Chapter 1 General Provisions
Article 1 (Basic Principles)
nanumsam complies with the personal information protection regulations under the relevant laws and regulations that information and communications service providers must observe, such as the 『Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.』, 『Protection of Communications Secrets Act』, 『Telecommunications Business Act』, and 『Personal Information Protection Act』, and is committed to protecting user rights by establishing a Privacy Policy based on relevant laws.
nanumsam complies with the regulations of Regulation (EU) 2016/679 (hereinafter referred to as "GDPR") in processing personal data in connection with the activities of an establishment in the European Economic Area (hereinafter referred to as "EEA"), offering goods or services to data subjects in the EEA, or monitoring their behavior.
Chapter 2 Categories of Personal Information Collected and Methods of Collection
Article 2 (Personal Information Collected)
nanumsam collects the following personal information for membership registration and management, provision of various services, and marketing purposes at the time of registration, through identity verification, or during the service utilization process.
- General member information such as name, date of birth, address, gender, and age
- Clinical information such as diagnosis name, disease stage, and imaging data (images)
- In the course of using the service, the following information may be automatically generated and collected: (i) IP address, (ii) Cookie, (iii) Browser type and language, and (iv) Service use log.
"Personal Information" specified in this Privacy Policy means information relating to an identified or identifiable natural person, in the same context as "personal data" defined by the GDPR.
Article 3 (Methods of Collecting Personal Information)
nanumsam collects personal information through the following methods:
- Collection through voluntary provision by members during service registration, usage, or identity verification processes
- Automatic collection in the course of utilizing the services provided by nanumsam or technologies used to access the service (e.g., mobile location data, IP address, or phone number)
Chapter 3 Purposes of Collection and Use of Personal Information
Article 4 (Purposes of Collection and Use of Personal Information)
nanumsam collects and uses (processes) members' personal information for the following purposes:
- Membership Registration and Management: Purposes of confirming the user's intent to register, identification and authentication in accordance with the provision of membership services, maintenance and management of membership status, prevention of fraudulent use of services, and notification of changes regarding membership services and nanumsam services overall.
- Provision of Cloud Medical Data Services: Provision of cloud services to manage, operate, and maintain medical data, provide personalized medical services, and improve the quality of medical care.
Chapter 4 Retention and Use Period of Personal Information
Article 5 (Basic Principles of Personal Information Retention and Use Period)
In principle, nanumsam destroys the user's personal information without delay upon membership withdrawal. However, if separate consent is obtained from the user regarding the retention period of personal information, or if relevant laws and regulations impose an obligation to retain information for a certain period, the personal information will be stored safely for the corresponding period.
Article 6 (Statutory Retention Period Required by Law)
Cases where relevant laws and regulations, such as the Act on Consumer Protection in Electronic Commerce, the Electronic Financial Transactions Act, and the Protection of Communications Secrets Act, require the retention of information for a certain period are as follows. nanumsam retains personal information during these periods in accordance with legal regulations and will never use this information for any other purpose.
Act on Consumer Protection in Electronic Commerce
- Records on contracts or withdrawal of subscription, etc.: Retained for 5 years
- Records on payment and supply of goods, etc.: Retained for 5 years
- Records on consumer complaints or dispute resolution: Retained for 3 years
Electronic Financial Transactions Act
- Records on electronic financial transactions: Retained for 5 years
Protection of Communications Secrets Act
- Log-in records: Retained for 3 months
Chapter 5 Destruction of Personal Information
Article 7 (Procedures and Methods for Destruction of Personal Information)
- nanumsam will destroy personal information within 5 days from the expiration of the retention period, or within 5 days from the date when the personal information is deemed unnecessary due to the achievement of processing purposes, abolition of the service, or termination of the business.
- nanumsam selects the personal information for which reasons for destruction have occurred and destroys the personal information with the approval of nanumsam's Privacy Officer.
- nanumsam destroys personal information through the following methods:
- Personal information recorded or stored on paper: Destroyed by shredding with a shredder or by incineration
- Personal information stored in electronic file format: Deleted using technical methods such as low-level formatting so that the records cannot be reproduced
Chapter 6 Provision and Entrustment of Personal Information
Article 8 (Basic Principles of Personal Information Provision and Entrustment)
nanumsam uses members' personal information only within the scope notified in Article 4, and does not use it beyond that scope, nor disclose members' personal information externally or provide it to a third party in principle without the member's prior consent. However, the following cases are exceptions:
- Where the member consents in advance
- Where personal information is processed and provided in a form that cannot identify a specific individual for statistical compilation purposes
- Where requested by investigative agencies or other law enforcement agencies in accordance with the procedures and methods prescribed by laws and regulations for investigative purposes or by provisions of other laws
Article 9 (Entrustment of Personal Information Processing)
nanumsam entrusts part of the necessary work for providing services to external companies, and establishes necessary matters, manages, and supervises them so that the entrusted companies handle personal information safely in accordance with the Information and Communications Network Act.
Entrusted Contractors
Content of Entrusted Work / Retention and Use Period of Personal Information
- Seoul St. Mary's Hospital: Remote consultation/advice/reading, disease trend analysis/statistics | Until membership withdrawal or termination of the entrustment contract
- Seoul National University Bundang Hospital: Remote consultation/advice/reading, disease trend analysis/statistics
- OO Public Health Center: High-risk patient monitoring, comprehensive management
- Data integration and classification of checkup results
Chapter 7 Rights of Members and Methods of Exercise
Article 10 (Right to Protection of Personal Information)
- Members have the following rights regarding their personal information. However, these rights may not be recognized in all circumstances. If a member wishes to exercise any of these rights, nanumsam will guide the member on whether the corresponding right can be exercised.
- The right to request access to personal information
- The right to request rectification if there are errors, etc.
- The right to erasure of personal information (the so-called "right to be forgotten")
- The right to move, copy, or transfer personal information (data portability)
- The right to request suspension of processing
- The exercise of rights under Paragraph 1 can be made to nanumsam in writing, via email, or facsimile (FAX) in accordance with Form No. 8 of the Enforcement Rules of the Personal Information Protection Act.
- If a member requests the rectification or erasure of errors in personal information, nanumsam will not use or provide the personal information until the rectification or erasure is completed.
- The exercise of rights under Paragraph 1 can be carried out through a legal representative or a person who has been delegated, such as an agent. In this case, a power of attorney in accordance with Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
Article 11 (Withdrawal of Consent to Collection, Use, and Provision of Personal Information)
- Members may withdraw their consent to the collection, use, and provision of personal information through membership registration at any time.
- Members may experience restrictions in using the service upon withdrawal of consent under the preceding paragraph.
Chapter 8 Measures to Ensure the Safety of Personal Information
Article 12 (Measures to Ensure the Safety of Personal Information)
nanumsam takes the following technical, managerial, and physical measures necessary to ensure safety in accordance with Article 29 of the Personal Information Protection Act:
- Conducting Regular Internal Audits
Regular internal audits are conducted to ensure safety related to the handling of personal information. - Anonymization of Information
Medical imaging datasets to be stored and managed in the imaging database will be de-identified. - Minimization and Training of Staff Handling Personal Information
Measures are implemented to manage personal information by designating specific employees who handle personal information and minimizing the staff to only those in charge. - Establishment and Implementation of an Internal Management Plan
An internal management plan is established and implemented for the secure processing of personal information. - Technical Countermeasures Against Hacking, etc.
nanumsam installs security programs, performs periodic updates and inspections to prevent leakage and damage to personal information caused by hacking or computer viruses, installs systems in areas where external access is controlled, and monitors and blocks access technically and physically. - Access Restriction to Personal Information
Necessary measures are taken for access control to personal information through granting, changing, and canceling access rights to the database system that processes personal information, and unauthorized external access is controlled using an intrusion prevention system. - Use of Locking Devices for Security
Documents and auxiliary storage media containing personal information are stored in a safe place equipped with locking devices.
Chapter 9 Privacy Officer and Personnel Contact Information
Article 13 (Privacy Officer)
- nanumsam takes overall responsibility for matters related to personal information processing and has designated a Privacy Officer as follows to handle data subjects' complaints and remedy damages in connection with personal information processing.
- Members can inquire about all personal information protection inquiries, complaint handling, damage relief, etc., that occur while using nanumsam's services to the Privacy Officer and the department in charge. nanumsam will respond to and process data subjects' inquiries without delay.
Chapter 10 Matters Concerning Amendments to the Privacy Policy
Article 14 (Amendments to the Privacy Policy)
This Privacy Policy applies from the enforcement date, and if there are additions, deletions, or corrections of changes in accordance with laws and policies, it will be notified through notices from 7 days before the implementation of the changes.
(Amendments to the Privacy Policy)
This Privacy Policy will take effect on June 20, 2026.