Vulnerability Report

Vulnerability Report

Intromedic enriches customers' lives with vitality, joy, and energy.

Reporter E-mail
Anonymous Submission Submit anonymously.
Product Name Model Name
SW Version Vulnerability
Detailed Description
Reproduction Method
File Attachment

File
Impact Range
Occurrence Frequency
Disclosure

Privacy Policy

Privacy Policy
Intromedic Co., Ltd. (hereinafter, the "Company") values your personal information and complies with the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this Privacy Policy, we inform you how the personal information you provide is used and protected. If this policy is revised, the Company will notify users through website notices (or individual notices).

This policy is effective as of: August 25, 2008.

1) Items of Personal Information Collected 2) Purpose of Collection and Use of Personal Information 3) Retention and Use Period of Personal Information 4) Procedures and Methods for Destruction of Personal Information 5) Provision of Personal Information 6) Entrustment of Collected Personal Information 7) Rights of Users and Legal Representatives and How to Exercise Them 8) Installation/Operation of Automatic Collection Devices and Refusal Thereof 9) Civil Service Regarding Personal Information 10) Protection of Personal Information of Children Under 14 01. Items of Personal Information Collected
• The Company collects the following personal information for membership registration, consultation, service applications, and related services.
• Collected items: name, date of birth, login ID, password, home phone number, home address, mobile phone number, email, company name, department, resident registration number, access logs, and cookies
• Collection method: website (membership registration)

02. Purpose of Collection and Use of Personal Information
• The Company uses collected personal information for the following purposes.
• Member management
Identity verification for member services, personal identification, prevention of fraudulent use by bad members, prevention of unauthorized use, confirmation of intent to join, age verification, complaint handling, and other civil service processing
• Use for marketing and advertising
Development and specialization of new services (products), delivery of promotional information such as events, analysis of access frequency, and statistics on member service usage

03. Retention and Use Period of Personal Information
• In principle, personal information is destroyed without delay once the purpose of collection and use has been achieved. However, the following information may be retained for the period specified below for the stated reasons.
• Retained items
Name, date of birth, login ID, password, home phone number, home address, mobile phone number, email, company name, department, resident registration number, service usage records, access logs, and cookies
• Basis for retention
Identity verification for member services and delivery of promotional information such as events
• Retention period: 3 years

04. Procedures and Methods for Destruction of Personal Information
• In principle, the Company destroys personal information without delay after the purpose of collection and use has been achieved. The procedures and methods are as follows.
• Destruction procedure
Information entered by members for registration, etc., is transferred to a separate database (or separate document storage for paper records) after the purpose is achieved, retained for a certain period according to internal policy and relevant laws (see retention period), and then destroyed. Personal information transferred to a separate database is not used for any purpose other than as required by law.
• Destruction method
Personal information stored in electronic file form is deleted using technical methods that prevent record recovery.

05. Provision of Personal Information
• In principle, the Company does not provide users' personal information to external parties. Exceptions include the following cases.
- When users have given prior consent
- When required by law, or when requested by investigative agencies according to legal procedures for investigation purposes

06. Entrustment of Collected Personal Information
• The Company does not entrust customer information to external companies without customer consent. If such a need arises in the future, the Company will notify customers of the entrusted party and entrusted work, and obtain prior consent if necessary.
07. Rights of Users and Legal Representatives and How to Exercise Them
• Users and legal representatives may, at any time, view or correct their own personal information or that of children under 14, and may also request cancellation of membership.
• To view or correct personal information, users (or children under 14 through legal representatives) may use "Change Personal Information" (or "Edit Member Information"). To cancel membership (withdraw consent), click "Member Withdrawal," complete identity verification, and proceed with viewing, correction, or withdrawal. You may also contact the personal information manager by mail, phone, or email, and we will take action without delay.
• If you request correction of errors in personal information, such information will not be used or provided until correction is completed. If incorrect personal information has already been provided to a third party, the correction result will be notified to that third party without delay so that correction can be made.
• Personal information deleted or terminated at the request of users or legal representatives is processed according to "Retention and Use Period of Personal Information Collected by Intromedic" and is not viewed or used for any other purpose.

08. Installation/Operation of Automatic Collection Devices and Refusal Thereof
• The Company operates cookies that store and retrieve your information from time to time. A cookie is a very small text file sent by the server used to operate a website to your browser and stored on your computer hard disk. The Company uses cookies for the following purposes.
• Purpose of using cookies, etc.
Analysis of access frequency and visit times of members/non-members, identification of user preferences and interests, trace tracking, participation rates in events, and visit counts for targeted marketing and personalized services. You have the right to choose whether to install cookies. Therefore, you may allow all cookies, confirm each time a cookie is saved, or refuse all cookies through browser settings.
• How to refuse cookie settings
Example: You can refuse cookies by selecting browser options to allow all cookies, confirm whenever a cookie is saved, or refuse all cookies.
• Setting example (Internet Explorer)
Tools at the top of the browser > Internet Options > Privacy. However, if you refuse cookie installation, there may be difficulties in providing services.

09. Civil Service Regarding Personal Information
• To protect customers' personal information and handle related complaints, the Company designates related departments and a personal information manager as follows.
• Customer service department: Marketing Headquarters
Phone: 02-801-9324
Email: marketing@intromedic.com
• You may report all personal information protection complaints arising from use of the Company's services to the personal information manager or relevant department. The Company will provide prompt and sufficient responses to reported matters.
• If you need to report or consult on other personal information infringements, please contact the following organizations.
• 1. Personal Dispute Mediation Committee (www.1336.or.kr/1336)
2. Information Protection Mark Certification Committee (www.eprivacy.or.kr/02-580-0533~4)
3. Supreme Prosecutors' Office Internet Crime Investigation Center (http://icic.sppo.go.kr/02-3480-3600)
4. National Police Agency Cyber Terror Response Center (www.ctrc.go.kr/02-392-0330)

10. Protection of Personal Information of Children Under 14
• Membership registration for children under 14 (hereinafter, "children") is conducted through a separate form written in easy-to-understand language, and legal representative consent is always obtained when collecting personal information.
• The Company sends an email to the legal representative to confirm consent and requests a reply by email.
• A child's legal representative may request access, correction, or deletion of the child's personal information, and the Company will take necessary action without delay when such requests are made.