Privacy Policy
Divine Company ("Company", "we") complies with the Personal Information Protection Act (PIPA) of the Republic of Korea and other applicable laws, and has established and published this Privacy Policy to safeguard personal information processed in connection with 'Statlane' (the "Service"), our Korea-focused multi-channel advertising and behavioral-analytics SaaS platform. This Policy separately governs the personal information of users (members) who sign up for the Service and the visitor data collected through the behavioral-analytics tools that users install on their own websites.
- Effective date
- August 1, 2026
- Default jurisdiction
- United States (CCPA/CPRA)
This is the current version, effective as of the date shown above. When revised, the Company will provide at least 7 days’ prior notice (30 days for changes unfavorable to users) via in-service notice or similar; the latest version supersedes prior versions.
1. Data Controller and Contact
The Company (Divine Company; Business Registration No. 572-19-01127; address: 713 Bugaksan-ro, Bldg. 3, Rm. 307, Seongbuk-gu, Seoul, Republic of Korea) acts as the data controller for the personal information of users who sign up for the Service and is responsible for its processing. For the representative, telephone number, email and other specific business details, please refer to the business information the Company publishes within the Service. With respect to visitor personal information collected through the Company's behavioral-analytics tool (collector) that a user installs on the user's own website or service, the user (tenant) is the data controller, and the Company acts solely as a processor handling such data on the user's instructions. In that case, the primary responsibility for providing a privacy notice to visitors and for responding to data-subject requests lies with the user.
2. Personal Information We Collect
The Company processes the following personal information to provide the Service. (1) Membership sign-up information: name or contact person's name, ID, password (stored encrypted), email, mobile number, and business details of the affiliated entity (trade name, business registration number, etc.). (2) Payment information: identifiers of the payment method used for recurring subscription billing, and authorization/transaction records handled by the payment gateway (sensitive payment data such as full card numbers is processed by the payment gateway and, as a rule, is not retained by the Company). (3) Service usage records: access logs, IP address, device/browser information, and in-service activity history. (4) Visitor behavioral data: page views, clicks, events and similar behavioral data collected through the collector installed by users (governed separately under Section 3). The Company does not collect sensitive information beyond the scope permitted by applicable law in the course of providing the Service.
3. Visitor Behavioral Analytics (collector)
The Service provides functionality to collect and analyze visitor behavioral data (page views, clicks, scrolls, conversion events, approximate access environment, etc.) through a collection script (collector; collection domain t.statlane.kr) that users install on their own websites. The data controller for such data is the user (tenant) that installs and operates it, and the Company processes it as a processor in accordance with the user's instructions. Collection of visitor data is premised on a consent gate that the user implements on the user's own website, and collection and use that require consent under applicable law take place only where the visitor's consent has been confirmed. For the session replay feature available on the PREMIUM plan, by default all input fields (including passwords and payment information) and text patterns in the form of card numbers, resident registration numbers, phone numbers, and email addresses are automatically masked at the collector (client) before storage, and this masking is enforced client-side. Other personal information rendered as plain text on the screen is protected only within the scope of the masking selectors and blocked areas that the user designates, and the Company does not additionally re-mask received replay data on the server. Users are therefore responsible for designating masking and blocking selectors for sensitive areas.
Our first-party analytics script (t.statlane.kr/loader.js) collects page interactions. Collection is gated by cookie consent (analytics category); the exact data points and retention are pending legal review. (G2.3 integration)
<script src="//t.statlane.kr/loader.js" async></script>Read more in the Cookie Policy 4. Purposes and Legal Bases of Processing
The Company processes personal information for the following purposes, each on a corresponding legal basis. (1) Sign-up, identity verification, provision of the Service, and performance of the service agreement: performance of a contract (PIPA Art. 15(1)(iv)). (2) Payment, settlement and refunds for paid plans: performance of a contract and compliance with legal obligations (including the Act on Consumer Protection in Electronic Commerce). (3) Optional processing such as marketing communications and granular analytics or add-on features: the data subject's consent (PIPA Art. 15(1)(i)). (4) Prevention of fraudulent use, security and stable operation: processing necessary to achieve the Company's legitimate interests where those interests manifestly override the rights of the data subject and do not exceed a reasonably related scope (PIPA Art. 15(1)(vi)). (5) Statistical analysis for service improvement: pseudonymized/statistical processing for statistical purposes (PIPA Art. 28-2 and related provisions), carried out in a form that does not identify any specific individual. (6) Compliance with legal obligations and handling of disputes: compliance with legal obligations and the Company's legitimate interests. Where processing is based on consent, the data subject may withdraw consent at any time, and such withdrawal does not affect the lawfulness of processing carried out beforehand.
7. Cross-Border Transfers
The Company stores all user and visitor data, including personal information, within a domestic (Republic of Korea) region and does not store or retain personal information overseas. However, to perform certain generative and analytics features (for example, processing analytical queries or handling images uploaded by users), the minimum data necessary to achieve the processing purpose is transiently transmitted to and computed by a generative-AI inference provider located in the United States, after which it is discarded upon return of the result. This is a cross-border transfer of entrusted processing and storage necessary to perform the contract and to enhance the convenience of data subjects under Article 28-8(1)3 of the Personal Information Protection Act, carried out without separate consent of data subjects by disclosing the matters in each item of Article 28-8(2) in this Policy. Pursuant to Article 28-8(2), the Company discloses the following. (i) Categories of personal information transferred: the minimum data necessary to perform the feature, such as data contained in the analytical query requested by the user, samples of visitor comments/text, and images uploaded by the user. (ii) Destination country, timing, and method of transfer: to the United States, at the time the relevant AI feature is invoked, transiently over an encrypted channel in a manner that does not involve storage. (iii) Transferee: a generative-AI inference provider located in the United States. The transferee's specific legal name and contact details will be confirmed at the launch of the commercial Service and published and disclosed as an annex to this Policy (a data-processing disclosure incorporated as part of this Policy). (iv) Purpose of use and retention/use period of the transferee: limited to performing the generation/analysis inference requested by the user; the data is discarded immediately upon completion of processing and is not separately stored or retained. (v) Method, procedure, and effect of refusing the cross-border transfer: the user may refuse the above transfer by choosing not to use the AI analysis/generation features, in which case use of those AI features is restricted; refusal may be made by not enabling the relevant feature in the Service settings or by request through the contact channel the Company publishes. Until the transferee's legal name and contact details are confirmed and disclosed, the Company does not enable the function of transferring personal information to the United States. In addition, certain stateless computations may be performed in a Japan region during operation of the Service, but only as transient computation that does not involve storage of data.
8. Retention Periods
As a rule, the Company destroys personal information without delay once the purpose of processing has been achieved, and applies the following retention periods. (1) Member account information: until membership withdrawal. Upon withdrawal, account identifiers are irreversibly anonymized (de-identified), and, except for information subject to a statutory retention obligation, destroyed. However, anonymized records for fraud prevention and statistical purposes may be retained in a form that does not identify any individual. (2) Service usage records and event data: 13 months from the date of collection. (3) Session replay data: 3 months from the date of collection. (4) Payment and transaction records: 5 years, in accordance with the Act on Consumer Protection in Electronic Commerce and other applicable laws. Where a law prescribes a different retention period, that period takes precedence. The specific basis for the retention period (TTL) of each data type is available in the data-retention disclosure table the Company provides within the Service.
9. Security Measures
The Company implements the administrative, technical and physical safeguards required by applicable law to process personal information securely. (1) Administrative measures: minimizing the number of personnel handling personal information, managing and periodically reviewing access privileges, and establishing and implementing an internal management plan. (2) Technical measures: one-way hashing of authentication data such as passwords, encryption of data at rest and in transit, access control and retention of access logs, and operation of intrusion prevention and detection systems. (3) Data minimization and exposure control: for behavioral data such as session replay, by default all input fields and card-number, resident-registration-number, phone, and email patterns are automatically masked client-side, plain-text personal information on the screen is protected within the scope of the masking/blocking selectors the user designates, and data is minimized to what is necessary for the analytical purpose. The Company continuously reviews and improves these measures; however, due to the nature of transmission over the internet, absolute security cannot be guaranteed.
10. Your Rights and How to Exercise Them
- Right to access personal information (Art. 35)
- Right to correction and deletion of errors (Art. 36)
- Right to suspend processing (Art. 37)
- Right to withdraw consent for consent-based processing
- Right to object to and request an explanation of fully automated decisions (Art. 37-2)
- Right to seek remedy through the Personal Information Dispute Mediation Committee in case of rights infringement
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure ('right to be forgotten', Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21) and to withdraw consent (Art. 7)
- Right not to be subject to solely automated individual decisions, including profiling (Art. 22)
- Right to lodge a complaint with a supervisory authority
- Right to know and access personal information collected and used
- Right to request deletion of personal information
- Right to request correction of inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit the use and disclosure of sensitive personal information
- Right not to be discriminated against for exercising these rights
11. Automated Decision-Making and Profiling
The analytics and estimation features the Company provides within the Service produce aggregated statistics and predictive or estimated metrics to assist users' decision-making; the Company does not, on its own, make individual automated decisions that produce legal or similarly significant effects on data subjects. Segmentation and estimation based on visitor behavioral data are likewise statistical in nature and are not intended to effect automated dispositions regarding any specific individual. Data subjects may, to the extent recognized by applicable law, request an explanation of and object to automated decisions.
12. Children's Privacy
The Service is a B2B service intended for business and professional users; it is not directed to children under the age of 14 and does not collect the personal information of children under 14. If the Company becomes aware that the personal information of a child under 14 has been collected without the consent of a legal guardian, it will destroy that information without delay. Where a user operates a service directed to children on the user's own website, the responsibility for complying with laws on children's privacy and obtaining legal-guardian consent lies with that user as the data controller.
13. Data Protection Officer and Inquiries
The Company has designated a Data Protection Officer as follows to oversee personal-information processing and to handle inquiries and complaints from data subjects. Data Protection Officer: Chanwoo Jang; email: info@statlane.kr; phone: +82 10-2848-8955. Data subjects may direct all privacy-related inquiries, complaints, and requests for remedy arising from use of the Service to the Data Protection Officer, and the Company will respond and act without delay. Where a data subject requires consultation or dispute mediation regarding a privacy infringement, assistance may be sought from the following bodies: the Personal Information Dispute Mediation Committee (www.kopico.go.kr); the Privacy Infringement Report Center and Personal Information Protection Commission counseling (dial 118 without an area code, privacy.kr); and the cyber investigation units of the Supreme Prosecutors' Office and the National Police Agency.
14. Changes to This Policy
This Privacy Policy may be amended in response to changes in law, the Service, or Company policy. Where the Company amends this Policy, it will provide advance notice, specifying the changes and their effective date, through in-service notices and similar means. For amendments that materially affect data subjects' rights, the Company will give notice at least 30 days in advance as required by applicable law and, where necessary, obtain renewed consent. The amended Policy takes effect on the announced effective date.