Article 1 (Items Collected and Methods)
The Company collects the following personal information in the course of membership registration, service use, payment, and customer inquiries. The Company does not direct its service to children under 14, and children under 14 may not register without the consent of a legal representative.
Items collected
- Required: email address, nickname, profile image (provided by the relevant provider upon social login)
- Optional: phone number, date of birth / At payment: payment method information and transaction records (full card numbers are not stored by the Company and are handled by the payment gateway)
- Collected automatically: IP address, cookies, device information (OS, browser), service usage records, access logs, records of abusive use
Collection methods
- Social login (Google, Apple, Kakao) or email sign-up
- Automatic collection during service use
- Direct entry when submitting a customer inquiry
Article 2 (Purposes of Collection and Use)
The Company uses the collected personal information only for the following purposes, and where a purpose changes, it provides prior notice and obtains consent.
| Items collected | Purpose of use |
|---|---|
| Email, nickname | Member identification, service provision, customer support |
| Payment information | Processing payments for paid content and handling refunds |
| Device / access information | Improving service quality, strengthening security, preventing misuse |
| Email (only where marketing consent is given) | Sending advertising information such as new sheet music and events. Sent only with prior consent under Article 50 of the Network Act, and consent can be withdrawn at any time under My Page > Settings |
Article 3 (Retention and Destruction)
The Company destroys users' personal information without delay once the purpose of collection has been achieved or the retention period has elapsed. However, where applicable law requires retention for a certain period, the information is stored separately for that period.
- Destroyed immediately upon membership withdrawal (stored separately for the relevant period where there is a statutory retention obligation)
- Act on E-Commerce: records of contracts and withdrawal of subscription for 5 years; records of payment and supply of goods for 5 years; records of consumer complaints and dispute handling for 3 years; records of labelling and advertising for 6 months
- Protection of Communications Secrets Act: service usage records (access logs) for 3 months
Article 4 (Provision to Third Parties)
The Company provides personal information to third parties only where Article 17 or 18 of PIPA applies, such as with the data subject's consent or under a special provision of law. Where a vendor performs work on the Company's behalf (payment processing, hosting, etc.), this constitutes entrustment of processing under Article 7 below, not provision to a third party.
- Where there is a request made under procedures prescribed by law, pursuant to law or for investigative purposes
- Where a purchase of sheet music or a lesson occurs, the minimum scope necessary for settlement, tax accounting, and handling copyright disputes (purchase date, product name, amount, buyer identifier) is provided to the selling artist
Article 5 (Rights of Users)
Data subjects may at any time request access to, correction, deletion, suspension of processing of, and transmission of their personal information. Such rights may be exercised in writing, by email, or by other means under Article 41(1) of the Enforcement Decree of PIPA, and the Company will act on such requests without delay.
- Access, correction, deletion, suspension of processing: edit directly under My Page > Settings, or request through customer support (contact@firstchorus.art)
- Right to data portability: users may request that their personal information (member profile, purchase and download history) be transmitted to them or to another controller in JSON or CSV format; the Company processes such requests within 10 business days and reports the transmission record back to the requester
- For children under 14, a legal representative may exercise these rights on the child's behalf; the Company verifies that the requester is the data subject or a duly authorised representative before processing
- The Company does not make automated decisions that significantly affect data subjects (Article 37-2 of PIPA), such as credit or eligibility scoring. Recommendation and search ranking of sheet music does not fall within this category
Article 6 (Personal Information Protection Officer)
The Company takes overall responsibility for matters related to the processing of personal information and has designated a Personal Information Protection Officer as below to handle user complaints and remedy damages related to personal information processing.
Article 7 (Entrustment of Processing and Overseas Transfer)
To provide the Service smoothly, the Company entrusts the processing of personal information as set out below. When entering into an entrustment agreement, the Company specifies in writing — pursuant to Article 26 of PIPA — the prohibition on processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on sub-entrustment, and liability including damages, and supervises the processor.
| Processor | Entrusted work | Items processed | Country |
|---|---|---|---|
| PortOne Inc. | Payment processing, payment authentication, refunds | Payment method information, transaction records, email | Republic of Korea |
| Supabase Inc. | Database, member authentication, file storage | Member information and information necessary for use of the Service generally | United States |
| Vercel Inc. | Web application hosting | Access logs, IP address, service usage information | United States |
| Resend, Inc. | Sending transactional, settlement, and notification emails, and managing the marketing consent list | Email address, message content | United States |
| PostHog, Inc. | Service usage analytics and improvement (only where analytics cookies are consented to) | Access and usage behaviour, device information, pseudonymised identifier | United States |
| Functional Software, Inc. (Sentry) | Error collection and service reliability | Access information and device information at the time of an error | United States |
| Cloudflare, Inc. | Lesson video streaming (where the lesson service is offered) | Video playback request information, IP address | United States |
If the entrusted work or the processor changes, the Company will disclose the change through this privacy policy without delay.
Article 8 (Operation of and Refusal of Automatic Collection Devices such as Cookies)
The Company uses cookies and similar technologies to maintain login sessions, operate the shopping cart, and analyse service usage. On a first visit, a cookie consent banner allows users to choose separately between necessary and analytics cookies; analytics cookies operate only where consent has been given.
- Necessary cookies: login session, shopping cart, security (CSRF protection). If refused, the Service cannot be used for login or payment
- Analytics cookies: visit statistics and usability improvement (PostHog). Refusing them does not affect use of the Service
- Cookie settings can be changed or refused at any time via the cookie banner at the bottom of the screen or via browser settings (Chrome: Settings > Privacy and security > Cookies / Safari: Preferences > Privacy / Edge: Settings > Cookies and site permissions / Firefox: Settings > Privacy & Security)
- The Company does not collect behavioural information for online targeted advertising, nor does it provide such information to advertising businesses
Article 9 (Procedure and Method of Destruction)
The Company destroys personal information without delay once it becomes unnecessary, for example because the retention period has elapsed or the purpose of processing has been achieved.
- Procedure: personal information for which grounds for destruction have arisen is destroyed with the approval of the Personal Information Protection Officer
- Electronic files: permanently deleted by technical means that make recovery and reproduction impossible
- Paper documents: shredded or incinerated
- Information that must be preserved under applicable law is moved to a separate database or stored in a separate location, and is not used for any purpose other than preservation
Article 10 (Measures to Ensure the Safety of Personal Information)
The Company takes the following administrative, technical, and physical measures to ensure the safety of personal information.
- Administrative: establishment and implementation of an internal management plan, minimisation and training of personnel handling personal information, periodic self-inspection
- Technical: access control for the personal information processing system (row-level security), retention and tamper-protection of access records, encrypted storage and transmission of passwords and payment-related information (HTTPS/TLS), anti-malware and security updates
- Physical: access control over the cloud infrastructure where personal information is stored (including the physical security of processors' data centres)
- Sensitive payment credentials such as card numbers are not stored on the Company's servers and are handled by the payment gateway (PortOne)
Article 11 (Department Receiving and Handling Access Requests)
Data subjects may file a request to access personal information under Article 35 of PIPA with the department below. The Company endeavours to process access requests promptly.
Article 12 (Remedies for Infringement of Rights)
Data subjects may apply to the following bodies for dispute resolution or consultation in order to obtain relief for infringement of personal information. Where a data subject objects to a disposition by the Company under Articles 35, 36, or 37 of PIPA, an administrative appeal may be filed under the Administrative Appeals Act.
- Personal Information Dispute Mediation Committee · 1833-6972 · www.kopico.go.kr
- Personal Information Infringement Report Centre (KISA) · 118 · privacy.kisa.or.kr
- Supreme Prosecutors' Office · 1301 · www.spo.go.kr
- National Police Agency · 182 · ecrm.police.go.kr
Revision history
- January 1, 2026 — Initial version
- August 5, 2026 — Added entrustment and overseas transfer disclosures, cookie operation and refusal methods, destruction procedure, safety measures, department receiving access requests, remedies for infringement of rights, and the right to data portability (to reflect the mandatory items under Article 30 of PIPA)