AB Clinic (hereinafter referred to as "the Clinic") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act to protect the personal information of data subjects and to process related concerns promptly and smoothly.
Article 1 (Purpose of Personal Information Processing)
The Clinic uses the collected personal information for the following purposes and does not use it for purposes beyond those stated. If there is a change in the purpose of use, prior consent will be obtained.
Provision of Medical Services: Diagnosis, appointment confirmation, patient verification during examinations and treatments, billing, payment, and refunds.
Customer Management and Communication: Handling complaints, resolving concerns, providing medical information, and offering consultation services.
Compliance with Legal Obligations: Retaining medical records and responding to legal and administrative requirements.
Research and Education: Quality management of medical services and utilization for internal statistical analysis.
Article 2 (Retention and Processing Period of Personal Information)
The Clinic processes and retains personal information in accordance with legal regulations or with the consent of the data subject. The major retention and processing periods are as follows:
Membership Information
Until account deletion
Medical Records
Retained for 10 years as per the Medical Law Enforcement Rules, Article 15
Payment Information
Retained for 5 years according to the Credit Information Act
Survey and Event Information
Destroyed immediately after the purpose is achieved
Article 3 (Categories and Methods of Personal Information Collection)
Collected Information
During Membership Registration Required: Name, ID, Password, Email, Mobile Number, Address, Date of Birth / Optional: Gender, Preferred Treatment Information
During Medical Treatment and Payment Required: Name, Gender, Date of Birth, Contact Information, Address, Medical History, Treatment Records, Payment Information
Automatically Collected Access logs, IP address, and cookie information
Collection Methods
Website, written forms, phone, fax, email, online consultations, in-person visits, etc.
Article 4 (Provision of Personal Information to Third Parties)
The Clinic does not provide personal information to third parties without the data subject’s consent, except in the following cases:
When required by law
When necessary for the urgent protection of life, body, or property of the data subject
When submitting medical records for reimbursement claims to the Health Insurance Review & Assessment Service
Article 5 (Destruction of Personal Information)
The Clinic promptly destroys personal information when the retention period expires or when processing objectives have been achieved.
Destruction Procedure: Deleted after internal approval upon reaching the destruction criteria
Destruction Method: Electronic files are permanently erased, and paper documents are shredded or incinerated
Article 6 (Rights of Data Subjects)
Data subjects have the following rights regarding their personal information:
Request to access personal information
Request correction or deletion of personal information
Request to stop the processing of personal information
Article 7 (Security Measures for Personal Information)
The Clinic takes the following measures to ensure the protection of personal information:
Administrative Measures: Employee training on personal information handling, establishment of internal management plans
Technical Measures: Encryption, access control, and installation of security programs
Physical Measures: Restricted access to data storage and IT rooms
Article 8 (Use and Rejection of Cookies)
The Clinic may use cookies for website operation, and data subjects can refuse cookie settings. However, rejecting cookies may limit the use of certain services.
Article 9 (Personal Information Protection Officer)
For inquiries regarding personal information protection, please contact the designated officer below: