Privacy Policy

DONGJIN IEGONG Co., Ltd. (hereinafter referred to as the "Company") places great importance on protecting the personal information of its users (hereinafter referred to as "Data Subjects") and complies with all applicable laws and regulations related to personal information protection, including the "Personal Information Protection Act" and the "Act on Promotion of Information and Communications Network Utilization and Information Protection".
Through this Privacy Policy, the Company informs you of the purposes and methods for which the personal information provided by Data Subjects or users is being used, and what measures the Company is taking to protect your personal information, so that you can easily check this information.
If the Company revises this Privacy Policy, it will announce the reasons for and details of such changes through a notice on the main page of its website or via a separate pop-up window.

Purpose of Collection and Use of Personal Information

Article 1 (Service Provision)
(1) Fulfillment of service provision
(2) Receipt and handling of customer inquiries

Article 2 (User Management)
(1) Identity verification and personal identification for service use
(2) Prevention of fraudulent use and unauthorized access
(3) Verification of legal guardian consent when collecting personal information of children under the age of 14
(4) Record retention for dispute resolution, handling of complaints and other civil matters, and delivery of notices

Article 3 (Marketing/Advertising)
(1) Development of new services and provision of customized services
(2) Provision of services and placement of advertisements based on demographic characteristics, and analysis of access frequency
(3) Verification of service effectiveness and statistics on members' service usage
(4) Provision of information on events and promotions, delivery of prizes, market research, etc.
(5) Notification of the latest company information

Items of Personal Information Collected and Collection Methods

Article 4 (Items Collected)
- Name, email address, vehicle identification number (not mandatory items)

Article 5 (Collection Methods)
- When necessary, through personal information collection sections on the website, in writing, by email, by phone, through event participation, etc.
※ The above personal information includes not only the information as collected at the time of collection but also any information subsequently modified.

Retention and Use Period of Personal Information

Article 6 (Collection and Use of Personal Information)
The Company may collect personal information in any of the following cases and may use it within the scope of the purpose of collection.
(1) Where the user's consent has been obtained
(2) Where there are special provisions in the law or it is unavoidable in order to comply with legal obligations
(3) Where the user or their legal guardian is unable to express their intent, or prior consent cannot be obtained due to an unknown address or similar reasons, and it is clearly deemed necessary for the urgent protection of the life, body, or property of the user or a third party
(4) Where it is necessary to achieve the legitimate interests of the Company and such interests clearly take precedence over the rights of the user. In such cases, this applies only where the processing is substantially related to the Company's legitimate interests and does not exceed a reasonable scope.

Article 7 (Retention and Use Period of Personal Information)
The Company retains and uses the user's personal information from the time of collection until the purpose of collection and use is achieved, and destroys the information without delay once the purpose has been achieved. However, where the Company is obligated to retain the information under applicable laws such as the Commercial Act, the Company will retain the user's personal information for the required period.

Outsourcing of Personal Information Processing

Article 8 (Outsourcing of Personal Information Processing)
1. The Company outsources personal information processing tasks to external specialized companies as follows in order to smoothly carry out its operations, such as handling user inquiries. If the outsourced company changes, the Company will notify users of the new company name through a notice or this Privacy Policy.

Outsourced Task Contractor Outsourcing Period
Website management/maintenance afeelnet Until expiration of
the outsourcing contract
Customer inquiries DONGJIN IEGONG Co., Ltd.
2. When entering into an outsourcing contract, the Company specifies in the contract or other documents, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than the outsourced task, technical and administrative protective measures, restrictions on sub-outsourcing, management and supervision of the contractor, and liability for damages, and supervises whether the contractor processes personal information safely.

Provision of Personal Information to Third Parties

Article 9 (Provision of Personal Information to Third Parties)
1. The Company may provide (including sharing) the user's personal information to third parties in any of the following cases.
(1) Where the user's consent has been obtained
(2) Where personal information is provided within the scope of the purpose of collection pursuant to subparagraphs 2 and 3 of Article 6
2. When providing personal information to a third party located overseas, the Company must inform the user of the matters prescribed by the Personal Information Protection Act and obtain their consent, and must not enter into any contract regarding the cross-border transfer of personal information that violates said Act.

Article 10 (Restrictions on the Use and Provision of Personal Information)
1. The Company shall not use personal information for purposes other than those set forth in Articles 1, 2, and 3, or provide it to third parties beyond the scope set forth in paragraphs 1 and 2 of Article 9.
2. Notwithstanding paragraph 1, the Company may use personal information for purposes other than the intended purpose or provide it to third parties in any of the following cases, except where doing so is likely to unfairly infringe upon the interests of the user or a third party.
(1) Where separate consent has been obtained from the user
(2) Where there are special provisions in applicable laws
(3) Where the user or their legal guardian is unable to express their intent, or prior consent cannot be obtained due to an unknown address or similar reasons, and it is clearly deemed necessary for the urgent protection of the life, body, or property of the user or a third party
(4) Where it is necessary for purposes such as statistical compilation or academic research, and the personal information is provided in a form that does not identify any specific individual

Procedures and Methods for Destroying Personal Information

Article 11 (Principle of Destruction)
As a general rule, unless the Company is required to retain personal information under applicable laws, the Company destroys such information without delay after the purpose of collection and use has been achieved.

Article 12 (Destruction Procedures)
(1) The Company establishes a destruction plan for personal information (or personal information files) subject to destruction and destroys it accordingly. The Company selects the personal information (or personal information files) for which grounds for destruction have arisen and destroys the personal information (or personal information files) with the approval of the Company's Chief Privacy Officer.
(2) Personal information provided by the user to the Company is, after the purpose of collection and use has been achieved, transferred to a separate database (or a separate filing cabinet in the case of paper documents) and stored for a certain period in accordance with internal policies and other applicable laws for information protection reasons (see Retention and Use Period), after which it is destroyed.
(3) Personal information transferred to a separate database is not used for any purpose other than the purpose for which it is retained, except as required by applicable laws.

Article 13 (Destruction Methods)
(1) Personal information stored in electronic file format is deleted using technical methods that render the records unrecoverable.
(2) Personal information printed on paper is destroyed by shredding or incineration.

Rights of Customers and Legal Guardians and How to Exercise Them

Article 14 (Withdrawal of Consent)
Users or their legal guardians (in the case of children under the age of 14) may withdraw their consent to the collection, use, and provision of personal information at any time.

Article 15 (Correction of Information)
1. Users may request the Company to access, receive, and correct errors in their own personal information, and legal guardians may do so with respect to the personal information of children under the age of 14.
2. Requests for access to personal information and suspension of processing may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act, which limit the rights of Data Subjects.
3. Requests for correction and deletion of personal information cannot be made where the personal information is specified as subject to collection under other laws.

Article 16 (Correction Methods)
Users may exercise the rights under Articles 14 and 15 after completing an identity verification procedure pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, by contacting the customer service center or the Company's Chief Privacy Officer in writing, by phone, or by email.

Article 17 (Confirmation of Correction)
If a user requests the correction of errors in their personal information, the Company will not use or provide the personal information in question until the correction is completed, and if the personal information has already been provided to a third party, the Company will notify the third party without delay so that the correction can be made.

Article 18 (Destruction)
If a user or their legal guardian withdraws consent, the Company, as a general rule, destroys the information without delay. However, where retention is mandated by applicable laws, the information is handled in accordance with the "Retention and Use Period of Personal Information" section of this Privacy Policy, and measures are taken to ensure that it can be accessed or used only when absolutely necessary.

Installation/Operation of Automatic Data Collection Devices and How to Refuse Them

Article 19 (Installation/Operation of Automatic Collection Devices)
The Company operates "cookies" and similar tools that frequently store and retrieve user information. A cookie is a very small text file sent by the server operating the Company's website to the user's browser and stored on the user's computer hard disk. The Company uses cookies and similar tools to analyze website access frequency and visit times, identify and analyze users' areas of interest, and track participation in various events and the number of visits, in order to provide targeted marketing and personalized services.

Article 20 (Choice Regarding Automatic Collection)
Users have the right to choose whether to allow the installation of cookies. Accordingly, users may configure their web browser options to allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies.

Article 21 (Refusing Automatic Collection)
To refuse cookie settings, users may select options in their web browser to allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies. (However, if you refuse the storage of cookies, you may experience difficulties using some services that require login.)
※ Example of how to configure settings (for Internet Explorer): Tools at the top of the web browser → Internet Options → Privacy → Advanced → Select your preferred setting

Measures to Ensure the Security of Personal Information

Article 22 (Security Measures)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the technical, administrative, and physical measures necessary to ensure security as set forth in Articles 23 through 26 of this policy.

Article 23 (Encryption of Personal Information)
Among the personal information of Data Subjects, items prescribed by laws and regulations are stored and managed in encrypted form. In addition, separate security features are used for important data, such as encrypting the data or using file lock functions when storing and transmitting files.

Article 24 (Technical Measures)
To prevent the leakage or damage of personal information due to hacking, computer viruses, or similar threats, the Company installs security programs, performs periodic updates and inspections, installs systems in areas with restricted external access, and monitors and blocks access both technically and physically.

Article 25 (Restriction of Access to Personal Information Processing Systems)
The Company takes the necessary measures to control access to personal information by granting, modifying, and revoking access rights to the database systems that process personal information, and controls unauthorized external access using intrusion prevention systems.

Article 26 (Minimization and Training of Staff Handling Personal Information)
The Company designates staff members who process personal information, minimizes their number by limiting it to those in charge, and implements measures to manage personal information through regular training.

Chief Privacy Officer and Handling of Complaints Related to Personal Information

Article 27 (Management of Personal Information)
The Company designates the following department, Chief Privacy Officer, and staff member in charge in order to protect users' personal information, handle complaints from Data Subjects regarding personal information processing, and provide remedies for damages.

Category Chief Privacy Officer Privacy Manager
Name Cheolwoo Park, Team Leader Hoseop Lee, Manager
Department HR & General Affairs Team HR & General Affairs Team
Phone 054-762-2111 054-762-2111
Email info@idongjin.com info@idongjin.com
Article 28 (Problem Resolution)
If you raise any opinions or complaints regarding the Company's Privacy Policy with the customer service department or the Chief Privacy Officer listed above, the Company will take prompt and sincere action to resolve the issue.

Article 29 (Reporting and Consultation on Infringement)
If you need to report or consult on other personal information infringements, please contact the following organizations.
1) Personal Information Dispute Mediation Committee: 1833-6972 (no area code required) (www.privacy.go.kr)
2) Personal Information Infringement Report Center: 118 (no area code required) (privacy.kisa.or.kr)
3) Supreme Prosecutors' Office Internet Crime Investigation Center: 1301 (no area code required) (www.spo.go.kr)
4) National Police Agency Cyber Terror Response Center: 182 (no area code required) (ecrm.cyber.go.kr/minwon/main)

Changes to the Privacy Policy

Article 30 (Effective Date)
This Privacy Policy was revised on July 20, 2026. If there are any additions, deletions, or modifications to its content due to changes in laws, policies, or security technologies, the Company will announce the reasons for and details of such changes on its website at least 7 days before the revised Privacy Policy takes effect.