Terms

Effective Date

Jul 23, 2026

CrossAngle (hereinafter referred to as the “Company”) establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act. This policy is designed to protect the personal information of users and to address any related grievances promptly and effectively in connection with the use of Xangle (www.xangle.io).

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. The personal information collected will not be used for any other purposes unless the purpose of use changes, in which case the Company will take necessary actions such as obtaining separate consent in accordance with the Personal Information Protection Act.

1.1 Service Provision and Operation: providing website services, and optimizing system access and the usage environment.

1.2 Handling of Customer Inquiries: verifying User inquiries, contacting and notifying for fact-finding, and notifying of processing results.

1.3 Service Development and Statistical Analysis: identifying access frequency, and improving quality and utilizing for marketing through analysis of Service usage records.

Article 2 (Purpose of Collection and Use of Personal Information)

The Company provides the Service without a separate membership registration, and collects and utilizes the minimum amount of personal information necessary for the following purposes:

2.1 Processing and Retention Period of Personal Information

Purpose of Collection and Use of Personal Information

2.2 Information Collected During Service Use

∙ Information such as the user's browser type, operating system, IP address, access logs, and cookies.

∙ When using a mobile device: device information, operating system details.

2.3 Methods of Collecting Personal Information

∙ Collected through customer service interactions.

∙ Collection via 'Cookies.'

∙ Information generated through log analysis programs.

∙ Collection through smartphone applications.

Article 3 (Retention and Use Period of Personal Information)

3.1 The Company shall promptly destroy personal information when it becomes unnecessary, such as when the retention period has expired or the purpose of processing has been achieved.

3.2 If applicable laws and regulations require a specific retention period, the Company will securely store personal information for that period:

∙ Records of service and app visits: 3 months (Protection of Communications Secrets Act).

∙ Records of consumer complaints or dispute resolution: 3 years (Electronic Commerce Act).

3.3 The procedures and methods for destroying personal information are as follows:

∙ Destruction procedure: The Company identifies personal information that is no longer necessary and destroys it with the approval of the Company’s personal information protection officer.

∙ Destruction method: Personal information stored electronically is destroyed using technical methods that render it irretrievable. Personal information stored in paper form is destroyed by shredding or incineration.

Article 4 (Provision and Consignment of Personal Information to Third Parties)

4.1 The Company does not provide users' personal information to third parties without prior consent. However, the Company may provide personal information without user consent if required by relevant laws and regulations.

4.2 When entering into an entrustment contract, the Company documents the prohibition of processing personal information beyond the scope necessary for performing the entrusted tasks, mandates technical and administrative protection measures, restricts re-consignment, and establishes guidelines for the management and supervision of the entrusted party and liability for damages in accordance with Article 26 of the Personal Information Protection Act. The Company also supervises the entrusted party to ensure that personal information is processed securely. If there are changes to the consignment details or the entrusted party, the Company will promptly disclose such changes through this Privacy Policy.

Article 5 (Rights and Obligations of the Data Subject and How to Exercise Them)

5.1 The information subject (or their legal representative if under the age of 14) has the right to access, correct, delete, or request the suspension of processing of their personal information held by the Company at any time.

5.2 The exercise of these rights may be carried out by submitting a request in writing, via email, or by facsimile (FAX) to the contact information of the personal information protection officer listed in Article 8.1 below. This should be done using the form provided in Appendix 8 of the Enforcement Rules of the Personal Information Protection Act. The Company will take action promptly upon receipt of the request.

5.3 The rights mentioned in Paragraph 1 may also be exercised through an authorized agent, such as the legal representative of the information subject or a person duly delegated. In such cases, a power of attorney must be submitted using the form in Appendix No. 11 of the “Notice on Personal Information Processing Methods.”

5.4 Requests for access to personal information or the suspension of processing may be restricted under Article 35 (4) and Article 37 (2) of the Personal Information Protection Act.

5.5 Requests for the correction or deletion of personal information cannot be made if the personal information is designated for collection under other applicable laws.

5.6 When requesting access, correction, deletion, or suspension of processing in accordance with the rights of the information subject, the Company will verify the identity of the requester to ensure they are either the information subject or their legitimate representative.

Article 6 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof)

The Company may utilize cookies to offer an optimized service for users.

6.1 What is a cookie?

∙ A cookie is a small piece of data sent by the server operating the Company's website and stored on the user's computer browser, typically on the hard disk and the like of the user's PC.

6.2 Purpose of Using Cookies

∙ Cookies are used to tailor services to users by identifying their preferences and interests.

∙ The Company reads the contents of cookies stored on the user’s device to maintain user preferences and provide optimized services.

∙ Advertisers or marketing companies may also use cookies in banners displaying advertisements on our website. In such cases, these cookies collect users' IP addresses for system management and statistical analysis, and the personal information collected by such cookies is subject to the privacy policy of the respective advertiser or marketing company.

6.3 Installation, Operation, and Rejection of Cookies

∙ Users have the option to accept all cookies, receive notifications when cookies are stored, or refuse to store cookies altogether by adjusting their web browser settings.

∙ However, refusing to save cookies may result in difficulties in providing certain services.

∙ How to Allow or Deny the Installation of Cookies:

How to Allow or Deny the Installation of Cookies

Article 7 (Measures to Secure the Safety of Personal Information)

The Company implements the following measures to ensure the safety of personal information:

∙ Administrative Protection Measures: Establishing and enforcing internal management plans, conducting regular employee training (at least once a year), and others.

∙ Technical Protection Measures: Managing access rights to personal information processing systems, installing access control systems, and others.

∙ Physical Protection Measures: Installing and operating systems in controlled access areas, establishing and implementing secure access control procedures, and others.

Article 8 (Personal Information Protection Officer)

8.1 The Company is responsible for the overall processing of personal information and has appointed a Personal Information Protection Officer to handle complaints and provide relief for information subjects concerning personal information processing:

Name/Position: Hyunwoo Lee / CEO

Telephone: 02-558-4437

For reporting or consultation regarding personal information infringements, you can also contact the following organizations:

(1) Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)

(2) Personal Information Infringement Report Center: 118 (https://privacy.kisa.or.kr)

(3) Supreme Prosecutors' Office: 1301 (www.spo.go.kr)

(4) National Police Agency: 182 (https://minwon24.police.go.kr)

8.2 To request access to personal information under Article 35 of the Personal Information Protection Act, please contact the Personal Information Protection Officer or the department in charge of personal information protection as outlined in Paragraph 1. The Company will strive to process access requests promptly.

8.3 The information subject may contact the Personal Information Protection Officer or the department responsible for personal information protection for any inquiries, complaints, or requests for damage relief or access related to personal information while using the Company's services. The Company will respond to and process inquiries promptly.

Article 9 (Obligation of Privacy Policy Notification)

If there are any additions, deletions, or modifications to this Privacy Policy, the Company will provide prior notice through the Notice section at least 7 days before the changes take effect. However, if there is a significant change affecting user rights, such as changes to the types of personal information collected or the purposes of use, the Company will notify users at least 30 days in advance and may seek renewed user consent if necessary.

∙ Date of Notice: June 24, 2026

∙ Effective Date: July 23, 2026