Privacy Policy

Site Privacy Policy

Rainbow Robotics Co., Ltd. (the “Company”) establishes and discloses the following privacy policy pursuant to Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. The personal information being processed is not used for any purpose other than the following, and where the purpose of use is changed, the Company will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.

1. Website membership registration and management
Personal information is processed for the purposes of confirming the intention to register as a member, identifying and authenticating the individual in connection with the provision of membership services, maintaining and managing member status, preventing fraudulent use of the services, and giving various notices and communications.

2. Handling of civil petitions
Personal information is processed for the purposes of verifying the identity of the petitioner, confirming the details of the petition, contacting and notifying the petitioner for fact-finding, and notifying the results of processing.

3. Provision of services
Personal information is processed for the purposes of providing content and verifying identity.

4. Use for marketing and advertising
Personal information is processed for the purposes of developing new services (products) and providing customised services, providing event and promotional information and opportunities to participate, verifying the effectiveness of the services, ascertaining access frequency, and compiling statistics on members’ use of the services.

Article 2 (Processing and Retention Period of Personal Information)

① The Company processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period consented to by the data subject when the personal information was collected.

② The processing and retention period for each category of personal information is as follows.

Retained itemBasisRetention period
Personal information relating to website membership registration and managementConsent of the data subject3 years
User information for handling requests such as access to personal informationPersonal Information Protection Act, Articles 35-393 years
Personal information relating to inquiriesConsent of the data subject1 year
Service visit recordsProtection of Communications Secrets Act1 year

Article 3 (Provision of Personal Information to Third Parties)

Not applicable

Article 4 (Entrustment of Personal Information Processing)

Not applicable

Article 5 (Rights and Obligations of Data Subjects and Their Legal Representatives, and How to Exercise Them)

① A data subject may at any time exercise rights against the Company, such as requesting access to, correction of, deletion of, or suspension of the processing of personal information.

② The exercise of rights under Paragraph 1 may be made to the Company in writing, by e-mail or by facsimile (FAX) pursuant to Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on it without delay.

③ The exercise of rights under Paragraph 1 may be made through an agent, such as the data subject’s legal representative or a duly authorised person. In such case, a power of attorney in the form of Annex No. 11 of the “Public Notice on Methods of Personal Information Processing (No. 2020-7)” must be submitted.

④ A request for access to personal information or for suspension of processing may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

⑤ A request for correction or deletion of personal information may not seek deletion where the personal information is specified as a subject of collection under other laws.

⑥ Where a data subject makes a request for access, a request for correction or deletion, or a request for suspension of processing under their rights, the Company verifies whether the person making the request is the data subject or a duly authorised agent.

Article 6 (Items of Personal Information Processed)

1. Recruitment / purchase / product / other inquiries
Information provided, such as name and e-mail address

2. The following personal information items may be automatically generated and collected in the course of using internet services.
IP address, cookies, MAC address, service use records, visit records, records of improper use, etc.

Article 7 (Destruction of Personal Information)

① Where personal information becomes unnecessary, such as upon the expiry of the retention period or the achievement of the processing purpose, the Company destroys the personal information concerned without delay.

② The procedure and method for destroying personal information are as follows.

  • 1. Destruction procedure
    The Company selects the personal information for which a ground for destruction has arisen and destroys it with the approval of the Company’s personal information protection officer.
  • 2. Destruction method
    Information in the form of electronic files is destroyed using a technical method that makes the records irreproducible. Personal information printed on paper is destroyed by shredding or incineration

Article 8 (Measures to Ensure the Safety of Personal Information)

The Company takes the following measures to ensure the safety of personal information.

1. Administrative measures: minimising and training the staff who handle personal information, establishing and implementing an internal management plan, etc.

2. Technical measures: technical countermeasures against hacking and the like, encryption of personal information, restriction of access to personal information, use of locking devices for document security, etc.

Article 9 (Matters Concerning the Installation and Operation of, and Refusal of, Devices that Automatically Collect Personal Information)

① The Company uses ‘cookies’, which store usage information and retrieve it from time to time, in order to provide individually customised services to users.

② A cookie is a small amount of information that the server (http) used to operate the website sends to the user’s computer browser, and it may also be stored on the hard disk of the user’s PC.

  • a. Purpose of using cookies : Cookies are used to provide users with optimised information by ascertaining visits to and patterns of use of each service and website the user has visited, popular search terms, whether the connection is secure, and so on.
  • b. Installation and operation of, and refusal of, cookies : You may refuse the storage of cookies through the option settings in Tools>Internet Options>Privacy at the top of your web browser.
  • c. If you refuse the storage of cookies, you may experience difficulty in using customised services.

Article 10 (Personal Information Protection Officer)

① The Company has overall responsibility for the work relating to the processing of personal information and, in order to handle complaints from data subjects and provide remedies for damage in relation to the processing of personal information, has designated a personal information protection officer as set out below.

► Personal Information Protection Officer
Name: Lee Jungho, Chief Executive Officer

► Department in Charge of Personal Information Protection
Department: Marketing Team Person in charge: Kim Yurim Contact: Tel) 042-719-8104, Fax) 042-719-8071, E-mail) yr.kim@rainbow-robotics.com

① Data subjects may direct to the personal information protection officer and the department in charge all matters relating to personal information protection inquiries, complaints and remedies for damage that arise while using the Company’s services (or business). Rainbow Robotics will respond to and handle data subjects’ inquiries without delay.

Article 11 (Request for Access to Personal Information)

A data subject may submit a request for access to personal information under Article 35 of the Personal Information Protection Act to the department below. The Company will endeavour to ensure that data subjects’ requests for access to personal information are processed promptly.

► Department Receiving and Handling Requests for Access to Personal Information
Department: Marketing Team Person in charge: Kim Yurim Contact: Tel) 042-719-8104, Fax) 042-719-8071, E-mail) yr.kim@rainbow-robotics.com

Article 12 (Remedies for Infringement of Rights)

In order to obtain a remedy for infringement of personal information, a data subject may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Centre of the Korea Internet & Security Agency, and the like. For other reports of, and consultation on, personal information infringement, please contact the organisations below.

1. Personal Information Dispute Mediation Committee : (no area code) 1833-6972 (www.kopico.go.kr)

2. Personal Information Infringement Report Centre : (no area code) 118 (privacy.kisa.or.kr)

3. Supreme Prosecutors’ Office : (no area code) 1301 (www.spo.go.kr)

4. National Police Agency : (no area code) 182 (ecrm.cyber.go.kr)

A person whose rights or interests have been infringed by a disposition taken, or an omission made, by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information) or Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act may request an administrative appeal as prescribed by the Administrative Appeals Act.

※ For details on administrative appeals, please refer to the website of the Central Administrative Appeals Commission (www.simpan.go.kr).

Article 13 (Changes to the Privacy Policy)

① This privacy policy applies from 10 February 2023.