1. Company and Officer Information
- Company Name: Furence
- Representative: Shin Hyeon-sam
- Address: 503-504, Ace Gasan Tower, 121 Digital-ro, Geumcheon-gu, Seoul, Republic of Korea
- Privacy Officer: Shin Hyeon-sam
- Contact: sam@furence.com / +82-2-6443-5600
2. Collection Items and Purpose of Use
(1) Collection Items
- Account/Authentication: Email address, password (or authentication identifier, social account identifier), name/display name
- Device/Identification: Device information (model, OS/browser version, etc.), IP address, cookie/similar technology identifiers
- Service Usage: Service access time, service usage records (feature usage history, error logs), payment identifiers and transaction records (when applicable)
- Voice/Content: Voice recording files, transcripts, speaker identifiers, generated summaries, key points, action items
- Optional: Job title/department, user dictionary (glossary), personalization settings
(2) Purpose of Use
- Speech-to-text (STT), speaker separation, summary and meeting minutes generation and provision
- Account opening and login, social account linking
- Quality improvement and statistical analysis (within the scope of de-identification and pseudonymization)
- Service security and stabilization (access control, incident response logs, etc.)
- Customer support and complaint handling
(3) Sensitive Information Notice
(4) Legal Basis for Processing
Contract performance and consent, legitimate interests (stabilization and security), compliance with legal obligations
3. Retention Period, Storage Location, and Destruction
(1) Basic Retention Period
- Original Voice: Default 30 days
- Transcripts and Meeting Minutes: Default 1 year
- Access and Security Logs: 6 months to 1 year
- Payment and Transaction Information: 5 years according to relevant laws
(2) Destruction Principles
Data is destroyed without delay upon achievement of purpose or expiration of retention period. When deletion requests are made by users or administrators, logical deletion is performed immediately followed by periodic physical destruction. Backup data is overwritten according to rotation policies, and destruction records are kept and preserved.
(3) Storage Location
Data is stored primarily in domestic regions. When on-premise is selected, processing occurs only within the customer's environment.
(4) Long-term Inactive User Measures
For users inactive for 1 year, destruction or separate storage is implemented after prior notification.
4. Separate Retention According to Laws
- Communications Secret Protection Act: Log records, etc. for 3 months
- Act on Consumer Protection in Electronic Commerce: Consumer complaints and dispute handling for 3 years, payment and goods supply for 5 years, contracts and withdrawal for 5 years
- Framework Act on National Taxes and Value-Added Tax Act: Tax-related records for 5 to 10 years
- Electronic Financial Transactions Act (when applicable): Electronic financial transaction records for 5 years
- Company Policy: Fraudulent use prevention records for 6 months
6. Third-party Provision and Processing Consignment
(1) Third-party Provision Principles
Information is provided minimally only when there is legal basis or user consent.
(2) Processing Consignment
Some operations may be consigned to trustees for service operation efficiency. In this case, trustee names, consignment scope, storage regions, and protective measures are transparently disclosed.
(3) Re-consignment Management
Equal protection levels are secured during re-consignment, and related notification procedures are followed.
(4) Processing Consignment List
- Domestic Cloud IaaS (e.g., Naver Cloud or KT Cloud): Infrastructure provision, data storage and backup (Republic of Korea, encryption, access control, physical security)
- Notification Service (e.g., Toast, KT Notification): Email and SMS transmission (Republic of Korea, transmission encryption, minimal log retention)
- Customer Support System (e.g., Zendesk domestic agency or in-house helpdesk): Inquiry and ticket processing (Republic of Korea, minimum privileges, audit logs, masking)
Changes will be notified in advance.
7. International Transfer
(1) Basic Principles
Personal information may be transferred to overseas operators in relation to social account integration and optional external AI/cloud function provision. We comply with notification, consent, and protective measures prescribed by relevant laws during international transfers.
(2) International Transfer Targets and Countries (Examples)
Social Login Integration
- Google LLC (United States and global regions)
- Apple Inc. (United States and global regions)
- Microsoft Corporation (United States and global regions)
- NAVER Corporation (Republic of Korea and global service infrastructure)
- Kakao Corp. (Republic of Korea and global service infrastructure)
Cloud and Platform
- Amazon Web Services, Inc. (United States and global regions)
External AI API (Optional Features)
- OpenAI, L.L.C. (United States and global regions)
- Other translation/summary APIs: Corresponding operators and operating countries
(3) Items Transferred
- Common Technical and Log Items: Email address, device information, IP address, cookie/similar identifiers, service access time, service usage records
- Voice/Content Items: Voice files, transcription text, prompt/setting values (pseudonymization and masking are applied as a principle before transmission when using external AI APIs)
- Social Login Items: Social account identifier, email address, display name, authentication token, etc. (according to platform provision scope)
(4) Transfer Timing and Method
Real-time transmission through encrypted networks. Transfer occurs at the time of authentication and authorization procedures, log collection, and optional feature calls (e.g., external AI).
(5) Retention and Use Period
- Social Login Related Information: Retained within platform policies and our account operation period (unnecessary information destroyed upon integration termination)
- External AI API: Immediately upon purpose achievement or short-term retention within operator policy scope (storage for learning purposes is basically prohibited or non-consented)
- Cloud Logs/Backup: Minimally retained within contract, legal, and security policy scope
(6) Information Manager Contact (Reference)
Follows each operator's public policies and contact information. We provide related information upon request.
(7) Protective Measures
Transmission and storage encryption, access control, re-transfer restrictions (contract), securing adequacy basis such as Standard Contractual Clauses (SCC) or equivalent, imposing incident notification obligations, applying pseudonymization/masking gates.
(8) Consent and Refusal
Users can choose consent for international transfer regarding social login or external AI function use, and if consent is refused, use of corresponding functions may be restricted. Upon consent withdrawal, integration is terminated and additional transfers are stopped.
(9) Current Basic Operation
This service basically provides social login functions, so international transfer notification and consent procedures apply. External AI APIs are operated as default OFF, and additional notification and consent are obtained when activated.
8. User Rights and Exercise Methods
- Scope of Rights: Access, correction, deletion, processing suspension, consent withdrawal, data portability rights
- Exercise Method: Requests can be made through the personal information menu in app settings or via email, phone, etc.
- Processing Principles: Processing is conducted within the scope of relevant laws, and completion status or reasons for inability are notified without delay.
- Minor Protection: Consent and rights exercise procedures by legal representatives are provided.
9. Automated Decision-making Notice
Automated processing including automatic summarization, tagging, and action item extraction is included. When significant impact is concerned, users can request additional explanations and human review.
10. Security Measures
Organizational Measures
Designation of data protection officer, regular training, minimum privilege assignment, separation of development, operation, and support privileges, regular audit log inspection
Technical Measures
Transmission and storage encryption, key management (KMS, HSM), multi-factor authentication, session timeout, role-based access control (RBAC), vulnerability assessment and penetration testing, anomaly monitoring, log integrity protection, data minimization and pseudonymization/masking
Physical Measures
Data center access control, CCTV operation, storage media import/export management
11. On-premise and Cloud Hybrid Policy
- Deployment Principles: Centered on on-premise, but cloud hybrid is possible.
- Data Ownership: Ownership of data processed in on-premise environments belongs to customers, and we do not access it in principle.
- Remote Support: Procedures of prior approval, temporary account use, session recording, and immediate privilege revocation upon work completion are followed.
- Policy Center (Administrator): Functions to block external APIs (default OFF), force retention period settings, and set log retention periods (recommended 1 year or more) are provided.
13. Incident Response
- Procedure: Detection → Isolation → Analysis → Mitigation → Notification → Recurrence Prevention
- Notification Content: Categories of affected information, occurrence time and cause, response methods, and contact information are provided without delay.
14. Contact Information
- Company Name: Furence
- Address: 503-504, Ace Gasan Tower, 121 Digital-ro, Geumcheon-gu, Seoul, Republic of Korea
- Representative: Shin Hyeon-sam
- Data Protection Officer: //////
- Contact: *****@furence.com / +82-2-6443-5600