Privacy Policy
How SEOLA handles the personal data collected during the application process.
Last updated: 21 September 2026
This document is a draft based on standard terms for medical education, congress support, tourism and concierge services for visiting healthcare professionals. Items that depend on business registration (business registration number, mail-order sales registration number) and some details may be completed or revised before the service opens. Questions: contact@theseola.com.
1. Personal Data We Collect
SEOLA (the "Company") collects the following personal data. 1. When you apply (required): name, e-mail address, medical licence number or qualification details, specialty, country and city of residence, program or package of interest, preferred language 2. When you apply (optional): WhatsApp or other contact details, how you heard about us, affiliated institution 3. After confirmation, where needed to run the program: passport name, number and expiry date, date of birth, flight details, accommodation requests, dietary restrictions, allergies and other health notes, emergency contact, names of accompanying persons 4. When you pay: remitter name, amount, date and method of payment, transaction reference issued by the payment service provider. Card numbers and other payment credentials are processed by the payment service provider and are not stored by the Company. 5. When you send an enquiry: name, e-mail address, organisation, message 6. Generated automatically while you use the website: IP address (stored as a hash), time of access, language preference cookie The Company does not use third-party tracking cookies for analytics or advertising.
2. Purpose of Collection and Use
1. Receiving applications, verifying eligibility, confirming participation and consultation 2. Registering participants for congresses and operating and booking program components such as accommodation, transport and interpretation 3. Processing payments, issuing receipts, handling refunds and payment-related disputes 4. Informing participants of schedules and changes, and contacting them in an emergency 5. Responding to enquiries and complaints 6. Complying with legal obligations, such as keeping transaction records 7. Sending news of future programs where the participant has separately consented The Company does not use personal data for any other purpose. If a purpose changes, separate consent is obtained in advance.
3. Retention and Use Period
The Company destroys personal data without delay once the purpose of collection and use has been achieved, except for the following, which are retained for the periods stated. 1. Applications with a payment record: 5 years, as records of payment and supply of goods or services (Korean Electronic Commerce Act) 2. Applications with a refund or dispute record: 3 years, as records of consumer complaints or dispute handling (Electronic Commerce Act) 3. Applications that ended without payment (received, consulted or cancelled): 1 year from the last record 4. Enquiries: 1 year from the last record 5. Records of contracts and withdrawals: 5 years (Electronic Commerce Act) 6. Records of labelling and advertising: 6 months (Electronic Commerce Act) 7. Website access logs: 3 months (Protection of Communications Secrets Act) 8. Passport details and other data collected to run a program: destroyed without delay after the program ends, unless essential to a payment or dispute record, in which case retained for that period The Company reviews data past its retention period at regular intervals and destroys it.
4. Disclosure to Third Parties
As a rule the Company does not disclose participants' personal data to third parties. It does so only to the minimum extent necessary to perform the Services, in the following cases. 1. Congress organisers and secretariats: where the participant has asked the Company to register on their behalf, the name, e-mail, affiliation, licence details and country needed for registration 2. Hotels and accommodation providers: name, passport details, contact details and check-in and check-out dates needed for the booking 3. Airlines, transport operators and travel insurers (where applicable): name, passport details, date of birth and contact details needed for the booking or policy 4. Host hospitals, clinics and lecture venues: name, affiliation and licence details needed for access and observation registration 5. Where required by law or requested by an investigating authority under due process Recipients must destroy the data once the purpose is fulfilled or the program ends. The specific recipients are communicated when participation is confirmed.
5. Outsourcing of Data Processing
The Company outsources the following processing to provide the Services. 1. Cloudflare, Inc. – website hosting, database and file storage 2. Resend, Inc. – sending application confirmations and notification e-mails 3. Payment service provider (to be announced when card payment is introduced) – card payment processing 4. Program operation partners (interpreters, vehicles, guides) – contact and escort for on-site operations Outsourcing contracts require compliance with data protection law, prohibit processing beyond the stated purpose, and provide for technical and organisational safeguards, restrictions on sub-processing and liability for damage. The Company supervises its processors and announces any change of processor through this Policy.
6. Cross-Border Transfers
The servers of the cloud hosting (Cloudflare) and e-mail (Resend) services used by the Company may be located outside Korea, including in the United States. Personal data is therefore stored and processed abroad as follows. 1. Recipients: Cloudflare, Inc. (United States), Resend, Inc. (United States) 2. Data transferred: all personal data listed in Section 1 (hosting); name, e-mail address and message content (e-mail) 3. Country, timing and method: the countries where the providers' data centres are located, including the United States, transferred over the network continuously as the service is used 4. Purpose and retention: within the purposes of Section 2 and the periods of Section 3 5. For participants residing outside Korea, personal data is transferred from the participant's country of residence to Korea for processing. Participants may refuse the cross-border transfer, in which case use of the Services through the website may be limited.
7. Your Rights and How to Exercise Them
1. Participants may at any time request access to, correction or deletion of, or suspension of processing of their personal data, and may withdraw consent. 2. Requests may be made by e-mail (contact@theseola.com) or in writing. The Company acts on the request and reports the result within 10 days of receipt. 3. A request made through a representative requires a power of attorney. 4. Data that must be kept under a legal retention obligation may be retained for that period despite a deletion request. In that case the Company explains the reason. 5. Participants residing in the European Union, the United Kingdom or other jurisdictions with comparable data protection law (such as the GDPR) may exercise the rights guaranteed there, including data portability and the right to lodge a complaint with a supervisory authority, through the same contact point.
8. Destruction Procedure and Method
1. The Company destroys personal data without delay once the retention period has expired or the purpose of processing has been achieved. Data past its retention period is reviewed regularly in the administration console and destroyed. 2. Data that must be kept under a legal obligation is stored separately and is not used for any other purpose. 3. Electronic files are deleted so that they cannot be recovered. Paper documents are shredded or incinerated.
9. Security Measures
1. Organisational measures: limiting the number of staff handling personal data, an internal management plan, regular reviews 2. Technical measures: access control and authentication for administrators, encryption in transit (HTTPS), hashing of IP addresses, retention of access logs 3. Physical measures: locked storage of documents and storage media
10. Data Protection Officer
Name: Kim Min Seo (Representative) E-mail: contact@theseola.com Telephone: +82-10-5583-8018 Participants may direct any enquiry, complaint or request for redress concerning personal data to the contact above. The Company responds and acts without delay.
11. Remedies for Infringement of Rights
To report or seek advice on a personal data infringement, you may contact the following Korean bodies. 1. Personal Information Infringement Report Center (KISA): 118 (no area code), privacy.kisa.or.kr 2. Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr 3. Supreme Prosecutors' Office, Cyber Investigation Division: 1301 (no area code), www.spo.go.kr 4. National Police Agency, Cyber Bureau: 182 (no area code), ecrm.police.go.kr Participants residing outside Korea may also lodge a complaint with the data protection authority of their country of residence.
12. Changes to This Policy
1. This Policy applies from 21 September 2026. 2. If the Policy is amended following changes in law, policy or the Services, the change is announced on this page at least 7 days before it takes effect. Changes that materially affect participants' rights are announced 30 days in advance. 3. Previous versions of the Policy are available on request.