CHOWIS PRIVACY POLICY

We respect your privacy and protect it. So, we have developed a Privacy Policy that covers how we collect, use, disclose, transfer, and store your information. Please take a moment to familiarize yourself with our privacy practices to be clear how we handle your personal information, what we do and don’t collect, and why.

  1.  Purpose of Collection and Use of Personal Information

Our primary task is to securely process the User’s personal information. Such information shall be used to provide a seamless service only within purpose and scope the user have consented, or except as otherwise prescribed in the relevant laws and regulations. You may be asked to provide your personal information during sign-up process, and our necessary services. We use only the necessary data for the purpose of (1) providing the accurate skin/hair analysis result and product recommendation services, (2) the statistical purposes and (3) improving the usability of the service quality (providing app usage guide, notice and promotional events and newsletters) and (3) improving the algorithms and training AI models which will be applied to the analysis services for the improved accuracy.

The following minimum personal information is collected when a user signs up for the Service or while the user uses the Services, through the home page, individual applications, and programs, and etc.

     2. What personal information we collect

A. Required Information: Information required to provide the fundamental features of the concerned service

Year of birth, gender, ethnicity, photos taken*, diagnosis results and service records.

* Sensitive Information: This app may collect the photos of the user’s face and skin/hair/scalp which are required for the app to conduct the proper consultation process, the main purpose of the app. Especially, the face photo is used for the app’s full facial viewing services where the users can understand the general skin condition and problems easily prior to performing detailed parameter-based process. This data will not be seen by other users, nor shared to any third parties without your consent. In addition, this data can be deleted in its entirety immediately upon the user’s request.

B. Optional Information: Additional information which needs to be collected to provide more specialized services

Name, email address, phone number, address

3. How we use your personal information

A. We use the personal information we collect to provide sustainable customer management and to determine appropriate services such as product recommendation.

B. Personal information of a user which requires the user’s consent is collected after obtaining such consent of the user prior to his/her use of the specific service, which consent is given by way of checking separate online checkboxes or through offline documentation. If a user checks an online checkbox or marks on the consent field of the offline document, the user is considered to consent to the collection and processing of the relevant personal information.

  1. Provision of Personal Information to Third Parties 

A. The Company shall use personal information of each user only within the scope of the purpose of collection and use of the personal information, and without the prior consent of a user, shall not use the personal information beyond such purpose or provide the personal information outside the Company, with the exceptions:

(1) where the user explicitly consents

(2) where the applicable laws and regulations requires

(3) where it is necessary for statistics, academic, market or industrial research in unidentifiable format.

B. Users may refuse to give consent to the provision of personal information to a third party, where applicable, provided that in such case the user may be restricted from using the service provided by the third party.

C. When providing personal information of a user to a third party in a foreign country, the Company shall inform the user of the same and obtain a separate consent, where necessary.

5. Entrustment of Personal Information Process and the Transfer of Personal information to Overseas

The Company may entrust the personal information processing work to a third party to perform contracts on providing services and improve convenience of users. When providing personal information of a user to a third party, the Company shall inform the user of the same and obtain a consent, where necessary.

As of today, some personal information is transferred overseas to perform the following affairs:

– Transferred company: Amazon Web Services, Inc

– Address : 410 Terry Avenue North, Seattle, WA 98109-5210, USA.

– Transferred country: the USA

– Transferred data: all the data collected on the application as specified in this Privacy Policy

– Purpose of the Transfer: cloud data analysis and saving in Amazon Web Service 

– Duration of the retention by the Transferred company: as long as is reasonably necessary to fulfil the relevant purposes set out in this privacy notice and during the period required or permitted by law.

  1. Retention of User’s Personal Data

As a general rule, the Company will process and retain the user’s personal data for a maximum period of one (1) year for the purposes it was collected as specified in Article 1 of this Privacy Policy, after which point the Company will delete the user’s information. The user’s photos (face) taken will be stored up to five (5) years solely for the R&D purposes in order to improve the accuracy of the analysis upon the user’s consent, after which point the Company will delete the relevant data. In addition, when a user withdraws his/her registration or consent, the company will promptly take necessary actions to delete or erase the user’s data. 

7. Procedure and Method of Deletion of Personal Information

The Company deletes personal information immediately when the personal information becomes unnecessary, including upon expiry of the retention/use period applicable to the personal information and upon attainment of the purpose for which the personal information was processed. The procedure and method of deleting personal information are as follows:

A. Deletion Procedures: The Company selects personal information in respect of which an event requiring destruction has occurred, and deletes the personal information with the approval of the Company’s personal information protection officer.

B. Destruction Method: In the case of personal information recorded or stored in electronic files, the Company deletes the personal information by using the technical or physical method ensuring that the personal information is not restorable or reproducible, and in the case of personal information recorded or stored in paper documents, the Company shreds the personal information with a shredder or incinerate the personal information.

C. The Company shall not be responsible for any loss or damage not attributable to the Company’s fault, including any accident caused by negligence of a user or occurring within an area not managed by the Company (for example, personal information of users which are collected and used by the cosmetics store, skin clinic or skin care shop, etc. purchasing or lending the precuts of the Company), to the extent the Company has fulfilled its obligations as a personal information processor; provided that the Company takes such measures for ensuring the safety of personal information as provided in Article 6, in the event a user’s personal information is lost, leaked, falsified or damaged due to negligence of the Company’s internal manager or an accident in technical management, the Company shall inform the user of such fact and seek for proper actions and remedies

  1. The User’s right to access, correct and withdraws of his/her consent

With respect to any of his/her personal information collected by the Company, a user may, at any time, request access (inspection), correction (modification), withdrawal of any given consent (withdrawal from membership or termination of contract), deletion or suspended processing.

In addition, the Company shall take all measures necessary to ensure that the withdrawal of consent to collection of personal information (withdrawal from membership) can be done easier than the way the personal information is collected.

  1. Personal Information Protection Officer

A. The Company designates and operates the following personal information protection officer and personal information protection division in charge of personal information matters in general to handle and remedy data subject’s complaints and carry out other customer services related to the processing of personal information

B. Personal Information Protection Officer

– Name: Ryan Won Suk Choi

– Title/position: C.E.O.

– Contact Detail:

Address: A-1301-2, 184, Jungbu-daero, Giheung-gu, Yonginsi, Gyeonggi-do, South Korea 17950.

Email: privacy@chowis.com

C. The User may inquire the foregoing matters to Personal Information Protection Officer via mail or email. The request will be handled in a proper and timely manner.
When a user requests for the correction of personal information, the concerned information shall not be displayed until such correction is completed.

  1. Change in the Privacy Policy

A. This Privacy Policy may be changed or amended if necessary, including based on law, government policy or the Company’s internal policy, and any addition, deletion or change herein will be notified through “Notification” on the Company’s website in advance in the case of any material change in a user’s rights, prior to the effective date of such addition, deletion or change.

Privacy Policy Version Information: v.3

Privacy Policy Revision Date: Privacy Policy Enforcement Date: 2021. 7. 21.