Lee&Pol (hereinafter referred to as “the Company,” including its brand name LeeAndPol) values customers’ personal information and complies with relevant laws such as the “Personal Information Protection Act.” Through the privacy policy, the Company informs customers of the purposes and methods of using the personal information provided and the measures taken to protect personal information.
■ Items and Methods of Personal Information Collection
a. Items of Personal Information Collected
The Company collects the following personal information for membership registration, consultation, service applications, etc.
- When registering: name, date of birth, login ID, password, email
- When applying for services: address, payment information
During the process of using services or handling business, service usage records, access logs, cookies, access IP, payment records, and records of improper usage may be generated and collected.
b. Collection Methods
- Website, written forms, bulletin boards, email, event applications, delivery requests, phone, fax, information collection tools
■ Purposes of Collecting and Using Personal Information
The Company uses the collected personal information for the following purposes:
Service provision and performance of contracts, and billing for services provided
- Providing content, purchasing and billing, shipping goods or sending invoices, financial transactions, identity verification, and financial services
Member management
- Identity verification for membership services, personal identification, preventing improper and unauthorized use by delinquent members, confirming intent to join, age verification, confirming consent from legal representatives when collecting personal information from children under 14, handling complaints, and delivering notices
Marketing and advertising
- Delivering advertising information for events, understanding access frequency, or analyzing service usage statistics of members
■ Retention and Use Period of Personal Information
In principle, the Company destroys the personal information without delay after achieving the purposes of collection and use. However, the following information is retained for the specified periods for the reasons stated below.
a. Reasons for Information Retention by Company Policy
- Even after a member withdraws, the Company may retain the member’s information for five years from the termination date of the service contract to prevent the recurrence of improper use by delinquent members, resolve disputes, and cooperate with requests from investigative agencies.
b. Reasons for Information Retention by Relevant Laws
- If retention is required by relevant laws such as the Act on Consumer Protection in Electronic Commerce, the Company retains member information for the specified period as follows:
Records related to contracts or withdrawals
- Retention reason: Act on Consumer Protection in Electronic Commerce
- Retention period: 5 years
Records related to payment and supply of goods
- Retention reason: Act on Consumer Protection in Electronic Commerce
- Retention period: 5 years
Records related to consumer complaints or dispute resolution
- Retention reason: Act on Consumer Protection in Electronic Commerce
- Retention period: 3 years
Log records
- Retention reason: Protection of Communications Secrets Act
- Retention period: 3 months
■ Procedures and Methods for Destroying Personal Information
In principle, the Company destroys personal information without delay after achieving the purposes of collection and use. The procedures and methods are as follows:
Destruction Procedures
- Information entered by members for registration, etc., is transferred to a separate database (or a separate document box in the case of paper) after achieving its purpose, and stored for a certain period according to internal policies and other relevant laws (refer to retention and use period) before being destroyed.
- Personal information transferred to a separate database is not used for purposes other than retention unless required by law.
Destruction Methods
- Personal information stored in electronic file formats is deleted using technical methods that prevent the records from being reproduced.
■ Provision of Personal Information
The Company does not, in principle, provide users’ personal information to external parties. However, exceptions are made in the following cases:
- When users have given prior consent
- When required by law or requested by investigative agencies following legal procedures and methods for investigation purposes
■ Entrustment of Collected Personal Information
The Company outsources operations to external professional companies as follows to perform services:
Entrusted Parties: [CJ Logistics] Entrusted Services: [Product shipment] Entrusted Parties: [KG Inicis, KakaoPay Co., Ltd.] Entrusted Services: [Payment and settlement services]
■ Rights of Users and Legal Representatives and How to Exercise Them
Users can view or modify their registered personal information at any time and can also request to cancel their membership.
- To view or modify personal information, users can click “Change Personal Information” (or “Edit Member Information,” etc.). To cancel membership (withdraw consent), users can click “Withdraw Membership” and go through the identity verification process for direct viewing, correction, or withdrawal.
- Alternatively, users can contact the Personal Information Protection Officer by mail, phone, or email, and the Company will take immediate action.
- If users request the correction of errors in personal information, the Company does not use or provide the information until the correction is completed. If incorrect personal information has already been provided to a third party, the Company will immediately notify the third party of the correction result to ensure the correction is made.
- Personal information that has been terminated or deleted at the user’s request is handled according to the “Retention and Use Period of Personal Information Collected by the Company” and cannot be viewed or used for other purposes.
■ Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
The Company operates cookies that store and retrieve users’ information. Cookies are small text files sent by the server used to operate the website to the user’s browser and are stored on the user’s computer hard disk.
- The Company uses cookies for the following purposes:
Purpose of Using Cookies
- Analyzing access frequency or visit times of members and non-members, identifying user preferences and interests, tracking traces, and providing targeted marketing and personalized services through understanding event participation levels and visit counts
- Users have the option to set cookie installation preferences. Users can allow all cookies, require confirmation each time a cookie is stored, or reject all cookies by setting options in their web browser.
- Example of settings (in the case of Internet Explorer): Tools > Internet Options > Privacy at the top of the web browser
- If users refuse the installation of cookies, there may be difficulties in providing services.
■ Personal Information Complaint Service
The Company designates the following departments and Personal Information Protection Officer to protect customers’ personal information and handle complaints related to personal information.
Personal Information Protection Officer
- Name: Joonhwa Lee
- Position: CEO
- Phone: 070-7805-6000
- Email: [email protected]
Personal Information Protection Manager
- Name: Joonhwa Lee
- Position: CEO
- Phone: 070-7805-6000
- Email: [email protected]
Users can report all personal information protection-related complaints arising from using the Company’s services to the Personal Information Protection Officer or the responsible department. The Company will promptly and adequately respond to users’ reports. For further assistance with personal information infringement, users can contact the following organizations:
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without area code)
- Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972)
- Supreme Prosecutors’ Office Cyber Investigation Division (spo.go.kr / area code + 1301)
- National Police Agency Cyber Safety Bureau (cyberbureau.police.go.kr / 182 without area code)