iFA Inc. (hereinafter 'the Company') values users' personal information and complies with the personal information protection provisions of laws and regulations including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection.
The Company distinguishes between mandatory information for providing basic services such as financial planning consultations, job applications, and various services, and optional information for providing customized services, and collects, retains, and processes the minimum personal information necessary for the performance of its duties.
Through this Privacy Policy, we inform you of how the personal information you provide is used, for what purposes, and how it is managed and protected.
[Article 1] Items of Personal Information Collected and Purpose of Processing
Users may use the website without any separate procedures. However, additional personal information may be collected during the use of the following services.
- 1. For personal consultation requests
Required: name, date of birth, mobile phone number, gender, email address
Optional: area of residence
- 2. For corporate consultation requests
Required: company name, contact person's name, mobile phone number, email address
Optional: industry, region, position, number of people
- For recruitment inquiries
- For job applications
Photo, field of application, name, resident registration number, mobile phone number, gender, marital status, address, email address, certifications, education, employer, tenure, position/duties
- 5. For event entries
Required: name, date of birth, mobile phone number, gender, email address
- 6. For customer center inquiries
Required: name, mobile phone number, email address
Sensitive personal information that may infringe upon the basic human rights of data subjects (race, ideology, political orientation, criminal records, medical information, etc.) is not collected.
However, service usage records such as IP addresses, cookies, visit dates and times, improper usage logs, and device information may be automatically generated during the use of services.
[Article 2] Methods of Collecting Personal Information
The minimum personal information is collected directly from users through methods including completing consultation request forms on the website, insurance contract applications, job application forms, service use, event entries, and collection through data generation frameworks. Personal information may also be collected in writing at offline events and seminars.
[Article 3] Processing and Retention Period of Personal Information
The Company retains and uses users' personal information only for the period during which services are provided. When consent to the collection and use of personal information is withdrawn, or when the purpose of collection and use has been achieved or the retention and use period has expired, the relevant personal information will be destroyed without delay.
However, the following information will be retained for the specified period for the reasons stated below.
Retained items: name, date of birth, gender, home address, mobile phone number, resident registration number
Legal basis: prevention of service use confusion, cooperation with relevant authorities for investigation of illegal users, preparation for disputes and investigation cooperation requests related to reports/consultations (Personal Information Protection Act)
Retention period: 5 years
In addition, where retention is required under applicable laws and regulations, the Company retains user information for the periods prescribed by such laws as follows.
Retained items: service use records, access logs, access IP information Legal basis: Communications Privacy Protection Act Retention period: 3 months Records of labeling/advertising: 6 months (Act on Consumer Protection in Electronic Commerce, etc.)
[Article 4] Provision of Personal Information to Third Parties
In principle, the Company processes personal information of data subjects within the scope specified for collection and use purposes, and does not process it beyond the original purpose or provide it to third parties without the prior consent of the data subject, except in cases prescribed by Article 18, Paragraph 2 of the Personal Information Protection Act.
- (1) Where separate consent has been obtained from the data subject
- (2) Where there are special provisions in other laws
- (3) Where the data subject or their legal representative is unable to express their intent, or prior consent cannot be obtained due to unknown address, etc., and it is clearly necessary for the urgent interests of the life, body, or property of the data subject or a third party
- (4) Where personal information is provided in a form that does not identify a specific individual, for purposes such as statistics compilation or academic research
- (5) Where other duties prescribed by law cannot be performed without using personal information for purposes other than the original purpose or providing it to a third party, and the matter has been deliberated and resolved by the Protection Committee
- (6) Where it is necessary to provide information to a foreign government or international organization for the implementation of treaties or other international agreements
- (7) Where it is necessary for the investigation of crimes and the filing and maintenance of prosecution
- (8) Where it is necessary for the court to perform its judicial duties
- (9) Where it is necessary for the execution of sentences, custody, and protective measures
[Article 5] Entrustment of Personal Information Processing
In principle, the Company does not entrust the processing of personal information to others without the consent of the data subject.
[Article 6] Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Such Rights
- 1. Data subjects may exercise the following rights related to the protection of personal information at any time.
- Request for access to personal information
- (2) Request for correction in case of errors, etc.
- Request for deletion
- Request for suspension of processing
- 2. The rights under Paragraph 1 may be exercised by contacting the Company in writing, by phone, email, fax, etc., and the Company will take action without delay.
- 3. When a data subject requests correction or deletion of errors in personal information, the Company will not use or provide such personal information until the correction or deletion is completed.
- 4. The rights under Paragraph 1 may be exercised through a legal representative or an authorized agent of the data subject. In such cases, a power of attorney in the form prescribed by Attached Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
- 5. Data subjects shall not infringe upon their own or others' personal information or privacy being processed by the Company in violation of the Personal Information Protection Act and other applicable laws.
- 6. When a data subject wishes to request access to their personal information, they must submit a personal information access request form indicating the items they wish to access among the following:
- (1) Items and content of personal information
- (2) Purpose of collection and use of personal information
- (3) Retention and use period of personal information
- (4) Status of provision of personal information to third parties
- (5) Facts and details of consent to processing of personal information
- 7. When a data subject wishes to request access to their personal information through the Minister of the Interior and Safety, they must submit a personal information access request form to the Minister, who shall forward the request to the Company without delay.
- 8. When a personal information processor receives a personal information access request form under Paragraph 6, it shall, within 10 days, notify the data subject via an access notification in the form prescribed by Attached Form No. 9, specifying the personal information to be accessed, and the date, time, and place of access. Where only partial access is granted, the reasons and methods of objection shall also be included.
- 9. A personal information processor may restrict access to certain items among the requested items, and shall allow access to the remaining items that are not restricted.
- 10. When a personal information processor intends to postpone or refuse a data subject's access request, it shall notify the data subject of the reasons for postponement or refusal and methods of objection via a postponement/refusal notification within 10 days of receiving the access request.
- 11. When a data subject wishes to request correction or deletion of their personal information, they must submit a personal information correction/deletion request form in the form prescribed by Attached Form No. 8 to the personal information processor.
- 12. A personal information processor that processes personal information files by receiving personal information from another personal information processor shall, upon receiving a correction or deletion request, either correct or delete the relevant personal information accordingly, or forward the correction/deletion request form to the head of the institution that provided the personal information without delay and take necessary measures based on the processing results.
- 13. When a personal information processor has taken corrective or deletion measures within 10 days of receiving the correction/deletion request form under Paragraph 12, it shall notify the data subject of such measures. Where it has not complied with a deletion request, it shall notify the data subject of the reasons and methods of objection via a correction/deletion result notification in the form prescribed by Attached Form No. 10.
- 14. When a data subject wishes to request suspension of processing of their personal information, they must submit a processing suspension request form in the form prescribed by Attached Form No. 8 to the personal information processor.
- 15. When a personal information processor has taken processing suspension measures within 10 days of receiving the processing suspension request form under Paragraph 14, it shall notify the data subject of such measures. Where it has not complied with the suspension request due to the proviso of the same paragraph, it shall notify the data subject of the reasons and methods of objection via a processing suspension result notification in the form prescribed by Attached Form No. 10.
[Article 7] Scope of representatives, etc.
- (1) Legal representative of the data subject
- (2) A person authorized by the data subject
[Article 8] Verification of data subjects or representatives
- 1. When a personal information processor receives a request for access, correction/deletion, or suspension of processing (hereinafter "access request, etc."), it shall verify whether the person making the request is the data subject themselves or a legitimate representative.
- 2. Where verification can be made through the shared use of administrative information, it shall be verified through such means. However, this shall not apply where the shared use of administrative information is not available or the data subject does not consent to the verification.
- 3. Where the person making the access request, etc. is the data subject themselves, they must present one of the following identification documents:
- Resident registration card
- Driver’s license
- Passport
- Public official ID
- (5) Other certificates officially recognized by administrative agencies that cannot be easily forged or misused
- 4. Where the person making the access request, etc. is a representative, they must present a power of attorney under Article 7, Paragraph 2 and an identification document proving the identity of the representative under Paragraph 3.
[Article 9] Destruction of Personal Information
The Company destroys personal information without delay in accordance with relevant laws upon expiration of the retention period and after the purpose of processing has been achieved.
- Destruction Procedure
Personal information is destroyed immediately after its purpose has been achieved, or transferred to a separate storage space and destroyed after a specified period in accordance with internal policies and applicable laws. Personal information transferred to separate storage is not used for any other purpose unless required by law.
- 2. Destruction deadline and methods
When personal information becomes unnecessary due to expiration of the retention period, achievement of the processing purpose, discontinuation of the relevant business, etc., it shall be destroyed without delay. Electronic file-format information is destroyed using technical methods that prevent the records from being reproduced. Personal information printed on paper is destroyed by shredding or incineration.
[Article 10] Measures to Ensure the Security of Personal Information
The Company has taken the following measures to ensure the security of personal information.
- 1. Establishment and implementation of internal management plans
The Company has established and implemented internal management plans in accordance with personal information protection laws for the safe processing of personal information.
- 2. Minimization and training of personnel handling personal information
Employees handling personal information are designated and managed to the minimum number necessary, and training on safe management is provided to such employees.
- 3. Restriction of access to personal information
Necessary measures for access control over personal information are taken through the granting, modification, and revocation of access rights to database systems that process personal information, and unauthorized external access is controlled.
- 4. Retention of access logs and prevention of forgery/alteration
Access logs to the personal information processing system (web logs, summary information, etc.) are retained and managed for a minimum of 6 months, and measures are taken to prevent forgery, alteration, theft, or loss of access logs.
- 5. Encryption of personal information
Personal information is securely stored and managed through encryption and other measures in accordance with the standards of personal information protection laws.
- 6. Installation and periodic inspection/update of security programs
Security programs are installed and periodically updated and inspected to prevent the leakage and damage of personal information caused by hacking or computer viruses.
- 7. Access control for unauthorized persons
Physical storage locations for personal information systems are maintained separately, and access control procedures for such locations have been established and are in operation.
[Article 11] Personal Information Protection Officer
Data Protection Officer
Name: Hyeonguk Lee
Title: Senior Managing Director
Data Protection Department Dept.: Compliance Team Tel: 02-2051-5281 Email: risk@ifa.co.kr
[Article 12] Remedies for Infringement of Rights
Data subjects may contact the following organizations for remedies, consultations, and other inquiries regarding personal information infringement.
Personal Information Infringement Report Center (operated by KISA)
Jurisdiction: reporting personal information infringement, consultation
Website: privacy.kisa.or.kr
Tel: 118 (no area code)
Address: (138-950) Personal Information Infringement Report Center, Korea Internet & Security Agency (KISA), 135 Jungdae-ro, Songpa-gu, Seoul
Personal Information Dispute Mediation Committee (operated by KISA)
Jurisdiction: personal information dispute mediation, collective dispute resolution (civil settlement)
Website: privacy.kisa.or.kr
Tel: 118 (no area code)
Address: (138-950) Personal Information Infringement Report Center, Korea Internet & Security Agency (KISA), 135 Jungdae-ro, Songpa-gu, Seoul
Supreme Prosecutors' Office Cybercrime Investigation Division: 02-3480-3573 (www.spo.go.kr) National Police Agency Cyber Terror Response Center: 1566-0112
[Article 13] Changes to the Privacy Policy
This Privacy Policy has been effective since November 1, 2016.