Privacy Policy

"ActRO" (hereinafter referred to as the "Company") values your personal information and complies with the Act on Promotion of Information and Communications Network Utilization and Information Protection.

Through this Privacy Policy, the Company informs you of the purposes and methods for which the personal information you provide is used, and the measures taken to protect your personal information. 

If the Company revises this Privacy Policy, it will announce the changes through a notice on the website (or through individual notice).

- Privacy Policy Notice Date: [Notice Date]

- This Policy is effective as of: [ [Effective Date] ]. 

 

Consent to the Collection of Personal Information 

The Company provides a procedure whereby you may click an "Agree" button or a "Do Not Agree" button regarding the contents of the Company's Privacy Policy or Terms of Use. If you click the "Agree" button, you are deemed to have consented to the collection of your personal information. 

 

Protection of Children's Personal Information 

- When the Company collects personal information of children under the age of 14, it obtains the consent of their legal guardian. 

- The legal guardian of a child under the age of 14 may request access to, correction of, or withdrawal of consent for the child's personal information, and upon such request, the Company will take the necessary measures without delay. 

 

Items of Personal Information Collected

The Company collects the following personal information for purposes such as membership registration, consultation, and service applications.

- Items collected: name, date of birth, gender, login ID, password, home telephone number, home address, mobile phone number, email, occupation, marital status, resident registration number, service usage records, access logs, cookies, access IP information, and payment records

- Methods of collection: through the website (membership registration, bulletin boards, etc.) and delivery requests 

 

Purposes of Collection and Use of Personal Information

The Company uses the collected personal information for the following purposes.

- Performance of contracts for the provision of services and settlement of fees arising from the provision of services

Provision of content, purchases and payment of fees, delivery of goods, and dispatch to billing addresses, etc.

- Member management

Identity verification for the use of membership-based services, personal identification, prevention of fraudulent and unauthorized use by improper members, confirmation of intent to register, age verification, confirmation of legal guardian consent when collecting personal information of children under the age of 14, handling of complaints and grievances, and delivery of notices

- Use in marketing and advertising

Delivery of promotional information such as events, analysis of access frequency, and statistics on members' use of services

However, the Company does not collect sensitive personal information that may infringe upon the user's fundamental human rights (such as race and ethnicity, ideology and creed, place of origin and registered domicile, political orientation and criminal records, health status and sex life, etc.). 


Retention and Use Period of Personal Information

- Your personal information is destroyed once the purpose of its collection or the purpose for which it was provided has been achieved, as follows.

- In the case of membership registration information: when the member withdraws membership or is expelled from membership

- In the case of payment information: when payment is completed in full or the statute of limitations for the claim has expired

- In the case of delivery information: when the goods or services have been delivered or provided (provided, however, that exceptions apply where retention is required under applicable laws such as the Commercial Act). 

- Notwithstanding the above retention periods, if it is necessary to continue retaining the information, the Company will obtain your consent. 


Procedures and Methods for the Destruction of Personal Information

In principle, the Company destroys the relevant information without delay after the purpose of collection and use of personal information has been achieved. The procedures and methods of destruction are as follows.

- Destruction procedure

Information you entered for purposes such as membership registration is, after its purpose has been achieved, transferred to a separate database (or, in the case of paper documents, a separate filing cabinet) and stored for a certain period in accordance with internal policies and other relevant laws governing information protection (refer to the Retention and Use Period), after which it is destroyed. Personal information transferred to a separate database is not used for any purpose other than retention, except as required by law.

- Destruction method 

- Personal information stored in electronic file form is deleted using a technical method that renders the records irreproducible. 

 

Provision of Personal Information

In principle, the Company does not provide users' personal information to external parties. However, the following cases are exceptions.

- Where users have given prior consent

- Where required by the provisions of applicable laws, or where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for investigative purposes 

 

Entrustment of Collected Personal Information

The Company may entrust your personal information to external parties for processing in order to improve its services. 

- When entrusting the processing of personal information, the Company will notify you of such fact in advance. 

- When entrusting the processing of personal information, the Company will clearly stipulate, through an entrustment agreement, matters such as compliance with instructions regarding personal information protection, confidentiality of personal information, prohibition of provision to third parties, and liability in the event of an incident, and will retain the contents of such agreement in writing or electronically. 

- Entrusted party: [Name of courier company]

- Entrusted task: [Details entrusted to the courier company] e.g., delivery of goods

- Entrusted party: [Name of PG (payment gateway) company]

- Entrusted task: [Details entrusted to the PG company] e.g., purchases and payment of fees 

 

Rights of Users and Legal Guardians and How to Exercise Them

Users may at any time view or modify their registered personal information and may also request to cancel their membership. 

To view or modify personal information, users may click "Change Personal Information" (or "Edit Member Information," etc.), and to cancel membership (withdraw consent), users may click "Member Withdrawal" and, after undergoing an identity verification procedure, directly access, correct, or withdraw their information. 

Alternatively, if you contact the Personal Information Manager in writing, by telephone, or by email, the Company will take action without delay. 

If you request the correction of an error in your personal information, the Company will not use or provide the relevant personal information until the correction is completed. In addition, if the erroneous personal information has already been provided to a third party, the Company will notify the third party of the correction result without delay so that the correction can be made. 

The Company processes personal information that has been canceled or deleted at the user's request in accordance with the "Retention and Use Period of Personal Information Collected by the Company" and ensures that it cannot be viewed or used for any other purpose. 

 

Technical Measures for the Protection of Personal Information

In handling your personal information, the Company takes the following technical measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged. 

- Your personal information is protected by a password, and important data is protected through separate security functions by encrypting files and transmitted data or using file locking functions.

- The Company takes measures to prevent damage caused by computer viruses by using antivirus programs. Antivirus programs are updated periodically, and in the event of a sudden virus outbreak, the Company provides the vaccine as soon as it becomes available to prevent the infringement of personal information. 

- The Company employs security devices (SSL or SET) that use encryption algorithms to securely transmit personal information over the network. 

- To prevent your personal information from being leaked through hacking or other means, the Company uses devices that block intrusion from outside, and has installed an intrusion detection system on each server to monitor intrusions 24 hours a day. 

 

Matters Concerning the Installation and Operation of Automatic Personal Information Collection Devices and the Refusal Thereof

The Company operates "cookies" and similar technologies that store and retrieve your information from time to time. A cookie is a very small text file sent to your browser by the server used to operate the website and is stored on your computer's hard disk. 

The Company uses cookies for the following purposes. 

► Purposes of using cookies, etc. 

- To provide target marketing and personalized services by analyzing the access frequency and visit times of members and non-members, identifying and tracking users' preferences and interests, and determining the degree of participation in various events and the number of visits 

You have the option to choose whether to install cookies. Accordingly, by setting options in your web browser, you may allow all cookies, undergo confirmation each time a cookie is stored, or refuse the storage of all cookies. 

► How to refuse cookie settings 

e.g., To refuse cookie settings, you may, by selecting the options of the web browser you use, allow all cookies, undergo confirmation each time a cookie is stored, or refuse the storage of all cookies. 

Example of how to set (in the case of Internet Explorer) 

: Tools at the top of the web browser > Internet Options > Privacy 

However, if you refuse the installation of cookies, you may experience difficulties in receiving services. 

 

Grievance Services Related to Personal Information

In order to protect customers' personal information and handle complaints related to personal information, the Company has designated the relevant department and Personal Information Manager as follows.

Personal Information Manager Name: [Manager Name]

Telephone Number: 031-689-4567

Email: admin@actro.co.kr

You may report any personal information protection grievances arising from your use of the Company's services to the Personal Information Manager or the responsible department. The Company will promptly provide a sufficient response to users' reports.

If you need to report or consult regarding other personal information infringements, please contact the agencies below.

1. Personal Information Dispute Mediation Committee (www.1336.or.kr / 1336)

2. Information Protection Mark Certification Committee (www.eprivacy.or.kr / 02-580-0533~4)

3. Internet Crime Investigation Center, Supreme Prosecutors' Office (http://icic.sppo.go.kr / 02-3480-3600)

4. Cyber Terror Response Center, National Police Agency (www.ctrc.go.kr / 02-392-0330)