
‹https://shelter.id› (hereinafter referred to as "Shelter") has the following policies to protect users' personal information, rights and interests, and to facilitate the handling of users' grievances related to personal information under the Privacy Act: ‹Shelter Co., Ltd.›("Shelter") will make an announcement through the website notice (or individual notice) when revising the personal information processing policy. ○ This policy will take effect from December 16, 2019. 1. For the purpose of processing personal information, ‹https://shelter.id› (hereinafter referred to as "shelter") processes personal information for the following purposes: The processed personal information will not be used for purposes other than the following, and we will seek prior consent if the purpose of use is changed. A. Sign up and manage membership of the website Personal information is processed for the purpose of verifying membership, identifying and authenticating oneself by providing membership services, maintaining and managing membership, preventing fraudulent use of services, and checking consent of legal representatives when collecting personal information. B. Complaint handling Personal information is processed for the purpose of identifying civil petitioners, verifying civil petitions, contacting and notifying them of the results of the processing, etc. C. Provide goods or services Personal information is processed for the purpose of providing services, billing, content provision, customized service provision, authentication of oneself, age certification, settlement of charges, etc. D. Use in marketing and advertising Personal information is processed for the purpose of developing new services (products) and customized services, providing event and advertising information and participation opportunities, providing and advertising services based on demographic characteristics, validating services, identifying access frequency, or statistics on members' use of services. 2. Privacy File Status 1. Personal information file name: Shelter Personal Information - Personal information items: e-mail, mobile phone number, password, login ID, gender, date of birth, name, credit card information, bank account information, service usage record, access log, cookie, access IP information, payment record, legal representative name, legal representative mobile phone number - Collection method: Provided by website and affiliates - Foundation for Possession: Consumer Protection in E-commerce, etc. - Retention period: 5 years - Related Acts and subordinate statutes: Records of collection, processing, use, etc. of credit information: 3 years, Records of consumer complaints or dispute handling: 3 years, Records of supply of payment, goods, etc.: 5 years, Records of marking/advertising: 6 months 3. Processing and Retention Period of Personal Information ① ‹Shelter Co., Ltd.›("Shelter") processes and holds personal information agreed upon by the information subject within the period of use in accordance with the Act. ② Each personal information processing and retention period is as follows. 1.‹Provide goods or services› Collect personal information related to the provision of goods or services.Retained for the above purpose from the date of consent to use to ‹5 years›.It's used. - Basis for Possession: Consumer Protection in E-commerce, etc. - Related Acts and subordinate statutes: 1) Records of collection, processing, use, etc. of credit information: 3 years 2) Records of complaints or disputes handled by consumers: 3 years 3) Records of payment and supply of goods, etc.: 5 years 4) Records of withdrawal of contracts or subscriptions, etc.: Five years; 5) Mark/Advertisement Record: 6 Months -Exception reason: 4. Matters concerning the provision of personal information to third parties ① Shelter Co., Ltd. (hereinafter referred to as "https://shelter.id") provides personal information to third parties only if it falls under Articles 17 and 18 of the Personal Information Protection Act, such as consent of the information subject and special provisions of the Act. ② ‹https://shelter.id› provides personal information to third parties as follows: - Person who is provided with personal information: - Purpose of use of personal information of the recipient: e-mail, mobile phone number, login ID, date of birth, name, credit card information, bank account information, service usage record, access log, cookie, access IP information - Possession of the recipient.Period of use: 5 years 5. Consignment of personal information processing ① ‹Shutter Co., Ltd.› ('Shutter') entrusts the following personal information processing tasks for smooth personal information processing. 1. ‹› (Currently None) - Consignee (trustee): - Contents of entrusted work: - Consignment period: ② ‹https://shelter.id› (hereinafter referred to as "shelter") stipulates in documents such as contracts that prohibit the processing of personal information, technical and management measures, restrictions on re-entrustment, management and supervision of trustees, and supervision of personal information. ③ If the details of the entrusted work or the trustee is changed, we will disclose it through this personal information processing policy without delay. 6. The rights and obligations of the information entity and its legal representatives, and the user of the exercise method, may exercise the following rights as a personal information entity: ① The information entity may exercise its right to access, correct, delete, request suspension of processing, etc. of personal information at any time. ② The exercise of rights under paragraph (1) may be made in writing, e-mail, FAX, etc. pursuant to Article 41 (1) of the Enforcement Decree of the Personal Information Protection Act, and the Shelter Co., Ltd. will take measures without delay. ③ The exercise of rights under paragraph (1) may be conducted through an agent, such as a legal representative of the information subject or a delegated person. In such cases, a power of attorney under attached Form 11 of the Enforcement Rules of the Personal Information Protection Act shall be submitted. ④ The right of the information subject may be restricted pursuant to Articles 35 (5) and 37 (2) of the Personal Information Protection Act. ⑤ A request for correction and deletion of personal information shall not be requested if the personal information is specified as a target for collection in other Acts and subordinate statutes. ⑥ When requesting perusal, correction or deletion, and suspension of processing according to the right of the information subject, Shelter Eun Co., Ltd. checks whether the person who requested perusal is himself or a legitimate agent. 7. Create items for processing privacy ① Shelter Co., Ltd. (https://shelter.id) handles the following personal information items: 1‹Registration and management of members on the homepage› - Required items: Email, mobile phone number, password, login ID, gender, date of birth, name, credit card information, bank account information, service usage record, access log, cookie, access IP information, payment record - Optional: Name of legal representative, mobile phone number of legal representative 8. Destruction of Personal Information ‹Shelter Co., Ltd.›("Shelter") shall, in principle, destroy the personal information without delay if the purpose of processing personal information is achieved. The procedure, deadline, and method of destruction are as follows. -Decommission procedure The information entered by the user is transferred to a separate DB after achieving the purpose (in the case of paper), stored for a certain period of time or destroyed immediately in accordance with internal policies and other related laws. At this time, personal information transferred to DB will not be used for any other purpose except by law. -Decreased If the personal information of the user expires, he/she shall destroy the personal information within five days from the date on which the personal information is deemed unnecessary, such as achieving the purpose of processing personal information, abolishing the relevant service, or termination of business. -Destruction method Information in the form of electronic files uses technical methods that cannot be played back. Personal information printed on paper is shredded with a shredder or destroyed by incineration. 9. Matters concerning the installation, operation, and rejection of automatic personal information collection devices; ① Shelter Co., Ltd. uses 'cookie' to store and recall usage information frequently to provide individual customized services. ② Cookies are a small amount of information sent by the server (http) used to run the website to the user's computer browser and can also be stored on the user's PC computer's hard disk. A. Purpose of use of cookies: It is used to provide optimized information to users by identifying the type of visit and use, popular search terms, security access, etc. for each service and website visited by users. B. Installation and Rejection of Cookies: You can refuse to save cookies using Tools ›Internet Options ›Set Options on the Privacy menu. C. Refusing to save cookies may cause difficulty in using customized services. 10. Creating a person in charge of privacy ① Shelter Co., Ltd. (hereinafter referred to as https://shelter.id) is responsible for handling personal information and designates a person in charge of personal information protection as follows for handling complaints and damage relief of information subjects related to personal information processing. ▶ Personal information protection manager Name: Kim Young-cheon Position: Developer Position: Team Leader Contact Us: 031-973-5350, dev@shelter.id ※ Connects to the department in charge of personal information protection. ▶ Department in charge of personal information protection Department Name: Development Team Person in charge: Kim Young-chun Contact Us: 031-973-5350, dev@shelter.id ② Information subjects may contact the person in charge and the department in charge of personal information protection for inquiries, complaints, damage relief, etc. related to personal information protection caused by using the service (or business) of Shelter Co., Ltd. (https://shelter.id). Shelter Co., Ltd. (https://shelter.id) will respond and process inquiries from the information subject without delay. 11. Changing Privacy Policy ① This personal information processing policy shall apply from the effective date, and if there is any addition, deletion, or correction of changes under Acts and subordinate statutes and policies, it shall be notified seven days prior to the enforcement of the change. 12. Personal Information Security Measures ‹Shelter Co., Ltd.› ('Shelter') takes technical, managerial and physical measures necessary to secure safety as follows under Article 29 of the Privacy Act: 1. Conduct regular self-audit In order to secure stability related to personal information handling, self-audit is conducted regularly (once a quarter). 2. Minimization and training of personnel handling personal information We are implementing measures to manage personal information by designating employees who handle personal information and minimizing them to those in charge. 3. Establishment and implementation of an internal management plan An internal management plan is established and implemented for the safe processing of personal information. 4. Technical countermeasures against hacking, etc. ‹Shelter Co., Ltd.› ('Shelter') installs security programs, updates and inspects periodically to prevent personal information leakage and damage caused by hacking or computer viruses, and installs systems in areas with restricted access from the outside, and monitors and blocks technically and physically. 5. Encryption of privacy Your personal information is encrypted, stored and managed, so only you know it, and important data uses separate security features such as encrypting files and transfer data or using file lock. 6. Storage of access records and prevention of forgery Records of access to the personal information processing system are kept and managed for at least six months, and security functions are used to prevent forgery, theft, and loss of access records. 7. Restrict access to personal information We take necessary measures to control access to personal information through granting, changing, and erasing access to database systems that process personal information, and control unauthorized access from outside using intrusion prevention systems. 8. Using Lockdowns for Document Security Documents including personal information, auxiliary storage media, etc. are stored in a safe place with locks. 9. Access control for unauthorized persons We set up and operate access control procedures separately for physical storage of personal information.