Your data, handled with transparent care.
SureM Co., Ltd. ("SureM" or "the Company") collects, uses, retains, and disposes of personal information in line with the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection. This English version is provided for reference; the binding original is the Korean policy published at surem.com.
Contents
- 01Purpose and items of personal information collected
- 02Retention period and sharing with third parties
- 03Outsourced processing of personal information
- 04Retention periods by record type
- 05Disposal policy and procedure
- 06Use of cookies and your right to refuse
- 07Your rights and how to exercise them
- 08User obligations
- 09Linked websites
- 10Safeguards against leakage and breach
- 11Privacy officer
- 12External authorities
- 13Other terms
Purpose and items of personal information collected
1.1 Purposes of collection and use
SureM collects and uses personal information for the following purposes:
- Member registration and account management
- Verification of service usage and settlement of usage fees
- Development of new services and marketing communications
- Other operational matters required to deliver the service
1.2 Items collected
| Category | Items | Requirement |
|---|---|---|
| Required | Name, ID, password, mobile phone number, email, CI (duplicate-signup verification) | Mandatory |
| Optional | Company name, business registration number, address | Optional |
1.3 Automatically generated information
In addition to the items above, the following information may be generated and collected while you use the service:
- Site visits, clicks, search terms, purchases, and event participation
- Records of product purchases and service usage
- Other service-usage records relevant to operations and security
Retention period and sharing with third parties
SureM processes personal information in accordance with the retention and disposal rules below, and does not use personal information beyond the stated purposes or share it with third parties without the user's consent.
2.1 When third-party sharing applies
Before sharing personal information with a third party, SureM will notify the user of, and obtain consent to, the following:
- The recipient of the personal information
- The recipient's intended purpose of use
- The personal information items being shared
- The retention and use period applied by the recipient
2.2 Right to refuse consent
You may refuse consent to third-party sharing. If a particular service requires sharing to function, refusing consent may limit access to that specific service; access to other services is unaffected.
2.3 Minimisation
Where sharing is unavoidable, SureM shares only the minimum scope necessary for the stated purpose, and reviews any reasonable objection raised by the user and responds appropriately.
Outsourced processing of personal information
3.1 Why we outsource
SureM may entrust the processing of personal information to qualified service providers in order to operate and deliver its services reliably. Outsourcing is governed by written contracts that bind processors to confidentiality, security, and audit obligations.
3.2 Current processors
| Processor | Outsourced task |
|---|---|
| PowerMuseum.com Co., Ltd. | Mobile-phone payment processing |
| Payments Systems | Credit-card payment processing |
| Kakao Commerce Corp. | Other payment processing |
| KakaoPay Corp. | Easy-payment service |
| Gigastark (Daesungmark) | Mobile-phone payment processing |
Retention periods by record type
4.1 Disposal trigger
SureM destroys personal information once the purpose of collection has been fulfilled, and instructs any third-party recipients to do the same in accordance with applicable law. Triggers include:
- Member-withdrawal request, or withdrawal of consent to processing
- Expiry or termination of the contracted service period
4.2 Statutory retention periods
Where retention is mandated by law for billing, dispute resolution, or fraud prevention, SureM retains the following records for the periods shown:
| Record type | Retention period |
|---|---|
| Routine service-usage records | 6 months |
| Records of billing or billing disputes | 5 years |
| Records related to fraud and complaints | 5 years |
| Records of payment, billing, or refunds | 3 years |
| Records of penalties charged to users | 5 years |
| Successful sign-in records | 3 months |
| Anomalous sign-in records | 12 months |
Disposal policy and procedure
5.1 Method of disposal
Personal information submitted at sign-up is stored in encrypted form in a dedicated database. When disposal is triggered, electronic records are deleted irrecoverably and any printed material is shredded.
- Personal-information databases are encrypted and segregated from other operational data so that disposal can be performed cleanly.
5.2 Procedure
- Personal information is reviewed with the user's consent and either destroyed or moved to a separate, restricted archive.
- Records are classified per the relevant legal basis: anything no longer required for service or compliance is destroyed.
Your rights and how to exercise them
7.1 Access and correction
You can view and correct your personal information at any time through the relevant account screens on SureM's website.
7.2 Correction requests
When you request a correction, SureM will not use the affected data for service delivery or marketing until the correction has been completed. If incorrect personal information has already been shared with a third party, SureM will promptly notify that third party so they can correct their records.
7.3 Withdrawal of membership
- After signing in, you can request withdrawal from [My Page] → [Account] → [Withdraw membership].
- Once withdrawal is verified, SureM will delete all stored personal information and usage records, subject only to the statutory retention obligations listed in section 4.
User obligations
8.1 Accuracy of information
You are responsible for the accuracy of the personal information you provide. Issues caused by inaccurate or out-of-date information you supplied are attributable to you, not SureM.
8.2 Protecting your credentials
SureM provides multiple safeguards to protect your account, but you should never share your password with anyone.
Linked websites
SureM may link to external websites for your convenience. Content on linked sites is outside SureM's control, and any information you enter on a linked site is not covered by this policy. We recommend reviewing the privacy policy of any third-party site you visit through a link from SureM.
Safeguards against leakage and breach
To protect personal information (including name, address, phone number, email address, and account details), SureM applies the following technical and managerial measures:
10.1 Technical safeguards
- Data in transit is encrypted, and the underlying networks and applications use additional encryption layers where appropriate.
- Access control systems prevent unauthorised external access, with 24/7 monitoring and incident response in case of security violations or disasters.
- Regular penetration tests and integrity checks verify that user data has not been damaged or exposed.
- Role-based access — read, modify, delete, and other permissions — are scoped to the minimum necessary, and changes are logged.
10.2 Managerial safeguards
- A designated privacy officer and dedicated team oversee personal-information protection, with periodic training to reinforce security culture.
- All staff receive security training, and additional training is delivered whenever this policy is amended. Clear escalation paths are in place so that suspected incidents are handled quickly.
- Managerial measures run alongside technical safeguards, and the combination is verified through periodic audits. Users are asked to change their password regularly and to sign out after use as part of shared responsibility.
- In the event of an incident, SureM will promptly notify affected users and provide the support and remediation required.
Privacy officer
- suremaster@surem.com
- Phone
- 1588-4640
Phone support is available 09:00–18:00 KST on Korean business days. Email is monitored continuously.
Other terms
13.1 Amendments
SureM may revise this privacy policy to reflect changes in law or business operations. When the policy is revised, SureM will provide advance notice on the website or by email.
13.2 Enforcement
On request, SureM will disclose change history, current status, third-party sharing details, and marketing-use status; you can ask SureM to correct or delete information within the scope permitted by applicable law.
- Company name
- SureM Co., Ltd.
- Registered address
- Unit 03, 9F, 85, Gwangnaru-ro 56-gil, Gwangjin-gu, Seoul, Republic of Korea
- Business registration no.
- 211-86-93893
- Mail-order business no.
- 2018-Seoul-Gwangjin-0648
- Korea desk
- Tel 1588-4640 · Fax 02-457-4640
- Global desk
- +1 714 494 3062
- English desk
- +82 70 4162 4744
- Chinese desk
- +82 70 4162 4714
- Mongolian desk
- +82 70 4162 4750
Have a question about how we handle your data?
Our privacy team will respond to formal requests within the timelines required by Korean law. You can also reach our general support team for routine questions.