This document has been translated into English for reference purposes only. In case of any conflict between the English and Korean versions, the Korean version shall take precedence.
CreativeLab Inc. (hereinafter referred to as the "Company" or "PacketStream") adheres to the Personal Information Protection regulations stipulated in the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. (hereinafter referred to as the "Information and Communications Network Act") and other related laws. The Company is committed to protecting user rights through a personal information processing policy based on the relevant laws.
Chapter 1. Purpose of Collection and Use of Personal Information
Personal information refers to information about a living individual, such as real name and other details that can identify the individual (including information that cannot identify a specific individual alone but can do so when combined with other information). The personal information collected by the Company is used for the following purposes:
Fulfillment of contract and billing for service provision
- Content provision, delivery of goods or sending invoices, identity verification, purchases, payment of fees, collection of charges
Member management
- Identity verification, individual identification, prevention of misuse and unauthorized use by problematic members, confirmation of the intention to join, restriction of registration and the number of registrations, verification of the legal representative of minors who joined before the revision of this policy, preservation of records for dispute resolution, complaint handling, and communication of notices
Marketing and advertising
- Development and specialization of new services (products)
- Service provision and advertising placement based on demographic characteristics
- Frequency of access analysis
- Statistics on service use by members
- Event management
- Transmission of promotional information (without providing the personal information of members to the individual or group requesting the advertisement)
Chapter 2. Types of Personal Information Collected and Method of Collection
The following information is collected at the time of initial membership registration for member identification and optimized service provision:
- Username
- Password
- Name/Corporate name
- Business registration number (for corporate members)
- Contact person's name (for corporate members)
- Email address
- Mobile phone number
- Real name verification information (CI/DI)
For service convenience, members may voluntarily provide the following information when updating their personal information:
- Address
- Fax number
- Phone number
- English name/English address
- Passport number (required for domain management regulations)
The following information may be generated and collected during service use, event participation, and other business processes:
- Real name
- Real name verification information (CI/DI)
- Gender
- Date of birth
- Occupation
- Company name
- Address
- Phone number
- Fax number
- English name/English address
- Passport number (required for domain management regulations)
- Payment method information such as bank/credit card details, service usage records, access logs, cookies, IP address information, payment records, bad usage records, user status information, visit date and time, unique device number (for mobile users, device ID or IMEI)
The Company collects personal information in the following ways:
- Membership registration, counseling boards, prize event entries, delivery requests via the website
- Collection through generated information collection tools
- Collection through necessary information during service use or voluntary provision by the user
Chapter 3. Retention and Use Period of Collected Personal Information
As a principle, the Company promptly destroys the collected personal information once the purpose of collection and use has been achieved. However, the following information will be retained for the period specified below for the reasons indicated:
Personal information retained upon member withdrawal
- Retained items: Name, business registration number, username, email address, mobile phone number, etc., provided by the member
- Basis for retention: Prevention of rejoining by problematic users, dispute resolution involving defamation, and cooperation in investigations
- Retention period: 1 year after withdrawal
In cases where retention is necessary under the provisions of related laws such as the Commercial Act and the Act on Consumer Protection in Electronic Commerce, etc., the Company will retain member information for a certain period as specified by the laws. In such cases, the retained information will be used only for its intended purpose, and the retention periods are as follows:
| Retained Item | Reason for Retention | Retention Period |
|---|---|---|
| Records related to contracts or withdrawal of offers | Act on Consumer Protection in Electronic Commerce, etc. | 5 years |
| Records on payment and supply of goods | Act on Consumer Protection in Electronic Commerce, etc. | 5 years |
| Records on consumer complaints or dispute resolution | Act on Consumer Protection in Electronic Commerce, etc. | 3 years |
| Records of visits (service usage records, access logs, IP address information) | Telecommunications Secrets Protection Act | 3 months |
Chapter 4. Procedure and Method of Destruction of Personal Information
The Company will promptly destroy personal information once the purpose of collection and use has been achieved or the retention and use period has expired. However, if a member has no usage record for 1 year, the Company will notify the member in advance and manage the personal information separately for 1 year before destruction. The destruction procedure and method are as follows:
Destruction Procedure
- The information entered by members for membership registration, etc., is stored for a certain period of time after achieving its purpose in accordance with internal policies and other related legal reasons (refer to the retention and use period) and then destroyed.
- This personal information will not be used for any purpose other than those stipulated by law.
Destruction Method
- Personal information printed on paper is shredded or incinerated, and personal information stored in electronic file format is deleted using a technical method that cannot reproduce the record.
Chapter 5. Provision and Sharing of Personal Information
In principle, the Company only uses the personal information of members for the purpose of collection and use, and does not disclose it to others or other companies/institutions. However, exceptions are made in the following cases:
With the user's prior consent
- Before collecting or providing information, the Company informs the member of who the business partners are, why and for what information is needed, how it will be protected/managed, and obtains consent. If the member does not agree, additional information will not be collected or shared with business partners.
In accordance with the provisions of the law or at the request of investigation agencies for investigation purposes following legally prescribed procedures and methods
Use and provision of personal information consistent with the purpose of use
- Providing the applicant's information to the relevant service registration business operator for domain, keyword, WINC, SSL registration
- For WHOIS service for domain names
- Providing contact information of the domain registrant involved in a dispute at the request of the dispute resolution organization or court
- Entrusting overseas escrow companies with the data of international domain name registrants' personal information in accordance with the contract with the Internet Corporation for Assigned Names and Numbers (ICANN), including member ID and password, domain name, name server information, expiration date, owner's name and address, email address
- At the request of government agencies for the performance of their duties specified in the relevant laws, such as domain name and name server information
- Using the member's information (name, address, telephone number) for business contact
- Providing information in a form that cannot identify a specific customer when necessary for statistical compilation, promotional materials, academic research, or market research
Chapter 6. Entrustment of Personal Information
The Company entrusts personal information for service improvement and ensures that personal information is managed safely during the entrustment contract in accordance with relevant legal provisions. The entrusted processing organizations and the content of entrusted work are as follows:
| Entrusted Party | Entrusted Work |
|---|---|
| KORYO CREDIT INFORMATION CO., LTD | Debt collection work |
| PAYLETTER INC | Payment services |
Chapter 7. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
To provide personalized and customized services to individual members, the Company uses 'cookies' which store and retrieve member information from time to time. Cookies are small packets of data sent to the user's browser by the server used to operate the website and are stored on the hard disk of the member's computer.
Purpose of using cookies
Analyzing the access frequency or visit time of members and non-members, identifying and tracking the tastes and interest areas of users, determining the degree of participation in various events and the number of visits for targeted marketing and personalized service provision.
How to refuse cookie settings
Members have the option to install cookies. Thus, members can allow all cookies by setting options in their web browser, go through confirmation every time a cookie is stored, or refuse to store all cookies.
Example of setting method (in the case of Internet Explorer): Web browser top > Tools > Internet Options > Privacy. However, if you refuse to install cookies, it may be difficult to use some services that require login.
Chapter 8. Technical and Administrative Measures for Personal Information Protection
Technical Measures
- Member's personal information is protected by passwords, and the data is secured with additional security functions.
- Members are required to follow password creation rules that prevent the use of easily guessable numbers like birthdays and phone numbers.
- The Company uses antivirus programs and malware defense software to prevent damage from computer viruses, and these are regularly updated daily.
- The Company uses routers and L3 switch equipment with intrusion blocking and detection functions to doubly secure personal information on the network.
- A separate intrusion blocking system (Firewall) is established to operate a triple personal information protection system.
- Personal information is encrypted and stored in the personal information protection system, and when transmitting personal information outside the Company's network or storing it on PCs, the system ensures it is encrypted.
Administrative Measures
- In addition to the efforts mentioned above, members themselves should be careful not to expose their passwords or other sensitive information to third parties, especially in public places. It is advisable for members to use their ID and password exclusively and to change passwords frequently.
- The Company has established separate computer management regulations as per Company policy, adhering to the following:
- Appointment of a personal information protection officer and matters related to the organization and operation of personal information protection
- Matters related to the training of personal information handlers
- Maintenance and regular inspection of access records to the personal information processing system
- Protective measures for printing and copying personal information
- Other necessary matters for the protection of personal information
Chapter 9. Rights of Users and Legal Representatives and How to Exercise Them
- Users can access or modify their registered personal information at any time and can also request to withdraw membership. To access or modify personal information, users can click 'Information Change' on the Company website, and for withdrawal, click 'Information Change > Membership Withdrawal' and follow the identity verification process.
- The Company will respond to requests for access, modification, withdrawal, or suspension of processing of personal information within 10 days and will notify the user of the outcome.
- The department and person responsible for receiving and processing requests for access, modification, withdrawal, or suspension of personal information are as follows:
- Department: Operations Team
- Contact Person: Seongyun Ku, [email protected]
- The Company processes personal information that has been terminated or deleted at the user's request according to the "Period of Retention and Use of Personal Information Collected by the Company" and ensures that it cannot be viewed or used for any other purpose.
Chapter 10. Personal Information Protection Officer and Consultation and Reporting
The Company has appointed a personal information protection officer to protect members' personal information and handle complaints related to personal information. If you have any inquiries regarding your personal information, please contact the personal information protection officer below:
- Department: Operations Team
- Contact Person: Seongyun Ku, [email protected]
Chapter 11. Additional Provisions for Users in the European Union (GDPR Notice)
For users located in the European Economic Area (EEA), the Company strives to comply with applicable data protection regulations, including the General Data Protection Regulation (GDPR). This Chapter applies only to users residing in the EEA.
Legal Basis for Processing Personal Data
The Company processes personal data under the following legal bases:
- Performance of a contract (e.g., service provision and billing)
- Compliance with legal obligations
- Legitimate interests pursued by the Company (e.g., service improvement, fraud prevention)
- Consent provided by the user, where applicable
Data Subject Rights
Under GDPR, users have the following rights:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
Users may exercise these rights by contacting the Company using the contact information provided in Chapter 10.
International Data Transfers
Personal data may be transferred outside the EEA, including to the Republic of Korea. In such cases, the Company ensures appropriate safeguards are in place in accordance with applicable laws.
Data Retention
Personal data will be retained only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Complaints to Supervisory Authority
If users believe that their personal data has been processed in violation of applicable laws, they have the right to lodge a complaint with a supervisory authority in their country of residence.