Last amended September 1, 2023
Privacy Policy v4.0
LogisValley Co., Ltd. (the "Company") attaches great importance to protecting the personal information of customers who use its services (the "Users"), and does its utmost to ensure that the personal information provided to the Company when Users use its services is protected. Accordingly, the Company complies with the personal information protection provisions and guidelines under the applicable statutes with which it must comply, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. and the Personal Information Protection Act. Through this Privacy Policy, the Company informs Users of the purposes and manner in which the personal information they provide is used, and of the measures taken to protect personal information.
The Company's Privacy Policy may be amended from time to time due to changes in government legislation or guidelines or changes in the Company's internal policies, and the Company has established the procedures necessary for its continuous improvement. Where the Privacy Policy is amended, the Company posts the changes on the Site immediately so that Users can readily identify what has been amended.
1. Personal Information Collected and Purposes of Use
The Company collects, through its entrusted partners, only the minimum information necessary to provide delivery services, and only for that purpose within the scope permitted by the applicable statutes. Personal information processed is not used for any purpose other than those set out below, and where the purpose of use changes, prior consent will be obtained.
The items of personal information collected and the purposes of collection and use are as follows.
| Category | Items collected | Purposes of collection and use |
|---|---|---|
| Delivery services | [Mandatory] Name, telephone number and address of the sender / recipient | Delivery of goods |
2. Retention and Use Period of Personal Information
The Company destroys personal information collected upon a request for logistics services immediately once the purpose for which it was provided has been achieved.
However, where information must be retained under the provisions of the applicable statutes, the following information is retained for the periods specified below for the reasons stated.
| Legal basis for retention | Retention period | Items retained |
|---|---|---|
| Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc. and Article 6 of its Enforcement Decree | 5 years | Records on contracts, withdrawal of offers, payment of price and supply of goods, etc. |
| 3 years | Records on consumer complaints or dispute resolution | |
| 6 months | Records on labelling and advertising | |
| Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree | 3 months | Log records and data tracing Users' internet access, etc. |
| 12 months | Other communications confirmation data |
3. Destruction of Personal Information
As a rule, the Company destroys personal information without delay once the information it holds is no longer necessary (for example, because the retention period has elapsed or the purpose of processing has been achieved). This does not apply where the information must be retained under other statutes. The procedures and methods of destruction are as follows.
1) Procedure for destruction
Unnecessary personal information and personal information files are handled under the responsibility of the personal information protection officer, in accordance with internal policies and statutory procedures. Information entered by a User is, once the purpose has been achieved, transferred to a separate database (or, in the case of paper, to separate documents) and is either stored for a certain period in accordance with internal policies and other relevant statutes, or destroyed immediately. Personal information transferred to such a database is not used for any other purpose except where required by law.
2) Time limit for destruction
Where the retention period for a User's personal information has elapsed, the information is destroyed within five days from the end of the retention period. Where the personal information has become unnecessary — for example because the purpose of processing has been achieved, the service concerned has been discontinued or the business has ended — it is destroyed within five days from the date on which the processing of that personal information is recognised as unnecessary.
3) Method of destruction
Personal information in the form of electronic files is permanently deleted by technical means that make the records unrecoverable, and personal information recorded and stored in paper documents is destroyed by shredding or incineration.
4. Provision of Personal Information to Third Parties
As a rule, the Company does not provide Users' personal information to any external party. The following cases are, however, excepted.
1) Where provision is required under the applicable statutes, or where an investigative agency so requests for the purpose of an investigation in accordance with the procedures and methods prescribed by statute
2) Where the User has consented in advance to the provision to, or disclosure to, a third party
3) Where the personal information is necessary for the performance of a contract relating to the provision of services and it is markedly difficult to obtain ordinary consent for economic or technical reasons
4) Where the information is processed into a form in which an individual cannot be identified and is used in that form
5. Entrustment of Personal Information Processing
In order to provide better services, offer customer convenience and otherwise carry out its business smoothly, the Company entrusts the processing (handling) of personal information to external companies as set out below. When concluding an entrustment contract, the Company specifies in the contract documents, in accordance with the Personal Information Protection Act, the prohibition on processing personal information for purposes other than performing the entrusted work, technical and managerial protective measures, restrictions on sub-entrustment, liability for damages and other matters concerning responsibility, and it trains and supervises the trustee to ensure that personal information is processed safely. Where the entrusted work or the trustee changes, the Company will disclose this through this Privacy Policy without delay.
| Entrusted work | Trustee | Details of the entrusted work |
|---|---|---|
| Parcel sorting | Hanaro TNS Co., Ltd. | Parcel sorting and logistics automation |
| Customer centre (call centre) | Hanaro TNS Co., Ltd. | Customer complaints and other enquiries |
6. Operation of Cookies
The Company does not use "cookies", which store and frequently retrieve information on the use of the service by data subjects. A cookie is a small amount of information that a website sends to a User's computer browser (Netscape, Internet Explorer, etc.) and which may be stored on the hard disk of the User's PC. When a User accesses a website, the User's computer reads the contents of the cookie in the User's browser and finds additional information about the User on the User's computer, enabling the service to be provided without the User having to enter additional information such as their name each time they connect. A cookie identifies the User's computer but does not identify the User personally. Users also have a choice regarding cookies. Under Tools > Internet Options at the top of a web browser, a User may choose to accept all cookies, to be notified when a cookie is installed, or to refuse all cookies.
7. Technical and Managerial Measures Relating to Personal Information
In handling Users' personal information, the Company limits access rights to personal information to the minimum number of personnel so that personal information is not lost, stolen, leaked, altered or damaged, and takes the following technical measures to ensure security in accordance with the relevant statutes, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. and the Personal Information Protection Act.
1) The Company does its utmost to prevent members' personal information from being leaked or damaged by hacking, computer viruses and the like.
2) The Company backs up data frequently in preparation for damage to personal information, uses up-to-date anti-virus software to prevent Users' personal information and data from being leaked or damaged, and ensures that personal information is stored in encrypted form and transmitted securely over networks through secure cryptographic algorithms and other means.
3) The Company controls unauthorised access from outside by means of an intrusion prevention system, and endeavours to put in place every possible technical device to secure the stability of its systems.
8. Processing of Personal Location Information
The Company processes personal location information as set out below, in accordance with the Act on the Protection and Use of Location Information (the "Location Information Act"). The Company may retain personal location information in order to provide the services under Article 4 of the LogisValley Location-Based Service Terms of Use.
• Personal location information is destroyed without delay once the purpose of using and providing the location-based service has been achieved.
• In the case of a service in which location information is stored together with a posting or content created by the location information subject, the personal location information is retained for the retention period of that posting or content.
• Where otherwise necessary in order to provide a location-based service, personal location information may be retained for the minimum period necessary to achieve the purpose of use.
Personal location information is destroyed without delay once the purposes of its collection and use have been achieved.
Where the purpose of processing personal location information has been achieved — for example because the purposes of collection and use have been fulfilled or the member has withdrawn — the personal location information is securely deleted so that it cannot be recovered or reproduced.
However, where there is a legitimate ground for retention, such as an obligation to retain the information under other statutes, that ground shall prevail. In addition, pursuant to Article 16(2) of the Location Information Act, data confirming the use and provision of a User's location information is retained in the location information system for six months.
Personal location information is not provided to third parties without the prior consent of the personal location information subject.
The Company does not provide personal location information to third parties without the consent of the personal location information subject. Where it is to be provided to a third party, the Company notifies the personal location information subject in advance of the recipient and the purpose of provision and obtains consent. Where personal location information is provided to a third party with the consent of the personal location information subject, the Company immediately notifies the subject, on each occasion, of the recipient, the date and time of provision and the purpose of provision.
• Provision of location information to third parties
| Recipient | Purpose of provision | Personal information items provided |
|---|---|---|
| Hanaro TNS Co., Ltd. | Vehicle location and travel route | Current location and travel route |
In order to manage and protect personal location information appropriately and to handle members' complaints smoothly, the Company designates as its location information protection officer a person in a position to bear substantive responsibility. The name and contact details of the location information protection officer are as follows.
• Location Information Protection Officer: Director Kim Dae-jung
• Telephone: +82-70-5100-0751
The Company does not collect location information of minors under the age of 19.
9. Personal Information Protection Officer and Manager
The Company designates a personal information protection officer and a person in charge of personal information protection, responsible for handling complaints concerning personal information, as follows.
| Category | Department and position | Name | Contact |
|---|---|---|---|
| Personal Information Protection Officer | ICT Business Division / Director | Kim Dae-jung | +82-70-5100-0751 / musimco@logisvalley.com |
| Personal Information Protection Manager | ICT Business Division / Team Leader | Jeong Gwang-ho | +82-70-5100-0761 / gh.jeong@logisvalley.com |
10. Consultation on and Reporting of Personal Information Infringement (Remedies for Infringement of Rights)
If you need to report or seek advice on an infringement of personal information, please contact the personal information protection officer by e-mail or telephone, or contact the Korean National Police Agency Cyber Safety Guardians, the Cyber Investigation Division of the Supreme Prosecutors' Office, the Privacy Infringement Report Centre or the Personal Information Dispute Mediation Committee.
| Organisation | Website | Telephone |
|---|---|---|
| Privacy Infringement Report Centre | www.privacy.kisa.or.kr | 118 (no area code) |
| Personal Information Dispute Mediation Committee | www.kopico.go.kr | 1833-6972 (no area code) |
| Cyber Crime Investigation Division, Supreme Prosecutors' Office | www.spo.go.kr | 1301 (no area code) |
| Cyber Bureau, Korean National Police Agency | cyberbureau.police.go.kr | 182 (no area code) |
11. Rights of Data Subjects and Their Legal Representatives, and How to Exercise Them
As data subjects, Users may exercise the following rights.
1) Request for access to personal information: You may request access to the personal information held by the Company pursuant to Article 35 (Access to Personal Information) of the Personal Information Protection Act. However, access may be restricted under Article 35(4) of that Act in any of the following cases.
1. Where access is prohibited or restricted by statute
2. Where there is a risk of harm to the life or body of another person, or of unjustly infringing the property or other interests of another person
3. Where access would cause serious difficulty in the performance by a public institution of any of the following functions
a) Functions relating to the imposition, collection or refund of taxes
b) Functions relating to the assessment of academic performance or the selection of entrants at schools of each level under the Elementary and Secondary Education Act and the Higher Education Act, at lifelong education establishments under the Lifelong Education Act, or at other higher education institutions established under other statutes
c) Functions relating to examinations concerning academic records, skills and recruitment, and to qualification screening
d) Functions relating to evaluations or judgements in progress concerning the calculation of compensation or benefits
e) Functions relating to audits or investigations in progress under other statutes
2) Request for correction or deletion of personal information: You may request correction or deletion pursuant to Article 36 (Correction and Deletion of Personal Information) of the Personal Information Protection Act. However, where other statutes expressly specify that the personal information is to be collected, deletion may not be requested.
3) Request for suspension of processing of personal information: You may request suspension of processing pursuant to Article 37 (Suspension of Processing of Personal Information, Etc.) of the Personal Information Protection Act. However, such a request may be refused under Article 37(2) of that Act in any of the following cases.
1. Where there is a special provision in a statute, or where suspension is unavoidable in order to comply with a statutory obligation
2. Where there is a risk of harm to the life or body of another person, or of unjustly infringing the property or other interests of another person
3. Where a public institution would be unable to perform the functions under its jurisdiction prescribed by other statutes without processing the personal information
4. Where performance of the contract would be difficult — for example, because the service agreed with the data subject could not be provided without processing the personal information — and the data subject has not clearly expressed an intention to terminate that contract
4) Request for withdrawal of consent: Pursuant to Article 39-7 (Special Provisions on Users' Rights, Etc.) of the Personal Information Protection Act, Users may withdraw their consent to the collection, use or provision of personal information.
5) Procedure for handling requests for access, correction or deletion, suspension of processing, and withdrawal of consent
1. Data subjects may exercise their rights by completing a "Request for Personal Information (Access, Correction/Deletion, Suspension of Processing)" in accordance with Form No. 8 attached to the Enforcement Rules of the Personal Information Protection Act and submitting it in writing, by e-mail or by fax.
2. Where a request is made for access, correction or deletion, suspension of processing, or withdrawal of consent in accordance with the rights of the data subject, LogisValley verifies whether the person making the request is the data subject in person or a duly authorised representative.
3. LogisValley takes measures to ensure that data subjects' requests are handled promptly.
6) The rights under Paragraphs 1 to 4 may be exercised through a representative, such as the data subject's legal representative or a person duly authorised by the data subject. In such a case, a power of attorney in accordance with Form No. 11 attached to the Enforcement Rules of the Personal Information Protection Act must be submitted.
7) Procedure for raising an objection: Where a request under Paragraphs 1 to 4 is refused, you may raise an objection with the personal information protection department specified below.
12. Changes to This Privacy Policy
This Privacy Policy was last amended on 1 September 2023. Where content is added, deleted or modified as a result of changes in government legislation or policy, changes in security technology or for any other reason, the Company will give notice of the reasons for and the content of the change by means of a pop-up window from at least ten days before the amendment takes effect.