Privacy Policy
This Privacy Policy takes effect on July 7, 2026. The Korean-language version of this Policy is the authoritative original; versions in other languages are provided as reference translations, and the Korean-language version prevails in the event of any conflict.
Effective date: July 7, 2026
Portzone Co., Ltd. (the "Company") operates "Mediport" (mediportkorea.com; the "Service"), a concierge service for foreign medical tourists. In accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following Privacy Policy in order to protect the personal information of data subjects and to handle related grievances promptly and effectively. The Company is a non-medical concierge service provider that supports language interpretation, appointment coordination with partner medical institutions, and accompaniment; medical services such as diagnosis and treatment are performed by licensed domestic partner medical institutions, and the Company does not perform them directly. The Company processes only the minimum personal information necessary for consultations and referrals to partner medical institutions, on the basis of the data subject's consent.
Article 1 (General Provisions and Business Operator Information)
This Privacy Policy applies to the processing of the personal information of data subjects who use the Service (mediportkorea.com) operated by the Company and the free consultation features connected to it.
Business operator information — Company name: Portzone Co., Ltd. (주식회사 포트존) / Representative Director: 송준 / Business Registration Number: 579-86-02828.
Foreign Patient Attraction Business Registration Number: A-2026-01-01-07030 (valid until June 22, 2029).
Address: Room 411, Daeryung Technotown 19th, 70 Gasan Digital 2-ro, Geumcheon-gu, Seoul, Republic of Korea (Postal Code 08589).
Personal information inquiries: sales@portzone.co.kr / Tel. 010-8721-5088.
The Company is a non-medical concierge service provider, and consultations are provided free of charge. Any and all medical services, such as diagnosis and treatment, are performed by licensed domestic partner medical institutions.
The Korean-language version of this Policy is the authoritative original. In the event of any conflict between the Korean-language version and a version translated into another language, the Korean-language version shall prevail.
Article 2 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes and does not use the processed personal information for any purpose other than those set out below. Should the purpose of use change, the Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
1. Responding to free consultations and confirming the medical departments and procedures in which the user is interested.
2. Matching the user with a suitable partner medical institution, arranging medical appointment referrals, and coordinating interpretation and accompaniment.
3. Replying to inquiries and providing updates on the progress of consultations.
4. Analyzing service usage statistics and improving the quality and convenience of the Service.
The legal basis on which the Company processes personal information is, in principle, the consent of the data subject (Article 15(1)1 of the Personal Information Protection Act); for sensitive information, provision to third parties, and cross-border transfers, the Company obtains separate consent in each case.
Article 3 (Items of Personal Information Collected and Methods of Collection)
The Company processes the following items of personal information.
[Items the user provides directly when submitting a consultation request (/consult)] name; country; medical departments and procedures of interest; free-text description of symptoms and requests; preferred visit date; visa status; estimated budget (selected as a range); additional request items (accommodation, interpretation, visa, pickup, and other required items); preferred contact method (type of messenger); messenger ID; referral source (self-reported by the user); referrer code; and whether consent to the collection and use of personal information, etc., was given, together with the date and time of such consent. Of these, the 'medical departments and procedures of interest' and the 'free-text description of symptoms and requests' constitute sensitive information as health-related information, and their processing is separately governed by Article 4.
[Items automatically generated and collected in the course of using the Service] anonymous session identifier (mp_sid, stored in the browser's localStorage); access IP address; device and browser information; pages visited; referral path information (referrer and internal landing-page paths); UTM parameters; and advertising click identifier (gclid). In the course of processing consultation requests, the Company uses the access IP address only temporarily for the purpose of abuse prevention (blocking spam and excessive requests), applies one-way hashing to it, and does not store it separately. However, access information may be recorded in the server logs and analytics tools of the hosting and analytics processors (Article 8).
Methods of collection — (a) the user entering information into the consultation form and submitting it (submission requires mandatory consent to the collection and use of personal information, etc.; if consent is not given, the consultation request is not submitted); and (b) automatic collection via cookies, similar storage technologies, and analytics beacons.
The Company processes the above items with the data subject's consent and collects only the minimum necessary items.
Article 4 (Matters Concerning the Processing of Sensitive Information)
In principle, the Company does not process sensitive information pursuant to Article 23 of the Personal Information Protection Act; however, where unavoidable for consultation purposes, it processes the health-related information set out below and obtains 'separate consent' for such processing, distinct from consent to the processing of general personal information.
Sensitive information items processed: medical departments and procedures of interest, and free-text description of symptoms and requests (health-related information).
Purpose of processing: to understand the user's treatment interests in order to match a suitable partner medical institution and to support appointment referral and interpretation.
Retention and use period: the information is destroyed without delay once the consultation and referral purposes have been achieved; where a statutory retention obligation applies, it is retained for the applicable period and then destroyed (Article 6 applies mutatis mutandis).
Notice of potential disclosure: if the user consents to provision to the matched partner medical institution as a third party, some of the above sensitive information (e.g., the medical departments and procedures of interest and the requests) may be provided to that medical institution.
How to withhold disclosure: the user may choose not to enter any health information they do not wish to share in the free-text symptom/request field, and may submit only the minimum information.
The user has the right to refuse consent to the processing of sensitive information; however, if consent is refused, the provision of core functions of the Service, such as confirming treatment interests and matching with partner medical institutions, may be restricted.
Article 5 (Matters Concerning the Processing of Unique Identifying Information)
The Company currently does not collect or process unique identifying information under Article 24 of the Personal Information Protection Act, such as resident registration numbers or passport numbers (not applicable).
Should it become necessary in the future to collect unique identifying information, such as passport numbers, for purposes such as confirming appointments, the Company will process such information only where there is a legal basis or where separate consent, distinct from consent to the processing of other personal information, has been obtained from the data subject, and will amend and disclose this Policy in advance.
Article 6 (Processing and Retention/Use Period of Personal Information)
In principle, once the purpose of processing personal information (responding to consultations and referring to and coordinating partner medical institutions) has been achieved, the Company destroys the relevant personal information without delay.
Where a data subject requests deletion of their personal information, the Company destroys the relevant personal information without delay, except where a statutory retention obligation applies.
Automatically collected access/usage information and behavioral information is destroyed or anonymized once the usage-analysis purpose has been achieved or the period specified in the retention policy of each analytics/advertising tool (Articles 8 and 13) has elapsed.
Where the relevant statutes prescribe an obligation to retain information for a certain period, the Company retains the personal information for the period prescribed by the applicable statute and then destroys it. In such cases, the retained personal information is not used for any purpose other than the purpose of retention.
Specific retention periods are determined according to the purpose of processing and the relevant statutes, and the Company destroys personal information whose retention period has elapsed or whose processing purpose has been achieved in accordance with the procedures and methods set out in Article 12.
Article 7 (Provision of Personal Information to Third Parties)
The Company provides personal information to third parties only within the scope consented to by the data subject; otherwise, it provides personal information only in cases falling under Articles 17 and 18 of the Personal Information Protection Act.
After a consultation, with the user's separate consent, the Company provides the necessary personal information to the domestic partner medical institution (hospital/clinic) matched with the user, for the purposes of appointment, referral, and interpretation. The specific details of such provision are as follows.
Recipient: the domestic partner medical institution (hospital/clinic) matched with the user. The specific medical institution is determined at the time of matching based on the outcome of the consultation.
Purpose of provision: medical appointment and referral, and interpretation support during the course of treatment.
Items provided: name, contact method (messenger ID), and the medical departments and procedures of interest and requests.
Retention and use period: as governed by the recipient partner medical institution's own privacy policy.
As a matter of principle, at the time of the actual matching, the Company specifically informs the user of the name of the recipient medical institution and the items and purpose of the provision, and provides the personal information only after confirming the user's consent.
The data subject has the right to refuse consent to provision to third parties; however, if consent is refused, the provision of the appointment-referral service with partner medical institutions may be restricted.
Article 8 (Outsourcing of Personal Information Processing)
For the smooth provision of the Service, the Company outsources personal information processing tasks to external specialized providers as follows.
Processor: Supabase — Outsourced task: database hosting and storage.
Processor: Vercel — Outsourced task: website hosting and serving.
Processor: Resend — Outsourced task: sending transactional (operational notification) emails related to consultation intake.
Processor: Google — Outsourced task: usage analysis via Google Analytics 4 and advertising-conversion measurement via Google Ads.
Processor: Microsoft (Microsoft Clarity) — Outsourced task: session analysis. Items constituting personally identifiable information are masked and not recorded.
When entering into outsourcing contracts, the Company, in accordance with Article 26 of the Personal Information Protection Act, specifies in the contract and other documents matters concerning the safe management of personal information, the prohibition of processing beyond the purpose, restrictions on re-outsourcing, technical and administrative protective measures, liability including damages, and other such matters, and supervises whether the processor handles personal information safely.
Should the content of the outsourced tasks or the processor change, the Company will disclose this without delay through this Privacy Policy.
Article 9 (Matters Concerning the Cross-Border Transfer of Personal Information)
Because the processors referred to in Article 8 are located overseas, the Company transfers personal information abroad. In accordance with Article 28-8(1)3(a) of the Personal Information Protection Act, the Company discloses the details of such cross-border transfers in this Privacy Policy as set out below, and also obtains separate consent to the cross-border transfer at the time of the consultation request.
Transferee: Supabase / Country of transfer: overseas (including the United States) / Items transferred: personal information collected through the consultation form and automatically collected information / Purpose of transfer: database hosting and storage / Date and method of transfer: transmitted from time to time over the information and communications network when the Service is used (over an encrypted communication channel) / Retention and use period: until termination of the outsourcing contract or destruction of the personal information / Personal information protection inquiries: the transferee's privacy policy (https://supabase.com/privacy).
Transferee: Vercel / Country of transfer: United States / Items transferred: access/usage information (IP, device and browser information, etc.) / Purpose of transfer: website hosting and serving / Date and method of transfer: transmitted from time to time over the information and communications network upon access / Retention and use period: until termination of the outsourcing contract / Personal information protection inquiries: https://vercel.com/legal/privacy-policy.
Transferee: Resend / Country of transfer: United States / Items transferred: information necessary for sending emails (recipient address, etc.) / Purpose of transfer: sending operational notification emails related to consultation intake / Date and method of transfer: transmitted over the information and communications network when emails are sent / Retention and use period: until termination of the outsourcing contract / Personal information protection inquiries: https://resend.com/legal/privacy-policy.
Transferee: Google / Country of transfer: United States / Items transferred: automatically collected information such as cookie, device, and usage information, and the advertising click identifier (gclid) / Purpose of transfer: usage analysis and advertising-conversion measurement / Date and method of transfer: transmitted from time to time over the information and communications network upon access / Retention and use period: in accordance with Google's policies / Personal information protection inquiries: https://policies.google.com/privacy.
Transferee: Microsoft (Microsoft Clarity) / Country of transfer: United States / Items transferred: session analysis information (personally identifiable items are masked) / Purpose of transfer: session analysis / Date and method of transfer: transmitted from time to time over the information and communications network upon access / Retention and use period: in accordance with Microsoft's policies / Personal information protection inquiries: https://privacy.microsoft.com/privacystatement.
The contact information for each transferee's personal information protection officer can be found in the respective company's privacy policy above.
The data subject may refuse the cross-border transfer. Such refusal may be exercised by not submitting a consultation request at all, or, for automatically collected items, by refusing the collection of non-essential signals in the consent banner or by blocking cookies in the browser; in such cases, the submission of a service request or the use of certain features may be restricted.
Article 10 (Processing of Personal Information When Using Messenger Platforms)
Where a user initiates a conversation with the Company for consultation via a messenger platform such as LINE, WhatsApp, WeChat, or KakaoTalk, the content of that conversation and related information is processed by the respective messenger platform operator chosen by the user, in accordance with that operator's privacy policy.
These messenger platforms are not processors of the Company but separate channels that the user chooses and uses on their own. As the Company has no authority to control the processing of personal information within those platforms, users are advised to also review the privacy policy of each messenger platform.
The Company processes consultation-related information provided by the user through a messenger only within the scope of the purposes set out in Article 2.
Article 11 (Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them)
The data subject may at any time request the Company to allow access to, correct, delete, or suspend the processing of their personal information, and may withdraw consent to the processing of personal information.
These rights may be exercised by contacting the personal information protection officer referred to in Article 16 in writing, by email (sales@portzone.co.kr), by telephone (010-8721-5088), or by other means, and the Company will take the necessary measures without delay.
The data subject may exercise the above rights through a legal representative or a duly authorized agent, in which case a power of attorney and other documents required under the Public Notice on the Methods of Processing Personal Information must be submitted.
When a request for access, correction, deletion, or suspension of processing is made, the Company verifies whether the requester is the data subject in person or a legitimate agent.
However, in cases falling under Article 35(4) and Article 37 of the Personal Information Protection Act—such as where a statute mandates the retention of personal information or where there is a risk of unfairly infringing upon another person's life, body, property, or interests—a request for access or suspension of processing may be restricted, in which case the Company notifies the data subject of the reason without delay.
The data subject is obliged to provide their personal information accurately and keep it up to date, and the Company is not liable for any disadvantage arising from the provision of inaccurate information.
Article 12 (Procedures and Methods for Destroying Personal Information)
Where the retention period of personal information has elapsed or personal information has become unnecessary because the processing purpose has been achieved, the Company destroys the relevant personal information without delay.
Destruction procedure: the Company selects the personal information subject to destruction and destroys it after review by the personal information protection officer.
Destruction method: personal information stored in electronic file form is permanently deleted by a method that renders recovery and reproduction impossible, and personal information recorded on paper documents or other printouts is destroyed by shredding or incineration.
Personal information that must be retained under statute is stored separately from other personal information in a separate database or a separate location and is not used for any purpose other than the purpose of retention.
Article 13 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof / Behavioral Information and Targeted Advertising)
To provide users with customized services and to analyze service usage statistics, the Company uses automatic collection devices such as cookies, browser storage (localStorage), and analytics beacons.
For non-essential advertising/analytics signals, the Company obtains the user's consent through a consent banner, and the user may refuse (opt out of) such signals.
The user may refuse to store, or may delete, cookies through the settings of their web browser. However, if the user refuses to store cookies, the use of certain service features may be restricted.
Collection and use of behavioral information — Through Google Analytics 4, Google Ads, and Microsoft Clarity, the Company automatically collects behavioral information such as the user's pages visited, referral path information (referrer and internal landing paths), UTM parameters, advertising click identifier (gclid), device/browser information, and session usage information. The method of collection is automatic collection via cookies, beacons, and the like, and the purpose of collection is usage analysis, advertising-conversion measurement, and service improvement.
Third parties that process behavioral information (advertising/analytics operators): Google and Microsoft. Retention and use periods are governed by each operator's policies.
How to refuse or block the collection of behavioral information: (a) refusing the collection of non-essential signals in the in-service consent banner; (b) blocking cookies through the web browser settings; and (c) blocking via Google Ads Settings and the Google Analytics Opt-out Browser Add-on, among others.
In session analysis via Microsoft Clarity, input items constituting personally identifiable information are masked and not recorded.
Article 14 (Measures to Ensure the Security of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following measures to ensure the security of personal information.
Administrative measures: establishing and implementing an internal management plan, minimizing the number of personnel who handle personal information and providing them with regular training, and granting and managing access rights to personal information within the scope necessary for their duties.
Technical measures: access control over the personal information processing system and restriction of access rights, encryption of personal information during transmission and storage, retention of access logs and prevention of their forgery or alteration, and response to malicious code through security programs such as antivirus software.
Physical measures: access control over the facilities and materials in which personal information is stored and processed.
The specific details of the security measures are operated in accordance with the relevant statutes and the Company's internal management plan, and the Company continuously reviews and supplements them in order to improve the level of personal information protection.
Article 15 (Processing of Personal Information of Children Under 14)
The Service is provided to adults, and the Company does not knowingly collect the personal information of children under 14 years of age.
If the Company becomes aware that the personal information of a child under 14 has been collected without the consent of a legal representative, it destroys such personal information without delay.
Article 16 (Personal Information Protection Officer and the Department Receiving and Handling Access Requests)
The Company takes overall responsibility for the work relating to the processing of personal information and, in order to handle data subjects' complaints relating to personal information processing and to provide remedies for damage, designates a personal information protection officer as follows.
Personal Information Protection Officer — Name: 송준 (Representative Director) / Email: sales@portzone.co.kr / Telephone: 010-8721-5088.
Department receiving and handling requests for access, etc., to personal information — The Company receives and handles data subjects' requests for access to, correction, deletion, or suspension of processing of, and withdrawal of consent to, personal information through the department to which the personal information protection officer belongs. The contact for receipt and handling is the same as that of the personal information protection officer above (email: sales@portzone.co.kr / telephone: 010-8721-5088).
Data subjects may direct any inquiries, complaints, or requests for remedy relating to personal information protection arising in the course of using the Service to the contact above, and the Company will respond to and handle them without delay.
Article 17 (Remedies for Infringement of Data Subjects' Rights)
To obtain relief for infringement of personal information, data subjects may apply for dispute resolution or consultation to the organizations listed below. These organizations are separate from the Company; please contact them if you are not satisfied with the results of the Company's own handling of personal information complaints and remedies, or if you require more detailed assistance.
Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr).
Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr).
Supreme Prosecutors' Office Cybercrime Investigation Division: 1301 (www.spo.go.kr).
National Police Agency Cyber Investigation Bureau: 182 (ecrm.police.go.kr).
In addition, where a person's rights or interests have been infringed by the Company's disposition of, or failure to act on, a request for access to, correction, deletion, or suspension of processing of personal information, that person may file an administrative appeal in accordance with the Administrative Appeals Act.
Article 18 (Amendment of the Privacy Policy and Effective Date)
This Privacy Policy takes effect on July 7, 2026.
The Company may amend the content of this Policy in line with changes in statutes, policies, or the Service, and when doing so will announce the changes and the effective date through the Service website before they take effect. However, where there is a material change to the rights of data subjects, the Company will provide notice at least 7 days before the effective date.
The Company maintains a revision history and makes previous versions of the Privacy Policy available for viewing through the website so that users can compare the content before and after the changes.
This Policy is permanently posted on the website under the title 'Privacy Policy' so that data subjects can easily access it.