COMPANY

CONTACT

Privacy Policy

Nano Fine Tech Co., Ltd. (hereinafter referred to as the "Company") values the personal information of its customers and complies with applicable laws and regulations concerning the promotion of information and communications network use and information protection.

Through this Privacy Policy, the Company explains how the personal information provided by customers is collected, used and protected, and what measures are taken to safeguard such information.

If the Company amends this Privacy Policy, the changes will be announced through the website notice board or by individual notification.

Privacy Policy Announcement Date: August 15, 2024

Effective Date: August 15, 2024

Consent to the Collection of Personal Information

The Company provides users with a procedure through which they may click an "Agree" or "Disagree" button regarding the Company's Privacy Policy or Terms of Use. By clicking the "Agree" button, the user shall be deemed to have consented to the collection of personal information.

Protection of Children's Personal Information

ο If the Company collects personal information from children under the age of 14, the Company shall obtain the consent of their legal representative.

ο A legal representative of a child under the age of 14 may request access to, correction of, or withdrawal of consent regarding the child's personal information. Upon receiving such a request, the Company shall take the necessary measures without delay.

Personal Information Collected

The Company collects the following personal information for membership registration, customer consultation, service applications and other related purposes.

ο Information collected: name, date of birth, gender, login ID, password, home telephone number, home address, mobile phone number, e-mail address, occupation, marital status, resident registration number, service usage records, access logs, cookies, IP address information and payment records.

ο Methods of collection: website activities such as membership registration and bulletin board use, and delivery requests.

Purpose of Collection and Use of Personal Information

The Company uses collected personal information for the following purposes.

ο Performance of contracts for service provision and settlement of fees

Provision of content, purchase and payment processing, delivery of goods, and shipment of invoices or billing-related materials.

ο Membership Management

Identity verification for membership services, personal identification, prevention of unauthorized or fraudulent use by improper members, confirmation of intent to register, age verification, confirmation of legal representative consent when collecting personal information from children under the age of 14, handling complaints and other customer inquiries, and delivery of notices.

ο Marketing and Advertising

Delivery of advertising information such as event information, analysis of access frequency and statistics regarding Members' use of the Services.

However, the Company does not collect sensitive personal information that may infringe upon fundamental human rights, such as race or ethnicity, ideology or beliefs, place of origin, political orientation, criminal records, health information or sexual life.

Retention and Use Period of Personal Information

ο Personal information will be destroyed when the purpose for which it was collected or provided has been achieved, as follows:

- Membership information: when the Member withdraws from membership or is expelled.

- Payment information: when payment has been completed or when the statute of limitations for the relevant claim expires.

- Delivery information: when the goods or services have been delivered or provided.

However, information may be retained where such retention is required under applicable laws, including the Commercial Act.

ο If continued retention is necessary even after the above retention period, the Company will obtain the user's consent.

Procedure and Method for Destruction of Personal Information

In principle, the Company destroys personal information without delay after the purpose of collection and use has been achieved. The destruction procedure and method are as follows.

ο Destruction Procedure

Information entered by Members for membership registration or other purposes is transferred to a separate database after the purpose has been achieved (or stored in a separate document storage facility in the case of paper records), and is retained for a certain period in accordance with internal policies and applicable laws before being destroyed.

Personal information transferred to a separate database shall not be used for any purpose other than retention, unless otherwise required by law.

ο Method of Destruction

- Personal information stored in electronic file format is deleted using technical methods that prevent the information from being reproduced or restored.

Provision of Personal Information to Third Parties

In principle, the Company does not provide users' personal information to external third parties. However, exceptions may apply in the following cases:

- Where the user has given prior consent.

- Where required by law, or where an investigative authority requests the information in accordance with procedures and methods prescribed by applicable laws for investigative purposes.

Entrustment of Personal Information Processing

The Company may entrust the processing of personal information to external service providers in order to improve the quality of its Services.

ο When personal information processing is entrusted, the Company will notify the user in advance.

ο When entrusting personal information processing, the Company will clearly stipulate through an outsourcing agreement or similar document that the service provider must comply with instructions relating to personal information protection, maintain confidentiality, refrain from unauthorized disclosure to third parties, and assume responsibility in the event of an incident. The relevant agreement will be retained in written or electronic form.

- Entrusted Party: [Name of Delivery Company]

- Scope of Entrusted Services: [Description of Delivery Services], e.g. delivery of goods

- Entrusted Party: [Name of PG Company]

- Scope of Entrusted Services: [Description of PG Services], e.g. purchase and payment processing

Rights of Users and Legal Representatives and How to Exercise Them

Users may access or modify their registered personal information at any time and may also request withdrawal of membership.

To access or modify personal information, users may select "Change Personal Information" or "Edit Member Information." To withdraw from membership or revoke consent, users may select "Membership Withdrawal" and complete the identity verification procedure before directly accessing, correcting or deleting their information.

Alternatively, users may contact the Personal Information Manager in writing, by telephone or by e-mail, and the Company will take action without delay.

If a user requests correction of inaccurate personal information, the Company will not use or provide such information until the correction is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction without delay so that the necessary correction can be made.

Personal information that has been terminated or deleted at the user's request will be processed in accordance with the retention and use period specified in this Privacy Policy and will not be accessed or used for any other purpose.

Technical Measures for the Protection of Personal Information

The Company takes the following technical measures to ensure that personal information is not lost, stolen, leaked, altered or damaged.

ο Personal information is protected by passwords, and important information is protected using separate security measures, including encryption of files and transmitted data or file-locking functions.

ο The Company uses antivirus software to prevent damage caused by computer viruses. Antivirus software is regularly updated, and when a new virus suddenly appears, the latest antivirus solution is provided as soon as it becomes available in order to prevent infringement of personal information.

ο The Company uses security technologies such as SSL or SET and encryption algorithms to securely transmit personal information over networks.

ο To prevent personal information from being leaked through hacking or other external attacks, the Company uses intrusion prevention devices and installs intrusion detection systems on each server to monitor intrusion attempts 24 hours a day.

Installation and Operation of Automatic Personal Information Collection Devices and How to Refuse Them

The Company uses cookies and similar technologies that store and retrieve user information from time to time. A cookie is a small text file sent to a user's browser by the server operating the Company's website and stored on the user's computer hard drive.

The Company uses cookies for the following purposes.

▶ Purpose of Using Cookies

- To analyze the access frequency and visiting times of Members and non-Members, identify user preferences and areas of interest, track user activity, measure participation in events and the number of visits, and provide targeted marketing and personalized services.

Users have the option to accept or reject cookies. Users may configure their web browser to allow all cookies, request confirmation whenever a cookie is stored, or refuse the storage of all cookies.

▶ How to Refuse Cookie Settings

For example, users may configure the options in their web browser to allow all cookies, request confirmation whenever a cookie is stored, or refuse all cookie storage.

Example for Internet Explorer: Web Browser > Tools > Internet Options > Privacy

Please note that refusing cookies may result in difficulties in using certain Services.

Privacy-Related Complaints and Inquiries

The Company has designated the following department and Personal Information Manager to protect customers' personal information and handle privacy-related complaints.

Personal Information Manager: Do-Yeop Kwak

Telephone: 031-340-3581

E-mail: dykwak@nanofine.co.kr

Users may report any privacy-related complaints arising from the use of the Company's Services to the Personal Information Manager or the relevant department. The Company will provide prompt and sufficient responses to such reports.

For additional reports or consultations regarding personal information infringement, please contact the following organizations:

1. Personal Information Dispute Mediation Committee

2. Privacy Mark Certification Committee

3. Supreme Prosecutors' Office Internet Crime Investigation Center

4. National Police Agency Cyber Terror Response Center