Balance — South Korea Country Annex
Effective date: 19 July 2026 Last updated: 19 July 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every South-Korean resident covered by this Annex; the Chief Privacy Officer (개인정보 보호책임자) designated under the Personal Information Protection Act (개인정보 보호법, "PIPA") Article 31, with business contact published as required by PIPA Art 31(3) and the Enforcement Decree; the designated contact point for the Personal Information Protection Commission (개인정보보호위원회, the "PIPC"), the Korea Internet & Security Agency ("KISA"), the Korea Communications Standards Commission ("KCSC"), the Korean National Police Agency ("KNPA"), and the Korea Consumer Agency ("KCA"), under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to PIPA (Act No. 10465 of 2011, comprehensively amended by Act No. 19234 of 14 March 2023, principal provisions in force from 15 September 2023, ADM provisions from 15 March 2024) or its Enforcement Decree; (b) any PIPC Notification, Guideline, or adequacy-style designation bearing on Art 28-8 (overseas transfer) or Art 28-9 (transfer suspension orders); (c) any amendment to Art 22-2 (consent of the legal representative for children under 14) or to the PIPC's children's-data guidance; (d) any change in the domestic-agent thresholds under PIPA Art 31-3 (ex-Art 39-11) and its Enforcement Decree (Balance is below the thresholds at the Effective date — tracked internally); (e) any amendment to the Act on the Consumer Protection in Electronic Commerce, etc. (the "E-Commerce Act") — in particular Art 17 (7-day withdrawal) and its digital-content carve-outs; (f) any amendment to the Youth Protection Act (청소년 보호법) or the Act on the Protection of Children and Youth against Sex Offenses (청소년성보호법, the "Youth Sex-Offense Protection Act"); (g) any amendment to the Civil Act Art 4 (age of majority — 19) or Art 5 (minor's juristic acts require the legal representative's consent); (h) any decision of the Constitutional Court of Korea or the Supreme Court of Korea materially bearing on PIPA or the constitutional right to informational self-determination (Constitution Arts 10, 17); (i) any change in Korea's EU-adequacy status (the European Commission adequacy decision for Korea of 17 December 2021 covers EU→Korea flows; it does not govern Korea→third-country flows); (j) any change to a sub-processor's Korea data-handling posture under our sub-processor register; (k) the bringing into force of any post-Effective-date Korean regulation governing automated processing or related techniques beyond PIPA Art 37-2 (covered by the deliberate-silence carve-out in § 2); (l) any KCSC or Youth-Protection designation affecting Balance's classification.
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — South Korea row).
- Children's Privacy Notice § 14 (Country annexes — South Korea row).
- Child Safety Standards § 13 (Country annexes — South Korea row).
- Terms of Service § 17 (South Korea consumer-protection carve-out — E-Commerce Act + Content Industry Promotion Act; KCA dispute mediation; age of majority 19).
- Subscription Terms § 18 (South Korea consumer-rights overlay — E-Commerce Act Art 17 7-day withdrawal with digital-content carve-out).
- Data Retention & Deletion Policy § 13 (South Korea — PIPC complaint route).
- our breach-notification runbook § 9 (South Korea breach-notification route under PIPA Art 34 — 72 hours).
- our international-transfer pack § 6 (PIPA Art 28-8 overseas-transfer consent mechanism).
This Annex is the canonical Korean-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Korean resident a right that the global Policy does not, this Annex governs; the converse also holds. The two are read together.
This Annex is drafted in English. PIPA practice and the PIPC's privacy-policy guidance expect the privacy policy for Korean data subjects to be available in Korean; a Korean translation of this Annex and of the common documents is provided via the language switcher at balance.babayagaprogram.com as part of the batch-1 locale rollout — that Korean rendering satisfies the Korean-language-policy expectation.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of Korea. PIPA is a national statute; there is no provincial data-protection sub-layer.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in onboarding, (b) the IP-geolocation read at sign-up (discarded immediately after the residence decision — our internal data-flow map § 2.1), and (c) the Play Store account locale. Reviewable at Settings → Account → Region. Where any signal identifies Korea, this Annex applies; the most-protective reading controls.
PIPA applies to any personal information controller processing Korean data subjects' personal information; the PIPC's established enforcement practice applies PIPA to offshore controllers offering services targeted at Korean data subjects (codified in the domestic-agent and overseas-transfer architecture of the 2023 amendment). Balance targets Korean residents through Google Play Korea and through this Annex; PIPA applies in full.
2. Statutory framework — what applies
| Instrument | What it does | Balance's posture |
|---|---|---|
| Constitution of the Republic of Korea — Arts 10, 17 | Human dignity + privacy of citizens; the Constitutional Court's right to informational self-determination doctrine. | Constitutional anchor. §§ 3, 6 below. |
| PIPA (as comprehensively amended 2023) | The principal statute. Art 15 collection/use lawful bases (consent; contract — the 2023 amendment broadened contract-necessity; legal obligation; vital interest; legitimate interest not overriding data-subject rights); Art 17 third-party provision; Art 22 consent methods (separated, itemised); Art 22-2 — consent of the legal representative for processing personal information of a child under 14, with plain-language duty toward the child; Art 23 sensitive information (not processed by Balance); Art 24/24-2 unique identifiers / resident registration numbers (never collected by Balance); Art 28-8 — overseas transfer requires (inter alia) the data subject's separate consent after disclosure of the items, destination country, dates/methods, recipient, and purposes/retention — or a PIPC-recognised certification/adequacy route; Art 28-9 PIPC transfer-suspension orders; Art 29 safety measures (Enforcement-Decree security standards); Art 31 Chief Privacy Officer; Art 31-3 domestic agent for large offshore providers (thresholds not met by Balance — tracked internally); Art 34 breach notification — data subjects and the PIPC/KISA within 72 hours (Enforcement Decree; ≥1,000 subjects or sensitive/illegal-access incidents reportable regardless of scale); Arts 35-37 access, correction/deletion, suspension; Art 37-2 (from 15 March 2024) — rights against fully automated decisions (refusal/explanation); Art 39 et seq. civil remedies incl. statutory damages; penalties up to 3% of related revenue for major violations. | The principal statute. Applies in full. Treatment throughout. |
| E-Commerce Act (Act on the Consumer Protection in Electronic Commerce, etc.) | Art 17 — 7-day right of withdrawal from the contract date (or supply date), with the digital-content carve-out once performance has begun with the consumer's express consent and the statutory disclosures; Art 13 disclosure duties; the Fair Trade Commission (KFTC) enforces. | Applies. Treatment in § 16 below. |
| Content Industry Promotion Act | Content-transaction user-protection rules, incl. the standard terms practice for digital content. | Applies. § 16 below. |
| Youth Protection Act | Youth (under 19) protection framework — harmful-media designations, parental-supervision policy. Balance is a parental-supervision tool consonant with the Act's framework; Balance distributes no youth-harmful media. | Applies as a context-setting fact. § 5 below. |
| Act on the Protection of Children and Youth against Sex Offenses | CSAM offences (Art 11 — production/distribution/possession of child or youth sexual-exploitation material), grooming (Art 15-2), and the reporting architecture. | Applies. § 14 below. |
| Civil Act — Art 4 + Art 5 | Age of majority 19; a minor's juristic act requires the legal representative's consent (voidable otherwise). | Applies. § 16 below — the subscribing parent must be 19+. |
| Network Act (Information and Communications Network Act) | Residual online-security and advertising rules (most privacy provisions merged into PIPA in 2020); Art 50 anti-spam (opt-in for commercial email). | Applies. § 12 below. |
| EU adequacy | The EU→Korea adequacy decision (17 December 2021) covers inbound EU flows; Korea→US/Kazakhstan outbound flows are governed by PIPA Art 28-8 — the signup separate consent is the mechanism (§ 8). | Context-setting fact. |
| Budapest Convention / Convention 108 | Korea is not a party to the Budapest Convention or Convention 108 at the Effective date; MLAT channels apply (Korea-US MLAT in force 1997). | Context-setting facts. § 13 below. |
(Any prospective Korean regulation governing automated processing, algorithmic decisions, or related techniques beyond PIPA Art 37-2 — including the Framework Act on Artificial Intelligence implementation and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence is deliberate.)
3. Supervisory authorities
3.1 PIPC
| Field | Value |
|---|---|
| Name | Personal Information Protection Commission (개인정보보호위원회, PIPC) — central administrative agency under the Prime Minister |
| Address | Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul, Republic of Korea |
| Website | https://www.pipc.go.kr/ |
| Complaint / dispute channels | Privacy Call Centre 118 (KISA-operated, privacy.kisa.or.kr); Personal Information Dispute Mediation Committee (https://www.kopico.go.kr/) |
| Breach-notification channel | PIPC/KISA breach-report portal per PIPA Art 34 + Enforcement Decree — 72 hours |
A Korean resident may complain to the PIPC, call the 118 centre, or seek dispute mediation (KOPICO) — before or after raising the matter with us at (named individual: ). Civil remedies include PIPA Art 39 damages (with statutory-damages election) and class-style mediation.
3.2 Other regulatory bodies
| Body | Subject matter | Channel |
|---|---|---|
| KISA | Security incidents; 118 privacy centre | https://www.kisa.or.kr/ — dial 118 |
| KCSC (Korea Communications Standards Commission) | Illegal-content reports incl. CSAM | https://www.kocsc.or.kr/ — report 1377 |
| KNPA — National Office of Investigation (Cyber Bureau) | Cybercrime + CSAE investigation | https://ecrm.police.go.kr/ — emergency 112 |
| KFTC (Fair Trade Commission) | E-Commerce Act enforcement | https://www.ftc.go.kr/ |
| Korea Consumer Agency (KCA) | Consumer counselling + dispute mediation | https://www.kca.go.kr/ — counselling 1372 |
3.3 The Chief Privacy Officer
PIPA Art 31 requires designation of a Chief Privacy Officer. The Balance CPO is , Director, BabaYaga Program, TOO — , published here, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. The domestic-agent designation duty (Art 31-3) attaches only above Enforcement-Decree thresholds (revenue/user-count) that Balance does not meet at the Effective date; the threshold watch is tracked internally per the locked user decision (no local representatives).
4. Lawful bases — PIPA Art 15 + Art 22-2
- Parent account data: Art 15(1)4 contract necessity + Art 15(1)1 consent obtained at sign-up with itemised, separated consent per Art 22.
- Kid profile + device data: for a kid under 14, the legal representative's consent under Art 22-2 — obtained by design through the parent-first onboarding (§ 5); for a kid 14-18, the parent's consent as holder of parental authority plus the kid's age-appropriate notice.
- Overseas transfer: the separate transfer consent under Art 28-8 obtained at sign-up (§ 8).
- Security, fraud-prevention, legal compliance: Art 15(1)2 legal obligation + Art 15(1)6 legitimate interest with balancing.
- No sensitive information (Art 23), no unique identifiers (Art 24), no resident registration numbers (Art 24-2) are ever collected. No advertising, profiling, or sale — monitoring/limits/tasks are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, never for any commercial purpose.
5. Children's rights overlay — Art 22-2 + Youth Protection framing
- The parent (legal representative) always consents; the kid never self-registers. The Art 22-2 under-14 legal-representative consent is satisfied by construction: the kid profile exists only inside the authenticated parent account, and the pairing act is the parent's. Art 22-2(2) minimum-data collection for verifying the representative relationship is satisfied without extra data collection — the representative is the account holder.
- Plain language toward the child (Art 22-2(3)): kid-facing screens use age-appropriate plain Korean/plain language; the Children's Privacy Notice (H2) carries the child-readable summary.
- The legal representative exercises the under-14 child's rights (access, correction, deletion, suspension) — § 6 below; the parent does so in-app or by email.
- Youth Protection Act framing: Balance is a parental-supervision tool; it exposes no content feed, no social surface, no youth-harmful media, no advertising.
- No tracking for our purposes, no behavioural advertising, no profiling — the PIPC's children's-data guidance (privacy-by-default for minors) is met by the only mode Balance ships.
6. PIPA rights catalogue — Arts 35-37-2
Honoured at and in-app (the legal representative exercises an under-14 kid's rights):
- Art 35 — access: in-app JSON export at Settings → Family → [kid name] → "Export this kid's data" + plain-language summary; response within 10 days (Enforcement-Decree standard).
- Art 36 — correction/deletion: Settings → Account → Edit; deletion at Settings → "Delete my account" / "Delete this kid"; Delete-account page; cascade per Data Retention & Deletion Policy § 7.
- Art 37 — suspension of processing: honoured on request; consent withdrawal honoured at any time with parity of ease.
- Art 37-2 — automated decisions: the right to refuse or demand explanation of fully automated decisions with material effects — Balance performs none; the earned-time ledger is deterministic and parent-reviewable.
- Art 28-8(4) transparency: the overseas-transfer disclosure items are stated in § 8 + the global Privacy Policy § 7.
- Remedies: PIPC complaint; 118 centre; KOPICO mediation; Art 39 civil damages (including statutory damages without proof of actual loss).
Requests may be in Korean or English, free of charge. Identity verification uses the parent's existing authentication credential.
7. Children's data — consent mechanics and minimisation
- The parent creates the account with a verified email (+ Google Play payment instrument where subscribed), then affirmatively creates the kid profile and pairs the kid's device — the Art 22-2 legal-representative consent, evidenced and logged, with the Art 22 itemised-consent screen (Korean for Korean parents).
- Data minimisation (Art 3(1)): only what the supervision service needs; proof media is E2EE to the parent's devices — Balance holds ciphertext only (§ 13).
- Kid data is never used for advertising, never profiled, never sold; retention per Data Retention & Deletion Policy.
8. International data transfers from Korea — PIPA Art 28-8
Balance transfers Korean residents' personal data to the United States (hosting) and grants controller access from Kazakhstan. The mechanism is the data subject's separate consent to the overseas transfer obtained at sign-up: the signup transfer-disclosure consent IS the Art 28-8 separate consent — it is presented separately from the general consent and discloses each Art 28-8(2) item:
- the items of personal information transferred (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens; E2EE proof-media ciphertext);
- the destination country (United States; controller access from Kazakhstan), and the timing and method of transfer (continuous, via encrypted network transmission);
- the recipients (the § 10 sub-processors) and their contact points;
- the recipients' purposes of use (service hosting/delivery only) and retention periods (per the Retention Policy);
- the method and effect of refusing consent (the service cannot be delivered without hosting; refusal means not using Balance).
Art 28-8(4) protective measures (security standards, breach handling, DPAs) are contractually imposed on every recipient per our international-transfer pack § 6, with the E2EE proof-media supplementary measure. The PIPC's Art 28-9 suspension power is acknowledged; § 18 covers any PIPC certification/equivalence route that could supplement consent.
9. Data residency for Korean residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region (E2EE ciphertext only). |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Korean resident's data held in Korea? | No. The Art 28-8 separate consent in § 8 grounds the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO), with administrative access under written processor DPAs. |
| Is there a Korean establishment or domestic agent? | No establishment; the Art 31-3 domestic-agent thresholds are not met at the Effective date (tracked internally). |
Korea imposes no data-localisation mandate on parental-control services.
10. Sub-processors touching Korean-resident data
| Sub-processor | Role | Location | Korea transfer basis |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (US); relationship per our internal vendor-handling plan | Hosts the FastAPI backend + MongoDB cluster | United States | PIPA Art 28-8 separate consent + Art 28-8(4) contractual protective measures; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | E2EE proof-media ciphertext + daily 30-day-rolling backups | United States (us multi-region) |
Art 28-8 consent + Google Cloud DPA; ciphertext-only. |
| Google LLC — Firebase Cloud Messaging | Push notifications | United States | Art 28-8 consent; push body free of sensitive content (M3). |
| Google LLC — Google Sign-In | Parent Google authentication (when used) | United States | Art 28-8 consent + Google DPA. |
| Google LLC — Google Play Billing | Subscription purchases | United States / Korea (Google Play) | Google Play Developer Distribution Agreement + Art 28-8 consent. |
| Resend, Inc. (San Francisco, CA, USA) | Transactional email | United States | Art 28-8 consent + DPA on file. |
Full list: our sub-processor register.
11. Breach notification — PIPA Art 34
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| Affected data subjects | Loss, theft, leakage of personal information. | Without delay — within 72 hours of awareness (Enforcement Decree), stating the items, when/how, mitigation steps the subject may take, our response measures, and contact points. | Direct email to the affected parent; in-app banner; public incident page fallback. Korean. |
| PIPC / KISA | Leakage of ≥ 1,000 data subjects' information, or sensitive information, or leakage by illegal access — reportable regardless of scale for the latter categories. | Within 72 hours. | The PIPC/KISA breach-report portal, filed by the CPO or Korean counsel on instruction. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 + runbook M1. | KNPA (ECRM/112) + KCSC + (where applicable) NCMEC. |
Internal SLA: our breach-notification runbook § 5.4 + § 9.
12. Cookies, spam, and electronic direct marketing
The PIPC treats cookie-equivalent identifiers as personal information where identifiability arises. The Balance app deploys strictly-necessary storage only (authentication tokens; device-pairing key wrap; earned-time cache), covered by the sign-up consent. The public site uses no analytics, advertising cookies, trackers, or fingerprinting. Balance sends no electronic direct marketing to Korean residents — transactional email only; if a marketing channel were ever introduced, the Network Act Art 50 opt-in rule (and night-time restrictions) would be implemented first. Behavioural advertising to children: never (PIPC children's guidance; product-wide policy).
13. Lawful-access requests and the encryption posture
Korean authorities may seek data via court-issued warrants under the Criminal Procedure Act, communications-data procedures under the Protection of Communications Secrets Act, and international channels (Korea-US MLAT; Korea is not a Budapest Convention party at the Effective date). Posture:
- Proof media is end-to-end encrypted (fresh per-file key, XChaCha20-Poly1305, wrapped to parent-device X25519 keys; ciphertext-only upload). No master key, no backdoor.
- Response protocol: (1) acknowledge within one business day; (2) engage Korean counsel to assess validity; (3) preserve relevant ciphertext; (4) inform the authority plaintext is unavailable from us; (5) cooperate in identifying the lawful route to the key-holding parent.
- No bulk plaintext interception assistance; no server-side content scanning. CSAE cooperation runs via § 14 regardless.
Full encryption posture: our encryption-posture record.
14. CSAE reporting routes — South Korea
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day. - Police: emergency 112; online at the KNPA Electronic Cybercrime Report & Management System
https://ecrm.police.go.kr/. - KCSC illegal-content report:
https://www.kocsc.or.kr/— hotline 1377 (CSAM category; KCSC issues blocking/deletion orders). - Child-abuse reporting: 112 integrated line (Child Welfare Act route); local child-protection agencies.
- Youth counselling: 1388 (Youth Counselling Welfare Centre — 24/7).
- NCMEC CyberTipline (
https://report.cybertip.org/) — provider-side discoveries route to NCMEC, which relays to Korean law enforcement.
Full routing table: Child Safety Standards § 8.5.
15. Complaint routes (summary)
| Authority | Subject matter | Channel |
|---|---|---|
| PIPC | PIPA | https://www.pipc.go.kr/ |
| KISA Privacy Call Centre | Privacy counselling + complaint intake | dial 118; https://privacy.kisa.or.kr/ |
| KOPICO | Personal-information dispute mediation | https://www.kopico.go.kr/ |
| KFTC | E-Commerce Act | https://www.ftc.go.kr/ |
| KCA / 1372 | Consumer counselling + KCA dispute mediation | dial 1372; https://www.kca.go.kr/ |
| Courts | PIPA Art 39 damages (incl. statutory damages); civil/criminal | Per jurisdiction |
A Korean resident may always first raise the matter at ; prior contact is not a precondition to any authority route.
16. Consumer rights — the E-Commerce Act overlay
- Art 13 disclosures: supplier identity, price, payment and withdrawal terms — implemented in Subscription Terms § 5.
- Art 17 — 7-day withdrawal: the consumer may withdraw within 7 days of the contract/supply date. For digital content, the right is excluded once performance has begun with the consumer's express consent and the statutory pre-disclosure — Balance implements the express-consent + acknowledgement mechanics in the purchase flow, and honours the Google Play refund route as the operational floor (Subscription Terms § 8).
- Content Industry Promotion Act: digital-content user-protection standards honoured via the same flow.
- KCA dispute mediation: available via 1372; nothing in the Terms displaces it.
- Standard-terms control: the Act on the Regulation of Terms and Conditions voids unfair standard terms — the Terms of Service are drafted to avoid each listed category.
- Contracting capacity: the age of majority is 19 (Civil Act Art 4); the subscribing parent/guardian must be 19 or older; a minor's contract is voidable (Art 5) — the kid never contracts with Balance.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — PIPA Art 28-8 consent mechanism on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
- Every change to a substantive row in §§ 2-16 bumps the frontmatter and triggers re-publication.
- A PIPA / Enforcement-Decree amendment, a PIPC Art 28-8/28-9 development (certification, equivalence, suspension practice), or a domestic-agent threshold event triggers an off-cycle rewrite of §§ 2, 3, 8.
- An Art 22-2 or PIPC children's-guidance change triggers an off-cycle update to §§ 5, 7.
- An E-Commerce Act / standard-terms change triggers an off-cycle update to § 16 + Subscription Terms.
- A material change to a sub-processor's posture triggers an off-cycle update to §§ 8, 10.
- The annual review is by 9 June. The Privacy Officer signs off; the Designated Child Safety Officer co-signs any change to §§ 5, 7, 11, 13, 14.
End of South Korea Country Annex.