Hyperrise Privacy Policy
Hyperrise Co., Ltd. (hereinafter referred to as the “Company”) establishes and discloses this Privacy Policy in order to protect the personal information of data subjects and to promptly and smoothly address any related complaints. This Privacy Policy applies to users who reside outside of the Republic of Korea. A separate Korean language Privacy Policy applies to users who reside in the Republic of Korea and is not a translation of this document.
The Company collects the minimum amount of personal information necessary to provide its services. The collected information is categorized as follows based on its source:
① Information you provide to us
Members directly provide this information when registering for the service, participating in events, or requesting customer support.
1) Payment-related Information: When a member uses payment methods provided by mobile carriers or open market operators, the Company does not collect payment information. However, if a complaint arises, the Company may request:
▶︎ Payment service provider: payment transaction ID, payment amount
▶︎ Mobile phone billing: payment approval number, device model
2) Children's Information: If a member is confirmed to be under the age of 13, the Company may collect Legal Guardian’s Personal Information to verify consent. Any personal information so collected will be destroyed immediately after the purpose is achieved. However, if consent cannot be verified, the Company may restrict the use of services.
② Information third parties provide to us
When you link your game account to an external platform, the Company receives the following information from the respective platform providers.
③ Information collected automatically
The following information is automatically generated and collected during the use of the services.
④ Methods of Collecting Personal Information
1) Collected through the consent process when registering for the Company’s services
2) Collected through a separate consent process for the purpose of conducting promotions and events
3) Automatically collected through platforms that have a partnership with the Company
4) Collected during payment or user support interactions, through voluntary provision or request
⑤ Refusal of Consent to the Collection and Use of Personal Information
Members may refuse consent to the collection and use of the above personal information. However, refusal may make it difficult to use the game services.
The Company transfers members’ personal information to overseas locations in order to provide stable services.
▶︎ The Company respects users’ rights and their right to informational self-determination, and users may refuse the overseas transfer of personal information by contacting the Chief Privacy Officer or through inquiries regarding personal information. However, refusal of overseas transfer of personal information may result in restrictions on the use of game services that require such overseas transfer.
▶ Pursuant to Article 45 of the GDPR, the Company relies on the European Commission’s adequacy decision for the Republic of Korea and transfers the personal information of EU residents to Amazon Web Services in the United States in accordance with the EU–U.S. Data Privacy Framework (DPF).
① Retention of your information. In general, the Company retains your personal information for as long as necessary to fulfill the purposes for which it was obtained and to provide our Services.
② Destruction Principle. In principle, the relevant information is destroyed without delay once a member withdraws from the service or the purpose of collection and use of personal information has been achieved.
③ Exceptions for Legal or Business Reasons. We may retain your personal information even after you have closed your account with us or we have ceased providing Services to you, if retention of your information is reasonably necessary for our legal or legitimate business reasons, such as to comply with our legal obligations, resolve disputes, prevent fraud or abuse, or enforce this Privacy Policy or our agreements.
In principle, the Company destroys personal information without delay once the purposes of collection and use have been achieved. The procedures and methods for destruction are as follows.
① Destruction Procedures
Information entered by members for the purpose of using the services, such as during member registration, is destroyed after being retained for the required period in accordance with the Company’s internal policies and applicable laws for information protection purposes (see “3. Retention and Use Period of Personal Information”), once the purposes of collection and use of personal information have been achieved.
② Destruction Methods
1) Electronic files: Deleted using technical methods that render the records irrecoverable
2) Printed materials: Destroyed by shredding or incineration
① To ensure the smooth handling of personal information-related tasks, the Company entrusts the processing of personal information to third parties as follows.
② When entering into an outsourcing agreement, the Company specifies in the contract matters required under the Personal Information Protection Act, including the prohibition on processing personal information for purposes other than the performance of entrusted tasks, technical and administrative safeguard measures, restrictions on sub-outsourcing, supervision and management of service providers, and liability for damages. The Company also supervises and manages service providers to ensure that personal information is processed securely.
① Members and legal guardians may, at any time, access, obtain copies of, correct, or update the personal information of themselves or of a child under the age of 13 (hereinafter referred to as a “Child”), and may also request termination of membership. Where consent is required for the collection, use, or provision of a Child’s personal information, the Company obtains the consent of the Child’s legal guardian. For this purpose, the Company may request the minimum necessary information from the legal guardian, such as the guardian’s name and contact information. Personal information of the legal guardian collected in this manner is not used for purposes other than verifying the guardian’s consent, nor is it provided to any third party.
② Members and legal guardians may withdraw their consent to the provision of personal information at any time (by withdrawing from membership). To withdraw consent to the provision of personal information, members may withdraw from membership by clicking “Account Deletion” (Setting -> Account Deletion) within the service. Members and legal guardians may access and correct or delete personal information by contacting the Company’s customer support center in writing, by email, or through the “1:1 Inquiry” feature within the service. Where a member requests correction or account deletion of personal information, the Company will not use or provide the relevant personal information until the correction has been completed. In addition, if incorrect personal information has already been provided to a third party, the Company will notify such third party of the correction without delay so that the correction can be made.
③ Personal information deleted at the request of a member or legal guardian is processed in accordance with the Company’s Terms of Service and related policies, and is not accessed or used for any other purposes.
The Company implements the following measures to prevent the loss, theft, leakage, alteration, or damage of members’ personal information. However, the Company shall not be held liable for any issues arising from the leakage of important personal information due to a member’s own negligence, such as loss of a device, or incidents occurring in areas beyond the Company’s control, even where the Company has fulfilled its personal information protection obligations.
① Technical Safeguards
1) The Company encrypts and stores items of members’ personal information designated under applicable laws and regulations. Access to and modification of personal information are permitted only after identity verification at the request of the data subject.
2) Important data containing personal information is protected through security measures such as encrypting files and transmitted data or applying file-locking functions.
3) To prevent the leakage or damage of members’ personal information due to hacking, computer viruses, or similar threats, the Company conducts continuous monitoring. In preparation for unforeseen incidents, the Company periodically backs up personal information and regularly manages antivirus programs to prevent infringement of personal information.
4) The Company takes all necessary measures to ensure the security of a systematically structured database system that processes personal information.
② Administrative Safeguards
1) The Company limits access to members’ personal information to the minimum number of personnel necessary and establishes, implements, and enforces an internal management plan. Personnel granted such minimum access include the following:
▶︎ Individuals who directly perform marketing, event operations, or customer support for members (including employees of entrusted service providers and partner companies)
▶︎ Individuals responsible for personal information protection, including the Chief Privacy Officer
▶︎ Individuals for whom the processing of personal information is unavoidable in the course of their duties
2) The Company provides periodic training to personnel handling personal information and to entrusted service providers regarding personal information protection obligations, thereby emphasizing compliance with this Policy.
3) The Company establishes and manages personal information processing guidelines through a dedicated department responsible for personal information protection. In addition, the Company regularly reviews compliance with internal regulations and makes prompt corrections where any issues are identified.
③ Physical Safeguards
1) The Company maintains separate physical storage locations for personal information systems in which personal information is stored and establishes and operates access control procedures for such locations.
2) Documents, auxiliary storage media, and other materials containing personal information are stored in secure locations equipped with locking devices.
The Company collects and uses behavioral information, including advertising identifiers and analytics software, to provide members with more customized, suitable, and useful services and to improve overall service quality.
① Collection and Use of Behavioral Information
▶︎ The Company does not collect sensitive behavioral information that may significantly infringe upon the user's rights, interests, or privacy, such as thoughts, beliefs, or medical history.
② Advertising identifiers, such as Android and Apple advertising IDs, are non-permanent and non-personal identifiers. Users may opt out of the use of advertising identifiers for interest-based advertising or reset such identifiers by changing their device settings. Advertising identifiers are not linked to personal information and are not used to identify individuals. Users may refuse the collection of advertising identifiers on their devices through the following paths.
▶︎ For Android devices: [Settings → Privacy → Ads → Delete or Reset Advertising ID]
▶︎ For iOS devices: [Settings → Privacy & Security → Tracking → Allow Apps to Request to Track (Off)]
1) During the use of the services, the following information is automatically generated and collected.
▶︎ Advertising identifiers (ADID/IDFA); device information (OS type and version, model name, language, device ID); IP address; access records; service use records; and user interaction data (invitations, gifts).
③ To ensure the stable provision of services, the Company uses software from various external partners related to analytics and advertising. Such partners may access members’ data and operate in accordance with their own privacy policies. For detailed information on data processing methods, please refer to the privacy policies of the respective partners.
④ California Residents' Right to Opt Out of Sharing. Certain advertising and analytics partners identified above may process your device and behavioral information in a manner that may be considered "sharing" for cross-context behavioral advertising purposes under California law. If you are a California resident, you may opt out of such sharing by adjusting your device's advertising identifier settings as described above, or by contacting us at support@hyperrise.kr.
⑤ The Company does not use cookies for the provision of its services.
① To protect members’ personal information and handle complaints related to personal information, the Company has designated a Chief Privacy Officer as follows.
▶︎ Chief Privacy Officer
- Department and Position: Development Division / Team Lead
- Name: Geun-yong Cho
- Phone: +82-53-215-0701
- Email: support@hyperrise.kr
▶︎ Privacy Protection Department
- Department: Information Security Team
- Phone: +82-53-215-0701
- Email: support@hyperrise.kr
▶︎ Inquiries and Complaints
- Department: Operations Team(Customer Service Center)
- Phone: +82-53-215-0701
- Email: support@hyperrise.kr
Supplementary Provisions
This Policy shall take effect on August 19, 2026.