Amorepacific Corporation (hereinafter “Company”) values the personal information of data subjects (hereinafter “Users”) who use the services provided by the Company and is making every effort to protect it.
The Company complies with all personal information protection laws and regulations, including the “Personal Information Protection Act” and the “Act on Promotion of Information and Communications Network Utilization and Information Protection.” It has separately established and adheres to its own Personal Information Handling Policy to further protect users’ personal information. Additionally, the Company always discloses its Personal Information Handling Policy on the main page of the Company’s website to ensure that users can easily access it at any time.
The Company’s Personal Information Handling Policy may be modified according to changes in relevant laws and notices or internal operational policies. The website will announce changes if the Company’s Personal Information Handling Policy is revised.
The Company’s personal information protection policy includes the following contents:
- Article 1 Personal Information Collection Items and Purpose of Collection and Use
- Article 2 Provision of Personal Information
- Article 3 Outsourcing of Personal Information Handling
- Article 4 Retention and Use Period, Disposal Procedures of Personal Information
- Article 5 Department Responsible for Personal Information Protection and Related Grievance Handling
- Article 6 Collection of Personal Information by Automatic Collection Devices
- Article 7 Access to and Correction of Personal Information
- Article 8 Withdrawal of Consent to the Collection, Use and Provision of Personal Information
- Article 9 Administrative, Technical and Physical Measures for Personal Information Protection
- Article 10 Users’ Rights and How to Exercise Them
- Article 11 Obligation to Notify Changes to Protection Policy
Article 1 (Personal Information Collection Items and Purpose of Collection and Use)
- ① The Company collects the minimum personal information necessary to provide services to users. The Company, however, may collect additional personal information optionally to provide users with higher-quality customized services.
- ② Without the user’s explicit separate consent, the Company does not collect sensitive personal information such as thoughts/beliefs, labor union/political party membership/withdrawal, political views, health, sexual life, past medical history, religion, place of origin, criminal records, etc., which may infringe upon fundamental human rights.
- ③ The items of personal information collected concerning the services provided by the Company and the primary purposes of collection and use are as follows:
Category |
Category |
Collection Items |
Purpose of Collection |
Retention and Use Period |
Reporting |
Optional |
Name (can be anonymous), telephone number, email address |
Securing communication channels for processing reports and sending results, managing report details |
6 months from the date of receipt of the report |
Workplace Harassment / Sexual Harassment Reports |
Required |
Name and affiliation |
Verification of reporter, management of report details |
6 months from the date of receipt of the report |
Optional |
Telephone number, email address |
Securing communication channels for processing reports and sending results, managing report details |
6 months from the date of receipt of the report |
④ IP addresses, cookies, visit time, service usage records, and records of inappropriate use may be automatically generated and collected during online service use or business processing.
⑤ When using online services (including mobile), information about the device (device model, operating system, browser, MAC ADDRESS, etc.) may be collected for user verification and service provision and to prevent fraudulent use. Additionally, mobile carrier information may be collected and used to provide PUSH services (only with customer consent), application version upgrades, and other services specific to mobile service characteristics.
⑥ In cases where the Company provides services other than those specified in paragraph 3, such as donation activities, prize events, or other services, the Company may collect and use personal information necessary for providing the service. In such cases, the Company will obtain separate consent from users after clearly stating all items, purposes, periods, right of refusal, and disadvantages upon refusal by relevant laws.
⑦ In addition to collecting personal information for service provision under paragraphs 3 and 4, the Company may collect personal information in the following cases. It will notify users of the processing purpose and items when collecting personal information:
* During customer consultation: Name, contact information (wired/wireless phone numbers, work/home addresses, email), age, etc., are collected to handle inquiries/complaints and notify processing results, and are retained for 3 years
⑧ Users may refuse to consent to collecting and using personal information. However, if users refuse the collection and use of personal information, there may be limitations on service use and benefit provision.
Article 2 (Provision of Personal Information)
- ① The Company will not use users’ personal information beyond the scope notified in Article 1 or provide it to third parties, except with the consent of users or as required by relevant laws.
- ② However, personal information may be provided without separate consent from users in the following cases:
- 1. When necessary for payment settlement by service provision
- 2. When necessary for statistical compilation, academic research, or market research, the information is processed in a form that cannot identify specific individuals before being provided to research organizations, survey institutions, research agencies, etc.
- 3. When there are special provisions in laws such as the Personal Information Protection Act, Act on Promotion of Information and Communications Network Utilization and Information Protection, Protection of Communications Secrets Act, Framework Act on National Taxes, Act on Real Name Financial Transactions and Confidentiality, Act on the Use and Protection of Credit Information, Framework Act on Telecommunications, Telecommunications Business Act, Local Tax Act, Consumer Protection Act, Criminal Procedure Act, etc.
- ③ When providing personal information to third parties overseas, the Company will inform users of the details and obtain their consent.
Article 3 (Outsourcing of Personal Information Handling)
- ① The Company may outsource the management of users’ personal information to external specialized companies to improve services and facilitate data processing.
- ② When outsourcing the processing of personal information, the Company manages and supervises to protect users’ personal information through outsourcing contracts, ensuring that service providers comply with personal information protection instructions, maintain the confidentiality of personal information, and prohibit the provision of personal information to third parties without user consent.
- ③ The processors who are entrusted with personal information processing and their tasks are as follows:
Processor |
Outsourced Tasks |
GROVE SOFT Co., Ltd. |
Site operation and data processing |
Kyndryl Korea Co., Ltd. |
Electronic processing and management of personal information |
MEGAZONE CLOUD Co., Ltd. |
Electronic processing and management of personal information |
- ④ The sub-processors who are entrusted with personal information processing and their tasks are as follows:
Processor |
Sub-processor |
Sub-outsourced Tasks |
MEGAZONE CLOUD Co., Ltd. |
Amazon Web Service Inc |
Electronic processing and management of personal information |
Article 4 (Retention and Use Period, Disposal Procedures of Personal Information)
Article 5 (Department Responsible for Personal Information Protection and Related Grievance Handling)
① The Company has designated a department responsible for personal information protection and related grievance handling to protect users’ personal information and address complaints about personal information. In addition, the Company has appointed a personal information management officer and a personal information management person in charge of promptly handling inquiries and complaints regarding users’ personal information.
Category |
Personal Information Protection Officer |
Personal Information Protection Manager |
Name |
Mr. Seung-il Oh |
Mr. Kwang-bok Lee |
Department |
Information Security Center |
Information Security Center |
Email Address |
PRIVACY@AMOREPACIFIC.COM |
PRIVACY@AMOREPACIFIC.COM |
Phone Number |
080-023-5454 (toll-free) (Mon-Fri: 09:00-18:00, excluding holidays) |
② When users need consultation due to the occurrence or concern of infringement regarding their personal information, they can contact not only the Company’s personal information protection department mentioned in paragraph 1 but also the following institutions:
- Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972 without area code)
- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118 without area code)
- Supreme Prosecutors’ Office Cyber Investigation Division (www.spo.go.kr / 1301 without area code)
- National Police Agency Cyber Investigation Bureau (ecrm.cyber.go.kr / 182 without area code)
Article 6 (Collection of Personal Information by Automatic Collection Devices)
- ① The Company may use ‘cookies’ (Internet connection information files and other personal information automatic collection devices) to store and periodically retrieve user information. A cookie is a small amount of information sent by the server operating the Company’s website to the user’s browser (Safari, Chrome, Internet Explorer, etc.). It can be stored on the user’s computer’s hard disk. When a user accesses the website, the Company’s computer reads the contents of cookies in the user’s browser. It can provide services without additional input, such as names, by finding the user’s information on their computer. Cookies identify the user’s computer but do not identify the user personally.
- ② The Company uses cookies to analyze users’ access frequency and visit times, track the number of visits, and improve services necessary for site operation.
- ③ The Company uses cookies to determine the level of user participation and number of visits in various events conducted by the Company, to provide differentiated entry opportunities, and as data to provide differentiated information according to users’ areas of interest.
- ④ Users have the option regarding cookie installation. Therefore, users can choose to allow all cookies, allow some cookies, or reject all cookies by setting options in their web browser.
- • Methods to specify cookie installation permission:
- - Internet Explorer : Click [Tools] on the Internet screen taskbar, select [Internet Options] -> Click [Privacy] tab -> Click [Advanced] -> Select cookie permission settings
- - Safari:
- (MacOS) From the top left menu bar, select [Safari] -> [Preferences] -> Go to [Privacy] in the [Preferences] window and select cookie permission settings (iOS) [Settings] -> Select [Safari] from the app list -> Select cookie permission settings in [Privacy & Security]
- - Chrome:
- (PC) Select [Settings] from the menu in the upper right corner of the web browser -> Select [Privacy & Security] -> Go to [Cookies and Other Site Data] and select cookie permission settings (Mobile) Select [Settings] from the menu in the upper right corner of the web browser -> Select [Site Settings] in Advanced settings -> Go to [Cookies] and select cookie permission settings
Article 7 (Access to and Correction of Personal Information)
- ① Users may contact the Company’s personal information protection department by phone, in writing, or by email at any time to request access, correction, deletion, or suspension of processing, and the Company will take relevant measures without delay in response to users’ requests.
- ② When a user requests correction of errors in personal information, the Company will not use, provide, or otherwise process the personal information until the correction is completed. In addition, if incorrect personal information has already been processed, we will ensure that the correction results are reflected immediately.
- ③ Access to and correction of personal information may be restricted in the following cases:
- 1. When there is concern that it may significantly harm the rights and interests of a third party
- 2. When there is concern that it may significantly interfere with the business of the service provider
- 3. When it violates laws and regulations, etc.
Article 8 (Withdrawal of Consent to the Collection, Use and Provision of Personal Information)
- ① Users may withdraw their consent to collecting, using, and providing personal information at any time. Consent can be withdrawn by requesting it from the person entrusted with processing personal information or by contacting the department responsible for personal information management in writing, by phone, or by email. In response to the user’s request, the Company will take immediate measures, such as destroying the user’s personal information.
- ② The Company strives to take necessary actions to make the withdrawal more effortless than the collection of the personal information.
Article 9 (Administrative, Technical and Physical Measures for Personal Information Protection)
- ① The Company establishes and implements internal management plans to process personal information safely and conducts training.
- ② The Company implements technical measures to ensure security so that users’ personal information is not lost, stolen, leaked, altered, or damaged when handling it.
- ③ Users’ personal information is managed using an internal network that cannot be accessed or infiltrated from external networks, and essential data is thoroughly protected through separate security features by encrypting files and transmission data or using file locking features.
- ④ The Company ensures network security by using firewalls and intrusion detection systems on each server to prepare against hacking and other external intrusions. It strengthens security by installing access control systems.
- ⑤ The Company prevents personal information infringement by installing anti-virus programs that constantly check for and handle the infiltration of malicious programs such as computer viruses and spyware on personal information processing systems and information devices used by personal information handlers.
- ⑥ The Company limits access to users’ personal information to a minimum number of personnel, establishes internal procedures for accessing and managing personal information to ensure its security, implements access control and locking devices, and ensures that employees are familiar with and comply with these procedures.
- ⑦ The handover of duties between personal information handlers is carried out thoroughly while maintaining security, and accountability for personal information incidents after joining or leaving the company is clearly defined.
- ⑧ Users should maintain accurate information through verification and management of the personal information they provide to the Company. If they use others’ personal information without authorization or infringe on others’ rights, they may be subject to sanctions by the Company as well as civil and criminal liability.
- ⑨ The Company assumes no responsibility for issues arising from personal information leakage due to users’ carelessness or Internet problems. Therefore, each user must appropriately manage their personal information to protect it and bear responsibility for this. However, if the loss, leakage, alteration, or damage of users’ personal information occurs due to misconduct or negligence on the part of the Company’s internal managers, the Company will immediately inform users of the facts and devise appropriate countermeasures and compensation.
Article 10 (Users’ Rights and How to Exercise Them)
- ① Users and their legal representatives may exercise rights related to viewing, modifying, changing personal information provided to the Company as themselves or as legal representatives, and withdrawing membership.
- ② The Company collects personal information of children under the age of 14 only with the consent of legal representatives (parents, etc.) to protect children’s personal information.
- ③ Users and legal representatives can exercise their rights by contacting the Company via the Internet, telephone, written documents, etc., regarding personal information, and the Company will take necessary measures without delay.
Article 11 (Obligation to Notify Changes to Protection Policy)
This policy may be amended according to changes in laws, policies, internal operational policies of the Company, or security technologies, and in such cases, we will promptly notify the reasons and content of the changed policy on the first page of the Company’s website.