JIAM Logo

Privacy Policy

Version: v1.3

Effective Date: May 29, 2025

Last Revised: May 2025

JEISYS MEDICAL Inc. (hereinafter the "Company") values the personal information of users in providing the global medical education platform [JIAM] service, and processes and protects personal information safely in accordance with applicable laws.

Article 1. Personal Information Controller and Contact

CategoryDetails
Company Name (Personal Information Controller / GDPR: Controller)JEISYS MEDICAL Inc.
RepresentativeRami Lee
Business Registration No.424-87-00852
Address2F-5F, E-Land Gasan Building,159, Gasan digital 1-ro, Geumcheon-gu, Seoul, Republic of Korea
Service NameJIAM — Global Medical Education Platform
Data Protection Officer (DPO)Shingeun Jo / Head of Management Support Division
DPO Emaildataprivacy@jeisys.com
Customer Inquiriesdataprivacy@jeisys.com

Article 2. Items of Personal Information Collected and Collection Methods

A. Items Collected

① Service Sign-up and Member Management

  • [Required] Name, email address, password, country/region of residence, medical professional verification information.
  • [Required] Physician license number or medical qualification supporting information.
  • [Required] Service language preference

② Service Usage Records

  • Access IP address, cookies, access date/time, service usage records, and device information
  • Course attendance records, certificate issuance history, and learning history

③ Marketing and Newsletter Subscription

  • [Optional] Email address (when marketing consent is given)
  • [Optional] Areas of interest and specialty (when consent to personalized content recommendations is given)

B. Collection Methods

  • Membership registration via the website and service usage process
  • Email verification process.
  • Automatic collection during service use (cookies, access logs, etc.)
  • Verification through the medical qualification authentication process

Article 3. Purposes of Processing and Legal Basis

Purpose of ProcessingDetails and Legal Basis
Member Registration and ManagementMember identification, identity verification, physician qualification verification, and granting of service access rights
Service ProvisionProvision of educational content, lecture streaming, material downloads, certificate issuance, learning history management, and customer support
Service Improvement and OperationService usage statistics analysis, error diagnosis, security management, and service quality improvement
Compliance with Legal ObligationsCompliance with applicable laws, dispute response, and handling of legal claims
Marketing and Promotion (Optional Consent)Notifications of new courses and events, and personalized content recommendations (processed only after separate consent)

The Company processes personal information based on contract performance, compliance with legal obligations, legitimate interests, or user consent, in accordance with applicable laws.

Article 4. Retention and Use Period of Personal Information

CategoryRetention Period
Member Information (name, email, license information, etc.)Destroyed without delay upon membership withdrawal. However, where necessary for dispute response or fulfillment of legal obligations, may be retained for up to 6 months in accordance with applicable laws and internal policies before destruction.
Service Usage Records (course attendance records, certificates, etc.)Course attendance records and certificate issuance history are retained for 5 years after membership withdrawal for educational history verification and certificate authenticity confirmation, then destroyed.
Access Logs (IP address, access date/time, etc.)Retained for up to 1 year for service stability, security management, and compliance with applicable laws, then destroyed.
Marketing Consent InformationMarketing and advertising consent information is destroyed without delay upon withdrawal of consent. However, the minimum information necessary for dispute response under applicable laws may be retained for a certain period.
Information Retained under the Act on the Consumer Protection in Electronic Commerce, Etc.
  • Records on contracts or subscription withdrawals: 5 years
  • Records on payments and supply of goods, etc.: 5 years
  • Records on consumer complaints or dispute handling: 3 years
  • Records on display/advertising: 6 months
Information Retained under the Protection of Communications Secrets ActUnder applicable laws, communication confirmation data may be retained for a certain period (up to 12 months) depending on the data type.

Article 5. Destruction of Personal Information

A. Destruction Procedure

  • When destruction grounds arise — such as membership withdrawal, expiration of the retention period, or fulfillment of the processing purpose — the Company destroys the relevant personal information without delay.
  • Personal information that must be retained for a certain period under applicable laws is stored and managed separately from other personal information and destroyed without delay after the statutory retention period.
  • Personal information in electronic file format is securely deleted using technical methods so that it cannot be recovered or reproduced. Personal information recorded on paper documents is destroyed by shredding or incineration.

B. Destruction Methods

Personal information in electronic file format is permanently deleted using secure technical methods that prevent recovery or reproduction.

Personal information recorded on paper documents is destroyed by shredding or incineration.

Personal information stored in cloud environments is securely deleted and managed in accordance with applicable laws and internal security procedures.

Article 6. Provision of Personal Information to Third Parties

As a general rule, the Company does not provide users' personal information to third parties. However, personal information may be provided in the following exceptional cases:

  • Where separate consent has been obtained from the user
  • Where special provisions exist under applicable laws, or where necessary to fulfill legal obligations.
  • Where a lawful request is made by investigative or government agencies under applicable laws
  • Where necessary for joint service provision with partner organizations, and separate prior consent has been obtained in accordance with applicable laws.

Article 7. Outsourcing of Personal Information Processing (Outsourcees / Processors)

For smooth service operation, the Company outsources personal information processing tasks as follows. The Company reflects necessary matters in contracts and supervises outsourcees (processors) to ensure that personal information is processed safely in accordance with applicable laws.

Outsourcee (GDPR: Processor)Outsourced TasksRetention and Use Period
Grids AgencyPlatform development, operation, maintenance, and system managementUntil termination of the outsourcing contract
Woongjin Co., Ltd.Cloud infrastructure operation and managementUntil termination of the outsourcing contract

Upon termination of the outsourcing contract, the outsourcee (processor) shall destroy the personal information without delay or return it to the Company in accordance with applicable laws.

Article 8. Overseas Transfer of Personal Information

Personal information may be processed overseas in the course of operating cloud services and webinar platforms. The Company provides notice as follows in accordance with applicable laws:

RecipientCountry of TransferPurpose of TransferItems TransferredRetention and Use Period
Amazon Web Services, Inc. (AWS)Primarily stored in Korea (Korea Central / Korea South); some overseas servers may be usedCloud infrastructure operation, data storage, and system managementPersonal information collected during service useService use period and retention period under applicable laws
Zoom Video Communications, Inc.United States, etc.Webinar and online seminar operationName, email, access records, and other service usage informationUntil the webinar operation purpose is fulfilled

Data subjects have the right to refuse consent to overseas transfer of personal information. However, if overseas transfer is essential to service provision, use of certain services may be restricted.

Members residing in Japan may request information regarding the level of protection and protective measures in the recipient country under the Act on the Protection of Personal Information (APPI).

Article 9. Measures to Ensure the Security of Personal Information

A. Technical Safeguards

  • Encryption of personal information and transmitted data
  • Restriction of access rights to personal information and operation of access control systems
  • Retention of access logs and measures to prevent forgery or alteration
  • Installation and periodic updating of security programs

B. Administrative Safeguards

  • Establishment and operation of an internal management plan
  • Minimization of personnel handling personal information and regular training
  • Designation of a Data Protection Officer and management/supervision

Article 10. Rights and Obligations of Data Subjects and How to Exercise Them

Members (data subjects) may, at any time and in accordance with applicable laws, request access to, correction or deletion of, suspension of processing of, or withdrawal of consent to the processing of their personal information.

Users in certain jurisdictions, including the EU, may also exercise the right to data portability, the right to object to processing, and rights regarding automated decision-making in accordance with applicable laws.

Rights may be exercised through 'My Page' or via email (dataprivacy@jeisys.com). The Company will process such requests without delay after identity verification, in accordance with applicable laws.

However, certain requests may be restricted where other laws require retention of personal information or where retention is necessary for performance of a contract.

When exercising rights through a representative, the Company may request submission of documents such as a power of attorney in accordance with applicable laws.

Article 11. Cookies and Automatic Collection Devices

The Company may use cookies to provide services and improve the user experience.

The cookies used by the Company are as follows:

  • Essential cookies: maintain login sessions and provide security functions.
  • Functional cookies: provide user convenience, such as language settings.
  • Analytics cookies: service usage statistics and performance analysis
  • Marketing cookies: personalized advertising and interest-based services

Analytics and marketing cookies are used only after obtaining user consent in accordance with applicable laws.

Users may refuse cookie storage or withdraw consent through browser settings or the 'Cookie Settings' function within the service. However, if essential cookies are blocked, use of certain services may be restricted.

Article 12. Data Protection Officer and Grievance Handling

The Company designates the following Data Protection Officer and responsible department to oversee personal information processing and handle inquiries and grievances from data subjects:

CategoryContact Information
Data Protection Officer (DPO)
  • Name: Shingeun Jo
  • Affiliation/Position: Management Support Division / Head of Division
  • Email: dataprivacy@jeisys.com
Personal Information Protection Officer (Working-level)Email: dataprivacy@jeisys.com
Customer Service HoursHours: Weekdays 09:00–18:00 (excluding national holidays)

The Company will endeavor to respond to and process inquiries and requests from data subjects as promptly as possible in accordance with applicable laws.

Remedies for Rights Infringement — External Organizations

For reports or consultations regarding personal information infringement, you may contact the following organizations:

OrganizationContact Information and Website
Personal Information Protection Commission☎ 182 (no area code) | www.privacy.go.kr
Personal Information Infringement Report Center (Korea Internet & Security Agency, KISA)☎ 118 (no area code) | privacy.kisa.or.kr
Supreme Prosecutors' Office — Cyber and Technology Crime Investigation Division☎ 02-3480-3571 | www.spo.go.kr
Korean National Police Agency — Cyber Bureau☎ 182 (no area code) | cyberbureau.police.go.kr
ecrm.police.go.kr

Article 13. Changes to the Privacy Policy

This Privacy Policy is effective from May 29, 2025.

The Company may revise this Policy in accordance with changes to applicable laws, service offerings, or personal information processing methods. Material changes will be communicated in advance through service announcements or other appropriate means.

Previous versions of the Privacy Policy are available within the service.