1. Overview
LI:ET Clinic (the “Clinic”) complies with the Personal Information Protection Act and other applicable laws and processes personal information lawfully and securely.
This Policy applies to public-website membership, social login, consultations and inquiries, the cart, online booking, booking lookup, and usage analytics. Medical records created during treatment are handled separately under medical laws and the Clinic’s medical-information procedures.
The Clinic processes only the minimum personal information needed for each purpose. If pseudonymized information is processed separately, the relevant details will be added to this Policy.
2. Purposes and Retention Periods
Membership and account management
- Purpose: identity verification, sign-up and login, account administration, email verification, and abuse prevention
- Retention: until account deletion. Direct identifiers are promptly deleted or de-identified, while records required by law are retained separately for the applicable period.
Consultations, inquiries, and online booking
- Purpose: request intake, identity verification, scheduling, booking lookup, change or cancellation guidance, customer support, and dispute handling
- Retention: three years from submission. If the content becomes part of a medical record, the statutory retention period for that record applies.
Optional marketing communications
- Purpose: notices about events, benefits, and Clinic news
- Retention: until consent is withdrawn or the account is deleted. Refusing consent does not restrict core consultation or booking services.
Service operation, security, and analytics
- Purpose: session continuity, incident response, access statistics, prevention of unauthorized access or spam, and security audits
- Retention: raw page-view and event records for 180 days, visitor identifiers for 365 days, and ordinary web sessions for three hours after the last activity. Records may be retained separately while a legal obligation or security incident remains unresolved.
3. Personal Information Processed and Collection Methods
Collected directly
- Sign-up: name, email address, phone number, encrypted password value, and consent timestamp
- Profile: date of birth, gender, country and language settings, and profile image if provided
- Consultations and inquiries: name, email address, phone number, inquiry type, subject, content, optional images, and consent timestamp
- Online booking: booking number and type, name, phone number, optional email, preferred date and time, selected treatments, quantity, estimated amount, requests, consent status, and document version
Received from social-login providers: provider name (Google, Kakao, or Naver), provider member identifier, email address, name or nickname, and profile-image URL, limited to the fields authorized on the provider’s consent screen.
Generated or collected automatically: IP address and one-way IP hash, visitor and session identifiers, cookies, device and browser data, access time, page URL, path and title, referrer, screen size, acquisition and campaign data, language, clicks, form-submission events, and error or security logs.
Information is collected through web or mobile inputs, consultation and booking flows, social-login integration, and records generated during service use. The Clinic does not request resident registration numbers or bank and card details during website membership or booking.
4. Sensitive Information and Children Under 14
General website inquiry and booking forms do not require health data such as diagnoses, medical history, surgery history, or medication history. Do not voluntarily enter health data or body images in request fields. Where health information is needed for treatment, the Clinic provides a separate process under applicable law.
Website membership services are generally offered to persons aged 14 or older. When booking treatment or processing personal information for a child under 14 is necessary, the request must be made through a legal representative and follow the legally required consent and identity-verification process.
The Clinic does not provide a feature for publishing sensitive information. Users should avoid posting personal information in public areas such as public boards.
5. Disclosure to Third Parties
The Clinic does not routinely provide personal information to third parties. It does so only to the minimum extent necessary when the data subject separately consents or the law specifically permits or requires disclosure.
If third-party disclosure becomes necessary, the Clinic will give advance notice of the recipient, purpose, data fields, retention period, and right to refuse, and will obtain consent where required. Information may be disclosed in response to a lawful request from an investigative or other competent authority.
6. Service Providers
Processor: Google LLC (Gmail/SMTP)
- Services: sending sign-up verification, password reset, consultation, and booking emails
- Data processed: recipient email address and name, email subject, and guidance content
Through contracts or service terms, the Clinic manages restrictions on processing beyond the entrusted purpose, security controls, subprocessors, incident response, and oversight. Changes to a processor or entrusted work will be disclosed in this Policy.
Electronic files are deleted in a manner designed to prevent recovery, and printed materials are shredded or destroyed by an equivalent method. Access logs and security records are retained and deleted according to operational policy.
7. Overseas Transfers
Recipient: Google LLC and affiliated service operators
- Destination: the United States and other countries where Google processes services
- Data: email address, recipient name, email subject, and guidance content
- Purpose: sending authentication and service-guidance emails
- Timing and method: transmitted over encrypted networks when an email is sent
- Retention: until the sending purpose is fulfilled or the related service contract ends, subject to any statutory period applicable to the provider
Email delivery is necessary to complete sign-up verification or provide consultation and booking guidance requested by the user. Users who do not want an overseas transfer may contact the privacy team, but email verification or replies may then be unavailable.
8. Cookies and Automatically Collected Information
The website may use session cookies for login, security, and language settings; a saved-email cookie when that option is selected; a visitor identifier retained for 365 days; and a 30-minute analytics-session identifier. Analytics may also collect IP addresses, and raw analytics records are retained for 180 days.
Users can inspect, delete, or block cookies in browser settings. Blocking cookies may prevent login, cart, booking, or language-retention features from working correctly. Settings are available in the privacy or cookie menu of the relevant browser.
9. Data Destruction
The Clinic destroys personal information without undue delay when the retention period expires or the processing purpose is fulfilled. Information that must continue to be retained by law is stored separately and is not used for another purpose.
Electronic files are securely deleted so that recovery or reproduction is difficult, and paper records are shredded or incinerated. When an account is deleted, direct identifiers are deleted or de-identified; information remaining in backups is destroyed according to the established backup rotation cycle.
Information incorporated into medical records, including treatment and surgery records, is retained separately for the period prescribed for each record under medical regulations and then destroyed.
10. Rights of Data Subjects and Legal Representatives
A data subject or authorized representative may request access, transmission, correction, deletion, suspension of processing, withdrawal of consent, or account deletion. Requests may be made by email, phone, or visit and will be handled under applicable procedures after identity or authority is verified.
Users must keep personal and account information current and must not misuse another person’s information or post unnecessary personal information in public areas.
A request may be restricted where retention is required by law or where fulfilling the request could infringe another person’s rights and interests. The Clinic will explain the reason for any restriction.
11. Security Measures
The Clinic limits personnel access to what is required for their duties, stores passwords using one-way encryption, and operates administrative and technical controls including administrator authentication, access control, session management, audit records, and periodic access reviews.
The Clinic also maintains transport protection, security updates, malware prevention, backup and recovery procedures, and physical access restrictions to prevent loss, theft, leakage, forgery, alteration, or damage.
12. Privacy Contact and Remedies
Privacy and grievance contact: LI:ET Clinic Privacy Team
Representative: Enoch Park
Email: lietclinic26@gmail.com
Phone: 010-3002-1023
For personal-information infringement reports or counseling, contact the KISA Privacy Infringement Report Center at 118 or privacy.kisa.or.kr. For dispute mediation, contact the Personal Information Dispute Mediation Committee at 1833-6972 or kopico.go.kr. Contacting the Clinic first allows us to investigate and respond promptly.
13. Changes and Effective Date
Additions, deletions, or amendments to this Policy will be announced on the website before they take effect. Changes that materially affect data-subject rights will be announced sufficiently in advance, and separate consent will be obtained where required.
Notice date: August 12, 2026
Effective date: August 19, 2026