Privacy Policy

This Privacy Policy ensures the lawful and secure processing of personal information in compliance with the Personal Information Protection Act to protect the freedom and rights of data subjects.

This document has been translated from the original Korean version for your convenience. In the event of any discrepancy, the Korean version shall prevail.

Article 1 (Purpose)

AplusR (hereinafter 'Company') establishes this Privacy Policy (hereinafter 'Policy') to protect the personal information of individuals (hereinafter 'Users' or 'Individuals') who use the services provided by the Company (hereinafter 'Company Services'), in compliance with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter 'Network Act'), and other relevant laws, and to promptly and smoothly handle grievances related to the protection of personal information of service users.

Article 2 (Principles of Personal Information Processing)

In accordance with personal information-related laws and this Policy, the Company may collect users' personal information, and collected personal information may be provided to third parties only with the individual's consent. However, where lawfully required by provisions of law, the Company may provide collected personal information to third parties without prior individual consent.

Article 3 (Disclosure of This Policy)

  • The Company discloses this Policy on the main page of the Company's website or through a page linked to the main page so that users can easily access it at any time.
  • When disclosing this Policy pursuant to Paragraph 1, the Company shall use font size, color, and other means to ensure users can easily review this Policy.

Article 4 (Amendments to This Policy)

  • This Policy may be amended in accordance with changes to personal information-related laws, guidelines, notices, or government or Company Service policies or content.
  • When the Company amends this Policy pursuant to Paragraph 1, it shall provide notice through one or more of the following methods:
    • Posting on the notice board or through a separate window on the main page of the Company's website
    • Notifying users by written document, fax, email, or similar methods
  • The Company shall provide notice of such amendments at least 7 days prior to the effective date of the Policy revision. However, in the case of significant changes to user rights, notice shall be provided at least 30 days in advance.

Article 5 (Information Collected for Membership Registration)

The Company collects the following information for user membership registration for Company Services:

  • Required information: Email address and nickname

Article 6 (Information Collected for Service Provision)

The Company collects the following information to provide its services to users:

  • Required information: User ID

Article 7 (Methods of Personal Information Collection)

The Company collects users' personal information through the following methods:

  • Users entering their personal information on the Company's website
  • Users entering their personal information through services other than the website provided by the Company, such as applications

Article 8 (Use of Personal Information)

The Company uses personal information in the following cases:

  • When necessary for Company operations, such as delivering notices
  • When necessary for service improvement for users, such as responding to inquiries and handling complaints
  • When necessary to provide the Company's services
  • When necessary for restricting use by members who violate laws and Company Terms, and for preventing and sanctioning actions that interfere with the smooth operation of the Service, including fraudulent use

Article 9 (Retention and Use Period of Personal Information)

  • The Company retains and uses users' personal information for the period necessary to achieve the purposes of collection and use of personal information.
  • Notwithstanding the foregoing, the Company retains records of fraudulent service use for up to 1 year from the date of membership withdrawal, in accordance with internal policies, to prevent fraudulent registration and use.

Article 10 (Retention and Use Period of Personal Information Under Applicable Laws)

The Company retains and uses personal information as follows in accordance with applicable laws:

  • Information and retention periods under the Act on the Consumer Protection in Electronic Commerce, Etc.:
    • Records related to contracts or withdrawal of offers: 5 years
    • Records related to payment and supply of goods: 5 years
    • Records related to consumer complaints or dispute resolution: 3 years
    • Records related to labeling and advertising: 6 months
  • Information and retention periods under the Protection of Communications Secrets Act:
    • Website log records: 3 months
  • Information and retention periods under the Electronic Financial Transactions Act:
    • Records related to electronic financial transactions: 5 years
  • Act on the Protection, Use, Etc. of Location Information:
    • Records related to personal location information: 6 months

Article 12 (Personal Information Destruction Procedures)

In principle, the Company shall promptly destroy personal information when it is no longer needed due to the achievement of the purpose of personal information processing, expiration of the retention and use period, or other reasons.

  • Information entered by users for membership registration and other purposes shall be transferred to a separate database (or separate filing cabinet for paper documents) after the purpose of personal information processing has been achieved, and shall be stored for a certain period in accordance with internal policies and other relevant laws regarding information protection (see retention and use periods) before being destroyed.
  • The Company shall destroy personal information for which a reason for destruction has arisen through the approval process of the Chief Privacy Officer.

Article 13 (Methods of Personal Information Destruction)

The Company deletes personal information stored in electronic file format using technical methods that make the records irreproducible, and destroys personal information printed on paper by shredding or incineration.

Article 14 (Measures for Transmission of Advertising Information)

  • When transmitting commercial advertising information using electronic transmission media, the Company obtains the user's explicit prior consent. However, prior consent is not required in the following cases:
    • When the Company has directly collected the recipient's contact information through a transaction relationship for goods, etc., and intends to transmit commercial advertising information about goods, etc. of the same type as those transacted with the recipient within 6 months from the date the transaction ended
    • When a telemarketer under the Door-to-Door Sales Act verbally informs the recipient of the source of personal information collection and makes a telemarketing call
  • Notwithstanding the foregoing, the Company shall not transmit commercial advertising information when the recipient expresses an intention to refuse reception or withdraws prior consent, and shall notify the recipient of the processing results of the refusal or withdrawal of consent.

This Policy shall be effective from April 1, 2024.