Conma Privacy Policy

Effective: September 16, 2026 · Last Amended: September 16, 2026 · Published by: Digitalog Technologies Co., Ltd.

Digitalog Technologies Co., Ltd. (the "Company") regards the personal information of data subjects as a matter of the utmost importance and seeks to be transparent about how such information is collected, used, and shared.

This Privacy Policy applies to information the Company collects when you use any of its products and services (collectively, the "Service"), or when you otherwise interact with the Company (such as attending Company events or communicating with the Company). Where a separate privacy policy applies, that policy shall prevail.

In order to protect the freedom and rights of data subjects, the Company processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act of the Republic of Korea (the "PIPA") and other applicable laws and regulations.

This Policy covers the categories of information the Company collects, how it is used and disclosed, how it is stored and protected, how long it is retained, how data subjects may access and control their information, and cross-border transfers.

This document is a privacy policy grounded in the laws of the Republic of Korea (including the PIPA). With respect to the processing of information relating to users residing in other jurisdictions, such as Europe, the United States, and Japan, the supplementary provisions of Article 17 apply in accordance with the relevant laws of those countries and regions (GDPR, CCPA, APPI, and the like).

If you do not agree to this Policy, please discontinue your use of the Service and any other form of interaction with the Company.

Where the Service is provided under an agreement with an organization to which the data subject belongs (for example, an employer), that organization may control the information processed within the Service. For details, please refer to the "End User Notice" in Article 15 of this Policy.

Article 1 (Purposes of Processing Personal Information)

1.1

The Company processes personal information for the purposes set out below. Personal information being processed will not be used for any purpose other than those set out below, and where the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the PIPA.

CategoryPurpose of processing
(1) Provision and personalization of the Serviceconfirming intent to register, identifying and authenticating the individual for the provision of membership-based Services, maintaining and managing membership status, preventing improper use of the Service, giving notices and notifications, handling grievances, processing transactions, login authentication, operating, maintaining, and improving the Service, providing personalized features and content recommendations, and supporting productivity and team collaboration
(2) Message handlingthe sending, delivery, and receipt of messages and the measurement of sending performance
(3) Provision of artificial intelligence featuresthe analysis, classification, and translation of text and the generation of reply drafts using artificial intelligence technology
(4) Development of and research into new Servicesdeveloping new Services and providing tailored Services, providing Services and displaying advertising according to statistical characteristics, verifying the effectiveness of the Service, ascertaining access frequency, compiling statistics on members' use of the Service, analyzing usage trends and patterns, and developing new products, features, and technologies
(5) Customer supportconfirming and handling users' inquiries, handling complaints, technical support, and problem resolution
(6) Marketing and communicationsdelivering information about the Company's services, features, and events; measuring the performance of advertising placed by the Company and selecting advertising audiences; displaying online interest-based advertising founded on behavioural information
(7) Integration with Meta platformswhere a user connects an account or grants access through Facebook Login or the Instagram Graph API, providing login authentication, content management, and related Service features
(8) Payment processing and billingprocessing payments for paid Services, billing, subscription management, and the processing of related credit information
(9) Generation of Service Output and data analysisproviding insights, reports, and analytical materials to users, and using personal information in anonymized and aggregated form for improving Service quality, developing new features, A/B testing, feature flag operation, and CRM message delivery and performance analysis
(10) Collection of withdrawal reasonsreason information collected optionally upon cancellation of a subscription or withdrawal of an account

Data from Meta platforms under item (7) is used solely to provide the authorized features of the Service and for no other purpose.

Article 2 (Categories of Personal Information Processed and Methods of Collection)

2.1

The Company collects personal information when a data subject uses the Service or provides information directly to the Company, and when it receives information from other sources.

2.2

Categories of personal information collected

(1) Information you provide directly

  • Required items (for registration and provision of the Service): email address, password (stored as a hash)
  • Account and profile information: name, contact details, company name, job title, profile photograph, and other information the data subject optionally adds to a profile
  • Payment information (for paid services): billing contact name, billing email address, and payment card information. However, the Company does not itself store or collect sensitive payment information such as card numbers, expiry dates, or CVCs, and processes it through the payment processors referred to in Article 19 (Toss Payments Co., Ltd. for payments in Korean won and Polar Software, Inc. for payments in foreign currency) (see Article 19 for details).
  • Content provided through the Service: content that the data subject posts, transmits, receives, or shares within the Service, together with automation settings (auto-reply templates, comment filter keywords, prize draw event settings, and the like)
  • Website content: feedback, survey responses, and event participation information submitted on the Company's websites (including social media)
  • Customer support channel information: contact details, problem summaries, related documents, and screenshots provided when requesting support to resolve an issue with the Service

(2) Information collected automatically through your use of the Service

  • Service usage information: features used, links clicked, files uploaded, search terms, and frequency of collaboration and communication
  • Device and connection information: IP address, cookies, operating system, browser and device information, access logs, page URLs, and error data
  • Notification and event records: records of in-Service notifications received, automation execution history, records of the sending, delivery, and opening of messages and of the selection of links sent, and subscription, payment, and Credit usage history

(3) Information collected from connected third-party platforms (Meta)

  • Collected through the Instagram Graph API to the extent connected and authorized by the user: the username, profile photograph, account metrics (follower count, impressions, reach, and the like), source post data (content, captions, hashtags, and media metadata), per-post insights, the source content and metadata of comments and direct messages (including the account identifier, username, and profile photograph of the counterparty to the conversation and any attached media), and follower demographics (anonymized and aggregated) of the connected account
  • Basic profile information obtained through Facebook Login
  • Public data of public Instagram Business/Creator accounts that a user requests to be analyzed or that the Company selects for analysis (limited to items made available by the Meta Graph API, such as account name, profile photograph, post content, and public metrics)

(4) Information collected from other sources

  • Other users: information provided when inviting members to, or designating members of, a workspace
  • Partners: billing and technical contact details and information on services of interest received from marketing and reseller partners
  • Public sources: publicly available databases and social media
  • Company affiliates: (not applicable at present)

(5) Information collected from message recipients

In relation to messages that a user sends through the Service, the Company collects records of whether the message was delivered and opened and of the selection of links contained in the message (such as the link identifier and the time of occurrence). The Company processes such records for the purposes of measuring sending performance, compiling statistics, and improving the quality of the Service, and does not identify recipients beyond the extent necessary for those purposes. Notifications to recipients, the obtaining of their consent, and other measures required under applicable law are performed by the user who sent the message.

2.3

Right to refuse consent and consequences of refusal

Users have the right to refuse to provide optional items. However, if you refuse to provide optional items, your use of certain Service features may be restricted. Required items (email address and password) are indispensable for registration and the provision of core Service functionality, and accordingly the Service cannot be used if you refuse to provide them.

2.4

Methods of collecting personal information

  • (1) Where a user consents to the collection of personal information and enters information directly in the course of registration or use of the Service
  • (2) Collection through web pages, email, facsimile, telephone, and similar channels in the course of consultation via customer support
  • (3) Automatic generation and collection of IP addresses, cookies, usage records, device information, and the like in the course of using the Service
  • (4) Receipt of information from a third-party service upon connecting that service

Article 3 (Retention and Use Period of Personal Information)

3.1

The Company processes and retains personal information within the retention and use period prescribed by law or within the retention and use period consented to by the data subject at the time of collection.

The processing and retention periods for each category of personal information are as follows.

  • (1) Membership registration and management (account information): destroyed without delay upon a request for withdrawal of membership. However, where an investigation or inquiry into a violation of applicable law is in progress, where claims or obligations arising from use of the Service remain outstanding, or where retention is otherwise necessary to comply with legal obligations, resolve disputes, or enforce agreements, the information is stored separately until the relevant grounds are resolved and is then destroyed.
  • (2) Information relating to the provision of the Service: until the supply of the Service and the payment and settlement of fees are complete
  • (3) Marketing information: until consent to receive marketing information is withdrawn
  • (4) Records of message sending and delivery and of link selection: retained for six months from the date of collection and then destroyed. Statistical information processed so that individuals cannot be identified may, however, be retained and used thereafter without limitation of period.
  • (5) The source content of direct messages and related metadata: destroyed upon the earlier of the expiry of six months from the date of collection or the member's withdrawal.
3.2

Where the Company is required by applicable law to preserve personal information rather than destroy it, the Company securely retains such personal information for the periods set out below.

In the Republic of Korea, the statutory grounds and periods for preservation are as follows.

(1) Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc.

  • Records on labelling and advertising: 6 months
  • Records on contracts and withdrawal of subscription: 5 years
  • Records on payment and the supply of goods: 5 years
  • Records on consumer complaints or dispute resolution: 3 years

(2) Article 15-2 of the Protection of Communications Secrets Act

  • Login records: 3 months
  • Service usage records: 3 months

(3) Article 22 of the Enforcement Decree of the Use and Protection of Credit Information Act

  • Records on the processing of credit information: 3 years

(4) Article 22 of the Electronic Financial Transactions Act

  • Payment-related transaction records: 5 years

(5) In other jurisdictions, including the European Union, the United States, and Japan, information is likewise retained for the periods prescribed by the applicable laws of the relevant region.

3.3

Personal information whose retention period has expired or whose purpose of processing has been achieved is destroyed without delay in accordance with Article 7, pursuant to the PIPA and other applicable laws.

Where immediate destruction is not technically possible, for example because the information resides in backup systems, the Company stores such information securely, isolates it from external access and further use, and destroys it immediately once deletion becomes possible.

Article 4 (Provision of Personal Information to Third Parties and Disclosure)

4.1

The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information) and, as a general rule, does not provide or disclose personal information externally without the prior consent of the data subject. The following are exceptions.

(1) Where the data subject has consented in advance

The Company follows a procedure of clearly informing the data subject of the recipient, the purpose of provision, the categories of personal information provided, and the retention and use period, and obtaining consent.

(2) Where information is disclosed to other users of the Service

  • Collaboration purposes: where a data subject creates content within the Service and chooses to share it with other users, that content and related profile information (such as name and profile photograph) may be displayed.
  • Workspace administration: the Owner or Admin of a workspace to which a data subject belongs may disclose the data subject's contact information to other members in order to support requests relating to the Service.
  • Community forums: where a data subject posts information on a public bulletin board or forum operated by the Company, that information and the associated profile information may be made public.

(3) Where required under the provisions of applicable law, or where a request is made by an investigative authority in accordance with the procedures and methods prescribed by law for investigative purposes

(4) Business transfers, etc.: in the event of a merger, sale of assets, financing, or acquisition of the business, collected personal information may be transferred, in which case the Company will provide notice to data subjects, including any available choices.

(5) Disclosure to affiliates: this is not applicable at present. Should information be disclosed to affiliates in the future, the protections set out in this Policy will apply.

4.2

Entrustment of personal information processing (Article 26 of the PIPA)

In order to provide the Service smoothly, the Company entrusts personal information processing tasks to external trustees as set out below. The Company enters into entrustment agreements with each trustee specifying the matters set out in each subparagraph of Article 26(1) of the PIPA, and supervises whether trustees process personal information securely.

TrusteeEntrusted workItems processedRetention period
Amazon Web Services (AWS)user authentication (Cognito) and cloud server operation and management (EKS, S3, SQS, Secrets Manager, and the like)email addresses, authentication tokens, and user data generated in the course of using the Serviceuntil withdrawal of membership
Anthropic PBCanalysis, classification, and translation of text and generation of reply drafts using artificial intelligence technologytext entered or received by users in the course of using the Service
Toss Payments Co., Ltd.payment processing (Korean won)transaction ID, approval number, payment amount, payment method type, payment date and time, and billing contact email address (excluding card numbers and CVCs)5 years under the Act on the Consumer Protection in Electronic Commerce, Etc.
Polar Software, Inc.payment processing (foreign currency)payment identifiers, order identifiers, user email addresses, payment amounts, and payment datesfive years under the Act on the Consumer Protection in Electronic Commerce
Google LLC (Google Analytics 4)Service usage statisticsanonymized visit dataup to 26 months
Hotjar Ltd.session replay and UX analyticsmasked session data1 year

The entrustment of personal information processing is governed by Article 26 of the PIPA and is legally distinct from the "provision to third parties" addressed in Article 5 of this Policy (Article 17 of the PIPA).

4.3

The Company does not currently provide personal information of data subjects to third parties for any purpose other than those specified in subparagraphs (2) through (5) of Article 4.1. Should this become necessary in the future, the Company will clearly inform data subjects of the recipient, purpose, items, and retention and use period and obtain their consent, or otherwise proceed in accordance with applicable law.

Article 5 (Provision of Personal Information to Third Parties)

5.1

The Company does not provide personal information to third parties for those third parties' own independent purposes.

5.2

Should provision to a third party become necessary in the future, the Company will, in accordance with Article 17 of the PIPA, clearly inform the data subject of (i) the recipient, (ii) the purpose of provision, (iii) the categories of personal information provided, and (iv) the retention and use period, and will follow a procedure of obtaining separate consent. Provision required under the provisions of applicable law is excepted.

5.3

Distinction from cooperation with service providers. The entrustment described in Article 4.2 (where a trustee processes personal information for the Company's purposes and under the Company's instructions) does not constitute "provision to a third party" under this Article. This Article applies where a third party processes personal information for its own independent purposes.

Article 6 (Cross-Border Transfer of Personal Information)

6.1

In order to process personal information smoothly, the Company provides and entrusts personal information processing tasks overseas as set out below. Toss Payments is a domestic operator in the Republic of Korea and is therefore not included among the cross-border transfers under this Article.

TransfereeContactCountry of transferItems transferredPurpose of useMethod and timing of transferRetention period
Amazon Web Services, Inc.aws-korea-privacy@amazon.comUnited States (the Republic of Korea, Seoul (ap-northeast-2) region serves as the principal processing facility; processing may take place in another region designated by the Company in order to ensure the availability of the Service)email addresses and authentication tokens, and user data generated in the course of using the Serviceuser authentication (Cognito) and cloud server operation and management (EKS, S3, SQS, Secrets Manager, and the like)in real time over HTTPS (upon use of the Service)until withdrawal of membership
Anthropic PBCanthropic_privacy@kimchang.comUnited Statestext entered or received by users in the course of using the Serviceprovision of artificial intelligence featuresin real time over HTTPS (upon execution of an artificial intelligence feature)
Polar Software, Inc.privacy@polar.shUnited Statespayment identifiers, order identifiers, user email addresses, payment amounts, and payment datesprocessing and verification of payments in foreign currencyin real time over HTTPS (upon payment in foreign currency)five years under the Act on the Consumer Protection in Electronic Commerce
Google LLC (GA4)googlekrsupport@google.comUnited Statesanonymized visit dataService usage statisticsin real time over HTTPSup to 26 months
Hotjar Ltd.dpo@hotjar.comMaltamasked session dataUX analyticsin real time over HTTPS1 year
Meta Platforms, Inc.https://help.meta.com/support/privacy/United Statesbehavioural information (service visit history, advertising identifiers, device and browser information)measuring the performance of advertising placed by the Company and selecting advertising audiencesin real time over HTTPS (upon use of the Service)
Google LLC (Google Ads)googlekrsupport@google.comUnited Statesbehavioural information (service visit history, advertising identifiers, device and browser information)measuring the performance of advertising placed by the Company and selecting advertising audiencesin real time over HTTPS (upon use of the Service)

Legal basis for transfer abroad: Article 28-8(1)3 of the Personal Information Protection Act

6.2

Where the Company transfers personal information overseas, it implements such of the following safeguards as are applicable.

No.Safeguard
(1)Execution of Standard Contractual Clauses (SCCs) with transferees
(2)Obtaining the express consent of data subjects
(3)Transfers to countries subject to an adequacy decision of the European Commission
(4)Application of other exceptional grounds permitted under applicable law
(5)Compliance with the Google API Services User Data Policy

Trustees are contractually bound to implement the legal and technical measures necessary for the protection of personal information, and the Company reviews compliance on an ongoing basis in order to safeguard the rights of data subjects and prevent infringements.

6.3

Data subjects may refuse the cross-border transfer of their personal information by contacting help@digitalog.ai. However, where a cross-border transfer is essential to the provision of the Service, refusal may result in restrictions on the use of part or all of the Service.

6.4

The Company may provide features that integrate with Google APIs (such as Google OAuth and Google Calendar). Information collected through such integrations is used in accordance with Google's API Services User Data Policy, including the Limited Use Requirements. The Company strictly complies with that policy and does not use personal information received through Google APIs for any purpose other than the specified functions, such as authentication and calendar access.

Article 7 (Procedures and Methods for Destroying Personal Information)

7.1

Where personal information becomes unnecessary, for example because the retention period has elapsed or the purpose of processing has been achieved, the Company destroys the personal information without delay.

7.2

Where personal information must continue to be preserved under other laws notwithstanding the expiry of the retention period consented to by the data subject or the achievement of the purpose of processing, the Company transfers such personal information to a separate database or preserves it in a different storage location. Such personal information is not used for any purpose other than preservation, except as required by law.

7.3

Destruction procedure. Information entered by users is destroyed either immediately or after being stored for a certain period in accordance with internal policies and other applicable laws, once the retention period has elapsed or the purpose of processing has been achieved. Personal information is destroyed with the approval of the Chief Privacy Officer.

7.4

Method of destruction. Personal information processed by the Company is destroyed by the following methods.

  • (1) Where in the form of an electronic file: permanent deletion by means that render restoration impossible
  • (2) Records, printed matter, documents, and other recording media other than electronic files: shredding or incineration

Article 8 (Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercise)

8.1

Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time.

  • (1) Request to access personal information
  • (2) Request to correct errors and other inaccuracies
  • (3) Request for deletion
  • (4) Request to suspend processing
  • (5) Request to withdraw consent
  • (6) Request to refuse, or to obtain an explanation of, an automated decision
  • (7) Request for information concerning the processing of personal information
  • (8) Request to withdraw consent to the cross-border transfer of personal information
8.1A

Where the Company makes a fully automated decision that materially affects the rights or obligations of a data subject, the Company will provide notice of that fact in advance and will guarantee the data subject's right to refuse the decision or to request an explanation of it.

8.2

Method of exercising rights. Rights may be exercised in writing, by electronic mail, by facsimile, or by similar means pursuant to Article 41(1) of the Enforcement Decree of the PIPA, and the Company will act within the period prescribed by applicable law.

  • (1) Access, correction, deletion, and withdrawal of membership may be carried out directly by the user through the account settings within the Service.
  • (2) Other rights, such as suspension of processing and the refusal of, or request for an explanation of, an automated decision, may be exercised by contacting the Chief Privacy Officer or the responsible department identified in Article 12.
  • (3) The Company verifies the identity of the requesting party by reasonable means, and where a request is made by an agent, the Company may require a power of attorney and the agent's identification.
8.3

Requests to access personal information and to suspend processing may be subject to limitations on the data subject's rights under Article 35(4) and Article 37(2) of the PIPA.

8.4

Where other laws expressly specify that particular personal information is to be collected, deletion of that personal information may not be requested in a request for correction or deletion.

Article 9 (Processing of Children's Personal Information)

The Company does not process the personal information of children under the age of 16. This standard satisfies the requirements for the protection of children under all applicable laws, including Article 22-2 of the Korean PIPA, Article 8 of the EU GDPR, the UK Data Protection Act 2018, and the United States COPPA. Upon registration, users represent that they are at least 16 years of age and have the legal capacity to enter into this agreement. Where it is confirmed after registration that the age requirement is not met, the Company will immediately terminate the account and destroy the personal information collected.

Article 10 (Measures to Ensure the Security of Personal Information)

10.1

In order to ensure the security of personal information, the Company implements the following measures, including technical and organizational measures that meet industry standards.

CategoryMeasures
(1) Administrative measuresestablishment and implementation of an internal management plan, minimization and management of access rights for personal information handlers, and the provision of personal information protection training
(2) Technical measuresmanagement of access rights to, and access control for, personal information processing systems, encryption of stored data, encrypted communication in transit, installation of security programs and periodic updates and inspections, and operation of intrusion prevention and detection systems
(3) Physical measuresthe facilities in which personal information is stored and processed are located in the data centres of the Company's cloud service provider, and the physical security of those facilities is governed by that provider's security framework. The Company implements access controls for its work devices and office premises
10.2

The Company does its utmost to manage users' personal information securely and makes efforts to protect personal information beyond the safeguards required under the Personal Information Protection Act. The Company conducts security reviews for information protection, including code-level security issue reviews.

10.3

No security system can be perfect, and it cannot be guaranteed that information in transit over the internet or stored on systems is entirely safe from external intrusion. However, the Company bears no liability for the leakage or exposure of personal information arising from a user's own intent or negligence, a user's failure to manage login credentials, or other causes outside the Company's scope of control.

10.4

Notification of personal information breaches. Upon becoming aware that personal information has been lost, stolen, or leaked, the Company will, pursuant to Article 34 of the PIPA and Article 40 of its Enforcement Decree, notify affected data subjects of the following matters without delay (or, where justifiable grounds exist, without delay after those grounds are resolved) by reasonable means such as email, in-Service notification, or written notice. Where the number of affected data subjects meets or exceeds the threshold prescribed by applicable law, the Company will report the breach to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) and will post notice on its website for at least seven days.

  • (1) The categories of personal information leaked
  • (2) The time at which, and circumstances in which, the leak occurred
  • (3) Information on steps data subjects may take to minimize harm
  • (4) The Company's response measures and remediation procedures
  • (5) The department and contact details for receiving reports of harm from data subjects

Article 11 (Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof)

11.1

The Company uses "cookies" in order to provide users with conveniences essential to their use of the Service, such as maintaining login sessions.

11.2

Types and purposes of cookies. The Company uses cookies as follows.

  • (1) Essential cookies — necessary for the provision of the Service and therefore cannot be refused.

(a) maintaining login status and managing authentication tokens (access, id, refresh)

(b) storing language settings and user preferences

(c) maintaining the selected connected Instagram account

(d) maintaining the payment session, limited to the checkout screen

  • (2) Analytics cookies — usage statistics and UX analysis for improving the quality of the Service. Details are governed by Article 11.3.
  • (3) Advertising cookies — measuring the performance of advertising placed by the Company and displaying interest-based advertising. Details and the method of refusal are governed by Article 11.6(4).
11.3

Analytics tools. The Company may use analytics tools such as Google Analytics and Hotjar in order to improve the quality of the Service. The items, purposes, and retention periods of the information collected by each tool are specified in the entrustment provisions of Article 4 and the cross-border transfer provisions of Article 6.

11.4

Refusal of cookies. Data subjects may allow or block cookies through their web browser settings. However, refusing essential cookies may cause difficulties in using the Service, such as logging in and making payments. The method of refusing advertising cookies is governed by Article 11.6(4).

11.5

The Company does not currently take any specific action in response to Do Not Track (DNT) signals sent by certain web browsers. Should the Company introduce in-Service cookie and tracking consent management features in the future, the relevant provisions of this Article will be updated.

11.6

Online interest-based advertising

  • (1) The Company collects and uses online behavioural information in order to measure the performance of the advertising it places and to select advertising audiences.
  • (2) The categories of behavioural information the Company collects are as follows. (a) service visit history and page view records; (b) advertising identifiers (such as cookies) and device and browser information; (c) records of the display and selection of advertisements and of resulting visits to the Service.
  • (3) Behavioural information is collected through the measurement tools of advertising providers installed by the Company in the Service and is transmitted to those providers; the providers and the countries of transfer are as set out in Article 6.1. The Company uses such information solely for measuring advertising performance and selecting advertising audiences.
  • (4) A data subject may refuse the collection of behavioural information or the display of interest-based advertising by the following means. (a) blocking cookies in the settings of the web browser, which blocks the collection of behavioural information itself; (b) the advertising settings provided by the advertising providers, through which the display of interest-based advertising may be refused in the Meta and Google account advertising settings, although the collection of behavioural information may continue in that case. Refusal does not affect any other use of the Service.
  • (5) Enquiries and requests to refuse in relation to behavioural information may be directed to the personal information protection officer or the responsible department set out in Article 12.

Article 12 (Chief Privacy Officer and Responsible Department)

12.1

The Company designates a Chief Privacy Officer as set out below, who assumes overall responsibility for matters relating to the processing of personal information and handles complaints and remediation for data subjects in connection with such processing.

Chief Privacy Officer

  • Name: Donggyu Son
  • Telephone: +82-70-4106-4243
  • Email: help@digitalog.ai

Department handling personal information grievances

  • Department: Development Office
  • Contact: Personal Information Protection Officer
  • Telephone: +82-70-4106-4243
  • Email: help@digitalog.ai
12.2

Data subjects may direct any inquiries, complaints, or requests for remediation relating to the protection of personal information arising from their use of the Company's Service to the Chief Privacy Officer or the responsible department. The Company will respond to and address such inquiries without delay.

12.3

Please take care not to provide sensitive personal information (such as resident registration numbers, health information, or political opinions) when making an inquiry.

Except where required by law or where the data subject has given express consent, the Company does not collect or process the following categories of sensitive information.

  • (1) Unique identifying information such as social security numbers and passport numbers
  • (2) Health information and medical records
  • (3) Political opinions, religion, and philosophical beliefs
  • (4) Race and ethnicity
  • (5) Biometric or genetic information
  • (6) Sexual orientation or information concerning sex life
  • (7) Criminal history or investigation records
  • (8) Trade union membership

Where a data subject voluntarily provides such sensitive information, that information is processed only within a strictly limited scope in accordance with this Policy and applicable law, and is destroyed without delay where it is not necessary.

12.4

Accessibility of this Policy: this Policy is made publicly available and may be viewed at any time without logging in. The latest version is available at the following links: www.conma.ai/en/privacy and www.digitalog.ai/en/terms-and-privacy?type=privacy

12.5

Language and governing text. This Policy is prepared in standard Korean, the official language of the Republic of Korea. Where a translation into English or any other language is provided, it is provided solely for the convenience of users; in the event of any inconsistency between the Korean version and a translation, the Korean version shall prevail. In any legal dispute, including litigation and arbitration, this Policy shall be construed on the basis of the Korean version, and no translation shall serve as a basis for its interpretation. This is subject to Article 17, where the language version of a particular region is required to prevail for data subjects in that region, or where applicable law so requires.

Article 13 (Remedies for Infringement of the Rights and Interests of Data Subjects)

13.1

Where a data subject has any concern about, or has suffered, an infringement relating to the protection of personal information, the data subject may contact the Company by the means set out below, or may request dispute resolution, consultation, or report the matter to the data protection supervisory authority of the relevant jurisdiction.

The Company respects the right of data subjects to informational self-determination and makes its best efforts to protect their rights and provide remedies. Data subjects may also contact the Chief Privacy Officer or the responsible department identified in Article 12 at any time to raise complaints, make inquiries, or exercise their rights.

13.2

Data subjects within the Republic of Korea

  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.privacy.go.kr
  • Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
  • Supreme Prosecutors' Office, Cyber Investigation Division: 1301 (no area code) / www.spo.go.kr
  • Korean National Police Agency, Cyber Investigation Bureau: 182 (no area code) / ecrm.police.go.kr
13.3

Residents of the European Union (EU): you may lodge a complaint with the supervisory authority (Data Protection Authority, DPA) of your Member State. A list of DPAs is available at edpb.europa.eu/about-edpb/about-edpb/members_en. Under the GDPR, you may lodge an objection with, or seek legal remedy through, the competent authority.

13.4

Residents of the United Kingdom (UK): Information Commissioner's Office (ICO) — ico.org.uk

13.5

Residents of California, United States: California Privacy Protection Agency (CPPA) — cppa.ca.gov

13.6

Residents of Japan: 個人情報保護委員会 (Personal Information Protection Commission, PPC) — www.ppc.go.jp

13.7

Other regions: data subjects may lodge a complaint with the data protection supervisory authority in their own jurisdiction and may pursue administrative or legal remedies available under applicable law.

Article 14 (Links to Other Websites or Services)

14.1

The Company's websites may contain links to other websites or services. In such cases, the Company is not responsible for the privacy practices of the linked external websites or services.

14.2

When you navigate to an external site, please be sure to review that site's privacy policy. This Privacy Policy applies only to the Service operated by the Company.

Article 15 (End User Notice)

15.1

Certain parts of the Company's Service may be designed for use by an organization (for example, a data subject's employer). Where the Service is provided through an organization, that organization holds administrative authority over the use of the Service as the Owner or Admin of the workspace, and inquiries relating to personal information should be directed to that organization's administrator. A data subject's use of the Service may be subject to that organization's policies, and the Company is not responsible for the privacy or security practices implemented by the administrating organization.

15.2

Owners and Admins may hold the following powers.

  • (1) Requiring a reset of a data subject's account password
  • (2) Restricting, suspending, or terminating access to the Service
  • (3) Accessing information within an account
  • (4) Installing or removing third-party applications and other integrations
15.3

Where a data subject uses the Service with an email address provided by an organization, the owner of that domain (such as an employer) may subsequently assert administrative authority over the account and the use of the Service, in which case the data subject will be separately notified. If you do not wish an administrator to hold administrative authority over your account or use of the Service, you must register for and access the Service using a personal email address.

15.4

Recipients of messages that a user sends through the Service may not be members of the Company. In such cases, the sending of the message and the use of links contained in it are governed by the policies determined by the user who sent it, and notifications to recipients, the obtaining of their consent, and other measures required under applicable law are performed by that user. The categories of information that the Company processes in order to measure sending performance are as set out in Article 2.2(5), and enquiries in this regard may be directed to help@digitalog.ai.

Article 16 (Amendments to this Privacy Policy)

16.1

This Privacy Policy applies from the effective date stated herein. The Company may amend this Privacy Policy, including in order to reflect changes in law or in the Service.

Where this Privacy Policy is amended, the Company will post the changes on this page, and the amended Privacy Policy will take effect seven days after posting.

16.2

However, where changes materially affecting the rights of data subjects arise, as set out below, the Company will give prior notice by separate means at least 30 days in advance.

  • (1) Changes to the categories of personal information collected
  • (2) Additions to or changes in the purposes for which personal information is used
  • (3) Changes relating to provision to third parties or cross-border transfers
  • (4) Changes to retention periods, procedures for exercising rights, methods of consent, or other rights of data subjects
16.3

Such material changes will be notified in advance by one or more of the following methods.

  • (1) In-Service notification
  • (2) Posting of an announcement
  • (3) Individual notice sent to the email address registered at the time of sign-up
16.4

For relatively minor changes (such as editorial clarifications or corrections to statutory citations), posting on this page may suffice. The Company retains previous versions of the Privacy Policy so that data subjects may review them.

16.5

Where a matter requiring the data subject's consent under applicable law is changed, the Company obtains separate consent in respect of that matter. For other changes, where the Company gives notice of the change under Article 16.1 or 16.3 and the data subject does not expressly indicate refusal before the effective date, the data subject is deemed to have agreed to the amended Policy. A data subject who does not agree to a change may at any time discontinue use of the Service and withdraw their account.

16.6

(Special provision on the effective date) This Policy takes effect on September 16, 2026. However, the matters relating to online interest-based advertising — the advertising-related part of Article 1.1(6), the parts of Article 6.1 relating to Meta Platforms, Inc. and Google LLC (Google Ads), Article 11.2(3), the part of Article 11.4 relating to advertising cookies, and Article 11.6 — take effect on October 16, 2026.

Article 17 (Supplementary Regional Provisions)

17.1

Notice of privacy rights for California residents (CCPA/CPRA)

  • (1) The Company complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) as amended. The Company does not sell personal information, and data subjects may exercise the following rights.
  • - The right to request access to, and a copy of, the personal information collected
  • - The right to request deletion of personal information
  • - The right to opt out of the sale or sharing of personal information (Do Not Sell or Share My Personal Information)
  • - The right not to be discriminated against for exercising these rights
  • (2) Requests under the CCPA may be submitted to help@digitalog.ai.
  • (3) The Company may request an email address or government-issued identification in order to verify identity, and rights may also be exercised through an authorized agent. Requests are generally processed within 45 days.
17.2

Residents of the European Economic Area (EEA) and Switzerland (GDPR)

  • (1) The Company complies with the General Data Protection Regulation (GDPR) and related national laws, and guarantees the rights conferred by Articles 15 to 22 of the GDPR (access, rectification, erasure, restriction of processing, portability, objection, and rights relating to automated decision-making).
  • (2) Allocation of roles: with respect to personal information the Company collects directly from users, the Company acts as a Data Controller. Where a user (for example, an agency) uses the Service to process the personal information of its own clients or followers, the Company acts as a Data Processor on behalf of that user, and a separate Data Processing Addendum may apply.
17.3

Residents of the United Kingdom (UK GDPR and the Data Protection Act 2018)

  • (1) Following Brexit in 2020, the United Kingdom is not subject to the EU GDPR; the UK GDPR and the Data Protection Act 2018 apply instead. The Company complies with those laws and guarantees the rights of data subjects (access, rectification, erasure, restriction of processing, portability, objection, and rights relating to automated decision-making).
  • (2) The supervisory authority for UK residents is the Information Commissioner's Office (ICO, ico.org.uk).
17.4

Residents of Japan (APPI)

  • (1) The Company complies with the laws and regulations of Japan, including the Act on the Protection of Personal Information (APPI).
  • (2) The Company assumes primary responsibility for the management of personal data used jointly with affiliates or third parties.
  • (3) The Company does not provide the personal information of Japanese residents to third parties for marketing purposes without prior consent.
17.5

Residents of the Republic of Korea

  • (1) The Company complies with applicable laws including the Personal Information Protection Act (PIPA), the Use and Protection of Credit Information Act, the Electronic Financial Transactions Act, the Act on the Consumer Protection in Electronic Commerce, Etc., the Protection of Communications Secrets Act, and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.
  • (2) Where any provision of this Policy conflicts with a mandatory provision of the laws of the Republic of Korea, that mandatory provision shall prevail.

Article 18 (Use of Meta Platform Data and Requests for Data Deletion)

18.1

The Service may use Meta platforms, including Facebook Login and the Instagram Graph API, in order to provide certain login and data synchronization features. All data received from Meta platforms is processed in strict compliance with the Meta Platform Terms and related policies.

18.2

The Company adheres to the following principles.

  • (1) The Company accesses only data that the user has expressly authorized.
  • (2) The Company uses Meta data solely for the purpose of providing the Service features requested by the user.
  • (3) The Company does not sell data received from Meta to third parties.
  • (4) Users may withdraw access to Meta data at any time through their Meta account settings or the disconnection feature within the Service.
18.3

Users wishing to request deletion of data received from Meta platforms may contact help@digitalog.ai, and the Company will promptly delete such data in accordance with the Meta Platform Terms and applicable privacy laws.

Article 19 (Processing of Payment and Credit Information)

19.1

The Company does not itself collect or store sensitive payment information such as full card numbers, CVCs, or card expiry dates; it entrusts payment processing to, or carries it out through, payment processors. Payments in Korean won are processed by Toss Payments Co., Ltd., a payment gateway registered under the Electronic Financial Transactions Act, which complies with PCI-DSS (Payment Card Industry Data Security Standard). Payments in foreign currency are processed by Polar Software, Inc. (United States) acting as the merchant of record; in such cases the Company provides Polar Software, Inc. with the minimum information necessary to verify the transaction, such as payment identifiers, order identifiers, and the user's email address.

19.2

Information retained by Toss Payments

  • Full card number
  • Card expiry date
  • CVC
  • Cardholder name
19.3

Information retained by the Company

(1) Information relating to recurring payments — retained while the user uses paid services

  • Billing key (the payment identifier issued by Toss Payments): stored with AES-256 encryption
  • Masked card number (for example, **** **** **** 1234)

(2) Payment transaction metadata

  • Transaction ID and approval number
  • Payment amount and payment method type (card, account transfer, virtual account, or simple payment)
  • Payment date and time
  • Billing contact name and email address
19.4

Legal basis and retention periods

  • Payment transaction records: 5 years (Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc.)
  • Credit information processing records: 3 years (Article 22 of the Enforcement Decree of the Use and Protection of Credit Information Act)
  • Electronic financial transaction records: 5 years (Article 22 of the Electronic Financial Transactions Act)
19.5

Application of the Credit Information Act. Certain payment-related information constitutes "credit information" under the Use and Protection of Credit Information Act, and the Company complies with the obligations regarding collection, use, provision, and protection prescribed by that Act.

19.6

Handling of payment failures. Where an automatic payment fails, the Company may retry the payment for a certain period. During the retry period, the minimum information necessary to confirm the payment, such as the reason for failure, is temporarily retained and is then updated or deleted once the payment succeeds or the user changes their payment method. Where a user cancels a subscription or withdraws membership, the billing key and masked card number described in Article 19.3(1) are destroyed without delay unless a preservation obligation applies under applicable law.

Article 20 (Service Outputs)

20.1

The Company analyzes data from a user's own connected accounts, together with public data of IG Business/Creator accounts made publicly available through the Instagram Graph API, in order to provide insights, periodic reports, competitor comparison reports, and industry average and benchmark metrics. The composition of such outputs and the rights of use and ownership in them are governed by Article 5-2 (Service Outputs) of the Terms of Service.

20.2

Industry average and benchmark metrics are provided as statistically aggregated results processed so that individual data subjects cannot be identified.

20.3

Where the Company wishes to use the case of a particular data subject for the promotion of the Service, it will obtain that data subject's prior consent.

20.4

Inquiries or objections relating to this Article may be submitted to help@digitalog.ai.

Contact

  • Company: Digitalog Technologies Co., Ltd.
  • Chief Executive Officer: Donggyu Son
  • Address: Room 210, Jena-dong, 245 Dongbaekjungang-ro, Giheung-gu, Yongin-si, Gyeonggi-do, Republic of Korea
  • Email: help@digitalog.ai
  • Telephone: +82-70-4106-4243
  • Business Registration Number: 759-86-02818
  • Mail-Order Sales Registration Number: 2025-Yongin Giheung-0063

Published: August 15, 2026 / Effective: September 16, 2026 (the effective date of certain provisions is governed by Article 16.6)