Privacy Policy Annex · English

Privacy Policy Annex for Overseas Churches

English translation for churches using Wesleysoft outside the Republic of Korea.
The Korean original prevails.

Translation — effective 12 October 2026

This is an English translation provided for your understanding. The Korean original is the authoritative version (Article 11). Korean original: 개인정보 처리방침 부록. This Annex applies only to churches that use Wesleysoft outside the Republic of Korea; nothing changes for churches in Korea. The Privacy Policy itself is available at 개인정보처리방침 (Korean).

Wesleysoft (the "Company") adds this Annex to its Privacy Policy (the "Policy") for churches that use Wesley Gyojeok (웨슬리 교적, church records), Wesley Jaejeong (웨슬리 재정, church finance) and Wesley Simbang Plus (웨슬리 심방플러스, pastoral visits) outside the Republic of Korea. Matters not set out in this Annex are governed by the Policy. Where this Annex and the Policy differ, this Annex prevails with respect to overseas churches.

Article 1 (Scope)

  1. This Annex applies to churches that selected 「해외 사용 교회」 (church using the service outside Korea) at sign-up and were approved by the Company (each an "Overseas Church"), and to the personal data of members and other persons that an Overseas Church enters into the service.
  2. An Overseas Church cannot log in to the service until the Company approves it. Until then, the Company processes only the information needed for the sign-up application.

Article 2 (Roles and Responsibilities)

  1. With respect to the member data and financial records entered by an Overseas Church, the party that determines the purposes and means of processing (the controller) is the Overseas Church. The Company processes that data on behalf of and on the instructions of the Overseas Church (the processor).
  2. The Company does not process the entrusted personal data for any purpose other than providing the service, and does not view or use it unless instructed by the Overseas Church.
  3. Obligations that the laws of the church's country impose on controllers — such as informing members of the processing, establishing a legal basis for processing, and responding to members' requests to exercise their rights — are fulfilled by the Overseas Church. The Company cooperates by providing the functions and information needed for this.
  4. The terms of processing between the Overseas Church and the Company are set out in the separate "Data Processing Agreement for Overseas Churches".

Article 3 (Personal Data Processed)

  1. For sign-up and account management, the Company itself processes the following information:

    1. Required — church name, country of use, name of the contact person, mobile telephone number (with country code), e-mail address, password

    2. The Korean church identification number (고유번호) is not collected from Overseas Churches. Sign-up confirmation and ID and password recovery are carried out by e-mail only.

  2. The categories of member data and financial records processed on behalf of an Overseas Church are the same as in Article 2 of the Policy. In addition, the following may be processed:

    1. Family name and given name in Latin letters; address in the format of that country (street address, city, state or region, postal code)

    2. Where the church issues donation receipts under the rules of its country: the donor's name, address, and the amount and date of each donation

  3. The Company does not process Korean resident registration numbers for Overseas Churches. A church may choose not to enter dates of birth.

Article 4 (Storage Location and International Transfers)

  1. All data of Overseas Churches is stored on the Company's servers located in the Republic of Korea (sub-processor: YourIT Co., Ltd.) and is kept separate for each church from the data of other churches.
  2. When an Overseas Church enters data into the service, that data is transferred from the church's country to the Republic of Korea. This transfer is based on the following:

    1. Member States of the European Union, Norway, Iceland and Liechtenstein — the decision of the European Commission recognising that the Republic of Korea ensures an adequate level of protection of personal data (Commission Implementing Decision (EU) 2022/254 of 17 December 2021).

    2. United Kingdom — The Data Protection (Adequacy) (Republic of Korea) Regulations 2022.

    3. Türkiye — member data is processed only after the Overseas Church and the Company have concluded the standard contract set by the Turkish Personal Data Protection Authority and the Overseas Church has notified the Authority of it.

    4. Other countries — member data is processed only after the Overseas Church and the Company have put in place the transfer mechanism required by the laws of that country (such as standard contractual clauses).

  3. Except as described in Article 6, the Company does not transfer the data of Overseas Churches onward outside the Republic of Korea.

Article 5 (Sub-processing)

  1. To provide the service, the Company engages the processors listed in Article 5 of the Policy as sub-processors. For Overseas Churches they are as follows. All are businesses established in the Republic of Korea and process data within the Republic of Korea.
    Sub-processorProcessing entrusted
    YourIT Co., Ltd.Provision of servers and storage; data storage
    NHN Cloud Corp.Sending e-mails such as sign-up confirmations, payment notices and password recovery (no text messages are sent to mobile numbers outside Korea)
    Upstage Co., Ltd.Drafting sermon texts in Wesley Simbang Plus (only the items stated in Article 2 of the Policy are sent; no information that identifies a member is sent)
    Toss Payments Co., Ltd.Processing of fee payments (Overseas Churches currently pay by bank transfer)
  2. If the Company changes or adds a sub-processor, it will amend this Annex and give notice in advance. The Overseas Church may object as provided in the Data Processing Agreement.

Article 6 (Route Guidance and Google Maps)

  1. When a user of an Overseas Church presses the Route (길안내) button for a visit in Wesley Simbang Plus, the destination address is passed to the map service operated by Google LLC (United States).
  2. Only the destination address of the visit the user pressed is passed. No other information, such as the member's name or contact details, is passed. Nothing is passed unless the button is pressed.
  3. The address passed is processed in accordance with the privacy policy of Google LLC.

Article 7 (Members' Rights and How to Exercise Them)

  1. Members may, as provided by the laws of the church's country, exercise rights over their personal data such as the rights of access, rectification, erasure, restriction of processing, objection to processing and data portability. Where processing is based on consent, they may withdraw their consent at any time.
  2. As a rule, members exercise their rights with the Overseas Church, which is the controller. The Overseas Church can view, correct, delete or download member data on the screens of the service.
  3. If a member makes a request directly to the Company, the Company forwards it to the church without delay and acts on the church's instructions.
  4. Members have the right to lodge a complaint with the data protection supervisory authority of the country in which they live.

Article 8 (Retention and Destruction)

The retention period and method of destruction for the data of Overseas Churches follow Articles 3 and 8 of the Policy. After the service contract ends, the data is kept for 90 days so that the church can export it, and is then destroyed so that it cannot be recovered. If an Overseas Church requests immediate destruction, the Company destroys the data without delay.

Article 9 (Security Measures)

The Company applies to the data of Overseas Churches the same measures as described in Article 9 of the Policy. These include encryption in transit (HTTPS), storage of passwords using an irreversible method, access controls that keep each church's data separate so that other churches cannot see it, role-based permissions, the operation of a firewall and anti-malware software, and regular backups.

Article 10 (Notification of Personal Data Breaches)

  1. If the Company becomes aware of an incident in which the data of an Overseas Church has been or may have been leaked, it notifies the church without delay of the facts and circumstances, the scope of the data concerned, and the measures the Company has taken.
  2. The Company provides the information and cooperation needed for the Overseas Church to notify the supervisory authority and members within the period set by the laws of its country.

Article 11 (Language)

The Korean version of this Annex is the authoritative original. Translations into English and other languages are provided for your understanding. If a translation differs from the Korean original, the Korean original prevails, unless the laws of the church's country provide otherwise.

Article 12 (Contact)

Questions about this Annex and requests to exercise rights may be sent to the Company's Chief Privacy Officer.

Chief Privacy OfficerChoi Sangbong (Representative)
E-mailwesleysoft@wesleysoft.com
HoursWeekdays, Korean time (the contact screen also shows the local time of the church's country)

Supplementary Provision

This Annex takes effect on 12 October 2026.

Wesleysoft · Representative: Choi Sangbong · Business Registration No. 237-31-01809
Address: 101-105, 74 Bonghwa-ro, Wonju-si, Gangwon State, Republic of Korea (Dangye-dong, Dangye Samik Apartment)
Telephone +82 10-2586-5119 · E-mail wesleysoft@wesleysoft.com

문의하기

교회 상황을 알려주시면 알맞은 요금제를 안내해 드리겠습니다. 처음 설정도 도와드립니다.

보내주신 정보는 도입 상담 목적으로만 사용하며, 상담이 끝나면 파기합니다. 자세한 내용은 개인정보처리방침을 참고하십시오.
폼이 어려우시면 wesleysoft@wesleysoft.com으로 보내주셔도 됩니다.