WORKTIME SOFT · POLICY
Privacy Policy
Effective October 2, 2026. This policy applies to the games operated by WorktimeSoft in the Republic of Korea.
1. Scope and controller
This policy applies to the official website of WorktimeSoft (주식회사 워크타임소프트, the “Company”) and the web and mobile services, software, games and related customer support that refer to this policy. The Company processes personal data and protects users’ rights under the Personal Information Protection Act (PIPA) and other applicable law.
Controller: 주식회사 워크타임소프트 (WorktimeSoft) / Representative: 김란 / Address: 인천광역시 서해구 솔빛로 55, 521동 3층 3호(청라동, 청라반도유보라), Republic of Korea / Privacy officer: 김란, Representative / Contact: [email protected]
| Service | Processing covered |
|---|---|
| WorktimeSoft company website | Device and connection information needed to access the site, and enquiries received by email. Visiting the company introduction page alone does not collect game accounts, login tokens, match information or payment information. |
| Covenant Rise | Data relevant to the account, sign-in, gameplay, purchase and support functions you use. The account and gameplay processing in sections 3–6 and account cookies, retention and deletion in sections 10–13 describe this game’s operating rules. |
Personal data is processed to the extent needed for the Services and features you use. Service-specific categories and purposes are explained below.
2. Purposes and legal grounds
The Company processes personal data as needed to provide the Services. Information generated during registration and use, supplied by external sign-in providers or provided by you in enquiries or transactions is used for the common and service-specific purposes below. Each purpose uses the data collected by the relevant Service and the retention and deletion rules in sections 11–13.
| Category | Purpose | Ground |
|---|---|---|
| Account and gameplay | Registration, sign-in, account connection, and progress, match and reward management | PIPA Article 15(1)(1): separate consent to collection and use of personal data obtained before registration. |
| Payments and dispute records | Purchase verification, delivery, cancellation, refunds and statutory transaction records | Performance of a contract and legal obligations, including Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. |
| Security and misuse prevention | Detecting and preventing account theft, abnormal access, automated repeated requests, fraudulent transactions and benefit abuse; investigating terms or operating-policy breaches and restricting use; investigating security incidents, recovering from harm and handling appeals | Processing necessary for contract performance. Where a separate legitimate interest is relied on, only to the extent that PIPA Article 15(1)(6) is satisfied. |
| User verification, operational notices and support | Verifying users and account ownership, recovering access, handling enquiries, reports and disputes, notifying terms or policy changes and service operations, and providing security warnings and outcomes. Comparing email addresses provided during registration or enquiries with necessary account and transaction records, and sending verification and notices by email | Measures requested by the user and processing necessary for contract performance: PIPA Article 15(1)(4). Statutory notices rely on the relevant legal ground, such as Article 15(1)(2). |
| Service quality and stability | Analysing usage, connection frequency, errors and performance; checking data accuracy and consistency; resolving and recovering from outages; improving features and environments; developing features and technology related to existing Services | Processing necessary for contract performance or legitimate interests meeting PIPA Article 15(1)(6). Analysis or development requiring separate consent is performed with that consent. |
| Legal compliance and protection of rights | Retaining transaction and dispute records, responding to statutory requests, establishing facts and managing evidence to protect users’ and the Company’s rights and resolve disputes | Legal obligations, including PIPA Article 15(1)(2). Separate processing to protect rights is limited to cases satisfying Article 15(1)(6). |
| Processing requiring separate consent | Stated purposes, such as a new optional feature | Separate consent under the applicable ground, including PIPA Article 15(1)(1). |
If required information is not provided, the relevant account or function may be unavailable. Basic service access is not restricted merely because you refuse optional processing. Agreement to the terms or acknowledgement of this policy is not treated as consent to advertising messages.
Both guest and registered accounts separately agree to the Terms of Service and to collection and use of personal data before registration. Required collection and use information presented at registration is as follows.
| Category | Details |
|---|---|
| Purpose | Checking age eligibility and the need for guardian consent; registration, identification, sign-in, account connection, and progress, match and reward management. Where a family connection exists, a family manager authenticated through the linked email can see the connected game names and nicknames. Even after a player reaches adulthood, a manager using the existing email can continue to see this information until the linked email is changed or the family connection is ended. The family management screen does not show player IDs, ages, connection or battle records, currency balances or purchase history, and management authentication cannot be used to enter the game. Change the linked email through family account management on the website. Requests to change or end an individual member’s connection or withdraw consent are handled by customer support after identity and authority checks. |
| Data | Birth date used temporarily to determine age (the original is not stored in the account database); internal account identifier (UID); optionally connected sign-in provider and provider account identifier; game nickname; registration and activity times; guest credential hash; faction and country selection; currency, card, upgrade, rank, match and reward records; required consent version and time; age group; dates of transition at ages 14 and 16; guardian consent status. The player’s email and real name are not collected for the game account. Guardian email consent is explained separately. |
| Retention and use period | Until account closure or withdrawal of consent. Ordinary guests without an external sign-in connection expire 30 days after their last activity and are deleted during subsequent periodic cleanup. This 30-day expiry deletion does not apply to the game accounts and progress of children who joined a family account with guardian consent. Transaction and dispute records subject to separate statutory retention are stored separately for the periods stated in this policy. |
| Right to refuse and consequences | You may refuse consent. As this is the minimum information needed to provide an account and the game, refusal prevents guest or ordinary registration and gameplay. This does not include consent to advertising or marketing messages. |
Processing based on grounds other than consent, such as handling support requests, fulfilling purchases and retaining statutory records, is distinguished by purpose and legal ground. Registration consent does not include consent to advertising messages or personal-data processing for a separate purpose through business tools.
3. Accounts and authentication
| Category | Data | Purpose |
|---|---|---|
| Ordinary guest account | Account ID, creation, last-activity and expiry times, and credential hash | Guest identification, continued sign-in, expiry and deletion |
| Registered account | Account UID, chosen sign-in provider and its account identifier, creation and activity information | Authentication, account connection and service use |
| Registration confirmation | Versions of the agreed Terms of Service, collection and use notice and Privacy Policy; collection and use consent status; age group; age-14 and age-16 transition dates; guardian consent status, version and time; consent time | Checking and recording conditions of use |
| Account-closure request | Requesting account, request and processing status and times, and deletion-status receipt hash | Identity verification, deletion processing and status information |
| Child family account | Account ID, game nickname, family-registration status, guardian connection and consent records, creation, activity and authentication-expiry information, and credential hash | Child account identification, progress retention, guardian management and account recovery |
A birth date entered for age verification is used temporarily on the server to calculate the age group and transition dates at ages 14 and 16. Its original value is not stored in the account database. Transition dates and the UID are protected as information linked to a user. Real name, phone number, address and gender are not required registration fields.
Age-verification input is used only while processing the request; the original birth date is not logged. A temporary identifier, age group and transition dates for the pre-registration guardian process are handled as signed authentication information valid for 30 minutes. Account-stored age groups and transition dates are retained until account closure or consent withdrawal. Guest expiry and deletion follow the rules above.
Where a family connection exists, a family manager authenticated through the linked email can see the connected game names and nicknames. Even after a player reaches adulthood, a manager using the existing email can continue to see this information until the linked email is changed or the family connection is ended. The family management screen does not show player IDs, ages, connection or battle records, currency balances or purchase history, and management authentication cannot be used to enter the game. Change the linked email through family account management on the website. Requests to change or end an individual member’s connection or withdraw consent are handled by customer support after identity and authority checks.
4. Information received through external sign-in
| Provider | Information received and used | Storage and use |
|---|---|---|
| User identifier and authentication response | Only the account identifier is used for connection. Email and real name are not stored in the game account. | |
| Apple | User identifier and sign-in response, including authentication and refresh tokens | The account identifier is used. Email and real name are not stored in the game account. Tokens needed to revoke the Apple connection on account closure are stored encrypted. |
| User identifier and authentication response | Only the account identifier is used for connection. Email and real name are not stored in the game account. |
We do not access mailboxes or contact lists through external sign-in. Accounts are not automatically merged even if different providers use the same email address. Google and Facebook access tokens are used for sign-in processing and are not retained long-term in the account database.
We do not request email permission through external sign-in. Unnecessary email or name fields in a response are not saved as account information. Apple revocation tokens are deleted after use for account deletion.
Optional external account connection uses the sign-in provider and its account identifier; the player’s email and real name are neither requested nor stored as game-account data. Previously held contact information and support materials you send directly by email follow their respective retention and deletion rules. Game-account verification uses the UID and an authenticated session. Knowing a UID alone does not authorise an account change or refund.
5. Game profiles and usage records
The Company processes nicknames, selected factions and countries, currency, cards, upgrades, passes, missions, attendance, rewards, transactions, rankings, match records, battle and story results, and related times. A country displayed in a game is not used as proof of payment country or actual residence.
Opponents and ranking screens may show information needed for gameplay, such as nickname, selected country and faction, deck and match records. Emails, external sign-in identifiers and purchase evidence are not displayed in public profiles. Do not include another person’s personal data or sensitive information in a nickname.
6. Access security and misuse prevention
Access processing involves IP addresses, connection times, request paths, authentication cookies and technical errors. Repeated-request controls temporarily use transformed identifiers derived from original IP addresses and authentication information, together with request counts, in memory. Original IP addresses are not stored long-term in game profiles.
Abnormal access may trigger additional authentication or verification using Cloudflare Turnstile. Security and incident logs are managed to avoid recording unnecessary personal data, such as authentication tokens or enquiry content.
To prevent simultaneous use of the same account, the Company manages the current login-session identifier and issue time. A new login ends game access through the previous session. Session information is used for account protection and deleted with the account.
Where abnormal sign-in or access, account theft, fraudulent transactions or breaches of terms or operating policies are suspected, the Company may compare and analyse the necessary account identifiers, email addresses and verification status, access, usage and transaction records, and reports collected by that Service. Findings are used for further verification, account protection, misuse prevention, assessment of restrictions, recovery from harm and appeals.
Where necessary, the Company may use registered contact details or an email supplied in an enquiry to verify account ownership, notify abnormal activity, request further verification or communicate outcomes. Security and operational notices are handled separately from advertising-message consent.
7. Customer support and rights requests
When an enquiry, report or appeal about the Company or a Service is received, the Company processes the reply email, content, attachments and necessary account ID, nickname, incident time and order number. If ownership of an account or transaction, or legal guardian status, needs to be checked, the required information and reasons are explained and only the minimum necessary material is requested.
Do not send passwords, sign-in verification codes, full payment-card numbers or resident registration numbers. Unnecessary information in submitted materials is deleted or masked.
8. Purchase and refund information
When you purchase paid content or request a refund, the Company processes app-store transaction identifiers, products, purchase and verification times, status, amount and currency, delivery, cancellation and refund records, and necessary purchase evidence. Evidence required to retry purchase processing is stored encrypted.
The app store you choose handles payment methods and charging. The Company checks the purchase-account connection, receipt authenticity and cancellation or refund status; it does not directly collect full card numbers or payment passwords. A Google Play pre-purchase country check is used only to determine purchase availability, not stored in the game database or profile or reused for marketing.
9. Device and website information
Browser and device type, operating system, IP address, request path and technical errors may be processed for service provision and security when accessing a website, app or other Service.
The Company does not operate advertising-ID-based personalised advertising or external behavioural-analytics trackers. Information independently collected by external sign-in and app-store services is subject to their providers’ privacy policies.
10. Cookies and device storage
Covenant Rise uses cookies for continued sign-in and security. Login sessions last up to seven days, guest authentication is based on 30 days of activity, and temporary registration-consent cookies last 30 minutes. Temporary cookies are also used during sign-in and reauthentication for account deletion.
Browser storage may contain account selection, display and sound settings, device-only practice progress and request information needed for communication recovery.
You can block cookies or delete stored data through browser privacy or site-data settings. Mobile devices also provide app-data and site-storage controls. Blocking or deleting them may restrict continued sign-in, guest access or storage functions. Deleting device data alone does not close the server account.
11. Retention of account and game information
This section describes retention for Services provided in the Republic of Korea. If the Company provides Services in another region, it separately explains the processing rules applicable there.
| Information | Period | Handling |
|---|---|---|
| Registered account, game records and contact details | Until account closure or withdrawal of collection and use consent; deletion processing begins on request | Prompt deletion except for records subject to statutory retention |
| Ordinary guest account and game records without external sign-in | Expires 30 days after last activity | Deleted during periodic cleanup after expiry |
| Encrypted Apple revocation token | Account lifetime and the period needed to complete disconnection | Deleted after revoking the Apple connection on account closure |
| Deletion-status receipt | Available for up to 30 days from the request | Completed cases are deleted during periodic cleanup after expiry. Pending cases remain only as long as needed to complete deletion. |
| Child family account and game records | Until the relevant game account is closed or collection and use consent is withdrawn | Excluded from ordinary guest 30-day expiry deletion. On a deletion request, information not subject to statutory retention is promptly deleted. |
If an external-service or server failure occurs during deletion, account use is blocked first and processing is retried. Pending data is not reused for gameplay or marketing.
A family email connection is not removed merely because age changes. Expiry of authentication or ending a connection through management-account closure or similar circumstances does not itself delete the game account and progress. Family management information and members’ game-account information each follow their own retention periods.
12. Support and statutory transaction records
| Category and data | Period | Ground or purpose |
|---|---|---|
| Reply email, enquiry and resolution of an ordinary support request | Up to one year after resolution | Continuity of handling and follow-up on the same matter |
| Contract and withdrawal records: order number, product, contract and withdrawal details and times | Five years | Article 6 of the Act on the Consumer Protection in Electronic Commerce, etc. and Article 6 of its Enforcement Decree |
| Payment and delivery records: transaction identifier, amount and currency, payment, grant and refund records | Five years | Article 6 of the same Act and Article 6 of its Enforcement Decree |
| Consumer complaints and disputes: requester contact details, dispute details, verification materials and outcome | Three years | Article 6 of the same Act and Article 6 of its Enforcement Decree |
| Product-description and advertising records: published product information and advertisements | Six months | Article 6 of the same Act and Article 6 of its Enforcement Decree |
Statutory transaction records remain separate from game-use information after account closure and are accessible only to staff who need them for the relevant purpose. Where a separate legal ground, such as a court order, requires longer retention, only the relevant materials are retained for the necessary period. They are promptly destroyed when retention ends.
13. Deletion of personal data
The Company promptly destroys personal data when its retention period ends or its purpose has been achieved and it is no longer needed. Electronic files are deleted using methods that make recovery difficult; paper materials are shredded or incinerated. Records retained under law are managed separately.
Request account closure and full deletion using the account-deletion function on the relevant game’s website or app. For Covenant Rise, use game settings or https://covenantrise.com/account/delete/. After identity verification, sign-in connections, contacts, profile and game records are processed for deletion. The receipt lets you check processing status.
Cloudflare D1 recovery backups may retain pre-deletion data for up to 30 days. Backup access is limited to recovery needs. Following restoration, deletion requests are reconciled so that deleted information is not reused in the Service. Device-only information can be removed through browser-storage or app-data controls.
14. Processing providers and business tools
| Provider or service | Work | Information processed |
|---|---|---|
| Cloudflare, Inc. | Web hosting, game servers and databases, match processing, access protection and company-domain email forwarding. Sending guardian verification emails when family accounts are provided. | Account and game records, authentication and transaction information, access requests and other material needed for that work. Sender and recipient addresses, message content and attachments of enquiries sent to the company domain are processed for forwarding. Verification delivery processes recipient email addresses, a fixed notice containing a one-time code, and sending and delivery information. |
| Google LLC · Gmail | Sending and receiving customer-support emails and managing support records | Requester reply email, enquiry content, attachments and processing records |
Providers’ subprocessors and privacy information
- Cloudflare subprocessors and functions
- Google Privacy Policy and external processing
- OpenAI subprocessors and the listed product scope
- Anthropic subprocessors · Trust Center
- ChatGPT consumer services · Korea privacy and processor information
- Anthropic consumer services · external providers and privacy
- Claude consumer-service retention and deletion
- Microsoft Privacy Statement
- Microsoft Products and Services Data Protection Addendum
The Company’s processing agreements address prohibitions on use outside the stated purpose, safeguards, subprocessors, management, supervision and responsibility. The Company checks providers’ handling of the entrusted work.
AI and business-material management services
| Provider or service | Work | Data | Method |
|---|---|---|---|
| OpenAI · API (including Codex with an API key) | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Necessary materials from code, files, logs and tool results are transmitted over a network when making business-related API requests or running development and connected tools such as Codex. |
| OpenAI · ChatGPT Pro (including Codex with a ChatGPT account) | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Necessary materials from code, files, logs and tool results are transmitted and stored over a network when staff enter conversations, attach files or use development and connected tools such as Codex. |
| Anthropic · Claude API | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Transmission of the materials needed for API requests |
| Anthropic · Claude Pro | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Staff conversation input, file attachments and review of responses |
| Microsoft · Microsoft 365 (Office 365) / Excel / OneDrive | Preparing, classifying, reconciling, storing, synchronising and sharing materials among authorised staff for user and account management, support, complaints and disputes, payment, settlement and refund reconciliation, misuse and security investigations, service operation and maintenance, and statutory recordkeeping. | Account ID, nickname and reply email, enquiries, reports, appeals and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of collected connection times, IP addresses, request paths, gameplay and transaction-processing records, and identifiers in error logs. | Creating business documents and spreadsheets in Microsoft 365 (Office 365) and Excel, and storing, synchronising and sharing them in OneDrive |
The Company uses these services for support, user management, account protection, security investigations, transactions, refunds, and service development and maintenance. It enters, attaches or connects only material needed for each request and removes or masks unnecessary identifiers and attachment content. Login passwords, verification codes, secret keys and full payment-card numbers are not included in the data processed for this work.
Originals, business files, conversations and attachments managed by the Company follow the relevant retention periods in sections 11 and 12. Temporary working copies are deleted once the task’s purpose is achieved.
AI providers may retain security records and residual data after deletion under the relevant service contract and privacy terms. Processing materials for Company work is not intended to supply data for the provider’s general model improvement.
Personal-data processing through business tools follows this policy’s purposes, categories, retention, processing-provider and overseas-transfer rules. Processing requiring separate consent takes place within the scope of that consent.
Where needed to investigate service errors or migrate or recover data, the account, gameplay, transaction and error information in the table may be processed through AI services. Only information needed for the task is used; unnecessary identifiers are removed or masked.
External providers may use affiliates or other processors to operate their services. Their functions and applicable services are described in the official information below; scope differs between consumer and organisational products.
Processing and protection conditions for Microsoft services follow the official policies and contracts applicable to the relevant service.
Processing conditions and the storage, retention and deletion of materials are managed separately for API services and consumer Pro services under each service’s contract and the relevant rules in this policy.
AI-assisted development, maintenance and error investigation include processing code, files, logs and connected-tool results through development tools such as Codex. If those materials contain personal data supplied to AI, that data may also be processed by the relevant AI service. The Company limits materials to what the business purpose requires and removes personal data or substitutes test data where possible. AI processing of business materials is distinguished from a provider’s model-training or improvement use and is managed under each service’s contract, policy and applicable data settings.
The Company uses Microsoft 365 (Office 365), Excel and OneDrive to create, store, synchronise and share materials needed for user and account management, support, transactions and refunds, security investigations and service operation. Data categories and retention follow the rules for the relevant activity in this policy.
15. Overseas transfers
The Company’s AI work for support, user management, account protection, abnormal-activity and security investigations, payments, refunds, service development, maintenance and error investigation includes OpenAI API, ChatGPT Pro, Anthropic Claude API and Claude Pro. Microsoft 365 (Office 365), Excel and OneDrive are used to manage business materials. Use of these services may transmit or store the personal data below on overseas servers or allow access or processing from abroad. Excel files fall within the relevant service’s transfer scope when uploaded or synchronised to OneDrive or attached to an AI service.
| Receiving service | Data | Purpose | Timing and method |
|---|---|---|---|
| OpenAI · API (including Codex with an API key) | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Necessary materials from code, files, logs and tool results are transmitted over a network when making business-related API requests or running development and connected tools such as Codex. |
| OpenAI · ChatGPT Pro (including Codex with a ChatGPT account) | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Necessary materials from code, files, logs and tool results are transmitted and stored over a network when staff enter conversations, attach files or use development and connected tools such as Codex. |
| Anthropic · Claude API | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Network transmission when making API requests or running connected tools needed for business processing or technical investigations |
| Anthropic · Claude Pro | Account ID and nickname, reply email, enquiry content and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of email-verification status collected by the relevant Service, connection times, IP addresses, request paths, usage, gameplay and transaction-processing records, reports, appeals and identifiers in error logs. | Classifying and summarising enquiries and drafting responses; verifying and protecting users and accounts; assisting investigations of abnormal behaviour, misuse and security incidents; reviewing reports and appeals and drafting operational and security notices; reconciling purchase, payment and refund information and documenting outcomes; developing, maintaining and improving service quality, investigating errors, and verifying data migration and recovery. | Network transmission and storage when business materials are entered in conversations, attached as files or supplied through connected tools |
| Microsoft · Microsoft 365 (Office 365) / Excel / OneDrive | Account ID, nickname and reply email, enquiries, reports, appeals and attachments, order number, product, purchase date, amount, transaction status, refund request and outcome as needed for the task; where needed for security or technical investigations, the necessary portions of collected connection times, IP addresses, request paths, gameplay and transaction-processing records, and identifiers in error logs. | Preparing, classifying, reconciling, storing, synchronising and sharing materials among authorised staff for user and account management, support, complaints and disputes, payment, settlement and refund reconciliation, misuse and security investigations, service operation and maintenance, and statutory recordkeeping. | Network transmission and storage when business files are uploaded, synchronised or shared |
The Company uses Cloudflare infrastructure, Gmail, external sign-in providers and app stores, and the AI and cloud business services in section 14. Storage on their overseas servers or access by overseas providers may constitute an overseas transfer under PIPA. Overseas-transfer rules apply even when Services are offered only to users in Korea.
| Category | Transfer and processing details |
|---|---|
| Cloudflare recipient and contact | Cloudflare, Inc. / Privacy enquiries: [email protected] / Contract enquiries: [email protected] |
| Cloudflare data and purposes | Necessary account identifiers, authentication and contact information, gameplay, match and transaction records, IP addresses and access requests. Website and game provision, storage, authentication, security and incident response. Sender and recipient addresses, content and attachments of enquiries received at the company domain are processed for forwarding to staff inboxes. On a family verification request, the guardian’s recipient email and notice containing a one-time code are sent through Cloudflare email delivery services, which process sending and delivery information. |
| Cloudflare timing and method | Network transmission and storage when handling access, sign-in, gameplay and related requests; access by authorised staff where technical support is needed |
| Cloudflare processing regions | Processing may occur in multiple countries and regions where Cloudflare provides services. See the Cloudflare network locations for countries and cities. Regions may differ for request processing, storage and technical support. |
| Cloudflare retention | Company-stored account, game and transaction data follow sections 11–13. Provider security and operational records are processed for periods necessary for service provision and security or retention required by law. |
| Gmail recipient and contact | Google LLC / Google privacy contact information: policies.google.com/privacy?hl=ko |
| Gmail data, purposes and timing | Reply or registration email, enquiries, reports and attachments, minimum materials needed for account verification and security investigations, and processing records. Network transmission and storage when receiving and replying to enquiries, verifying accounts, sending operational or security notices and managing support records. |
| Gmail processing regions and retention | Processing may occur on Google servers in multiple countries. See Google data centre locations. Enquiry and transaction materials retained by the Company follow section 12 and are deleted when their period ends. Provider deletion and backup procedures and statutory retention apply separately. |
| OneDrive recipient and contact | Microsoft / See the official Microsoft privacy and data-protection information in section 14 for privacy enquiries and product-specific conditions. |
| OneDrive processing regions and retention | Microsoft states that information may be stored and processed in Korea, the United States and countries where Microsoft or its providers operate facilities. See the official Microsoft information below for details. Company business materials follow the retention and deletion rules in sections 11–13. |
| AI processing regions and storage | Input materials may be processed and stored on overseas servers of the service used. The official links below provide OpenAI and Anthropic contacts, processing regions, and storage and deletion information. |
Provider-published infrastructure locations and privacy information
- Cloudflare network countries and cities
- Cloudflare South Korea PIPA information
- Google data centre locations
- OpenAI Privacy Policy and international transfers
- OpenAI API retention and processing locations
- Anthropic Privacy Policy and overseas processing
- OpenAI ChatGPT Korea privacy addendum and overseas transfers
- Claude consumer-service retention and deletion
- Microsoft Privacy Statement, retention and deletion
- Microsoft Korea privacy supplement and overseas transfers
These links describe providers’ overall infrastructure and processing practices. They do not mean that every user’s data is stored in every listed country. Processing regions may vary with request handling, storage and support activities.
The Company gives notice of transferred data, countries, timing and methods, recipients and contacts, purposes and retention periods, and how to refuse, and transfers data on an applicable legal basis. Processing and storage necessary for contract performance rely on PIPA Article 28-8(1)(3) only when its requirements are met. Separate consent is obtained for transfers that require it.
External sign-in services and app stores process information described in sections 4, 8 and 16 during authentication and purchases you choose. Processing through OpenAI API, ChatGPT Pro, Claude API, Claude Pro, Excel and OneDrive follows the work and data scope in section 14 and the applicable processing-provider and overseas-transfer basis. Acknowledging this policy is not blanket consent to that processing.
You may send overseas-transfer enquiries or requests to stop transfers to [email protected]. The Company checks the request scope and statutory retention obligations. If stopping processing essential to account provision restricts functions, it explains those restrictions and how to close the account.
To handle verification-email bounces and prevent unwanted repeated sending, Cloudflare may process recipient emails and blocking reasons and status in a suppression list. Blocks following temporary delivery failures normally last 24 hours; some permanent bounces result in seven-day blocks. Blocks for nonexistent addresses, repeated recipient errors or spam complaints may have no automatic expiry. Expiry of a block does not mean deletion of all related records. Requests for access, deletion and other rights concerning this information may be made through the contact in section 19. After identity verification, the Company takes necessary measures within the provider’s processing scope and applicable law.
Verification-email processing information
16. Third-party disclosures and external providers
The Company processes personal data for the purposes described in this policy and discloses it to third parties only with user consent or a legal basis. Providers’ independent processing for sign-in and app-store services is distinguished from processing entrusted by the Company.
The Company exchanges information necessary for authentication and disconnection with the Google, Apple or Facebook provider you choose, and transaction information necessary for purchase verification, cancellation and refunds with the app store used for payment. Game currency and match records are not supplied to external sign-in providers.
Sections 14 and 15 describe data and overseas processing for storing customer-response materials in Microsoft OneDrive and using OpenAI ChatGPT and Anthropic Claude for programming, changes, error analysis and technical support.
For a lawful production request from a court, investigative authority or similar body, the Company checks the legal basis and scope and supplies only necessary information. If personal data is transferred through a business transfer, merger or similar event, it gives notice of the transfer, recipient and contact details and options for users who do not want the transfer, as required by PIPA.
17. Security safeguards
The Company limits staff access and permissions to what is necessary and applies safeguards such as hashing or encrypting authentication and contact information, encrypted communications, access controls and separate secret-key management. Personal data is managed to avoid unnecessary disclosure in logs or public screens.
If a personal-data breach or similar incident is confirmed, the Company takes necessary response measures and notifies authorities and users where statutory requirements apply.
18. Automated processing and review
Matchmaking, reward verification, request-rate limits and abnormal-transaction checks use automated processing based on server rules. You may request an explanation and review of restrictions or transaction errors at [email protected].
Where processing meets the conditions for an automated decision under PIPA Article 37-2, you may exercise rights such as refusal and requesting an explanation within the scope of the law. The Company checks the applicable conditions and exceptions and provides the necessary explanation or reprocessing with human involvement.
For statutory requests to refuse, explain or review automated decisions, the Company provides the outcome within 30 days of receipt. If a justified reason requires an extension, it explains the reason and schedule and extends only within the legally permitted scope. Reasons for refusing a request are provided without delay.
When AI is used to review business materials, staff verify the facts and evidence. Sanctions, refunds and account deletion are not decided solely on AI output.
19. Rights of users and legal guardians
You may request access to, correction or deletion of your personal data, suspension of processing and withdrawal of consent. You may also act through a legal guardian or authorised representative. The Company may request the minimum information needed to verify identity or representative authority.
Send statutory rights requests, including access, correction, deletion and suspension, to [email protected]. Provide the request details and minimum information needed to verify identity; the Company replies with the outcome. For account closure and full account deletion, use the website or app deletion function in section 13. Passwords and sign-in verification codes are not required.
The Company enables access within 10 days of receiving an access request. If access is restricted, delayed or refused on statutory grounds, it explains the reason and how to object within that period. For suspension requests, it provides the outcome or refusal reason and objection method within 10 days of receipt. Correction, deletion and consent-withdrawal requests are also handled without delay, with any statutory exceptions explained.
Deletion or suspension may be restricted to the extent prescribed by law, including for information another law requires to be collected or retained. Withdrawal does not affect lawful processing before withdrawal. If stopping processing necessary for a Service prevents use of a feature, the Company explains the impact.
20. Children and young players
The ages 12, 14 and 16 in this section concern Covenant Rise registration and guardian procedures in the Republic of Korea. Other Services’ age and personal-data rules are described in their service information.
Covenant Rise in Korea does not permit new registration or guest access for children under 12. Ages 12–15 require a legal guardian’s consent and verification for registration and gameplay before account creation and play. For ages 12–13, the purposes, data categories, retention, right to refuse and consequences of child-data collection and use are separately explained and the legal guardian’s consent is confirmed. For ages 14–15, the player’s own collection and use consent is distinguished from the guardian’s registration and gameplay consent. Ages 16 or older follow the ordinary registration process.
Higher binding age restrictions under local law or a distribution platform apply where relevant. Advisory ratings are distinguished from legal prohibitions. A content rating alone does not determine capacity to consent to data processing or enter a contract. Guardian requests such as cancelling a minor’s purchase are handled after necessary relationship checks.
Registration and gameplay for ages 12–15 are restricted while guardian consent and verification services are unavailable. When guardian consent is requested through family accounts, a guardian-managed email is collected to send verification instructions and a one-time code. Registration and data consent are not blanket consent to all paid-content purchases. Requests for consent withdrawal, account deletion or assistance may be made through the game account menu or [email protected].
Family accounts process the guardian’s management email separately from the child’s game profile. The child’s own email and real name are not required for family linking. Even when a guardian’s email is used, the child’s account ID, nickname, age group, progress and family connection information remain protected under this policy.
| Category and data | Purpose | Retention |
|---|---|---|
| Guardian management email, guardian account identifier, email-verification status and time | Authenticating and recovering guardian management accounts, preventing duplicates, connecting children and sending necessary security and service notices | Until guardian account closure. Deleted after explaining procedures needed for linked child accounts; statutory records remain separate under section 12. |
| Guardian-child connection identifiers, legal-guardian confirmation responses, agreed document and notice versions, consent and withdrawal times and status | Child linking, consent verification and management, rights requests and disputes | Management connection records remain until the connection ends; evidence of a child game account’s registration and use consent remains until that game account closes. Only records qualifying for statutory contract or consumer-dispute retention are stored separately for the purposes and periods in section 12. |
| Unused child-approval identifier, guardian identifier, age group and transition dates, consent responses, document versions and time | Confirming guardian approval and the relevant child’s registration or connection request | Approval is valid for up to 10 minutes; unused records are promptly deleted after expiry. Records used for registration or linking follow the child connection and consent retention rules above. |
| Email-verification request identifier, encrypted recipient email, code verification value, request, expiry and verification times, and attempt count | Sending and verifying authentication emails; preventing code reuse and brute-force attempts | Promptly deleted after the request’s 10-minute validity ends. The code verification value is discarded after successful verification or the attempt limit is reached. |
| Irreversible keyed verification value of the email, rate-limit time window and request count | Preventing verification-email abuse | Promptly deleted one hour after the rate-limit record is created. |
| Guardian management session hash, guardian account identifier, creation and expiry times | Maintaining management sign-in and verifying access authority | Valid for up to 30 minutes after creation and promptly deleted after expiry. Signing out or signing in again invalidates the previous session. |
Guardians may refuse collection and use consent needed for family verification and linking. Refusal restricts those functions and registration or use by children who require guardian consent. The Company separately explains and confirms consent to processing the guardian’s own information, consent to the child’s registration and use, and consent to collection and use of personal data for a child under 14. Emails for authentication, security and consent verification serve those purposes and are not treated as consent to advertising messages.
Legal guardians may request access, correction, deletion, suspension and withdrawal of consent for a child’s personal data through section 19. To protect other family members’ information, the Company may request the minimum material needed to verify account and representative authority. Do not send sign-in codes or passwords to customer support.
On guardian management account closure, the management email and sign-in information are deleted. If a child still requires guardian management or is undergoing deletion, the necessary account-handling or support steps are explained first. A child’s game account and progress that have moved to ordinary-user status in the Korean Service are not deleted merely because the guardian management account closes. Evidence of that game account’s registration and use consent follows the retention rules above.
The 10-minute request validity and deletion rules above apply to temporary requests in the Company’s authentication database. They do not mean remotely deleting an email already delivered to the recipient’s inbox. Provider delivery and security records are handled separately under the processing-provider and overseas-transfer information in sections 14 and 15. Email retained by a recipient follows that email service’s retention and deletion settings.
21. Privacy contact and remedies
Privacy officer: 김란, Representative / Requests and replies: [email protected]. This contact handles rights requests, including access, and privacy enquiries and complaints. Do not send passwords or sign-in verification codes.
In addition to contacting the Company, you may seek advice or dispute mediation from the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 without an area code in Korea) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).
22. Changes and effective date
If this policy changes, the Company announces the changes and effective date on the website or in the game. Matters requiring separate notice or consent, such as new processing purposes, third-party disclosures or overseas transfers, are applied after the procedures required by law.
Previous policies are available in the legal-document history. Providing an English policy does not itself expand service territories, features or the scope of personal-data processing.
See the legal document board for document history. Family-account provisions apply when the relevant feature is provided. Required separate notice and consent procedures are completed before new processing begins.