Data Alliance Co., Ltd. (hereinafter the "Company") values the protection of personal information of users of the gcube service operated by the Company (https://console.gcube.ai, hereinafter the "Service"). To protect users' personal information, the Company complies with all laws and regulations related to personal information protection, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, and has established and complies with this Privacy Policy. The Company discloses this policy on its website so that users can easily access it at any time, and does its utmost to protect consumer rights and interests.
This Privacy Policy will be updated when there are changes to laws or guidelines related to personal information, and may change according to changes in service policy, so please check it regularly when visiting.
1. Collection and Use of Personal Information
A. The purpose for which the Company collects personal information is to verify the identity of users and their intention to use the Service, in order to provide optimized and customized services. At initial member registration, the Company collects only the minimum information strictly necessary to perform the essential functions of the Service, and may additionally collect information necessary for payment, delivery of goods, and refunds in connection with use of the services provided by the Company.
B. The Company does not use personal information for purposes other than the stated purposes of collection and use, nor does it provide such information to third parties without the user's consent.
C. The Company may collect and use personal information for the following purposes. However, where the collection and retention of resident registration numbers and bank account numbers is unavoidable under relevant laws — such as the Act on Consumer Protection in Electronic Commerce, the Framework Act on National Taxes, the Electronic Financial Transactions Act, and the Act on Reporting and Using Specified Financial Transaction Information — the Company may collect such information after notifying the user.
1) Suppliers / Consumers
2) Affiliated services
Where the Company additionally collects personal information through affiliates for the purpose of providing affiliated services, it does so after obtaining the user's separate consent.
3) Other
In the course of using the Service or processing business, the following information may be automatically generated and collected, stored, combined, and analyzed:
- Service usage records (IP address, cookies, date and time of visit, etc.) and usage-history information: prevention of fraudulent use, prevention of unauthorized use, development of new services, provision of customized services, etc.
D. When collecting users' personal information, the Company obtains the user's consent unless there is a legal basis otherwise, and does not collect information that may infringe fundamental human rights
- such as race, place of origin, place of family registry, ideology, political orientation, criminal records, or health status — except with the user's consent or as required by law.
E. The Company allows anyone to register as a member; however, as a rule, the Company does not collect personal information of minors under the age of 19, for whom consent of a legal representative is required for the collection and use of personal information. Where the consent of a legal representative has been obtained, the Company may collect and use the personal information of users under the age of 19.
F. The Company may collect personal information by the following methods:
1) Website, mobile application, mobile web page, written form, fax, telephone, customer center inquiries, event participation
2) Automatic collection through generated-information collection tools
G. In collecting personal information, the Company provides a procedure for consenting to personal information necessary for service provision as "mandatory consent items." The Company may refuse to provide the Service if the user does not consent to providing the personal information necessary for the Service.2. Provision of Personal Information to Third Parties
A. In principle, the Company provides users' personal information to external parties only with the user's prior consent. However, the following cases are exceptions:
1) Where required by law, or where there is a request from investigative agencies or supervisory authorities in accordance with the procedures and methods prescribed by law for investigation or inspection purposes
2) Where necessary for the settlement of usage fees
3) Where it is necessary for the urgent protection of the life, body, or property interests of the user or a third party, but consent cannot be obtained
B. In principle, the Company uses personal information or provides it to third parties within the scope notified under "Collection and Use of Personal Information," and does not use it beyond that scope or provide it to third parties. However, the following cases are exceptions:
1) Where users have consented in advance to disclosure or provision to third parties
2) Where required by law, or where there is a request from investigative agencies or supervisory authorities in accordance with the procedures and methods prescribed by law for investigation or inspection purposes
C. In other cases where the provision of personal information to third parties is necessary, the Company may provide personal information to third parties through lawful procedures, such as obtaining the user's consent. Where necessary for the performance of users' transactions, the Company may provide personal information as follows through lawful procedures, such as obtaining the user's consent:
※ However, where retention is required under the provisions of relevant laws, information may be retained for the applicable retention period.
D. Users may withhold consent to the provision of personal information to third parties and may withdraw such consent at any time. Even if consent is refused, the member registration service remains available; however, use or provision of related services based on third-party provision may be restricted. Any changes regarding the provision of personal information to third parties will be announced or separately notified.3. Outsourcing of Personal Information Processing (in connection with PG providers)
A. The Company may outsource the processing of personal information to others in order to provide smooth and improved services. In such cases, the Company notifies users of all of the following matters in advance and obtains consent. The same applies where any of the following matters changes:
1) The party entrusted with the processing of personal information
2) The details of the work for which personal information processing is outsourced
B. Where necessary for the performance of contracts regarding the provision of information and communications services and for the enhancement of user convenience, the Company may outsource personal information processing to others without going through the notification and consent procedures, by disclosing the matters in each item of Paragraph (a) in accordance with the Privacy Policy.
C. The Company outsources work related to the processing of personal information as follows, and takes necessary measures in accordance with relevant laws so that personal information can be safely managed at the time of outsourcing contracts. At the time of an outsourcing contract, the Company considers the trustee's capability for personal information protection measures and periodically verifies the trustee's performance of obligations, such as safe management and destruction of personal information. The information processed under outsourcing is limited to the minimum necessary to provide smooth services.
1) Status of domestic outsourcing of personal information processing
4. Retention of Users' Personal Information: Use Period and Destruction
In principle, the Company retains and uses users' personal information during the notified and agreed period, and destroys it without delay when the purpose of collection and use of personal information has been achieved or when the user requests destruction. However, the following information is retained for the specified periods for the reasons stated below.
A. Grounds for information retention under relevant laws and Company policy.
Where retention is required under the provisions of relevant laws such as the Commercial Act, the Company retains users' personal information as prescribed by such laws and does not use it for other purposes such
1) Grounds for information retention under relevant laws
2) Grounds for information retention under Company policy
• Records of fraudulent transactions
• Reason for retention: exclusion of fraudulent transactions
• Retention period: 5 years
• Retained items: name, ID (email), CI/DI, mobile phone number, email address, date of birth
• Fraudulent transaction: a transaction whose method or content violates laws, the terms of service between the Company and the user, or public order and good morals, or otherwise infringes the rights or interests of the Company, members, or others.
B. The retention and use period of collected personal information runs from the conclusion of the service use agreement (member registration) until termination of the service use agreement (including withdrawal applications and ex officio withdrawal). Upon withdrawal of consent, the Company destroys the user's personal information without delay, except for data stored for a certain period pursuant to the retention grounds specified above, and where personal information processing has been outsourced to a third party, the Company instructs the trustee to destroy it as well.
C. From October 1, 2024, for users who have not used the Company's services for one year, the Company will, based on Article 39-6 of the Personal Information Protection Act, notify the user in advance and destroy the personal information or store it separately. However, where retention is required under the provisions of relevant laws such as the Protection of Communications Secrets Act and the Act on Consumer Protection in Electronic Commerce, the Company retains users' personal information for the specific period prescribed by such laws.
D. No later than 30 days before the expiration of the period under Paragraph (c), the Company notifies the user
— by means such as announcements or email — of the fact that the personal information will be destroyed or separately stored and managed, the expiration date of the period, and the items of personal information concerned. For this purpose, users must provide and update accurate contact information with the Company.
E. Method of destruction. Users' personal information is destroyed without delay after the purpose of collection and use has been achieved. Personal information printed on paper is destroyed by shredding or incineration, and personal information stored in electronic file format is destroyed using technical or physical methods that make the records unrecoverable.
5. Operation and Refusal of Cookies
A. Purpose of using cookies
1) The Company uses "cookies," which store usage information, in order to provide personalized services on the internet sites operated by the Company. A cookie is a small amount of information that a website server sends to the user's browser and is stored on the hard disk of the user's computer.
2) The Company can provide specific customized services that are only possible through the use of cookies.
3) The Company may use cookies to identify members and maintain members' login status.
B. Installation/operation and refusal of cookies
1) Users have the right to choose whether cookies are installed. Accordingly, by adjusting options in the web browser, users may allow all cookies, refuse all cookies, or require confirmation each time a cookie is saved.
2) Example of how to refuse cookie storage (for Internet Explorer): Tools at the top of the web browser > Internet Options > Privacy. If you refuse the storage of cookies, some services provided by the Company, such as personalized services, may be difficult to use.
6. Rights of Users and Legal Representatives
A. Users and legal representatives may at any time view and correct their personal information through "Edit Information" on the relevant site, and if requested by email or in writing, the Company will process viewing, correction, or deletion. Where a user's personal information has been provided to a third party or its processing has been outsourced, the user may request destruction from the Company or from the "third party"/"trustee." However, the member ID (email) and name cannot be corrected; exceptions may be permitted for name changes due to legal name change and for changes to resident (business) registration numbers due to administrative issues. Where correction or deletion is prohibited or restricted under other laws, such processing may be restricted. In addition, where a correction of an error in personal information has been requested, the Company will not use or provide the relevant personal information until the correction is completed, unless provision of the personal information is requested under other laws. If incorrect personal information has already been provided, the Company will notify the third party of the correction result so that the correction is carried out.
B. Users and legal representatives may at any time request suspension of processing of their personal information in the Service. However, the request for suspension of processing may be refused in the following cases:
1) Where there are special provisions in law, or where it is unavoidable in order to comply with legal obligations
2) Where there is a risk of harming another person's life or body, or of unjustly infringing another person's property or other interests
3) Where it would be difficult to perform the contract, such as being unable to provide the service agreed with the data subject, if the personal information is not processed, and the data subject has not clearly expressed an intention to terminate the contract
C. You may at any time withdraw the consent you have given to the collection, use, and provision of personal information through member registration and the like. To withdraw consent, click "Withdraw Membership" on the Company's site, or contact us in writing or by email, and we will take necessary measures such as deletion of personal information without delay. However, where the Company is required to retain your personal information under laws or the provisions of the Terms, such processing may be restricted. In this case, you must state your member ID (email) and identity-verification information for identification purposes, and withdrawal may result in some restrictions on the Service or the inability to use some services.
7. Obligations of Users
Users have an obligation to protect their own personal information. The Company shall not be liable for problems arising from the leakage of personal information — absent fault on the part of the Company — caused by the user's own carelessness, such as the transfer, lending, or loss of the ID (email), password, or access media, or leaving the seat while logged in, or by problems on the internet that the Company cannot control despite exercising considerable care, such as hacking using methods or technologies that cannot be blocked by security measures under relevant laws.
A. Users must keep their personal information up to date, and responsibility for problems arising from users' entry of inaccurate information rests with the users themselves.
B. Registering as a member using another person's personal information, or processing payments using a misappropriated ID (email) or the like, may result in loss of user qualification and punishment under relevant laws.
C. Users are responsible for maintaining the security of their ID (email), password, etc., and may not transfer or lend them to third parties. Users have an obligation to cooperate with periodic password changes for security in accordance with the Company's personal information protection policy.
D. After using the Company's services, users must log out of their account and close the web browser program.
E. Users must comply with laws related to personal information, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Personal Information Protection Act, and the Resident Registration Act.
8. Responsibility for Linked Sites
The Company may provide users with links to other websites. However, this Privacy Policy does not apply to the collection of personal information by linked websites.
9. Technical and Administrative Safeguards for Personal Information
In processing users' personal information, the Company takes the following technical and administrative protective measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged.
A. Establishment and implementation of an internal management plan.
The Company establishes and implements an internal management plan for personal information so that users' personal information can be safely managed and protected.
B. Encryption of personal information.
Users' personal information is stored and managed with one-way encryption, and personal information such as names, bank account numbers, and credit card numbers is encrypted with secure cryptographic algorithms for storage and management.
C. Countermeasures against hacking and the like.
To prevent the leakage of users' personal information through intrusion into the Company's information and communications network, such as hacking, the Company operates intrusion detection and intrusion prevention systems 24 hours a day. To prepare for contingencies, all intrusion detection systems and intrusion prevention systems are configured and operated redundantly, and sensitive personal information is transmitted safely over the network through encrypted communications and the like.
D. Minimization and training of personal information handlers.
The Company limits its personal information handlers to a minimum, and raises awareness of the importance of personal information protection through administrative measures such as training for personal information handlers.
E. Operation of a dedicated personal information protection unit.
For the efficient protection of personal information, the Company verifies implementation of the Privacy Policy and compliance by personal information handlers, and strives to correct any problems immediately upon discovery.
F. Retention of access records and prevention of forgery/alteration.
The Company securely retains and manages records of personal information handlers' access to the personal information processing system, and periodically inspects access records to prevent forgery, alteration, or loss of such records.
10. Chief Privacy Officer
The Company does its utmost so that users can use the Company's services safely. Users may report all personal-information-protection complaints related to use of the Company's services, and the Company responds promptly and faithfully to users' reports.
Chief Privacy Officer
Lee Gwang-beom, CEO
Email
@data-alliance.com
Phone
02-6354-3282
※ If you need to report or consult on other personal information infringements, please contact the following organizations:
• Personal Information Dispute Mediation Committee/www.kopico.go.kr/1833-6972
• Personal Information Infringement Report Center /privacy.kisa.or.kr/(국번없이) 118
• Supreme Prosecutors' Office, Cybercrime Investigation Center/www.spo.go.kr/(국번없이) 1301
• National Police Agency, Cyber Safety Bureau/ https://ecrm.police.go.kr/minwon/main/(국번없이)182
11. Duty of Notification
The contents of this Privacy Policy may be added to, deleted, or amended due to changes in relevant laws and guidelines or the Company's needs. In such cases, the Company will give prior notice at least 7 days in advance through the website or by email; where prior notice is difficult, notice will be given without delay, and unless otherwise announced, the change takes effect 7 days after the notice. However, where material contents are changed, notice will be given at least 30 days in advance, and unless otherwise announced, the change takes effect 30 days after the notice. The Company may also obtain the customer's separate consent where necessary under relevant laws.
Effective date: October 1, 2024