Furence Privacy Policy

Voice Recording-based Conversation Transcript and AI Meeting Minutes Service

This Privacy Policy has been established to clarify the protection principles of personal information processed in relation to the provision of voice recording-based conversation transcripts and AI meeting minutes services (moai-note.ai, MoAI, hereinafter "Service") provided by Furence (https://furence.com/), the rights of users, the obligations of the company, and security measures. This policy applies to mobile/web applications, backend servers, cloud and on-premise environments.

1. Company and Officer Information

  • Company Name: Furence
  • Representative: Shin Hyeon-sam
  • Address: 503-504, Ace Gasan Tower, 121 Digital-ro, Geumcheon-gu, Seoul, Republic of Korea
  • Privacy Officer: Shin Hyeon-sam
  • Contact: sam@furence.com / +82-2-6443-5600

2. Collection Items and Purpose of Use

(1) Collection Items

  • Account/Authentication: Email address, password (or authentication identifier, social account identifier), name/display name
  • Device/Identification: Device information (model, OS/browser version, etc.), IP address, cookie/similar technology identifiers
  • Service Usage: Service access time, service usage records (feature usage history, error logs), payment identifiers and transaction records (when applicable)
  • Voice/Content: Voice recording files, transcripts, speaker identifiers, generated summaries, key points, action items
  • Optional: Job title/department, user dictionary (glossary), personalization settings

(2) Purpose of Use

  • Speech-to-text (STT), speaker separation, summary and meeting minutes generation and provision
  • Account opening and login, social account linking
  • Quality improvement and statistical analysis (within the scope of de-identification and pseudonymization)
  • Service security and stabilization (access control, incident response logs, etc.)
  • Customer support and complaint handling

(3) Sensitive Information Notice

Since meeting content may contain sensitive information, prior notice is provided at the recording stage and automatic masking functions are provided as default.

(4) Legal Basis for Processing

Contract performance and consent, legitimate interests (stabilization and security), compliance with legal obligations

3. Retention Period, Storage Location, and Destruction

(1) Basic Retention Period

  • Original Voice: Default 30 days
  • Transcripts and Meeting Minutes: Default 1 year
  • Access and Security Logs: 6 months to 1 year
  • Payment and Transaction Information: 5 years according to relevant laws

(2) Destruction Principles

Data is destroyed without delay upon achievement of purpose or expiration of retention period. When deletion requests are made by users or administrators, logical deletion is performed immediately followed by periodic physical destruction. Backup data is overwritten according to rotation policies, and destruction records are kept and preserved.

(3) Storage Location

Data is stored primarily in domestic regions. When on-premise is selected, processing occurs only within the customer's environment.

(4) Long-term Inactive User Measures

For users inactive for 1 year, destruction or separate storage is implemented after prior notification.

6. Third-party Provision and Processing Consignment

(1) Third-party Provision Principles

Information is provided minimally only when there is legal basis or user consent.

(2) Processing Consignment

Some operations may be consigned to trustees for service operation efficiency. In this case, trustee names, consignment scope, storage regions, and protective measures are transparently disclosed.

(3) Re-consignment Management

Equal protection levels are secured during re-consignment, and related notification procedures are followed.

(4) Processing Consignment List

  • Domestic Cloud IaaS (e.g., Naver Cloud or KT Cloud): Infrastructure provision, data storage and backup (Republic of Korea, encryption, access control, physical security)
  • Notification Service (e.g., Toast, KT Notification): Email and SMS transmission (Republic of Korea, transmission encryption, minimal log retention)
  • Customer Support System (e.g., Zendesk domestic agency or in-house helpdesk): Inquiry and ticket processing (Republic of Korea, minimum privileges, audit logs, masking)

Changes will be notified in advance.

7. International Transfer

(1) Basic Principles

Personal information may be transferred to overseas operators in relation to social account integration and optional external AI/cloud function provision. We comply with notification, consent, and protective measures prescribed by relevant laws during international transfers.

(2) International Transfer Targets and Countries (Examples)

Social Login Integration

  • Google LLC (United States and global regions)
  • Apple Inc. (United States and global regions)
  • Microsoft Corporation (United States and global regions)
  • NAVER Corporation (Republic of Korea and global service infrastructure)
  • Kakao Corp. (Republic of Korea and global service infrastructure)

Cloud and Platform

  • Amazon Web Services, Inc. (United States and global regions)

External AI API (Optional Features)

  • OpenAI, L.L.C. (United States and global regions)
  • Other translation/summary APIs: Corresponding operators and operating countries

(3) Items Transferred

  • Common Technical and Log Items: Email address, device information, IP address, cookie/similar identifiers, service access time, service usage records
  • Voice/Content Items: Voice files, transcription text, prompt/setting values (pseudonymization and masking are applied as a principle before transmission when using external AI APIs)
  • Social Login Items: Social account identifier, email address, display name, authentication token, etc. (according to platform provision scope)

(4) Transfer Timing and Method

Real-time transmission through encrypted networks. Transfer occurs at the time of authentication and authorization procedures, log collection, and optional feature calls (e.g., external AI).

(5) Retention and Use Period

  • Social Login Related Information: Retained within platform policies and our account operation period (unnecessary information destroyed upon integration termination)
  • External AI API: Immediately upon purpose achievement or short-term retention within operator policy scope (storage for learning purposes is basically prohibited or non-consented)
  • Cloud Logs/Backup: Minimally retained within contract, legal, and security policy scope

(6) Information Manager Contact (Reference)

Follows each operator's public policies and contact information. We provide related information upon request.

(7) Protective Measures

Transmission and storage encryption, access control, re-transfer restrictions (contract), securing adequacy basis such as Standard Contractual Clauses (SCC) or equivalent, imposing incident notification obligations, applying pseudonymization/masking gates.

(8) Consent and Refusal

Users can choose consent for international transfer regarding social login or external AI function use, and if consent is refused, use of corresponding functions may be restricted. Upon consent withdrawal, integration is terminated and additional transfers are stopped.

(9) Current Basic Operation

This service basically provides social login functions, so international transfer notification and consent procedures apply. External AI APIs are operated as default OFF, and additional notification and consent are obtained when activated.

8. User Rights and Exercise Methods

  • Scope of Rights: Access, correction, deletion, processing suspension, consent withdrawal, data portability rights
  • Exercise Method: Requests can be made through the personal information menu in app settings or via email, phone, etc.
  • Processing Principles: Processing is conducted within the scope of relevant laws, and completion status or reasons for inability are notified without delay.
  • Minor Protection: Consent and rights exercise procedures by legal representatives are provided.

9. Automated Decision-making Notice

Automated processing including automatic summarization, tagging, and action item extraction is included. When significant impact is concerned, users can request additional explanations and human review.

10. Security Measures

Organizational Measures

Designation of data protection officer, regular training, minimum privilege assignment, separation of development, operation, and support privileges, regular audit log inspection

Technical Measures

Transmission and storage encryption, key management (KMS, HSM), multi-factor authentication, session timeout, role-based access control (RBAC), vulnerability assessment and penetration testing, anomaly monitoring, log integrity protection, data minimization and pseudonymization/masking

Physical Measures

Data center access control, CCTV operation, storage media import/export management

11. On-premise and Cloud Hybrid Policy

  • Deployment Principles: Centered on on-premise, but cloud hybrid is possible.
  • Data Ownership: Ownership of data processed in on-premise environments belongs to customers, and we do not access it in principle.
  • Remote Support: Procedures of prior approval, temporary account use, session recording, and immediate privilege revocation upon work completion are followed.
  • Policy Center (Administrator): Functions to block external APIs (default OFF), force retention period settings, and set log retention periods (recommended 1 year or more) are provided.

12. Cookies and Similar Technologies

  • Purpose of Use: Essential cookies necessary for authentication and security, functional cookies for user convenience, cookies for de-identified statistical analysis, etc. may be used.
  • Refusal Method: Storage can be refused through browser settings, but some functions may be restricted in this case.

13. Incident Response

  • Procedure: Detection → Isolation → Analysis → Mitigation → Notification → Recurrence Prevention
  • Notification Content: Categories of affected information, occurrence time and cause, response methods, and contact information are provided without delay.

14. Contact Information

  • Company Name: Furence
  • Address: 503-504, Ace Gasan Tower, 121 Digital-ro, Geumcheon-gu, Seoul, Republic of Korea
  • Representative: Shin Hyeon-sam
  • Data Protection Officer: //////
  • Contact: *****@furence.com / +82-2-6443-5600