All personal information processed by Lienjang Plastic Surgery Clinic (hereinafter referred to as the "Clinic") is collected, retained, and processed based on relevant laws and regulations. The 「Personal Information Protection Act」 provides general standards for handling such personal information. In accordance with these regulations, the Clinic handles all collected, retained, and processed personal information lawfully and appropriately to ensure the proper execution of public duties and to protect the rights and interests of information subjects. Furthermore, the Clinic respects the rights of information subjects, including the right to request access, correction, deletion, and suspension of processing of their personal information as prescribed by relevant laws. Information subjects may file an administrative appeal in accordance with the Administrative Appeals Act if their legal rights or interests are infringed upon.
To protect the personal information and rights of information subjects and to smoothly address grievances related to personal information in accordance with the 「Personal Information Protection Act」, the Clinic establishes the following Privacy Policy. Any amendments to this Privacy Policy will be announced through website notices (or individual notifications).
Article 1. Items of Personal Information Collected and Collection Method
When collecting personal information, the Clinic notifies users in advance of the scope and purpose of collection through the registration application or Terms of Use in accordance with relevant laws. The personal information items collected are as follows.
1) Items Collected During Website Registration
- ① Collected Items: Name, ID, Password, Region of Residence, Mobile Phone Number, Email, Access Logs, Cookies, Access IP Information
- ② Personal Information Collection Method: Website (Member Registration)
※ The following information may be automatically generated and collected during the process of service usage or service provision:
Service usage records, access logs, cookies, access IP information
2) Items Collected During Medical Treatment
- ① Required Items: Clinic Registration Number, Name (Korean), Date of Birth, Address, Email, Pregnancy Possibility, Referral Path
- ② Health Information: Personal health information deemed necessary by medical staff to provide medical treatment and services.
3) Items Collected During Payment of Medical Fees
- ① Credit Card Payments: Card issuer name, card number, and other credit card payment approval information.
※ If personal information is collected temporarily for other specific purposes, a separate notice will be provided at the time of collection.
4) Personal Information Collection Methods
- ① Collection via the website, written forms, fax, telephone, consultation boards, and emails.
Article 2. Purpose of Collection and Use of Personal Information
The Clinic utilizes the collected personal information for the following purposes. All information provided by users will not be used for any purpose other than those specified below, and prior consent will be sought if the purpose of use changes.
- ① Identity verification procedures for medical treatment/examination/reservation lookup and medical services
- ② Diagnosis and treatment services
- ③ Administration services such as billing, collection, and refund of medical fees
- ④ Delivery of medical bills, statements, certificates, medications/supplies, and test results
- ⑤ Entrustment of online/offline tests and requests for external examinations
- ⑥ Establishing communication channels to resolve complaints and grievances
- ⑦ Quality control of medical care, legal and administrative responses, and measures for clinic operation
- ⑧ Minimal analysis data required for education and research
- ⑨ Providing medical information, academic information, and clinic announcements
- ⑩ Informing services for promotional/marketing purposes
Article 3. Processing Personal Information of Children Under 14
The Clinic does not collect personal information from children under the age of 14. In other words, individuals under 14 are not eligible for treatment and services, and consequently, there are no provisions for legal guardians to exercise the rights of members under the age of 14.
Article 4. Retention and Use Period of Personal Information
In principle, after the purpose of collecting and using personal information has been achieved, the information is destroyed without delay. However, the following information is retained for the period specified below for the reasons stated.
- ① Retained Items: Name, Gender, Login ID, Password, Home Phone Number, Mobile Phone Number, Email
- ② Basis for Retention: Website Terms of Use / Article 15 of the Enforcement Regulations of the Medical Service Act (Retention of Medical Records)
- ③ Retention Period: Destroyed upon membership withdrawal / 10 years for Medical Records
Article 5. Destruction Procedures and Methods of Personal Information
In principle, the Clinic destroys personal information without delay once the purpose of collection and use has been fulfilled. The procedures and methods are as follows.
-
① Destruction Procedure
Information entered by members for registration or other purposes is transferred to a separate database (or a separate filing cabinet for paper documents) after the purpose is achieved. It is stored for a certain period and then destroyed in accordance with internal policies and other relevant privacy laws (refer to the retention and use period). Personal information transferred to a separate database will not be used for any purpose other than retention unless required by law.
-
② Destruction Method
Personal information stored in electronic file formats is deleted using technical methods that prevent the records from being regenerated. Personal information printed on paper is shredded or incinerated.
Article 6. Provision of Personal Information to Third Parties
- ① The Clinic processes the personal information of information subjects only within the scope specified in Article 2 (Purpose of Collection and Use of Personal Information). It provides personal information to third parties only under Articles 17 and 18 of the Personal Information Protection Act, such as when consent is obtained from the information subject or under special provisions of the law. Otherwise, it does not provide personal information to third parties.
- ② The Clinic provides personal information to third parties as follows:
1. Atium Co., Ltd.
- Recipient: Atium Co., Ltd.
- Recipient's Purpose of Use:
- ① Processing tasks related to patient identification, medical appointment scheduling, cancellations, etc.
- ② Guiding clinic utilization and introducing new clinic services and event information.
- ③ Mobile notifications regarding treatment, reservations, scheduled hospitalizations, and scheduled examinations.
- Items Provided: Name, ID, Password, Gender, Mobile Phone Number, Email, Region of Residence
- Recipient's Retention and Use Period
- ① The retention period is identical to that of the collecting institution. However, this is limited to cases resulting from termination of the contract with the collecting institution.
- ② Users have the right to refuse consent. However, refusing consent may prevent booking medical appointments, which could impact patient convenience and satisfaction.
2. Active BH Co., Ltd.
- Recipient: Active BH Co., Ltd.
- Recipient's Purpose of Use: Introduction of promotional event information for its official online mall.
- Items Provided: Name, ID, Gender, Mobile Phone Number, Email, Region of Residence
- Recipient's Retention and Use Period: ① The retention period is identical to that of the collecting institution. However, this is limited to cases resulting from termination of the contract with the collecting institution.
Article 9. Measures to Ensure the Safety of Personal Information
The Clinic takes the following measures to secure the safety of personal information.
1) Administrative Measures
-
① Establishment and Implementation of Internal Management Plans
Internal management plans are established and implemented for the secure processing of personal information.
-
② Minimization and Training of Handling Staff
Staff handling personal information are strictly designated, and differential access authority is granted to manage personal information securely.
-
③ Conducting Regular Self-Audits
Regular self-audits are conducted to secure safety regarding personal information handling.
2) Technical Measures
-
① Encryption of Personal Information
Critical personal information is encrypted during storage and transmission. Separate security features, such as file encryption, are used when handling data within the company.
-
② Technical Countermeasures Against Hacking
To prevent data leaks and damage from hacking or computer viruses, security programs are installed, updated, and inspected regularly. Systems are installed in areas restricted from external access and monitored technically and physically.
-
③ Restricting Access to Personal Information
Necessary measures are taken to control access to personal information by granting, changing, and canceling access rights to the database system processing personal information. Intrusion prevention systems are used to block unauthorized external access.
-
④ Retention of Access Records and Prevention of Forgery
Access records to the personal information processing system are retained and managed for at least 1 year, and security functions are used to prevent forgery, theft, or loss of access records.
3) Physical Measures
-
① Locking Devices for Document Security
Documents and auxiliary storage media containing personal information are stored in secure locations equipped with locking devices.
-
② Access Control for Unauthorized Persons
Physical storage locations for personal information systems are set up separately, and access control procedures are established and operated.
Article 10. Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
The Clinic operates 'cookies' that store and retrieve your information from time to time. Cookies are very small text files sent to your browser by the server operating the Clinic's website and stored on your computer's hard drive. The Clinic uses cookies for the following purposes.
- ① Analyzing the access frequency or visit time of members and non-members, identifying users' preferences and interests, and using them as a metric for service reorganization.
- ② Tracking the number of visits to various events hosted by the Clinic to provide differentiated information based on individual areas of interest. You have the right to choose whether to install cookies. Therefore, you can allow all cookies, require confirmation each time a cookie is saved, or refuse to save all cookies by configuring options in your web browser.
Article 12. Installation and Operation Management Policy for Visual Information Processing Devices
The Clinic installs and operates visual information processing devices for the following purposes in accordance with Article 25, Paragraph 1 of the Personal Information Protection Act.
-
① Basis and Purpose of Installation
- Facility safety and fire prevention
- Personnel entry/exit management and control
- Crime prevention for customer safety
- Prevention of illegal intrusion by outsiders
-
② Number of Devices, Installation Location, and Shooting Range
The number of devices, installation location, and shooting range are as follows:
- Number of Devices: Total of 97 units (61 for Petit Center, 36 for Plastic Surgery Center)
- Installation Location & Shooting Range: Inside the clinic premises
-
③ Management Responsibility and Access Authorized Persons
To protect personal visual information and handle complaints related to it, the Clinic designates the following Personal Visual Information Protection Officer:
| Classification |
Personal Visual Information Protection Officer |
| Name/Position |
Contact Information |
| Lienjang Clinic |
Representative Director Chang Young-woo |
02-591-3625 |
| Lienjang Plastic Surgery Clinic |
-
④ Shooting Time and Retention Period of Visual Information
The shooting time, retention period, and storage location of visual information are as follows:
- Shooting Time: 24 hours
- Retention Period: Within 14 days from the date of shooting
- Storage Location: Clinic Server Room
-
⑤ Method and Location for Checking Personal Visual Information
- How to Check: Contact the Visual Information Management Officer in advance and visit the Clinic.
- Location: Inside the clinic premises
-
⑥ Measures for Information Subject's Request to Access Visual Information
Information subjects can request access, confirmation of existence, or deletion of personal visual information at any time. However, this is limited to visual information in which you are recorded, or personal visual information clearly necessary for the urgent life, body, or financial interests of the information subject. The Clinic will take necessary measures without delay upon request. Notwithstanding the request, access can be denied in the following cases, and a written notification explaining the reason for denial and appeal methods will be sent within 10 days:
- How to Check: Contact the Visual Information Management Officer in advance and visit the Clinic.
- Location: Clinic Server Room
-
⑦ Measures to Ensure Safety of Visual Information
Visual information processed by the Clinic is safely managed through encryption measures. In addition, as an administrative measure, access rights are differentially granted, and the creation date/time, purpose of access, viewer, and access date/time are recorded to prevent forgery or alteration. Locking devices are installed for secure physical storage.
Article 13. Remedies for Infringement on Rights and Interests of Information Subjects
For reports or consultations regarding personal information infringement, please contact the following organizations.
Article 14. Amendments to the Privacy Policy
This Privacy Policy may change due to amendments in relevant laws, guidelines, or internal operating policies. Any amendments will be notified through the website.
Effective Date: February 20, 2024
Amendments to the Privacy Policy
- ① This privacy policy is effective from February 20, 2024.
- ② Previous versions of the privacy policy can be found below:
- Applied from Feb 28, 2022 ~ Feb 19, 2024(Click)
- Applied from Mar 30, 2012 ~ Feb 28, 2022(Click)