Privacy Policy
This is a reference translation of the Korean original. In the event of any discrepancy, the Korean version prevails.
VWAY Co., Ltd. (the “Company”) complies with the Personal Information Protection Act, the Protection of Communications Secrets Act, the Telecommunications Business Act, and the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this Privacy Policy, the Company explains for what purposes and in what manner the personal information you provide is used, and what measures are taken to protect it.
Article 1. Purpose of collection and use, items collected, and methods of collection
- “Personal information” means information about a living individual that can identify that individual (including information that, even if it alone cannot identify a specific individual, can readily be combined with other information to do so).
- The Company uses the collected personal information for the following purposes.
- Communication: handling inquiries and consultations, providing notices, and the like
- Provision of content and services: use of services by individuals and corporate customers, settlement of payments, identity verification for financial transactions and related financial services, and the like
- Events, marketing and research: delivery of event and promotional information, statistical surveys on service use, and the like
- Other provision of services
- For the purposes stated above, the Company collects personal information as follows.
- Required items: name, company name, position, phone number, e-mail, how you heard about us
- Methods of collection: website, telephone, e-mail, event entry
- In the course of using the service or processing business, information such as service usage records, access logs, cookies, access IP information, payment records and suspension records may be generated and collected
- Information about users of supplementary services or event entries (only where separate consent to additional collection has been obtained)
- The Company collects personal information only with the user’s consent. Information that may infringe the user’s fundamental human rights — such as race, place of origin, registry of origin, ideology, political orientation, criminal records or health status — is not collected except with the user’s consent or as provided by law.
- The Company does not collect personal information of children under the age of 14, for whom the consent of a legal representative would be required for collection and use.
- The Company may collect personal information by the following means.
- Website, telephone, e-mail, event entry
Article 2. Provision of personal information to third parties and outsourcing
1. Provision to third parties
The Company provides personal information to third parties only where Articles 17 and 18 of the Personal Information Protection Act apply, such as with the consent of the data subject or under special provisions of law. Details are as follows.
| Recipient | Purpose | Items provided | Period of use |
|---|---|---|---|
| Stibee | Sending newsletters and e-mail notices | Name, company name, position, phone number, e-mail | Until the subscription ends |
| Korea Post | Shipping training materials and certificates | Name, company name, position, phone number, postal code, address, description of contents | Until the recipient’s purpose is achieved |
| Software Safety Technology Association | Examination registration and issuance of certificates | Name, company name, position, phone number, e-mail, date of birth, address | Validity period of the certificate |
2. Outsourcing of processing
Where the Company outsources the processing of personal information for smooth operation of its business, it stipulates the matters necessary for personal information to be managed safely in the outsourcing contract in accordance with the applicable laws. At present there is no outsourced processing.
Article 3. Retention and use period
- The Company may retain the information provided by the user until the purpose of use has been achieved. In principle, once deletion is complete the user’s personal information is permanently removed from the Company’s hard disks, and documents are shredded so that they cannot be used for any purpose.
- However, where retention is required under the applicable laws, the Company retains user information for the periods prescribed by those laws, as set out below.
- Where individual consent has been obtained from the user, the agreed retention period
- Legal basis: Act on Consumer Protection in Electronic Commerce; Protection of Communications Secrets Act
Records on contracts or withdrawal of subscription (E-Commerce Act) 5 years Records on payment and supply of goods or services (E-Commerce Act) 5 years Records on consumer complaints or dispute resolution (E-Commerce Act) 3 years Records on access (Protection of Communications Secrets Act) 3 months Records on electronic financial transactions (Electronic Financial Transactions Act) 5 years
Article 4. Rights of users and how to exercise them
- Users may at any time request access to, correction of, or deletion of their personal information with respect to the following.
- The user’s personal information held by the Company
- Records of the Company’s use of the user’s personal information or provision of it to third parties
- Records of the consent given to the Company for collection, use and provision of personal information
- Users may view and correct their own information directly within the Company’s services, or separately request access and correction from the privacy officer in writing, by telephone or by e-mail.
- Users may at any time request suspension of the processing of their personal information.
- Users may at any time withdraw the consent they gave to the collection, use and provision of personal information at the time of registration.
- Users may withdraw consent directly after identity verification within the Company’s services, or by contacting the privacy officer in writing, by telephone or by e-mail; the Company will then take the necessary measures without delay, such as destroying the user’s personal information. Even where consent is withdrawn, a minimum of information is retained as required by the applicable laws.
Article 5. Destruction procedure and method
Personal information is destroyed without delay once the purpose of collection and use has been achieved or the retention and use period has elapsed. The Company’s destruction procedure and method are as follows.
- Destruction procedure
Personal information entered by the user is stored for a certain period after the purpose has been achieved, in accordance with internal policy and other information protection grounds under the applicable laws (see “Retention and use period”), and is then destroyed. Such personal information is not used for any purpose other than that for which it is retained, except as provided by law. - Destruction method
Personal information printed on paper is destroyed by shredding or incineration, and personal information stored in electronic file form is deleted using a technical method that makes the records irrecoverable.
Article 6. Installation, operation and refusal of automatic collection devices
- The Company uses “cookies”, which store and retrieve user information from time to time. A cookie is a small packet of data sent by the server to the user’s web browser when the website is used, and is stored on the hard disk of the user’s computer. Cookies identify the user’s computer but do not identify the user personally. The Company uses cookies for the following purposes.
- Purpose of use: ① maintaining the user’s session ② analysing access frequency and visit duration, understanding the user’s preferences and interests, tracking activity, and identifying participation in events and number of visits, in order to provide targeted marketing and personalised services
You have a choice regarding the installation of cookies. By setting the options in your web browser you may allow all cookies, be asked for confirmation each time a cookie is stored, or refuse to store all cookies.
- ① Internet Explorer: Tools > Internet Options > Privacy > Settings > Advanced
- ② Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
- ③ Chrome: Settings > Privacy and security > Cookies and other site data
If you refuse or block the storage of cookies, you may experience difficulties in using the service.
Article 7. Technical and administrative measures for protection
The Company’s technical and administrative measures to protect personal information are as follows.
- Installation, updating and periodic inspection of antivirus software to prevent damage to personal information by computer viruses
- Restriction of access to personal information by setting access rights to the personal information system
- Designating the minimum number of personal information handlers, setting their permissions and providing training, and managing personal information safely
Article 8. Name, department and contact of the privacy officer
To protect users’ personal information and handle complaints related to personal information, the Company has appointed a privacy officer. If you have any questions regarding personal information, please contact the privacy officer or the person in charge below.
Privacy Officer
- Name
- Moon Kyung Tae, General Manager
- Department
- Solution Business Division
- Phone
- 02-508-3913
- moon@vwaycorp.com
Privacy Manager
- Name
- Wi Sun Mi, Manager
- Department
- Management Support Team
- Phone
- 02-508-3913
- smwi@vwaycorp.com
To obtain redress for infringement of personal information, you may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Privacy Infringement Report Center of the Korea Internet & Security Agency, and similar bodies. For other reports of and consultations on privacy infringement, please contact the organisations below.
- Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
- Privacy Infringement Report Center118 (no area code)privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division1301 (no area code)www.spo.go.kr
- National Police Agency, Cyber Bureau182 (no area code)ecm.cyber.go.kr
Article 9. Changes to this Privacy Policy
If there are additions, deletions or amendments to this Privacy Policy, the Company will give notice through its website from seven days before the effective date of the change. However, changes to matters material to users’ rights or obligations will be notified at least 30 days in advance.
Enacted 1 May 2022

