Maypure Privacy Policy
Privacy Policy of Maypure Co., Ltd.
Maypure Co., Ltd. (hereinafter the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to handle related complaints promptly and smoothly.
Article 1. Purpose of Processing Personal Information
The Company processes personal information for the following purposes only. It will not use the information for any purpose other than those specified below. If the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
1. Membership Registration and Management
- Confirming membership registration intent
- Identifying and authenticating members for membership-based services
- Maintaining and managing member status
- Preventing fraudulent use of services
- Verifying legal guardian consent for children under 14
- Sending notices and handling complaints
2. Provision of Goods or Services
- Delivery of goods and provision of services
- Sending contracts and invoices
- Providing content and personalized services
- Identity and age verification
- Processing payments and settlements
- Collecting outstanding debts
3. Handling Complaints
- Verifying the identity of complainants
- Checking complaint details and notifying results
Article 2. Processing and Retention Period of Personal Information
- The Company retains and uses personal information within the period stipulated by law or agreed upon by the data subject.
- The processing and retention periods are as follows:
- Membership Registration and Management: Until membership is withdrawn
- However, information may be retained until the end of the following situations:
- If under investigation for legal violations: until the investigation ends
- If there are unresolved financial obligations related to service use: until settlement is complete
- However, information may be retained until the end of the following situations:
Article 3. Provision of Personal Information to Third Parties
- The Company processes personal information only within the scope specified in Article 1 and will provide it to third parties only when consent is given or as permitted under Articles 17 and 18 of the Personal Information Protection Act.
- If necessary for service provision, the Company may provide personal information to third parties with the data subject’s consent, and only to the minimum extent required.
- Recipient: (e.g.) OOO Card Co., Ltd.
- Purpose of Use: (e.g.) Joint event operation and affiliated credit card issuance
- Information Provided: (e.g.) Name, address, phone number, email address, card account info
- Retention and Use Period: (e.g.) During the term of the credit card issuance contract
Article 5. Rights of Data Subjects and Legal Representatives
- Data subjects may exercise the following rights at any time:
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
- Rights may be exercised via written request, telephone, email, or fax, and the Company will respond promptly.
- When correction or deletion is requested, the Company will not use or provide the data until the request is fulfilled.
- Rights may be exercised through a legal representative or an authorized agent with a valid power of attorney (as per Form No. 11 of the Enforcement Rules).
- Data subjects must not infringe upon the privacy or personal information of themselves or others in violation of related laws.
Article 6. Items of Personal Information Processed
The Company processes the following personal information for member identification and customer support (e.g., event participation, customer inquiries by fax, mail, phone, or help center):
- Membership Registration and Management
- Required items: Account information set by the user via external services such as Kakao or Naver
- Includes: Email, phone number
- Required items: Account information set by the user via external services such as Kakao or Naver
Article 7. Destruction of Personal Information
- The Company will promptly destroy personal information when the retention period expires or processing is no longer necessary.
- Destruction procedures and methods:
- Procedure: Subject to approval by the Data Protection Officer
- Method:
- Permanently delete electronic files to prevent recovery
- Shred or incinerate physical documents
Article 8. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure data security:
- Administrative Measures: Internal management policies, regular employee training
- Technical Measures: Access control, encryption, security software installation
- Physical Measures: Restricted access to data centers and archives
Article 9. Personal Information Protection Officer
- The Company operates a dedicated personal information protection team and appoints the following Personal Information Protection Officer:
▶ Personal Information Protection Officer
- Name: Seunggyun Na
- Position: CEO
- Contact: revibio@naver.com
- You may also contact the following agencies for reports or consultation regarding personal data breaches:
| Organization | Website |
|---|---|
| Personal Information Infringement Center | https://privacy.kisa.or.kr |
| Supreme Prosecutors’ Office Cyber Crime Division | http://www.spo.go.kr |
| National Police Agency Cyber Bureau | http://cyberbureau.police.go.kr |
Supplementary Provision This Privacy Policy shall take effect from February 10, 2025.