Everspin Co., Ltd. (hereinafter referred to as the 'Company') establishes and discloses the following privacy policy in accordance with Article 30 of the 「Personal Information Protection Act」 to protect the personal information of the subjects and to handle related grievances quickly and smoothly.
1. Purpose of Processing Personal Information
The company processes personal information for the following purposes. The personal information being processed will not be used for purposes other than the following, and if the purpose of use changes, necessary measures such as obtaining separate consent will be implemented in accordance with Article 18 of the 「Personal Information Protection Act」.
Member Registration and Management
Personal information is processed for the purpose of confirming the intention to join, identifying and authenticating individuals according to the provision of membership services, maintaining and managing membership qualifications, preventing unauthorized use of services, and various notices and notifications.
Handling Civil Affairs
Personal information is processed for the purpose of identifying the identity of the complainant, confirming the complaint, contacting and notifying for investigation, and notifying the results of the processing.
Provision of Goods or Services
Personal information is processed for the purpose of providing services, sending contracts and invoices, providing content, providing customized services, identity verification, age verification, and fee payment and settlement.
Utilization in Marketing and Advertising
Personal information is processed for the purpose of developing new services (products) and providing customized services, providing events and promotional information and opportunities to participate, identifying the effectiveness of services, and identifying access frequency or statistics on members' service use. Matters concerning the provision of personal information to third parties.
2. Items of Personal Information to be Processed and Period of Retention and Use
The company processes the following personal information items with the consent of the information subject in accordance with Article 15 (1) 1 and Article 22 (1) 7 of the 「Personal Information Protection Act」.
Purpose of Collection
Items Collected
Retention and Usage Period
Confirmation of intention to join
Email, mobile phone number, password, date of birth, name
Upon withdrawal from membership
Identity identification and authentication for membership services
Email, mobile phone number, password, date of birth, name
Upon withdrawal from membership
Maintenance and management of membership, prevention of unauthorized service use
Email, service usage records, access logs, cookies, access IP information, company name
Upon withdrawal from membership
3. Matters Concerning the Procedure and Method of Destroying Personal Information
The company destroys personal information without delay when the personal information becomes unnecessary, such as the lapse of the personal information retention period or the achievement of the processing purpose.
If the personal information must continue to be preserved in accordance with other laws and regulations despite the lapse of the retention period consented to by the information subject or the achievement of the processing purpose, the personal information is moved to a separate database (DB) or preserved in a different storage location.
Cases and periods to be preserved by laws and regulations
Records on the collection/processing and use of credit information: 3 years
Records on consumer complaints or dispute handling: 3 years
Records on payment and supply of goods: 5 years
Records on contracts or withdrawal of subscription: 5 years
Records on labeling/advertising: 6 months
The procedure and method of destruction are as follows.
Destruction Procedure
The company selects the personal information for which the reason for destruction has occurred and destroys it with the approval of the personal information protection officer.
Destruction Method
The company destroys personal information recorded and stored in the form of electronic files using a method that cannot be restored, and personal information recorded and stored in paper documents is destroyed by shredding with a shredder or incineration.
4. Matters Concerning the Provision of Personal Information to Third Parties
The company processes the personal information of the subject only within the scope specified in the purpose of processing, and provides personal information to third parties only in cases falling under Articles 17 and 18 of the 「Personal Information Protection Act」, such as the consent of the information subject or special provisions of the law, and does not provide it otherwise.
5. Matters Concerning the Entrustment of Personal Information Processing
The company does not entrust the collected personal information.
If the company entrusts personal information for business processing in the future, it will specify matters such as the prohibition of processing for purposes other than the purpose of the entrusted work, technical and administrative protection measures, restrictions on re-entrustment, and supervision of the trustee in the contract in accordance with Article 26 of the 「Personal Information Protection Act」, and supervise the trustee.
6. Matters Concerning the Overseas Transfer of Personal Information
The company does not provide or entrust the collected personal information to foreign countries.
7. Matters Concerning Measures to Ensure the Safety of Personal Information
The company is taking the following technical and administrative measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged in processing user's personal information.
Technical Protective Measures for Personal Information
The company is taking technical measures such as intrusion detection systems and system monitoring to prepare for external intrusions like hacking.
Administrative Protective Measures for Personal Information
The company emphasizes compliance with the privacy policy through personal information protection training for the person in charge. In addition, an internal management plan is established and access authority is limited to a minimum number of personnel.
8. Matters Concerning the Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof
The company processes the following behavioral information items with the consent of the information subject in accordance with Article 15 (1) 1 and Article 22 (1) 7 of the 「Personal Information Protection Act」.
Behavioral information is collected and used for data analysis to propose optimized services and solutions to users.
The company uses 'cookies' to store and frequently retrieve usage information to provide individual services and convenience to users.
A cookie is a small amount of information that a server (http) used for website operation sends to the information subject's browser and is stored on the information subject's PC or mobile.
Information subjects can allow or block cookies through the option settings in the web browser.
However, if you refuse to store cookies, you may experience difficulties in using customized services.
How to refuse cookie settings
You can allow all cookies, check each time they are stored, or refuse all through the browser options.
Allow/Block cookies in web browsers
Chrome: Settings > Privacy and security > Clear browsing data
Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
Allow/Block cookies in mobile browsers
Chrome: Mobile settings > Privacy and security > Clear browsing data
Safari: Mobile settings > Safari > Advanced > Block All Cookies
Samsung Internet: Mobile settings > Browsing data > Delete browsing data
9. Matters Concerning the Rights and Obligations of Information Subjects and Legal Representatives and How to Exercise Them
Information subjects may exercise their rights, such as requesting access to, correction, deletion, suspension of processing, withdrawal, or refusal/explanation of automated decisions, against the company at any time.
Rights can be exercised in writing or by e-mail in accordance with Article 41 (1) of the Enforcement Decree of the Personal Information Protection Act, and the company will take action without delay.
Information subjects can request access, modification, or deletion by sending an e-mail to privacy@everspin.co.kr at any time.
Information subjects can withdraw consent for collection and use by sending an e-mail to privacy@everspin.co.kr at any time.
Information subjects can request refusal or explanation of automated decisions by sending an e-mail to privacy@everspin.co.kr at any time.
Rights can be exercised through a legal representative of the information subject or a person who has been delegated.
In this case, a power of attorney in the form of Attachment No. 11 of the “Notice on Personal Information Processing Methods” must be submitted.
Requests for access to and suspension of processing of personal information may be restricted according to Article 35 (4) and Article 37 (2) of the Personal Information Protection Act.
Requests for deletion of personal information cannot be made if the personal information is specified as a target for collection in other laws and regulations.
In cases where the information subject has consented to automated decision-making, has been notified in advance through a contract, etc., or where there are clear provisions in the law, refusal to automated decisions is not recognized, and only requests for explanation and review are possible.
In addition, requests for refusal or explanation of automated decisions may be rejected if there are justifiable reasons, such as the risk of unfairly infringing on the life, body, property, or other interests of others.
The company confirms whether the person making the request for rights is the person themselves or a legitimate representative.
10. Personal Information Protection Officer and Department in Charge
The company is overall responsible for personal information processing and has designated a personal information protection officer as follows to handle complaints and provide remedies for information subjects.
The company has designated the following personal information protection officer to handle complaints and provide remedies for information subjects.
Personal Information Protection Officer / Department: Team Leader Jaesung Kim / Information Security Team
Information subjects may inquire about all personal information protection-related matters, complaint handling, and damage relief that occur while participating in the company's marketing activities to the personal information protection officer and the department in charge. The company will answer and process the inquiries of information subjects without delay.
11. Remedial Methods for Infringement of Rights and Interests of Information Subjects
Information subjects may apply for dispute resolution or consultation to the following institutions to receive remedy for personal information infringement. For other reports and consultations on personal information infringement, please contact the following institutions.
Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
The company guarantees the right to self-determination of personal information and strives for consultation and damage relief. Please contact the department below for help.
Customer consultation and reporting related to personal information protection