GinnoLab (the Company) establishes and publishes this Privacy Policy under Article 30 of Korea's Personal Information Protection Act to protect personal data and promptly and effectively handle related concerns.
| Company / Representative | GinnoLab / Jinho Yoon |
|---|---|
| Address | Room 203, 22 Sicheong-ro, Wonju-si, Gangwon State, Republic of Korea |
| Industry | Manufacturing (small workplace with four regular employees) |
| Publication Method | Permanently linked from the website footer and displayed on the workplace noticeboard |
| Effective Date / Revision | Effective 24 August 2026 / Rev.0 (initial issue) |
Article 1. Purposes of Processing
The Company processes personal data for the purposes below and does not use it for other purposes. If purposes change, it takes required measures, including separate consent, under Article 18 of the Personal Information Protection Act.
| Category | Purpose |
|---|---|
| Human Resources and Labor Management | Recruitment, employment contracts, payroll and social insurance, attendance and service administration, training records, separation and severance settlement, and statutory recordkeeping |
| Business Partner Management | Identify contacts; conclude and perform contracts; manage orders, deliveries and inspections; invoice and settle payments; communicate transaction matters; resolve disputes |
| Inquiry Handling | Confirm and respond to product inquiries, quotation requests, complaints and grievances received through the website, telephone or email |
| Statutory Compliance | Prepare, retain and submit records required by tax, labor, occupational safety and health, and other applicable laws |
Article 2. Personal Data Processed
Anonymous Grievances & Suggestions: Anonymous submission formdoes not require login, name, email or telephone number. It stores the category, title, message, receipt number, submission time and processing status, accessible only to designated personnel. Do not include unnecessary personal information in your message. IP addresses and browser information are not separately stored with reports, although hosting-provider security and access logs may be generated. The contact fields required for general website inquiries below do not apply to the anonymous form.
The Company processes the following data. As a small workplace, it does not operate public membership registration and limits data to what is necessary for its work.
| Data Subject | Data Collected | Collection Method | Basis for Collection |
|---|---|---|---|
| Employees (including job applicants) |
Required: name, date of birth, contact details, address, email, bank account, education and work history Legally required: resident registration number, solely for payroll and statutory social insurance reporting Optional: qualifications, emergency contact and family relationships where relevant to family allowances or year-end tax settlement |
Job applications and paper or electronic documents submitted when employment contracts are concluded | Article 15(1)(1), (2) and (4) (consent, statutory obligations and contract performance) Resident registration number: Article 24-2(1)(1) |
| Business partner contacts | Required: company, department and position, contact person's name, telephone and email Optional: fax number |
Contracts, business cards, orders, quotations and received emails | Article 15(1)(4) (necessary to conclude or perform a contract) |
| Website inquirers | Required: name or company name, telephone or email, and inquiry content Automatically generated: access IP address and date/time |
Website inquiry form | Article 15(1)(1) (consent) |
Article 3. Processing and Retention Periods
The Company processes and retains data for the period prescribed by law or consented to at collection. The periods for each activity are listed below.
| Processing Activity | Retention Period | Legal Basis |
|---|---|---|
| Human Resources and Labor Management | 3 years after employment ends | Article 42, Labor Standards Act (retention of employment records) |
| Payroll and withholding tax records | 5 years after the filing deadline | Article 85-3, Framework Act on National Taxes |
| Eligibility acquisition and loss for the four statutory social insurance programs | 3 years | National Pension Act, Employment Insurance Act and related laws |
| Occupational safety and health records, including training and medical examination results | 3 years generally; 5 years for medical examination results | Enforcement Rule of the Occupational Safety and Health Act |
| Business partner contact information | 5 years after the business relationship ends | Article 33, Commercial Act; Article 85-3, Framework Act on National Taxes |
| Transaction evidence, including tax invoices | 5 years | Article 71, Value-Added Tax Act |
| Website inquiry records | 1 year after handling is completed | Individual consent |
| Unsuccessful job applicant information | 3 months after recruitment ends; 1 year with separate retention consent | Article 11, Fair Hiring Procedure Act |
| Personal data system access logs | 1 year (2 years when processing data of 50,000 or more individuals) | Article 8, Standards for Ensuring the Safety of Personal Information |
Article 4. Third-Party Disclosure
- The Company processes personal data only within the purposes stated in Article 1 and discloses it to third parties only where permitted by Articles 17 and 18 of the Personal Information Protection Act, including consent or specific statutory grounds.
- The Company does not disclose or sell personal data to third parties for marketing.
- The Company regularly provides personal data to the following recipients as required by law.
| Recipient | Purpose of Disclosure | Data Disclosed | Retention and Use Period |
|---|---|---|---|
| National Health Insurance Service, National Pension Service, Korea Workers' Compensation & Welfare Service, and competent tax office | Statutory obligations including social insurance reporting and reconciliation and withholding tax | Name, resident registration number, address, contact details and remuneration | Period required by applicable law |
| Company-appointed payroll transfer bank | Salary and expense transfers | Name and bank account number | Until the transfer is completed |
| Company-appointed medical examination provider | Medical examinations under the Occupational Safety and Health Act | Name, date of birth, affiliation and contact details | 5 years after the medical examination |
Article 5. Outsourced Processing
The Company outsources the following personal data processing activities for efficient operations.
| Processor (service provider) | Outsourced Work | Processing Term |
|---|---|---|
| Kim Seunghyeon Tax & Accounting Office | Payroll calculation, statutory social insurance reporting and tax filing services | Until the service contract ends |
| Website maintenance provider (name disclosed upon appointment) | Website operation and maintenance and inquiry-board management | Until the service contract ends |
| Document shredding contractor (name disclosed upon appointment) | Destruction of paper documents containing personal data | Until destruction is completed |
- Under Article 26 of the Personal Information Protection Act, outsourcing contracts specify purpose limitations, technical and organizational safeguards, subcontracting restrictions, supervision, liability and compensation obligations.
- Changes to outsourced work or service providers will be disclosed promptly in this Privacy Policy.
Article 6. Deletion Procedures and Methods
- When personal data is no longer needed because its retention period or purpose has ended, the Company deletes it without delay, within five days of the reason arising.
- If another law requires continued retention after the consented period or purpose ends, move the data to a separate database or storage location.
1. Deletion Procedure The privacy officer identifies data due for deletion and deletes it with the approval of the CEO, who also serves as Chief Privacy Officer. Record deletion results in the Personal Data Deletion Register and retain them for three years.
2. Deletion Methods
| Storage Format | Deletion Method |
|---|---|
| Electronic files | Permanently delete using dedicated deletion software so recovery is impossible. When disposing of media, physically destroy it by drilling or incineration, or degauss it. |
| Paper and printed documents | Shred or incinerate. Obtain a destruction certificate when using a contractor. |
Article 7. Individual and Representative Rights, Duties and Procedures
- Individuals may at any time request access, correction, deletion or suspension of processing, withdraw consent, or object to and request explanations of automated decisions where applicable.
- Rights may be exercised in writing, by email or fax under Article 41 of the Enforcement Decree of the Personal Information Protection Act. The Company will act without delay.
- When an individual requests correction or deletion of inaccurate personal data, the Company will not use or disclose it until correction or deletion is complete.
- A legal representative or authorized agent may exercise rights. Submit a power of attorney using Form 11 attached to the Notice on Methods of Processing Personal Information.
- Access and processing-suspension rights may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act.
- Individuals must not unlawfully infringe personal data or privacy handled by the Company.
| Right | Response Deadline | How to Submit |
|---|---|---|
| Access request | Within 10 days of receipt | Visit the business address, call +82 10-9201-2448, Email ceo@ginnolab.com; fax +82 504-958-1746 Identity verification, such as an identification document check, is required upon receipt. |
| Correction or deletion request | Within 10 days of receipt | |
| Processing-suspension request | Within 10 days of receipt | |
| Withdrawal of consent | Immediately upon request |
Article 8. Security Safeguards
The Company takes the following safeguards under Article 29 of the Personal Information Protection Act and the Standards for Ensuring the Safety of Personal Information.
| Category | Action |
|---|---|
| Organizational Measures | · Establish and implement an internal personal data management plan and review implementation annually · Limit authorized personal data handlers to the minimum necessary for work · Train personal data handlers at least annually and obtain confidentiality pledges |
| Technical Measures | · Differentiate access permissions to personal data systems, including PCs, and keep records of permission changes and revocations · Set account passwords of at least eight characters combining letters, numbers and special characters, and change them every six months · Encrypt unique identifiers, passwords and account numbers in storage and apply safeguards during transmission · Retain system access logs for at least one year, review monthly and protect against alteration · Install and automatically update anti-malware software · Set work PC screensavers to activate after 10 minutes and prohibit internet-sharing settings |
| Physical Measures | · Store documents and media containing personal data in locked cabinets · Control office access and lock the premises outside working hours · Require prior approval before removing personal data from the workplace |
Article 9. Automatic Collection Technologies and Opt-Out
- The Company may use cookies that store and retrieve usage information to provide personalized services.
- Cookies are small pieces of information sent by a web server to a user's browser and may be stored on the user's computer.
- Cookie purposes: website visit records, service improvements based on usage patterns, and convenient inquiry handling
- Cookie settings and refusal: use the browser's Tools > Internet Options > Privacy settings to reject cookies.
- Refusing cookies may limit personalized services, but does not restrict basic functions such as viewing the website or submitting inquiries.
- The Company does not operate online behavioral advertising that collects, uses or discloses user behavioral information.
Article 10. Pseudonymized Information
The Company does not currently process pseudonymized data for statistics, scientific research or public-interest archiving. If it does so in future, it will disclose the purposes, data, use periods, third-party provision and safeguards in this policy under Articles 28-2 through 28-7 of the Personal Information Protection Act.
- Keep additional information needed to reverse pseudonymization separately.
- Do not process pseudonymized data to identify an individual. If identifying information is generated, immediately stop processing and retrieve and delete it.
- Create and retain records of pseudonymized data processing, including purposes and recipients of third-party disclosures.
Article 11. Privacy Officers and Grievance Contact
The Company appoints the following Chief Privacy Officer to oversee processing and handle privacy complaints and remedies. As a small workplace with four regular employees, CEO Jinho Yoon also serves as Chief Privacy Officer under Article 32(2) of the Enforcement Decree of the Personal Information Protection Act.
| Category | Name / Position | Contact | Responsibilities |
|---|---|---|---|
| Chief Privacy Officer | Jinho Yoon / CEO | Telephone +82 10-8965-7458 Email ceo@ginnolab.com | Overall privacy management, policy establishment and revision, safeguard implementation review, and breach response oversight |
| Privacy Officer (Grievance contact) | Gibeom Kwon / ESG Officer | Telephone +82 10-9201-2448 Email coo@ginnolab.com | Receive access, correction, deletion and suspension requests; handle privacy concerns; support staff training; review access logs |
Contact the Chief Privacy Officer or responsible department for privacy inquiries, complaints or remedies arising from Company services. The Company will respond and act without delay.
Article 12. Domestic Representative
As a business with an address or place of business in Korea, the Company is not subject to the domestic representative requirement in Article 31-2 of the Personal Information Protection Act.
Article 13. Remedies for Privacy Infringements
Individuals may seek dispute resolution or advice from the Personal Information Dispute Mediation Committee or KISA Privacy Infringement Report Center. Other privacy-related reports and consultations may be directed to the organizations below.
| Organization | Responsibilities | Telephone | Website |
|---|---|---|---|
| Personal Information Dispute Mediation Committee | Personal data dispute mediation and collective dispute mediation (civil remedies) | 1833-6972 | www.kopico.go.kr |
| Privacy Infringement Report Center (Korea Internet & Security Agency) | Report privacy infringements and request advice | 118 (within Korea, no area code) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | Investigation and consultation on personal data-related crimes | 1301 (within Korea, no area code) | www.spo.go.kr |
| Korean National Police Agency Cyber Investigation Bureau | Investigation and reporting of personal data-related crimes | 182 (within Korea, no area code) | ecrm.police.go.kr |
Article 14. Changes to This Policy
- This Privacy Policy applies from 24 August 2026.
- When laws, policies or security technology require additions, deletions or amendments, announce the reasons and changes on the website and workplace noticeboard at least seven days before taking effect, or 30 days for changes materially affecting individual rights.