NHN Corporation (nhncorp.com, hereinafter referred to as “Company” or “NAVER”) complies with the regulations on personal information protection of related legislation, which an information communication service provider must abide by, including Act on Promotion of Information and Communication Network Utilization and Information Protection, Personal Information Protection Act, Communication Privacy Protection Act, Telecommunications Business Act, and does its best to protect user rights by developing Privacy Policy based on the related legislation.
This Privacy Policy is applied to the services provided by NAVER and to me2day, Wingbus and Wingspoon that can be used with a NAVER ID.
<General user registration: register with telephone number>
<Real name user registration: register optionally with resident registration number or i-PIN>
<Group ID registration>
<Foreigner general user registration: register with telephone number>
<Foreigner real name user registration >
NAVER collects personal information using the following:
To provide contents and customized services, to deliver goods or invoices, to conduct self-authentication, to make purchase and payment, to collect fee.
To conduct self-identification for the use of member-only services and for the compliance with limited self-identification policy, to verify personal identity, to prevent dishonest or unauthorized use by delinquent users (users who have permanently been forbidden to use services in accordance with first and second paragraphs of Article 20 of NAVER’s Terms of Use, due to the violation of the subparagraphs 1 to 8, paragraph 1 of Article 11), to verify intention to join membership, to limit acquisition of membership or number of accounts per user, to verify approval from a legal agent when collecting personal information of a user under the age of 14, to verify legal agent’s identity afterward, to retain records for settlement of conflicts, to process civil complaints including customer complaints, to deliver notices.
To develop new services and provide customized services, to provide services and place advertisements based on statistical characteristics, to confirm validity of the service, to provide information on events and advertisement as well as opportunity to participate, to identify access frequency, to make statistics on member’s service usage.
Company uses personal information of users within the scope indicated in “2. Purpose for Collection and Use of Personal Information,” does not go beyond that scope without prior consent of the user, and principally does not disclose personal information of users to third parties. However, the following cases are exceptions.
Company entrusts personal information as the following for the purpose of service enhancement, and in accordance with related legislation presents the necessary regulations upon signing of contract to ensure safe management of entrusted personal information.
Company entrusts personal information to the following organizations for the following purposes.
| Organization | Purpose | Period of retention and use |
|---|---|---|
| NHN I&S Co., Ltd. | Service operation, event prize delivery, customer service support | Until the termination of account by the user or the termination of the contract |
| inComms Co., Ltd., Gplus Co., Ltd. | Customer service | |
| Greenweb Service Co., Ltd. | Service operation | |
| Nplex Co., Ltd. | Photo printing service operation | |
| NHN Business Platform Co., Ltd. | System operation for provision of services | |
| Happybean Foundation | Happybean operation | |
| NHN Technology Services Co., Ltd. | Management of infrastructure, development and testing of services | |
| Skylogis Co., Ltd. | Delivery of service products or event prizes | |
| NICE Group Co., Ltd., National Information and Credit Evaluation Inc., Seoul Credit Rating and Information Inc., Korea Association for ICT Promotion |
Real name verification | Personal information is not saved separately as the corresponding companies are already retaining the information |
| Mobile service providers and credit card companies, which users are using | Self identification |
※ For certain services, customer consultation regarding payment and refund can be carried out by external content providers (click).
In principle, the personal information of users is destroyed without delay once the purpose of collection and use of the personal information has been accomplished. However, the following information will be retained over the described period for the corresponding reasons.
If relevant legislation, including Commercial Law and Act on the Consumer Protection in the Electronic Commerce Transactions states to do so, Company retains the information for the period specified by legislation. In this case, Company uses the retained information only for the purpose of retention, the period of which is as stated below:
In principle, the personal information of users is destroyed without delay once the purpose of collection and use of the personal information has been accomplished. Company destroys personal information following the procedure and method stated below.
NAVER utilizes cookies to provide users with the optimized and customized information including adverts based on the analysis of user’s patterns of visiting and using NAVER’s services and websites, popular search terms as well as the data about connection using SSL, news page editing and number of users.
Company takes the following technical and administrative measures for the purpose of safety acquisition that will prevent loss, theft, leak, falsification or damage of personal information while it is handling the personal information of its users.
Passwords of NAVER user IDs are known only by the users as they are stored and managed in encrypted form, and only the users who know their passwords can view and make changes to their personal information.
Company does its best to prevent leakage or damage of the user’s personal information by hacking or computer viruses.
Company also frequently makes back-up copies of the personal information in case of deterioration, prevents leakage or damage of the information by using the latest vaccine programs, uses encrypted communication to facilitate safe transmission of personal information on the network.
In addition, NAVER controls external intrusion utilizing intrusion prevention system, and does its best to be equipped with all possible technological instruments to ensure system security.
Company restricts handling of the information only to authorized employee who is issued with a separate password, which is periodically updated. The employee in charge of the personal information management is constantly reminded of the importance of adherence to the privacy policy through employee training conducted frequently.
Company also does its best to resolve and correct any problem should it occur, through its special team for privacy protection that monitors enforcement of NAVER Privacy Policy as well as employees’ adherence to it.
However, Company does not take any responsibility for problems related to leakage of ID, password and resident registration number caused by user’s carelessness or internet connection.
You may file all your complaints with regard to personal information protection in NAVER services to the manager or the department in charge of protection of personal information.
Company will swiftly and fully respond to users’ reports.
Please refer to the organizations below for further consultation or report on other cases of personal information infringement:
We notify you that this NAVER Privacy Policy does not apply to the act of collecting personal information by websites linked to NAVER.
In addition, detailed information on protection of personal information in NAVER mobile services is available on NAVER Mobile Privacy Protection page.
Any addition, deletion or modification of this document will be notified through Notification on the homepage at least seven days prior to such revision taking effect. However, if significant changes are made to user rights, including changes to collection and use of personal information and disclosure of the information to third parties, users will be notified at least 30 days prior to intended changes.