Privacy policy
Advertising monitoring service SORIMON
Privacy policy
iPlateia Inc. Service Planning August 29, 2018
Privacy policy
iPlateia Inc. (the “Company”) takes care in handling customers’ personal information.
The Company complies with all applicable laws, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, and makes every effort to protect members’ personal information. This policy explains the purposes and methods for using personal information provided by users and how that information is managed and protected.
- Personal information collected and collection methods
- Personal information collected
First, when a user registers, the Company collects the following minimum personal information to support registration and login, customer assistance, and optimized services.- Registration by general users, foreign nationals, and children under 14:
- Required: name, user ID, password, email address, and the legal representative’s identity verification value.
- Optional: birth year and gender.
- Registration using a social network account: name, email address, birth year, and gender.
Second, when mobile services are used, device information — device model, hardware ID, and operating system version — and basic service usage statistics may be collected. These include information about interest in advertising materials, use of advertising analytics and the application, and data for member-targeted or personalized recommendations within the service. This information is collected in a form that cannot identify an individual. If additional personal information needs to be collected during use of the service, the Company will inform the member in advance and obtain consent.
Third, the following information may be generated and collected automatically during service use or business processing:- IP address, cookies, visit date and time, operating system type, browser type, payment records, service usage records, and records of improper use.
Fourth, when paid services are used, the following information may be collected by a personal information processor — a payment processing provider. The Company does not retain payment information.- Credit card payment: card issuer, card number, etc.
- Mobile phone payment: mobile phone number, carrier, payment authorization number, etc.
- Bank transfer: bank name, account number, etc.
- Gift certificate payment: gift certificate number.
- Registration by general users, foreign nationals, and children under 14:
- Collection methods
The Company collects personal information through the following methods:- Website, mobile application, written forms, fax, telephone, inquiry board, email, and event entries.
- Personal information collected
- Purposes of processing personal information
- Performing contracts for service provision and settling service charges
Providing goods and content, personalized services, invoices and purchase histories, virtual currency — SORIMON Cash — and synchronization between devices; verifying identity; processing purchases and payments; collecting charges; and related activities. - Member management
Verifying identity, preventing improper use by disqualified members — members permanently suspended for violations of Article 16 of the SORIMON Terms of Use — and unauthorized use, confirming the intention to register, retaining records for dispute resolution, handling complaints, and delivering notices. - Developing new services and marketing
Developing new services, providing personalized services based on demographic characteristics and usage patterns, displaying advertisements, offering event participation opportunities, identifying access frequency, and compiling statistics on members’ service use.
- Performing contracts for service provision and settling service charges
- Consent to the collection of personal information
First, the Company provides a procedure allowing customers to choose whether to consent to the privacy policy or terms of use through an “Agree” button. Selecting “Agree” is deemed consent to storing the entered personal information in the Company’s customer database and using it for the purposes specified above.
Second, when consent to collection is obtained through a third party, such as a partner company, customers are also provided with a procedure to accept the privacy policy or terms of use using an “Agree” button. Selecting it is likewise deemed consent. - Sharing and disclosure of personal information
The Company uses personal information within the scope stated in Section 2, “Purposes of processing personal information,” and does not use it beyond that scope or disclose it to other individuals, companies, or organizations, except in the following circumstances:- The customer has consented to disclosure in advance.
- Disclosure is required by law or requested by an investigative authority for an investigation in accordance with legally prescribed procedures and methods.
- Disclosure is necessary to settle charges for services provided.
- Information is necessary for statistics, academic research, or market research and is provided in a form that cannot identify a specific individual.
- Use of personal information and disclosure to third parties
For product and event promotions, SORIMON provides names, addresses, and contact details to the following partners only to the extent necessary for the relevant work. It establishes and supervises requirements to ensure that partner companies handle personal information safely. Information is destroyed without delay once its purpose has been fulfilled.- Recipients: affiliated partner companies.
- Purpose: event participation.
- Information provided: name, telephone number, and address.
- Retention and use period: destroyed immediately once the purpose has been fulfilled.
- Outsourcing the processing of personal information
To provide smooth and convenient services, SORIMON outsources personal information processing to specialist external companies within a minimum, limited scope. Outsourcing contracts separately stipulate requirements to ensure that personal information is managed safely.- Domestic companies
Payments
- Processor: KG Inicis.
- Outsourced tasks: payment processing and purchase protection services.
- Retention and use period: until membership withdrawal or contract expiration.
Verification
- Processor: NICE Credit Information.
- Outsourced tasks: identity verification.
- Retention and use period: destroyed immediately once the purpose has been fulfilled.
Message delivery
- Processor: Kakao Corp.
- Outsourced tasks: sending SMS or Alimtalk notification messages.
- Retention and use period: destroyed immediately once the purpose has been fulfilled.
- Overseas companies
Push notifications
- Processor: Amazon.
- Destination country: United States.
- Outsourced tasks: sending notification messages to mobile devices.
- Retention and use period: follows the retention policy for records concerning consumer complaints or dispute resolution.
- Domestic companies
- Overseas transfer of personal information
The Company transfers personal information overseas as follows to provide its services:- Information transferred: user ID and unique mobile device ID.
- Destination country: United States.
- Time and method of transfer: transmitted over the network when an inquiry is submitted.
- Recipient: Amazon.
- Recipient’s purpose of use: identifying individual devices by category.
- Recipient’s retention and use period: until membership withdrawal.
- Retention periods and membership withdrawal
- Retention and use periods for personal information
Personal information is destroyed without delay when a member requests withdrawal, withdraws consent to collection and use, the purpose of collection and use has been fulfilled, or the retention and use period has ended. However, the following information is stored separately for the periods required by applicable laws and is destroyed without delay after those periods expire.Records of contracts or withdrawal of offers
- Legal basis: Act on the Consumer Protection in Electronic Commerce.
- Retention period: 5 years.
Records of payments and supply of goods
- Legal basis: Act on the Consumer Protection in Electronic Commerce.
- Retention period: 5 years.
Records of consumer complaints or dispute resolution
- Legal basis: Act on the Consumer Protection in Electronic Commerce.
- Retention period: 3 years.
Website visit records
- Legal basis: Protection of Communications Secrets Act.
- Retention period: 3 months.
- Membership withdrawal and restrictions on re-registration
The user ID of an account whose withdrawal has been completed can never be reused. The email address may be reused after 30 days. Duplicate user IDs and email addresses are checked to enforce re-registration restrictions by comparing unique, irreversibly encrypted one-way values. - Rights
In principle, users have the right to refuse consent to the collection of personal information under the Personal Information Protection Act. If consent is refused, membership registration is unavailable.
- Retention and use periods for personal information
- Procedures and methods for destroying personal information
In principle, personal information is destroyed without delay once the purpose of its collection and use has been fulfilled. The Company uses the following procedures and methods.- Procedures
- Information entered for membership registration or similar purposes is transferred to a separate database — or a separate filing cabinet for paper records — after its purpose has been fulfilled. It is retained for a specified period under internal policies and other applicable legal requirements for information protection before being destroyed. See the retention and use periods.
- Retained personal information is not used for any other purpose unless permitted by law.
- Methods
- Personal information printed on paper is destroyed by shredding or incineration.
- Personal information stored in electronic files is deleted using technical methods that prevent the records from being recovered.
- Procedures for dormant accounts
- Under Article 29 of the Act on Promotion of Information and Communications Network Utilization and Information Protection and Article 16 of its Enforcement Decree, SORIMON designates accounts that have not logged in for one year or longer as dormant and manages their personal information separately to protect it.
- Information subject to dormant account processing: all information collected or managed during registration or changes to member information.
- SORIMON notifies the user by email or other means one month before the separate storage period for the dormant account’s personal information begins.
- Personal information belonging to dormant accounts is destroyed without delay three years after separate storage begins.
- Procedures
- Cookies and user choices
- Use and purposes of cookies
Like other websites, the Company uses cookies. Cookies are small amounts of information that a website sends to the Internet browser on a user’s computer and stores on its disk. They identify the computer rather than the customer. Cookies are used to provide optimized services, including keeping users signed in, remembering user IDs, and analyzing usage patterns. - Installation, operation, and rejection of cookies
Customers can choose whether to allow cookies. Although the process varies by browser, most browsers allow users to accept or reject cookies or delete all existing cookies through their settings. Rejecting cookie storage may restrict access to some services that require login.Cookie settings
- Internet Explorer: Tools → Internet Options → Privacy → set the privacy level.
- Chrome: Settings → Show advanced settings → Privacy and content settings → set the cookie level.
- Firefox: Options → Privacy → History and custom settings → set the cookie level.
- Safari: Preferences → Privacy → set the level for cookies and website data.
- Use and purposes of cookies
- Users’ rights and obligations
- Users’ rights
- Customers may view or modify their registered personal information at any time and may request membership withdrawal.
- To view or modify personal information, select “Change Information.” To cancel membership or withdraw consent, select “Withdraw Membership.” After identity verification, users can view or correct information or complete withdrawal directly.
- The Company will act without delay if contacted by letter, telephone, or email through the personal information protection officer.
- When correction of an error is requested, the relevant personal information will not be used or disclosed until the correction is complete. If incorrect information has already been provided to a third party, the Company will notify that party of the correction without delay so that its records can be corrected.
- Users’ obligations
- Please keep your personal information accurate and current to prevent unexpected incidents. Customers are responsible for incidents caused by inaccurate information they provide. Using another person’s information or entering false information may result in loss of membership.
- Customers are responsible for protecting themselves and respecting other people’s information. Take care to prevent disclosure of your personal information, including your password, and do not damage other people’s personal information or posts.
- Failure to meet these responsibilities that harms another person’s information or dignity may be punishable under the Act on Promotion of Information and Communications Network Utilization and Information Protection and other applicable laws.
- Users’ rights
- Technical and organizational protection measures
When processing personal information, the Company takes the following technical and organizational measures to prevent loss, theft, disclosure, alteration, or damage.- Password encryption
Passwords for SORIMON member accounts are stored and managed in encrypted form and are known only to the account holder. Only the holder who knows the password can view or change personal information. - Measures against hacking and other threats
The Company makes every effort to prevent members’ personal information from being disclosed or damaged by hacking or computer viruses.- It frequently backs up data, uses up-to-date antivirus software to prevent disclosure or damage to users’ information and data, and uses encrypted communications to transmit personal information safely over networks.
- It uses firewalls to prevent unauthorized external access and strives to implement all available technical measures to ensure system security.
- Limiting and training staff who process information
- Staff who process personal information are limited to those responsible for the relevant work. They are assigned individual passwords that are updated regularly. Frequent training emphasizes compliance with the privacy policy.
- Staff handling personal information sign security commitments when joining the Company to prevent disclosures by personnel. Internal procedures audit implementation of the privacy policy and employees’ compliance.
- Handover of personal information processing duties is conducted thoroughly while maintaining security. Responsibility for personal information incidents during and after employment is clearly defined.
- Dedicated personal information protection organization
An internal organization dedicated to personal information protection checks implementation of the policy and compliance by responsible staff, and strives to correct any problems immediately. However, the Company assumes no responsibility for problems caused by disclosure of user IDs, passwords, email addresses, or other personal information due to the user’s own negligence or problems on the Internet.
- Password encryption
- Personal information protection officer and responsible staff
- Duties to manage and protect personal information
The Company makes every effort to use personal information safely and provide the best service. The personal information protection officer is responsible for incidents that contravene the measures stated above. However, the Company assumes no responsibility for damage to information resulting from unforeseen incidents caused by inherent network risks, such as hacking, despite technical safeguards, or for disputes arising from posts written by visitors. - Contact details for the responsible department
Users may report any personal information protection complaints arising from use of the Company’s services to the personal information protection officer or the responsible department. The Company will provide prompt and sufficient responses.Personal information management department and protection officer
- Name: Kim Chang-gyun.
- Department: Personal Information Protection Team.
- Position: CTO.
- Telephone: 02-6213-2045.
This number connects to the department responsible for personal information protection, which accepts requests to access personal information. - Fax: 02-6213-2052.
- Email: comfuture@iplateia.com.
For other reports or consultations concerning personal information infringements, contact the following organizations:- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 without an area code.
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972 without an area code.
- Cyber Investigation Division of the Supreme Prosecutors’ Office: www.spo.go.kr / 1301 without an area code.
- Cyber Safety Bureau of the National Police Agency: cyberbureau.police.go.kr / 182 without an area code.
- Duties to manage and protect personal information
- Duty to give notice
Additions, deletions, or amendments to this privacy policy will be announced in the website’s notices section at least seven days before the revision. The policy includes a version number, the date of the change announcement, and the effective date so that revisions can be identified easily.
Privacy policy version: 1.0
Privacy policy effective date: August 29, 2018