Privacy Policy
Effective Date: September 3, 2026 (item 6, cross-border transfer of personal information under entrusted work, takes effect September 9, 2026 — see the revision history below)
Quantum Jump Club (hereinafter 'Company') complies with the Personal Information Protection Act and other relevant laws and does its best to protect users' personal information.
1. Personal Information Collected
The Company collects the following personal information to provide services:
- Required items: Email address, Name (nickname)
- Optional items: Profile photo, Interests, Occupation
- For payment: Payment information (card company, payment date, etc. - card numbers are not stored)
- Automatically collected: Service usage records, access logs, cookies, IP address, device information
- Podcast guest application: Name, email, phone, company, title, bio (collected from non-members)
- Podcast live pre-registration: Name, email, company (optional) (collected from non-members)
- Singularity Builders free briefing application: Name, phone, company or brand, role, biggest current challenge (optional) (collected from non-members)
2. Purpose of Collection and Use
Collected personal information is used only for the following purposes:
- Service provision and member management
- Payment processing and refunds for paid services
- Service improvement and new service development
- Marketing and advertising (with separate consent)
- Compliance with legal obligations
- Podcast broadcast notices and guest appearance coordination (schedule, live link, replay notices)
- Singularity Builders free briefing schedule and participation instructions
3. Retention and Use Period
Personal information is destroyed without delay when the purpose of collection is achieved. However, if retention is required by relevant laws, it will be stored for that period.
- Records on contracts or withdrawal: 5 years (E-Commerce Act)
- Records on payment and supply of goods: 5 years (E-Commerce Act)
- Records on consumer complaints or disputes: 3 years (E-Commerce Act)
- Login records: 3 months (Protection of Communications Secrets Act)
- Singularity Builders free briefing application data: 30 days from application
Destruction Procedure and Method
Personal information whose retention period has expired is deleted automatically under a pre-established destruction policy. Any other destruction is carried out with the confirmation of the Privacy Officer.
Personal information stored in databases is deleted, and any copy remaining in the provider backups expires together with that backup retention window. Any personal information printed on paper is shredded or incinerated.
4. Third-Party Provision
In principle, the Company does not provide users' personal information to third parties. However, exceptions are made in the following cases:
- When the user has given prior consent
- When required by law or requested by investigative agencies
Current Third-Party Provision Status
- TossPayments: Payment processing (payment information)
- Google: Social login (email, name)
- Kakao: Social login (email, name, profile photo)
5. Processing Entrustment
The Company entrusts personal information processing as follows for service provision:
- TossPayments - Payment processing
- AWS (Amazon Web Services) - Cloud infrastructure
- Resend - Email delivery
- Solapi - SMS delivery
- Supabase - Database hosting and data storage
6. Cross-Border Transfer of Personal Information under Entrusted Work
This section concerns a separate system the Company operates under entrustment from a client company. It does not apply to the personal information of users of this site (qjc.app). For processing entrustment relating to user personal information, see the Processing Entrustment item above.
The Company performs the operation and maintenance of an automated tally system for collective-building management-body meetings, entrusted by client companies (meeting agencies). In the course of that work, personal information provided by the client or its original entruster (the management body) is entrusted to or stored with the overseas providers listed below. The legal procedures for cross-border transfer, including notice to and consent from data subjects, are led by the client or original entruster as the personal information controller; the Company discloses the following as the entrusted processor, pursuant to Article 28-8 of the Personal Information Protection Act as applied mutatis mutandis by Article 26(8).
Personal information items processed by that system
Name, date of birth or registration number, address, unit number, ownership share, and contact of unit owners and occupants; the entries on powers of attorney and written resolutions; and signature images. Below, "all processed items" refers to this list.
The processing regions and retention periods below reflect the settings of the accounts the Company uses to operate that system, and are separate from this site's infrastructure settings.
a. Google LLC (automated document recognition)
- Items transferred: Full page images of powers of attorney and written resolutions. Depending on the form, these may include name, date of birth or registration number, address, contact, unit number, ownership share, voting content, and signature image. Images are transmitted in full without prior separation or masking. Of the recognition results, only the first six digits of any resident registration number are stored in the Company's systems, and page images are not retained in the Company's systems (for retention on the recipient side, see the retention period below).
- Country: United States (under the Gemini API terms, data may be temporarily stored or cached in other countries where Google or its agents operate facilities)
- Timing and method: Transmitted via API over an encrypted channel at the time a recognition request is made
- Recipient: Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. Privacy inquiries: Google Cloud data protection team (support.google.com/cloud/contact/dpo)
- Purpose of use: Generating and returning the requested document recognition results
- Retention period: Retained for 55 days for abuse detection (Gemini API usage policy). On paid tiers, prompts and responses are not used for model training.
- How to refuse: Data subjects may refuse in writing or by phone to the client or management body, using the method stated in the meeting convocation notice; such documents are then excluded from automated recognition.
- Effect of refusal: The document is processed manually without automated recognition.
b. Vercel Inc. (application runtime environment)
- Items transferred: All processed items listed above. Processed transiently as requests and responses during application execution; not retained in a persistent data store.
- Country: United States (server function execution region: Washington, D.C. area, iad1)
- Timing and method: Continuously during the system operation period, as request/response processing over an encrypted channel
- Recipient: Vercel Inc., 440 N Barranca Avenue #4133, Covina, California 91723, USA. Privacy inquiries: privacy@vercel.com
- Purpose of use: Provision of the server and application runtime environment
- Retention period: Retained for the minimum period necessary to provide the service, then deleted (Vercel privacy notice and data processing addendum). The provider does not publish a specific number of days.
- How to refuse: Same as item a above.
- Effect of refusal: Excluded from system-based tallying; tallied manually instead.
c. Supabase Pte. Ltd. (data storage and backup)
- Items transferred: All processed items listed above
- Country: Data is stored in the Republic of Korea (Seoul, ap-northeast-2). However, the contracting entity is a Singapore company and technical support is performed by the U.S. entity Supabase, Inc. as a sub-processor, so access from Singapore and the United States may occur during support and operations.
- Timing and method: Continuously during the system operation period, as storage and retrieval over an encrypted channel
- Recipient: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Privacy inquiries: privacy@supabase.io (Singapore entity, per the data processing agreement) or privacy@supabase.com (US entity Supabase, Inc., per its privacy policy)
- Purpose of use: Data storage and backup
- Retention period: The term of the entrusted work. Upon termination, returned or destroyed per the client's instructions. The provider's daily automated backups retain the most recent seven days.
- How to refuse: Same as item a above.
- Effect of refusal: Same as item a above.
7. Rights of Data Subjects
Users may exercise the following rights at any time:
- Request access to personal information
- Request correction or deletion of personal information
- Request suspension of personal information processing
- Withdraw consent
Rights can be exercised through the settings menu within the service or through customer support.
If you provided information without an account, you may submit your request to the Privacy Officer listed below.
8. Security Measures
The Company takes the following measures to ensure the safety of personal information:
- Encryption of personal information
- Access authority management and restrictions
- Access log retention and forgery prevention
- Installation and operation of security programs
9. Privacy Officer
The Company designates a Privacy Officer as follows to take overall responsibility for personal information processing and to handle user complaints and damage relief related to personal information processing:
Privacy Officer: Sangrok Jeong
Email: news@quantumjumpclub.com
Phone: 010-8216-8366
10. Cookie Usage
The Company uses cookies for service convenience. Cookies are small text files that websites store on users' browsers.
Purpose of cookie use: Login maintenance, service usage analysis, personalized service provision
Users can refuse to store cookies through browser settings, but this may cause difficulties in using the service.
11. Remedies for Infringement of Data Subject Rights
To seek redress for a personal information infringement, you may apply to the bodies below for dispute resolution or counselling. You may also contact the Privacy Officer above regarding the Company's own processing.
- Privacy Infringement Report Centre: 118 (no area code) · privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 · www.kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Division: 1301 (no area code) · www.spo.go.kr
- National Police Agency Cyber Bureau: 182 (no area code) · ecrm.cyber.go.kr
12. Changes to Privacy Policy
This privacy policy may be modified due to changes in laws, policies, or security technologies. Changes will be notified through notices within the service from 7 days before implementation.
Revision History
- Enacted January 28, 2026 — as amended by the correction below, this is the version currently in force.
- Corrected September 3, 2026 — fills in statutory disclosures that were missing: remedies for infringement of data subject rights (item 11) and the destruction procedure and method (item 3); states how data subjects without an account may exercise their rights (item 7); and reclassifies Supabase from third-party provision to processing entrustment. What the Company processes has not changed; these entries were missing or inconsistent with the facts, so the correction applies from publication.
- Effective September 9, 2026 — adds item 6, cross-border transfer of personal information under entrusted work. Only this item is pending; until it takes effect, this policy is read without item 6, with items 7-12 renumbered as items 6-11.