The online service provided by SNP lab Inc. (hereinafter referred to as "Company") is important for the user's personal information, and "Act on the Promotion of Information and Communication Network Use and Information Protection" and "Personal Information Protection Act" The Act on the Law on Personal Information, such as the Act on the Use and the Act on the Use and Protection of Credit Information, and the Ministry of Public Administration and Security and the Korea Communications Commission, the Financial Services Commission, and the Fair Trade Commission. I am observing. If the company collects, uses, and provides users' personal information, it must inform the user in advance and go through the agreement process. However, if you refuse consent, all or part of the service may be limited. Companies want to inform you that the personal information provided by the user is used for any purpose and method, and is always trying to protect it.
¡¤ This policy will be implemented from
1. Personal information item collected
The company collects the following personal information by dividing the following personal information by selecting basic services such as membership registration and smooth customer consultation and selection information for customized services. Even if you do not enter the selection information, there is no restriction on the use of the service, and no sensitive personal information (race, thought and creed, political tendency, criminal records, medical information, etc.) are not collected.
A. Mandatory
The following information can be automatically generated and collected during the service process or service provision process.
-Mail address, service usage record, access log, cookie, access IP information, defective use record
B. Selection information
Counseling/Inquiries: Name: Name, mobile phone, mail address
C. How to collect personal information
Homepage membership, event application, collection through collection tools, member information modification, fax, telephone, customer center inquiries
2. Purpose of collecting and using personal information
Companies use the collected personal information for the following purposes. All the information provided by the user is not used except for the purpose required for the following purposes, and if the purpose of use is changed, it will obtain prior consent.
A. Settlement of the fee for contract implementation and service provision
Content provision, purchase and rate payment, goods delivery or claim, financial transaction identification and financial services, etc.
B. Member management
Use of membership service and identification, personal identification, disruption of defect members, prevent unauthorized use of unauthorized members, confirm the intention of subscription, confirm age, and when collecting personal information under 14 years of age, Civil complaint processing, notice
C. Use for marketing and advertising
Information delivery and customized service according to the event event, provision of services according to demographic characteristics, advertising, identification of connection frequency or statistics on members' service use
3. Personal information processing and holding period
The company processes and retains personal information within the period of retention and use of personal information from the user's personal information retention, use period or information subjects during the period of providing services from the date of membership.
A. Personal information related to the homepage membership and management, civil affairs processing, goods or services, marketing and advertising is held and used for the purpose of using the above purpose from the date of consent on collection and use.
B. If it is necessary to preserve it in accordance with the provisions of relevant laws and regulations, such as the Law on Consumer Protection in e -commerce, the company shall keep member information for a certain period of time prescribed by the relevant laws and regulations. In this case, the company uses the information to be kept only for the purpose of the storage, and the preservation period is as follows.
-Recision on contracts or withdrawal of subscriptions: Act on consumer protection in e -commerce (preservation period: 5 years)
-Recording on the supply of payment and goods, etc.
-She Preservation of Electronic Financial Transactions: Electronic Financial Transactions Act (Preservation Period: 5 years)
-Securing records on the issuance of tax invoices: VAT Act (Preservation Period: 5 years)
-She Preservation of Consumer Complaints or Dispute Processing: Act on Consumer Protection in E -Commerce (Preservation Period: 3 years)
-She Preservation of Records on Collection/Processing and Use of Credit Information: Act on the Use and Protection of Credit Information (Preservation Period: 3 years)
-Recording of identity verification (name, mobile phone number, legal representative information, date of birth, gender, identity verification): Law on the Promotion of Information and Communication Network Use and Information Protection (Preservation Period: 6 months)
-She preservation of records of service records, access logs, access IP information: Communication Secret Protection Act (Preservation Period: 3 months)
-She Preservation of Records on Label/Advertising: Act on Consumer Protection in E -Commerce, etc. (Preservation Period: 6 months)
-She retention of records on e -mails: Prevention of confusion of service use, investigation of investigative institutions for illegal users (preservation period: 1 month)
4. Matters concerning the provision of third parties of personal information
Companies have the personal information of users 2. It is used within the scope of the collection and use of personal information, and without the user's prior consent, it shall not use the user's personal information to the outside or in principle. However, in the following cases, you can pay attention and provide personal information.
A. IRS
-Person who receives personal information: IRS
-Purpose of using personal information of the receiver: Tax invoice issuance
-The item provided: Mutual name, representative name, business registration number, workplace location, representative e -mail, person in charge, person in charge
-Leeviors of those who are provided: When the service comes first on the date of termination, termination, or the termination date of the contract.
B. Financial Services Agency
-Person who receives personal information: Financial Services Agency
-Purpose of using personal information of the receiver: CMS withdrawal service
-The item provided: Mobile phone number, social security number, bank account information, bank name, deposit name name
-Leaves and usage period of those who are provided: 5 years
C. If you have the requirements of the investigative agency in accordance with the provisions of the law, or according to the procedures and methods prescribed by the law for the purpose of investigation.
D. It is significantly difficult to obtain ordinary consent for economic and technical reasons as a personal information necessary for the implementation of the contract for the provision of the service.
5. Consignment of the collected personal information processing
Companies do not entrust the user's information to external companies without the user's consent. If such a need is in the future, we will notify the user about the consignment subjects and the consignment work and receive the consent if necessary.
6. Information subject's rights and obligations and how to exercise
Users and legal representatives (those who have the effect of representatives under the provisions of the law without the delegation of the law, and refer to the parental authority or guardian of a minor), are registered at any time, and the personal information of children under the age of 14 You can search or modify it and request to be signed.
Personal information change (or 'membership information modification') to inquire and revise the personal information of users or children under the age of 14, and click 'withdrawal' in order to perform the termination (withdrawal). After passing through the identity verification process, it is possible to directly view, correct or withdraw. Alternatively, please contact the person in charge of personal information management.
If you request a correction of errors of your personal information, you will not use or provide the personal information until you complete the correction. In addition, if the wrong personal information has already been provided to a third party, the correction will be made by notifying the third party without delay.
Companies are terminated or deleted by the request of a user or legal representative. Personal information processing and retention period is processed as specified and cannot be viewed or used for other purposes.
7. Matters concerning the installation, operation, and rejection of personal information automatic collection devices
In order to provide users with specialized services, the company operates 'Cookie' that stores and loads users from time to time. Cookie is a very small text file used by a server used to operate the website to the user's browser. Companies use cookies for the following purposes.
A. Purpose of using cookies
Analyzing the frequency of members and non -members 'access and visiting time, identifying and tracing users' tastes and interests, tracing traces, participating in various events, and identifying visits, etc. I have. Therefore, the user can set up an option in the web browser, allow all cookies, check each time the cookie is stored, or refuse to store all cookies.
B. How to refuse cookies
To refuse cookies, you can select the options of the web browser used by the user to allow all cookies, check each time you save cookies, or refuse to save all cookies.
-Setting method (for Internet Explorer): Tools at the top of the web browser> Internet option> Personal information
-However, if you refused to install cookies, it may be difficult to use the service.
8. Technical and administrative protection measures of personal information
The user's personal information is protected by passwords and encryption, and is required to secure safety as follows.
A. Personal information encryption
The user's personal information is protected by a password, and important data protects them through separate security functions such as encrypting files and transmission data or using file lock functions.
B. Technical measures for hacking, etc.
In order to prevent the user's personal information from being leaked or damaged by hacking or computer viruses, a system is installed in an area where access from the outside, and the use of intrusion blocking devices and intrusion detection systems are monitored for 24 hours. And when the vaccine program is periodically updated and sudden virus appears, it is prevented from being infringed by applying it as soon as the vaccine comes out. In addition, we are working with all possible technical devices to secure security in other systems.
C. Restriction on access to personal information processing system
Companies establish criteria for granting, changing, and eradication of access rights to database systems systematically organized to handle personal information, and operate a method of generating passwords, and changing cycles, and controlling access to other personal information We are doing the necessary measures.
D. Education of personal information handling
Personal information -related employees are limited to the person in charge, minimizing them, regular training on the acquisition of new security technologies and personal information protection, and giving separate passwords to manage access to access.
E. Personal ID and password management
The ID and password used by the user are in principle that only the user is used. Companies are not responsible for the problems caused by leaking personal information such as ID and password due to the user's personal carelessness and the risk of basic Internet. With security awareness of your password, you can change your password frequently and pay special attention so that your personal information is not leaked when logging in on a public PC.
9. Personal information destruction procedure and method
In principle, the company destroys the information without delay after the purpose of collecting and using personal information is achieved. The destruction procedures and methods are as follows:
A. Destruction procedure
The information entered by the user will be destroyed in accordance with the laws and regulations in the internal policy and related laws after the retention period has elapsed or has elapsed or has elapsed the retention period.
B. Destruction period
When the personal information of the user has elapsed, the personal information has elapsed within 7 days of the end of the retention period, and when the personal information is unnecessary, such as achieving the purpose of processing personal information, abolition of the service, and the termination of the business, personal information Desine the personal information within 7 days from the date when the processing of the process is unnecessary.
C. Destruction way
Information in the form of an electronic file uses a technical method that cannot play the record. Personal information printed on paper is grinded with a grinder or destroyed through incineration.
10. Personal Information Protection Officer
In order to protect the user's personal information and handle complaints related to personal information, the company is designating the personal information manager and the personal information protection department as shown below. The user can use the company's services to all personal information protection complaints to the personal information manager and department.
A. Personal information protection officer
Name : Kim Tae-yoon
Belonging : CS
Position : CEO
Phone : 043-212-7775
e-mail : taesway@gmail.com
B. Personal information protection department
department : Personal Information Protection Team
Name : Kim Tae-yoon
Phone : 043-212-7775
e-mail : taesway@gmail.com
11. How to relief in invasion of rights
If you need a report or consultation on other personal information infringement, please contact the agency below.
A. Personal Information Infringement Report Center (Operation of the Korea Internet & Security Agency)
-Jurk: Report on the facts of personal information infringement, application for consultation
-Homepage: Privacy.kisa.or.kr
-Phone: (without national number) 118
B. Personal Information Dispute Coordination Committee (Operation of the Korea Internet & Security Agency)
-Jurges: Application for reconciliation of personal information disputes, coordination of group disputes (civil resolution)
-Homepage: Privacy.kisa.or.kr
-Phone: (without national number) 118
The Supreme Prosecutors' Office Cyber Crime Investigation Team: 02-3480-3573 (www.spo.go.kr)
Police Agency Cyber Crime Investigation Team: 1566-0112 (www.netan.go.kr)
12. Supplies
In accordance with the change of laws and policies, policies or security technologies, if there is any addition, deletion and modification of the current privacy policy, the company will notify the company's notice from at least 7 days before the effective date of change. However, changes to the importance of the user's rights or obligations will be notified at least 30 days before the effective date.
A. Personal information handling policy announcement date :
B. Personal information handling policy enforcement date :