Privacy Policy
View Previous Versions
Flitto Inc. (hereinafter the "Company") processes personal information lawfully and manages it safely in compliance with the requirements of the Personal Information Protection Act (「개인정보 보호법」) and relevant laws and regulations in order to protect the freedom and rights of data subjects. Accordingly, in accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following privacy policy in order to inform data subjects of the procedures and standards concerning the processing and protection of personal information and to handle related grievances promptly and smoothly.
This Policy applies to the Vogl and Vogl Stage services operated by the Company under the Vogl brand (hereinafter collectively the "Service").
The Company does not process the personal information of children under the age of 14.
※ Unless otherwise provided, the definitions of terms used in this Policy shall be as set out in the 'Vogl Terms of Service'.
Article 1 (Items of Personal Information Processed, Purposes and Retention Periods)
① The Company collects the following minimum personal information for purposes such as the provision of various services.
Personal information is collected through information directly entered or linked by the user in the course of membership registration and use of the Service, information directly entered by the data subject in the course of submitting an inquiry, and information automatically generated and collected in the course of using the Service.
If a user does not consent to the collection and use of personal information, membership registration and the smooth use of the Service may be difficult.
1. Vogl Service
Items Processed | Details | Purpose of Processing | Processing and Retention Period | Legal Basis |
|---|---|---|---|---|
Member information |
| Membership registration and provision of the Service | Until 10 days after withdrawal (recoverable by logging in again), and completely deleted thereafter | Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract) |
Subscription and payment/refund history |
| Processing of recurring payments and refunds | Until 5 years after withdrawal (compliance with laws and regulations) | Article 6 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce (「전자상거래법 시행령」) |
Conversation records | Voice, transcribed text, translation drafts and meeting minutes summaries generated in Quick Chat and Online Meeting | Provision of the Service and improvement of service quality; use, reproduction, modification and distribution of Translation Output generated by users for research purposes relating to the operation, improvement and promotion of the Company's services and the development of new services | Retained permanently after anonymization | Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject) |
Custom Assistant input and stored items |
| Creation of Datasets and application to translation | Destroyed immediately after withdrawal (LinkedIn: destroyed after 3 months) | Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject) |
Inquiry records | Records of inquiries and CS handling, and personal information provided by the inquirer (contact details, email information, etc.)
| Handling of user inquiries | Until 3 years after withdrawal | Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce |
Non-member guest voice and language information | Voice and language information | Provision of the Service to non-members | Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation | Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract) |
2. Vogl Stage Service
Items Processed | Details | Purpose of Processing | Processing and Retention Period | Legal Basis |
|---|---|---|---|---|
Service inquiries |
| Receipt of and response to customer inquiries, service guidance | 3 years after completion of processing the inquiry | Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject) |
Member account information | Account information created and issued by the Company in accordance with the Individual Agreement (email address, password) | Identification of members and provision of the Service | Until termination of the service agreement and completion of the withdrawal process | Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract) |
Conversation records | Voice, transcribed text and translation results generated in an online space (Room) | Provision of real-time interpretation and translation services and improvement of service quality | Anonymized immediately upon collection and stored in a non-decryptable manner | Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject) |
Non-member guest voice and language information | Voice and language information (no personally identifiable information is collected) | Provision of the Service to non-members | Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation | Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract) |
3. Personal Information Collected Automatically
In the course of using the Service, the following information is automatically generated and collected through cookies and the like. For details, please refer to Articles 7 and 8.
Items | Purpose of Collection | Retention Period |
|---|---|---|
Service usage records, access logs, device information, cookies, behavioral information | Analysis and improvement of usage statistics for the enhancement of service quality, error analysis, provision of customized services | In accordance with the retention period for each solution under Articles 7 and 8 |
② However, in the cases falling under the following grounds, the Company processes and retains personal information until the relevant ground or period ends.
Operation of member services
Where an investigation or inquiry due to a violation of relevant laws and regulations is under way, until the conclusion of that investigation or inquiry
Where claims and obligations arising from use of the Service remain outstanding, until the settlement of those claims and obligations
Provision of the Service and processing of payments (retention under relevant laws and regulations)
Item | Retention Period | Basis for Retention |
|---|---|---|
Records concerning contracts or withdrawal of subscription, etc. | 5 years | Article 6, Paragraph 1, Subparagraph 2 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce |
Records concerning payment of consideration and the supply of goods, etc. | 5 years | Article 6, Paragraph 1, Subparagraph 3 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce |
Records concerning consumer complaints or dispute resolution | 3 years | Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce |
Records concerning labeling and advertising | 6 months | Article 6, Paragraph 1, Subparagraph 1 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce |
Article 2 (Destruction of Personal Information)
① When personal information becomes unnecessary, such as upon the lapse of the retention period or the achievement of the purpose of processing, the Company destroys such personal information without delay upon obtaining the approval of the Chief Privacy Officer.
② Where personal information must continue to be retained under other laws and regulations even though the retention period consented to by the data subject has elapsed or the purpose of processing has been achieved, such personal information shall be transferred to a separate database (DB) or retained in a different storage location.
③ The procedures and methods for the destruction of personal information are as follows.
Upon the lapse of 10 days after withdrawal, personally identifiable information (email, nickname, identifying information in voice data, etc.) is completely deleted from the database and backups.
Payment/subscription information is deleted after the statutory retention period has elapsed.
The voice and language information of non-member guests is deleted immediately upon the end of the conversation.
Information in the form of electronic files is deleted using technical methods that make the records irreproducible, and personal information printed on paper is destroyed by shredding with a shredder or by incineration.
Article 3 (Provision of Personal Information to Third Parties)
① The Company processes the personal information of data subjects within the scope of the purposes of processing specified in Article 1, and does not provide it to third parties beyond the original scope of purposes without the consent of the data subject.
② However, in the following cases, the Company may provide personal information to third parties without the consent of the data subject.
Where there are special provisions in statutes or where it is unavoidable in order to comply with legal obligations
Where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by statutes
Legal basis: Article 18, Paragraph 2, Subparagraph 2 of the Personal Information Protection Act and Article 215 of the Criminal Procedure Act (「형사소송법」)
Recipients: the competent police agency and prosecutors' office
Items provided: information within the scope requested
Article 4 (Entrustment of Personal Information Processing and Overseas Transfer)
① Pursuant to Article 26 (Restrictions on Processing of Personal Information Following Business Entrustment) and Article 28-8 (Overseas Transfer of Personal Information) of the Personal Information Protection Act, the Company entrusts the processing of personal information to domestic and overseas companies (including overseas transfer) as follows, in order to perform the data subject's service agreement and to enhance convenience.
1. Domestic Entrustment of Processing
Entrusted Company | Content of the Entrusted Work | Related Service |
|---|---|---|
Stibee Inc. | Sending emails for marketing purposes, managing mailing lists | Vogl Stage |
2. Overseas Entrustment of Processing and Transfer
Entrusted Company | Content of the Entrusted Work | Items Entrusted/Transferred | Country of Transfer / Timing and Method | Retention and Use Period | Security Measures | Related Service |
|---|---|---|---|---|---|---|
Paddle, Inc. (3811 Ditmars Blvd, #1071 Astoria, New York, 11105-1803, USA) | Payment processing | Payment information (credit card information, payment amount, recurring payment/refund history) | United States, EU / remote transmission over an encrypted communications network (SSL) each time the user uses the payment function | Until 5 years after withdrawal | GDPR compliance, data encryption | Vogl |
RevenueCat, Inc (1032 E Brandon Blvd #3003 Brandon, Florida, 33511, USA) | Payment processing | Subscription information (subscription start date, cancellation date, renewal date, refund date, receipt PDF) | United States, EU / remote transmission over an encrypted communications network (SSL) when the user registers, renews or cancels a subscription or when payment history is generated | Until 5 years after withdrawal | GDPR compliance, data encryption | Vogl |
Amazon Web Services, Inc. (410 Terry Avenue North, Seattle, WA 98109-5210, USA) | Operation of IT infrastructure for the provision of the Service, cloud server management and data storage | Service usage records, membership registration information (email, etc.), log data and device information | United States (however, the actual data storage is located in the AWS Seoul Region) / remote transmission over an encrypted communications network (HTTPS/TLS) at the time of use of the Service | Until withdrawal of membership or termination of the entrustment agreement | Compliance with ISO 27001/27017/27018 and SOC 1/2/3 certifications, data encryption | Vogl |
Zendesk, Inc. (989 Market St, San Francisco, CA 94103, USA / privacy@zendesk.com) | Customer support response, CS history management and provision of technical support services | Records of support inquiries (content of inquiry, attachments, etc.), email address, service usage records | United States and others / remote transmission over an encrypted communications network (SSL/TLS) at the time of a support inquiry | Until withdrawal of membership or termination of the entrustment agreement | Compliance with SOC 2 Type II and ISO 27001 certifications, data access control and encryption | Vogl, Vogl Stage |
② When entering into an entrustment agreement, the Company specifies in documents such as the agreement matters concerning the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on sub-entrustment, management and supervision of the entrustee, and liability including damages, and supervises whether the entrustee processes personal information safely.
③ Data subjects may refuse the overseas transfer of their personal information. However, if you refuse the transfer, your use of the Service may be restricted. If you do not wish the transfer to take place, please contact the Customer Support Center (support@vogl.ai).
④ Where the content of the entrusted work or the entrustee changes, the Company shall disclose this without delay through this Privacy Policy.
Article 5 (Safeguards for Personal Information)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative and physical measures to ensure the safety of personal information.
Encryption of personal information : the personal information of data subjects (including voice data and translation drafts) is transmitted via the TLS (HTTPS) protocol, and passwords and payment information are encrypted and stored. The voice and language information of non-member guests is encrypted and then destroyed immediately upon the end of the conversation.
Access restriction : access to personal information is controlled through the granting, modification and revocation of access rights to the database system that processes personal information, and unauthorized access from outside is controlled using an intrusion blocking system. Access rights to personal information are granted on a limited basis only to the personnel in charge (backend developers, the Operations/CS team, the Chief Privacy Officer, etc.) in accordance with the principle of least privilege.
Regular security inspections : security programs are installed and inspected periodically in order to prevent the leakage and damage of personal information by hacking, computer viruses and the like, and anomalies in payment/subscription/conversation events are detected through regular security inspections conducted at least once a year.
Article 6 (Rights and Obligations of Data Subjects and Their Legal Representatives and How to Exercise Them)
① Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time (hereinafter the "exercise of rights").
Request for access to personal information
Request for correction where there is an error or the like
Request for deletion
Request for suspension of processing
Request for withdrawal of consent
② The exercise of rights may be carried out, in accordance with the Enforcement Decree of the Personal Information Protection Act (「개인정보 보호법 시행령」), through the Customer Support Center (support@vogl.ai) by means such as in writing or by email, and the Company shall process the request within 10 days of its receipt. Where there is a legitimate ground on which the request may be refused under the laws and regulations relating to the protection of personal information, the Company shall inform the data subject of that ground.
③ The exercise of rights may also be carried out through an agent, such as the data subject's legal representative or a person duly authorized by the data subject. In such case, a power of attorney in the form of Annexed Form No. 11 under the Notice on Methods of Processing Personal Information (「개인정보 처리 방법에 관한 고시」) must be submitted.
④ Where a data subject requests the correction or deletion of errors in personal information, the Company shall not use or provide such personal information until the correction or deletion is completed.
⑤ A data subject's right to request access to and suspension of the processing of personal information may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
⑥ Where other statutes specify that the personal information is subject to collection, the deletion of such personal information may not be requested.
⑦ The Company verifies whether the person exercising the rights is the data subject himself or herself or a duly authorized agent.
Article 7 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof)
① In order to provide users with individually customized services and to analyse and improve usage statistics for the enhancement of service quality, the Company uses 'cookies', which store usage information and retrieve it from time to time.
② The cookies in use in the Service are as follows.
Cookie Name | Provider | Purpose | Description |
|---|---|---|---|
\_clck | Microsoft Clarity | Analytics/statistics | Recognizes returning visitors and retains settings. |
\_clsk | Microsoft Clarity | Analytics/statistics | Aggregates the activity of a single session into one record. |
CLID | Microsoft Clarity | Analytics/statistics | Identifies whether Clarity is being used for the first time across sites. |
MUID | Microsoft | Analytics/statistics | Assigns a unique browser ID, which is shared across Microsoft sites. Used for performance measurement, analytics and advertising tracking. |
③ When a data subject accesses the service website, a cookie notice banner is displayed, and clicking the "Confirm" button is deemed to constitute consent to the collection of cookies.
④ Data subjects have the option as to the installation of cookies and may allow or refuse cookies, or delete collected cookies, through the settings of their web browser or mobile device. The methods of blocking and deleting cookies for each platform you use are as follows, and the methods may differ depending on the platform version. Other web browsers not listed here (e.g. Firefox, Opera) also provide cookie setting functions.
Platform | Method of Blocking/Deletion (Path) |
|---|---|
Chrome | [Delete] Web browser settings > Privacy and security > Delete browsing data |
Edge | [Delete] Web browser settings > Cookies and site permissions > Manage and delete cookies and site data |
Safari | [Block] Preferences > 'Prevent cross-site tracking' and 'Block all cookies' |
Firefox | [Settings] Settings > Privacy & Security > Cookies and Site Data |
Android | [Block] Settings > Security and privacy > More privacy settings > turn off 'Android personalization service' [Delete] Settings > Security and privacy > More privacy settings > Ads > Delete advertising ID |
iOS | [Block] Settings > Privacy > Apple Advertising > turn off the 'Personalized Ads' switch |
⑤ When using a web browser (PC/mobile), you may use the Service in an environment that does not permit the collection of cookies by accessing it via the following paths.
Platform | Method of Use (Path) |
|---|---|
Chrome | Select the '⋮' icon at the top right of the web browser > New Incognito window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N) |
Edge | Select the '⋮' icon at the top right of the web browser > New InPrivate window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N) |
Chrome (mobile web) | Select the '⋮' icon at the top right of the mobile browser > New Incognito tab |
Safari (mobile web) | Mobile device Settings > Safari > Advanced > 'Block All Cookies' |
Samsung Internet (mobile web) | Select the 'Tabs' icon at the bottom of the mobile browser > turn on Secret mode > Start |
⑥ If the storage of cookies is refused, difficulty may arise in using some services.
Article 8 (Collection and Use of Behavioral Information and Refusal Thereof)
① In the course of the use of the Service, the Company directly collects and uses users' 'behavioral information' in order to provide users with optimized customized services and benefits, online customized advertising and the like.
Advertising business operator collecting and processing behavioral information | Google (Analytics, Firebase) |
Items of behavioral information collected | Advertising identifiers: 'device identifiers' randomly assigned to mobile phones (meaning Device ID, AAID (Advertising ID) on Android OS, and IDFA (Identifier For Advertisers) on iOS), and users' app visit and usage history |
Method of collection | Automatically collected and transmitted when the user runs and uses the app |
Purpose of collection | Provision of customized advertising based on users' interests, analysis of error information arising during use of the Service |
Matters concerning the retention, use and destruction of behavioral information | Collected behavioral information is retained and used for up to 2 months from the date of collection in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the privacy policy of the advertising business operator (Google) (https://policies.google.com/privacy) and its data retention guidance (https://support.google.com/analytics/answer/7667196?hl=ko). |
Advertising business operator collecting and processing behavioral information | Microsoft (https://clarity.microsoft.com/) |
Items of behavioral information collected | How users interact with the website |
Method of collection | Automatically collected in real time using cookies when the user accesses and uses the website |
Purpose of collection | Improvement of usability and provision of user-customized services |
Matters concerning the retention, use and destruction of behavioral information | Collected behavioral information is retained and used for the periods set out below for each type of information in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the data retention policy of the advertising business operator (Microsoft) (https://learn.microsoft.com/en-us/clarity/setup-and-installation/data-retention) and the Clarity Terms of Use (https://clarity.microsoft.com/terms ).
|
② The above behavioral information is information automatically generated and collected on the basis of cookies, and users may refuse the collection of cookies or delete collected cookies in accordance with the methods set out in Article 7, Paragraphs 4 and 5.
Article 9 (Compliance with Laws)
The Company processes personal information in compliance with relevant laws and regulations, including the Personal Information Protection Act of the Republic of Korea.
Article 10 (External Links)
This Privacy Policy applies only to the services of the Company. Where a user accesses an external website via a link while using the Service, the Company shall not be responsible for the protection of personal information on that website, even if the Company provided that link. Please check the privacy policy of the external website before using it.
Article 11 (Chief Privacy Officer and Department in Charge)
① The Company designates a Chief Privacy Officer and a department in charge as set out below, in order to take overall responsibility for work relating to the processing of personal information and to ensure data subjects' right to informational self-determination, handle complaints and provide remedies for damage.
Chief Privacy Officer
Category | Details |
|---|---|
Name | Jungsoo Lee |
Position | CEO |
Privacy Department
Category | Details |
|---|---|
Department | Operations Team |
Person in charge | Jingu Kim |
② Data subjects may direct to the Chief Privacy Officer and the department in charge any matters relating to the protection of personal information, the handling of complaints, remedies for damage and the like that arise while using the Company's services. The Company responds to and handles data subjects' inquiries sequentially within 10 days.
Article 12 (Remedies for Infringement of Data Subjects' Rights)
In order to obtain remedies for infringement of personal information, data subjects may apply to the Personal Information Dispute Mediation Committee, the Privacy Infringement Report Center of the Korea Internet & Security Agency and the like for dispute resolution, consultation or the like. For other reports of and consultations on infringement of personal information, please contact the agencies below.
Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
Privacy Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) (http://www.spo.go.kr )
Cyber Investigation Bureau, Korean National Police Agency: 182 (no area code) (http://ecrm.police.go.kr )
Article 13 (Amendment of the Privacy Policy)
① The content of this Policy shall be posted on the service screen or announced by other means, and shall take effect with respect to all users who have agreed to this Policy.
② The Company may amend this Policy in compliance with relevant laws and regulations. In the event of an amendment, the Company shall give notice to users by an announcement within the Service or by email at least 7 days before the effective date, and shall give notice 30 days in advance of any amendment that is unfavourable to users.
③ Where a user does not express refusal by the effective date after the Company has announced the changes under this Article, the user shall be deemed to have agreed to the changes. Refusal may be expressed through the Customer Support Center (support@vogl.ai).
④ In the case of an unfavourable amendment, users may expressly choose whether to consent, and if consent is refused, use of the Service may be restricted.
⑤ The amended Policy shall be announced in accordance with Paragraph 1 and shall take effect from the effective date.
Amendment History of the Privacy Policy
Version | Effective Date | Key Changes |
|---|---|---|
v1.0 | September 28, 2026 | Consolidated enactment of the Chat Translation and Live Translation Privacy Policies |
Date of Notice and Effective Date
Date of Notice : September 21, 2026
Effective Date : September 28, 2026
Upon the entry into force of this Policy, the previous 'Flitto Chat Translation Privacy Policy' and 'Flitto Live Translation Privacy Policy' are consolidated into and replaced by this Policy.y this Policy.