※ idsTrust implements the following policies to protect customers' valuable personal information.
1. Items of personal information to be collected
idsTrust(hereinafter referred to as the 'Company')values the personal information of users and complies with the personal information protection regulations of laws related to personal information, such as the 'Personal Information Protection Act' and the 'Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.'. The company complies with the guidelines designated by relevant organizations such as the Ministry of Public Administration and Security and the Korea Communications Commission. Through the personal information handling policy, the company informs you of what purpose and method the personal information provided by users is being used and what measures are being taken to actively protect personal information.
2. Purpose of collection and use of personal information
The company uses the collected personal information for the following purposes. All information provided by users will not be used for any purpose other than necessary for the following purposes, and prior consent will be sought when the purpose of use is changed.
Advertising inquiry Provision of content, provision of specific customized services
3. Consent to collection and use of personal information
When collecting user's personal information, the purpose of collection and use of personal information, the items of personal information to be collected, and the retention and use period of personal information are notified to the user and consent is obtained in accordance with the provisions of the relevant laws and regulations. Or notice through the privacy policy.
4. Retention and use period of personal information
The company retains and uses the user's personal information only for the period of providing the service. When the purpose of collection and use is achieved or the retention and use period ends, the personal information is destroyed without delay.
5. Personal information destruction procedure and method
In principle, the company destroys the information without delay after the purpose of collecting and using personal information is achieved. The destruction procedure and method are as follows.
Destruction procedure
The information entered by the user to subscribe to the newsletter is moved to a separate DB after the purpose is achieved. (In the case of paper, it is moved to a separate filing cabinet.) The information is destroyed after being stored for a certain period of time according to internal policies and reasons for information protection pursuant to other relevant laws (refer to retention and use period).
Personal information transferred to a separate DB will not be used for other purposes unless it is required by law.
Destruction method
Personal information stored in the form of an electronic file is deleted using a technical method that cannot reproduce the record.
Personal information printed on paper is shredded with a shredder or destroyed by incineration.
Exception
Posts and attachments, excluding personal information, can be backed up and stored by the company.
6. Inspection, renewal, modification and withdrawal of consent of personal information
Users can view or correct their personal information registered on the homepage at any time, and if necessary, a rejection request for newsletter subscriptions accepted by the user will be processed immediately according to a certain process.
7. Provision of personal information
The company uses users' personal information within the scope notified in "2. Purpose of collection and use of personal information" The company does not use the user's personal information beyond the range of movement without the user's prior consent or, in principle, does not provide the user's personal information to the outside. However, in the following cases, personal information may be used and provided with care.
When users have agreed to the disclosure in advance
Personal information necessary for the fulfillment of the contract for the provision of services, where it is significantly difficult to obtain normal consent for economic/technical reasons
If there is a request from an investigative agency in accordance with the regulations or in accordance with the procedures and methods set forth in the law for the purpose of investigation In the case of complete succession and transfer of the rights and obligations of a service provider, such as a merger or sale, we will notify you in advance of justifiable reasons and procedures in detail, and give you the option to withdraw your consent to personal information.
8. Technical and managerial protection measures for personal information
The company has the following technical and managerial measures to ensure safety in handling personal information of users so that personal information is not lost, stolen, leaked, falsified or damaged.
Countermeasures against hacking The company is doing its best to prevent leakage or damage of members' personal information due to hacking or computer viruses. In preparation for damage to personal information, data is backed up from time to time, and the latest whitewashing program is used to prevent users' personal information or data from being leaked or damaged. We strive to transmit personal information safely over the network through encrypted communication, etc. In addition, unauthorized access from outside is controlled by using an intrusion prevention system. The company is trying to have all possible technical devices to secure security systematically.
Training of staff handling personal information The company minimizes employees related to personal information. We conduct regular training on acquisition of new security technologies and obligations to protect personal information. Administrative measures are being implemented, such as granting a separate password to manage access rights.
9. Operation of Cookies
This site uses 'cookies' that store and retrieve user information from time to time in order to provide customized services tailored to users. Cookies are a small amount of information transmitted to the user's computer browser by the server (HTTP) used to run the website, and are also stored on the hard disk of the user's PC computer.When a user accesses the website, the website's computer reads the contents of the cookie in the user's browser. Additional information of the user can be found on the user's computer and the service can be provided without additional input such as name according to access. Cookies identify the user's computer, but do not personally identify the user In addition, users have a choice about cookies. By setting options in the web browser used by the user, the user can accept all cookies, check whenever a cookie is saved, or refuse to save all cookies.
10. Civil service related to personal information
In order to protect users' personal information and handle complaints related to personal information, the company appoints the person in charge of personal information management as follows. Users can report all personal information protection-related complaints that occur while using the company's services to the person in charge of personal information management. The company will provide prompt and sufficient answers to users' reports.
Personal information manager
Name : Kim Kyung-jin
Phone : 02-550-8192
email : kjnpkw@idstrust.com
If you need to report or consult about other personal information infringement, please contact the organizations below.
Personal Information Infringement Reporting Center (www.1336.co.kr/118 without an area code)
Information Protection Mark Certification Committee (www.eprivacy.co.kr/02-580-0533~4)
Internet Crime Investigation Center, Supreme Prosecutors' Office (icic.sppo.go.kr/02-3480-3600)
National Police Agency Cyber Terror Response Center (www.ctrc.go.kr/02-392-0330)
11. Additional Policy
This privacy policy is effective from August 01, 2020. If there is any change in this content (addition, deletion, or modification of the privacy policy due to changes in laws, policies, or security technology), it will be announced through the notice on the company website at least 30 days prior to the effective date.In order to protect users' personal information and handle complaints related to personal information, the company appoints the person in charge of personal information management as follows. Users can report all personal information protection-related complaints that occur while using the company's services to the person in charge of personal information management. The company will provide prompt and sufficient answers to users' reports.