[Privacy Policy]
Wooribyul Co., Ltd. (“Company”) values your personal information and complies with the law on Republic of Korea’s privacy regulations under Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. and Personal Information Protection Act. Through this Policy, the Company regards personal information of the users as important and inform them of the purpose and method of Company's using the personal information provided by the users and the measures taken by the Company for protection of those personal information.
Personal Information items to be collected
The company collects the following personal information for membership registration, consultation, service application, etc.
- Collected items
Required information: ID, name, password, affiliation, date of birth, contact information, email, address
The following information may be collected only for users of the service in the Wooribyul online services such as competition application, education application, education application inquiry, municipal branch application, certificate issuance application, volunteer application, donation application partner application, inquiry, etc.
- Method of collection
The Company collects the information of users in a way of the followings:
Website (membership registration), competition application, education application, education application inquiry, provincial and provincial branch application, certificate issuance application, volunteer application, donation application Partner application, enquiry, etc.
Purpose of collection and use of personal information
The company uses the collected personal information for the following purposes.
- Member Management
Identity verification according to membership service use, personal identification, prevention of illegal use by bad members and prevention of unauthorized use, confirmation of intent to join, age verification, complaint handling, complaint handling, etc., delivery of notice
- Use for marketing and advertising
Delivery of advertising information such as events, identification of access frequency, or statistics on member service use
Period of retention and use of personal information
In principle, users' personal information is destroyed without delay when the purpose of collection and use of personal information is achieved. However, the following information is retained for the period specified for the following reasons.
- Reasons for information retention according to company internal policy
Record of illegal use
Reason for retention: Prevention of fraudulent use
Retention period: 1 year
- Reasons for information retention according to related laws
If it is necessary to preserve it in accordance with the provisions of related laws, such as the Commercial Act, the Consumer Protection Act in Electronic Commerce, etc.,
the company keeps member information for a certain period as stipulated by the relevant laws and regulations.
Contents |
Reason |
Period |
Records on contract or subscription withdrawal |
Act on Consumer Protection in Electronic Commerce, Etc. |
5 years |
Records on payment and supply of goods, etc. |
Wooribyul |
5 years |
Records on Electronic Financial Transactions |
Wooribyul |
5 years |
Records on consumer complaints or dispute resolution |
Wooribyul |
3 years |
Records of identity verification |
Act on Promotion of Information and Communications Network Utilization and Information Protection |
6 mounths |
Website visit history |
Communication Secret Protection Act |
3 mounths |
Procedure and method of destruction of personal information
In principle, when an individual requests destruction of personal information, the company destroys it without delay. The destruction procedure and method are as follows.
- Destruction procedure
The information entered by the member for membership registration, etc. is transferred to a separate DB after the purpose is achieved (a separate filing cabinet in the case of paper) and is scheduled according to internal policies and information protection reasons according to other relevant laws (refer to retention and use period) It is destroyed after being stored for a period of time.
Personal information transferred to a separate DB will not be used for any other purpose other than being retained unless it is required by law.
- Destruction method
Personal information stored in electronic file format is deleted using a technical method that cannot reproduce the record. Personal information printed on paper is shredded with a shredder or destroyed through incineration
Measures to ensure the safety of personal information
In accordance with Article 29 of the Personal Information Protection Act, the company is taking the following technical/administrative and physical measures necessary to secure safety.
- Minimization and training of personnel handling personal information
We are implementing measures to manage personal information by designating employees who handle personal information and limiting them to the person in charge.
- Implement regular self-audits
Implement regular (once a year) self-audits to secure the stability of personal information handling
- Establishment and implementation of internal management plan
Implement regular (once a year) self-audits to secure the stability of personal information handling
- Encryption of personal information
Customer's personal information is stored and managed in an encrypted way, so only the user can know it. For important data, separate security functions such as encrypting files and transmission data or using a file lock function are used.
- Technical measures against hacking, etc.
To prevent leakage and damage of personal information caused by hacking or computer viruses, the company installs security programs, periodically updates and inspects them, installs systems in areas where access is controlled from outside, and technically and physically monitors and blocks them.
- Restrict access to personal information
We take necessary measures to control access to personal information by granting, changing, and canceling access rights to the database system that processes personal information, and use an intrusion prevention system to control unauthorized access from outside. In the case of the person in charge of the job, the right to access the personal information processing system is differentially granted to the minimum extent necessary for the performance of the job depending on the nature of the job.
- Storage of access records and Forgery prevention
The records of access to the personal information processing system are kept and managed for at least six months, and security functions are used to prevent forgery, theft, or loss of access records.
- Use of locks for document security
Documents and auxiliary storage media containing personal information are stored in a safe place with a lock.
- Access control for unauthorized persons
A separate physical storage place for personal information is established and access control procedures are established and operated.
Sharing and Provision of Personal Information
The company uses the user's personal information within the scope notified in the 'Purpose of Collection and Use of Personal Information', and in principle does not use it beyond this scope or provide it to outside parties without the user's prior consent. However, exceptions are made in the following cases.
- When users consent in advance
- Under the provisions of laws and regulations, or if there is a request from the investigation agency in accordance with the procedures and methods prescribed in the laws for the purpose of investigation
Users' rights and how to exercise them
Users can inquire or modify their registered personal information at any time and may request cancellation of membership.
Users can directly view and correct personal information by clicking “Edit My Information” to ‘change personal information’ (or ‘modify member information’, etc.).
Or, if you contact the person in charge of personal information management in writing, by phone or e-mail, we will take action without delay.
If you request correction of errors in personal information, the personal information will not be used or provided until the correction is completed. In addition, if incorrect personal information has already been provided to a third party, we will notify the third party of the result of the correction without delay so that the correction can be made.
The Company handles personal information that has been canceled or deleted at the request of the user as specified in the “Period of Retention and Use of Personal Information Collected by the Company” and is not allowed to be viewed or used for any other purpose.
Matters concerning the installation, operation and rejection of the automatic personal information collection device
The company operates 'cookies' that store and find your information from time to time. Cookies are very small text files sent to your browser by the server used to operate the company's website and are stored on your computer's hard disk. The company uses cookies for the following purposes:
Purpose of use, such as cookies
- Target marketing and personalized services are provided by analyzing the access frequency and visit time of members and non-members, identifying users' tastes and interests and tracking traces, and identifying the degree of participation in various events and the number of visits, etc.
You have the option to install cookies. Therefore, you can accept all cookies by setting options in your web browser, check each time a cookie is saved, or refuse to save all cookies.
How to refuse cookie settings
- Example: As a method of refusing to set cookies, you can accept all cookies by selecting the option of your web browser, check each time you save a cookie, or refuse to save all cookies.
Example of setting method (in case of Internet Explorer)
Tools at the top of your web browser > Internet Options > Privacy
However, if you refuse to install cookies, there may be difficulties in providing services.
Complaint service regarding personal information
In order to protect customers' personal information and handle complaints related to personal information, the company has designated the relevant department and personal information manager as follows.
Name of department in charge of customer service
Phone number: 031-980-7500
Email: info@wooribyul.co.kr
Name of person in charge of personal information management
Phone number: 031-980-7500
Email: info@wooribyul.co.kr
You can report any complaints related to personal information protection that occur while using the company's services to the person in charge of personal information management or the department in charge. The company will promptly and sufficiently respond to users' reports.
If you need to report or consult on other personal information infringement, please contact the following organizations.
- Personal Dispute Mediation Committee (Website: http://www.1336.or.kr Phone: 1336)
- Information Protection Mark Certification Committee (Website: http://www.eprivacy.or.kr Phone: 02-580-0533~4)
- Internet Crime Investigation Center of Supreme Prosecutors' Office (Website: http://icic.sppo.go.kr Phone: 02-3480-3600)
- Cyber Terror Response Center of Korean National Police Agency (Website: http://www.ctrc.go.kr Phone: 02-392-0330)
Duty of notice
If there are additions, deletions, or modifications to the current privacy policy, we will notify you through the 'Notice' on the website at least 7 days before the revision. However, if there is an important change in user rights, such as collection and use of personal information or provision to a third party, it will be notified at least 30 days in advance.
- Effective Date: September 10, 2021