Coreana Cosmetics Co., Ltd. (hereinafter “Coreana”) uses and provides the user’s personal information based on the user’s consent, and actively guarantees the user’s right(the right to control one’s own personal information).
Coreana complies with applicable laws, personal information protection regulations and guidelines of the Republic of Korea, which must be obeyed by information communication service providers.
1. Purpose of Personal Information Processing
Coreana processes personal information for the following purposes. The processed personal information will not be used for any purpose other than the following, and prior consent will be sought when the purpose of use is changed.
- Establishment of a contract for service provision (identification of the individual and confirmation of his/her intention, etc.)
- Implementation of services (CS handling consultation, beauty consultation.)
2. Processing and retention period of personal information
In principle, users’ personal information is destroyed without delay when the purpose of processing personal information is achieved. However, the following information is retained for the period specified for the following reasons.
- Records on payment and supply of goods for 5 years
- Record of consumer complaints or disputes for 3 years
- Items of personal information to be collected
- Name, address, mobile phone number, E-mail, consultation details
3. Disclosing personal information to third parties
In principle, Coreana handles users' personal information within the scope specified in Article 1 (Purpose of Personal Information Processing), and does not process beyond the original scope or provide it to a third party without the user's prior consent. However, personal information may be processed in the following cases.
- In case the user consents to the provision and disclosure by a third party in advance.
- When provision is required by law, etc.
- In the case of personal information necessary for the implementation of the contract for the provision of services, when it is significantly difficult to obtain ordinary consent for economic/technical reasons.
4. Rights and obligations of information subjects and legal representatives and how to exercise them
Users can exercise the following rights as information subjects.
Request to view personal information: Personal information files held by Coreana may be requested to be viewed in accordance with Article 35 (Access to Personal Information) of the 「Personal Information Protection Act」. When requesting access to personal information, access may be restricted in accordance with Article 35 (5) of the Act.
1) When disclosure is prohibited or restricted by law
2) If there is a risk of harming the life or body of another person or unfairly infringing on the property and other interests of another person
- Request for correction or deletion of personal information: Personal information files held by Coreana may be requested for correction or deletion in accordance with Article 36 (Correction and deletion of personal information) of the 「Personal Information Protection Act」. However, if the personal information is specified as a target of collection in other laws, the deletion cannot be requested.
- Request to suspend processing of personal information: You may request to suspend processing of personal information files held by Coreana in accordance with Article 37 of the 「Personal Information Protection Act」 (Stop processing of personal information, etc.). When requesting the suspension of processing of personal information, the request for suspension of processing may be rejected in accordance with Article 37 (2) of the Act.
- 1. If there are special provisions in the law or it is unavoidable to comply with the legal obligations
- 2. If there is a risk of harming the life or body of another person or unfairly infringing on the property and other interests of another person
- 3. If a public institution is unable to perform its duties as stipulated by other laws without processing personal information
- 4. If it is difficult to fulfill the contract, such as not being able to provide the service agreed upon with the information subject if personal information is not processed, and the information subject does not clearly indicate its intention to terminate the contract
- You can view, correct, and delete personal information through the customer center (080-022-5013).
- Requests for suspension of processing of personal information will be taken care of by contacting via email to the person in charge of personal information management.
- In the case of children under the age of 14, the legal representative has the right to inquire or correct the child's personal information, and the right to withdraw consent to collection and use.
5. List of personal information to be processed
The items of personal information processed by Coreana and the collection method to provide services are as follows.
- Collection items: name, address, mobile phone number, e-mail, consultation details
- Collection method: website
6. Destruction of personal information
In principle, Coreana will destroy personal information without delay when the purpose of processing personal information is achieved. However, this is not the case when preservation is required according to other laws. The procedures, deadlines and methods of destruction are as follows.
1) Destruction procedure
The information entered by the user will be stored for a certain period of time or immediately destroyed in accordance with the internal policy and related laws after the purpose is achieved.
If the retention period of personal information has elapsed, the user's personal information is destroyed within 5 days from the end of the retention period, and within 5 days from the date of recognition when the personal information becomes unnecessary, such as when the purpose of processing personal information is achieved.
3) Destruction method
Since the personal information files processed by Coreana are recorded in the form of electronic files, they are destroyed using a technical method that cannot be reproduced.
7. Matters concerning the installation and operation of the automatic personal information collection device and its rejection
It aims to provide targeted marketing and personalized services by analyzing the frequency of site access and visit time, and identifying the degree of participation in various events and number of visits, etc. You have the option to install cookies. Therefore, you can accept all cookies by setting options in your web browser, check each time a cookie is saved, or refuse to save all cookies.
2) How to decline cookie settings
Users have the option of installing cookies. Users can allow all cookies by choosing their options in the web browser, users can block all cookies or they can set it as having option to allow or block whenever cookies is to be saved in users’ web browser.
Example of setting method (in case of Internet Explorer): Tools at the top of the web browser -> Internet Options -> Personal Information
8. Measures to ensure the safety of personal information
In accordance with Article 29 of the 「Personal Information Protection Act」, Coreana is taking the following technical, managerial and physical measures necessary to ensure safety.
1) Establishment and implementation of internal management plan
Coreana's internal management plan is established and implemented in compliance with the internal management guidelines of the Ministry of Public Administration and Security.
2) Minimization of personal information handling personnel and training
We are implementing measures to manage personal information by designating and minimizing the person in charge of handling personal information.
3) Restricting access to personal information
We take necessary measures to control access to personal information by granting, changing, and canceling access rights to the database system that processes personal information, and use an intrusion prevention system to control unauthorized access from outside.
4) Storage of access records and prevention of forgery
Records of access to the personal information processing system (web logs, summary information, etc.) are stored and managed for at least 6 months, and security functions are used to prevent forgery, theft, or loss of access records.
5) Encryption of personal information
Users' personal information is encrypted, stored and managed. In addition, we use a separate security function such as encrypting important data for storage and transmission.
6) Technical measures against hacking
Coreana installs a security program to prevent leakage and damage of personal information caused by hacking or computer viruses, and periodically updates and inspects it. We install the system in an area where access is controlled from outside, and performs technical/physical monitoring and maintenance. It also detects attempts to control network traffic as well as illegally change information.
7) Access control for unauthorized persons
The physical storage place of the personal information system is separate, and access control procedures are established and operated.
9. Privacy Officer
In order to protect personal information and handle complaints related to personal information, Coreana has designated the person in charge of personal information protection and the person in charge as follows. (Person in charge of personal information protection pursuant to Article 31 Paragraph 1 of the Personal Information Protection Act)
Personal Information Protection Officer
Department in charge: ROG Department
Name: Kim Young Tai
10. Consignment of handling of personal information
Coreana consigns personal information as follows to provide services, and stipulates necessary matters so that personal information can be safely managed in the consignment contract in accordance with relevant laws and regulations. The company's personal information consignment processing agency and consignment work are as follows.
|Period of retention and use of personal information
|Lotte Global Logistics
|Delivery of service items and event prizes
|Until the end of the consignment contract
|NICE Information Service Co., Ltd.
|i-Pin authentication, mobile phone identity verification
|Not saved separately
11. Remedies for Infringement of Rights
The information subject may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency Personal Information Infringement Report Center in order to receive relief from personal information infringement. In addition, for other personal information infringement reports and consultations, please contact the following organizations.
1. Personal Information Dispute Mediation Committee: (without area code) 118 (ext. 2)
2. Information Protection Mark Certification Committee: 02-580-0533~4 (http://eprivacy.or.kr)
3. Advanced Crime Investigation Division, Supreme Prosecutors' Office: 02-3480-2000 (http://www.spo.go.kr/)
4. National Police Agency Cyber Terror Response Center: 02-392-0330 (http://www.ctrc.go.kr/)