Privacy Policy

Effective date: 2024-07-01

Privacy Policy

The Korea Galleries Art Fair Association (KIAF SEOUL, www.kiaf.org, the "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) in order to protect users' personal information and to promptly and smoothly handle related grievances.

This Policy applies to the KIAF VIP mobile application (the "App") and related services provided by the Company.

  • Effective Date: July 1, 2024

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. The personal information processed will not be used for any purpose other than the following, and where the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent in accordance with PIPA.

  1. Membership registration and management: confirming intent to register, identity verification and authentication, maintaining and managing membership, various notices and communications, and record retention for dispute resolution
  2. VIP ticket services: verifying VIP tickets via invitation tokens and invite codes, and providing ticket and entry information
  3. Program reservation (RSVP) processing: providing VIP program information, and handling applications, confirmations, cancellations, and check-ins
  4. Guest (companion) invitations: sending guest invitations and processing companion entry
  5. Push notifications: sending service notices and program- and ticket-related notifications
  6. Marketing and advertising: providing advertising information such as newsletters (only for users who have consented to receive them)

2. Items of Personal Information Processed

The Company processes the following items of personal information.

CategoryItems CollectedTime of Collection
Membership registration (required)Login ID, password, emailAt registration
Marketing consent (optional)Newsletter subscription consentAt registration
Contact information (required)Name, mobile phone number, emailWhen using a ticket / applying for RSVP
Guest invitation (optional)Guest's email, mobile phone numberWhen inviting a guest
Push notifications (automatic)Device identifier, FCM push token, OS/platform, app versionOn app launch / when notification permission is granted
Service use (automatic)RSVP application history, notification receipt/read records, access logsWhen using the Service

The Company does not collect sensitive information such as race, ideology, or political views, nor information unnecessary for providing the Service, such as gender, date of birth, occupation, or hobbies.

3. Processing and Retention Period of Personal Information

  1. The Company processes and retains personal information within the retention and use period prescribed by law, or within the retention and use period consented to by the data subject at the time of collection.
  2. The processing and retention period for each item is as follows.
    • Member information: until withdrawal of membership. However, where retention is required under applicable laws, until the end of the relevant period
    • Contact and RSVP information: until termination of the service use agreement or the data subject's request for deletion
    • Push notification tokens and device information: destroyed upon refusal of notifications, deletion of the App, or after a certain period of inactivity
    • Access logs and other usage records: the retention period prescribed by applicable laws, such as the Protection of Communications Secrets Act

4. Provision of Personal Information to Third Parties

  1. The Company provides personal information to third parties only where it falls under Articles 17 and 18 of PIPA, such as with the consent of the data subject or special provisions of law.
  2. As a rule, the Company does not provide users' personal information to external third parties. Where provision to a third party becomes necessary in the future, the Company will give prior notice of the recipient, purpose of provision, items provided, and retention period, and will obtain consent.

5. Outsourcing of Personal Information Processing

  1. The Company outsources personal information processing tasks as follows in order to provide the Service smoothly.

    OutsourceeOutsourced Task
    Google LLC (Firebase Cloud Messaging)Processing of device tokens for push notification delivery
  2. When concluding an outsourcing contract, the Company specifies in documents, in accordance with Article 26 of PIPA, matters concerning the prohibition of processing personal information beyond the purpose of performing the outsourced task, technical and managerial protective measures, restrictions on re-outsourcing, management and supervision of the outsourcee, and liability for damages, and supervises whether the outsourcee processes personal information safely.

  3. Where the content of the outsourced task or the outsourcee changes, the Company will disclose it without delay through this Privacy Policy.

6. Overseas Transfer of Personal Information

The Company transfers personal information overseas for push notification delivery as follows.

TransfereeCountry of TransferItems TransferredPurposeRetention/Use Period
Google LLCUnited States and other countries where Google data centers are locatedFCM push token, device identifierDelivery of push notification messagesUntil termination of the outsourcing contract or fulfillment of the transfer purpose

A user may refuse the above overseas transfer by disabling notifications in the device or App settings. In this case, however, the use of push notification services may be restricted.

7. Personal Information of Children Under the Age of 14

The Company does not collect the personal information of children under the age of 14, and children under the age of 14 may not register as members or use the Service.

8. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them

  1. A data subject may, at any time, request access to, correction of, deletion of, or suspension of processing of their personal information.
  2. The exercise of rights under Paragraph 1 may be made in writing, by email, or similar means, in accordance with Article 41(1) of the Enforcement Decree of PIPA, and the Company will act on it without delay.
  3. The exercise of rights may be made through a legal representative of the data subject or an authorized agent. In this case, a power of attorney in the form of Annex No. 11 of the Enforcement Rule of PIPA must be submitted.
  4. The right to request access to and suspension of processing of personal information may be restricted under Article 35(4) and Article 37(2) of PIPA.
  5. A request for correction or deletion of personal information may not be made where the personal information is specified as a subject of collection under other laws.
  6. The Company verifies whether the person exercising the right is the data subject themselves or a legitimate representative.

9. Destruction of Personal Information

  1. The Company destroys the relevant personal information without delay when the purpose of processing has been achieved or the retention period has elapsed.
  2. Destruction procedure: the Company selects the personal information for which a cause for destruction has arisen and destroys it upon confirmation by the Company's Privacy Officer.
  3. Destruction deadline: within 5 days from the end date where the retention period has elapsed, and within 5 days from the relevant date where the personal information has become unnecessary due to achievement of the processing purpose, discontinuation of the Service, etc.
  4. Destruction method: information in electronic file form is deleted using technical methods that prevent the records from being reproduced.

10. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

  1. The App does not use web browser cookies.
  2. The Company may automatically collect information such as device identifiers, FCM push tokens, and OS/app versions in order to provide push notifications and improve service quality.
  3. A user may refuse the collection of push tokens and the receipt of notifications by disabling notification permission through the device's OS settings or the App settings.

11. Measures to Ensure the Safety of Personal Information

In accordance with Article 29 of PIPA, the Company takes the following technical, managerial, and physical measures necessary to ensure safety.

  1. Managerial measures: establishment and implementation of an internal management plan, minimization of personal information handlers, and training
  2. Technical measures: management of access rights to the personal information processing system, installation of an access control system, encryption of important information such as passwords, retention of access logs, and installation of security programs
  3. Physical measures: access control to computer rooms, data storage rooms, and the like

12. Privacy Officer

The Company designates a Privacy Officer as follows to take overall responsibility for tasks related to the processing of personal information and to handle complaints and provide remedies for data subjects in relation to personal information processing.

  • Privacy Officer
    • Name: Son Hye-hyun
    • Title: General Manager
    • Contact: +82-2-766-3702, kiaf@kiaf.org
  • Department in Charge of Privacy
    • Department: Kiaf SEOUL Secretariat
    • Person in charge: Yoo Ri-na
    • Contact: +82-2-766-3703, design@kiaf.org

Data subjects may direct any inquiries, complaints, or requests for remedy regarding personal information protection arising from their use of the Service to the above contacts, and the Company will respond and handle them without delay.

13. Remedies for Infringement of Rights

To obtain relief from personal information infringement, data subjects may apply to the following organizations for dispute resolution or consultation.

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cyber Investigation Division: 1301 (www.spo.go.kr)
  • National Police Agency Cyber Investigation Bureau: 182 (ecrm.cyber.go.kr)

14. Changes to the Privacy Policy

This Privacy Policy applies from the effective date. Where there are additions, deletions, or corrections of changes in accordance with laws and policies, the Company will give notice through an in-app announcement from seven (7) days prior to the implementation of the changes.

Kiaf SEOULKiaf SEOUL