PANENA
PANENA Privacy Policy
Panena Co., Ltd. (hereinafter referred to as the “Company”) complies with applicable laws and regulations relating to personal information protection, including the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., the Personal Information Protection Act, and the Protection of Communications Secrets Act, in providing the gut health management platform “PANENA” (hereinafter referred to as the “Service”), and makes its best efforts to protect users’ rights and interests. In order to promptly and smoothly handle related grievances, the Company hereby establishes and discloses this Privacy Policy as follows.
Article 1 Personal Information Processed
①The Company processes the following categories of personal information without obtaining separate consent where permitted by applicable law.
| Legal Basis | Purpose of Collection and Use | Items | Retention Period |
|---|---|---|---|
| Personal Information Protection Act Article 15(1)(2) (Special provisions under law) Electronic Commerce Consumer Protection Act Article 6 (Retention of transaction records, etc.) | Records related to contracts or withdrawal of subscription, etc. | Member identification information, contract/withdrawal records | five (5) years from date of collection |
| Records related to consumer complaints or dispute resolution | Member identification information, dispute resolution records | three (3) years from date of collection | |
| Personal Information Protection Act Article 15(1)(2) (Special provisions under law) Protection of Communications Secrets Act Article 15-2 (Cooperation obligation of telecommunications service providers) | Communication fact verification data | Access logs, IP address, cookies | Three (3) months from date of collection |
| Personal Information Protection Act Article 15(1)(4) (Performance of contract) | Identity verification and age verification | Identity verification information (name, date of birth, gender, mobile carrier name, mobile phone number, CI) | Until membership withdrawal |
| maintenance and management of membership status, service provision, and prevention of fraudulent use of services | Name, email address, mobile phone number, year of birth, gender | six (6) months after membership withdrawal | |
| Simplified membership registration via SNS accounts | - Google: CI (Connected Information), email address, name, date of birth, gender, mobile phone number - Naver: CI (Connected Information), email address, name, date of birth, gender, mobile phone number - Kakao: CI (Connected Information), Kakao account, name, date of birth, gender, mobile phone number | 6 months after membership withdrawal | |
| Payment and refund processing | Name, mobile phone number, payment number, refund account (bank name, account number) | three (3) months after payment and refund | |
| Customer inquiry handling and dispute resolution | Name, mobile phone number, email | three(3) months after inquiry handling and dispute resolution |
②The Company processes the following personal information with the consent of the user.
| Legal Basis | Purpose of Collection and Use | Items | Retention Period |
|---|---|---|---|
| Personal Information Protection Act Article 23(1)(1) (Sensitive information) | Service provision | Recent bowel movement information, recent intestinal and related physical symptoms, recent sleep duration, probiotic intake information, recent dietary habits, recent stress level | six(6) months after membership withdrawal |
| Personal Information Protection Act Article 15(1)(1) (Consent of the data subject) | Provision of service information, events, and promotional/advertising information | Name, mobile phone number, email address | Until membership withdrawal or withdrawal of consent Provided, however, that where retention is required under applicable laws and regulations, the information shall be retained for the relevant period. |
Article 2 Personal Information of Children Under 14
The Company does not process personal information of children under the age of 14.
Article 3 Entrustment of Personal Information Processing
①In order to provide services to users, the Company entrusts personal information processing tasks as follows. Where there is any re-entrustment of personal information processing tasks, the details of the re-entrusted party and the re-entrusted tasks shall be disclosed through the trustee’s privacy policy.
| Entrusted Party | Entrusted Work |
|---|---|
| Amazon Web Services Korea LLC(Seoul Region) | Server operation and data storage |
| Supabase, Inc. | Database operation and backend service provision |
| Toss Payments Co., Ltd. | Payment and refund processing |
| Alrineun Saramdeul Co., Ltd. | SMS and KakaoTalk messaging |
②When concluding an entrustment agreement, the Company stipulates in writing, pursuant to Article 26 of the Personal Information Protection Act, matters concerning prohibition of processing personal information for purposes other than the entrusted work, technical and managerial protective measures, restriction of re-entrustment, supervision of the trustee, and liability for damages. The Company also supervises whether the trustee safely processes personal information.
③If the contents of the entrusted work or the entrusted parties are changed, the Company shall disclose such changes without undue delay through this Privacy Policy.
Article 4 Destruction Procedures and Methods of Personal Information
①The Company shall destroy personal information without undue delay when such personal information becomes unnecessary due to the expiration of the retention period or the achievement of the purpose of processing.
②Where personal information must be retained under other applicable laws despite the expiration of the retention period agreed upon by the user or the achievement of the purpose of processing, such personal information shall be transferred to a separate database (DB) or stored in a different storage location for retention.
③The procedures and methods for destruction of personal information are as follows:
- 1.
Destruction Procedures
The Company selects personal information for which grounds for destruction have arisen and destroys such personal information upon approval by the Company’s Personal Information Protection Officer.
- 2.
Destruction Methods
Personal information recorded and stored in electronic file formats shall be destroyed in a manner that prevents reproduction of the records. Personal information recorded and stored on paper documents shall be destroyed by shredding or incineration.
Article 5 Rights of Users and Legal Representatives and Methods of Exercising Such Rights
①The Company protects users’ rights as follows.
- 1.
Users may, at any time, access or correct their personal information. If a user wishes to access or correct his or her personal information, the user may directly access or correct such information through [My Page – My Information], send an email to the Company ([admin@panenalabs.com]), or make a request to the department responsible for personal information protection, and the Company shall take action without delay.
- 2.
Users may, at any time, withdraw their consent to the processing of personal information, or request deletion of or suspension of processing of the relevant personal information. If a user wishes to withdraw consent or request deletion or suspension of processing, the user may send an email to the Company ([admin@panenalabs.com]) or make a request to the department responsible for personal information protection, and the Company shall take action without delay after completing identity verification procedures.
- 3.
Where a user requests access to, correction of, or deletion of personal information, the Company shall not use or provide the relevant personal information until such correction or deletion has been completed.
②The rights under Paragraph (1) may also be exercised through a representative, such as the user’s legal representative or an authorized agent. In such case, a power of attorney in the form prescribed in Attached Form No. 11 of the Public Notice on Methods of Processing Personal Information (Notice No. 2025-5) must be submitted.
③Where a request is made for access to personal information or suspension of processing thereof, the user’s rights may be restricted if any of the grounds set forth in Article 35(4) or Article 37(2) of the Personal Information Protection Act apply.
④A request for correction or deletion of personal information may not be made where such personal information is specified as information subject to collection under other applicable laws and regulations.
⑤When a user requests access, correction, deletion, or suspension of processing pursuant to this Article, the Company may verify whether the requesting person is the data subject or a duly authorized representative.
Article 6 Measures to Ensure the Security of Personal Information
The Company implements the following measures to ensure the security of personal information:
- 1.
Administrative Measures: Establishment and implementation of internal management plans, operation of a dedicated organization, and regular employee training.
- 2.
Technical Measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of personal information, and installation and updating of security programs.
- 3.
Physical Measures: Access control to computer rooms and document storage rooms; storage of documents and auxiliary storage media in secure locations equipped with locking devices; safety measures against disasters and emergencies; and control over the inbound and outbound movement of storage media
Article 7 Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
①The Company uses “cookies” to store and retrieve user information from time to time in order to provide customized services to users.
②Cookies are very small text files sent by the server used to operate a website to a user’s browser and stored on the user’s computer. When the user subsequently visits the website, the website server reads the contents of the cookies stored on the user’s hard disk in order to maintain the user’s preferences and provide customized services.
- 1.
Purpose of Using Cookies: Cookies are used to provide optimized information to users by identifying users’ visits to and usage patterns of each service and website visited, popular search terms, security access status, and other related information.
- 2.
Installation/Operation and Rejection of Cookies: Users may allow all cookies, require confirmation whenever a cookie is stored, or refuse the storage of all cookies by configuring the settings of their web browser. However, if the installation of cookies is refused, use of the website may become inconvenient, and certain services requiring login may be difficult to use.
[Examples of Configuration Methods]
- 3.
Internet Explorer: Tools Menu > Internet Options > Privacy
- 4.
Chrome: Tools Menu > Show Advanced Settings > Content Settings under Privacy > Cookies
- 5.
Configuration methods may vary depending on the version and type of browser. For more detailed instructions, please refer to the help section of the relevant browser.
Article 8 Personal Information Protection Officer
The Company makes its best efforts to prevent users’ personal information from being damaged or infringed and has appointed a Personal Information Protection Officer who is responsible for overseeing matters related to the processing of personal information, as set forth below. However, even where the Company has implemented all technical, physical, and administrative measures required by law for the protection of personal information, the Company shall not be liable for any damages not attributable to the Company, including damages arising from the user’s own negligence or incidents occurring in areas not under the Company’s control. ▶ Personal Information Protection Officer Name : Kim Jong-hyun Position : CEO Contact Information : 1811-6228
Article 9 Methods of Remedy for Infringement of Rights and Interests
Users may apply to the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center of the Korea Internet & Security Agency, or other relevant organizations for dispute resolution, consultation, or other remedies in relation to personal information infringement. For reports, consultations, or inquiries regarding other personal information infringements, please contact the following organizations.
- 1.
Personal Information Dispute Mediation Committee: 1833-6972 (without area code) (http://www.kopico.go.kr)
- 2.
Personal Information Infringement Report Center: 118 (without area code) (privacy.kisa.or.kr)
- 3.
National Police Agency: 182 (without area code) (ecrm.police.go.kr)
Article 10 Scope of Application of this Privacy Policy
①Where necessary for the use of the Service, the Company may provide users with links to websites operated by other companies. In such cases, the Company has no control over the protection of personal information on external websites and therefore cannot and does not make any representations or warranties regarding such services or materials provided through such external websites.
②Where personal information is collected on another company’s website accessed through an advertisement banner of the Company’s affiliate or a third party displayed on the Company’s service pages, this Privacy Policy shall not apply. Users are advised to exercise caution when providing personal information.
- 1.
This Privacy Policy shall apply from [Day] [Month] [Year]
- 2.
Previous versions of the Privacy Policy may be viewed below.
- Applicable from [Day] [Month] [Year] to [Day] [Month] [Year](Click)
This Privacy Policy shall become effective on the Effective Date. If the Company amends this Privacy Policy, the timing of the amendment and effectiveness thereof, as well as the amended contents, shall be notified through a pop-up notice on the website (or through an individual notice).
Effective Date: [Day] [Month] [Year]
Amendments to the Privacy Policy