Privacy policy

This is an English translation of our Korean privacy policy (개인정보 처리방침). If the two differ, the Korean version prevails.

Hello Mindfulness is part of the Korea Institute for Mindfulness and Neuroscience (KIMN, ‘the Institute’, k-mindfulness.com), which runs the website hellomindfulness.com. The Institute has drawn up and publishes this privacy policy under Article 30 of the Korean Personal Information Protection Act (PIPA), to protect your personal data and to deal with any related concerns promptly and smoothly.

Article 1 (Personal data we process: what, why, on what basis and for how long)

We process only the minimum personal data needed for the purposes below and use it for nothing else. The website has no registration, login or payment.

Visiting the website (recorded automatically)

  • Data: IP address, date and time of access, page requested, referring page, browser and operating system, response status
  • Purpose: delivering the website, keeping it secure, fixing errors
  • Legal basis: the Institute’s legitimate interest in running the website securely (PIPA Article 15(1)(vi))
  • Retention: up to 3 months, then deleted automatically (Institute policy)

Emailing us

  • Data: email address, name (if given), content of your message
  • Purpose: reading and answering your enquiry (including questions about courses)
  • Legal basis: the Institute’s legitimate interest in answering your enquiry (PIPA Article 15(1)(vi))
  • Retention: 1 year after we have answered, then deleted (Institute policy)

Article 2 (Cookies and other automatic data collection)

We use no cookies or other tools that collect personal data automatically, and we store nothing in your browser. The website uses no external fonts or scripts, no advertising and no social-media plugins.

The video on the home page is provided by Vimeo (USA), an independent third-party provider. Nothing is loaded from Vimeo until you press play. When you do, your browser connects directly to Vimeo, which receives your IP address and browser information. We use Vimeo’s “do not track” setting, which stops the player from collecting viewing statistics and from setting tracking cookies. Vimeo still sets security cookies (from its protection service Cloudflare), and the player also loads files from other servers, such as Google’s. We have no control over how Vimeo handles this data; Vimeo’s privacy policy applies.

Article 3 (Disclosure to third parties)

We do not give your personal data to third parties, except with your separate consent or where the law specifically requires it. If you play the video on the home page, your browser sends data directly to Vimeo (see Article 2).

Article 4 (Service providers processing data on our behalf)

We entrust the following providers with processing personal data for the website. Our contracts forbid them to use the data for anything else and require security measures, and we supervise their compliance.

  • Hostinger International Limited: website hosting and server operation
  • Google Asia Pacific Pte. Ltd.: receiving and storing email, and running our Google Workspace (sub-processor: Google LLC)

If a provider or its task changes, we will announce it in this privacy policy.

Article 5 (Transfer of personal data abroad)

Because our web server and email service are located outside Korea, we transfer personal data abroad as follows (entrusted processing and storage). The legal basis is given for each transfer.

Website hosting

  • Recipient: Hostinger International Limited (contact: gdpr@hostinger.com)
  • Countries: Germany (Frankfurt) and France (backup servers)
  • Data: website access records (Article 1)
  • Purpose: website hosting and server operation
  • When and how: sent over the network when you visit the website
  • Retention: up to 3 months
  • Legal basis: transfer to an EU country whose level of data protection the Personal Information Protection Commission has recognised as equivalent (PIPA Article 28-8(1)(v))

Email service

  • Recipients: Google Asia Pacific Pte. Ltd. (Singapore) and its sub-processor Google LLC (USA) (contact: https://support.google.com/policies/contact/general_privacy_form)
  • Countries: Singapore, the United States and other countries where Google has data centres
  • Data: email enquiry data (Article 1)
  • Purpose: receiving and storing email
  • When and how: sent over the network when you email us
  • Retention: 1 year after we have answered
  • Legal basis: entrusted processing and storage needed to answer your enquiry, disclosed in this privacy policy (PIPA Article 28-8(1)(iii))

If you do not want your data transferred abroad, you can choose not to use the website or email us. In that case you will not be able to use the website or contact us by email.

Article 6 (Destruction of personal data)

When the retention period ends or the purpose has been fulfilled, we destroy the data without delay. Access records are deleted from the server automatically at the end of their retention period, and emails are deleted so that they cannot be restored. Where the law requires us to keep data, we store it separately from other personal data.

Article 7 (Your rights and how to exercise them)

You can at any time ask us to show you your personal data, to correct or delete it if it is wrong, or to stop processing it. Send your request to the email address in Article 9; we will act within the period set by law. A legal representative or someone you have authorised can also exercise these rights on your behalf.

Article 8 (Security measures)

We protect personal data with the following measures:

  • All connections to the website are encrypted (HTTPS)
  • Server access is limited to authorised staff and possible only with cryptographic keys
  • The website is static, with no database, user accounts or input forms, which keeps the personal data we process to a minimum

Article 9 (Privacy officer)

We have designated the following department to oversee the processing of personal data and to handle related questions, complaints and redress.

Article 10 (Remedies)

To seek redress for an infringement of your personal data, you can apply to the following Korean bodies for dispute resolution or advice:

Article 11 (Information for visitors in Switzerland and the EU/EEA)

Where the Swiss Federal Act on Data Protection (FADP) or the EU General Data Protection Regulation (GDPR) applies, please also note the following:

  • Controller: Korea Institute for Mindfulness and Neuroscience (한국마음챙김뇌과학연구소), for Hello Mindfulness, privacy@hellomindfulness.com
  • Website access records: the Institute’s legitimate interest in the security and reliable operation of the website (GDPR Article 6(1)(f))
  • Email enquiries: the Institute’s legitimate interest in answering your enquiry (GDPR Article 6(1)(f))
  • Vimeo video: Vimeo, an independent third-party provider, is contacted only if you choose to play the video (your consent, GDPR Article 6(1)(a))
  • Transfers to the United States: Google LLC is certified under the EU–US and Swiss–US Data Privacy Frameworks (DPF); standard contractual clauses (SCCs) also apply.

In addition to the rights above, you have the right to restrict processing, the right to data portability, and the right to object to processing based on legitimate interest. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) or to the supervisory authority in your EU/EEA country of residence.

Article 12 (Changes to this privacy policy)

This privacy policy applies from 4 October 2026. If it changes, we will announce the changes and their effective date on the website; earlier versions are available on request.