【 Privacy Policy 】
『Skin&Beam』 (hereinafter referred to as 'the Clinic') places great importance on the protection of your personal information and complies with the [Personal Information Protection Act].
The Clinic informs you through this privacy policy about how the personal information you provide is used, in what manner, and what measures are taken to protect your personal information.
1. Items of Personal Information Collected and Collection Methods
2. Purpose of Collection and Use of Personal Information
3. Retention and Usage Period of Personal Information and Destruction Procedures and Methods
4. Installation/Operation of Automatic Personal Information Collection Devices and Matters Regarding Refusal Thereof
5. Rights of Users and Legal Representatives and Methods of Exercising Such Rights
6. Methods for Withdrawing Consent
7. Provision and Entrustment of Personal Information
8. Provision and Entrustment of Personal Information to Third Parties
9. Personal Information Protection Officer
10. Measures to Ensure the Safety of Personal Information
11. Obligation to Notify Upon Policy Changes
1. Items of Personal Information Collected and Collection Methods
The Clinic collects only the minimum personal information necessary for service use during internet membership registration and appointment booking. Essential information for medical care is collected through the medical card without separate consent in accordance with the Medical Service Act. For additional services (advertising) beyond medical care, a separate consent form for collection and use must be completed, and there shall be no disadvantage in medical care even if the consent form is not completed.
- Required items: Name, date of birth, gender, address, age, contact number, mobile phone number, email, hospital registration number, service application status
- Health information: Visit information, disease information, prescription information, medical records
- Payment information: Credit card company name, card number, and other card payment authorization information
2. Purpose of Collection and Use of Personal Information
① Required
- Medical information: Provision of medical services for diagnosis and treatment, and administrative services such as billing, payment collection, and refunds
- Appointment information: Used for identity verification procedures related to appointment booking, appointment inquiry, and other service usage
Notification of clinic news, disease information, etc. through text messages and SNS, and surveys
- Other: Used for creating visiting customer analysis data for new service development
Basic data for outsourced laboratory test requests
- Collection of consumer harm information pursuant to Article 52 of the Framework Act on Consumers
Restriction measures against users who violate laws and the Clinic's terms of use, prevention and sanctions against activities that impede the smooth operation of services including unauthorized use, prevention of personal information theft and unauthorized use, record retention for dispute mediation, handling of civil complaints, etc.
② Optional
- Marketing and promotion: Clinic news, clinic procedures and events, personalized advertising and marketing, cosmetics and other promotional information
3. Retention and Usage Period of Personal Information and Destruction Procedures and Methods
[Retention and Usage Period]
- The Clinic retains collected customer personal information only for the patient registry period of 5 years and the legally mandated period for retaining medical records (10 years), after which it is deleted from the database. However, if outstanding credit/debt relationships remain, retention continues until the settlement of such credit/debt relationships
- If the information provider requests deletion of personal information, it shall be deleted immediately
However, even when the purpose of collection or the purpose for which information was provided has been achieved, personal information may be retained if there is a need for preservation under the Commercial Act or other laws
* Records related to consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce, etc.)
* Records related to the collection, processing, and use of credit information: 3 years (Credit Information Use and Protection Act)
* Records related to identity verification: 6 months (Act on Promotion of Information and Communications Network Utilization and Information Protection)
[Destruction Procedures and Methods]
- Destruction procedure: Immediate destruction by the destruction method after the legally mandated retention period
- Destruction method: Personal information stored in electronic file format is deleted using technical methods that prevent the records from being reproduced, and personal information printed on paper is destroyed by shredding or incineration
- Upon termination of customer management service entrustment: The entrusted party shall permanently destroy all related files and DB data within 2 weeks
4. Installation/Operation of Automatic Personal Information Collection Devices and Matters Regarding Refusal Thereof
In addition to the personal information described above, the service recognizes visitors through cookies, pixel tags or web beacons, and IP addresses, and uses them for the purposes described below. By using the Skin&Beam website and services, you are deemed to have consented to the use of such technologies including cookies. (A cookie is a small text file transmitted by a website or its service provider to a user's web browser on their computer, which enables the website or service provider's system to recognize the user's web browser and store and remember certain information. A pixel tag or web beacon is a transparent graphic image placed on a web page or email to indicate whether a page/image has been viewed or to instruct a browser to display content from another server. An IP address is online address information assigned by an internet service provider to the user's PC or other device connecting to the internet. There are widely varying views across countries on whether IP addresses constitute personal information.)
① Remembering the content used during previous service visits to provide an enhanced service environment for the user on subsequent visits
② Analysis of service visit traffic and understanding of service usage patterns
③ Utilization for service visit traffic analysis through contracts with third parties as needed
④ Personalized advertising and marketing
⑤ Restriction measures against users who violate laws and the Clinic's terms of use, prevention and sanctions against activities that impede the smooth operation of services including unauthorized use, prevention of personal information theft and unauthorized use, record retention for dispute mediation, handling of civil complaints, etc.
How to refuse cookie settings
○ Example: You may allow all cookies, require confirmation each time a cookie is saved, or refuse all cookies by selecting options in your web browser. Setting method example (for Internet Explorer)
: Tools at the top of the web browser > Internet Options > Privacy
However, if you refuse cookie installation, there may be difficulties in providing services.
5. Rights of Users and Legal Representatives and Methods of Exercising Such Rights
Reservations by minors are made through separate forms written in plain and easy-to-understand language, and the consent of legal representatives is always obtained when collecting personal information.
The Clinic collects the minimum information, such as the name and contact details of the legal representative, from minors in order to obtain the consent of legal representatives, and obtains such consent in accordance with the methods prescribed in the personal information processing policy.
Legal representatives of minors may request access to, correction of, and deletion of the minor's personal information. If you wish to access, correct, or delete a minor's personal information, click on 'Edit Member Information,' complete the legal representative verification process, and then the legal representative may directly access, correct, or delete the minor's personal information, or contact the Personal Information Protection Officer by mail, phone, or fax, and necessary measures will be taken.
※ Personal information that is required to be retained by law cannot be modified or deleted during the retention period even upon request.
6. Methods for Withdrawing Consent
You may withdraw your consent to the collection, use, and provision of optional personal information given at the time of online appointment booking at any time. If you contact the Personal Information Protection Officer by mail, phone, or fax, necessary measures such as destroying your personal information will be taken without delay.
7. Provision and Sharing of Personal Information
The Clinic shall not use your personal information beyond the scope notified in the purpose of collection and use, nor provide it to any other person, company, or organization, except with your consent or as required by relevant laws.
- Submission of medical records for claiming medical care benefit costs to the Health Insurance Review and Assessment Service under the National Health Insurance Act
- Provision in a form that does not identify specific individuals when necessary for statistical compilation and academic research
- Submission upon request by investigative agencies in accordance with procedures and methods prescribed by law
8. Provision and Entrustment of Personal Information to Third Parties
The Clinic entrusts personal information for internet appointment and text notification services as described below, and stipulates the necessary matters to ensure that personal information is managed safely during entrustment contracts in accordance with relevant laws.
The Clinic's personal information entrustment processing organizations and the details of entrusted tasks are as follows.
Entrusted company: Memento Co., Ltd.
Details of entrusted tasks: Website operation and management, DB management and storage, clinic, procedure and event, personalized advertising and marketing, cosmetics, cosmetics event, and other promotional information delivery
Personal information retention and usage period: Until the termination of the entrustment contract
9. Personal Information Protection Officer
Name: Ha Eun-hwan
Position: Director of Skin&Beam
Affiliation: Skin&Beam
Phone: 1544-2994
10. Measures to Ensure the Safety of Personal Information
The Clinic has implemented various security measures as technical safeguards for the protection of users' personal information. All information provided by users is securely protected and managed by security equipment such as firewalls.
Additionally, as an administrative measure for the protection of users' personal information, the Clinic has established procedures for access to and management of users' personal information, limits the number of personnel who process users' personal information to a minimum, and conducts ongoing security training. Furthermore, users of systems that process personal information are designated and assigned passwords, which shall be updated regularly.
11. Obligation to Notify Upon Policy Changes
This privacy policy was established on April 11, 2013, and if there are any additions, deletions, or modifications to the content due to changes in laws, policies, or security technologies, the reasons and details of the changes shall be notified through the Clinic's website at least 7 days before the implementation of the revised privacy policy.
Date of announcement: April 11, 2013
Effective date: April 11, 2013