Privacy Policy
FactBlock Corp.(“we” or the “Company”) legally processes and safely manages personal information in compliance with the provisions of the Personal Information Protection Act (“PIPA”) and other relevant statutes to protect the freedom and rights of users. Accordingly, in accordance with Article 30 of the PIPA, we implemented and post this Privacy Policy (this “Policy”) in order to guide users to the procedures and standards for processing of personal information and to handle related grievances promptly and smoothly.
Table of Contents
Article 1 (Scope of Collection, Purpose of Use, Retention and Use Period of Personal Information)
Article 2 (Provision of Personal Information to Third Parties)
Article 3 (Entrustment of Personal Information Processing)
Article 4 (Cross-border Transfer of Personal Information)
Article 5 (Procedures and Methods for Destroying Personal Information)
Article 6 (Rights and Duties of Users and Legal Representatives and Methods of Exercising them)
Article 7 (Measures to Ensure Safety of Personal Information)
Article 8 (Privacy Officer)
Article 9 (Methods of Remedy for Infringement of Rights and Interests)
Article 10 (Changes to the Privacy Policy)
Article 1 (Scope of Collection, Purpose of Use, Retention and Use Period of Personal Information)
(1) The Company processes users(“users” or “participants”)' personal information for the following purposes. The personal information to be processed will not be used for any purpose other than the following purposes, and if the purpose of use is changed, necessary measures, such as obtaining a separate consent pursuant to Article 18 of the PIPA, will be implemented:
- Purpose of Use : KBW2026 participant registration and ticket management, event operation, and provision of event-related information and inquiry support(Required)
- Collected Items : Participant's name, email address, affiliation, job title, country of residence and ticket payment details
- Retention and Use Period : Until three years from the end date of KBW2026
- Purpose of Use : Provision of promotional and marketing information regarding KBW2026 and its sponsors, and transmission of advertising information(Optional)
- Collected Items : Participant's name, email address
- Retention and Use Period : Until three years from the end date of KBW2026
(2) Where required to retain personal information under applicable laws and regulations, the Company will retain personal information for the periods specified below even after the purpose of its collection and use has been fulfilled.
- Legal Grounds : Electronic Financial Transactions Act, Art. 22 (1)
- Items Retained : Records related to electronic financial transactions
- Retention Period : 5 years
- Legal Grounds : Act on the Consumer Protection in Electronic Commerce, Art. 6 and its Enforcement Decree Art. 6
- Items Retained : Records of contracts or subscription withdrawals (5 years), Records of payments and the supply of goods (5 years), Records of consumer complaints or dispute handling (3 years), Records on labeling and advertising (6 months)
Article 2 (Provision of Personal Information to Third Parties)
(1) The Company will process users' personal information only within the scope specified in the purpose of processing personal information, and will not provide it to a third party without the user's consent.
(2) The Company provides personal information to third parties for smooth provision of the service as follows:
- Recipient : Dunamu Inc.
- Purpose of Provision : Verifying promotional code eligibility, verifying participants and administering the event, providing event-related notices and responding to inquiries by Dunamu Inc.
- Personal Information Provided : Name, affiliation, job title
- Retention and Use Period : Personal information will be destroyed 30 days after the conclusion of KBW2026. However, where retention is required under applicable laws and regulations, such information will be retained for the period prescribed by such laws and regulations.
- Applicable to : Only for applicants using a promotional code provided by Dunamu Inc.
- Recipient : Seoul Tourism Organization
- Purpose of Provision : Management of KBW2026 support payments
- Personal Information Provided : Name, affiliation, email address and country of residence
- Retention and Use Period : For one year after the end of KBW2026.
(3) The Company may provide personal information to third parties without the user’s consent where the Company is required to submit personal information pursuant to applicable laws and regulations, or where such disclosure is necessary to address emergency situations, such as disasters, infectious diseases, incidents or accidents posing an imminent risk to life or physical safety, or an imminent risk of property loss.
Article 3 (Entrustment of Personal Information Processing)
(1) The Company entrusts the following personal information processing tasks for the smooth processing of personal information.
- Consignee : FBMICE Corp.
- Details of Entrusted Work : Participant registration and ticket management, event operations, and provision of event-related information and inquiry support
- Sub-processor : Nowis
- Details of Subcontracted Work : Participant registration management, event badge issuance
- Consignee : FACTBLOCK GLOBAL PTE. LTD.
- Details of Entrusted Work : Ticket management and operations
- Consignee : Eximbay
- Details of Entrusted Work : Payment processing
- Consignee : Brevo
- Details of Entrusted Work : Email delivery
(2) In accordance with Article 26 of the PIPA, when entering into a consignment contract, the Company specifies in documents such as contracts certain matters including prohibition of processing personal information other than for the purpose of performing consignment work, technical and administrative protection measures, restrictions on re-consignment, management and supervision of the consignee, and liability for damages, etc., and supervises whether the consignee handles personal information safely.
(3) If the content of the entrusted work or the consignee is changed, the Company will disclose it through this Policy without delay.
Article 4 (Cross-border Transfer of Personal Information)
(1) The Company may transfer users' personal information overseas for the purposes specified in this Privacy Policy and for the provision of services.
(2) Pursuant to Article 28-8 of the relevant law, the Company will disclose the following information in this Privacy Policy prior to transferring personal information.
- Recipient (Country) : FACTBLOCK GLOBAL PTE. LTD.(Singapore)
- Items Transferred : Name, affiliation, job title, and email address, country of residence and ticket payment details
- Date and Method of transfer : At the time of ticket purchase / Through information and communications network
- Purpose of Use : Ticket management and participant registration
- Retention and Use Period : 3 years
- Recipient (Country) : Sendinblue SAS (Brevo, France)
- Items Transferred : Name and email address
- Date and Method of transfer : When sending notification emails / Through information and communications network
- Purpose of Use : Sending event-related emails
- Retention and Use Period : 3 years
(3) The Company may take reasonable measures to protect personal information in accordance with the laws of the countries where the personal information is transferred, retained, or processed, and the personal information may be subject to data protection laws that differ from those of Korea.
Article 5 (Procedures and Methods for Destroying Personal Information)
(1) When the personal information becomes unnecessary, such as the expiration of the retention period of personal information or the achievement of the purpose of processing, the Company destroys the personal information without delay.
(2) In cases where personal information must continue to be preserved pursuant to other laws and regulations despite the expiration of the personal information retention period agreed upon by the user or the purpose of processing has been achieved, the personal information will be transferred to a separate database or stored in a different storage location.
(3) The procedures and methods of destroying personal information are as follows:
1. Destruction procedure: The Company will select the personal information for which the reason for destruction has occurred and destroy the personal information with the approval of the Privacy Officer of the Company;
2. Destruction method: The Company will destroy personal information recorded and stored in the form of electronic files so that the records cannot be reproduced, and the personal information recorded and stored in paper documents will be destroyed by shredding or incineration.
Article 6 (Rights and Duties of Users and Legal Representatives and Methods of Exercising them)
(1) Users may exercise their rights to the Company at any time, such as requesting viewing, correction, deletion, and suspension of processing of personal information. However, the exercise of the right, such as the request for viewing, correction, deletion, suspension of processing of personal information, by the user shall be limited under the provisions of the relevant statutes such as Article 35 (4), Article 36 (1), and Article 37 (2) of PIPA.
(2) Users may exercise their rights through e-mail, telephone, etc. in accordance with Article 41 (1) of the Enforcement Decree of the PIPA, and the Company will take action without delay.
(3) The exercise of the rights under Paragraph (1) may be made through the legal representative of the user or an agent such as a person who has been delegated. In this case, a power of attorney in the attached Form 11 shall be submitted.
(4) Users and their legal representatives may view or correct personal information in 'My Ticket > Edit My Information' after logging into the service.
(5) When requesting correction or deletion of personal information, if the personal information is specified as the object of collection in other statutes, the deletion cannot be requested.
(6) The Company will confirm whether the person who made the request for access, correction or deletion, or suspension of processing, etc. according to the user's right is the identical person or a legitimate agent.
Article 7 (Measures to Ensure Safety of Personal Information)
The Company takes the following measures to ensure safety of personal information:
(1) Administrative measures:
1. Establishment and implementation of internal management plan: For the safe handling of personal information, a Privacy Officer is designated and an internal management plan is established and implemented.
2. Minimization of the number of personnel handling personal information and training on information protection: The minimum number of personnel handling personal information is designated and operated, and information protection training and inspections are conducted for persons handling personal information.
(2). Technical measures:
1. Preparation of technical measures against hacking, etc.: The Company installs security programs to prevent the leakage or damage of users' personal information due to hacking or computer viruses, and manages to protect it safely through periodic checks and updates of the latest patches.
2. Management of access rights to the personal information processing system: The Company establishes and operates access control measures for personal information by granting, changing, and revoking access rights to the system that processes personal information, and controls unauthorized access from the outside using an intrusion prevention system.
3. Encryption of personal information: The Company stores and manages important personal information such as user passwords by applying a secure encryption algorithm.
(3). Physical measures:
1. Designation and operation of protected areas: The Company separately designates, operates and manages computer rooms, etc., where important information such as users' personal information is handled as protected areas such as control areas or restricted areas.
2. Access control for unauthorized persons: The Company establishes and operates access control procedures for protected areas, and prevents leakage and damage of users' personal information.
Article 8 (Privacy Officer)
(1) The Company has designated the following Personal Information Protection Officer to oversee matters relating to the processing of personal information and to handle users’ complaints and provide remedies for damages related to the processing of personal information.
- Privacy Officer : Park Andrew Weik
- Email : privacy@koreablockchainweek.com
Department in Charge of Personal Information Protection
- Department Name : Operations Department
- Email : privacy@koreablockchainweek.com
(2) The user may file a request for access to personal information pursuant to Article 35 of the PIPA with the department in charge specified above, and the Company will endeavor to promptly process the data subject’s request for access.
(3) The Company is not liable for any damages not attributable to the Company, such as user negligence or accidents in areas not managed by the Company, even though the Company has fulfilled the technical, physical and administrative measures required by law to protect personal information.
Article 9 (Methods of Remedy for Infringement of Rights and Interests)
(1) Users may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of the Korea Internet and Security Agency, etc. For other reports and consultations of personal information infringement, please contact the following agencies:
Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr);
Personal Information Infringement Reporting Center: (without area code) 118 (privacy.kisa.or.kr);
Supreme Prosecutors' Office: (without area code) 1301 (www.spo.go.kr);
National Police Agency: (without area code) 182 (ecrm.cyber.go.kr).
(2) Any person whose rights or interests have been infringed due to the disposition or omission made by the head of a public institution in response to a request under Articles 35, 36 and 37 of the PIPA may file an administrative appeal under the provisions of the Administrative Appeals Act.
Central Administrative Appeals Commission: (without area code) 110 (www.simpan.go.kr)
Article 10 (Changes to the Privacy Policy)
(1) This Privacy Policy shall take effect on August 31, 2026.
(2) Previous versions of the Privacy Policy are available through the version selector above.
- Revised on August 31, 2026 (applicable from February 26, 2026)
(3) In the event of any additions, deletions, or modifications to this Privacy Policy, the Company will notify users through a notice on its website at least 7 days prior to the effective date.
KBW2026 | Asia's Premier Crypto Event (Sep. 30 - Oct 1, Seoul)