Privacy Policy
First announced September 8, 2025 · First effective September 8, 2025
Anyone who wishes to use the website services (the “Service”) of MICHELOROBOTICS Co., Ltd. (the “Company”) must review and agree to this policy.
Article 1 (Purposes of Collecting and Processing Personal Information)
The Company collects and processes personal information for the following purposes. Personal information is not used for any purpose other than those listed below, and if the purpose of use changes, the Company will obtain separate consent in accordance with Article 18 of the Personal Information Protection Act. 1. Member registration and management The Company processes personal information to confirm a customer's intent to join, verify identity for paid services, identify individual users, prevent fraudulent use and unauthorized access by bad-faith users, verify the identity of legal representatives, keep records for dispute resolution, handle customer complaints, and deliver notices. 2. Contract fulfillment and billing for services provided The Company processes personal information to authenticate financial transactions and process payments, deliver goods or invoices, provide services and content, verify age, collect fees, and settle accounts. 3. Handling customer inquiries The Company processes personal information to verify identity, confirm the details of an inquiry, contact the customer for fact-finding, and notify the customer of the outcome. 4. New service development and marketing/advertising The Company processes personal information to develop new services and personalized offerings, provide services and advertising suited to demographic characteristics, verify service validity, and analyze visit frequency or usage statistics. 5. Methods of collecting personal information The Company collects personal information through the following methods: · Website, written forms, fax, phone, consultation boards, email, event entries, delivery requests · Information provided by partner companies · Automated data-collection tools
Article 2 (Processing, Items, and Retention Period of Personal Information)
1. Processing of personal information The Company processes personal information collected with the consent of data subjects and personal information required by law. At initial registration, the Company collects the following information to identify the customer and provide the service: · Required items for warehouse-operator members: business registration number, company name, representative address/landline phone number/representative email, warehouse information, contact person's name/mobile number, etc. (for foreign nationals, alien registration number, passport number, and legal representative information are also included) · Required items for shipper members: business registration number, company name, representative address/landline phone number/representative email, contact person's name/mobile number, etc. · The following information may be generated and collected automatically while using the service or during business processing: IP address, cookies, visit date/time, service usage records, access logs, payment records, shipping performance data, records of fraudulent use (records of any usage restriction imposed on the user) · The following information may be collected only from users of add-on or personalized services, or during event entries (where separate consent for additional collection is obtained). · The following payment information may be collected when using paid services: Credit card payment: card issuer name, card number, etc. Mobile payment: mobile phone number, carrier, payment approval number, etc. Bank transfer: bank name, account number, etc. 2. Retention and use period of personal information In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, the following information is retained for the stated period for the stated reason. 1) Reasons for retention under internal company policy Records of fraudulent use – Retained items: records of abnormal service use – Reason for retention: prevention of fraudulent registration and use – Retention period: 5 years ※ “Records of fraudulent use” means transaction records that violate the terms of use or infringe on the rights or interests of others, including records for which the Company has imposed a usage restriction. 2) Reasons for retention under relevant laws Where retention is required under the Commercial Act, the Act on Consumer Protection in Electronic Commerce, or other relevant laws, the Company retains customer information for the period specified by those laws. In such cases, the Company uses the retained information only for the purpose of retention, and the retention periods are as follows. a. Records related to contracts or withdrawal of subscription – Retained items: subscription, registration, and contract documents (including consent forms) – Legal basis: Act on Consumer Protection in Electronic Commerce – Retention period: 5 years b. Records related to consumer complaints and dispute resolution – Retained items: electronic documents related to customer complaints and disputes – Legal basis: Act on Promotion of Information and Communications Network Utilization and Information Protection – Retention period: 3 years c. Personal information retained in connection with commercial transactions – Retained items: transaction records, electronic financial transaction records, and other electronic documents – Legal basis: Commercial Act, Act on Consumer Protection in Electronic Commerce, Electronic Financial Transactions Act, Framework Act on National Taxes, etc. – Retention period: 5 years d. Survey statistics – Retained items: data containing personal information created after compiling survey statistics – Legal basis: data collection for customer-satisfaction activities and system improvement – Retention period: 5 years e. Website visit records – Retained items: website visit records – Legal basis: Protection of Communications Secrets Act – Retention period: 3 months
Article 3 (Provision of Personal Information to Third Parties)
In principle, the Company processes a data subject's personal information only within the scope of the purposes stated at the time of collection, and does not process it beyond that scope or provide it to third parties without the data subject's prior consent, except in the following cases: · Where prior consent has been given or separate consent is obtained from the data subject · Where there is a special provision in the law · Where the data subject or their legal representative is unable to express intent, or prior consent cannot be obtained due to an unknown address, and it is clearly deemed necessary for the urgent life, body, or property interests of the data subject or a third party · Where it is necessary for compiling statistics or academic research and the personal information is provided in a form that cannot identify a specific individual · Where failing to use the personal information for purposes other than its original purpose, or failing to provide it to a third party, would make it impossible to perform duties prescribed by other laws, and the matter has been reviewed and resolved by the Protection Commission · Where necessary to provide information to a foreign government or international organization in order to implement a treaty or other international agreement · Where necessary for criminal investigation and the filing and maintenance of a public prosecution · Where necessary for a court to carry out its adjudicative duties · Where necessary for the execution of a sentence, custody, or protective disposition
Article 4 (Outsourcing of Personal Information Processing)
The Company does not outsource the processing of personal information. If outsourcing becomes necessary, the Company will document the arrangement covering the matters below, and will disclose any changes through this privacy policy without delay. · Prohibition on processing personal information for purposes other than the outsourced work · Administrative and technical protective measures for personal information · Safety management of personal information The Company also discloses on this website the scope and purpose of any outsourced work, restrictions on re-outsourcing, measures to secure the safety of personal information, oversight of the outsourced party's management of retained personal information, liability for damages if the outsourced party breaches its obligations, and the identity of the party to whom processing is outsourced (the “Trustee”).
Article 5 (Rights and Obligations of Data Subjects and How to Exercise Them)
1. Requesting access to personal information Under Article 35 (Access to Personal Information) of the Personal Information Protection Act, data subjects may request access to the personal information files held by the Company. However, such requests may be restricted under Article 35(5) in the following cases: · Where access is prohibited or restricted by law · Where access is likely to harm the life or body of another person, or unjustly infringe on the property or other interests of another person · Where a public institution would suffer serious disruption to any of the following duties: ① Assessment, collection, or refund of taxes ② Examinations related to academic ability, skills, or hiring, and qualification screening ③ Ongoing evaluation or judgment regarding the calculation of compensation, etc. ④ Audits and investigations in progress under other laws 2. Requesting correction or deletion of personal information Under Article 36 (Correction and Deletion of Personal Information) of the Personal Information Protection Act, data subjects may request correction or deletion of the personal information files held by the Company. However, deletion cannot be requested where the personal information is designated for collection and retention under other laws or under Article 2(2) of this policy. 3. Requesting suspension of processing Under Article 37 (Suspension of Processing of Personal Information, etc.) of the Personal Information Protection Act, data subjects may request suspension of processing using Management Form No. 6 (Withdrawal Request Form), and the Company will act on such requests without delay upon receipt. However, a request to suspend processing may be denied under Article 37(2) in the following cases: · Where there is a special provision in the law, or it is unavoidable in order to comply with a legal obligation · Where it is likely to harm the life or body of another person, or unjustly infringe on the property or other interests of another person · Where a public institution would be unable to perform duties prescribed by other laws if it did not process the personal information · Where failing to process the personal information would make it difficult to fulfill a contract, such as a service agreed upon with the data subject, and the data subject has not clearly expressed an intent to terminate the contract
Article 6 (Destruction of Personal Information)
In principle, the Company destroys personal information without delay once the purpose of processing has been achieved. The procedure, timing, and method of destruction are as follows. · Destruction procedure Information entered by a user for member registration, etc., is moved to a separate database (or a separate filing cabinet, in the case of paper records) once its purpose has been achieved, retained for a set period under internal policy and applicable law (see Retention and Use Period), and then destroyed. Such personal information is not used for any purpose other than retention, except as required by law. · Destruction timing and method Once the retention period has expired, or the purpose of processing has been achieved, or the related business has been discontinued such that the personal information is no longer needed, the Company destroys it without delay. Information in electronic file form is destroyed using a technical method that prevents the record from being reconstructed. Personal information printed on paper is destroyed by shredding or incineration.
Article 7 (Measures to Secure the Safety of Personal Information)
The Company has implemented the following technical and administrative measures to protect personal information. · Minimizing and training staff who handle personal information Only staff who need to handle personal information are designated and managed, and they receive training on secure handling practices. · Restricting access to personal information The Company controls access to the database systems that process personal information by granting, changing, and revoking access privileges, and blocks unauthorized outside access using an intrusion-prevention system. Documents and storage media containing personal information are kept in locked locations. · Retaining and preventing forgery or alteration of access records Records of access to personal-information processing systems (web logs, summary information, etc.) are retained and managed for at least six months, with security features in place to prevent such records from being forged, altered, or lost. · Encryption of personal information Resident registration numbers and passwords are stored and managed securely through encryption. Important data is also encrypted during storage and transmission, among other security measures. Customers themselves should also take care not to expose their password and ID to third parties. · Installing and periodically updating security programs The Company installs security programs and updates and inspects them periodically to prevent personal information from being leaked or damaged by hacking or computer viruses. · Controlling access by unauthorized persons The Company maintains a separate physical location for the systems that store personal information, installs those systems in an access-controlled area, and operates access-control procedures. The Company regularly backs up data to guard against damage, uses up-to-date antivirus software to prevent leakage or damage of users' personal information, and uses encrypted communications to transmit personal information safely over networks. The Company also uses an intrusion-prevention system to block unauthorized external access, and strives to implement every reasonable technical safeguard to secure the system. · Establishing and implementing an internal management plan The Company has established and implements an internal management plan for the safe handling of personal information.
Article 8 (Installation, Operation, and Right to Refuse Automatic Personal-Information Collection Devices, such as Internet Access Files)
The Company's website services do not accept customer registration over the internet; only offline-registered customers can log in to receive services, and the Company does not collect any information via login from non-customers. However, to provide personalized services, the Company operates “cookies,” which repeatedly store and retrieve information from the mobile phones or computers of offline-registered customers. A cookie is a very small text file that a website's server sends to a customer's browser, and it may be stored on the customer's computer hard drive. ※ Purpose of using cookies, etc. Non-customers cannot log in. Customers log in to the website using an ID and password, or, in the case of mobile, a phone number and radio number. A cookie is stored on a registered customer's computer or mobile device the first time the customer's browser is identified. Cookies allow a logged-in customer to maintain their preferences on the “Service” or website and to use personalized services more conveniently. Customers have the option to decide whether to install cookies; by adjusting their browser settings, a customer may allow all cookies, be prompted for confirmation each time a cookie is stored, or refuse the storage of all cookies. ※ How to set up, operate, or refuse cookies To refuse cookies, a customer can choose the browser options to allow all cookies, be asked for confirmation each time a cookie is saved, or refuse the storage of all cookies. Example setup method (Internet Explorer): ① From the [Tools] menu, select [Internet Options]. ② Click the [Privacy] tab. ③ Set the desired [privacy level]. However, if a customer's cookies do not function or have been deleted, the customer may be unable to use the Company's website services.
Article 9 (Contact Information for the Personal Information Protection Officer)
In accordance with Article 31(1) of the Personal Information Protection Act, the Company has designated a Personal Information Protection Officer to handle complaints and remedy damages related to personal information processing, as follows. Personal Information Protection Officer Jangjun Park, CEO, MICHELOROBOTICS Co., Ltd. Contact: 070-4406-0412 Email: contact@michelorobotics.com For reports or consultations regarding other personal-information infringements, please contact the following organizations. · Personal Information Infringement Report Center (privacy.kisa.or.kr / 118, no area code) · Supreme Prosecutors' Office Cyber Crime Investigation Division (www.spo.go.kr / 02-3480-3571) · National Police Agency Cyber Safety Bureau (www.ctrc.go.kr / 182, no area code)
Article 10 (Other)
Please note that this privacy policy does not apply to the practices of any third-party websites linked from the Service's web pages or app.
Article 11 (Duty of Notification)
If this privacy policy is revised due to changes in operating policy or security technology—such as additions, deletions, or amendments to its content—the Company will provide notice through the website's (or app's) notice board (or individual notice) at least 7 days in advance. – Privacy policy first announced: September 8, 2025 – Privacy policy first effective: September 8, 2025
