Article 1 Items and Methods of Collecting Personal Information
The Company collects the following personal information when users apply for the services below on the Site. The Company provides its services without a separate membership registration process, and the items listed below are collected only when a user applies for the corresponding feature.
1. Items Collected
Items collected by application feature
| Application Feature | Required Items | Optional Items |
| Free Diagnosis Request |
Name, company name, phone number, email |
Request details |
| Service Brochure Download |
Name, email, phone number |
- |
Information collected automatically during service use: IP address, cookies, access logs, browser and device information
2. Collection Method
Direct input by users through application forms on the website
Article 2 Purposes of Collecting and Using Personal Information
The Company uses the personal information it collects for the following purposes. The Company does not use processed personal information for any purpose other than those specified in this Article.
- Processing free diagnosis requests: verifying the applicant, providing diagnosis results, and contacting the applicant for consultation and result follow-up
- Providing the service brochure: verifying the applicant, sending the brochure, and responding to related inquiries
- Responding to inquiries: reviewing and answering submitted inquiries, and providing additional guidance as needed
- Marketing and sales activities: providing service-related information and notices about new services or events (only where separate consent has been given)
- Preventing fraudulent use and improving the service: statistical analysis and service quality improvement
※ The Company does not use personal information for any purpose other than those stated above. If the purpose of use changes, the Company will take necessary measures, including obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
Article 3 Retention and Use Period of Personal Information
As a general rule, the Company destroys personal information without delay once the purpose of its collection and use has been achieved. However, in the following cases, the Company retains the information for the stated period.
1. Retention Under the Company's Internal Policy
- Free diagnosis / brochure request information: retained for one year after the request is processed, then destroyed (for handling follow-up inquiries and maintaining service quality). However, if a user separately requests deletion, the information is destroyed immediately.
2. Retention Under Applicable Laws
Retention items required by law
| Retained Item | Legal Basis | Retention Period |
| Records of display/advertising |
Act on Consumer Protection in Electronic Commerce, etc. |
6 months |
| Records of consumer complaints or dispute resolution |
Act on Consumer Protection in Electronic Commerce, etc. |
3 years |
| Website visit records (access logs) |
Protection of Communications Secrets Act |
3 months |
Article 4 Procedures and Methods of Destroying Personal Information
1. Destruction Procedure
Information entered by users is moved to a separate database (or, for paper records, a separate filing cabinet) once its purpose has been achieved, stored for a set period in accordance with internal policy and applicable law, and then destroyed.
2. Destruction Method
Personal information stored in electronic file form is deleted using technical methods that render the records unrecoverable. Personal information printed on paper is destroyed by shredding or incineration.
Article 5 Provision of Personal Information to Third Parties
The Company processes users' personal information only within the scope specified in Article 1, and does not process it beyond that scope or provide it to third parties without the user's prior consent. However, the Company may provide users' personal information to third parties in the following cases, in accordance with applicable law.
- Where the user has given prior consent
- Where required by law, or where an investigative agency requests the information for investigative purposes in accordance with the procedures and methods prescribed by law
※ The Company does not currently provide personal information to any external third party. If this changes in the future, the Company will amend this Policy and provide advance notice.
Article 6 Outsourcing of Personal Information Processing
To ensure the smooth handling of personal information, the Company may outsource personal information processing tasks to external service providers as follows.
Outsourced personal information processing
| Service Provider | Outsourced Task | Outsourcing Period |
| Cloud service provider |
Operating servers for data storage |
Duration of service use |
When entering into an outsourcing agreement, the Company specifies in the contract, in accordance with Article 26 of the Personal Information Protection Act, matters such as the prohibition on processing personal information for purposes other than the outsourced task, technical and administrative safeguards, restrictions on re-outsourcing, oversight of the service provider, and liability for damages, and supervises whether the service provider processes personal information safely.
Article 7 Rights and Obligations of Data Subjects and How to Exercise Them
As data subjects, users may exercise the following rights.
- Requesting access to personal information
- Requesting correction in the event of errors
- Requesting deletion
- Requesting suspension of processing
These rights may be exercised in writing, by phone, by email, or through other means, and the Company will take action without delay. If a user requests correction of an error in their personal information, the Company will not use or provide that information until the correction has been completed. Rights may also be exercised through a legal representative or an authorized agent, in which case a power of attorney must be submitted.
Article 8 Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information.
- Administrative measures: establishing and implementing an internal management plan, and minimizing and training personnel who handle personal information
- Technical measures: managing access rights to personal information processing systems, installing access control systems, encrypting unique identification information, and installing security software
- Physical measures: controlling access to computer rooms, data storage rooms, and similar facilities
Article 9 Installation, Operation, and Refusal of Cookies
The Company may use "cookies" that store and periodically retrieve usage information in order to provide users with a customized service.
- Purpose of using cookies: analyzing users' access frequency and visit duration, and identifying users' areas of interest to improve the service
- Installing, operating, and refusing cookies: users can refuse to allow cookies by adjusting the privacy settings in their web browser (e.g., Tools > Internet Options > Privacy). Please note that refusing cookies may make it difficult to use some features of the service.
Article 10 Personal Information Protection Officer
The Company has designated a Personal Information Protection Officer as shown below, who is responsible for overseeing personal information processing and handling user complaints and remedies related to personal information.
- Name
- Byul Namgung
- Title
- Division Head
- Contact
- +82-10-5376-1220
Users may direct any inquiries, complaints, or requests for remedy related to personal information protection arising from the use of the Company's services to the Personal Information Protection Officer or the responsible department. The Company will respond to and handle such inquiries without delay.
Article 11 Remedies for Infringement of Data Subject Rights
Data subjects may apply to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, or similar bodies for dispute resolution or consultation regarding infringement of personal information. For other reports or consultations regarding personal information infringement, please contact the organizations below.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Crime Investigation Division: 1301 (no area code) (www.spo.go.kr)
- National Police Agency Cyber Bureau: 182 (no area code) (cyberbureau.police.go.kr)
Article 12 Changes to This Privacy Policy
This Privacy Policy applies from its effective date. If any additions, deletions, or corrections are made in accordance with applicable law or Company policy, notice will be posted on the Site at least 7 days before such changes take effect.