Privacy Policy

Sun Vascular Clinic (hereinafter referred to as the “Clinic”), pursuant to the Personal Information Protection Act of the Republic of Korea, hereby establishes this Privacy Policy to protect users’ personal information and rights, and to ensure that any grievances relating to personal data are handled in a prompt and appropriate manner. The Clinic recognizes that users’ personal information is both a valuable personal asset and an essential component of its operations. Accordingly, the Clinic shall make its utmost effort to protect personal information throughout all stages of its business processes. In the event that this Privacy Policy is amended, the Clinic shall notify users of such amendments through its website.

Chapter 1. Consent Procedure for the Collection of Personal Information

The Clinic shall provide users with a procedure to indicate consent to the collection of personal information. When a user clicks the “Agree” button after reviewing this Privacy Policy or the Terms of Service, such action shall be deemed as consent to the collection and processing of personal information.

Chapter 2. Purpose of Collecting and Using Personal Information

The Clinic shall collect and use personal information solely for the following purposes. Collected information shall not be used for any other purpose, and in the event of a change in the purpose of use, the Clinic shall obtain the user’s prior consent.

a. Name, ID, Password: To verify a user’s intention to register as a member; To prevent fraudulent or unauthorized use of services; To analyze login frequency and service usage patterns; and To verify and identify members when providing membership-based services.

b. Email Address, Phone Number (including consent to receive messages): To deliver notices, verify user intentions, and handle inquiries or complaints; To provide a smooth communication channel between the Clinic and users; To deliver promotional information, event details, and participation opportunities; and To analyze connection frequency and compile statistical data on service usage.

c. Address, Phone Number: To ensure accurate delivery of gifts, prizes, or purchased goods.

Chapter 3. Transmission of Advertising Information

a. The Clinic shall not transmit any commercial or advertising information for profit-making purposes against the user’s explicit expression of refusal to receive such communications.

b. The Clinic may notify users of amendments to the Terms of Service, changes in service provision, new products or services, event announcements, or other relevant information via email, SMS, or other electronic communication methods. In such cases, the Clinic shall comply with all applicable legal requirements regarding the content and method of such notifications.

c. When transmitting advertising or promotional information for online marketing purposes, the Clinic shall clearly identify the nature of such communication in both the subject line and body of the message, so that users can easily recognize it as advertising content.

Chapter 4. Scope of Personal Information Collected

The Clinic allows users to access most of its content freely without requiring a separate membership registration process. However, in order to use certain membership-based services, users shall be required to provide the following information:

a. Personal Information Items Collected: Name, email address, date of birth, user ID, password, gender, address, mobile phone number (or telephone number), consent to receive emails, consent to receive SMS, service usage records, access logs, and recipient information (name, telephone number, address, email).

b. Methods of Collecting Personal Information: Through membership registration and other forms within the website (e.g., inquiry forms, bulletin boards, or event participation pages).

Chapter 5. Retention and Use Period of Personal Information

The Clinic shall promptly destroy personal information once the purpose of its collection and use has been achieved.
However, certain information may be retained for a specified period for the following reasons:

  • Retained Items: Name, login ID, password, email address, date of birth
  • Reason for Retention: To prevent recurrence of fraudulent or improper use by members with a history of misconduct
  • Retention Period: One (1) month

In addition, where it is necessary to retain personal information in accordance with relevant laws and regulations, the Clinic shall store such information for the period prescribed under those laws, as follows: Records of consumer complaints or dispute resolution: Three (3) years (pursuant to the Act on the Consumer Protection in Electronic Commerce)

Chapter 6. Procedures and Methods for the Destruction of Personal Information

In principle, the Clinic shall promptly destroy personal information once the purpose of processing such information has been fulfilled. The procedures, timelines, and methods for destruction are as follows:

  • Destruction Procedures

    Information entered by a member during registration or service use shall, upon fulfillment of its intended purpose, be transferred to a separate database (or, in the case of paper documents, stored in a separate file cabinet). It shall then be retained for a certain period in accordance with the Clinic’s internal policies and applicable laws and regulations (see Chapter 5: Retention and Use Period of Personal Information), and subsequently destroyed. Personal information transferred to a separate database shall not be used for any purpose other than retention, except as required by law.

  • Destruction Timelines

    When the retention period for personal information has expired, the Clinic shall destroy such information within five (5) days from the end of the retention period. When personal information becomes unnecessary due to the achievement of its processing purpose, discontinuation of the relevant service, or termination of the business, the Clinic shall destroy such information within five (5) days from the date it is determined to be no longer necessary.

  • Destruction Methods

    Personal information stored in electronic file formats shall be deleted using technical methods that make the records irrecoverable.

Chapter 7. Measures to Ensure the Security of Personal Information

In accordance with Article 29 of the Personal Information Protection Act, the Clinic implements the following measures to ensure the security of personal information:

a. Minimization and Training of Personnel Handling Personal Information The Clinic designates specific employees to handle personal information and limits access to authorized personnel only, implementing management measures to minimize the number of individuals who process personal data.

b. Encryption of Personal Information Users’ personal information and passwords are encrypted for storage and management, ensuring that only the user can know them. Important data is protected through additional security measures such as file and transmission data encryption or the use of file lock functions.

Chapter 8. Designation of the Personal Information Protection Officer

The Clinic makes every effort to ensure that customers can use its services safely and securely. The person responsible for handling customers’ personal information is designated as follows, and the Clinic responds promptly and sincerely to all inquiries related to personal information.

▶ Personal Information Protection Officer

Name:

Department / Position:

Email:

Telephone Number:

Data subjects may contact the Personal Information Protection Officer or the designated personnel regarding any matters related to the protection of personal information, complaint handling, or remedies for damages arising from the use of the Clinic’s services.

Chapter 9. Collection of Feedback and Handling of Complaints

The Clinic values the feedback of its members, and every member has the right to receive a sincere response to any inquiries. To ensure smooth communication with its members, the Clinic operates a customer service center.


Real-time consultations and telephone inquiries are available only during business hours. Inquiries received by email or postal mail shall be answered sincerely within 24 hours of receipt. However, inquiries received after business hours, on weekends, or on public holidays shall, in principle, be handled on the next business day.
The Clinic shall take the following actions regarding stolen personal information:

1. When the Clinic becomes aware that a user has used another person’s personal information to register for membership or for other purposes, it shall, without delay, take the necessary measures, such as suspending the use of the corresponding ID or terminating the membership.

2. When a user who has recognized that their own personal information has been stolen requests suspension of service use or membership withdrawal for the relevant ID, the Clinic shall immediately take the necessary actions.
If consultation regarding personal information is required, users may contact the following organizations:

Personal Information Infringement Report Center: http://www.118.or.kr

Supreme Prosecutors’ Office Cyber Crime Investigation Center: http://icic.sppo.go.kr

National Police Agency Cyber Terror Response Center: http://www.police.go.kr/ctrc/ctrc_main.htm

Chapter 10. Duty of Notification

This Privacy Policy shall take effect from the date of implementation. In the event of any additions, deletions, or amendments in accordance with relevant laws or internal policies, the Clinic shall notify users of such changes through a public notice at least seven (7) days prior to the effective date of the revised policy.