Privacy Policy
REPIC Clinic (hereinafter referred to as the "Clinic") establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of users and to promptly and smoothly handle any related concerns.Article 1 (Purpose of Processing Personal Information)
The Clinic processes personal information for the following purposes. The collected personal information will not be used for purposes other than those specified below. If the purpose of use changes, we will take the necessary steps, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act. 1. Membership Registration and Management • Verification of membership registration intent • User identification and authentication for membership services • Maintenance and management of membership status • Identity verification under the limited identity verification system • Prevention of unauthorized service use • Verification of parental or legal guardian consent for children under 14 • Notifications and announcements • Handling of complaints 2. Provision of Goods or Services • Delivery of goods • Provision of services • Issuance of contracts and invoices • Delivery of content • Personalized service provision • Identity and age verification • Payment processing and billing • Collection of debts 3. Complaint Handling • Verification of the complainant’s identity • Confirmation of complaints • Communication for factual investigation • Notification of complaint resolution resultsArticle 2 (Processing and Retention Period of Personal Information)
① The Clinic processes and retains personal information within the period specified by law or the period agreed upon when collecting the information. ② The processing and retention periods for each category of personal information are as follows: 1. Membership Registration and Management • Retained until membership withdrawal • However, in cases where a violation of law is under investigation, information will be retained until the investigation is concluded. • If there are outstanding financial transactions, information will be retained until the settlement of those transactions. 2. Provision of Goods or Services • Retained until the completion of service provision and payment processing • However, in cases where retention is required by law, the following periods apply: ◦ Records of advertisements and contracts: 6 months ◦ Records of transactions (contracts, payments, delivery of goods): 5 years ◦ Consumer complaints or dispute resolution records: 3 years ◦ Telecommunications records (under the Communications Privacy Act): ▪ Subscriber communication details: 1 year ▪ Computer communication, internet log records, and access tracking: 3 months ③ Visitor feedback prize draw • Purpose: contacting people who enter the prize draw after leaving visitor feedback, to tell them if they have won (feedback scores and comments are collected without a name or contact details, and the draw has nothing to do with the scores or content) • Items: one contact method chosen by the entrant and its contact detail (one of email, WhatsApp, LINE, WeChat, KakaoTalk or Instagram) • Retention: 3 months after the draw is completed (or the period shown on the entry form, up to 12 months). Regardless of the draw, the contact detail is destroyed 12 months after the entry date. • Entering the draw is optional; you can submit feedback without agreeing to it. ④ Identity check for viewing before-and-after photos • Purpose: confirming your identity (sending and checking a verification code) before you view before-and-after photos, and preventing misuse • Items: for email verification, your email address, the IP address and browser information of the request, and the time of verification; a record of your viewing consent (verification method, language, notice version and time, with no personally identifying information). If you verify with LINE Login, your LINE account identifier is used only for the check and is not stored. • Retention: 30 days (destroyed without delay after that)Article 3 (Provision of Personal Information to Third Parties)
① The Clinic processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information) and does not provide personal information to third parties without the user’s consent, unless required by law under Articles 17 and 18 of the Personal Information Protection Act. ② When necessary for service provision, the Clinic may obtain consent under Article 17, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act and provide minimal personal information to third parties. • Recipients: REPIC Clinic Gangnam, REPIC Clinic Myeongdong, and any REPIC branch opened in the future (each branch is operated by a different clinic founder, so sharing between branches constitutes provision to a third party) • Purpose of use by the recipient: coordinated care between branches, checking reservation, consultation and treatment history, customer management • Items provided: name, date of birth, contact number, email, nationality, reservation details, treatment history, questionnaire answers (including health information), clinical photos • Retention period of the recipient: until the receiving branch has fulfilled the purpose (information that must be kept under relevant laws is kept for the legally required period) • You have the right to refuse this consent. However, it is required for reservations and registration, and they will be restricted if you refuse. • Other than the above, the Clinic does not provide users' personal information to any third party. If this becomes necessary, the Clinic will inform you in advance of the recipient, purpose of use, items provided and retention period, and obtain your consent.Article 4 (Outsourcing of Personal Information Processing)
① The Clinic outsources personal information processing tasks as follows in order to carry out its services. 1. SMS / KakaoTalk notifications - Processor: Alineun Saramdeul Co., Ltd. (service name: Aligo) - Scope of work: Sending reservation notices and identity verification messages - Items transferred: Mobile phone number - Country of the processor: Republic of Korea 2. Email delivery - Processor: Plus Five Five, Inc. (service name: Resend) - Scope of work: Sending reservation notices and identity verification emails - Items transferred: Email address - Country of the processor: United States 3. Reservation integration - Processor: Chunneung IT Co., Ltd. (service name: SmartDoctor) - Scope of work: Registering reservations and looking up patients in the EMR system - Items transferred: Name, contact number, reservation details - Country of the processor: Republic of Korea 4. Content delivery and file storage - Processor: Cloudflare, Inc. - Scope of work: Website content delivery (CDN) and storage of uploaded files - Items transferred: Access logs (including IP address), uploaded files - Country of the processor: United States ② When entering into an outsourcing agreement, the Clinic specifies in writing — in accordance with Article 26 of the Personal Information Protection Act — the prohibition of processing personal information beyond the purpose of the outsourced work, technical and administrative safeguards, restrictions on re-outsourcing, supervision of the processor, and liability including damages, and supervises whether the processor handles personal information safely. ③ Among the processors above, Plus Five Five, Inc. (Resend) and Cloudflare, Inc. are located outside the Republic of Korea. Pursuant to Article 28-8 (1) 3 of the Personal Information Protection Act, the Clinic transfers personal information abroad to the extent necessary to perform the contract and discloses the details through this policy. - Country of transfer: United States - Time and method of transfer: Transmitted over the network at the time the relevant service is used - Recipients and contacts: Plus Five Five, Inc. (Resend) [email protected] / Cloudflare, Inc. [email protected] - Purpose of use by the recipient: Performance of the outsourced work listed in paragraph ① - Retention and use period of the recipient: Until the purpose of the outsourced work is achieved (within the Clinic's retention period) ④ Should the content of the outsourced work or the processor change, the Clinic will disclose the change without delay through this privacy policy.Article 5 (User Rights and How to Exercise Them)
① Users can exercise the following privacy rights at any time: 1. Request access to personal information 2. Request corrections for errors 3. Request deletion of personal information 4. Request suspension of data processing ② These requests can be made via written document, phone, email, or fax, and the Clinic will promptly respond. ③ If a user requests correction or deletion of personal information due to errors, the Clinic will not use or provide the information until the correction is completed. ④ Users may authorize a legal representative or an agent to act on their behalf by submitting a power of attorney as per the format in Annex 11 of the Personal Information Protection Act Enforcement Rules. ⑤ Users must not infringe upon the privacy of themselves or others when exercising their rights under relevant laws.Article 6 (Destruction of Personal Information)
① The Clinic will immediately dispose of personal information when the retention period expires or when it is no longer needed. ② If personal information must be retained beyond the agreed period due to legal requirements, it will be transferred to a separate database (DB) or stored in a different location. ③ Methods of Disposal: • Procedure: The Clinic selects personal information for disposal and obtains approval from the Privacy Officer before deletion. • Method: ◦ Electronic files are permanently deleted so that they cannot be restored. ◦ Paper documents are shredded or incinerated.Article 7 (Security Measures for Personal Information)
The Clinic implements the following security measures to protect personal information: 1. Administrative Measures: Internal management plans, employee training 2. Technical Measures: Access control, encryption of sensitive data, security programs 3. Physical Measures: Restricted access to server rooms and document storage areasArticle 8 (Use of Cookies and Automated Collection Tools)
① The Clinic uses cookies to provide customized services to users. ② Cookies are small text files sent by the website’s server to the user's browser and stored on their device. ③ Users can adjust their browser settings to allow, block, or delete cookies. How to Manage Cookies • Chrome: Settings > Privacy & Security > Clear Browsing Data • Edge: Settings > Cookies & Site Permissions > Manage & Delete Cookies • Safari (Mobile): Settings > Safari > Advanced > Block All Cookies • Samsung Internet: Settings > Browsing Data > Clear Browsing Data ④ The Clinic collects and uses service usage patterns, search history, and security access status to optimize service delivery. ⑤ To analyze website use and improve our services, the Clinic uses the following third-party analytics tools. Through cookies and similar technologies, they collect pages visited, on-screen behavior such as clicks and scrolling, device and browser information, and country of access. Information you type into the booking form, such as your name and contact details, is masked and not collected. • Google Analytics / Google Tag Manager (Google LLC, USA): visit statistics • Microsoft Clarity (Microsoft Corporation, USA): analysis of on-screen behavior (clicks, scrolling) to improve the website • Meta Pixel (Meta Platforms, Inc., USA): measuring advertising performance This information is stored on each provider's servers (in the USA or other countries outside Korea) and kept for the period set by each provider's policy. You can refuse collection by blocking cookies as described in ③ above, or by installing the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).Article 9 (Privacy Officer and Inquiries)
① The Clinic has appointed a Privacy Officer responsible for handling personal information-related inquiries and complaints. ▶ Privacy Officer • Name: Jeon Hyeonji • Position: Representative • Contact: 02-6952-0312 (Inquiries will be directed to the relevant department)Article 10 (Legal Remedies for Privacy Violations)
Users can contact the following agencies for dispute resolution and privacy-related inquiries: 1. Personal Information Dispute Mediation Committee: ☎ 1833-6972 | www.kopico.go.kr 2. Personal Information Infringement Report Center: ☎ 118 | privacy.kisa.or.kr 3. Supreme Prosecutors' Office: ☎ 1301 | www.spo.go.kr 4. Cyber Bureau, National Police Agency: ☎ 182 | ecrm.police.go.kr Article 11 (Implementation and Changes to the Privacy Policy) This privacy policy is effective as of February 27, 2025. Amended September 25, 2026: Article 3 ② revised (provision among REPIC branches); Article 8 ⑤ (third-party analytics tools) added. Amended October 9, 2026: Article 2 ③ (visitor feedback prize draw) and ④ (identity check for viewing before-and-after photos) added.



