Privacy Policy

Hold Clinic (hereinafter referred to as "the Clinic") handles all personal information in accordance with relevant laws and regulations. The Personal Information Protection Act provides general standards for the handling of personal data, and the Clinic collects, retains, and processes such information lawfully and appropriately to ensure both the smooth operation of its services and the protection of data subjects' rights. The Clinic respects your rights to access, correct, delete, or request suspension of processing of your personal information as stipulated by law, and data subjects may appeal in accordance with the Administrative Appeals Act in cases of infringement. This Privacy Policy is designed to protect your personal information and resolve any related complaints effectively, and any future revisions to this policy will be announced on our website (or individually).

Types and Methods of Personal Information Collection

When collecting personal information, the Clinic provides advance notice of the scope and purpose in membership application forms or terms of use according to relevant laws. The information we collect is listed below.

A. Information Collected During Medical Consultations

Required: Clinic registration number, name (in Korean), date of birth, address, email, marital status, route of visit

Health Information: Medical history, family history, and any personal health details deemed necessary for the provision of medical services

B. Information Collected During Payment

When paying by credit card: Card company, card number, and other approval information for card payment

※ If personal information must be collected temporarily for a specific purpose, we will notify and obtain it separately.

C. Methods of Collecting Personal Information

Through online consultation, online reservation, or other services provided online.

Purpose of Collection and Use of Personal Information

The Clinic uses collected personal information for the following purposes only. All information you provide will not be used for any purpose other than those stated below, and if the purpose changes, prior consent will be obtained.

1. Identification for consultation/examination/reservation check and treatment

2. Services for diagnosis and treatment

3. Administrative services such as billing, payment, and refund of medical expenses

4. Sending statements, receipts, various certificates, and delivery of medicine/supplies and results

5. Outsourcing/ordering of online/offline tests and external laboratory requests

6. Maintaining communication channels for handling inquiries and complaints

7. Quality control of medical services, and legal/administrative responses for hospital operations

8. Minimum analysis for education and research

9. Notices about medical, academic, or clinic information

Retention and Usage Period of Personal Information

In principle, personal information is destroyed without delay once the purpose of collection and use has been fulfilled. However, the following information will be retained for the reasons and periods specified below.

1. Items retained: Name, gender, mobile phone number, email

2. Basis for retention: Clinic website Terms of Use/Medical Service Act Enforcement Rule Article 15 (preservation of medical records)

3. Retention period: Medical records for 10 years

Destruction Procedures and Methods of Personal Information

As a rule, the Clinic promptly destroys personal information once the purpose of collection and use has been achieved.

A. Destruction Procedure

Information entered for treatment reservations, etc. is transferred to a separate database (or stored in a separate file cabinet in the case of paper documents) after its purpose is fulfilled. It is stored for a certain period according to internal policy and relevant laws (see the retention and usage period), and then destroyed. Personal data transferred to a separate DB will not be used for any purpose other than legal retention.

B. Destruction Method

Personal information in electronic files is deleted using technical methods that do not allow data to be restored. Paper documents are shredded or incinerated.

Provision and Sharing of Personal Information

The Clinic will not use your personal information for purposes other than those notified or share it with third parties, unless you have consented or exceptions are stipulated by law. However, exceptions include:

1. Submitting medical records to the Health Insurance Review & Assessment Service for medical fee claims as required by the National Health Insurance Act

2. When users have given prior consent to disclosure

3. When required for investigations according to legal procedures and methods by law enforcement

4. When providing information for statistics or academic research in a manner that does not disclose individual identities

Entrustment of Personal Information Processing

To provide better services and ensure smooth business operations, the Clinic may entrust certain personal information processing tasks to specialized external companies. Through consignment agreements, the Clinic requires these companies to comply with privacy laws, maintain confidence, prohibit third-party provision, assume responsibility in the event of an accident, specify the consignment period, and ensure the return or destruction of personal information upon completion. The Clinic manages these obligations to keep your data safe.

Third-Party Sharing and Processing of Personal Information

- Provider of personal information: Hold Clinic

- Personal information manager: Dr. Oh Jeong Seop

- Recipient of information: Hold (see website https://www.hold.hair)

A. Purpose of Use by the Recipient

1. Patient identification, medical appointment, and cancellation-related processes

2. Notification of clinic use, new services, events, and promotions

3. Mobile notifications regarding consultations, appointments, admission, and scheduled examinations

B. Retention and Usage Period by the Recipient

1. Same retention period as the collecting institution, except upon contract termination between institutions

2. You have the right to refuse consent, but refusal may limit your ability to make reservations and decrease convenience and satisfaction

Rights of Users and Legal Representatives and How to Exercise Them

If a customer requests access, correction, or deletion of their personal information, the Clinic will sincerely respond and promptly process such requests. For your protection, access, correction, and deletion of personal information are not provided over phone, mail, fax, or other non-in-person channels.

A. Accessing Personal Information

1. You may visit the Clinic to request access to your personal information, to which we will respond promptly.

B. Correction and Deletion of Personal Information

2. If you request correction or deletion of your personal data, and it is found to be erroneous or correction/deletion is recognized as necessary, the Clinic will correct or delete it promptly. We may request documentation necessary to verify the details.

3. When you request access, correction, or deletion, you may be asked to provide identification such as a resident registration card, passport, or driver's license to confirm your identity.

4. If the Clinic has a valid reason to deny full or partial access, correction, or deletion, you will be informed and the reason explained.

5. Legal representatives of children under 14 may request access, correction, deletion, or suspension of processing of the child's personal information after submitting proof of relationship and identification.

Operation and Refusal of Automatic Personal Information Collection Devices

The Clinic uses "cookies" to save and retrieve your information whenever necessary. Cookies are small text files sent to your browser by the server running the Clinic's website and stored on your computer's hard disk. We use cookies for the following purposes:

1. To analyze access frequency and visit times of members and non-members, and identify users' preferences and interests to help improve services

2. To record the number of visits to Clinic events and provide customized information based on personal interests

You have the option to accept or refuse cookies. By adjusting your web browser settings, you can allow all cookies, confirm each time a cookie is saved, or refuse all cookies entirely. Please note that refusing cookies may make certain services unavailable.

Personal Information Protection Officer

The Clinic has implemented technical security measures, such as firewalls and other security equipment, to protect users' personal information. All information you provide is safely managed and protected. Administratively, we limit the number of employees who handle personal data and provide ongoing training, as well as establish procedures for accessing and managing such data. Users of our systems are issued individual passwords, which are changed regularly.

Obligation to Notify About Policy Changes

This privacy policy may be revised due to changes in relevant laws, guidelines, or internal operating policies. Any changes will be posted on our homepage (https://holdclinicgn.com/).

Role
Name
Department
Email
Personal Information Protection Officer
Oh Jeong Seop
Chief Doctor
gangnam@hold.clinic
Personal Information Manager
Oh Jeong Seop
Chief Doctor
gangnam@hold.clinic

Effective Date: July 22, 2024

If you need to report or consult about personal information infringement, you may contact the organizations below.

1. Personal Information Dispute Mediation Committee (https://www.kopico.go.kr) (No area code) 1833-6972

2. Privacy Mark Accreditation Committee (www.eprivacy.or.kr/02-550-9531~2)

3. Supreme Prosecutors' Office Cyber Investigation Team (http://spo.go.kr/ (No area code) 1301, cid@spo.go.kr)

4. National Police Agency Cyber Security Bureau (http://cyberbureau.police.go.kr/02-3150-2659)