U2MEDTEK Co., Ltd. (hereinafter referred to as the 'Company') highly values the privacy of our users and complies with relevant laws and regulations, including the "Personal Information Protection Act" of the Republic of Korea, as well as the Google Play Developer Policy.
This policy explains how the personal information and app data of users who use the SinusViewer app service (hereinafter referred to as the 'Service'), which interfaces with our dedicated near-infrared transilluminator device, SinusView Air (hereinafter referred to as the 'Device'), are collected, used, and protected.
1. Purpose of Collection and Use, Items, and Retention Period of Personal Information
The Company collects the minimum personal information necessary for the following purposes. Collected information will not be used for purposes other than those specified, and we will obtain prior consent if the purpose of use changes.
| Category |
Purpose of Collection and Use |
Collected Items |
Retention and Use Period |
| User |
- Membership registration and identification - Account management and providing "Find Password" function |
Login ID, password, affiliation (organization), email address |
Until membership withdrawal (However, if required by relevant laws and regulations, until the end of the designated period) |
| Automatically Collected Items |
- Troubleshooting service errors and improving service - Security auditing |
Service usage records, access logs, device information |
Until membership withdrawal (However, if required by relevant laws and regulations, until the end of the designated period) |
| Examinee (Patient/Subject) |
- Managing light transmittance measurement history by examinee - Providing cloud synchronization features |
Name (pseudonymized), gender, chart number |
Until membership withdrawal (However, if required by relevant laws and regulations, until the end of the designated period)
On-Device Processing (Stored only on the Android device if the cloud feature is not used)
|
| Image Information |
- Capturing transillumination images - Measuring paranasal sinus light transmittance - Providing cloud synchronization features |
Near-infrared (NIR) images, paranasal sinus light transmittance data |
Until membership withdrawal (However, if required by relevant laws and regulations, until the end of the designated period)
On-Device Processing (Stored only on the Android device if the cloud feature is not used)
|
⚠️ Status of the Examinee's Personal Information Processor and the Company:
The 'User' (and their affiliated institution) using this Service acts as the Data Controller regarding the examinee's personal information and is solely responsible for obtaining direct consent from the examinee for the collection and use of their personal information.
The Company acts as a Data Processor that technically processes the examinee's personal information (such as near-infrared images, sinus light transmittance data, etc.) within the scope entrusted by the User.
The Company does not independently use such information for purposes other than those directed by the User or specified in the entrustment agreement.
Requests regarding consent to collect/use, correction, or deletion of examinee personal information must, in principle, be processed through the User, and the Company will support such requests upon the User's direction.
⚠️ Notice on Processing Sensitive Information: The image information collected by this Service falls under 'Sensitive Information' under the Personal Information Protection Act. The Company will strictly never use this information for any purpose other than measuring transmittance and providing the Service.
2. Camera Permission and User Data Handling (Google Play Policy Compliance)
While this Service interfaces with dedicated transilluminator hardware equipped with a near-infrared camera to measure light transmittance, it does not access or use the mobile device's built-in camera.
- Purpose of Use: Images acquired through the dedicated transilluminator device are analyzed in real-time solely to generate paranasal sinus light transmittance measurements.
- Cloud Synchronization and Transfer: Examinee data is transmitted to the server only when the user explicitly agrees and enables the 'Cloud Sync' function within the app. This feature can be disabled at any time in the app settings.
- Data Security: All camera images and app data are transmitted over HTTPS (SSL/TLS) secure encrypted sessions and are safely encrypted when stored on the server.
3. Procedure and Method of Personal Information Destruction
In principle, the Company destroys personal information without delay once the purpose of collection and use is achieved, or when the retention period required by relevant laws and regulations expires. The procedure and method of destruction are as follows:
- Destruction Procedure: Personal information stored within the app is destroyed when the app is deleted. Personal information stored in the cloud is transferred to a separate database, retained for a certain period according to relevant laws, and then destroyed.
- Destruction Method:
- Electronic file format: Permanently deleted using technical methods that render the records unrecoverable.
4. Provision of Personal Information to Third Parties and Entrustment
In principle, the Company does not provide or outsource the personal information of Users and Examinees to external third parties.
However, when using external cloud servers to ensure service stability, we manage and supervise the cloud service providers to prevent them from using personal information for purposes other than those specified.
Entrustment of Personal Information Processing - The Company may outsource personal data processing for the purpose of storing and processing personal information on cloud servers as follows:
- AWS (Amazon Web Services)
- GCP (Google Cloud Platform)
- Ncloud (Naver Cloud)
5. Rights of Users and Legal Representatives and How to Exercise Them
- Users may view or modify their registered personal information or that of the examinees they manage at any time, and may request termination of subscription (account deletion).
- If you wish to access, correct, or delete personal information, you can do so via the in-app settings or the following account deletion process page:
https://blog.u2medtek.com/article/howto-unregister/
- If a User requests the correction of an error in their personal information, the Company will not use or provide the corresponding personal information until the correction is completed.
- If the Service is not used for a certain period of time (2 years), the account will be converted into an inactive account. The personal information stored in the cloud will be transferred to a separate storage facility, stored for a specified period of time in accordance with relevant laws and regulations, and then destroyed. Users may request to view their personal information within the period prescribed by law.
6. Measures to Ensure the Security of Personal Information
The Company implements the following technical and administrative measures to prevent personal information from being lost, stolen, leaked, altered, or damaged:
- Technical Measures: Encrypted storage of personal and sensitive data, application of HTTPS encrypted communication during transmission, prevention of computer viruses using antivirus software, and blocking external intrusions using firewalls.
- Administrative Measures: Restricting access to personal information to a minimal number of authorized personnel, establishing and implementing internal management plans, and conducting regular security training for employees.
7. Matters Concerning the Installation, Operation, and Rejection of Automatic Personal Information Collection Devices
The Company uses essential session information and cookies solely for personal identification. We do not use this data for any other purposes, nor do we collect or manage behavioral data for targeted advertising. If you decline the automatic collection of this information, the Company will not be able to provide the services.
8. Chief Privacy Officer and Complaint Handling Department
The Company has designated a Chief Privacy Officer (CPO) to take overall responsibility for personal information processing, handle user complaints, and provide remedy for damages related to personal information processing as follows:
- Chief Privacy Officer (CPO)
- Name: Yang-seok Kim
- Email: yskim@u2medtek.com
- Phone: +82-2-6952-7078