In accordance with Article 30 of the Personal Information Protection Act, Shinsegae Eye Clinic establishes and discloses the following privacy policy for the website and mobile application (iOS/Android, hereinafter the 'Service') provided by Shinsegae Eye Clinic, in order to protect the personal information of data subjects (customers) and to promptly and smoothly handle related grievances.
1. Purpose of Collecting and Using Personal Information
Shinsegae Eye Clinic uses collected personal information for the following purposes:
- Fulfilling service (website and mobile app) contracts and providing related content
- Identity verification, personal identification, preventing unauthorized use, handling complaints and grievances, delivering notices
- Marketing and advertising, providing event and promotional information, delivering services and advertisements based on demographic characteristics, analyzing access frequency and service usage statistics
- Verifying the identity of petitioners, confirming grievance details, contacting for fact-finding investigations, and notifying processing results
- Sending service notifications and, where consented, marketing push notifications within the mobile app
2. Categories of Personal Information Collected
The following personal information is collected for membership registration, consultation, reservation, and service applications:
- Required items: Name, date of birth, login ID, password, mobile phone number, email address, access logs, cookies, service usage records
- Optional items: Branch, areas of interest, event preferences, registration channel, mailing and SMS service opt-in
- Automatically collected when using the mobile app: Access IP, device OS type/version, app version, visit and usage records (camera, photo, location, microphone, contacts, and advertising identifiers are NOT collected)
- Retention period: Semi-permanent until opt-out or membership withdrawal request
- Collection method: Website and mobile app (membership registration, consultation board, reservation board, simplified login, etc.)
3. Retention and Use Period of Personal Information
① Shinsegae Eye Clinic processes and retains personal information within the consented retention period or the period prescribed by law.
② Specific processing and retention periods are as follows:
- Customer registration and management: Until service agreement termination; if credit/debt relationships remain, until settlement
- E-commerce contracts, withdrawal, payment, and supply records: 5 years
- Information collected for diagnosis and treatment: In accordance with the Medical Service Act
- Even after the purpose of collection or provision is achieved, personal information may be retained if preservation is required under the Commercial Act or other applicable laws
4. Provision of Personal Information to Third Parties
Shinsegae Eye Clinic does not provide personal information to third parties except in cases falling under Article 17 of the Personal Information Protection Act, such as separate consent from the data subject or special provisions of law.
5. Rights, Obligations, and Exercise Methods of Data Subjects
Data subjects may exercise the following personal information protection rights against Shinsegae Eye Clinic at any time:
① Request to access personal information ② Request for correction of errors ③ Request for deletion ④ Request for processing suspension
These may be submitted in writing, by email, or by fax in accordance with Annex Form No. 8 of the Enforcement Rules of the Personal Information Protection Act, and Shinsegae Eye Clinic shall take action without delay.
If a data subject requests correction or deletion of errors in personal information, the information shall not be used or provided until the correction or deletion is completed.
Rights may be exercised through a legal representative or an authorized agent.
In such cases, a power of attorney in accordance with Annex Form No. 11 of the Enforcement Rules must be submitted.
Members may request account deletion and removal of their personal information via the 'Delete Account' menu in My Page on the mobile app or website, or by contacting the Personal Information Protection Officer below. Upon request, personal information is destroyed without delay except where retention is separately required by applicable law.
6. Categories of Personal Information Processed
Shinsegae Eye Clinic processes the following categories of personal information:
- Required items: Name, date of birth, login ID, password, mobile phone number, email address, access logs, cookies, service usage records
- Optional items: Branch, areas of interest, event preferences, registration channel, mailing and SMS service opt-in
7. Destruction of Personal Information
① In principle, Shinsegae Eye Clinic destroys personal information without delay when the purpose of processing has been achieved. The procedures, deadlines, and methods of destruction are as follows:
When the retention period has expired, personal information shall be destroyed within 5 days from the end of the retention period. When personal information becomes unnecessary due to achievement of the processing purpose, discontinuation of the relevant service, or termination of the business, it shall be destroyed within 5 days from the date it is deemed unnecessary.
② Shinsegae Eye Clinic destroys personal information by the following methods:
- Electronic files: File deletion, disk formatting, or technical methods that prevent reproduction
- Paper documents: Shredding or incineration
8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
Shinsegae Eye Clinic operates "cookies" and similar technologies that regularly store and retrieve user information to provide customized services.
- Cookies are used for analyzing access frequency and visit times, identifying user preferences and interests, tracking usage patterns, measuring event participation and visit counts, and providing personalized services
- Users may set their web browser options to allow all cookies, require confirmation each time a cookie is stored, or refuse all cookie storage.
In the mobile app environment, access logs, device information, and usage records may be automatically collected for similar purposes instead of browser cookies. Users may limit the collection of such information through their device settings, although this may restrict use of certain services.
9. Mobile App Permissions and Push Notifications
The Shinsegae Eye Clinic app (iOS/Android) operates the following device permissions and notification features to provide its services.
- Device permissions
This app does not request device permissions such as camera, photo library, location, microphone, contacts, or biometric authentication (fingerprint/Face ID). If a new permission becomes necessary to provide a service, users will be notified in advance and their consent will be obtained. - Push notifications
Users may separately choose whether to receive service notifications and marketing notifications in the app's [Settings] menu. Marketing notifications are sent only with user consent, and users may opt out at any time via the [Settings] menu or the device's notification settings. - Advertising identifiers
This app does not collect advertising identifiers (ADID, IDFA, etc.) and does not track users across other apps or websites.
10. Measures to Ensure the Security of Personal Information
In accordance with Article 29 of the Personal Information Protection Act, Shinsegae Eye Clinic implements the following technical, managerial, and physical measures to ensure security:
- Regular internal audits
Internal audits are conducted regularly (once a year) to ensure the security of personal information handling. - Minimizing and training personnel handling personal information
Designated personnel are assigned and limited to minimize the number of people handling personal information. - Establishing and implementing internal management plans
Internal management plans are established and implemented for the safe processing of personal information. - Technical measures against hacking
Security programs are installed with regular updates and inspections, and systems are placed in access-controlled areas with technical and physical monitoring and blocking to prevent personal information leakage and damage from hacking or computer viruses. - Encryption of personal information
User passwords are encrypted during storage and management. Important data is protected using file encryption, transmission data encryption, or file locking features. - Restricting access to personal information
Access to database systems processing personal information is controlled through the granting, modification, and revocation of access rights, and unauthorized external access is controlled through intrusion prevention systems.
11. Personal Information Protection Officer
Shinsegae Eye Clinic designates the following Personal Information Protection Officer to oversee personal information processing and handle complaints and damage relief:
Personal Information Protection Officer
- Name: Kim Jae-bong
- Title: Medical Director
- Contact: 062-226-1100
12. Handling of Non-Consent
Users (data subjects) have the right to refuse consent to the collection and use of personal information. However, refusal may result in restrictions on related service provision.
13. Effective Date
This privacy policy is effective from January 1, 2025, and was revised on July 30, 2026 to add provisions related to the mobile app (iOS/Android).