Handling Policy of personal information in digital contents service

 


1. The purpose of handling personal information

Digital Contents Service (here in after referred to as "Our service") of GIRJAESOFT Co., Ltd. process personal information for the following purposes.
Handled information will not be used for other purposes rather than this, and prior consent will be asked if the purpose of use is changed.

Membership and Management
We process personal information for the following purpose; confirmation of the intent of registration, identification for membership service and maintenance of membership qualification.


2. Personal information status
Personal information that Our Service registers and discloses according to Privacy Protection Act, article 32 and purpose of processing the information are as following;

- Entries of personal information: ID, E-mail, password, phone number(option)
- Method of collection: ALUVUU app
- Ground of possession: store and manage videos/photos include fetal face image
- Retention period: until the user’s membership is canceled



3. Commitment to Personal Information Management
Our Service consigns personal information processing tasks for seamless personal information business processing as follows.
Our Service is prohibited from processing personal information except for following consignment tasks in accordance with Article 25 of the Privacy Protection Act, technical and administrative protection measures. Extended contract limit, protection, can be found in contract documents, such as the trustee for matters related to responsible management, supervision, and compensation for damages, and it also supervises whether the trustee handles personal information securely.
If the contents of the consignment service or the consignee change, we will disclose it through this personal information processing policy as soon as possible.


4. Rights, duties of information subject and how to exercise them
As the subject of personal information, users can exercise the following rights.
The information subject may exercise the right of privacy protection of Our Service at any time as follows.
- Right to access your personal information
- Right to edit your personal information for incorrect information
- Right to delete your personal information
- Right to hold the process
According to Annex 8 of Privacy Protection Act, you can exercise right for Section 1 through in writing, email and fax, and Our Service will proceed without delay.
If the subject requests correction or deletion of personal information on Our Service, the personal information is not provided or used elsewhere until the correction or deletion is completed.

However, the data in which personal information is removed for the purpose of research is not included in the deletion request.
The exercise of the rights under Section 1 may be done through the legal representative of the information entity or the agent who has been delegated. In this case, you must submit a power of attorney according to Form 11 of the Enforcement Regulations of the Personal Information Protection Act.


5. Complete Items in Personal Information Processing
Our Service processes the following personal information items:
- Required: ID, email, password

- Optional: Cell phone number (User can input the phone number after registering account for account recovery)

Information provided from login method using Facebook, Google account are as follows.

-Nickname, E-mail address

Information you directly provide us
- Entries of contents when you use our services: videos/photos include fetal face image for use Fetal Face Recognition and Face Manipulation, private contents to leave record for your baby

Information you provide us when you use our services

The ALUVUU app no ​​longer uses a sharing function between users, so there is no need to store a lot of data on the server, but the following information is collected for some records and specific features.

- Device Information: We collect information about your device, including the hardware model, operating system and version, browser type and language, and mobile network information. We also collect certain device information that will help us diagnose problems in the event you experience any crash or other problem while using our Services.

- Camera and Photo Gallery: Some of our services require us to collect images and other information from your device’s camera and photo gallery. We’ll access your camera and photo gallery only after you give us your consent.

- Media & Apple Music Library: Some of our services require us to collect media list and other information from your device’s storage. We’ll access your Media & Apple Music library only after you give us your consent.

- Face Recognition: ALUVUU use face recognition technology to recognize fetal faces in photos and camera experiences. We may detect and classify fetal face data from your contents to provide face recognition and facial manipulation features.

- Face Manipulation of Fetal Avatar 3D model: Specifically, we may use manipulation related information to provide users with more suitable contents and preferred fetal avatar 3D model. The information we collect cannot be used for identifying a specific person, and is used to provide the mentioned features only. This information is not shared with any third parties.



6. Destruction of Personal Information
Our Service will, in principle, destroy all personal information without delay when the purpose of processing personal information achieved. The procedures, deadlines, and methods of destruction are as follows.

Destruction procedure

User's personal information is transferred to a separate DB after completion of the purpose (separate documents in case of paper) and it will be destroyed after a certain period of time in accordance with the internal policy and other related laws. At this time, the personal information which transferred to the DB is not used for any other purposes unless it is required by law.

Time Required before Personal Information Destroyed
User's personal information is going to be held within the period of retention of personal information. When that personal information becomes unnecessary, such as in the case of fulfillment of purpose based on personal information processing process, or in the case of abolition of service or termination of business, we will destroy the personal information immediately from the day when processing of personal information is considered as unnecessary.

Destruction Method
Information in the form of electronic files is destroyed using technical methods in which the records cannot be reproduced.
If you want to destruct your personal data, please send email by the link follow.

Send Email for Personal Data Destruction

Personal information printed on paper is destroyed by a paper shredder or incinerated.


7. Measures to Ensure the Safety of Personal Information
Our Service, pursuant to Article 29 of the Personal Information Protection Act, provide the following technical, administrative, and physical measures to ensure safety of personal information.
Encrypted private information
User's personal information and password are saved and managed after encrypted which means only the user could know. Important data could be protected by special security functions such as encrypting files and transmitted-data, or using file-lock function.
Restriction on accessing private information
By granting, changing, and erasing access authority on data base processing private information, access control on private information is made. Also, unauthorized access from external is controlled by the firewall system.

Safely stored private information

We store and process encrypted information in the United States or any other country in which we maintain facilities with Google Cloud and AWS.

Using minimal private Information

- Communicate with you. That means just what it says; respond to your comments and questions; provide customer service; and send you technical notices, security alerts, and other informational messages;

- Monitor and analyze trends and usage

- Develop, improve, and refine products, services, and functionality

- Verify your identity and prevent fraud or other unauthorized or illegal activity


8. To be filled by privacy officer
Our Service appoints a privacy officer, in charge of managing private information, to handle complaints and minimize damages in relation to private information processing.

Privacy Officer
Name: SangLim Lee
Position: Manager
Phone: +82-70-4355-2378
Email:
info@mail.girjae.com

The information subject can inquire of service (or business) related to Our Service with regard to the protection of personal information, enquiries and complaints. The responsible department will be contacted and Our Service will respond to inquiries regarding information subject without delay and will process it as soon as possible.


9. Amendment of Personal Data Processing Policy
This Personal Data Processing Policy will be applied from enforcement date and any addition, deletion or modification following a regulation or policy shall be announced through a notification 7 days before the date of implementation.