Article 1 (Purpose)
Flitto Inc. (hereinafter referred to as the “Company”) processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act and related laws and regulations to protect the freedom and rights of data subjects. Accordingly, pursuant to Article 30 of the 「Personal Information Protection Act」, the Company establishes and discloses this Privacy Policy to inform data subjects of the procedures and standards for processing and protecting personal information, and to ensure prompt and smooth resolution of related grievances.
※ Unless otherwise defined, terms used in this policy follow the definitions set forth in the ‘Terms of Service’.
Article 2 (Items of personal information processed, purpose, and retention period)
-
The Company collects the minimum necessary personal information as listed below to provide various services.
a. Use of personal information is deemed to be consented to upon membership registration. Failure to consent may make membership registration and smooth service use difficult.
b. Personal information is collected through information directly entered or linked by the user during the membership registration and service usage process.
| Processing Items | Details | Purpose | Processing and Retention Period | Legal Basis |
|---|---|---|---|---|
Chat history and voice messages |
Voice recordings, transcribed text, translation drafts, and meeting summaries generated within chat rooms | Service provision and service quality improvement | Anonymized and permanently stored | Article 58-2 of the Personal Information Protection Act (Exceptions to Application) |
Inquiry Details |
Inquiry and customer service history, personal information provided by the inquirer (contact information, email address, etc.) |
Handling user inquiries |
Retained for three years after the inquiry has been resolved |
Article 6, Paragraph 1, Subparagraph 4 of the Enforcement Decree of the Electronic Commerce Act |
-
However, personal information will be processed and retained until the relevant reason or period ends in the following cases:
a. Member Service Operation
ⅰ. Until the conclusion of any ongoing investigation or inquiry due to violation of relevant laws and regulations
ⅱ. Until the settlement of any outstanding creditor-debtor relationship arising from website use
b. Service Provision and Payment Processing
ⅰ. Records related to contracts or withdrawal of subscription: 5 years (Article 6, Paragraph 1, Item 2 of the Enforcement Decree of the Consumer Protection Act in Electronic Commerce, etc.)
ⅱ. Records related to consumer complaints or dispute resolution: 3 years (Article 6, Paragraph 1, Item 4 of the Enforcement Decree of the Consumer Protection Act in Electronic Commerce, etc.)
ⅲ. Records related to labeling and advertising: 6 months (Article 6, Paragraph 1, Item 1 of the Enforcement Decree of the Consumer Protection Act in Electronic Commerce, etc.)
Article 3 (Destruction of Personal Information)
The Company shall promptly destroy personal information when it is no longer necessary, such as upon expiration of the retention period or achievement of the processing purpose.
-
The procedures and methods for destroying personal information are as follows:
a. Destruction Procedure
ⅰ. If a user makes a specific request, the data will be deleted in accordance with the disposal procedure, even before the retention period expires.
b. Methods for Destruction
ⅰ. Electronic data is deleted in an unrecoverable manner; physical records are shredded.
ⅱ. Personal identifiable information (such as email addresses, display names, and identifying information in voice data) will be completely deleted from the database and backups.
Article 4 (Entrustment of Personal Information Processing and Cross-Border Transfer)
Pursuant to Article 26 (Restrictions on Processing Personal Information under Business Entrustment) and Article 28-8 (Cross-Border Transfer of Personal Information) of the Personal Information Protection Act, the Company entrusts the processing of personal information as follows to fulfill the service use agreement with the data subject and enhance convenience.
Entrusted Company |
Content of Entrusted Tasks |
Items Entrusted/Transferred |
Country of Transfer / Timing and Method |
Retention and Use Period |
Security Measures |
|---|---|---|---|---|---|
Amazon Web Services, Inc. |
IT infrastructure operation for service provision, cloud server management, and data storage |
Service usage history, member information (such as email addresses), log data, and device information |
United States (however, actual data storage is located in the AWS Seoul Region) / Remote transmission via encrypted communication networks (HTTPS/TLS) at the time of service use |
Until account deletion or termination of the outsourcing contract |
Compliance with ISO 27001/27017/27018 and SOC 1/2/3 certifications, data encryption |
Zendesk, Inc. |
Providing customer consultation responses, CS history management, and technical support services |
Consultation inquiry details (inquiry content, attachments, etc.), email address, service usage records |
USA, etc. / Remote transmission via encrypted communication network (SSL/TLS) at the time of consultation inquiry |
Until account deletion or termination of the outsourcing contract |
Compliance with SOC 2 Type II and ISO 27001 certification, data access control and encryption |
-
The company may exceptionally provide personal information to relevant authorities without the data subject's consent in the following cases.
a. Legal Basis: Article 18(2)(2) of the Personal Information Protection Act, Article 215 of the Criminal Procedure Act
b. Recipient: Competent police agency, public prosecutor's office
c. Items Provided: Information within the scope of the request
Article 5 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
Administrative Measures
Personal information (including voice data and translation drafts) is transmitted via TLS (HTTPS).
Physical Measures
Access Restriction: Database access is managed under the principle of least privilege. Onboarding data and conversation records are accessible only to backend developers, operations/CS teams, and the Personal Information Protection Officer.
Technical Measures
Security Monitoring: Detect anomalies in conversation events through regular security checks conducted at least once a year
Article 6 (Rights, Obligations, and Exercise Methods of Data Subjects and Legal Representatives)
Data subjects may request the Company to access, correct, delete, suspend processing, or withdraw consent for their personal information (hereinafter “exercise rights”) when necessary. However, non-member guests cannot exercise these rights as their personally identifiable information is not collected.
The Company does not collect personal information from children under the age of 14.
Exercise of rights may be made to the Company through the Customer Center (ct.support@flitto.com) in accordance with Article 41(1) of the Enforcement Decree of the 「Personal Information Protection Act」. The Company must process the request within 10 days after the data subject exercises their rights and must provide reasons if the request is denied.
Rights may also be exercised through an agent, such as the data subject's legal representative or an authorized delegate. In such cases, a power of attorney in the format specified in [Appendix 11] of the “Notice on Personal Information Processing Methods” must be submitted.
The data subject's right to request access to personal information and suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.
If other laws or regulations explicitly designate such personal information as subject to collection, deletion of that personal information cannot be requested.
The company verifies whether the person exercising the rights is the data subject themselves or a legitimate representative.
Article 7 (Compliance with Laws and Regulations)
The Company processes personal information in compliance with relevant laws and regulations, including the Korean Personal Information Protection Act, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
Article 8 (Changes to the Privacy Policy)
The contents of this policy shall be posted on the service screen or notified by other means, and shall take effect for all members who have agreed to this policy.
The Company may change the policy in compliance with relevant laws and regulations. When making changes, the Company must notify members via an in-service notice or email at least 7 days prior to the effective date. Changes unfavorable to members must be notified 30 days in advance.
After the Company notifies changes pursuant to this clause, if the user does not express refusal by the effective date, it shall be deemed that the user has consented to the changes. Refusal may be expressed through the Customer Center (ct.support@flitto.com).
In the case of unfavorable changes, the user may explicitly choose whether to consent. Service use may be restricted if consent is refused.
The amended terms shall be notified in accordance with Paragraph 1 and shall take effect from the effective date.
Article 9 (Chief Privacy Officer & Responsible Personnel)
-
The Company has designated a Personal Information Protection Officer as follows to oversee all matters related to personal information processing and to resolve inquiries from data subjects concerning personal information processing.
Chief Privacy Officer
Department: Personal Information Management Team
Name: Lee Jeong-su
Position: CEO
Contact: ct.support@flitto.comPersonal Information Protection Officer
Department: Personal Information Management Team
Officer: Kim Jin-gu
Contact: help@flitto.com
Data subjects may contact the Personal Information Protection Officer regarding all inquiries related to personal information protection arising from the use of the Company's services, including the receipt and processing of such inquiries and legal issues.
The company will respond to data subjects' inquiries within 3 to 5 business days.
Article 10 (Remedies for Infringement of Rights)
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Reporting Center, or similar bodies to seek redress for personal information infringements. For other reports or consultations regarding personal information infringement, please contact the following institutions:
Personal Information Dispute Mediation Committee: (Without an area code) 1833-6972 (www.kopico.go.kr)
Personal Information Infringement Reporting Center: (Without an area code) 118 (privacy.kisa.or.kr)
National Police Agency: (Without an area code) 182 (http://ecrm.police.go.kr )
Announcement Date and Effective Date
Announcement Date: March 24, 2026
Effective Date: April 8, 2026