DAEON Law Firm (hereinafter referred to as the "Firm") complies with the personal information protection provisions of the applicable laws and regulations, including the Personal Information Protection Act and
the Act on Promotion of Information and Communications Network Utilization and Information Protection, and
has established this Privacy Policy in accordance with the relevant laws and regulations, making every effort to protect the rights and interests of users.
For the purposes of this Privacy Policy, "Member" is limited to a user of the information and communications services provided by an information and communications service provider as defined in Article 2, Paragraph 4 of the Act on Promotion of Information and Communications Network Utilization and Information Protection.
Where the Firm intends to collect and use a Member's personal information, it shall obtain the Member's own consent in accordance with Articles 15, 22 and 24 of the Personal Information Protection Act.
In addition, where personal information obtained from a Member is to be provided to a third party, the Firm shall obtain the Member's own prior consent in accordance with Articles 17, 22 and 24 of the Personal Information Protection Act.
This Privacy Policy shall apply from its effective date, and in the event of any addition, deletion or correction of its contents pursuant to laws or policies, such changes will be announced through the Notice section at least 7 days prior to their taking effect.
1. Purposes of Collection and Use of Personal Information
1) Website membership registration and management
Confirmation of the intention to register as a member, identification and authentication of the individual for the provision of membership-based services, maintenance and management of membership status, identity verification under the limited identity verification system, prevention of fraudulent use of services, confirmation of legal guardian consent when collecting personal information of children under the age of 14, various notices and notifications, handling of grievances, and retention of records for dispute mediation, etc.
2) Handling of civil complaints
Verification of the complainant's identity, confirmation of the details of the complaint, contact and notification for fact-finding, notification of the results of handling, etc.
3) Provision of goods or services: development and improvement of services, provision of content, delivery of invoices, identity verification for financial transactions and financial services, age verification, payment and settlement of fees, management of delinquent accounts and risk management in the event of default, debt collection, provision of loan/investment services, etc.
4) Use for marketing and advertising
Delivery of the latest information on new service development and events, provision of customized services, provision of services and placement of advertisements based on statistical analysis, etc.
2. Personal Information to Be Collected and Used
The Firm collects personal information as set out below, comprising the information required for the provision of basic services such as membership registration, smooth customer consultation and various other services, as well as information for the provision of customized services.
1) Personal identification information
Name, date of birth, gender, business registration number, date of issuance of resident registration card, contact information (mobile phone, home, workplace), address (home, workplace), email, name of workplace, department, position, nationality, driver's license number, passport number, alien registration number, ID, password, access logs, cookies, service usage records, access IP information, voice data, etc.
2) When using investment services
Bank account information, resident (corporate) registration number (for withholding tax returns on investment income)
3. Retention and Use Period of Personal Information
The Firm retains personal information collected from data subjects with their consent for a period of 5 years from the date of membership withdrawal or the date of termination of the creditor-debtor relationship (provided that, where the relevant laws and regulations expressly stipulate a separate period, such period shall apply).
4. Procedures and Methods for the Destruction of Personal Information
In principle, the Firm destroys the relevant information without delay once the purpose of collection and use of the personal information has been achieved or the retention and use period has expired. The procedures, time limits and methods for destruction are as follows.
1) Destruction procedure: Information entered by users for membership registration and other purposes is, once the purpose has been achieved, transferred to a separate database system (DB) (or a separate filing cabinet in the case of paper documents) and stored for a certain period pursuant to internal policies and other information protection grounds under the relevant laws and regulations (see Retention and Use Period), after which it is destroyed.
2) Destruction time limit: Where the retention period of a user's personal information has expired, the Firm destroys such personal information within 5 days from the end of the retention period; where the personal information has become unnecessary due to the achievement of the purpose of processing, the discontinuation of the relevant service, the closure of business, or otherwise, the Firm destroys such personal information within 5 days from the date on which its processing is deemed unnecessary.
3) Destruction method: Personal information transferred to a separate DB is not used for any other purpose except as required by law. Personal information stored in electronic file format is deleted using technical methods that render the records unrecoverable.
5. Rights and Obligations of Data Subjects and How to Exercise Them
1) Access to and correction of personal information
Members and their legal guardians may at any time access or correct the registered personal information of the customer.
Access to and correction of personal information may be carried out directly under "Edit Member Information," and may also be requested in writing, by email, by FAX or otherwise, using Attached Form No. 8 of the Enforcement Rules of the Personal Information Protection Act.
2) Requests for deletion of personal information
Where a data subject requests the correction or deletion of personal information on grounds such as errors therein, the Firm shall not use or provide the relevant personal information until the correction or deletion has been completed.
3) Withdrawal of consent to the collection, use and provision of personal information
Members may at any time withdraw their consent to the collection, use and provision of personal information. Withdrawal of consent may be requested in writing, by email, by FAX or otherwise, using Attached Form No. 8 of the Enforcement Rules of the Personal Information Protection Act, and upon receipt the Firm shall promptly take measures such as registering the withdrawal of consent and destroying the personal information, and shall then notify the customer accordingly.
However, personal information for which consent has been withdrawn or which has been destroyed at the request of the user or a legal guardian is handled by the Firm as set out in the "Retention and Use Period of Personal Information," and is processed so that it cannot be accessed or used for any other purpose.
6. Installation, Operation and Refusal of Automatic Personal Information Collection Devices
The Firm operates "cookies," which store and retrieve customer information from time to time. A cookie is a very small text file sent to the user's computer browser by the server used to operate the Firm's website, and it may also be stored on the user's computer hard disk.
1) Purpose of use of cookies, etc.
Cookies may be used to analyze the access frequency and visit times of Members and non-members, to identify users' preferences and areas of interest and track their activity, and to determine the degree of participation in various events and the number of visits, for the purposes of targeted marketing and the provision of personalized services, etc.
2) Installation, operation and refusal of cookies
Members have the right to choose whether cookies are installed. Accordingly, by setting the options in their web browser, Members may allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. However, if a Member refuses the installation of cookies, there may be difficulties in the provision of services. ☞ How to set: Tools at the top of the web browser → Internet Options → Privacy
7. Complaint Services Regarding Personal Information
The Firm has designated a Chief Privacy Officer as set out below, who takes overall responsibility for the handling of personal information and for the handling of complaints and the remedying of damages of data subjects in connection with the processing of personal information.
1) Chief Privacy Officer
- Company name: Job of Brothers
- Name: Go Beop
- Telephone: 010 - 6270 - 1143
2) Handling of complaints
All inquiries, complaints, requests for remedy of damages and other matters relating to personal information protection arising in the course of using the Firm's services (or business) may be directed to the Chief Privacy Officer and the department in charge, and the Firm will respond to and handle customer inquiries without delay.
3) Other reporting or consultation centers
- Personal Information Dispute Mediation Committee (www.1336.or.kr ☏ 1336)
- ePRIVACY Mark Certification Committee (www.eprivacy.or.kr ☏ 02-580-0533~4)
- Supreme Prosecutors' Office Internet Crime Investigation Center (http://icic.sppo.go.kr ☏ 02-3480-3600)
- National Police Agency Cyber Bureau (www.ctrc.go.kr ☏ 02-392-0330)
8. Measures to Ensure the Security of Personal Information
In accordance with Article 29 of the Personal Information Protection Act, the Firm takes the following technical, administrative and physical measures necessary to ensure security.
1) Minimization of and training for staff handling personal information
The Firm designates the staff who handle personal information, limits such duties to the persons in charge, and minimizes the number of managing staff in administering personal information.
2) Establishment and implementation of an internal management plan
The Firm has established and implements an internal management plan for the secure processing of personal information.
3) Special audits: To ensure security in connection with the handling of personal information, the Firm conducts regular (once a month) internal special audits.
4) Encryption of personal information
Users' personal information and passwords are stored and managed in encrypted form so that they are known only to the user, and important data is protected by separate security functions such as encryption of files and transmitted data or the use of file locking functions.
5) Technical measures against hacking, etc.
To prevent the leakage or damage of personal information by hacking, computer viruses or the like, the Firm installs security programs, performs periodic updates and inspections, installs its systems in areas to which external access is controlled, and monitors and blocks access by technical and physical means.
6) Restriction of access to personal information
The Firm takes the measures necessary to control access to personal information through the granting, modification and revocation of access rights to the database system that processes personal information, and controls unauthorized access from outside using an intrusion prevention system.
7) Retention of access records and prevention of forgery and alteration
The Firm retains and manages records of access to the personal information processing system for a minimum of 6 months, and uses security functions to prevent such access records from being forged, altered, stolen or lost.
8) Use of locking devices for document security
Documents and auxiliary storage media containing personal information are kept in a secure place equipped with a locking device.
9) Access control for unauthorized persons
The Firm maintains a separate physical storage location for personal information and has established and operates access control procedures for that location.