SPPSEOGWIPEAN PROJECT
Privacy Policy

Privacy Policy

SPP Co., Ltd. (hereinafter the “Company”) establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes and does not use it for any purpose other than those stated below. If the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

  • Venue rental (MICE) consultation, quotation, and reservation confirmation
  • Review of and reply to partnership and other inquiries
  • Verification of facts and contact in the course of handling inquiries

Article 2 (Items of Personal Information Processed)

The Company collects the following personal information through the inquiry forms on its website. The Company does not accept membership registration on the website and does not collect payment information.

  • Venue rental inquiries: organization name, contact person's name, phone number, email, preferred rental date, rental venue, purpose of rental, required options, additional notes
  • Partnership and other inquiries: name, email, phone number, content of the inquiry
  • Information automatically generated and collected in the course of using internet services: IP address, access date and time, service usage records

Article 3 (Processing and Retention Period of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law, or the retention and use period consented to by the data subject at the time of collection.

  • Inquiry and venue rental consultation records: destroyed within 1 year from the date the inquiry is resolved
  • However, where retention is required under relevant laws, the information is kept until the end of that period.
  • Internet access log records under the Protection of Communications Secrets Act: 3 months

Article 4 (Provision of Personal Information to Third Parties)

The Company processes the personal information of data subjects only within the scope specified in Article 1, and provides it to third parties only where the data subject consents or where Article 17 of the Personal Information Protection Act otherwise applies, such as under special provisions of law. At present, the Company does not provide the personal information of data subjects to any third party.

Article 5 (Consignment of Personal Information Processing)

For the smooth handling of personal information, the Company consigns personal information processing tasks as follows.

  • Consignee: Google LLC — Consigned task: sending, receiving and storing the Company's business email (Google Workspace)

When entering into a consignment agreement, the Company specifies in writing, in accordance with Article 26 of the Personal Information Protection Act, matters such as the prohibition of processing personal information for purposes other than performing the consigned task, technical and administrative safeguards, restrictions on re-consignment, management and supervision of the consignee, and liability including damages, and supervises whether the consignee processes personal information safely. If the content of the consigned task or the consignee changes, the Company will disclose this without delay through this policy.

Article 6 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

A data subject may exercise the following rights against the Company at any time.

  • Request to access personal information
  • Request for correction in the event of errors
  • Request for deletion
  • Request to suspend processing

Rights may be exercised in writing, by telephone, by email, or by other means, and the Company will act on such requests without delay. Where a data subject requests the correction or deletion of errors in personal information, the Company will not use or provide the personal information concerned until the correction or deletion is complete. Rights may also be exercised through the data subject's legal representative or a duly authorized agent, in which case a power of attorney in the form of Attached Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.

Article 7 (Destruction of Personal Information)

When personal information becomes unnecessary, such as upon the expiry of the retention period or the achievement of the processing purpose, the Company destroys it without delay. Personal information recorded and stored in electronic file form is destroyed in a manner that renders the records irrecoverable, and personal information recorded and stored on paper is destroyed by shredding or incineration.

Article 8 (Measures to Ensure the Security of Personal Information)

  • Administrative measures: establishment and implementation of an internal management plan, and staff training
  • Technical measures: management of access rights to personal information processing systems, access control, encryption of data in transit (HTTPS), and installation of security programs
  • Physical measures: access control for areas where records are stored

Article 9 (Installation and Operation of Automatic Personal Information Collection Devices, and Refusal Thereof)

The Company's website does not use cookies to identify users. However, access records may be logged automatically in the course of operating the web server, and these are used solely to ensure the stability of the service and to prevent misuse.

Article 10 (Personal Information Protection Officer and Department for Access Requests)

The Company has designated a personal information protection officer as set out below, who takes overall responsibility for personal information processing and handles complaints and remedies for data subjects in relation to personal information processing.

  • Personal information protection officer and the department receiving and handling access requests: Management Administration Department
  • Contact: 064-735-1455 · lsh@seogwipean.org

Data subjects may direct to the personal information protection officer any matters concerning personal information protection arising from their use of the Company's services, including inquiries, complaints and requests for remedy, and the Company will respond and take action without delay.

Article 11 (Remedies for Infringement of Rights and Interests)

Data subjects may contact the following bodies for remedies, consultation and other matters concerning infringement of personal information.

  • Personal Information Infringement Report Center (Korea Internet & Security Agency): privacy.kisa.or.kr · 118 (no area code)
  • Personal Information Dispute Mediation Committee: www.kopico.go.kr · 1833-6972
  • Supreme Prosecutors' Office Cybercrime Investigation Division: www.spo.go.kr · 02-3480-3573
  • National Police Agency Cyber Investigation Bureau: ecrm.police.go.kr · 182 (no area code)

Article 12 (Effective Date and Amendment of the Privacy Policy)

This privacy policy takes effect on August 1, 2026. Where content is added, deleted or modified due to changes in laws, policies or security technology, notice will be given through the website from 7 days before the effective date of the change.