Corporation DRAX (hereinafter referred to as the “Company” ) has established the following personal information processing guidelines in order to protect the personal information of information subjects and to promptly and smoothly handle complaints related thereto in accordance with Article 30 of the Personal Information Protection Act. Disclosed. Article 1 (Purpose of processing personal information) The company processes personal information for the following purposes. Personal information being processed will not be used for purposes other than the following, and if the purpose of use changes, necessary measures will be taken, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act. 1. Website membership registration and management a member , identification of the person in accordance with the provision of membership services . Certification , maintenance of membership . Management , identity verification through the implementation of a limited identity verification system, prevention of illegal use of services, confirmation of legal representative's consent when processing personal information of children under 14 years of age, various notices . Personal information is processed for purposes such as notification and grievance handling. 2. Provision of goods or services We process personal information for the purposes of delivering goods , providing services, sending contracts and invoices, providing content, providing customized services, identity verification, age verification, bill payment and settlement, and debt collection. 3. Grievance handling Contact to confirm the identity of the complainant , confirm the complaint, and investigate the facts . Personal information is processed for purposes such as notification and notification of processing results. Article 2 (Processing and retention period of personal information) ① The company processes and retains personal information within the personal information retention and use period in accordance with laws and regulations, or within the personal information retention and use period consented to when collecting personal information from the information subject. ② The processing and retention period for each personal information is as follows. 1. Website membership registration and management: Until withdrawal of business/organization website However , in the case of the following reasons, until the end of the relevant reason: 1) If an investigation, investigation, etc. is in progress for violation of relevant laws and regulations, until the investigation or investigation is completed. 2) If any claims or debts remain due to use of the website, until the relevant claims or debts are settled. 2. Provision of goods or services : Goods ․ Completion of service supply and payment ․ Until settlement is completed However , in the following cases, until the end of the relevant period: Labeling in accordance with the Act on Consumer Protection in Electronic Commerce , etc. Records of transactions such as advertisements , contract details and implementation - mark . Records regarding advertising : 6 months - Records of contract or subscription withdrawal, payment, supply of goods, etc.: 5 years Records on handling consumer complaints or disputes : 3 years 2) Storage of communication confirmation data in accordance with Article 41 of the 「Communication Secrets Protection Act」 - Subscriber telecommunication date and time, start ․ End time, other party subscriber number, frequency of use , transmitting base station location tracking data: 1 year - Computer communication, internet log records, access tracking data: 3 months Article 3 (Provision of personal information to third parties) ① The company processes the personal information of the information subject only within the scope specified in Article 1 (Purpose of processing personal information), and only processes personal information in cases that fall under Article 17 of the Personal Information Protection Act, including the consent of the information subject and special provisions of the law. Provided to third parties. ② The company provides personal information to third parties as follows. - Persons receiving personal information : PR Gate Co., Ltd. - Purpose of use of personal information of the recipient : Business partnership, such as confirmation of participation application items provided : name, address, phone number, email address - Period of retention and use by recipient : 6 months after application Article 5 (Rights of users and legal representatives and methods of exercising them) ① The information subject may exercise the following rights related to personal information protection against the company at any time. 1. Request to view personal information 2. Request for correction if there is an error, etc. 3. Request for deletion 4. Request to suspend processing ② Rights pursuant to Paragraph 1 may be exercised to the Company in writing, by phone, e-mail, facsimile (FAX), etc., and the Company will take action without delay. ③ If the information subject requests correction or deletion of errors in personal information, the company will not use or provide the personal information until correction or deletion is completed. ④ The exercise of rights under paragraph 1 may be done through an agent, such as the information subject's legal representative or a person authorized to do so. In this case, you must submit a power of attorney in the format of Appendix 11 of the Enforcement Rules of the Personal Information Protection Act. ⑤ The information subject shall not violate the personal information and privacy of the information subject or others processed by the company in violation of relevant laws and regulations, such as the Personal Information Protection Act. Article 6 (Personal information items processed) The company processes the following personal information items. 1. Website membership registration and management Required items : email, password, name, phone number, address, date of birth 2. Provision of goods or services Required items : Payment information such as name, date of birth, ID, password, address, phone number, email address , credit card number, bank account information, etc. 3. The following personal information items may be automatically created and collected during the use of Internet services. IP address, cookie, MAC address, service use record, visit record, bad use record, etc. Article 7 (Destruction of personal information) ① When personal information becomes unnecessary, such as when the personal information retention period has passed or the purpose of processing has been achieved, the company destroys the relevant personal information without delay. ② In cases where personal information must continue to be preserved pursuant to other laws and regulations despite the expiration of the personal information retention period agreed to by the information subject or the purpose of processing has been achieved, the personal information shall be transferred to a separate database (DB) or storage location changed. Save it differently. ③ The procedures and methods for destroying personal information are as follows. 1. Destruction Procedure The company selects the personal information that requires destruction and destroys the personal information with the approval of the company's personal information protection manager. 2. Method of destruction The company records in the form of electronic files . The saved personal information is formatted in low level format ( Low) so that the records cannot be played back. Level It is destroyed using methods such as Format and recorded in paper documents . Stored personal information is destroyed by shredding or incineration. Article 8 (Measures to ensure the safety of personal information) The company is taking the following measures to ensure the safety of personal information. 1. Management measures: establishment and implementation of internal management plan, regular employee training, etc. 2. Technical measures: Management of access rights to personal information processing system, installation of access control system, unique identification information Installation of encryption and security programs, etc. 3. Physical measures: Access control to computer rooms, data storage rooms, etc. Article 9 (Matters regarding installation, operation and refusal of automatic personal information collection devices) ① The company uses ‘cookies’ to store usage information and retrieve it from time to time in order to provide individualized services to users. ② Cookies are a small amount of information that the server (http) used to run the website sends to the user's computer browser and are sometimes stored on the hard disk of the user's computer. go . Purpose of use of cookies: They are used to provide optimized information to users by identifying visitation and usage patterns, popular search terms, secure access, etc. for each service and website visited by the user. me . Installation, operation and refusal of cookies: You can refuse to store cookies through option settings in the Tools>Internet Options>Privacy menu at the top of your web browser . all . If you refuse to store cookies, you may have difficulty using customized services. Article 10 (Personal Information Protection Manager) ① The company is responsible for overall management of personal information processing, and has designated a personal information protection manager as follows to handle complaints and provide relief for damage from information subjects related to personal information processing. ▶ Personal information protection officer Name : Yoo Seon-kyung Position : Representative Contact : Tel.02-569-9924 Fax.031-459-8531 ※ You will be connected to the personal information protection department. ▶ Personal information protection department Department : Drax Contact person : Yoo Seon-kyung Contact : Tel.02-459-8530 Fax.031-459-8531 ② Information subjects may inquire about all personal information protection-related inquiries, complaint handling, damage relief, etc. that arise while using the company's services (or business) to the personal information protection manager and responsible department. The company will respond and process inquiries from information subjects without delay. Article 11 (Request to view personal information) The information subject may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the department below. The company will endeavor to promptly process the information subject's request to view personal information. ▶ Receiving a request to view personal information ․ processing department Department : Drax Contact person : Yoo Seon-kyung Contact : Tel.02-459-8530 Fax.031-459-8531 Article 12 (Methods for relief from rights infringement) Information subjects can inquire about damage relief and consultation regarding personal information infringement to the organizations below. ▶ Personal Information Infringement Reporting Center (operated by Korea Internet & Security Agency) - Responsibilities : Reporting personal information infringement, requesting consultation - Website: privacy.kisa.or.kr -Phone : (without area code) 118 - Address: Personal Information Infringement Reporting Center, 3rd floor, 9 Jinheung-gil, Naju-si, Jeollanam-do ( 301-2, Bitgaram-dong ) (58324) ▶ Personal Information Dispute Mediation Committee - Responsibilities: Request for personal information dispute mediation, collective dispute mediation (civil resolution) - Website: www.kopico.go.kr - Phone: (without area code) 1833-6972 - Address: (03171) 4th floor, Seoul Government Complex, 209 Sejong-daero, Jongno-gu, Seoul ▶ Supreme Prosecutors' Office Cyber Crime Investigation Team: 02-3480-3573 (www.spo.go.kr) ▶ National Police Agency Cyber Safety Bureau: 182 (http://cyberbureau.police.go.kr) Article 13 (Implementation and change of personal information processing policy) This privacy policy is effective from the date of posting on the site .