Privacy Policy

Last updated: [TO BE REVIEWED]

⚠️ This document is a draft prepared from the service design materials. Items marked [TO BE REVIEWED] — such as the operating entity (legal name, address, contact), the data protection officer, the legal basis for cross-border transfers, and the detailed list of processors — must be finalized through legal review before this policy takes effect.

This Privacy Policy explains how KARE ("the Company") collects, uses, stores, and deletes the personal data of users of the KARE PASS integrated voucher service ("the Service"). The Company complies with applicable laws and strives to protect users’ personal data.

1. Service Operator

2. Personal Data We Collect

The Company collects the following personal data to provide the Service.

3. Purposes of Collection and Use

4. Provision of Personal Data to Third Parties

To process bookings requested by users, the Company provides the minimum necessary information to partners, limited to what is required to fulfill the booking.

5. Entrustment of Personal Data Processing

The Company may entrust certain tasks to external providers to deliver the Service smoothly, and imposes contractual obligations to keep personal data secure.

6. No Handling of Personal Health Records (PHR)

The Company does not collect, store, or process any personal health information (EMR/PHR) such as diagnoses, prescriptions, test results, or procedure details.

Even for medical and aesthetic bookings, only schedule information such as the scheduled visit date is processed, and any medical information is automatically blocked at the input and logging stages so it does not enter the system.

7. Retention and Deletion of Personal Data

8. Rights of Data Subjects

Users may exercise the following rights regarding their personal data.

9. Cross-Border Transfer of Personal Data

The Service targets a global user base, and personal data may be transferred abroad during entrustment and infrastructure operation. Details such as the destination countries, items, timing, method, and legal basis are [TO BE REVIEWED].

10. Security Measures

11. Social Login

When you log in with a Google, Apple, or Facebook account, the Company receives a user identifier and email from that provider and uses them to identify your account. Depending on the provider’s policy, some information (e.g., email) may not be provided.

12. Data Protection Officer

13. Notice of Changes

If this Privacy Policy is amended by addition, deletion, or modification, we will announce the changes within the Service before they take effect. Effective date: [TO BE REVIEWED].

Back to home