Privacy Policy
PARAMETA's policy on the collection and use of personal information.
PARAMETA (hereinafter the “Company”) establishes and discloses the following Privacy Policy under Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed is not used for purposes other than those below, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
- Identity verification and management for each service
Personal information is processed for the purposes of identifying and authenticating the individual in connection with service provision, confirming whether a legal representative has consented when processing the personal information of a child under 14, and issuing various notices and communications.
- Grievance handling
Personal information is processed for the purposes of verifying the identity of the complainant, confirming the details of the complaint, contacting and notifying the complainant for fact-finding, and communicating the results of processing.
Article 2 (Items of Personal Information and Retention Periods)
① The Company processes and retains personal information within the retention and use period prescribed by statute, or within the retention and use period agreed to by the data subject at the time of collection.
② The Company processes the following items of personal information; the processing and retention periods for each service are as follows.
1. Jjeung (쯩)
| Service | Purpose of collection and use | Items collected and used | Retention period |
|---|---|---|---|
| Jjeung (mobile identity verification) | Confirming whether the user is under 14 and whether a legal representative has consented | (Required) Identity information (name, date of birth, gender, mobile carrier, phone number, CI, Korean/foreign national); legal representative information (guardian's name, date of birth, gender, mobile carrier, phone number, CI, Korean/foreign national) | Destroyed immediately after confirming whether the user is under 14 and whether a legal representative has consented; not stored |
| Mobile identity verification | (Required) Name, date of birth, gender, mobile carrier, phone number, CI, Korean/foreign national, resident registration number | Provided to the carrier relay agency; not stored | |
| Driver's licence verification | Detecting forgery or alteration of a driver's licence | (Required) Driver's licence OCR information (name, date of birth, licence number, licence serial number) | Destroyed immediately after forgery/alteration detection |
| Duplicate-registration identification | (Required) Personal identifier (a value derived from CI) | Until withdrawal from the service |
The app requests the following access permissions when providing the service.
| App permission | Legal basis | Purpose of use | Period of use |
|---|---|---|---|
| CAMERA (required) | Consent of the data subject | Scanning QR codes and photographing identification documents | While the app is running |
2. BROOF
| Purpose | Items collected | Retention period |
|---|---|---|
| Institutional user registration and certificate issuance | (Required) Institution (company) name, representative email, registrant's name, registrant's email (Optional) Registrant's mobile number, certificate issuance details (recipient email, certificate) ※ The items collected may differ depending on the type of certificate. | Until expiry of service use Certificates issued by an institution are retained even after that institution's service use expires, unless the recipient deletes them. |
| Individual user registration and certificate management | (Required) Name, email, password (Optional) Mobile number, certificate information ※ The items collected may differ depending on the type of certificate. | Until withdrawal of membership |
Article 3 (Provision of Personal Information to Third Parties)
① The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only where Article 17 of the Personal Information Protection Act applies, such as with the consent of the data subject or under special provisions of law.
Article 4 (Outsourcing of Personal Information Processing)
① For smooth processing of personal information, the Company outsources personal information processing tasks as follows.
| Outsourcee | Scope of outsourced work (service) | Outsourcing period |
|---|---|---|
| Coupmarketing Co., Ltd. | Event operation, voucher delivery and other customer support (Jjeung) | Until termination of the outsourcing agreement |
| CODEF | Detection of forgery or alteration in driver's licence verification (Jjeung) | Destroyed immediately after forgery/alteration detection |
| Iamport | Provision of member information for pass purchase and identity verification (BROOF) | Until termination of the outsourcing agreement |
| Danal | Mobile identity verification service (BROOF) | Until termination of the outsourcing agreement |
| NetFunnel Co. (넷퍼씨) | Sending certificate issuance notices and sharing messages via email and KakaoTalk (BROOF) | Until termination of the outsourcing agreement |
② When entering into an outsourcing agreement, the Company specifies in the contract or other documents, in accordance with Article 25 of the Personal Information Protection Act, matters such as the prohibition of processing personal information for purposes other than performing the outsourced work, technical and administrative safeguards, restrictions on re-outsourcing, management and supervision of the outsourcee, and liability including damages; and the Company supervises whether the outsourcee processes personal information safely.
③ If the content of the outsourced work or the outsourcee changes, the Company will disclose the change without delay through this Privacy Policy.
Article 5 (Destruction of Personal Information)
① When personal information becomes unnecessary — for example, because the retention period has elapsed or the processing purpose has been achieved — the Company destroys it without delay.
② Where personal information must continue to be preserved under other statutes even though the retention period consented to by the data subject has elapsed or the processing purpose has been achieved, the Company moves that personal information to a separate database or stores it in a different location.
③ The procedures and methods for destroying personal information are as follows.
- Destruction procedure
The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the responsible officer.
- Destruction method
Personal information recorded and stored in electronic file form is destroyed using methods such as a low-level format so that the records cannot be reproduced; personal information recorded and stored on paper is destroyed by shredding or incineration.
Article 6 (Installation and Operation of Automatic Collection Devices, and Refusal Thereof)
① The Company uses “cookies”, which store and retrieve usage information of data subjects from time to time.
② A cookie is a small piece of information that the server (http) used to operate the website sends to the user's browser, and it may be stored on the hard disk of the user's PC.
- Purpose of cookies: Cookies are used to provide more convenient services by identifying such things as how often and for how long users visit.
- Installation, operation and refusal of cookies: Users may allow or block cookies through their browser's option settings.
- Internet Explorer: Tools menu at the top right of the browser > Internet Options > Privacy > Settings > Advanced
- Edge: Settings menu at the top right of the browser > Cookies and site permissions > Manage and delete cookies and site data
- Chrome: Settings menu at the top right of the browser > Privacy and security > Cookies and other site data
- If you refuse or block the storage of cookies, you may experience difficulties in using the service.
Article 7 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
- Administrative measures: establishing and implementing an internal management plan, conducting regular employee training, and the like
- Technical measures: managing access rights to personal information processing systems, installing access control systems, encrypting unique identifying information, and installing security programs
- Physical measures: access control for the server room, document storage room and similar areas
Article 8 (Chief Privacy Officer)
① The Company designates a Chief Privacy Officer as set out below, who takes overall responsibility for personal information processing and handles complaints and remedies for data subjects in relation to personal information processing.
- Chief Privacy Officer and responsible department
- Officer: Cheon Gyeongmin
- Department: Information Security Team
- Contact: [email protected]
② Data subjects may direct any inquiries, complaints or requests for remedy relating to personal information protection that arise while using the Company's services (or business) to the Chief Privacy Officer and the responsible department. The Company will respond to and handle such inquiries without delay.
Article 9 (Rights and Obligations of Data Subjects and How to Exercise Them)
① Data subjects may exercise the following rights relating to personal information protection against the Company at any time.
- Request to access personal information
- Request for correction where there are errors
- Request for deletion
- Request to suspend processing
② The rights under paragraph ① may be exercised against the Company in writing, by telephone, by email, by facsimile (FAX) and similar means, and the Company will act on them without delay.
③ Where a data subject requests correction or deletion of errors in personal information, the Company will not use or provide that personal information until the correction or deletion is complete.
④ The rights under paragraph ① may be exercised through an agent, such as the data subject's legal representative or a duly authorised person. In that case, a power of attorney in the form of Annex No. 11 to the Enforcement Rules of the Personal Information Protection Act must be submitted.
⑤ Data subjects must not infringe the personal information or privacy of themselves or others processed by the Company in violation of the Personal Information Protection Act or other relevant statutes.
Article 10 (Requests to Access Personal Information)
Data subjects may submit requests to access personal information under Article 35 of the Personal Information Protection Act to the department below. The Company will endeavour to process such requests promptly.
- Department receiving and handling access requests
- Department: Information Security Team
- Contact: [email protected]
Article 11 (Remedies for Infringement of Rights)
Data subjects may contact the following bodies for remedy or counselling regarding infringement of personal information. These bodies are separate from the Company; please contact them if you are not satisfied with the Company's own handling of a complaint or its remedy, or if you need more detailed assistance.
- Privacy Infringement Report Centre: 118 (privacy.kisa.or.kr)
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Cybercrime Investigation Division, Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Cyber Bureau, Korean National Police Agency: 182 (cyberbureau.police.go.kr)
Article 12 (Changes to This Privacy Policy)
① This Privacy Policy applies from 21 August 2024.
② The application periods of previous Privacy Policies are as follows.
- 24 July 2022 – 20 August 2024
- 11 May 2022 – 24 July 2022
- 28 March 2022 – 10 May 2022
This English text is a reference translation. The Korean version at /privacy is the authoritative text and prevails in the event of any discrepancy.