[Internet membership service]
– email address, ID
[Online payment service]
– Name, address, telephone number, and email address
• Information collected while the users use services
Besides of information directly provided by the users, the Company may collect information in the course that the users use the service provided by the Company.
[Equipment information]
– Equipment identifier, operation system, hardware version, equipment set-up and telephone number
[Log information]
– Log data, use time, search word input by users, internet protocol address, cookie and web beacon
• Member management and identification
• To detect and deter unauthorized or fraudulent use of or abuse of the Service
• Performance of contract and service fee settlement regarding provision of services demanded by the users
• Improvement of existing services and development of new services
• Making notice of function of company sites or applications or matters on policy change
• To help you connect with other users you already know and, with your permission, allow other users to connect with you
• To make statistics on member’s service usage, to provide services and place advertisements base on statistical characteristics
• To provide information on promotional events as well as opportunity to participate
• To comply with applicable laws or legal obligation
• Use of information with prior consent of the users (for example, utilization of marketing advertisement)
The Company agrees that it will obtain consent from the users, if the Company desires to use the information other than those expressly stated in this Policy.
The users or their legal representatives, as main agents of the information, may exercise the following options regarding the collection, use and sharing of personal information by the Company:
• exercise right to access to personal information;
• make corrections or deletion;
• make temporary suspension of treatment of personal information; or
• request the withdrawal of their consent provided before
If, in order to exercise the above options, you, as an user, use the menu of ‘amendment of member information of webpage or contact the Company by using representative telephone or sending a document or e-mails, or using telephone to the responsible department (or person in charge of management of personal information), the Company will take measures without delay: Provided that the Company may reject the request of you only to the extent that there exists either proper cause as prescribed in the laws or equivalent cause.
The Company has the right to amend or modify this Policy from time to time and, in such case, the Company will make a public notice of it through bulletin board of its website (or through individual notice such as written document, fax or e-mail) and obtain consent from the users if required by relevant laws.
(1) Data transmission
Considering it engages in global businesses, the Company may provide the users’ personal information to the companies located in other countries for the purpose as expressly stated in this Policy. For the places where the personal information is transmitted, retained or processed, the Company takes reasonable measures for protecting that personal information.
In addition, when the personal information obtained from the European Union is used or disclosed, the Company may have to comply with safe harbor principle as required by the Commerce Department of USA, take other measures or obtain consent from users so far as those complies with the regulations of EU so as to use a standardized agreement provision approved by executing organizations of EU or securing proper safe measures.
(2) 3rd party’s sites and services
The website, product or service of the Company may include the links to the ones of a 3rd party and the privacy protection policy of the site of 3rd party may be different. Thus, it is required for the users to check additionally that policy of a 3rd party site linked to the site of the Company.
(3) Guide for users residing in California
If the user resides in California, certain rights may be given. The Company prepares preventive measures necessary for protecting personal information of members so that the Company can comply with online privacy protection laws of California.
In case of leakage of personal information, a user may request the Company to check the leakage. In addition, all the users in the website of the Company, can modify their information at any time by using the menu for changing information by connecting their personal account.
Moreover, the Company does not trace the visitors of its website nor use any signals for ‘tracing prevent’. The Company will not collect and provide any personal identification information through ad services without consent of users.
(4) Guide for users residing in Korea
The Company guides several additional matters to be disclosed as required by the information network laws and personal information protection laws in the Republic of Korea as follows:
(a) Information collected
The items collected by the Company are as follows:
• Required information
[Internet membership service]
– email address, ID
[Online payment service]
– Name, address, telephone number, and email address
In the course of using services, the information as described below may be created and collected:
Information of devices (equipment/device identifier, operation system, hardware version, equipment set-up and telephone number)
Log information (Log data, use time, search word input by users, internet protocol address, cookie and web beacon)
Other created information
• Optional information
The user may reject the collection and use of optional items and, even in case of rejection, there is no limit on use of services
[User analysis]
– The reason for membership, occupation, marriage status, wedding anniversary, interest category and SNS account information
[Provision of customized ad]
– Contents and result of marketing activities and event participation
[Delivery of urgent notice]
– Information provided by the users regarding execution, maintenance, execution, management of other agreements and event participation
[Marketing]
– Preference, advertisement environment, visited pages regarding service use of users
(b) Commission for collected personal information
For carrying out services, the Company commissions external professional companies (subcontractors) to process personal information as follows. This commissioned works for processing personal information is carried out by each subcontractor and service only if necessary for providing that service.
In commissioning process of personal information, in order to secure safety of personal information , the Company supervises and ensure to expressly state in the agreement with subcontractors so that those subcontractors will safely process personal information by strictly complying with directions regarding personal information protection, keeping personal
[YESCALL]
– Description of commissioned works (services) : Member management
(c) Period for retention and use of personal information
In principle, the Company destructs personal information of users without delay when: the purpose of its collection and use has been achieved; the legal or management needs are satisfied; or users request: Provided that, if it is required to retain the information by relevant laws and regulations, the Company will retain member information for certain period as designated by relevant laws and regulations. The information to be retained as required by relevant laws and regulations are as follows:
Record regarding contract or withdrawal of subscription: 5 years (The Act on Consumer Protection in Electronic Commerce)
Record on payment and supply of goods: 5 years (The Act on Consumer Protection in Electronic Commerce)
Record on consumer complaint or dispute treatment: 3 years (The Act on Consumer Protection in Electronic Commerce)
Record on collection/process, and use of credit information: 3 years (The Act on Use and Protection of Credit Information)
Record on sign/advertisement: 6 months(The Act on Consumer Protection in Electronic Commerce)
Log record of users such as internet/data detecting the place of user connection: 3 months(The Protection of Communications Secrets Act)
Other data for checking communication facts: 12 months (The Protection of Communications Secrets Act)
(d) Procedure and method of destruction of personal information
In principle, the Company destructs the information immediately after the purposes of its collection and use have been achieved without delay: Provided that, if any information is to be retained as required by relevant laws and regulations, the Company retain it for the period as required by those laws and regulations before destruction and, in such event, the personal information which is stored and managed separately will never be used for other purposes. The Company destructs: hard copies of personal information by shredding with a pulverizer or incinerating it; and delete personal information stored in the form of electric file by using technological method making that information not restored.
(e) Technical, managerial and physical measures for protection of personal information
In order to prevent the loss, theft, leakage, alteration or damage of personal information of the users, the Company takes technical, managerial and physical measures for securing safety as follows:
Technical measures]
– Utilize security servers for transmitting encryption of personal information
– Take measures of encryption for confidential information
– Install and operate access control devices and equipments
– Establish and execute internal management plan
[Managerial measures]
– Appoint a staff responsible for protecting personal information
– Provide education and training for staffs treating personal information
– Establish and execute internal management plan
– Establish rules for writing passwords which is hard to be estimated
– Ensure safe storage of record of access to personal information processing system
– Classify the level of authority to access to personal information processing system
[Physical measures]
– Establish and operate the procedure for access control for the facilities for storing personal information
– Store documents and backing storage containing personal information in safe places which have locking device