Cellin Clinic Hongdae (hereinafter the "Clinic") establishes and discloses the following privacy policy in accordance with Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
The establishment and operation of the Site and system are performed by Rootsquare Inc., the brand headquarters, under the entrustment of the Clinic (see Article 6).
This privacy policy applies from September 15, 2026.
Article 1 (Purpose of Processing Personal Information)
The Clinic processes personal information for the following purposes, and does not use the personal information it processes for purposes other than the following. Where the purpose of use changes, the Clinic shall implement the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
- Homepage membership registration and management: confirmation of intent to register, identification and authentication of the individual, maintenance and management of membership status, prevention of unauthorized use of the Service, confirmation of whether the consent of a legal representative has been obtained when processing the personal information of a child under the age of 14, various notices and notifications, and grievance handling
- Provision of appointment services: receipt, confirmation, change, and cancellation of visit appointments, and appointment-related guidance
- Handling of civil affairs: identity verification, confirmation of the matter of complaint, contact and notification for fact-finding, and notification of the processing result
- Use for marketing and advertising (optional): provision of advertising information such as events and benefits, and provision of participation opportunities (limited to cases where the data subject has consented)
Article 2 (Processing and Retention Period of Personal Information)
① The Clinic processes and retains personal information within the retention and use period prescribed by statute or the retention and use period consented to by the data subject.
② The processing and retention period for each item is as follows.
- Membership registration and management, provision of appointment services, and handling of civil affairs: until the withdrawal of membership. Upon withdrawal of membership or achievement of the processing purpose, the relevant personal information is destroyed without delay.
- Use for marketing and advertising (optional): until consent is withdrawn
③ Notwithstanding the above periods, where there is an obligation to retain information under relevant statutes, the information is retained for the period prescribed by such statute regardless of whether membership has been withdrawn (e.g., service access records, etc., under the Protection of Communications Secrets Act).
Article 3 (Items of Personal Information Processed)
The Clinic processes the following items of personal information. Membership registration is carried out per branch, and where the same person has registered at two or more branches, that person is registered and managed separately as a member of each branch. Accordingly, requests for inspection, correction, deletion, and withdrawal are also processed on the basis of the member of the relevant branch.
- Direct membership registration (Korean nationals) — required: ID, password, name, contact information (mobile phone number), date of birth, gender
- Direct membership registration (foreign nationals) — required: ID, password, name, email address, date of birth, gender (for foreign national members, the email address is collected instead of contact information (mobile phone number))
- Registration via social login — where a person registers or logs in via Kakao (with future expansion to Naver, Google, etc.), information necessary for member identification and registration, such as the name (or nickname), email, contact information, date of birth, gender, and social account identifier, is provided from the relevant social login provider (the items provided may vary depending on each provider's policy and the scope to which the Member has consented)
- At the time of an appointment: desired branch, desired date and time
- Automatically collected items: access logs, access IP information, cookies, service usage records
- Optional items: areas of interest, whether to receive marketing information
- Children under the age of 14: the name, relationship, and contact information of the legal representative (see Article 4)
Article 4 (Matters Concerning the Processing of Personal Information of Children Under the Age of 14)
① When the Clinic collects the personal information of a child under the age of 14, it obtains the consent of the legal representative and collects the minimum personal information necessary to perform the relevant service (required items: the name, relationship, and contact information of the legal representative).
② When the Clinic collects the personal information of a child under the age of 14, it may request from the child the minimum information such as the name and contact information of the legal representative, and it verifies whether a lawful legal representative has consented by one of the following methods.
- Having the legal representative indicate whether they consent on an internet site posting the contents of the consent, and notifying the legal representative, by text message to their mobile phone, that the Clinic has confirmed such indication of consent
- Having the legal representative indicate whether they consent on an internet site posting the contents of the consent, and verifying their identity through identity authentication of the legal representative's mobile phone, etc.
- Sending an email containing the contents of the consent and receiving from the legal representative an email containing an expression of intent to consent
- Informing the contents of the consent by telephone and obtaining consent, or informing of a method by which the contents of the consent can be confirmed and then obtaining consent through a subsequent telephone call
- Other methods equivalent to the above that inform the legal representative of the contents of the consent and confirm the expression of intent to consent
③ The legal representative may request the inspection, correction, or update of the relevant child's personal information, or withdraw consent to membership registration, in which case the Clinic shall take the necessary measures without delay.
Article 5 (Matters Concerning the Provision of Personal Information to Third Parties)
The Clinic processes the data subject's personal information only within the scope specified in Article 1, and does not provide personal information to third parties except with the consent of the data subject or in cases falling under Articles 17 and 18 of the Personal Information Protection Act (such as special provisions of law).
Article 6 (Matters Concerning the Entrustment of Personal Information Processing)
① The Clinic entrusts personal information processing tasks as follows for the smooth handling of personal information affairs.
- Rootsquare Inc. — establishment, operation, and maintenance of the Cellin online reservation site and system, member management, and appointment receipt processing
② Where personal information is provided from a social login provider (such as Kakao) within the scope to which the Member has consented, the privacy policy of each provider also applies to matters concerning the collection and use of such information.
③ When entering into an entrustment contract, the Clinic specifies in documents such as the contract, pursuant to Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information beyond the purpose of performing the entrusted tasks, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of the entrustee, and liability such as compensation for damages, and supervises whether the entrustee processes personal information safely.
④ Where the content of the entrusted tasks or the entrustee changes, the Clinic shall disclose it without delay through this privacy policy.
Article 7 (Matters Concerning the Processing of Pseudonymized Information)
① The Clinic may process pseudonymized information without the consent of the data subject for purposes such as the compilation of statistics and scientific research, pursuant to Article 28-2 of the Personal Information Protection Act. Pseudonymized information means information processed so that a specific individual cannot be identified without additional information.
② The Clinic may allow Rootsquare Inc., which has been entrusted with the operation of the Service, to use member information in a pseudonymized or anonymized form so that it can perform statistics and analysis for ascertaining and improving the usage status of Cellin's overall services. In this case, the analysis does not include information that can identify an individual.
- Purpose of processing: compilation of service usage statistics and improvement of the service through analysis of usage behavior
- Items processed: information such as age group, gender, branch, and appointment/usage records that has been pseudonymized or anonymized
- Retention and use period: until the purpose of analysis is achieved
③ When processing pseudonymized information, the Clinic complies with the following pursuant to Articles 28-4 and 28-5 of the Personal Information Protection Act.
- It does not process pseudonymized information for the purpose of re-identifying a specific individual, and where information that can identify a specific individual is generated in the course of processing, it immediately ceases processing and recovers and destroys such information.
- It separately stores additional information for restoring the pseudonymized information to its original state, and takes the technical and managerial measures necessary to ensure safety, such as minimizing access privileges.
Article 8 (Procedure and Method for Destroying Personal Information)
① When personal information becomes unnecessary, such as upon the lapse of the retention period or the achievement of the processing purpose, the Clinic destroys the relevant personal information without delay.
② Where, despite the lapse of the retention period consented to by the data subject or the achievement of the processing purpose, the information must continue to be retained under other statutes, the relevant personal information is moved to a separate database or retained in a different storage location.
③ The procedure and method of destruction are as follows.
- Procedure of destruction: the personal information for which a cause for destruction has arisen is selected and destroyed with the approval of the privacy officer.
- Method of destruction: information in the form of electronic files is permanently deleted by a technical method that makes recovery and reproduction impossible, and information recorded in paper documents is destroyed by shredding or incineration.
Article 9 (Rights and Obligations of the Data Subject and Legal Representative and the Method of Exercising Them)
① The data subject may at any time request the Clinic to inspect, correct, delete, or suspend the processing of personal information.
② The exercise of the rights under Paragraph 1 may be made in writing, by email, etc., pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Clinic shall take measures thereon without delay.
③ The exercise of rights may be made through a representative such as the data subject's legal representative or a duly authorized person, in which case a power of attorney in the form of Annexed Form No. 11 of the Notice on Methods of Personal Information Processing must be submitted.
④ A request for the inspection of personal information and the suspension of processing may be restricted pursuant to Articles 35(4) and 37(2) of the Personal Information Protection Act, and a request for correction or deletion may be restricted where the personal information is specified as a subject of collection in other statutes.
⑤ The Clinic verifies whether the person who exercises the rights is the individual concerned or a duly authorized representative.
Article 10 (Measures to Ensure the Safety of Personal Information)
The Clinic takes the following measures necessary to ensure safety, pursuant to Article 29 of the Personal Information Protection Act.
- Managerial measures: establishment and implementation of an internal management plan, minimization and regular training of staff handling personal information, and regular self-inspection
- Technical measures: management of access privileges to the personal information processing system, installation and operation of an access control system, encrypted storage and transmission of important information such as passwords, retention of access records and prevention of forgery and alteration, and installation and periodic update and inspection of security programs
- Data separation per branch: member data is logically separated and managed per branch (tenant), and access privileges are controlled so that each branch can access only its own member data.
- Physical measures: access control over computer rooms, data storage rooms, etc.
Article 11 (Matters Concerning the Installation, Operation, and Refusal of Devices That Automatically Collect Personal Information)
① The Clinic uses "cookies" that store usage information and retrieve it from time to time in order to provide customized services to users.
② A cookie is a small amount of information that the website server sends to the user's browser, and it is stored on the user's terminal.
- Purpose of using cookies: provision of optimized information by ascertaining visit and usage patterns, confirming whether a secure connection is used, etc.
- Installation, operation, and refusal of cookies: users may refuse the storage of cookies in the settings (options) of their web browser. However, if the storage of cookies is refused, difficulties may arise in using some customized services.
Article 12 (Privacy Officer)
① The Clinic designates a privacy officer as follows to take overall responsibility for tasks concerning the processing of personal information and to handle complaints from data subjects and provide remedies for damages in connection with the processing of personal information.
- Name: PARK TAE WOOK
- Position: Chief Director
- Contact: 1800-6156
② The data subject may direct all inquiries, complaint handling, and remedies for damages related to personal information protection arising during the use of the Service to the privacy officer, and the Clinic shall respond and process them without delay.
Article 13 (Department That Receives and Handles Requests for Inspection of Personal Information)
The data subject may make a request for the inspection of personal information under Article 35 of the Personal Information Protection Act to the privacy officer (contact: 1800-6156).
Article 14 (Remedies for Infringement of the Data Subject's Rights and Interests)
In order to obtain remedies for infringement of personal information, the data subject may apply for dispute resolution or counseling to the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
- National Police Agency: 182 (no area code) (ecrm.cyber.go.kr)
Article 15 (Change of the Privacy Policy)
① This privacy policy applies from September 15, 2026.
② Where the Clinic changes this policy, it shall give notice of the changes through the Site notices from 7 days prior to enforcement (from 30 days prior in the case of a change that is disadvantageous or material to the data subject).
