PRIVACY POLICY

Privacy Policy

BASE Dermatology Clinic values your personal information
and manages it securely in accordance with applicable laws.

BASE Dermatology Clinic (hereinafter "the Clinic") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act, to protect the personal information of data subjects and to promptly and smoothly handle related grievances.

Article 1 (Purpose of Processing Personal Information)

The Clinic processes personal information for the following purposes. The processed personal information will not be used for any purpose other than those stated below, and if the purpose of use changes, necessary measures such as obtaining separate consent will be taken.

  1. Online consultation and booking — We collect name, contact number, email, treatment of interest, and inquiry details for consultation responses and appointment guidance.
  2. Appointment confirmation and management — Schedule notifications, modification/cancellation processing, and follow-up guidance.
  3. Service improvement and statistical analysis — Anonymized data is used to improve service quality.

Article 2 (Categories of Personal Information Processed)

The Clinic processes the following categories of personal information.

CategoryRequired ItemsOptional Items
Online Consultation Booking Name, contact number, inquiry details, consent to personal information collection and use Email, treatment of interest
Automatically Collected IP address, access time, cookies, browser information -

Article 3 (Processing and Retention Period of Personal Information)

  1. The Clinic processes and retains personal information within the retention and use period prescribed by law or within the retention and use period agreed upon at the time of collection from the data subject.
  2. The processing and retention periods for each type of personal information are as follows.
    • Online consultation booking information: 3 years after consultation ends (Act on the Consumer Protection in Electronic Commerce, Etc.)
    • Medical records: Retained for up to 10 years in accordance with Article 22 of the Medical Service Act
    • Automatically collected information (logs): 3 months

Article 4 (Provision of Personal Information to Third Parties)

The Clinic processes personal information of data subjects only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as the data subject's consent or special provisions of law.

Article 5 (Entrustment of Personal Information Processing)

The Clinic entrusts the processing of personal information as follows for smooth handling of personal information tasks.

TrusteeEntrusted Tasks
Website hosting provider Website operation and data storage
Google (reCAPTCHA) Spam/abuse prevention

In entrustment contracts, in accordance with Article 26 of the Personal Information Protection Act, matters regarding prohibition of processing personal information beyond the purpose of the entrusted task, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the trustee, and liability including compensation for damages are specified in documents such as contracts, and we supervise whether the trustee processes personal information safely.

Article 6 (Rights and Obligations of Data Subjects and Methods of Exercise)

  1. Data subjects may exercise the following rights related to personal information protection with the Clinic at any time.
    • Request to access personal information
    • Request for correction in case of errors
    • Request for deletion
    • Request to suspend processing
  2. Rights may be exercised through written request, phone, or email to the Clinic, and the Clinic will take action without delay.

Article 7 (Destruction of Personal Information)

  1. The Clinic will destroy personal information without delay when it is no longer needed, such as when the retention period has expired or the purpose of processing has been achieved.
  2. The methods of destruction are as follows.
    • Electronic files: Permanently deleted using methods that prevent recovery or reproduction
    • Paper documents: Shredded or incinerated

Article 8 (Measures to Ensure the Security of Personal Information)

The Clinic takes the following measures to ensure the security of personal information.

  1. Administrative measures: Establishment and implementation of internal management plans, regular staff training
  2. Technical measures: Management of access permissions to personal information processing systems, installation of access control systems, encryption of unique identification information, installation and operation of security programs
  3. Physical measures: Access control for computer rooms, data storage rooms, etc.

Article 9 (Personal Information Protection Officer)

The Clinic designates the following Personal Information Protection Officer to oversee the handling of personal information processing tasks and to handle grievances and damage relief for data subjects related to personal information processing.

Personal Information Protection Officer

Name: Dr. Byungsoo Kim

Position: Chief Director

Phone: 051-711-4111

Email: baseskin@baseskin.co.kr

Article 10 (Methods of Remedy for Infringement of Rights)

Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, or other relevant organizations to obtain remedies for personal information infringement.

Article 11 (Changes to the Privacy Policy)

This Privacy Policy is effective from May 15, 2026. In case of additions, deletions, or corrections to changes in accordance with laws and policies, we will notify through announcements on our website at least 7 days before the implementation of changes.