Privacy Policy
1. Purpose of processing personal information
(“http://sapzaru.com” or “sapzaru”) processes personal information for the following purposes, and is not used for purposes other than the following.
-Confirmation of customer subscription, identification and authentication by providing services to customers, maintenance and management of membership, payment of payments by supply of goods or services, supply and delivery of goods or services, etc.
2. Processing and retention period of personal information
① ('http://sapzaru.com' or'sapzaru') is an individual within the period of retention and use of personal information agreed upon when collecting personal information from an information subject or the period of retention and use of personal information according to laws and regulations. Process and retain information.
② Specific personal information processing and retention periods are as follows.
☞ Refer to the example below and describe the retention period and related laws and rationale for personal information processing and personal information processing.
(Example)-Customer subscription and management: Until the service use contract or membership cancellation, but if the bond-debt relationship remains, until the settlement of the bond/debt relationship
-Supply records of contract, subscription withdrawal, payment, and goods in e-commerce: 5 years
3. Personal information processing consignment
① ('sapzaru') entrusts the following personal information processing services for smooth personal information processing.
One.
-Trustee (trustee): sapzaru
-Contents of entrusted work: identity verification according to the use of membership service, complaint handling such as complaint handling, delivery of notices, development of new services (products) and provision of customized services, information on events and advertisements, and participation opportunities
-Consignment period: destroy without delay
② ('http://sapzaru.com' or'sapzaru') is prohibited from the processing of personal information, technical and administrative protection measures, and re-entrustment in addition to the purpose of performing consignment work pursuant to Article 25 of the Personal Information Protection Act when signing a consignment contract. In addition, the management and supervision of the trustee, and the responsibility for damages, etc. are specified in documents such as contracts, and the trustee is supervised to safely handle personal information.
③ If the contents of the consignment service or the trustee are changed, we will disclose it through this personal information processing policy without delay.
4. Rights and obligations of the data subject and legal representatives and how to exercise them The user can exercise the following rights as the data subject.
① The information subject can exercise the following privacy rights at any time for sapzaru (“http://sapzaru.com” or “sapzaru”).
1. Request to view personal information
2. Request for correction in case of errors
3. Request to delete
4. Request to stop processing
5. Preparation of items of personal information to be processed
① ('http://sapzaru.com' or'sapzaru') processes the following personal information items.
1 <Member registration and management>
-Required items: Email, password question and answer, password, login ID, service usage record, access log, access IP information
-Optional: Email, password question and answer, password, login ID
6. Destruction of personal information ('sapzaru'), in principle, destroys the personal information without delay when the purpose of processing personal information is achieved. The procedure, deadline and method of destruction are as follows.
-Destruction procedure
The information entered by the user is transferred to a separate DB after achieving the purpose (separate documents in the case of paper) and stored for a certain period of time according to internal policies and other related laws or immediately destroyed. At this time, personal information transferred to the DB will not be used for any other purpose unless required by law.
-Destruction time
When the retention period of the personal information has elapsed, the user's personal information is provided within 5 days from the end date of the retention period. We destroy the personal information within 5 days from the date when it is deemed unnecessary.
7. Matters concerning the installation, operation and rejection of automatic collection of personal information
sapzaru does not use ‘cookies’ that store the information subject's usage information and call it from time to time.
8. Personal information protection officer
① sapzaru ('http://sapzaru.com' or'sapzaru') is responsible for the handling of personal information, and for the purpose of handling complaints and remedy of information subjects related to personal information processing as follows: Personal information protection officer is designated.
▶ Personal information protection officer
Name: sapzaru
Position: Representative
Position: CEO
Contact: sapzaru@gmail.com,
※ It leads to the department in charge of personal information protection.
▶ Personal Information Protection Department
Department name: sapzaru management team
Contact person: sapzaru
Contact: sapzaru@gmail.com,
② The information subject is the person in charge of personal information protection for all inquiries, complaints, and damage relief related to personal information protection while using the service (or business) of sapzaru ('http://sapzaru.com' or'sapzaru'). You can contact the department in charge. sapzaru ("http://sapzaru.com" or "sapzaru") will respond and process information inquiries without delay.
9. Change of personal information processing policy
① This personal information processing policy will be applied from the effective date, and if there are any additions, deletions, or corrections of changes in accordance with laws and policies, the notice will be notified 7 days prior to the implementation of the changes.
10. Measures to secure the safety of personal information ('sapzaru') is in accordance with Article 29 of the Personal Information Protection Act.
1. Minimization and training of personal information handling staff
We are taking measures to manage personal information by designating and minimizing the number of employees who handle personal information.
2. Restrict access to personal information
We take necessary measures to control access to personal information through granting, changing, and canceling access rights to the database system that processes personal information. We control unauthorized access from the outside using an intrusion prevention system.
3. Access control for unauthorized persons
Separate physical storage areas for personal information are set and access control procedures are established and operated.