개인정보처리방침 / Privacy Policy
개인정보처리방침Privacy Policy
최종 업데이트일 / Last Updated: [발효일]
1.개요
[운영사명](이하 "회사")은(는) 이용자의 개인정보를 중요하게 생각하며, 대한민국 「개인정보 보호법」 및 EU 일반개인정보보호규정(GDPR) 등 관련 법령을 준수합니다. 본 개인정보처리방침은 회사가 LCMD Studio(이하 "서비스")를 제공함에 있어 어떤 개인정보를 어떻게 수집·이용·보관·파기하는지를 설명합니다.
2.수집하는 개인정보 항목
회사는 서비스 제공을 위하여 다음과 같은 개인정보를 수집합니다.
- 회원가입 정보: 이메일 주소, 이름(닉네임), 프로필 이미지
- 소셜 로그인 제공정보: Google·Apple·Kakao·Naver 등 제공자로부터 제공받는 계정 식별자, 이메일, 프로필 정보
- 서비스 이용 기록: 생성 요청 내역, 이용 메뉴, 설정 등
- 업로드 콘텐츠: 회원이 업로드·입력한 이미지·텍스트·영상 등
- 결제 정보: 결제수단 정보 및 거래내역(실제 결제는 결제대행사를 통해 처리)
- 기기·로그·쿠키 정보: IP 주소, 브라우저·OS 정보, 접속 일시, 쿠키 및 유사 기술로 수집되는 정보
3.개인정보의 수집 및 이용 목적
회사는 수집한 개인정보를 다음의 목적으로 이용합니다.
- 회원 식별, 본인 확인 및 계정 관리
- AI 기반 비주얼·콘텐츠 생성 등 서비스의 제공 및 운영
- 고객 문의 응대 및 공지사항 전달
- 유료 서비스 결제·정산 및 환불 처리
- 서비스 품질 개선, 신규 기능 개발 및 이용 통계 분석
- 부정 이용 방지, 보안 및 법령상 의무 이행
- 이용자 동의에 기반한 마케팅·이벤트 정보 제공
4.처리의 법적 근거
EU/EEA 거주자 등 GDPR이 적용되는 경우, 회사는 다음 법적 근거(GDPR 제6조)에 따라 개인정보를 처리합니다.
- 동의(Art. 6(1)(a)): 마케팅 정보 수신, 선택적 항목 수집 등
- 계약의 이행(Art. 6(1)(b)): 회원가입 및 서비스 제공에 필요한 처리
- 법적 의무의 준수(Art. 6(1)(c)): 관련 법령상 보관·신고 의무 이행
- 정당한 이익(Art. 6(1)(f)): 서비스 보안, 부정 이용 방지, 서비스 개선 등
5.개인정보의 보유 및 이용 기간
회사는 원칙적으로 개인정보의 수집·이용 목적이 달성되거나 회원이 탈퇴한 경우 해당 개인정보를 지체 없이 파기합니다.
다만 관련 법령에서 일정 기간 보관을 요구하는 경우(예: 전자상거래 등에서의 소비자보호에 관한 법률에 따른 계약·청약철회·대금결제 및 재화 공급에 관한 기록 등) 해당 법령이 정한 기간 동안 보관한 후 파기합니다.
6.제3자 제공 및 처리위탁
회사는 이용자의 개인정보를 본인의 동의 없이 제3자에게 제공하지 않으며, 법령에 특별한 규정이 있는 경우에 한하여 제공합니다. 회사는 서비스 제공을 위하여 다음과 같은 업무를 외부에 위탁할 수 있습니다.
- 클라우드·인프라 제공자: 서버 호스팅 및 데이터 저장
- AI 모델·생성 엔진 제공자: AI 생성물 산출을 위한 처리
- 분석 도구 제공자: 서비스 이용 통계 및 품질 분석
- 결제대행사(PG): 결제 및 정산 처리
- 고객지원·메시지 발송 도구: 문의 응대 및 알림 발송
회사는 수탁자와 개인정보 보호 관련 사항을 계약으로 규정하고 수탁자가 안전하게 개인정보를 처리하도록 관리·감독합니다.
7.개인정보의 국외 이전
회사는 글로벌 서비스를 제공하는 과정에서 클라우드 인프라 등의 위치에 따라 개인정보가 국외에서 저장·처리될 수 있습니다.
국외 이전이 발생하는 경우, 회사는 GDPR이 요구하는 적정성 결정 또는 표준계약조항(SCC) 등 적절한 보호조치를 마련하고, 「개인정보 보호법」상 국외 이전에 관한 고지 및 동의 절차를 준수합니다.
8.이용자의 권리
이용자는 언제든지 자신의 개인정보에 대하여 열람·정정·삭제·처리정지를 요구하거나 수집·이용 동의를 철회할 수 있습니다.
GDPR이 적용되는 이용자는 추가로 접근권, 정정권, 삭제권(잊힐 권리), 처리제한권, 데이터 이동권 및 처리 거부권을 행사할 수 있습니다. 권리 행사는 본 방침에 기재된 연락처를 통해 요청할 수 있으며, 회사는 관련 법령에 따라 지체 없이 처리하고 권리 행사를 이유로 이용자에게 불이익을 주지 않습니다.
9.쿠키 및 추적 기술
회사는 이용자 경험 개선, 로그인 유지, 이용 분석 등을 위하여 쿠키 및 유사 기술을 사용할 수 있습니다.
이용자는 브라우저 설정을 통하여 쿠키 저장을 거부하거나 삭제할 수 있습니다. 다만 일부 쿠키를 차단하는 경우 로그인 유지 등 서비스의 일부 기능이 정상적으로 동작하지 않을 수 있습니다.
10.개인정보의 안전성 확보 조치
회사는 개인정보의 안전한 처리를 위하여 다음과 같은 조치를 취합니다.
- 관리적 조치: 내부관리계획 수립·시행, 접근 권한의 최소화 및 정기 점검
- 기술적 조치: 개인정보의 암호화, 접근통제 시스템 운영, 접속기록 보관 및 위·변조 방지
- 물리적 조치: 전산실·자료보관실 등에 대한 접근 통제
11.아동의 개인정보
서비스는 원칙적으로 만 14세 미만(대한민국 기준) 아동을 대상으로 하지 않습니다. GDPR이 적용되는 지역에서는 만 16세 미만(또는 회원국이 정한 연령) 아동의 개인정보는 법정대리인의 동의가 있는 경우에 한하여 처리합니다.
회사는 법정 연령 미만 아동의 개인정보가 보호자의 동의 없이 수집된 사실을 확인하는 경우 지체 없이 해당 정보를 파기합니다.
12.개인정보보호책임자
회사는 개인정보 처리에 관한 업무를 총괄하고 이용자의 문의·불만 처리 및 피해 구제를 담당하는 개인정보보호책임자를 다음과 같이 지정하고 있습니다.
- 개인정보보호책임자: [개인정보보호책임자]
- 연락처: [contact@이메일]
13.방침의 변경
본 개인정보처리방침은 법령·정책 또는 서비스의 변경에 따라 개정될 수 있습니다.
방침을 개정하는 경우 회사는 변경 사항과 시행일자를 서비스 화면을 통하여 공지하며, 중요한 변경의 경우 별도의 방법으로 안내합니다.
14.문의 및 구제 방법
개인정보 관련 문의는 [contact@이메일]으로 연락하실 수 있습니다.
개인정보 침해에 대한 신고·상담이 필요한 경우 아래 기관에 문의할 수 있습니다.
- 개인정보분쟁조정위원회 (kopico.go.kr)
- 개인정보침해 신고센터 (privacy.kisa.or.kr / 국번 없이 118)
- 대검찰청 사이버수사과 / 경찰청 사이버수사국
- EU/EEA 이용자: 거주지 관할 감독기관(Supervisory Authority)에 민원을 제기할 권리가 있습니다.
1.Overview
[운영사명] (the "Company") values users’ personal data and complies with applicable laws, including the Personal Information Protection Act ("PIPA") of the Republic of Korea and the EU General Data Protection Regulation ("GDPR"). This Privacy Policy explains what personal data the Company collects, uses, retains, and destroys in providing LCMD Studio (the "Service").
2.Personal Data We Collect
The Company collects the following personal data to provide the Service.
- Registration information: email address, name (nickname), profile image
- Social login information: account identifier, email, and profile information provided by providers such as Google, Apple, Kakao, and Naver
- Service usage records: generation requests, menus used, settings, and the like
- Uploaded content: images, text, video, and other materials uploaded or entered by the Member
- Payment information: payment method details and transaction records (actual payment is processed through a payment gateway)
- Device, log, and cookie information: IP address, browser/OS information, access date and time, and information collected through cookies and similar technologies
3.Purposes of Collection and Use
The Company uses collected personal data for the following purposes.
- Member identification, verification, and account management
- Provision and operation of the Service, including AI-based visual and content generation
- Responding to customer inquiries and delivering notices
- Processing payment, settlement, and refunds for paid services
- Improving service quality, developing new features, and analyzing usage statistics
- Preventing misuse, ensuring security, and fulfilling legal obligations
- Providing marketing and event information based on user consent
4.Legal Basis for Processing
Where GDPR applies (e.g., for residents of the EU/EEA), the Company processes personal data on the following legal bases (Article 6 of the GDPR).
- Consent (Art. 6(1)(a)): receiving marketing information, collection of optional items, etc.
- Performance of a contract (Art. 6(1)(b)): processing necessary for registration and provision of the Service
- Compliance with a legal obligation (Art. 6(1)(c)): retention and reporting duties under applicable law
- Legitimate interests (Art. 6(1)(f)): service security, prevention of misuse, service improvement, etc.
5.Retention and Use Period
In principle, the Company destroys personal data without delay once the purpose of collection and use has been achieved or the Member withdraws.
However, where applicable law requires retention for a certain period (e.g., records on contracts, withdrawal of subscription, payment, and supply of goods under the Act on the Consumer Protection in Electronic Commerce), the data is retained for the period set by such law and then destroyed.
6.Provision to Third Parties and Outsourcing
The Company does not provide users’ personal data to third parties without consent, except where specifically provided by law. The Company may outsource the following tasks to provide the Service.
- Cloud/infrastructure providers: server hosting and data storage
- AI model/generation engine providers: processing to produce AI Output
- Analytics providers: usage statistics and quality analysis
- Payment gateways (PG): payment and settlement processing
- Customer support and messaging tools: handling inquiries and sending notifications
The Company stipulates data protection matters by contract with its processors and manages and supervises them to ensure personal data is processed safely.
7.International Transfers
In the course of providing a global service, personal data may be stored and processed outside the user’s country depending on the location of cloud infrastructure and the like.
Where an international transfer occurs, the Company puts in place appropriate safeguards such as an adequacy decision or Standard Contractual Clauses (SCCs) as required by the GDPR, and complies with the notice and consent procedures for cross-border transfers under PIPA.
8.Your Rights
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal data, or withdraw consent to its collection and use.
Users to whom the GDPR applies may additionally exercise the rights of access, rectification, erasure (the right to be forgotten), restriction of processing, data portability, and objection to processing. Rights may be exercised via the contact in this Policy; the Company will act without undue delay in accordance with applicable law and will not disadvantage users for exercising their rights.
9.Cookies and Tracking Technologies
The Company may use cookies and similar technologies to improve user experience, maintain login sessions, and analyze usage.
Users may refuse or delete cookies through their browser settings. However, blocking certain cookies may prevent some features of the Service, such as maintaining login sessions, from functioning properly.
10.Security Measures
The Company takes the following measures for the safe handling of personal data.
- Administrative measures: establishing and implementing an internal management plan, minimizing access privileges, and conducting regular reviews
- Technical measures: encryption of personal data, operation of access control systems, and retention of access logs with protection against forgery and alteration
- Physical measures: access control to server rooms, data storage rooms, and the like
11.Children’s Personal Data
The Service is, in principle, not intended for children under the age of 14 (per the Republic of Korea). In regions where the GDPR applies, personal data of children under the age of 16 (or the age set by the member state) is processed only with the consent of a legal guardian.
If the Company learns that personal data of a child under the applicable age has been collected without guardian consent, it will destroy such data without delay.
12.Privacy Officer
The Company designates a Privacy Officer who oversees personal data processing and is responsible for handling user inquiries, complaints, and remedies, as follows.
- Privacy Officer: [개인정보보호책임자]
- Contact: [contact@이메일]
13.Changes to this Policy
This Privacy Policy may be revised in line with changes in law, policy, or the Service.
When the Policy is revised, the Company will announce the changes and their effective date through the Service, and will provide separate notice for material changes.
14.Inquiries and Remedies
For privacy-related inquiries, please contact [contact@이메일].
If you need to report or consult about a personal data infringement, you may contact the following authorities.
- Personal Information Dispute Mediation Committee (kopico.go.kr)
- Privacy Infringement Report Center (privacy.kisa.or.kr / dial 118)
- Cyber Investigation Division, Supreme Prosecutors’ Office / National Police Agency
- EU/EEA users: you have the right to lodge a complaint with the supervisory authority in your place of residence.