Privacy Policy
Plaif Inc. (hereinafter referred to as the “Company”) establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of Korea in order to protect the personal information of data subjects and to promptly and smoothly handle related complaints.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than those specified below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent from the data subject in accordance with Article 18 of the Personal Information Protection Act.
1. Membership Registration and Management
Personal information is processed for the following purposes:
Verification of intent to register as a member
Identification and authentication for providing membership services
Maintenance and management of membership status
Identity verification under the limited identity verification system
Prevention of fraudulent use of services
Verification of consent from legal representatives when processing personal information of children under the age of 14
Notification and communication of various announcements
Handling of customer inquiries and complaints
2. Provision of Goods or Services
Personal information is processed for the following purposes:
Delivery of goods
Provision of services
Sending contracts and invoices
Provision of content
Provision of customized services
Identity verification
Age verification
Payment processing and settlement
Collection of outstanding payments
3. Handling of Complaints
Personal information is processed for the following purposes:
Verification of complainant identity
Confirmation of complaint details
Communication and notification for fact-finding investigations
Notification of processing results
Article 2 (Processing and Retention Period of Personal Information)
① The Company processes and retains personal information within the period specified by applicable laws or within the retention period agreed upon when collecting personal information from the data subject.
② The processing and retention periods for each category of personal information are as follows:
1. Membership Registration and Management
Until the user withdraws membership from the website.
However, personal information may be retained until the relevant matter is resolved in the following cases:
When an investigation is ongoing due to a violation of relevant laws, until the investigation is completed
When outstanding claims or obligations remain due to website usage, until such claims and obligations are settled
2. Provision of Goods or Services
Until the completion of supply of goods/services and completion of payment and settlement.
However, personal information may be retained for the following periods according to applicable laws:
Records related to transactions under the Act on Consumer Protection in Electronic Commerce, Etc.
Records regarding advertisements: 6 months
Records regarding contracts, subscription withdrawals, payments, and supply of goods: 5 years
Records regarding consumer complaints and dispute resolution: 3 years
Records retained under Article 41 of the Protection of Communications Secrets Act
Telecommunications date, start/end time, subscriber number, usage frequency, and location tracking data of base stations: 1 year
Internet log records, access tracking data, and computer communications records: 3 months
Article 3 (Provision of Personal Information to Third Parties)
① The Company processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only when one of the following applies:
The consent of the data subject has been obtained
There are special provisions under applicable laws
Other cases permitted under Article 17 of the Personal Information Protection Act
② The Company provides personal information to third parties as follows:
Recipient of personal information:
Purpose of use by recipient:
Items of personal information provided:
Retention and usage period:
Article 4 (Entrustment of Personal Information Processing)
① The Company entrusts personal information processing tasks to external parties for efficient business operations as follows:
Trustee: Imweb Co., Ltd.
Scope of entrusted tasks:
Shopping mall hosting service system operation
Mobile app services
Marketing services
Additional and partnership services
Alimtalk, Friend Talk, and SMS message delivery services
Trustee: OOO Payment Gateway (PG)
Scope of entrusted tasks:
Payment processing and escrow services
Trustee: OOO Delivery Company
Scope of entrusted tasks:
Product delivery services
Trustee: OOO Customer Center
Scope of entrusted tasks:
Customer support services
Trustee: OOO
Scope of entrusted tasks:
Identity verification services
② When entering into outsourcing agreements, the Company specifies matters related to the prohibition of processing personal information beyond the entrusted purpose, technical and administrative protection measures, restrictions on subcontracting, supervision of trustees, and liability for damages in accordance with Article 25 of the Personal Information Protection Act. The Company supervises whether trustees safely process personal information.
③ If the scope of entrusted tasks or trustees change, the Company will disclose such changes through this Privacy Policy without delay.
Article 5 (Rights of Users and Legal Representatives and Methods of Exercise)
① Data subjects may exercise the following rights related to personal information protection at any time:
Request access to personal information
Request correction of inaccurate information
Request deletion of personal information
Request suspension of processing
② Requests under Paragraph 1 may be submitted to the Company through written documents, telephone, email, fax, or other methods, and the Company will take action without delay.
③ If a data subject requests correction or deletion of inaccurate personal information, the Company will not use or provide such information until the correction or deletion has been completed.
④ Rights under Paragraph 1 may be exercised through a legal representative or an authorized agent. In such cases, a power of attorney pursuant to the relevant enforcement regulations must be submitted.
⑤ Data subjects must not infringe upon the personal information or privacy of themselves or others by violating applicable laws while exercising their rights.
Article 6 (Items of Personal Information Processed)
The Company processes the following personal information:
1. Membership Registration and Management
Required information:
Name
Date of birth
ID
Password
Address
Phone number
Gender
Email address
I-PIN number
Optional information:
Marital status
Areas of interest
2. Provision of Goods or Services
Required information:
Name
Date of birth
ID
Password
Address
Phone number
Email address
I-PIN number
Credit card information
Bank account information
Payment-related information
Optional information:
Areas of interest
Previous purchase history
3. Information Automatically Collected During Internet Service Use
The following information may be automatically generated and collected:
IP address
Cookies
MAC address
Service usage records
Visit history
Records of improper use
Article 7 (Destruction of Personal Information)
① The Company destroys personal information without delay when it becomes unnecessary due to expiration of the retention period or achievement of the processing purpose.
② If personal information must be retained according to other laws despite expiration of the agreed retention period or achievement of the processing purpose, such information will be transferred to a separate database or stored separately.
③ The procedures and methods for destruction are as follows:
1. Destruction Procedure
The Company selects personal information subject to destruction and destroys it after approval from the person responsible for personal information protection.
2. Destruction Method
Electronic files are permanently deleted using methods such as low-level formatting so that recovery is impossible.
Paper documents are shredded or incinerated.
Article 8 (Measures to Ensure Security of Personal Information)
The Company takes the following measures to ensure the security of personal information:
Administrative measures:
Establishment and implementation of internal management plans
Regular employee training
Technical measures:
Management of access rights to personal information processing systems
Installation of access control systems
Encryption of unique identification information
Installation of security programs
Physical measures:
Access control for data centers and document storage facilities
Article 9 (Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)
① The Company uses cookies to provide customized services by storing and retrieving usage information.
② Cookies are small amounts of information sent by web servers to users’ browsers and may be stored on users’ hard drives.
a. Purpose of Using Cookies
Cookies are used to identify:
Website visit patterns
Usage behavior
Popular search terms
Secure connection status
in order to provide optimized services.
b. Cookie Installation and Rejection
Users may refuse cookie storage through browser settings:
Tools → Internet Options → Privacy Settings
c. Consequences of Rejecting Cookies
If cookie storage is rejected, some customized services may not function properly.
Article 10 (Personal Information Protection Officer)
① The Company appoints a personal information protection officer responsible for overall personal information processing and handling related complaints and remedies.
Personal Information Protection Officer
Name: OOO
Position: OOO
Contact:
Phone:
Email:
Fax:
Department Responsible for Personal Information Protection
Department: OOO Team
Person in charge: OOO
Contact:
Phone:
Email:
Fax:
② Data subjects may contact the Personal Information Protection Officer or relevant department regarding inquiries, complaints, and remedies related to personal information protection. The Company will respond and handle such matters without delay.
Article 11 (Requests for Access to Personal Information)
Data subjects may request access to their personal information pursuant to Article 35 of the Personal Information Protection Act through the department below.
The Company will make efforts to promptly process requests for access.
Department Handling Requests
Department: OOO
Person in charge: OOO
Contact:
Phone:
Email:
Fax:
Article 12 (Methods for Remedying Rights Violations)
Data subjects may contact the following organizations for consultation or remedies regarding personal information violations.
Personal Information Infringement Report Center
(Operated by Korea Internet & Security Agency)
Responsibilities:
Reporting personal information violations
Consultation services
Website: privacy.kisa.or.kr
Phone: 118
Address:
3rd Floor, Personal Information Infringement Report Center,
9 Jinheung-gil, Naju-si, Jeollanam-do, Republic of Korea
Personal Information Dispute Mediation Committee
Responsibilities:
Personal information dispute mediation
Collective dispute mediation
Website: www.kopico.go.kr
Phone: 1833-6972
Address:
4th Floor, Government Complex Seoul,
209 Sejong-daero, Jongno-gu, Seoul, Republic of Korea
Supreme Prosecutors’ Office Cyber Crime Investigation Division
Phone: 02-3480-3573
Website: www.spo.go.kr
Korean National Police Agency Cyber Bureau
Phone: 182
Website: cyberbureau.police.go.kr
Article 13 (Enforcement and Amendment of Privacy Policy)
This Privacy Policy shall take effect from 20XX. X. X.