Privacy Policy

The NSTRI Data Platform (from now on referred to as the "Platform"), operated by the National Strategic Technology Specialized Research Institute (from now on referred to as the "Institute"), complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Protection of Communications Secrets Act, the Telecommunications Business Act, and other relevant laws and regulations that information and communications service providers must observe. By these laws and regulations, this Privacy Policy has been established to protect personal information, ensure the rights and interests of users, and facilitate handling user complaints related to personal information.

Chapter 1: Purpose, Retention Period, and Collection Items of Personal Information

Article 1 (Purpose of Processing Personal Information)

The Institute processes personal information for the following purposes. Personal information processed by the Institute is not used for purposes other than those listed below. In the event of a change in processing purposes, the Institute will take necessary measures, such as obtaining separate consent by Article 18 of the Personal Information Protection Act.

  • Membership Registration and Management
  • The Institute collects personal information upon registration on the Platform to provide membership services, confirm membership and withdrawal intentions, identify and authenticate users, maintain and manage membership status, prevent improper use of Platform services and information, handle complaints, confirm legal representative identity, limit the number of registrations, retain records for dispute resolution, and deliver notices.

  • Execution of Contracts Related to Platform Service Provision and Fee Settlement
  • Personal information is collected for service provision, invoice issuance, identity verification, payment processing, and fee collection.

  • Development of New Services and Marketing Utilization
  • Personal information is collected for developing new and customized services, statistical analysis based on service usage, verification of service effectiveness, event participation opportunities, analysis of access frequency, and marketing purposes.

  • Handling Platform Complaints
  • Personal information is collected for developing new and customized services, statistical analysis based on service usage, verification of service effectiveness, event participation opportunities, analysis of access frequency, and marketing purposes.

Article 2 (Retention and Processing Period of Personal Information)

In principle, the personal information of members is destroyed without delay upon member withdrawal or upon achieving the intended purpose of use. However, the following information will be retained for the specified period for the reasons listed below:

  • Retention of Personal Information with Separate Consent
    • If investigations or inquiries related to violations of relevant laws are in progress: Until the end of such investigations/inquiries.
    • If there are outstanding claims or debts related to Platform use, it will be up to the respective claims or obligations to be settled.
    • Records of improper use: One year after withdrawal.
    • Files determined to contain malicious infections: One month.
    • Handling of complaints: Three years after the conclusion of complaint processing.
  • Retention of Information by Relevant Laws
  • The Institute retains member information for a specified period as required by laws such as the Commercial Act and the Act on Consumer Protection in Electronic Commerce. In this case, retained information is used solely for the purposes specified, with retention periods as follows:

    • Records on contracts or withdrawal of subscriptions: Five years.
    • Records on payment and supply of goods, etc.: Five years.
    • Ledgers and supporting documents related to all transactions defined by tax law: Five years.
    • Records related to electronic financial transactions: Five years.
    • Login records: Three months.

Article 3 (Items of Personal Information Processed and Collection Methods)

  • The Institute collects the following minimum personal information to facilitate membership registration, smooth complaint handling, and the provision of various services.
    • Membership Management and Administration

    • - Mandatory Items: Email address, ID, password, affiliated institution.
      - Optional Items: ORCID.

    • Fee Settlement for Service Provision

    • 2-1. Payment Processing

      - Credit Card: Date of birth (or business registration number for businesses), credit card number, card expiration date.

  • During service use or service-related operations, the following information may be automatically generated or additionally collected:
    • IP address, cookies, device information, access logs, visit timestamps, service usage records, records of improper use, and payment records.
  • During the service use process, additional information may be collected for specific service users as follows:
    • Where Separate Consent for Personal Information Collection is Obtained
    • - General Inquiries: Email address.
      - Research Project Creation: Institutional Review Board (IRB) approval, Data Review Board (DRB) approval.

  • The Institute collects personal information through the following methods:
    • Collection via the website, written forms, email, and consultation boards.
    • Collection through data generation tools.

Chapter 2: Provision and Outsourcing of Personal Information Processing

Article 4 (Provision of Personal Information to Third Parties)

The Institute shall, in principle, process personal information within the scope specified in "Article 1: Purpose of Processing Personal Information" and shall not use or disclose personal information to external parties beyond this scope without the prior consent of the data subject, except in the following cases:

  • When separate consent is obtained from the data subject.
  • When there are special provisions in the law.
  • When it is impossible to obtain prior consent due to the data subject or legal representative being incapable of expressing intent or when the data subject's whereabouts are unknown, and it is necessary for the immediate protection of life, body, or property of the data subject or a third party.
  • When necessary for statistical or academic research purposes, provided that personal information is provided in a form that makes it impossible to identify a specific individual.
  • When using personal information beyond its intended purpose or providing personal information to third parties, it is necessary to perform duties prescribed by other laws, subject to deliberation and resolution by the Protection Committee.
  • When providing information to foreign governments or international organizations for the implementation of treaties or other international agreements.
  • When necessary for investigating crimes, prosecution, and the maintenance of prosecution.
  • When necessary to execute sentences, protective custody, or protective orders.

Article 5 (Outsourcing of Personal Information Processing)

  • To enhance service quality, the Institute outsources the processing of personal information as follows:
  • - Entrusted Party: NHN KCP
    - Entrusted Task: Credit card payment processing.

  • In compliance with relevant laws, the Institute stipulates in outsourcing contracts, by Article 26 of the Personal Information Protection Act, that personal information shall not be processed for purposes other than the intended purposes of the outsourced task. The contracts also include clauses on technical and administrative protective measures, the scope and purpose of the entrusted task, restrictions on re-entrustment, security measures, management and supervision of the entrusted party, and damage responsibilities. The Institute monitors and supervises the entrusted party to ensure personal information is handled securely.
  • If the outsourced tasks are changed or the processing is re-entrusted to another party, such information will be disclosed through links to the entrusted party's privacy policy.

Chapter 3: Procedures and Methods for Destroying Personal Information

Article 6 (Procedures and Methods for Destroying Personal Information)

  • Personal information of members shall, in principle, be destroyed without delay once the purpose of its collection and use has been achieved.
  • If the retention period for personal information, as agreed upon with the data subject, has expired, or if the processing purpose has been fulfilled, but the information must be retained by internal policies or other relevant laws (as specified in Article 2: Processing and Retention Period of Personal Information), the applicable personal information shall be transferred to a separate database (or, in the case of paper records, to a separate file cabinet) and stored safely for a designated period before being destroyed.
  • The procedures and methods for destroying personal information are as follows:
    • Destruction Procedure
    • The Institute establishes a personal information destruction plan for information that needs to be destroyed. Personal information identified as requiring destruction is selected, and the destruction is carried out with the approval of the Personal Information Protection Officer.

    • Destruction Methods
      • Personal information printed on paper shall be shredded using a shredder or incinerated.
      • Personal information stored in electronic file formats shall be deleted using technical methods that make the records irrecoverable.

Chapter 4: Rights of Members and Legal Representatives

Article 7 (Rights, Duties, and Methods of Exercise for Data Subjects and Legal Representatives)

  • Data subjects may exercise their rights to request access, correction, deletion, and suspension of processing their personal information at any time from the Institute.
  • Data subjects may exercise their rights directly via the "Account > Profile" page, by contacting the administrator, or through easily accessible methods such as written request, phone, email, or electronic communication. The Institute shall take appropriate actions within ten business days of receiving the request and inform the data subject accordingly.
  • If a data subject requests correction or deletion of their personal information due to errors, the Institute shall not use or provide the personal information until the correction is completed.
  • Personal information terminated or deleted at the data subject's request shall be processed as specified in "Article 2 (Processing and Retention Period of Personal Information)". It will not be accessible or usable for other purposes.
  • The rights stipulated in Paragraph 1 may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney by Form No. 11 of the public notice on the methods of personal information processing must be submitted.

Chapter 5: Technical and Managerial Measures to Protect Personal Information

Article 8 (Measures to Ensure the Security of Personal Information)

The Institute takes the following technical and managerial measures to prevent the loss, theft, leakage, alteration, or damage of personal information by Article 29 of the Personal Information Protection Act:

  • Minimization and Training of Personnel Handling Personal Information
  • The Institute designates and restricts the handling of personal information to specific personnel and limits the number of personnel involved.

  • Regular Self-Audit
  • The Institute conducts regular self-audits (at least once a year) to ensure the security of personal information handling.

  • Establishment and Implementation of Internal Management Plan:
  • The Institute establishes and implements an internal management plan to safely handle personal information.

  • Encryption of Personal Information Member passwords are stored and managed in an encrypted format known only to the member, and critical data is encrypted for both file and transmission data security.
  • Technical Measures Against Hacking
  • The Institute implements security programs and regularly updates and inspects to prevent personal information leakage or damage caused by hacking or computer viruses. It ensures secure transmission of information through encrypted communication and restricts access to systems installed in controlled areas with technical and physical monitoring and blocking.

Chapter 6: Installation, Operation, and Refusal of Automated Personal Information Collection Devices

Article 9 (Installation, Operation, and Refusal of Automated Personal Information Collection Devices)

  • The Institute uses "cookies" to store and retrieve member information frequently to provide personalized services.
  • A cookie is a small text file sent by the server operating the website to the member's browser and may be stored on the member's hard disk. When the member revisits the website, the server reads the content of the cookie stored on the member's hard disk to maintain personalized settings and provide tailored services.
  • Cookies do not automatically or actively collect personally identifiable information, and members may refuse or delete cookies at any time.
    • Purpose of Using Cookies
    • Cookies analyze member access frequency, visit times, service usage patterns, security connections, and other data to provide optimized information.

    • Installation, Operation, and Refusal of Cookies
      • Members have the option to set cookie preferences. By adjusting their browser settings, they may choose to allow all cookies, receive a prompt each time a cookie is saved, or reject all cookies.
      • If cookies are rejected, the Institute's services may be challenging.

Chapter 7: Miscellaneous

Article 10 (Personal Information Protection Officer)

The Institute has designated the following Personal Information Protection Officer responsible for overseeing personal information processing, handling complaints from data subjects, and providing remedies for damages related to personal information processing:

  • Personal Information Protection Officer/Manager:

  • - Name: Kyungmin Cho
    - Department: NSTRI
    - Operations Team
    - Phone: +82 02-2072-4628
    - Email: kmcho1201@snuh.org

  • Data subjects may contact the Personal Information Protection Officer or the relevant department for any privacy-related inquiries or complaints arising from using the Platform. The Institute will respond promptly and thoroughly to all reported matters.
  • Data subjects may request access to their personal information through the relevant department under Article 35 of the Personal Information Protection Act. The Institute will endeavor to ensure that access requests are promptly processed.

Article 11 (Remedies for Infringement of Rights)

Data subjects may seek dispute resolution or consultation from the Personal Information Dispute Mediation Committee, Korea Internet & Security Agency Personal Information Infringement Report Center, or other relevant organizations to receive remedies for infringements of their personal information. For more information, contact:

  • Personal Information Dispute Mediation Committee (https://www.kopico.go.kr / 1833-6972)
  • Personal Information Infringement Report Center (https://privacy.kisa.or.kr / 118)
  • Supreme Prosecutors' Office Cyber Investigation Division (http://www.spo.go.kr / 1301)
  • Cyber Bureau of National Police Agency (https://ecrm.police.go.kr / 182)

Article 12 (Exceptions)

The Institute's Privacy Policy does not apply to personal information collected by websites linked to the Institute's Internet services.

Article 13 (Obligation to Notify)

In the event of additions, deletions, or modifications to this Privacy Policy, the Institute shall notify users through the Platform's "Notice" section at least seven days before the changes. In the event of significant changes to user rights, the Institute shall notify users at least 30 days in advance and may request user consent again if necessary.

Supplementary Provisions

This Privacy Policy shall be effective as of September 13, 2024.