개인정보 처리방침

[ 꼼실포토 ] | 서비스명: Pixel Air (픽셀에어)

공고일: 2026년 8월 5일 | 시행일: 2026년 8월 12일 | 버전: v1.1

[ 꼼실포토 ](이하 "회사")는 개인정보보호법 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 다음과 같이 개인정보 처리방침을 수립·공개합니다.

제1조 (총칙 및 적용 범위)

① 회사는 "Pixel Air(픽셀에어)"라는 명칭으로, AI 안면인식 기술을 활용하여 행사 현장에서 촬영된 사진을 참가자 개인에게 자동 분류·전송하는 서비스(이하 "서비스")를 제공합니다. "Pixel Air"는 회사가 제공하는 서비스의 명칭이며, 본 처리방침상 권리·의무의 주체는 회사입니다.

② 회사는 서비스 운영 과정에서 취급하는 개인정보를 관련 법령 및 본 처리방침에 따라 적법하게 처리하며, 정보주체의 개인정보와 권익을 보호합니다.

③ 회사는 행사 주최사로부터 개인정보 처리 업무를 위탁받아 수행하는 수탁사이며, 본 서비스와 관련한 개인정보처리자는 각 행사 주최사입니다.

④ 본 처리방침은 개인정보보호법 제26조 제8항에 따라 수탁자에게 준용되는 같은 법 제30조에 근거하여, 회사가 수탁사로서 실제 수행하는 개인정보 처리의 내용을 정보주체가 직접 확인할 수 있도록 수립·공개하는 것입니다. 정보주체에 대한 고지·동의 및 권리 행사의 1차적 주체는 각 행사 주최사이며, 그 처리 기준은 주최사의 개인정보 처리방침 및 위탁계약에 따릅니다.

⑤ 본 처리방침은 회사가 운영하는 참가자용 웹 페이지(QR 동의·등록 페이지, 사진 수령 갤러리 페이지) 및 관련 처리 시스템에서 이루어지는 개인정보 처리에 적용됩니다.

제2조 (수집하는 개인정보 항목 및 처리 목적)

회사는 행사 주최사로부터 위탁받아 다음의 개인정보를 수집·처리합니다.

일반 개인정보성명, 이메일 주소, 휴대폰 번호 중 참가자가 선택한 사진 수신 수단에 해당하는 항목
민감정보사진의 분류 및 전송을 위하여 참가자가 등록한 얼굴 사진(이하 "등록 사진") 및 등록 사진에서 추출한 안면 특징값
사진 파일행사 현장에서 촬영된 사진 중 사진 매칭 및 참가자 전송을 위하여 회사 시스템에 업로드된 파일(얼굴 이미지 포함)
접속 기록참가자용 웹 페이지 이용 시 자동으로 생성되는 IP 주소, 접속 일시, 브라우저 정보. 이 중 동의 시점의 접속 기록은 동의 사실의 입증을 위하여 전자 동의 기록의 일부로 보존됩니다.
처리 목적AI 안면인식 기반 개인별 사진 자동 분류, 베스트 컷 선별(눈감음·흔들림·노출과다 필터링), 본인 사진 전송, 동의 사실의 기록 및 입증, 서비스 이용 관련 문의 응대
처리 형태개인정보보호법 제26조에 따른 위탁 처리이며, 개인정보처리자는 각 행사 주최사입니다.
법적 근거개인정보보호법 제15조 제1항 제1호, 제23조 제1항 제1호(정보주체의 별도 동의), 제26조

제3조 (개인정보의 보유 및 이용 기간)

① 회사는 다음의 기간 동안 개인정보를 보유하며, 기간이 만료되면 지체 없이 파기합니다.

구분보유기간사유
참가자 일반 개인정보 (성명·연락처)행사 종료일로부터 30일위탁계약 및 정보주체의 동의
등록 사진행사 종료일로부터 30일미전송 사진의 재전송 요청 처리 등 서비스 완결에 필요한 기간 (위탁계약 및 정보주체의 동의)
안면 특징값 (민감정보)사진 전송 완료 즉시 파기를 원칙으로 함. 다만 사진의 재전송 및 미전송 요청 처리 등 서비스 완결을 위해 행사 종료일로부터 최대 30일간 보유할 수 있으며, 해당 기간 만료 즉시 파기개인정보보호법 제21조·제23조
행사 촬영 사진 (시스템 업로드 파일)행사 종료일로부터 30일미전송 사진의 재전송 요청 처리 등 서비스 완결에 필요한 기간 (위탁계약)
전자 동의 기록 (일시·IP·동의 항목)동의일로부터 5년상법 제64조에 따른 상사시효 및 동의 사실의 입증
참가자 페이지 접속 기록행사 종료일로부터 30일서비스 운영 및 보안 목적의 자체 보존 기준

② 정보주체가 개인정보의 삭제 또는 동의 철회를 요청한 경우, 회사는 제1항의 기간에 관계없이 해당 정보를 지체 없이 파기합니다.

제4조 (개인정보의 파기)

① 회사는 개인정보의 보유기간이 경과하거나 처리 목적이 달성된 경우, 해당 개인정보를 지체 없이 파기합니다.

② 파기 대상과 방법은 다음과 같습니다.

안면 특징값안면인식 처리 시스템의 삭제 기능을 통하여 해당 특징값을 삭제합니다.
이미지 파일등록 사진, 시스템에 업로드된 행사 촬영 사진, 썸네일 및 전송용 압축파일을 저장소의 삭제 기능을 통하여 삭제합니다.
데이터베이스 저장 정보성명·연락처 등 데이터베이스에 저장된 개인정보 내역을 삭제합니다.
종이 문서현장에서 서면 형태의 동의서 등을 수령한 경우, 분쇄기로 분쇄하거나 소각하여 파기합니다.

③ 제2항에 따라 파기된 개인정보는 회사의 서비스 및 운영 시스템에서 조회하거나 복구할 수 없습니다.

④ 회사는 파기 일시, 파기 대상 항목 및 처리자를 기록한 파기 이력을 보존하며, 행사 주최사의 요청이 있는 경우 파기 결과를 확인할 수 있는 자료를 제공합니다.

⑤ 법령에 따라 보존 의무가 있는 정보는 해당 기간 동안 다른 개인정보와 분리하여 보관한 후 파기합니다.

제5조 (민감정보(생체인식정보)의 처리)

⚠ 안면 특징값은 개인정보보호법 시행령 제18조에 따른 생체인식정보로서 민감정보에 해당합니다. 회사는 정보주체로부터 일반 개인정보와 별도로 명시적 동의를 받은 경우에 한하여 이를 처리합니다.

① 회사의 안면인식 처리 방식은 다음과 같습니다.

특징값 추출 대상참가자의 사진분류 및 전송을 위해 등록한 얼굴 사진(등록 사진)
검색 방식등록 사진에서 추출한 안면 특징값을 사용하여 행사 현장에서 촬영된 사진에서 해당 참가자가 포함된 사진을 찾습니다.
저장되는 특징값의 범위저장되는 안면 특징값은 서비스 이용에 동의하고 얼굴 사진을 등록한 참가자의 것에 한정됩니다. 행사 현장 촬영 사진 속 얼굴의 대조값은 검색 과정에서 일시적으로 생성되나 저장되지 않으며, 검색 완료 즉시 소멸합니다.
처리 목적개인별 사진 자동 분류, 베스트 컷 선별, 본인 사진 전송
처리 기술Amazon Web Services Rekognition
저장 위치AWS 서울 리전 (ap-northeast-2). 국내에서만 처리·보관하며 국외로 이전하지 않습니다.
암호화저장 시 AES-256 서버 측 암호화, 전송 구간 TLS 1.2 이상 적용
제3자 제공AWS는 위탁 처리에 한하며 해당 데이터를 다른 목적으로 이용하지 않습니다.
파기 시점본 처리방침 제3조 및 제4조에 따릅니다.

② 회사는 안면 특징값을 개인별 사진 분류 및 전송 목적 외의 용도로 이용하지 않으며, 다른 행사 또는 다른 참가자의 검색에 재사용하지 않습니다.

③ 회사는 안면 특징값의 처리에 동의하지 않은 참가자로부터 얼굴 사진을 수집하지 아니하며, 그 안면 특징값을 저장·보관하지 않습니다.

제6조 (사진의 서비스 소개 목적 활용)

① 회사가 행사 촬영 사진을 회사의 서비스 소개 목적으로 활용하는 경우, 정보주체의 별도 선택 동의 및 행사 주최사의 사전 서면 동의를 모두 받은 경우에 한하여 이루어지며, 동의하지 않더라도 사진 전송 서비스 이용에 어떠한 불이익도 없습니다.

활용 범위서비스 소개 자료, 제안서, 홈페이지, 온라인 채널 등 홍보자료로 활용합니다.
보유 기간동의일로부터 최대 2년 또는 동의 철회 시까지 중 먼저 도래하는 시점까지
동의 철회 창구pixelair.co@gmail.com

② 본 조의 활용 동의는 언제든지 철회할 수 있으며, 철회 요청 시 회사는 해당 사진의 추가 활용을 즉시 중단하고 보유 중인 해당 사진을 파기합니다. 다만 철회 이전에 이미 배포·게시된 자료의 회수는 기술적·물리적으로 불가능할 수 있으며, 이는 정보주체의 철회권을 제한하는 것이 아니라 이미 완료된 배포 행위의 특성에 따른 것입니다.

③ 행사 주최사가 자체적인 홍보·아카이빙 목적으로 행사 사진을 활용하는 것은 개인정보처리자인 행사 주최사의 처리 영역으로서 본 처리방침의 적용 대상이 아니며, 해당 주최사의 개인정보 처리방침 및 참가 안내에 따릅니다.

제7조 (개인정보 처리의 위탁)

① 회사는 서비스 운영을 위하여 다음과 같이 개인정보 처리 업무를 위탁하고 있습니다.

수탁사위탁 업무
Amazon Web Services (AWS Korea LLC)AI 사진분류 및 전송
Railsware Products Studio LLC (Mailtrap)사진 수령 안내 이메일 발송
솔라피 주식회사 (SOLAPI)사진 수령 안내 문자(SMS) 발송

② 회사는 위탁계약 체결 시 개인정보보호법 제26조에 따라 목적 외 처리 금지, 안전성 확보 조치, 재위탁 제한, 수탁자에 대한 관리·감독 및 손해배상 등에 관한 사항을 문서에 명시하고, 수탁사가 이를 준수하는지 감독합니다.

③ 회사가 행사 주최사로부터 위탁받은 업무를 제1항의 수탁사에 재위탁하는 경우, 개인정보보호법 제26조 제6항에 따라 주최사의 사전 동의를 받습니다.

④ 위탁 업무의 내용이나 수탁사가 변경될 경우, 회사는 본 처리방침을 통하여 지체 없이 공개합니다.

제8조 (개인정보의 국외 이전)

① 회사는 참가자에 대한 사진 수령 안내를 발송하기 위하여 아래와 같이 개인정보를 국외로 이전하고 있습니다. 본 이전은 개인정보보호법 제28조의8 제1항 제3호에 따라 계약의 이행 및 정보주체 편의 증진을 위하여 필요한 처리위탁에 해당하며, 같은 조 제2항 각 호의 사항을 다음과 같이 공개합니다.

이전받는 자Railsware Products Studio LLC (서비스명: Mailtrap) | 연락처: support@mailtrap.io
이전되는 국가미국 (델라웨어주 법인, 사업장: 캘리포니아주 패서디나)
이전 시기 및 방법참가자에게 사진 수령 안내 이메일(발신 주소: noreply@pixel-air.com)을 발송하는 시점에, 정보통신망을 통하여 암호화된 상태로 전송
이전되는 항목수신자 성명, 이메일 주소
이전받는 자의 이용 목적참가자 본인에 대한 사진 수령 안내 이메일의 발송
이전받는 자의 보유·이용 기간발송 처리 완료 시까지. 다만 발송 이력은 해당 서비스 제공자의 정책에 따라 일정 기간 보관될 수 있습니다.
이전 거부 방법정보주체는 pixelair.co@gmail.com으로 국외 이전 거부 의사를 통지하실 수 있으며, 회사는 통지를 받은 즉시 해당 정보주체의 이메일 주소를 국외 이전 대상에서 제외합니다.

② 제1항에 따라 국외 이전을 거부하시는 경우 이메일을 통한 사진 수령은 불가능합니다. 다만 문자(SMS) 등 국내에서만 처리되는 다른 수신 수단을 선택하실 수 있으며, 이 경우에도 사진 수령 서비스는 정상적으로 이용하실 수 있습니다.

③ 문자(SMS) 발송을 위한 개인정보는 국내 사업자인 솔라피 주식회사를 통하여 국내에서만 처리되며, 국외로 이전되지 않습니다.

④ 안면 특징값 및 사진 파일은 AWS 서울 리전(ap-northeast-2)에서만 처리·보관되며 국외로 이전되지 않습니다.

제9조 (개인정보의 제3자 제공)

① 회사는 정보주체의 개인정보를 제3자에게 제공하지 않습니다. 다만 다음 각 호 및 제2항의 경우는 예외로 합니다.

1. 정보주체가 사전에 별도로 동의한 경우

2. 법령에 특별한 규정이 있거나, 수사 목적으로 법령에 정해진 절차와 방법에 따라 수사기관의 요구가 있는 경우

② 행사 사진의 특성상 여러 참가자가 함께 촬영되는 경우가 대부분입니다. 이에 따라 각 참가자에게 본인이 포함된 사진을 전송하는 과정에서, 해당 사진에 함께 촬영된 다른 참가자의 얼굴 이미지가 포함될 수 있습니다. 회사는 본인 외의 참가자가 식별 가능한 형태로 포함된 사진의 전송을 최소화하기 위한 촬영 단계의 조치를 취하고 있습니다.

③ 제2항에 따른 제공에 있어 제공받는 자는 해당 사진에 함께 촬영된 다른 참가자이고, 제공되는 항목은 사진에 포함된 얼굴 이미지이며, 제공 목적은 서비스를 이용하고자 하는 참가자의 사진 전송입니다. 참가자의 단말기로 전송이 완료된 이후에는 해당 수신 참가자가 사진을 보유하며, 회사는 이에 관여하지 않습니다.

④ 촬영 자체를 원하지 않는 참가자 또는 본인이 포함된 사진의 전송 제외를 원하는 참가자는 행사 주최사 또는 회사에 요청하실 수 있으며, 회사는 요청을 받은 즉시 해당 사진을 전송 대상에서 제외합니다.

⑤ 회사가 수탁사로서 처리하는 행사 참가자 정보는 제1항부터 제4항까지에 정한 경우 이외에 제3자에게 제공하지 않으며, 이를 판매하거나 광고 목적으로 이용하지 않습니다.

제10조 (정보주체의 권리·의무 및 행사 방법)

① 정보주체는 다음과 같은 권리를 행사할 수 있습니다.

열람 요구수집된 개인정보 및 민감정보의 처리 현황과 내용의 확인을 요구할 수 있습니다.
정정·삭제 요구부정확한 정보의 수정 또는 불필요한 정보의 삭제를 요구할 수 있습니다.
처리 정지 요구개인정보 처리의 정지를 요구할 수 있습니다.
동의 철회언제든지 동의를 철회할 수 있으며, 철회 요청 시 회사가 보유 중인 개인정보 및 안면 특징값을 지체 없이 파기합니다. 다만 이미 참가자 본인에게 전송이 완료된 사진은 참가자 본인의 단말기에 전달된 것으로 기술적으로 회수가 불가능합니다. 이는 정보주체의 동의 철회권을 제한하는 것이 아니라, 이미 완료된 전송 행위의 기술적 특성에 따른 것입니다.
손해배상 청구개인정보 침해로 손해가 발생한 경우 피해 구제를 신청할 수 있습니다.

② 권리 행사는 다음의 방법으로 요청하실 수 있습니다.

접수 창구이메일 pixelair.co@gmail.com 로 제출
처리 기간접수일로부터 10일 이내 (부득이한 사유가 있는 경우 10일 범위에서 연장하며, 그 사유를 통보합니다)
대리인에 의한 행사법정대리인 또는 위임을 받은 자를 통하여 행사할 수 있으며, 이 경우 위임 사실을 확인할 수 있는 서류를 제출하여야 합니다.

③ 행사 참가자의 개인정보에 관한 열람·정정·삭제·처리정지 요구는 개인정보처리자인 해당 행사 주최사에도 하실 수 있습니다. 회사에 접수된 요구는 수탁사로서 지체 없이 처리하며, 필요한 경우 해당 주최사에 통보합니다.

④ 정보주체는 관련 법령을 준수하여야 하며, 타인의 개인정보를 침해하거나 허위의 정보를 제공하여서는 안 됩니다.

제11조 (만 14세 미만 아동의 개인정보 처리)

① 회사는 만 14세 미만 아동의 개인정보를 처리하는 경우, 개인정보보호법 제22조의2에 따라 법정대리인의 동의를 받습니다.

② 법정대리인의 동의가 확인되지 않은 경우 해당 아동에 대해서는 서비스를 제공하지 않으며, 이미 수집된 정보가 있는 경우 지체 없이 파기합니다.

③ 만 14세 미만 아동의 참가가 예상되는 행사의 경우, 회사는 행사 주최사와 사전에 법정대리인 동의 절차를 협의합니다.

제12조 (개인정보의 안전성 확보 조치)

회사는 개인정보보호법 제29조 및 같은 법 시행령 제30조에 따라 개인정보의 안전성 확보를 위하여 다음의 조치를 취하고 있습니다.

관리적 조치개인정보 내부관리계획 수립 및 시행, 개인정보취급자 인원 최소화 및 교육
기술적 조치전송 구간 암호화(TLS 1.2 이상), 저장 데이터의 AES-256 서버 측 암호화, 접근 권한 관리 및 제한
물리적 조치개인정보가 저장된 업무용 기기 및 저장매체를 안전한 장소에 보관 및 접근 통제
접속기록 관리개인정보처리시스템의 접속기록을 관련 고시에서 정하는 기간 이상 보관

제13조 (자동 수집 장치의 설치·운영)

① 본 조는 회사가 운영하는 참가자용 웹 페이지(QR 동의·등록 페이지, 사진 수령 갤러리 페이지)에 적용됩니다.

② 회사는 참가자용 웹 페이지에서 쿠키(cookie)를 비롯한 개인정보 자동 수집 장치를 설치·운영하지 않습니다.

③ 향후 자동 수집 장치를 도입하는 경우, 회사는 그 목적·수집 항목 및 거부 방법을 본 처리방침에 반영하여 사전에 공개합니다.

제14조 (사업자 정보 및 개인정보 보호책임자)

① 본 처리방침상 개인정보 처리에 관한 권리·의무의 주체인 사업자 정보는 다음과 같습니다.

상호[ 꼼실포토 ]
대표자[ 윤은실 ]
사업자등록번호[ 594-30-01670 ]
서비스명Pixel Air (픽셀에어)

② 회사는 개인정보 처리에 관한 업무를 총괄하여 책임지고 정보주체의 불만 처리 및 피해 구제를 담당하는 개인정보 보호책임자를 다음과 같이 지정하고 있습니다.

개인정보 보호책임자성명: 윤은실 / 직책: 대표
연락처전화: [070-8098-9202 ] | 이메일: pixelair.co@gmail.com

③ 정보주체는 서비스를 이용하면서 발생한 모든 개인정보 보호 관련 문의, 불만 처리 및 피해 구제에 관한 사항을 개인정보 보호책임자에게 문의하실 수 있으며, 회사는 지체 없이 답변하고 처리해드릴 것입니다.

제15조 (개인정보 침해 신고 및 권익 구제 방법)

정보주체는 개인정보 침해로 인한 구제를 받기 위하여 다음의 기관에 도움을 요청할 수 있습니다.

기관명담당 업무연락처
개인정보보호위원회개인정보 침해 신고 및 정책 문의www.pipc.go.kr 국번없이 182
개인정보 분쟁조정위원회개인정보 분쟁 조정 신청www.kopico.go.kr 1833-6972
한국인터넷진흥원(KISA)개인정보 침해 신고 상담privacy.kisa.or.kr 국번없이 118
대검찰청 사이버수사과사이버 범죄 신고www.spo.go.kr 1301
경찰청 사이버수사국사이버 범죄 신고ecrm.cyber.go.kr 국번없이 182

제16조 (개인정보 처리방침의 변경)

① 본 처리방침은 시행일로부터 적용되며, 법령 및 방침의 변경 사유에 따라 내용이 변경될 수 있습니다.

② 회사는 처리방침을 변경하는 경우 시행 7일 전부터 참가자용 웹 페이지 및 행사 주최사를 통하여 고지합니다. 다만 정보주체의 권리에 중대한 변경이 있는 경우에는 시행 30일 전부터 고지합니다.

③ 이전 버전의 처리방침은 제14조의 연락처로 요청하시면 제공해 드립니다.

개정 이력

버전시행일
v1.02026년 5월 1일
v1.12026년 8월 12일

본 처리방침은 개인정보보호법 제30조에 따라 수립·공개되었으며, 회사의 개인정보동의서 및 개인정보 처리 위탁계약서와 함께 적용됩니다.

본 처리방침은 개인정보보호법 제30조에 따라 공개됩니다.
문의 pixelair.co@gmail.com

Privacy Policy

[ Kkomsil Photo ] | Service name: Pixel Air

Published: 5 August 2026 | Effective: 12 August 2026 | Version: v1.1

[ Kkomsil Photo ] (the "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act ("PIPA") of the Republic of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly and effectively.

This English text is a reference translation provided for the convenience of readers. The Korean version is the official text; in the event of any discrepancy, the Korean version prevails.

Article 1 (General Provisions and Scope of Application)

① The Company provides a service under the name "Pixel Air" that uses AI facial recognition technology to automatically sort photographs taken at an event venue and deliver them to individual participants (the "Service"). "Pixel Air" is the name of the service provided by the Company; the holder of the rights and obligations under this Privacy Policy is the Company.

② The Company processes the personal information it handles in the course of operating the Service lawfully and in accordance with applicable laws and this Privacy Policy, and protects the personal information and interests of data subjects.

③ The Company acts as a processor entrusted by the event host with personal information processing duties. The personal information controller in respect of the Service is the host of each event.

④ This Privacy Policy is established and disclosed pursuant to Article 30 of PIPA, as applied mutatis mutandis to entrusted processors under Article 26(8) of the same Act, so that data subjects may directly review the personal information processing actually carried out by the Company as a processor. The primary party responsible for notice, consent and the exercise of rights vis-à-vis data subjects is the host of each event, and the applicable standards are set out in that host's privacy policy and in the data processing agreement.

⑤ This Privacy Policy applies to personal information processing carried out on the participant-facing web pages operated by the Company (the QR consent and registration page and the photo retrieval gallery page) and in the related processing systems.

Article 2 (Categories of Personal Information Collected and Purposes of Processing)

As entrusted by the event host, the Company collects and processes the following personal information.

General personal informationAmong the participant's name, email address and mobile telephone number, the items corresponding to the delivery method selected by the participant
Sensitive informationThe facial photograph registered by the participant for the purpose of sorting and delivering photographs (the "Registered Photograph") and the facial feature vector extracted from that Registered Photograph
Photograph filesAmong the photographs taken at the event venue, the files uploaded to the Company's system for matching and delivery to participants (including facial images)
Access logsIP address, access date and time, and browser information generated automatically when the participant-facing web pages are used. Access logs recorded at the time of consent are retained as part of the electronic consent record for the purpose of evidencing that consent.
Purposes of processingAutomatic per-person photograph sorting based on AI facial recognition; best-shot selection (filtering of closed eyes, motion blur and overexposure); delivery of the participant's own photographs; recording and evidencing of consent; and responding to enquiries relating to use of the Service
Nature of processingEntrusted processing under Article 26 of PIPA. The personal information controller is the host of each event.
Legal basisPIPA Article 15(1)1, Article 23(1)1 (separate consent of the data subject), and Article 26

Article 3 (Retention and Use Period)

① The Company retains personal information for the periods set out below and destroys it without delay upon expiry of the applicable period.

CategoryRetention periodBasis
Participant general personal information (name, contact details)30 days from the end date of the eventData processing agreement and consent of the data subject
Registered Photograph30 days from the end date of the eventThe period necessary to complete the Service, including handling of re-delivery requests for undelivered photographs (data processing agreement and consent of the data subject)
Facial feature vector (sensitive information)Destroyed immediately upon completion of photograph delivery as a matter of principle. It may, however, be retained for up to 30 days from the end date of the event in order to complete the Service, including handling of re-delivery and non-delivery requests, and is destroyed immediately upon expiry of that period.PIPA Articles 21 and 23
Event photographs (files uploaded to the system)30 days from the end date of the eventThe period necessary to complete the Service, including handling of re-delivery requests for undelivered photographs (data processing agreement)
Electronic consent records (timestamp, IP address, consent items)5 years from the date of consentThe five-year commercial limitation period under Article 64 of the Commercial Act, and evidencing of consent
Participant page access logs30 days from the end date of the eventThe Company's own retention standard for service operation and security purposes

② Where a data subject requests deletion of personal information or withdraws consent, the Company destroys the relevant information without delay, regardless of the periods set out in paragraph ①.

Article 4 (Destruction of Personal Information)

① Where the retention period has elapsed or the purpose of processing has been achieved, the Company destroys the personal information concerned without delay.

② The subjects and methods of destruction are as follows.

Facial feature vectorsDeleted using the deletion function of the facial recognition processing system.
Image filesRegistered Photographs, event photographs uploaded to the system, thumbnails and delivery archive files are deleted using the deletion function of the storage service.
Information stored in databasesPersonal information records stored in databases, such as names and contact details, are deleted.
Paper documentsWhere consent forms or similar documents have been received in paper form at the venue, they are destroyed by shredding or incineration.

③ Personal information destroyed under paragraph ② cannot be retrieved or restored from the Company's Service or operational systems.

④ The Company maintains a destruction record noting the date and time of destruction, the items destroyed and the person responsible, and provides materials evidencing the outcome of destruction upon request by the event host.

⑤ Information subject to a statutory retention obligation is stored separately from other personal information for the applicable period and is then destroyed.

Article 5 (Processing of Sensitive Information — Biometric Information)

⚠ Facial feature vectors constitute biometric information under Article 18 of the Enforcement Decree of PIPA and are therefore sensitive information. The Company processes them only where it has obtained the data subject's explicit consent, given separately from consent to the processing of general personal information.

① The Company's facial recognition processing operates as follows.

Source of feature extractionThe facial photograph registered by the participant for photograph sorting and delivery (the Registered Photograph)
Search methodThe facial feature vector extracted from the Registered Photograph is used to locate, among the photographs taken at the event venue, those in which that participant appears.
Scope of stored feature vectorsStored facial feature vectors are limited to those of participants who have consented to use of the Service and registered a facial photograph. Comparison values derived from faces appearing in event photographs are generated transiently during the search process, are not stored, and cease to exist immediately upon completion of the search.
Purposes of processingAutomatic per-person photograph sorting, best-shot selection, and delivery of the participant's own photographs
Processing technologyAmazon Web Services Rekognition
Storage locationAWS Seoul Region (ap-northeast-2). Processed and stored solely within the Republic of Korea and not transferred abroad.
EncryptionAES-256 server-side encryption at rest; TLS 1.2 or higher in transit
Provision to third partiesAWS acts solely as an entrusted processor and does not use the data for any other purpose.
Time of destructionAs provided in Articles 3 and 4 of this Privacy Policy.

② The Company does not use facial feature vectors for any purpose other than per-person photograph sorting and delivery, and does not reuse them for other events or for searches relating to other participants.

③ The Company does not collect facial photographs from participants who have not consented to the processing of facial feature vectors, and does not store or retain their facial feature vectors.

Article 6 (Use of Photographs for Service Promotion)

① Where the Company uses event photographs for the purpose of introducing or promoting its Service, it does so only where it has obtained both the separate optional consent of the data subject and the prior written consent of the event host. Declining to give such consent results in no disadvantage whatsoever in relation to use of the photograph delivery service.

Scope of useUse in service introduction materials, proposals, the website and online channels and other promotional materials.
Retention periodUntil the earlier of two years from the date of consent or the withdrawal of consent
Channel for withdrawal of consentpixelair.co@gmail.com

② Consent under this Article may be withdrawn at any time. Upon a withdrawal request, the Company immediately ceases any further use of the photograph concerned and destroys the copy it holds. Recovery of materials already distributed or published prior to withdrawal may be technically and physically impossible; this does not limit the data subject's right of withdrawal but reflects the nature of distribution already completed.

③ Use of event photographs by the event host for its own promotional or archival purposes falls within the processing domain of the event host as the personal information controller, is not governed by this Privacy Policy, and is subject to that host's privacy policy and participation notices.

Article 7 (Entrustment of Personal Information Processing)

① For the operation of the Service, the Company entrusts personal information processing duties as follows.

Sub-processorEntrusted duties
Amazon Web Services (AWS Korea LLC)AI photograph sorting and delivery
Railsware Products Studio LLC (Mailtrap)Sending of photograph retrieval notification emails
SOLAPI Co., Ltd.Sending of photograph retrieval notification SMS messages

② When concluding an entrustment agreement, the Company specifies in writing, in accordance with Article 26 of PIPA, matters including the prohibition of processing beyond the stated purpose, safety measures, restrictions on sub-entrustment, supervision of the entrusted party and liability for damages, and supervises the sub-processor's compliance.

③ Where the Company sub-entrusts to a sub-processor listed in paragraph ① duties entrusted to it by an event host, it obtains the host's prior consent in accordance with Article 26(6) of PIPA.

④ Where the content of the entrusted duties or the identity of a sub-processor changes, the Company discloses the change without delay through this Privacy Policy.

Article 8 (Cross-Border Transfer of Personal Information)

① In order to send photograph retrieval notifications to participants, the Company transfers personal information abroad as set out below. This transfer constitutes entrusted processing necessary for the performance of a contract and for the convenience of the data subject under Article 28-8(1)3 of PIPA, and the matters listed in Article 28-8(2) of the same Act are disclosed as follows.

TransfereeRailsware Products Studio LLC (service name: Mailtrap) | Contact: support@mailtrap.io
Country of transferUnited States of America (Delaware corporation; place of business: Pasadena, California)
Timing and method of transferAt the time a photograph retrieval notification email (sender address: noreply@pixel-air.com) is sent to the participant, transmitted in encrypted form over the information and communications network
Items transferredRecipient's name and email address
Transferee's purpose of useSending photograph retrieval notification emails to the participant
Transferee's retention and use periodUntil completion of the sending process. Sending logs may, however, be retained for a certain period in accordance with the service provider's policy.
Method of refusing transferA data subject may notify the Company of a refusal of cross-border transfer at pixelair.co@gmail.com. Upon receipt of such notice, the Company immediately excludes that data subject's email address from cross-border transfer.

② Where a data subject refuses cross-border transfer under paragraph ①, photograph retrieval by email is not possible. The data subject may, however, select another delivery method processed solely within the Republic of Korea, such as SMS, and may in that case continue to use the photograph delivery service without restriction.

③ Personal information used for SMS delivery is processed solely within the Republic of Korea through SOLAPI Co., Ltd., a domestic provider, and is not transferred abroad.

④ Facial feature vectors and photograph files are processed and stored solely in the AWS Seoul Region (ap-northeast-2) and are not transferred abroad.

Article 9 (Provision of Personal Information to Third Parties)

① The Company does not provide the personal information of data subjects to third parties, except in the cases set out in the following subparagraphs and in paragraph ②.

1. Where the data subject has given separate prior consent

2. Where there is a special provision in a statute, or where an investigative authority makes a request for investigative purposes in accordance with the procedures and methods prescribed by statute

② Owing to the nature of event photography, most photographs include several participants together. Accordingly, when a photograph in which a participant appears is delivered to that participant, the facial images of other participants photographed alongside them may be included. The Company takes measures at the photography stage to minimise the delivery of photographs in which persons other than the recipient are included in an identifiable form.

③ In relation to the provision described in paragraph ②, the recipients are the other participants photographed in the same photograph, the item provided is the facial image contained in the photograph, and the purpose of provision is delivery of photographs to participants wishing to use the Service. Once delivery to a participant's device is complete, the receiving participant holds the photograph and the Company has no further involvement.

④ A participant who does not wish to be photographed at all, or who wishes to be excluded from delivery of photographs in which they appear, may make a request to the event host or to the Company. Upon receipt of such a request, the Company immediately excludes the relevant photographs from delivery.

⑤ Except in the cases set out in paragraphs ① through ④, the Company does not provide participant information that it processes as an entrusted processor to any third party, and does not sell it or use it for advertising purposes.

Article 10 (Rights and Obligations of Data Subjects and How to Exercise Them)

① Data subjects may exercise the following rights.

Right of accessTo request confirmation of the status and content of processing of their personal information and sensitive information.
Right to rectification and erasureTo request correction of inaccurate information or deletion of unnecessary information.
Right to suspension of processingTo request that processing of personal information be suspended.
Withdrawal of consentConsent may be withdrawn at any time. Upon a withdrawal request, the Company destroys the personal information and facial feature vectors it holds without delay. Photographs already delivered to the participant have been transmitted to the participant's own device and cannot technically be recovered. This does not limit the data subject's right to withdraw consent but reflects the technical nature of a transmission already completed.
Right to claim damagesTo seek redress where damage has arisen from an infringement of personal information.

② Rights may be exercised by the following means.

Point of contactSubmission by email to pixelair.co@gmail.com
Processing periodWithin 10 days of receipt (where unavoidable grounds exist, this may be extended by up to a further 10 days, with notice of the grounds)
Exercise through an agentRights may be exercised through a legal representative or a duly authorised agent, in which case documentation evidencing the authorisation must be submitted.

③ Requests for access, rectification, erasure or suspension of processing concerning an event participant's personal information may also be made to the relevant event host as the personal information controller. Requests received by the Company are handled without delay in its capacity as an entrusted processor and, where necessary, are notified to the relevant host.

④ Data subjects must comply with applicable laws and must not infringe the personal information of others or provide false information.

Article 11 (Processing of Personal Information of Children Under 14)

① Where the Company processes the personal information of a child under 14 years of age, it obtains the consent of the child's legal representative in accordance with Article 22-2 of PIPA.

② Where the consent of a legal representative is not confirmed, the Company does not provide the Service to the child concerned and destroys without delay any information already collected.

③ For events at which the participation of children under 14 is anticipated, the Company agrees the legal representative consent procedure with the event host in advance.

Article 12 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of PIPA and Article 30 of its Enforcement Decree, the Company takes the following measures to ensure the security of personal information.

Administrative measuresEstablishment and implementation of an internal management plan for personal information; minimisation of the number of personnel handling personal information and provision of training
Technical measuresEncryption in transit (TLS 1.2 or higher), AES-256 server-side encryption of stored data, and management and restriction of access privileges
Physical measuresStorage of business devices and storage media containing personal information in secure locations with access control
Access log managementRetention of access logs of the personal information processing system for at least the period prescribed by the relevant public notice

Article 13 (Installation and Operation of Automatic Collection Devices)

① This Article applies to the participant-facing web pages operated by the Company (the QR consent and registration page and the photo retrieval gallery page).

② The Company does not install or operate cookies or any other device that automatically collects personal information on its participant-facing web pages.

③ Should the Company introduce such a device in future, it will disclose the purpose, the items collected and the means of refusal in advance by reflecting them in this Privacy Policy.

Article 14 (Business Information and Personal Information Protection Officer)

① The business entity holding the rights and obligations relating to personal information processing under this Privacy Policy is as follows.

Business name[ Kkomsil Photo ]
Representative[ Eunsil Yoon ]
Business registration number[ 594-30-01670 ]
Service namePixel Air

② The Company has designated a Personal Information Protection Officer, who has overall responsibility for personal information processing and handles complaints and remedies for data subjects, as follows.

Personal Information Protection OfficerName: Eunsil Yoon / Title: Representative
ContactTel: [ 070-8098-9202 ] | Email: pixelair.co@gmail.com

③ Data subjects may direct all enquiries, complaints and requests for remedy relating to personal information protection arising from use of the Service to the Personal Information Protection Officer, and the Company will respond and act without delay.

Article 15 (Reporting Infringements and Remedies)

Data subjects may seek assistance from the following bodies in order to obtain redress for infringements of personal information.

OrganizationFunctionContact
Personal Information Protection CommissionReporting of personal information infringements and policy enquirieswww.pipc.go.kr | 182 (no area code)
Personal Information Dispute Mediation CommitteeApplications for mediation of personal information disputeswww.kopico.go.kr | 1833-6972
Korea Internet & Security Agency (KISA)Consultation on reports of personal information infringementprivacy.kisa.or.kr | 118 (no area code)
Supreme Prosecutors' Office, Cyber Investigation DivisionReporting of cybercrimewww.spo.go.kr | 1301
National Police Agency, National Office of Investigation (Cyber Bureau)Reporting of cybercrimeecrm.cyber.go.kr | 182 (no area code)

Article 16 (Amendments to This Privacy Policy)

① This Privacy Policy applies from its effective date, and its content may be amended in response to changes in applicable laws or in the Company's policies.

② Where the Company amends this Privacy Policy, it gives notice from 7 days before the effective date through the participant-facing web pages and through event hosts. Where there is a material change affecting the rights of data subjects, notice is given from 30 days before the effective date.

③ Previous versions of this Privacy Policy are available on request using the contact details in Article 14.

Revision history

VersionEffective date
v1.01 May 2026
v1.112 August 2026

This Privacy Policy is established and disclosed pursuant to Article 30 of the Personal Information Protection Act and applies together with the Company's personal information consent form and data processing agreement.

This English text is a reference translation. The Korean version is the official text and prevails in the event of any discrepancy.