Privacy Policy
Han Business&Company Co., Ltd. (hereinafter the 'Company') establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to promptly and smoothly handle any related grievances.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information being processed shall not be used for any purpose other than those listed below, and if the purpose of use is changed, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
- Website membership registration and management
Personal information is processed for the purposes of confirming the intention to register as a member, identifying and authenticating individuals in connection with the provision of membership services, maintaining and managing membership status, preventing fraudulent use of services, verifying the consent of a legal guardian when processing the personal information of children under the age of 14, and various notices and notifications. - Provision of goods or services
Personal information is processed for the purposes of providing services, sending contracts and invoices, providing content, providing customized services, billing and settlement of fees, and debt collection. - Use for marketing and advertising
Personal information is processed for the purposes of developing new services (products) and providing customized services, providing event and promotional information and opportunities to participate, providing services and posting advertisements according to demographic characteristics, verifying the effectiveness of services, identifying access frequency, and compiling statistics on members' use of services.
Article 2 (Processing and Retention Period of Personal Information)
- The Company processes and retains personal information within the retention and use period stipulated by applicable laws, or within the retention and use period consented to by the data subject at the time of collection.
- The processing and retention period for each type of personal information is as follows.
- Personal information related to website membership registration and management is retained and used for the purposes stated above for up to 5 years from the date of consent to its collection and use.
- Legal basis for retention: Article 15 (Collection and Use of Personal Information), Paragraph 1 of the Personal Information Protection Act
- Records on the collection/processing and use of credit information: 3 years
- Records on payment and the supply of goods, etc.: 5 years
- Records on contracts or withdrawal of subscriptions, etc.: 5 years
- Records on labeling/advertising: 6 months
- Records on fraudulent use: 1 year
Article 3 (Items of Personal Information Processed)
The Company processes the following items of personal information.
- Website membership registration and management
- Required items
Email, mobile phone number, password, login ID, gender, date of birth, name, company phone number, position, department, company name, occupation, credit card information, service usage records, access logs, cookies, access IP information, payment records, legal guardian's name, legal guardian's home phone number, legal guardian's home address, legal guardian's mobile phone number - Optional items
Gender, anniversary, marital status, hobbies, physical information, education, religion
Article 4 (Matters Concerning the Processing of Personal Information of Children Under the Age of 14)
- When collecting the personal information of children under the age of 14, the Company collects the minimum personal information necessary to perform the relevant service with the consent of a legal guardian.
Required items: legal guardian's name, relationship, contact information - In addition, when collecting a child's personal information for the purpose of service-related promotions, the Company obtains separate consent from the legal guardian.
- When collecting the personal information of a child under the age of 14, the Company may request minimum information from the child, such as the legal guardian's name and contact information, and verifies whether a lawful legal guardian has given consent through one of the following methods.
- A method whereby the legal guardian indicates whether they consent on the website where the contents of the consent are posted, and the personal information controller notifies the legal guardian via mobile phone text message that it has confirmed such indication of consent
- A method whereby the legal guardian indicates whether they consent on the website where the contents of the consent are posted, and the legal guardian's card information, such as a credit card or debit card, is provided
- A method whereby the legal guardian indicates whether they consent on the website where the contents of the consent are posted, and the legal guardian's identity is verified through mobile phone identity authentication or similar means
- A method whereby a written document stating the contents of the consent is issued directly to the legal guardian, or delivered by mail or fax, and the legal guardian signs and seals the consent and submits it
- A method whereby an email stating the contents of the consent is sent, and an email containing the legal guardian's expression of consent is received in return
- A method whereby the contents of the consent are conveyed to the legal guardian by phone and consent is obtained, or a method of confirming the contents of the consent, such as an internet address, is provided and consent is obtained through a subsequent phone call
- Any other method equivalent to the above whereby the contents of the consent are conveyed to the legal guardian and the expression of consent is confirmed
Article 5 (Matters Concerning the Provision of Personal Information to Third Parties)
The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as the consent of the data subject or special provisions of the law.
Article 6 (Matters Concerning the Outsourcing of Personal Information Processing)
- For the smooth processing of personal information tasks, the Company may outsource personal information processing tasks, and the trustees will be announced separately.
- When entering into an outsourcing contract, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in documents such as the contract matters concerning responsibilities, including the prohibition of processing personal information beyond the purpose of performing the outsourced tasks, technical and administrative protective measures, restrictions on re-outsourcing, management and supervision of the trustee, and compensation for damages, and supervises whether the trustee processes personal information safely.
- In the event that the content of the outsourced tasks or the trustee changes, the Company will disclose such changes without delay through this Privacy Policy.
Article 7 (Procedures and Methods for Destruction of Personal Information)
- The Company destroys the relevant personal information without delay when it becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose.
- If personal information must continue to be retained in accordance with other laws despite the expiration of the retention period consented to by the data subject or the achievement of the processing purpose, the Company moves the relevant personal information to a separate database (DB) or stores it in a different location.
Personal information items retained: account information, transaction date - As for the procedures and methods for the destruction of personal information, the personal information for which grounds for destruction have arisen is selected, and the personal information is destroyed with the approval of the Company's Chief Privacy Officer.
- As for the method of destruction, information in the form of electronic files is destroyed using technical methods that make the records unrecoverable, and personal information printed on paper is destroyed by shredding or incineration.
Article 8 (Measures Concerning the Destruction of Personal Information of Non-Users, etc.)
- The personal information controller converts users who have not used the service for one year into dormant accounts and stores their personal information separately. The separately stored personal information is retained for one year and then destroyed without delay.
Article 9 (Matters Concerning the Rights and Obligations of Data Subjects and Their Legal Guardians, and How to Exercise Them)
- The data subject may, at any time, exercise rights against Han Business&Company Co., Ltd., such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information.
- The exercise of rights under Paragraph 1 may be made against Han Business&Company Co., Ltd. in writing, by email, or by facsimile (FAX), etc., in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and Han Business&Company Co., Ltd. will take action thereon without delay.
- The exercise of rights under Paragraph 1 may be made through an agent, such as the data subject's legal guardian or a duly authorized person. In this case, you must submit a power of attorney in accordance with the form in Annex No. 11 of the "Notice on Methods of Processing Personal Information (Notice No. 2020-7)."
- Requests for access to and suspension of the processing of personal information may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
- Requests for the correction or deletion of personal information cannot demand the deletion of such personal information if it is specified as a subject of collection under other laws.
- When a data subject requests access, correction or deletion, or suspension of processing in accordance with their rights, the Company verifies whether the person making the request is the data subject themselves or a duly authorized agent.
Article 10 (Matters Concerning Measures to Ensure the Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
- Minimization and training of staff handling personal information
The Company implements measures to manage personal information by designating staff who handle personal information and limiting and minimizing such staff to the persons in charge. - Restriction of access to personal information
The Company takes necessary measures to control access to personal information by granting, changing, and revoking access rights to the database systems that process personal information, and controls unauthorized access from the outside through technical methods such as intrusion prevention systems or firewalls. - Access control for unauthorized persons
The Company maintains a separate physical storage location where personal information is kept, and establishes and operates access control procedures for it.
Article 11 (Matters Concerning the Installation, Operation, and Refusal of Devices that Automatically Collect Personal Information)
- The Company uses 'cookies' that store and retrieve usage information from time to time in order to provide individualized customized services to users.
- A cookie is a small piece of information that the server (http) used to operate the website sends to the user's computer browser, and it may also be stored on the hard disk of the user's PC.
- Purpose of using cookies: Cookies are used to provide optimized information to users by identifying the visit and usage patterns of each service and website the user has visited, popular search terms, whether the connection is secure, and so on.
- Installation, operation, and refusal of cookies: You can refuse to store cookies through the option settings in Tools > Internet Options > Privacy menu at the top of your web browser.
- If you refuse to store cookies, you may experience difficulties in using customized services.
Article 12 (Matters Concerning the Collection, Use, Provision, and Refusal of Behavioral Information)
- The personal information controller collects and uses behavioral information in order to provide data subjects with optimized customized services and benefits, online customized advertising, and the like during the course of service use.
- The personal information controller collects behavioral information as follows.
- Items of behavioral information collected: the user's website/app service visit history, search history, and purchase history
- Method of collecting behavioral information: automatically collected when the user visits/launches the website or app
- Purpose of collecting behavioral information: to provide a personalized product recommendation service (including advertising) based on the user's interests and preferences
- The personal information controller allows online customized advertising businesses to collect and process behavioral information as follows.
- Method of collecting behavioral information: automatically collected and transmitted when the user visits our website or launches the app
- Items of behavioral information collected and processed: the user's web/app visit history, search history, and purchase history
Article 13 (Criteria for Determining Additional Use and Provision)
In accordance with Article 15, Paragraph 3 and Article 17, Paragraph 4 of the Personal Information Protection Act, the Company may additionally use and provide personal information without the consent of the data subject, taking into account the matters set forth in Article 14-2 of the Enforcement Decree of the Personal Information Protection Act. Accordingly, the Company has considered the following matters in order to make additional use and provision without the consent of the data subject.
- Whether the purpose of the additional use and provision of personal information is related to the original purpose of collection
- Whether the additional use and provision is foreseeable in light of the circumstances under which the personal information was collected or the processing practices
- Whether the additional use and provision of personal information unfairly infringes upon the interests of the data subject
- Whether measures necessary to ensure safety, such as pseudonymization or encryption, have been taken
Article 14 (Matters Concerning the Chief Privacy Officer)
- The Company designates a Chief Privacy Officer as set forth below, who takes overall responsibility for personal information processing tasks and handles complaints and provides remedies for damages from data subjects in connection with personal information processing.
Chief Privacy Officer
Name: Han Ji-man
Position: Data Protection Officer
Rank: Director
Contact: 82-2-900-4446, ziman.han@hanbnc.com - Data subjects may direct any inquiries, complaints, requests for remedies, and other matters related to personal information protection that arise while using the services (or business) of Han Business&Company Co., Ltd. to the Chief Privacy Officer and the department in charge. Han Business&Company Co., Ltd. will respond to and handle the inquiries of data subjects without delay.
Article 15 (Remedies for Infringement of the Rights and Interests of Data Subjects)
In order to obtain relief for personal information infringement, data subjects may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, and the like. For other reports and counseling regarding personal information infringement, please contact the agencies below.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
- National Police Agency: 182 (no area code) (ecrm.cyber.go.kr)
A person whose rights or interests have been infringed due to a disposition or omission by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may request an administrative appeal in accordance with the provisions of the Administrative Appeals Act.
For details on administrative appeals, please refer to the website of the Central Administrative Appeals Commission (www.simpan.go.kr).
Article 16 (Notification of the Privacy Policy)
This Privacy Policy takes effect from August 19, 2023.