Privacy Policy

View Previous Versions

Flitto Inc. (hereinafter the "Company") processes personal information lawfully and manages it safely in compliance with the requirements of the Personal Information Protection Act (「개인정보 보호법」) and relevant laws and regulations in order to protect the freedom and rights of data subjects. Accordingly, in accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following privacy policy in order to inform data subjects of the procedures and standards concerning the processing and protection of personal information and to handle related grievances promptly and smoothly.

 

This Policy applies to the Vogl and Vogl Stage services operated by the Company under the Vogl brand (hereinafter collectively the "Service").

The Company does not process the personal information of children under the age of 14.

※ Unless otherwise provided, the definitions of terms used in this Policy shall be as set out in the 'Vogl Terms of Service'.

Article 1 (Items of Personal Information Processed, Purposes and Retention Periods)

① The Company collects the following minimum personal information for purposes such as the provision of various services.

  1. Personal information is collected through information directly entered or linked by the user in the course of membership registration and use of the Service, information directly entered by the data subject in the course of submitting an inquiry, and information automatically generated and collected in the course of using the Service.

  2. If a user does not consent to the collection and use of personal information, membership registration and the smooth use of the Service may be difficult.

1. Vogl Service

 

Items Processed

Details

Purpose of Processing

Processing and Retention Period

Legal Basis

Member information

  • Email registration: email address, password, nickname

  • Social login (Google): Access Token, name, profile picture, email address, ID, native language

  • Social login (Apple)

  • Required: Access Token, name, ID, native language

  • Optional email address

  • Social login (LinkedIn): Access Token, name, picture, email address

Membership registration and provision of the Service

Until 10 days after withdrawal (recoverable by logging in again), and completely deleted thereafter

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)

Subscription and payment/refund history

  • Subscription information: subscription start date, cancellation date, renewal date, refund date, receipt PDF

  • Payment information: transaction ID, payment status, date and time of payment, tax information, final payment amount, email address, billing country, purchased product information, receipt URL, invoice information

  • For card payments: card brand, last 4 digits of the card number, expiration date

  • For Paypal payments: Paypal account

Processing of recurring payments and refunds

Until 5 years after withdrawal (compliance with laws and regulations)

Article 6 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce (「전자상거래법 시행령」)

Conversation records

Voice, transcribed text, translation drafts and meeting minutes summaries generated in Quick Chat and Online Meeting

Provision of the Service and improvement of service quality; use, reproduction, modification and distribution of Translation Output generated by users for research purposes relating to the operation, improvement and promotion of the Company's services and the development of new services

Retained permanently after anonymization

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Custom Assistant input and stored items

  • Required: name, field of use, Dataset title

  • Optional: English name, keywords, links to custom materials (including keywords generated from URLs such as LinkedIn profiles/YouTube/websites), uploaded files

Creation of Datasets and application to translation

Destroyed immediately after withdrawal (LinkedIn: destroyed after 3 months)

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Inquiry records

Records of inquiries and CS handling, and personal information provided by the inquirer (contact details, email information, etc.)

  1. Flitto Customer Support Center inquiries

  1. Required: email address, name of the person in charge, company name, inquiry type, content of inquiry

  2. Optional: telephone number, attachments

  1. Vogl Customer Support Center inquiries

  1. Service usage inquiries (Online Meeting / Quick Chat / Custom Assistant / plan management / inquiries on the use of Webex)

  1. [Required] email address, detailed inquiry type, content of inquiry

  2. [Optional] telephone number, platform in use, attachments

  1. Business inquiries

  1. [Required] service of inquiry (Vogl / Vogl Stage / Vogl Zone / other), email address, name (person in charge), how you heard about us, content of inquiry

  2. [Optional] company name, telephone number,
    attachments

  3. Additional items by service of inquiry

  1. Vogl Stage: [Required] inquiry type (conference use / corporate and institutional use / public and educational institution use / partnership)

  2. Vogl Zone: [Required] inquiry type (adoption / partnership / use / other)

  3. Vogl, other: no additional items

  1. Error reports

  1. [Required] email address, whether the email is registered with Vogl, content of inquiry

  2. [Optional] device used to access Vogl, telephone number, attachments

Handling of user inquiries

Until 3 years after withdrawal

Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Non-member guest voice and language information

Voice and language information

Provision of the Service to non-members

Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)


2. Vogl Stage Service


Items Processed

Details

Purpose of Processing

Processing and Retention Period

Legal Basis

Service inquiries

  • Required: email address, name of the person in charge, company name, how you heard about us, inquiry type, telephone number, content of inquiry

  • Optional: attachments

Receipt of and response to customer inquiries, service guidance

3 years after completion of processing the inquiry

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Member account information

Account information created and issued by the Company in accordance with the Individual Agreement (email address, password)

Identification of members and provision of the Service

Until termination of the service agreement and completion of the withdrawal process

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)

Conversation records

Voice, transcribed text and translation results generated in an online space (Room)

Provision of real-time interpretation and translation services and improvement of service quality

Anonymized immediately upon collection and stored in a non-decryptable manner

Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (consent of the data subject)

Non-member guest voice and language information

Voice and language information (no personally identifiable information is collected)

Provision of the Service to non-members

Encrypted and then used for the transcription and translation of the conversation, and destroyed immediately upon the end of the conversation

Article 15, Paragraph 1, Subparagraph 4 of the Personal Information Protection Act (performance of a contract)


3. Personal Information Collected Automatically

In the course of using the Service, the following information is automatically generated and collected through cookies and the like. For details, please refer to Articles 7 and 8.


Items

Purpose of Collection

Retention Period

Service usage records, access logs, device information, cookies, behavioral information

Analysis and improvement of usage statistics for the enhancement of service quality, error analysis, provision of customized services

In accordance with the retention period for each solution under Articles 7 and 8


② However, in the cases falling under the following grounds, the Company processes and retains personal information until the relevant ground or period ends.

  1. Operation of member services

  1. Where an investigation or inquiry due to a violation of relevant laws and regulations is under way, until the conclusion of that investigation or inquiry

  2. Where claims and obligations arising from use of the Service remain outstanding, until the settlement of those claims and obligations

  1. Provision of the Service and processing of payments (retention under relevant laws and regulations)

 

Item

Retention Period

Basis for Retention

Records concerning contracts or withdrawal of subscription, etc.

5 years

Article 6, Paragraph 1, Subparagraph 2 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning payment of consideration and the supply of goods, etc.

5 years

Article 6, Paragraph 1, Subparagraph 3 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning consumer complaints or dispute resolution

3 years

Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce

Records concerning labeling and advertising

6 months

Article 6, Paragraph 1, Subparagraph 1 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce


Article 2 (Destruction of Personal Information)

① When personal information becomes unnecessary, such as upon the lapse of the retention period or the achievement of the purpose of processing, the Company destroys such personal information without delay upon obtaining the approval of the Chief Privacy Officer.

② Where personal information must continue to be retained under other laws and regulations even though the retention period consented to by the data subject has elapsed or the purpose of processing has been achieved, such personal information shall be transferred to a separate database (DB) or retained in a different storage location.

③ The procedures and methods for the destruction of personal information are as follows.

  1. Upon the lapse of 10 days after withdrawal, personally identifiable information (email, nickname, identifying information in voice data, etc.) is completely deleted from the database and backups.

  2. Payment/subscription information is deleted after the statutory retention period has elapsed.

  3. The voice and language information of non-member guests is deleted immediately upon the end of the conversation.

  4. Information in the form of electronic files is deleted using technical methods that make the records irreproducible, and personal information printed on paper is destroyed by shredding with a shredder or by incineration.

Article 3 (Provision of Personal Information to Third Parties)

① The Company processes the personal information of data subjects within the scope of the purposes of processing specified in Article 1, and does not provide it to third parties beyond the original scope of purposes without the consent of the data subject.

② However, in the following cases, the Company may provide personal information to third parties without the consent of the data subject.

  1. Where there are special provisions in statutes or where it is unavoidable in order to comply with legal obligations

  2. Where an investigative agency makes a request for investigative purposes in accordance with the procedures and methods prescribed by statutes

  • Legal basis: Article 18, Paragraph 2, Subparagraph 2 of the Personal Information Protection Act and Article 215 of the Criminal Procedure Act (「형사소송법」)

  • Recipients: the competent police agency and prosecutors' office

  • Items provided: information within the scope requested

Article 4 (Entrustment of Personal Information Processing and Overseas Transfer)

① Pursuant to Article 26 (Restrictions on Processing of Personal Information Following Business Entrustment) and Article 28-8 (Overseas Transfer of Personal Information) of the Personal Information Protection Act, the Company entrusts the processing of personal information to domestic and overseas companies (including overseas transfer) as follows, in order to perform the data subject's service agreement and to enhance convenience.

1. Domestic Entrustment of Processing


Entrusted Company

Content of the Entrusted Work

Related Service

Stibee Inc.

Sending emails for marketing purposes, managing mailing lists

Vogl Stage


2. Overseas Entrustment of Processing and Transfer


Entrusted Company

Content of the Entrusted Work

Items Entrusted/Transferred

Country of Transfer / Timing and Method

Retention and Use Period

Security Measures

Related Service

Paddle, Inc.

(3811 Ditmars Blvd, #1071 Astoria, New York, 11105-1803, USA)

Payment processing

Payment information (credit card information, payment amount, recurring payment/refund history)

United States, EU / remote transmission over an encrypted communications network (SSL) each time the user uses the payment function

Until 5 years after withdrawal

GDPR compliance, data encryption

Vogl

RevenueCat, Inc

(1032 E Brandon Blvd #3003 Brandon, Florida, 33511, USA)

Payment processing

Subscription information (subscription start date, cancellation date, renewal date, refund date, receipt PDF)

United States, EU / remote transmission over an encrypted communications network (SSL) when the user registers, renews or cancels a subscription or when payment history is generated

Until 5 years after withdrawal

GDPR compliance, data encryption

Vogl

Amazon Web Services, Inc.

(410 Terry Avenue North, Seattle, WA 98109-5210, USA)

Operation of IT infrastructure for the provision of the Service, cloud server management and data storage

Service usage records, membership registration information (email, etc.), log data and device information

United States (however, the actual data storage is located in the AWS Seoul Region) / remote transmission over an encrypted communications network (HTTPS/TLS) at the time of use of the Service

Until withdrawal of membership or termination of the entrustment agreement

Compliance with ISO 27001/27017/27018 and SOC 1/2/3 certifications, data encryption

Vogl

Zendesk, Inc.

(989 Market St, San Francisco, CA 94103, USA / privacy@zendesk.com)

Customer support response, CS history management and provision of technical support services

Records of support inquiries (content of inquiry, attachments, etc.), email address, service usage records

United States and others / remote transmission over an encrypted communications network (SSL/TLS) at the time of a support inquiry

Until withdrawal of membership or termination of the entrustment agreement

Compliance with SOC 2 Type II and ISO 27001 certifications, data access control and encryption

Vogl, Vogl Stage


② When entering into an entrustment agreement, the Company specifies in documents such as the agreement matters concerning the prohibition of processing personal information for purposes other than performing the entrusted work, technical and administrative protective measures, restrictions on sub-entrustment, management and supervision of the entrustee, and liability including damages, and supervises whether the entrustee processes personal information safely.

③ Data subjects may refuse the overseas transfer of their personal information. However, if you refuse the transfer, your use of the Service may be restricted. If you do not wish the transfer to take place, please contact the Customer Support Center (support@vogl.ai).

④ Where the content of the entrusted work or the entrustee changes, the Company shall disclose this without delay through this Privacy Policy.

Article 5 (Safeguards for Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative and physical measures to ensure the safety of personal information.

  1. Encryption of personal information : the personal information of data subjects (including voice data and translation drafts) is transmitted via the TLS (HTTPS) protocol, and passwords and payment information are encrypted and stored. The voice and language information of non-member guests is encrypted and then destroyed immediately upon the end of the conversation.

  2. Access restriction : access to personal information is controlled through the granting, modification and revocation of access rights to the database system that processes personal information, and unauthorized access from outside is controlled using an intrusion blocking system. Access rights to personal information are granted on a limited basis only to the personnel in charge (backend developers, the Operations/CS team, the Chief Privacy Officer, etc.) in accordance with the principle of least privilege.

  3. Regular security inspections : security programs are installed and inspected periodically in order to prevent the leakage and damage of personal information by hacking, computer viruses and the like, and anomalies in payment/subscription/conversation events are detected through regular security inspections conducted at least once a year.

Article 6 (Rights and Obligations of Data Subjects and Their Legal Representatives and How to Exercise Them)

① Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time (hereinafter the "exercise of rights").

  1. Request for access to personal information

  2. Request for correction where there is an error or the like

  3. Request for deletion

  4. Request for suspension of processing

  5. Request for withdrawal of consent

② The exercise of rights may be carried out, in accordance with the Enforcement Decree of the Personal Information Protection Act (「개인정보 보호법 시행령」), through the Customer Support Center (support@vogl.ai) by means such as in writing or by email, and the Company shall process the request within 10 days of its receipt. Where there is a legitimate ground on which the request may be refused under the laws and regulations relating to the protection of personal information, the Company shall inform the data subject of that ground.

③ The exercise of rights may also be carried out through an agent, such as the data subject's legal representative or a person duly authorized by the data subject. In such case, a power of attorney in the form of Annexed Form No. 11 under the Notice on Methods of Processing Personal Information (「개인정보 처리 방법에 관한 고시」) must be submitted.

④ Where a data subject requests the correction or deletion of errors in personal information, the Company shall not use or provide such personal information until the correction or deletion is completed.

⑤ A data subject's right to request access to and suspension of the processing of personal information may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.

⑥ Where other statutes specify that the personal information is subject to collection, the deletion of such personal information may not be requested.

⑦ The Company verifies whether the person exercising the rights is the data subject himself or herself or a duly authorized agent.

Article 7 (Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof)

① In order to provide users with individually customized services and to analyse and improve usage statistics for the enhancement of service quality, the Company uses 'cookies', which store usage information and retrieve it from time to time.

② The cookies in use in the Service are as follows.

 

Cookie Name

Provider

Purpose

Description

\_clck

Microsoft Clarity

Analytics/statistics

Recognizes returning visitors and retains settings.

\_clsk

Microsoft Clarity

Analytics/statistics

Aggregates the activity of a single session into one record.

CLID

Microsoft Clarity

Analytics/statistics

Identifies whether Clarity is being used for the first time across sites.

MUID

Microsoft

Analytics/statistics

Assigns a unique browser ID, which is shared across Microsoft sites. Used for performance measurement, analytics and advertising tracking.


③ When a data subject accesses the service website, a cookie notice banner is displayed, and clicking the "Confirm" button is deemed to constitute consent to the collection of cookies.

④ Data subjects have the option as to the installation of cookies and may allow or refuse cookies, or delete collected cookies, through the settings of their web browser or mobile device. The methods of blocking and deleting cookies for each platform you use are as follows, and the methods may differ depending on the platform version. Other web browsers not listed here (e.g. Firefox, Opera) also provide cookie setting functions.

 

Platform

Method of Blocking/Deletion (Path)

Chrome

[Delete] Web browser settings > Privacy and security > Delete browsing data

Edge

[Delete] Web browser settings > Cookies and site permissions > Manage and delete cookies and site data

Safari

[Block] Preferences > 'Prevent cross-site tracking' and 'Block all cookies'

Firefox

[Settings] Settings > Privacy & Security > Cookies and Site Data

Android

[Block] Settings > Security and privacy > More privacy settings > turn off 'Android personalization service'

[Delete] Settings > Security and privacy > More privacy settings > Ads > Delete advertising ID

iOS

[Block] Settings > Privacy > Apple Advertising > turn off the 'Personalized Ads' switch


⑤ When using a web browser (PC/mobile), you may use the Service in an environment that does not permit the collection of cookies by accessing it via the following paths.

 

Platform

Method of Use (Path)

Chrome

Select the '⋮' icon at the top right of the web browser > New Incognito window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N)

Edge

Select the '⋮' icon at the top right of the web browser > New InPrivate window (Windows: Ctrl+Shift+N / Mac: Command+Shift+N)

Chrome (mobile web)

Select the '⋮' icon at the top right of the mobile browser > New Incognito tab

Safari (mobile web)

Mobile device Settings > Safari > Advanced > 'Block All Cookies'

Samsung Internet (mobile web)

Select the 'Tabs' icon at the bottom of the mobile browser > turn on Secret mode > Start


⑥ If the storage of cookies is refused, difficulty may arise in using some services.

Article 8 (Collection and Use of Behavioral Information and Refusal Thereof)

① In the course of the use of the Service, the Company directly collects and uses users' 'behavioral information' in order to provide users with optimized customized services and benefits, online customized advertising and the like.

 

Advertising business operator collecting and processing behavioral information

Google (Analytics, Firebase)

Items of behavioral information collected

Advertising identifiers: 'device identifiers' randomly assigned to mobile phones (meaning Device ID, AAID (Advertising ID) on Android OS, and IDFA (Identifier For Advertisers) on iOS), and users' app visit and usage history

Method of collection

Automatically collected and transmitted when the user runs and uses the app

Purpose of collection

Provision of customized advertising based on users' interests, analysis of error information arising during use of the Service

Matters concerning the retention, use and destruction of behavioral information

Collected behavioral information is retained and used for up to 2 months from the date of collection in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the privacy policy of the advertising business operator (Google) (https://policies.google.com/privacy) and its data retention guidance (https://support.google.com/analytics/answer/7667196?hl=ko).


Advertising business operator collecting and processing behavioral information

Microsoft (https://clarity.microsoft.com/)

Items of behavioral information collected

How users interact with the website

Method of collection

Automatically collected in real time using cookies when the user accesses and uses the website

Purpose of collection

Improvement of usability and provision of user-customized services

Matters concerning the retention, use and destruction of behavioral information

Collected behavioral information is retained and used for the periods set out below for each type of information in accordance with the settings of the service analytics solution, and is automatically destroyed by the system once that period has elapsed. For details, please refer to the data retention policy of the advertising business operator (Microsoft) (https://learn.microsoft.com/en-us/clarity/setup-and-installation/data-retention) and the Clarity Terms of Use (https://clarity.microsoft.com/terms ).

  • Click Data: 13 months

  • Playback Data: 30 days

  • Labeled or favorited sessions: 13 months


② The above behavioral information is information automatically generated and collected on the basis of cookies, and users may refuse the collection of cookies or delete collected cookies in accordance with the methods set out in Article 7, Paragraphs 4 and 5.

Article 9 (Compliance with Laws)

The Company processes personal information in compliance with relevant laws and regulations, including the Personal Information Protection Act of the Republic of Korea.

Article 10 (External Links)

This Privacy Policy applies only to the services of the Company. Where a user accesses an external website via a link while using the Service, the Company shall not be responsible for the protection of personal information on that website, even if the Company provided that link. Please check the privacy policy of the external website before using it.

Article 11 (Chief Privacy Officer and Department in Charge)

① The Company designates a Chief Privacy Officer and a department in charge as set out below, in order to take overall responsibility for work relating to the processing of personal information and to ensure data subjects' right to informational self-determination, handle complaints and provide remedies for damage.

Chief Privacy Officer

 

Category

Details

Name

Jungsoo Lee

Position

CEO

Email

help@flitto.com


Privacy Department


Category

Details

Department

Operations Team

Person in charge

Jingu Kim

Email

privacy@flitto.com


② Data subjects may direct to the Chief Privacy Officer and the department in charge any matters relating to the protection of personal information, the handling of complaints, remedies for damage and the like that arise while using the Company's services. The Company responds to and handles data subjects' inquiries sequentially within 10 days.

Article 12 (Remedies for Infringement of Data Subjects' Rights)

In order to obtain remedies for infringement of personal information, data subjects may apply to the Personal Information Dispute Mediation Committee, the Privacy Infringement Report Center of the Korea Internet & Security Agency and the like for dispute resolution, consultation or the like. For other reports of and consultations on infringement of personal information, please contact the agencies below.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)

  2. Privacy Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)

  3. Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) (http://www.spo.go.kr )

  4. Cyber Investigation Bureau, Korean National Police Agency: 182 (no area code) (http://ecrm.police.go.kr )

Article 13 (Amendment of the Privacy Policy)

① The content of this Policy shall be posted on the service screen or announced by other means, and shall take effect with respect to all users who have agreed to this Policy.

② The Company may amend this Policy in compliance with relevant laws and regulations. In the event of an amendment, the Company shall give notice to users by an announcement within the Service or by email at least 7 days before the effective date, and shall give notice 30 days in advance of any amendment that is unfavourable to users.

③ Where a user does not express refusal by the effective date after the Company has announced the changes under this Article, the user shall be deemed to have agreed to the changes. Refusal may be expressed through the Customer Support Center (support@vogl.ai).

④ In the case of an unfavourable amendment, users may expressly choose whether to consent, and if consent is refused, use of the Service may be restricted.

⑤ The amended Policy shall be announced in accordance with Paragraph 1 and shall take effect from the effective date.

Amendment History of the Privacy Policy


Version

Effective Date

Key Changes

v1.0

September 28, 2026

Consolidated enactment of the Chat Translation and Live Translation Privacy Policies


Date of Notice and Effective Date

  • Date of Notice : September 21, 2026

  • Effective Date : September 28, 2026

Upon the entry into force of this Policy, the previous 'Flitto Chat Translation Privacy Policy' and 'Flitto Live Translation Privacy Policy' are consolidated into and replaced by this Policy.y this Policy.

CEO

Simon Lee

CPO

Simon Lee

Business Registration Number

215-87-72878

E-Commerce Registration Number

2014-SeoulGangnam-02858

Address

(06173) 6F, 20 Yeongdong-daero 96-gil, Gangnam-gu, Seoul, Republic of Korea

© 2026 Flitto Inc. All rights reserved.

Family site

CEO

Simon Lee

CPO

Simon Lee

Business Registration Number

215-87-72878

E-Commerce Registration Number

2014-SeoulGangnam-02858

Address

(06173) 6F, 20 Yeongdong-daero 96-gil, Gangnam-gu, Seoul, Republic of Korea

© 2026 Flitto Inc. All rights reserved.

Family site

© 2026 Flitto Inc. All rights reserved.

Flitto Business Information

Family site