establishes and discloses a personal information processing policy as follows to protect the personal information of the information subject and to quickly and smoothly handle related grievances in accordance with Article 30 of the Personal Information Protection Act.
○ This personal information processing policy will take effect from July 22, 2022.
Article 1 (Purpose of processing personal information) ’ processes personal information for the following purposes: The personal information being processed is not used for any purpose other than the following, and if the purpose of use is changed, necessary measures will be implemented, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
1. Register and manage membership on the homepage
Personal information is processed for the purpose of confirming the intention to sign up for membership, identifying and certifying membership, maintaining and managing membership, preventing fraudulent use of services, checking the consent of legal representatives, notifying, and handling complaints.
2. Handling of civil affairs
Personal information is processed for the purpose of identifying the complainant’s identity, checking complaints, contacting and notification for fact-finding, and notification of processing results.
3. Provision of goods or services
It processes personal information for the purpose of delivery of goods, service provision, content provision, customized service provision, personal authentication, rate payment, and settlement.
4. Use in marketing and advertising
Personal information is processed for the purpose of developing new services (products) and providing customized services, providing event and advertising information and providing opportunities for participation, providing services according to demographic characteristics, publishing advertisements, and validating services.
Article 2 (Period of processing and holding personal information)
① processes and holds personal information within the period of use, or the period of use of personal information agreed upon when collecting personal information from the information subject.
② The processing and holding period of each personal information is as follows.
1.
Collect personal information related to .Held for the above purpose of use from the date of consent for use to It’s used.
Grounds for retention: Need to retain information for member management
Article 3 (processing of personal data items).
① handles the following personal information items
1 .
Essential items : email, cell phone number, home addresses, passwords, login id, service records, payment records.
Selection : home phone number, date of birth.
Article 4 (Matters concerning the provision of personal information to third parties)
① processes personal information only within the scope specified in Article 1 (purpose of processing personal information), and provides personal information to third parties only if it falls under Articles 17 and 18 of the Personal Information Protection Act, such as consent of the data subject and special provisions of the law.
② provides personal information to third parties as follows.
1. < ABYBOM >
Person receiving personal information: ABYBOM
Purpose of using personal information of the recipient: e-mail, mobile phone number, home address, password, login ID, date of birth, name, service usage record, payment record
the possession of a person on offerPeriod of use: semi-permanent
Article 5 (Matters concerning entrustment of personal information processing)
① entrusts personal information processing work as follows for smooth personal information processing.
Consignee (Consignee): CJ Logistics
Contents of entrusted business: Product delivery
② In accordance with Article 26 of the Personal Information Protection Act, stipulates in documents such as contracts, such as prohibition of personal information processing, technical and management protection measures, re-entrustment restrictions, and supervises whether the trustee handles personal information safely.
③ If the contents of the entrusted work or the trustee changes, we will disclose it through this personal information processing policy without delay.
Article 6 (Procedures for destruction of personal information and method of destruction)
① destroys personal information without delay when personal information becomes unnecessary, such as the passage of the personal information retention period or the achievement of the purpose of processing.
② The procedure and method of destroying personal information are as follows.
1. Revocation procedure selects the personal information in which the reason for destruction occurred, and destroys the personal information with the approval of the person in charge of personal information protection of .
2. Destruction method
Information in the form of electronic files uses technical methods that cannot reproduce records.
The personal information printed on the paper is destroyed by crushing or incineration with a shredder
Article 7 (Matters concerning the rights and obligations of the information subject and legal representative and the method of exercising them)
① The information subject may exercise the rights to ABYBOM at any time, such as requesting access to personal information, correction, deletion, and suspension of processing.
② The exercise of rights under paragraph 1 can be made to ABYBOM in writing, e-mail, and fax in accordance with Article 41 1 of the Enforcement Decree of the Personal Information Protection Act, and ABYBOM will take action without delay.
③ The exercise of rights under paragraph 1 may be conducted through a legal representative of the information subject or a delegated person, etc.In such cases, "Notification on how to process personal information (No. 2020-7)" You must submit a power of attorney in accordance with attached Form 11.
④ Requests for access to personal information and suspension of processing may limit the rights of the data subject pursuant to Articles 35 4and 37 2 of the Personal Information Protection Act.
⑤ Requests for correction and deletion of personal information cannot be requested if the personal information is specified as a collection target in other laws.
⑥ ABYBOM confirms whether the person who requested access, correction/deletion, or suspension of processing is the person or a legitimate agent.
Article 8 (Matters concerning measures to ensure the safety of personal information) is taking the following measures to ensure the safety of personal information.
1. Conduct regular self-audit
Self-audit is conducted regularly (once a quarter) to secure stability related to personal information handling.
2. Establishing and implementing an internal management plan
Internal management plans are established and implemented for safe processing of personal information.
3. Encryption of personal information
Your personal information is encrypted, stored, and managed, so only you can know your personal information, and important data uses separate security features such as encrypting files and transmission data or using file locking functions.
4. Storage of access records and prevention of forgery
Records accessed to the personal information processing system are stored and managed for at least one year, but if personal information is added to more than 50,000 information subjects, or if unique identification or sensitive information is processed, it is stored and managed for more than two years.
In addition, security features are used to prevent forgery, theft, or loss of access records.
5. Restrict access to personal information
We take necessary measures to control access to personal information by granting, changing, and canceling access to the database system that processes personal information, and control unauthorized access from the outside using an intrusion prevention system.
6. Use of locks for document security
Documents containing personal information, auxiliary storage media, etc. are stored in a safe place with a lock.
Article 9 (Matters concerning the installation, operation, and rejection of devices that automatically collect personal information)
① To provide individual customized services to users, ABYBOM uses a cookie that stores usage information and loads it from time to time.
② Cookies are a small amount of information that the server (http) used to run the website sends to the user's computer browser and is also stored on the hard disk in the user's PC computer.
A. Purpose of using cookies: It is used to provide optimized information to users by identifying the types of visits and usage of each service and website visited by users, popular search terms, security access, etc.
B. Installation and Operation and Denial of Cookies: You can deny saving cookies by setting options in the Tools > Internet Options > Privacy menu at the top of your web browser.
C. Refusing to save cookies may make it difficult to use customized services.
Article 10 (Matters concerning the collection, use, provision, refusal, etc. of behavioral information)
Matters concerning the collection, use, provision, rejection, etc. of behavioral information
does not collect, use, or provide behavioral information for online customized advertisements.
Article 11 (Criteria for determining additional use and provision)
< ABYBOM > In accordance with Article 15 (3) and 17 (4) of the 「Personal Information Protection Act」, taking into account the matters pursuant to Article 14-2 of the 「Personal Information Protection Act Enforcement Decree」, additional personal information is added without the consent of the information subject. It can be used and provided.
Accordingly, in order for to provide additional use and provision without the consent of the information subject, the following matters were considered.
▶ Whether the purpose of additional use and provision of personal information is related to the original purpose of collection
▶ Whether additional use and provision are predictable in light of circumstances or processing practices in which personal information is collected
▶ Whether additional use or provision of personal information unfairly violates the interests of the information subject
▶ Whether measures necessary for ensuring safety, such as pseudonym processing or encryption, have been taken
※ The criteria for judging considerations for additional use and provision shall be prepared and disclosed by the business operator/organization