Privacy Policy
In accordance with Article 30 of the Korean Personal Information Protection Act, Cheongdam The Cell Clinic (the “Clinic”) establishes and discloses this Privacy Policy as follows to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
1. Purposes of Processing Personal Information
- Medical care and medical consultations, and confirmation of and guidance on appointments
- Billing and collection of medical fees, and issuance of medical certificates and other certificates
- Preparation and retention of medical records under applicable laws such as the Medical Service Act
- Handling of complaints and delivery of notices related to medical care
2. Personal Information Processed
- For medical care: name, date of birth, sex, contact information, address, and health-related information such as records of medical care, treatments, and tests
- Website: The Clinic’s website does not accept membership registration, online consultations, or booking requests, and does not collect personal information through the website. While you use the website, access logs (IP address, access date and time, browser information) may be automatically generated on the hosting provider’s servers.
- The “Don’t show again today” setting in pop-ups is stored only in the user’s browser and is not collected by the Clinic.
3. Processing and Retention Period of Personal Information
The Clinic retains personal information for the retention periods prescribed by law and destroys it without delay once the retention period expires or the purpose of processing has been achieved. The main retention periods under Article 15 of the Enforcement Rule of the Korean Medical Service Act are as follows.
- Medical records and surgical records: 10 years
- Patient registers, test details and test findings records, radiographs and their reports, and nursing records: 5 years
- Copies of medical certificates, etc.: 3 years
- Prescriptions: 2 years
4. Provision to Third Parties
The Clinic does not provide personal information to third parties without the consent of the data subject. However, it may be provided only to the extent permitted by the Personal Information Protection Act, such as where special provisions exist in laws including the National Health Insurance Act and the Medical Service Act, or where an investigative agency makes a lawful request.
5. Outsourcing of Personal Information Processing
The clinic may entrust personal information processing to outside parties where necessary for its operations, such as running the electronic medical record (EMR) system or sending appointment and notification text messages. When doing so, in accordance with Article 26 of the Personal Information Protection Act, the clinic sets out the necessary terms in the entrustment contract to keep personal information safe, and discloses the contractor and the entrusted work through this policy.
If you use Naver Booking, your booking information is processed in accordance with the privacy policy of NAVER Corporation, and the Clinic uses it only to the extent necessary for confirming bookings and providing guidance on your visit.
6. Procedures and Methods for Destroying Personal Information
Personal information whose retention period has expired is destroyed without delay in accordance with internal procedures. Electronic files are deleted using methods that make recovery impossible, and paper documents are shredded or incinerated.
7. Rights and Obligations of Data Subjects and How to Exercise Them
Data subjects may at any time request the Clinic to provide access to, correct, delete, or suspend the processing of their personal information. These rights may be exercised in writing, by telephone, or by other means, and the Clinic will take action without delay. They may also be exercised through a legal representative or an authorized person. However, deletion cannot be requested for medical records and other information that must be retained under applicable laws.
8. Processing of Sensitive Information
The Clinic processes health-related information for the purpose of medical care, and does so only to the extent necessary for that purpose on the basis of applicable laws such as the Medical Service Act.
9. Measures to Ensure the Security of Personal Information
- Administrative measures: minimizing the number of staff who handle personal information and providing regular training
- Technical measures: access rights management, access control, passwords, and other security measures
- Physical measures: access control to places such as medical record storage areas
10. Operation of Video Surveillance Devices
If the clinic installs and operates video surveillance equipment for facility safety and the prevention of fire and theft, it will, in accordance with Article 25 of the Personal Information Protection Act, post signs stating the purpose, location, recording range and the person in charge. Recorded footage is kept only as long as necessary for that purpose and then deleted without delay. Such equipment is not installed in places where privacy could be infringed, such as treatment rooms.
11. Chief Privacy Officer
- Chief Privacy Officer: Park Ki-beom (Chief Director)
- Contact: 02-6952-7503
12. Remedies for Infringement of Rights
If you need consultation or relief regarding an infringement of personal information, you may contact the organizations below.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors’ Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
13. Changes to the Privacy Policy
This privacy policy takes effect on October 1, 2026. Any changes will be announced on this page.