Privacy Policy

What personal data Doeeum collects through its inquiry form and job applications, why, for how long, how it is destroyed, and your rights.

This policy covers both the inquiry forms and job applications.

1. What we collect

Do EEUM Inc. ("we") collects personal data through two channels only.

a. Project / assessment inquiry form

  • Company, contact name, email, phone, inquiry type, message
  • Automatically: IP address, timestamp

b. Company profile download form

  • Company, contact name, email
  • Automatically: IP address, timestamp

c. Job applications

  • Required: name, email, phone, resume file (PDF)
  • Optional: highest education, career summary, cover letter, portfolio URL
  • Automatically: IP address, timestamp

We do not collect Korean resident registration numbers during hiring, nor photographs, date of birth, gender, marital status, family details or place of origin — the items the Fair Hiring Procedure Act prohibits employers from requesting. Please remove your resident registration number from your resume before submitting; files found to contain one are automatically rejected and deleted, and we ask you to re-submit.

2. Why we use it

  • Inquiries: answering your question and keeping a record of the conversation
  • Profile download: sending the document and confirming delivery
  • Job applications: running the hiring process for the posting you applied to and telling you the outcome
  • Talent pool (only with your separate consent): letting you know about future openings

We do not use your data for any other purpose. If the purpose changes we ask for your consent again.

3. How long we keep it

  • Inquiries: 3 years from submission
  • Profile downloads: 1 year from submission
  • Job applications: destroyed within 180 days of the hiring decision (a posting may set a shorter period, and the period shown on the consent screen prevails)
  • Talent pool, if you consented: 365 days from consent

Data past its retention period is destroyed as described in section 4. Where another law requires retention, we keep the data for that period and then destroy it. If you ask us to delete your data sooner, we do so without delay.

4. How we destroy it

a. Procedure

  • Data whose retention period has expired, or whose purpose has been fulfilled, is selected for destruction automatically.
  • A scheduled job runs daily, finds the due records and deletes them.
  • The same job then re-queries the records to verify the deletion, force-deletes anything left, and raises an alert.

b. Method

  • Electronic records are permanently erased in a manner that makes recovery impossible. The store holding application attachments has neither versioning nor object lock, so no earlier version of a deleted file survives.
  • Any paper output is shredded or incinerated.

5. Sharing with third parties

We do not provide personal data to third parties.

The only exception is a lawful request from an investigative authority following due process, and even then we verify the basis and scope and respond with the minimum required.

6. Processing entrusted to others

We entrust part of the processing to the following processor.

  • Processor: Amazon Web Services, Inc. / Scope: data storage and cloud infrastructure / Location: ap-northeast-2 (Seoul, Republic of Korea) region

The contract sets out safeguards in writing, and we supervise the processor so that data is not used beyond the entrusted purpose. Any change of processor or scope is published in this policy.

Inquiry and application contents are encrypted at rest. Only the recruiter role can open an application, and every read is written to an audit log.

7. Your rights and how to exercise them

You may at any time ask us to:

  • give you access to your personal data
  • correct it if it is wrong
  • delete it
  • stop processing it
  • withdraw your consent (withdrawing an optional consent does not affect an application already under way)

Send your request by email to admin@doeeum.com, addressed to the privacy officer named in section 8. We respond within 10 days of receiving it. Where we need to verify your identity we ask for the minimum information and destroy it immediately after the check.

You may also contact the Personal Information Dispute Mediation Committee or the KISA privacy infringement report centre for advice or dispute resolution.

8. Privacy officer

We have designated a privacy officer responsible for personal data processing and for handling complaints and remedies.

  • Privacy officer: Privacy Officer: Eunha Park (placeholder — replace with the appointed officer)
  • Email: admin@doeeum.com
  • Phone:
  • Address: 4F Daewon Building, 228 Hwagok-ro, Gangseo-gu, Seoul, Republic of Korea

9. Security measures

  • Submitted data is encrypted at rest; job applications use a separate key and a separate store.
  • Application attachments are uploaded to an isolated store and can only be opened after passing a malware scan.
  • Access is granted to the smallest number of people who need it, and reads are recorded in an audit log.
  • Administrative access requires multi-factor authentication.

10. Changes to this policy

This policy may change as the law or our practices change. We publish any change on this page at least 7 days before it takes effect.