Privacy Policy
Korea Digital Exchange (referred to as the ‘Company' hereafter) protects users’ personal information and interests according to the Act on Promotion of Information Network Usage and Information Protection and takes following measures to smoothly handle users’ complaints related to personal information The privacy policy applies to all services of the company's website (https://flybit.com), and separate privacy policy may apply to the services provided by other websites. The company will notify you through the website announcement (or individual notice) when revising the privacy policy.
1. Purpose of processing personal information
The Company uses the collected personal information for the following purposes. The processed personal information will not be used for any purpose other than the following purposes and will be subject to prior agreement if the purpose of use is changed
1) Membership and its management
Checking the intend to join the membership, identification and verification based on membership service provision, maintenance and management of membership status, prevention of illegal use of services. We process the personal information for the purposes of; notifying of various notices, handling complaints, and record keeping for dispute settlement, etc.
2) Providing goods or services
We process the personal information for the purposes of; providing services, contents, and personalized services, or verifying yourself.
3) Marketing and advertising
We process the personal information for the purposes of; developing new services(products) and providing customized services, providing event and advertisement information and participation opportunity, providing services and advertising according to demographic characteristics, validation of services, understanding access frequencies or statistics on member's use of services.
4) Provide data for investigation agencies
We process personal information by providing data in case of a legitimate and legitimate inquiry based on investigation of hacking / fraud incidents and other statutory obligations
2. Processing and retention period of personal information
The company processes following personal information.
1) Personal Information Items:
(Mandatory Items) E-mail, Mobile phone number, Login ID, Password, Name, Gender, Date of birth
(Optional Items) Bank account number, ID card with the latter 7 digits of resident registration number masked, Photo of you holding an ID card, (Information that is automatically generated during the course of service use or process) Service usage history, Access log, Cookie, IP address accessed, Deposit/Withdrawal information
2) Collection Method: The members provide the personal information directly when joining membership or verifying yourself.
3) Retention Basis: Your consent
4) Retention Period: Until you terminate your membership or withdraw your consent to use the personal information. However, if there is a record of fraudulent use or suspected fraudulent use by a user pursuant to the terms of use of the company, despite the termination request of membership or the withdrawal of consent to use personal information from the user, the personal information is stored for 5 years from the time of collection until destroyed.
5) Despite the Company’s privacy policy, the personal Information required to be kept under the following laws and regulations shall be kept for the period prescribed by the relevant laws and regulations
① Personal information related to the use of services (Login records)
- Retention Basis: Communication Confidentiality Protection Law
- Retention Period: 3 months
② Records of display / advertisement
- Retention Basis: Consumer Protection Act in Electronic Commerce, etc.
- Retention Period: 6 months
③ Records on contract or withdrawal
- Retention Basis: Consumer Protection Act in Electronic Commerce, etc.
- Retention Period: 5 years
④ Records of payment or supply of goods
- Retention Basis: Consumer Protection Act in Electronic Commerce, etc.
- Retention Period: 5 years
⑤ Records on consumer complaints or disputes
- Retention Basis: Consumer Protection Act in Electronic Commerce, etc.
- Retention Period: 3 years
⑥ Records on electronic financial transactions
- Retention Basis: Electronic Financial Transaction Law
- Retention Period: 5 years
3. Consignment of Personal information processing
1) The Company does not disclose your personal information to any external organization. However, in a case that you consents directly to the provision of your personal information to the third party, you are obligated to provide the personal information to the Company in accordance with the relevant laws and regulations, or to resolve issues provided that the immediate danger to the user's life or safety is identified, we provide the personal information.
2) The company consigns the personal information processing as follows for smooth personal information processing
- Consignee : NICE Information Service Co., Ltd
- Consignment Service: Checking real subscriber name of your mobile phone, SMS verification service
- Provision Item: Name, Gender, Date of birth, Mobile phone number, Mobile phone service provider
- Consignment Period: Until you terminate your membership or withdraw your consent to use the personal information
- Consignee : Mail Link
- Consignment Service: SMS or e-mail service
- Provision Item: Name, E-mail, Mobile phone number
- Consignment Period: Until you terminate your membership or withdraw your consent to use the personal information
- Consignee : Surem Co., Ltd
- Consignment Service: International SMS Service
- Provision Item: Name, E-mail, Mobile phone number
- Consignment Period: Until you terminate your membership or withdraw your consent to use the personal information
- Consignee : Coocon Co., Ltd
- Consignment Service: Deposit and Withdrawal Service
- Provision Item: Name of account holder, Name of financial institution, Account number
- Consignment Period: Until you terminate your membership or withdraw your consent to use the personal information
- Consignee : Zendesk, Inc
- Consignment Service: Deposit and Withdrawal Service
- Provision Item: Details required for the Consultation; Name, E-mail, Mobile phone number, Date of birth, Member ID, Withdrawal breakdown, Deposit breakdown, and etc.
- Consignment Period: Until you terminate your membership or withdraw your consent to use the personal information
3) The Company manages and supervises the consignee not to violate the laws and regulations related to the Personal Information Protection Law if the Company provides the personal information to the consignee.
4) If the the consignment service or the consignee changes, the Company will disclose it through this privacy policy without delay.
4. The rights, duties and methods of the exercise of the rights of the subject
You may exercise the following rights as a subject of the personal information.
1) The subject may exercise its right related to the following personal information protection at any time toward the Company.
① Request to view the personal information
② Request to correction the personal information in case of an error
③ Request to deletion the personal information
④ Request to stop processing the personal information
2) The exercise of the rights pursuant to 1) above may be made in writing, by e-mail, etc. in accordance with the Form 8 of the Enforcement of the Personal Information Protection Law, and the Company shall take an action without delay.
3) If you request correction or deletion of your personal information error, the company will not use or provide the relevant personal information until the error correction or deletion is completed.
4) The exercise of the rights pursuant to 1) above may be done through you, your legal representative, or the delegate. In this case, you must submit a power of attorney according to Form 11 of the Enforcement of the Personal Information Protection Law.
5. Destruction of the personal information
Once the purpose of collecting and using personal information is achieved, the Company will immediately destroy the relevant personal information. The procedure and method of destruction are as follows.
1) Destruction Procedure: The information entered by the user is transferred to a separate DB after the completion of its purpose (for papers, moved to a separate storage place) and, i) is stored for a certain period of time according to the internal policy and other related laws and regulations, or ii) destroyed immediately. The personal information transferred to DB is not used for any other purposes unless it is required by the law.
2) Destruction Deadline: If the retention period of the personal information has lapsed, the personal information is destructed within 5 days from the end of the retention period, and if the personal information is no longer necessary because the purpose of collecting and using personal information is achieved, the relevant service is abolished, or the business is terminated, the personal information is destructed within 5 days from the day when it is deemed unnecessary to process the personal information.
3) Destruction Method: The information in the form of electronic files uses technical method that cannot reproduce records. The personal information printed on paper is crushed by crusher or destroyed by incineration.
6. Matters concerning the installation, operation and rejection of the automatic collection device of the personal information
1) Cookies are used to support users for faster and more convenient use of the website and to provide customized services
2) Users have the option of installing cookies. Therefore, you can allow all cookies, check every time a cookie is saved, or refuse to save all cookies by setting the options in the Tools> Internet Options> Privacy menu at the top of your web browser
3) If you refuse to install cookies, you will not experience inconvenience to use the website or experience difficulty to use some of our services.
7. Measures to ensure the security of the personal information
The Company, pursuant to Article 29 of the Personal Information Protection Law, has the following technical, administrative and physical measures to ensure the security of the personal information.
1) Establishment and implementation of internal management policies
The Company has established and implemented internal management policies for the safe processing of the personal information
2) Technical measures against hacking
The Company installs and periodically updates and checks a security program to prevent leakage and damage of the personal information caused by hacking or computer viruses, and installs the system in an restricted area to monitors and blocks the system technically/physically.
3) Encryption of the personal information
Important personal information and password are stored and managed in an encrypted form so that only the user can know them, and important data is provided with separate security functions such as encrypting file and transmission data or using file lock function
4) Storage of access history and prevention of forgery
The Company keeps and manages the access history to the personal information processing system for at least six months and uses the security function to prevent access history from being forged, lost, or stolen.
5) Restriction on access to the personal information
The Company takes necessary measures to control access to personal information through the granting, modification and cancellation of access rights to the personal information processing database system hat processes personal information, and controls unauthorized access from outside using firewall system.
6) Use of locks for document security
The Company keeps documents with the personal information and auxiliary storage system in a safe place with locks.
7) Access control towards an unauthorized person
The Company has separate physical storage for storing the personal information and has set up access control procedures for them.
8. Personal information protection manager
1) In order to oversee the processing of personal information and handle complaints and remedies related to the personal information, the Company has designated the responsible department and the personal information manager as follows.
▶ Personal Information Protection Manager
- Name: Kim Seok Jin
- Title: CEO
- E-mail address: privacy@flybit.com
▶ Personal Information Protection Department
- Department: Information Security Team
- E-mail address: privacy@flybit.com
2) The subject of the personal information may contact the personal information protection department or the personal information protection manager regarding any personal information protection inquiries, complaints, damage remedies, etc. that occurred while using the Company's service(or business). The Company will do our best to respond to the inquiries promptly and sincerely.
3) The responsibility for maintaining the security of the ID and password related to the user's personal information belongs to the user himself/herself. The Company never asks the user directly about the password in any way, so please be careful not to let the password be leaked to others. Especially if you are online in a public place, you need to be extra careful.
4) The Company is not responsible for any damage to information due to unexpected accidents caused by network dangers, such as hacking using advanced technologies, despite the Company's possible technical remedies.
5) Notwithstanding this privacy policy, if the Company is obliged to provide the personal information based on laws and regulations of the Republic of Korea, the Company may provide such information pursuant to a court order.
6) The company endeavors to comply with the privacy policy. But we can provide personal information based on Korean relevant Act and regulations. If they must have a court order.
9. Request to view the personal information
The following organizations are separate entities. Please contact them if you are not satisfied with the Company's own treatment of your personal information complaints and damage relief results, or if you need further assistance.
▶ KISA Privacy Complaints Center
• Duty: Personal information infringement fact report, consultation application
• Website: privacy.kisa.or.kr
• Tel: 118
▶ Personal Information Dispute Resolution Committee
• Duty: Personal information dispute resolution procedures guide, Application, Coordination (Civil Settlement)
• Website: www.kopico.go.kr
• Tel: 1833-6972
▶ Supreme Prosecutors’ Office
• Duty: Criminal case, crime report, etc.
• Website: www.spo.go.kr
• Tel: 02) 3480-3573
▶ Cyber Bureau, Korean National Police Agency
• Duty: Personal information infringement, hacking, virus, game fraud, spam, prevention information, etc.
• Website: cyberbureau.police.go.kr
• Tel: 182
10. Change of privacy policy
This privacy policy will be effective from the Effective Date, and if there is an addition, deletion, or correction, the Company will notify you through announcement 7 days before the effective date of such change.
Supplementary Provision #1
(Effective Date) This privacy policy will be effective January 31, 2018.
Supplementary Provision #2
(Effective Date) This privacy policy will be effective November 27, 2019.
Supplementary Provision #3
(Effective Date) This privacy policy will be effective March 5, 2020.
Supplementary Provision #4
(Effective Date) This privacy policy will be effective March 18, 2020.
Supplementary Provision #5
(Effective Date) This privacy policy will be effective March 26, 2020.
Supplementary Provision #6
(Effective Date) This privacy policy will be effective June 04, 2020.