Skip to content
MangoBoost

Privacy Policy

Latest Updated: August 07, 2026

All personal information handled by MangoBoost Inc. (hereinafter the "Company") is collected, held, and processed based on relevant laws or with the consent of the data subject.

The Company, in compliance with the Personal Information Protection Act of the Republic of Korea and other relevant laws to protect the freedom and rights of data subjects, lawfully processes and safely manages personal information. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company hereby establishes and discloses this Privacy Policy in order to inform data subjects of the procedures and standards for the processing and protection of personal information, and to enable related concerns and complaints to be handled promptly and smoothly.

[ Summary of Key Personal Information Processing ]

General Personal Information CollectedMeasures to Ensure the Security of Personal InformationRecruitment Applicant Information Collected
Name, email, company name, phone number, etc.Details available under "Measures to Ensure the Security of Personal Information"Name, contact information, education, career, etc. (collected through recruitment platform)
Purpose of Processing Personal InformationProvision of Personal Information to Third PartiesEntrustment of Personal Information Processing
Responding to website inquiries, sending newsletters, conducting the recruitment process, etc.In principle, the Company does not provide personal information to third partiesDetails available under "Status of Outsourced Personal Information Processing"
Retention Period of Personal InformationFixed-Type Video Information Processing Devices (CCTV)Department for Concerns or Complaints
Until the purpose of processing is achieved (provided that, where applicable law requires, information is retained until the relevant statutory retention period)Details available under the "Fixed-Type Video Information Processing Device Operation and Management Policy"Department in charge of personal information protection (Infra Engineering Team)

The Company's Privacy Policy consists of the following contents.

  • Article 1. Purpose of Processing Personal Information
  • Article 2. Items of Personal Information Processed
  • Article 3. Period of Processing and Retention of Personal Information
  • Article 4. Procedures and Methods for the Destruction of Personal Information
  • Article 5. Provision of Personal Information to Third Parties
  • Article 6. Entrustment of Personal Information Processing and Article 6-2. Overseas Collection and Transfer of Personal Information
  • Article 7. Measures to Ensure the Security of Personal Information
  • Article 8. Installation and Operation of, and the Right to Refuse, Automatic Personal Information Collection Devices
  • Article 9. Rights and Obligations of Data Subjects and Legal Representatives, and the Methods of Exercising Them
  • Article 10. Name of the Personal Information Protection Officer, the Department in Charge of Personal Information Affairs, and the Department for Concerns or Complaints
  • Article 11. Remedies for Infringement of the Rights and Interests of Data Subjects
  • Article 12. Operation and Management of Fixed-Type Video Information Processing Devices
  • Article 13. Changes to This Privacy Polic

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed is not used for any purpose other than those listed below, and if the purpose of use changes, the Company will implement necessary measures, including obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.

Responding to Website Inquiries

The Company processes personal information for the purpose of receiving and responding to inquiries regarding products and services (“Contact Us”), and managing consultation history.

Providing Newsletters and Marketing Information

The Company processes personal information for the purpose of sending newsletters covering product updates, benchmark results, industry insights, and other contents, and for providing notices of events and functions.

Conducting the Recruitment Process

The Company processes personal information for the purpose of receiving application documents from job applicants, conducting the selection process, and notifying applicants of the results. (Recruitment is conducted through a recruitment platform entrusted by the Company; see Article 6 for detailed processing policies.)

Article 2 (Items of Personal Information Processed)

The Company collects and processes the personal information items set out below. However, the Company, in principle, does not collect sensitive information that could infringe on the privacy of data subjects, and where such collection is necessary, the Company obtains separate consent and uses the information only within the scope of the purpose for which consent was given.

① Items of Personal Information

CategoryItems of Personal Information ProcessedRetention Period
Website Inquiries (Contact Us)Name, email (business), company name, country, phone number, inquiry type, inquiry content3 years after processing the customer's inquiry
Newsletter SubscriptionName, email (business), company name, phone number, country/region, language, industry of interest, expected timing of replacement (purchase)Until withdrawal of subscription (opt-out)
Recruitment ApplicationsName, contact information, email, education, career history, cover letter, portfolio, and other application form detailsRetained for 3 years from the date of application (for applicants who do not consent to such retention, destroyed without delay upon completion of recruitment process)
Automatically Collected InformationCookies, access IP, date/time of visit, service usage recordsDestroyed 1 year after collection

② Status of Cookie (Automatic Collection Device) Use

The Company uses cookies for website usage statistics analysis, visitor convenience, and provision of customized content, and uses them as follows.

  • Website visit statistics and traffic analysis (e.g., Google Analytics, Google Search Console, Google Tag Manager (GTM), Microsoft Clarity web analytics tools)
  • Advertising scripts/pixels used to measure marketing campaign performance (e.g., LinkedIn Insight Tag)

Please refer to Article 8 for detailed methods of allowing or blocking cookies.

Processing of personal information of children under the age of 14: In principle, the Company does not provide services targeted at children under the age of 14 and does not directly collect the personal information of children under the age of 14. Where it is necessary to collect the personal information of a child under the age of 14, the Company follows the relevant procedures, including obtaining the consent of the legal representative, pursuant to Article 22-2 of the Personal Information Protection Act.

Article 3 (Period of Processing and Retention of Personal Information)

In principle, the Company retains personal information until the purpose of processing has been achieved and then destroys it without delay; provided, however, that where retention is required under relevant laws, the Company retains the information for the relevant period before destroying it.

① Retention Period by Purpose of Retention

Purpose of RetentionItems RetainedRetention PeriodBasis
Responding to website inquiriesInquirer information and inquiry content3 years after processing the customer's inquiryInternal policy (in preparation for disputes; with reference to the 3-year period under Article 6(1)(iv) of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, etc.)
Sending newslettersSubscriber informationUntil withdrawal of subscription (opt-out)Article 21 of the Personal Information Protection Act
Recruitment applicant informationApplication forms and all attached documentsRetained for 3 years from the date of application; for applicants who do not consent to such retention, deleted without delay upon completion of recruitment process. Information of successful candidates employed by the Company is retained separately for HR management purposes during the employment period pursuant to Article 42 of the Labor Standards Act.Personal information Protection Act Article 15(1)(i); Labor Standards Act Article 42
Retention of access records to the personal information processing systemAccess recordsAt least 1 year (at least 2 years for systems processing information of 50,000 or more data subjects, or unique identification information/sensitive information)Personal Information Protection Act Article 29; Enforcement Decree Article 30(1)(v); Article 8 of the Standards for Measures to Ensure the Security of Personal Information

Article 4 (Procedures and Methods for the Destruction of Personal Information)

The Company destroys personal information without delay once it becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing. However, where personal information for which the retention period consented to by the data subject has expired, or for which the purpose of processing has been achieved, must nevertheless continue to be retained pursuant to other laws, the Company transfers such personal information to a separate database (DB) or stores it in a different location.

※ The items of personal information retained pursuant to other laws, the basis for retention, and the retention period can be found under "Article 3 (Period of Processing and Retention of Personal Information)."

1. Destruction Procedure

  • The Company selects personal information requiring destruction and destroys it upon approval from the Company's Personal Information Protection Officer.

2. Destruction Method

  • Personal information recorded and stored in electronic file form is destroyed using technical methods that render the records unrecoverable, and personal information recorded and stored on paper documents is destroyed by shredding or incineration.

Article 5 (Provision of Personal Information to Third Parties)

The Company processes the personal information of data subjects only within the scope of the purposes specified in Article 1, and does not provide personal information to third parties except for cases falling under Articles 17 and 18 of the Personal Information Protection Act, including where the data subject has given separate consent or where specifically provided for by law.

Article 6-1 (Entrustment of Personal Information Processing)

For the smooth handling of personal information affairs, the Company entrusts the processing of certain personal information to external specialized institutions as follows.

In addition, when entering into an entrustment agreement, the Company specifies in the contract, pursuant to Article 26 of the Personal Information Protection Act, matters concerning the prohibition on processing personal information for purposes other than the entrusted task, technical and managerial protective measures, restrictions on re-entrustment, supervision and management of the trustee, and liability for damages, and supervises whether the trustee processes personal information in a safe manner. Any change in the content of the entrusted task or the trustee will be disclosed by the Company without delay through this Privacy Policy.

TrusteeEntrusted TaskRetention Period
Doodlin Inc. (service: Greeting)Receipt of recruitment applications, management of the hiring process, storage of application documents3 years from the date of application (for applicants who do not consent to such retention, destroyed without delay upon completion of recruitment process)
Flex Co., Ltd.HR management of employees (leave, attendance, and other internal HR administration)Duration of employment and per relevant laws

Article 6-2 (Overseas Collection and Transfer of Personal Information)

① The Company uses cookies and other automatic collection devices for website usage statistics analysis, online marketing, and similar purposes, and in this process personal information may be transferred overseas as described below. The specific recipient, country of transfer, and retention/use period are specified after confirming the status of the web log/advertising analytics tools currently in use (e.g., Google Analytics, Google Search Console, Google Tag Manager (GTM), Microsoft Clarity, LinkedIn Insight Tag) and cloud infrastructure in use.

1. Legal basis for overseas transfer

Article 28-8(1)(i) of the Personal Information Protection Act (consent of the data subject) or Article 28-8(1)(iii) of the same Act (overseas entrustment/storage of personal information necessary for the execution and performance of a contract, where matters concerning the transfer have been disclosed in the privacy policy)

2. Items of personal information transferred

automatically collected information such as cookies, access IP, and website visit/usage records

3. Country to which personal information is transferred, and the name of the recipient (or the company name and contact information for entities)

Service Name (Tool)RecipientRecipient CountryTiming & Method of TransferPurpose of Use by RecipientRetention & Use Period
Google AnalyticsGoogle LLCUSA, etc. (location of Google's data centers)Automatically transmitted via network (HTTPS) when visiting the website / using the serviceWebsite traffic analysis, user behavior analysis and tag management, search exposure optimizationDestroyed after the set retention period (e.g., 14 months)
Google Search ConsoleGoogle LLCUSA, etc. (location of Google's data centers)Automatically transmitted via network (HTTPS) when visiting the website / using the serviceAnalysis of search exposure status and search engine optimization (SEO)Destroyed after the set retention period (e.g., 16 months)
Google Tag ManagerGoogle LLCUSA, etc. (location of Google's data centers)Automatically transmitted via network (HTTPS) when visiting the website / loading tags (scripts)Inserting and managing various website scripts and tracking codes (tags), collecting and analyzing visitor records and behavioral dataRetained until tag settings are changed or deleted
Microsoft ClarityMicrosoft CorporationUSAAutomatically transmitted via network (HTTPS) when visiting the website / using the serviceAnalysis of user behavior (heatmaps, session recordings, etc.) and UX improvementDestroyed after up to 1 year from collection date (per Microsoft policy)
LinkedIn Insight TagLinkedIn CorporationUSAAutomatically transmitted via network (HTTPS) when visiting the websiteAd performance measurement, visitor statistics analysis, and targeted advertising/retargetingDirectly identifying information destroyed within 7 days; pseudonymized data retained for 180 days before destruction

4. Purpose of use and retention/use period of the personal information by the recipient

Automatically collected information directly collected and stored by the Company is destroyed one year after collection, and information transferred overseas is separately retained and managed in accordance with the policies of the recipient.

5. Method, procedure, and effect of refusing the overseas transfer of personal information

Data subjects may withhold consent to overseas transfer by using the cookie-blocking methods described in Article 8, in which case the provision of customized services may be limited.

② Where the Company otherwise entrusts the processing of personal information to an overseas trustee or stores it on an overseas server, the Company provides notice in accordance with the matters set out in each item of Paragraph 1, mutatis mutandis.

Article 7 (Measures to Ensure the Security of Personal Information)

The Company uses its best efforts to safely manage the personal information of users, and makes additional efforts to protect personal information beyond the security measures required under the Personal Information Protection Act.

① Administrative Measures

  • Establishing and implementing internal regulations and plans for the safe processing and management of personal information
  • Designating and operating a Personal Information Protection Officer for the safe protection and management of personal information
  • Granting differentiated access authority to personal information by job function, and minimizing the number of personnel who handle personal information
  • Conducting regular training for personnel who handle personal information
  • Requiring all employees to sign a security pledge upon joining the Company, in order to prevent leakage of information by individuals

② Technical Measures

  • Granting personal information processing system access to authorized personnel on an individual basis and limited to the minimum scope necessary for the relevant duties
  • Retaining and managing the access records of personal information handlers for at least 2 years
  • Installing and operating access control systems to prevent unauthorized access to systems and security incidents
  • Encrypting data transmitted and received over networks, and encrypting the storage of important personal information
  • Installing and operating anti-virus software and performing periodic updates

③ Physical Measures

  • Designating physical locations where personal information is stored, such as computer and server rooms, as protected areas, and establishing access control procedures
  • Controlling the movement of equipment, materials, and auxiliary storage media into and out of such areas

Article 8 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

① The Company uses cookies, which store and periodically retrieve usage information, in order to provide individualized services and convenience to website users.

② Cookies, which refer to small pieces of information sent by the web server that operates the website to the data subject's browser, are stored on the data subject's PC or mobile device and automatically transmitted from the data subject's browser to the server when the website is accessed.

③ Data subjects may configure their web browser options to allow or block cookies. However, refusing to store cookies may cause difficulty in using customized services.

< Methods of Allowing/Blocking Cookies >

▸ Methods of Configuring Cookie Settings in a Web Browser (Examples)

  • Chrome: Browser Settings > Privacy and Security > Clear Browsing Data
  • Edge: Browser Settings > Cookies and Site Permissions > Manage and Delete Cookies and Site Data
  • Whale: Browser Settings > Privacy > Clear Browsing Data

▸ Methods of Configuring Cookie Settings in a Mobile Browser (Examples)

  • Chrome: Mobile Browser Settings > Privacy and Security > Clear Browsing Data
  • Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
  • Samsung Internet: Mobile Browser Settings > Browsing Data > Delete Browsing Data

Article 9 (Rights and Obligations of Data Subjects and Legal Representatives, and the Methods of Exercising Them)

① Data subjects may exercise their rights to access, correct, delete, suspend the processing of, and withdraw consent to their personal information at any time against the Company (hereinafter "exercise of rights").

※ Requests to exercise rights (including access, correction, deletion, and suspension of processing) with respect to personal information of a child under the age of 14 must be made directly by the legal representative; a data subject who is a minor aged 14 or older may exercise such rights personally or through a legal representative.

② The exercise of rights against the Company may be made in writing, by telephone, by email, or by fax, or by other means, pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.

③ The exercise of rights may also be made through a legal representative of the data subject or an authorized agent. In this case, a power of attorney in the form prescribed by the "Notice on Methods of Processing Personal Information" must be submitted.

④ Data subject's right to request access to personal information and suspension of processing may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ Where other laws specify that certain personal information is subject to collection, the deletion of such personal information may not be requested.

⑥ The Company verifies whether the person exercising a right is the data subject or a duly authorized agent.

⑦ The Company will endeavor to ensure that the exercise of rights by data subjects is processed promptly.

Article 10 (Name of the Personal Information Protection Officer, Department in Charge of Personal Information Affairs, and Department for Concerns or Complaints)

① The Company designates the following Personal Information Protection Officer, who is responsible for overseeing personal information processing affairs and handling complaints and remedies for data subjects in relation to the processing of personal information.

Personal Information Protection OfficerPersonal Information Protection Manager
· Name: Jang-woo Kim, CEO
· Title: Personal Information Protection Officer
· Email: privacy@mangoboost.io
· Phone: +82-2-525-3089
· Fax: +82-2-525-3088
· Name: Hyun-seung Nam
· Title: Personal Information Protection Manager
· Email: privacy@mangoboost.io
· Phone: +82-2-525-3089
· Fax: +82-2-525-3088

② Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from the use of the Company's services to the Personal Information Protection Officer and the responsible department.

Article 11 (Remedies for Infringement of the Rights and Interests of Data Subjects)

Data subjects may apply to the following institutions for dispute resolution or consultation in order to obtain remedies for infringement of personal information.

InstitutionContact
Personal Information Dispute Mediation Committee1833-6972 (no area code) / www.kopico.go.kr
Personal Information Infringement Report Center118 (no area code) / privacy.kisa.or.kr
Supreme Prosecutors' Office1301 (no area code) / www.spo.go.kr
National Police Agency Cyber Investigation Bureau182 (no area code) / ecrm.police.go.kr

Article 12 (Operation and Management of Fixed-Type Video Information Processing Devices)

① Grounds for and Purpose of Installing Fixed-Type Video Information Processing Devices

The Company installs and operates fixed-type video information processing devices for the following purposes, pursuant to Article 25(1) of the Personal Information Protection Act.

  • Facility safety and management, and fire prevention
  • Crime prevention for the safety of customers

② Number, Location, and Filming Range of Fixed-Type Video Information Processing Devices

  • Installation location and filming range: Server room, office entrance
  • Number of devices installed: 12

③ Administrator and Persons with Access Authority

CategoryDepartmentPositionName
AdministratorOS TeamLeaderHyo-ju Lee
Access Authority HolderOS TeamManagerYong-hoon Park

④ Filming Hours, Retention Period, Storage Location, and Processing Method of Video Information

Recording HoursRetention PeriodStorage Location
24 hours a day (continuous)No longer than 60 daysServer room
  • Processing method: The Company records and manages matters concerning use of personal video information for purposes other than its original purpose, provision to third parties, destruction, and requests for access, and permanently deletes the information by a method that prevents recovery upon expiration of the retention period.

⑤ Method and Location to Review Personal Video Information

  • Method of review: Review is available by contacting the personal video information administrator in advance and visiting the relevant department.
  • Location for review: OS Team

⑥ Measures in Response to a Data Subject's Request to Access Personal Video Information

Data subject may request access to, or confirmation of the existence of or deletion of, video information limited to footage in which the data subject appears, and the Company will take the necessary measures without delay.

⑦ Measures to Ensure the Security of Personal Video Information

Personal video information processed by the Company is safely managed through encryption and other measures. In addition, as an administrative measure to protect personal video information, the Company grants differentiated access authority to personal information, and to prevent forgery or alteration of personal video information, the Company records and manages the date and time of creation of the video information and, upon each access, the purpose of access, the person who accessed it, and the date and time of access. Furthermore, the Company has installed locking devices to ensure the safe physical storage of personal video information.

Article 13 (Changes to This Privacy Policy)

This Privacy Policy is effective as of August 9, 2026. Date of the most recent revision to this Privacy Policy: August 9, 2026.