Privacy Policy
Contents
- Article 1. Personal data we collect
- Article 2. Purpose of collection and use
- Article 3. Retention and use period
- Article 4. Provision to third parties
- Article 5. Destruction procedure and method
- Article 6. Your rights and how to exercise them
- Article 7. Data protection officer
- Article 8. Consignment of processing
- Article 9. Transfer of personal data abroad
- Article 10. Automatic collection devices and how to refuse them
- Article 11. Security measures
- Article 12. Changes to this policy
Article 1. Personal data we collect
For handling 1:1 inquiries, we collect the following, entered directly by the user.
- Required name, contact (email or phone), inquiry subject and content
- Automatically collected cookies, visit time, browser information (for visit analytics)
We do not store your access IP address in the inquiry record.
Article 2. Purpose of collection and use
We use the personal data we collect for the purposes below. If the purpose changes, we obtain consent in advance.
- Receiving and handling inquiries, and replying with the outcome
- Providing product and service information, and customer support
- Statistical analysis for service improvement and new service development
Article 3. Retention and use period
As a rule we destroy personal data without delay once the purpose of collection and use has been achieved. Where a statute requires retention, we keep it for the period below.
| Inquiry and consultation records | 1 year after handling is complete |
|---|---|
| Data retained under statute | The period prescribed by that statute |
Article 4. Provision to third parties
We do not use personal data beyond the scope stated in this policy, nor provide it to third parties, except in the following cases.
- Where the data subject has consented in advance to such provision
- Where required by statute, or requested by an investigative authority under due process
Transfers abroad arising from the anti-bot service are described separately in Article 9.
Article 5. Destruction procedure and method
We destroy personal data whose retention period has expired or whose purpose has been achieved, by the following procedure and methods.
- Procedure We identify the data due for destruction and destroy it with the approval of the data protection officer.
- Electronic files Permanently deleted by a technical method that makes recovery impossible.
- Paper documents Shredded or incinerated.
Article 6. Your rights and how to exercise them
You may exercise the following rights regarding your personal data at any time.
- Request access to your personal data
- Request correction of errors
- Request deletion
- Request suspension of processing
You may submit your request to the data protection officer in Article 7 in writing, by phone, or by email, and we will act without delay. Access requests are received and handled through the same channel.
You may exercise these rights through a legal representative or an authorized agent. If we decline a request, we will inform you of the reason and how to appeal.
Article 7. Data protection officer
We have designated a data protection officer, who takes overall responsibility for personal data processing and handles your inquiries and remedies.
| Name | Data Protection Officer |
|---|---|
| Phone | +82-31-467-5800 |
| infocni@samjin.com |
To seek remedy for a privacy infringement, you may apply to the following bodies for dispute resolution or advice.
| Personal Information Dispute Mediation Committee | 1833-6972 |
|---|---|
| Privacy Infringement Report Center | 118 |
| Supreme Prosecutors’ Office Cyber Investigation Division | 1301 |
| National Police Agency Cyber Bureau | 182 |
Article 8. Consignment of processing
We may consign part of our personal data processing to external parties to the extent necessary for smooth service delivery. Where we enter into such a contract, we specify in it the prohibition of processing beyond the consigned purpose, restrictions on sub-consignment, and supervision of the trustee, and we supervise whether the trustee handles personal data safely.
If the consigned work or the trustee changes, we disclose it through this policy without delay.
Article 9. Transfer of personal data abroad
We use Google LLC’s reCAPTCHA on the 1:1 inquiry form to prevent automated submissions. In this process, the following information is transferred abroad.
| Recipient | Google LLC |
|---|---|
| Country | United States |
| Items transferred | Access IP address, browser and device information, reCAPTCHA usage records |
| Time and method | Transmitted automatically over the network when the inquiry form is displayed or submitted |
| Purpose | Preventing automated submissions (bot and spam blocking) |
| Retention period | As set out in Google LLC’s privacy policy |
If you prefer not to have your data transferred abroad, you may contact us directly at infocni@samjin.com instead of using the form; such inquiries are received in the same way.
Article 10. Automatic collection devices and how to refuse them
We use cookies — small pieces of information sent by our server to your browser and stored on your device — to understand how the site is used.
to_day | Counts daily unique visitors / kept 2 days |
|---|---|
to_off | Stored only when you opt out of visit statistics / kept 1 year |
All cookies we use are first-party cookies that we install and operate ourselves; we do not use third-party advertising cookies. You may refuse cookies or delete stored cookies in your browser settings. Refusing them does not impede your use of this site; only the accuracy of visit statistics changes.
Article 11. Security measures
We take the following measures to keep personal data secure.
- Minimized access Inquiries can be viewed only by authenticated administrators.
- One-way hashing of credentials Administrator passwords are stored using a one-way function that cannot be reversed.
- No direct web access to data files The area where inquiries are stored is blocked at the server from direct web access.
- Irreversible handling of IP addresses Access IPs, used solely for spam prevention and to avoid counting the same visitor twice, are converted to an irreversible value for comparison; the original address is never stored in either case. The converted value is deleted automatically after 10 minutes for spam-prevention records and after 3 days for visit statistics.
Article 12. Changes to this policy
This policy may be amended in line with changes to relevant statutes or company policy. Where it changes, we announce the change on this website from seven days before it takes effect.
Announced 2026-07-22
Effective 2026-07-29