1. Scope this Privacy Notice
Genesis Business Solutions & Services (“Company”, “We”, “Our”, or “Us”) understands that you are aware of and care about your own privacy, and we take that seriously.
This Privacy Notice (this or the “Notice”) applies to your use of this website (http://expat-mart.com/) or mobile application, (collectively the “Services”), regardless of how you access or use these Services, including access via mobile devices and apps.
If you are protected by Korean national law this Notice does not applies to you to find out how we process and protect your personal data.
Please check the Notice from time to time when you visit our website, as the Notice may be amended pursuant to the government’s policy or out of necessity of the Company.
Date of Notification: 2020.12.09
2. Data Controller
The Company is the data controller of personal data processed in relation to our service operated through Expat Mart. You can contact the Company as follows;
Genesis Business Solutions & Services 2F, Woosuk Building, #84, Dokseodang-ro, Yongsan-gu, Seoul, Korea04420, Tel: +82-70-7841-9798 Email: firstname.lastname@example.org
3. Data Protection Officer and Contact
If you have any questions or complaints about this Notice or privacy issues in relation to the use of our services, you can contact the Data Protection Officer.
Data Protection Officer
Name: K.M. MEENA
4. What Personal Data We Collect and Process
We collect your personal data when you use our Services, create a new expat-mart account, provide us with information via a web form, add or update information in your expat-mart account or otherwise interact with us. We do not collect any sensitive data (e.g. personal data revealing racial, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, data concerning a natural person's sex life or sexual orientation or personal data relating to criminal convictions and offences).
In total, we collect the following personal data:
Personal data you provide when using our Services or creating an account
• Data that identifies you, such as your name, email addresses, ID, and password that you provide when setting up our expat-mart account or at a later date.
• Data regarding orders or purchases that you provide in a transaction
• Content that you share with other users through Services such as feedback, ratings, product reviews and associated comments.
• Financial information (e.g. credit card and bank account numbers, payment details) in connection with a transaction or Smile Cash management.
• Shipping, billing, and other information you provide in connection with the purchase or shipping of an item, as well as information required for customs clearance (such as tax identification numbers or other identification numbers) and relevant shipping information (such as shipment numbers and tracking information) if shipped through one of our programs.
• You may provide us with additional information through a web form or by inquiries, dispute resolution, participation of the any promotions or if you contact us for any other reason regarding our Services.
• Other data that we are required or entitled by applicable law to collect and process and that we need for your authentication or identification, or for the verification of the data we collect.
Personal data we collect automatically when you use our Services or create an account
• Data that is generated as part of one of your transactions (orders, purchases, shipping) or participation of any promotions or that is linked to your account as a result of a transaction in which you are involved, such as transaction amounts and time of transactions and payment methods
• Data that is generated through your other actions when you use our Services and which is linked to your expat-mart account, e.g. when you place items in your shopping cart, place items on the wish list, favorite shop, purchased shop or viewed items.
• Data regarding all other interactions with our Services, your communications with us.
• Computer and connection information, such as your IP address, date and time of your access, your browser type, referral URL, device ID or individual device identifier, operating system type and version, Session ID, wireless carrier, and cookie-related data (e.g. cookie ID).
5. Purposes and Legal Basis for Data Processing and Categories of Recipients
We process your personal data for various purposes and pursuant to various legal bases. We process your personal data primarily to provide and improve our Services, to contact you about your expat-martaccount and our Services, to provide customer service, and to detect, prevent, mitigate and investigate fraudulent or illegal activity.
We process your personal data in order to fulfil our contract with you and to provide you with our Services. This includes the following purposes:
• Processing of data relating to you or your company for the purpose of entering into a contract with you and executing it.
• Provision of our Services, including but not limited to enabling and performing transactions with other users (including the transmission of your personal data to other users where necessary to perform the transaction, including in cases of terminated, failed or subsequently voided transactions), providing and enhancing features such as payment processing, ratings and expat-martaccount management, providing other services you may use (as described in connection with such services), and ensuring the functionality of our Services. In connection with the provision of our Services, we will send you notifications relating to the execution of transactions and the use of our Services in accordance with the communication preferences in your expat-mart account.
• Enabling the delivery of purchased items by logistics/shipping service providers including notifications in connection with the delivery (such as tracking information), the latter to the extent permitted by applicable law without your consent.
• Provision of our payment services.
• Solution of problems with your expat-mart account, arbitration of disputes, providing other services and within the scope of customer service. For these purposes, we may contact you via notification email or push notification on your mobile device.
• Enforcement of our User Agreement, this Privacy Notice and other rules and policies.
We process your personal data in order to comply with legal obligations to which we are subject. This includes the following purposes
• Participation in proceedings (including judicial proceedings) conducted by public authorities or government agencies, in particular, for the purpose of detecting, investigating and prosecuting illegal acts.
• Prevention, detection and mitigation of illegal activities
• Ensuring the information security of our Services.
• Retention and storage of your personal data to comply with specific legal retention requirements.
We process your personal data in order to protect your vital interests or the vital interests of another natural person. This includes the following purposes:
• Prevention, detection, mitigation and investigation of unlawful activities that may result in impairment of your vital interests or the vital interests of another natural person, unless there is a statutory obligation to this effect.
We process your personal data where necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. In order to reconcile our legitimate interests with your rights, we have introduced appropriate control mechanisms. On this basis, we process your data for the following purposes:
• Participation in proceedings (including judicial proceedings) conducted by courts, law enforcement agencies, government agencies or public authorities, intergovernmental or supranational bodies, in particular for the purpose of detecting, investigating and prosecuting illegal acts, unless there is a statutory obligation to this effect, and we may legitimately assume that the disclosure of the data is necessary to avert imminent disadvantages or to report a suspicion of an illegal act. In such cases, we will only disclose what we believe is necessary.
• Protection of the legitimate interests of third parties in connection with civil law disputes, unless there is a statutory obligation to this effect, if we may legitimately assume that it is necessary to disclose the data to such third parties in order to avert imminent disadvantages.
• Prevention, detection, mitigation and investigation of fraud, security breaches and other prohibited or unlawful activities, including the assessment of corresponding risks, unless there is a statutory obligation to this effect.
• Monitoring and improvement of the information security of our Services, unless there is a statutory obligation to this effect.
• Performance of identity checks, evaluation of applications and comparison of information for accuracy and verification purposes.
• Provision of functions for users that make the processing of transactions easier or more convenient (e.g. translation of the Services, administration of several delivery addresses).
• Analysis and improvement of the Services from us e.g. by reviewing information from users about blocked or crashed pages in order to identify and solve problems and to provide you with an improved user experience, including as part of product development.
• To the extent permitted by applicable law without your consent, communications with you via email to offer you vouchers, discounts and special offers and to inform you about our Services. If you do not wish to receive marketing communications from us, you can also unsubscribe by clicking on the link in the email you received.
• Assertion of or Defence against legal claims, including those asserted by one user against another user.
We may also process your personal data on the basis of your consent, which you have given so that we or third parties can enable you to use certain services or make them available to you.
We will not make any automated decisions about you that would significantly affect you unless such a decision is necessary for entering into, or the performance of, a contract with you, we have obtained your consent, or we are required by applicable law to use such technology. You will find information on your right to object to this processing of your data below under Rights as a data subject.
6. Categories of Recipients
Without your consent, we will not pass on your personal data to third parties for their marketing or advertising purposes, nor will we sell or otherwise make it available to third parties for a fee. We only disclose your personal data when it is necessary for the purposes mentioned in this Notice.
We may share your data with third party service providers who provide services on our behalf. We have contracts in place with these service providers. This means that they cannot do anything with your personal data unless we have instructed them to do it. They will not share your personal data with any organization apart from us. They will hold it securely and retain it for the period we instruct.
When necessary, we transmit your personal data to following data processors and recipients for one or several of the purposes described in this Notice:
• Other expat-martusers, which includes sellers
• External service providers and shipping companies
• External service providers who facilitate events or promotions on our behalf
• External service providers who provide customer services or fraud monitoring on our behalf
• Payment service providers including the PayPal Inc. group of companies
• External operators of websites, applications, services and tools
• Law enforcement agencies, courts, government agencies or public authorities, intergovernmental or supranational bodies
• Third parties who are involved in judicial proceedings, in particular, if they submit a legal order, court order or equivalent legal order to us.
7. Storage Duration and Erasure
As a general rule, the Company retains and uses customer’s personal data for as long as it is required in order to fulfil the relevant purposes described in this Notice. Once the purposes of collection and use of the personal data are achieved, it is without delay destroyed (provided, however, that the personal data will be destroyed after two (2) months from the date of termination of a shopping service user agreement (“User Agreement”) to prevent re-registration during the re-registration probation period).
However, if required to retain personal data pursuant to applicable laws, we retain user’s personal data for such duration as prescribed thereby.
8. Rights as a Data Subject
Subject to possible restrictions under national law, as a data subject, you have the right to access, rectification, and erasure, restriction of processing and data portability with regard to your personal data. In addition, you can withdraw your consent and object to our processing of your personal data on the basis of legitimate interests. You can also lodge a complaint with a supervisory authority.
Your rights in detail:
• You can withdraw your consent to the processing of your personal data by us at any time. As a result, we may no longer process your personal data based on this consent in the future. The withdrawal of consent has no effect on the lawfulness of processing based on consent before its withdrawal.
• You have the right to obtain access to your personal data that is being processed by us. In particular, you may request information on the purposes of the processing, the categories of personal data concerned, the categories of recipients to whom the personal data have been or will be disclosed, the envisaged period for which the personal data will be stored, the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data or to object to such processing, the right to lodge a complaint with a supervisory authority, any available information as to the personal data’s source (where they are not collected from you), the existence of automated decision-making, including profiling and, where appropriate, meaningful information on its details. Your right to access may be limited by national law.
• You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
• You have the right to obtain from us the erasure of personal data concerning you, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims. The right to erasure may be limited by national law.
• You have the right to obtain from us restriction of processing to the extent that
- he accuracy of the data is disputed by you,
- he processing is unlawful, but you oppose the erasure of the personal data,
- we no longer need the data, but you need it to assert, exercise or defend legal claims or
- you have objected to the processing.
• You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller ('right to data portability').
• You have the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or your place of work.
• If your personal data is processed on the basis of legitimate interests, you have the right to object to the processing of your personal data on grounds relating to your particular situation. This also applies to profiling. If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing.
The exercise of the above data subjects' rights (e.g. right to access or erasure) is generally free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge an appropriate fee (at most our actual costs) in accordance with the applicable statutory regulations or refuse to process the application.
Find out how to manage cookies on popular browsers:
• Google Chrome
• Microsoft Edge
• Mozilla Firefox
• Microsoft Internet Explorer
• Apple Safari
To find information relating to other browsers, visit the browser developer's website.
10. Data Security
We protect your personal data through technical and organisational security measures to minimise risks associated with data loss, misuse, unauthorised access and unauthorised disclosure and alteration. To this end we use firewalls and data encryption, for example, as well as physical access restrictions for our data centres and authorisation controls for data access.
11. Children’s Privacy
Our services are not intended for use by children. We do not knowingly collect personal data from users who are considered children under applicable national laws. According to our User Agreement, children are not permitted to use our Services.