LEGAL
Privacy Policy
ZiPIDA Inc. (“ZiPIDA” or the “Company”) has established the following Privacy Policy in accordance with the Personal Information Protection Act (PIPA) to protect users’ personal information and their rights and interests, and to handle users’ grievances related to personal information smoothly.
If ZiPIDA amends this Privacy Policy, it will announce the amendment through website notices (or individual notice).
This Privacy Policy takes effect on January 1, 2020.
1. Purposes of processing personal information
ZiPIDA processes personal information for the following purposes. Personal information processed by ZiPIDA is not used for any purpose other than the following, and ZiPIDA will seek prior consent if the purpose of use changes.
A. Website membership sign-up and management
Personal information is processed for the purposes of confirming the intent to sign up for membership, identifying and authenticating users for the provision of membership-based services, maintaining and managing membership, verifying identity under the limited identity verification system, preventing fraudulent use of services, confirming whether a legal representative has consented when personal information of children under 14 is collected, sending various notices and notifications, handling grievances, retaining records for dispute mediation, etc.
B. Provision of goods or services
Personal information is processed for the purposes of providing services, providing content, providing personalized services, identity authentication, age verification, payment and settlement, etc.
C. Use for marketing and advertising
Personal information is processed for the purposes of developing new services (products) and providing personalized services, providing event and advertising information and opportunities to participate, providing services and displaying advertisements based on demographic characteristics, checking the validity of services, identifying access frequency or compiling statistics on members’ use of services, etc.
2. Status of personal information files
Personal information file name: ZiPIDA
- Personal information items: email, mobile phone number, password, login ID, gender, date of birth, name, occupation, anniversaries, hobbies, educational background, service usage records, access logs, cookies, IP address information, payment records
- Collection method: website, paper forms, prize promotions
- Basis for retention: records on the collection of app membership information, etc.
- Retention period: 3 years
- Relevant law: records on the collection, processing, use, etc. of credit information: 3 years
3. Processing and retention periods of personal information
ZiPIDA processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period to which the data subject consented when the personal information was collected.
The respective processing and retention periods for personal information are as follows.
Use for marketing and advertising
Personal information related to use for marketing and advertising is retained and used for the above purposes for up to 3 years from the date of consent to its collection and use.
- Basis for retention: information for use in marketing and advertising
- Relevant law: records on the collection, processing, use, etc. of credit information: 3 years
- Exceptions:
4. Provision of personal information to third parties
ZiPIDA provides personal information to third parties only in cases that fall under Articles 17 and 18 of PIPA, such as where the data subject has consented or where special provisions of law apply.
ZiPIDA provides personal information to third parties as follows.
- Recipient of personal information: ZiPIDA
- Recipient’s purpose of use: email, mobile phone number, home address, home phone number, password question and answer, password, login ID, gender, date of birth, name
- Recipient’s retention and use period: 1 year
5. Outsourcing of personal information processing
For the smooth handling of personal information-related work, ZiPIDA outsources personal information processing tasks as follows.
- Outsourcee (entrusted party): ZiPIDA
- Outsourced tasks: purchases and payment, delivery of goods or sending of bills and the like, identity authentication (financial transactions, financial services), collection of charges, identity verification for the use of membership-based services, handling of complaints and other requests, delivery of notices, development of new services (products) and provision of personalized services, provision of event and advertising information and opportunities to participate
- Outsourcing period: 1 year
When concluding an outsourcing contract, ZiPIDA, in accordance with Article 25 of PIPA, specifies in the contract or other documents the prohibition of processing personal information for purposes other than performing the outsourced tasks, technical and administrative safeguards, restrictions on re-outsourcing, management and supervision of the outsourcee, liability for damages, and other matters concerning responsibility. ZiPIDA also supervises whether the outsourcee processes personal information securely.
If there is any change to the details of the outsourced tasks or to the outsourcee, ZiPIDA will disclose it without delay through this Privacy Policy.
6. Rights and obligations of data subjects and legal representatives, and how to exercise them
As data subjects, users may exercise the following rights.
- Data subjects may at any time exercise rights against ZiPIDA Inc., such as requesting access to, correction of, erasure of, or suspension of processing of their personal information.
- The rights under paragraph 1 may be exercised against ZiPIDA Inc. in writing, by email, by fax, etc., in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and ZiPIDA Inc. will take action on such requests without delay.
- The rights under paragraph 1 may be exercised through a representative, such as the data subject’s legal representative or a person authorized to act on their behalf. In this case, a power of attorney in the format of Annex Form No. 11 of the Enforcement Rule of the Personal Information Protection Act must be submitted.
- The data subject’s rights to request access to personal information and suspension of processing may be restricted under Article 35(5) and Article 37(2) of PIPA.
- With respect to requests for correction and erasure of personal information, erasure cannot be requested where other laws specify that the personal information is subject to collection.
- When a request for access, a request for correction or erasure, or a request for suspension of processing is made under the data subject’s rights, ZiPIDA verifies whether the person making the request is the data subject or an authorized representative.
7. Personal information items processed
ZiPIDA processes the following personal information items.
Website membership sign-up and management
- Required items: email, mobile phone number, home address, home phone number, password question and answer, password, login ID, gender, date of birth, name, service usage records, access logs, cookies, IP address information, payment records
- Optional items:
8. Destruction of personal information
In principle, ZiPIDA destroys personal information without delay once the purposes of processing have been achieved. The destruction procedure, deadline, and method are as follows.
Destruction procedure
After the purpose has been achieved, information entered by users is moved to a separate database (or separate files, for paper records) and is destroyed either after being stored for a certain period in accordance with internal policy and other relevant laws, or immediately. Personal information moved to the database is not used for any other purpose except as provided by law.
Destruction deadline
Where the retention period has elapsed, users’ personal information is destroyed within 5 days of the end of the retention period. Where the personal information is no longer needed, such as when the purpose of processing has been achieved, the relevant service has been discontinued, or the business has ended, it is destroyed within 5 days of the date on which its processing is recognized as no longer necessary.
Destruction method
Information in electronic file form is destroyed using technical methods that make the records unrecoverable.
9. Installation, operation, and refusal of automatic personal information collection tools
- To provide individually personalized services, ZiPIDA uses “cookies,” which store usage information and retrieve it as needed.
- Cookies are small pieces of information sent to the user’s computer browser by the server (HTTP) used to operate a website, and they may also be stored on the hard disk of the user’s PC.
- Purpose of cookies: Cookies are used to provide users with optimized information by identifying their visit and usage patterns for each service and website they visit, popular search terms, whether a secure connection is used, etc.
- Installation, operation, and refusal of cookies: Users can refuse the storage of cookies through the option settings in the Tools > Internet Options > Privacy menu at the top of their web browser.
- If users refuse the storage of cookies, they may have difficulty using personalized services.
10. Chief Privacy Officer
ZiPIDA has designated a Chief Privacy Officer (CPO), as shown below, to take overall responsibility for work related to personal information processing and to handle matters such as data subjects’ complaints and remedies for damages related to personal information processing.
Chief Privacy Officer
- Name: JeongYoung Lee
- Position: Principal Researcher
- Rank: Principal Researcher
- Contact: +82-10-7120-6334, [email protected]
Data subjects may contact the Chief Privacy Officer and the responsible department with any inquiries, complaints, requests for remedies for damages, and other matters concerning personal information protection that arise while using ZiPIDA’s services (or business).
ZiPIDA will respond to and handle data subjects’ inquiries without delay.
11. Changes to this Privacy Policy
This Privacy Policy applies from its effective date. If content is added, deleted, or corrected in accordance with laws and policies, the changes will be announced through website notices starting 7 days before they take effect.
12. Security measures for personal information
In accordance with Article 29 of PIPA, ZiPIDA takes the following technical, administrative, and physical measures necessary to ensure security.
Restriction of access to personal information
ZiPIDA takes the measures necessary to control access to personal information by granting, changing, and revoking access rights to the database systems that process personal information, and uses a firewall to control unauthorized access from outside.