Privacy Policy Privacy Policy

All personal information processed by Lienjang Plastic Surgery Clinic (hereinafter referred to as the "Clinic") is collected, retained, and processed based on relevant laws and regulations. The 「Personal Information Protection Act」 provides general standards for handling such personal information. In accordance with these regulations, the Clinic handles all collected, retained, and processed personal information lawfully and appropriately to ensure the proper execution of public duties and to protect the rights and interests of information subjects. Furthermore, the Clinic respects the rights of information subjects, including the right to request access, correction, deletion, and suspension of processing of their personal information as prescribed by relevant laws. Information subjects may file an administrative appeal in accordance with the Administrative Appeals Act if their legal rights or interests are infringed upon.

To protect the personal information and rights of information subjects and to smoothly address grievances related to personal information in accordance with the 「Personal Information Protection Act」, the Clinic establishes the following Privacy Policy. Any amendments to this Privacy Policy will be announced through website notices (or individual notifications).

Article 1. Items of Personal Information Collected and Collection Method

When collecting personal information, the Clinic notifies users in advance of the scope and purpose of collection through the registration application or Terms of Use in accordance with relevant laws. The personal information items collected are as follows.

1) Items Collected During Website Registration

  • ① Collected Items: Name, ID, Password, Region of Residence, Mobile Phone Number, Email, Access Logs, Cookies, Access IP Information
  • ② Personal Information Collection Method: Website (Member Registration)

※ The following information may be automatically generated and collected during the process of service usage or service provision:
Service usage records, access logs, cookies, access IP information

2) Items Collected During Medical Treatment

  • ① Required Items: Clinic Registration Number, Name (Korean), Date of Birth, Address, Email, Pregnancy Possibility, Referral Path
  • ② Health Information: Personal health information deemed necessary by medical staff to provide medical treatment and services.

3) Items Collected During Payment of Medical Fees

  • ① Credit Card Payments: Card issuer name, card number, and other credit card payment approval information.

※ If personal information is collected temporarily for other specific purposes, a separate notice will be provided at the time of collection.

4) Personal Information Collection Methods

  • ① Collection via the website, written forms, fax, telephone, consultation boards, and emails.
Article 2. Purpose of Collection and Use of Personal Information

The Clinic utilizes the collected personal information for the following purposes. All information provided by users will not be used for any purpose other than those specified below, and prior consent will be sought if the purpose of use changes.

  • ① Identity verification procedures for medical treatment/examination/reservation lookup and medical services
  • ② Diagnosis and treatment services
  • ③ Administration services such as billing, collection, and refund of medical fees
  • ④ Delivery of medical bills, statements, certificates, medications/supplies, and test results
  • ⑤ Entrustment of online/offline tests and requests for external examinations
  • ⑥ Establishing communication channels to resolve complaints and grievances
  • ⑦ Quality control of medical care, legal and administrative responses, and measures for clinic operation
  • ⑧ Minimal analysis data required for education and research
  • ⑨ Providing medical information, academic information, and clinic announcements
  • ⑩ Informing services for promotional/marketing purposes
Article 3. Processing Personal Information of Children Under 14

The Clinic does not collect personal information from children under the age of 14. In other words, individuals under 14 are not eligible for treatment and services, and consequently, there are no provisions for legal guardians to exercise the rights of members under the age of 14.

Article 4. Retention and Use Period of Personal Information

In principle, after the purpose of collecting and using personal information has been achieved, the information is destroyed without delay. However, the following information is retained for the period specified below for the reasons stated.

  • ① Retained Items: Name, Gender, Login ID, Password, Home Phone Number, Mobile Phone Number, Email
  • ② Basis for Retention: Website Terms of Use / Article 15 of the Enforcement Regulations of the Medical Service Act (Retention of Medical Records)
  • ③ Retention Period: Destroyed upon membership withdrawal / 10 years for Medical Records
Article 5. Destruction Procedures and Methods of Personal Information

In principle, the Clinic destroys personal information without delay once the purpose of collection and use has been fulfilled. The procedures and methods are as follows.

  • ① Destruction Procedure
    Information entered by members for registration or other purposes is transferred to a separate database (or a separate filing cabinet for paper documents) after the purpose is achieved. It is stored for a certain period and then destroyed in accordance with internal policies and other relevant privacy laws (refer to the retention and use period). Personal information transferred to a separate database will not be used for any purpose other than retention unless required by law.
  • ② Destruction Method
    Personal information stored in electronic file formats is deleted using technical methods that prevent the records from being regenerated. Personal information printed on paper is shredded or incinerated.
Article 6. Provision of Personal Information to Third Parties
  • ① The Clinic processes the personal information of information subjects only within the scope specified in Article 2 (Purpose of Collection and Use of Personal Information). It provides personal information to third parties only under Articles 17 and 18 of the Personal Information Protection Act, such as when consent is obtained from the information subject or under special provisions of the law. Otherwise, it does not provide personal information to third parties.
  • ② The Clinic provides personal information to third parties as follows:

1. Atium Co., Ltd.

- Recipient: Atium Co., Ltd.
- Recipient's Purpose of Use:

  • ① Processing tasks related to patient identification, medical appointment scheduling, cancellations, etc.
  • ② Guiding clinic utilization and introducing new clinic services and event information.
  • ③ Mobile notifications regarding treatment, reservations, scheduled hospitalizations, and scheduled examinations.

- Items Provided: Name, ID, Password, Gender, Mobile Phone Number, Email, Region of Residence
- Recipient's Retention and Use Period

  • ① The retention period is identical to that of the collecting institution. However, this is limited to cases resulting from termination of the contract with the collecting institution.
  • ② Users have the right to refuse consent. However, refusing consent may prevent booking medical appointments, which could impact patient convenience and satisfaction.

2. Active BH Co., Ltd.

- Recipient: Active BH Co., Ltd.
- Recipient's Purpose of Use: Introduction of promotional event information for its official online mall.
- Items Provided: Name, ID, Gender, Mobile Phone Number, Email, Region of Residence
- Recipient's Retention and Use Period: ① The retention period is identical to that of the collecting institution. However, this is limited to cases resulting from termination of the contract with the collecting institution.

Article 7. Delegation of Personal Information Processing
  • ① For smoother operations, such as providing better services and customer convenience, the Clinic entrusts personal information processing tasks to external specialized companies as follows. Through delegation agreements, the Clinic regulates compliance with personal information protection laws, confidentiality of personal information, prohibition of third-party provision, liability in the event of accidents, delegation periods, and the obligation to return or destroy personal information after processing terminates, managing them to ensure safety.
    Trustee Entrusted Task Entrusted Personal Information Retention Period
    Atium Co., Ltd. Computer system operations, new service & event notifications, CCTV management Name, Clinic Registration Number, Date of Birth Until the termination of the delegation contract
  • ② If the contents of the entrusted task or the trustee change, it will be disclosed through this Privacy Policy without delay.
Article 8. Rights and Obligations of Information Subjects and Legal Guardians, and How to Exercise Them
  • ① Information subjects may exercise their rights to request access, correction, deletion, or suspension of processing of their personal information from the Clinic at any time.
    ※ Minors over the age of 14 may exercise their rights directly or through their legal guardians.
  • ② Rights can be exercised in writing, via email, or by fax in accordance with Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act, and the Clinic will take action without delay.
  • ③ Rights may also be exercised through a legal guardian or an authorized representative. In this case, a power of attorney in accordance with Form 9 of the "Notice on Personal Information Processing Methods (No. 2020-7)" must be submitted.
  • ④ Requests for access and suspension of processing may be restricted under Article 35, Paragraph 4, and Article 37, Paragraph 2 of the Personal Information Protection Act in the following cases:
    - When there are special provisions in the law or it is inevitable to comply with legal obligations.
    - When there is a risk of harming another person's life or body, or unreasonably infringing upon another person's property and other interests.
    - When it is difficult to perform a contract, such as failing to provide agreed services unless personal information is processed, and the information subject has not clearly expressed their intent to terminate the contract.
  • ⑤ Correction and deletion cannot be requested if the personal information is explicitly designated as a collection object in other laws and regulations.
  • ⑥ When a request for access, correction/deletion, or suspension of processing is made based on the rights of the information subject, the Clinic verifies whether the person making the request is the individual themselves or a legitimate representative.
Article 9. Measures to Ensure the Safety of Personal Information

The Clinic takes the following measures to secure the safety of personal information.

1) Administrative Measures

  • ① Establishment and Implementation of Internal Management Plans
    Internal management plans are established and implemented for the secure processing of personal information.
  • ② Minimization and Training of Handling Staff
    Staff handling personal information are strictly designated, and differential access authority is granted to manage personal information securely.
  • ③ Conducting Regular Self-Audits
    Regular self-audits are conducted to secure safety regarding personal information handling.

2) Technical Measures

  • ① Encryption of Personal Information
    Critical personal information is encrypted during storage and transmission. Separate security features, such as file encryption, are used when handling data within the company.
  • ② Technical Countermeasures Against Hacking
    To prevent data leaks and damage from hacking or computer viruses, security programs are installed, updated, and inspected regularly. Systems are installed in areas restricted from external access and monitored technically and physically.
  • ③ Restricting Access to Personal Information
    Necessary measures are taken to control access to personal information by granting, changing, and canceling access rights to the database system processing personal information. Intrusion prevention systems are used to block unauthorized external access.
  • ④ Retention of Access Records and Prevention of Forgery
    Access records to the personal information processing system are retained and managed for at least 1 year, and security functions are used to prevent forgery, theft, or loss of access records.

3) Physical Measures

  • ① Locking Devices for Document Security
    Documents and auxiliary storage media containing personal information are stored in secure locations equipped with locking devices.
  • ② Access Control for Unauthorized Persons
    Physical storage locations for personal information systems are set up separately, and access control procedures are established and operated.
Article 10. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices

The Clinic operates 'cookies' that store and retrieve your information from time to time. Cookies are very small text files sent to your browser by the server operating the Clinic's website and stored on your computer's hard drive. The Clinic uses cookies for the following purposes.

  • ① Analyzing the access frequency or visit time of members and non-members, identifying users' preferences and interests, and using them as a metric for service reorganization.
  • ② Tracking the number of visits to various events hosted by the Clinic to provide differentiated information based on individual areas of interest. You have the right to choose whether to install cookies. Therefore, you can allow all cookies, require confirmation each time a cookie is saved, or refuse to save all cookies by configuring options in your web browser.
Article 11. Chief Privacy Officer
  • ① The Clinic oversees the overall management of personal information processing and has designated a Chief Privacy Officer as follows to handle complaints and remedy damages of information subjects related to personal information processing:
    Classification Chief Privacy Officer
    Name/Position Contact Information
    Lienjang Clinic Representative Director Chang Young-woo 02-591-3625
    Lienjang Plastic Surgery Clinic
  • ② Information subjects may inquire with the Chief Privacy Officer and the designated department regarding all personal information protection inquiries, complaint handlings, and damage remedies arising while using the Clinic's services. The Clinic will respond to and process inquiries from information subjects without delay.
Article 12. Installation and Operation Management Policy for Visual Information Processing Devices

The Clinic installs and operates visual information processing devices for the following purposes in accordance with Article 25, Paragraph 1 of the Personal Information Protection Act.

  • ① Basis and Purpose of Installation
    - Facility safety and fire prevention
    - Personnel entry/exit management and control
    - Crime prevention for customer safety
    - Prevention of illegal intrusion by outsiders
  • ② Number of Devices, Installation Location, and Shooting Range
    The number of devices, installation location, and shooting range are as follows:
    - Number of Devices: Total of 97 units (61 for Petit Center, 36 for Plastic Surgery Center)
    - Installation Location & Shooting Range: Inside the clinic premises
  • ③ Management Responsibility and Access Authorized Persons
    To protect personal visual information and handle complaints related to it, the Clinic designates the following Personal Visual Information Protection Officer:
    Classification Personal Visual Information Protection Officer
    Name/Position Contact Information
    Lienjang Clinic Representative Director Chang Young-woo 02-591-3625
    Lienjang Plastic Surgery Clinic
  • ④ Shooting Time and Retention Period of Visual Information
    The shooting time, retention period, and storage location of visual information are as follows:
    - Shooting Time: 24 hours
    - Retention Period: Within 14 days from the date of shooting
    - Storage Location: Clinic Server Room
  • ⑤ Method and Location for Checking Personal Visual Information
    - How to Check: Contact the Visual Information Management Officer in advance and visit the Clinic.
    - Location: Inside the clinic premises
  • ⑥ Measures for Information Subject's Request to Access Visual Information
    Information subjects can request access, confirmation of existence, or deletion of personal visual information at any time. However, this is limited to visual information in which you are recorded, or personal visual information clearly necessary for the urgent life, body, or financial interests of the information subject. The Clinic will take necessary measures without delay upon request. Notwithstanding the request, access can be denied in the following cases, and a written notification explaining the reason for denial and appeal methods will be sent within 10 days:
    - How to Check: Contact the Visual Information Management Officer in advance and visit the Clinic.
    - Location: Clinic Server Room
  • ⑦ Measures to Ensure Safety of Visual Information
    Visual information processed by the Clinic is safely managed through encryption measures. In addition, as an administrative measure, access rights are differentially granted, and the creation date/time, purpose of access, viewer, and access date/time are recorded to prevent forgery or alteration. Locking devices are installed for secure physical storage.
Article 13. Remedies for Infringement on Rights and Interests of Information Subjects

For reports or consultations regarding personal information infringement, please contact the following organizations.

Organization Telephone URL
Personal Information Infringement Report Center 118 (without area code) http://privacy.kisa.or.kr
Personal Information Dispute Mediation Committee 1833-6972 (without area code) https://www.kopico.go.kr
Cyber Crime Investigation Division, Supreme Prosecutors' Office 1301 (without area code) http://www.spo.go.kr
Cyber Investigation Bureau, National Police Agency 182 (without area code) https://ecrm.cyber.go.kr
Article 14. Amendments to the Privacy Policy

This Privacy Policy may change due to amendments in relevant laws, guidelines, or internal operating policies. Any amendments will be notified through the website.

Effective Date: February 20, 2024
Amendments to the Privacy Policy
  • ① This privacy policy is effective from February 20, 2024.
  • ② Previous versions of the privacy policy can be found below:

- Applied from Feb 28, 2022 ~ Feb 19, 2024(Click)

- Applied from Mar 30, 2012 ~ Feb 28, 2022(Click)

빠른 상담신청 입력폼