Privacy Policy
Flitto, Inc. (hereinafter referred to as the "Company") establishes and publicly discloses this Privacy Policy as follows, in order to protect the personal information of data subjects pursuant to Article 30 of the Personal Information Protection Act and to handle related grievances promptly and smoothly.
This Policy applies to the Live Translation service (hereinafter referred to as the "Service") operated by the Company. The Company does not process the personal information of children under the age of 14.
Article 1 (Purposes of Processing, Items Collected, and Retention Periods)
The Company processes personal information for the following purposes. Personal information being processed shall not be used for purposes other than those stated below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.
1. Service Inquiries (Zendesk)
Personal information is collected for the purpose of receiving and responding to customer inquiries and providing service guidance.
Inquiry Channel: https://support.flitto.com/hc/ko/requests/new?ticket_form_id=28554198999449
Category | Items Collected | Retention Period |
|---|---|---|
Required | Email address, Name (contact person/title and position), Company name, Phone number | 2 years after inquiry resolution |
2. Automatically Collected Personal Information
During the use of the Company's Service, the following information is automatically generated and collected through cookies. This information is used for the purpose of usage statistics analysis and service quality improvement. For details, please refer to Article 7.
Cookie Name | Provider | Items Collected | Purpose of Collection |
|---|---|---|---|
_clck | Microsoft Clarity | Visitor identification information, settings values | Recognizing returning visitors and maintaining settings |
_clsk | Microsoft Clarity | Session activity records | Aggregating activities within a single session into one record |
CLID | Microsoft Clarity | Browser identification information | Identifying whether Clarity has been used across sites |
MUID | Microsoft | Unique browser ID | Performance measurement, analysis, and advertising tracking |
3. Collection Methods
Direct input: Data subjects enter information directly on the "Contact Us" page of the Service website.
Automatic collection: Automatically generated and collected through cookies during the use of the Service.
4. Retention of Personal Information Pursuant to Applicable Laws
The Company retains personal information in accordance with applicable laws as follows:
Item | Retention Period | Legal Basis |
|---|---|---|
Records relating to consumer complaints or dispute resolution | 3 years | Article 6 of the Act on Consumer Protection in Electronic Commerce, Etc. and Article 6 of its Enforcement Decree |
Article 2 (Procedures and Methods for Destruction of Personal Information)
1. Destruction Procedures
When the retention period for personal information has expired, or the purpose of processing has been achieved, rendering the personal information unnecessary, the Company shall obtain approval from the Personal Information Protection Officer and destroy the relevant personal information without delay.
However, where retention is required under other applicable laws, the information shall be preserved by transferring it to a separate database (DB) or storing it in a different storage location for the applicable retention period.
2. Destruction Methods
Electronic files containing personal information shall be deleted using technical methods that render the records unrecoverable.
Personal information printed on paper shall be shredded using a shredder or destroyed by incineration.
Article 3 (Provision of Personal Information to Third Parties)
The Company processes personal information of data subjects within the scope of purposes specified in Article 1 and does not provide personal information to third parties beyond the original scope of purpose without the consent of the data subject.
However, personal information may be provided to third parties without the consent of the data subject in the following cases:
Where there are specific provisions in other laws or where it is unavoidable to comply with statutory obligations;
Where an investigative agency makes a request in accordance with the procedures and methods prescribed by law for the purpose of investigation.
Article 4 (Overseas Transfer and Entrustment of Personal Information)
The Company entrusts the processing of personal information and transfers it overseas as follows, pursuant to Article 26 (Entrustment of Business) and Article 28-8 (Overseas Transfer) of the Personal Information Protection Act, for the fulfillment of the service usage agreement and enhancement of user convenience.
Entrusted Entity | Description of Entrusted Business | Items Entrusted/Transferred | Destination Country / Timing and Method | Retention and Usage Period | Security Measures |
|---|---|---|---|---|---|
Zendesk, Inc. (privacy@zendesk.com) | Customer consultation response, CS history management and technical support services | Consultation inquiry details (inquiry content, attachments, etc.), email address, service usage records | United States / Transmitted remotely via encrypted communication network (HTTPS/TLS) at the time of inquiry | Until membership withdrawal or termination of the entrustment agreement | SOC 2 Type II and ISO 27001 certification compliance, data access control and encryption |
When executing an entrustment agreement, the Company specifies in the contractual documents the prohibition of processing personal information beyond the scope of the entrusted business, technical and administrative protective measures, restrictions on re-entrustment, management and supervision of the entrusted party, liability for damages, and other relevant matters, and supervises whether the entrusted party processes personal information safely.
Users may refuse the overseas transfer of personal information. However, if the transfer is refused, the use of the Service may be limited. If you do not wish for the transfer, please contact us through the Customer Center.
Any changes in the content of the entrusted business or the entrusted party shall be promptly disclosed through this Privacy Policy.
Article 5 (Measures to Ensure the Security of Personal Information)
The Company takes the following technical, administrative, and physical measures necessary to ensure security in accordance with Article 29 of the Personal Information Protection Act:
Encryption of personal information: Personal information of data subjects is encrypted for storage and management. Data is transmitted securely using TLS (HTTPS) protocol.
Access control: The Company controls access to database systems that process personal information by granting, modifying, and revoking access rights; controls unauthorized access from external sources using intrusion prevention systems; and grants access rights to personal information only to the relevant personnel in charge based on the principle of least privilege.
Regular security inspections: Security programs are installed and periodically inspected to prevent the leakage and damage of personal information caused by hacking, computer viruses, and other threats.
Article 6 (Rights, Obligations, and Methods of Exercise for Data Subjects and Legal Representatives)
1. Rights of Data Subjects
Data subjects may exercise the following rights relating to personal information protection against the Company at any time:
Right to request access to personal information
Right to request correction in the case of errors, etc.
Right to request deletion
Right to request suspension of processing
Right to withdraw consent
2. Methods of Exercising Rights
The above rights may be exercised by contacting the Company's Customer Center (ctlt@flitto.com) in writing, by email, or by other methods. The Company shall process such requests within 10 days of receipt. However, where there are legitimate grounds under personal information protection-related laws for refusing a request, the Company shall inform the data subject of such grounds.
3. Exercise Through a Representative
The exercise of rights may be carried out through a legal representative of the data subject or an authorized agent. In such cases, a power of attorney in the form prescribed in Appendix No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
Where a data subject has requested correction or deletion of errors in personal information, the Company shall not use or provide the relevant personal information until the correction or deletion has been completed.
Article 7 (Matters Concerning the Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)
1. Purpose of Using Cookies
The Company uses cookies solely for the purpose of usage statistics analysis and improvement to enhance service quality.
2. Cookies in Use
Cookie Name | Provider | Purpose | Description |
|---|---|---|---|
_clck | Microsoft Clarity | Analytics/Statistics | Recognizes returning visitors and maintains settings. |
_clsk | Microsoft Clarity | Analytics/Statistics | Aggregates activities within a single session into one record. |
CLID | Microsoft Clarity | Analytics/Statistics | Identifies whether Clarity has been used across sites. |
MUID | Microsoft | Analytics/Statistics | Assigns a unique browser ID, shared across Microsoft sites. Used for performance measurement, analysis, and advertising tracking. |
3. Consent to Cookie Collection
When data subjects access the Service website, a cookie usage notification banner is displayed. Clicking the "Confirm" button is deemed as consent to cookie collection.
4. How to Refuse Cookie Settings
Data subjects have the option to accept or refuse the installation of cookies by configuring their web browser settings:
Chrome: Settings → Privacy and Security → Cookies and other site data
Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data
Safari: Preferences → Privacy → Cookies and website data
Firefox: Settings → Privacy & Security → Cookies and site data
Article 8 (Personal Information Protection Officer and Responsible Department)
The Company designates the following Personal Information Protection Officer to oversee all matters related to the processing of personal information, to be responsible for and ensure the protection of data subjects' right to self-determination regarding their personal information, and to handle complaints and remediate damages.
Personal Information Protection Officer
Category | Details |
|---|---|
Name | Jungsoo Lee |
Title | CEO |
Personal Information Protection Department
Category | Details |
|---|---|
Department | Operations Team |
Contact Person | Jingu Kim |
Users may direct all personal information protection-related inquiries, complaints, and requests for damage remediation arising from the use of the Company's Service to the Personal Information Protection Officer and the responsible department. The Company shall respond to and process users' inquiries without delay.
Article 9 (Remedies for Infringement of Rights of Data Subjects)
Data subjects may apply for dispute resolution, consultation, or other remedies to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center, or other relevant organizations. For reporting and consulting on other personal information infringement matters, please contact the following organizations:
Personal Information Dispute Mediation Committee: (No area code) 1833-6972 (www.kopico.go.kr)
Personal Information Infringement Report Center: (No area code) 118 (privacy.kisa.or.kr)
Supreme Prosecutors' Office Cyber Investigation Division: (No area code) 1301 (Supreme Prosecutors' Office)
National Police Agency Cyber Bureau: (No area code) 182 (ECRM – Cybercrime Reporting System)
Pursuant to Articles 35 (Access to Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act, a person who has suffered an infringement of rights or interests due to a disposition or omission by a public institution in response to a request by the data subject may file an administrative appeal in accordance with the Administrative Appeals Act.
Central Administrative Appeals Commission: (No area code) 110 (Online Administrative Appeals)
Article 10 (Changes to the Privacy Policy)
This Privacy Policy shall be posted on the Service screen or made available through other means, and shall take effect for all users who have consented to this Policy.
The Company may amend this Policy in compliance with applicable laws. In the event of an amendment, users shall be notified at least 7 days prior to the effective date through an in-service notice or by email. For changes that are disadvantageous to users, notice shall be given at least 30 days in advance.
After the Company posts the amended matters pursuant to this Article, if a user does not express an intention to refuse by the effective date, the user shall be deemed to have consented to the amended matters. Users may express their intention to refuse through the Customer Center (ctlt@flitto.com).
In the case of changes that are disadvantageous, users may expressly choose whether or not to consent. If consent is refused, the use of the Service may be limited.
The amended terms shall be posted in accordance with Paragraph 1 and shall take effect from the effective date.
Privacy Policy Amendment History
Version | Effective Date | Key Changes |
|---|---|---|
v1.0 | October 1, 2025 | Initial enactment |
Addendum
This Policy shall take effect from [August 6, 2026].