Host Center Co., Ltd. (hereinafter referred to as "Host Center" or the "Company") strictly complies with domestic laws and regulations concerning the protection of personal information, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. (hereinafter the "Information and Communications Network Act") and the Personal Information Protection Act. This Privacy Policy covers the following matters.
- Purposes of collection and use of personal information
- Items of personal information collected and collection methods
- Retention and use period of collected personal information
- Procedures and methods for destruction of personal information
- Provision and sharing of personal information
- Companies entrusted with personal information processing
- Installation, operation, and refusal of automatic personal information collection devices
- Technical and administrative measures for protecting personal information
- Rights of users and legal guardians and how to exercise them
- Personal Information Protection Officer, consultation, and reporting
Article 1 (Purposes of Collection and Use of Personal Information)
The Company uses the personal information it collects for the following purposes.
1. Performance of contracts for service provision and settlement of fees for services provided
- Content provision, delivery of goods or invoices, identity verification fee payment, fee collection
2. Membership management
- Identity verification and personal identification for use of membership services, prevention of fraudulent and unauthorized use by delinquent members, confirmation of intent to join, restriction on membership registration and number of registrations, identity verification of the legal guardian of members under age 14 who joined before this policy was amended, record retention for dispute resolution, handling of complaints and civil petitions, and delivery of notices
3. Use for marketing and advertising
- Delivery of advertising information such as event notices
Article 2 (Items of Personal Information Collected and Collection Methods)
The Company collects the following personal information for membership registration, consultation, and service applications.
1. [Items of Personal Information Collected]
- Required items: Name, login ID, password, mobile phone number, email, company name, company phone number, service usage records, access logs, access IP information, payment records, business registration number
- Voluntarily provided information (for service convenience): Address, fax number, phone number, English name/English address
- Information generated during service use/event participation: Real name, real-name verification value, gender, date of birth, occupation, company name, address, phone number, fax number, English name/English address, payment method information such as bank/credit card details, service usage records, access logs, cookies, access IP information, payment records, records of improper use, user status information, and date and time of visits
2. [Collection Methods]
- Membership registration via the website, consultation board, and written forms
- Collection when required information is needed for service use, or through voluntary provision by users
Article 3 (Retention and Use Period of Collected Personal Information)
In principle, personal information is destroyed without delay once its retention period has elapsed or the purpose of its collection and use has been achieved. However, the following information is retained for the periods specified below, for the reasons stated.
1. Personal information retained upon membership withdrawal
- Retained items: Name, business registration number, ID, email address, mobile phone number, etc. provided by the member
- Basis for retention: Prevention of re-registration by delinquent users, handling of disputes over rights infringement such as defamation, and cooperation with investigations
- Retention period: 1 year after membership withdrawal
2. Retention under relevant laws (Commercial Act, Act on Consumer Protection in Electronic Commerce, etc.)
- Records concerning contracts or withdrawal of subscription: Act on Consumer Protection in Electronic Commerce, Etc. (Retention period: 5 years)
- Records concerning payment and supply of goods: Act on Consumer Protection in Electronic Commerce, Etc. (Retention period: 5 years)
- Records concerning consumer complaints or dispute handling: Act on Consumer Protection in Electronic Commerce, Etc. (Retention period: 3 years)
- Records concerning visits (service usage records, access logs, access IP information): Protection of Communications Secrets Act (Retention period: 3 months)
Article 4 (Procedures and Methods for Destruction of Personal Information)
- Destruction procedure: Information entered by a member for membership registration, etc. is transferred to a separate database (or, in the case of paper documents, a separate filing cabinet) once its purpose has been achieved, stored for a set period in accordance with internal policy and other applicable laws, and then destroyed. Personal information is not used for any purpose other than that for which it is held, except as required by law.
- Destruction method: Personal information printed on paper is destroyed by shredding or incineration, and personal information stored in electronic file form is deleted using technical methods that prevent the records from being recovered.
Article 5 (Provision and Sharing of Personal Information)
In principle, the Company uses members' personal information only within the scope of the purposes for which it was collected, and does not disclose it to third parties or other companies/organizations. However, the following are exceptions:
- Where the user has given prior consent (Before collecting or providing information, the Company informs the member who the business partner is, what information is required and why, and how long and in what manner it will be protected/managed, and obtains consent; if the user does not consent, the information is not collected or shared)
- Where required by statute, or where a law enforcement agency requests information for investigative purposes in accordance with procedures and methods prescribed by law
- Use and provision of personal information consistent with the purpose of collection
- Where a government agency requests domain name and name server information, etc. in order to carry out duties prescribed by law
- Where a member's information (name, address, phone number) is used for business-related contact
Article 6 (Outsourcing of Collected Personal Information)
In principle, the Company does not outsource the processing of personal information to a third party without the user's consent. Where the Company does outsource personal information processing, it does so in accordance with Article 26 of the Personal Information Protection Act, and publishes the details of the outsourced work and the recipient on the Company's website.
[Personal Information Outsourcing Companies and Outsourced Tasks]
| Outsourced Company | Outsourced Task |
|---|
| T-Pro | Automatic transfer payment service |
| Saehan Credit Information | Debt collection service |
| KG Allat, T&B Soft | Payment service (card, virtual account) |
| IT Stone Co., Ltd., Korea Corporate Security Co., Ltd., Ion Security, Kannaro Information & Communications Co., Ltd., K-sign Co., Ltd., iNet Hosting Co., Ltd., Hansol Nexzi | Server hosting value-added services |
Article 7 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
The Company does not operate devices, such as cookies, that automatically collect personal information generated during the use of internet services.
Article 8 (Technical and Administrative Measures for Protecting Personal Information)
The Company takes the following measures to ensure the security of personal information.
- [Establishment of an internal management plan] The Company has established and implements an internal management plan for the safe management of personal information.
- [Encryption of users' personal information] Information is transmitted through encrypted communication channels, and the Company does not collect a separate user ID and password for consultation requests.
- [Countermeasures against hacking, etc.] The Company maintains technical safeguards, including regular data backups, use of up-to-date antivirus software, encrypted communications, and an intrusion prevention system (firewall).
- [Minimization and training of personnel handling personal information] Access authority is granted only to designated personnel, passwords are updated periodically, and regular training is conducted.
- [Operation of a dedicated personal information protection organization] Compliance is verified through a dedicated in-house organization. (However, the Company is not liable for any leakage of personal information caused by the user's own negligence or problems on the Internet.)
Article 9 (Rights of Users and Legal Guardians and How to Exercise Them)
1. [Viewing, correcting, and withdrawing personal information]
Users may, at any time, view or correct their registered personal information, or request withdrawal of membership. (Viewing/correction: "Change Information" on the website; withdrawal: "Customer Center > Service Termination Request Form")
- Requests to view, correct, withdraw, or suspend processing of personal information are acted upon, and the user notified of the result, within 10 days.
- Department responsible for receiving and handling requests: Host Center Sales Team (Contact: Namgung Jeong-tae, Deputy General Manager / TEL: 070-8855-4257, FAX: 02-591-1115 / Address: Room 701, Gyeonggi Corporate Growth Center, Pangyo Techno Valley 2, 42 Changeop-ro, Sujeong-gu, Seongnam-si, Gyeonggi-do)
2. [Membership registration of children under 14]
Host Center does not accept membership registration from children under the age of 14.
3. [Withdrawal of transactions with minors]
Transactions with minors require the prior consent of a legal guardian (parent), and transactions concluded without such consent may be cancelled. If the legal guardian requests withdrawal within 7 days after the transaction is concluded, the transaction will be withdrawn (refunded).
Article 10 (Personal Information Protection Officer, Consultation, and Reporting)
Host Center designates a Personal Information Protection Officer and staff to handle inquiries and complaints from users regarding personal information.
[Personal Information Protection Officer and Staff]
| Category | Personal Information Protection Officer | Personal Information Management Staff |
|---|
| Department | Sales Team | Development Team |
| Name | Namgung Jeong-tae | Han Won-beom |
| Phone | 070-8855-4257 | 070-8855-4645 |
| Email | anaconda@hostcenter.co.kr | wonbum6841@hostcenter.co.kr |
[Other Agencies for Reporting and Consultation on Personal Information Infringement]
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118, no area code)
- Supreme Prosecutors' Office Cyber Investigation Division (www.spo.go.kr / 1301, no area code)
- National Police Agency (ecrm.police.go.kr / 182, no area code)