Privacy Policy
2022-11-29
This English translation is provided for reference only. In case of any discrepancy, the Korean version shall prevail.
‘Team42’ (hereinafter the “Company”) places great importance on the personal information of its customers and complies with the “Act on Promotion of Information and Communications Network Utilization and Information Protection,” the “Personal Information Protection Act,” the “Act on the Protection, Use, etc. of Location Information,” and other relevant laws and regulations.
Through this Privacy Policy, the Company informs customers of the purposes for which and the manner in which their personal information is used, and of the measures taken to protect personal information.
The Company makes this Privacy Policy publicly available on its service screens or website so that customers can easily view and check it at any time.
1. Items of Personal Information Collected and Methods of Collection
A. When collecting customers’ personal information, the Company notifies customers in advance of the scope of collection and the purposes of collection and use through the membership application form, the Terms of Service, or similar means, in accordance with the relevant laws and regulations.
B. The personal information of customers collected by the Company is as follows.
1) Personal information collected when using the services
Gender, connecting information (CI), phone number, date of birth, Facebook unique ID, Google account unique ID, service usage history, smartphone information, statistical data, service settings information, and access logs.
When the 1:1 inquiry feature on the website is used, cookies and IP addresses are automatically collected and may be used for purposes such as statistical analysis of service usage.
2) Personal information collected in connection with the use of paid services (restoration, refunds, etc.)
Email address, purchase history details (date of purchase, order number, order details, etc.), and real name and certificate of family relations for verifying payments made by a person other than the user
C. The Company collects personal information by the following methods.
- Membership registration through in-service input, the 1:1 inquiry board on the website, entries for prize events, delivery requests, tools for collecting generated information, etc.
D. The Company does not collect personal information that is likely to clearly infringe upon the rights, interests, or privacy of customers, such as ideology, beliefs, or past medical history, except as required by law or with the customer’s consent.
2. Purposes of Collection and Use of Personal Information
The purposes for which the Company collects and uses customers’ personal information are as follows.
A. Performance of contracts for the provision of services and settlement of charges for the provision of paid services
Provision of content, billing for the use of paid services, and identity verification
B. User management
Personal identification, prevention of fraudulent use by delinquent members and of unauthorized use, verification of duplicate registration, confirmation of intent to register, retention of records for dispute resolution, handling of complaints and other civil petitions, and delivery of notices
C. Use for marketing and advertising
Development of new services and provision of customized services, provision of services and display of advertisements based on statistical characteristics, verification of service effectiveness, identification of access frequency, statistics on members’ use of the services, and provision of event and promotional information and opportunities to participate
3. Use, Provision, and Entrustment of Personal Information
A. The Company uses and provides customers’ personal information within the scope notified in the Terms of Service and in the “Purposes of Collection and Use of Personal Information” section of the Privacy Policy, and does not use or provide it beyond that scope. However, the following cases are exceptions. Where necessary for the settlement of charges, or where there are special provisions in the relevant laws and regulations, such as the Framework Act on National Taxes, the Local Tax Act, the Protection of Communications Secrets Act, the Act on Real Name Financial Transactions and Confidentiality, the Credit Information Use and Protection Act, the Framework Act on Telecommunications, the Telecommunications Business Act, the Framework Act on Consumers, the Bank of Korea Act, and the Criminal Procedure Act, the Company may use customers’ personal information beyond the scope notified to customers at the time of collection or the scope specified in the Terms of Service, or provide it to third parties. However, even in cases under the relevant laws and regulations, the Company does not provide customers’ personal information unconditionally, but provides it in accordance with the procedures and methods prescribed by law
B. With respect to personal information necessary for performing a contract for the provision of services, where it is clearly difficult to obtain ordinary consent for economic or technical reasons, the Company may collect and use personal information without the customer’s consent.
C. Entrustment of personal information processing
For the provision of services and the performance of its business, the Company entrusts personal information processing tasks to external specialized service providers, and, in accordance with the relevant laws and regulations, stipulates in the entrustment contracts the matters necessary to ensure that personal information is managed securely.
The Company’s entrusted personal information processors, the details of the entrusted tasks, and the periods of retention and use of personal information are as follows.
Trustee: Amazon Web Services, Inc.
Purpose of transfer: Provision of cloud services
Items transferred: Information processed through the app, which can be found in Section ‘1. Items of Personal Information Collected and Methods of Collection’ of this Policy.
Country of transfer: Stored in the AWS Korea, Global, and Arab regions, and transmitted over the network at the time the services are used.
Contact of the person in charge of information management: aws-korea-privacy@amazon.com
Period of retention and use of transferred items: Until the termination of the entrustment contract, or otherwise in accordance with the retention periods prescribed by law.
4. Period of Retention and Use of Personal Information
A. The Company retains users’ personal information for as long as users use the services provided by the Company. With respect to personal information collected with a member’s consent, the Company may retain and use the member’s personal information for as long as the membership is maintained, and when a member requests withdrawal, the information is completely deleted so that it can no longer be viewed or used. However, in order to restore damage and protect victims in the event of damage caused by identity theft or the like, the Company may retain member information for the period determined by each individual service, up to a maximum of 30 days from the date of withdrawal, after which it is completely deleted. In addition, exceptions are made where individual consent has been obtained from the member or where retention is required under relevant laws and regulations, such as the Commercial Act and the Act on the Consumer Protection in Electronic Commerce, etc.
B. In accordance with the 「Act on Promotion of Information and Communications Network Utilization and Information Protection」 and its Enforcement Decree, the Company deletes the personal information of members who have not used the services for one consecutive year (hereinafter “dormant accounts”) in order to protect their personal information. However, permanently suspended users are excluded.
C. Where the Company is required to preserve customers’ personal information under the provisions of relevant laws and regulations, the Company retains the information for the period prescribed by those laws and regulations. (However, records of service use restrictions are retained for the duration of the service.)
D. Users’ personal information is destroyed without delay once the purposes of its collection and use have been achieved; however, the following information is preserved for the periods specified below for the reasons stated, and is not used for any other purpose.
1) In the case of users who have caused trouble in the services through improper use of the services, the relevant personal information may be retained for one year for the purpose of requesting an investigation by judicial authorities or protecting other users
2) Users’ personal information may be retained for certain periods prescribed by the Act on the Consumer Protection in Electronic Commerce, etc., the Protection of Communications Secrets Act, the Act on Promotion of Information and Communications Network Utilization, and other relevant laws and regulations.
Records of contracts or withdrawal of subscriptions, etc.
Reason for retention: Act on the Consumer Protection in Electronic Commerce, etc.
Retention period: 5 years
Records of payments and supply of goods
Reason for retention: Act on the Consumer Protection in Electronic Commerce, etc.
Retention period: 5 years
Records of consumer complaints or dispute resolution
Reason for retention: Act on the Consumer Protection in Electronic Commerce, etc.
Retention period: 3 years
Records of identity verification
Reason for retention: Act on Promotion of Information and Communications Network Utilization and Information Protection
Retention period: 6 months
Records of service visits
Reason for retention: Protection of Communications Secrets Act
Retention period: 3 months
5. Procedures and Methods for Destruction of Personal Information
A. When the purposes of collection and use of the collected personal information have been achieved or the period of retention and use has expired, the Company destroys the information without delay, except where retention is required under the customer’s consent, the Terms of Service, or the relevant laws and regulations.
B. Personal information recorded on paper is shredded with a shredder or incinerated, and personal information stored electronically is deleted using technical methods that make it impossible to reproduce the records.
6. Rights of Users and Legal Representatives and Methods of Exercising Them
1) Users and legal representatives may at any time exercise the rights prescribed by law, such as requesting access, correction, restriction of processing, and withdrawal of consent, with respect to the registered personal information of the user or of the relevant child under the age of 14.
2) The rights under Paragraph 1 may be exercised by contacting the Company in writing, by telephone, by email, or by other means, and the Company will take the necessary measures without delay upon the user’s request.
3) Where a user has requested the correction or deletion of errors in their personal information, the Company will not use the relevant personal information or provide it to third parties until the correction or deletion has been completed.
4) The rights under Paragraph 1 may be exercised through an agent, such as the user’s legal representative or a person delegated by the user. In this case, a power of attorney in the form of Annex Form No. 11 of the Enforcement Rule of the Personal Information Protection Act must be submitted.
7. Installation and Operation of Devices That Automatically Collect Personal Information, and Refusal Thereof
The Company operates ‘cookies’ and similar technologies that store and retrieve users’ information from time to time. A cookie is a very small text file that the server used to operate the Company’s website sends to the user’s browser, and it is stored on the hard disk of the user’s computer. The Company uses cookies for the following purposes.
1) Purposes of using cookies, etc.
To provide personalized services by analyzing the access frequency and visit times of members and non-members, identifying users’ preferences and areas of interest, tracking their traces, and determining the number of visits.
2) How to refuse cookie settings
Users have the option to choose whether to allow the installation of cookies. Accordingly, by setting options in their web browser, users may allow all cookies, be prompted each time a cookie is stored, or refuse the storage of all cookies. However, if a member refuses to allow cookies to be stored, it may be difficult to provide some services
[How to configure cookie settings]
① Internet Explorer: At the top of the web browser, [Tools] → [Internet Options] → [Privacy] → [Advanced]
② Chrome: At the top right of the web browser, [⋮] → [Settings] → [Privacy and security] → [Cookies and other site data]
8. Technical, Administrative, and Physical Measures to Protect Personal Information
In processing members’ personal information, the Company takes the following technical and administrative measures to ensure its security so that personal information is not lost, stolen, leaked, altered, or damaged.
The Company does its utmost to prevent members’ personal information from being leaked or damaged by hacking, computer viruses, and the like. To prepare for damage to personal information, the Company backs up data regularly, uses up-to-date antivirus programs to prevent customers’ personal information or data from being leaked or damaged, and uses encryption algorithms and similar means so that personal information can be transmitted securely over networks. In addition, the Company controls unauthorized access from outside by using intrusion prevention systems, and endeavors to put in place every other possible technical means to ensure system security.
The Company constantly emphasizes compliance with the Privacy Policy. The Company also checks the implementation of the Privacy Policy and compliance by the persons in charge, and endeavors to correct and rectify any problems immediately when they are found. However, the Company shall not be liable in any way for problems arising from the leakage of personal information due to the member’s own negligence or problems on the Internet.
9. Personal Information Management Officer and Civil Petition Services
A. The Company has designated a personal information management officer to protect customers’ personal information and to handle complaints related to personal information. If you have any inquiries regarding your personal information, please contact the personal information management officer or the person in charge of personal information management below.
[Personal Information Management Officer / Person in Charge]
Name: Sungsoo Na
Contact: 02-6371-4200
Email: support@mafia42.co.kr
B. If you need other consultation regarding personal information, you may contact the following organizations.
-
Personal Information Infringement Report Center (privacy.kisa.or.kr / ☎ 118 without area code)
-
Cyber Investigation Division, Supreme Prosecutors’ Office (spo.go.kr / ☎ 1301 without area code)
-
Cyber Bureau, Korean National Police Agency (cyberbureau.police.go.kr / ☎ 182 without area code)
-
Personal Information Dispute Mediation Committee (kopico.go.kr / ☎ 1833-6972 without area code)
Date of Announcement: November 24, 2022
Effective Date: November 29, 2022