Hashscraper Co., Ltd. (hereinafter referred to as the "Company") operates Hashscraper services (hereinafter referred to as the "Service") and complies with the relevant legal regulations related to personal information protection, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, Personal Information Protection Act, Telecommunications Privacy Act, and the Electric Communications Business Act, to protect the rights and interests of users.
This Privacy Policy is written to inform users of how the personal information they provide is collected, used, and what measures the Company takes to protect personal information.
1. Collection of Personal Information and Collection Method
1) Items of Personal Information Collected
(1) The Company collects the following minimum personal information as mandatory items to facilitate smooth customer support and service provision upon initial membership registration:
- Mandatory items: Email, name (nickname), password, type (individual/corporate/organization), region
- Optional items: Company/organization name, department
(2) Additional information may be collected during the service usage process or business processing, such as:
- Transaction information: For individuals, date of birth, accounting personnel information (name, contact information, email address) for tax invoice issuance, etc.
- Service usage information: Mobile phone number, IP address, cookies, visit date and time, service usage records, improper usage records, browser information, operating system information (OS), device information, MAC address, visit date and time, etc.
2) Collection Method of Personal Information
The Company collects personal information through the following methods:
(1) Website, written forms, telephone, email, event participation, fax, consultation tools, delivery requests
(2) Provided by partner companies
2. Purpose of Collection and Use of Personal Information
1) User Management
Provision of member-based services, personal identification, restrictions on usage for members who violate the terms of use, sanctions against improper use of services, confirmation of intention to join, limitation on the number of registrations, confirmation of legal representative's consent when collecting personal information of children under 14 years of age, future verification of legal representative, record retention for dispute resolution, complaint processing, notification of notices, confirmation of intention to withdraw membership, etc.
2) Utilization for Development of New Services and Marketing/Advertising
Development of new services and provision of personalized services, provision of services and advertising based on statistical characteristics, confirmation of service validity, provision of event information and participation opportunities, provision of advertising information, understanding usage frequency, statistics on user service usage, etc.
3) Performance of Contractual Obligations and Fee Settlement for Paid Services
Provision of content, provision of specific customized services, charging for the use of paid services, purchase and payment for goods, delivery of goods or billing, debt collection for fees, etc.
4) Use as Legal Evidence
Submission of evidence in legal disputes
3. Sharing and Provision of Personal Information
The Company uses the personal information of users within the scope notified in "2. Purpose of Collection and Use of Personal Information" and does not disclose the user's personal information to external parties beyond this scope without the user's prior consent, except in the following cases:
1) When the user has given prior consent
2) When required by law or when requested by an investigative agency according to the procedures and methods specified in the law for investigation purposes
4. Handling of Personal Information by Outsourcing
In order to improve the service, the Company entrusts personal information as follows and stipulates necessary matters to ensure the safe management of personal information in accordance with relevant laws and regulations.
1) NICE Payment Service Corp.: Payment processing via credit card
2) NHN KCP Corp.: Mobile phone authentication
3) NHN Entertainment Corp.: Sending KakaoTalk notifications
4) Amazon Web Services Inc.: Operation and management of domestic and foreign cloud servers where personal information is stored
5. Retention and Use Period of Personal Information
In principle, the user's personal information is promptly disposed of once the purpose of collection and use of personal information is achieved. However, if there is a need to retain the information in accordance with the provisions of the Commercial Act, the Act on Consumer Protection in Electronic Commerce, etc., the Company will retain the member's information for a certain period specified by the relevant laws. In this case, the retention period is as follows:
1) Records related to contracts or withdrawal of offers
- Retention reason: Act on Consumer Protection in Electronic Commerce, etc.
- Retention period: 5 years
2) Records related to payment of fees and supply of goods, etc.
- Retention reason: Act on Consumer Protection in Electronic Commerce, etc.
- Retention period: 5 years
3) Records of handling consumer complaints or disputes
- Retention reason: Act on Consumer Protection in Electronic Commerce, etc.
- Retention period: 3 years
4) Website visit records
- Retention reason: Telecommunications Privacy Act
- Retention period: 3 months
6. Personal Information Destruction Procedure and Method
The user's personal information is disposed of promptly after the purpose of collection and use of personal information is achieved. The Company's personal information destruction procedure and method are as follows:
1) Destruction Procedure
- Personal information entered by the user for membership registration is stored in a separate DB (for paper records, in a separate file) and is destroyed after being stored for a certain period according to the Company's internal policy and other relevant laws (refer to the retention and use period)
- Personal information is not used for any purpose other than retention.
2) Destruction Method
- Personal information printed on paper is destroyed through shredding or incineration.
- Personal information stored in electronic file format is deleted using technical methods that prevent record reproduction.
7. Rights of Users and Legal Representatives and How to Exercise Them
- Users and legal representatives can inquire about or modify the personal information of themselves or the child under 14 years of age registered with the Company, and they may refuse consent or request withdrawal of membership (withdrawal of consent). However, in such cases, some or all of the services may be difficult to use.
- To inquire about or modify personal information (or member information), use the "Change Personal Information" (or "Modify Member Information," etc.) function on the service. To request withdrawal of membership (withdrawal of consent), contact the Company's contact information provided on the website or use the member withdrawal function on the service.
- Alternatively, you can contact the personal information management officer in writing, by telephone, or by email, and we will promptly take the necessary measures.
- If a user requests the correction of an error in personal information, we will not use or provide the personal information until the correction is completed. If incorrect personal information has already been provided to a third party, we will notify the third party of the correction without delay to ensure that the correction is made.
- Personal information that has been terminated or deleted at the request of the user or the legal representative will be processed and handled in accordance with the "Retention and Use Period of Personal Information" section, and access or use for other purposes will not be allowed.
8. Installation/Operation and Rejection of Personal Information Automatic Collection Device
1) What is a cookie?
- The Company uses cookies to provide personalized and customized services.
- A cookie is a very small text file sent from the web server operating the website to the user's browser. It is
stored on the user's hard disk, and when the user visits the website again, the web server reads the contents of the cookie stored on the user's hard disk to maintain the user's settings and provide personalized services.
- Cookies do not automatically or actively collect information that identifies individuals, and users can refuse or delete all cookies by setting options in their web browser.
2) Purpose of Using Cookies by the Company
-The Company uses cookies to store and periodically retrieve the user's preferred settings to provide a faster web environment and support convenient use by improving the service.
- The Company uses cookies to analyze the frequency of access, visit time, visit frequency, etc., to understand the user's preferences and areas of interest for service provision.
3) Installation/Operation and Rejection of Cookies
- Users have the option to allow or reject cookie installation. Therefore, users can allow all cookies, confirm each time cookies are stored, or reject all cookie storage through their web browser options.
- However, if you reject the storage of cookies, certain features for online contract performance, such as tracking, may not function properly, and the Company shall not be responsible for any problems caused by the user's carelessness or internet issues, such as leakage of IDs, passwords, etc.
- The method to specify whether to allow the installation of cookies (for Internet Explorer) is as follows:
① Click [Tools] > [Internet Options].
② Click [Privacy].
③ Set [Privacy Level].
- The method to specify whether to allow the installation of cookies (for Chrome) is as follows:
① Click the icon in the upper right corner [Customize > Settings].
② Click [Advanced > Content Settings].
③ Set [Cookies and site data].
9. Technical and Managerial Measures for Protection of Personal Information
The Company makes efforts to ensure the safety of personal information and prevent its loss, theft, leakage, alteration, or damage during the processing of personal information of users.
1) Password encryption
User passwords for the service are encrypted and stored, known only to the users themselves, and only users with the password can verify and modify personal information.
2) Measures against hacking, etc.
The Company strives to prevent user personal information from being leaked or damaged due to hacking or computer viruses.
The Company regularly backs up data to prevent personal information from being lost and uses the latest virus protection programs to prevent personal information and data from being leaked or damaged. Additionally, the Company uses encryption communication to securely transmit personal information over the network. Furthermore, the Company controls unauthorized access from external sources using an intrusion prevention system and makes efforts to secure all possible technical devices to enhance security.
3) Minimization of employees handling personal information and training
Personal information processing personnel of the Company is limited to designated personnel, and they are provided with separate passwords, which are regularly renewed. In addition, regular training is provided to employees to emphasize compliance with the Service's Privacy Policy.
4) Operation of a dedicated team for personal information protection
The Company operates an internal personal information protection team to verify compliance with the Service's Privacy Policy and the compliance of personnel. In case of any problems, the team takes immediate corrective action. However, the Company shall not be held responsible for any problems caused by the user's negligence or problems on the internet, such as leakage of IDs, passwords, etc.
10. Personal Information Management Officer and Contact Information for Inquiries
Users can report all complaints related to personal information protection or request consultation to the Personal Information Management Officer or the relevant department. The Company will respond promptly with sufficient answers to users' complaints.
Personal Information Management Officer
Name: Kim Kyung-ho
Department: Development Department
Position: CEO
Email: help@hashscraper.com
For other complaints or inquiries related to personal information infringement, please contact the following agencies:
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without area code)
- Cyber Crime Investigation Unit of the Supreme Prosecutor's Office (www.spo.go.kr / 02-3480-3571)
- Cyber Safety Bureau of the Korean National Police Agency (www.ctrc.go.kr / 182 without area code)
11. Scope of Application
This "Service Privacy Policy" does not apply to other websites linked to the Service that collect personal information. This "Service Privacy Policy" applies only to members who have signed a service agreement with the Company.
12. Notification Obligation
If there are any additional, deleted, or modified contents in this Privacy Policy, we will notify you by email at least 7 days before the revision. However, if there are significant changes to the rights of users, such as the collection and use of personal information, and third-party provision, we will notify you at least 30 days in advance.
13. Application of Electronic Signature Privacy Policy
When a user requests an electronic signature from a signatory as a requester, the Electronic Signature Privacy Policy is also applied.
Revised date: December 23, 2019
Effective date: December 23, 2019