Privacy Policy

Rokaus Hotel (hereinafter referred to as the "Hotel") collects, retains, and processes all personal information based on the "Personal Information Protection Act" and the "Act on Promotion of Information and Communications Network Utilization and Information Protection, etc."

The "Personal Information Protection Act" provides general rules regarding the handling of personal information, while the "Act on Promotion of Information and Communications Network Utilization and Information Protection, etc." establishes norms to protect the personal information of users of information and communication services and to create a secure environment.

The Hotel will handle the collection, retention, and processing of personal information in a lawful and appropriate manner to properly perform hotel operations and protect the rights and interests of customers in accordance with the provisions of the "Personal Information Protection Act" and the "Act on Promotion of Information and Communications Network Utilization and Information Protection, etc."

Additionally, the Hotel respects customers' rights regarding the personal information it holds, including the rights to access, correct, delete, and request cessation of processing, as stipulated in the "Personal Information Protection Act." Users may also file administrative complaints under the "Administrative Litigation Act" regarding infringements of their rights under the "Personal Information Protection Act."

This Privacy Policy may be amended in accordance with relevant laws, guidelines, and changes in internal company policies. Changes will be notified as prescribed by applicable laws.

Here is the translation of the order of this Privacy Policy:

  1. 1. Purpose of Processing Personal Information
  2. 2. Items of personal information processed
  3. 3. Period of retention and use of personal information
  4. 4. Provision of personal information to third parties
  5. 5. Outsourcing of personal information processing
  6. 6. Rights and obligations of information subjects and methods of exercise
  7. 7. Destruction of personal information
  8. 8. Measures for securing the safety
  9. 9. Installation, operation, and refusal of automatic collection devices
  10. 10. Personal information protection manager
  11. 11. Remedies for infringement of rights
  12. 12. Changes to the Privacy Policy

1. Purpose of Processing Personal Information

The hotel processes personal information for the following purposes. Processed personal information will not be used for purposes other than those stated below, and consent will be obtained in advance if the purpose of use changes.

  1. A. Service Provision
    1. • Verification of identity and contract fulfillment related to reservations and provision of rooms, dining facilities, banquets, and wedding services
    2. • Utilization in customer satisfaction surveys
    3. • Provision of customized services
  2. B. Utilization in Marketing and Advertising
    1. • Development of new services and provision of customized services
    2. • Promotion of new services and provision of various event information
    3. • Provision of services and advertising based on demographic characteristics

2. Items of Personal Information Being Processed

For the purpose of providing services, the hotel collects and processes personal information within the necessary minimum scope as follows:

  1. A. Room Guest Information
    1. • Required items: Name, date of birth, unique identification number (passport number), nationality, payment method
    2. • Optional items: Email address, address, company, city, postal code, phone number, membership number
  2. B. Service Provision
    1. • Customer Satisfaction Surveys
      1.    o Required items: Customer name, email address, mobile phone number
      2.   o Optional items: Other details
      • Banquet Hall Reservations
      1.   o Required items: Name, mobile phone number, email address, company name, country, event name, reservation date, number of attendees
      2.   o Optional items: Business card attachment, event purpose, event format, Set up, related documents, other requests
      • Combined Room and Banquet Hall Reservations
      1.   o Required items: Name, mobile phone number, email address, company name, country, event name, reservation date, number of attendees, (Room) reservation date, room type
      2.   o Optional items: Business card attachment, event purpose, event format, Set up, related documents, other requests
      • Family Event Reservations
      1.   o Required items: Name, mobile phone number, email address, event type, reservation date, number of attendees
      2.   o Optional items: Meal format, consultation request, other requests
      • Wedding Reservation Information
      1.   o Required items: Name, mobile phone number, email address, wedding reservation date (1st choice), reservation date (2nd choice), number of attendees
      2.   o Optional items: Content of consultation request, other requests
  3. C. Counseling and Reporting Center Provision
    1. • Required items: Customer name, email address, contact information
    2. • Optional items: Counseling content

3. Processing and Retention Period of Personal Information

  1. A. The hotel retains personal information for a certain period after achieving the purposes of collection or provision based on internal policies and other relevant laws related to information protection (refer to retention and use period). Specific destruction timelines are as follows:
    1. 1. General delivery information: When goods or services are delivered or provided
    2. 2. Information collected for events or similar purposes: When the event or similar activity ends (except when separate notification was given at the time of consent for personal information collection)
  2. B. If there is a need to retain member information under provisions of related laws, the company retains the information for specific periods as follows:
    1. 1. Records related to contracts or withdrawal of subscriptions: 5 years
    2. 2. Records related to payment of fees and supply of goods: 5 years
    3. 3. Records related to consumer complaints or dispute resolution: 3 years
    4. Additionally, personal identification information and preference information for revisits and customized customer services are retained for 5 years.

4. Provision of Personal Information to Third Parties

The hotel does not provide personal information to third parties without the consent of customers. However, exceptions are made in the following cases:

  1. A. When the customer has given prior consent.
  2. B. When required by law, or when there is a request from investigative agencies according to the procedures and methods prescribed by law for investigative purposes.

5. Outsourcing of Personal Information Processing

  1. A. For the purpose of service fulfillment, the hotel operates by outsourcing personal information handling tasks to external specialized companies as follows:
설치 대수, 설치 위치 및 촬영범위 내용
Contractor Subcontractor Purpose and Details of Outsourcing Items Outsourced and Remarks Retention and Use Period
Parnas Hotel Co., Ltd. PNS Co.,Ltd Rokaus Hotel operations and management All customer information (phone number, name, date of birth, email, etc.) Upon termination of outsourcing contract
Parnas Hotel Co., Ltd. IBS Industry Co., Ltd Facility management subcontract operation Room number, guest name, stay period (check-in/check-out dates) Upon termination of outsourcing contract
Parnas Hotel Co., Ltd. Angels Staff Co., Ltd. Pool management subcontract operation Room number, guest name, stay period (check-in/check-out dates) Upon termination of outsourcing contract
Korea Information & Communications Co., Ltd Credit card payment processing Credit card number, payment date, mobile phone number Card number: Payment date: 3 months Mobile phone number: 5 years
Subsidiary Information Technology Co., Ltd. Operation and maintenance of computer systems Name, email address, phone number, address Upon termination of outsourcing contract
  1. B. To ensure the safety of personal information protection during outsourcing contracts, we strictly adhere to instructions related to personal information protection, prohibit the provision of personal information to third parties, and clearly define responsibilities in case of incidents. We maintain records of the contract details in written or electronic form.
    In the event of a change in subcontractors, the hotel will announce the updated company names on the Privacy Policy page of its website.

6. Rights and Obligations of Data Subjects and Methods of Exercising Them

  1. A. As a data subject, you have the following rights:
    1. 1. Request for Access to Personal Information You may request access to your personal information files held by the hotel under Article 35 of the Personal Information Protection Act. However, access may be restricted under Article 35(5) of the law:
      1. • Cases where access is prohibited or restricted by law
      2. • Cases where there is a risk of harm to another person's life or body, or unfair infringement on another person's property and other interests
    2. 2. Request for Correction or Deletion of Personal Information You may request correction or deletion of your personal information files held by the hotel under Article 36 of the Personal Information Protection Act. However, this right may not apply if the collection of such information is explicitly stated in other laws.
    3. 3. Request for Suspension of Processing of Personal Information You may request the suspension of processing your personal information files held by the hotel under Article 37 of the Personal Information Protection Act. However, your request for suspension of processing may be denied under Article 37(2) of the law:
      1. • Cases where there is a special provision under the law or where compliance with legal obligations is necessary
      2. • Cases where there is a risk of harm to another person's life or body, or unfair infringement on another person's property and other interests
      3. • Cases where it is difficult to perform the contract without processing personal information, and the data subject has not clearly expressed an intention to terminate the contract
  2. B. If you wish to exercise your right to access, correct, delete, suspend processing, or withdraw consent regarding your personal information, please contact the department responsible for handling personal information access requests and the Data Protection Officer in writing, by phone, or by email. We will promptly take action after verifying your identity.
  3. C. If you have requested correction of your personal information, we will not use or provide the information until the correction is completed. Moreover, if incorrect personal information has already been provided to a third party, we will promptly notify them of the correction results to ensure that corrections are made.
  4. D. Please ensure that your personal information is entered accurately and kept up to date to prevent accidents.
  5. E. You have the right to protect your personal information and also have the obligation not to infringe on others' information. Please take care to prevent the leakage of your personal information and refrain from damaging others' personal information, including in postings.
  6. F. To facilitate smooth communication regarding requests for access to personal information, we operate a customer service department. The contact information is as follows:
    1. • Customer Service Department: Management Support Team
    2. • Phone Number: +82 2-6923-8140
    3. • Address: 25, Hangang-daero 23-gil, Yongsan-gu, Seoul

7. Destruction of Personal Information

  1. A. Destruction Procedure
    1. - The hotel destroys personal information after a certain period of time according to internal policies and other relevant laws for information protection reasons, once the purpose of collection and use has been achieved. When personal information becomes unnecessary due to the expiration of the retention period or achievement of the processing purpose, it is promptly destroyed.
    2. - If personal information must be retained under other laws despite the expiration of the consented retention period from the data subject or the achievement of the processing purpose, the information is transferred to a separate database (DB) or stored in a different location.
  2. B. Destruction Method
    1. - Personal information printed on paper is destroyed through shredding or incineration. Personal information stored in electronic file formats is deleted using technical methods that prevent regeneration.

8. Measures to Ensure Security of Personal Information

  1. A. Establishment and Implementation of Internal Management Plan
    The hotel establishes and implements an internal management plan in compliance with the guidelines of the Ministry of Administration and Safety. Regular training sessions are also conducted.
  2. B. Minimization and Education of Personal Information Handlers
    We minimize the number of personnel handling personal information and conduct regular education sessions for them to ensure thorough management of personal information.
  3. C. Access Control to Personal Information
    Access to databases handling personal information is restricted, managed, and controlled by granting, changing, or revoking access permissions. We utilize intrusion prevention systems to control unauthorized access from external sources.
  4. D. Storage and Prevention of Alteration of Access Records
    We maintain and manage records (web logs, summaries, etc.) of accesses to personal information systems for at least 3 months, ensuring that access records are protected against tampering, theft, or loss using security features.
  5. E. Encryption of Personal Information
    Customer personal information is stored and managed in encrypted form. Moreover, important data is encrypted during storage and transmission using separate security features.
  6. F. Technical Measures Against Hacking and Other Threats
    To prevent leakage or damage of personal information due to hacking, computer viruses, etc., the hotel installs security programs, conducts regular updates and checks, and sets up systems in areas where access is controlled, ensuring technical and physical monitoring and blocking.
  7. G. Access Control for Unauthorized Personnel
    We establish and operate access control procedures for physical storage locations of personal information systems separately.

9. Installation, Operation, and Refusal of Personal Information Automatic Collection Devices

  1. A. The hotel uses 'cookies' to store and retrieve usage information periodically in order to provide personalized services to users.
  2. B. Cookies are small pieces of information sent by the server (HTTP) operating the website to the user's computer browser, and they may also be stored on the users' PC hard drives.
    1. • Purpose of using cookies: Cookies are used to track and analyze user visits and usage patterns on various services and websites visited by users, including popular search terms and security access status, to optimize information provided to users.
    2. • Installation, operation, and refusal of cookies: Users can refuse cookie storage by adjusting the options settings in the Tools > Internet Options menu of their web browsers.
  3. C. Refusal to store cookies may result in difficulties in using personalized services.

10. Personal Information Protection Manager

To protect personal information and handle complaints related to personal information, we have designated the following individuals as the personal information protection manager and responsible personnel:

  1. A. Personal Information Protection Manager: Manhwan Han (Executive)
  2. B. Personal Information Protection Administrator: Wonjae Jung (IT Team Leader)
  3. C. Personal Information Protection Officer: Sungyeong Lee (IT Team)

11. Remedies for Rights Violations

Customers can apply for dispute resolution or consultation regarding personal information breaches through institutions such as the Personal Information Dispute Mediation Committee and the Korea Internet & Security Agency's Personal Information Breach Report Center.
For any other reports or consultations regarding personal information breaches, please contact the following organizations:

  1. A. Personal Information Breach Report Center (Operated by Korea Internet & Security Agency)
    1. • Responsibilities: Reporting facts of personal information breaches, applying for consultations
    2. • Website: privacy.kisa.or.kr
    3. • Phone: 118 (no area code needed)
    4. • Address: 3rd Floor, 9 Jinheung-gil, Naju-si, Jeollanam-do, 58324, South Korea
  2. B. Personal Information Dispute Mediation Committee
    1. • Responsibilities: Applying for personal information dispute mediation, group dispute mediation (civil resolution)
    2. • Website: www.kopico.go.kr
    3. • Phone: 1833-6972 (no area code needed)
    4. • Address: 4th Floor, Government Seoul Complex, 209 Sejong-daero, Jongno-gu, Seoul, 03171, South Korea
  3. C. Cyber Crime Investigation Unit, Supreme Prosecutors' Office: 02-3480-3573 (www.spo.go.kr)
  4. D. Cyber Safety Bureau, Korean National Police Agency: 182 (http://cyberbureau.police.go.kr)

12. Changes to the Privacy Policy

This privacy policy takes effect from the date of enforcement.

  1. A. Date of Announcement: May 13, 2024
  2. B. Effective Date: May 13, 2024
  3. Previous Privacy Policy(2023.02.01)