㈜에이씨티(이하 "회사")는 개인정보 보호법 제30조에 따라 정보주체의 개인정보를 보호하고 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 다음과 같이 개인정보 처리방침을 수립·공개합니다.
시행일자: 2026년 5월 1일
제1조 (개인정보의 처리 목적)
회사는 다음의 목적을 위하여 개인정보를 처리합니다. 처리하고 있는 개인정보는 다음의 목적 이외의 용도로는 이용되지 않으며, 이용 목적이 변경되는 경우에는 개인정보 보호법 제18조에 따라 별도의 동의를 받는 등 필요한 조치를 이행할 예정입니다.
1. 회원 가입 및 관리
회원제 서비스 제공에 따른 본인확인, 개인 식별, 부정이용 방지, 각종 고지·통지, 고충처리 등을 목적으로 개인정보를 처리합니다.
2. 서비스 제공
맞춤형 서비스 제공, 콘텐츠 제공, 본인인증, 요금결제·정산 등을 목적으로 개인정보를 처리합니다.
3. 마케팅 및 광고 활용 (선택)
신규 서비스 개발 및 맞춤 서비스 제공, 이벤트 및 광고성 정보 제공 및 참여기회 제공, 인구통계학적 특성에 따른 서비스 제공및 광고 게재, 서비스의 유효성 확인, 접속빈도 파악 등을 목적으로 개인정보를 처리합니다.
제2조 (처리하는 개인정보 항목)
회사는 다음의 개인정보 항목을 처리하고 있습니다.
1. 필수항목
- 소셜 로그인 ID (카카오톡, 구글, 애플)
- 닉네임
- 이메일 주소
- 디바이스 시리얼 번호
2. 선택항목
- 데일리 기록 사진 (사용자가 직접 촬영한 피부 상태 사진)
※ 저장 방식은 제3조에서 정합니다.
- 피부 타입 설문 응답 (건성/지성/복합성 등)
- 연령대 (선택 시)
- 성별 (선택 시)
- 비식별 얼굴 조각 이미지
※ 별도의 「AI 데이터 활용 동의 약관」에 동의한 경우에만 수집합니다.
3. 자동 수집 항목
- 서비스 이용 기록
- 접속 로그
- IP 주소
- 쿠키
- 광고식별자 (ADID/IDFA)
- 기기정보 (OS 버전, 기기 모델명)
- 앱 오류·비정상 종료 로그
- 푸시 알림 토큰 (알림 수신 동의 시)
- 구독 결제 상태 (구독 이용 시)
4. 위치정보
- GPS 좌표 (수집 즉시 날씨 인덱스로 변환 후 즉시 파기)
- 실제 GPS 좌표는 서버에 저장되지 않으며, 4바이트 날씨 인덱스만 저장됩니다
제3조 (카메라 사용 및 사진 수집)
1. 카메라 권한 사용 목적
회사는 다음 목적으로 카메라 권한을 요청합니다:
- 데일리 기록: 사용자가 자신의 피부 상태를 사진으로 기록
- 기록 관리: 날짜별 기록 열람
2. 촬영 및 저장
- 사용자가 직접 촬영 버튼을 눌러야만 촬영됩니다
- 자동 촬영 또는 백그라운드 촬영하지 않습니다
- 얼굴 또는 신체 일부(피부)를 촬영할 수 있습니다
- 데일리 기록 사진은 이용자의 기기에 저장됩니다
- 회사 서버에는 기록 날짜, 촬영 부위, 태그, 메모 등 사진을 제외한 정보가 저장됩니다
- 기기를 변경하거나 앱을 삭제하는 경우 기기에 저장된 사진은 복구되지 않습니다
3. 사진의 사용 목적
- 이용자 본인의 기록 열람
- 이용자가 별도로 동의한 경우, 「AI 데이터 활용 동의 약관」에 따른 AI 모델 개선
4. 사진의 처리 방식
- 회사는 얼굴/피부 사진을 본인 확인이나 생체 인증 목적으로 이용하지 않습니다
- 피부 상태 분석은 이용자의 기기에서 수행되며, 분석 결과 수치가 서버에 저장됩니다
- AI 모델 개선을 위한 비식별 얼굴 조각 이미지 수집은 별도의 「AI 데이터 활용 동의 약관」에 동의한 경우에 한하여 이루어지며, 동의하지 않더라도 서비스 이용에 제한이 없습니다
5. 선택 및 거부
- 데일리 기록 사진 촬영은 선택사항입니다
- 카메라 권한을 거부하셔도 다른 서비스 이용에 제한이 없습니다
- 기기 설정에서 언제든지 카메라 권한을 철회할 수 있습니다
6. 보관 및 삭제
- 기기에 저장된 사진: 이용자가 삭제하거나 앱을 삭제할 때까지
- 서버에 저장된 기록 정보: 회원 탈퇴 시 또는 삭제 요청 시까지
- 이용자는 앱 내 기능을 통해 저장된 사진을 삭제할 수 있습니다
제4조 (개인정보의 처리 및 보유 기간)
회사는 법령에 따른 개인정보 보유·이용기간 또는 정보주체로부터 개인정보를 수집 시에 동의받은 개인정보 보유·이용기간 내에서 개인정보를 처리·보유합니다.
1. 회원 가입 및 관리: 회원 탈퇴 시까지
단, 다음의 사유에 해당하는 경우에는 해당 사유 종료 시까지
- 관계 법령 위반에 따른 수사·조사 등이 진행 중인 경우에는 해당 수사·조사 종료 시까지
- 서비스 이용에 따른 채권·채무관계 잔존 시에는 해당 채권·채무관계 정산 시까지
2. 데일리 기록 사진: 회원 탈퇴 시 또는 사용자 삭제 요청 시까지
3. 관계 법령에 따른 보존
- 계약 또는 청약철회 등에 관한 기록: 5년 (전자상거래법)
- 대금결제 및 재화 등의 공급에 관한 기록: 5년 (전자상거래법)
- 소비자 불만 또는 분쟁처리에 관한 기록: 3년 (전자상거래법)
- 표시·광고에 관한 기록: 6개월 (전자상거래법)
- 서비스 방문기록: 3개월 (통신비밀보호법)
제5조 (개인정보의 제3자 제공)
회사는 정보주체의 개인정보를 제1조(개인정보의 처리 목적)에서 명시한 범위 내에서만 처리하며, 정보주체의 동의, 법률의 특별한 규정 등 개인정보 보호법 제17조에 해당하는 경우에만 개인정보를 제3자에게 제공합니다.
회사는 다음과 같이 개인정보를 제3자에게 제공하고 있습니다:
1. 마일리지 포인트 전환 서비스
- 제공받는 자: ㈜카페24 (자사몰 운영)
- 제공 목적: 마일리지의 자사몰 포인트 전환
- 제공 항목: 휴대전화 번호 또는 Cafe24 계정 ID, 전환 마일리지 금액
- 보유 및 이용기간: 포인트 사용 완료 시 또는 회원 탈퇴 시까지
제6조 (개인정보처리의 위탁)
회사는 원활한 개인정보 업무처리를 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.
1. AWS (Amazon Web Services)
- 위탁업무 내용: 클라우드 서버 호스팅, 데이터 저장
- 위탁기간: 회원 탈퇴 시 또는 위탁계약 종료 시까지
2. 소셜 로그인 제공사
- 카카오 (주식회사 카카오)
- 구글 (Google LLC)
- 애플 (Apple Inc.)
- 위탁업무 내용: 소셜 로그인 인증
- 위탁기간: 회원 탈퇴 시 또는 위탁계약 종료 시까지
3. 주식회사 카페24
- 위탁업무 내용: 자사몰 연동, 마일리지 적립금 전환 처리
- 위탁기간: 회원 탈퇴 시 또는 위탁계약 종료 시까지
4. Google LLC (Firebase)
- 위탁업무 내용: 앱 이용 분석, 오류 수집, 원격 설정
- 위탁기간: 위탁계약 종료 시까지
5. Functional Software, Inc. (Sentry)
- 위탁업무 내용: 앱 오류 및 비정상 종료 로그 수집
- 위탁기간: 위탁계약 종료 시까지
6. RevenueCat, Inc.
- 위탁업무 내용: 구독 상태 확인 및 결제 관리
- 위탁기간: 위탁계약 종료 시까지
7. OneSignal, Inc.
- 위탁업무 내용: 푸시 알림 발송
- 위탁기간: 알림 수신 동의 철회 시 또는 위탁계약 종료 시까지
제6조의2 (개인정보의 국외 이전)
회사는 서비스 제공을 위해 다음과 같이 개인정보 처리업무를 국외 사업자에게 위탁하고 있으며, 이에 따라 개인정보가 국외로 이전됩니다. 이 이전은 개인정보 보호법 제28조의8 제1항 제3호에 따른 처리위탁에 해당하며, 같은 조 제3항에 따라 아래와 같이 공개합니다.
[서비스 제공에 필수적인 이전]
1. Google LLC (Firebase)
- 이전 국가: 미국
- 이전 항목: 기기정보, 앱 이용기록, 오류 로그
- 이전 목적: 앱 이용 분석 및 오류 수집
2. Functional Software, Inc. (Sentry)
- 이전 국가: 미국
- 이전 항목: 오류 로그, 기기정보
- 이전 목적: 앱 안정성 개선
[이용자가 선택할 수 있는 이전]
3. RevenueCat, Inc.
- 이전 국가: 미국
- 이전 항목: 구매 이력, 앱 이용자 식별자
- 이전 목적: 구독 상태 확인 및 결제 관리
- 이 이전은 이용자가 구독 서비스를 이용하는 경우에만 이루어집니다
4. OneSignal, Inc.
- 이전 국가: 미국
- 이전 항목: 푸시 알림 토큰, 이용자 식별자
- 이전 목적: 푸시 알림 발송
- 이 이전은 이용자가 알림 수신에 동의한 경우에만 이루어집니다
[공통 사항]
- 이전 일시 및 방법: 서비스 이용 시점에 정보통신망을 통해 전송
- 보유·이용 기간: 위탁계약 종료 시까지
- 거부 방법 및 효과
· 1호와 2호의 이전은 서비스 제공과 앱 안정성 확보에 필수적이므로 이를 거부하시는 경우 서비스를 이용하실 수 없습니다. 이전을 원하지 않으시는 경우 회원 탈퇴를 통해 중단하실 수 있습니다
· 3호의 이전은 구독 서비스를 이용하지 않으시면 발생하지 않습니다
· 4호의 이전은 기기의 알림 설정에서 알림 권한을 해제하여 거부하실 수 있습니다
· 3호와 4호를 거부하시더라도 다른 서비스 이용에는 제한이 없습니다
제7조 (정보주체의 권리·의무 및 행사방법)
정보주체는 회사에 대해 언제든지 다음 각 호의 개인정보 보호 관련 권리를 행사할 수 있습니다.
1. 개인정보 열람 요구
2. 오류 등이 있을 경우 정정 요구
3. 삭제 요구
4. 처리정지 요구
권리 행사는 회사에 대해 서면, 전화, 전자우편, 모사전송(FAX) 등을 통하여 하실 수 있으며 회사는 이에 대해 지체 없이 조치하겠습니다.
권리 행사는 정보주체의 법정대리인이나 위임을 받은 자 등 대리인을 통하여 하실 수도 있습니다. 이 경우 개인정보 보호법 시행규칙 별지 제11호 서식에 따른 위임장을 제출하셔야 합니다.
정보주체는 개인정보 보호법 등 관계법령을 위반하여 회사가 처리하고 있는 정보주체 본인이나 타인의 개인정보 및 사적 생활을침해하여서는 아니됩니다.
제8조 (개인정보의 파기)
회사는 개인정보 보유기간의 경과, 처리목적 달성 등 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
1. 파기절차
- 정보주체로부터 동의받은 개인정보 보유기간이 경과하거나 처리목적이 달성되었음에도 불구하고 다른 법령에 따라 개인정보를 계속 보존하여야 하는 경우에는, 해당 개인정보를 별도의 데이터베이스(DB)로 옮기거나 보관장소를 달리하여 보존합니다.
2. 파기방법
- 전자적 파일 형태의 정보는 기록을 재생할 수 없는 기술적 방법을 사용합니다
- 종이에 출력된 개인정보는 분쇄기로 분쇄하거나 소각하여 파기합니다
3. 데일리 기록 사진 파기
- 기기에 저장된 사진: 이용자가 삭제하거나 앱을 삭제할 때 파기됩니다 (복구 불가)
- 과거 서버에 저장된 사진이 있는 경우: 삭제 요청 시 또는 회원 탈퇴 시 서버에서 파기합니다
제9조 (개인정보의 안전성 확보조치)
회사는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
1. 관리적 조치
- 내부관리계획 수립·시행
- 정기적 직원 교육
2. 기술적 조치
- 개인정보처리시스템 등의 접근권한 관리
- 접근통제시스템 설치
- 개인정보의 암호화
- 보안프로그램 설치 및 주기적 갱신·점검
3. 물리적 조치
- 전산실, 자료보관실 등의 접근통제
4. 사진 데이터 보안
- 기기에 저장된 사진은 기기의 보안 기능으로 보호됩니다
- 서버와 주고받는 정보는 HTTPS로 암호화하여 전송합니다
- 서버에 저장되는 정보는 암호화하여 보관하며, 접근 권한을 최소화합니다
제10조 (개인정보 자동 수집 장치의 설치·운영 및 거부)
회사는 이용자에게 개별적인 맞춤서비스를 제공하기 위해 이용정보를 저장하고 수시로 불러오는 '쿠키(cookie)'를 사용합니다.
1. 쿠키의 사용 목적
- 이용자의 접속 빈도나 방문 시간 등을 분석
- 이용자의 취향과 관심분야를 파악
- 각종 이벤트 참여 정도 및 방문 회수 파악
- 타겟 마케팅 및 개인 맞춤 서비스 제공
2. 쿠키의 설치·운영 및 거부
- 이용자는 쿠키 설치에 대한 선택권을 가지고 있습니다
- 웹브라우저에서 옵션을 설정함으로써 모든 쿠키를 허용하거나, 쿠키가 저장될 때마다 확인을 거치거나, 모든 쿠키의 저장을거부할 수도 있습니다
- 다만, 쿠키의 저장을 거부할 경우 로그인이 필요한 일부 서비스는 이용에 어려움이 있을 수 있습니다
제11조 (개인정보 보호책임자)
회사는 개인정보 처리에 관한 업무를 총괄해서 책임지고, 개인정보 처리와 관련한 정보주체의 불만처리 및 피해구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
개인정보 보호책임자
- 성명: 장광우
- 전화번호: 1588-2983
- 이메일: [email protected]
정보주체는 회사의 서비스를 이용하시면서 발생한 모든 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 개인정보 보호책임자에게 문의하실 수 있습니다. 회사는 정보주체의 문의에 대해 지체 없이 답변 및 처리해드릴 것입니다.
제12조 (권익침해 구제방법)
정보주체는 개인정보침해로 인한 구제를 받기 위하여 개인정보분쟁조정위원회, 한국인터넷진흥원 개인정보침해신고센터 등에분쟁해결이나 상담 등을 신청할 수 있습니다.
- 개인정보분쟁조정위원회: (국번없이) 1833-6972 (www.kopico.go.kr)
- 개인정보침해신고센터: (국번없이) 118 (privacy.kisa.or.kr)
- 대검찰청: (국번없이) 1301 (www.spo.go.kr)
- 경찰청: (국번없이) 182 (ecrm.cyber.go.kr)
제13조 (개인정보 처리방침의 변경)
이 개인정보 처리방침은 2026년 5월 1일부터 적용됩니다.
이전의 개인정보 처리방침은 아래에서 확인하실 수 있습니다.
- 해당사항 없음 (최초 제정)
㈜에이씨티 (ACT Inc.)
대표전화: 1588-2983
이메일: [email protected]
ACT Inc. (hereinafter referred to as "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to promptly and smoothly handle related grievances.
Effective Date: May 1, 2026
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed is not used for purposes other than the following, and if the purpose of use changes, necessary measures will be taken, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
1. Member Registration and Management
Personal information is processed for the purposes of identity verification, personal identification, prevention of fraudulent use, various notices and notifications, and grievance handling in accordance with membership service provision.
2. Service Provision
Personal information is processed for the purposes of providing customized services, content provision, identity authentication, payment and settlement, etc.
3. Marketing and Advertising Use (Optional)
Personal information is processed for the purposes of developing new services and providing customized services, providing event and advertising information and participation opportunities, providing services and placing advertisements according to demographic characteristics, verifying service effectiveness, and identifying access frequency.
Article 2 (Personal Information Items Processed)
The Company processes the following personal information items:
1. Required Items
- Social login ID (KakaoTalk, Google, Apple)
- Nickname
- Email address
- Device serial number
2. Optional Items
- Daily record photos (skin condition photos taken by users themselves)
* Storage method is set out in Article 3.
- Skin type survey responses (dry/oily/combination, etc.)
- Age group (when selected)
- Gender (when selected)
- De-identified facial patch images
* Collected only when the user has agreed to the separate AI Data Use Consent Terms.
3. Automatically Collected Items
- Service usage records
- Access logs
- IP address
- Cookies
- Advertising identifier (ADID/IDFA)
- Device information (OS version, device model name)
- App error and crash logs
- Push notification token (when notification consent is given)
- Subscription payment status (when using a subscription)
4. Location Information
- GPS coordinates (immediately converted to weather index and immediately destroyed after collection)
- Actual GPS coordinates are not stored on the server; only 4-byte weather index is stored
Article 3 (Camera Use and Photo Collection)
1. Purpose of Camera Permission Use
The Company requests camera permission for the following purposes:
- Daily records: Users record their skin condition through photos
- Record management: Viewing records by date
2. Photography and Storage
- Photos are taken only when the user directly presses the capture button
- No automatic photography or background photography
- Face or body parts (skin) can be photographed
- Daily record photos are stored on the user's device
- The Company's servers store information other than the photo, such as record date, area photographed, tags and notes
- Photos stored on the device are not recoverable if the device is changed or the app is deleted
3. Purpose of Photo Use
- Viewing the user's own records
- Where the user has separately consented, AI model improvement under the AI Data Use Consent Terms
4. Photo Processing
- The Company does not use face/skin photos for identity verification or biometric authentication purposes
- Skin condition analysis is performed on the user's device, and the resulting scores are stored on the server
- Collection of de-identified facial patch images for AI model improvement takes place only where the user has agreed to the separate AI Data Use Consent Terms, and there is no restriction on service use if consent is not given
5. Selection and Rejection
- Daily record photo taking is optional
- Even if you refuse camera permission, there are no restrictions on using other services
- You can revoke camera permission at any time in device settings
6. Retention and Deletion
- Photos stored on the device: Until the user deletes them or deletes the app
- Record information stored on the server: Until member withdrawal or deletion request
- Users may delete stored photos through the functions provided in the app
Article 4 (Processing and Retention Period of Personal Information)
The Company processes and retains personal information within the personal information retention and use period according to laws or the personal information retention and use period agreed upon when collecting personal information from data subjects.
1. Member Registration and Management: Until member withdrawal
However, in the following cases, until the end of the relevant reason:
- If investigation or inquiry is in progress due to violation of related laws, until the end of such investigation or inquiry
- If credit or debt relationship remains from service use, until settlement of such credit or debt relationship
2. Daily Record Photos: Until member withdrawal or user deletion request
3. Retention According to Related Laws
- Records on contracts or withdrawal of offers: 5 years (Electronic Commerce Act)
- Records on payment and supply of goods: 5 years (Electronic Commerce Act)
- Records on consumer complaints or dispute resolution: 3 years (Electronic Commerce Act)
- Records on labeling and advertising: 6 months (Electronic Commerce Act)
- Service visit records: 3 months (Protection of Communications Secrets Act)
Article 5 (Provision of Personal Information to Third Parties)
The Company processes personal information of data subjects only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only when data subject consent, special provisions of law, etc. correspond to Article 17 of the Personal Information Protection Act.
The Company provides personal information to third parties as follows:
1. Mileage Point Conversion Service
- Recipient: Cafe24 Co., Ltd. (company mall operation)
- Provision purpose: Conversion of mileage to company mall points
- Provision items: Mobile phone number or Cafe24 account ID, conversion mileage amount
- Retention and use period: Until point use completion or member withdrawal
Article 6 (Consignment of Personal Information Processing)
The Company consigns personal information processing tasks as follows for smooth personal information processing:
1. AWS (Amazon Web Services)
- Consigned task content: Cloud server hosting, data storage
- Consignment period: Until member withdrawal or consignment contract termination
2. Social Login Providers
- Kakao (Kakao Corporation)
- Google (Google LLC)
- Apple (Apple Inc.)
- Consigned task content: Social login authentication
- Consignment period: Until member withdrawal or consignment contract termination
3. Cafe24 Corporation
- Consigned task content: Company mall integration, mileage store-credit conversion
- Consignment period: Until member withdrawal or consignment contract termination
4. Google LLC (Firebase)
- Consigned task content: App usage analytics, error collection, remote configuration
- Consignment period: Until consignment contract termination
5. Functional Software, Inc. (Sentry)
- Consigned task content: App error and crash log collection
- Consignment period: Until consignment contract termination
6. RevenueCat, Inc.
- Consigned task content: Subscription status verification and payment management
- Consignment period: Until consignment contract termination
7. OneSignal, Inc.
- Consigned task content: Push notification delivery
- Consignment period: Until withdrawal of notification consent or consignment contract termination
Article 6-2 (Transfer of Personal Information Overseas)
The Company consigns personal information processing tasks to overseas providers for service delivery, and personal information is transferred overseas accordingly. These transfers constitute consigned processing under Article 28-8(1)3 of the Personal Information Protection Act and are disclosed below pursuant to Article 28-8(3) of the same Act.
[Transfers essential to service provision]
1. Google LLC (Firebase)
- Country: United States
- Items transferred: Device information, app usage records, error logs
- Purpose: App usage analytics and error collection
2. Functional Software, Inc. (Sentry)
- Country: United States
- Items transferred: Error logs, device information
- Purpose: App stability improvement
[Transfers the user can choose]
3. RevenueCat, Inc.
- Country: United States
- Items transferred: Purchase history, app user identifier
- Purpose: Subscription status verification and payment management
- This transfer occurs only when the user uses the subscription service
4. OneSignal, Inc.
- Country: United States
- Items transferred: Push notification token, user identifier
- Purpose: Push notification delivery
- This transfer occurs only when the user has consented to receive notifications
[Common terms]
- Time and method of transfer: Transmitted over the information and communications network at the time of service use
- Retention and use period: Until consignment contract termination
- How to refuse and the effect of refusal
- The transfers in items 1 and 2 are essential to service provision and app stability; if you refuse them you cannot use the Service. If you do not want these transfers, you may stop them by withdrawing your membership
- The transfer in item 3 does not occur if you do not use the subscription service
- The transfer in item 4 can be refused by revoking notification permission in your device settings
- Refusing items 3 and 4 places no restriction on your use of other services
Article 7 (Rights and Obligations of Data Subjects and Exercise Methods)
Data subjects may exercise the following personal information protection-related rights against the Company at any time:
1. Request to view personal information
2. Request for correction if there are errors
3. Request for deletion
4. Request for suspension of processing
Rights may be exercised through writing, telephone, email, fax, etc. to the Company, and the Company will take action without delay.
Rights may be exercised through a legal representative of the data subject or an authorized agent. In this case, a power of attorney according to Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
Data subjects must not violate the Personal Information Protection Act and other related laws to infringe on the personal information and private life of themselves or others processed by the Company.
Article 8 (Destruction of Personal Information)
The Company destroys personal information without delay when personal information becomes unnecessary, such as when the retention period has elapsed or the processing purpose has been achieved.
1. Destruction Procedure
- Even if the personal information retention period agreed upon from the data subject has elapsed or the processing purpose has been achieved, if personal information must continue to be preserved according to other laws, the relevant personal information is moved to a separate database (DB) or stored in a different storage location.
2. Destruction Method
- Information in electronic file format uses technical methods that cannot reproduce records
- Personal information printed on paper is destroyed by shredding with a shredder or incineration
3. Daily Record Photo Destruction
- Photos stored on the device: Destroyed when the user deletes them or deletes the app (non-recoverable)
- Where photos were previously stored on the server: Destroyed from the server upon deletion request or member withdrawal
Article 9 (Measures to Ensure Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information:
1. Administrative Measures
- Establishment and implementation of internal management plan
- Regular employee training
2. Technical Measures
- Access authority management for personal information processing systems
- Installation of access control systems
- Encryption of personal information
- Installation and periodic update and inspection of security programs
3. Physical Measures
- Access control to computer rooms, data storage rooms, etc.
4. Photo Data Security
- Photos stored on the device are protected by the device's own security features
- Information exchanged with the server is encrypted in transit using HTTPS
- Information stored on the server is kept encrypted with access authority minimized
Article 10 (Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)
The Company uses 'cookies' that store and retrieve usage information to provide individualized customized services to users.
1. Purpose of Cookie Use
- Analysis of users' access frequency and visit time
- Identification of users' tastes and interests
- Identification of degree of participation in various events and number of visits
- Target marketing and provision of personalized services
2. Installation, Operation, and Rejection of Cookies
- Users have the right to choose cookie installation
- By setting options in the web browser, you can allow all cookies, go through confirmation each time cookies are stored, or refuse storage of all cookies
- However, if you refuse cookie storage, there may be difficulties in using some services that require login
Article 11 (Personal Information Protection Officer)
The Company designates a Personal Information Protection Officer as follows to oversee personal information processing tasks and to handle complaints and damage relief related to personal information processing by data subjects:
Personal Information Protection Officer
- Name: Jang Gwang-woo
- Phone: 1588-2983
- Email: [email protected]
Data subjects may contact the Personal Information Protection Officer regarding all personal information protection-related inquiries, complaint handling, damage relief, etc. that occur while using the Company's services. The Company will respond to and process data subjects' inquiries without delay.
Article 12 (Remedy for Rights Infringement)
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, Korea Internet & Security Agency Personal Information Infringement Report Center, etc. to receive relief for personal information infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 (without area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (without area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (without area code) (www.spo.go.kr)
- National Police Agency: 182 (without area code) (ecrm.cyber.go.kr)
Article 13 (Changes to Privacy Policy)
This Privacy Policy is effective from May 1, 2026.
Previous Privacy Policies can be found below:
- Not applicable (initial enactment)
ACT Inc.
Phone: 1588-2983
Email: [email protected]