Política de privacidad
Privacy Policy
Gravity Labs Co., Ltd. (hereinafter referred to as "the Company") complies with the personal information protection regulations under the relevant laws and regulations, such as the "Act on Promotion of Information and Communications Network Utilization and Information Protection" and the "Personal Information Protection Act," and has established a privacy policy in accordance with these laws to protect the rights and interests of its members.
Article 1 (Items of Personal Information Collected and Collection Method)
The personal information collected by the Company and its collection methods are as follows:
1. During the membership registration process of a person (hereinafter referred to as "member") who wants to become a member of the service (hereinafter referred to as the "Service") provided through the "AHEALTH" application of the Company or the Service provided through that application, the following personal information is collected:
1. Mobile phone number
2. The following information may be automatically generated and collected during the use of the Service:
1. IP address, MAC address, connection log, service usage record, bad usage record, device information (device model, mobile carrier information, hardware ID, basic statistics on service usage), and application installation and usage history of the device (including various wireless devices such as mobile phones and tablet PCs).
3. When a member uses the Service for the first time, the Company collects the following personal information:
1. Member's health information, location data
4. From the moment a member uses the Service for the first time, the Company may access the following functions to collect personal information:
1. In order to provide the functions of the Service, the Company may access the camera, microphone, and photo album functions of the member's device to collect the member's portrait, video, voice, etc."
Article 2 (Purpose of collection/use of personal information)
The company collects/uses personal information in Article 1 for the following purposes:
1. Membership management, including verification of intent to join, age verification, member identification, rejection reasons, and confirmation of intent to withdraw.
2. Service provision.
3. Discovery of new service elements, improvement of existing services, and provision of customized services based on demographic analysis, service visit and usage records analysis, and more.
4. Protection of members and service operation, including measures to restrict use of service by members who violate laws and terms, prevention and sanctions against acts that interfere with the smooth operation of the service, prevention of account misuse and fraudulent transactions, and notification of necessary notices such as terms revisions, record preservation for dispute resolution and dispute mediation, and complaint processing.
5. Analysis of service usage records and frequency of access, statistics related to service usage, provision of customized services and advertising based on service analysis and statistics.
6. Establishment of a service usage environment that ensures the security, privacy, and safety of members.
7. In the case where a separate consent from members is obtained, email address and SNS account information may be used for marketing, promotions, event information, and advertising.
Article 3 (Provision of personal information to third parties)
1. The company will not provide a member's personal information to a third party without the member's prior consent, except in the following cases:
1. When the member has given written consent.
2. When the company has an obligation to submit a member's personal information under the provisions of the law.
Article 4 (Disadvantages of refusal to collect/use/provide personal information)
1. Members have the right to refuse to consent to the collection/use of personal information. However, if a member refuses to consent to the collection/use of personal information, the following disadvantages may occur:
1. If a member refuses to allow the company to collect/use the personal information that it intends to collect/use when applying for membership, the member cannot join the service.
2. If a member refuses to allow the company to collect/use or access personal information or mobile phone functions during the service usage process, the provision of the service to the member may be limited.
2. Members have the right to refuse to consent to the collection/use of information in Article 2, Item 7. However, if a member refuses, the member may not receive information about marketing, promotions, events, benefits, or may face disadvantages such as restrictions on using affiliated services.
Article 5 (Retention and Use Period of Personal Information)
1. The company will generally retain personal information (including sensitive information as defined in this article) until the member withdraws from the service. However, in order to prepare for unexpected withdrawals due to personal information theft, etc., the company will keep the personal information for 7 days after receiving the request for withdrawal.
2. Even after withdrawal, if there is a need to retain personal information under relevant laws and regulations, the company may retain the information for a certain period of time.
1. Records related to contracts or withdrawals: 5 years
2. Records related to complaints or dispute resolution by members: 3 years (except for ongoing civil, criminal, or administrative procedures)
3. Records related to advertisements: 6 months
4. Records related to electronic financial transactions: 5 years
5. Information related to service access, usage frequency, and location tracking data detected by a base station: 1 year
6. Information related to login records and location tracking data of the access point that can confirm the location of the mobile phone used to access the service: 3 months
Article 6 (Procedure and Method of Personal Information Destruction)
The company will promptly destroy personal information when the collection/use period expires. The procedure and method of destruction are as follows:
1. Procedure: The company selects personal information for destruction and obtains approval from the company's personal information protection manager before destroying the information.
2. Method:
1. In case of electronic files: delete using a technically irreversible method
2. In case of printed materials or other records: shred or incinerate
Article 7 (Separate Storage of Personal Information)
In the case of long-term non-use by members, personal information will be separately stored or destroyed according to the following:
1. In accordance with the Information and Communication Network Act, the company will move the ID and personal information of members who do not use the service, such as not logging in, to a separate database (or filing cabinet for paper records) to protect their personal information for the period chosen by the member at the time of joining (1 year, 3 years, or until withdrawal) or destroy it.
2. The company will notify the member of the expiration of the period, the fact that the personal information is being separately stored or destroyed, and the personal information items by electronic mail, written notice, facsimile transmission, telephone, or a similar method 30 days prior to the expiration of the effective period.
Article 8 (Rights of Members and How to Execute Them)
1. Members have the following rights related to personal information protection and can exercise them at any time. However, in such cases, the use of all or part of the service may be difficult.
1. Withdrawal of consent
2. Request for access to personal information
3. Request for correction if there are errors
4. Request for deletion
5. Request for suspension of processing
2. Members may exercise the rights under the preceding paragraph through email, phone, or written request, and the company shall promptly take measures and notify the results of the processing through email, text message, or written notification.
3. If a member requests correction of personal information errors, the company shall not use or provide such personal information to a third party until the correction is completed from the time the request was received.
4. If a member requests deletion of personal information, the company shall destroy such personal information in accordance with the procedures and methods for the destruction of personal information under Article 7.
5. Members can request to view, modify, or delete personal information directly or through a delegate (representative). When requesting through a representative, the member must submit a power of attorney in the form of Annex 11 under the Enforcement Regulations of the Personal Information Protection Act to the company.
Article 9 (Installation, Operation, and Rejection of Personal Information Automatic Collection Devices)
1. The company uses sessions that store and retrieve personal information from time to time.
1. Session: Refers to the storage of personal information by the server used for service operation during the member's connection time.
2. Sessions help maintain the environment set by members for convenient use and provide optimized customized services and utilization records to improve services.
3. Members do not have the right to choose whether to install a session, and a session is automatically created on the server when using services that require login.
4. If members do not want the company to access the photo album, camera, or microphone of their smartphone or tablet PC, the company will provide technical means to block access by the member (that is, members can block or deactivate access to the photo album, camera, and microphone of the Money Work app on their mobile phone).
Article 10 (Measures for Ensuring Security of Personal Information)
The company takes the following technical, managerial, and physical measures to ensure the security of personal information to prevent loss, theft, leakage, alteration, or damage of personal information in handling personal information:
1. Managerial measures: establishment and implementation of an internal management plan, regular employee education
2. Technical measures: access control management for personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs
3. Physical measures: access restriction to personal information storage servers and personal information usage devices
Article 11 (Personal Information Protection Manager)
The company designates relevant departments and a personal information management responsible person to protect personal information and handle complaints related to personal information. Members can report all complaints related to personal information protection that occur while using the company's services to the personal information management responsible person or the responsible department. The company will provide a prompt and sufficient response to members' reports.
* Personal Information Protection Department | Gravity Labs Customer Center: 02-6084-0713 | Email: contact@tracerofficial.com | Inquiry Hours: Weekdays 10:00 a.m. to 6:00 p.m. KST (Lunch Break: 12:00 p.m. to 1:00 p.m KST. Closed on Saturdays, Sundays, and holidays)
* Personal Information Management Responsible Person | Jacob Kim | Email: contact@tracerofficial.com
* If you need to report or consult about other personal information breaches, please contact the following organizations:
* Personal Information Protection Center (http://www.1336.or.kr)
* Personal Information Dispute Mediation Committee (www.kopico.go.kr)
* Cybercrime Investigation Department, Supreme Prosecutors' Office (http://spo.go.kr)
* Cyber Safety Bureau, National Police Agency (http://cyberbureau.police.go.kr/)
Article 12 (Notification)
If there are any additions, deletions, or modifications to the content of this privacy policy, the company will provide prior notice through an announcement at least 14 days before the revision.
* Effective Date: February 13, 2023.
2023.02.16.