SK Rent-a-Car Co., Ltd. (hereinafter the “Company”) highly values personal information and personal location information (hereinafter the “personal information”) of customers using SK Rent-a-Car service (hereinafter the “Service”) provided by the Company and is dedicated to safeguarding customers’ personal information.
The Company complies with all laws and regulations related to personal information protection, including the Personal Information Protection Act, the Credit Information Use And Protection Act, and the Act On The Protection And Use Of Location Information, while separately establishing and complying with the Company’s Privacy Policy, to protect the personal information of its members. In addition, the Company discloses its Privacy Policy on the first page of its website to allow its members to view it easily at any time. Any modification to the Company’s Privacy Policy will be notified on the website.
The Company’s Privacy Policy contains the following:
- 01. Collected Personal Information, Purpose of Processing, and Period of Retention and Use
- 02. Personal Information Processing for Children Under 14 Years of Age
- 03. Provision of Personal Information to a Third Party
- 04. Consignment of Personal Information Handling
- 05. Destruction Procedures and Methods of Personal Information
- 06. Rights and Obligations of Data Subject and Legal Representatives, and How to Exercise Them
- 07. Measures to Ensure the Security of Personal Information
- 08. Installation, Operation, and Rejection of Tools Collecting Personal Information Automatically
- 09. Collection, Use, Provision, and Rejection of Behavioral Information
- 10. Chief Personal Information Protection Officer and Personal Information Access Request
- 11. Remedies for Violation of Rights and Interests of Data Subjects
- 12. Installation and Operation of Visual Data Processing Devices
- 13. Amendments to the Privacy Policy
01. Collected Personal Information, Purpose of Processing, and Period of Retention and Use
① The Company processes the personal information of data subjects as follows:
| Category | Required / Optional | Items Collected | Purpose of Use | Retention Period | ||
|---|---|---|---|---|---|---|
| Service | Channel | |||||
| Membership | SK Rental for foreigners | Online | Required | Name, ID, password, mobile phone number, nationality, passport number, email address(verification upon membership sign-up), date of birth | To verify membership and provide membership services | Until withdrawal of membership |
| Optional | Mobile phone number, service usage history (search history etc.), Driver’s license number, license type |
|
| |||
| Driver’s License Registration | Online | Optional | Driver’s license number, license type, driver license classification | To verify vehicle rental qualifications | Until withdrawal of membership or deletion of license information | |
| Short-term Contract | Online | Required | Name, date of birth, email address, passport number |
| 5 years after the termination of the contractual business relationship | |
| Driver’s license number, license type, license expiry date, license issue date, date of birth | To verify vehicle rental qualifications | |||||
| Card payment information (card issuer, card type, card number, expiration date, date of birth, first 2 digits of password) | To settle fees based on the fulfillment of the purchase contract and provision of service | |||||
| (In case of using affiliate services) (SKT) T Membership number, Point Password (KT) Membership number (LG U+) Membership number, Date of birth (Korean Air, Asiana Airlines) Name, airline membership/mileage number |
| |||||
| Device | Required | (Collected only in case of vehicle theft or non-return) Vehicle location information (GPS) |
| Until the vehicle is retrieved | ||
| Branch | Offline | Required | Name, gender, date of birth, mobile phone number, email address, nationality |
| 5 years after the termination of the contractual business relationship | |
| Driver’s license number, license type (Foreigner) Passport number, copy of passport Copy of (International) Driving Permit | To verify vehicle rental qualifications | |||||
| Card issuer, last 4 digits of the card number | To settle fees based on the fulfillment of the purchase contract and provision of service | |||||
| Address | To send bills in the event of penalties or debts | |||||
| (Additional Driver) Name, date of birth, mobile phone number | To register additional driver | 2 years after the termination of the contractual business relationship (for foreign passports and driver’s license - 10 years after the termination of the contractual business relationship) | ||||
| (Additional Driver) Driver’s license number, license type, license issue date, license expiry date, date of birth (Foreigner) Passport number, copy of passport Copy of (International) Driving Permit | To verify vehicle rental qualifications | |||||
| Device | Required | (Collected only in case of vehicle theft or non-return) Vehicle location information (GPS) |
| Until the vehicle is retrieved | ||
| Offline | Required | (Keyed-in credit card transaction agreement for foreigners) Credit card number, expiration date, owner, contact number, address, relationship with the renter, email address | To process keyed-in transactions for additional costs incurred during vehicle rental | 6 months after the termination of the contractual business relationship | ||
※ Online: Website (Web/Mobile Web), Mobile app.
※ Offline: Phone call, branch
※ External: Consignee, affiliate
※ Device: A device (Smart Link) is installed in a rental vehicle to collect vehicle location information. (Requests are made to SK Telecom to determine the location information.)
② In the process of using the service, the following personal (location) information items may be automatically generated and collected:
- IP address, cookies, MAC address, mobile device OS information, service usage history, visit history, call logs during consultation, etc.
※ Even after the purpose of collecting and using personal information is achieved, records that must be retained according to relevant laws, including the Act On The Consumer Protection In Electronic Commerce, are retained for a certain period before destruction.
- • Records on contracts or withdrawal of subscription: 5 years
- • Records on payment and supply of goods: 5 years
- • Records on handling member complaints and disputes: 3 years
- • Commercial ledgers and important documents related to business: 10 years
- • Communication confirmation data (login record): 3 months
02. Personal Information Processing for Children Under 14 Years of Age
The Company does not collect personal information of children under 14 years old, and their membership registration is not allowed.
03. Provision of Personal Information to a Third Party
① The Company processes the data subject's personal information only within the scope specified for the purpose of processing the personal information. Personal information is provided to third parties only when it falls under Articles 17 and 18 of the Personal Information Protection Act, such as the consent of the data subject and special provisions in other statute; otherwise, the Company does not provide the personal information of the data subject to third parties.
② The company provides personal information to third parties as follows:
| Service | Recipient | Items Provided | Recipient’s Purpose of Use | Retention and Use Period |
|---|---|---|---|---|
| Short-term Contract | (In case of using affiliate services) Korean Air, Asiana Airlines | Name, affiliate member number / mileage number, rental period | To verify data to accumulate/settle mileage points | Until affiliate service termination |
| (In case of using affiliate services) Jin Air | Name, vehicle number, date and time of departure, date and time of arrival | To verify data for affiliate service settlement | ||
| (In case of using affiliate services) SKT, KT, LG U+ | (Common) Membership number (SKT) Point password (LG U+) Date of birth | To verify membership |
③ In the event of emergencies, such as disaster, infectious disease, incident or accident causing urgent life or bodily harm, and imminent property loss, the Company may provide personal information to the relevant organizations. For more information, please click here (link to the Personal Information Handling and Protection Rules in Emergency Situations, jointly announced by the relevant government departments in October 2021).
※ In this case, the Company will provide only the minimum necessary personal information based on applicable laws and will not provide information for purposes other than those specified.
04. Consignment of Personal Information Handling
① In order to facilitate personal information processing, the Company entrusts personal information processing as follows:
| Category | Consignee | Description of Tasks Entrusted | |
|---|---|---|---|
| Vehicle Rental | Contract / Customer Management | Sales partners who signed a car rental brokerage contract with SK Rent-a-Car Co., Ltd. |
|
| Car Life Service Co.,Ltd | Customer center operation, TM on the Company’s products and services (TMs are limited to cases where prior consent is obtained.) | ||
| Companies that signed a business outsourcing contract for sales offices/customer centers, etc. | Processing sales office/customer center tasks, customer consultation, and contracts | ||
| Short-term Rental/Insurance Car Rental | Companies that signed a business outsourcing contract related to short-term rentals and insurance car rentals | Providing insurance car rental services | |
| Delivery | Songin Co., Ltd., Car life Service Co., Ltd., Taewo Logistics Co., Ltd. , HK Logistics Co., Ltd., CJ Logistics Corporation, Hi Auto Members Co., Ltd., Sangwon Logistics Co., Ltd., Motor man Co., Ltd. | Rental vehicle delivery | |
| Vehicle Management | Supplies Delivery | SERVEONE | Vehicle supplies delivery, after-sales service |
| Visit Inspection | Car Life Service Co.,Ltd | Visit inspection | |
| Repair | Samsung Fire Service Claim Adjustment Co., Ltd. | Rental vehicle repair (Anycar Land) | |
| Master Co., Ltd. | Rental vehicle repair | ||
| GS Mbiz Co., Ltd. | Rental vehicle repair (Auto Oasis) | ||
| Companies that signed a business outsourcing contract related to vehicle repair | Rental vehicle repair (cooperative maintenance) | ||
| Inspection | SS-Car, Asta Networks Co., Ltd., Open Mile, Carforyou | Rental vehicle inspection agency | |
| Emergency Service | SK Speedmate Co., Ltd. | Emergency roadside assistance service for rental vehicle | |
| Visit Inspection | Car123-Jasper | Visit inspection | |
| Total | AJ Maintenance Partners | General rental vehicle repair, accident handling agency, rental vehicle inspection agency, emergency roadside assistance in case of accidents, visit inspection | |
| System | Operation / Development (Maintenance) | SK AX | Information system development and maintenance/management, infrastructure and DB operation |
| Sk shieldus | Information protection system operation | ||
| Summit Corporation | Mobile rent-a-car service development and operation | ||
| Netpathy | eDM sending system maintenance | ||
| SK Networks Co., Ltd. | Consultation system (CSS) development, operation and maintenance | ||
| SK M&Service | Computerized information processing and maintenance / management | ||
| TA9 | Information system development and maintenance/management | ||
| In / outbound system | Daou Technology | Providing SMS/MMS sending service | |
| Biztalk | Providing AlimTalk/SMS/MMS sending service | ||
| HumusOn | Providing push message-sending service | ||
| SPECTRA | Providing chat consultation solution | ||
| Quve17, Earlysloth | Supplying a happy call system | ||
| Sejong Telecom, Narae Internet, LG Uplus | Providing 080 opt-out service | ||
| TA9 | Collecting and providing personal location information (mobile phone location) | ||
| Autobegins | Providing vehicle information inquiry service | ||
| Graybox | providing online customized advertising and service provision solutions | ||
| Identity Verification | SCI Information Service | Identity verification via mobile phone | |
| Credit Inquiry | NICE Information Service | Performing credit rating inquiry for confirmation of long-term car rental | |
| Payment | FIRST DATA | Providing a credit card payment system | |
| Hyosung FMS | Direct debit service | ||
| NICE Payments, Korea Payment Networks | Providing payment system | ||
| KG Inicis | Providing a payment system (payment of usage fees and charging fees) | ||
| Cloud | Microsoft, Amazon | Providing Cloud service (Azure-Seoul Region, AWS-Seoul Region) | |
| Other | Debt Collection | F&U Credit Information, MG Credit Information Service, KS Credit Information | Delegation of debt collection |
| Duksung DM | Sending notification and billing of overdue payments, termination notices, and other contract-related postal mails (including proof of contents) | ||
| Events | NHN AD | Collection and use of personal information of consumers participating in various events | |
| eMFORCE No Move No Works | SK Rent-a-Car official SNS channel managements & event management SK Rent-a-Car coupon delivery and benefit information | ||
| 11st Street | Sending gifticons | ||
| Survey | NAVER | Use of survey platform | |
| Delivery | Korea Post | Courier delivery | |
| EV Link | Softberry Co., Ltd. | EV Link service outsourcing | |
② In order to facilitate personal information processing, the Company re-entrusts personal information processing as follows:
| Consignee | Re-consignee | Purpose of Reconsignment |
|---|---|---|
| SK AX | Soulbit I-Tech | Operation of car rental sales support system and B2C system |
| C&Thoth | DBA and middleware tasks, operation of network / server / storage / backup systems toktok server operation and management (messenger), operation of car rental sales support system | |
| SK Broadband | Transmission of information to provide SMS service within NateOnBiz | |
| Able Com | H/W and S/W operation for car rental consultants | |
| ec-Bank | Tax invoice (RTax) system operation | |
| EPIENCE | RTok payment and My Service operation | |
| ToBeWay | Computerized Biztalk information processing, maintenance / management | |
| NETS Co., Ltd. | Group portal’s integrated account management | |
| SK Shieldus | Issuance / renewal / revocation of toktok access authentication certificate, Group portal’s integrated account management | |
| SK AX(Beijing) Co., Ltd. Shenyang Branch | Infra DBA and middleware tasks, operation of server / storage / backup systems, toktok server operation and management (integrated account management / messenger / email / portal), issuance / renewal / revocation of toktok access authentication certificate | |
| Okta Inc. | Providing user authentication service for toktok access | |
| UWS | Cloud system operation (Azure) | |
| Nix Vision | OnSpace system operation | |
| Dituel | Visit management system operation | |
| Hasung CNI | Purchase management system (Buyone) operation | |
| P&P Consulting | RDAP system operation | |
| etecus | M365 operation | |
| eMFORCE | Coop Marketing | Gift delivery agency |
| SK M&Service | Huevertech | Network maintenance |
| SK telecom | SK M&Service | Counseling center operation |
| TA9 | GLIM | EV Link system strategic planning |
③ When entering into a consignment contract, the Company complies with Article 26 of the Personal Information Protection Act, specifying in documents responsibilities, including prevention of personal information processing for other purposes than performing the entrusted work, technical and managerial safeguards of personal information, restriction on reconsignment, management and supervision of consignees, and compensation for damages. The Company supervises whether consignees process personal information safely.
④ In case any change is made to the content of the consigned tasks and consignees, the Company will promptly disclose it through this Privacy Policy.
05. Destruction Procedures and Methods of Personal Information
① When the retention period expires, or the purpose of processing is achieved for personal information, which thereby becomes no longer necessary, the Company shall destroy such personal information without delay. The procedure, deadline, and method of destruction are as follows:
| Category | Description | |
|---|---|---|
| Destruction procedure | Personal information for which a reason for destruction has occurred, such as an expired retention period or achieved purpose of processing, is selected and destroyed. | |
| Destruction Deadline | End of the retention period | Within 5 days from the end date |
| Achieved the purpose of processing Service abolition Termination of business | Within 5 days from the date when processing personal information is deemed unnecessary | |
| Destruction Method | Information in the form of electronic files is destroyed using technical methods that do not allow the reproduction of records. Personal information printed on paper is destroyed by shredding or incineration. | |
② If the personal information collected upon the data subject’s consent must be preserved under different laws despite the retention period having expired, and the purpose of processing has been achieved, the Company transfers the personal information to a separate database (DB) or preserves it in a different storage location.
③ When the Company achieves the purpose of collection, use, or provision of the collected personal location information, it shall destroy the personal location information without delay unless the information must be recorded and preserved to verify the collection, use, and provision of location information in accordance with Article 16 Paragraph 2 of the Act On The Protection And Use Of Location Information.
However, the Company shall immediately destroy the information after using it within the scope of the purpose agreed to by the customer in accordance with Article 23 of the Act On The Protection And Use Of Location Information.
In this case, when destroying the personal location information or data verifying the collection of location information, the Company uses technically irreversible methods to delete, shred, or incinerate the record.
06. Rights and Obligations of Data Subject and Legal Representatives, and How to Exercise Them
Users, as the data subject, may recognize the following obligations and exercise their rights at any time according to the procedures with respect to the Company.
| Category | Description |
|---|---|
| Obligations | The data subject has the obligation to protect their personal information. The Company shall not be liable for problems arising from the leakage of personal information without any reason attributable to the Company due to the following reasons: data subject’s negligence, such as transfer, rental, or loss of ID, password, access media, etc., and vacating while logged in; or, problems on the Internet that the Company cannot control despite its considerable care, such as hacking using methods or technologies that cannot be blocked by security measures under relevant laws. 1) The data subject must keep their personal information up-to-date, and any problems arising from inaccurate information input are the data subject's responsibility. 2) Registering membership using another person’s personal information or processing payment using another person’s ID may result in disqualification as a data subject and punishment in accordance with relevant laws. 3) The data subject is responsible for maintaining the security of ID, password, etc., and may not transfer or lend them to third parties. The data subject has the obligation to cooperate with periodic password changes for security according to the Company’s Privacy Policy. 4) The data subject must log out of the account and close the web browser program after using the Company’s services. 5) The data subject must comply with the Act On Promotion Of Information And Communications Network Utilization And Information Protection, the Personal Information Protection Act, the Resident Registration Act, and other laws regarding personal information. |
| Rights | The data subject may exercise their rights related to personal information with respect to the Company at any time, and the rights are as follows: 1) Request for access to personal information 2) Request for correction in case of errors 3) Request for deletion 4) Request for suspension of processing The Company shall verify whether the person requesting access, correction, deletion, or suspension of processing by the rights of the data subject is the data subject or a legitimate representative. The data subject’s rights may be restricted in case of requests for access to personal information and suspension of processing in accordance with Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act. Requests for correction and deletion of personal information cannot be made if the personal information is specifically included in items to be collected under other laws. |
| How to Exercise the Rights (Procedure) | The data subject’s rights with respect to the Company can be exercised in writing, email, or facsimile (FAX) under Article 41, Paragraph 1 of the Enforcement Decree of the Personal Information Protection Act. Rights can also be exercised through an agent, such as the data subject’s legal representative or a person authorized to do so. In this case, a power of attorney according to the format specified in Annex 11 of the Guidelines on Personal Information Processing Methods. |
※ If the data subject requests correction or deletion of personal information, the Company will not use or provide such personal information until the correction or deletion is completed.
07. Measures to Ensure the Security of Personal Information
The Company takes technical/managerial and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act.
| Category | Measures | Description |
|---|---|---|
| Managerial Measures | Minimization of personal information processing personnel | The Company minimizes the authority of personal information processors to protect personal information. |
| Regular training for personal information processing personnel | The Company provides regular annual training to raise awareness of personal information protection. | |
| Regular internal inspections | The Company conducts regular in-house inspections to ensure the stability of personal information processing. | |
| Establishment and implementation of internal management plans | The Company has established and implemented internal management plans to process and manage personal information safely. | |
| Technical Measures | Encryption of personal information | Users’ personal information and passwords are encrypted for storage/management. Separate security features are used during transmission for safe management. |
| Technical measures against hacking, etc. | Security programs are installed for regular update/inspection to prevent leakage and damage of personal information due to hacking, computer viruses, etc. Systems are installed in areas with controlled access from outside to monitor and block access technically and physically. | |
| Access restrictions on personal information | Necessary measures are taken to control access to personal information by granting, changing, or revoking access rights to the database system that processes personal information. An intrusion prevention system is used to control unauthorized access from outside. | |
| Access recordkeeping and prevention of forgery and alteration | Access records to the personal information processing/handling system are stored and managed for at least two years, and security features are used to prevent forgery, alteration, theft, and loss of access records. | |
| Physical Measures | Use of locking devices for document security | Documents and auxiliary storage media containing personal information are stored in a safe place with locking devices. |
| Access control for unauthorized individuals | A separate physical storage location is designated for storing personal information, and access control procedures are established and operated accordingly. | |
| Safety measures for disasters and catastrophes | Crisis response procedures, such as risk response manuals, are established and inspected in preparation for disasters and catastrophes, including natural disasters. |
08. Installation, Operation, and Rejection of Tools Collecting Personal Information Automatically
Under Article 29 of the Personal Information Protection Act, the Company takes technical/managerial and physical measures to ensure safety as follows:
- ① The Company uses cookies, storing and retrieving usage records, to provide individualized custom services to users.
- ② Cookies are small blocks of data that a server (HTTP) used to run the website sends to the user’s computer browser and may be stored on the user’s PC hard drive.
- ③ Purpose of using cookies
Cookies are used to understand users' visit and use patterns, whether secured access is made, etc., for each service and website they visit to provide optimized information to users. - ④ Installation, operation, and rejection of cookies
Users can reject storing cookies by setting the options in the web browser menu, as shown below.
| Category | Setup Instructions |
|---|---|
| Internet Explorer |
|
| Edge |
|
| Chrome |
|
※ However, rejecting cookie storage may prevent the use of some services that require login.
9. Collection, Use, Provision, and Rejection of Behavioral Information
① In the process of using the service, the company collects and uses behavioral information as follows to provide optimized customized services, benefits, and online customized advertisements.
| Category | Details |
|---|---|
| Behavioral information items collected | User’s service visit/use history, search and product inquiry history, purchase history |
| How to collect behavioral information | Automatically collected and transmitted when users visit our website or run our app |
| Purpose of collecting behavioral information | Product/service development and user analysis including statistics and customer analysis, and provision of customized advertisements based on user behavior information |
| Period of retention and use of behavioral information | It is retained/used for up to 1 year from the date of collection, and is deleted without delay at the end of the retention period. |
| Contact information for user damage relief methods, etc. | Department in charge: Information Protection Center Phone number: 02-6474-5796 |
② Users can block the collection of behavioral information at any time through the following methods.
[Web browser]
- Above '9. You can block the collection of behavioral information by following the methods provided in Article 4 of ‘Installation/Operation and Rejection of Devices that Automatically Collect Personal Information’.
[Smartphone]
- Android: Settings → Google → Advertising → Delete Advertising ID
- iOS: Settings → Privacy & Security → Tracking → Allow apps to request tracking OFF
10. Chief Personal Information Protection Officer and Personal Information Access Request
① The Company is responsible for the overall management of information processing and appoints a Chief Personal Information Officer, as described below, to address data subjects’ complaints and provide remedies related to personal information processing.
② The Information Agency may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the departments below. The company will strive to promptly process the information subject's request to view personal information.
| Chief Personal Information Protection Officer | |
|---|---|
| Department | Data Privacy Center |
| Name / Title | Kim-Jung Ho, Technical Advisor |
| Customer Personal Information Protection Manager | |
|---|---|
| Department | SK Rent-a-Car Information Protection Center |
| Name / Title | Jong-won Jeong, Manager |
| Phone Number | +82-2-6474-5796 |
※ Data subjects may contact the Chief Personal Information Protection Officer for any matters related to personal information protection inquiries, complaint handling, damage relief, etc., arising from the use of the Company’s services (or businesses). The Company will respond to and handle inquiries from data subjects promptly.
11. Remedies for Violation of Rights and Interests of Data Subjects
① The Company seeks opinions from members regarding their personal information and has established procedures and methods to address complaints. If consultation is needed for other personal information, individuals may contact the Privacy Call Center (operated by the Korea Internet Security Agency), the Personal Information Dispute Mediation Committee, the Cybercrime Investigation Division of the Supreme Prosecutors’ Office, and the Cyber Bureau of the National Police Agency.
| Privacy Call Center (operated by the Korea Internet & Security Agency) | |
|---|---|
| Responsibilities | Report personal information infringement and apply for a consultation. |
| Website | privacy.kisa.or.kr |
| Phone number | (no area code) 118 |
| Address | Privacy Call Center,(Postal Code 58324) 3F, 9, Jinheung-gil, Naju-si, Jeollanam-do, |
| Personal Information Dispute Mediation Committee | |
|---|---|
| Responsibilities | Apply for personal information dispute mediation and perform collective dispute mediation (resolution through civil proceedings) |
| Website | www.kopico.go.kr |
| Phone number | (no area code) 1833-6972 |
| Address | (Postal Code 03171) 4F, Government Complex Seoul, 209, Sejong-daero, Jongno-gu, Seoul |
| Cybercrime Investigation Division of the Supreme Prosecutors’ Office | |
|---|---|
| Website | www.spo.go.kr |
| Phone number | (no area code) 1301 |
| Cyber Bureau of the National Police Agency | |
|---|---|
| Website | ecrm.police.go.kr |
| Phone number | (no area code) 182 |
② The Company guarantees the data subjects’ right to self-determination of personal information and strives to provide consultation and damage relief related to personal information infringement. If reporting or consultation is necessary, individuals can contact the responsible department below.
| Customer Consultation and Reporting Regarding Personal Information Protection | |
|---|---|
| Department | SK Rent-a-Car Information Protection Center |
| Person in Charge | Jong-won Jeong |
| Contact Number | +82-2-6474-5796 |
12. Installation and Operation of Visual Data Processing Devices
① The Company installs and operates visual data processing devices as follows:
1. Grounds and purposes for installation of visual data processing devices
- Company facility safety and fire prevention
- Crime prevention for customer safety
- Prevention of vehicle theft and damage
2. Number of installations and locations: Number of installations by branch and branch locations
| Location of Installation | Number of Installation | Scope of Filming | Visual Data Officer |
|---|---|---|---|
| SK Rent-a-Car entrance on each floor | 20 units | Inside | General Affairs PL |
| Jeju EV Park parking tower, maintenance workshop, office entrance, etc. | 77 units | Inside / Outside | Jeju Contents Business Team Head |
| Jeju Billy Car parking lot, car wash building, desk entrance, etc. | 33 units | Inside / Outside | Jeju Vehicle Management QC Team Head |
| Parking lots and office entrances at direct branches other than the headquarters | 10 units | Inside / Outside | Regionals Project Team Heads |
| Regional logistics center entrances and parking lots | 30 units | Inside / Outside | Regional Logistics Center Managers |
| Branch / Centers | Differs by branch / center | Each business operation’s title holders (Branch Heads, Center Managers, etc.) | |
3. Visual data officer, responsible department, and person with access to visual data: Each branch’s person in charge
4. Visual data filming hours, retention period, storage location, and processing method
- Filming hours: 24 hours
- Retention period: 30 days from the time of filming
- Storage location and processing method: stored and processed in each branch’s visual data processing device management system
5. Method and place for checking visual data: Request each branch’s person in charge
6. Measures in response to data subjects’ request to view visual data: An application must be made with a request for inspection/confirmation of the existence of the personal visual data, and access is allowed only when the data subject himself/herself is filmed, or when it is explicitly required for the benefit of the data subject’s life, body, and property.
7. Technical, managerial, and physical measures to protect visual data: Establishment of an internal management plan, access control and restriction of access rights, application of safe storage and transmission technology of visual data, storage of processing records and measures for preventing forgery or alteration, and provision of storage facilities and installation of locking devices.
13. Amendments to the Privacy Policy
① Any addition, deletion, and correction of the Privacy Policy made pursuant to changes in applicable laws, policies, or security technologies will be notified on the website at least seven (7) days prior to the enforcement date of such the amended Privacy Policy, including reasons and details of the changes.
② This Privacy Policy is effective from 29, May, 2025.