The Company (hereinafter referred to as the “Company”) establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than those listed below, and if the purpose of use changes, necessary measures such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act will be implemented.
1. Website Membership Registration and Management
Personal information is processed for purposes such as confirming the intention to register as a member, providing member services, identification and authentication for the provision of member services, maintaining and managing membership qualifications, identity verification under the limited identity verification system, prevention of fraudulent use of services, verification of consent from legal guardians when processing personal information of children under the age of 14, notices and announcements, and grievance handling.
2. Provision of Goods or Services
Personal information is processed for purposes such as delivery of goods, provision of services, sending contracts and invoices, providing content, providing customized services, identity verification, age verification, payment and settlement of fees, and debt collection.
3. Grievance Handling
Personal information is processed for purposes such as verifying the identity of complainants, confirming complaints, contacting and notifying for fact-finding investigations, and notifying the results of processing.
Article 2 (Processing and Retention Period of Personal Information)
① The Company processes and retains personal information within the personal information retention and use period prescribed by law or agreed upon by the data subject at the time of collection.
② The processing and retention periods for each type of personal information are as follows:
1. Website Membership Registration and Management: Until withdrawal from the business/organization website
However, in the following cases, until the relevant reason ends:
1) If investigations or inquiries due to violations of related laws are in progress, until such investigations or inquiries are completed
2) If claims and obligations arising from website use remain unsettled, until such claims and obligations are settled
2. Provision of Goods or Services: Until the supply of goods/services and payment/settlement are completed
However, in the following cases, until the relevant period expires:
1) Records related to transactions such as 표시·advertising, contract details, and performance under the Act on Consumer Protection in Electronic Commerce, etc.
- Records on 표시·advertising: 6 months
- Records on contracts or withdrawal of subscription, payment, and supply of goods: 5 years
- Records on consumer complaints or dispute resolution: 3 years
2) Retention of communication confirmation data under Article 41 of the Protection of Communications Secrets Act
- Subscriber telecommunications date and time, start/end time, counterpart subscriber number, usage frequency, and location tracking data of transmitting base stations: 1 year
- Computer communication and internet log records, access location tracking data: 3 months
Article 3 (Provision of Personal Information to Third Parties)
① The Company processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or special provisions of law.
② For smooth service provision, the Company may provide personal information to third parties within the minimum necessary scope after obtaining consent from the data subject pursuant to Article 17(1)1 of the Personal Information Protection Act in the following cases:
- Recipient of personal information:
- Purpose of use by recipient:
- Items of personal information provided:
- Retention and use period by recipient:
Article 4 (Entrustment of Personal Information Processing)
① The Company entrusts personal information processing tasks as follows for smooth handling of personal information affairs.
- Details of entrusted tasks
- Entrusted party (processor): Imweb Co., Ltd.
- Details of entrusted tasks: Provision of systems for shopping mall hosting services, mobile app services, marketing services and additional affiliated services, AlimTalk, FriendTalk, and text message sending agency services, etc.
- Entrusted party (processor): OOO PG
- Details of entrusted tasks: Payment and escrow services
- Entrusted party (processor): OOO Delivery
- Details of entrusted tasks: Product delivery services
- Entrusted party (processor): OOO Customer Center
- Details of entrusted tasks: Customer consultation services
- Entrusted party (processor): OOO
- Details of entrusted tasks: Identity verification services
- **Sub-processors**
- **Sub-processor: Imweb Co., Ltd. → Infobip Ltd.**
- **Details of entrusted tasks: Sending text messages and KakaoTalk AlimTalk (informational messages)**
- **Sub-processor: Imweb Co., Ltd. → LUNASOFT Co., Ltd.**
- **Details of entrusted tasks: Sending text messages, KakaoTalk AlimTalk (informational messages), and FriendTalk messages**
② When entering into entrustment contracts, the Company specifies matters related to prohibition of personal information processing for purposes other than entrusted tasks, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of processors, and liability such as compensation for damages in documents such as contracts pursuant to Article 25 of the Personal Information Protection Act, and supervises whether processors safely handle personal information.
③ If the content of entrusted tasks or processors changes, the Company will disclose such changes promptly through this Privacy Policy.
Article 5 (Rights of Data Subjects and Legal Representatives and Methods of Exercise)
① Data subjects may exercise the following rights related to personal information protection at any time against the Company:
1. Request access to personal information
2. Request correction in case of errors, etc.
3. Request deletion
4. Request suspension of processing
② Rights under Paragraph 1 may be exercised through written documents, telephone, email, fax, etc., and the Company will take action without delay.
③ If a data subject requests correction or deletion of personal information due to errors, etc., the Company will not use or provide such personal information until the correction or deletion is completed.
④ Rights under Paragraph 1 may be exercised through a legal representative or an authorized agent of the data subject. In such cases, a power of attorney in the form specified in Appendix No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
⑤ Data subjects shall not infringe upon their own or others’ personal information and privacy processed by the Company in violation of related laws such as the Personal Information Protection Act.
Article 6 (Items of Personal Information Processed)
The Company processes the following personal information items:
1. Website Membership Registration and Management
Required items:
Optional items:
2. Provision of Goods or Services
Required items:
Optional items:
Article 7 (Destruction of Personal Information)
① The Company destroys personal information without delay when the retention period expires or the processing purpose is achieved and the personal information becomes unnecessary.
② If personal information must continue to be preserved pursuant to other laws despite the expiration of the agreed retention period or achievement of the processing purpose, such personal information will be transferred to a separate database (DB) or stored in a different location.
③ The procedures and methods for destruction of personal information are as follows:
1. Destruction Procedure
The Company selects personal information for destruction when grounds for destruction arise and destroys such personal information after obtaining approval from the Company’s Chief Privacy Officer.
2. Destruction Method
The Company destroys personal information recorded and stored in electronic file form in a manner that prevents restoration, and destroys personal information recorded and stored on paper documents by shredding or incineration.
Article 8 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information:
1. Administrative measures: Establishment and implementation of internal management plans, regular employee training, etc.
2. Technical measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs, etc.
3. Physical measures: Access control to computer rooms and data storage rooms
Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
① The Company uses cookies that store and frequently retrieve user information in order to provide individualized customized services.
② Cookies are small amounts of information sent by the server (HTTP) operating the website to the user’s computer browser and stored on users’ PCs or mobile devices.
③ Data subjects may set options in their web browser to allow or block cookies. However, if cookie storage is refused, there may be difficulties in using customized services.
▶ Allowing/Blocking Cookies in Web Browsers
- Chrome: Web Browser Settings > Privacy and Security > Clear Browsing Data
- Edge: Web Browser Settings > Cookies and Site Permissions > Manage and Delete Cookies and Site Data
▶ Allowing/Blocking Cookies in Mobile Browsers
- Chrome: Mobile Browser Settings > Privacy and Security > Clear Browsing Data
- Safari: Mobile Device Settings > Safari > Advanced > Block All Cookies
- Samsung Internet: Mobile Browser Settings > Browsing History > Clear Browsing History
④ The Company collects and uses information such as users’ visits to each service and website, usage patterns, popular search terms, and secure access status during the service use process in order to provide optimized information to users.
Article 10 (Chief Privacy Officer)
① The Company designates the following Chief Privacy Officer to oversee personal information processing affairs and handle complaints and remedies related to personal information processing.
▶ Chief Privacy Officer
Name: OOO
Position: OOO
Contact: , ,
※ Connected to the department in charge of personal information protection.
▶ Department in Charge of Personal Information Protection
Department: OOO Team
Contact: , ,
② Data subjects may contact the Chief Privacy Officer and the responsible department regarding all inquiries, complaints, and remedies related to personal information protection arising while using the Company’s services (or business). The Company will respond and process such inquiries without delay.
Article 11 (Request for Access to Personal Information)
Data subjects may request access to personal information pursuant to Article 35 of the Personal Information Protection Act from the following department. The Company will endeavor to process requests for access promptly.
▶ Department for Receiving and Processing Requests for Access to Personal Information
Department: OOO
Contact: , ,
Article 12 (Methods of Remedy for Infringement of Rights and Interests)
Data subjects may contact the following organizations for damage relief, consultation, etc. regarding personal information infringement.
1. Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
2. Personal Information Infringement Report Center: (without area code) 118 (privacy.kisa.or.kr)
3. Supreme Prosecutors’ Office: (without area code) 1301 (www.spo.go.kr)
4. National Police Agency: (without area code) 182 (ecrm.police.go.kr/minwon/main)
Article 13 (Enforcement and Amendment of the Privacy Policy)
This Privacy Policy shall take effect from XX/XX/20XX.