What is Personal Data Processing Policy?
www.thehandsome.com (hereinafter referred to as the THEHANDSOME.COM) personal data processing policy may be changed in accordance with the changes in laws and guidelines of the government and the changes in the policies of the THEHANDSOME.COM and the person-in-charge of managing personal data protection is stated at the bottom of the page.
This personal data processing policy is stated in order to ensure fundamental rights, including the personal secrets and freedom and communication secrets, of internet users who uses the THEHANDSOME.COM website and prevent violation of human rights caused by illegal tapping and information leakage. As the personal data processing policy of the THEHANDSOME.COM website may be changed in accordance with the changes in laws and guidelines of the government, hence the THEHANDSOME.COM users are strongly encouraged to frequently check for any changes to the policy during your visit to the THEHANDSOME.COM website.
Personal Data Processing Policy
Article 1 General Provisions
- ① “Personal Information” refers to the information of a living individual of which the given information including full name, mobile phone number, personal identification value (CI: Connecting Information – the personal identification information provided by personal identification institutes for linking services) may identify a certain individual (should the information alone insufficient for identification of a certain individual, this includes the ones that might easily associated with other information to identify the individual).
- ② The THEHANDSOME.COM thinks highly of your personal data protection and is complying with the personal data protection regulations in accordance with the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. and the guidelines of personal data protection enacted by the Ministry of Information and Communication. The THEHANDSOME.COM informs for what the personal data you had provided are being used, how they are used, and what measures are being taken for personal data protection.
- ③ The THEHANDSOME.COM opens personal data protection policy to public in the first page of the website so that you may easily inquire at any time.
- ④ The THEHANDSOME.COM is determining necessary procedures to revise personal data protection policy for its continuous improvement. Moreover, in the event of revising the personal data protection policy, version numbers, etc. are given for your easy inquiry.
Article 2 Collection of Personal Data and Purpose of Usage
Most contents on the THEHANDSOME.COM can be freely accessed without a separate membership registration. In the event of using the services of the THEHANDSOME.COM, following data may be collected under your consent; there shall be no restriction to the service usage even if you choose not to enter optional data.
- ① Minimal required data are collected to provide delivery and various information.
- ② Personal data of all members registered in the THEHANDSOME.COM will not be used for any other purposes except aforementioned special purposes. However, in the event of revision of usage purpose and uses of personal data, the THEHANDSOME.COM will seek for consent of all members at all costs.
- ③ The THEHANDSOME.COM is collecting the following personal data during registration of membership and order of goods or services, and collected data are classified into compulsory and optional data.
- ④ In the event of withdrawal of the THEHANDSOME.COM membership or disqualification of membership in accordance with Article 8 of the THEHANDSOME.COM terms and conditions, the personal data of said member collected by the THEHANDSOME.COM shall be destroyed.
- 1. Scope of personal data collected at necessary points during registration of membership and order placement
Collection Method Purpose of Usage Collection Information Collected Data Registration of Membership Service usage and consultation Compulsory Name, Gender, Brith Date, ID, Password, E-mail Purchase and delivery Payment of purchase Compulsory Payment Information : Credit card/Debit card, Paypal, Alipay Delivery of purchase, Shipping Address Compulsory Orderer Information : Name, E-mail
Delivery Information : Name, Shipping address, Phone numberOthers Introduction of new service/goods Optional Phone number, E-mail Sending URL for app installation Optional Phone number - 2. Data generated in the service usage process
Collection Method Purpose of Usage Collection Information Collected Data Retention Period THEHANDSOME.COM
Web site
Mobile App
Mobile WebPersonal Identification Compulsory Personal identification value (CI, DI), age, age group Upon withdrawal of membership or legal compulsory retention period Service usage records Compulsory - IP address, cookie, date and time of visit, service usage and termination records, Mobile device information (when using mobile service)
- Bank account information, credit card information, point card number, transaction information, issuance of tax receipt, etc.
- Delivery information such as address, name and contact of recipient
- Mobile device information for using mobile service: OS type & version, device type, advertising identifier
- Additional mobile device information for using mobile application: UUID, push token, Membership ID- Cookies to be expired when closing browser or logging out ※ When allowing access authority to THEHANDSOME.COM application, all mobile device information is not collected, but is collected with the limits required for running application service.
- 3. Other legal compulsory collected data, etc
Related law Purpose of usage Collected items Retention period Protection of Communications Secrets Act Provision to investigative agency (provided in the event of due process such as court warrant) Log records, IP, etc. 3 months Act on the Consumer Protection in Electronic Commerce, etc. Verification of consumer complaints or dispute settlement and contract contents Customer identification data, dispute settlement records, contract/withdrawal records 3 years / 5 years
Article 3 Collection of Personal Data by Cookie
- ① Our company may use cookie to provide personalized service. Cookie is a small data packet that is sent to user’s browser from HTTP server and it is saved in member’s computer hard drive. Cookie identifies your computer but does not identify you as an individual.
- ② Our company uses cookie for following purposes:
- 1. Analyzes connection frequency or visiting hours of members and non-members to use as standards to target marketing and service improvemernt
- 2. Leaves traces of items viewed with interest to use to show recently viewed items during subsequent shopping. Cookie identifies customer’s computer but does not identify customers as individual. It is expired when cookie browser is closed or logged out.
- ③ Customers has option on usage of cookies. Therefore, the customer may allow/reject all cookies or set to confirm whenever cookie is stored through web browser settings. Method to reject cookie is as follows: (For Internet Explorer) Web brower [Tools] menu, select [Internet Options] > select [Privacy] tab > select desired option from [Advanced]. However, if cookie is disabled, there may be difficulties in using certain services.
Article 4 Provision to Third Party
- ① The THEHANDSOME.COM shall only use customer’s personal data in the scope specified in Article 2 [Collection of Personal Information and Purpose of Usage] and shall not use for purposes exceeding said scope or provide to other people, businesses or institutions. In particular, in the following circumstances, we shall exercise caution to use and provide personal data.
- 1. Affiliation : When personal data is provided to parties other than affiliates determined in paragraph 4 of this Article in this policy, the THEHANDSOME.COM shall seek for your consent through electronic mail or in writing.
- 2. Sale, merger and acquisition, etc. : In the event where rights and obligations of service provider is completely succeeded and transferred, customers will be notified of justifiable reasons and procedures in detail and we will provide options to withdraw customer’s consent on personal data.
- ② Notification and method of consent shall be notified through notification in initial pages of online website without delay and when necessary, they will be individually notified through e-mail at least once.
- ③ The following are exceptions:
- 1. When there are requests from related institutions for the purposes of investigation in accordance with related laws.
- 2. When providing to advertisers, affiliates or research organizations for preparation of statistics, academic research or market research in the form where certain individual cannot be identified.
- 3. When there are requests in accordance with procedures determined in other related laws.
- 4. However, even in exceptions, when data are provided in accordance with related laws or due to requests from investigative institutes, as an operation rule we notify such event to concerned party. Notification may inevitably not be sent based on the law. We will strive to prevent indiscrete provision of data against original purpose of collection and usage.
- ④ HANDSOME may provide customer’s personal data to, or share customer’s personal data with, the following affiliates to provide customers with better services, such period will be limited within customer’s data provision consent term.
Article 5 Perusal/Correction of Personal Data
- ① Customer may peruse or make correction on registered personal data at any time. Should you wish to peruse and correct personal data, click [Change Membership Details] in the THEHANDSOME.COM website to personally peruse or make correction, or contact personal data manager and person-in-charge in writing, via telephone or e-mail and we will take measures without delay.
- ② If customer request correction of error in personal data, we will not use or provide the concerned personal data until correction is completed.
- ③ If we already had provided erroneous personal data to third party, we will to correct the error by notifying the corrected result to third party without delay.
Article 6 Consent to Overseas Transfer
- The company transfers personal data overseas as follows:
- ① Name of transferee of personal data : Amazon Web Services Inc.
- ② Transfer method, transferred country : Transferred to Japan (Tokyo) through electronical transmission
- ③ Collected personal data / purpose / retention period
- 1. Collected data upon registration of membership and purpose of collection (compulsory)
- • Collected data : ID(e-mail), password, name, telephone number, date of birth, sex
- • Purpose of collection : Identification of member and delivery of notification, securement of seamless communication path including confirmation of individual intention and complaint handling
- • Usage period : 3 months after withdrawal of membership
- 2. Collected data upon purchasing of goods and purpose of collection (compulsory, identical for purchase by non-members)
- • Collected data : Personal identification data (data required for personal identification including CI, DI, date of birth, sex, needed once only during initial personal identification), name of purchaser, delivery address, delivery contact, payment method
- • Purpose of collection : Used for fulfillment of contract concluded with customers including delivery/installation of purchased goods, personal identification for complaint handling
- • Usage period : Until fulfillment of purpose of collection above
- 3. Collected data for marketing purposes and purpose of collection (optional)
- • Collected data : e-mail address, mobile phone address (SNS and push dispatch), addressof mail recipient
- • Purpose of collection : Used for marketing purposes including promotion and recommendation of new products only to consented customers
- • Usage period : Until withdrawal of consent
- 1. Collected data upon registration of membership and purpose of collection (compulsory)
Article 7 Withdrawal of Consent on Collection/Usage Provision of Personal Data
- ① Customer may withdraw consent on collection, usage, and provision of personal data given upon registration of membership at any time.
Withdrawal of consent can be done via [Change Membership Details] or [Withdraw Membership] in [My Page] on initial screen of website, or we will take necessary measures to immediately delete personal data if you contact personal data manager in writing or via telephone and e-mail. When consent is withdrawn and personal data is destroyed, such fact will be notified to customer without delay. - ② The THEHANDSOME.COM shall take necessary measure to make withdrawal of consent on collection of personal data (withdrawal of membership) easier than collecting personal data.
- ③ Collected personal data is processed in accordance with specified retention and usage period of personal data, and they are processed so that they may not be perused or used for other purposes.
Article 8 Retention / Usage Period and Destruction of Personal Data
- ① Customer’s personal data will be destroyed without delay upon fulfillment of purpose of collection and usage including withdrawal of membership or request of withdrawal of consent.
However, when there is a need to retain personal data for certain periods for the purposes of confirmation of transaction related relationships between rights and duties in accordance with related laws including Act on the Consumer Protection in Electronic Commerce, etc., they shall be retained for certain periods as follow:- 1. ArticAle 6 of the Act on the Consumer Protection in Electronic Commerce, etc.
- • Records on contract or withdrawal of contract : 5 years
- • Records on payment and supply of goods or services : 5 years
- • Records on customer complaints or dispute settlement : 3 years
- 2. Article 15-2 of the Protection of Communication Secrets Act
- • Internet log record data, access point tracking data : 3 months
- 3. Other related laws
Introduction of personal data expiration policy- • HANDSOME shall, for the protection of personal data of long-term (more than 1 year) service nonuser, separately store and manage the personal data of nonuser after September 2016.
- • Non-using period shall be calculated by date of log in and contact with counselor, and personal data of service nonuser shall be separately stored for the period determined by laws.
- • HANDSOME shall notify concerned user about the separation/storage of personal data of nonuser, 1 month before coming of such period.
- • Separately stored personal data of nonuser shall be retained for a certain period in accordance with the related laws and shall be destroyed after expiration of said period. Personal data of nonuser shall be provided again, on the request of concerned user, at the point of resumption of service.
- 1. ArticAle 6 of the Act on the Consumer Protection in Electronic Commerce, etc.
- ② The company shall notify the dormant member (member who did not use service within recent 12 months) on disqualification of membership and if the answer is unheard within the period determined in the notification, the company may disqualify the membership in accordance with Article 29 paragraph 2 of the Act on the Promotion of Information and Communication Network Utilization and Information Protection, etc.
In this case, personal data and service usage data of the dormant member including member’s ID shall be destroyed or separately stored. - ③ However, personal data for minimal identification including ID, personal identification value, and e-mail address may be stored for 3 months after withdrawal of membership and request of withdrawal to prevent confusion in service usage and wrongful use.
- ④ The methods of destruction of personal identification are as follow:
- 1. Personal data printed on paper shall be destroyed through shredding by shredder or incineration
- 2. Personal data stored in electronic file format shall be destroyed by using unrecoverable technical method
Article 9 Technical and Administrative Measures for Protection of Personal Data
- ① Technical measures
The THEHANDSOME.COM, in handling personal data of customers, devised following technical measures for securement of safety and to prevent loss, theft, leak, falsification, or damage of personal data:- 1. Personal data of customers are password protected and important data are protected through separate security functions including encryption of file and transmitted data or file locking function.
- 2. The THEHANDSOME.COM prevents damages by computer virus by using vaccine program. The vaccine program is periodically updated and in case of sudden emergence of virus, we provide the vaccine as soon as it is released and hence violation of personal data is prevented.
- 3. The THEHANDSOME.COM is adopting security system (SSL or SET) that can safety transmit password data on network by using encryption algorithm.
- 4. To prepare for external intrusion including hacking, we make a full security preparation by using firewall and weak spot analysis system.
- ② Administrative measures
The THEHANDSOME.COM limits the access authority of personal data of customers to minimal number of people. The following are the people relevant for such minimal number of people.- • People who performs marketing business directly against user
- • People who performs personal data protection business, including personal data protection manager and person-in-charge
- • Other people whose handling of personal information due to business is inevitable
- 1. We implemented regular in-house training and external commissioned education with regard to acquisition of new security techniques and responsibility for protection of personal data on employees who handle personal data.
- 2. We are arranging internal procedures to prevent leak of information by people through security pledge by handlers of personal data upon their entrance to company and to audit the commitments on personal data protection policy and employee’s compliance to the policy.
- 3. Transfer of duties of handlers of personal data is thoroughly taken place under secure conditions and liabilities on personal data accidents after entrance and resignation are clarified.
- 4. Personal data and general data are separately stored and not stored together.
- 5. Data processing room and archives are designated as special protected area and entry and exit are controlled.
- 6. In the event where loss, leak, falsification, or damages of personal data is triggered due to error of internal manager or technical accidents, the THEHANDSOME.COM shall immediately notify the customers about such facts and shall devise appropriate measures and compensation.
- ③ Other protection measures
- 1. Personal data leakage notification/report system
The THEHANDSOME.COM will, upon getting knowledge of the occurrence of loss, theft, or leakage of personal data, notify user about such knowledge without delay and will report to Korea Communications Commission or Korea Internet and Security Agency.
In addition, countermeasures of the THEHANDSOME.COM, measures that can be taken by user, and user consultation window will also be notified/reported together. - 2. Personal data leakage notification/report system
- • The THEHANDSOME.COM shall, for the protection of personal data of long-term service nonuser, separately manage the personal data dormant member (member who did not use service within recent 12 months) from data of other members.
- • HANDSOME shall notify concerned user on disqualification of membership 1 month before separately managing personal data of dormant member, and if the answer is unheard within the period determined in the notification, the company may disqualify the membership.
- 3. Personal data usage record notification system
The THEHANDSOME.COM shall, in order to secure user’s autonomy on personal data, periodically (more than once per year) notify personal data usage record to concerned user.- • Purpose of collection/usage of personal data and collected personal data
- • Person provided with personal data, purpose of such provision and provided personal data
- • Person consigned to process personal data and the content of such consigned business
- 1. Personal data leakage notification/report system
- The THEHANDSOME.COM shall notify concerned user 1 month prior to the separate storage and management of personal data of dormant member of his/her disqualification of membership, and should the user have no reply within the period determined in the notification, the THEHANDSOME.COM may disqualify such member.
Article 10 Posts
- ① The THEHANDSOME.COM values the posts of customers and does its best to protect them so that they are not falsified, damaged or deleted. However, otherwise may apply in case of the following:
- 1. Posts that circulate false information and defame reputation of others with an intention of slandering the person.
- 2. Posts that disclose personal information of someone without his/her consent, violate the copyright of the THEHANDSOME.COM and third parties, or are different with the topic of BBS.
- 3. The THEHANDSOME.COM may, in order to activate a healthy BBS culture, delete, or revise with symbols, certain parts of posts that disclose personal information of someone without consent.
- 4. In the event where the content can be transferred to BBS on other topic, the transfer path is disclosed to prevent any misunderstandings. In other cases, the posts may be deleted after expressed or individual warning.
- ② Basically, all rights and responsibilities related to the posts are borne by poster. In addition, information voluntarily disclosed through posts may be difficult to be protected, therefore please consider carefully before disclosure of information.
Article 11 Consigned Processing of Personal Data
- The THEHANDSOME.COM may, for improvement of services, consign processing of collection, handling, and management of personal data to outside party.
- • In the event where processing of personal data is consigned, consigned institute and such fact will be notified to customers through website without delay.
Consigned business Consignee Consigned Personal Data Customer service Metanet MCC Name, address, contacts, mobile number, etc. Delivery of ordered goods Post Office Parcel Service, Sily Promotion, DHL Korea, Gogovan Korea, FASTBOX Name (masking), address, contacts (safety number) Personal identification NICE Information Service, KICA Date of birth, I-Pin number, mobile number, etc. Payment details KG inicis, LG CNS, KRP Payment details (credit card, mobile number) Dispatch of SMS, MMS KG inicis, LG CNS, KRP Mobile number Provision of services including goods delivery Ipass Name, address, contacts Processing and maintenance/management of computer data Innotree Co., Ltd. Newform, Hyundai IT&E, Megazone Name, address, contacts, mobile number, etc. Provision of call center equipment and system Hyundai HCN Voice recordings - * Shared information will be limited to minimum information needed to achieve concerned purposes.
Article 12 Responsibilities and Obligations of User and Legal Representative
- ① Users shall update personal information to latest information to prevent unexpected accidents. Responsibility arising from the incorrect information entered by user shall be borne by user him/herself, and should user enter false information including piracy of information of other people, the membership may be disqualified.
- ② Customer has rights to have his/her personal data protected and, at the same time, obligations to protect him/herself and not violate information of others.
Please be careful on leakage of customer’s personal data including passwords, and to not violate personal data of others including their posts.
Should customers fail to observe such obligations and damage data and dignity of others, he/she can be punished by the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
Article 13 Collection of Feedback and Complaints Processing
- ① The THEHANDSOME.COM values feedback of customers and customers has right to receive sincere answers on their questions at all times.
- ② The THEHANDSOME.COM operates customer service center with the following for effective communication with the customers.
Customer service center Electronic mail hsglobal@thehandsome.com Telephone number 1800-5700 Address (Postcode : 06013) HANDSOME Building,
523 Dosan-daero, Gangnam-gu, SeoulFax number 02-3416-4905
Article 14 Department-in-Charge of Personal Data Protection
- The THEHANDSOME.COM strives its best so that customers can safely use good information. In protecting personal data, upon occurrence of accidents that is against the notifications to customers, person-in-charge of personal data protection shall bear all responsibilities. However, the THEHANDSOME.COM shall bear no liabilities to damages to data due to unforeseen accidents occurred by the fundamental dangers on networks, including hacking, despite having taken technical complementary measures, and various disputes due to posts published by customers. Director and person-in-charge who handle personal data of customers are as follow, and they shall sincerely answer to your questions on personal data as soon as possible.
Director of personal data protection Person-in-charge of personal data protection • Name : Lee Jeong Deuk • Department : Sales headquarters, in charge of marketing
• Position : Executive director
• E-mail : security_center@thehandsome.com
• Telephone number : 1800-5700• Name : Yeo Yu Jeong
• Department : Online business team
• Position : Deputy team leader
• E-mail : security_center@thehandsome.com
• Telephone number : 1800-5700
Article 15 Personal Data Protection for Minors under 14
- "The THEHANDSOME.COM" does not receive registration of membership of minors under 14 who require the consent of their legal representative.
Article 16 Transmission of Commercial Information
- ① The THEHANDSOME.COM shall not transmit for-profit commercial information against customer’s expressed intent to unsubscribe.
- ② In the event where customer had consented to subscription of e-mail transmission including newsletters, the THEHANDSOME.COM shall take following measures in subject and body of e-mail for customers’ easy recognition:
- 1. Subject of e-mail : the word (Advertisement) may not be included in the subject line and the subject shall display the main contents of the body of e-mail
- 2. Body of e-mail :
- • The name, e-mail address, telephone number and address of sender to whom the customer may show the intent to unsubscribe shall be stated.
- • The method to which the customer can easily show his/her intent to unsubscribe shall be stated in Korean and English.
- • The time and content of customer’s consent shall be stated.
- ③ In the event where e-mail on commercial information for online marketing including product information is sent, the THEHANDSOME.COM shall take following measures in subject and body of e-mail for customer’s easy recognition:
- 1. Subject of e-mail : the word (Advertisement) shall be stated in the start of subject line in Korean without empty space and subsequently the main contents of the body of e-mail shall be displayed.
- 2. Body of e-mail :
- • The name, e-mail address, telephone number, and address of sender to whom the customer may show the intent to unsubscribe shall be stated.
- • The method to which the customer can easily show his/her intent to unsubscribe shall be stated in Korean and English.
- ④ In the event where for-profit commercial information is sent through transmission other than e-mail, including fax and text messages, the word (Advertisement) shall be stated at the start of the transmission and the contacts of sender shall be stated within the contents of transmission.
Article 17 Personal Data Processing Policy Change Notification
- This personal data processing policy may be changed in accordance with the changes in laws and guidelines of the government and the changes in the policies of the THEHANDSOME.COM, and when adding, deleting or revising content, it should be notified 7 days earlier before enforcement date by posting on a website or sending an email. If it is difficult to notify in advance, notification should be made as soon as possible.
- However, when adding, deleting, or revising very important matters such as collection of personal data & purpose of usage or provision to third party, it should be notified 30 days earlier.
- Notification Date : 2020-06-25
Enforcement Date : 2020-06-25
- Date of changing Privacy Policy