top of page

DERAMA

Privacy Policy

The online mall 'Cosmetique De Rama' (cremederama.com) (the "Shopping Mall"), operated by Derama Global Co., Ltd. (the "Company"), complies with personal data protection regulations under the Personal Information Protection Act and other relevant laws, and makes every effort to protect users' personal information. Through this Privacy Policy, the Company informs users of the purposes and methods for which the personal information they provide is used, and the measures taken to protect that information.

Article 1 (Items and Methods of Personal Information Collection)

1. The Company collects the following personal information for membership registration, consultation, service applications, etc.

a. When registering as a member (required)

•       Name, ID, password, mobile phone number, email address

b. When placing orders and making payments (required)

•       Recipient name, shipping address, contact information, payment information (credit card company name, card number, etc. are collected directly by the PG company and are not stored by the Company)

c. Information automatically generated and collected during service use

•       IP address, cookies, visit date/time, service usage records, records of improper use, device information (OS, browser type, etc.)

d. When participating in events/giveaways (optional)

•       Date of birth, gender, shipping address, and other items collected additionally depending on the event

2. Collection method: Information is collected through the website's membership registration and order/payment screens, event applications, and consultations via customer service, where users consent to the collection of personal information and directly enter the information themselves.


Article 2 (Purposes of Collecting and Using Personal Information)

The Company uses the collected personal information for the following purposes.

•       Member management: Identity verification and personal identification for membership services, prevention of fraudulent use by delinquent members, confirmation of intent to join, age verification, complaint handling, etc.

•       Provision of goods or services: Delivery of goods, provision of services, sending of contracts/invoices, provision of content, payment and settlement of fees, debt collection

•       Use in marketing and advertising: Development of new services (products) and provision of customized services, delivery of advertising information such as events, identification of access frequency, statistics on service use (only where separate consent has been given)


Article 3 (Retention and Use Period of Personal Information)

1. In principle, the Company destroys users' personal information without delay once the purpose of collecting and using the information has been achieved. However, the following information is retained for the stated periods for the reasons indicated.

a. Retention under the Company's internal policy

•       Records of fraudulent use: 1 year (to prevent fraudulent use)

b. Retention under relevant laws

Where retention is required under laws such as the Act on Consumer Protection in Electronic Commerce, etc., the Company retains member information for the periods prescribed by the relevant laws, as follows.

Retained Item

Retention Period

Legal Basis

Records on contracts or withdrawal of subscription

5 years

Act on Consumer Protection in Electronic Commerce, etc.

Records on payment and supply of goods, etc.

5 years

Act on Consumer Protection in Electronic Commerce, etc.

Records on consumer complaints or dispute resolution

3 years

Act on Consumer Protection in Electronic Commerce, etc.

Records on display and advertising

6 months

Act on Consumer Protection in Electronic Commerce, etc.

Records on electronic financial transactions

5 years

Electronic Financial Transactions Act

Login records

3 months

Protection of Communications Secrets Act


Article 4 (Procedures and Methods for Destroying Personal Information)

1. In principle, users' personal information is destroyed without delay once the purpose of its collection and use has been achieved.

2. Destruction procedure: Information entered by users is transferred to a separate database (or, in the case of paper documents, a separate filing cabinet) after the purpose has been achieved, and is then stored for a set period or destroyed immediately in accordance with internal policy and other relevant laws.

3. Destruction method: Personal information stored in electronic file form is deleted using technical methods that make the records unrecoverable, and personal information printed on paper is destroyed by shredding or incineration.


Article 5 (Provision of Personal Information to Third Parties)

In principle, the Company does not provide users' personal information to outside parties. However, the following are exceptions:

•       Where the user has given prior consent to the provision of information to a third party

•       Where required by law, or where a request is made by an investigative agency in accordance with the procedures and methods prescribed by law for investigative purposes

•       Where the minimum information necessary for delivery (recipient's name, address, contact information) is provided to a delivery company for shipping purposes


Article 6 (Outsourcing of Personal Information Processing)

To ensure smooth provision of services, the Company outsources personal information processing tasks to external specialized companies as follows.

Trustee

Outsourced Task

KG Inicis

Credit card and other payment processing, identity verification

Courier companies (delivery agents)

Product delivery

Website hosting and system operation


When entering into an outsourcing agreement, the Company specifies in the contract or other documents, in accordance with Article 26 of the Personal Information Protection Act, matters such as the prohibition on processing personal information for purposes other than performing the outsourced work, technical and administrative protection measures, restrictions on re-outsourcing, management and supervision of the trustee, and liability for damages, and supervises whether the trustee processes personal information safely.


Article 7 (Rights of Users and Legal Representatives and Methods of Exercising Them)

1. Users and their legal representatives may, at any time, view or correct their own registered personal information or that of a child under the age of 14, and may also request termination of membership (withdrawal of consent).

2. To view or correct personal information, users may click "Change Personal Information"; to terminate membership (withdraw consent), users may click "Withdraw Membership," after which they may directly view, correct, or withdraw following an identity verification process. Users may also contact customer service in writing, by phone, or by email, and the Company will take action without delay.

3. Where a user requests correction of an error in their personal information, the Company will not use or provide the relevant personal information until the correction has been completed.


Article 8 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

1. The Company uses "cookies" that store and periodically retrieve usage information in order to provide individually customized services to users.

2. Cookies are small pieces of information sent by the server operating the website to a user's browser, and may also be stored on the hard disk of the user's PC.

•       a. Purpose of using cookies: To analyze users' access frequency and visit times, identify users' preferences and interests, track usage patterns, and understand the degree of participation in various events and number of visits, for the purpose of targeted marketing and personalized services.

•       b. Installation, operation, and refusal of cookies: Users have the option of whether to allow the installation of cookies, and may configure their web browser to allow all cookies, to require confirmation each time a cookie is stored, or to refuse the storage of all cookies.

•       c. However, if a user refuses the installation of cookies, there may be difficulties in using certain services.


Article 9 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

•       Administrative measures: Establishment and implementation of an internal management plan, regular employee training, etc.

•       Technical measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs

•       Physical measures: Access control for computer rooms, data storage rooms, etc.


Article 10 (Privacy Officer)

The Company designates a Privacy Officer as follows, who takes overall responsibility for personal information processing and handles user complaints and remedies related to personal information processing.

•       Privacy Officer: Hyo Kim (CEO)

•       Contact: 02-3453-4628

•       Email: deramaglobal@gmail.com

•       Address: 303 Eonju-ro, Gangnam-gu, Seoul (Yeoksam-dong)

Users may direct any inquiries, complaints, or requests for remedies related to personal information protection arising from the use of the Company's services to the Privacy Officer and the relevant department. The Company will respond to and handle users' inquiries without delay.

If you need to report or consult regarding other personal information infringements, please contact the following organizations:

•       Personal Information Infringement Report Center (privacy.kisa.or.kr / 118, no area code)

•       Supreme Prosecutors' Office Cyber Crime Investigation Division (spo.go.kr / 1301, no area code)

•       National Police Agency Cyber Bureau (cyberbureau.police.go.kr / 182, no area code)


Article 11 (Changes to the Privacy Policy)

This Privacy Policy applies from its effective date. In the event of any additions, deletions, or corrections to its contents due to changes in laws or policy, notice will be given through the notice board beginning 7 days before the changes take effect.

Date of Announcement: July 29, 2026    Effective Date: August 5, 2026

Our Store

309 Eonju-ro, Gangnam-gu, Seoul

Derama Global, 4th floor of Kiseong Building

 

Monday - Friday: 9am - 6pm
Weekends and public holidays: Closed

 

Phone number: 02-3453-4628

Email: deramaglobal@gmail.com

Customer Service

Phone number: 02-3453-4628

Follow our latest news on Instagram and blog

You can find out.

  • Instagram

Derama Global Co., Ltd.

303, Eonju-ro, Gangnam-gu, Seoul (Yeoksam-dong) 1st, 2nd, 7th, 8th floor

Representative: Kim Hyo

Business registration number:
602-86-00310 Business No. Lookup >

Mail order business registration number: 2017-Seoul Gangnam-0243

Personal information manager: Kim Hyo

Representative number: 02-3453-4628

Fax: 02-3453-8874

Email: deramaglobal@gmail.com

Hosting provided by: WIX

Copyright © DERAMA All rights reserved.

bottom of page