1. Information to be collected and method of collection
(1) Personal information items to be collected Personal information items to be collected by the Company are as follows: • Information provided by the users The Company may collect the information directly provided by the users. ∘ Name, address, telephone number, and email address ∘ Payment information including account number and card number ∘ Delivery information including delivery address, name and contact information of recipient ∘ Information of bid, purchase and sales wh of information directly provided by the users, the Company may collect information in the course that the users use the service provided by the Company. ∘ Log data, use time, search word input by users, internet protocol address, cookie and web beacon ∘ User verification : Image of ID whose numbers are masked manually or automatically(Image is only used for verification and will be erased immediately right af verifica ) ∘ Preference, advertisement environment, visited pages regarding service use of users (2) Method of collection The Company collects the information of users in a way of the followings: • webpage, written form, fax, telephone calling, e-mailing, tools for collection of created information • provided by partner companies
2. Use of collected information The Company uses the collected information of users for the following purposes:
• Member management and identification • To detect and deter unauthorized or fraudulent use of or abuse of the Service • Performance of contract and service fee settlement regarding provision of services demanded by the users • Improvement of existing services and development of new services • Making function of company sites or applications or matters on policy change • To help you connect with other users you already know and, with your permission, allow other users to connect with you • To make statistics on member's service usage, to provide services and place advert based on statistical characteristics • To provide information on promotional events as well as opportunity to participate • To comply with applicable laws or legal obligation • Use of information with prior consent of the users (for example, utilization of marketing advertisement) The Company agrees that it will obtain consent from the users, if the Company desires to use the information other than th ose expressly stated in this Policy.
3. Sharing collected information Except for the following cases, the Company will not share personal information with a 3rd party:
• when the Company shares the information with its affiliates, partners and service providers; ∘ When the Company's affiliates, partners and service providers carry out services such as bill payment, execution of orders, products delivery and dispute resolution (including disputes on payment and delivery) for and on behalf of the Company • when the users consent the shar advance; ∘ when the user selects to be provided by the information of products and services of certain companies by sharing his or her personal information with those companies ∘ when the user selects to allow his or her personal information to be shared with the sites or platform of other companies such as social networking sites ∘ other cases where the user gives prior consent for sharing his or her personal information • when the sharing is required by the laws - if required to be disclosed by the laws and regulations; or - if required to be disclosed by the investigative agencies for detecting crimes in accordance with the procedure and method as prescribed in the laws and regulations
4. Cookies, Beacons and Similar Technologies The Company may collect collective and impersonal information through 'cookies' or 'web beacons'. Cookies are very small text files to be sent to the browser of the users by the server used for operation of the websites of the Company and will be stored in hard-disks of the users' computer. Web beacon is a small quantity of code which exists on the websites and e-mails. By using web beacons, we may know whether a user has interacted with certain webs or the contents of email. These functions are used for evaluating, improving services and setting-up users' experiences so that much improved services can be provided by the Company to the users The items of cookies to be collected by the Company and the purpose of such collection are as follows: strictly necessary cookies This cookie is a kind of indispensable cookie for the users to use the functions of website of the Company. Unless the users allow this cookie, the services such as shopping cart or electronic bill payment cannot be provided. This cookie does not collect any information which may be used for marketing or memorizing the sites visited by the users (Examples of necessary cookies) ∘ Memorize the information entered in an order form while searching other pages during web browser session ∘ and check-out, memorize ordered services ∘ Check whether login is made on website ∘ Check whether the users are connected with correct services of the website of the Company while the Company changes the way of operating its website ∘ Connect the user server of the services performance cookies This cookie collects information how the users use the website of the Company such as the information of the pages which are visited by the users most. This data helps the Company to optimize its website so that the users can search that website more comfortably. This cookie does not collect any information of the users. Any and all the information collected by this cookie will be processed collectively and the anonymity will be guaranteed. (Examples of performance cookies) ∘ Web analysis: provide statistical data on the ways of using website ∘ Advertisement response fee: check the effect of advertisement of the Company ∘ Tracing affiliated companies; one of visitors of the Company provides anonymously feedback to the affiliated companies ∘ Management of error: measure an error which may occur so as to give a help for improving website ∘ Design testing: test other design of the website of Company targeting cookies or advertising This cookie is connected with the services provided by a 3rd party such as the buttons of 'good' and 'share'. The 3rd party provides these services by recognizing that the users visit the website of the Company. (Examples of targeting cookies or advertising cookies) ∘ carry out PR to the users as targets in other websites by connecting through social networks and these networks use the information of users' visit ∘ provide the information of users' visit to ad age can suggest an ad which may attract the interest of the users The users have an option for cookie installation. So, they may either allow all cookies by setting option in web browser, make each cookie checked whenever it is saved, or refuses all cookies to be saved: Provided that, if the user rejects the installation of cookies, it may be difficult forthat user to use the parts of services provided by the Company.
5. Users' right to access and option The users or their legal representatives, as main agents of the information, may exercise the following options regarding the collection, use and sharing of personal information by the Company:
• exercise right to access to personal information; • make corrections or deletion; • make temporary suspension of treatment of personal information; or • request the withdrawal of their consent provided before If, in order to exercise the above options, you, as an user, use the menu of 'amendment of member information of webpage or contact the Company by using representative telephone or sending a document or e-mails, or using telephone to the responsible department (or person in charge of management of personal information), the Company will take measures without delay: Provided that the Company may reject the request of you only to the extent that there exists either proper cause as prescribed in the laws or equivalent cause.
6. Security The Company regards the security of personal information of uses as very important. The company constructs the following security measures to protect the users' personal information from any unauthorized access, release, use or modification • Encryption of personal information - Transmit users' personal information by using encrypted communication zone - Store important information such as passwords • Countermeasures against hacking - Install a system in the zone the external access to which is controlled so as to prevent leakage or damage of users' personal information by hacking or computer virus • Establish and execute internal management plan
7. Protection of personal information of children In principle, the Company does not collect any information from the children under 13 or equivalent minimum age as prescribed in the laws in relevant jurisdiction. The website, products and services of the Company are the ones to be provided to ordinary people, in principle. The website or application of the Company has function to do age limit so that children cannot use it and the Company does not intentionally collect any personal information from children through that function. (Additional procedure for collecting personal information from children) However, if the Company collects any personal information from children under 13 or equivalent minimum age as prescribed in the laws in relevant jurisdiction for the services for unavoidable reason, the Company will go through ad of the followings for protecting that personal information of children: • obtain consent from the parents or guardian of children so as to collect personal information of children or directly send the information of products and services of the Company • give the parents or guardian of child a notice of Company's policy of privacy protection for children including the items, purpose and sharing of personal information collected • grant to legal representatives of children a right to access to personal information of that children/correction or deletion of personal information/temporary suspension of treat personal information/ and request for withdrawal of their consent provided before • limit the amount of personal information exceeding those necessary for participation in online activities
8. Modification of Privacy Protection Policy The Company has the right to amend or modify this Policy from time to time and, in such case, the Company will make a public notice of it through bulletin board of its website (or through individual notice such as written document, fax or e-mail) and obtain consent from the users if required by relevant laws.
9. Others Data transmission Considering it engages in global businesses, the Company may provide the users' personal information to the companies located in other countries for the purpose as expressly stated in this Policy. For the places where the personal information is transmitted, retained or processed, the Company takes reasonable measures for protecting that personal information. In addition, when the personal information obtained from the European Union is used or disclosed, the Company may have to comply with safe harbor principle as required by the Commerce Department of USA, take other measures or obtain consent from users so far as those comp the regulations of EU so as to use a standardized agreement provision approved by executing organizations of EU or securing proper safe measures. 3rd party's sites and services The website, product or service of the Company may include the links to the ones of a 3rd party and the privacy protection policy of the site of 3rd party may be different. Thus, it is required for the users to check additionally that policy of a 3rd party site linked to the site of the Company. Guide for users residing in California, If the user resides in California, certain rights may be given. The Company prepares preventive measures necessary for protecting personal information of members so that the Company can comply with online privacy protection laws of California. In case of leakage of personal information, a user may request the Company to check the leakage. In addition, all the users in the website of the Company, can modify their information at any time by using the menu for changing information by connecting their personal account. Moreover, the Company does not trace the visitors of its website nor use any signals for 'tracing prevent'. The Company will not collect and provide any personal identification information through ad services without consent of users. Guide for users residing in Korea The Company guides several additional matters to be disclosed as required by the information network laws and personal information protection laws in the Republic of Korea as follows: Information collected The items collected by the Company are as follows: • Examples of required information ∘ Name, address, telephone number, and email address ∘ For payment with credit card : name of card company, number and expiration of card ∘ For small sum payment charged on the mobile phone: mobile phone number∘ payment by remittance: name of bank, account number and password of account ∘ For deposit without a bankbook: name of remitter, contact information ∘ Delivery information including delivery address, name and contact information of recipient ∘ Information of bid, purchase course of using services, the information as described below may be created and collected: ∘ Information of devices (equipment/device identifie r, operation system, hardware version, equipment set-up and telephone number) ∘ Log information (Log data, use time, search word input by users, internet protocol address, cookie and web beacon) ∘ Location information (Information of device location including specific geographical location detected through GPS, Bluetooth or Wi-Fi) ∘ Other created information • Examples of optional items The user may reject the collection and use of optional items and, even in case of rejection, there is no limit on use of services User分析 ∘ The reason for membership, occupation, marriage status, wedding anniversary, interest category and SNS account information Provision of customized ad ∘ Contents and result of marketing activities and event participation Delivery of ∘ Information provided main urgent notice management of other agreements and event participation Marketing ∘ Preference, advertisement environment, visited pages regarding service use of users Period for retention and use of personal information In principle, the Company destructs personal information of users without delay when: the purpose of its collection and use has been achieved; the legal or management needs are satisfied; or users request: Provided that, if it is required to retain the information by relevant laws and regulations, the Company will retain member information for certain period as designated by relevant laws and regulations. The information to be retained as required by relevant laws and regulations are as follows: ∘ Record regarding contract or withdrawal of subscription: 5 years (The Act on Consumer Protection in Electronic Commerce) ∘ Record on payment and supply of goods (The yar Act on Consumer Protection in Electronic Commerce) ∘ Record on consumer complaint or dispute treatment: 3 years (The Act on Consumer Protection in Electronic Commerce) ∘ Record on collection/process, and use of credit information: 3 years (The Act on Use and Protection of Credit Information) ∘ Record on sign/advertisement: 6 months(The Act on Consumer Protection in Electronic Commerce) ∘ Log record of users such as internet/data detecting the place of user connection: 3 months(The Protection of Communications Secrets Act ) ∘ Other data for checking communication facts: 12 months (The Protection of Communications Secrets Act) Procedure and method of destruction of personal information In principle, the Company destructs the information immediately after the purposes of its collection and use have been achieved without delay: Provided that, if any information is to be retained as required by relevant laws and regulations, the Company retain it for the period as required by those laws and regula and, in such event, the personal information which is stored and managed separately will never be used for other purposes. The Company destructs: hard copies of personal information by shredding with a pulverizer or incinerating it; and delete personal information stored in the form of electric file by using technological method making that information not restored. Technical, managerial and physical measures for protection of personal information In order to prevent the loss, theft, leakage, alteration or damage of personal information of the users, the Company takes technical, managerial and physical measures for securing safety as follows: ∘ servers for transmitting encryption of personal information ∘ Establish and execute internal management plan ∘ Appoint a staff responsible for protecting personal information ∘ Provide education and training for staffs treating personal information ∘ Establish and execute internal management plan ∘ Class information processing system Staff responsible for managing personal information The staff of the Company responsible for managing personal information is as follows: • Name of staff responsible for managing personal information: Geyoun Cho Dept. ：マネジメントTel。 : +82)010-3760-3896 Contact : email@example.com The date of latest update: Apr.22. 2019
10. Responsible department of Company The Company designates the following department and person in charge of personal information in order to protect personal information of customers and deal with complaints from customers: • Department responsible for privacy protection and customer service : Management Address : 278, -ro, Songpa-gu, Seoul, Republic of Korea