CJ ENM Co., Ltd Entertainment Division (hereinafter “Company”) actively protects the personal information of users (“Users”) and has established, and is in compliance with, the Company’s privacy policy (hereinafter “Privacy Policy”) for the purpose of complying with all personal information-related laws and regulations. Through the Privacy Policy set forth below, the Company informs Users of the purpose and method of use of personal information provided by Users and the measures being taken to protect their personal information.
This Privacy Policy is published on the Company’s website and is easily accessible at any time. The Privacy Policy includes the following subject matters.
- 1. Procedure for providing consent to the collection and use of personal information
- 2. List of personal information items collected and the purpose of collecting and using personal information
- 3. Retention, period of use, and destruction of personal information
- 4. Installation, operation, and rejection of automatic personal information collection devices
- 5. Users' rights with respect to personal information and how to exercise them
- 6. Chief Privacy Officer and customer center
- 7. Consent for providing and sharing personal information to a third party
- 8. Consent to the consignment of personal information processing
- 9. Withdrawal of consent to collection, use or provision of personal information
- 10. Information on the collection of personal information of children under the age of 14
- 11. Technical and administrative protection of personal information
- 12. Duty to notify
1. Procedure for providing consent to the collection and use of personal information
Users may provide consent to the collection, use, provision to third parties, and consignment of processing, etc. of their personal information by reading the “Privacy Policy” and “Consent Form for the Collection and Use of Personal Information” posted on the Company’s CP License Sales homepage (htttps://cplicense.cjenm.com), and clicking on the button “consent to the collection and use of personal information” provided on the homepage.
2. List of personal information items collected and the purpose of collecting and using personal information
The Company collects and uses only the minimum personal information necessary to provide its service. The collected personal information is not used for any purpose other than for which consent was obtained. In the event the purpose of using personal information is changed after the User consents, necessary measures, such as obtaining an additional prior consent from the User, will be taken.
- 1)Method of collection
- Collection of information by using the Company’s website services via PC and/or mobile
- Collection of information generated by a log analysis program
- Collection of information by using internet cookies
- 2)Collected items, purpose, and retention period
- (Required Consent) Use of the “Contact Us” Service
| Purpose of collection and use | To use Contact Us service, receive and handle inquiries, and notify processing results |
|---|
| Collected items | Name, email address, mobile phone number, affiliation, country name |
|---|
| Retention period | Within one(1) month from the completion of the application process or within five(5) days from the date of request for withdrawal by the data subject |
|---|
- 3)Information generated and collected during the use or processing of a service
The following information may be generated and collected to provide personalized services during the use or processing of a service.
- Frequency of use, service usage time, and usage records
- Access log and access IP information, cookies, usage records, session information
3. Retention, period of use, and destruction of personal information
- 1)Period of use and retention period
The Company retains and uses personal information only for the period agreed upon by the user (period of use) to provide services and handle inquiries in accordance with the personal information collection/use purpose.
- 2)Storage and preservation period of personal information
If it is necessary for the Company to preserve personal information based on User consent or pursuant to laws or other related regulations, the Company keeps and preserves the personal information for the consented period or the period set by law or regulation.
- Records related to visitor access (logs) and tracking data that can confirm the location of the information and communication device: Three (3) months (Protection of Communications Secrets Act);
- Respective period for each type of communication confirmation data pursuant to Article 15-2 of the Communications Secret Protection Act and Article 41 of the Enforcement Decree of the same Act
- Other storage and preservation periods: the period consented to when separate User consent was obtained
- 3)Procedure and method of destroying personal information
- A.Destruction procedure
The information provided by a User for the use of service is transferred to a separate DB after its purpose is achieved, stored for a certain period in accordance with the Company’s internal policy set forth under Section (2) above and upon expiration of the preservation period destroyed by the method specified in Section C below. Personal information transferred to a separate DB will not be used for any purpose other than as permitted by laws and regulations.
- B.Information subject to destruction
Information for which the preservation period set forth under Section (2) above has expired
- C. Destruction method
- Personal information in written and/or printed form: shredded or incinerated
- Personal information stored in the form of electronic files such as DB: deleted using technology that does not allow restoration or recovery of records
4. Installation, operation, and rejection of automatic personal information collection devices
Cookies, records of service usage, and access device information may be generated automatically and collected and stored in the User’s PC (hard disk, etc.) during the process of using Company services. Cookies are data that websites send to the users’ web browsers (Internet Explorer, Chrome, Firefox, etc.). The Company provides cookies to Users who use the Company’s website, and when the User revisits the Company’s website, the Company reads the details of the cookies stored in the user’s PC and analyzes information such as visit records, services used, service connection time and frequency, and information generated or provided (entered) during the process of using the service in order to improve services, prevent illegal use, and check user errors.
Strictly necessary cookies
| Cookies | Purpose | About | Expiration date | Deployer |
|---|
| CookieConsent | Stores the user's cookie consent status | HTTPcookies | 1 day | cplicense.cjenm.com |
| _ga | Registers a unique ID that is used to generate statistical data about how visitors use the website | HTTPcookies | 2 years | google |
| _gat | Used by Google Analytics to control the request speed | HTTPcookies | 1 day | google |
| _gid | Registers a unique ID that is used to generate statistical data about how visitors use the website | HTTPcookies | 1 day | google |
- Notice of Cookies, Effective Scope, Third-Party Cookies
Notice of cookies is only valid when using the Company’s website (https://cplicense.cjenm.com). The user may also receive third-party cookies from the Company’s service providers when using the Company’s website. However, the cookies collected by the Company are not provided to third parties. The Company will notify the User when it provides cookies, and the User has the right to decline the collection of cookies provided by the Company. However, if the User declines the collection of cookies, there may be limitations in using some services of the Company’s website.
- Method to decline the collection of cookies
- For Chrome : Settings > Security and Privacy> Cookies and other site data
- For Internet Explorer : Tools > Internet Options > Privacy > Settings > Advanced
- For Microsoft Edge: Settings > Cookies and Site Permissions > Manage and delete cookies and site data
5. Users' rights with respect to personal information and how to exercise them
Users can always visit the Company’s website and request to view, correct, or delete their stored personal information.
- 1)Users may request to view or verify personal information through the Company’s website or customer center.
- 2)When a User requests to view or verify his or her own personal information, the User must present his or her ID (copy) such as a resident registration card, passport, and driver’s license to confirm the identity of the User.
- 3)When a User’s delegate requests to view or verify the user’s personal information, the delegate must present a POA (power of attorney) indicating the relationship between the User and the delegate, a seal certificate of the User, and the ID of the delegate.
- 4)When a request is made by a User to correct any errors in personal information, the subject personal information will not be used or provided until the correction is completed. If any incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction without delay so that the third party may also make corrections accordingly.
- 5)However, the viewing and correction of personal information may be restricted in the following cases:
- A.Existence of a risk of significantly harming the life, body, property, or rights and interests of the User or a third party
- B.Existence of a risk of significantly impairing the service provider’s work
- C.Violation of any laws and/or regulations
6. Chief Privacy Officer and customer center
7. Consent for providing and sharing personal information to a third party
The Company uses a User’s personal information only within the scope specified in the Privacy Policy, and does not use or provide to a third party personal information beyond the specified scope. However, personal information may be provided in exceptional cases such as when the User gives prior consent or when a request is made pursuant to the provisions and procedures set forth by related laws and regulations.
8. Consent to the consignment of personal information processing
The Company consigns personal information processing work to the consignment companies listed below for purposes including the operation and maintenance of services and provision and management of user convenience. The Company manages the consignment companies by entering into service agreements which require the consignment companies to be and remain in compliance with related laws, regulations, and guidelines, protect personal information and comply with confidentiality provisions, and return and destroy personal information immediately upon the expiration or termination of the service agreement.
| Consignment company | Purpose of consignment work |
|---|
| MEDIA4THONE Inc. | Website construction/operation and management, maintenance |
| CJ OliveNetworks Co., Ltd. | IT asset management |
9. Withdrawal of consent to collection, user or provision of personal information
Users may request to withdraw their consent to the collection and use of personal information and to delete or stop the processing of the personal information. To submit such request, please contact the Chief Privacy Officer, and the Company will process it immediately after completing the identity verification process
10. Information on the collection of personal information of children under the age of 14
- 1)In principle, the Company does not collect personal information of children under the age of 14 (“Children” or “Child”). However, in the inevitable case of collecting personal information for the purpose of providing services, the Company obtains the consent of the legally authorized representative (“LAR”) of the Child as a mandatory procedure.
- 2)In order to obtain the consent of the LAR (e.g. parent), the Company collects from the Child a minimum amount of personal information such as the name and contact information of the LAR. The LAR may view, correct, and delete the Child’s personal information, and if they wish to do any of the foregoing, the LAR can make a request to the Chief Privacy Officer by phone or email and the Company will take necessary measures.
11. Technical and administrative protection of personal information
The Company provides the following technical and administrative safety measures to ensure that Users’ personal information is not lost, stolen, leaked, altered, or damaged.
- 1)Technical protection measures
-
A.Personal information is protected by a password, and important data is protected by using separate security features such as encrypting files and transmitted data or setting a lock on the file.
-
B.The Company takes measures to prevent damage caused by computer viruses by using an antivirus program. Antivirus programs are updated regularly, and in the event a virus unexpectedly appears, the Company immediately applies the antivirus update therefor upon its release to prevent infringement of personal information.
-
C.The Company uses a Secure Sockets Layer (SSL) device to safely transmit personal information over the network.
-
D.To prevent leakage of Users’ personal information from events such as hacking, the Company has installed its systems in an area restricted from external access and uses a device that blocks unauthorized access.
-
2)Administrative protection measures
-
A.The Company provides the necessary procedures for Users to manage and access personal information so that officers and employees become familiar and comply with such procedures. The Company periodically conducts compliance checks to ensure compliance of such procedures.
-
B.The Company limits the number of people who can process Users’ personal information to a minimum, manages access rights, and ensures compliance with laws and policies through internal trainings. The people who process Users’ personal information is as follows.
- Person whose work involves direct or indirect communication with users
- Person whose work involves the management and protection of personal information, such as the Chief Privacy Officer
- Person whose work inevitably involves access to personal information
-
C.The Company prevents any leakage of information (including personal information) in advance by requiring new hires to sign the information protection pledge, reminding employees of their obligations to protect personal information as often as necessary, and preparing internal procedures for compliance auditing.
-
D.The handover of work by the personal information manager is carried out securely, and the responsibility of each onboarding and offboarding employee for any case of personal information infringement is clearly set forth in the Company’s internal policy.
12. Duty to notify
In the event of any amendments to this Privacy Policy due to changes in Company policies, government policies, laws and regulations or security technology, the Company will post a notice on its website prior to such amendment.
- Current Privacy Policy Version: 1.2 (See previous policy)
- Notification date: September 27, 2024 / Implementation date: October 4, 2024