Privacy Policy

Obliv Clinic Seoul Origin (the ‘Clinic’) establishes and discloses the following privacy policy under the Personal Information Protection Act, to protect the personal information of data subjects and to handle related concerns promptly and smoothly.

Article 1 (Purposes of processing personal information)

The Clinic processes personal information for the purposes below. Personal information is not used for any other purpose; if the purpose of use changes, the necessary measures — such as obtaining separate consent under Article 18 of the Personal Information Protection Act — will be taken.

  • Provision of medical services: consultations, examinations, appointments and appointment confirmation, and all services needed for diagnosis and treatment
  • Billing: payment for treatment, settlement, and health-insurance benefit claims
  • Patient care: identity verification, delivery of notices, handling of complaints, and service-satisfaction surveys
  • Legal obligations: issuing and retaining supporting documents under the Medical Service Act, tax legislation and other laws

Article 2 (Processing and retention periods)

The Clinic processes and retains personal information within the retention and use period prescribed by law, or the period consented to at the time of collection.

  • Medical records: 10 years
  • Examination result reports: 5 years
  • Prescriptions: 2 years
  • Patient care and marketing (where consented): until the end of service use or withdrawal of consent

Article 3 (Items of personal information processed)

The Clinic collects only the minimum personal information needed to provide its services.

  • Required items: name, resident registration number, address, telephone number, medical information (including medical history)
  • Optional items: email address, consent to marketing use
  • How it is collected: the registration form completed at the clinic, website bookings, telephone consultations
  • The website uses cookies and similar automatic collection tools to understand usage statistics and referral paths; you can refuse cookies in your browser settings.

Article 4 (Provision to third parties)

In principle, the Clinic processes personal information within the scope set out in Article 1, and does not process it beyond that scope or provide it to third parties without the data subject’s prior consent, except in the following cases.

  • Where separate consent has been obtained from the data subject
  • Where a specific legal provision applies, or it is unavoidable in order to comply with a legal obligation
  • In emergencies, where necessary for the urgent protection of the life, body or property of the data subject or a third party
  • Statutory review and claim bodies for health-insurance benefits, such as the Health Insurance Review & Assessment Service and the National Health Insurance Service

Article 5 (Outsourcing of processing)

The Clinic may outsource personal-information processing tasks within the scope needed for smooth operations, and where it does so it manages and supervises the contractors as required by the relevant laws.

Article 6 (Rights of data subjects and legal representatives, and how to exercise them)

Data subjects may at any time ask the Clinic for access to, correction or deletion of, or suspension of processing of, their personal information. The Clinic acts within 10 days as required by the relevant laws; access to and copies of medical records are handled under the Medical Service Act.

Article 7 (Destruction of personal information)

When personal information is no longer needed — the retention period has passed, or the purpose has been achieved — the Clinic destroys it without delay. Records that other laws such as the Medical Service Act require to be kept, including medical records, are stored securely in a separate database or storage location for the required period.

Article 8 (Measures to secure personal information)

To keep personal information secure, the Clinic takes administrative, technical and physical measures including an internal management plan, staff training, access-permission management, encryption of unique identifiers, security software, and access controls to the director’s office and consultation rooms.

Article 9 (Personal information manager)

Personal Information Protection Officer and manager: Park Young-jin / Chief Director / Obliv Clinic Seoul Origin Branch / Contact: 02-6956-3438, official@oblivseoul.kr

Article 10 (Reporting and remedies for infringement)

If you object to the exercise of rights under Article 38 of the Personal Information Protection Act, or your personal information has been infringed, you can contact the bodies below.

  • Personal Information Protection Commission (182, no area code) | www.pipc.go.kr
  • Personal Information Infringement Report Centre (118, no area code) | privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee (1833-6972) | www.kopico.go.kr
  • Supreme Prosecutors’ Office Cyber Investigation Division (1301, no area code) | www.spo.go.kr
  • National Police Agency Cyber Investigation Bureau (182, no area code) | ecrm.cyber.go.kr

Article 11 (Changes to this privacy policy)

This privacy policy applies from 20 April 2026. If it is revised, notice will be given at least 30 days before the changes take effect, on the clinic noticeboard, the website or another accessible channel.