Privacy Policy Addendum for GDPR
Privacy Policy Addendum for GDPR
Download Full PDF
Introduction
This addendum is supplementary to our Privacy Policy, explaining the privacy rights of EU/EEA residents when using our Services, as guaranteed by GDPR (General Data Protection Regulation).
Please read this addendum in conjunction with our Privacy Policy.
1. Information of Data Protection Officer (DPO)
As a sole proprietor, I act as the primary contact for data protection matters in connection with our Services.
Name: YUNA LIM
Office Address: THE GENUYN.
27, Hoenamu-ro, Yongsan-gu, Seoul, Republic of Korea
Email Address: privacy@thegenuyn.com
2. Lawfulness of Processing
We process your personal information only when we have a lawful basis to do so. The following table outlines the purposes for which we process your data and the corresponding legal bases.
| The Purpose of Personal Information Processing | Legal Basis |
|---|---|
|
To provide the Services and fulfill your orders Processing orders, delivering PDF download links via Pandora app, and managing user accounts. |
GDPR Article 6(1)(b) - Performance of a contract |
| Processing is necessary to deliver the digital products you purchased. | |
|
To process payments and prevent fraud Secure payment processing via Eximbay or PayPal. (Note: We do not store your credit card information directly.) |
GDPR Article 6(1)(b) – Performance of a contract |
| GDPR Article 6(1)(f) – Legitimate interests | |
| Necessary to process your payment securely and protect against fraudulent transactions. | |
|
To enforce the Terms of Service and protect our rights Defending against legal claims and enforcing our agreements. |
GDPR Article 6(1)(f) - Legitimate interests |
| We have a legitimate interest in defending our business rights and property. | |
|
To comply with legal requirements Tax reporting and accounting compliance in the Republic of Korea. |
GDPR Article 6(1)(c) - Compliance with a legal obligation |
| As a business in Korea, we are legally required to maintain transaction records for tax authorities. | |
|
To perform customer services Responding to inquiries via email or customer support channels. |
GDPR Article 6(1)(b) - Performance of a contract |
| Necessary to answer your questions regarding your purchase or download issues. | |
|
To analyze site usage and improve services Using Google Analytics 4 to understand traffic and user behavior. |
GDPR Article 6(1)(a) - Consent |
| Based on your consent to non-essential cookies via our cookie banner. | |
|
To promote services, events and products Sending marketing emails and newsletters. |
GDPR Article 6(1)(a) – Consent |
| Only if you have explicitly subscribed to our newsletter. |
3.Possible consequences of failure to provide information
Some personal information collected from you (e.g., email address for digital delivery) is required for us to fulfill our duties defined in a contract made with you. If you deny or fail to provide this required personal information, we will not be able to process your order or provide the download links for the Services.
4. Your rights under the GDPR
In order to exercise your rights of personal information described in our Privacy Policy, please send an email at privacy@thegenuyn.com. Based on GDPR, we may require you to verify your identity when you request us to exercise your rights. If someone sends us such request on behalf of you, the person needs to provide proof of your identity.
5. International transfer of personal information
Personal Information may be transferred to and processed in countries outside your country of residence. As we operate from the Republic of Korea and use global service providers, your data will be transferred as follows:
A. Service Provider Infrastructure
We use the infrastructure of reputable cloud and SaaS providers. Specifically, our store is hosted on Shopify. We also use Google Workspace (email), Google Analytics 4, Pandora (digital downloads), Eximbay, and PayPal (payment processing). These providers are contractually bound to process your personal information only on our documented instructions and in compliance with applicable data protection laws.
B. Transfer to the Republic of Korea (Data Controller)
Your data is transferred to the Republic of Korea where the business proprietor is located. The European Commission has adopted an Adequacy Decision for the Republic of Korea (adopted on 17 December 2021). This means that personal data can be freely transferred from the EU/EEA to the Republic of Korea without the need for additional safeguards such as Standard Contractual Clauses.
C. Other International Transfers Shopify and other service providers may process data in Canada, the United States, or other locations.
- Canada: Recognized by the European Commission as providing an adequate level of protection.
- Other Countries: Where we transfer your personal information to a country where the adequacy level has not been certified, we rely on appropriate safeguards such as Standard Contractual Clauses (“SCCs”) provided by our processors (e.g., Shopify's Data Processing Addendum).
6. Automated decision-making (including profiling)
We do not engage in automated decision-making that produces legal effects concerning you or similarly significantly affects you (as defined in GDPR Article 22). We may use automated tools such as Google Analytics 4 for statistical analysis and to improve our Services.
7. Update to this PP Addendum
We may revise or update this Privacy Policy Addendum from time to time in accordance with our Privacy Policy.
Last Updated: December 12, 2025
THE GENUYN