The company website does not use analytics or advertising cookies or build visitor profiles. Only connection data needed to deliver the site and emails you choose to send may be processed.
This page reflects the service and platform behavior currently available.
A separate notice applies to the Nesecu product page
The Nesecu product page uses Google Analytics only after you choose Allow analytics. For that optional analytics, the Nesecu web analytics notice takes priority over statements in this policy that the company website does not use analytics.
1. Scope and purposes
This policy applies to the company introduction, product index, and company contact surfaces on mmche.studio. The separate Nesecu Privacy Policy covers app photos, advertising, purchases, and app support.
Mustardmustache processes information only as needed to deliver pages, maintain security, answer company, partnership, and press inquiries, and comply with law.
2. Information processed
Hosting infrastructure may temporarily process IP address, access time, requested URL, browser or device information, and error or security records to deliver and protect the site. Mustardmustache does not use this data for advertising or visitor behavior profiles.
If you email us, we process the sender address, display name, signature, inquiry, and files you choose to attach. Do not send government identifiers, financial or health data, original photos of pets or children, or other unnecessary sensitive information.
The company website does not install or operate cookies, advertising identifiers, or other automatic collection devices for personalized advertising or visitor analytics, so no behavioral information is collected. You can block or delete cookies at any time in your browser settings.
Mustardmustache does not collect sensitive information or unique identifiers on this site and does not create or process pseudonymized information.
- Website analytics or advertising cookies: none
- Company website account or first-party database: none
- Company contact: hello@mmche.studio
3. Disclosure, processors, and international handling
Mustardmustache does not sell inquiry information or disclose it to third parties unless required by law or separately authorized by you.
Managed hosting, content delivery and security infrastructure, and Google Workspace email may process network or email information outside Korea. Transfers occur through encrypted connections when you visit or send email and are handled under each provider's security, retention, and applicable legal terms.
4. Retention and deletion
Ordinary company inquiries are kept for one year after closure. Contract, purchase, refund, or dispute records may be kept for three years unless applicable law requires longer.
Electronic records held separately by Mustardmustache are securely deleted when their purpose ends. The operator does not retain hosting security logs as a separate visitor profile; infrastructure providers delete them under their operational procedures after the necessary period.
5. Your rights and contact
You may request access, correction, deletion, or restriction of inquiry records about you. We act without undue delay unless retention is legally required or another person's rights would be affected.
Contact the Mustardmustache privacy team at hello@mmche.studio. We may request only the minimum additional information needed to verify the request. Section 8 explains how to exercise each right.
6. Children under 14
The company website does not offer an account or inquiry service directed to children under 14 and does not knowingly collect a child's personal information. A legal guardian should send any inquiry involving a child's personal information.
If we learn that a child's personal information has been collected, we destroy it without delay and, at a legal guardian's request, confirm what was processed.
7. Destruction of personal information
Mustardmustache destroys personal information without delay when the retention period has passed, the processing purpose has been fulfilled, or the information is otherwise no longer needed.
Destruction procedure: information that has become eligible for destruction is identified and destroyed after review by the privacy officer. Information that must be preserved under other statutes is moved to separate storage and destroyed when that preservation period ends.
Destruction method: electronic files are permanently deleted so that the records cannot be reproduced, and any printed material is shredded or incinerated.
8. Rights of data subjects and legal representatives, and how to exercise them
You may at any time request access to your personal information, correction of errors, deletion, or suspension of processing.
Under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, these requests may be made in writing, by email, or by fax, and Mustardmustache acts on them without delay. You can send a request to hello@mmche.studio.
The legal representative of a child under 14, or a person you authorize, may exercise these rights on your behalf. In that case a power of attorney in the form prescribed by Annex 11 of the Notice on Personal Information Processing Methods must be submitted.
Mustardmustache asks only for the minimum additional information needed to confirm that the requester is the data subject or a duly authorized representative. A request may be limited where a statute requires the information to be retained, or where granting it would unfairly harm another person's life, body, property, or rights; in that case the reason is explained.
Mustardmustache does not make automated decisions that affect your rights or obligations, so there is no processing subject to the refusal or explanation rights under Article 37-2 of the Personal Information Protection Act. Mustardmustache is also not a controller subject to the data portability right under Article 35-2 of that Act.
9. Security measures
Under Article 29 of the Personal Information Protection Act, Mustardmustache applies the following security measures.
- Administrative — the number of people who handle personal information is limited to the representative alone, and processing procedures are reviewed against privacy legislation and the official drafting guidance.
- Technical — access to accounts and work devices that handle personal information is restricted and protected by account security measures. Web pages and email are transmitted over encrypted connections.
- Physical — work devices and storage media are locked and access-controlled.
10. Owner responsibility and breach notification
Under Article 30-3 of the Personal Information Protection Act, 설지환, the owner of Mustardmustache, holds ultimate responsibility for personal information protection and secures the staffing and budget needed to process personal information safely.
If Mustardmustache learns that personal information has been lost, stolen, leaked, forged, altered, or damaged, it notifies the affected users without delay under Article 34 of that Act, together with the items and time of the breach, the steps you can take, and how to claim damages or apply for dispute mediation.
11. Remedies for infringement of rights
If you need counseling or remedies for a privacy infringement, you can contact the following Korean authorities.
A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (access), Article 36 (correction or deletion), or Article 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act.
- Personal Information Dispute Mediation Committee — +82-1833-6972 — www.kopico.go.kr
- Privacy Infringement Report Centre (KISA) — +82-118 — privacy.kisa.or.kr
- Supreme Prosecutors' Office, Cybercrime Investigation Division — +82-1301 — www.spo.go.kr
- Korean National Police Agency, Cybercrime Report System — +82-182 — ecrm.police.go.kr
12. Changes to this policy and revision history
This policy applies from its effective date. If content is added, removed, or changed because of a change in law or in the service, notice is posted on this page at least seven days before the change takes effect. Changes that are significant and unfavorable to users are announced at least 30 days in advance.
Urgent changes required by law or security may take effect immediately, with the reason explained afterward.
- v1.0 (effective 27 July 2026) — first issue
- v1.1 (effective 31 July 2026) — revised
- v1.2 (effective 24 August 2026) — destruction procedure, how to exercise rights, security measures, owner responsibility and breach notification, remedies, and privacy officer details added to meet Article 30 of the Personal Information Protection Act
13. Privacy officer and access request desk
- Data controller
- Mustardmustache
- Privacy officer
- 설지환 (Representative)
- Grievance and access request desk
- Mustardmustache Privacy Team
- hello@mmche.studio
- Business address
- 2F, Unit 4, 78 Saeun-ro, Giheung-gu, Yongin-si, Gyeonggi-do 17079, Republic of Korea
