Effective: July 2, 2026 · Last Amended: July 2, 2026 · Published by: Digitalog Technologies Co., Ltd.
Digitalog Technologies Co., Ltd. (the "Company") regards the personal information of data subjects as a matter of the utmost importance and seeks to be transparent about how such information is collected, used, and shared.
This Privacy Policy applies to information the Company collects when you use any of its products and services (collectively, the "Service"), or when you otherwise interact with the Company (such as attending Company events or communicating with the Company). Where a separate privacy policy applies, that policy shall prevail.
In order to protect the freedom and rights of data subjects, the Company processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act of the Republic of Korea (the "PIPA") and other applicable laws and regulations.
This Policy covers the categories of information the Company collects, how it is used and disclosed, how it is stored and protected, how long it is retained, how data subjects may access and control their information, and cross-border transfers.
This document is a privacy policy grounded in the laws of the Republic of Korea (including the PIPA). With respect to the processing of information relating to users residing in other jurisdictions, such as Europe, the United States, and Japan, the supplementary provisions of Article 17 apply in accordance with the relevant laws of those countries and regions (GDPR, CCPA, APPI, and the like).
If you do not agree to this Policy, please discontinue your use of the Service and any other form of interaction with the Company.
Where the Service is provided under an agreement with an organization to which the data subject belongs (for example, an employer), that organization may control the information processed within the Service. For details, please refer to the "End User Notice" in Article 15 of this Policy.
The Company processes personal information for the purposes set out below. Personal information being processed will not be used for any purpose other than those set out below, and where the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the PIPA.
The Company collects personal information when a data subject uses the Service or provides information directly to the Company, and when it receives information from other sources.
Categories of personal information collected
(1) Information you provide directly
(2) Information collected automatically through your use of the Service
(3) Information collected from connected third-party platforms (Meta)
(4) Information collected from other sources
Right to refuse consent and consequences of refusal
Users have the right to refuse to provide optional items. However, if you refuse to provide optional items, your use of certain Service features may be restricted. Required items (email address and password) are indispensable for registration and the provision of core Service functionality, and accordingly the Service cannot be used if you refuse to provide them.
Methods of collecting personal information
The Company processes and retains personal information within the retention and use period prescribed by law or within the retention and use period consented to by the data subject at the time of collection.
The processing and retention periods for each category of personal information are as follows.
Where the Company is required by applicable law to preserve personal information rather than destroy it, the Company securely retains such personal information for the periods set out below.
In the Republic of Korea, the statutory grounds and periods for preservation are as follows.
(1) Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc.
(2) Article 15-2 of the Protection of Communications Secrets Act
(3) Article 22 of the Enforcement Decree of the Use and Protection of Credit Information Act
(4) Article 22 of the Electronic Financial Transactions Act
(5) In other jurisdictions, including the European Union, the United States, and Japan, information is likewise retained for the periods prescribed by the applicable laws of the relevant region.
Personal information whose retention period has expired or whose purpose of processing has been achieved is destroyed without delay in accordance with Article 7, pursuant to the PIPA and other applicable laws.
Where immediate destruction is not technically possible, for example because the information resides in backup systems, the Company stores such information securely, isolates it from external access and further use, and destroys it immediately once deletion becomes possible.
The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information) and, as a general rule, does not provide or disclose personal information externally without the prior consent of the data subject. The following are exceptions.
(1) Where the data subject has consented in advance
The Company follows a procedure of clearly informing the data subject of the recipient, the purpose of provision, the categories of personal information provided, and the retention and use period, and obtaining consent.
(2) Where information is disclosed to other users of the Service
(3) Where required under the provisions of applicable law, or where a request is made by an investigative authority in accordance with the procedures and methods prescribed by law for investigative purposes
(4) Business transfers, etc.: in the event of a merger, sale of assets, financing, or acquisition of the business, collected personal information may be transferred, in which case the Company will provide notice to data subjects, including any available choices.
(5) Disclosure to affiliates: this is not applicable at present. Should information be disclosed to affiliates in the future, the protections set out in this Policy will apply.
Entrustment of personal information processing (Article 26 of the PIPA)
In order to provide the Service smoothly, the Company entrusts personal information processing tasks to external trustees as set out below. The Company enters into entrustment agreements with each trustee specifying the matters set out in each subparagraph of Article 26(1) of the PIPA, and supervises whether trustees process personal information securely.
The entrustment of personal information processing is governed by Article 26 of the PIPA and is legally distinct from the "provision to third parties" addressed in Article 5 of this Policy (Article 17 of the PIPA).
The Company does not currently provide personal information of data subjects to third parties for any purpose other than those specified in subparagraphs (2) through (5) of Article 4.1. Should this become necessary in the future, the Company will clearly inform data subjects of the recipient, purpose, items, and retention and use period and obtain their consent, or otherwise proceed in accordance with applicable law.
The Company does not provide personal information to third parties for those third parties' own independent purposes.
Should provision to a third party become necessary in the future, the Company will, in accordance with Article 17 of the PIPA, clearly inform the data subject of (i) the recipient, (ii) the purpose of provision, (iii) the categories of personal information provided, and (iv) the retention and use period, and will follow a procedure of obtaining separate consent. Provision required under the provisions of applicable law is excepted.
Distinction from cooperation with service providers. The entrustment described in Article 4.2 (where a trustee processes personal information for the Company's purposes and under the Company's instructions) does not constitute "provision to a third party" under this Article. This Article applies where a third party processes personal information for its own independent purposes.
In order to process personal information smoothly, the Company provides and entrusts personal information processing tasks overseas as set out below. Toss Payments is a domestic operator in the Republic of Korea and is therefore not included among the cross-border transfers under this Article.
Legal basis for cross-border transfer: Article 28-8(1), subparagraph 3(a) of the PIPA, together with the consent of the data subject
When transferring personal information overseas, the Company implements the following legal safeguards.
Trustees are contractually bound to implement the legal and technical measures necessary for the protection of personal information, and the Company reviews compliance on an ongoing basis in order to safeguard the rights of data subjects and prevent infringements.
Data subjects may refuse the cross-border transfer of their personal information by contacting help@digitalog.ai. However, where a cross-border transfer is essential to the provision of the Service, refusal may result in restrictions on the use of part or all of the Service.
The Company may provide features that integrate with Google APIs (such as Google OAuth and Google Calendar). Information collected through such integrations is used in accordance with Google's API Services User Data Policy, including the Limited Use Requirements. The Company strictly complies with that policy and does not use personal information received through Google APIs for any purpose other than the specified functions, such as authentication and calendar access.
Where personal information becomes unnecessary, for example because the retention period has elapsed or the purpose of processing has been achieved, the Company destroys the personal information without delay.
Where personal information must continue to be preserved under other laws notwithstanding the expiry of the retention period consented to by the data subject or the achievement of the purpose of processing, the Company transfers such personal information to a separate database or preserves it in a different storage location. Such personal information is not used for any purpose other than preservation, except as required by law.
Destruction procedure. Information entered by users is destroyed either immediately or after being stored for a certain period in accordance with internal policies and other applicable laws, once the retention period has elapsed or the purpose of processing has been achieved. Personal information is destroyed with the approval of the Chief Privacy Officer.
Method of destruction. Personal information processed by the Company is destroyed by the following methods.
Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time.
Where the Company makes a fully automated decision that materially affects the rights or obligations of a data subject, the Company will provide notice of that fact in advance and will guarantee the data subject's right to refuse the decision or to request an explanation of it.
Method of exercising rights. Rights may be exercised in writing, by electronic mail, by facsimile, or by similar means pursuant to Article 41(1) of the Enforcement Decree of the PIPA, and the Company will act within the period prescribed by applicable law.
Requests to access personal information and to suspend processing may be subject to limitations on the data subject's rights under Article 35(4) and Article 37(2) of the PIPA.
Where other laws expressly specify that particular personal information is to be collected, deletion of that personal information may not be requested in a request for correction or deletion.
The Company does not process the personal information of children under the age of 16. This standard satisfies the requirements for the protection of children under all applicable laws, including Article 22-2 of the Korean PIPA, Article 8 of the EU GDPR, the UK Data Protection Act 2018, and the United States COPPA. Upon registration, users represent that they are at least 16 years of age and have the legal capacity to enter into this agreement. Where it is confirmed after registration that the age requirement is not met, the Company will immediately terminate the account and destroy the personal information collected.
In order to ensure the security of personal information, the Company implements the following measures, including technical and organizational measures that meet industry standards.
(1) Administrative measures: establishment and implementation of an internal management plan, operation of a dedicated organization, regular staff training, and minimization of access privileges
(2) Technical measures:
(3) Physical measures: access control for computer rooms, data storage rooms, and similar facilities, designation of secure areas, and establishment of disaster recovery plans
The Company makes its best efforts to manage users' personal information securely and undertakes additional privacy protection efforts beyond the security measures required by the PIPA. The Company conducts periodic security reviews, including penetration testing and code-level security issue reviews, and also carries out personal information management consulting and training.
No security system can be perfect, and it cannot be guaranteed that information in transit over the internet or stored on systems is entirely safe from external intrusion. However, the Company bears no liability for the leakage or exposure of personal information arising from a user's own intent or negligence, a user's failure to manage login credentials, or other causes outside the Company's scope of control.
Notification of personal information breaches. Upon becoming aware that personal information has been lost, stolen, or leaked, the Company will, pursuant to Article 34 of the PIPA and Article 40 of its Enforcement Decree, notify affected data subjects of the following matters without delay (or, where justifiable grounds exist, without delay after those grounds are resolved) by reasonable means such as email, in-Service notification, or written notice. Where the number of affected data subjects meets or exceeds the threshold prescribed by applicable law, the Company will report the breach to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) and will post notice on its website for at least seven days.
The Company uses "cookies" in order to provide users with conveniences essential to their use of the Service, such as maintaining login sessions.
Purposes of cookie use. The Company uses cookies for the following essential functions.
Analytics tools. The Company may use analytics tools such as Google Analytics and Hotjar in order to improve the quality of the Service. The items, purposes, and retention periods of the information collected by each tool are specified in the entrustment provisions of Article 4 and the cross-border transfer provisions of Article 6.
Refusal of cookies. Data subjects may allow or block cookies through their web browser settings. However, refusing essential cookies may cause difficulties in using the Service, including login and payment.
The Company does not currently take any specific action in response to Do Not Track (DNT) signals sent by certain web browsers. Should the Company introduce in-Service cookie and tracking consent management features in the future, the relevant provisions of this Article will be updated.
The Company designates a Chief Privacy Officer as set out below, who assumes overall responsibility for matters relating to the processing of personal information and handles complaints and remediation for data subjects in connection with such processing.
Chief Privacy Officer
Department handling personal information grievances
Data subjects may direct any inquiries, complaints, or requests for remediation relating to the protection of personal information arising from their use of the Company's Service to the Chief Privacy Officer or the responsible department. The Company will respond to and address such inquiries without delay.
Please take care not to provide sensitive personal information (such as resident registration numbers, health information, or political opinions) when making an inquiry.
Except where required by law or where the data subject has given express consent, the Company does not collect or process the following categories of sensitive information.
Where a data subject voluntarily provides such sensitive information, that information is processed only within a strictly limited scope in accordance with this Policy and applicable law, and is destroyed immediately where it is not necessary.
Accessibility of this Policy: this Policy is made publicly available and may be viewed at any time without logging in. The latest version is available at the following links: www.conma.ai/en/privacy and www.digitalog.ai/en/terms-and-privacy?type=privacy
Language and governing text. This Policy is prepared in standard Korean, the official language of the Republic of Korea. Where a translation into English or any other language is provided, it is provided solely for the convenience of users; in the event of any inconsistency between the Korean version and a translation, the Korean version shall prevail. In any legal dispute, including litigation and arbitration, this Policy shall be construed on the basis of the Korean version, and no translation shall serve as a basis for its interpretation. This is subject to Article 17, where the language version of a particular region is required to prevail for data subjects in that region, or where applicable law so requires.
Where a data subject has any concern about, or has suffered, an infringement relating to the protection of personal information, the data subject may contact the Company by the means set out below, or may request dispute resolution, consultation, or report the matter to the data protection supervisory authority of the relevant jurisdiction.
The Company respects the right of data subjects to informational self-determination and makes its best efforts to protect their rights and provide remedies. Data subjects may also contact the Chief Privacy Officer or the responsible department identified in Article 12 at any time to raise complaints, make inquiries, or exercise their rights.
Data subjects within the Republic of Korea
Residents of the European Union (EU): you may lodge a complaint with the supervisory authority (Data Protection Authority, DPA) of your Member State. A list of DPAs is available at edpb.europa.eu/about-edpb/about-edpb/members_en. Under the GDPR, you may lodge an objection with, or seek legal remedy through, the competent authority.
Residents of the United Kingdom (UK): Information Commissioner's Office (ICO) — ico.org.uk
Residents of California, United States: California Privacy Protection Agency (CPPA) — cppa.ca.gov
Residents of Japan: 個人情報保護委員会 (Personal Information Protection Commission, PPC) — www.ppc.go.jp
Other regions: data subjects may lodge a complaint with the data protection supervisory authority in their own jurisdiction and may pursue administrative or legal remedies available under applicable law.
The Company's websites may contain links to other websites or services. In such cases, the Company is not responsible for the privacy practices of the linked external websites or services.
When you navigate to an external site, please be sure to review that site's privacy policy. This Privacy Policy applies only to the Service operated by the Company.
Certain parts of the Company's Service may be designed for use by an organization (for example, a data subject's employer). Where the Service is provided through an organization, that organization holds administrative authority over the use of the Service as the Owner or Admin of the workspace, and inquiries relating to personal information should be directed to that organization's administrator. A data subject's use of the Service may be subject to that organization's policies, and the Company is not responsible for the privacy or security practices implemented by the administrating organization.
Owners and Admins may hold the following powers.
Where a data subject uses the Service with an email address provided by an organization, the owner of that domain (such as an employer) may subsequently assert administrative authority over the account and the use of the Service, in which case the data subject will be separately notified. If you do not wish an administrator to hold administrative authority over your account or use of the Service, you must register for and access the Service using a personal email address.
This Privacy Policy applies from the effective date stated herein. The Company may amend this Privacy Policy, including in order to reflect changes in law or in the Service.
Where this Privacy Policy is amended, the Company will post the changes on this page, and the amended Privacy Policy will take effect seven days after posting.
However, where changes materially affecting the rights of data subjects arise, as set out below, the Company will give prior notice by separate means at least 30 days in advance.
Such material changes will be notified in advance by one or more of the following methods.
For relatively minor changes (such as editorial clarifications or corrections to statutory citations), posting on this page may suffice. The Company retains previous versions of the Privacy Policy so that data subjects may review them.
For material changes falling under any subparagraph of Article 16.2, the Company will seek the separate consent of data subjects to the changes, and where a data subject does not consent, the Company will not carry out the processing of personal information to which those changes relate. For minor changes, where the Company gives notice of the changes in accordance with Article 16.1 and the data subject does not expressly object before the date of application, the data subject shall be deemed to have consented to the amended Policy. A data subject who does not agree with the changes may discontinue use of the Service and withdraw their account at any time.
Notice of privacy rights for California residents (CCPA/CPRA)
Residents of the European Economic Area (EEA) and Switzerland (GDPR)
Residents of the United Kingdom (UK GDPR and the Data Protection Act 2018)
Residents of Japan (APPI)
Residents of the Republic of Korea
The Service may use Meta platforms, including Facebook Login and the Instagram Graph API, in order to provide certain login and data synchronization features. All data received from Meta platforms is processed in strict compliance with the Meta Platform Terms and related policies.
The Company adheres to the following principles.
Users wishing to request deletion of data received from Meta platforms may contact help@digitalog.ai, and the Company will promptly delete such data in accordance with the Meta Platform Terms and applicable privacy laws.
The Company entrusts the collection, storage, and processing of sensitive payment information, such as full card numbers, CVCs, and card expiry dates, to Toss Payments Co., Ltd. Toss Payments is a payment gateway registered under the Electronic Financial Transactions Act and complies with the Payment Card Industry Data Security Standard (PCI-DSS).
Information retained by Toss Payments
Information retained by the Company
(1) Information relating to recurring payments — retained while the user uses paid services
(2) Payment transaction metadata
Legal basis and retention periods
Application of the Credit Information Act. Certain payment-related information constitutes "credit information" under the Use and Protection of Credit Information Act, and the Company complies with the obligations regarding collection, use, provision, and protection prescribed by that Act.
Handling of payment failures. Where an automatic payment fails, the Company may retry the payment for a certain period. During the retry period, the minimum information necessary to confirm the payment, such as the reason for failure, is temporarily retained and is then updated or deleted once the payment succeeds or the user changes their payment method. Where a user cancels a subscription or withdraws membership, the billing key and masked card number described in Article 19.3(1) are destroyed without delay unless a preservation obligation applies under applicable law.
The Company analyzes data from a user's own connected accounts, together with public data of IG Business/Creator accounts made publicly available through the Instagram Graph API, in order to provide insights, periodic reports, competitor comparison reports, and industry average and benchmark metrics. The composition of such outputs and the rights of use and ownership in them are governed by Article 5-2 (Service Outputs) of the Terms of Service.
Industry average and benchmark metrics are provided as statistically aggregated results processed so that individual data subjects cannot be identified.
Where the Company wishes to use the case of a particular data subject for the promotion of the Service, it will obtain that data subject's prior consent.
Inquiries or objections relating to this Article may be submitted to help@digitalog.ai.