Privacy Policy
Privacy Policy
This translation is provided for convenience only. In the event of any discrepancy, the Korean original shall prevail.
Effective Date: June 1, 2026
FOREST AG405 places importance on users' personal information and complies with the Personal Information Protection Act.
Article 1 (Purposes of Collection and Use of Personal Information)
FOREST AG405 (the "Company") processes personal information for the following purposes. Personal information being processed will not be used for purposes other than the following, and if the purpose of use changes, the Company will implement necessary measures such as obtaining separate consent. ① Membership registration and management - Confirming intent to register as a member, identifying and authenticating members in connection with the provision of membership services, maintaining and managing membership status, preventing fraudulent use of the Services, and providing various notices and notifications, etc. ② Provision of services - Providing services such as admission ticket and program reservations, facility rental/wedding inquiries, and accommodation reservations, providing content, and providing customized services ③ Use for marketing and advertising - Developing new services and providing customized services, providing event and promotional information and opportunities to participate, verifying the validity of the Services, identifying access frequency, or compiling statistics on members' use of the Services
Article 2 (Items of Personal Information Collected)
The Company collects the following items of personal information. ① Required items - Membership registration: name, email, password, contact information - Reservation services: name of person making the reservation, contact information, email, reservation details - Inquiry services: name, contact information, email, inquiry content ② Optional items - Consent to receive marketing communications ③ Information automatically generated and collected during use of the Services - IP address, cookies, service usage records, visit records, records of improper use
Article 3 (Retention and Use Period of Personal Information)
① The Company processes and retains personal information within the retention and use period required by law or the retention and use period consented to by the data subject at the time of collecting personal information. ② The processing and retention periods for each type of personal information are as follows. - Membership information: until withdrawal of membership - Reservation information: 1 year after completion of the reservation - Inquiry content: 3 years after completion of processing the inquiry ③ Retention pursuant to relevant laws - Records concerning contracts or withdrawal of subscription, etc.: 5 years - Records concerning payment and supply of goods, etc.: 5 years - Records concerning consumer complaints or dispute resolution: 3 years - Records concerning website visits: 3 months
Article 4 (Provision of Personal Information to Third Parties)
The Company processes the personal information of data subjects only within the scope specified in Article 1, and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as the data subject's consent or special provisions of law. The Company does not currently provide users' personal information to any third party.
Article 5 (Outsourcing of Personal Information Processing)
① To improve its services, the Company outsources personal information processing tasks as follows. | Subcontractor | Outsourced task | Retention period | |---------|---------|---------| | (주)코리아포트원 | Provision of payment integration service | Until termination of the payment service | | (주)카카오 | Kakao login | Until withdrawal of membership | ② When entering into an outsourcing contract, the Company specifies in the contract or other documents, in accordance with relevant laws, matters concerning the prohibition of processing personal information for purposes other than performing the outsourced task, technical and managerial protective measures, restrictions on re-outsourcing, management and supervision of the subcontractor, and liability for damages, and supervises whether the subcontractor processes personal information safely.
Article 6 (Rights and Obligations of Data Subjects and Methods of Exercise)
① A data subject may exercise the following personal information protection rights against the Company at any time. - Request to view personal information - Request for correction in the event of an error, etc. - Request for deletion - Request to suspend processing ② The exercise of rights may be made against the Company in writing, by email, by fax, or by other means, and the Company shall take action on this without delay. ③ Where another law specifies that certain personal information is subject to collection, a request for correction or deletion of that personal information may not be made.
Article 7 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information. ① Administrative measures: establishing and implementing an internal management plan, regular employee training ② Technical measures: managing access rights to the personal information processing system, etc., installing an access control system, encrypting unique identification information, etc., installing security programs ③ Physical measures: access control for computer rooms, data storage rooms, etc.
Article 8 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
① The Company uses "cookies" that store and periodically retrieve usage information in order to provide users with individually customized services. ② Cookies are small pieces of information that a server used to operate the website sends to a user's computer browser, and they may also be stored on the hard disk of the user's PC. ③ Users have a choice regarding the installation of cookies. Accordingly, by setting options in their web browser, users may allow all cookies, be prompted for confirmation each time a cookie is saved, or refuse to save all cookies.
Article 9 (Personal Information Protection Officer)
The Company designates a Personal Information Protection Officer as follows, who is fully responsible for personal information processing matters and handles complaints and remedies for data subjects in connection with personal information processing. ▶ Personal Information Protection Officer - Name: 장경민 - Contact: 031-885-4050 - Email: min2494@hanmail.net Data subjects may direct all inquiries, complaint handling, and remedy requests related to personal information protection arising from their use of the Company's services to the Personal Information Protection Officer.
Article 10 (Changes to the Privacy Policy)
① This Privacy Policy applies from its effective date, and in the event of any addition, deletion, or correction of content due to changes in laws or policy, notice will be given through the notices section from 7 days before the changes take effect. ② Previous versions of the Privacy Policy can be found below.
Article 11 (Remedies for Infringement of Rights)
Data subjects may inquire about remedies for damages, consultations, etc., regarding infringement of personal information at the following institutions. ▶ Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency) - Responsibilities: reporting personal information infringement, requesting consultation - Website: privacy.kisa.or.kr - Phone: 118 (no area code needed) ▶ Personal Information Dispute Mediation Committee - Responsibilities: filing for personal information dispute mediation, collective dispute mediation - Website: www.kopico.go.kr - Phone: 1833-6972 (no area code needed) ▶ Supreme Prosecutors' Office Cyber Investigation Division: 02-3480-3573 (www.spo.go.kr) ▶ National Police Agency Cyber Bureau: 182 (cyberbureau.police.go.kr)
Revision History
- • June 1, 2026: Changed payment processing subcontractor ((주)토스페이먼츠 → (주)코리아포트원)
- • January 1, 2025: Privacy Policy established
