Policy for personal information handling

Previous version date: July 1, 2014
Current version date: September 3, 2016
View previous version

According to the personal information protection act and the act on promotion of information and communication network utilization and information protection, <CYBERONE Co. Ltd.>(‘www.cyberone.kr’, hereunder, ‘CYBERONE’) establishes and opens the privacy policy to protect personal information of the users and rights, and handle the complaints of the users timely and harmoniously, as follows.

  1. 1. Handling items of personal information

    ‘CYBERONE’ handles the following items of personal information.

    1. 1) Joining membership of homepage and its control

      - Essential items: member ID, password, name, cellphone No, e-mail address, company name, direct phone No (intercom)

      - Optional items: phone No, title, function

    2. 2) Others

      1. ① Recruitment

        Essential items: photo, applicant name (Korean and English), password, e-mail address, address, marital status, cellphone No, veterans, disability, military status, self-introduction

        Optional items: Chinese name, home phone No, careers, family information, foreign language skill and licenses, overseas experiences, awards, training, resume, and other attachment files for the application

        Collection method: web-page for recruitment, e-mail submission, document submission

      2. ② Visitors

        Essential items: name, contact details

        Optional items: company name

  2. 2. Purposes of personal information handling

    ‘CYNERONE’ handles the personal information for the following purposes, and shall not use that beyond the scope.

    1. 1) Joining membership of homepage and its control

      - handle personal information for the purposes of checking the intention to join membership and checking the membership status when inquiring the services.

    2. 2) Others

      1. ① Recruitment: recruitment related works such as identification of the applicant, checking the evidences of qualification, employment screening, and so on
      2. ② Visitors: checking identification of visitors for physical security in the company
  3. 3. Period of personal information handling and storage

    ‘CYBERONE’ handles and holds the personal information for the holding and usage period of the personal information according to the regulations and within the holding and usage period agreed from the information owners when collecting that.

    1. 1) Joining membership of homepage and its control: until withdrawal

      - handle personal information for the purposes of checking the intention to join membership and checking the membership status when inquiring the services.

    2. 2) Others

      1. ① Hiring: until the end of the recruitment process
      2. ② Visitors: 1 year
  4. 4. Rights and duties of information owners and methods of execution

    1. 1) Information owners can execute the rights related to the personal information protection as follows to ‘CYBERONE’ at any time.

      1. ① Request browsing personal information
      2. ② Request correction in case of errors, and so on
      3. ③ Request deletion
      4. ④ Request holding handling
    2. 2) Rights stated in Section 1) can be executed for ‘CYBERONE’ by written documents, e-mail, FAX, and so on according to the template 8 in the enforcement regulation of the personal information protection act, and ‘www.cyberone.kr’ (hereunder, ‘CYBERONE homepage’) will take the action without delay.

    3. 3) If information owner requests to amend or delete the errors of personal information, ‘CYBERONE homepage’ will not use or provide the related personal information until amendment or deletion is completed.

    4. 4) Rights stated in Section 1) can be executed by legal representative of the information owner or its delegate. In this case, power of attorney according to the template 11 in the enforcement regulation of the personal information protection act should be submitted.

  5. 5. Abrogation of personal information

    If the purposes of personal information handling are satisfied, ’CYBERONE’ in principle abrogates the personal information without delay. The process, timeline, and methods are as follows.

    - Abrogation process
    Information entered by users is transferred to separate DB (in case of papers, to separate documents) after satisfying the purposes, and abrogated immediately or after certain period of time according to the internal guideline or other regulations. The personal information transferred to the DB shall not be used for other purposes unless by law.
    - Abrogation timeline
    When the personal information of users becomes unnecessary due to expiry of its holding period, achievement of its handling purposes, discontinuation of the services, termination of the business, and so on, the information is abrogated without delay.
    - Abrogation methods
    For electronic files of the information, the technical method that cannot recover the records shall be used. For paper-based information, it shall be shredded or incinerated.
  6. 6. Measures to secure the security of personal information

    According to Article 29 in the personal information protection act, ‘CYBERONE’ takes the technical, administrative, and physical measures required to secure the security as follows.

    1. 1. Minimization of staff handling personal information and training

      The company assigns and limits the staff members that handle personal information as a measure to manage personal information.

    2. 2. Regular internal audit

      The company performs internal audit regularly (quarterly) to secure the security related to personal information handling.

    3. 3. Establishment and execution of internal management plan

      The company establishes and executes the internal management plan to handle personal information safely.

    4. 4. Encoding personal information

      Personal information of users is encoded with password to be stored and controlled, which only the person himself/herself can recognize. For important data, separate security functions are used such as coding files and transmission data or file locking.

    5. 5. Technical measures against hacking, and so on

      ‘CYBERONE’ installs security program to prevent from leakage or damage of personal information by hacking, computer virus, and so on; updates and checks regularly; sets the system at the restricted area; and monitors them technically and physically.

    6. 6. Restriction to access personal information

      ‘CYBERONE’ takes the necessary actions to control the access to personal information by allocation, amendment, and cancellation of the access authority to the database system to handle personal information, and unauthorized access from external sources is controlled using firewalls system.

    7. 7. Storage of access records and prevention of forgery

      Access records to personal information handling system are stored and controlled for at least 6 months. The security function is used for access records to prevent from forgery, theft, and missing.

    8. 8. Using lock for document security

      Documents, auxiliary data storage, and so on containing personal information are stored at the safe place with lock.

    9. 9. Access control for unauthorized personnel

      Physical storage place to keep personal information is separately assigned and its access process is established and operated.

  7. 7. Manager of personal information protection

    If the purposes of personal information handling are satisfied, ’CYBERONE’ in principle abrogates the personal information without delay. The process, timeline, and methods are as follows.

    1. ① ‘CYBERONE’ assigns manager of personal information protection to be responsible for overall handling of personal information, complaints of the information owners, recovery of damage related to personal information handling, and so on as below.

      Information entered by users is transferred to separate DB (in case of papers, to separate documents) after satisfying the purposes, and abrogated immediately or after certain period of time according to the internal guideline or other regulations. The personal information transferred to the DB shall not be used for other purposes unless by law.

      Manager of personal information protection
      Name Suk Won You Department Business Planning
      Title Department head Phone No 02-3475-4956
      E-mail cyberone@cyberone.kr FAX 02-3475-4870

      You can check the contents by scrolling horizontally.

    2. ② Information owners can request any inquiries related to personal information protection, complaint handling, recovery of damage, and so on when using the services of ‘CYBERONE’ to manager of personal information protection and related department. ‘CYBERONE’ shall answer and handle the inquiries from information owners without delay.

  8. 8. Claim for inspection of personal information

    Information owners can claim the inspection of personal information according to Article 35 of personal information protection act to the following department. The company tries to handle the claim for inspection of personal information from information owners in a timely manner.

    • Department handling the claim for inspection of personal information
      Department HR and GA E-mail cyberone@cyberone.kr
      Phone No 02-3475-4981 FAX 02-3475-4870

      You can check the contents by scrolling horizontally.

  9. 9. Remedies for infringement on rights

    Information owners can request the remedies for infringement, counseling, and so on to the following institution.
    <The following institution is independent from the company, and ask them if you are not satisfied with the complaint handling and remedies of the company, or if you require more detailed assistance.>

    • ▶ Reporting center for infringement of personal information (operated by Korea Internet & Security Agency)
      Functions Report and counselling for infringement of personal information, apply counseling. Homepage privacy.kisa.or.kr
      Phone No (Without exchange number) 118 Address (138-950) Reporting center for infringement of personal information, Korea Internet and Security Agency, 135, Jungdae-ro, Songpa-gu, Seoul

      You can check the contents by scrolling horizontally.

      ▶ Mediation committee for personal information disputes
      Functions Apply mediation for personal information dispute, mediation for group disputes (civil resolution) Homepage www.kopico.go.kr
      Phone No 1833-6972 Address (03171) 4th FL, Government Complex-Seoul, 209, Sejong-daero, Jongno-gu, Seoul

      You can check the contents by scrolling horizontally.

  10. 10. Amendment of policy for personal information handling

    1. 1. This policy is applied from the effective date. In case of addition, deletion, and correction according to the changes of regulations and guidelines, they will be posted through Notice from 7 days before the execution of the changes.

    2. 2. Please check the previous version of the policy as below.