Privacy Policy
Data Clinic Privacy Policy
Effective Date: January 1, 2025
Pebblous Inc. ("Company") is committed to protecting the privacy and rights of individuals by complying with the Personal Information Protection Act and other applicable laws. This Privacy Policy outlines how the Company collects, processes, and protects users' personal information.
1. Purpose of Personal Information Processing
The Company processes personal information for the following purposes:
- User Registration & Management: Verification of membership, account maintenance, prevention of unauthorized use, notifications, and customer support.
- Service Provision: Delivery of basic and customized services, billing, payment processing, and debt collection.
- Marketing & Advertising: Personalized advertisements, promotional event participation, and notifications.
- Service Improvement & Development: Enhancing existing services and developing new services.
Personal information will not be used for purposes other than those stated above without additional user consent.
2. Collected Personal Information
The Company collects only the minimum amount of personal information necessary for service provision.
(1) Collected Information
- At Registration: Email address (ID), password.
- For Paid Services: Payment details such as credit card information, bank account details, or mobile payment information.
- Automatically Collected Data: IP address, cookies, service usage records, device information (e.g., phone model, OS version), and advertising identifiers.
3. Retention and Processing Period
Personal information is retained for the following periods:
- Until membership withdrawal or loss of eligibility.
- If required by law, data is retained for the legally mandated period.
4. Third-Party Sharing of Personal Information
The Company does not share personal information with third parties except in the following cases:
- With user consent.
- When required by law or regulatory authorities.
5. Delegation of Personal Information Processing
The Company entrusts certain tasks to third-party service providers, ensuring data security through contracts.
Example:
- Amazon Web Services (Seoul Region): Cloud service provider for secure data storage.
6. User Rights
Users may exercise the following rights:
- Request access, correction, deletion, or suspension of processing of personal data.
- Withdraw consent at any time.
- Manage cookies through browser settings.
- Request explanations regarding automated decisions affecting them.
Requests can be submitted via email at contact@dataclinic.ai.
7. Data Security Measures
The Company implements the following security measures:
- Administrative: Internal management policies, employee training.
- Technical: Data encryption, access control, monitoring of system logs.
- Physical: Restricted access to server rooms and data storage facilities.
8. Policy Updates
This Privacy Policy may be updated to reflect legal or service changes. Changes will be announced at least 7 days before they take effect, with major changes (e.g., data usage modifications) announced at least 30 days in advance.
For inquiries regarding this policy, please contact contact@dataclinic.ai.
