Privacy

Privacy Policy

1. Purpose
This policy establishes the following guidelines for Korea Expert Co., Ltd. (hereinafter referred to as the “Company”) to ensure that all personal information it handles complies with the personal information protection regulations set forth in the Personal Information Protection Act and other relevant laws and regulations, thereby protecting the personal information and rights and interests of data subjects (users) and facilitating the smooth resolution of grievances related to personal information. Translated with DeepL.com (free version)
2. Categories of Personal Information Processed
The Company processes the items listed below and collects only the minimum amount of personal information necessary to provide its services; it does not collect personal information from individuals under the age of 14. To use our services, you must fill out both required and optional fields; however, leaving optional fields blank will not affect the provision of basic services. The Company processes information collected with your consent in accordance with the law.
  • 1. Employee Recruitment and Human Resources Management
    - Required fields: Name, Gender, Address, Date of Birth, Photo, Contact Information (Email Address, Cell Phone Number), Veterans Status (if applicable), Military Service Status (if applicable), Educational Background, Work Experience, Project Experience, Certifications, Personal Statement, Written/Practical Test Results (if applicable).
    - Optional Information: None
  • 2. Responding to Product Inquiries
    - Required fields: Company Name/Department, Name, Phone Number, Email, Inquiry Details
    - Optional fields: Job Title/Position
  • 3. Marketing (Opt-in)
    - Required fields: Company/Organization Name, Full Name, Contact Information, Email Address
  • 4. Use of Internet Services
    - Items: IP address, cookies, service usage history, visit history
3. Purpose of Personal Information Processing
The Company processes personal information for the following purposes. The personal information being processed will not be used for any purposes other than those listed below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
  • 1. Employee Recruitment and Human Resources Management: We process personal information for the purposes of handling administrative tasks related to job applications and recruiting new employees.
    2. Handling Product Inquiries: We process personal information to collect and respond to inquiries regarding our company’s products.
    3. Marketing: We process the personal information of data subjects who have consented to receive communications in order to send promotional information, such as event and seminar announcements; provide services and display advertisements based on demographic characteristics; and send e-newsletters.
    4. While using the Internet service, personal information items listed in Article 2, Item 3 may be automatically generated and collected.
4. Processing and Retention Period of Personal Information
The Company processes personal information for the following purposes. The personal information being processed will not be used for any purposes other than those listed below, and if the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
  • ① The Company processes and retains personal information within the retention and use period prescribed by law or within the retention and use period agreed upon by the data subject at the time of collection, and destroys such information without delay once the purpose of processing has been achieved.
  • ② The processing and retention periods for each type of personal information are as follows.
    1. Employee Recruitment and Human Resources Management: Personal information collected from job applicants during the recruitment process is destroyed once recruitment for the position in question is completed. Personal information of employees is retained and used after their resignation solely for the purposes of accident prevention, investigations, dispute resolution, handling of complaints, and compliance with legal obligations.
    2. Handling of Product Inquiries: Personal information will be retained and used for one year from the date of consent regarding its collection, use, and disclosure. However, if a request is made to delete the collected personal information, such information will be destroyed immediately.
    3. Marketing: Personal information will be retained and used for one year from the date of consent regarding its collection, use, and disclosure. However, if a request is made to delete the collected personal information, such information will be destroyed immediately.
    4. Internet service usage and visit records are retained for three months in accordance with the provisions of the “Communications Secrecy Protection Act.”
5. Disclosure of Personal Information to Third Parties
The Company processes the data subject’s personal information only within the scope specified in the purpose of processing such information and shall not provide such information to third parties without the data subject’s consent, except in cases prescribed by law, such as the data subject’s consent or special provisions of the law, in accordance with “Article 18 of the Personal Information Protection Act (Provisions on Restrictions on the Use and Provision of Personal Information for Purposes Other Than Those Specified).” However, personal information may be used for purposes other than those specified or provided to third parties in the following cases:
  • 1. When consent has been obtained from the data subject
    2. When there are special provisions under other laws
    3. When the data subject or his or her legal representative is unable to express his or her will, or when prior consent cannot be obtained due to an unknown address or other reasons, and it is deemed clearly necessary to protect the urgent interests of the data subject or a third party regarding life, physical safety, or property
    4. When necessary for the investigation of a crime and for the initiation and prosecution of criminal charges
6. Outsourcing of Personal Information Processing
As a general rule, the Company does not outsource the processing of data subjects’ information to external vendors. However, if the Company outsources the processing of personal information to a third party, it will do so in accordance with “Article 26 of the Personal Information Protection Act (Restrictions on the Processing of Personal Information in Connection with Outsourcing),” and will disclose the details of the outsourced tasks and the recipient through notices and the Privacy Policy. Furthermore, the Company will obtain prior consent when necessary.
7. Rights, Obligations, and Methods of Exercising Rights of Data Subjects
  • ① Data subjects may exercise the following rights related to the protection of personal information with the Company at any time:
    1. Request to access personal information
    2. Request for correction in the event of errors or inaccuracies
    3. Request for deletion
    4. Request to suspend processing
  • ② You may exercise your rights under Paragraph 1 in writing, via email, or by fax, and the Company will take action without delay.
  • ③ Requests to access personal information or suspend its processing may be restricted in accordance with Article 35, Paragraph 4, and Article 37, Paragraph 2 of the Personal Information Protection Act.
  • ④ Requests for the correction or deletion of personal information cannot be made if other laws or regulations explicitly designate such personal information as subject to collection.
  • ⑤ When receiving requests for access, correction, deletion, or suspension of processing in accordance with the data subject’s rights, the Company will verify whether the person making the request is the data subject or a legitimate representative.
  • ⑥ If a data subject requests the correction of an error in their personal information, the Company shall not use or provide such personal information until the correction is completed.
8. Procedures and Methods for the Destruction of Personal Information
  • ① The Company shall destroy personal information without delay (within 5 days) when it is no longer necessary, such as upon the expiration of the retention period or the achievement of the purpose of processing.
  • ② If the Company is required to continue retaining personal information pursuant to other laws and regulations even after the retention period agreed upon with the data subject has expired or the purpose of processing has been achieved, the Company shall transfer such personal information to a separate database or store it in a different location.
  • ③ The procedures and methods for the destruction of personal information are as follows.
    1. Destruction Procedure: The Company identifies the personal information for which grounds for destruction have arisen and destroys it upon approval from the Company’s Data Protection Officer.
    2. Destruction Method: The Company destroys personal information recorded and stored in electronic file format in a manner that prevents the data from being recovered, and destroys personal information recorded and stored on paper documents by shredding or incineration.
9. Measures to Ensure the Security of Personal Information
The Company implements the following technical, administrative, and physical measures to ensure the security of personal information.
  • 1. Administrative Measures: Establishment and implementation of internal management plans; operation of a dedicated organization; regular employee training
    2. Technical Measures: Management of access rights to personal information processing systems; installation of access control systems; encryption of personal information; installation and updating of security software
    3. Physical Measures: Access control for computer rooms, data storage rooms, and other facilities
10. Remedies for Violations of Rights
  • ① To seek redress for a personal information infringement, data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency, the Personal Information Infringement Reporting Center, and other relevant organizations. For other reports or consultations regarding personal information infringements, please contact the following organizations.
    1. Personal Information Dispute Mediation Committee: (No area code required) 1833-6972 (www.kopico.go.kr)
    2. Personal Information Infringement Reporting Center: (No area code required) 118 (privacy.kisa.or.kr)
    3. Supreme Prosecutors’ Office: (No area code required) 1301 (www.spo.go.kr)
    4. National Police Agency Cyber Safety Guardians: (No area code required) 182 (ecrm.cyber.go.kr)
  • ② The Company guarantees data subjects’ right to self-determination regarding their personal information and strives to provide consultation and redress for damages resulting from personal information infringements. If you need to file a report or seek consultation, please contact the relevant department listed below.
    - Management Support Team: 02-712-9039
  • ③ Any person whose rights or interests have been infringed upon due to a disposition or omission by the head of a public institution in response to a request made pursuant to the provisions of Article 35 (Access to Personal Information), Article 36 (Correction and Deletion of Personal Information), and Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeal Act.
    1. Central Administrative Appeals Commission: (No area code required) 110 (www.simpan.go.kr)
11. Matters Concerning the Chief Privacy Officer, etc.
  • ① The Company has designated the following Chief Privacy Officer and other personnel to take overall responsibility for personal information processing and to handle complaints from data subjects and provide remedies for damages related to such processing.
    1. Chief Privacy Officer: Bae Jin-hee, Executive Vice President / 02-782-5200 / jhbae@kei.co.kr
    2. Data Protection Officer: Park Young-jin, Assistant Manager / 02-782-5200 / yjpark@kei.co.kr
  • ② Data subjects may contact the Data Protection Officer and the responsible department regarding any inquiries, complaints, or requests for redress related to personal information protection that arise while using the Company’s services or conducting business with the Company. The Company will respond to and address data subjects’ inquiries without delay.
  • ③ Data subjects may submit requests to access their personal information to the Personal Information Protection Department in accordance with Article 35 of the Personal Information Protection Act. The Company will make every effort to ensure that data subjects’ requests to access their personal information are processed promptly.
12. Changes to the Privacy Policy
  • This policy takes effect on the effective date, and any additions, deletions, or amendments made in accordance with laws, regulations, or this policy will be announced via the notices section.
    Privacy Policy Effective Date: August 23, 2024
    Effective Date of the Privacy Policy: August 23, 2024