Privacy Policy
Hold Clinic (hereinafter referred to as "the Clinic") collects, retains, and processes all personal information based on relevant laws and regulations. The Personal Information Protection Act provides general standards for the handling of such personal information, and the Clinic will handle the personal information collected, retained, and processed in accordance with these legal provisions lawfully and appropriately to ensure the proper performance of public duties and the protection of the rights and interests of data subjects. In addition, the Clinic respects the rights and interests of data subjects, such as requests for access, correction, deletion, and suspension of processing of personal information held in accordance with relevant laws, and data subjects may file an administrative appeal in accordance with the Administrative Appeals Act in the event of infringement of such legal rights and interests. The Clinic has established the following privacy policy to protect the personal information and rights of data subjects and to smoothly handle complaints related to personal information in accordance with the Personal Information Protection Act. If the privacy policy is revised, it will be announced through website notices (or individual notices).
Items and Methods of Personal Information Collection
When collecting personal information, the Clinic notifies the scope and purpose of collection in advance at the time of application for membership or in the terms of use, in accordance with relevant laws and regulations. The items of personal information collected are as follows.
A. Items Collected During Medical Treatment
Required items: Hospital registration number, name (in Korean), date of birth, address, email, marital status, route of visit
Health information: Personal health information deemed necessary by medical staff for the provision of medical services, such as medical history and family history
B. Items Collected During Payment of Medical Fees
For credit card payments: Card company name, card number, and other card payment approval information
※ If personal information is collected temporarily for a specific purpose, it will be separately notified and collected.
C. Methods of Collecting Personal Information
Collected through services provided online, such as online consultations and online reservations.
Purpose of Collection and Use of Personal Information
The Clinic uses the collected personal information for the following purposes. All information provided by users will not be used for purposes other than those necessary for the following purposes, and if the purpose of use changes, prior consent will be obtained.
① Identity verification procedures for medical treatment/examination/reservation inquiry and treatment
② Services for diagnosis and treatment
③ Administrative services such as billing, payment, and refund of medical fees
④ Sending of medical fee statements, details, certificates, and delivery of medicines/products and results
⑤ Consignment of online/offline tests, requests for external tests
⑥ Securing communication channels to assist with handling complaints/grievances
⑦ Legal and administrative responses and measures for quality management of medical care and hospital operation
⑧ Minimum analysis data required for education and research
⑨ Guidance on medical information, academic information, and hospital information
Retention and Use Period of Personal Information
In principle, personal information is destroyed without delay after the purpose of collection and use has been achieved. However, the following information is retained for the period specified below for the following reasons.
① Retained items: Name, gender, mobile phone number, email
② Basis for retention: Terms of use of the Clinic's website/Article 15 of the Enforcement Rules of the Medical Service Act (Retention of medical records)
③ Retention period: 10 years for medical records
Procedures and Methods for Destruction of Personal Information
In principle, the Clinic destroys personal information without delay after the purpose of collection and use has been achieved.
A. Destruction Procedure
Information entered by members for procedure reservations, etc., is transferred to a separate database (or a separate document box in the case of paper) after the purpose is achieved and is stored for a certain period in accordance with internal policies and other relevant laws (see retention and use period) before being destroyed. Personal information transferred to a separate database is not used for any purpose other than retention unless required by law.
B. Destruction Method
Personal information stored in electronic file format is deleted using technical methods that make the records irrecoverable. Personal information printed on paper is shredded or incinerated.
Provision and Sharing of Personal Information
The Clinic does not use your personal information beyond the scope notified in the purpose of collection and use or provide it to others, other companies, or institutions without your consent or unless required by relevant laws and regulations. However, exceptions are made in the following cases.
① Submission of medical records to the Health Insurance Review and Assessment Service for claiming medical care benefits under the National Health Insurance Act
② When users have given prior consent to disclosure
③ When required by law or when requested by investigative agencies in accordance with procedures and methods prescribed by law for investigative purposes
④ When necessary for statistical compilation or academic research, provided that the information is processed and provided in a form in which specific individuals cannot be identified
Entrustment of Personal Information Processing
For better service and customer convenience, the Clinic entrusts the processing of personal information to external specialized companies as follows for smooth business operations. Through consignment contracts, the Clinic stipulates compliance with personal information protection laws, confidentiality of personal information, prohibition of provision to third parties, liability for accidents, consignment period, obligation to return or destroy personal information after the end of processing, etc., and manages compliance to ensure that personal information is managed safely.
Matters Concerning Third-Party Sharing of Personal Information
- Provider of personal information: Hold Clinic
- Person in charge of personal information: Director Daeyoung Kang
- Recipient of personal information: Hold (see website https://www.hold.hair)
A. Purpose of Use of Personal Information by the Recipient
① For patient identification and processing of tasks related to medical appointment, cancellation, etc.
② For guidance on hospital use and information on new services and events of the hospital
③ For mobile notifications regarding treatment, reservation, scheduled admission, and scheduled examination
B. Retention and Use Period of Personal Information by the Recipient
① The retention period of personal information is the same as that of the information collecting institution. However, this applies only in the event of termination (cancellation) of the contract with the information collecting institution.
② You have the right to refuse consent, but if you refuse, it may not be possible to make a medical appointment, which may affect patient convenience and satisfaction.
Rights of Users and Legal Representatives and How to Exercise Them
If a customer requests access, correction, or deletion of personal information, the Clinic will respond sincerely and process it without delay. To protect personal information, procedures for access, correction, and deletion of personal information by means other than a visit by the customer, such as by phone, mail, or fax, are not provided.
A. Access to Personal Information
① Customers may visit the Clinic to request access to their personal information, and the Clinic will respond promptly.
B. Correction/Deletion of Personal Information
① If a customer requests correction or deletion of personal information, and it is determined that there is an error in the personal information or that correction/deletion is necessary, the Clinic will correct or delete it without delay. The Clinic may request supporting documents necessary to verify the facts of the correction/deletion.
② When a customer requests access, correction, or deletion of their personal information, the Clinic will verify the customer's identity by requesting identification such as a resident registration card, passport, or driver's license.
③ If the Clinic has a legitimate reason to refuse access, correction, or deletion of all or part of the personal information, it will notify the customer and explain the reason.
④ The legal representative of a child under the age of 14 may request access, correction, deletion, or suspension of processing of the child's personal information, and must submit proof of relationship and identification.
Matters Concerning the Installation/Operation and Rejection of Automatic Personal Information Collection Devices
The Clinic operates "cookies" that store and retrieve your information from time to time. A cookie is a very small text file sent to your browser by the server used to operate the Clinic's website and stored on your computer's hard disk. The Clinic uses cookies for the following purposes.
① To analyze the frequency of access or visit times of members and non-members and to identify users' preferences and interests for use as a basis for service improvement.
② To use as data to provide differentiated information according to individual interests by identifying the number of visits to various events conducted by the Clinic.
You have the option to install cookies. Therefore, you can allow all cookies, check each time a cookie is saved, or refuse to save all cookies by setting options in your web browser. If you refuse to install cookies, some services may be difficult to provide.
Personal Information Protection Officer
The Clinic has established security devices as technical measures to protect users' personal information. All information provided by users is safely protected/managed by security equipment such as firewalls. In addition, as an administrative measure for personal information protection, the Clinic has established procedures necessary for access to and management of users' personal information, limits the number of personnel handling users' personal information to a minimum, and provides continuous security training. The Clinic also designates users of systems that process personal information, assigns user passwords, and regularly updates them.
Obligation to Notify Policy Changes
This privacy policy may be changed due to changes in relevant laws and guidelines or changes in internal operating policies. If the Clinic's privacy policy is changed, it will be announced through the website (https://holdclinicgn.com/).
Effective Date: July 22, 2024
If you need to report or consult about personal information infringement, please contact the following organizations.
1. Personal Information Dispute Mediation Committee (https://www.kopico.go.kr) (No area code) 1833-6972
2. ePrivacy Mark Certification Committee (www.eprivacy.or.kr/02-550-9531~2)
3. Supreme Prosecutors' Office Cyber Crime Investigation Division (http://spo.go.kr/ (No area code) 1301, cid@spo.go.kr)
4. National Police Agency Cyber Security Bureau (http://cyberbureau.police.go.kr/02-3150-2659)