Privacy Policy

Privacy Policy

'Kaesung Technologies, Inc.' (hereinafter referred to as the 'Company') values the personal information of data subjects and complies with personal information protection regulations under relevant laws such as the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Protection of Communications Secrets Act, and the Telecommunications Business Act. The Company will lawfully and appropriately handle personal information collected, retained, and processed in accordance with relevant laws and regulations to ensure the proper execution of business and to protect the rights and interests of data subjects.
This policy takes effect on: September 01, 2026.

Purpose of Processing Personal Information

The Company processes personal information for the following purposes. Processed personal information will not be used for purposes other than the following, and if the purpose of use changes, prior consent will be sought.

A. Receipt of Customer Feedback and Job Applications

The Company collects the minimum amount of personal information necessary for online inquiries. The specific purposes of processing are as follows:
- Securing communication channels to answer online inquiries or execute response services.

Items and Methods of Collecting Personal Information

A. Items of Personal Information Collected

First, the Company collects the following minimal personal information for customer feedback and job applications to provide services:
- Required items: Name, Email address, Mobile phone number
Second, the following information may be automatically generated and collected during the service use and processing phase:
- Access IP information, cookies, service usage records, access logs

B. Method of Collecting Personal Information

- Website > Online Inquiry > Directly entered by the customer

Processing and Retention Period of Personal Information

In principle, after the purpose of collecting and using personal information is achieved, the Company destroys the relevant information without delay. However, the following information is retained for the period specified below for the following reasons:
- Retained items: Name, Email address, Mobile phone number
- Grounds for retention: Internal management regulations of the Company
- Retention period: 2 years

Matters Concerning Provision of Personal Information to Third Parties

The Company uses the personal information of data subjects within the scope notified under the purpose of collection and use, and will not use it beyond the scope of purpose or provide it to external parties without prior consent of the data subject, in principle. However, exceptions are made in the following cases:
- When separate consent is obtained from the data subject
- When there are special provisions in law or it is unavoidable to comply with legal obligations
- When the data subject or their legal representative is unable to express their intent, or prior consent cannot be obtained due to an unknown address, and it is deemed clearly necessary for the urgent life, body, or property interests of the data subject or a third party
- In any of the following cases, personal information of the data subject may be used for purposes other than intended or provided to a third party, except when there is a risk of unreasonably infringing on the rights and interests of the data subject or a third party:
1) When provided in a form that cannot identify a specific individual for purposes such as statistics compilation and academic research
2) When necessary to carry out duties under other laws that cannot be performed without using personal information for purposes other than intended or providing it to a third party, following deliberation and resolution by the Personal Information Protection Commission
3) When necessary to provide to a foreign government or international organization to fulfill a treaty or other international agreement
4) When necessary for criminal investigation and prosecution and maintenance of public prosecution
- When necessary for the court to perform judicial tasks
- When necessary for the execution of criminal penalties, custody, or protective orders
- In the case of providing personal information to a third party, the Company will notify the data subject of information regarding the recipient third party, the third party's purpose of use, the items of personal information provided, and the recipient's retention and usage period.

Matters Concerning Destruction of Personal Information

In principle, after the purpose of collecting and using personal information is achieved, the Company destroys the relevant information without delay. The destruction procedures and methods are as follows:

A. Destruction Procedure

Information entered by users is transferred to a separate DB (in the case of paper, a separate filing cabinet) after the purpose is achieved, stored for a certain period according to internal policies and other information protection reasons under relevant laws (refer to retention and usage period), and then destroyed. Personal information transferred to a separate DB will not be used for purposes other than being retained unless required by law.

B. Destruction Method

- Personal information stored in electronic file format is deleted using technical methods that render records unrecoverable.
- Records, printed matters, documents, and other recording media other than electronic file format are destroyed through shredding or incineration.

Matters Concerning Delegation of Personal Information Processing

When concluding a delegation contract with a third party, the Company explicitly states in documents such as contracts matters concerning responsibilities such as prohibition of processing personal information outside the purpose of performing delegated tasks, technical and managerial protection measures, restrictions on re-delegation, management and supervision of trustees, and compensation for damages in accordance with Article 25 of the Personal Information Protection Act, and supervises whether the trustee safely processes personal information.
The Company's entrusted personal information processing agencies and the details of entrusted tasks are as follows:

A. Entrusted Processing Agency and Details of Entrusted Tasks / Reason for Storage

- Agency: CMania
- Reason for storage: System development and maintenance

Matters Concerning Measures to Ensure the Safety of Personal Information

In handling the personal information of data subjects, the Company takes the following measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged:

A. Establishment and Implementation of Internal Management Plan

The Company establishes and implements an internal management plan in accordance with the 'Standards for Measures to Ensure the Safety of Personal Information'.

B. Minimization and Education of Personnel Handling Personal Information

The Company limits employees handling personal information to designated personnel, assigns separate passwords that are regularly updated, and emphasizes compliance with the privacy policy through frequent training for personnel.

C. Restriction of Access to Personal Information

The Company takes necessary measures to control access to personal information by granting, changing, and canceling access rights to database systems that process personal information, and uses a Virtual Private Network (VPN) when personal information handlers access the personal information processing system from outside via information and communications networks.

D. Retention of Access Logs and Prevention of Forgery/Falsification

The Company retains and manages records of access to the personal information processing system (web logs, etc.) for at least one year, and uses security functions to prevent access logs from being forged, falsified, stolen, or lost.

E. Encryption of Personal Information

The personal information of data subjects is encrypted, stored, and managed. In addition, critical data is protected using separate security features, such as being encrypted during storage and transmission.

F. Measures Against Hacking and Cyber Threats

1) The Company does its best to prevent members' personal information from being leaked or damaged by hacking or computer viruses.
2) Data is backed up frequently in preparation for damage to personal information, and the latest antivirus programs are used to prevent leakage or damage to personal information or data of data subjects. Personal information is safely transmitted on networks through encrypted communications, etc.
3) In addition, unauthorized access from the outside is controlled using intrusion prevention systems, and the Company strives to equip all possible technical devices to secure systemic security.

G. Access Control for Unauthorized Persons

The Company maintains a separate physical storage location for personal information systems containing personal information and establishes and operates access control procedures.

H. Encryption of Passwords

Passwords are encrypted, stored, and managed, so only the data subject knows them. Checking and modifying personal information can only be done by the data subject who knows the password.

I. Operation of Personal Information Protection Organization

Through the in-house personal information protection organization, the Company verifies the implementation of the Privacy Policy and compliance of personnel, striving to immediately correct and rectify any issues found.
However, the Company assumes no liability for issues caused by the leakage of personal information, such as ID, password, or resident registration number, due to the data subject's own negligence or internet environment issues.

Matters Concerning Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

The Company currently does not operate devices that automatically collect personal information generated when using services, such as cookies. However, if necessary to provide services in the future, automatic collection devices may be installed and operated, in which case data subjects can choose to allow cookie installation or refuse to store all cookies.

A. What are Cookies?

The Company uses 'cookies' to store and frequently retrieve user information in order to provide personalized and customized services. Cookies are very small text files sent by the server used to operate a website to the user's browser and stored on the user's computer hard disk. When the data subject visits the website later, the website server reads the content of the cookies stored on the hard disk to maintain settings and provide customized services. Cookies do not automatically/actively collect personally identifiable information, and data subjects can refuse to store or delete these cookies at any time.

B. Purpose of Cookie Usage by the Company

Currently, the Company does not use cookies. However, they may be used in the future to maintain environment settings for data subjects and provide customized services.

C. Installation, Operation, and Refusal of Cookies

Data subjects have the option regarding cookie installation. Therefore, data subjects can allow all cookies, go through confirmation each time a cookie is saved, or refuse to save all cookies by adjusting options in their web browser. However, if cookie storage is refused, services that require login may be difficult to use. The method to specify whether to allow cookie installation (for Internet Explorer) is as follows:
1) Select [Internet Options] from the [Tools] menu.
2) Click the [Privacy tab].
3) Set the [Privacy Level].

Matters Concerning Rights and Obligations of Data Subjects and Methods of Exercise, Including Rights to Access, Correct, Delete, and Suspend Processing

Users may request to inspect, correct errors in, or delete their personal information held by the Company at any time, and the Company is obligated to take necessary measures in response. When a user requests correction of an error, the relevant personal information will not be used until the error is corrected. Furthermore, customer information that has been deleted following a deletion request will no longer be stored. Deletion requests can be made via email, fax, or telephone.
Data subjects may exercise the following rights:

A. Request to Access Personal Information

Data subjects may request access to their personal information held by the Company at any time pursuant to Article 35 (Access to Personal Information) of the Personal Information Protection Act. However, the Company may restrict access in the following cases:
1) When access is prohibited or restricted by law
2) When there is a risk of harming the life or body of another person, or unreasonably infringing on the property and other interests of another person

B. Request to Correct or Delete Personal Information

Data subjects may request correction or deletion of their personal information held by the Company in accordance with Article 36 (Correction and Deletion of Personal Information) of the Personal Information Protection Act. However, if the personal information is specified as a collection target under other laws, deletion cannot be requested.

C. Request to Suspend Processing of Personal Information

Data subjects may request suspension of processing of their personal information held by the Company in accordance with Article 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act. However, requests to suspend processing may be refused in the following cases:
- When there are special provisions in law or it is unavoidable to comply with legal obligations
- When there is a risk of harming the life or body of another person, or unreasonably infringing on the property and other interests of another person
- When it is difficult to perform a contract, such as being unable to provide services agreed upon with the data subject without processing personal information, and the data subject has not clearly expressed their intent to terminate the contract

D. Others

1) If a data subject requests correction or deletion of errors in personal information, the personal information will not be used or provided until correction or deletion is completed. In addition, if incorrect personal information has already been provided to a third party, the result of correction or deletion will be notified to the third party without delay so that correction can be made.
2) Personal information terminated or deleted at the request of a data subject or legal representative is handled in accordance with what is specified in the retention and usage period of personal information, and processed so that it cannot be accessed or used for other purposes.

Matters Concerning Amendments to the Privacy Policy

The Company maintains the following privacy policy to protect the personal information and rights/interests of data subjects in accordance with relevant laws and smoothly address grievances related to personal information. When revising the privacy policy, notification will be provided through website announcements (or individual notices).

Matters Concerning Personal Information Protection Officer

The Company designates relevant departments and a personal information management officer as follows to protect customer personal information and handle complaints related to personal information:

  • Chief Privacy Officer (CPO)

    - Gildong Hong
    - Tel : 051.831.4545
    - Email : sales@ksmag.co.kr

  • Privacy Manager

    - Gildong Hong
    - Tel : 051.831.4545
    - Email : sales@ksmag.co.kr

  • Privacy Staff

    - Gildong Hong
    - Tel : 051.831.4545
    - Email : sales@ksmag.co.kr


You may report all complaints related to personal information protection arising from using the Company's services to the personal information management officer or the responsible department. The Company will promptly provide sufficient answers to users' reports.

Department for Receiving and Processing Requests for Access to Personal Information

Data subjects may submit requests for access to personal information under Article 35 of the Personal Information Protection Act to the department below. The Company will strive to ensure that requests for access to personal information are processed promptly.
Department for receiving and processing personal information access requests (limited to cases where access requests for personal information collected during customer feedback and job applications are needed)

Contact Person Tel Email
Gildong Hong 051.831.4545 sales@ksmag.co.kr


Remedies for Infringement of Rights and Interests of Data Subjects

If you need to report or consult about other personal information infringements, please contact the following agencies:
- Personal Information Dispute Mediation Committee (www.1336.or.kr, Tel: 1336)
- Information Security Mark Certification Committee (www.eprivacy.or.kr, Tel: 02-580-0533~4)
- Cybercrime Investigation Unit, Supreme Prosecutors' Office (http://www.spo.go.kr, Tel: 02-3480-3573)
- Cyber Bureau, National Police Agency (https://cyberbureau.police.go.kr/, Tel: 02-392-0330)
CMANIA