Privacy Policy
“Samsung Electronics Co., Ltd.” (hereinafter referred to as the “Company”) values the User’s personal information and is committed to complying with laws related to personal information such as the “Personal Information Protection Act” and the “Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.”
The Company shall inform the User of the purpose and methods regarding the use of the personal information received from the User and what measures are taken to protect the User’s personal information through the Privacy Policy.
0. General Provisions
“Personal information” refers to information about a living individual that may be used to identify the individual such as the last name, first name, resident registration number (or social security number), etc., including information that may be easily combined with other information to identify a specific individual although such information alone may not be sufficient to identify the individual.
※ Some of the information below includes details regarding data that may not be recognized as “personal information” as it may be impossible to identify a specific individual. To guarantee the right of self-determination of the User, the Company shall also notify as much of the Company’s policy regarding general data through this Privacy Policy.
The Company has posted this Privacy Policy on the first page of the Samsung Account Homepage (
account.samsung.com) so that Users can easily view it at any time.
In addition, information that applies specifically to certain services can be viewed by clicking on the names of the services under this Privacy Policy.
The Company has procedures established that are required for revision to continuously improve the Privacy Policy. In addition, in the event that a revision is made to the Privacy Policy, a version number, etc. shall be assigned to it so that the details of the revision may easily be identified.
This Policy shall take effect on October 15, 2021, and any revisions shall be announced on the website through notifications (or individually notified by mail/email/phone/SMS, etc.).
1. Rights of the User and the Legal Representative and How to Exercise Them
(1) The User and his/her legal representative may request to view, correct/delete, suspend processing, or withdraw consent to the following matters at any time in connection with the personal information of the registered User him/herself or a pertinent User under 14 years of age.
- – Personal information the Company possesses: Refer to “4. Personal Information Items to be Collected and Methods of Collection”.
- – The current status of the Company’s use of personal information or provision to a third party: Refer to “5. Purpose of Collection and Use of Personal Information” and “6. Provision and Overseas Transfer of Personal Information to Third Parties”.
- – The current status of the User’s consent to the collection, use, provision, etc. of personal information by the Company: When signing up to or using the service, etc. for the first time (for more information, please refer to “4. Personal Information Items to be Collected and Methods of Collection”, “5. Purpose of Collection and Use of Personal Information”, and “6. Provision and Overseas Transfer of Personal Information to Third Parties”).
For this, the “Change Personal Information” (or “Edit Member Information”, etc.) menu on the Homepage or Samsung Privacy Portal (https://privacy.samsung.com) may be used. Users may also use the main phone number (1588-4730), or contact the Privacy Officer by mail/phone/email.
The Company may refuse a request to view, correct/delete all or part of the personal information in the following cases.
- - When viewing is prohibited or restricted by law
- - When it may cause harm to the life/body of others or unduly infringe upon the property and other interests of others
(2) If the User requests correction of an error in personal information, the Company shall not use said personal information or provide it to a third party until the correction is completed. In addition, if incorrect personal information has already been provided to a third party, the third party shall be notified of the corrected information without delay.
The Company shall process personal information deleted or suspended from processing by the request of the User or the legal representative in accordance with the terms stated in “7. Retention and Usage Period of Personal Information” and ensures that it is not accessed or used for any other purposes.
The User must enter his/her accurate and up-to-date personal information. The User is responsible for any accidents that occur due to inaccurate information entered by the User, and if the User enters false information, such as information stolen from others, membership privileges may be lost.
The User not only has the right to have his/her personal information protected, but also has an obligation to protect himself/herself and not to infringe on the information of others. Please be careful not to leak the User’s personal information including the password and be careful not to damage the personal information of others including their postings. If the User fails to fulfill such responsibilities and damages the information and the reputation of others, the User may be subject to punishment under the “Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.”, or other laws.
2. Information on the Privacy Officer and Customer Support Department, etc.
To protect the User’s personal information and handle complaints related to personal information, the Company has designated departments and officers in charge of personal information protection as follows:
(1) Customer Support Department
Customer Support Department: Samsung Electronics Big Data Center BD Strategy Team
Telephone: 1588-3366
Contact Info: https://help.content.samsung.com
(2) Privacy Officer and Department in Charge of Personal Information Protection
Privacy Officer: Head of Privacy Office
Personal Information Protection Department: Personal Information Protection Office
Telephone: 1588-4730
Contact Info: privacy.sec@samsung.com
(3) Other Institutions
The User may report all complaints related to the protection of personal information that occurred while using the Company’s services to the Privacy Officer or the department in charge. The Company will respond to User’s report promptly and sufficiently.
If the User needs to report other personal information infringements or receive consultation, please contact the following organizations.
- - Personal Information Infringement Report Center (https://privacy.kisa.or.kr / 118 without area code)
- - Cybercrimes Investigation Division, Forensic Science Investigation Department, Supreme Prosecutors’ Office (http://cybercid.spo.go.kr / 1301 without area code)
- - National Police Agency Cyber Bureau (http://cyberbureau.police.go.kr / 182 without area code)
3. Matters Related to Installation, Operation, and Rejection of an Automatic Personal Information Collection Tool
Samsung uses “cookies” that frequently store and find the User’s information. Cookies are very small text files that are sent to the User’s browser by the server used for the operation of the Company’s website and are stored on the hard disk of the User’s computer.
(1) Purposes of Using Cookies, etc.
The Company uses cookies, etc. for the purposes of targeted marketing and provision of personalized customization service through the implementation of auto login function, analysis of access frequency or visit time, etc. of members and non-members, identification of the User’s taste and interests and tracking the trace, identification of the degree of participation in various events and the number of visits, etc.
(2) How to Set Cookies
The User has the right to choose whether to have cookies installed. Therefore, by setting options on the web browser, may allow all cookies, or confirm each time a cookie is stored, or refuse all cookies from being stored.
However, if the User refuses to have cookies installed, there may be difficulty in providing the services.
- - How to set cookies (on Internet Explorer 11.0): Select “Internet Options” from the “Tools” menu.
Click on the “Privacy” tab.
Select “Advanced” and set the suitable cookie acceptance level for you.
- – How to view cookies received (on Internet Explorer 11.0): Click “Internet Options” in the “Tools” menu.
Click on the “General” tab.
Go to “Settings” in “Search History,” and look at “View Files”.
- – How to refuse cookie installation (on Internet Explorer 11.0): Click on “Internet Options” in the “Tools” menu.
Click on the “Privacy” tab.
Select advanced level from “Default” and set to “Block all cookies”.
4. Personal Information Items to be Collected and Methods of Collection
(1) Personal Information We Collect
The Company collects the following information from the User when signing up or using the services for the first time.
When collecting personal information of Users, the Company collects minimum amount of personal information necessary for the provision of services.
The Company shall not restrict or refuse to provide services based on the reasons of the customer’s refusal to consent regarding collection/use of personal information on non-required items when creating an account and using individual services.
□ Required Information
※ The User may refuse to consent to the collection/use of required information, but may not be able to sign up, use the services, or use the Homepage, etc. if he/she refuses to consent as this information is necessary to provide the services.
① Personal information required for membership registration
- ㆍID (email address/mobile phone number), password, name, gender, date of birth, country information
- ㆍMobile phone number, duplication information (DI), encrypted connecting information (CI), information of the legal representative for children under 14 years of age (name, date of birth, CI, DI of the legal representative)
② Information necessary for using each service, service usage records/purchases or repair-related information
- ㆍUsage record of each service/purchase or repair-related information
- ㆍLog data, cookies and web beacons, usage time, app installation and deletion record, search words entered by the User, information uploaded by the User
- ㆍDevice information (information given to the device during the process of production and sale and information given during the operation of the device: includes IMEI, DUID, terminal model information, terminal OS information, Mac Address, access IP information, etc.), device purchase date (date of first use, date of first call, proof of purchase, etc.)
- ㆍPhone number, contact list, my profile, incoming/outgoing phone numbers, attached files
- ㆍUsage record of Samsung Members Community (includes nickname, postings, photos, comments, etc. entered by the User)
- ㆍUsage record of Samsung Rewards Service (point usage details)
- ㆍLocation information: Collected only when it is necessary to provide the service (for example, “Find My Mobile” service, etc.) with separate consent.
- ㆍVoice information: Collected only when it is necessary to provide the service (for example, “S Translator” service, etc.) with separate consent.
- ㆍInformation required to register for Samsung Electronics membership services: (Detailed information on Samsung Electronics membership Privacy Policy)
- ㆍ Homepage, membership site, Samsung Electronics Store, other event site activity information [ID, password, personally identifiable information, access log, usage record, cookies]
③ Samsung Cloud (collected only when using Samsung Cloud service)
- ㆍContent backed up or synchronized on Samsung Cloud such as Schedule, Contacts, Messages, Gallery (including details of photos/videos such as shooting date and time, location information at the time of shooting, etc.), S Note, Memo, Reminder, Settings for the internet browser/keyboard/email, etc. and relevant data
- ㆍ(When not synced with Microsoft OneDrive) When selecting the image analysis function from Samsung Cloud: Photo classification information (person, background, object, etc.)
- ㆍ(When synced with Microsoft OneDrive) Information provided by Microsoft: Gallery contents synchronized through OneDrive (including details of photos/videos such as shooting date and time, location information at the time of shooting, etc.) and relevant data, photo/video classification information (person, place, object, etc.)
※ Specific information items provided by Microsoft may vary slightly depending on the Samsung Cloud version, etc. that the User is using.
④ Items collected for the provision of the customization service (collected only when using the customization service)
The Company's devices and services are designed to provide customization service by cleverly and intelligently predicting what the User needs and wants.
If the User activates the customization service option, the User can receive an improved user experience such as customized contents, recommendations, etc. through the device and service, and the information necessary to provide such customization service (hereinafter referred to as “information for customization service”) is as follows.
- ㆍDevice information (unique identification information, setting information, status information, app installation list and frequency of use)
- ㆍMetadata of played music and saved photos
- ㆍContacts and frequency of contact
- ㆍInternet browser usage record (visited site information, search words, bookmarks, etc., excluding when using the secret mode)
- ㆍLocation information
- ㆍInformation and usage records registered in the Company's services
- ㆍThird-party service information linked to the customization service by the User
⑤ Items collected for the provision of the Share function (collected only when using the Share function)
- ㆍSamsung account ID, phone number (SIM, phone numbers saved on the terminal, or phone numbers registered on the Samsung account), Contact information (names/phone numbers/emails saved in the Contacts)
※ For a more convenient and accurate registration, the registered phone number may be collected/used for the two-step verification of the Samsung account.
⑥ Items collected for the provision of information through image analysis (collected only when using Bixby Vision)
- ㆍImage information, location information (GPS)
⑦ Items collected for the provision of Secure Wi-Fi service (limited to only when using the applicable service)
- ㆍData to be sent encrypted
⑧ Items collected for customer support (limited to only when using the 1:1 inquiry customer support)
- ㆍEmail address or phone number, country information (language information), product model name, service version information, inquiry details entered by individuals and attached files, and system log files
- ㆍSIM card serial number, service provider, base station information (limited to the sending function of call disconnection log)
- ㆍAdditional information collected when applying for a refund (of the following, items that require additional collection may vary depending on the payment method, etc.)
: Account information (bank, account number, account holder), contacts (phone number), purchased content, payment date and time, payment amount, Samsung Account information used at the time of payment, mobile phone number and service provider or credit card company and authorization number used for payment, reasons for refund request/payment cancellation
□ Optional Information
※ Users may refuse to consent to the collection/use of optional items, and because these are not required information for service provision, Users may be able to register for membership, use services, access the Homepage, etc. even after the refusal.
If the collection/use of optional items becomes necessary in the process of using the service, separate guidance shall be provided to obtain consent.
① Reason for registration, occupation, marital status, wedding anniversary, interest categories, main purpose of mobile phone use (personal/business), household information [name(s) of spouse and/or children • phone number • address • E-mail • social media account information • date of birth, etc.]
② Information related to mobile phone purchase [mobile service provider, mobile phone model name, date of registration, number of contracted installment months, place of purchase, purchase price, serial number, lot number]
③ Marketing, event details
- ㆍInformation related to marketing activity/events [details of marketing activity and results, details of event participation and results]
- ㆍPossession and use of coupons/event codes, prize selection/receipt result
④ Affiliate details
- ㆍInformation related to the affiliates and affiliate franchise stores [affiliate name, affiliate member number, affiliate member registration date, event participation date, benefits and marketing activity information related to the affiliates]
⑤ Information entered by customers at the time of service registration and use
- ㆍInformation entered at the time of registration for Samsung account: Photos
- ㆍInformation entered when using My Profile: Location
⑥ Other information provided by the User himself/herself related to conclusion/maintenance/performance/management/event participation, etc. of agreements
※ The Company does not collect sensitive information that may significantly infringe upon the User’s privacy (information about ideology/beliefs, membership of/withdrawal from labor unions/political parties, political opinions, health, sex life, etc.).
※ In principle, the Company does not collect personal information if the User is under 14 years of age.
When inevitably collecting personal information of a user under 14 years of age for the use of the service, the Company shall obtain the consent of the legal representative in advance, destroy the relevant information upon the completion of the related task without delay, and strictly manage the personal information while the task is in progress.
In addition, the Company shall not use the personal information of Users under 14 years of age for marketing purposes.
(2) Methods of Personal Information Collection
- - Collection of information directly entered/saved by the User through use of service/Homepage/email/consultation board/sweepstakes application, event participation, etc.
- - Collection through mail/fax/phone/PDA, etc. during the process of offline/call centers/repair service and consultation, etc.
- - Collection through tools that collect generated information
- – Collection of information provided by partners such as affiliate card operators, etc.
※ The Company has prepared a procedure to allow the User to select “Agree” or “Disagree” for each part of the Company’s Privacy Policy Agreement.
5. Purpose of Collection and Use of Personal Information
□ The Company uses the personal information collected for the following purposes.
① Member management and identity verification
- – Identity verification, age verification, confirmation of consent of a legal representative when collecting personal information from a child under 14 years of age, processing customer concerns such as complaints, delivery of notices, provision of benefits and guidance, prevention of misuse and unauthorized use by malicious users
- – When purchasing membership products and using services / Identity verification and personal identification for processing personal information and upon the information subject’s request to access, correct, delete, or suspend processing of personal information
② Provision of Services
- – Provision of products, services, and content, purchases and payments, product shipping
- – Provision of Samsung Rewards services such as points accumulation and use
- – Provision of optimized services for the User and improvement of functions (providing customized content and recommendation information, etc. based on the User's past usage behavior)
- – Provision of repair services and update information, etc. for the products purchased by the User
③ Provision of unified services through Samsung account
- – Provision of the same usage environment and functions on various devices connected through Samsung account
- – Provision of continuous customer support services
- – Using various services based on Samsung account and syncing basic data between services [Example: My Profile]
- – Provision of communication functions such as profile sharing, content, sending/receiving messages and attached files, sharing functions for sharing content by creating groups or links, and video calls
④ Used for improvement of existing services, development of new services and marketing/advertising, etc.
- – Customer satisfaction surveys, product/service development research, research/development/specialization of new services
- – Provision of marketing information such as events/promotions, etc. and delivery of prizes, provision of services and advertisement postings according to demographic characteristics, identification of access frequency, or analysis and statistics on members’ product purchases and service use, service/device/information recommendation, market trends inference, market research, and use of statistical analysis data
⑤ Purchase consultation and responding to customer inquiries
- – Receipt and provision of answers to inquiries, inquiry details management, and correction of terminal errors
⑥ Customization Service
- – By activating the customization service option, Users can receive a better experience on relevant devices and services. For example, it can improve your user experience with Samsung services by offering hints and information customized for you when using the voice recognition service, or remembering the songs you enjoy listening to on rainy days and recommending it later. Or, if you give the command “Remind me to buy a bottle of water when I am almost home”, it can remember the command and remind you when you are almost home.
- – The aforementioned information for customization service is analyzed through an automated system and used for the provision of customized content and information, etc. on each service, analysis to provide better services, and the improvement and development of services as stated above. In addition, if there are advertisements that are legally posted/transmitted to the User (for example, if posting of an advertisement is unavoidable to provide the service for free, or if an advertisement is sent according to the User's consent, etc.), it may be used to provide the User with advertisements that the User may find the most useful.
⑦ Provision of Share function
- – Support to find shareable Samsung Account Users through using the information saved in the Contacts of all devices logged in with the same Samsung account.
- – Support Samsung Account Users to be able to find the person they want to share content with using the phone number or email.
- – Support convenient sharing of content (file, schedule, things-to-do, etc.) and profile photos among Samsung Account Users
6. Provision and Overseas Transfer of Personal Information to Third Parties
In principle, the Company does not provide the User’s personal information to third parties. However, exceptions may be made in the following cases.
- - When required by the provisions of laws and regulations, or when requested by an investigative authority for the purpose of investigation in accordance with the procedures and methods prescribed by the law
- - When necessary for billing for paid services that were provided
- - When the information is provided after being processed so that a specific individual cannot be identified for the purpose of statistical preparation, academic research, or market research
- - When the Users consented in advance
※ The companies listed below may change in the future. If the company shall be changed, or when the User’s personal information shall be provided or shared for reasons other than those listed, it shall be provided through a separate procedure to obtain User consent.
① (S Translator) Service
- – Recipient: Nuance Communications Inc. (United States)
- – Personal information provided: Voice to be translated
- – Purpose of use of the recipient: Improvement of voice recognition function, development of devices and services
- – Retention and usage period: Until the purpose is achieved
② Samsung Cloud service (when synced with Microsoft OneDrive)
- – Recipient: Microsoft Corporation (+82-2-531-4500)
- – Personal information provided: Gallery content synchronized on Samsung Cloud (including details of photos/videos such as shooting date and time, location information at the time of shooting, etc.) and relevant data
- – Purpose of use of the recipient: 1) Provision of Gallery Sync service through OneDrive; 2) provision of search, tag functions, etc. through photo/video analysis (such as classification based on people, locations, objects)
- – Retention and usage period: Retention/use of original photo/video data while it is saved on OneDrive
- – Transfer date and method: Transmission through the network when synchronizing photos/videos
- – Transferred country: United States
③ When using the services of the affiliates with Samsung account
- – Recipient and provided personal information: View details of affiliates and information provided to affiliates
- – Purpose of use of the recipient: 1) Creation of a login credential or account for a partner service using Samsung account information; 2) Provision of account connection information to facilitate syncing between Samsung and partner services
- – Retention and usage period: Until the purpose of service provision is achieved
7. Retention and Usage Period of Personal Information
In principle, the Company shall destroy the applicable personal information without delay after the purposes for which the information was collected and used have been achieved.
However, some items are destroyed after being stored for a certain period of time after membership withdrawal for the purposes of preventing fraudulent subscription/use of services, settlement of reward points, and processing of CS as follows.
- – For the purposes of preventing fraudulent subscription/use of services and settlement of reward points: Encrypted CI, reward points accumulation/use history → Store for 12 months after membership withdrawal
- – Purpose of processing CS: GUID, Samsung account ID, phone number, encrypted CI, reward points accumulation/use history → Store for 90 days after membership withdrawal
However, pursuant to Article 36 (6) of the Personal Information Protection Act, the personal information of Users that has not been used for a period of one year shall be stored separately, and if not used again, shall be destroyed after four years. If it is necessary to preserve personal information in accordance with the regulations of relevant laws, the Company shall retain the personal information for a certain period of time specified by relevant laws as follows. In such cases, the Company shall transfer the personal information to a separate database (DB) or store at a different storage location.
- – Records related to the cancellation of contracts or subscriptions: 5 years (Act on the Consumer Protection in Electronic Commerce, etc.)
- – Records of payments and supply of goods, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce, etc.)
- – Records of the handling of consumer complaints or disputes: 3 years (Act on the Consumer Protection in Electronic Commerce, etc.)
- – Records of the collection/handling, usage, etc. of credit information: 3 years (Credit Information Use and Protection Act)
- – Records on labeling/advertising: 6 months (Act on the Consumer Protection in Electronic Commerce, etc.)
- – User’s log record for the internet, etc./User’s access location tracking data: 3 months (Protection of Communications Secrets Act)
- – Other data for verifying communication: 12 months (Protection of Communications Secrets Act)
8. Procedure and Method of Destroying Personal Information
In principle, the Company shall destroy the applicable personal information without delay after the purposes for which the information was collected and used have been achieved. The information shall be destroyed using the following procedure and method.
(1) Destruction Procedure
After the purpose of use is achieved, User’s personal information shall be moved to a separate DB (separate filing cabinet in the case of paper) to be stored for a certain period of time and destroyed according to the reasons for information protection under internal policies and other relevant laws (refer to “7. Retention and Usage Period of Personal Information”). Personal information transferred to a separate DB shall not be used for purposes other than retention unless otherwise required by law.
(2) Destruction Method
Personal information saved in an electronic file format shall be deleted using a technical method that makes it impossible for records to be restored.
Personal information printed on paper shall be destroyed by shredding or through incineration.
9. Consignment and Overseas Transfer of Collected Personal Information
The Company consigns the processing of personal information to an external specialized company by service as follows only if it is necessary for the implementation of services.
In the event that the Company entrusts the handling of personal information to a third party, the Company shall define clearly the duty to strictly comply with the instructions related to personal information protection, confidentiality obligations regarding personal information, prohibition of provision to a third party and liability in the event of an accident, duty to return or destroy personal information after the entrustment period and termination of processing, etc., and the Company shall supervise the consignment company to ensure that the consignment company safely handles the personal information.
In the event that there shall be a change in the consignment company or the work to be entrusted, it shall be announced on the website notification (or individually notified by mail/email/phone/SMS, etc.).
○ Name of consignment company: LG Uplus Corp., KG INICIS Co., Ltd., Korea Information and Communications Co., Ltd.
○ Work to be entrusted: Purchase and payment, settlement, voucher benefits operation
○ Name of consignment company: NICE Information Service Co., Ltd.
○ Work to be entrusted: Real name verification in accordance with relevant laws
○ Name of consignment company: Macromill Embrain, Korea Research Co., Ltd., Korea Management Association Construction Co., Ltd., Nielsen Koreanclick Co., Ltd.
○ Work to be entrusted: Customer satisfaction and usage behavior survey on devices
○ Name of consignment company: Samsung SDS Co., Ltd. and partners, digitalDigm Inc., Miracom Inc. Co., Ltd., Warepoint Co., Ltd., RNBSOFT Co., Ltd., BD Inc., Innotree Co., Ltd., Openhands Co., Ltd., Bespin Global Co., Ltd.
○ Work to be entrusted: Membership management of apps and websites such as Samsung Electronics business website and SamsungWA.com, delivery of notifications, processing of customer inquiries, sending DMs, purchase consulting service management, system development and operation for provision of services, system monitoring, management of phone number verification system, service server operation and management, etc.
○ Name of consignment company: Samsung Electronics Service
○ Work to be entrusted: Processing customer inquiries on Samsung Electronics business website, non-member customer inquiries, and responding to purchase consultation
○ Name of consignment company: Staffs Co., Ltd.
○ Work to be entrusted: Complaint consultation/processing such as answering user inquiries or handling complaints
○ Name of consignment company: Soribada Co., Ltd.
○ Work to be entrusted: Member management and system management, running promotions, VOC processing related to Samsung Music/MILK
○ Name of consignment company: Nuance Communications Inc. (United States)
○ Work to be entrusted: S-Translator voice recognition processing
○ Name of consignment company: LH Co., Ltd.
○ Work to be entrusted: Constructing promotion event page/gathering applicants
○ Name of consignment company: SK Planet Co., Ltd.
○ Work to be entrusted: Product recommendation service and recommended product statistics and effect analysis service
○ Name of consignment company: CIZION
○ Work to be entrusted: Social media comments service and purchase referral service through the comments service, verification of referral customers for referral bonuses and statistics service
○ Name of consignment company: ToBe Networks Inc., SureM Co., Ltd. Infobip Ltd.
○ Work to be entrusted: Processing text verification required by services provided by Samsung account, Samsung Cloud, and Samsung, sending notices
○ Name of consignment company: IBM Co., Ltd.
○ Work to be entrusted: Development of complaint processing system/execution of operational tasks
○ Name of consignment company: InfoBank Corp.
○ Work to be entrusted: Agency for sending event prizes
○ Name of consignment company: BIZTALK Co., Ltd.
○ Work to be entrusted: Agency for sending KakaoTalk notification messages
○ Name of consignment company: Amazon Web Services Inc.
○ Work to be entrusted: Operation and management of domestic cloud server where personal information is stored
○ Name of consignment company: eGlue Communications
○ Work to be entrusted: Running events/promotions, sending prizes
○ Name of consignment company: ETNERS Co., Ltd.
○ Work to be entrusted: Monitoring Samsung Electronics Service app and business website customer inquiry
○ Name of consignment company: Samsung Electronics Sales Co., Ltd.
○ Work to be entrusted: Membership operation work, service provision and settlement
○ Name of consignment company: Google, Inc.
○ Work to be entrusted: Samsung account website user statistical analysis
○ Name of consignment company: Shinsegae Co., Ltd. and its partners (Sunwoo Co., Ltd., Efolium Co., Ltd., The Nature Holdings Co., Ltd.)
○ Work to be entrusted: Shipping free gifts
○ Name of consignment company: GS Retail Co., Ltd. and its partner (GS Net Vision Co., Ltd.)
○ Work to be entrusted: Sending mobile gift certificates and shipping prizes to customers who have made purchases
○ Name of consignment company: TTB Corporation
○ Work to be entrusted: Processing customer inquiry, checking service usage amount and usage history as per customer inquiry, service statistics system maintenance and operation for Samsung Cloud service
○ Name of consignment company: Megazone Corp and its partners (Megazone Cloud Corp., Starlabs Corp., Jiguem Company)
○ Work to be entrusted: Developing source code related to server system change management, maintenance, and operation of Samsung Cloud service
○ Name of consignment company: 3Channel Corp.
○ Work to be entrusted: Running events
○ Name of consignment company: Manpower Korea Inc.
○ Work to be entrusted: Samsung Electronics membership operation work (respond to customer inquiry and change information), provision of service and settlement
○ Name of consignment company: Samsung Electronics Philippines Corporation (SEPCO)
○ Work to be entrusted: Operation and management of the cloud server
○ Name of consignment company: Cheil Worldwide Inc. and its partners (DOES interactive, New Turn Group, D.Tribe Co., Ltd., dmajor Company, Designfever, Bstones, I4UWORKS Inc., Mpuzzle Communications, Open Tide China (Korea) Co., Ltd., PentaBreed Co., Ltd., Mega Communications, 99℃, HelloNature, Univ Tomorrow Co., Ltd., Plan-S, Marketing Jiymlab, Sean Communications, iPartners, RED Communications, PengTai Greater China Co., Ltd., digitalDigm Inc., Group IDD, Macon Corp., Oblique Table, Oproject, KPR & Associates, Inc., Samsung Welstory Co., Ltd., Newtype Imageworks, ANP Communications, Imfine, SPtek, DreamYoungs)
○ Work to be entrusted: Agency for events
○ Name of consignment company: Microsoft Korea Inc.
○ Work to be entrusted: Operation and management of domestic cloud server where personal information is stored
○ Name of consignment company: Adobe Systems Software Ireland Limited
○ Work to be entrusted: Agency for sending messages (emails)
○ Name of consignment company: Leo Burnett Korea Inc.
○ Work to be entrusted: Operating community events and marketing
○ Name of consignment company: Concentrix Service Korea Corporation
○ Work to be entrusted: Managing community postings and VOC processing
○ Name of consignment company: Khoros, Persistent, Infogain, Hinterlands, Clarotest, iTalent, Social Edge, Cloud Elements, Akismet, Sumo Logic, Akamai, Smooch, Netbase, Ooyala, Box, Infoesearch, Netmania, ServiceRocket
○ Work to be entrusted: Development, operation, and maintenance of community solutions
○ Name of consignment company: Kakao Corp.
○ Work to be entrusted: Kakao advertisement integration service
○ Name of consignment company: Samsung SDS and its partner (ZTC Solution)
○ Work to be entrusted: Implementation and analysis service of general big data analysis solutions for Korea
○ Name of consignment company: Samsung SDS and its partner (Microsoft Korea Inc.)
○ Work to be entrusted: General operation of NextCDM cloud for Korea
○ Name of consignment company: Jade Apple Marketing Inc.
○ Work to be entrusted: Sending promotional MMS to membership customers during offline events
○ Name of consignment company: Google Asia Pacific Pte. Ltd.
○ Work to be entrusted: Operation and management of cloud server where personal information is stored
○ Name of consignment company: Multicampus Co., Ltd.
○ Work to be entrusted: Consignment of tasks essential for provision of services > Website and system management, web page operation, conducting of online marketing
○ Name of consignment company: Samsung SDS Co., Ltd. and its partners (Irush Co., Ltd., Uzen Co., Ltd., GentlePie Co., Ltd., Hi Web Solution Co., Ltd., Pickple CNS Co., Ltd.)
○ Work to be entrusted: Member management of Samsung.com, delivery of notices, handling of customer inquiries, sending DMs, system development and operation for provision of services, system monitoring
○ Name of consignment company: Kantar Korea Co., Ltd., Gallup Korea Co., Ltd., Buzzmetrics Co., Ltd. Global Research Co., Ltd.
○ Work to be entrusted: Samsung Electronics membership, Membership Blue product customer satisfaction and usage behavior surveys
○ Name of consignment company: Pengtai Greater China Co., Ltd.
○ Work to be entrusted: Conducting of Samsung.com and Samsung Electronics membership online marketing tasks
○ Name of consignment company: Samsung SDS and its partner (Uniwis Inc.)
○ Work to be entrusted: Operation and management of Samsung Rewards server
○ Name of consignment company : Samsung SDS, Bespin Global, Northstart, DBJ, Google INC.
○ Work to be entrusted : System development, maintanance, service server and data management
In addition, some personal information is consigned to and stored by overseas agencies for service provision, convenience enhancement, etc. for the User.
○ Name and contact information of the receiving company: Samsung SDS Europe Ltd., (Contactsds@samsung.com)
○ Receiving country: Great Britain/Germany
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing overseas data center that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Samsung SDS China, Ltd., (Contactsds@samsung.com)
○ Receiving country: China
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing overseas data center that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Amazon Web Services Inc., (https://aws.amazon.com/compliance/contact/)
○ Receiving country: Ireland/United States/Singapore
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Samsung RD Institute India Bangalore Private Limited., (comp.srib@samsung.com)
○ Receiving country: India
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period, developing system service provision
○ Name and contact information of the receiving company: Joyent Inc., (https://www.joyent.com/contact/)
○ Receiving country: Netherlands/United States/Singapore
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Samsung Electronics America, Inc. (SEA) and its partners (Infovision, Worldlink) (NAPrivacy@sea.samsung.com)
○ Receiving country: United States
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Sections 4. (1) and 4. (2)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Infovision (info@infovision.com)
○ Receiving country: United States
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Sections 4. (1) and 4. (2)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Worldlink (support@worldlink.com.np)
○ Receiving country: United States
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Sections 4. (1) and 4. (2)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Google INC. (https://analytics.google.com/)
○ Receiving country: United States
○ Receipt date and time, and method: Transmission over network at the time of use of visitor service within the website
○ Personal information items to be transferred: Collection of cookies, data related to device browser, IP address, site/app activity (not sending personally identifiable information)
○ Recipient’s purpose of use and retention/usage period: For gathering statistics on user interactions taking place on websites and apps (providing and maintaining IP address service security, and notifying User’s access country information), User and event data stored for 26 months
○ Name and contact information of the receiving company: Samsung Electronics Philippines Corporation (SEPCO) (+63 2 7214 7777)
○ Receiving country: Philippines
○ Receipt date and time, and method: Transmission over network at the time of use of visitor service within the website, or transmission over network at any time for statistics system operation
○ Personal information items to be transferred: Name of the website selected by the User, URL, ID and PW, the User's card information and payment information from the collected items
○ Recipient’s purpose of use and retention/usage period: Operating and managing the cloud server where personal information is stored during the personal information storage period and establishing and operating a statistics system that processes encrypted personal information
○ Name and contact information of the receiving company: Microsoft Korea Inc.
○ Receiving country: Ireland/United States/Singapore
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Collected items specified in Section 4. (1)
○ Recipient’s purpose of use and retention/usage period: Operating and managing cloud server that stores personal information during the personal information storage period
○ Name and contact information of the receiving company: Adobe Systems Software Ireland Limited 02-530-8000 (Korea office)
○ Receiving country: Singapore/Australia
○ Receipt date and time, and method: Transmission over network every time data is updated
○ Personal information items to be transferred: Encrypted email address, hashed email address, and behavioral information for the use and navigation of cookie-based websites
○ Recipient’s purpose of use and retention/usage period: Used for advertising/targeting purposes (email: information not retained and deleted after using as information for sending emails, cookie data: up to 180 days, uploaded customer information data: up to 24 months)
○ Receiving company name and receiving country:
United States – Khoros, AWS, Infogain, iTalent, Social Edge, Cloud Elements, Akismet, Sumo Logic, Akamai, Smooch, Netbase, Ooyala, Box, ServiceRocket
India – Persistent, Infoesearch
Australia – Hinterlands
Argentina – Clarotest
Great Britain – Netmania
○ Receipt date and time, and method: Transmission over network at the time of use of service
○ Personal information items to be transferred: Nickname, follow/following list, postings created by the User
○ Recipient’s purpose of use and retention/usage period: Provide server for operating communities and maintaining server
○ Name and contact information of the receiving company: Google Asia Pacific Pte. Ltd. / 02-531-9000 (Korea office)
○ Receiving country: United States, Chile, Ireland, Netherlands, Denmark, Finland, Belgium, Singapore, Taiwan
○ Receipt date and time, and method: Transmission over network every time data is updated
○ Personal information items to be transferred: Hashed email address, hashed mobile phone number, and behavioral information for the use and navigation of cookie-based websites
○ Recipient’s purpose of use and retention/usage period: Used for advertising/targeting purposes (consignment of processing), deleted immediately after advertising/targeting is complete (usually within 48 hours)
10. Other Policies for Processing Personal Information
(1) Technical and Administrative Measures to Protect Personal Information
The Company takes the following technical/administrative measures in processing the User’s personal information to ensure safety so that it shall not be lost, stolen, leaked, altered, or damaged.
- Establishment and implementation of an internal management plan
- ㆍAn internal management plan is established and implemented for safe processing of personal information
- ᆞImplementation of personal information protection measures and compliance of the person in charge of tasks are verified through the Company’s personal information protection organization, etc., and immediate measures are taken to correct any issues found.
- Installation and operation of the access control tool
- ᆞUnauthorized access from outside is restricted through an intrusion prevention system, and other efforts are made to secure all possible technological tools to ensure systemic security.
- Measures to prevent forgery/alteration of access record
- ᆞAccess record to the personal information processing system is retained/managed, and security features are used to prevent forgery/alteration of the access record.
- Encryption of personal information
- ᆞThe User’s personal information is protected by a password, and the information is encrypted or a file lock function is used when a file is stored. In addition, the data being transmitted is encrypted, and critical data is protected through separate security features.
- Protection against hacking, etc.
- ㆍMeasures are taken through antivirus programs to prevent damage caused by malicious viruses. Antivirus programs are updated periodically, and when a new virus suddenly appears, applicable antivirus programs are provided as soon as they become available to prevent the breach of personal information.
- ᆞA Secure Socket Layer (SSL), an encryption transmission method that can safely transmit personal information on the network, is adopted.
- ㆍIn preparation for external intrusions such as hacking, etc., each server uses an Intrusion Prevention System, vulnerability assessment system, etc. and every effort is made to ensure security.
- ᆞPersonal information and general data are not stored together; they are stored separately on different servers.
- Minimization and training of employees handling personal information
- ᆞThe right to access the User’s personal information shall be restricted to people who directly work with the User to perform marketing tasks, people who perform personal information management tasks such as those in charge of personal information protection and people in charge of personal information management, and other people who must inevitably handle personal information for work, etc.
- ᆞRegular internal training and external consignment training on new security technologies and the duty to protect personal information shall be conducted for employees who handle personal information.
- ᆞWhen joining the company, all employees must fill out a security pledge to prevent personal information leakage. In addition, internal procedures are in place to audit the implementation of personal information protection measures and the compliance of employees.
- ᆞThe transfer of duties by the personal information handler will take place under strict security, and responsibilities pertaining to personal information-related incidents after joining and leaving the company shall be clarified.
- ᆞThe computer room and data storage room are set up as special restricted areas to control access.
(2) Policy on Providing Links
The Company may provide the User with links to other companies’ websites or materials, and the User may use products and services developed by third parties through Samsung services (for example, downloading applications developed by a third party from the Samsung Galaxy Store, etc.).
In such cases, the Company shall not be held responsible or guarantee the usefulness of the products, services, or materials provided as the Company has no control over the third party's websites, materials, products, or services. When redirected to another website after clicking on a link provided by the Company, the privacy policy of that site is unrelated to the Company. Please review the policy of the newly visited site.
(3) Administration Policy for Postings
The Company values the User’s postings and shall do the best to protect them so that they are not altered, damaged, or deleted. However, the following cases shall be exceptions.
- - Spam-like postings
- - Postings that defame others by spreading false information with the purpose of slandering
- - Postings that disclose the identity of others without consent
- - Postings that infringe on the rights such as intellectual property rights of the Company or a third party
- - Other postings that are unrelated to the topic of the board
In order to foster a desirable usage of boards, when User discloses personal information of others without consent, the Company may delete certain parts of the applicable posting or replace them with symbols, etc. In addition, if the posting is suitable for another board with a different topic, the posting shall be moved and the transfer path shall be specified so that there shall be no misunderstandings.
In other cases, the posting may be deleted after an explicit or individual warning.
Fundamentally, all rights and responsibilities related to the posting rest with the individual author. In addition, as the information that the User discloses voluntarily through postings is difficult to be protected, please consider carefully before disclosing information.
(4) Policy to Reject Unauthorized Collection of Email Addresses
The Company rejects unauthorized collection of posted email addresses through email collection programs or any other technical tools. Violation of this may be subject to punishment under the “Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.”, or other laws.
(5) Transmission of Advertising Information
The Company shall not transmit advertising information for commercial purposes without explicit consent from the Users.
If the Users agreed to receive emails such as product information or newsletters, the Company shall do the following to the subject and body of the email so that the Users can easily recognize them.
- - In the subject line of the email, indicate that it is an (advertisement) at the beginning of the subject.
- - The body of the email shall specify the name, email address, phone number, and address of the sender, and indicate methods by which the User may easily express their intention to unsubscribe.
When advertising information for commercial purposes is transmitted through means other than email, such as fax/mobile text messages, necessary measures shall be taken such as marking the beginning of the message with the phrase “advertisement” in accordance with the relevant laws.
(6) Advertisement ID
Interest-based advertisement shall be provided based on the analysis of User’s preferences and interests based on the User’s usage history of Samsung Mobile and Samsung services, and additional items to which the User consented.
Information utilized for the purpose of interest-based advertisement shall be processed based on Samsung advertisement ID (Samsung advertisement ID is a randomized ID which cannot identify the User) unless there is separate additional consent of the User,
and the User may reset the above Samsung advertisement ID in the “Settings” menu.
If reset, all existing information utilized as basis for Samsung advertisement ID shall be deleted, and the new Samsung advertisement ID and the existing Samsung advertisement ID shall not be linked. Therefore, if Samsung advertisement ID is reset, the accuracy of interest-based advertisement may be decreased because the User’s interests need to be newly analyzed.
Also, if the User does not wish to receive interest-based advertisements, the User can opt-out at any time through Samsung services that use interest-based advertisements. In this case, only general advertisements that are not based on the User's usage history shall be provided.
Privacy Policy Version Number: V 9.4
Privacy Policy Enforcement Date: October 15, 2021