Privacy Policy

Effective June 23, 2026

This policy explains what personal information we process, for what purposes, and how we protect it.

1. General

DTDMC Crisis Diagnosis Platform (the "Company") complies with applicable laws, including the Personal Information Protection Act, and maintains this policy to protect members' personal information.

2. Personal Information We Collect

The Company collects the following personal information.

  • Sign-up (required): email, name, nickname, password (stored encrypted).
  • Optional: phone number, country, profile information.
  • Consent records: whether the terms, privacy, and marketing consents were granted, the time of consent, the IP at consent, and the terms version.
  • When using health tools (sensitive information): aging-pathway responses and results, records such as calcium, exercise, and bone density, member-entered information such as medications and health conditions, and bone-density (DXA) report images.
  • When requesting consultation: the consultation content and information needed to respond.
  • When using the community: posts and comments shown under a nickname (email is not disclosed).
  • Automatically collected: access IP, access time, usage records, device and browser information, cookies, and session information.

Even at payment, the Company does not directly store payment-method information such as card numbers (the payment gateway processes it).

3. Purpose of Collection and Use

  • Member identification, sign-up and login, identity confirmation, and prevention of misuse.
  • Providing the Service: economic and health diagnosis information, record management, the community, and mileage operation.
  • Receiving consultation requests and contacting members to provide reports (offline).
  • Notices and inquiry responses, security and incident response, and service improvement.
  • Fulfilling legal obligations and responding to disputes.
  • Sending marketing and event information only to members who have consented.

4. Retention and Use Period

1) In principle, the Company destroys personal information without delay upon a member's withdrawal or once the purpose of collection and use is achieved.

2) However, where retention is required by applicable law, the information is kept for the relevant period.

  • Records on contracts or withdrawal of subscription: 5 years (Electronic Commerce Act).
  • Records on payment and supply of goods: 5 years (Electronic Commerce Act).
  • Records on consumer complaints or dispute handling: 3 years (Electronic Commerce Act).
  • Login and access records: 3 months or more (Protection of Communications Secrets Act, etc.).

Specific retained items and periods will be finalized after operator confirmation: [To be provided by the operator]

5. Provision to Third Parties

The Company does not provide members' personal information to third parties beyond the scope stated in this policy, except where the member has consented in advance or where required by law.

6. Outsourcing and Cross-Border Transfer

To provide a stable service, the Company outsources processing of personal information to domestic and overseas providers as below, and some processing takes place on overseas servers. When outsourcing, the Company stipulates the matters needed to ensure personal information is managed safely.

  • Database hosting: storage of member and service data (cloud database such as Turso).
  • Server hosting: operation of the Service (Render, Singapore region / Vercel).
  • File storage: private storage of report images and the like (Cloudflare R2).
  • Email delivery: sign-up, verification, and notice emails (SendGrid).
  • SMS delivery: verification and notice messages (SMS delivery providers).
  • Report recognition: transcription of numbers from bone-density report images (Google generative AI, Gemini).
  • Payment processing (upon future introduction of paid services): payment gateway (Stripe, etc.).

The specific processors, transfer countries, timing and method of transfer, and retention periods will be reflected in this policy after operator confirmation: [To be provided by the operator]

7. Processing of Sensitive (Health) Information

1) The Company treats the health-related information members enter when using health tools, and bone-density (DXA) report images, as sensitive information and processes them with separate consent.

2) Report images are kept in private storage with access restricted so that only the member can view them.

3) Report recognition is an auxiliary process that transcribes numbers; the Company does not use it for medical diagnosis purposes.

4) A member who does not wish to enter health information or register reports may choose not to use those features.

8. Rights of Data Subjects

1) Members may at any time request access to, correction, deletion, or suspension of processing of their personal information, and may withdraw consent.

2) Some information can be viewed and edited directly in in-service settings; other requests are received through the contact below.

3) Upon receiving a request, the Company processes it without delay in accordance with applicable law.

9. Destruction of Personal Information

1) The Company destroys personal information without delay once the retention period ends or the processing purpose is achieved.

2) Electronic files are deleted by an unrecoverable method, and printouts are shredded or incinerated.

10. Security Measures

  • Passwords are stored encrypted by a method that cannot be decrypted.
  • Authentication information is managed with secure cookies (httpOnly), and the communication channel is encrypted (HTTPS).
  • Sensitive files such as report images are kept in private storage with access controlled.
  • Access-rights management, retention of access logs, and limits on abnormal access (request rate limiting) are applied.

11. Cookies and Automatic Collection

1) The Company uses cookies and sessions to maintain login, for security, and to improve the Service.

2) Members may refuse cookie storage through browser settings, but in that case use of some features, such as login, may be limited.

3) The Company does not use third-party tracking tools for advertising.

12. Personal Information of Children Under 14

The Company does not, in principle, accept sign-up by children under 14, and where collection is unavoidable, obtains the consent of a legal representative.

13. Privacy Officer and Contact

The privacy officer and contact are as follows: [To be provided by the operator] (name, title, email, contact).

Members who need consultation regarding infringement of personal information may contact bodies such as the Korea Internet & Security Agency Privacy center (privacy.kisa.or.kr, 118).

14. Changes to This Policy

This policy may be revised in line with changes in law or the Service; revisions and their effective date are announced on the Service.

Effective date: June 23, 2026

← DTDMC Insight