Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") governs the processing of visitor personal data that Divine Company ("Company") carries out on behalf of any business or individual that subscribes to and uses Statlane (statlane.kr, the "Service"), including data collected through the Service's visitor behavior analytics collector (t.statlane.kr). Under this DPA, the customer ("Customer" or "member") acts as the controller (the entrusting party) of visitor personal data, and the Company acts as the processor (the entrusted party) that processes such data on the Customer's documented instructions. This DPA forms part of the Service agreement and Privacy Policy and takes effect when the Customer subscribes to the Service or installs and uses the collector. It is entered into pursuant to Article 26 of the Personal Information Protection Act of the Republic of Korea ("PIPA") and reflects standard controller-processor terms.
- Effective date
- August 1, 2026
- Default jurisdiction
- United States (CCPA/CPRA)
This is the current version, effective as of the date shown above. When revised, the Company will provide at least 7 days’ prior notice (30 days for changes unfavorable to users) via in-service notice or similar; the latest version supersedes prior versions.
Section 1 (Purpose)
This DPA sets out, for the Company's processing of visitor personal data on behalf of the Customer through the Service, the scope of the entrusted work, the Company's obligations as processor, the safeguarding of data subject rights, the secure management of personal data, and the handling of data upon termination, all under Article 26 of PIPA. The purpose of the processing is to collect, store, and analyze the behavioral data (visits, events, referral sources, and the like) of visitors to the Customer's websites or services and to provide the Customer with integrated analytics reports and related features. The Company processes personal data only to the extent necessary to achieve that purpose.
Section 2 (Roles of the Parties)
Under this DPA, the Customer, as the party that determines the purposes and means of collecting and using visitor personal data, is the controller (entrusting party), and the Company, which processes personal data on the Customer's instructions, is the processor (entrusted party). Pursuant to Article 26 of PIPA, the Company processes personal data only within the scope of the entrusted work as documented by the Customer (including this DPA, the Service configuration, and the Customer's instructions) and does not process personal data contrary to the Customer's instructions. Where the Company is subject to a legal compliance obligation, it may process data to that extent and, unless prohibited by applicable law, will inform the Customer of the reason.
Section 3 (Nature of Processing and Categories of Personal Data)
The personal data the Company processes on the Customer's behalf is limited to visitor behavioral data, and its purpose, categories, data subjects, and duration are as set out above. The Company does not process personal data beyond the scope instructed by the Customer through collector configuration and use of the Service.
Section 4 (Obligations of the Processor)
As processor, the Company complies with the following obligations. First, it processes personal data only within the scope of the purposes documented by the Customer and does not use it for any other purpose or disclose it to third parties. Second, it complies with PIPA and related laws and the Customer's lawful instructions and implements the security measures in Section 7. Third, it limits the personnel who process personal data to a minimum, imposes confidentiality obligations on them, and provides relevant training. Fourth, it does not sub-process except as provided in Section 5. Fifth, where it considers that an instruction from the Customer would violate applicable law, it promptly notifies the Customer. The Company does not use personal data for its own purposes beyond performing the entrusted work; provided that the generation and use of statistical and aggregate information is permitted only within the scope the Customer has authorized in advance through the Service configuration or a separate document, only for statistical purposes permitted under Article 28-2 of PIPA, and only with respect to information processed so that no individual can be identified, and the Company notifies the Customer of such processing. Such processing is carried out consistently with the statistical/de-identified processing standard in Section 12.2 of the Terms of Service.
Section 5 (Sub-processing)
The Company may sub-process part of the personal data processing to cloud infrastructure providers, AI generation/analysis processing providers, and similar service providers in order to provide the Service, and obtains the prior consent of the Customer, as controller, before doing so. Upon accepting this DPA, the Customer gives prior consent to sub-processing to the categories of sub-processors that the Company enumerates through this DPA and the Privacy Policy (such as cloud infrastructure providers, payment gateway providers, and AI generation/analysis inference providers). Where the Company intends to add a new sub-processor, it notifies the Customer in advance of the sub-processor's name and the nature of the sub-processed work, and if the Customer does not object in writing within a reasonable grace period (as a rule, 14 days) after such notice, the Customer is deemed to have consented to that sub-processing. Where the Customer objects on reasonable grounds, the parties will discuss a reasonable alternative, and if no alternative is agreed, the Customer may terminate the relevant feature or the agreement. The Company imposes on each sub-processor, by contract, data protection obligations equivalent to those of the Company under this DPA, supervises the sub-processor, and remains responsible, to the extent provided by applicable law, for harm caused by the sub-processor's processing of personal data.
Section 6 (Cross-Border Processing of Personal Data)
Each of the above cross-border activities is subject to Article 28-8 of PIPA (cross-border transfer of personal data). The Company provides the Customer with the matters set out in each item of Article 28-8(2) (the categories of personal data transferred; the destination country, timing, and method of transfer; the name and contact details of the transferee; the purpose of use and the retention/use period; and the method, procedure, and effect of refusing the cross-border transfer), and the Customer, as controller, must disclose these in its own privacy notice directed to its visitors (data subjects). The Company's posting of these matters in its own Privacy Policy does not relieve the Customer of its notice obligation to its visitors. Because these activities constitute the entrustment of processing and storage necessary to perform the Service contract and for the convenience of data subjects, they may be conducted without separate consent from data subjects where the above matters are disclosed in the privacy policy under Article 28-8(1)3 of PIPA. The Company applies the protective measures required by this DPA and applicable law to personal data processed abroad, and publishes the matters under Article 28-8(2) — including the transferee's name and contact details, destination country, categories transferred, purpose of processing, retention/use period, and method of refusal — as information incorporated as part of the Privacy Policy.
Section 7 (Security Measures)
Pursuant to Article 29 of PIPA and the related notification (Standards for Measures to Ensure the Safety of Personal Data), the Company implements the following technical, administrative, and physical measures to prevent personal data from being lost, stolen, leaked, forged, altered, or damaged. First, minimum grant of access rights to the personal data processing systems, access control, and account/privilege management. Second, encryption of data in transit and encryption of sensitive data at rest. Third, retention and review of access logs and measures to prevent their forgery or alteration. Fourth, installation and updating of security software to prevent malicious programs. Fifth, physical access control and measures against disasters and outages. The Company continually reviews and improves the level of its security measures in line with applicable law and the changing threat environment.
Section 8 (Support for Data Subject Rights)
Where a data subject exercises rights directly with the Company, the Company promptly notifies the Customer as controller and acts on the Customer's instructions, and complies to the extent that applicable law imposes direct obligations on the Company. The Company may charge a reasonable fee for such support to the extent permitted by applicable law.
Section 9 (Notification of Personal Data Breach)
Where the Company becomes aware of a personal data breach, loss, theft, or similar security incident ("Breach") involving personal data it processes, it notifies the Customer, as controller, without undue delay and promptly after becoming aware (in principle within 72 hours, or more quickly where the matter is urgent). The notification includes the categories of personal data affected, the time and circumstances, the potential impact on data subjects, and the measures the Company has taken and its mitigation plans, together with the information the Customer needs to fulfill its obligations to notify data subjects under Article 34 of PIPA and to report to the Personal Information Protection Commission and the Korea Internet & Security Agency. The Company provides related materials and cooperation so that the Customer can fulfill its statutory notification and reporting obligations.
Section 10 (Customer's Audit Rights)
The Customer may audit whether the Company is processing the entrusted personal data securely in accordance with this DPA and applicable law. Upon reasonable prior notice, the Customer may request that the Company submit materials on its personal data processing status and security measures or, where necessary, request a documentary review, and the Company cooperates absent good reason not to. Audits and reviews are conducted, ordinarily no more than once per year, in a manner that does not unreasonably interfere with the Company's normal business operations, and access may be limited to the extent necessary to protect the Company's trade secrets and the personal data of other customers and third parties. Where an audit identifies matters requiring improvement, the Company implements corrective measures within a reasonable period.
Section 11 (Return and Deletion upon Termination)
Upon termination of this DPA or the Service agreement, the Company returns to the Customer or deletes the personal data it processed on the Customer's behalf, at the Customer's option. Deletion is carried out by a method from which recovery or reproduction is impossible, and, at the Customer's request, the Company provides materials confirming the deletion. However, where the Company is required by applicable law to retain data, it retains such data securely, solely for the relevant purpose, for the period required by that law before deletion. If the Customer does not request return within a reasonable period after termination (a grace period the Company notifies through the Service interface), the Company may delete the data.
Section 12 (Liability and Indemnification)
The Company and the Customer each comply with their respective obligations under PIPA and applicable law and are responsible for harm arising from their own fault. Where the Company processes personal data beyond the scope of the entrusted work and thereby causes harm to a data subject or third party, the relevant liability provisions apply by treating the Company as an employee of the Customer, consistent with the intent of Article 26(7) and 26(6) of PIPA. However, the Company is not liable for harm arising from the Customer's instructions, errors in information the Customer provides or configures, or the Customer's violation of applicable law. The scope and limits of the Company's liability follow the Service agreement (the Partner Data API Terms of Service where the Customer is a partner, and otherwise the Terms of Service) to the extent permitted by applicable law. However, the Company's liability to the Customer for personal data infringement is not subject to the fee-based limit under the Service agreement and instead follows PIPA and other applicable laws; and no excessive blanket exclusion of liability that applicable law does not permit will apply.
Section 13 (Term)
This DPA takes effect when the Customer subscribes to the Service or installs and uses the collector and, being subordinate to the Service agreement, remains in force for the term of that agreement. This DPA terminates together with the Service agreement. However, provisions that by their nature must survive termination (including post-incident cooperation under Section 9, return/deletion under Section 11, and liability and indemnification under Section 12) remain in effect after termination to the extent necessary to achieve their purpose. Where changes to this DPA are required due to amendments to personal data protection laws, the Company notifies the changes through the Service interface or the Privacy Policy.
Section 14 (Contact)
Inquiries regarding this DPA and the entrusted processing of personal data may be submitted through the data protection officer and business information the Company publishes on the Service interface (statlane.kr) and in its Privacy Policy (trade name: Divine Company / 디바인컴퍼니; business registration number: 572-19-01127; address: Room 307, Building 3, 713 Bugaksan-ro, Seongbuk-gu, Seoul, Republic of Korea). For other business information, such as the representative, contact number, and mail-order sales registration number, please refer to the latest information the Company publishes on the Service interface.