Seaway Global Co., Ltd. recognizes the protection of personal information as a fundamental responsibility and is committed to managing personal data in accordance with applicable laws and internationally recognized standards. We consider data privacy and information security to be essential elements of our business operations and apply high standards of governance and internal controls to safeguard the information entrusted to us.

We are also committed to providing clear and transparent information regarding the collection, use, and management of personal data so that customers and stakeholders can fully understand their rights and choices. Further details are available in our Privacy Policy below.

Article 1 Purpose of Collection and Use of Personal Information

Seaway Global Co., Ltd. (hereinafter referred to as the “Company”) collects and uses personal information within the scope of the following purposes: · Responding to customer inquiries and consultations · Processing quotation requests, contract execution, and fulfillment · Providing products and services, delivery, and after-sales support · Compliance with applicable laws and internal regulations, and handling disputes The Company uses collected personal information only within the scope of the above purposes. In the event that the purpose of use changes, the Company will take necessary measures, including obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

Article 2 Items of Personal Information Collected

The Company may collect the following personal information in order to provide services: · Company name, contact person’s name, email address, and telephone number · Inquiry details · Service usage records such as IP address, cookies, and access logs

Article 3 Retention and Use Period of Personal Information

The Company will promptly destroy personal information once the purpose of collection and use has been achieved.
However, in the following cases, personal information may be retained for a certain period in accordance with internal policies or applicable laws:
1) Retention Based on Internal Policies · Website inquiries and quotation request records: 1 year · Business communications and consultation records with clients: 3 years · Contract and delivery-related records: 5 years after contract termination 2) Retention in Accordance with Applicable Laws · Records on contracts or withdrawal of offers: 5 years · Records on payment and supply of goods or services: 5 years · Tax invoices and accounting records: 5 years · Records on consumer complaints or dispute resolution: 3 years · Website access records (including IP address): 3 months Upon expiration of the retention period, personal information will be safely destroyed in accordance with relevant laws and internal procedures.

Article 4 Provision of Personal Information to Third Parties

The Company does not, in principle, provide personal information to third parties.
However, in accordance with Article 18 of the Personal Information Protection Act, personal information may be used beyond the original purpose or provided to third parties in the following cases:
1. Where separate consent has been obtained from the data subject 2. Where required by law or special provisions in other statutes 3. Where clearly necessary to protect the life, body, or property of the data subject or a third party 4. Where provided in a form that does not identify specific individuals for statistical or academic research purposes 5. Where required for court proceedings 6. Where requested by investigative authorities in accordance with applicable laws

Article 5 Measures to Ensure the Security of Personal Information

The Company implements the following measures to ensure the security of personal information in accordance with Article 29 of the Personal Information Protection Act. 1) Administrative Measures · Establishment and implementation of internal management plans for personal information protection · Designation of authorized personnel and management of access rights · Regular education and training of employees on personal information protection and information security

2) Technical Measures · Restricting access to personal information to authorized personnel only · Operation of security programs and access control systems · Application of appropriate safeguards when storing or transmitting personal information

3) Physical Measures · Access control to facilities where personal information is stored · Secure storage of documents and storage media in locked locations

Article 6 Rights and Obligations of Data Subjects and Methods of Exercise

Data subjects may exercise the following rights regarding personal information at any time: · Request access to personal information · Request correction or deletion of personal information · Request suspension of processing of personal information 1. Requests may be made in writing, by email, or through other methods provided by the Company, and the Company will take necessary actions without delay in accordance with applicable laws. 2. Rights may also be exercised through a legal representative or an authorized agent. In such cases, the Company may request submission of documents verifying authorization. 3. Requests for access or suspension of processing may be restricted in accordance with Articles 35 and 37 of the Personal Information Protection Act. 4. Requests for correction or deletion may be restricted where the personal information is required to be collected or retained under other applicable laws. 5. The Company may verify the identity of the requester to ensure that the request is made by the data subject or a duly authorized representative.

Article 7 Personal Information Protection Officer

· Department in Charge: Management Support Team · Officer: Andy Park · Tel: +82-51-995-3999 · Email: admin@seawayglobal.com 1. Requests may be made in writing, by email, or through other methods provided by the Company, and the Company will take necessary actions without delay in accordance with applicable laws. 2. Rights may also be exercised through a legal representative or an authorized agent. In such cases, the Company may request submission of documents verifying authorization. 3. Requests for access or suspension of processing may be restricted in accordance with Articles 35 and 37 of the Personal Information Protection Act. 4. Requests for correction or deletion may be restricted where the personal information is required to be collected or retained under other applicable laws. 5. The Company may verify the identity of the requester to ensure that the request is made by the data subject or a duly authorized representative.

Article 8 Remedies for Infringement of Rights

Data subjects may apply for dispute resolution or consultation regarding personal information infringement to the following organizations: · Personal Information Dispute Mediation Committee / Tel: +82-1833-6972 / Website: www.kopico.go.kr · Personal Information Infringement Report Center / Tel: +82-118 / Website: privacy.kisa.or.kr · Supreme Prosecutors’ Office Cyber Investigation Division / Tel: +82-1301 / Website: www.spo.go.kr · National Police Agency Cyber Bureau / Tel: +82-182 / Website: ecrm.police.go.kr The Company is committed to protecting the data subject’s right to informational self-determination and to providing consultation and remedies for personal information infringement. For any inquiries related to personal information, please contact the Personal Information Protection Officer.

Article 9 (Changes to this Privacy Policy)

This Privacy Policy may be amended in accordance with applicable laws, regulations, or Company policies.

Effective Date: February 12, 2026