This Privacy Policy shall take effect as of February 1, 2019.
Hantle System Co., Ltd. (hereinafter referred to as the “Company”) establishes the following Privacy Policy in accordance with the Personal Information Protection Act to protect users’ personal information and rights, and to smoothly handle users’ complaints related to personal information. In the event that this Privacy Policy is amended, the Company will provide notice through announcements on the website (or by individual notice).
1. Purpose of Collection and Use of Personal Information
The Company processes personal information for the following purposes. The personal information processed shall not be used for purposes other than those stated below, and if the purpose of use is changed, prior consent will be obtained.
A. Website Membership Registration and Management
Personal information is processed for purposes such as confirming the intent to register as a member, identifying and authenticating users in connection with the provision of membership-based services, maintaining and managing membership status, verifying identity in accordance with the limited identity verification system, preventing fraudulent use of services, delivering various notices and notifications, handling complaints, and retaining records for dispute resolution.
B. Handling of Civil Complaints
Personal information is processed for purposes such as verifying the identity of complainants, confirming the details of complaints, contacting and notifying complainants for fact-finding, and informing them of the results of complaint handling.
C. Provision of Goods or Services
Personal information is processed for purposes such as delivery of goods, provision of services, issuance of invoices, provision of content, provision of customized services, identity verification, age verification, and payment processing and settlement.
D. Use for Marketing and Advertising
Personal information is processed for purposes such as developing new services (products) and providing customized services, providing event and promotional information and opportunities for participation, providing services and displaying advertisements based on demographic characteristics, verifying the effectiveness of services, identifying frequency of access, and compiling statistics on members’ service usage.
2. Items of Personal Information Collected and Methods of Collection
A. Items Collected
A-1. Items Collected upon Membership Registration
- Required items: Name, gender, login ID, password, email address, date of birth, address, mobile phone number
- Optional items: Home phone number, consent to receive SMS messages, consent to receive emails
- Purpose of collection: Identification of members and delivery of notices, confirmation of user intent, handling complaints, and securing smooth communication channels
A-2. Automatically Collected Information
- Access IP information, cookies, service usage records, access logs, etc.
A-3. Other Cases (Events or Marketing Activities, etc.)
- Information collected: Address, date of birth, telephone number, mobile phone number, name, email address, etc.
- Where personal information is collected on a short-term basis for specific purposes, such collection will be separately announced in advance.
B. Methods of Collection b-1. Personal information is collected through the following methods:
- Website (membership registration), written forms, telephone, fax, customer consultation bulletin boards, event participation, service usage, and modification of member information
3. Consent to the Collection of Personal Information
The Company has established procedures that allow you to indicate your consent by checking the “Agree” button with respect to the contents of the Company’s Privacy Policy or Terms and Conditions. By checking the “Agree” button, you are deemed to have consented to the collection of your personal information.
4. Matters Concerning the Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
A. To provide individualized customized services, the Company uses “cookies,” which store and retrieve usage information from time to time.
B. Cookies are small pieces of information sent by the server (HTTP) used to operate a website to a user’s computer browser, and may be stored on the hard disk of the user’s PC.
- Purpose of using cookies: Cookies are used to identify users’ visits to each service and website, usage patterns, popular search terms, and whether secure connections are used, in order to provide users with optimized information.
- Installation, operation, and refusal of cookies: You may refuse the storage of cookies by adjusting the options in your web browser settings under “Tools > Internet Options > Privacy.”
- If you refuse the storage of cookies, you may experience difficulties in using customized services.
5. Retention and Processing Period of Personal Information
A. The Company processes and retains personal information within the retention and use period prescribed by applicable laws or within the period agreed upon by the data subject at the time of collection.
B. Each item of personal information shall be destroyed once the purpose of collection or the purpose for which it was provided has been achieved, as follows:
- Membership registration information: When the Member withdraws from membership or is expelled
- Personal information collected for temporary purposes such as surveys or events: When the relevant survey or event has concluded
C. Notwithstanding the foregoing, where it is necessary to retain personal information for a certain period to confirm transactional rights and obligations in accordance with applicable laws such as the Commercial Act and the Act on Consumer Protection in Electronic Commerce, etc., such information shall be retained for the periods specified below:
- Records concerning contracts or withdrawal of subscription, etc.: 5 years
- Records concerning consumer complaints or dispute resolution: 3 years
6. Provision and Sharing of Personal Information with Third Parties
The Company shall not, under any circumstances, use or provide users’ personal information beyond the scope notified under “Items of Personal Information Collected and Purposes of Collection” and “Purpose of Use of Personal Information,” except where the user has given consent or where otherwise permitted under applicable laws. However, the following cases shall be exceptions:
- Where users have given prior consent.
- Where it is necessary for the settlement of fees in connection with the provision of services.
- Where it is necessary for the performance of a contract (e.g., product delivery/installation, service-related operations).
- Where there are sufficient grounds to determine that disclosure of customer information is necessary in order to take legal action against a person who has caused mental or material damage to others.
- Where personal information is provided to external institutions or organizations in a form that does not identify specific individuals, for purposes such as statistical compilation, marketing analysis, or market research.
- Where required by relevant laws and regulations, or where investigative authorities request such information in accordance with the procedures and methods prescribed by law for investigative purposes.
- Where the personal information is necessary for the performance of a contract relating to the provision of services, and obtaining ordinary consent is significantly difficult due to economic or technical reasons.
7. Rights and Obligations of Data Subjects and Methods of Exercising Such Rights
A. Data subjects may exercise the following personal information protection–related rights with respect to the Company at any time:
- Request access to personal information
- Request correction in the event of errors
- Request deletion
- Request suspension of processing
B. The exercise of rights pursuant to Paragraph 1 may be made to the Company in writing, by email, or by facsimile (FAX) using the form prescribed in Appendix Form No. 8 of the Enforcement Rules of the Personal Information Protection Act, and the Company shall take action without delay.
C. Where a data subject requests correction or deletion of personal information due to errors, etc., the Company shall not use or provide such personal information until the correction or deletion is completed. d. The rights set forth in Paragraph 1 may be exercised through a legal representative of the data subject or an authorized agent. In such cases, a power of attorney in the form prescribed in Appendix Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
8. Destruction of Personal Information
In principle, the Company shall destroy personal information without delay once the purpose of processing such personal information has been achieved. The procedures, time limits, and methods of destruction are as follows
A. Destruction Procedures
Information entered by users is transferred to a separate database (or, in the case of paper documents, to separate files) after the purpose of collection has been achieved, and is stored for a certain period in accordance with internal policies and relevant laws before being destroyed, or destroyed immediately. At this time, personal information transferred to a database shall not be used for any purpose other than those prescribed by law.
B. Time Limit for Destruction
Users’ personal information shall be destroyed within five (5) days from the end date of the retention period when the retention period has expired. Where personal information becomes unnecessary due to the achievement of the processing purpose, discontinuation of the relevant service, or termination of business, such personal information shall be destroyed within five (5) days from the date on which it is recognized as no longer necessary.
C. Methods of Destruction
Personal information in electronic file format shall be destroyed using technical methods that make the records irrecoverable.
Personal information printed on paper shall be destroyed by shredding or incineration.
9. Measures to Ensure the Security of Personal Information
In accordance with Article 29 of the Personal Information Protection Act, the Company implements the following technical, administrative, and physical measures necessary to ensure the security of personal information.
A. Minimization and Training of Personnel Handling Personal Information
The Company designates employees who handle personal information and limits such handling to authorized personnel only, thereby minimizing the number of employees involved and implementing measures to manage personal information securely.
B. Regular Internal Audits
To ensure the stability and security of personal information handling, the Company conducts regular internal audits (once per quarter).
C. Establishment and Implementation of an Internal Management Plan
The Company establishes and implements an internal management plan to ensure the safe processing of personal information.
D. Encryption of Personal Information
Users’ personal information, including passwords, is stored and managed in encrypted form so that only the user can access it. Important data is additionally protected through security measures such as encrypting files and transmitted data or using file-locking functions.
E. Technical Measures Against Hacking, etc.
To prevent leakage or damage of personal information caused by hacking or computer viruses, the Company installs security programs, performs regular updates and inspections, and installs systems in areas with controlled external access, implementing technical and physical monitoring and blocking measures.
F. Access Control to Personal Information
The Company takes necessary measures to control access to personal information by granting, changing, or revoking access rights to database systems that process personal information, and uses intrusion prevention systems to block unauthorized external access.
G. Retention and Prevention of Forgery or Alteration of Access Records
Records of access to personal information processing systems are stored and managed for at least six (6) months, and security measures are used to prevent forgery, alteration, theft, or loss of such access records.
H. Use of Locking Devices for Document Security
Documents and auxiliary storage media containing personal information are stored in secure locations equipped with locking devices.
I. Control of Unauthorized Access
The Company separately designates physical storage locations for personal information and establishes and operates access control procedures for such locations.
10. Chief Privacy Officer
A. The Company has designated a Chief Privacy Officer as follows to take overall responsibility for matters related to the processing of personal information, and to handle complaints and provide remedies for damages related to personal information.
Name:
Position:
Department:
Telephone:
Fax:
Email:
B. Data subjects may contact the Chief Privacy Officer or the relevant department regarding any inquiries, complaints, or requests for remedies related to personal information protection that arise while using the Company’s services (or business). The Company will respond to and process such inquiries without delay.
11. Changes to the Privacy Policy
A. This Privacy Policy shall take effect from the effective date, and in the event of any additions, deletions, or amendments due to changes in laws or policies, such changes will be notified through announcements at least 7days prior to their implementation.