Privacy Policy
This document is a draft. It must be finalised after legal review, and the bracketed items must be replaced with actual values.
Registration details and the work-hour computer records collected by the agent.
Account management, collection of work records and delivery of statistics, grievance handling.
None, except where a specific provision of law applies.
[processor · task]. State "none" where nothing is outsourced.
Access, correction, deletion, suspension, transfer, and explanation or refusal of automated decisions.
Data protection officer [email] · access request desk [department].
[Company] (the "Company") establishes and discloses the following privacy policy pursuant to Article 30 of the Personal Information Protection Act ("PIPA"), in order to protect the personal data of data subjects and to handle related grievances promptly.
Effective date [effective date] · Last revised [last revised date]
Article 1 (Purposes of Processing)
The Company processes personal data solely for the purposes below. Where a purpose changes, the Company obtains separate consent and takes the other measures required under Article 18 of PIPA.
- Registration and account management — confirming intent to register, identifying the person, preventing misuse, delivering notices
- Collection of work records — collecting and storing usage on the recorded computers
- Generating and delivering statistics — computer usage, applications, file usage, activity logs, network traffic, performance scores and screen captures
- Handling grievances — receiving enquiries, verifying facts, notifying outcomes
Article 2 (Categories of Personal Data Processed)
Required at registration
- Account holder — email address, password
- Recorded person — email address, user name, computer name, company code
Optional
- Position, phone number, main duties — the Service may be used without these.
Collected by the agent — gathered automatically on the recorded computer during work hours.
- Computer usage — powered-on time, active time
- Application usage — names of programs run and how long
- File usage — names of files used and how often
- Activity log — what ran, and when
- Network usage — traffic sent and received
- Screen capture images
Screen capture is selective, never full-screen. Programs registered as excluded, and any window whose title contains an excluded keyword, are not captured.
Generated automatically in the course of use
IP address, cookies, service usage records and access logs.
Not collected
The Company does not collect sensitive data or unique identifiers (resident registration, passport, driver's licence or alien registration numbers).
Article 3 (Processing and Retention Period)
The Company processes and retains personal data within the period required by law or consented to by the data subject, and destroys it without delay once that period ends.
| Category | Retention | Basis |
|---|---|---|
| Account information | 30 days after withdrawal | Consent, to prevent abusive re-registration and handle grievances |
| Work records and statistics | [retention period] | Service agreement and consent |
| Screen capture images | [retention period] | Service agreement and consent |
| Access logs | 3 months | Protection of Communications Secrets Act, Article 15-2 |
When the service agreement ends, work records and screen captures are destroyed immediately at the Member's request.
Article 4 (Provision to Third Parties)
The Company processes personal data only within the scope stated in Article 1 and does not provide it to third parties, except where separate consent has been given or a specific provision of law applies under Articles 17 and 18 of PIPA.
Article 5 (Outsourcing of Processing)
The Company may outsource processing tasks and discloses the processor and the scope of the work in this policy.
| Processor | Task | Period | Country |
|---|---|---|---|
| [processor] | [task] | [period] | [country] |
When entering such a contract, the Company specifies in writing the prohibition on processing beyond the purpose, technical and administrative safeguards, restrictions on sub-processing, supervision of the processor and liability for damages, as required by Article 26 of PIPA.
Article 6 (Destruction of Personal Data)
Personal data that is no longer needed is destroyed without delay, with the approval of the data protection officer.
- Electronic files — permanently deleted by a method that prevents recovery.
- Paper documents — shredded or incinerated.
Data that must be preserved by law is moved to a separate database or stored in a different location and is not used for any other purpose.
Article 7 (Rights of Data Subjects and Legal Representatives)
A data subject may at any time exercise the following rights.
- Request access to personal data
- Request correction of errors
- Request deletion
- Request suspension of processing
- Request transfer to another controller (Article 8)
- Request an explanation of, refuse, or seek human review of an automated decision (Article 9)
Requests may be made in writing, by email or by fax under Article 41(1) of the Enforcement Decree, and the Company acts on them without delay. A request made through an agent requires a power of attorney in the prescribed form.
Rights of recorded persons — A recorded person may read their own work records and statistics on the same screens as the Member, and may delete their own screen captures where the Member's settings allow it.
How to exercise — email [privacy email] · phone [phone] · post [address]
Article 8 (Right to Data Portability)
Under Article 35-2 of PIPA, a data subject may require their personal data to be transmitted to another controller or managing institution.
- Transferable data — registration details, work records, computed statistics
- Format — JSON or CSV
- How to request — by email to [privacy email]; processed within 10 business days of the request
- Checking status and history — the outcome and the transmission history are returned to the requester's email and can be reconfirmed on request
Article 9 (Automated Decisions)
The Company computes a performance score automatically. Its criteria, procedure and method are disclosed below under Article 37-2 of PIPA.
Criteria
- The work hours set under Work style
- Active time and powered-on time within those hours
- The category assigned to each program run, which determines whether it counts as work-related
Procedure — (1) the agent collects usage; (2) active time is aggregated against the work hours; (3) work-related activity is separated by program category; (4) the ratio is computed as a score.
Method — a rule-based calculation using a fixed formula. No machine-learning model is used, and personal data is not used to train artificial intelligence.
Human involvement — the score is reference material and does not by itself determine any personnel action. Where a Member makes a decision affecting a data subject's rights or obligations on the basis of this score alone, the obligations under Article 37-2 in respect of that decision rest with the Member.
Rights of the data subject
- Explanation — an explanation of the reasons and criteria may be requested; the Company replies within 15 days.
- Refusal — automatic computation may be refused, in which case its effect is suspended.
- Human review — re-processing with human review may be requested; the result is notified within 30 days of completion, extendable to 60 days with notice of the reason.
Exercise these by email [privacy email] or phone [phone].
Article 10 (Children Under 14)
The Service is not offered to children under 14 and the Company does not collect their personal data. Any such data found to have been collected is destroyed without delay. A legal representative may request access to, correction of, deletion of, or suspension of processing of a child's personal data.
Article 11 (Automatic Collection Devices and How to Refuse Them)
The Company uses cookies to keep the sign-in state and the language selection.
Behavioural information — the Company does not run personalised advertising, does not collect advertising identifiers (ADID/IDFA), and does not provide behavioural information to third parties.
How to refuse
- Delete cookies in the browser.
- Chrome — Settings > Privacy and security > Cookies and other site data
- Edge — Settings > Cookies and site permissions > Manage cookies and site data
- Safari — Preferences > Privacy > Manage website data
- Firefox — Settings > Privacy & Security > Cookies and Site Data
- Turn on the browser's third-party cookie blocking.
- Block all cookies. Sign-in persistence and the language setting will then be limited.
- Use a private or incognito window, where history and cookies are not stored.
Article 12 (Security Measures)
The Company takes the measures required by the Standards for Securing Personal Data.
- Administrative — an internal management plan, minimisation and training of staff who handle personal data, regular self-audits
- Technical — access control for the processing system, retention and tamper-protection of access logs, encryption, intrusion prevention and detection, anti-virus
- Physical — controlled access to the server room and the archive
Article 13 (Data Protection Officer and Access Request Desk)
The Company designates a data protection officer with overall responsibility for personal data processing and for handling complaints and remedies.
Data protection officer
- Name [name] · Title [title]
- Phone [phone] · Email [email]
Access request desk
- Department [department] · Contact [contact]
- Phone [phone] · Email [email]
Grievance handling
- Department [department] · Email [email] · Hours [hours]
Article 14 (Notification of Breach)
On becoming aware that personal data has been, or may have been, lost, stolen, leaked, forged, altered or damaged, the Company notifies data subjects without delay and reports to the competent authorities, stating:
- the categories of data affected;
- when it occurred and how;
- what the data subject can do to limit the harm;
- the Company's response and the remedy procedure;
- the department and contact for reporting harm; and
- how to claim damages and apply for dispute mediation.
Remedies for Infringement
- Personal Information Dispute Mediation Committee — 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Centre — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office — 1301 (www.spo.go.kr)
- National Police Agency — 182 (ecrm.police.go.kr)
Changes to This Policy
This policy applies from its effective date. Where content is added, removed or corrected, notice is given at least 7 days before the change takes effect, or 30 days where the change is unfavourable to data subjects.
Revision history
- [effective date] — first issued