● Privacy Policy
Space G&D (hereinafter referred to as "the company") values the personal information of users and complies with the "Act on Promotion of Information and Communications Network Utilization and Information Protection."
The company informs users through the Privacy Policy about how their personal information provided will be used and in what manner, as well as the measures taken to protect personal information.
The company's privacy policy includes the following contents.
1.Collection of Personal Information Items and Methods
2.Purpose of Collecting and Using Personal Information
3.Retention and Use Period of Personal Information
4.Sharing and Providing Personal Information
5.Outsourcing of Personal Information Processing
6.Procedures and Methods for Destruction of Personal Information
7.Rights of Users and Legal Representatives and How to Exercise Them
8.Installation, Operation, and Refusal of Automatic Collection Devices for Personal Information
9.Technical and Administrative Protection Measures for Personal Information
10.Personal Information Management Officer
11.Reporting and Dispute Resolution Related to Personal Information
12.Obligation to Notify Changes
Chapter 1: Collection of Personal Information Items and Methods
1. Collected Personal Information Items
① The company collects the following personal information for membership registration, service applications, customer consultations, and other related purposes.
- During Membership Registration
<Required Items> :
- ID
- Password
- Password security question and answer
- Name
- Nickname (or Alias)
- Email
- Contact Information (Mobile or Landline Phone Number)
- Date of Birth
- Gender
- Legal Guardian Information (for children under the age of 14)
<Optional Items> :
- Place of Residence
- Self-Introduction
- Mailing Service Subscription
- SMS Reception Status
- Information Disclosure
- When applying for certain services: Address,Business-related information (Business Name, Business Registration Number, Representative's Name, Business Address/Phone Number/Fax Number/Email Address, Website URL, Telecommunication Sales Business Registration Number)
- For refunds : Account Information (Bank Name, Account Number, Account Holder's Name)
② During the process of using the service or handling business operations, the following information may be generated and collected:
-Service Usage Records
-Access Logs
-Cookies
-Access IP Information
-Payment Records
-Suspension Records
-Malicious Usage Records
2. Methods of Collecting Personal Information
The company collects personal information using the following methods:
① Website, Membership registration through written forms
② Phone, Fax, Customer consultations and service management through the consultation bulletin board
Chapter 2: Purpose of Collecting and Using Personal Information
The company uses the collected personal information for the following purposes.
1. Fulfillment of contracts related to service provision and settlement of fees associated with the services provided.
Providing services and content, sending goods, invoices, or other documents, identity verification, purchase and fee payment, and fee collection.
2. Membership Management
Verification of identity for membership services, personal identification, prevention of misuse by bad members and unauthorized use, confirmation of intention to join, limitations on membership and number of registrations, verification of consent from legal representatives when collecting personal information from children under 14, subsequent verification of the legal representative's identity, retention of records for dispute resolution, handling of complaints and grievances, and communication of notices.
3. Development of new services and marketing, advertising.
Development and specialization of new services (products), provision of services and advertising based on demographic characteristics, identification of access frequency, statistics on members' use of services, and delivery of promotional information such as events.
Chapter 3: Retention and Use Period of Collected Personal Information
In principle, personal information will be destroyed without delay after the purpose of collection and use has been achieved. However, the following information will be retained for the specified periods for the reasons stated below.
1. Reasons for Retention of Information Based on Company Internal Policies
Even if a member withdraws, the company retains the member's information as outlined below to ensure the smooth provision of services and to prevent the misuse of services.
Name, Email Address, Contact Information (Mobile or Landline Phone Number)
- Reason for Retention: To prevent confusion in service usage, resolve disputes, and cooperate with requests from law enforcement agencies.
- Retention Period: 1 Year
Records of Misuse/Bad Usage (including personal information of misusers/bad users)
- Reason for Retention: To prevent misuse and bad usage of services and to prevent re-registration of misusers/bad users.
- Retention Period: 1 Year
2. Reasons for Retention of Information According to Relevant Laws
If it is necessary to retain information in accordance with the provisions of relevant laws such as the Commercial Act and the Act on Consumer Protection in Electronic Commerce, the company will retain member information for a specific period as stipulated by the relevant laws. In this case, the company will use the retained information solely for the purpose of retention, and the retention period is as follows:
- Records related to contracts or withdrawal of offers.
- Reason for Retention: Compliance with the Act on Consumer Protection in Electronic Commerce.
- Retention Period: 5 Years
Records related to payment transactions and the supply of goods, etc.
- Reason for Retention: Compliance with the Act on Consumer Protection in Electronic Commerce.
- Retention Period: 5 Years
Records related to consumer complaints and dispute resolution.
- Reason for Retention: Compliance with the Act on Consumer Protection in Electronic Commerce.
- Retention Period: 3 Years
Log Records
- Reason for Retention: Compliance with the Telecommunications Secret Protection Act.
- Retention Period: 3 Months
Chapter 4: Sharing and Providing Personal Information
The company uses users' personal information within the scope defined for collection and use purposes and does not use it beyond this scope or disclose/provide it to external parties. However, exceptions apply in the following cases.
1. If the member has given prior consent to provide or share with a third party.
2. If required by law or if there is a request from law enforcement agencies in accordance with the procedures and methods prescribed by law for investigation purposes.
Chapter 5: Outsourcing of Personal Information Processing
The company outsources personal information as follows for service fulfillment and stipulates necessary provisions to ensure that personal information is managed securely in accordance with relevant laws when entering into outsourcing contracts. In the event of changes to the outsourcing company, the name of the changed company will be notified through announcements or the Privacy Policy screen.
The company's personal information processing outsourcing organizations and the details of the outsourced tasks are as follows.
- Outsourcing Recipient: 1004pr
- Details of Outsourced Tasks: Website management and SMS notification service for members.
- Retention and Use Period of Personal Information: Until the termination of the outsourcing contract.
Chapter 6: Procedures and Methods for Destruction of Personal Information
The company will, in principle, destroy the relevant information without delay after the purpose of collecting and using personal information has been achieved. The procedures and methods for destruction are as follows.
1. Destruction Procedures
① The information entered by users for membership registration and other purposes will be stored for a certain period after the purpose is achieved, in accordance with internal policies and other relevant laws regarding information protection (see retention and use period), before being destroyed.
② The personal information will not be used for any purpose other than retention, except as required by law.
2. Destruction Methods
① Personal information printed on paper will be destroyed by shredding it with a shredder or by incineration.
② Personal information stored in electronic file format will be deleted using technical methods that render the records unrecoverable.
Chapter 7: Rights of Users and Legal Representatives and How to Exercise Them
1. Members and legal representatives may access or modify the personal information of themselves or the children under the age of 14 at any time and may also request the termination of membership (withdrawal of consent).
2. To access or modify the personal information of a member or a child under the age of 14, the user can click on "Edit Member Information," and to terminate membership (withdrawal of consent), they can click on "Withdraw Membership." After going through the identity verification process, they can directly view, correct, or withdraw their information. Alternatively, they may contact the personal information management officer via written communication, phone, email, or the consultation bulletin board, and action will be taken without delay.
3. If a member or legal representative requests a correction of errors in personal information, the company will not use or provide the relevant personal information until the correction is completed. If incorrect personal information has already been provided to a third party, the company will promptly notify the third party of the correction results to ensure the correction is made.
4. The company processes personal information that is terminated or deleted at the request of a member or legal representative in accordance with the provisions outlined in "3. Retention and Use Period of Collected Personal Information" and ensures that it cannot be accessed or used for any other purposes.
Chapter 8: Installation, Operation, and Refusal of Automatic Collection Devices for Personal Information
The company uses cookies to store and retrieve member information periodically in order to provide personalized services tailored to each member. Cookies are small text files sent by the server operating the company's website to the user's browser and are stored on the user's computer hard drive. While they can identify the user's computer, they do not personally identify the user.
1. Purpose of Using Cookies, etc.
The company uses cookies for the following purposes:
- Analyzing the access frequency and visit duration of both members and non-members to understand user preferences and interests, tracking user behavior, and assessing participation in various events and visit counts for targeted marketing and providing personalized services.
2. How to Refuse Cookie Settings
Members have the option to manage cookie installation. Therefore, members can configure their web browser settings to either allow all cookies, prompt for confirmation each time a cookie is saved, or refuse the storage of all cookies.
Example of How to Set Up: (For Internet Explorer) Click on "Tools" at the top of the web browser. > Internet Options > Personal Information
However, to access the company's website and use its services, cookies must be allowed. If cookies are refused, it may be difficult to use services that require login.
Chapter 9: Technical and Administrative Measures for Personal Information Protection
Members' personal information is primarily protected by the member's ID and password. The company has established the following technical and administrative measures to ensure the safety of personal information and prevent leakage, alteration, or damage:
1. Technical Measures
① The passwords for member accounts are stored in an encrypted format, making them known only to the account holder. Therefore, only the individual who knows the ID and password can access and modify personal information that requires account login.
② The company regularly backs up data to protect against damage to personal information and employs the latest antivirus programs to prevent the leakage or damage of members' personal information or data due to computer viruses.
③ The company has implemented various security measures to ensure the safe transmission of personal information over the network in cases such as payments.
④ The company uses an intrusion prevention system (firewall) to control unauthorized access from external sources and prevent information leakage due to hacking. Additionally, the company strives to implement all possible technical measures to ensure system security.
2. Administrative Measures
① The company makes every effort to verify the identity of the member when handling personal information, such as requests for password retrieval, and to ensure that the information is processed securely.
② The company restricts access to personal information to the personal information management officer and those who are necessary to handle personal information for business purposes. It also emphasizes compliance with the personal information processing policy through regular training for employees handling personal information.
In addition to the company's efforts mentioned above, members should take care to prevent their personal information, such as IDs, passwords, and resident registration numbers, from being exposed on the internet or leaked to others. The company is not responsible for any leakage of personal information, including IDs and passwords, due to the member's negligence or lack of management.
Therefore, members should ensure that their ID and password are used only by themselves, regularly change their passwords, and use a combination of letters and numbers that are difficult for others to guess.
Additionally, it is advisable to always log out after using the service and to close the web browser. This procedure is especially important for ensuring personal information security when sharing a computer with others or using public places.
Chapter 10: Personal Information Management Officer
The company has designated a Personal Information Management Officer to protect members' personal information and address any complaints related to personal information. Members can report any personal information protection-related issues arising from using the service to the Personal Information Management Officer or the relevant department. The company will promptly provide adequate responses to user reports.
1. Personal Information Management Officer
- Name: Hun Jung
- Tel : 02.3144.3307
- Email: spacegnd@daum.net
2. Personal Information Management Department
- Department: Internet Department
- Tel : 02.3144.3307
- Email: spacegnd@daum.net
Chapter 11: Reporting and Dispute Resolution Related to Personal Information
If you need to report or seek consultation regarding personal information infringement, please contact the Personal Information Infringement Reporting Center of the Korea Internet & Security Agency (KISA).
Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
Personal Information Infringement Reporting Center: 118 (privacy.kisa.or.kr)
Cyber Investigation Division of the Supreme Prosecutors' Office: 02-3480-3570 (cybercid.spo.go.kr)
Cyber Safety Bureau of the National Police Agency: 182 (cyberbureau.police.go.kr)
Chapter 12: Obligation to Notify Changes
In the event of additions, deletions, or modifications to the current Personal Information Processing Policy due to changes in laws, policies, or security technologies, the revised policy will be notified at least 7 days prior to its implementation through the 'Announcements' section on the company's website.
1. Announcement Date: September 25, 2024
2. Effective Date: October 5, 2024