Privacy Policy
Yon Korean Medicine Clinic Privacy Protection and Processing Policy
Yon Korean Medicine Clinic (hereinafter referred to as the 'Clinic') establishes and discloses this Privacy Policy in accordance with Article 30 of the 「Personal Information Protection Act」 to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
Article 1 (Purpose of Personal Information Processing)
The Clinic processes personal information for the following purposes. The personal information being processed will not be used for any purpose other than the following, and if the purpose of use is changed, necessary measures will be taken, such as obtaining separate consent.
- Membership registration and management: Identity verification via social media simple login (Google, etc.), maintenance and management of membership status
- Medical appointment and management: Guidance on appointment schedules, processing of changes and cancellations
- Provision of medical services: Advance information verification for treatment and consultation, provision of customized medical services
- Operation of AI chatbot service: Understanding consultation context based on chatbot conversation history and linking with appointments
Article 2 (Items of Personal Information Processed)
The Clinic collects the minimum amount of personal information necessary to provide services.
- Required items:
- For treatment/consultation: Name, contact information (email, mobile phone number), appointment date and time
- For social media login: Email address, name, social media provider identifier (ID)
- Optional items (collected when using the AI chatbot):
- Full conversation history with the chatbot (symptoms, pain areas, areas of interest, consultation history, etc.)
※ As soon as the user completes an appointment through the chatbot, the conversation log is delivered to the medical staff for reference in treatment. - Automatically collected items: IP address, cookies, service usage history, access logs
Article 3 (Processing and Retention Period of Personal Information)
The Clinic processes and retains personal information within the retention/use period required by law or the period agreed upon when collecting personal information from the data subject.
[Retention Period]
- Website member information: Until membership withdrawal (However, if an investigation or inquiry is underway due to a violation of relevant laws, until the completion of such investigation or inquiry)
- Medical appointment information and chatbot consultation logs: Until the purpose of the treatment is achieved, or 3 years/5 years from the appointment date (in accordance with the retention period of medical records under the Medical Service Act)
- However, in cases of simple consultation/appointment cancellation without receiving medical treatment: Discarded 1 year after the date of collection
Article 4 (Provision of Personal Information to Third Parties and Access Rights)
The Clinic provides personal information to third parties only in cases that fall under Articles 17 and 18 of the 「Personal Information Protection Act」, such as the consent of the data subject or special provisions in the law.
[Specification of System Access Rights]
For the smooth operation of the appointment system and connection to medical treatment, collected personal information (appointment information and chatbot conversation contents) is stored in the Clinic's database and can be accessed by the following parties:
- Medical Staff (Doctors, Nurses, Consultation Managers): For the purpose of preparing for medical consultations and managing appointments
- System Administrator (Web/DB Administrator): For the purpose of fixing system errors, data backup, and security management
Article 5 (Entrustment and Overseas Transfer of Personal Information Processing)
The Clinic entrusts personal information processing tasks as follows for smooth service provision, and personal information is transferred overseas due to the use of global cloud services.
- Domestic entrusted companies
- Trustee: PREDAQ (or not applicable)
- Entrusted work: Website maintenance, system error correction
- Overseas Transfer of Personal Information (Use of Cloud Servers)
The Clinic keeps personal information overseas as follows to operate the membership registration and login authentication system (Firebase Authentication).
Country of transfer USA Recipient (Corporate name) Google LLC Date and method of transfer Transferred via network with encryption whenever the service is used Transferred items Email address, password (encrypted), login ID, profile picture (if set), access logs Purpose of transfer Operation of member authentication system, data backup, and security management Retention and use period Until membership withdrawal or the end of the entrustment contract Contact information of manager johjaesung@gmail.com (Personal Information Protection Officer of the Clinic)
Article 6 (Rights, Obligations, and Exercise Methods of Data Subjects)
Users can exercise their rights to access, correct, delete, or suspend the processing of their personal information at any time, and the Clinic will take action without delay. However, the deletion of medical records that must be preserved according to relevant laws such as the Medical Service Act may be restricted.
Article 7 (Measures to Ensure the Safety of Personal Information)
The Clinic takes the following measures to ensure the safety of personal information:
- Administrative measures: Establishment and implementation of internal management plans, regular staff training
- Technical measures: Management of access rights to personal information processing systems, installation of security programs, encryption of unique identification information (HTTPS communication, etc.)
- Physical measures: Access control to computer rooms, document storage rooms, etc.
Article 8 (Personal Information Protection Officer)
The Clinic appoints the following Personal Information Protection Officer to oversee tasks related to personal information processing and to handle grievances and provide relief for damages related to personal information processing.
- Name and Position: Representative Hong Ji-yeon
- Affiliation: Yon Korean Medicine Clinic
- Contact: 031-935-5758