개인정보 처리방침

General Provisions

Josefkim ("Company" or "Josefkim") is committed to protecting your personal information and complies with applicable laws such as the Act on Promotion of Information and Communications Network Utilization and Information Protection, and the Protection of Communications Secrets Act.

This Privacy Policy outlines how we collect, use, and protect your data.

1. Protection of Users Personal Information

"Personal Information" refers to information related to a living individual that can identify the person, such as name, contact details, or other identifiable data.

2. Items Collected and Methods of Collection

(1) Collected Items
- Required: Name, real-name verification (e.g., i-PIN), date of birth, gender, user ID, password, address, home phone, mobile number, email
- Optional: Occupation, marital status, anniversary
- Automatically Collected: IP address, cookies, service usage history, access logs
- Payment Info: Card details or bank account (depending on payment method)
- Shipping/Service Info: Recipient name, contact details
- Event Participation: Additional data as stated during event entry

(2) Collection Methods
Data is collected via the website during membership registration and information updates.

(3) Consent
Consent is obtained via an agreement prompt during signup. In some legal or technical cases, personal data may be used without explicit consent as permitted by law.

3. Provision and Sharing with Third Parties

Josefkim collects the minimum necessary personal information to provide better, high-quality services such as user registration and personalized offerings. The personal information collected is used for the following purposes:

(1) Member Management
To verify identity for membership-based services, distinguish individuals, prevent misuse by unauthorized or malicious users, prevent identity theft and unauthorized use through real-name verification, confirm user ownership of rental, membership, or one-time purchase products, confirm membership intent and age, handle complaints and customer service inquiries, and deliver important notifications.

(2) Fulfillment of Service Contracts and Billing
To fulfill contractual obligations related to service provision and to settle fees: providing content, delivering ordered products, distributing event prizes, processing purchases and payments, issuing invoices, verifying financial transactions, providing financial services, and collecting outstanding payments.

(3) Development of New Services, Marketing, and Advertising
To develop new services and offer personalized services, deliver promotional and event-related information, analyze access frequency, and provide targeted services or advertisements based on statistical analysis of users’ service usage patterns.

The above information includes not only the data provided at the time of registration but also any updates made through later modifications.

4. Sharing and Disclosure Principles

As a general principle, the Company does not use a user’s personal information beyond the scope stated in “3. Purpose of Collection and Use of Personal Information,” nor does it provide such information to third parties, other companies, or institutions. However, exceptions may apply in the following cases:
(1) When the user has given prior consent to the provision of personal information to a third party
(2) When required by other applicable laws or regulations

5. Retention and Usage Period

(1) Data is deleted once the purpose is fulfilled

(2) Retention Periods:

1. Contract & Cancellation: 5 years

2. Payments & Delivery: 5 years

3. Complaints: 3 years

(3) Inactive users (1+ year): Data may be deleted unless otherwise specified

6. Destruction Procedures and Methods

As a general principle, Josefkim promptly destroys personal information once the purpose of its collection and use has been fulfilled. The procedures and methods of destruction are as follows:

(1) Destruction Procedure
1. Information provided for purposes such as membership registration is transferred to a separate database (or, in the case of paper documents, stored in a secure file cabinet) after the intended purpose has been achieved. It is then retained for a certain period in accordance with internal policies and relevant laws (refer to the retention and use period), and subsequently destroyed.
2. Such personal information will not be used for any purpose other than legal requirements or the stated retention purpose.

(2) Destruction Methods
1. Personal information printed on paper is destroyed by shredding or incineration.
2. Personal information stored in electronic file format is deleted using technical methods that render the data irrecoverable.

7. Rights of Users and Legal Representatives

(1) Users and their legal representatives may, at any time, view or modify their own registered personal information, or request to cancel their membership.

(2) To view or modify personal information, users can click on "Edit Personal Information" (or “Update Member Info”), and to cancel membership (withdraw consent), they can click on “Delete Account.” These actions require identity verification, after which users can directly access, correct, or delete their data.

(3) Users may also contact the personal data protection officer in writing, by phone, or via email, and appropriate action will be taken after identity verification.

(4) If a user requests correction of an error in their personal information, the information in question will not be used or shared until the correction is completed. If the incorrect information has already been provided to a third party, Josefkim will promptly notify that party of the correction so that it can be properly applied.

(5) Personal information that has been canceled or deleted at the request of the user or their legal representative will be handled in accordance with the retention and usage period specified in section “6. Retention and Use of Personal Information,” and will not be accessed or used for any other purpose.

8. Use of Cookies and Refusal Options

To provide users with specialized and personalized services, Josefkim uses "cookies" that store and retrieve user information from time to time. A cookie is a small piece of data sent by the server (HTTP) used to operate the website to the user’s browser, and it may also be stored on the user’s hard drive.

The Company uses cookies for the following purposes:

(1) Purpose of Using Cookies
Cookies are used to analyze the frequency and time of visits by both members and non-members, to understand users’ preferences and areas of interest, to track usage patterns, and to determine participation in various events and the number of visits. This information is utilized for targeted marketing and providing personalized services.

(2) Installation, Operation, and Rejection of Cookies
Users have the option to allow or reject the use of cookies. By configuring their web browser settings, users can choose to:
Allow all cookies
Receive a prompt each time a cookie is stored
Reject all cookies
Please note: If a user refuses to store cookies, some services that require login may not function properly.
Example of Cookie Settings (for Internet Explorer):
Go to the top menu of your web browser → Tools > Internet Options > Privacy tab.

9. Technical and Managerial Safeguards

Josefkim takes the following technical and administrative measures to ensure the safety of users’ personal information and to prevent loss, theft, leakage, alteration, or damage during handling:

(1) Password Encryption
Passwords associated with member IDs are stored and managed in encrypted form, known only to the user. These passwords are encrypted using a one-way hashing algorithm. Personal information can only be viewed or modified by users who know their own password.

(2) Protection Against Hacking and Other Threats
The company makes every effort to prevent personal information from being leaked or damaged due to hacking, computer viruses, or other threats. Data is regularly backed up to prepare for potential damage, and up-to-date antivirus programs are used to protect against data breaches or corruption. Encrypted communication is employed to ensure the safe transmission of personal data over the network. In addition, intrusion prevention systems are in place to control unauthorized external access, and all technically and administratively feasible security measures are implemented to enhance system security.

(3) Minimization and Training of Personnel Handling Personal Information
Employees handling personal data are limited to designated personnel only. These individuals are given separate, regularly updated passwords and receive ongoing training to ensure strict compliance with the company’s privacy policy.

(4) Operation of a Dedicated Privacy Protection Team
A dedicated internal privacy protection team is responsible for monitoring the implementation of privacy policies and compliance by the designated personnel. When any issues are identified, immediate corrective actions are taken.
Note: The company assumes no responsibility for incidents caused by the user’s own negligence or issues arising from the nature of the internet, such as the leakage of ID, password, or identity verification information.

(5) Encryption of Personally Identifiable Information
Personally identifiable information such as real-name verification data, registration authentication, phone numbers, bank account numbers, and addresses (including specific lot or unit numbers) is encrypted before being stored and managed. Access to or modification of such data is permitted only by the data subject.

(6) Prevention of Tampering with Access Records
When a personal information handler accesses the personal data processing system, access logs including date, time, and activity are recorded and stored separately to prevent tampering or unauthorized modification.

10. Personal Information Protection Officer

Josefkim values customer feedback highly and allows you to report any personal information-related complaints arising during the use of our services to our data protection team.

RoleNameAffiliationE-Mail
Chief Privacy OfficerMinkoo KimJosefkim Inc.mk.kim@josefkim.com
Data Protection ManagerMinkoo KimJosefkim Inc.mk.kim@josefkim.com

Customers may also seek resolution or consultation regarding personal information infringements through the following organizations:

- Privacy Portal: privacy.go.kr
- KISA: privacy.kisa.or.kr / 118
- Prosecution Cyber Unit: spo.go.kr / 02-3480-3600
- Cyber Terror Center: ctrc.go.kr / 02-392-0330

11. User Responsibilities

Please make sure to keep your personal information accurate and up to date to prevent unexpected incidents. You are solely responsible for any issues that arise from providing incorrect information. If false information is entered, such as by using someone else’s personal data, your Josefkim membership may be revoked or access to the Josefkim website may be suspended. You are also responsible for maintaining the security of your user ID and password related to your personal information.

As a user, you have the right to have your personal information protected, and also the obligation to protect yourself and not infringe on the privacy of others. Josefkim will never ask for your password by any means, so please take extra care not to share it with anyone. Be cautious not to harm or disclose others’ personal information, including in posts or comments. If you fail to fulfill these responsibilities and infringe on others’ information, you may be subject to legal penalties under applicable laws. Extra caution is advised when accessing the site in public spaces.

Josefkim has appointed a Data Protection Officer and a dedicated team responsible for handling personal data-related feedback and complaints.

12. Notification of Changes

Changes to this policy will be posted at least 7 days in advance (30 days if changes affect user rights).

Notice Date: May 28, 2025
Effective Date: June 28, 2025