How Link Plastic Surgery collects, uses, and protects your personal information.
Link Plastic Surgery (hereinafter "the Clinic") has established and publishes this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, to protect the personal information of data subjects and to promptly and effectively handle related complaints.
The Clinic processes personal information for the following purposes. Personal information collected shall not be used for any purpose other than those stated below. If the purpose of use changes, the Clinic will obtain separate consent and take other necessary measures in accordance with Article 18 of the Personal Information Protection Act.
1. Website membership registration and management
Personal information is processed for the purposes of: verifying intent to register; identity verification and authentication for membership services; maintaining and managing membership status; identity verification under the limited identification system; preventing fraudulent use of services; confirming legal guardian consent for processing personal information of children under 14; various notifications; and handling complaints.
2. Provision of goods or services
Personal information is processed for the purposes of: delivering goods; providing services; sending contracts and invoices; providing content; providing customized services; identity and age verification; payment processing and settlement; and debt collection.
3. Handling complaints
Personal information is processed for the purposes of: verifying the identity of the complainant; confirming the details of the complaint; contacting and notifying for fact-finding; and communicating the outcome of the resolution.
① The Clinic processes and retains personal information within the retention and use period prescribed by law or within the retention and use period agreed upon at the time of collection from the data subject.
② The retention period for each category is as follows:
Website membership registration and management: Until withdrawal from the website. However, in the following cases, retention continues until the relevant matter is resolved:
1) If an investigation or inquiry is in progress due to a violation of applicable laws — until the conclusion of such investigation or inquiry.
2) If outstanding claims or obligations remain from the use of the website — until such claims or obligations are settled.
① Data subjects may exercise the following rights regarding their personal information at any time:
1. Request to access personal information
2. Request correction of errors
3. Request deletion
4. Request to suspend processing
② Rights under Paragraph 1 may be exercised by written request, telephone, email, or fax, and the Clinic shall take action without delay.
③ If a data subject requests correction or deletion of errors in personal information, the Clinic shall not use or provide such information until the correction or deletion is complete.
④ Rights under Paragraph 1 may be exercised through a legal guardian or authorized representative. In such cases, a power of attorney in the form prescribed by the Enforcement Rules of the Personal Information Protection Act (Form No. 11) must be submitted.
⑤ Data subjects shall not infringe upon the personal information or privacy of themselves or others being processed by the Clinic in violation of the Personal Information Protection Act or other applicable laws.
The Clinic processes the following categories of personal information:
1. Website membership registration and management
Required items: name, date of birth, user ID, password, address, phone number, gender, email address, i-PIN number.
Optional items: areas of interest.
2. Automatically collected information
The following items may be automatically generated and collected during use of internet services: IP address, cookies, MAC address, service usage records, visit records, and records of improper use.
① The Clinic shall destroy personal information without delay when it is no longer needed due to expiration of the retention period, achievement of the processing purpose, or other reasons.
② If personal information must be retained under other laws despite the expiration of the agreed retention period or achievement of the processing purpose, the information shall be moved to a separate database or stored in a different location.
③ Procedures and methods for destruction:
Procedure: The Clinic selects personal information for which grounds for destruction have arisen and destroys it with the approval of the Clinic's Personal Information Protection Officer.
Method: Personal information stored in electronic file format is destroyed using methods such as low-level formatting to prevent recovery. Personal information recorded on paper documents is destroyed by shredding or incineration.
The Clinic implements the following measures to ensure the security of personal information:
1. Administrative measures: Establishment and implementation of an internal management plan; regular staff training.
2. Technical measures: Management of access rights to personal information processing systems; installation of access control systems; encryption of unique identification information; installation of security software.
3. Physical measures: Access control for server rooms, document storage areas, and other facilities.
① The Clinic uses cookies and similar technologies to improve user experience and analyze website usage.
② The following third-party services are used on this website:
a. Google Analytics 4 (GA4)
Provider: Google LLC (USA). Purpose: Website traffic analysis, user behavior patterns, page performance measurement. GA4 does not store full IP addresses. Data retention is set to the minimum period. Google Signals and advertising personalization features are disabled.
b. Microsoft Clarity
Provider: Microsoft Corporation (USA). Purpose: Heatmaps, scroll tracking, and session recordings to improve website usability. Keyboard input masking is enabled (Strict mode) to prevent recording of personal information entered in forms.
c. Google Tag Manager (GTM)
Provider: Google LLC (USA). Purpose: Managing analytics and marketing tags. GTM itself does not collect personal data.
d. Naver Analytics
Provider: Naver Corporation (South Korea). Purpose: Website traffic analysis for Korean search engine optimization.
③ These services may transfer data to servers located outside the Republic of Korea, including the United States. Such transfers are conducted under the service providers' standard data processing agreements.
④ You may refuse cookie storage by adjusting the privacy settings in your web browser. Please note that refusing cookies may affect your experience on certain parts of the website.
⑤ To opt out of Google Analytics tracking, you may install the Google Analytics Opt-out Browser Add-on.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional information applies:
a. Legal basis for processing: We process your personal data based on your consent (for analytics cookies and contact form submissions) and our legitimate interest in operating and improving our website and medical services.
b. Your rights under GDPR: In addition to the rights listed in Article 5 above, you have the right to:
— Request data portability (receive your data in a structured, commonly used format)
— Object to processing based on legitimate interest
— Lodge a complaint with your local Data Protection Authority
— Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
c. Data transfers: Your data may be transferred to countries outside the EEA (South Korea, United States) where our service providers operate. These transfers are safeguarded by the service providers' Standard Contractual Clauses (SCCs) or equivalent mechanisms.
d. Data retention: Analytics data is retained for the minimum period necessary (2 months for GA4). Contact form submissions are retained until the inquiry is resolved and then deleted within 30 days.
⑥ For any GDPR-related inquiries, please contact us at linkpsclinic@gmail.com.
The Clinic has designated the following Personal Information Protection Officer to oversee all matters related to the processing of personal information and to handle complaints and remedy damages related to data subjects' personal information.
Data subjects may contact the following organizations for damage relief, counseling, and other inquiries regarding personal information infringement.
Personal Information Protection Officer
Officer: Sung Ha-min / Jung Min-su
Email: linkpsclinic@naver.com
If you need to report or consult regarding personal information infringement, please contact the following organizations:
1. Personal Information Dispute Mediation Committee — kopico.go.kr / 1336
2. ePrivacy Mark Certification Committee — eprivacy.or.kr / 02-580-0533
3. Supreme Prosecutors' Office Cyber Investigation Division — spo.go.kr / 02-3480-3600
4. National Police Agency Cyber Bureau — ecrm.cyber.go.kr / 02-392-0330