Doosan Enerbility Co., Ltd. (hereinafter "Company") complies with the relevant laws and regulations dealing with personal information protection, including the Personal Information Protection Act and the Act on Promotion of Information Communications Network Utilization and Information Protection. The Company is doing its utmost to protect the rights and interests of its customers and Documents Protection System users (hereinafter "Data Subjects") in accordance with the Privacy Policy on Handling of Personal Information, which was devised based on the relevant laws.
The Privacy Policy on Handling of Personal Information is used by the Company to notify the data subjects of how and for what purpose the personal information is being used and what measures are being taken for the protection of personal information. In the event of any amendments to the policy, notification will be given on the amendments via the Documents Protection System or individual notice.
The Company greatly values the personal information of its customers or data subjects who are users of Documents Protection Service (share.protection.doosan.com) and as such, does its best to ensure the protection of such personal information. To this end, the Company is complying with the relevant laws, such as the Personal Information Protection Act and the Act on Promotion of Information Communications Network Utilization and Information Protection (hereinafter "Information Communications Network Act").
Article 1.Scope of Collected Personal Information
- The Company uses fair and lawful methods to collect the data subjects' personal information.
- The personal information collected by the Company shall be limited to the minimum information that is required for the provision of services, and unless permitted by law or given consent by the data subject, the Company shall not collect any sensitive personal information, which has the risk of clearly infringing upon the privacy of data subjects (personal ideology & beliefs, political views, health, sexual orientation, genetic information, criminal record, etc.), nor shall any personal identification information that can be used to identify specific individuals be gathered.
Article 2.Types of Personal Information Collected & Data Collecting Method
The types of personal information collected by the Company on the data subjects are as listed below. During the course of using the company website, the data items specified under No. 2 may be automatically generated and collected.
-
Provision of permission to use service
- Required items: Email address
- Optional items: none
-
Service analysis and service level improvement: automatically generated and collected during the Internet service use process
- Service usage records, access logs, cookies, access IP, connected device, Email address information
Article 3.Collection of Personal Information & Purpose of Collected Information
The Company collects the personal information of data subjects for the following purposes.
-
Customer Related Information
- External site use and grant permission processing: service permission registration, etc.
- Analysis of Services & Enhancement of Service Quality: By analyzing the service usage, the users are provided with better services and an improved Documents Protection Service (Analysis of services and enhancement of service quality), etc.
Article 4.Personal Information Retention & Usage Period
-
External site use and grant permission processing
- Data Held: Email address
- Retention Period: 1 year
-
Analysis of Service & Enhancement of Service Quality
- Data Held: Service usage log, access log, cookies, IP connection, connected device, Email address information
- Retention Period: Within 1 year after expiration of period of use and permission
Article 5.Personal Information Disposal Process & Method
-
Disposal Process
The Company shall dispose of the personal information within 1 year from the end of the personal information retention and usage period. If the personal information is no longer needed owing to reasons, such as fulfillment of the purpose of the personal information handling, shutdown of the relevant service or closing of the business, the personal information shall be disposed of within five days from the day it was recognized that the information is no longer needed.
-
Disposal Method
- Personal Information on Paper & Printouts : To be shredded or incinerated
- Personal Information Saved in Electronic File Format: To be permanently deleted using technology that prevents recovery of the deleted records
Article 6.Disclosure of Personal Information to Third Parties
The Company shall not disclose any of the personal information to third parties without just cause, unless it is required by law or prior consent was obtained from the data subject. However, the following cases shall be exceptions.
- Consent was obtained from the data subject
- Disclosure of the information is requested in specific provisions of relevant laws or is deemed unavoidable if one wishes to fulfill legal obligations
- The data subject or his/her legal representative is in a state in which an opinion or intent cannot be expressed or prior consent cannot be gained owing to an invalid address, but disclosure to a third party is urgently needed for the sake of the data subject or third party's life, physical well-being or the person's interests, such as those related to his/her property
Article 7.Commissioning of Personal Information Handling Service
The Company commissions an outside agency to handle some of the work required for provision of services and has a set of regulations set up to manage and monitor matters for the purpose of ensuring that the personal information can be safely handled as stipulated in the relevant laws. The commissioned service for handling of personal information is as follows.
Article 7.Commissioning of Personal Information Handling Service Table
Provides details of the trustee and the entrusted work.
| Information Recipient |
Description of Commissioned Service |
| Doosan Corporation Digital Innovation |
Operation & Management of System (Maintenance) |
Article 8.Rights & Obligations of Data Subjects and Method for Exercising Rights
- The data subjects may request for the viewing, modification or withdrawal of consent at any time in regard to their personal information. Should the data subject contact the department in charge of personal information in order to file a written request or make a request by phone or email, proper action shall be immediately taken without delay to address the matter.
- In the event of a request by the data subject for the correction of an error in his/her personal information, the Company shall not use or disclose the personal information until correction of the error has been completed.
- In the case of minors who are of the age 14 or younger, the child's legal representative has the right to view or amend the child's personal information, as well as the right to withdraw the consent given on the collection and usage of personal information.
- In the event of a request for the cancellation or deletion of personal information by the data subject or his/her legal representative, this shall be handled in accordance with the Privacy Policy on Handling of Personal Information, and the personal information shall not be viewed or used for any other purposes.
Article 9.Installation, Operation or Declining of Automatic Personal Data Collecting Tool
- The Company operates "cookies" which are used to store and track information about the data subjects. Cookies are small blocks of text files that are sent by a website server to be stored on the user's computer hard drive.
- The data subject has the option of choosing to accept the cookies or not. Options can be set to either accept all cookies, confirm each time a cookie is about to be stored or decline all cookies. However, if the data subject decides to decline installation of the cookies, some difficulties may be encountered in using the services.
Article 10.Personal Information Safeguarding Measures
In accordance with Article 29 of the Personal Information Protection Act and Article 28 of the Information Communications Network Act, the Company is taking technical, administrative and physical measures aimed at ensuring the security of personal information.
-
Personal information handling personnel kept to a minimum
- To ensure the protection of personal information, minimal authority is granted to those assigned with handling personal information.
-
Training conducted on regular basis for relevant personnel
- Training is conducted on a regular basis to promote awareness of the importance of personal information protection.
-
Internal inspections conducted on regular basis
- The Company conducts inspections on a regular basis to ensure the security of personal information.
-
Creating and implementing personal information management plans
- The Company shall create and manage a corporate plan for the safe handling and management of personal information.
-
Encryption of Personal Information
- The data subject's personal information and password are stored and managed in encrypted format and a security mechanism is applied in the data transmission process to ensure that the data is safely managed.
-
Anti-Hacking Measures
- The Company has security programs installed to prevent personal information leaks and damages from occurring due to computer hacking or virus infections, and has periodic updates and inspections performed, which may lead to the installation of security systems in designated off-limits areas, enabling the Company to perform technical and physical surveillance and protect the system against infiltrations.
-
Restriction of Access to Personal Information
- Measures such as granting, changing and cancelling of authority for accessing the personal information management system are being taken to effectively control the access to personal data, and an infiltration prevention system is being used to control unauthorized access by outsiders.
-
Storing of Access Logs and Prevention of Forgeries
- A system access log containing records of the access made to the personal information management system is stored and managed for a minimum period of six months, and a security mechanism is used to prevent any data forgery, theft or loss from occurring to the log.
-
Lock Devices Used for Document Security
- Documents and data storage devices containing personal information are kept in a safe place with a lock device.
-
Access Control for Unauthorized People
- A separate physical location for storing personal information is kept, with an access control process being set up and applied.
However, the Company shall not be liable for incidents that arise due to the data subject's own fault or owing to basic risks inherent in the Internet.
Article 11.Personal Information Protection Administrator and Managing Department
-
The Company has appointed the following department and person to be in charge of the protection of personal information and the handling of associated complaints.
-
Personal Information Protection Administrator
- Name : Sunjung Kim, Vice President, CISO
- Email : de.privacy@doosanenerbility.com
-
Department in Charge of Personal Information Protection Administrator
- Department : IT Team
- Name : Heemoon Yang, Team Leader
- Email : de.privacy@doosanenerbility.com
-
Department in Charge of Personal Information Protection Staff
- Department : IT Team
- Name: Beomjin Chae
- Tel : +82 31 5179 3100
- Email : beomjin.chae@doosan.com
-
Should you need to file a report or receive consultation on a personal information infringement case, please contact the following agencies.
- Korea Internet & Security Agency (KISA)'s Personal Information Infringement Reporting Center (https://privacy.kisa.or.kr Tel : 118)
- Supreme Prosecutor's Office Cybercrime Investigation Division (www.spo.go.kr Tel : 1301)
- Korean National Police Agency's Cyber Security Division (www.cyberbureau.police.go.kr Tel : 182)
Article 12.Notice of revision of personal information processing policy
If there is an addition, deletion, or modification of the contents of this personal information processing policy, the reason and contents of the change will be announced through the website before implementing the changed personal information processing policy.
Enforcement date :