totle Privacy Policy
This Policy (the "Policy") explains the way of treatment of the information which is provided or collected in the web sites on which this Policy is posted.
In addition, the Policy also explains the information which is provided or collected in the course of using the applications of the Company which exist on the websites or platforms of other companies.
The Company is the controller of the information provided or collected in the websites on which this Policy is posted and in the course of using the applications of the Company which exists in the websites or platforms of other company.
Through this Policy, the Company regards the personal information of the users as important and informs them of the purpose and method of the Company's using the personal information provided by the users and the measures taken by the Company for the protection of that personal information.
This Policy will be effective June 13, 2022, and, in case of modification thereof, the Company will make public notice of it by posting it on the bulletin board of the Company's website or individual notice through sending mail, fax, or e-mails.
1. Information to be collected and method of collection
1.1 Personal information items to be collected
Personal information items to be collected by the Company are as follows:
A. Information provided by the users
The Company may collect the information directly provided by the users.
Internet membership service
• Name, email address, ID, national information, encoded identification information (CI), identification information of overlapped membership (DI)
• For minors, information of legal representatives (name, birth date, CI and DI of legal representatives)
Online payment service
• Name, address, telephone number, and email address
• Payment information including account number and card number
B. Information collected while the users use services
Besides of information directly provided by the users, the Company may collect information in the course that the users use the service provided by the Company.
Equipment information
• Equipment identifier, operation system, hardware version, equipment set-up, type and set-up of browser, use information of website or application and telephone number
Log information
• IP address, log data, use time, search word input by users, internet protocol address, cookie and web beacon
Organization information
• Name, job title, department, mail address, phone number, company telephone number
Receipt confirmation information
• Sender/receiver mail address, mail subject
Reservation sending information
• Sender/receiver mail address, mail subject, mail content, mail account user id, password
1.2 Method of collection
The Company collects the information of users in a way of the following:
• webpage, written form, fax, telephone calling, e-mailing, tools for collection of created information
• provided by partner companies
2. Use of collected information
2.1 The Company uses the collected information of users for the following purposes:
• Member management and identification
• To detect and deter unauthorized or fraudulent use of or abuse of the Service
• Performance of a contract, service fee payment, and service fee settlement regarding the provision of services demanded by the users
• Improvement of existing services and development of new services
• Making notice of the function of company sites or applications or matters on policy change
• To help you connect with other users you already know and, with your permission, allow other users to connect with you
• To make statistics on member’s service usage, to provide services, and place advertisements based on statistical characteristics
• To provide information on promotional events as well as opportunity to participate
• To comply with applicable laws or legal obligations
• Use of information with the prior consent of the users (for example, utilization of marketing advertisement)
The Company agrees that it will obtain consent from the users if the Company desires to use information other than those expressly stated in this Policy.
2.2 Lawful processing of personal information under GDPR
Processing personal information by the Company shall be lawful only if and to the extent that at least one of the following applies:
• A user has given consent to the processing of his or her personal information.
• Processing is necessary for the performance of a contract to which a user is a party or in order to take steps at the request of a user prior to entering into a contract:
- Member management, identification, etc.
- Performance of a contract in relation to providing the services required by users, payment and settlement of fees, etc.
• Processing is necessary for compliance with a legal obligation to which the Company is subject
- Compliance with relevant laws, regulations, legal proceedings, and requests by the government
• Processing is necessary in order to protect the vital interests of users or other natural persons
- Detection of, prevention of, and response to fraud, abuse, security risks, and technical issues that may harm users or other natural persons
• Processing is necessary for the performance of a task carried out in the public interest or in the excise of official authority vested in the Company
• Processing is necessary for the purposes of the legitimate interests pursued by the Company or by a third party
(except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child).
3. Disclosure of collected information
• We use the collected information only for following up on sales leads and marketing, advertising, promotions, or other similar purposes.
We do not disclose personal information with a 3rd party except the following:
• when the Company discloses the information with its affiliates, partners, and service providers;
- When the Company's affiliates, partners, and service providers carry out services such as bill payment, execution of orders, products delivery, and dispute resolution (including disputes on payment and delivery) for and on behalf of the Company
• when the users consent to disclose in advance;
- when the user selects to be provided with the information of products and services of certain companies by sharing his or her personal information with those companies
- when the user selects to allow his or her personal information to be shared with the sites or platforms of other companies such as social networking sites
- other cases where the user gives prior consent for sharing his or her personal information
• when disclosure is required by the laws:
- if required to be disclosed by the laws and regulations; or
- if required to be disclosed by the investigative agencies for detecting crimes in accordance with the procedure and method as prescribed in the laws and regulations
4. Cookies, Beacons, and Similar Technologies
The Company may collect collective and impersonal information through 'cookies' or 'web beacons'.
Cookies are very small text files to be sent to the users' browsers by the server used for the operation of the websites of the Company and will be stored on hard disks of the user's computer.
A web beacon is a small quantity of code that exists on websites and e-mails. By using web beacons, we may know whether a user has interacted with certain webs or the contents of the email.
These functions are used for evaluating, improving services, and setting-up users' experiences so that many improved services can be provided by the Company to the users.
The items of cookies to be collected by the Company and the purpose of such collection are as follows:
4.1 strictly necessary cookies
This cookie is a kind of indispensable cookie for the users to use the functions of the website of the Company.
Unless the users allow this cookie, the services such as shopping cart or electronic bill payment cannot be provided.
This cookie does not collect any information which may be used for marketing or memorizing the sites visited by the users.
• Memorize the information entered in an order form while searching other pages during a web browser session.
• Check whether login is made on the website.
• Check whether the users are connected with the correct services of the website of the Company while the Company changes the way of operating its website.
• Connect the users with certain applications or servers of the services.
4.2 performance cookies
This cookie collects information on how the users use the website of the Company such as the information
of the pages which are visited by the users most.
This data helps the Company to optimize its website so that users can search that website more comfortably.
This cookie does not collect any information about who are the users.
Any and all the information collected by this cookie will be processed collectively and anonymity will be guaranteed.
• Web analysis: provide statistical data on the ways of using the website.
• Management of error: measure an error that may occur so as to give help for improving the website.
4.3 functionality cookies
This cookie is used for memorizing the set-ups so that the Company provides services and improves the visits of users.
Any information collected by this cookie does not identify the users individually.
• Memorize set-ups applied such as layout, text size, basic set-up, and colors.
• Memorize when the customer responds to a survey conducted by the Company.
5. Prohibited and Restricted Content
You agree that you will not use totle services to:
• Upload any Content that is unlawful, harmful, threatening, abusive, harassing, tortious, defamatory, vulgar, obscene, pornographic, libelous, invasive of privacy or publicity rights, hateful, or racially, sexually, ethnically, or otherwise objectionable.
• Upload any content that contains software viruses, worms, trojan horses, time bombs, trap doors, or any other computer code, files, or programs or repetitive requests for information designed to interrupt, destroy or limit the functionality of any computer software or hardware or telecommunications equipment or to diminish the quality of, interfere with the performance of, or impair the functionality of the Services or totle. You agree that totle may also delete the contents above without notice.
6. Google Service
6.1 Collection of Google Service Data
The totle does not collect any data when communicating between your computer and Google Services. However, when an error occurs, only error-related data is collected with the consent of the user.
6.2 Storing of user data
The totle stores collected calendar, contacts, tasks, and drive-related data in the OUTLOOK data file or on local computer.
6.3 Collection and use of Information by the Google Service Provider
The collection and use of information by Google Service Provider is not governed by this privacy policy.
Functionally, the Totle exchanges and transmits calendaring data between the User's computer and the Service.
Therefore, please refer to https://policies.google.com/privacy for information about the Google Service Provider's privacy practices.
7. User’s right
The users or their legal representatives, as main agents of the information, may exercise the following rights regarding the collection, use, and sharing of personal information by the Company:
• exercise the right to access personal information;
• make corrections or deletions;
• make temporary suspension of treatment of personal information;
• request the withdrawal of their consent provided before
If, in order to exercise the above rights, you, as a user, use the menu of 'amendment of member information on the webpage or contact the Company by sending a document or e-mail, or using a telephone to the company (or person in charge of the management of personal information or a deputy), the Company will take measures without delay:
Provided that the Company may reject the request of you only to the extent that there exists either proper cause as prescribed in the laws or equivalent cause.
User’s right when applying GDPR
The users or their legal representatives, as main agents of the information, may exercise the following rights regarding the collection, use, and sharing of personal information by the Company:
• The right to access personal information;
- The users or their legal representatives may access the information and check the records of the collection, use, and sharing of the information under the applicable law.
• The right to rectification;
- The users or their legal representatives may request to correct inaccurate or incomplete information.
• The right to erasure;
- The users or their legal representatives may request the deletion of the information after the achievement of their purpose and the withdrawal of their consent.
• The right to restriction of processing;
- The users or their legal representatives may make temporary suspension of treatment of personal information in case of disputes over the accuracy of the information and the legality of information treatment, or if necessary to retain the information.
• The right to data portability
- The users or their legal representatives may request to provide or transfer the information.
• The right to object
- The users or their legal representatives may suspend the treatment of personal information if the information is used for the purpose of direct marketing, reasonable interests, the exercise of official duties and authority, and research and statistics.
• The right to automated individual decision-making, including profiling
- The users or their legal representatives may request to cease the automated treatment of personal information, including profiling, which has a critical impact or cause a legal effect on them.
If, in order to exercise the above rights, you, as a user, use the menu of 'amendment of member information of the webpage or contact the Company by sending a document or e-mail, or using a telephone to the Company (person in charge of the management of personal information or a deputy), the Company will take measures without delay:
Provided that the Company may reject the request of you only to the extent that there exists either proper cause as prescribed in the laws or equivalent cause.
8. Security
The Company regards the security of personal information of uses as very important.
The company constructs the following security measures to protect the user's personal information from any unauthorized access, release, use, or modification.
• Encryption of personal information
- Transmit users' personal information by using an encrypted communication zone.
- Store important information such as passwords after encrypting it.
• Countermeasures against hacking
- Install a system in the zone the external access to which is controlled so as to prevent leakage or damage of users' personal information by hacking or computer virus.
• Establish and execute an internal management plan
• Install and operate the access control system
• Take measures to prevent forging or alteration of access records
9. Measures to Secure Stability of Personal Information
9.1 Conduct regular self-audits
• regularly conduct self-audits to ensure stability in handling personal information.
9.2 Minimizing the Number of Employees Authorized to Handle Personal Information and Education
• Restrict the employees that may handle personal information to the person in charge, and assigns separate passwords therefor and renews such passwords regularly, and totle makes best efforts to comply with totle’s Privacy Policy by providing education from time to time to the persons in charge.
9.3 Establishment and implementation of an internal management plan
For the safe processing of personal information, an internal management plan is established and implemented.
9.4 Technical countermeasures against hacking, etc.
• Security programs are installed and regularly inspected to prevent personal information leakage and damage caused by hacking and computer viruses.
9.5 Encryption of personal information
• Among the personal information of the information subject, passwords, important information, and payment-related information is stored and managed after being encrypted, and for important data, separate security functions are used, such as encrypting files and transmission data or using a file lock function.
9.6 Storage of access records and prevention of forgery
• Records of access to the personal information processing system are kept and managed for at least two years, and security functions are used to prevent forgery, alteration, theft, and loss of access records.
9.7 Restricting access to personal information
• Take necessary measures to control access to personal information by granting, changing, or canceling access rights to the database system that handles personal information, and we control unauthorized access from outside using an intrusion prevention system.
9.8 Using locks for document security
• Documents and auxiliary storage media containing personal information are stored in a safe place with a lock.
9.9 Control of access to unauthorized persons
• Unauthorized persons are prohibited from entering important facilities of the company.
10. Modification of Privacy Protection Policy
The Company has the right to amend or modify this Policy from time to time and, in such case, the Company will make a public notice of it through the bulletin board of its website (or through individual notice such as written document, fax, or e-mail)
and obtain consent from the users if required by relevant laws.
11. Others
11.1 Data transfer to other countries
Considering it engages in global businesses, the Company may provide the user's personal information to the companies located in other countries for the purpose as expressly stated in this Policy.
For the places where personal information is transmitted, retained, or processed, the Company takes reasonable measures for protecting that personal information.
In addition, when personal information obtained from the European Union or Switzerland is used or disclosed, the Company may have to comply with the US-EU Privacy Shield and Swiss-US Privacy Shield, take other measures, or obtain consent from users so far as those comply with the regulations of EU so as to use a standardized agreement provision approved by executing organizations of EU or securing proper safety measures.
11.2 Guide for users residing in California
If the user resides in California, certain rights may be given.
• The Company prepares preventive measures necessary for protecting the personal information of members so that the Company can comply with the online privacy protection laws of California.
• In case of leakage of personal information, a user may request the Company to check the leakage.
• In addition, all the users on the website of the Company can modify their information at any time by using the menu for changing information by connecting their personal accounts.
• Moreover, the Company does not trace the visitors of its website nor use any signals for 'tracing prevent'.
• The Company will not collect and provide any personal identification information through ad services without the consent of users.
11.3 Guide for users residing in Korea
The Company guides several additional matters to be disclosed as required by the information network laws and personal information protection laws in the Republic of Korea as follows:
A. Personal information items to be collected
Personal information items to be collected by the Company are as follows:
a) Information provided by the users
The Company may collect the information directly provided by the users.
Internet membership service
• Name, email address, ID, national information, encoded identification information (CI), identification information of overlapped membership (DI)
• For minors, information of legal representatives (name, birth date, CI and DI of legal representatives)
Online payment service
• Name, address, telephone number, and email address
• Payment information including account number and card number
B. Information collected while the users use services
Besides information directly provided by the users, the Company may collect information in the course that the users use the service provided by the Company.
Equipment information
• Equipment identifier, operation system, hardware version, equipment set-up, type and set-up of the browser, use information of website or application and telephone number
Log information
• IP address, log data, use time, search word input by users, internet protocol address, cookie, and web beacon
Organization information
• Name, job title, department, mail address, phone number, company telephone number
Receipt confirmation information
• Sender/receiver mail address, mail subject
Reservation sending information
• Sender/receiver mail address, mail subject, mail content, mail account user ID, password
a) Period for retention and use of personal information
In principle, the Company destructs personal information of users without delay when: the purpose of its collection and use has been achieved;
the legal or management needs are satisfied, or the users request:
Provided that, if it is required to retain the information by relevant laws and regulations, the Company will retain member information for a certain period as designated by relevant laws and regulations.
The information to be retained as required by relevant laws and regulations are as follows:
• Record regarding contract or withdrawal of subscription: 5 years (The Act on Consumer Protection in Electronic Commerce)
• Record on payment and supply of goods:5 years (The Act on Consumer Protection in Electronic Commerce)
• Record on consumer complaint or dispute treatment: 3 years (The Act on Consumer Protection in Electronic Commerce)
• Record on collection/process, and use of credit information: 3 years (The Act on Use and Protection of Credit Information)
• Record on sign/advertisement: 6 months (The Act on Consumer Protection in Electronic Commerce)
• Log record of users such as internet/data detecting the place of user connection: 3 months (The Protection of Communications Secrets Act)
• Other data for checking communication facts: 12 months (The Protection of Communications Secrets Act)
b) Procedure and method of destruction of personal information
In principle, the Company destructs the information immediately after the purposes of its collection and use have been achieved without delay:
Provided that, if any information is to be retained as required by relevant laws and regulations, the Company retain it for the period as required by those laws and regulations before destruction and, in such event, the personal information which is stored and managed separately will never be used for other purposes.
The Company destructs:
hard copies of personal information by shredding them with a pulverizer or incinerating it; and deleting personal information stored in the form of an electric file by using technological methods making that information not restored.
c) Technical, managerial and physical measures for the protection of personal information
In order to prevent the loss, theft, leakage, alteration, or damage of personal information of the users, the Company takes technical, managerial, and physical measures for securing safety as follows:
(1) Technical measures
• Utilize security servers for transmitting encryption of personal information
• Take measures of encryption for confidential information
• Install and operate access control devices and equipment
• Establish and execute an internal management plan
(2) Managerial measures
• Appoint a staff responsible for protecting personal information
• Provide education and training for staff treating personal information
• Establish and execute an internal management plan
• Establish rules for writing passwords that are hard to be estimated
• Ensure safe storage of records of access to the personal information processing system
• Classify the level of authority to access to the personal information processing system
(3) Physical measures
• Establish and operate the procedure for access control for the facilities for storing personal information
• Store documents and backing storage containing personal information in safe places which have a locking device.
12. Contact information of Company
Please use one of the following methods to contact the Company should you have any queries with respect to this policy or wish to update your information:
Company: e-glue Cloud
Address: 9F, 38, Mapo-daero, Mapo-gu, Seoul, Republic of Korea
Tel: +82-70-4192-7522
E-mail: support@e-glue.co.kr
The Company designates the following Data Protection Officer (DPO) in order to protect the personal information of customers and deal with complaints from customers.
DPO of the Company: Sungha Kim (CMO)
Address: 9F, 38, Mapo-daero, Mapo-gu, Seoul, Republic of Korea
Tel: +82-70-4192-7522
E-mail: support@e-glue.co.kr