How we collect, use, and protect your personal information.
This English translation is provided for reference. In case of any discrepancy, the original Korean version prevails.
Gangnam Seoyon Plastic Surgery Clinic (hereinafter "the Clinic") places great importance on protecting your personal information and complies with the Korean Personal Information Protection Act.
Through this Privacy Policy, the Clinic informs you of the purposes and methods for which the personal information you provide is used, and the measures taken to protect that information.
The Privacy Policy is organized as follows:
The Clinic collects only the minimum personal information necessary for service use upon membership registration. When using the Clinic's services, there are required and optional fields during registration; optional fields such as email subscription do not affect service use even if left blank.
a. [Medical Records] – Items collected: name, date of birth, address, contact information, medical record
※ Under the Medical Service Act, unique identifying information and medical records must be retained (no separate consent required).
b. [Information Collected at Website Membership Registration]
– Required: name, ID, password, address, contact information (phone, mobile), email address
– Optional: birthday, SMS subscription, email subscription, areas of interest
– During service use or service-related processing, the following may be automatically generated and collected: service usage records, access logs, cookies, and access IP information.
c. [Methods of Collection] – Personal information is collected through:
· Website, written forms, fax, telephone, consultation board, and email.
The Clinic uses collected personal information for the following purposes. All information provided will not be used for any purpose other than those listed below; if the purpose changes, prior consent will be obtained.
a. [Medical Records] – Provision of diagnostic and treatment services, and administrative services such as billing, payment, and refunds.
b. [Website Membership Information]
– Required information: appointment booking, appointment lookup, member-only services, and posting in online boards (1:1 consultation / private consultation / post-op consultation / reviews, etc.).
– Optional information: clinic news and health-related information via email, surveys, troubleshooting, personalized service, statistical analysis of service use, and other new service announcements.
The Clinic does not collect sensitive personal information that may infringe on the user's basic human rights.
Within the above scope, the Clinic may collect additional information voluntarily provided by users to deliver more comprehensive services.
The Clinic shall destroy personal information without delay once the collection or provision purpose has been fulfilled.
a. [Medical Records] – Retained according to retention standards specified in the Medical Service Act.
b. [Website Membership Information]
Retained until membership withdrawal or removal. However, the Clinic may retain personal information when retention is required by law (Commercial Act, etc.) even after the original purpose has been fulfilled.
– Records of consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
– Records of credit information collection/processing/use: 3 years (Use and Protection of Credit Information Act)
– Records of identity verification: 6 months (Act on Promotion of Information and Communications Network Utilization and Information Protection)
– Records of website visits: 3 months (Protection of Communications Secrets Act)
The Clinic destroys personal information immediately after its purpose has been fulfilled. Procedures and methods are as follows:
a. [Destruction Procedure] Information entered by users for membership registration is destroyed immediately after the purpose has been fulfilled, using the methods below.
b. [Destruction Method] Personal information stored in electronic file format is deleted using technical methods that prevent recovery. Personal information printed on paper is destroyed by shredding or incineration.
The Clinic shall not use your personal information beyond the purposes notified in "Purposes of Collection and Use" or provide it to third parties (other persons or organizations) unless you have given consent or such use is permitted by law.
To deliver services, the Clinic outsources personal information processing as detailed below, and stipulates necessary requirements in outsourcing contracts to ensure that personal information is securely managed in accordance with relevant laws.
Contractor: YourDev
Scope of Outsourced Work: Website maintenance, access log management, member account management
Personal Information Outsourced: name, address, phone number
Retention and Use Period: until termination of the outsourcing contract.
Membership registration for children under the age of 14 (hereinafter "children") is conducted via a separate form written in language children can easily understand, and parental consent (legal representative) is required when collecting personal information.
To obtain consent from a legal representative, the Clinic collects minimal information from the child (such as the legal representative's name and contact details), and obtains consent following the methods set forth in this Privacy Policy.
A child's legal representative may request access, correction, or deletion of the child's personal information. To do so, click "Member Information Edit," complete the legal representative verification process, and the legal representative may directly access, correct, or delete the child's personal information. Alternatively, you may contact the Personal Information Protection Officer in writing, by phone, or by fax to request the necessary action.
The Clinic does not provide or share information about children with third parties. If a legal representative requests correction of an error in personal information collected from a child, use and provision of the relevant personal information is suspended until the error is corrected.
※ Personal information that is required by law to be retained cannot be modified or deleted within the retention period, even upon request.
You may at any time withdraw your consent to the collection, use, and provision of personal information given at membership registration. To terminate your account, click "Account Termination" in the My Page section of the Clinic's website. The Personal Information Protection Officer will verify the request, and termination will be completed within 10 days of the application date. You may also contact the Personal Information Protection Officer in writing, by phone, or by fax, and we will take the necessary actions, including destruction of your personal information, without delay.
The Clinic uses "cookies" to store and retrieve your information from time to time. Cookies are very small text files sent by the server operating the Clinic's website to your browser, stored on your computer's hard drive.
You have the right to choose whether to accept cookies. You may set your web browser options to allow all cookies, prompt you each time a cookie is stored, or refuse all cookies. If you refuse cookies, however, some services may not function properly.
To protect your personal information and address any related complaints, the Clinic has appointed a Personal Information Protection Officer:
Name: Choi Dong-Il
Title: Director
Affiliation: Gangnam Seoyon Plastic Surgery
Contact: +82-2-535-8889
You may report any privacy-related complaints arising from your use of the Clinic's services to the Personal Information Protection Officer. The Clinic will provide prompt and sufficient responses to user inquiries.
For other privacy-related reports or consultations, please contact the following organizations:
In handling users' personal information, the Clinic implements the following technical and managerial measures to prevent loss, theft, leakage, alteration, or damage:
a. [Password Encryption] Passwords set during registration are stored and managed in encrypted form, known only to the user; viewing or modifying personal information is also possible only by the user who knows the password.
b. [Measures Against Hacking] The Clinic does its best to prevent leakage or damage of member personal information caused by hacking or computer viruses. Data is regularly backed up, the latest antivirus software is used to prevent leakage or damage of user information, important user data is stored encrypted, and personal information is securely transmitted via encrypted communication. An intrusion prevention system is also used to control unauthorized external access.
c. [Minimization and Training of Staff Handling Personal Information] Staff who handle personal information at the Clinic are limited to designated personnel; separate passwords are assigned and updated regularly, and regular and ad-hoc training is conducted.
※ The Clinic shall not be liable for any issues arising from leakage of personal information (phone number, password, resident registration number, etc.) due to user negligence or internet-related problems beyond the Clinic's control.
This Privacy Policy was last revised on the date below. If content is added, deleted, or modified due to changes in laws, policy, or security technology, the Clinic will announce the reason and details on its website at least 7 days before the revised Privacy Policy takes effect.
· Effective Date: October 6, 2020