NEOQUANT

NeoQuant Consent to Collection and Use of Personal Information

Revised

This English version is a courtesy translation provided for reference only. The Korean version is the original, legally binding document and shall prevail in case of any discrepancy.

NeoQuant Co., Ltd. (NeoQuant) safely processes and protects the personal (credit) information (hereinafter "personal information") of data subjects (hereinafter "Customers") in accordance with the relevant laws.* NeoQuant discloses this Privacy Policy so that Customers' grievances can be handled smoothly, and to inform Customers that their personal information is being managed securely. *Relevant laws: the Personal Information Protection Act, the Credit Information Use and Protection Act, and others.

Table of Contents

① Collection and Use of Personal Information

② Provision to Third Parties and Entrustment / Overseas Transfer

③ Retention Period and Destruction

④ Measures to Ensure the Safety of Personal Information

⑤ Processing of Personal Location Information

⑥ Matters Concerning the Processing of Connecting Information (CI)

⑦ How Customers and Legal Representatives May Exercise Their Rights and Obligations

⑧ Chief Privacy Officer and Grievance Handling Department

⑨ Effective Date of the Privacy Policy and Changes

① Collection and Use of Personal Information

With the Customer's consent, NeoQuant collects the minimum information strictly necessary to use the NeoQuant services. Items that are strictly necessary to use the services are obtained through mandatory consent, and all other items are obtained through optional consent. NeoQuant does not use the collected items for any purpose other than the stated purpose, and continuously updates this Privacy Policy whenever the processed items or purposes change. Even after giving consent, if you wish to withdraw it, please note that you may do so at any time from the settings menu (NeoQuant App > ☰ Full Menu > ⚙️ Settings > Terms and Consent to Personal Information Processing). (However, for certain essential services such as remittance and payment, a cancellation function may not be provided.)

There are broadly five ways in which NeoQuant collects and processes personal information.

Information collected within the NeoQuant App

1. Information that the Customer directly enters into the NeoQuant services

2. Information that the Customer retrieves through the inquiry services of the NeoQuant App

At the time of sign-up, information such as name, date of birth, gender, mobile phone number, financial institution name/account number, account holder name, email address, CI (Connecting Information), DI (Duplicate Sign-up Verification Information), whether the person is a Korean national or a foreigner, nationality, and Customer identification value is processed. The purposes for processing personal information at sign-up are as follows.

• Identity verification • Conclusion, maintenance, performance, management, and improvement of contracts for the provision of services • Customer consultation, incident investigation, complaint handling, and dispute resolution • Fulfillment of statutory obligations • Selection of recipients of services (limited to the services the Customer uses) • Automatic entry of retained information to prevent input errors when using services or verifying identity • Detection and management of financial fraud and abnormal transactions • Detection of and guidance on malicious apps (Android)

Information collected in the course of consultation and complaint handling

NeoQuant also collects personal information when a damage incident is reported to the NeoQuant Customer Center or in the course of receiving complaints.

Information collected from sources other than the Customer (information provided by partner companies)

NeoQuant has personal information that is provided from sources other than the Customer (such as provision by third parties and entrustment/consignment processing).

Processing of automatically generated information and behavioral information

Such information may be automatically generated and collected in the course of using the services or processing personal information. NeoQuant processes only the minimum necessary behavioral information, and it does not include sensitive information—such as ideology, beliefs, or medical history—that may infringe on an individual's rights, interests, or privacy. Children's services whose main Customers are those under the age of 14 do not collect behavioral information for the purpose of tailored advertising, and tailored advertising is not provided to those under the age of 14.

Pseudonymized information

In accordance with Article 28-2 (Processing of Pseudonymized Information, etc.) of the Personal Information Protection Act, NeoQuant may pseudonymize information so that a specific individual cannot be identified, and use and provide such pseudonymized information for purposes such as compiling statistics, scientific research, and preservation of records in the public interest. NeoQuant safely stores pseudonymized information through access control and destroys it after the retention period has elapsed.

※ Additional use and provision of personal information

Within a scope reasonably related to the original purpose of collection, NeoQuant may use and provide personal information without the Customer's consent, taking into account factors such as whether any disadvantage is caused to the Customer and whether measures necessary to ensure safety, such as encryption, have been taken. In the case of such additional use or provision, this is explained under ① personal information collected for each NeoQuant service without the Customer's consent, or ② personal information provided to third parties without the Customer's additional consent.

※ Additional information

For a service used for the first time, NeoQuant may request the Customer to enter essential information, and if NeoQuant already holds certain information, it may omit the entry or provide input convenience for the Customer.

For remittance services (such as remittance to a contact), basic guidance on the remittance is provided through chat. (However, for external spam messages, we recommend blocking them.)

In accordance with the relevant laws, NeoQuant may send informational and functional messages (such as payment details, periodic notices regarding personal information processing, and notices of consent to receive advertising and marketing). These are sent via the Customer's contact information, and advertising information is sent only to Customers who have given optional consent.

When a NeoQuant member makes a remittance, information such as the recipient's name and account number may remain in the financial transaction records. This is information essential for making the remittance and must be retained in accordance with the relevant laws. If the recipient is not a NeoQuant member, that information is retained only in the financial transaction records and is used only for Customer consultation and complaint handling.

Automatic scanning for malicious app information (Android OS) - To provide safe financial services, NeoQuant scans the app packages installed on the Customer's mobile phone, and if a malicious app is detected, it suspends financial transactions and recommends deleting the malicious app. In addition, to prevent fraudulent transactions, NeoQuant collects malicious app information (installation time, package name, permissions, etc.) and whether a remote control app is running, so that you can use the NeoQuant App safely.

② Provision to Third Parties / Entrustment / Overseas Transfer

NeoQuant may provide personal information to partner companies and may also entrust the processing of personal information to them. Whenever matters concerning provision to third parties or entrusted processing change, NeoQuant continuously updates this Privacy Policy. NeoQuant processes personal information only within the scope specified in the purposes of processing, and does not provide personal information for any purpose other than the purposes of provision to third parties and entrustment. If provision or entrustment for a purpose other than the stated purpose arises, NeoQuant provides it only after obtaining the Customer's additional consent or where it falls under Articles 17 and 18 of the Personal Information Protection Act, such as special provisions of the law.

1) Provision to Third Parties

When providing personal information to third parties, NeoQuant obtains the Customer's consent and provides it to partner companies only to the minimum extent necessary.

What is provision to third parties? It refers to providing personal information for the business purposes of the recipient, whereby, after the personal information is provided, the right to manage the personal information passes to the third party.

※ In the event of an emergency,* personal information may be provided to the relevant authorities without the Customer's consent in accordance with the relevant laws (Article 15(1), subparagraphs 2, 3, and 5 through 7 of the Personal Information Protection Act). * Emergency: disasters, infectious diseases, incidents or accidents that pose an imminent risk to life or body, imminent loss of property, and the like.

2) Entrustment

When entering into entrustment and re-entrustment contracts, NeoQuant, in accordance with Article 26 of the Personal Information Protection Act, specifies in documents such as the contract the matters concerning liability—including the prohibition of processing personal information beyond the purpose of performing the entrusted work, technical and administrative protection measures, restrictions on re-entrustment, management and supervision of the entrusted party, and damages—and regularly supervises whether the entrusted party processes personal information safely.

When the entrusted party re-entrusts NeoQuant's personal information processing work, it obtains NeoQuant's consent, and NeoQuant discloses the re-entrusted party and the details of the re-entrusted work through this Privacy Policy.

If the details of the entrusted work or the entrusted party change, NeoQuant will disclose this without delay through this Privacy Policy.

What is entrustment? It means delegating personal information processing work to a partner company in order to carry out the business purposes of the personal information controller.

3) Overseas Transfer

For the purpose of providing services, NeoQuant transfers personal information overseas either under a contract or with the Customer's consent.

What is overseas transfer? It means the movement of personal information (through provision, entrustment, or storage) to a third country that has a different personal information protection framework.

③ Retention Period and Destruction

1) Retention Period

NeoQuant retains personal information for the 'retention period' consented to by the Customer or in accordance with the relevant laws.

The retention period for the personal information collected for each service can be confirmed through the information set out in <① Collection and Use of Personal Information>.

2) Destruction

(1) Destruction Procedure

When personal information becomes unnecessary because one of the following grounds for destruction arises, NeoQuant destroys it without delay (within 5 days).

1. When the Customer withdraws consent 2. When the purpose of processing has been achieved 3. When the retention period has elapsed 4. Discontinuation of the relevant service 5. Termination of the business 6. Expiration of the processing period for pseudonymized information

Even when one of the above cases arises, if the information must continue to be retained in accordance with the relevant laws, it is preserved by moving it to a separate database (DB) or by storing it in a different location.

(2) Method of Destruction

Personal information stored in electronic file form is destroyed so that it cannot be recovered, in accordance with the relevant laws, and personal information recorded on paper documents is destroyed by shredding.

※ Matters concerning long-term inactive users

As the Personal Information Protection Act was amended* (effective March 15, 2024), the dormant member system was abolished.

Please note that, as of October 19, 2023, NeoQuant no longer carries out the destruction or separate storage of the data of Customers who do not use NeoQuant for a long period.

④ Measures to Ensure the Safety of Personal Information

NeoQuant strives to establish and continuously improve its personal information management system, and makes the following efforts to ensure the safety of personal information.

1) Security Certifications

Through continuous investment in security and the voluntary acquisition of security certifications, NeoQuant always stays one step ahead in its preparations.

Acquisition of information protection certifications such as ISO 27001, ISO 27701, ISMS-P, PCI-DSS, and CBPR

2) Administrative Efforts

NeoQuant makes administrative efforts to ensure the safe processing of personal information.

Establishing and implementing an internal management plan, and conducting activities to raise employees' awareness of personal information protection through personal credit information protection training and campaigns

3) Technical Efforts

NeoQuant makes technical efforts to block illegal access and to prevent the forgery or alteration of access records, among other things.

1. Management of access rights to the personal information processing system 2. Installation and operation of intrusion prevention systems and intrusion detection systems 3. Blocking of external internet networks (network separation) 4. Safe password management (setting and operating standards such as password creation methods and change cycles) 5. Management of access log records 6. Encrypting personal information for safe storage and transmission 7. Installation of antivirus software and periodic updates and inspections

4) Physical Efforts

To protect personal information, NeoQuant makes physical efforts by controlling access to areas such as computer rooms and data storage rooms.

1. Access control to personal information storage areas - Safely storing personal information storage media (printouts, USB drives, etc.) in locations equipped with locking devices 2. Establishing and implementing protective measures to prevent the leakage or exposure of personal information and important information in personal work environments such as work PCs, desks, and drawers 3. Controlling the removal and bringing-in of personal information media (auxiliary storage media) containing personal information 4. Disposing of auxiliary storage media or printouts as unusable when destroyed so that they cannot be reproduced

⑤ Processing of Personal Location Information

1) Purpose of Processing and Retention Period

NeoQuant safely handles the relevant laws and NeoQuant's location-based services. For detailed matters concerning the processing of personal location information, please refer to the Location-Based Service Terms of Use.

Only for services that use location information, NeoQuant processes personal location information after separately obtaining consent to the Location-Based Service Terms of Use, and location information is used and retained while the individual service is being used.

When the purpose of collecting, using, or providing personal location information has been achieved, NeoQuant destroys without delay any personal location information other than the data confirming the use and provision of location information that must be recorded and preserved pursuant to Article 16(2) of the Act on Location Information.

2) Basis and Period for Retaining Data Confirming Collection, Use, and Provision

Customers may request data confirming the use and provision of their personal location information.

In accordance with Article 16(2) of the Act on the Protection and Use of Location Information, NeoQuant automatically records and preserves in its location information system the data confirming the collection, use, and provision of the Customer's location information.

In accordance with Article 6 of the Standards for Administrative and Technical Protection Measures for Location Information, NeoQuant retains the data confirming the use and provision of personal location information for at least 6 months.

3) Destruction Procedure and Method

Location information is processed only for Customers who have consented to the Location-Based Service Terms of Use, according to the services required in the NeoQuant App, and is destroyed without delay when the purpose of use has been achieved.

Personal credit information stored in electronic file form is destroyed so that it cannot be recovered, and personal information recorded on paper documents is destroyed by shredding.

4) Matters Concerning Provision to Third Parties

When NeoQuant provides a service involving provision to third parties, it notifies the Customer in advance of the recipient and the purpose of provision and obtains the Customer's consent.

If personal location information is provided to a third party designated by the Customer, NeoQuant notifies the Customer—each time and via the telecommunications terminal device that collected the personal location information—of the recipient, the date and time of provision, and the purpose of provision. However, in the following cases, NeoQuant will notify the Customer via a telecommunications terminal device or email address that the Customer has specified and designated in advance.

Where the telecommunications terminal device that collected the personal location information does not have the capability to receive text, voice, or video

Where the Customer has requested in advance to be notified by means such as online posting

※ Additional information

The location information manager is held concurrently by the CPO, who is the Chief Privacy Officer described in <⑧ Chief Privacy Officer and Grievance Handling Department>.

Where consent is given to the use or provision of personal location information for the protection of the life or body of a 'child aged 8 or under,' a 'person under adult guardianship,' or a 'person with a disability under the Act on Welfare of Persons with Disabilities,' the consent of the person concerned is required. Accordingly, where a guardian consents in writing to the use or provision of personal location information for a person falling under the above, the guardian holds all of the user's rights under the location service terms.

⑥ Matters Concerning the Processing of Connecting Information (CI)

In accordance with Article 23-5 (Generation and Processing of Connecting Information, etc.) and Article 23-6 (Obligation to Take Safety Measures for Connecting Information, etc.) of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., NeoQuant safely processes users' Connecting Information (hereinafter "Connecting Information") and provides the related information as follows.

1) Basis for Processing Connecting Information

In accordance with Article 23-5(1) and (4) of the Information and Communications Network Act, NeoQuant generates, collects, and uses Connecting Information with the user's consent.

2) Purposes of Collecting and Using Connecting Information

NeoQuant processes Connecting Information for the following purposes. For details such as the services in which Connecting Information is processed, please refer to 'personal information collected for each NeoQuant service with the Customer's consent' or 'personal information collected for each NeoQuant service without the Customer's consent.'

1. Identity verification and age verification

2. Identification, authentication, and linkage of the individual in connection with financial transactions

3. Identification of users across services and prevention of fraudulent use

3) Retention and Use Period of Connecting Information

Connecting Information is retained and used until each processing purpose is achieved in accordance with ③ Retention Period and Destruction of the NeoQuant Privacy Policy, and where there is an obligation under the relevant laws, it is retained for that period.

4) Provision of Connecting Information to Third Parties and Entrustment

Where NeoQuant provides a user's Connecting Information to a third party or entrusts it externally, it discloses the details in accordance with ② Provision to Third Parties / Entrustment / Overseas Transfer of the NeoQuant Privacy Policy.

5) Measures to Ensure the Safety of Connecting Information

In accordance with Article 23-6 of the Information and Communications Network Act and Article 29 of the Personal Information Protection Act, NeoQuant implements the following technical, administrative, and physical protection measures to ensure the safe processing of Connecting Information.

1. Establishment and implementation of an internal management plan

NeoQuant establishes and implements an internal management plan for the protection of Connecting Information, and conducts inspections and training at least once a year.

2. Management and minimization of access rights

NeoQuant minimizes the number of personnel who can access Connecting Information and manages the history of granting, changing, and revoking access rights.

3. Encrypted storage and transmission of Connecting Information

When storing Connecting Information, NeoQuant encrypts it using a secure algorithm, and uses encrypted communication channels when transmitting and receiving it over the internet.

4. Separate storage of Connecting Information

NeoQuant stores and manages unique identifying information, such as resident registration numbers, separately from Connecting Information so that they are not leaked together.

5. Security inspections and vulnerability assessments

NeoQuant conducts regular vulnerability inspections and security inspections of the Connecting Information processing system at least once a year.

6) Response Plan for Connecting Information Breach Incidents

In accordance with Article 13(2), subparagraph 5 of the Enforcement Decree of the Information and Communications Network Act, NeoQuant establishes and implements the following response plan to prepare for breach incidents such as the loss, theft, leakage, forgery, or alteration of Connecting Information.

1. Procedure for recognizing and reporting breach incidents

When a Connecting Information breach incident occurs, it is immediately reported to the Chief Privacy Officer and the incident response team, and, in accordance with the reporting criteria, reported without delay to the relevant authorities (the Personal Information Protection Commission, the Broadcasting, Media and Communications Commission, etc.).

2. Emergency measures and minimization of damage

NeoQuant promptly identifies the scope of the breach incident, and blocks systems and analyzes logs to prevent further leakage.

3. Notification to users

NeoQuant notifies users without delay of the occurrence of the incident, the details of the damage, the response measures taken, and the point of contact for inquiries.

4. Establishment of measures to prevent recurrence

Based on the results of analyzing the cause of the incident, NeoQuant establishes technical and administrative measures to prevent recurrence, and supplements its response system through regular inspections and training.

7) Connecting Information Manager

The Connecting Information protection officer who oversees the protection of Connecting Information and the response to breach incidents is held concurrently by the Chief Privacy Officer (CPO), and users may submit inquiries, complaints, breach reports, and the like related to personal information in accordance with ⑦ How Customers and Legal Representatives May Exercise Their Rights and Obligations of the NeoQuant Privacy Policy.

⑦ How Customers and Legal Representatives May Exercise Their Rights and Obligations

1) Guidance on Rights, Obligations, and Their Exercise

Customers may exercise the following personal information protection rights at any time.

1. Request to access personal information and request for notification 2. Request for correction in the event of errors or the like 3. Request for deletion and request to withdraw consent 4. Request to suspend processing 5. Request for notification of the use and provision of credit information

When NeoQuant processes personal information collected from sources other than the Customer, unless there is a justifiable reason, NeoQuant will inform the Customer, within 10 business days from the date of the Customer's request, of the source of collection, the purpose of processing, and the fact that the Customer has the right to request the suspension of the processing of personal information.

Where the Customer requests the correction or deletion of errors or the like in personal information, NeoQuant does not use or provide the personal information until the correction or deletion is completed.

In accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, rights may be exercised against NeoQuant through means such as written document (mail), telephone, email, fax, NeoQuant App Customer Center consultation (chat), and in-person consultation. For detailed contact information, please refer to <2) Department Handling Requests to Access Personal Credit Information and Related Grievances> of ⑦ Chief Privacy Officer and Grievance Handling Department.

Please refer to the following for the procedure for exercising rights through the NeoQuant App.

Access, correction, and deletion of personal information: NeoQuant App > ☰ Full Menu > Settings > 'My Information · Address Management' tab

Other requests such as access, or objections to the results: NeoQuant App > ≡ Full Menu > Customer Center

Rights may also be exercised through an agent, such as a legal representative or a duly authorized person. In this case, please note that a power of attorney in accordance with <Form No. 11 attached to the Notification on Methods of Processing Personal Information (No. 2020-7)> must be submitted. In addition, NeoQuant verifies whether the person making the request for access or the like is a duly authorized agent.

Where NeoQuant refuses the Customer's request on the basis of any subparagraph of Article 20(4) of the Personal Information Protection Act, unless there is a justifiable reason, NeoQuant will inform the Customer of the grounds and reasons for the refusal within 3 business days from the date of the Customer's request.

In accordance with Article 35 of the Credit Information Use and Protection Act, upon the Customer's request, NeoQuant notifies the Customer of the details of the use and provision of personal credit information free of charge once a year.

※ How to withdraw consent to personal information

Except for certain mandatory consents, the NeoQuant App provides a way to easily review most personal information consents and to withdraw them at any time. However, please note that, in order to properly process financial transactions, the withdrawal of consent for some services may not be processed immediately.

1. When you withdraw your membership, all consents, including mandatory consents, are automatically withdrawn. 2. You can withdraw consent for each service via NeoQuant App > ☰ Full Menu > Settings > Terms and Consent to Personal Information Processing > by reviewing the (service-specific) consent statement and terms and using the [Withdraw Consent] button. 3. For the financial MyData service, you can withdraw consent via NeoQuant App > ☰ Full Menu > Settings > Manage Imported Assets (Financial MyData) > the [Disconnect] button for each connected institution. 4. For consent to receive advertising/marketing, you can turn text messages and push notifications on/off individually under Full Menu > Settings > Notifications > Benefits・Marketing Notifications, and if all are turned off, you are deemed to have withdrawn your consent to receive them.

2) Matters Concerning the Processing of Personal Information of Children Under the Age of 14

When collecting personal information from children under the age of 14, NeoQuant obtains the consent of their legal representative and collects only the minimum personal information. For essential services that do not apply to children under the age of 14, NeoQuant does not separately collect or use personal information.

Requests such as access to the personal information of a child under the age of 14 must be made directly by the legal representative, and a minor aged 14 or over may exercise rights concerning personal information either by the minor themselves or through their legal representative.

In order to obtain the consent of the legal representative, NeoQuant may collect from the child the legal representative's name, relationship, and contact information, and the legal representative giving consent must be signed up for the NeoQuant App. As for the method of obtaining consent, the legal representative indicates whether they consent in the NeoQuant App, and after the consent is confirmed, the legal representative is notified of the consent by text message.

The way for a legal representative to check, in the NeoQuant App, the history of consent to the processing of a child's personal information is as follows.

NeoQuant App > ☰ Full > ⚙️ Settings > Terms and Consent to Personal Information Processing under 'Legal Information and Others' (child's name)

⑧ Chief Privacy Officer and Grievance Handling Department

1) Chief Privacy Officer (CPO) and Credit Information Administrator/Protector (CIAP)

NeoQuant designates a Chief Privacy Officer (CPO) who also serves as the Credit Information Administrator/Protector (CIAP), as set out below, to take overall responsibility for work related to the processing of personal information and to handle data subjects' complaints and remedy their damage in connection with the processing of personal information.

Name: Lee Seul-gi

Position: Co-CEO

Email: lsk@neoqnt.biz

Unit 3, 6th Floor, 40-19 Dumul-ro 11beon-gil, Namyangju-si, Gyeonggi-do (Byeollae-dong, Pungjeon Plaza)

2) Department Handling Requests to Access Personal Credit Information and Related Grievances

For all grievances arising while using the NeoQuant services (personal information protection inquiries, complaint handling, damage relief, etc.), please contact the Chief Privacy Officer and the department in charge listed below.

Person in Charge: Lee Seul-gi

Contact: 010-4813-0762

[Email] lsk@neoqnt.biz [Location] Unit 3, 6th Floor, 40-19 Dumul-ro 11beon-gil, Namyangju-si, Gyeonggi-do (Byeollae-dong, Pungjeon Plaza)

3) Methods of Remedy for Infringement of Rights and Interests

You may inquire about damage relief, consultation, and the like regarding personal information infringement through the institutions listed below. The following institutions are separate from NeoQuant; please contact them if you are dissatisfied with the results of NeoQuant's own handling of personal information complaints and damage relief, or if you need more detailed assistance.

Institution: Privacy Infringement Report Center

Contact: 118 (no area code)

Website: privacy.kisa.or.kr

Personal Information Dispute Mediation Committee

1833-6972

www.kopico.go.kr

Supreme Prosecutors' Office Cyber Investigation Division

1301 (no area code)

www.spo.go.kr

National Police Agency Cyber Safety Bureau (Police Civil Complaint Call Center)

182 (no area code)

ecrm.police.go.kr

⑨ Effective Date of the Privacy Policy and Changes

※ For inquiries about the content of NeoQuant's Privacy Policy after revision, you may contact lsk@neoqnt.biz. This <Privacy Policy> shall apply from 2026. 07. 03.