Policy
Privacy Policy
The Korea Industrial Vocational Training Association (KIVTA) publishes this Privacy Policy to protect personal information and data-subject rights and to resolve privacy concerns promptly.
Effective date: August 8, 2026
1. Controller and Scope
KIVTA processes personal information for website membership, training applications and operation, certificate issuance, customer support, and employee and instructor administration. This Policy applies to personal information handled through those services and activities.
2. Purposes, Categories, and Retention
- Account registration and management — Purpose: identification, login, verification, and access management / Data: login ID, password (stored as a one-way hash), name, date of birth, gender, position, email, mobile number, postal address, and mobile verification records / Retention: until account withdrawal. Identifiers and credentials are deleted or anonymized promptly, and the withdrawal-processing record is retained for up to one year.
- Workplace registration and verification — Purpose: workplace verification, training and invoicing, and company-admin review / Data: business registration number, company and representative names, industry and business type, address, phone, fax, invoice email, employee count, and submitted files such as a business registration certificate / Retention: until account withdrawal or the workplace relationship ends, except legally retained transaction and tax records.
- Training and certificates — Purpose: application processing, training operation, attendance and completion history, certificate issuance and lookup / Data: member and workplace data, course and schedule, application, assignment, attendance and completion history, first six digits of date-of-birth identification, and certificate records / Retention: until account withdrawal or the training-history and certification purpose ends. Minimum records needed for legal obligations or proof of completion may be segregated and retained for the applicable period.
- Payments, settlement, invoices, and refunds — Purpose: deposit verification, application matching, invoicing, refunds, and accounting / Data: payer or depositor name, transaction date and time, amount, transaction memo, bank and account information, business registration number, and invoice email / Retention: five years after the transaction or the period required by law.
- Customer inquiries and chat — Purpose: receiving and responding to inquiries, complaints, and disputes / Data: name, contact details if provided, inquiry and conversation content, attachments, and support records / Retention: 30 days after chat closure. Records configured for separate archiving are retained for up to one year, or until an ongoing dispute is resolved.
- Employee and instructor administration — Purpose: recruitment and contracting, assignment, payroll and tax, attendance and leave, and certificates / Data: name, date of birth, contact details, address, career and qualification data, affiliation, employee number, position, contract, attendance and leave data, payroll, tax, bank and account data, and HR submissions / Retention: during employment or contract and for three years afterward. Tax and accounting evidence is retained for five years after the statutory filing deadline or as otherwise required by law.
- Optional promotional notices — Purpose: training courses and schedules, association news, and important official notices / Data: email, workplace fax number, and consent status and timestamp / Retention: until consent withdrawal or account withdrawal. Consent status is reconfirmed every two years.
- Service-use and security records — Purpose: session continuity, troubleshooting, misuse prevention, security audits, and dispute response / Data: session and cookie identifiers, IP address, browser and device information (User-Agent), access, usage, and administrator-action records / Retention: session and authentication data until expiry; security and audit records until the related incident is closed or the internal audit purpose is completed.
3. Statutory Retention
- Advertising records: six months
- Contract and withdrawal-of-offer records: five years
- Payment and supply-of-goods-or-services records: five years
- Consumer complaint and dispute records: three years
- Tax books and transaction evidence: five years after the statutory filing deadline, subject to legal exceptions
- Employee rosters and key employment, wage, hiring, termination, and leave records: three years from the statutory start date
4. Collection Methods and Refusal of Consent
KIVTA collects personal information through website forms and uploads, training applications, support, email and phone communications, workplace verification, and transaction processing. Some data may be generated automatically while the service is used.
Membership is operated for adults, and KIVTA does not intentionally collect account-registration information from children under 14.
You may refuse consent. Refusal of required collection may prevent account registration, training applications, or identity verification. Refusal of optional data or promotional notices does not restrict the basic service.
5. Third-Party Disclosure and Overseas Transfer
KIVTA does not routinely disclose personal information to third parties. It may disclose the minimum information permitted by law when the data subject separately consents, disclosure is required by law, or urgent life, health, or property interests must be protected.
KIVTA currently has no routine overseas transfer in its direct processing activities. If an overseas transfer is introduced, KIVTA will disclose the recipient, country, data, purpose, method, retention, and refusal procedure in advance and complete the required legal process.
6. Processors and External Services
Only the minimum data necessary to perform each task is transmitted. When engaging a processor, KIVTA documents restrictions on secondary use, safeguards, subprocessors, supervision, and liability, and supervises the processor. Changes to processors or tasks will be published in this Policy.
- Aligo (Alrineun Saramdeul Co., Ltd.) — mobile verification and training or service SMS / mobile number and message content
- Kakao Corp. (Daum Mail) — account verification, training, service, and support email / name, email address, and message content
- K-Net Co., Ltd. (Barobill) — bank-transaction lookup and invoice-related work when enabled / business registration number, invoice email, account and transaction data
- Public Data Portal and National Tax Service business-status lookup, and APICK — business-status verification and workplace information enrichment / business registration number
7. Destruction of Personal Information
KIVTA destroys personal information promptly when its retention period expires or its purpose is fulfilled. Information that must remain under another law is segregated and is not used for another purpose during statutory retention.
Electronic files are securely deleted to make recovery or reproduction difficult, and paper records are shredded or incinerated. Backup copies are deleted on the defined backup cycle and are controlled against renewed use if restored.
8. Data-Subject Rights
You may request access, data portability where legally applicable, correction, deletion, restriction, consent withdrawal, or account withdrawal. Requests may be made through My Page, the website inquiry channel, or the privacy contact below, including through a legal or authorized representative.
KIVTA verifies the requester or representative and responds within the period required by law. If a legal exception limits access, deletion, or restriction, KIVTA will explain the reason and how to object.
9. Cookies and Automatically Collected Data
KIVTA may use session and remember-me cookies for authentication continuity and security. IP address, User-Agent, use, and error records may be generated during access. KIVTA does not collect behavioral data for personalized advertising.
You may reject or delete cookies in your browser settings. Blocking cookies may prevent authentication continuity and some other features from working normally.
10. Safeguards and Automated Decisions
KIVTA does not make decisions that produce legal or similarly significant effects on a data subject solely through an automated system.
- Administrative: minimum authorized personnel, role-based access, training, and review of access and administrator-action logs
- Technical: one-way password hashing, encryption of sensitive HR and account data, encrypted transmission, access control, security updates, vulnerability and log management
- Physical: separate storage and access restrictions for private files such as HR documents
11. Privacy and Grievance Contact
Requests to exercise privacy rights and inquiries or complaints may be directed to this department.
- Department: Information Management Team
- Phone: +82-2-867-6448 / Fax: +82-2-6007-1503
- Email: kivta@daum.net
- Address: Room 507, 58 Gasan digital 1-ro, Geumcheon-gu, Seoul, Republic of Korea
12. External Remedies
You may contact these organizations if you are dissatisfied with KIVTA's response or need independent consultation or relief.
- Personal Information Infringement Report Center: 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Korean National Police Cybercrime Reporting System: 182 / ecrm.police.go.kr
13. Policy Changes
This Policy takes effect on August 8, 2026. Changes will be announced on the policy page or in a website notice at least seven days before they take effect, or at least 30 days in advance for material changes to data-subject rights.
For privacy inquiries or rights requests, contact the KIVTA Information Management Team at +82-2-867-6448 or kivta@daum.net.