Weekly LSAT ("we", "us") operates the website at weeklylsat.com and publishes a free email newsletter. This policy explains what personal information we handle, why, and what you can do about it. It is written to meet the Republic of Korea's Personal Information Protection Act (PIPA) and the Act on Promotion of Information and Communications Network Utilization and Information Protection (Network Act), and — for readers in the EU, UK, and United States — the GDPR, UK GDPR, and applicable US state privacy and email laws.
| Data controller | WeeklyLSAT 2F 205, 96 Banyeo-ro, Haeundae-gu Busan 48036 Republic of Korea |
|---|---|
| Privacy Officer (개인정보 보호책임자) |
Privacy Office, WeeklyLSAT privacy@weeklylsat.com |
You can reach us about anything in this policy at privacy@weeklylsat.com. We answer privacy requests within 10 days.
| Email address | Required. It's the only field on the signup form. |
|---|---|
| Consent record | The date, time, and IP address at the moment you subscribed, plus the date and time you confirmed via the double opt-in email. We keep this solely to prove that you consented, which the law requires us to be able to do. |
| Email engagement | Whether an email was opened and which links were clicked, where your email client permits it. We use this only to judge whether the newsletter is any good. You can defeat it by disabling remote images in your email client. |
|---|---|
| Basic site analytics | Page views and referrer, in aggregate. See section 8 on cookies. |
We do not collect your name, phone number, date of birth, address, payment details, LSAT scores, test dates, or any information about your applications. We have no accounts and no passwords. If we ever add those, we will update this policy and tell you before it takes effect.
| Sending you the newsletter | Your consent. PIPA Art. 15(1)(1) and Network Act Art. 50(1); GDPR Art. 6(1)(a). |
|---|---|
| Service notices about the newsletter itself | E.g. a change to this policy or to the sending schedule. Same consent basis; we keep these rare and never use them as disguised marketing. |
| Keeping a consent record | Legal obligation — we must be able to demonstrate valid consent. PIPA Art. 22; GDPR Art. 7(1). |
| Measuring engagement, security, abuse prevention | Our legitimate interest in running a functioning newsletter that isn't overrun by bots. GDPR Art. 6(1)(f). |
We will not use your email address for any purpose beyond the ones listed here without asking you again first.
| Your email address | Until you unsubscribe or ask for deletion. We then erase it without undue delay, and in any case within 30 days. |
|---|---|
| Consent and unsubscribe records | Up to 3 years after you leave the list. The Network Act requires us to retain proof of consent and of opt-out handling; keeping a record of your unsubscribe is also what stops us from accidentally re-adding you. |
| Engagement data | Deleted or de-identified within 12 months. |
When a retention period ends, electronic records are permanently deleted so that they cannot be recovered. We keep no paper records.
Reconfirming your consent. Where required by the Network Act, we will contact you around every two years to confirm you still want the newsletter. If you don't respond, we'll stop sending.
We do not sell your personal information, and we never have. We do not share it with advertisers, data brokers, or other newsletters. We do not run list swaps.
We do use a small number of service providers to actually operate the newsletter. Under PIPA these are entrusted processors (수탁자); under GDPR, processors. They may only act on our instructions:
| REPLACE_WITH_ESP_NAME e.g. Kit, Beehiiv, Mailchimp |
Stores the subscriber list and sends the emails. Located in the United States. |
|---|---|
| Cloudflare, Inc. | Hosts weeklylsat.com, serves this page, and provides DNS and security filtering. |
If we change providers, we'll update this list here. We may also disclose information where a law, warrant, or court order compels us to — and we will tell you if we're legally permitted to.
Our email provider stores data on servers outside Korea, primarily in the United States. The data transferred is your email address and engagement data described above; the purpose and retention are as described in sections 3 and 4. Transfers of EU/UK personal data rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the provider. If you object to this transfer, we unfortunately cannot deliver the newsletter to you — you may decline to subscribe or unsubscribe at any time.
Wherever you live, you can:
Email privacy@weeklylsat.com from the address you subscribed with and we'll handle it — within 10 days under PIPA, within 30 days under GDPR, and within 45 days under US state law. There is no charge. You may also act through an authorized agent.
We make no automated decisions about you and do not profile you. We knowingly collect nothing from children under 14 (Korea) or under 16 (EU/UK); if you believe a child has subscribed, tell us and we'll delete the record.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authority as required — under PIPA, without delay and within 72 hours; under GDPR, within 72 hours to the supervisory authority.
This site sets no advertising cookies and no third-party marketing trackers. We do not run Meta Pixel, Google Ads tags, or similar.
For traffic measurement we use Cloudflare Web Analytics, which is cookieless. It records aggregate page views and referrers, does not set any cookie, does not fingerprint your device, and cannot follow you to other websites. Because it stores nothing on your device and does not identify you, no cookie banner is required.
Newsletter emails may contain a tracking pixel to count opens, as described in section 2. Blocking remote images in your email client prevents this.
We honor Global Privacy Control (GPC) signals where your browser sends one.
Tell us first — privacy@weeklylsat.com. Most things are fixable in a day. If you're not satisfied, you can complain to:
| Korea | Personal Information Infringement Report Center (KISA) — privacy.kisa.or.kr, 118 Personal Information Dispute Mediation Committee — kopico.go.kr, 1833-6972 Personal Information Protection Commission — pipc.go.kr |
|---|---|
| EU / UK | Your national data protection authority, or the UK Information Commissioner's Office (ico.org.uk). |
| United States | Your state Attorney General, or the FTC (reportfraud.ftc.gov). |
If we change anything material — new data collected, a new purpose, a new processor — we will post the revised policy here with a new "last updated" date and email subscribers at least 7 days before it takes effect. Minor clarifications will be posted without separate notice.