아이디의원 강남점 (the "Clinic") operates the id Clinic 강남점 website (the "Branch Site") and, in order to comply with the Personal Information Protection Act of Korea (PIPA) and other applicable laws and to safely protect users' personal information, establishes and discloses this Privacy Policy as follows.
This Policy applies to the processing of personal information through the Branch Site. Medical records generated and documented in the course of treatment after a visit are managed and retained separately in accordance with the Medical Service Act.
Article 1 (Purposes of Processing, Categories Collected, and Retention Periods)
The Clinic processes only the minimum personal information necessary for the following purposes.
| Purpose of Processing | Categories Collected | Retention and Use Period |
|---|---|---|
| Receiving online reservations, confirming and communicating reservations, and managing reservations | (Required) Name, mobile phone number or email, first visit/return visit status, reserved treatment item and preferred date and time, whether sedation is requested, identity verification value; (Optional, varies by site) Gender, nationality, date of birth, messenger type and ID, referral source, special requests | TODO(예: 3년) from the date of collection, or until a deletion request is made |
| Receiving and responding to online consultations | (Required) Name, mobile phone number (Korean site) or email (foreign-language sites); (Optional) Content of inquiry | TODO(예: 3년) from the date of collection, or until a deletion request is made |
| Identity verification (mobile phone SMS verification, email verification code) | Mobile phone number or email, verification result value | Until the purpose of verification is fulfilled |
| Service operation, security, and prevention of fraudulent use | Access IP address, access logs, device and browser information, date and time of consent | 3 months (Protection of Communications Secrets Act) |
※ The Clinic does not collect personal information from children under the age of 14 through the Branch Site. Reservation requests may only be made by persons aged 18 or older, and consultation and reservation requests for minors must be made by a legal guardian. ※ The Clinic does not collect resident registration numbers or sensitive information such as health information through the Branch Site. Treatment-related information, such as treatment history, is collected and managed separately after a visit in accordance with the Medical Service Act.
Article 2 (Methods of Collection)
- Information entered directly by users on the reservation request, consultation request, and reservation inquiry screens of the Branch Site
- Information collected during the identity verification process (SMS and email verification)
- Access logs, cookies, and similar data generated and collected automatically in the course of using the Services
Article 3 (Provision of Personal Information to Third Parties)
The Clinic processes users' personal information only within the scope disclosed in Article 1 and does not provide it to third parties except with the user's prior consent or as required by law.
For the handling of reservations and consultations, the Clinic provides personal information to third parties, with the user's consent, as follows:
| Recipient | Purpose of Provision | Categories Provided | Retention and Use Period |
|---|---|---|---|
| Affiliated medical institutions and entities: id Hospital, id Dental Clinic, id Dermatology Clinic, id Clinic, id Healthcare Co., Ltd., id Networks Co., Ltd. | Confirming and communicating reservations, and providing information on treatments and products, by telephone, text message, or messenger (SNS) | Name, contact details, reserved items | Until the purpose of provision is fulfilled or until the user requests deletion |
Article 4 (Outsourcing of Personal Information Processing)
To provide the Services smoothly, the Clinic outsources personal information processing tasks as follows, and when concluding outsourcing agreements, it stipulates the processor's personal information protection obligations and supervises the processor in accordance with Article 26 of the Personal Information Protection Act of Korea (PIPA).
| Processor | Outsourced Task | Retention and Use Period |
|---|---|---|
| (주)아이디네트웍스 | Operation of the integrated website (Hub Site) and the reservation system | Until termination of the outsourcing agreement |
| TODO(호스팅 수탁사) | Website hosting and system operation | Until termination of the outsourcing agreement |
| TODO(CRM 수탁사) | Operation of the reservation and customer relationship management (CRM) system | Until termination of the outsourcing agreement |
| TODO(문자·이메일 발송 수탁사) | Sending verification codes and notification text messages and emails | Until termination of the outsourcing agreement |
Article 5 (Cross-Border Transfer of Personal Information)
To provide the identity verification function, the Clinic outsources personal information processing to an overseas service provider as follows. Users may refuse the cross-border transfer by contacting the Chief Privacy Officer; in that case, use of services requiring identity verification (reservation requests and inquiries) may be restricted.
| Recipient | Destination Country | Timing and Method of Transfer | Categories Transferred | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|
| Google LLC (Firebase Authentication) | United States | Transmitted via telecommunications network at the time of identity verification | Mobile phone number or email, authentication token | Processing of mobile phone SMS and email identity verification | Until the outsourced task is completed |
Article 6 (Destruction of Personal Information)
- The Clinic destroys personal information without delay once it is no longer needed, such as upon expiration of the retention period or fulfillment of the purpose of processing.
- Where retention is required by law, the relevant information is moved to a separate database (DB) or stored in a separate location.
- Information in electronic file form is deleted using technical methods that render it unrecoverable, and paper documents are destroyed by shredding or incineration.
Article 7 (Installation, Operation, and Refusal of Cookies and Other Automatic Collection Tools)
- The Branch Site uses cookies and browser storage (localStorage) to provide users with convenient services.
- Essential: Providing basic service functions, such as language settings and temporary storage of reservation items of interest (cart)
- Analytics and marketing: Identifying referral sources (UTM parameters) and analyzing service usage statistics
- Users may refuse or delete cookies through their web browser settings. However, refusing cookies may make it difficult to use some parts of the Services.
- Cookies for analytics and marketing purposes are used only with the user's consent.
Article 8 (Rights and Obligations of Data Subjects and Legal Guardians, and How to Exercise Them)
- Users may at any time request that the Clinic allow access to, correct, delete, or suspend the processing of their personal information, and may withdraw their consent.
- These rights may be exercised directly on the reservation inquiry screen (My Page) or by contacting the Chief Privacy Officer in writing, by telephone, or by email, and the Clinic will act without delay. However, medical records and other information subject to retention obligations under the Medical Service Act or other laws are governed by those laws.
- These rights may also be exercised through a legal guardian or an authorized representative. In such cases, a power of attorney complying with applicable laws must be submitted.
- If a user requests correction of an error in their personal information, the Clinic will not use or provide the personal information concerned until the correction is completed.
Article 9 (Measures to Ensure the Security of Personal Information)
The Clinic takes the following measures to ensure the security of personal information:
- Administrative measures: Establishing and implementing an internal management plan, and minimizing and training staff who handle personal information
- Technical measures: Managing access rights to personal information processing systems, operating access control systems, encrypting personal information in transit (TLS), and retaining access logs
- Physical measures: Controlling access to server rooms, data storage rooms, and similar facilities
Article 10 (Chief Privacy Officer)
- Chief Privacy Officer: TODO(지점 보호책임자) (TODO(직책))
- Telephone: TODO(전화)
- Email: TODO(이메일)
- Medical institution: 아이디의원 강남점, TODO(지점 주소), TODO(지점 전화)
Article 11 (Remedies for Infringement of Rights)
Users may contact the following organizations for remedies, counseling, and other assistance regarding infringements of personal information:
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.kopico.go.kr
- Privacy Report Center of KISA (Korea Internet & Security Agency): 118 (no area code) / privacy.kisa.or.kr
- Supreme Prosecutors' Office: 1301 (no area code) / www.spo.go.kr
- National Police Agency: 182 (no area code) / ecrm.cyber.go.kr
Article 12 (Notice to Overseas Users)
The Clinic also provides the Services to users accessing from outside Korea. Users in regions where the GDPR applies, such as the European Economic Area (EEA) and the United Kingdom, have, under applicable laws, the rights of access, rectification, erasure, restriction of processing, and data portability with respect to their personal information, as well as the right to lodge a complaint with a supervisory authority, and may exercise these rights by contacting the Chief Privacy Officer at the contact details set out in Article 10. Please note that personal information collected by the Clinic is processed and stored on servers located in the Republic of Korea.
Article 13 (Changes to the Privacy Policy)
- This Policy applies from its effective date, and its content may be added to, deleted, or amended in response to changes in laws, policies, or the Services.
- If this Policy is changed, the Clinic will give notice through the Branch Site notice board at least 7 days before the effective date. However, in the case of material changes affecting users' rights, such as changes to the categories collected, the purposes of processing, or third-party provision, notice will be given at least 30 days in advance.
- Previous versions of the Privacy Policy are available at:
- TODO(이전 버전 링크)