmation of membership intent, provision and maintenance of membership services, personal identification and verification User ID, password, nickname, email address
Automatically collected information during service use Push notification data (notification title, content, sender app information, reception time, etc.), device identification information (push token, device ID, OS version, model name, access logs, etc.)

Currently, the NotiDrop app collects only user ID, password, nickname, and email address, and does not have a separate age verification process. Personal information of children under 14 years of age is not separately collected.

Personal Information Collection Methods
Direct input by users through the membership registration process
Automatic collection and transmission from registered devices after users explicitly consent to push notification access permissions and synchronization service use within the app

Notice
Collected push notification content (including sensitive information) is used solely for the purpose of providing integrated notification and synchronization services, and will not be provided to third parties in an identifiable form for advertising, marketing, or other purposes without the user's prior consent.

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law or the retention period agreed upon when collecting personal information from data subjects. The specific retention and use periods are as follows:

Member information: Retained for 30 days after withdrawal for recovery purposes, then anonymized

Information for service use (notification data, registered device information, etc.): Retained for 30 days after withdrawal then anonymized, or until deletion of the registered device

However, if retention is required under related laws, it will be retained for the period specified in the applicable laws, and will be anonymized after the retention period expires.

The Company securely anonymizes personal information when the retention period expires or the processing purpose is achieved.

Information Required to be Retained Under Related Laws

Notwithstanding the retention periods stated above, if retention is necessary pursuant to the provisions of related laws, personal information will be retained for the period specified by the applicable laws. This information will be used only for the purpose of retention.

Category Retention Purpose Retention Period
Act on Consumer Protection in Electronic Commerce, etc. Records of contracts, withdrawal of offers, payment, supply of goods 5 years
Act on Consumer Protection in Electronic Commerce, etc. Records of consumer complaints or dispute resolution 3 years
Act on Consumer Protection in Electronic Commerce, etc. Service use records, access logs, access IP information 3 months

Article 4 (Provision of Personal Information to Third Parties)

The Company does not, in principle, provide users' personal information to external parties without their consent. However, the following exceptions apply:

When users have given prior consent

When required to comply with legal obligations in accordance with procedures and standards prescribed by law

When personal information processing tasks are outsourced to provide services, and personal information protection obligations are strictly managed and supervised through contracts, etc.

When providing personal information to third parties, the Company clearly informs users of the purpose of provision, categories of personal information provided, name and contact information of the third party, retention and use period, etc., and obtains separate consent when necessary.

Details regarding third-party provision are provided in the separate "Entrustment of Personal Information Processing" section, and users have the right to confirm or refuse consent to third-party provision at any time.

Article 5 (Entrustment of Personal Information Processing)

The Company may entrust some personal information processing tasks to external specialized companies to provide smooth services. When concluding entrustment contracts, the Company specifies the following contents in documents (or electronic documents) in accordance with Article 26 of the Personal Information Protection Act, and supervises whether the trustees process personal information securely.

Entrusted tasks: System development and maintenance, server hosting and data storage, customer consultation and inquiry handling, etc.

Purpose of entrustment: Efficient service provision, stable service operation and management, enhancement of customer convenience

When concluding entrustment contracts, the Company clearly stipulates obligations related to personal information protection in accordance with Article 26 of the Personal Information Protection Act, such as prohibition of processing personal information beyond the purpose of performing entrusted tasks, technical and administrative protection measures, restrictions on re-entrustment, compensation for damages, etc., and periodically supervises whether the trustees process personal information securely while maintaining the contract contents in written or electronic document form.

If the content of entrusted tasks or the trustees change, this will be promptly disclosed through this Privacy Policy.

Article 6 (Rights of Data Subjects and Legal Representatives and Exercise Methods)

Users may request access, correction, deletion, suspension of processing, and withdrawal of consent regarding their personal information at any time. Requests can be made through the personal information management menu within the app or customer service center, and the Company will take action without delay.

This service does not separately collect personal information of children under 14 years of age.

Article 7 (Measures to Ensure Safety of Personal Information)

In processing users' personal information, the Company implements the following technical, administrative, and physical measures necessary to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged.

Establishment and implementation of internal management plans: Internal management plans are established and implemented for the secure processing of personal information.

Minimization and training of personal information handling staff: Staff handling personal information is minimized, and regular training on personal information protection obligations is conducted.

Encryption of personal information:
Users' passwords are encrypted for storage and management, and secure encrypted communication (SSL/TLS) is used to protect personal information and sensitive information during transmission.
In particular, sensitive information such as push notification data is encrypted during collection and transmission, and is securely stored in encrypted form when saved on servers.

Technical measures against hacking, etc.: Security programs are installed and periodically updated and inspected to prevent leakage and damage of personal information by hacking or computer viruses, and unauthorized external access is controlled.

Restriction of access to personal information: Access control to personal information is implemented through granting, changing, and revoking access rights to database systems processing personal information, and intrusion prevention systems are used to control unauthorized external access.

Retention and prevention of falsification of access records: Records of access to personal information processing systems (web logs, summary information, etc.) are retained and managed for at least 1 year, and security functions are used to prevent access records from being falsified, stolen, or lost.

Physical safety measures: Physical access to locations storing personal information, such as computer rooms and data storage rooms, is controlled.

Article 8 (Personal Information Protection Officer and Department)

The Company designates a Personal Information Protection Officer as follows to protect users' personal information and handle complaints related to personal information.

Personal Information Protection Officer

Name Position Contact
Choi Min-seo CEO 010-4291-0603
ms.choi@werebridge.com

You may contact the Personal Information Protection Officer and department regarding all personal information protection inquiries, complaint handling, damage relief, etc. that occur while using the NotiDrop app service. The Company will respond to and handle data subjects' inquiries without delay.

Article 9 (Remedies for Infringement of Rights and Interests)

Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, etc. to receive relief for personal information infringement. In addition, if relief is needed for mental or property damage caused by personal information infringement, compensation for damages may be claimed under related laws.

Personal Information Dispute Mediation Committee (Personal Information Protection Commission)

Jurisdiction Website Contact
Personal information dispute mediation applications, collective dispute mediation (civil resolution) www.kopico.go.kr 1833-6972
(without area code)

Personal Information Infringement Report Center (KISA)

Jurisdiction Website Contact
Personal information infringement report, consultation applications privacy.kisa.or.kr 118
(without area code)

Supreme Prosecutors' Office Cyber Investigation Division

Jurisdiction Website Contact
Investigation of various cybercrimes and criminal proceedings www.spo.go.kr 1301
(without area code)

National Police Agency Cyber Investigation Bureau

Jurisdiction Website Contact
Cybercrime reporting and investigation www.spo.go.kr 182
(without area code)

You may apply for consultation and relief for personal information infringement to the above institutions, and if you are not satisfied with the Company's internal personal information complaint handling results or need more detailed assistance, you may contact the relevant institutions.

Article 10 (Changes to Privacy Policy)

This Privacy Policy may be changed in accordance with changes in related laws, the Company's internal policies, or security technology.

When the Company changes the Privacy Policy, the reason for and content of the change will be posted on the website (or in-app notices) at least 7 days in advance, and the changed Privacy Policy will take effect 7 days after posting.

However, for important matters that change unfavorably to users, such as categories of personal information collected or purpose of use of personal information, advance notice will be given at least 30 days in advance, and if users do not agree to the changes, they may discontinue use of the service.

Users are advised to periodically review the updated Privacy Policy.

Supplementary Provisions

This Privacy Policy shall be effective from December 29, 2025.