Privacy Policy
Version: v1.3
Effective Date: May 29, 2025
Last Revised: May 2025
JEISYS MEDICAL Inc. (hereinafter the "Company") values the personal information of users in providing the global medical education platform [JIAM] service, and processes and protects personal information safely in accordance with applicable laws.
Article 1. Personal Information Controller and Contact
| Category | Details |
|---|---|
| Company Name (Personal Information Controller / GDPR: Controller) | JEISYS MEDICAL Inc. |
| Representative | Rami Lee |
| Business Registration No. | 424-87-00852 |
| Address | 2F-5F, E-Land Gasan Building,159, Gasan digital 1-ro, Geumcheon-gu, Seoul, Republic of Korea |
| Service Name | JIAM — Global Medical Education Platform |
| Data Protection Officer (DPO) | Shingeun Jo / Head of Management Support Division |
| DPO Email | dataprivacy@jeisys.com |
| Customer Inquiries | dataprivacy@jeisys.com |
Article 2. Items of Personal Information Collected and Collection Methods
A. Items Collected
① Service Sign-up and Member Management
- [Required] Name, email address, password, country/region of residence, medical professional verification information.
- [Required] Physician license number or medical qualification supporting information.
- [Required] Service language preference
② Service Usage Records
- Access IP address, cookies, access date/time, service usage records, and device information
- Course attendance records, certificate issuance history, and learning history
③ Marketing and Newsletter Subscription
- [Optional] Email address (when marketing consent is given)
- [Optional] Areas of interest and specialty (when consent to personalized content recommendations is given)
B. Collection Methods
- Membership registration via the website and service usage process
- Email verification process.
- Automatic collection during service use (cookies, access logs, etc.)
- Verification through the medical qualification authentication process
Article 3. Purposes of Processing and Legal Basis
| Purpose of Processing | Details and Legal Basis |
|---|---|
| Member Registration and Management | Member identification, identity verification, physician qualification verification, and granting of service access rights |
| Service Provision | Provision of educational content, lecture streaming, material downloads, certificate issuance, learning history management, and customer support |
| Service Improvement and Operation | Service usage statistics analysis, error diagnosis, security management, and service quality improvement |
| Compliance with Legal Obligations | Compliance with applicable laws, dispute response, and handling of legal claims |
| Marketing and Promotion (Optional Consent) | Notifications of new courses and events, and personalized content recommendations (processed only after separate consent) |
The Company processes personal information based on contract performance, compliance with legal obligations, legitimate interests, or user consent, in accordance with applicable laws.
Article 4. Retention and Use Period of Personal Information
| Category | Retention Period |
|---|---|
| Member Information (name, email, license information, etc.) | Destroyed without delay upon membership withdrawal. However, where necessary for dispute response or fulfillment of legal obligations, may be retained for up to 6 months in accordance with applicable laws and internal policies before destruction. |
| Service Usage Records (course attendance records, certificates, etc.) | Course attendance records and certificate issuance history are retained for 5 years after membership withdrawal for educational history verification and certificate authenticity confirmation, then destroyed. |
| Access Logs (IP address, access date/time, etc.) | Retained for up to 1 year for service stability, security management, and compliance with applicable laws, then destroyed. |
| Marketing Consent Information | Marketing and advertising consent information is destroyed without delay upon withdrawal of consent. However, the minimum information necessary for dispute response under applicable laws may be retained for a certain period. |
| Information Retained under the Act on the Consumer Protection in Electronic Commerce, Etc. |
|
| Information Retained under the Protection of Communications Secrets Act | Under applicable laws, communication confirmation data may be retained for a certain period (up to 12 months) depending on the data type. |
Article 5. Destruction of Personal Information
A. Destruction Procedure
- When destruction grounds arise — such as membership withdrawal, expiration of the retention period, or fulfillment of the processing purpose — the Company destroys the relevant personal information without delay.
- Personal information that must be retained for a certain period under applicable laws is stored and managed separately from other personal information and destroyed without delay after the statutory retention period.
- Personal information in electronic file format is securely deleted using technical methods so that it cannot be recovered or reproduced. Personal information recorded on paper documents is destroyed by shredding or incineration.
B. Destruction Methods
Personal information in electronic file format is permanently deleted using secure technical methods that prevent recovery or reproduction.
Personal information recorded on paper documents is destroyed by shredding or incineration.
Personal information stored in cloud environments is securely deleted and managed in accordance with applicable laws and internal security procedures.
Article 6. Provision of Personal Information to Third Parties
As a general rule, the Company does not provide users' personal information to third parties. However, personal information may be provided in the following exceptional cases:
- Where separate consent has been obtained from the user
- Where special provisions exist under applicable laws, or where necessary to fulfill legal obligations.
- Where a lawful request is made by investigative or government agencies under applicable laws
- Where necessary for joint service provision with partner organizations, and separate prior consent has been obtained in accordance with applicable laws.
Article 7. Outsourcing of Personal Information Processing (Outsourcees / Processors)
For smooth service operation, the Company outsources personal information processing tasks as follows. The Company reflects necessary matters in contracts and supervises outsourcees (processors) to ensure that personal information is processed safely in accordance with applicable laws.
| Outsourcee (GDPR: Processor) | Outsourced Tasks | Retention and Use Period |
|---|---|---|
| Grids Agency | Platform development, operation, maintenance, and system management | Until termination of the outsourcing contract |
| Woongjin Co., Ltd. | Cloud infrastructure operation and management | Until termination of the outsourcing contract |
Upon termination of the outsourcing contract, the outsourcee (processor) shall destroy the personal information without delay or return it to the Company in accordance with applicable laws.
Article 8. Overseas Transfer of Personal Information
Personal information may be processed overseas in the course of operating cloud services and webinar platforms. The Company provides notice as follows in accordance with applicable laws:
| Recipient | Country of Transfer | Purpose of Transfer | Items Transferred | Retention and Use Period |
|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Primarily stored in Korea (Korea Central / Korea South); some overseas servers may be used | Cloud infrastructure operation, data storage, and system management | Personal information collected during service use | Service use period and retention period under applicable laws |
| Zoom Video Communications, Inc. | United States, etc. | Webinar and online seminar operation | Name, email, access records, and other service usage information | Until the webinar operation purpose is fulfilled |
Data subjects have the right to refuse consent to overseas transfer of personal information. However, if overseas transfer is essential to service provision, use of certain services may be restricted.
Members residing in Japan may request information regarding the level of protection and protective measures in the recipient country under the Act on the Protection of Personal Information (APPI).
Article 9. Measures to Ensure the Security of Personal Information
A. Technical Safeguards
- Encryption of personal information and transmitted data
- Restriction of access rights to personal information and operation of access control systems
- Retention of access logs and measures to prevent forgery or alteration
- Installation and periodic updating of security programs
B. Administrative Safeguards
- Establishment and operation of an internal management plan
- Minimization of personnel handling personal information and regular training
- Designation of a Data Protection Officer and management/supervision
Article 10. Rights and Obligations of Data Subjects and How to Exercise Them
Members (data subjects) may, at any time and in accordance with applicable laws, request access to, correction or deletion of, suspension of processing of, or withdrawal of consent to the processing of their personal information.
Users in certain jurisdictions, including the EU, may also exercise the right to data portability, the right to object to processing, and rights regarding automated decision-making in accordance with applicable laws.
Rights may be exercised through 'My Page' or via email (dataprivacy@jeisys.com). The Company will process such requests without delay after identity verification, in accordance with applicable laws.
However, certain requests may be restricted where other laws require retention of personal information or where retention is necessary for performance of a contract.
When exercising rights through a representative, the Company may request submission of documents such as a power of attorney in accordance with applicable laws.
Article 11. Cookies and Automatic Collection Devices
The Company may use cookies to provide services and improve the user experience.
The cookies used by the Company are as follows:
- Essential cookies: maintain login sessions and provide security functions.
- Functional cookies: provide user convenience, such as language settings.
- Analytics cookies: service usage statistics and performance analysis
- Marketing cookies: personalized advertising and interest-based services
Analytics and marketing cookies are used only after obtaining user consent in accordance with applicable laws.
Users may refuse cookie storage or withdraw consent through browser settings or the 'Cookie Settings' function within the service. However, if essential cookies are blocked, use of certain services may be restricted.
Article 12. Data Protection Officer and Grievance Handling
The Company designates the following Data Protection Officer and responsible department to oversee personal information processing and handle inquiries and grievances from data subjects:
| Category | Contact Information |
|---|---|
| Data Protection Officer (DPO) |
|
| Personal Information Protection Officer (Working-level) | Email: dataprivacy@jeisys.com |
| Customer Service Hours | Hours: Weekdays 09:00–18:00 (excluding national holidays) |
The Company will endeavor to respond to and process inquiries and requests from data subjects as promptly as possible in accordance with applicable laws.
Remedies for Rights Infringement — External Organizations
For reports or consultations regarding personal information infringement, you may contact the following organizations:
| Organization | Contact Information and Website |
|---|---|
| Personal Information Protection Commission | ☎ 182 (no area code) | www.privacy.go.kr |
| Personal Information Infringement Report Center (Korea Internet & Security Agency, KISA) | ☎ 118 (no area code) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office — Cyber and Technology Crime Investigation Division | ☎ 02-3480-3571 | www.spo.go.kr |
| Korean National Police Agency — Cyber Bureau | ☎ 182 (no area code) | cyberbureau.police.go.kr ecrm.police.go.kr |
Article 13. Changes to the Privacy Policy
This Privacy Policy is effective from May 29, 2025.
The Company may revise this Policy in accordance with changes to applicable laws, service offerings, or personal information processing methods. Material changes will be communicated in advance through service announcements or other appropriate means.
Previous versions of the Privacy Policy are available within the service.