Privacy Policy
Yonsei SM Pain Clinic (hereinafter “the Clinic”) establishes and discloses the following privacy policy pursuant to Article 30 of the Personal Information Protection Act (PIPA), in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
Article 1 (Purposes of Processing Personal Information)
The Clinic processes personal information for the following purposes. The personal information processed will not be used for any purpose other than those stated below; should the purpose of use change, the Clinic will take the necessary measures, such as obtaining separate consent under Article 18 of the PIPA.
- Appointment booking and consultation: receiving bookings, identity verification, schedule guidance, and processing changes or cancellations
- Provision of medical services: examination, prescription, procedures, and the creation and management of medical records
- Customer support: answering inquiries and handling complaints
- Compliance with legal obligations: retention and reporting required under the Medical Service Act, the National Health Insurance Act, the Income Tax Act, and other relevant laws
- Service improvement: website usage statistics and service quality improvement (statistics that exclude identifying information)
Article 2 (Personal Information Items Processed)
The Clinic processes the following personal information items.
① When booking or consulting via the website
- Required: name, mobile phone number, preferred appointment date and time
- Optional: symptom category, treatment of interest, email address, additional inquiry details
- Additional for new-patient provisional bookings: date of birth
② During treatment (after visiting)
- resident registration number, health insurance information, medical records (symptoms, diagnosis, prescriptions, procedure history), imaging records (X-ray, ultrasound, etc.), and consent forms
③ Automatically collected items
- access IP address, cookies, access logs, service usage records, browser type, operating system information
- SMS verification code (automatically discarded after 5 minutes)
- bot-prevention verification token (Cloudflare Turnstile, discarded immediately after verification)
④ Marketing analytics items (optional, with consent)
- advertising source (UTM source/medium/campaign, gclid), landing page, session identifier — retained for 30 days
Article 3 (Processing and Retention Periods)
The Clinic processes and retains personal information within the retention and use period required by law or within the retention and use period consented to by the data subject at the time of collection. The processing and retention period for each type of personal information is as follows.
| Item | Retention period | Legal basis |
|---|---|---|
| Booking and consultation information (website form) | 1 year | Framework Act on Consumers (dispute resolution) |
| Medical records | 10 years | Enforcement Rule of the Medical Service Act §15, Table 4 |
| Patient register | 5 years | Enforcement Rule of the Medical Service Act |
| Prescriptions | 2 years | Enforcement Rule of the Medical Service Act |
| Operation records and consent forms | 10 years | Enforcement Rule of the Medical Service Act |
| Examination reports and test records | 5 years | Enforcement Rule of the Medical Service Act |
| Radiology and imaging records | 5 years | Enforcement Rule of the Medical Service Act |
| Copies of medical certificates, etc. | 3 years | Enforcement Rule of the Medical Service Act |
| Access logs and IP | 3 months | Protection of Communications Secrets Act |
| Marketing analytics information (UTM, etc.) | 30 days | Period of user consent |
After the retention period expires, the information is destroyed without delay (see Article 5).
Article 4 (Provision of Personal Information to Third Parties)
The Clinic processes personal information only within the scope specified in Article 1 (Purposes of Processing), and provides personal information to third parties only where it falls under Articles 17 and 18 of the PIPA, such as with the consent of the data subject or where specifically provided by law.
- National Health Insurance Service: claims for insurance benefits (National Health Insurance Act)
- Medical dispute mediation bodies and legally authorized agencies: the Korea Medical Dispute Mediation and Arbitration Agency, investigative authorities, etc., upon request based on law
- With the data subject’s own consent: such as issuing documents for insurance claims where the individual has consented
Article 5 (Destruction of Personal Information)
The Clinic destroys personal information without delay once it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.
① Destruction procedure
Information entered by users is, after the purpose is achieved, moved to a separate database (or, for paper, separate files) and stored for a certain period in accordance with internal policy and other relevant laws before being destroyed, or destroyed immediately.
② Destruction method
- Electronic files: destroyed using secure deletion methods that prevent the records from being recovered
- Paper documents: shredded or incinerated
Article 6 (Entrustment of Personal Information Processing)
For smooth personal information processing, the Clinic entrusts personal information processing tasks as follows.
| Entrusted party | Entrusted task |
|---|---|
| Aligo Co., Ltd. [TBD-3 exact company name and address] | Sending appointment guidance, confirmation, and reminder SMS/LMS messages |
| Dr. Palette [TBD-3 exact company name and address] | Operating the electronic medical record (EMR) system and managing booking data |
| Cloudflare, Inc. (USA) | Bot-prevention verification (Turnstile) — overseas processing entrustment |
| [TBD-2 WP hosting provider] | Website hosting and server operation |
When entering into entrustment contracts, in accordance with Article 26 of the PIPA, the Clinic specifies in documents such as the contract the prohibition of processing personal information beyond the purpose of the entrusted work, technical and managerial protective measures, restrictions on re-entrustment, supervision of the trustee, and liability matters such as compensation for damages, and supervises whether the trustee processes personal information safely.
Article 7 (Rights and Obligations of Data Subjects and How to Exercise Them)
Data subjects may exercise the following personal information protection rights with respect to the Clinic at any time.
- Request to access personal information
- Request to correct information where there are errors
- Request to delete information (except information whose retention is mandated by other laws such as the Medical Service Act)
- Request to suspend processing
These rights may be exercised with respect to the Clinic in writing, by telephone, by email, by facsimile (FAX), and the like, pursuant to Article 41(1) of the Enforcement Decree of the PIPA, and the Clinic will act on them without delay.
Where a data subject requests correction or deletion of an error in personal information, the Clinic will not use or provide the personal information in question until the correction or deletion is completed.
Article 8 (Measures to Ensure the Safety of Personal Information)
Pursuant to Article 29 of the PIPA, the Clinic takes the following technical, managerial, and physical measures necessary to ensure safety.
- Managerial measures: establishment and implementation of an internal management plan, and regular staff training
- Technical measures: access-rights management for the personal information processing system, installation of access-control systems, encryption of unique identifying information, and installation of security programs
- Physical measures: access control for the computer room, data storage room, and the like
Article 9 (Installation, Operation, and Refusal of Automatic Collection Devices)
The Clinic uses “cookies” that store and retrieve usage information from time to time in order to provide individually customized services to users.
① Purposes of using cookies
- Analyzing users’ access frequency and visit times
- Tracking users’ advertising source (UTM, gclid) (for measuring marketing effectiveness, retained for 30 days)
- Temporarily storing identity-verification tokens (when using the booking widget)
② How to refuse cookies
Users can allow all cookies, confirm each time a cookie is stored, or refuse the storage of all cookies by configuring the options in their web browser. However, if users refuse to store cookies, they may experience difficulty using some services.
Article 10 (Personal Information Protection Officer)
The Clinic designates a Personal Information Protection Officer as set out below to take overall responsibility for personal information processing and to handle complaints and provide remedies for data subjects in relation to personal information processing.
Personal Information Protection Officer
- Name: Shin Myung-ju
- Position: Director
- Contact: 02-3442-0888
- Email: [TBD-1 official clinic email]
Data subjects may direct any inquiries, complaints, or requests for remedy regarding personal information protection arising from using the Clinic’s services to the Personal Information Protection Officer. The Clinic will respond to and handle the data subject’s inquiries without delay.
Article 11 (Remedies for Infringement of Rights)
Data subjects may inquire about remedies, counseling, and the like for personal information infringement with the agencies below.
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301 (no area code) / www.spo.go.kr
- National Police Agency: 182 (no area code) / ecrm.cyber.go.kr
Article 12 (Changes to the Privacy Policy)
This privacy policy applies from its effective date. Where there are additions, deletions, or corrections of changes pursuant to laws and policy, the changes will be announced through notices from seven days before they take effect.
Effective date: [TBD-4 effective date — now vs. widget beta start date]