Privacy Policy
2014-02-07
This English translation is provided for reference only. In case of any discrepancy, the Korean version shall prevail.
Article 1 (General Provisions)
A. Team42 (hereinafter the “Company”) places great importance on the personal information of its customers and complies with the personal information protection provisions of the relevant laws and the Personal Information Protection Guidelines of the Korea Communications Commission.
B. Through this Privacy Policy, the Company informs customers of the purposes for which and the manner in which their personal information is used, and of the measures taken to protect personal information.
C. The Company makes this Privacy Policy publicly available on its service screens or website so that customers can easily view and check it at any time.
D. The Company may amend this Privacy Policy in accordance with changes to the relevant laws and regulations, the Personal Information Protection Guidelines of the Korea Communications Commission, or its internal operating rules, and when amending the Privacy Policy, the Company assigns a version number or the like so that customers can easily identify the amended provisions.
Article 2 (Items of Personal Information Collected and Methods of Collection)
A. When collecting customers’ personal information, the Company notifies customers in advance of the scope of collection and the purposes of collection and use through the membership application form, the Terms of Service, or similar means, in accordance with the relevant laws and regulations.
B. The personal information of customers collected by the Company is as follows.
1. Personal information collected when using the services
Gender, phone number, date of birth, Facebook unique ID, Google account unique ID, email address, service usage history, registration information such as profile, smartphone information, statistical data, service settings information, access logs, etc.
2. Personal information collected in connection with the use of paid services (restoration, refunds, etc.)
Email address, purchase history details (date of purchase, order number, order details, etc.), and real name and certificate of family relations for verifying payments made by a person other than the user
C. The Company collects personal information by the following methods.
- Membership registration through in-service input, written forms, telephone, or fax, the consultation board, entries for prize events, delivery requests, tools for collecting generated information, etc.
D. The Company does not collect personal information that is likely to clearly infringe upon the rights, interests, or privacy of customers, such as ideology, beliefs, or past medical history, except as required by law or with the customer’s consent.
Article 3 (Purposes of Collection and Use of Personal Information)
The purposes for which the Company collects and uses customers’ personal information are as follows.
A. Performance of contracts for the provision of services and settlement of charges for the provision of paid services
Provision of content, billing for the use of paid services, and identity verification
B. User management
Personal identification, prevention of fraudulent use by delinquent members and of unauthorized use, verification of duplicate registration, confirmation of intent to register, retention of records for dispute resolution, handling of complaints and other civil petitions, and delivery of notices
C. Use for marketing and advertising
Development of new services and provision of customized services, provision of services and display of advertisements based on statistical characteristics, verification of service effectiveness, identification of access frequency, statistics on members’ use of the services, and provision of event and promotional information and opportunities to participate
Article 4 (Use and Provision of Personal Information)
A. The Company uses and provides customers’ personal information within the scope notified in the Terms of Service and in the “Purposes of Collection and Use of Personal Information” section of the Privacy Policy, and does not use or provide it beyond that scope. In particular, the Company will exercise care in using and providing personal information in the following cases.
1. Within the services, your profile information and the ratings of members of the opposite sex that you select are shared with other members.
2. Where the Company’s rights and obligations as a service provider are fully succeeded to or transferred as a result of a sale, merger, acquisition, or the like, the Company will notify customers in detail and in advance of the fact that personal information is to be transferred; the name (or, in the case of a corporation, the corporate name), address, telephone number, and other contact information of the person receiving the transfer of personal information (hereinafter the “Business Transferee, etc.”); and the methods and procedures by which customers may withdraw their consent if they do not wish their personal information to be transferred, and will give customers the option to withdraw their consent with respect to their personal information.
B. Where the customer has given consent, or, even without the customer’s consent, where necessary for the settlement of charges, or where there are special provisions in the relevant laws and regulations, such as the Framework Act on National Taxes, the Local Tax Act, the Protection of Communications Secrets Act, the Act on Real Name Financial Transactions and Confidentiality, the Credit Information Use and Protection Act, the Framework Act on Telecommunications, the Telecommunications Business Act, the Framework Act on Consumers, the Bank of Korea Act, and the Criminal Procedure Act, the Company may, notwithstanding the provisions of Paragraph (1), use customers’ personal information beyond the scope notified to customers at the time of collection or the scope specified in the Terms of Service, or provide it to third parties. However, even in cases under the relevant laws and regulations, the Company does not provide customers’ personal information unconditionally, but provides it in accordance with the procedures and methods prescribed by law.
C. With respect to personal information necessary for performing a contract for the provision of services, where it is clearly difficult to obtain ordinary consent for economic or technical reasons, the Company may collect and use personal information without the customer’s consent.
Article 5 (Period of Retention and Use of Collected Personal Information)
A. The Company retains users’ personal information for as long as users use the services provided by the Company.
B. Users’ personal information is destroyed once the purposes for which it was collected or provided have been achieved. Where a user withdraws membership or has their member ID deleted due to false entry of personal information, the collected personal information is deleted and processed so that it cannot be used for any purpose. However, since there is a risk of damage such as identity theft after termination of use, personal information is temporarily retained for 7 days. After 7 days, it is completely deleted from the member database.
C. In addition, copies of identification documents submitted for identity verification in the event of a dispute over identity theft are destroyed immediately after the identity has been verified.
D. Users’ personal information is destroyed without delay once the purposes of its collection and use have been achieved; however, the following information is preserved for the periods specified below for the reasons stated, and is not used for any other purpose.
1. In the case of users who have caused trouble in the services through improper use of the services, the relevant personal information may be retained for one year for the purpose of requesting an investigation by judicial authorities or protecting other users
2. Users’ personal information may be retained for certain periods prescribed by the Act on the Consumer Protection in Electronic Commerce, etc., the Protection of Communications Secrets Act, the Act on Promotion of Information and Communications Network Utilization, and other relevant laws and regulations.
a. Records of contracts or withdrawal of subscriptions, etc.: 5 years
b. Records of payments and supply of goods: 5 years
c. Records of consumer complaints or dispute resolution: 3 years
d. Records of labeling and advertising: 6 months
e. Access logs and service usage records: 3 months
f. Records of identity verification: 6 months
Article 6 (Destruction of Personal Information)
A. When the purposes of collection and use of the collected personal information have been achieved or the period of retention and use has expired, the Company destroys the information without delay, except where retention is required under the customer’s consent, the Terms of Service, or the relevant laws and regulations.
B. Personal information recorded on paper is shredded with a shredder or incinerated, and personal information stored electronically is deleted using technical methods that make it impossible to reproduce the records.
Article 7 (Rights of Customers and Methods of Exercising Them)
A. Customers may at any time view or correct the personal information held by the Company, the history of use and provision of their personal information, and the history of their consent to collection, use, and provision. Where it is recognized that correction or deletion is necessary, such as where the relevant personal information contains errors or is found to have exceeded its retention period, the Company will correct it without delay.
B. Customers who wish to view or correct their online registration information may do so through an online inquiry to the cyber customer center or by contacting the webmaster by email, and the Company will take the necessary measures without delay.
C. Where an agent visits and requests certification of access, the Company verifies precisely whether the person is a legitimate agent by requiring the submission of a power of attorney confirming that lawful delegation has been received, the principal’s certificate of seal impression, the agent’s identification, and the like.
D. Where a customer has requested the correction of errors in their personal information, the Company will not use or provide the personal information until the correction has been completed.
E. Where incorrect personal information has already been provided to a third party, the Company will notify the third party of the result of the correction without delay so that the correction is made.
F. Customers must enter their personal information accurately and keep it up to date, and must notify the Company of any changes. Customers are responsible for any consequences arising from inaccurate information they have entered themselves or from changes in customer information of which the Company is unaware because the customer failed to notify the Company.
G. Where a customer misappropriates or infringes upon another person’s information or enters false information, the customer’s service may be terminated and membership may be forfeited, and the customer may be punished under the relevant laws and regulations.
H. Where a customer’s requests are likely to interfere with the Company’s business, such as repeated requests to view or provide personal information, or where the volume of the request is so substantial that costs are incurred, the Company may postpone or refuse the customer’s request or charge the customer the actual costs incurred in processing it (such as copying costs).
Article 8 (Rights of Customers and Methods of Exercising Them)
In order to provide individual users with personalized and customized services, the Company uses ‘cookies,’ which store users’ information and retrieve it from time to time.
1. Purposes of using cookies
Provision of targeted marketing and personalized services by analyzing the access frequency and visit times of members and non-members, identifying users’ preferences and areas of interest, tracking their traces, and determining the degree of participation in various events and the number of visits
2. How to refuse cookie settings
Users may refuse the installation of cookies. However, if users refuse the installation of cookies, it may be difficult to use some services that require login.
(How to configure, based on IE) At the top of the web browser, Tools > Internet Options > Privacy > Sites (block)
Article 9 (Withdrawal of Consent to the Collection, Use, and Provision of Personal Information)
A. Customers may at any time withdraw the consent they have given to the collection, use, and provision of their personal information. This may be done by contacting the personal information management officer or the person in charge in writing, by telephone, by email, or by other means, and the Company will take the necessary measures, such as deleting the personal information, without delay.
B, Where the Company has taken measures such as destroying personal information as a result of a customer’s withdrawal of consent, the Company will notify the customer of that fact at the customer’s request.
Article 10 (Technical/Administrative Measures to Protect Personal Information)
A. Technical measures: In handling personal information, the Company takes the following technical measures to ensure its security so that personal information is not lost, stolen, leaked, altered, or damaged.
1. The Company takes measures to prevent the forgery or alteration of access records.
2. Depending on its type, personal information is managed by storing it with encryption at the level required by the relevant laws and regulations or by applying encryption technology during transmission.
3. The Company takes measures to prevent damage caused by computer viruses by using antivirus programs, and prevents the infringement of personal information by updating the antivirus programs regularly and applying a vaccine as soon as it becomes available when a new virus suddenly appears.
4. The Company has adopted security devices that use encryption algorithms to transmit personal information securely over networks.
5. To guard against hacking and other external intrusions, the Company does its utmost to maintain security by using intrusion prevention systems and vulnerability analysis systems for each server.
B. Administrative measures
1. The Company has established and implements an internal management plan for the protection of personal information.
2. The Company restricts access rights to personal information to the minimum number of personnel necessary.
3. The Company provides regular in-house training and outsourced external training for employees who handle personal information on topics such as acquiring new security technologies and obligations to protect personal information.
4. The Company prevents human-caused information leaks in advance by having employees sign a security pledge upon joining the Company, and has established internal procedures to audit the implementation of the Privacy Policy and employees’ compliance with it.
5. The Company ensures that the handover of duties by personal information handlers is carried out thoroughly while security is maintained, and clearly establishes responsibility for personal information incidents after joining and leaving the Company.
6. Personal information and general data are not stored together but are stored separately.
7. Computer rooms, data storage rooms, and the like are designated as special protected areas, and access to them is controlled.
8. The Company is not responsible for incidents caused by customers’ mistakes or by the inherent risks of the Internet. Customers must properly manage their own IDs and passwords and take responsibility for protecting their own personal information.
9. Where the theft, leakage, alteration, or damage of personal information is caused by a mistake of an internal administrator or an accident in technical management, the Company will take appropriate measures and provide compensation.
Article 11 (Personal Information Management Officer and Consultations/Reports)
A. The Company has designated a personal information management officer to protect customers’ personal information and to handle complaints related to personal information. If you have any inquiries regarding your personal information, please contact the personal information management officer or the person in charge of personal information management below.
[Personal Information Management Officer / Person in Charge]
Name: Sungsoo Na
Contact: 02-6338-7651
Email: team42kr@naver.com
B. If you need other consultation regarding personal information, you may contact the following organizations.
– Personal Information Infringement Report Center: Tel. 118 / Email 118@kisa.or.kr / Website http://www.118.or.kr
– Privacy Mark Certification Committee: Tel. 02-580-0533 / Website http://www.privacymark.or.kr
– Internet Crime Investigation Center, Supreme Prosecutors’ Office: Tel. 02-3480-3600 / Website http://icic.sppo.go.kr
– Cyber Terror Response Center, Korean National Police Agency: Tel. 02-392-0330 / Website http://www.police.go.kr
Addenda
Article 1 Effective Date
This Privacy Policy shall take effect on February 7, 2014.