Consent for Personal Data Retrieval Service
Consent to Additional Collection and Use of Personal Information and Delegation of Processing for the Personal Data Retrieval Service
The Korean version is the authoritative text. In case of any conflict or inconsistency between the Korean and English versions, the Korean version governs.
apitree Inc. ((주)에피트리, hereinafter the "Company") obtains the following consent at the time of first use of the service under which the Company retrieves and obtains, on the Member's behalf, the Member's own information from institutions designated by the Member and delivers it to the Member (hereinafter the "Personal Data Retrieval Service").
1. Items Collected and Used
-
Authentication means: joint certificates and financial certificates (certificate files and passwords), and account information of the institutions subject to retrieval (login credentials such as IDs and passwords)
-
Retrieval request information: the institutions designated by the Member, the retrieval products and items, and the retrieval conditions (period, subject, etc.)
-
Retrieval result information: all information returned by the institution subject to retrieval in response to the Member's request (including, depending on the retrieval product, information such as name, date of birth, address, qualifications and licenses, tax payment and income, financial transactions, vehicles and real estate; the retrieval results may contain resident registration numbers and other unique identification information)
2. Purpose of Collection and Use
Retrieving and issuing, on the Member's behalf, the Member's own information as requested by the Member, and delivering the results to the Member (or to the Member's application designated by the Member)
3. Processing Method and Retention Period
-
Authentication means are stored encrypted (AES-256-GCM) and are destroyed without delay when the Member requests deletion or withdraws from membership. The Member may view and delete stored authentication means at any time.
-
Retrieval result information is processed only within the scope of the purpose of delivering it to the Member, and is not stored in the Company's systems after delivery is completed (no-storage principle). In the records (logs) of the processing, unique identification information is masked.
-
Retrieval request information (usage records of which retrievals were made at which institutions) is retained for the period prescribed by the relevant statutes for the purposes of fee settlement and dispute response.
4. Delegation of Processing (Agency)
The Member consents to the Company, for the performance of the Personal Data Retrieval Service, accessing the systems of the institutions subject to retrieval on the Member's behalf and using the Member's authentication means to retrieve and obtain the Member's own information. The Company shall not use the authentication means beyond the scope of the Member's request.
5. Right to Refuse Consent and Disadvantages of Refusal
You have the right to refuse this consent. However, if you refuse, you will not be able to use the Personal Data Retrieval Service, while there is no restriction on your use of other services.