Privacy Policy
2024.09.05
※ This policy takes effect on September 5, 2024.
'ESTsoft' (hereinafter referred to as 'the Company') values the personal information of job applicants and complies with the laws related to the 'Promotion of Information and Communications Network Utilization and Information Protection'. The Company informs applicants how their personal information is being used through the personal information processing policy, and what measures are being taken to protect personal information. Should there be any changes to the personal information processing policy, the Company will announce them through the homepage notice. If you have any questions about the changes, you can visit the ESTsoft website at any time to check.
1. Personal information items processed
The company allows you to apply for a job without a separate membership registration process, and collects the following personal information through the website to provide opportunities for job applications. 1) Scope of personal information collected at the time of job application - Required information: Name, Phone number, Email - Optional information: Date of birth, Address, Cover letter, Resume, Educational background, Photo, Video, License information, Work experience, Gender, Nationality, Veterans affairs, Disability matters (for preferential hiring in accordance with the law on employment of the disabled), Portfolio, Career description, Field of application, Desired salary, Previous salary, Referrer, Application route, Other unstructured information entered directly by the person or uploaded through an attachment that may identify an individual 2) Scope of personal information collected when using the inquiry service - Required information: Email
2. Purpose of Personal Information Processing
1) Confirmation of personal identification for job application, confirmation of qualifications, checking the recruitment status, modification of job application form, delivery of notices, response to inquiries, etc., securing a smooth communication path with applicants, management of future possible resources
3. Provision of Personal Information to Third Parties
1) The company fundamentally does not use personal information beyond the scope of the purposes of collection and use as notified in Article 2, nor do they provide it to third parties. However, the following cases are exceptions: - When applicants have agreed in advance to disclosure - When it is in good faith considered required by law (e.g., when there is a legitimate request from a government/law enforcement agency according to related laws)
2) Even in exceptional circumstances, if information is provided according to related laws or upon the request of enforcement agencies, it is a principle to notify the individual concerned. However, there may be cases where it is impossible to give notice due to legal grounds. We will ensure that information is not indiscriminately provided contrary to the original purpose of collection and use.
3) Moreover, the company does not entrust the applicant's information to external companies without the consent of the applicant. Should the need arise in the future, we will notify the applicant about the entrusted party and the contents of the entrusted work and, if necessary, obtain prior consent.
4) Occasionally, job applicants may be offered a position in companies that have a special relationship with the company (subsidiaries, affiliates), and in such cases, we will always contact the applicants individually to undergo consent procedures before transferring the application to the relevant company.
4. Personal Information Processing Consignment
To provide an enhanced service, we may entrust the processing of your personal information to an external party.
Where we entrust the processing of personal information, we will notify you of this in advance.
The entrusted personal information processing companies and the scope of that work are as follows.
· Trustee: Greeting
· Scope of entrustment: Operation of the recruitment website and the recruitment management IT system, and handling of related inquiries
· Information shared: Personal information contained in the job application
· Retention and use period of the shared information: Until the hiring company deletes the application, or until the entrustment contract ends
5. Processing and Retention Period of Personal Information
1) As a principle, personal information is immediately destroyed after the purpose of its collection and use has been achieved. However, personal information may be retained for a certain period as agreed upon when collection occurred, and as stipulated by other related laws. If an applicant withdraws consent to provide personal information, the relevant personal information will be immediately deleted.
6. Personal Information Destruction Procedure and Method
1) The personal information of job applicants will, in principle, be destroyed without delay once the purpose of processing the personal information has been achieved. The company's personal information destruction procedure and method are as follows.
2) Destruction Procedure - Information entered by users for job applications is transferred to a separate DB (or a separate file in the case of paper) after its purpose has been achieved, and then stored for a certain period according to internal policies and other relevant laws and regulations (see retention and usage period) before being destroyed. - Such personal information will not be used for any other purpose than retention unless required by law.
3) Method of Destruction - Personal information printed on paper is destroyed either by shredding or burning. - Personal information stored in electronic file format is deleted using technical methods that prevent the records from being restored.
7. User rights, obligations, and their exercise method
1) Personal information provided when applying for a job at the company can be viewed, modified, and deleted freely after identity verification (real-name verification) until the recruitment process is completed.
2) After the completion of the hiring process, modifications and deletions are not possible. However, if the applicant wishes, they can request deletion by contacting the customer service center or the personal information protection grievance department on the ESTsoft website, and we are deleting it. The company processes the personal information that has been deleted at the request of the applicant according to what is specified in "The Processing and Retention Period of Personal Information Collected by the Company", and ensures that it is not accessed or used for any other purpose.
3) Users must not violate the Personal Information Protection Act and related laws, infringing on their own or others' personal information and privacy in accordance with this personal information processing policy.
4) In the case of children under the age of 14, legal guardians have the right to inquire or modify the child's personal information, and withdraw consent for the collection and use of the information. At this time, the minimum personal information of the legal guardian can be collected from the respective child.
8. Technical/Administrative Protection Measures for Personal Information
1) The company has devised the following technical/administrative measures to ensure the safety of applicants' personal information so that it is not lost, stolen, leaked, tampered with, or damaged.
2) Password Encryption - The password set during the company's job application is encrypted and stored and managed so that only the person knows it, and it is possible for the person who knows the password to check and change personal information.
3) Countermeasures against hacking, etc. - The company does its best to prevent applicants' personal information from being leaked or damaged by hacking or computer viruses. In preparation for damage to personal information, data is regularly backed up, and the latest antivirus programs are used to prevent applicants' personal information or data from being leaked or damaged, and encrypted communication is used to safely transmit personal information over the network. In addition, an intrusion prevention system is used to control unauthorized access from outside, and the company is striving to equip all possible technical devices to ensure security systematically.
4) Minimizing and training personal information processing employees - The company’s personal information-related processing employees are limited to the person in charge, and a separate password is assigned and regularly renewed for this, and ad hoc training is conducted, emphasizing the protection of applicants' personal information.
5) Operation of a personal information protection dedicated organization - Through in-house personal information protection organizations, the company strives to immediately correct and rectify problems by checking the implementation of the company's personal information processing policies and compliance of the person in charge. However, the company is not responsible for any problems that may occur due to the user's own negligence or problems on the Internet, such as leakage of personal information such as passwords and social security numbers.
9. Matters related to the installation and operation of devices that automatically collect personal information such as internet access information files, and the rejection thereof
'The company' uses cookies to provide personalized services to users. Cookies are small data files sent from an HTTP server to the user's browser and are stored on the user's device. Cookies may contain information about the websites used and the user's personal information, which may be shared with the server. Users can choose to allow all cookies, to be checked each time cookies are saved, or to refuse the storage of all cookies by selecting [Tools] > [Internet Options] > [Security] > [Custom Level] based on web browser options (IE standard).
10. Privacy Officer and Guidance for Related Departments
1) You may report to the Personal Information Protection Officer or the responsible department any complaint relating to personal information protection that arises in the course of using the Company's online job application and similar services. The Company will provide a prompt and thorough response to reports from users.
2) Personal Information Protection Officer and responsible department
- Personal Information Protection Officer: Head of the IT Planning Division
- Responsible department: Information Security Team
- Phone: 02-583-4620
- Contact: privacy@estsoft.com
3) For questions relating to recruitment personal information, please contact the department below.
- Department: People Partner Team
- Email: recruit@estsoft.com
4) To obtain redress for infringement of personal information, users may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center and similar bodies. For other reports of, or counseling on, personal information infringement, please contact the organizations below.
- Personal Information Infringement Report Center (operated by KISA) (https://privacy.kisa.or.kr / 118, no area code)
- Supreme Prosecutors' Office Cyber Investigation Division (http://www.spo.go.kr / 1301, no area code)
- Korean National Police Agency (ecrm.police.go.kr)
- Personal Information Dispute Mediation Committee (https://www.kopico.go.kr/)
11. Duty of Notification
1) In case of any addition, deletion, or modification of the current Privacy Policy, it will be announced through the 'Notices' section on the website at least 7 days prior to the amendment. However, in the case of significant changes that affect user rights, such as the collection and use of personal information or provision to third parties, it will be announced at least 30 days in advance.
2) Announcement Date: September 8, 2022 3) Implementation Date: September 22, 2022
