SEOLREIM CLINIC Privacy Policy
Seolreim ClinicPursuant to Article 30 of the Personal Information Protection Act, the company (the ‘Company’) establishes and publishes this Privacy Policy to protect users’ personal information and promptly and efficiently resolve related complaints.
This Privacy Policy covers the following matters.
1. Purposes of Processing Personal Information
2. Processing and Retention Periods
3. Categories of Personal Information Processed and Collection Methods
4. Processing Personal Information of Children Under 14
5. Provision of Personal Information to Third Parties
6. Outsourcing of Personal Information Processing
7. Procedures and Methods for Destroying Personal Information
8. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
9. Measures to Safeguard Personal Information
10. Installation and Operation of Automatic Data-Collection Tools and How to Refuse Them
11. Privacy Officer
12. Remedies for Infringement of Data Subjects’ Rights
13. Changes to the Privacy Policy
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes only. If a purpose changes, it will take necessary measures, such as obtaining separate consent, under Article 18 of the Personal Information Protection Act.
(1) Website Membership Registration and Management
Personal information is processed to confirm an intention to register; identify and authenticate members for membership services; maintain and manage membership; prevent misuse; verify legal-representative consent when processing data of children under 14; provide notices; and handle complaints.
(2) Provision of Goods or Services
Personal information is processed to provide content, handle purchases and payments, deliver goods or invoices, provide services, and offer personalized services.
(3) Marketing and Advertising
Personal information is processed to provide event and advertising information and participation opportunities, measure visit frequency, and compile statistics on members’ use of the Service.
2. Processing and Retention Periods
(1) The Company processes and retains personal information within the retention and use period agreed to when collecting it from the data subject. It promptly destroys the information when the processing purpose is fulfilled or the data subject requests service termination. The respective processing and retention periods are as follows.
① Website membership registration and management: Until membership withdrawal.
② Provision of goods or services: Until supply of the goods or services and payment and settlement are complete.
(2) Where retention is required by applicable laws, the Company retains member information for the legally prescribed periods below.
① Records of contracts or withdrawal of offers
- Legal basis: Act on Consumer Protection in Electronic Commerce, Etc.
- Retention period: 5 years
② Records of payment and supply of goods or services
- Legal basis: Act on Consumer Protection in Electronic Commerce, Etc.
- Retention period: 5 years
③ Records of consumer complaints or dispute resolution
- Legal basis: Act on Consumer Protection in Electronic Commerce, Etc.
- Retention period: 3 years
④ Records of labeling and advertising
- Legal basis: Act on Consumer Protection in Electronic Commerce, Etc.
- Retention period: 6 months
⑤ Service visit records
- Legal basis: Protection of Communications Secrets Act
- Retention period: 3 months
3. Categories of Personal Information Processed and Collection Methods
(1) Categories of Personal Information Processed
① The Company collects the following personal information for membership registration, consultations, service applications, and related purposes.
- Standard membership registration
Required: User ID, password, name, email address, mobile number, date of birth, and legal-representative information for applicants under 14.
Optional: Gender
- Product orders
Required: Order information (name, email address, mobile number), shipping information (name, address, mobile number), and an order-inquiry password for guest orders.
Optional: Landline number
- Kakao social login
Required: Name
- Naver social login
Required: User ID, name, email address
Optional: Nickname, birthday
② The following information may be generated and collected while using the Service or conducting business operations.
- Service-use records, access logs, cookies, IP-address information, payment records, suspension records, and misuse records
(2) Collection Methods
- Website, written forms, bulletin boards, email, event entries, delivery requests, telephone, fax, partner-provided information, and tools that collect generated information
4. Processing Personal Information of Children Under 14
(1) When collecting personal information from children under 14, the Company obtains consent from their legal representative and collects only the minimum information needed to provide the Service.
- Required: [Enter personal information collected through the legal-representative consent form]
(2) When collecting personal information from children under 14, the Company may request minimal information such as the legal representative’s name and contact details, and verifies lawful representative consent using one of the following methods.
- Having the legal representative indicate consent on a website displaying the consent terms, then sending a text message to the representative’s mobile phone confirming that the data controller has verified the consent.
- Having the legal representative indicate consent on a website displaying the consent terms and provide credit-card, debit-card, or other card information.
- Having the legal representative indicate consent on a website displaying the consent terms, then verifying their identity through mobile-phone authentication or a similar method.
- Providing the legal representative with a written consent form directly, by post, or by fax, and having them sign or affix their seal and return it.
- Emailing the consent terms and receiving an email from the legal representative expressing consent.
- Explaining the consent terms by telephone and obtaining consent, or directing the representative to a website address or other means of reviewing the terms and obtaining consent in a follow-up call.
- Other equivalent methods of informing the legal representative of the consent terms and verifying their expression of consent.
5. Provision of Personal Information to Third Parties
(1) The Company processes personal information only within the purposes stated in Article 1 (Purposes of Processing Personal Information), and provides it to third parties only in circumstances permitted under Articles 17 and 18 of the Personal Information Protection Act, such as data-subject consent or a specific legal provision.
(2) The Company provides personal information to third parties as follows.
| Third-Party Recipient | Purpose of Provision | Personal Information Provided | Recipient’s Retention and Use Period |
| [Third-party recipient] | [Purpose of provision] | [Personal information provided] | [Recipient’s retention and use period] |
(3) In emergencies such as disasters, infectious disease outbreaks, incidents or accidents posing imminent danger to life or physical safety, or imminent property loss, the Company may provide personal information to relevant authorities without data-subject consent under the jointly issued government ‘Rules for Processing and Protecting Personal Information in Emergencies.’
For details,click here*to review the information.
6. Outsourcing of Personal Information Processing
(1) The Company outsources the following personal-information processing tasks to facilitate operations.
Service Provider | Outsourced Task |
Cafe24 Corp. | Provision and maintenance of the online-store hosting system |
(2) When entering an outsourcing agreement, the Company documents matters required under Article 26 of the Personal Information Protection Act, including prohibition of processing beyond the outsourced purpose, technical and administrative safeguards, restrictions on subcontracting, management and supervision of the provider, and liability for damages. It supervises providers to ensure safe processing.
(3) Any change to an outsourced task or service provider will be promptly disclosed through this Privacy Policy.
7. Procedures and Methods for Destroying Personal Information
The Company promptly destroys personal information when it is no longer needed, including upon expiry of its retention period or fulfillment of its processing purpose.
(1) Destruction Procedure
① If another law requires continued retention after the agreed retention period expires or the purpose is fulfilled, the personal information is transferred to a separate database or retained in a separate storage location.
② Personal information transferred to a separate database is not used for other purposes except as required by law.
(2) Destruction Methods
① Electronic files are destroyed using technical methods that prevent recovery of the records.
② Personal information printed on paper is destroyed by shredding or incineration.
8. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
(1) Data subjects may at any time exercise rights against the Company, including requests to access, correct, delete, or suspend processing of personal information.
(2) To view or amend personal information, click ‘Change Personal Information’ or ‘Edit Member Information.’ To cancel membership or withdraw consent, click ‘Withdraw Membership.’ After identity verification, you may directly view, correct, or withdraw.
(3) Alternatively, contact the Privacy Officer in writing, by telephone, or by email, and we will act without delay.
(4) Rights under paragraph 1 may be exercised through a legal representative or authorized agent. In this case, a power of attorney using Form 11 appended to the Notification on Personal Information Processing Methods (No. 2020-7) must be submitted.
(5) Requests for access or suspension of processing may be restricted under Article 35(4) or Article 37(2) of the Personal Information Protection Act. For correction or deletion requests, deletion cannot be demanded if another law specifically requires collection of that information.
(6) When receiving a request for access, correction, deletion, or suspension under a data subject’s rights, the Company verifies that the requester is the data subject or a duly authorized representative.
9. Measures to Safeguard Personal Information
The Company takes the following measures to safeguard personal information.
(1) Administrative measures: Establishment and implementation of an internal management plan, a dedicated organization, and regular employee training.
(2) Technical measures: Management of access rights to personal-information processing systems, installation of access-control systems, encryption of personal information, and installation and updating of security software.
(3) Physical measures: Access controls for server rooms, document-storage rooms, and similar facilities.
10. Installation and Operation of Automatic Data-Collection Tools and How to Refuse Them
The Company uses cookies, which store and retrieve usage information, to provide individualized services. Cookies are small pieces of information sent by a website’s server to the user’s browser and may be stored on the computer’s hard drive.
(1) Purpose of Cookies
Cookies are used to provide optimized information by identifying visits and usage patterns across services and websites, popular search terms, and whether connections are secure.
(2) Installation, Operation, and Refusal of Cookies
You can refuse cookie storage through the options under Tools > Internet Options > Privacy at the top of your browser.
Refusing cookies may, however, make personalized services difficult to use.
11. Privacy Officer
(1) The Company appoints the following Privacy Officer to oversee personal-information processing and handle data-subject complaints and remedies for harm.
o Privacy Officer
Name: Jungha Kang
Department: Management Team
Telephone: 02-511-7674
Email: sulskin@naver.com
(2) Data subjects may contact the Privacy Officer or responsible staff about all privacy inquiries, complaints, and remedies arising from use of the Company’s services. The Company will respond and act without delay.
12. Remedies for Infringement of Data Subjects’ Rights
(1) To seek redress for a privacy infringement, you may apply for dispute resolution or consultation through the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency’s Privacy Infringement Report Center, or similar organizations. For other reports or inquiries, contact the agencies below.
Personal Information Dispute Mediation Committee: 1833-6972 (no area code; privacy.go.kr)
Privacy Infringement Report Center: 118 (no area code; privacy.kisa.or.kr)
Supreme Prosecutors’ Office: 1301 (no area code; www.spo.go.kr)
Korean National Police Agency: 182 (no area code; ecrm.cyber.go.kr)
(2) A person whose rights or interests are infringed by a public-agency head’s disposition or failure to act on a request under Article 35 (Access), Article 36 (Correction or Deletion), or Article 37 (Suspension of Processing, etc.) of the Personal Information Protection Act may seek an administrative appeal under the Administrative Appeals Act.
※ For details about administrative appeals, visit the Central Administrative Appeals Commission website (www.simpan.go.kr).
13. Changes to the Privacy Policy
This Privacy Policy takes effect on January 27, 2025.