Everspin Co., Ltd. (hereinafter referred to as the 'Company') establishes and discloses the following privacy policy in accordance with Article 30 of the 「Personal Information Protection Act」 to protect the personal information of the subjects and to handle related grievances quickly and smoothly. This privacy policy is effective from April 30, 2022.
Article 1 (Purpose of Processing Personal Information)
The company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than the following, and if the purpose of use changes, necessary measures such as obtaining separate consent will be implemented in accordance with Article 18 of the 「Personal Information Protection Act」.
Member Registration and Management
Personal information is processed for the purpose of confirming the intention to join, identifying and authenticating individuals according to the provision of membership services, maintaining and managing membership qualifications, preventing unauthorized use of services, and various notices and notifications.
Handling Civil Affairs
Personal information is processed for the purpose of identifying the identity of the complainant, confirming the complaint, contacting and notifying for investigation, and notifying the results of the processing.
Provision of Goods or Services
Personal information is processed for the purpose of providing services, sending contracts and invoices, providing content, providing customized services, identity verification, age verification, and fee payment and settlement.
Utilization in Marketing and Advertising
Personal information is processed for the purpose of developing new services (products) and providing customized services, providing events and promotional information and opportunities to participate, identifying the effectiveness of services, and identifying access frequency or statistics on members' service use.
[Appendix <1> Selection of Lawful Processing of Personal Information according to GDPR application]
Article 2 (Processing and Retention Period of Personal Information)
The company processes and retains personal information within the period of retention and use of personal information in accordance with laws or the period of retention and use of personal information agreed upon when collecting personal information from the information subject.
The personal information processing and retention period is held and used for the purposes of Article 1 (Purpose of Processing Personal Information) for up to 3 years from the date of consent for collection and use.
Related Laws:
Records on the collection/processing and use of credit information: 3 years
Records on consumer complaints or dispute handling: 3 years
Records on payment and supply of goods: 5 years
Records on contracts or withdrawal of subscription: 5 years
Records on labeling/advertising: 6 months
Article 3 (Provision of Personal Information to Third Parties)
The company processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the 「Personal Information Protection Act」, such as the consent of the information subject or special provisions of the law.
Article 4 (Entrustment of Personal Information Processing)
The company processes the information subject's personal information only within the scope specified in the purpose of processing, and provides personal information to third parties only in cases falling under Articles 17 and 18 of the 「Personal Information Protection Act」, such as the consent of the information subject or special provisions of the law, and does not provide the subject's personal information to third parties otherwise.
If the content of the entrusted work or the trustee changes, we will disclose it through this privacy policy without delay.
Article 5 (Rights and Obligations of Information Subjects and Legal Representatives and How to Exercise Them)
Information subjects may exercise their rights, such as requesting access to, correction, deletion, or suspension of processing of personal information, against the company at any time.
The exercise of rights under Paragraph 1 can be made in writing, by e-mail, or by facsimile (FAX) in accordance with Article 41 (1) of the Enforcement Decree of the Personal Information Protection Act, and the company will take action without delay.
The exercise of rights under Paragraph 1 can be done through a legal representative of the information subject or an authorized person. In this case, a power of attorney must be submitted in accordance with the form of Attachment 11 of the “Notice on Personal Information Processing Methods (No. 2020-7)”.
Requests for access to and suspension of processing of personal information may be restricted under Article 35 (4) and Article 37 (2) of the Personal Information Protection Act.
Requests for correction and deletion of personal information cannot be made if the personal information is specified as a target for collection in other laws.
The company verifies whether the person who made the request for access, correction/deletion, or suspension of processing is the person themselves or a legitimate representative. [Appendix <2> Selection of 'User Rights' according to GDPR application]
Article 6 (Items of Personal Information to be Processed)
The company processes the following personal information items.
Required items: Email, mobile phone number, password, date of birth, name, service usage records, access logs, cookies, access IP information
Optional items: Company name
Article 7 (Destruction of Personal Information)
The company destroys personal information without delay when the personal information becomes unnecessary, such as the lapse of the retention period or the achievement of the processing purpose.
If the personal information must continue to be preserved in accordance with other laws despite the lapse of the retention period agreed upon by the information subject or the achievement of the processing purpose, the personal information is moved to a separate database (DB) or preserved in a different storage location.
The procedure and method of personal information destruction are as follows:
Destruction Procedure: The company selects the personal information for which the reason for destruction has occurred and destroys the personal information with the approval of the company's personal information protection officer.
Destruction Method:
Information in the form of electronic files is destroyed using a technical method that cannot reproduce the records.
Personal information printed on paper is destroyed by shredding with a shredder or by incineration.
Article 8 (Measures to Ensure the Safety of Personal Information)
Minimization and Training of Employees Handling Personal Information: We designate employees who handle personal information and implement measures to manage personal information by limiting it to the minimum number of personnel.
Establishment and Implementation of Internal Management Plan: We establish and implement an internal management plan for the safe processing of personal information.
Technical Measures against Hacking, etc.: To prevent the leakage and damage of personal information caused by hacking or computer viruses, the company installs security programs, performs periodic updates and inspections, and installs the system in an area where external access is controlled and monitors and blocks it technically and physically.
Restriction of Access to Personal Information: We are taking necessary measures to control access to personal information through granting, changing, and deleting access rights to the database system that processes personal information, and we use an intrusion blocking system to control unauthorized access from outside.
Article 9 (Matters Concerning the Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
The company uses 'cookies' to store and frequently retrieve usage information to provide individual customized services to users.
A cookie is a small amount of information that the server (http) used to operate the website sends to the user's computer browser and is stored on the hard disk of the user's PC computer.
A. Purpose of using cookies: It is used to provide optimized information to users by identifying the types of visits and use of each service and website visited by users, popular search terms, and whether secure access is available.
B. Installation, operation, and refusal of cookies: You can refuse to save cookies by setting options in the Tools > Internet Options > Privacy menu at the top of the web browser.
C. If you refuse to store cookies, you may experience difficulties in using customized services.
Article 10 (Others)
[Appendix <3> Selection of 'Overseas Transfer of Data']
[Appendix <4> Selection of 'Third-Party Sites and Services']
[Appendix <5> Selection of 'Information for California Residents']
Article 11 (Personal Information Protection Officer)
The company is overall responsible for the processing of personal information and has designated a personal information protection officer as follows to handle complaints and provide remedies for information subjects related to personal information processing.
Information subjects may inquire about all personal information protection-related inquiries, complaint handling, and damage relief that occurred while using the company's services (or business) to the personal information protection officer and the department in charge. Everspin will respond to and process information subjects' inquiries without delay.
Article 12 (Remedial Methods for Infringement of Rights)
Information subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency's Personal Information Infringement Report Center to receive remedies for personal information infringement. In addition, please contact the following institutions for other personal information infringement reports and consultations.
Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
Personal Information Infringement Report Center: (without area code) 118 (privacy.kisa.or.kr)
Supreme Prosecutors' Office: (without area code) 1301 (www.spo.go.kr)
National Police Agency: (without area code) 182 (ecrm.cyber.go.kr)
Any person whose rights or interests have been infringed by a disposition or omission made by the head of a public institution in response to a request under the provisions of Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), and Article 37 (Suspension of Processing of Personal Information, etc.) of the 「Personal Information Protection Act」 may file an administrative appeal as prescribed by the Administrative Appeals Act. ※ For details on administrative appeals, please refer to the website of the Central Administrative Appeals Commission (www.simpan.go.kr).
Article 13 (Personal Information Processing Policy Change)
This privacy policy is effective from April 30, 2022.
You can check the previous privacy policy below. Example) - Applicable from 20XX. X. X ~ 20XX. X. X (Click)
Appendix to Privacy Policy
Lawful Processing of Personal Information according to GDPR application
The company lawfully processes the user's personal information only in any of the following cases.
When the user has consented to the processing of their personal information
When processing is necessary for the performance of a contract to which the user is a party or to take measures at the user's request prior to entering into a contract
Member management, identity verification, etc.
Performance of contracts for providing services requested by users, fee payment and fee settlement, etc.
When processing is necessary for compliance with a legal obligation to which the company is subject
Compliance with relevant laws, regulations, legal processes, and government requests
When processing is necessary to protect the vital interests of the user or another natural person
Detection, prevention, and response to fraud, abuse, security risks, and technical problems that may harm users or other natural persons
When processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the company
When processing is necessary for the purposes of the legitimate interests pursued by the company or by a third party (except where such interests are overridden by the interests or fundamental rights and freedoms of the user which require protection of personal information, in particular where the user is a child)
'User Rights' according to GDPR application
The user or legal representative may exercise the following rights as a subject of information in relation to the company's collection, use, and sharing of personal information.
Right of Access to Personal Information: The user or legal representative may access information and request confirmation of records on the collection, use, and sharing of information in accordance with relevant laws.
Right to Rectification of Personal Information: The user or legal representative may request correction of inaccurate or incomplete information.
Right to Erasure of Personal Information: The user or legal representative may request the deletion of information upon achievement of purpose, withdrawal of consent, etc.
Right to Restrict Processing of Personal Information: The user or legal representative may request a restriction on information processing if there is a dispute over the accuracy of information, the lawfulness of information processing, or if preservation of information is necessary.
Right to Data Portability: The user or legal representative may request the provision or transfer of information.
Right to Object: The user or legal representative may request the cessation of information processing for direct marketing, information processing based on legitimate interests or the exercise of public tasks and official authority, and information processing for research and statistical purposes.
Right to Object to Automated Individual Decision-Making, including Profiling: The user or legal representative may request the cessation of automated information processing, including profiling, that has a legal effect on them or significantly affects them. For this purpose, please use the 'Edit Member Information' menu on the webpage, or contact the company (or the personal information management officer, agent) by letter, phone, or e-mail, and we will take action without delay. However, the company may refuse such requests only if there are valid reasons specified in the law or equivalent reasons.
Overseas Transfer of Data
As the company operates worldwide, it may provide users' personal information to companies located in other countries or other companies for the purposes specified in this privacy policy. The company takes reasonable measures to protect personal information where it is transmitted, held, or processed. In addition, when using or disclosing personal information obtained from the European Union or Switzerland, the company complies with the US-EU Privacy Shield agreement and the Swiss-US Privacy Shield agreement, uses standard contractual clauses approved by the European Union executive agency, or seeks other measures within the European Union regulations to ensure appropriate safeguards or seeks the user's consent.
Third-Party Sites and Services
The company's websites, products, and services may include links to third-party websites, products, and services.
The privacy policy of linked third-party sites may differ from the company's policy. Therefore, users must additionally review the privacy policies of the linked third-party sites.
Information for California Residents
If you are a resident of California, specific rights may be added. The company prepares necessary precautions to protect members' personal information in order to comply with the California Online Privacy Protection Act.
Users can request confirmation of information leakage if personal information is leaked. In addition, all users of the company website can change their information at any time by accessing their personal account and using the information correction menu.
Furthermore, the company does not track website visitors. We also do not use 'Do Not Track' signals. The company does not collect personally identifiable information through advertising services and provide it to other companies without the user's consent.