Privacy Policy

privacy policy

Grace Plastic Surgery Clinic (hereinafter referred to as "the Clinic") places great importance on the protection of your personal information and complies with the Personal Information Protection Act. Through this Privacy Policy, the Clinic informs you of the purposes and methods for which the personal information you provide is used, as well as the measures being taken to protect your personal information.

The order of this Privacy Policy is as follows.
1. Items of personal information collected and methods of collection
2. Purpose of Collection and Use of Personal Information
3. Retention and Usage Period of Personal Information, Destruction Procedures, and Destruction Methods
4. Rights of Users and Legal Representatives and Methods of Exercising Them
5. How to Withdraw Consent / Withdraw Membership
6. Provision and Sharing of Personal Information
7. Outsourcing of Personal Information Processing
8. Chief Privacy Officer
9. Measures to Ensure the Safety of Personal Information
10. Obligation to notify regarding policy changes

1. Items of personal information collected and how to modify them
Our clinic collects only the minimum personal information necessary for service use upon membership registration. Essential information for medical treatment is collected through the completion of a medical record card without separate consent, in accordance with the Medical Service Act. For additional services other than medical treatment, you must complete a separate consent form for collection and use; however, there will be no disadvantages regarding medical treatment even if you do not complete the consent form.
- Items of medical information collected: Name, address, contact information (telephone number, mobile phone number), medical records
- Additional service information collected: Name, address, contact information (mobile phone number), email address, occupation, marital status, date of birth, source of visit

2. Purpose of Collection and Use of Personal Information
This institution utilizes the collected personal information for the following purposes.
All information provided by the user will not be used for any purpose other than those necessary for the purposes listed below, and prior consent will be sought if the purpose of use changes.
- Medical Information: Provision of medical services for diagnosis and treatment, and administrative services such as billing, payment, and refunds.
- Additional Service Information: To secure a smooth communication channel for delivering hospital news and notices, handling complaints, etc.
- Used for marketing and advertising: Delivery of promotional information such as events, identification of access frequency, or statistics on members' service usage.

3. Retention and Usage Period of Personal Information, Destruction Procedures, and Destruction Methods
This hospital retains personal information for the retention period stipulated by the Medical Service Act and destroys personal information without delay thereafter.
- Retention Period: 10 years for medical records
Additional service information is destroyed together with patient information or upon the data subject's request for destruction.
- Destruction Procedure: Immediate destruction by the method of destruction after the statutory retention period
※ Relevant personal information is immediately destroyed after 10 years have passed since the last medical record was recorded.
- Method of Destruction: Personal information stored in the form of electronic files is deleted using technical methods that render the records unrecoverable, and personal information printed on paper is destroyed by shredding or incineration.

4. Rights of Users and Legal Representatives and Methods of Exercising Them
Membership registration for children under the age of 14 (hereinafter referred to as “children”) is conducted through a separate consent form written in simple language that is easy for children to understand, and consent from a legal representative is always obtained when collecting personal information.
To obtain the consent of a legal representative, this institution collects minimal information from children, such as the legal representative's name and contact information, and obtains such consent in accordance with the methods stipulated in the Privacy Policy. Users and legal representatives may exercise their rights regarding personal information by contacting this institution via the internet, telephone, or written correspondence, and this institution will take necessary measures without delay.
※ Personal information that is required to be retained by law cannot be modified or deleted within the retention period, even upon request.

5. How to Withdraw Consent / Withdraw Membership
You may withdraw your consent to the collection, use, and provision of personal information at any time. To withdraw your membership, please fill out a withdrawal application form or contact the Chief Privacy Officer in writing, by phone, or by fax. We will take necessary measures, such as destroying your personal information without delay.

6. Provision and Sharing of Personal Information
Except where your consent has been obtained or as required by relevant laws and regulations, this institution will not, under any circumstances, use your personal information beyond the scope notified in the purpose of collection and use, nor provide it to other individuals, companies, or organizations.
- In accordance with the National Health Insurance Act, we submit medical records to the Health Insurance Review & Assessment Service to claim medical benefits.
- When necessary for statistical compilation or academic research, data will be processed and provided in a form that prevents the identification of specific individuals.
- Submission, etc. upon request from investigative agencies in accordance with the procedures and methods prescribed by law.

7. Outsourcing of Personal Information Processing
This institution entrusts personal information to the following companies for the management of its personal information management system.
- Hospital Customer Information Management System: MediQ Co., Ltd. (Representative: Kim Geun-ho)
- Website Operation and Maintenance: Beyond M Co., Ltd.

8. Chief Privacy Officer
We have appointed a Data Protection Officer to protect your personal information and handle complaints related to personal information.

Name: Choi Mun-seop
Position: Director
Affiliation: Grace Plastic Surgery Clinic
Phone Number: 02-555-8558
Email: dccent@nate.com


9. Measures to Ensure the Safety of Personal Information
This institution has implemented various security measures as technical safeguards for the protection of users' personal information. All information provided by users is safely protected and managed by security equipment, such as firewalls.
In addition, as an administrative measure for the protection of users' personal information, this institution has established procedures necessary for accessing and managing users' personal information, limits the number of personnel handling users' personal information to a minimum, and conducts continuous security training.
In addition, we will designate users of the system that processes personal information, assign user passwords, and update them regularly.

10. Obligation to notify regarding policy changes
This Privacy Policy was established on March 15, 2012. In the event of any additions, deletions, or modifications to the content due to changes in laws, policies, or security technologies, we will announce the reasons for the changes and the details on the hospital's website at least 7 days prior to the implementation of the revised Privacy Policy.

April 1, 2012

Chief Director Choi Moon-seop