Privacy Policy

Privacy Policy

Effective Date: May 2, 2026

Hyundai Research Institute (hereinafter the "Company") complies with the Personal Information Protection Act (PIPA) and other relevant laws to lawfully process and securely manage the personal information of users of the hrd.hri.co.kr service (hereinafter "Users"), in order to protect their freedoms and rights.

Accordingly, in accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following Privacy Policy to inform Users of the procedures and standards for processing personal information and to handle related grievances promptly and smoothly.

Article 1(Personal Information Items Processed, Purposes of Processing, and Retention Periods)

The Company processes personal information as follows. The personal information being processed is not used for any purpose other than those set out below, and the processing and retention period for each category of personal information is as follows.

  1. 1.
    Education service inquiries (Required)
    • ·
      Items collected: organization, name, contact number, email, expected number of trainees, courses of interest, referral path, inquiry details
    • ·
      Retention and use period: 3 years
    • ·
      Legal basis: Article 15(1)1 of the Personal Information Protection Act
  2. 2.
    Provision of marketing information such as promotions and benefits related to education services (Optional)
    • ·
      Items collected: organization, name, email, contact number
    • ·
      Retention and use period: until separate consent is withdrawn
    • ·
      Legal basis: Article 15(1)1 of the Personal Information Protection Act
  3. 3.
    Retention periods required under relevant laws are observed as follows.
    • ·
      Records on consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce, etc.)
    • ·
      Website visit records: 3 months (Protection of Communications Secrets Act)

Article 2(Provision of Personal Information to Third Parties)

  1. 1.
    The Company processes Users' personal information only within the scope specified in the purposes of processing, and provides it to third parties only where Article 17 or 18 of the Personal Information Protection Act applies, such as with the User's consent or under special provisions of law; otherwise, it does not provide Users' personal information to third parties.
  2. 2.
    For the smooth provision of services, the Company provides personal information only to the minimum extent necessary, with the User's consent, in the following cases:
    • 1.
      Where required by the provisions of law, or where an investigative agency requests it for investigative purposes in accordance with the procedures and methods prescribed by law
    • 2.
      Where the User has consented in advance

Article 3(Outsourcing of Personal Information Processing)

  1. 1.
    For the smooth handling of personal information tasks, the Company outsources personal information processing as follows:
    • ·
      Outsourcee: Hyundai Movex / Outsourced work: system operation and management / Retention and use period: until termination of the outsourcing contract
    • ·
      Sub-outsourcee: Amazon Web Services Inc. (AWS Seoul Region) / Sub-outsourced work: system operation and management / Retention and use period: until termination of the outsourcing contract
  2. 2.
    When concluding an outsourcing contract, the Company specifies in documents such as the contract the prohibition of processing personal information beyond the purpose of the outsourced work, technical and administrative protection measures, restrictions on re-outsourcing, supervision of the outsourcee, and liability for damages, etc., in accordance with Article 26 of the Personal Information Protection Act, and supervises whether the outsourcee processes personal information safely.
  3. 3.
    If the content of the outsourced work or the outsourcee changes, the Company will disclose this without delay through this Privacy Policy.

Article 4(Procedures and Methods for Destroying Personal Information)

  1. 1.
    When personal information becomes unnecessary due to the expiration of the retention period or the achievement of the processing purpose, the Company destroys it without delay.
  2. 2.
    If personal information must continue to be preserved under other laws even though the retention period consented to by the User has expired or the processing purpose has been achieved, the Company transfers such personal information to a separate database (DB) or stores it in a different location.
  3. 3.
    The procedures and methods for destroying personal information are as follows:
    • 1.
      Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it upon approval of the Company's Personal Information Protection Officer.
    • 2.
      Destruction method: Personal information recorded and stored in electronic file form is destroyed so that the records cannot be reproduced, and personal information recorded and stored on paper documents is shredded or incinerated.

Article 5(Rights and Obligations of Data Subjects and Their Legal Representatives, and Methods of Exercise)

  1. 1.
    Users may exercise rights such as requesting access to, correction of, deletion of, or suspension of processing of their personal information against the Company at any time.
  2. 2.
    Rights may be exercised against the Company in writing, by email, or by facsimile (FAX) in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
  3. 3.
    Rights may also be exercised through an agent, such as the User's legal representative or a duly authorized person. In this case, a power of attorney in the form of Attached Form No. 11 under the "Notice on Methods of Processing Personal Information (Notice No. 2023-12)" must be submitted.
  4. 4.
    Requests for access to and suspension of processing of personal information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.
  5. 5.
    A request for correction or deletion of personal information cannot be made for its deletion where the personal information is specified as a subject of collection under other laws.
  6. 6.
    When a User exercises the right to request access, correction/deletion, or suspension of processing, the Company verifies whether the person making the request is the data subject or a legitimate agent.

Article 6(Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information:

  1. 1.
    Administrative measures: establishment and implementation of an internal management plan, operation of a dedicated organization, and regular employee training
  2. 2.
    Technical measures: management of access rights to personal information processing systems, installation of access control systems, encryption of personal information, and installation and updating of security programs
  3. 3.
    Physical measures: access control to computer rooms, data storage rooms, etc.
  4. 4.
    Other activities: In addition to the matters prescribed by law, the Company carries out personal information protection activities such as regular personal information protection consulting, security risk assessments, and mock drills against electronic intrusion, in order to ensure the security of personal information.

Article 7(Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

  1. 1.
    The Company uses 'cookies' that store and retrieve usage information from time to time in order to provide individually customized services to users.
  2. 2.
    A cookie is a small piece of information that the server (https) used to operate the website sends to the user's computer browser, and it may be stored on the hard disk of the user's PC.
    • 1.
      Purpose of using cookies: Cookies are used to provide users with optimized information by identifying visits and usage patterns for each service and website visited by the user, popular search terms, whether the connection is secure, and so on.
    • 2.
      Installation, operation, and refusal of cookies: Chrome browser — click '⋮' at the top right > New Incognito Window (Ctrl+Shift+N) / Edge browser — click '…' at the top right > New InPrivate Window (Ctrl+Shift+N)
    • 3.
      If you refuse to store cookies, you may experience difficulties using customized services.

Article 8(Personal Information Protection Officer)

  1. 1.
    The Company is overall responsible for tasks related to the processing of personal information and designates a Personal Information Protection Officer as below to handle Users' complaints and remedy of damage related to personal information processing.
    • ·
      Personal Information Protection Officer — Name: Lee Jeong-jae / Position: Head of Education Division (Executive Director) / Contact: 02-2072-6280, hrihri@hri.co.kr (connects to the personal information protection department)
    • ·
      Personal Information Protection Department — Department: Education Planning & Operations Office / Person in charge: Yeom Hye-yeon / Contact: 02-2072-6380, yeom@hri.co.kr (Fax: 02-2072-6290)
  2. 2.
    Users may direct any inquiries, complaints, or requests for remedy of damage related to personal information protection arising while using the Company's service (hrd.hri.co.kr) to the Personal Information Protection Officer or the responsible department. The Company will respond to and handle Users' inquiries without delay.

Article 9(Department Receiving and Handling Requests for Access to Personal Information)

Users may direct any inquiries, complaints, or requests for remedy of damage related to personal information protection arising while using the Company's service (hrd.hri.co.kr) to the Personal Information Protection Officer or the responsible department. The Company will respond to and handle Users' inquiries without delay.

  1. -.
    Department receiving and handling requests for access to personal information — Department: Education Planning & Operations Office / Person in charge: Yeom Hye-yeon / Contact: 02-2072-6380, yeom@hri.co.kr (Fax: 02-2072-6290)

Article 10(Remedies for Infringement of Data Subjects' Rights)

  1. 1.
    Users may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Privacy Infringement Report Center, etc., in order to obtain remedy for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following organizations:
    • 1.
      Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
    • 2.
      Privacy Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
    • 3.
      Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
    • 4.
      National Police Agency: 182 (no area code) (ecrm.cyber.go.kr)

Article 11(Changes to the Privacy Policy)

  1. 1.
    This Privacy Policy applies from May 2, 2026.
  2. 2.
    Previous versions of the Privacy Policy can be found in a separate archive.