Privacy Policy

BreadDiary (hereinafter "BreadDiary") establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act of Korea, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

○ This privacy policy applies from November 1, 2022.

Article 1 (Purposes of Processing Personal Information)

BreadDiary processes personal information for the following purposes. The personal information processed is not used for any purpose other than those below, and where the purpose of use changes, BreadDiary will take the necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

1. Website membership registration and management

Personal information is processed for the purposes of confirming the intention to register, identifying and authenticating the individual in connection with member services, maintaining and managing membership status, and preventing fraudulent use of the service.

2. Provision of goods or services

Personal information is processed for the purposes of providing services and providing content.

Article 2 (Processing and Retention Period of Personal Information)

① BreadDiary processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period consented to by the data subject at the time of collection.

② The processing and retention period for each category of personal information is as follows.

< Website membership registration and management >

The relevant personal information is retained and used for the above purpose for <1 year> from the date of consent to its collection and use.

Basis for retention: means of member authentication

Article 3 (Categories of Personal Information Processed)

① BreadDiary processes the following categories of personal information.

1. < Website membership registration and management >

Required: email address, cookies

Optional: none

Article 4 (Procedure and Method for Destroying Personal Information)

① BreadDiary destroys personal information without delay when it becomes unnecessary, such as upon the expiry of the retention period or the achievement of the processing purpose.

② Where personal information must continue to be preserved under other statutes even though the retention period consented to by the data subject has expired or the processing purpose has been achieved, the personal information is moved to a separate database (DB) or preserved in a different storage location.

1. Statutory basis:

2. Personal information preserved: email address

③ The procedure and method for destroying personal information are as follows.

1. Destruction procedure

BreadDiary selects the personal information for which a reason for destruction has arisen and destroys it with the approval of BreadDiary’s personal information protection officer.

2. Destruction method

Information in electronic file form is destroyed using technical methods that make the records irreproducible.

Article 5 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)

① Data subjects may exercise rights against BreadDiary at any time, such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information.

② The exercise of rights under Paragraph 1 may be made to BreadDiary in writing, by email, or by facsimile in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and BreadDiary will act on it without delay.

③ The exercise of rights under Paragraph 1 may be made through an agent, such as the data subject’s legal representative or a duly authorized person. In such cases, a power of attorney in the form of Annex No. 11 of the "Public Notice on Methods of Processing Personal Information (No. 2020-7)" must be submitted.

④ Requests for access to personal information and for suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ A request for correction or deletion of personal information cannot seek deletion where the personal information is expressly specified as subject to collection under other statutes.

Article 6 (Measures to Ensure the Security of Personal Information)

BreadDiary takes the following measures to ensure the security of personal information.

1. Conducting regular internal audits

Internal audits are conducted regularly (once per quarter) to ensure security in the handling of personal information.

2. Minimizing and training the staff who handle personal information

Measures are implemented to manage personal information by designating the staff who handle it and limiting handling to those persons only.

3. Establishing and implementing an internal management plan

An internal management plan is established and implemented for the safe processing of personal information.

4. Technical measures against hacking and similar threats

BreadDiary installs security programs and carries out periodic updates and inspections in order to prevent the leakage or damage of personal information caused by hacking, computer viruses, and similar threats.

5. Retaining access records and preventing forgery or alteration

Records of access to the personal information processing system are retained and managed for at least one year, and security features are used to prevent access records from being forged, altered, stolen, or lost.

6. Restricting access to personal information

Necessary measures are taken to control access to personal information by granting, changing, and revoking access rights to the database system that processes it, and unauthorized external access is controlled using an intrusion prevention system.

Article 7 (Installation, Operation, and Refusal of Automatic Collection Devices)

① BreadDiary uses "cookies," which store usage information and retrieve it from time to time, in order to provide individually tailored services to users.

② Cookies are small amounts of information that the server (http) used to operate the website sends to the user’s computer browser, and they may also be stored on users’ devices.

a. Purpose of cookies: used to determine whether the user’s connection is secure and to provide the user with optimized information.

b. Refusing to store cookies may cause difficulties in using the service.

Article 8 (Personal Information Protection Officer)

① BreadDiary takes overall responsibility for work relating to the processing of personal information and designates the personal information protection officer below to handle complaints and remedies for data subjects in relation to such processing.

▶ Personal Information Protection Officer

Name: SangUk Park

Contact: [email protected]

② Data subjects may direct to the personal information protection officer and the responsible department any inquiries, complaints, or requests for remedy relating to personal information protection that arise while using BreadDiary’s services (or business). BreadDiary will answer and handle such inquiries without delay.

Article 9 (Department Receiving and Handling Requests for Access to Personal Information)

Data subjects may submit requests for access to personal information under Article 35 of the Personal Information Protection Act to the department below. BreadDiary will endeavor to ensure that data subjects’ access requests are processed promptly.

▶ Department Receiving and Handling Personal Information Access Requests

Person in charge: SangUk Park

Contact: [email protected]

Article 10 (Remedies for Infringement of Data Subjects’ Rights)

To obtain relief for an infringement of personal information, data subjects may apply for dispute resolution or consultation to bodies such as the Personal Information Dispute Mediation Committee and the Privacy Infringement Report Center of the Korea Internet & Security Agency. For other reports of and consultations on personal information infringement, please contact the organizations below.

1. Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)

2. Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)

3. Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)

4. National Police Agency: 182 (ecrm.cyber.go.kr)

A person whose rights or interests are infringed by a disposition made or an omission by the head of a public institution in response to a request under Article 35 (access to personal information), Article 36 (correction or deletion of personal information), or Article 37 (suspension of processing of personal information) of the Personal Information Protection Act may file an administrative appeal as provided by the Administrative Appeals Act.

Article 11 (Changes to the Privacy Policy)

This privacy policy applies from November 1, 2022.