Doosan Corporation Information & Communications (“Doosan”) complies with the relevant laws and regulations dealing with personal information protection including the Personal Information Protection Act and the Act on Information Communications Network Use Promotion and Information Protection. Doosan strives to protect the rights and interests of persons providing personal information, such as customers, employees and Website users through its Privacy and Information Processing Policy and the Privacy and Information Handling Policy. Doosan notifies you of how and for what purposes we may use your information and what measures have been taken to protect your personal information through its policies regarding personal data privacy and information processing.. In the event any of the provisions of the relevant policies are amended, we will publicly notify you of such amendments through this Website or individually.
The Company’s policy related to personal information consists of the following: 1) the Privacy and Information Processing Policy regarding the personal information protection of all persons providing their own personal information, 2) the Privacy and Information Handling Policy regarding the personal information protection of this Website's users and 3) the Image Information Processing Equipment Operation & Management Policy regarding personal image information protection. However, privacy and Information handling policies related to other Doosan affiliates’’ websites are respectively set forth on those websites.
- 1. Privacy and Information Processing Policy
- 2. Privacy and Information Handling Policy
- 3. Image Information Processing Equipment Operation & Management Policy
1. Privacy and Information Processing Policy
01. General Rules
Personal information is information regarding a living person. That is, personal information refers to information that through which a person can be identified such as name, resident registration number and image. This includes information which may not identify a person on its own, but when combined with other information, may identify a person.
Personal information provider is a person who can be identified by the processed information.
Doosan will disclose the Privacy and Information Processing Policy on the first page of its Website(www.doosan.com) so that you can always easily check the policy. When the Policy is amended, we will publically notify you of the amendment through a notice on our Website or individually.
02. Processed Personal Information and Processing Purpose
Unless permitted by relevant laws and regulations or with the personal information provider’s prior consent, Doosan will not process any sensitive information and personal identification information issued for the purpose of identifying an individual that may seriously infringe the privacy of
A. Processed Information
- Name, e-mail address, address, residential area, company name, access login data
B. Purpose of processing
- Handling of user questions and complaints
03. Processing and the Retention Period of Personal Information
Once the purpose of collection and the use of personal information are met and completed, as a fundamental rule, the relevant information will be immediately destroyed. However, we will retain the following information during the period specified below and for the reasons specified below and we will obtain consent from the person who provided his or her own personal information, as necessary.
- Retained information: Name, e-mail address, residential area, company name
- Retention period: 1 year
- Reason of retention: Manage user questions and requests, identify users, etc.
- Retained information: Service use records, access logs, cookies, access IP information
- Retention period: 3 years
- Reason of retention: Improve service quality by analyzing user service uses
04. How Personal Information is Destroyed
Any personal information saved in an electronic file format will be deleted using a technology that prevents the recovery of the deleted records.
The personal information retained on paper will be shredded or burned.
05. Disclosure of Personal Information to a Third Party
Doosan will collect personal information within the scope of the purpose of the collection and will not use your personal information beyond the scope of collection purpose or offer or disclose it to a third party. However, the following are the exception to the above rule:
- - Consent was received from the person who provided his or her own personal information.
- - According to specific provisions in other relevant laws.
- - The person providing their own personal information or his/her legal representative is in a state in which an opinion/intention cannot be expressed, or prior consent cannot be gained due to an invalid address, but disclosure to a third party is urgently needed for the sake of the data provider or a third party’s life, body and property.
- - Necessary for statistical purposes and academic studies, where personal information is provided in a way as not to identify a specific individual.
06. Commissioning of Personal Information Processing
Doosan will not commission personal information processing to an outside agency without your consent.
07. Rights and Obligations of the Person Providing Their Own Personal Information and Method to Exercise the Rights
All the persons providing their personal information may request for the inspection, revision, deletion and cessation of the processing of their personal information. However, Doosan may reject or restrict such a request in the following cases:
- - When specifically required under the law or to comply with obligations under laws and regulations.
- - When there is a concern for harm to another person’s life or body, or when there is a concern of unlawfully infringing upon another person’s property and profits.
- - In a case where the service contracted with the personal information provider cannot be offered without processing his or her personal information, or when it is difficult to perform the service contracted with the personal information provider, but her or she does not clearly express his/her intention to terminate the contract.
[Method and Procedure to Exercise Rights]
- A person wanting to exercise the above rights regarding their personal information may complete the Read/Inspect, Revise, Delete and Suspend the Processing Form and sent it by email or fax to the department in charge of personal information (See “09. Customer Request Service on Personal Information” concerning the department).
- Unless there is a legitimate reason, Doosan will take a proper action within 10 days of receiving such a request. When there is a reason to reject or restrict the request, we will inform you of the reason and a method to appeal the decision within 5 days upon receiving the request. When the concerned person or legal representative makes a request as above, we can confirm the identity of the person or legal representatives by checking their identification cards such as a resident registration card or a recognized electronic signature.
08. Technical, Administrative and Physical Protection Measures for Personal Information
Doosan takes the following safeguards in handling personal information so that it will not be lost, stolen, leaked, modified, or damaged:
- Doosan complies with the criteria set forth by laws and regulations for the safe storage and transmission of personal information.
- We protect against computer virus by using a vaccine program. The vaccine program is periodically updated, but if there is a sudden emergence of a new virus, we will implement the appropriate vaccine as soon as it becomes available so that personal information infringement can be prevented.
- To deal with outside infiltration, including hacking, we use an infiltration interruption system and a weakness analysis system.
- Doosan restricts the rights to access personal information to the following cases: a person carrying out sales and marketing activity involving the personal information provider, a person engaging in personal information management and a person whose task requires the use of personal information.
- We conduct regular in-house training and external commissioned training for those employees that handle personal information and we thoroughly manage and supervise them to comply with the laws and regulations regarding personal information protection.
- To protect personal information, we limit physical access to the information through the use of locks and similar devices.
- We control access to the computer room and archives by designating and operating them as specially protected areas.
09. Customer Request Service for Personal Information
Doosan has appointed the following department and personal information protection administrator to protect personal information and to process complaints related to personal information:
A. Department in Charge of Personal Information
- Department: Information Security Team
- Tel: 02-3670-8588
- Fax: 02-3670-8555
- Email: firstname.lastname@example.org
- Business hours: (Monday - Friday) 09:00 – 18:00, (Saturday, Sunday): holiday
B. Personal information Protection Administrator
- Name: General Manager Sangrae Lee
- Tel: 02-3670-8588
- Email: email@example.com
Should you need to report a personal information infringement or receive consultation regarding infringement, please contact the following agencies:
1. Personal Information Dispute Mediation Committee (http://privacy.kisa.or.kr/118)
2. Privacy Infringement Report Center (http://privacy.go.kr/118)
3. Information Protection Mark Authentication Committee (www.eprivacy.or.kr/02-580-0533~4)
4. Supreme Prosecutors’ Office Internet Crime Investigation Center (http://icic.sppo.go.kr/02-3480-3600)
5. National Police Agency Cyber Terror Response Center (www.ctrc.go.kr/02-392-0330)
10. Obligation of Public Notification
When the current Privacy and information Processing Policy is amended or deleted, we will provide notice on our Website 10 days before such amendment or deletion takes place
- Date of Public Notification: September 30, 2011
- Date of Enforcement: September 30, 2011
2. Privacy and Information Handling Policy
Doosan Group (“Doosan”) greatly values users’ personal information and complies with the Act on Information Communications Network Use Promotion and Information Protection.
We inform you about how and for what purpose users’ personal information is used and what actions are taken for the privacy protection of the users. In the event that any of the provisions of the Privacy and Information Handling Policy are amended or updated, we will publicly notify you of such amendments or updates through this Website or individually. The following Privacy and Information Handling Policy applies to this Website (www.doosan.com)
This policy will take effect on January 18, 2010.
Collected Personal Information
Doosan collects the following personal information for consultation, application for service and so on:
- Collected information: Name, e-mail address, residential area, company name, access logs
- How personal information is collected: Website (Customer Center (Contact Us))
Disclosure of Personal Information
We will not externally disclose any personal information that has been collected through the Website, except with your prior consent or under situations where we are required by law to disclose your personal information to such third parties as law enforcement authorities, judicial authorities, or other government authorities.
However, the following exceptions will apply for the following cases:
- When users have agreed in advance.
- In the case when it is required by law or when an government agency requests pursuant to the procedures and methods set forth in the relevant laws and regulations for the purpose of investigation.
In the event that we consider it necessary to release your personal information to an outside agency for commissioned services, we will notify you about the identity of the agency as well as the nature of the commissioned service and obtain your prior consent.
Retention and Destruction of Personal Information
Any information provided by a user will be banned from being used for the reasons other than the purpose of retention or to comply with relevant laws and regulations. After the purpose of collection and use of personal information is completed, the information concerned will be immediately destroyed without exception. If a user requests us to destroy his/her personal information, unless the required period to retain such information by law expires later than the time the request was made, the user’s information will be completely destroyed upon the receipt of such a request. The destruction procedure and method are presented below:
A. Retention and Use Period
- Retained information: Name, e-mail address, residential area and company name
- Retention period: 1 year
- Reason of retention: Manage user questions and requests, indentify users, etc.
- Retained information: Service use records, access logs, cookies and access IP information
- Retention period: 3 years
- Reason of retention: Gathering of statistics on users’ service uses
B. Destruction Procedures
Any information provided by you will be transferred to a separate DB (separate document box in the case of paper) upon completition of the purpose of its use and it will be stored for a certain period of time and then destroyed under our policy and other relevant laws and regulations. Such information will then be banned from use, other than for the purpose of retention or otherwise prohibited by law.
C. Destruction Method
Personal information stored in an electronic file format will be deleted using a technical method which prevents the retrieval of the deleted file.
Rights of a User and Legal Representative and Rights Exercising Method
A user and his/her legal representative may request to inquire, revise the user’s registered personal information and withdraw their consent at anytime. We will take the proper action upon receiving your request in writing, telephone, or email to the department in charge of personal information control.
In the event that you request the revision of an error in your personal information, we will not use or provide it until the revision is complete. If the wrong information has already been provided to a third party, we will immediately notify that third party of the revision processing result so that they can revise your personal information.
Doosan handles personal information that has been terminated or deleted pursuant to the request of a user or his/her legal representative in accordance with the provisions of the “Retention and Use Period” section and will prevent it from being read/inspected or used for other purposes.
Links to Other Sites
The Website may include links to the other websites and we are not responsible for the content of linked websites or the use of such websites. Users agree that your use of such linked websites will be governed by that wesites’ own privacy and information handling policies.
Protection of Personal Information
We maintain strict safeguards to protect your personal information from unauthorized or inappropriate access by limiting employee access to and use of the information.
Customer Support Services for Private Information
To protect customer’s private information and to processed related complaints, we have appointed a relevant department and personal information administrator as follows:
Customer service department: Information Security Team
Staff for personal information: General Manager Sangrae Lee
Should you need to file any reports regarding the infringement of personal information or if you have inquiries about the Privacy and Information Handling Policy, please contact the following agencies:
Personal Information Dispute Mediation Committee (http://www.1336.or.kr Phone no. : 1336)
Information Protection Mark Authentication Committee (http://www.eprivacy.or.kr Phone no. : 02-580-0533~4)
Supreme Prosecutors’ Office Internet Crime Investigation Center (http://www.sppo.go.kr Phone no. : 02-3480-3600)
National Police Agency Cyber Terror Response Center (http://www.ctrc.go.kr Phone no. : 02-392-0330)
Date of Public Notification: January 18, 2010
Date of Enforcement: January 18, 2010
3. Image Information Processing Equipment Operation & Management Policy
The company shall not install image information processing devices in open locations to gather personal information.