Privacy Policy

TheNEXA Privacy Policy

1. What is a Privacy Policy?

TheNEXA Inc.(hereinafter referred to as the “Company”) collects, uses, and provides the User’s personal information based on the User’s consent, and actively protects the User’s rights (to self-determination concerning their personal information).

The Company, as an information and communications service provider, is subject to and complies with the applicable laws, personal information protection provisions, and guidelines of the Republic of Korea.

The Privacy Policy refers to the guidelines with which the Company complies to protect the User’s invaluable personal information so that the User can use the services safely.

This Privacy Policy applies to services (hereinafter referred to as the “Services”) provided by the Company.

2. Personal Information we process

The Company collects personal information to the minimum extent necessary for service provision.

The Company collects minimum personal information necessary to provide the User with the Services when the User signs up or uses the Services on the website, applications, or programs as follows:

To sign up for a Taasfi

Required: email

To process a customer inquiry

Additional information may be required when processing an inquiry or consultation through Customer Service.

Additional personal information collected in the Service

ServiceInformation to be collected
Taasfi

For receiving advertising information: [optional] email, push token
To process customer inquiries
• General inquiries: [required] email, inquiry details

When uploading exchange files or custom files

When the User uploads an exchange file or custom file, the Company collects the uploaded file and the information it contains: exchange name, transaction date and time, transaction type, virtual asset type, quantity, transaction amount, fee, deposit/withdrawal details, transaction ID (TXID), wallet address, and exchange account identification information.

※ The items included may vary depending on the exchange and the format of the uploaded file.

For some Services, the Company may collect additional personal information, upon obtaining the User’s consent, to provide specialized services.

How personal information is collected:

The Company provides the User with prior notice of its collection of personal information. The Company collects personal information when:

The Company collects personal information as follows when the User uses the Services:

Information that may be automatically created and collected when the User uses the PC web, mobile web/app includes device information (OS, screen size, device ID, model of the device), IP address (to confirm the User’s country of access), cookies, date and time of visit, records of fraudulent use, records of service use.

The Company may obtain personal information from third parties for affiliated or connected services.

3. Purposes of processing personal information

The Company uses personal information for the purposes of member administration, service provision, and improvement, new service development, etc.

The Company collects the minimum personal information necessary to provide the User with Services as follows when the User signs up or uses the Services on the website, applications, or programs:

※ The original file collected through exchange file upload or custom file upload is deleted upon completion of transaction history extraction, when the relevant exchange connection is disconnected, or upon membership withdrawal. The extracted and organized transaction history and calculation results are retained until membership withdrawal or until the purpose of use is achieved.

Service CategoryItems CollectedPurpose of Collection and UseLegal BasisRetention and Use Period
Social login (Kakao)

[Required] Kakao account (email)
[Optional] phone number, name

Processing tasks for Taasfi service provision, including service use and consultation, responding to inquiries, and analysis for service improvementEach SNS provider provides the information to the Company after obtaining consent pursuant to Article 17(1) or Article 18(2) of the Personal Information Protection ActUntil membership withdrawal
Social login (Naver)

[Required] User unique identifier, email address
[Optional] phone number, name

Processing tasks for Taasfi service provision, including service use and consultation, responding to inquiries, and analysis for service improvementEach SNS provider provides the information to the Company after obtaining consent pursuant to Article 17(1) or Article 18(2) of the Personal Information Protection ActUntil membership withdrawal
Social login (LINE)

[Required] LINE account (email)
[Optional] name (or profile name), profile photo

Processing tasks for Taasfi service provision, including service use and consultation, responding to inquiries, and analysis for service improvementEach SNS provider provides the information to the Company after obtaining consent pursuant to Article 17(1) or Article 18(2) of the Personal Information Protection ActUntil membership withdrawal
Identification and authentication of data subject, identity verificationName, date of birth, gender, phone number, connecting information (CI), duplicate subscription information (DI), domestic/foreign statusRegistration/management as member information for identification, authentication, service use and consultation based on service use, prevention and response to fraudulent service use, and prevention of fraudulent use of age-restricted servicesArticle 15(1)4 and Article 15(1)6 of the Personal Information Protection ActUntil membership withdrawal. However, connecting information (CI) is stored for 1 year after hash encryption so it cannot be restored.

4. Providing personal information to third parties

Recipient third partiesRecipients' Purposes of UseItems of personal information providedRetention period
Partner tax accountants (tax firms, accounting firms)Tax consultationUser identifiable informationDestroyed immediately upon termination of membership (however, if a separate retention period is required by applicable laws and regulations, we will follow that period)

5. Provision and Entrustment of Personal Information

The company does NOT provide the User’s personal information to a third party unless consented to by the User or required by the laws.

The Company entrusts the following task to a third party.

The Company entrusts personal information processing tasks to a third party to perform tasks needed to provide the services. The Company manages and supervises the entrusted companies to comply with the applicable laws.

Entrusted companyEntrusted tasks
Amazon Web Service, Inc.Operating the service system, storing and backing up files and transaction history uploaded by the User, and security management

Amplitude, Inc.
Google Analytics

Analyze service usage patterns to recommend customized services to users and use them to improve service quality

6. Retention and disposal

The Company retains personal information until the purposes of the personal information use are fulfilled or the User deletes their account, with some exceptions applied.

The Company keeps the collected personal information until the purposes of the use of personal information are fulfilled or the User deletes their account. In case the Company terminates the Terms of Service with the User under the Terms of Use, however, the Company may keep the minimum personal information of the User for a certain period as required to prevent the User from signing up again during that period.

The Company destroys personal information without delay once the purposes of collection and use are fulfilled. The Company will employ the disposal methods and procedures as follows:

The Company destroys personal information in the form of electronic files securely to make the data unrecoverable and unrevivable. For other forms of personal information such as records, printouts, written forms, etc., the Company disposes of them by shredding or burning.

To comply with the internal policy, however, the Company keeps some types of personal information for certain periods before destroying them.

[Records regarding contract or withdrawal of subscription or records regarding payment and supply of goods]

[Records regarding consumer complaint or dispute handling]

[Records regarding books and supporting documentation related to transactions as required by the tax laws]

[Records regarding electronic financial transactions]

[Records regarding website visits]

The Company stores separately or deletes personal information of a Member who has not used the Services for 1 year or a period set by the Member, and the stored information will be destroyed without delay after being kept for four (4) years. Once personal information reaches its expiration date, the Company destroys the information immediately in an unrecoverable manner, even if the information is obligated to be retained by the laws.

7. Use and provision of personal information within the scope reasonably related to the purpose of collection

The company may use personal information or provide personal information to a third party without the user's consent, taking into account each of the following criteria within the original purpose of collection and reasonable scope.

  1. Whether it is related to the original purpose of collection is determined considering whether the original purpose of collection and the purpose of additional use and provision are related to the nature or disposition.
  2. Whether there is predictability of additional use or provision of personal information, in light of the circumstances or processing practices of personal information collection, is determined in consideration of the relationship between personal information processors and users, the level of technology and speed of development, and general circumstances (practices) established for a considerable period of time.
  3. Whether the user's interests are unfairly infringed is determined in consideration of whether the user's interests are substantially infringed in relation to additional purposes of use and whether the infringement is unfair.
  4. Whether necessary measures have been taken to secure safety, such as alias processing or encryption is determined considering whether safety measures are taken in consideration of the possibility of infringement, etc.

‍8. Matters Concerning InstallationㆍOperation and Refusal of Automatic Personal Information Collection Device

The Company may use cookies to provide web-based services.

Cookies are used to assist the User with faster and more convenient navigation of the website and offer customized services.

What is a cookie??

A cookie is a small piece of data (text file) that the server sends to the User’s browser to operate a website. A cookie is stored on the User’s personal computer.

Purpose of cookies

Cookies are used to provide personalized and customized services to the User by storing and recalling the User's information. When the User visits a website, the website server reads the cookies saved in the User’s device to maintain the User’s settings and provide customized services. Cookies help the User access the website conveniently by using existing settings. Cookies are also used to provide the User with customized information such as optimized advertisement based on the User’s website visit history and use patterns.

Detailed cookie list

Cookies used by a third party software (Google Analytics)

Detailed cookie list : _ga, _gat, gid

Rejection of cookies

Cookies do not store identification information such as names and phone numbers. and the User reserves the right to choose to install cookies. The User can thus adjust web browser settings to accept all cookies, be asked about cookies every time they are saved or refuse all cookies. Provided that, if the User refuses the installation of cookies, the User may find it harder to navigate the web or use services that require login.

How to adjust cookie preferences or reject them

  1. Internet Explorer: Select “Tools” menu at the top of the browser window > Select “Internet Options” > Select the “Privacy” tab > Set cookie options
  2. Chrome: Click “Settings” at the top right > Click “Security and Privacy” > Click “Cookies and other site data”
  3. For Microsoft Edge: Settings menu at the top of the web browser > Cookies and Site Permissions > Manage and delete cookies and site data

9. Rights and Obligations of Data Subjects and Their Legal Representatives, and Methods of Exercising Such Rights

is committed to protecting your rights.

  1. Data subjects can exercise their rights (hereinafter referred to as "exercise of rights") at any time, including the right to request access, rectification, deletion, suspension of processing, or withdrawal of consent for personal data held by Company, as well as the right to object to automated decision-making or request an explanation thereof.
  2. The exercise of rights may be made to Company through written form, electronic mail, or facsimile (FAX), in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and Company will respond to such requests without delay.
  3. The exercise of rights can also be carried out by a legal representative of the data subject or a delegated agent. In this case, a power of attorney in accordance with Form No. 11 of the “Notice on the Methods of Personal Information Processing” must be submitted.
  4. Requests for access to personal data and suspension of processing may be restricted in accordance with Article 35, Paragraph 4, and Article 37, Paragraph 2 of the Personal Information Protection Act.
  5. Requests for rectification and deletion of personal data cannot be made if the personal data is specified as a collection target under other legal regulations.
  6. When responding to requests for access, rectification, deletion, or suspension of processing in accordance with the rights of the data subject, TheNEXA will verify whether the person making the request is the data subject or a legitimate representative.

10. Data Protection Offer and Data Protection Manager

Questions about personal information protection?

If you have any questions, complaints, suggestions, and other matters related to personal information protection while using the Services, please contact the Company’s Data Protection Offer (DPO) or Data Protection Department. TheNEXA is committed to listening and responding to our Users quickly and sincerely.

Data Protection Officer

Data Protection Manager

If the User wishes to make a report or to consult about a potential infringement of personal information protection, please contact the following organizations:

Personal Information Infringement Report Center

Supreme Prosecutor’s Office, Cybercrime Investigation Division

National Police Agency, Cyber Terror Response Center

11. Actions Taken to Protect Personal Information

The company is making efforts as follows to safeguard the User’s personal information.

The Company has implemented the following technical and managerial measures to protect users’ personal information from loss, theft, disclosure, modification, or damage.

  1. Technical Measures

a. Personal information is protected by a password, and important data is protected through separate security functions, such as encryption of files and transmitted data and use of file lock functions.

b. Antivirus software is used to prevent damage from computer viruses. Antivirus software is updated periodically, and in the event of a sudden virus outbreak, the vaccine for the virus will be applied as soon as it is released to prevent the infringement of personal information.

c. SSL, a security protocol, has been adopted to help ensure the safe transmission of personal information through the network.

d. In order to prevent unauthorized disclosure of users’ personal information by hacking or other unauthorized access, the system is maintained in an area where external access is restricted, and intrusion-blocking devices are used.

  1. Managerial Measures

a. The Company has procedures in place needed for appropriate management of and access to users’ personal information. Company officers and employees are required to understand and comply with these procedures, and compliance is monitored regularly.

b. The Company limits the number of persons who can process users’ personal information to a minimum, controls their access rights, and educates such personnel to comply with applicable laws and policies. Persons who process users’ personal information are the following:

c. The Company requires new employees to sign an information protection pledge, reminds all of its employees from time to time of their duty to protect personal information, and has in place internal procedures to audit their compliance with such duties to prevent the unauthorized disclosure of information by its employees (including, personal information).

d. The transfer of duties for personal information managers takes place under secure conditions, and the Company prescribes the scope of liability regarding any personal information incidents for both current and former employees.

The company complies with the European Union’s General Data Protection Regulation (GDPR).

The Company complies with the GDPR and other data protection laws. The Company uses the User’s personal information for purposes as follows:

Under the GDPR and other relevant laws and regulations, the User can request to transfer their personal information to another controller or to suspend the processing of the personal information. The User also reserves the right to bring complaints to the information protection authorities. The User can make inquiries about data protection to the Customer Center. The Company processes such inquiries lawfully and quickly.

The Company’s Services are NOT intended for children. The Company collects personal information of children under the age of 16 who reside in the European Economic Area (EEA). In case the personal information of a child under the age of 16 living in the EEA is collected unintentionally in connection with the provision of the Services, the Company removes the information immediately. For inquiries about the personal information of children under the age of 16, please contact the Customer Center via phone or email.

To provide Services to the User, the Company may transfer, retain, and process personal information outside the EEA including the Republic of Korea. The User’s personal information may also be saved within the EEA when the information is stored in the device that the User uses to access the Services. When the Company transfers the User’s personal information outside the EEA, the Company guarantees a similar level of data protection as within the EEA by ensuring to take any one of the following measures:

For further inquiries about the measures to be taken by the Company when transferring personal information outside the EEA, please contact the Company.

Company complies with the California Consumer Privacy Act (CCPA).

The following notice applies only to California residents. Under the CCPA, consumers who reside in California can request to view, delete, or suspend the sale of personal information collected by the Company and NOT to be discriminated against for exercising the aforementioned rights. If the User exercises the right to opt-out-of-sale, the Company will not sell the User’s personal information and the Company will not discriminate against the User for exercising their rights related to personal information.

12. Changes to this Privacy Policy

If there are any changes, additions, or deletions to the content of this Privacy Policy due to changes in the applicable privacy laws, policies and security technologies, etc., the Company will notify the users of the amendment by posting an announcement on the Presented LIVE Notice Board prior to the amendment of the Privacy Policy. If major changes in the User’s rights are to be made such as a change in personal information items collected or purpose of use, the Company will provide the User with a minimum 30-day prior notice.

Company