OORT Inc. (hereinafter "OHSOFT") establishes and discloses the following privacy policy pursuant to Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
OHSOFT processes personal information for the following purposes. Processed personal information is not used for any purpose other than those set out below, and if the purpose of use changes, OHSOFT will take the necessary measures, such as obtaining separate consent, pursuant to Article 18 of the Personal Information Protection Act.
OHSOFT verifies identity in connection with service use, handles inquiries and complaints, and delivers notices; member information may also be used for marketing and advertising. OHSOFT may provide guidance and notices regarding new products, services, personalized materials, and significant policy changes affecting its products.
OHSOFT processes and retains personal information within the retention and use period prescribed by law or the retention and use period consented to by the data subject.
The specific processing and retention periods are as follows:
OHSOFT processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only with the consent of the data subject or where Articles 17 and 18 of the Personal Information Protection Act apply.
OHSOFT does not currently provide personal information to any third party.
OHSOFT does not entrust personal information processing work to any third party. (However, in the case of payment systems operated through a PG company, processing is performed by that company.)
When concluding an entrustment agreement, OHSOFT specifies in the contract, pursuant to Article 26 of the Personal Information Protection Act, matters such as the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the entrustee, and liability for damages, and supervises the entrustee's safe handling of personal information.
If the content of the entrusted work or the entrustee changes, OHSOFT will disclose the change without delay through this privacy policy.
A data subject may at any time exercise rights against OHSOFT, such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information.
Such rights may be exercised in writing, by e-mail, by facsimile, or by similar means pursuant to Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and OHSOFT will act on such requests without delay.
Rights may be exercised through the data subject's legal representative or an authorized agent. In that case, a power of attorney in the form of Attachment No. 11 of the "Public Notice on Methods of Processing Personal Information (No. 2020-7)" must be submitted.
Requests for access to personal information and for suspension of processing may be restricted pursuant to Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
Deletion may not be requested for personal information whose collection is expressly required by other statutes.
When a request for access, correction, deletion, or suspension of processing is made, OHSOFT verifies whether the requester is the data subject in person or a duly authorized agent.
Where personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the purpose of processing, OHSOFT destroys the personal information without delay.
Where personal information must continue to be retained under other statutes, OHSOFT stores such personal information in a separate database or another storage location.
Destruction procedure: OHSOFT selects the personal information for which a cause for destruction has arisen and destroys it with the approval of the Chief Privacy Officer.
OHSOFT takes the following measures to ensure the security of personal information:
The company uses cookies, such as those for maintaining login sessions, in order to provide its services; these are automatically deleted when the browser is closed.
Cookie settings can be adjusted in the browser options, and refusing cookies may limit the use of some services.
The software provided communicates over the Internet for its normal operation. The communication functions are used for update checks, genuine-user authentication and registration, and license management. By installing the program, the user consents to the use of the communication functions provided by this software.
OHSOFT designates a Chief Privacy Officer who oversees personal information processing work and handles data subjects' complaints and remedies for damage. The officer is also responsible for receiving and handling requests for access to personal information pursuant to Article 35 of the Personal Information Protection Act.
Data subjects may direct inquiries, complaints, requests for remedy of damage, and requests for access to personal information arising in the course of using OHSOFT's services to the contact above, and OHSOFT will respond and act promptly.
To obtain relief from an infringement of personal information, a data subject may apply for dispute resolution or consultation to the following organizations:
Where a person's rights or interests are infringed by a disposition or omission of a public authority in respect of a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act, an administrative appeal may be filed under the Administrative Appeals Act. For details, please refer to the Central Administrative Appeals Commission (www.simpan.go.kr).