Privacy Policy for Caidentia Campus Service

Effective Date of the Revised Privacy Policy: December 15, 2025



The company collects and processes users' personal information when providing the Caidentia Campus service.
The company highly values user privacy and complies with relevant laws, such as the Personal Information Protection Act. This policy outlines how the company collects, uses, and protects users' personal information.



1. Collection and Use of Personal Information

1.1 Collected Information and Purpose of Use
The company notifies users in advance and obtains consent when collecting personal information. The purpose, items collected, and retention period are as follows:
Category Collected Items Purpose of Collection Legal Basis Retention Period
Membership Registration (Required) Name, ID, Password, Email, Mobile Number, Date of Birth Education management and support, education history management
Membership qualification maintenance and management
Evaluation management, history tracking, user management, score provision, and VOC processing
Providing evaluation and education-related information
Data analysis and service improvement through statistical research
Personal Information Protection Act, Article 15(1)(4) (Contract Fulfillment) Until withdrawal
Identity Verification (Required) Name, Date of Birth, Gender, Mobile Number, CI (Connecting Information), DI (Duplicate Membership Confirmation Information), Telecommunication Provider User identification
Age verification
Membership authentication for service access
Personal Information Protection Act, Article 15(1)(4) (Contract Fulfillment) Until withdrawal
Automatically Collected Information During Service Use Service usage records, access logs, IP address, service application history, OS type, browser type, records for fraud prevention Compliance with legal obligations for consumer protection
Statistical analysis of service usage
User interest and preference-based data analysis
Providing personalized information services
Improving user convenience
Telecommunications Privacy Protection Act As required by law



2. Sharing and Disclosure of Personal Information (Third-Party Provision)

The company does not provide personal information to external parties except in the following cases:
When required by law or by investigative authorities through legal procedures
In emergency situations such as natural disasters, infectious diseases, life-threatening incidents, or urgent financial losses



3. Outsourcing of Personal Information Processing

1) The company ensures that outsourced entities adhere to strict security measures in compliance with the Personal Information Protection Act, Article 26.
2) Personal information is provided only to third parties necessary for the operation of the Caidentia Campus educational services.

Outsourced Company Purpose of Outsourcing
Mediopia System operation
Stibee Subscription and email services



4. Retention and Disposal of Personal Information

1) The company retains information for a legally mandated period and then destroys it securely.

Retained information and legal basis:

Retained Information Retention Period Legal Basis
Consumer complaints and dispute records 3 years Act on Consumer Protection in E-Commerce
Website visit records 3 years Telecommunications Privacy Protection Act

2) Disposal Process

Once the purpose of data collection is achieved, the company disposes of personal information promptly.
Printed data is shredded or incinerated, and electronically stored data is deleted using irreversible methods.



5. Measures to Secure Personal Information

The company implements the following security measures:
- Establishment and implementation of internal management plans for privacy protection
- Minimization and training of personnel handling personal data
- Access control and encryption for databases storing personal information
- Systematic monitoring and prevention of unauthorized access
- Storage of access logs for at least two years
- Security programs to prevent hacking, data breaches, and viruses



6. User Rights and Responsibilities

Users can view, modify, delete, or withdraw their personal information at any time via My Page.
Users can request to stop data processing, but requests may be declined in cases such as:
- If legally mandated obligations prevent data deletion
- If data processing is necessary to protect others’ safety, rights, or property
- If service agreements require data retention for continued service
Users must take precautions to protect their personal information and should not share IDs, passwords, or authentication credentials.



7. Cookies and Automatic Data Collection

The company uses cookies to store and retrieve user information for personalization and statistical analysis.
Users can disable cookies through their web browser settings, but this may affect service functionality.

Cookie settings can be adjusted in browser options, such as:
- Edge: Settings > Cookies and Site Permissions > Manage and Delete Cookies
- Chrome: Settings > Privacy and Security > Cookies and Other Site Data



8. Privacy Protection Contacts

Chief Privacy Officer (CPO): Jeong Jae-Hoon (Head of Management Support)
Privacy Management Team: Park Hyun-Ki (Manager), Moon Sun-Hee (Staff)
Phone: 02-785-9848

Customer Service Contact:
- Name: Park Jung-Hyun (Manager)
- Department: ValueUp Team
- Phone: 02-6121-8747
- Email: emroedu@emromail.co.kr

External Reporting Contacts:
- KISA (Korea Internet & Security Agency): privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Cyber Investigation Division, Supreme Prosecutor’s Office: www.spo.go.kr / 1301
- Cyber Crime Reporting System, National Police Agency: http://ecrm.cyber.go.kr / 182



9. Notification of Changes to the Privacy Policy

Any changes to this policy will be notified at least 7 days in advance on the company's website.

arrow_back_ios_new
arrow_upward

TOP