This Privacy Policy explains how nextai Inc. ("we", "us", or "our") collects, uses, discloses, and safeguards your information when you use the golaman mobile application and related services (the "Service"). Please read this policy carefully. By using the Service, you agree to the practices described herein.
Compliance standards covered: GDPR (EU/UK) CCPA / CPRA (CA) COPPA (US) PIPA (Korea)
| Category | Data Elements | When Collected |
|---|---|---|
| Account Registration | Email address, password (hashed), display name | Sign-up |
| Social Login | Social account ID, email, profile picture (via OAuth 2.0) | Social login |
| User Profile | Avatar image, bio, language / region preferences | Profile setup |
| Customer Support | Email address, message content, attachments | Support request |
| Payments (if applicable) | Transaction ID, purchase amount (card details handled solely by PCI-DSS-certified processor) | In-app purchase |
| Category | Data Elements |
|---|---|
| Device Information | Device model, OS name/version, app version, unique device identifiers (IDFA / GAID — collected only with your consent on iOS 14.5+ via ATT) |
| Usage Data | Features accessed, session duration, in-app events, crash reports, ANR logs |
| Network Information | IP address, approximate geolocation (country / city level derived from IP), network type |
| Analytics | Aggregated, pseudonymized behavioral data for product improvement |
| Purpose | Data Used |
|---|---|
| Provide, operate, and maintain the Service | Account data, usage data |
| Authenticate your identity and secure your account | Email, device identifiers, IP address |
| Personalize your in-app experience | Profile, preferences, usage patterns |
| Send transactional / service communications | Email address, push notification token |
| Send marketing communications (with prior consent) | Email address, push notification token |
| Analyze usage and improve the Service | Aggregated / anonymized usage data |
| Detect, prevent, and investigate fraud or abuse | Device info, IP address, usage logs |
| Comply with legal and regulatory obligations | As required by applicable law |
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases under Art. 6 GDPR:
| Legal Basis | Description | Examples |
|---|---|---|
| Performance of a Contract (Art. 6(1)(b)) | Processing necessary to deliver the Service you signed up for | Account creation, content delivery |
| Legitimate Interests (Art. 6(1)(f)) | Our or a third party's legitimate interests, balanced against your rights | Fraud prevention, security, product analytics |
| Consent (Art. 6(1)(a)) | You have given clear, specific, and freely-given consent | Marketing emails, push notifications, optional tracking |
| Legal Obligation (Art. 6(1)(c)) | Processing required by law | Tax records, lawful government requests |
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
We do not sell your personal information. We may disclose it only in the following circumstances:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Service Providers (Sub-processors) | Cloud hosting, analytics, crash reporting, push notifications, customer support tooling | Data Processing Agreements (DPA) with GDPR Standard Contractual Clauses where required |
| Payment Processors | Processing in-app purchases securely | PCI-DSS Level 1 certified; minimal data shared under strict DPA |
| Law Enforcement / Courts | Compliance with legally binding obligations or valid legal process | Disclosed only to the extent legally required; we notify users where permitted |
| Business Transfers | Merger, acquisition, sale of assets, or restructuring | Successor entity bound by this Privacy Policy or equivalent protections |
nextai Inc. is headquartered in the Republic of Korea, a country recognized as having an adequate level of data protection for EEA personal data under GDPR Art. 45 assessments. Your information may also be processed by our service providers in other countries.
For transfers from the EEA or UK to countries without an adequacy decision, we rely on:
You may request a copy of the applicable transfer safeguards by contacting us at privacy@nextai.co.kr.
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account & profile data | Until account deletion + 30-day grace period | Service operation / contract |
| Access / connection logs | 3 months | Telecommunications Secrets Protection Act (Korea) |
| Transaction & payment records | 5 years | E-Commerce Act / tax law (Korea & applicable jurisdictions) |
| Consumer complaints & dispute records | 3 years from resolution | Consumer Protection Act (Korea) |
| Encrypted backup copies | Up to 90 days after account deletion | Disaster recovery; automatically purged thereafter |
| Anonymized / aggregated analytics | Indefinitely (no re-identification possible) | Legitimate interests (product improvement) |
After the applicable retention period, data is securely deleted using industry-standard methods or irreversibly anonymized.
Depending on your country of residence, you may have some or all of the following rights regarding your personal information. We will respond to verified requests within 30 days (extendable by a further 60 days for complex requests).
Request a copy of the personal data we hold about you.
Correct inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Limit how we process your data in certain circumstances.
Receive your data in a structured, machine-readable format (JSON / CSV).
Object to processing based on legitimate interests or for direct marketing.
Not be subject solely to decisions based on automated processing with legal effects.
Withdraw consent at any time where processing is based on consent.
To exercise any right, contact us at privacy@nextai.co.kr or use the in-app privacy settings. We may need to verify your identity before fulfilling the request.
If you are in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU authorities is available at edpb.europa.eu.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following additional rights:
To submit a verifiable consumer request, email privacy@nextai.co.kr with the subject "California Privacy Request". We will respond within 45 days, extendable by a further 45 days with notice.
The Service is not directed to children under the age of 13 in the United States (or under the minimum age in your jurisdiction — up to 16 in certain EU member states). We do not knowingly collect personal information from children below the applicable age threshold without verifiable parental or guardian consent.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at privacy@nextai.co.kr. We will promptly delete such information upon verification.
The golaman mobile app uses the following tracking technologies:
| Technology | Purpose | How to Opt-Out |
|---|---|---|
| Device Identifiers (IDFA / GAID) | Analytics and attribution (collected only with ATT consent on iOS 14.5+) | iOS: Settings → Privacy → Tracking Android: Settings → Google → Ads |
| Firebase Analytics / Crashlytics | Crash reporting and aggregated usage analytics | In-app Privacy Settings → disable analytics |
| Push Notification Tokens | Delivering in-app and push notifications | Device notification settings or in-app notification preferences |
We honor "Limit Ad Tracking" signals and the Apple ATT framework. We currently do not respond to browser-based Do Not Track (DNT) signals as no universally accepted standard exists.
We implement industry-standard technical and organizational measures, including:
No method of transmission over the internet is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security against all threats.
The Service may contain links to or integrations with third-party websites, applications, or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy policies before providing any personal information.
| Company (Data Controller) | nextai Inc. |
| Headquarters | Republic of Korea |
| Privacy / DPO Contact | privacy@nextai.co.kr |
| EU / UK Representative | To be appointed pursuant to GDPR Art. 27 / UK GDPR Art. 27 — contact us for details |
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you via:
Your continued use of the Service after the effective date of any revision constitutes your acknowledgment of the updated Policy. We encourage you to review this page periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please reach out to us:
Privacy Team – golaman · nextai Inc.
📧 Email: privacy@nextai.co.kr
🌐 Website: https://nextai.co.kr/index.html
⏰ Response time: Within 30 days (Mon–Fri, 09:00–18:00 KST, excluding public holidays)
EEA / UK users who are not satisfied with our response may lodge a complaint with their local data protection supervisory authority. A directory of EU supervisory authorities is available at edpb.europa.eu.