個人情報保護方針

個人情報保護方針

個人情報保護方針

前のバージョンを見る

Flitto, Inc. (hereinafter referred to as the "Company") establishes and publicly discloses this Privacy Policy as follows, in order to protect the personal information of data subjects pursuant to Article 30 of the Personal Information Protection Act and to handle related grievances promptly and smoothly.

This Policy applies to the Live Translation service (hereinafter referred to as the "Service") operated by the Company. The Company does not process the personal information of children under the age of 14.


Article 1 (Purposes of Processing, Items Collected, and Retention Periods)

The Company processes personal information for the following purposes. Personal information being processed shall not be used for purposes other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

1. Service Inquiries (Zendesk)

Personal information is collected for the purpose of receiving and responding to customer inquiries and providing service guidance.

Inquiry Channel: https://support.flitto.com/hc/ko/requests/new?ticket_form_id=28554198999449


Category

Items Collected

Retention Period

Required

Email address, Name (contact person/title and position), Company name, Phone number

2 years after inquiry resolution


2. Automatically Collected Personal Information

During the use of the Company's Service, the following information is automatically generated and collected through cookies. This information is used for the purpose of usage statistics analysis and service quality improvement. For details, please refer to Article 7.


Cookie Name

Provider

Items Collected

Purpose of Collection

_clck

Microsoft Clarity

Visitor identification information, settings values

Recognizing returning visitors and maintaining settings

_clsk

Microsoft Clarity

Session activity records

Aggregating activities within a single session into one record

CLID

Microsoft Clarity

Browser identification information

Identifying whether Clarity has been used across sites

MUID

Microsoft

Unique browser ID

Performance measurement, analysis, and advertising tracking


3. Collection Methods

  • Direct input: Data subjects enter information directly on the "Contact Us" page of the Service website.

  • Automatic collection: Automatically generated and collected through cookies during the use of the Service.


4. Retention of Personal Information Pursuant to Applicable Laws

The Company retains personal information in accordance with applicable laws as follows:


Item

Retention Period

Legal Basis

Records relating to consumer complaints or dispute resolution

3 years

Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6 of its Enforcement Decree


Article 2 (Procedures and Methods for Destruction of Personal Information)

1. Destruction Procedures

When the retention period for personal information has expired, or the purpose of processing has been achieved, rendering the personal information unnecessary, the Company shall obtain approval from the Personal Information Protection Officer and destroy the relevant personal information without delay.

However, where retention is required under other applicable laws, the information shall be preserved by transferring it to a separate database (DB) or storing it in a different storage location for the applicable retention period.

2. Destruction Methods

  • Electronic files containing personal information shall be deleted using technical methods that render the records unrecoverable.

  • Personal information printed on paper shall be shredded using a shredder or destroyed by incineration.


Article 3 (Provision of Personal Information to Third Parties)

The Company processes personal information of data subjects within the scope of purposes specified in Article 1 and does not provide personal information to third parties beyond the original scope of purpose without the consent of the data subject.

However, personal information may be provided to third parties without the consent of the data subject in the following cases:

  1. Where there are specific provisions in other laws or where it is unavoidable to comply with statutory obligations;

  2. Where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for the purpose of investigation.


Article 4 (Overseas Transfer and Entrustment of Personal Information)

The Company entrusts the processing of personal information and transfers it overseas as follows, pursuant to Article 26 (Entrustment of Business) and Article 28-8 (Overseas Transfer) of the Personal Information Protection Act, for the fulfillment of the service usage agreement and enhancement of user convenience.


Entrusted Entity

Description of Entrusted Business

Items Entrusted/Transferred

Destination Country / Timing and Method

Retention and Usage Period


Security Measures



Zendesk, Inc. (privacy@zendesk.com)

Customer consultation response, CS history management and technical support services

Consultation inquiry details (inquiry content, attachments, etc.), email address, service usage records

United States / Transmitted remotely via encrypted communication network (HTTPS/TLS) at the time of inquiry

Until membership withdrawal or termination of the entrustment agreement

SOC 2 Type II and ISO 27001 certification compliance, data access control and encryption


When executing an entrustment agreement, the Company specifies in the contractual documents the prohibition of processing personal information beyond the scope of the entrusted business, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the entrusted party, liability for damages, and other relevant matters, and supervises whether the entrusted party processes personal information safely.

Users may refuse the overseas transfer of personal information. However, if the transfer is refused, the use of the Service may be limited. If you do not wish for the transfer, please contact us through the Customer Center.

Any changes in the content of the entrusted business or the entrusted party shall be promptly disclosed through this Privacy Policy.


Article 5 (Measures to Ensure the Security of Personal Information)

The Company takes the following technical, administrative, and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act:

  1. Encryption of personal information: Personal information of data subjects is encrypted for storage and management. Data is transmitted securely using TLS (HTTPS) protocol.

  2. Access control: The Company controls access to database systems that process personal information by granting, modifying, and revoking access rights; controls unauthorized access from external sources using intrusion prevention systems; and grants access rights to personal information only to the relevant personnel in charge based on the principle of least privilege.

  3. Regular security inspections: Security programs are installed and periodically inspected to prevent the leakage and damage of personal information caused by hacking, computer viruses, and other threats.


Article 6 (Rights, Obligations, and Methods of Exercise for Data Subjects and Legal Representatives)

1. Rights of Data Subjects

Data subjects may exercise the following rights relating to personal information protection against the Company at any time:

  1. Right to request access to personal information

  2. Right to request correction in the case of errors, etc.

  3. Right to request deletion

  4. Right to request suspension of processing

  5. Right to withdraw consent

2. Methods of Exercising Rights

The above rights may be exercised by contacting the Company's Customer Center (ctlt@flitto.com) in writing, by email, or by other methods. The Company shall process such requests within 10 days of receipt. However, where there are legitimate grounds under personal information protection-related laws for refusing a request, the Company shall inform the data subject of such grounds.

3. Exercise Through a Representative

The exercise of rights may be carried out through a legal representative of the data subject or an authorized agent. In such cases, a power of attorney in the form prescribed in Appendix No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.

Where a data subject has requested correction or deletion of errors in personal information, the Company shall not use or provide the relevant personal information until the correction or deletion has been completed.


Article 7 (Matters Concerning the Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)

1. Purpose of Using Cookies

The Company uses cookies solely for the purpose of usage statistics analysis and improvement to enhance service quality.


2. Cookies in Use


Cookie Name

Provider

Purpose

Description

_clck

Microsoft Clarity

Analytics/Statistics

Recognizes returning visitors and maintains settings.

_clsk

Microsoft Clarity

Analytics/Statistics

Aggregates activities within a single session into one record.

CLID

Microsoft Clarity

Analytics/Statistics

Identifies whether Clarity has been used across sites.

MUID

Microsoft

Analytics/Statistics

Assigns a unique browser ID, shared across Microsoft sites. Used for performance measurement, analysis, and advertising tracking.


3. Consent to Cookie Collection

When data subjects access the Service website, a cookie usage notification banner is displayed. Clicking the "Confirm" button is deemed as consent to cookie collection.


4. How to Refuse Cookie Settings

Data subjects have the option to accept or refuse the installation of cookies by configuring their web browser settings:

  • Chrome: Settings → Privacy and Security → Cookies and other site data

  • Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data

  • Safari: Preferences → Privacy → Cookies and website data

  • Firefox: Settings → Privacy & Security → Cookies and site data


Article 8 (Personal Information Protection Officer and Responsible Department)

The Company designates the following Personal Information Protection Officer to oversee all matters related to the processing of personal information, to be responsible for and ensure the protection of data subjects' right to self-determination regarding their personal information, and to handle complaints and remediate damages.


Personal Information Protection Officer


Category

Details

Name

Jungsoo Lee

Title

CEO

Email

help@flitto.com


Personal Information Protection Department


Category

Details

Department

Operations Team

Contact Person

Jingu Kim

Email

privacy@flitto.com


Users may direct all personal information protection-related inquiries, complaints, and requests for damage remediation arising from the use of the Company's Service to the Personal Information Protection Officer and the responsible department. The Company shall respond to and process users' inquiries without delay.


Article 9 (Remedies for Infringement of Rights of Data Subjects)

Data subjects may apply for dispute resolution, consultation, or other remedies to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center, or other relevant organizations. For reporting and consulting on other personal information infringement matters, please contact the following organizations:

  1. Personal Information Dispute Mediation Committee: (No area code) 1833-6972 (www.kopico.go.kr)

  2. Personal Information Infringement Report Center: (No area code) 118 (privacy.kisa.or.kr)

  3. Supreme Prosecutors' Office Cyber Investigation Division: (No area code) 1301 (Supreme Prosecutors' Office)

  4. National Police Agency Cyber Bureau: (No area code) 182 (ECRM – Cybercrime Reporting System)

Pursuant to Articles 35 (Access to Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act, a person who has suffered an infringement of rights or interests due to a disposition or omission by a public institution in response to a request by the data subject may file an administrative appeal in accordance with the Administrative Appeals Act.


Article 10 (Changes to the Privacy Policy)

  1. This Privacy Policy shall be posted on the Service screen or made available through other means, and shall take effect for all users who have consented to this Policy.

  2. The Company may amend this Policy in compliance with applicable laws. In the event of an amendment, users shall be notified at least 7 days prior to the effective date through an in-service notice or by email. For changes that are disadvantageous to users, notice shall be given at least 30 days in advance.

  3. After the Company posts the amended matters pursuant to this Article, if a user does not express an intention to refuse by the effective date, the user shall be deemed to have consented to the amended matters. Users may express their intention to refuse through the Customer Center (ctlt@flitto.com).

  4. In the case of changes that are disadvantageous, users may expressly choose whether or not to consent. If consent is refused, the use of the Service may be limited.

  5. The amended terms shall be posted in accordance with Paragraph 1 and shall take effect from the effective date.


Privacy Policy Amendment History

Version

Effective Date

Key Changes

v1.0

October 1, 2025

Initial enactment


Addendum

This Policy shall take effect from [August 6, 2026].

1. 目的

Flitto Inc.(以下「会社」)は、利用者の個人情報を保護し、個人情報保護法(韓国)、一般データ保護規則(GDPR、EU)、カリフォルニア州消費者プライバシー法(CCPA、米国)を含む適用法令を遵守するために、本プライバシーポリシーを制定・実施します。
本ポリシーは、Chat Translationサービス(以下「サービス」)の利用に関連して収集、利用、保存、削除される個人情報の処理手順を規定します。
本ポリシーで使用される用語は、特段の定めがない限り、サービス利用規約で定められた意味に従います。

2. 収集する個人情報の項目および収集方法

収集する情報

登録時:

  • メール登録:メールアドレス、パスワード、ニックネーム

  • ソーシャルログイン:メールアドレス、プロフィール名(OAuthを通じて提供)

サービス利用時:

  • サブスクリプション情報:サブスクリプション開始日、キャンセル日、更新日、返金日、レシート(PDF形式)

  • 支払い情報:クレジットカード情報(PaddleおよびRevenueCatでトークン化されて保存)および支払い関連詳細

  • カスタムアシスタント:利用者が設定した項目(分野、目的、データセット)

  • 会話記録:リモート会話およびオンラインミーティングのテキスト、音声、翻訳ドラフト、議事録要約(会員の場合、翻訳品質向上のために匿名化されて保存)

  • 顧客問い合わせ:メールアドレス、問い合わせ内容、カスタマーサービス記録(サービス改善のため一定期間保存)

非会員ゲスト:

  • ホストの招待リンクを通じて参加する場合、簡略化された同意(「同意する」クリック)により、音声および言語情報のみが収集されます。このデータは暗号化され、翻訳に使用された後、セッション終了時に即時削除されます。

  • 個人を特定できる情報は収集されません。

収集方法

個人情報は、登録およびログイン時に利用者が直接入力または連携した情報を通じて収集されます。

3. 個人情報の利用目的

会社は以下の目的で個人情報を利用します:

  • 利用者識別およびアカウント管理:利用者認証、アカウント統合、終了処理

  • サービス提供:リアルタイム翻訳、リモート会話、オンラインミーティング、カスタムアシスタント機能の提供

  • 支払い処理:サブスクリプション支払い、返金、支払いエラー対応

  • 品質向上:匿名化された会話ログおよび議事録要約による翻訳品質の向上

  • 顧客サポート:問い合わせ対応、サービス改善

4. 個人情報の保存および削除

保存期間

  • 会員情報:アカウント終了後10日間(再ログインによるアカウント復旧を可能にするため)保存後、完全に削除

  • サブスクリプション/支払い/返金記録:終了後5年間(電子商取引法および会計要件の遵守のため)。実際の支払い関連カード情報はPaddleで管理され、会社は別途保存しません。

  • 顧客問い合わせ記録:終了後2年間

  • 会員の会話ログ、音声データ、議事録要約:翻訳品質向上のため、匿名化されて無期限に保存

  • 非会員ゲストの音声および言語情報:暗号化処理後、セッション終了時に即時削除

削除手順

  • アカウント終了後10日経過後、個人を特定できる情報(例:メールアドレス、ニックネーム、音声データの識別情報)はデータベースおよびバックアップから完全に削除されます。

  • 支払い/サブスクリプション情報は、法的に定められた保存期間後に削除されます。

  • 非会員ゲストの音声および言語情報は、セッション終了時に即時削除されます。

  • 電子データは復元不可能な方法で削除され、物理的記録はシュレッダーで破棄されます。

5. 個人情報の第三者提供

会社は利用者の同意なく個人情報を第三者に提供しません。ただし、以下の場合は例外です:

  • トークン化されたカード情報は、支払い処理のためにPaddleおよびRevenueCatに提供されます。

  • 適用法令に基づき、捜査機関等の要求がある場合、関連情報を提供することがあります。

  • 非会員ゲストのデータは個人を特定できる情報を含まないため、第三者提供の対象となりません。

6. 個人情報の国外移転

支払い処理(Paddle)およびサブスクリプション管理(RevenueCat)のため、個人情報が国外に移転されることがあります。

  • 移転先国:米国、EU

  • 受領者:Paddle、RevenueCat

  • 移転項目:支払い情報(カード下4桁、支払金額)、サブスクリプション情報

  • セキュリティ対策:GDPR遵守、データ暗号化
    利用者は国外移転に同意しない権利があり、同意を拒否した場合、支払い機能が制限されることがあります。

7. 個人情報の安全性確保措置

  • 暗号化:個人情報(音声データ、翻訳ドラフトを含む)はTLS(HTTPS)で送信されます。パスワードおよび支払い情報は暗号化されて保存されます。非会員ゲストの音声および言語情報は暗号化処理後、即時削除されます。

  • アクセス制限:データベースへのアクセスは最小権限の原則に基づいて管理されます。オンボーディングデータおよび会話記録は、バックエンド開発者、運用/カスタマーサポートチーム、個人情報保護責任者に限定してアクセス可能です。

  • セキュリティ監視:年1回以上の定期セキュリティ監査を通じて、支払い、サブスクリプション、会話イベントの異常を検知します。

8. 利用者の権利

利用者は、カスタマーサポート(ct.support@flitto.com)を通じて個人情報の閲覧、訂正、削除を依頼できます。
非会員ゲストは個人を特定できる情報が収集されないため、閲覧、訂正、削除依頼の対象となりません。
会社は依頼受付後10日以内に処理し、拒否する場合はその理由を通知します。

9. 法令遵守

会社は、個人情報保護法(韓国)、一般データ保護規則(GDPR、EU)、カリフォルニア州消費者プライバシー法(CCPA、米国)など、適用法令を遵守して個人情報を処理します。

10. プライバシーポリシーの変更

本ポリシーは、サービスプラットフォーム上またはその他の方法で公表され、同意したすべての利用者に効力が発生します。
会社は適用法令を遵守して本ポリシーを改訂することがあります。変更は発効日の少なくとも7日前までにサービス内通知またはメールで公表されます。利用者に不利な重大な変更は、少なくとも30日前までに通知されます。
通知後に利用者が発効日までに拒否の意思を表明しない場合、変更に同意したものとみなされます。拒否の意思は ct.support@flitto.com を通じて表明できます。
重大な変更の場合、利用者は同意または拒否を明示的に選択でき、拒否した場合、サービス利用が制限されることがあります。
改訂されたプライバシーポリシーは第10条第1項に従って公表され、指定された発効日から効力が発生します。

11. 個人情報保護責任者

  • 個人情報保護責任者:李正洙(Jeongsu Lee)

  • 連絡先:ct.support@flitto.com
    個人情報の処理または法的問題に関する問い合わせは、営業日基準で3~5日以内に回答されます。

附則

本プライバシーポリシーは2025年10月1日から発効します。

CEO

イ・ジョンス

CPO

イ・ジョンス

事業者登録番号

215-87-72878

通信販売業申告番号

2014-SeoulGangnam-02858

住所

(06173) ソウル特別市江南区永東大路96ギル20 大和ビル6階 (三成洞 169)

© 2026 Flitto Inc. All rights reserved.

関連サイト

CEO

イ・ジョンス

CPO

イ・ジョンス

事業者登録番号

215-87-72878

通信販売業申告番号

2014-SeoulGangnam-02858

住所

(06173) ソウル特別市江南区永東大路96ギル20 大和ビル6階 (三成洞 169)

© 2026 Flitto Inc. All rights reserved.

関連サイト

© 2026 Flitto Inc. All rights reserved.

Flitto 事業者情報

関連サイト