BreadDiary (hereinafter "BreadDiary") establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
○ This privacy policy applies from November 1, 2022.
BreadDiary processes personal information for the following purposes. The personal information processed is not used for any purpose other than those below, and where the purpose of use changes, BreadDiary will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
Personal information is processed for the purposes of confirming the intention to register, identifying and authenticating the individual in connection with member services, maintaining and managing membership status, and preventing fraudulent use of the service.
Personal information is processed for the purposes of providing services and providing content.
① BreadDiary processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period consented to by the data subject at the time of collection.
② The processing and retention period for each category of personal information is as follows.
The relevant personal information is retained and used for the above purpose for <1 year> from the date of consent to its collection and use.
Basis for retention: means of member authentication
① BreadDiary processes the following categories of personal information.
Required: email address, cookies
Optional: none
① BreadDiary destroys personal information without delay when it becomes unnecessary, such as upon the expiry of the retention period or the achievement of the processing purpose.
② Where personal information must continue to be preserved under other statutes even though the retention period consented to by the data subject has expired or the processing purpose has been achieved, the personal information is moved to a separate database (DB) or preserved in a different storage location.
1. Statutory basis:
2. Personal information preserved: email address
③ The procedure and method for destroying personal information are as follows.
BreadDiary selects the personal information for which a reason for destruction has arisen and destroys it with the approval of BreadDiary’s personal information protection officer.
Information in electronic file form is destroyed using technical methods that make the records irreproducible.
① Data subjects may exercise rights against BreadDiary at any time, such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information.
② The exercise of rights under Paragraph 1 may be made to BreadDiary in writing, by email, or by facsimile in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and BreadDiary will act on it without delay.
③ The exercise of rights under Paragraph 1 may be made through an agent, such as the data subject’s legal representative or a duly authorized person. In such cases, a power of attorney in the form of Annex No. 11 of the "Public Notice on Methods of Processing Personal Information (No. 2020-7)" must be submitted.
④ Requests for access to personal information and for suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.
⑤ A request for correction or deletion of personal information cannot seek deletion where the personal information is expressly specified as subject to collection under other statutes.
BreadDiary takes the following measures to ensure the security of personal information.
Internal audits are conducted regularly (once per quarter) to ensure security in the handling of personal information.
Measures are implemented to manage personal information by designating the staff who handle it and limiting handling to those persons only.
An internal management plan is established and implemented for the safe processing of personal information.
BreadDiary installs security programs and carries out periodic updates and inspections in order to prevent the leakage or damage of personal information caused by hacking, computer viruses, and similar threats.
Records of access to the personal information processing system are retained and managed for at least one year, and security features are used to prevent access records from being forged, altered, stolen, or lost.
Necessary measures are taken to control access to personal information by granting, changing, and revoking access rights to the database system that processes it, and unauthorized external access is controlled using an intrusion prevention system.
① BreadDiary uses "cookies," which store usage information and retrieve it from time to time, in order to provide individually tailored services to users.
② Cookies are small amounts of information that the server (http) used to operate the website sends to the user’s computer browser, and they may also be stored on users’ devices.
a. Purpose of cookies: used to determine whether the user’s connection is secure and to provide the user with optimized information.
b. Refusing to store cookies may cause difficulties in using the service.
① BreadDiary takes overall responsibility for work relating to the processing of personal information and designates the personal information protection officer below to handle complaints and remedies for data subjects in relation to such processing.
② Data subjects may direct to the personal information protection officer and the responsible department any inquiries, complaints, or requests for remedy relating to personal information protection that arise while using BreadDiary’s services (or business). BreadDiary will answer and handle such inquiries without delay.
Data subjects may submit requests for access to personal information under Article 35 of the Personal Information Protection Act to the department below. BreadDiary will endeavor to ensure that data subjects’ access requests are processed promptly.
▶ Department Receiving and Handling Personal Information Access Requests
Person in charge: SangUk Park
Contact: [email protected]
To obtain relief for an infringement of personal information, data subjects may apply for dispute resolution or consultation to bodies such as the Personal Information Dispute Mediation Committee and the Privacy Infringement Report Center of the Korea Internet & Security Agency. For other reports of and consultations on personal information infringement, please contact the organizations below.
1. Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
2. Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
3. Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)
4. National Police Agency: 182 (ecrm.cyber.go.kr)
A person whose rights or interests are infringed by a disposition made or an omission by the head of a public institution in response to a request under Article 35 (access to personal information), Article 36 (correction or deletion of personal information), or Article 37 (suspension of processing of personal information) of the Personal Information Protection Act may file an administrative appeal as provided by the Administrative Appeals Act.
This privacy policy applies from November 1, 2022.