privacy
-
1. Collected Personal Information Items and Collection Methods
-
The personal information collected by the company through the website is as follows:
-
A. Personal Information Items Collected : Name and Email Address
B. Scope of Personal Information That May Be Collected During Service Use and Business Processing : Name and Email Address C. Collection Method : Collected through direct input by the customer after obtaining their consent to the collection of personal information items.
SWARMX's website complies with personal information protection regulations under the relevant laws, including the Personal Information Protection Act, and establishes and discloses the following Privacy Policy in accordance with Article 30 of the Personal Information Protection Act. This Privacy Policy applies from the effective date, and if there are any additions, deletions, or corrections due to changes in laws or policies, the changes will be announced at least 7 days before the implementation through a notice.
-
2. Purpose of Personal Information Collection and Use
-
The company collects and uses customers' personal information within the minimum necessary scope for the following purposes. The collected personal information will not be used for purposes other than those specified below, and if the purpose of use changes, prior consent will be obtained.
-
- Name and Email Address
Used for identity verification, handling inquiries and complaints, verifying customer requests, conducting fact-checking and notifications, providing responses to customers, and informing them about processing results.
-
3. Retention and Disposal of Personal Information
-
(1) The company will dispose of personal information when the purpose of collection and use has been achieved, when the agreed retention and usage period has expired, or when the customer withdraws consent for the collection of their personal information.
(2) If a customer does not use the company's services for 3 years (or a different period specified by applicable laws or requested by the customer), the company will either dispose of the customer's personal information immediately or store and manage it separately from other customers' personal information. In such cases, the company will notify the customer via email, written notice, phone, or a similar method at least 30 days before the retention period expires, informing them of the impending disposal or separate storage, the expiration date, and the specific personal information involved.
(3) Notwithstanding the above provisions, if the company is required by relevant laws and regulations to retain certain personal information for a specified period, it may retain all or part of the collected personal information for that period as an exception.
-
4. Provision of Personal Information to Third Parties
-
The company does not provide customers' personal information to external parties as a general rule. However, the following exceptions apply:
-
(1) When a customer's inquiry or complaint is related to SWARMX, the company may provide the customer's personal information to the relevant affiliated company to ensure a smooth service experience. In such cases, prior consent will be obtained from the customer.
(2) When required by law or requested by investigative authorities in accordance with legally prescribed procedures and methods for investigation purposes, the company may provide the customer’s personal information to the relevant authorities without prior consent.
-
5. Outsourcing of Personal Information Processing
-
(1) To ensure the proper execution of its services, the company entrusts the handling of personal information to external professional firms as follows:
- Entrusted Party : 000
- Scope of Entrusted Services : System operation outsourcing for service provision and collection of personal information
(2) When entering into an outsourcing contract, the company strictly complies with Article 26 of the Personal Information Protection Act stipulating in written agreements that the entrusted party: Is prohibited from processing personal information beyond the scope of the outsourced task Must implement technical and administrative security measures Cannot re-entrust the work without prior approval Will be monitored and supervised by the company, Bears responsibility for damages caused by mishandling of personal information
If any changes occur regarding the content of the outsourced work or the entrusted party, the company will promptly disclose such changes through this Privacy Policy.
-
6. Rights of Data Subjects and Methods of Exercise
-
(1) Customers may exercise the following rights regarding their personal information at any time:
- Request to access personal information
- Request correction if there are errors
- Request deletion
- Request suspension of processing
(2) Customers can exercise these rights via email or phone, and the company will take immediate action upon request.
(3) If a customer requests correction or deletion of their personal information due to errors, the company will not use or provide the relevant personal information until the correction or deletion is completed.
(4) Customers may also exercise these rights through a legal representative or an authorized agent. In such cases, a power of attorney must be submitted in accordance with Form No. 11 of the Enforcement Rules of the Personal Information Protection Act.
(5) Customers must not infringe on their own or others’ personal information or privacy by violating the Personal Information Protection Act or other applicable laws.
-
7. Personal Information Disposal Procedures and Methods
-
The company, in principle, immediately disposes of personal information once the purpose of its processing has been achieved. The procedures, deadlines, and methods for disposal are as follows:
(1) Disposal Procedure
Information entered by the customer is transferred to a separate database (DB) (or stored separately in paper form for physical documents) after the purpose has been fulfilled. It is retained for a certain period in accordance with internal policies and relevant laws before being permanently deleted or immediately disposed of. Personal information transferred to the DB will not be used for any other purpose unless required by law.
(2) Disposal Deadline
Customer-provided information is stored for a specified period in a separate database (or as separate documents for physical copies) after the purpose of use has been achieved, in accordance with internal policies and applicable laws. It is then permanently deleted or immediately disposed of. Any information moved to a separate database will not be used for any other purpose unless legally required.
(3) Disposal Methods
- For electronic files: Data is permanently erased using technical methods that prevent restoration.
- For printed documents: Personal information is shredded or incinerated to ensure complete destruction.
-
8. Measures to Ensure the Security of Personal Information
-
The company has established and implemented an internal management plan to ensure the secure handling of personal information.
(1) Establishment and Implementation of Internal Management Plan
An internal management plan has been developed and implemented to ensure the safe processing of personal information.
(2) Encryption of Personal Information
Customers' personal information is encrypted during storage and transmission, or file-lock functions are used Critical data is further protected through additional security measures.
(3) Minimization and Training of Personnel Handling Personal Information
The company restricts the number of personnel handling personal information to the minimum necessary. Employees responsible for handling personal information undergo regular and on-the-spot training to ensure security compliance.
-
9. Cookie Usage Policy
-
The company handles cookie usage as follows :
- This website does not collect or use cookies.
-
10. Personal Information Management Officer
-
(1) The company takes full responsibility for personal information processing and has designated a Personal Information Protection Officer to handle customer complaints and remedial actions related to personal information processing.
Personal Information Management Officer Information
Personal Information Management Department
Department :
Phone Number :
Email :
(2) Customers may contact the Personal Information Protection Officer or the relevant department for any inquiries, complaints, or remedial actions related to personal information protection while using the company's services (or business). The company will respond without delay and take appropriate action.
-
11. Consultation and Reporting of Personal Information Infringement
-
If customers need to consult or report a case of personal information infringement, they may contact the company's Personal Information Protection Officer or relevant department. Additionally, they may reach out to the following organizations:
Personal Information Protection Support Portal : www.privacy.co.kr (02-2100-3394)
Personal Information Infringement Report Center : www.118.or.kr (Dial 118 (toll-free))
Supreme Prosecutors' Office Cybercrime Investigation Division : www.spo.go.kr (02 - 3480 - 3571)
National Police Agency Cyber Terror Response Center : www.ctrc.go.kr (1566 - 0112)
-
12. Duty of Notification
-
This Privacy Policy is effective from the date of implementation. If there are any additions, deletions, or modifications due to changes in laws or company policies, the company will notify customers at least 7days prior to the implementation of the changes through a public notice.