Privacy policy
How we handle your personal information.
Privacy policy
Article 26 (Purpose of collecting and using personal information)
① Purpose of collection
ATOVIA (hereinafter the “Company”) collects the minimum personal information necessary to provide an optimised, tailored service, and does not use it for purposes other than those collected for without the user's consent.
② Purposes of processing
The Company processes personal information for the following purposes, and where the purpose changes it takes the necessary measures, including obtaining separate consent under Article 18 of the Personal Information Protection Act.
ⓐ Membership registration and management
Confirming intent to join, identity verification and maintaining eligibility, preventing improper use
Confirming the consent of a legal guardian for children under 14
Notices, notifications and handling complaints
ⓑ Providing goods or services
Delivering goods, providing services, sending contracts and invoices
Providing content and tailored services, identity and age verification
Payment and settlement, debt collection
ⓒ Handling grievances
Verifying the identity of the complainant and responding to enquiries
Investigating the facts and notifying the outcome
③ Possible collection of additional information
The Company may collect the following additional information as needed while you use the service.
ⓐ Payment, refunds and settlement
ⓑ Delivery and exchange of goods
ⓒ Customer enquiries and complaints
ⓓ Fulfilling obligations under the law
④ No provision to third parties
The Company does not provide personal information to third parties without the user's consent.
The following are exceptions.
ⓐ Where required by law (for example, a lawful request from an investigative authority)
ⓑ Where the member has consented in advance
ⓒ Where minimal information must be given to a courier or similar in order to provide the service
ⓓ Where urgent protection is needed because of imminent danger to a user's life, body or property
⑤ Principles of processing
The Company uses the personal information it collects in line with the purpose of providing the service, and does not use it for marketing or advertising, or provide it to third parties, without the member's consent.
In addition, under Article 30 of the Personal Information Protection Act, the Company establishes and publishes this privacy policy so that it can protect users' personal information and handle complaints promptly and smoothly.
Article 27 (Processing and retention periods)
① Retention principle
The Company processes and retains personal information within the retention and use period required by law, or within the period consented to by the member.
② Processing and retention periods
In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, it may retain personal information for the periods set out below where relevant laws require it.
1. Membership registration and management
Held until the member closes their account
However, where the following apply, held until they end
ⓐ Where an investigation or inquiry into a breach of relevant law is under way, until that investigation ends
ⓑ Where credit or debt from use of the site remains outstanding, until it is settled
2. Providing goods or services
Until the goods or services have been supplied and payment and settlement are complete
However, may be retained for a period under the following laws
a. Retention under the Act on Consumer Protection in Electronic Commerce
Records on labelling and advertising: 6 months
Records on contracts, withdrawal of subscription, payment and supply of goods: 5 years
Records on consumer complaints or dispute resolution: 3 years
b. Retention under the Credit Information Use and Protection Act
Records on the collection, processing and use of credit information: 3 years
c. Retention under the Act on Promotion of Information and Communications Network Utilisation and Information Protection
Records on identity verification: 6 months
d. Retention under Article 41 of the Protection of Communications Secrets Act
Subscriber telecommunication dates, start and end times, the other party's subscriber number, usage counts and originating base station location data: 1 year
Computer communication and internet log records, and access location tracking data: 3 months
③ Retention by individual consent
Where a member individually consents to retention for a specified period, the information may be held until then.
Article 28 (Provision to third parties and outsourcing of processing)
① Provision to third parties
ATOVIA does not provide personal information to third parties without the member's consent, and may do so only in the following cases.
ⓐ Where the law requires personal information to be provided to a particular body (for example, a request from an investigative authority)
ⓑ Where the member has consented in advance to the provision
ⓒ Where minimal information must be given to payment or delivery companies in order to provide the service
ⓓ Where urgent protection is needed because of imminent danger to a user's life, body or property
② Outsourcing of processing
ATOVIA may outsource some personal information processing in order to provide the service smoothly, and observes the following.
ⓐ Under Article 25 of the Personal Information Protection Act, we set out in the contract the prohibition on processing personal information beyond the purpose of the outsourced work, technical and administrative safeguards, restrictions on sub-contracting, management and supervision of the processor, liability for damages and related matters, and we supervise the processor's compliance.
ⓑ Where outsourcing is necessary, we notify members clearly in advance and obtain their consent.
ⓒ Where the content of the outsourced work or the processor changes, we publish it in this privacy policy without delay.
ATOVIA does not currently outsource any personal information processing; should it become necessary, we will notify members in advance and obtain their consent.
Article 29 (Items collected and how)
① Items collected
ATOVIA collects the minimum personal information needed for registration, use of the service, payment and refunds, and customer support, and does not collect resident registration numbers or i-PIN information.
a. Items required at registration and for using the service
Standard registration: username, password, name, mobile number, email address, sex, date of birth, year of birth, age band, address and delivery details
Kakao sign-in / registration: name, mobile number, email address, sex, date of birth, year of birth, age band, address and delivery details
Guest orders: orderer's name, payer's address, recipient's name, delivery details, contact number, customer note
Refund requests: orderer's name, payer's address, recipient's name, delivery details, contact number, refund account number
b. Information collected automatically while using the service
Service usage records, access logs, cookies, access IP information, payment records
② Items required for registration with a Kakao account
To complete Kakao sign-in or registration we collect name, mobile number, email address, sex, date of birth, year of birth, age band, address and delivery details. These are used to identify the member, verify identity and age, provide tailored services, and handle delivery and customer support.
③ Additional items for business or organisation Kakao accounts
Where the contact person for a business or organisation account must be verified: name, mobile number, email address, sex, date of birth, year of birth, age band, address and delivery details
④ Items collected for identity verification
Name, date of birth, sex, mobile number, national/foreign status, identity verification value (DI), encrypted user identifier (CI)
⑤ Items collected for a legal guardian's consent
Guardian's name, date of birth, sex, mobile number, duplicate registration check information (DI), encrypted user identifier (CI)
⑥ How personal information is collected
Registration on the shop, online consultation, the customer centre (by phone and online enquiry), and automatic collection while using the service
Where a legal guardian's consent is required, collected after separate consent through an identity verification agency
Article 30 (Personal information items processed)
ATOVIA processes the following personal information items in order to provide the service.
① Membership registration and management
Required: username, password, name, date of birth, sex, phone number, email address
Optional: areas of interest, marital status
② Providing goods or services
Required: username, password, name, date of birth, sex, phone number, email address, and payment details such as credit card number and bank account information
Optional: purchase history, areas of interest
③ Automatically collected items (generated while using the internet service)
IP address, cookies, MAC address, service usage records, visit records, records of improper use and similar
Article 31 (Destruction of personal information)
① Principle of destruction
Where personal information becomes unnecessary — because the retention period has passed or the purpose of processing has been achieved — ATOVIA destroys it without delay.
② Exceptions to destruction
In the following cases, personal information may be moved to a separate database or held in a different location.
Where the law requires retention for a set period
Where the user has consented
③ Procedure and method of destruction
a. Procedure
ATOVIA identifies the personal information for which grounds for destruction have arisen and destroys it with the approval of the data protection officer.
b. Method
Personal information recorded and stored as electronic files is permanently deleted (by low-level format or similar) so that it cannot be recovered.
Personal information on paper is destroyed by shredding or incineration.
Article 32 (Measures to secure personal information)
Under Article 29 of the Personal Information Protection Act, ATOVIA takes the following measures to keep personal information secure.
① Administrative measures
Establishing and carrying out an internal management plan
Regular staff training and security reviews
② Technical measures
Managing access rights to personal information processing systems
Installing access control systems and firewalls
Protecting personal information through encryption (encrypting unique identifying information)
Installing security software and reviewing it regularly
③ Physical measures
Controlling and restricting access to server rooms, record stores and similar
Designating secure areas and managing entry
Storing and disposing of documents and media containing personal information safely
Article 33 (Rights of users and legal guardians, and how to exercise them)
① Data protection rights
Users may exercise the following data protection rights against ATOVIA at any time.
ⓐ Requesting access to their personal information
ⓑ Requesting correction where there is an error
ⓒ Requesting deletion of their personal information
ⓓ Requesting that processing be stopped
② How to exercise these rights
Users may exercise these rights in writing, by phone, by email or by fax, and ATOVIA will act on them without delay.
③ Handling requests to correct or delete
Where a user requests correction of an error or deletion, ATOVIA will not use or provide that personal information until the correction or deletion is complete.
④ Exercising rights through a representative
Users may exercise their data protection rights through a legal guardian or an authorised representative.
In that case, a letter of authority in the form of Annex 11 to the Enforcement Rules of the Personal Information Protection Act must be submitted.
⑤ Duty to protect personal information
Users must comply with the Personal Information Protection Act and other relevant laws, and must not infringe others' personal information or privacy.
Article 34 (Installation and operation of automatic collection devices, and how to refuse them)
① Why cookies are used
ATOVIA uses ‘cookies’ in order to provide a tailored service.
A cookie is a small data file that a website server sends to a user's browser and which may be stored on the user's hard disk.
② What cookies are used for
Cookies are used for the following purposes.
ⓐ Analysing how users visit and use the websites and services they have visited
ⓑ Checking popular search terms and whether the connection is secure
ⓒ Providing information tailored to the user
③ How to set or refuse cookies
Users may refuse cookie storage through their web browser settings.
How to set this:
Internet Explorer: Tools > Internet Options > Privacy > Advanced
Chrome: Settings > Privacy and security > Cookies and other site data
④ If you refuse cookies
If you refuse cookie storage, tailored services may be limited.
Article 35 (Data protection officer and contact point)
① Data protection officer
ATOVIA oversees the protection and processing of personal information and designates the following data protection officer to handle complaints and provide remedies.
▶ Data protection officer
Name: Kim Jun-nyeon
Position: Representative
Contact: 010-2844-9201 / [email protected] / 0504-442-9201
※ Data protection enquiries are handled by the data protection department.
▶ Data protection department
Department: Administration
Contact person: Kim Jun-nyeon
Contact: 010-2844-9201 / [email protected] / 0504-442-9201
② Data protection enquiries and responses
Users may direct data protection enquiries, complaints and requests for remedy arising from use of ATOVIA's services to the data protection officer or the department above.
ATOVIA undertakes to answer and act on users' requests promptly.
Article 36 (Requests for access to personal information)
① Department receiving and handling access requests
Users may request access to their personal information under Article 35 of the Personal Information Protection Act, and ATOVIA will handle such requests promptly.
▶ Department receiving and handling access requests
Department: Administration
Contact person: Kim Jun-nyeon
Contact: 010-2844-9201 / [email protected] / 0504-442-9201
Article 37 (Remedies for infringement of rights)
Users may contact the following bodies for remedies and advice regarding infringement of personal information.
▶ Privacy Infringement Report Centre (operated by the Korea Internet & Security Agency)
Remit: reporting personal information infringement, requesting advice
Website: privacy.kisa.or.kr
Phone: 118 (no area code)
Address: 3rd floor, Privacy Infringement Report Centre, 9 Jinheung-gil, Naju-si, Jeollanam-do (58324)
▶ Personal Information Dispute Mediation Committee
Remit: applications for personal information dispute mediation and collective dispute mediation (civil resolution)
Website: www.kopico.go.kr
Phone: 1833-6972 (no area code)
Address: 4th floor, Government Complex Seoul, 209 Sejong-daero, Jongno-gu, Seoul (03171)
▶ Supreme Prosecutors' Office, Cybercrime Investigation Unit
Phone: 02-3480-3573
Website: www.spo.go.kr
▶ National Police Agency, Cyber Bureau
Phone: 182
Website: http://cyberbureau.police.go.kr
Article 38 (Effect and amendment of this privacy policy)
This privacy policy takes effect from 25 February 2023.
