Conma Privacy Policy

Effective: July 2, 2026 · Last Amended: July 2, 2026 · Published by: Digitalog Technologies Co., Ltd.

Digitalog Technologies Co., Ltd. (the "Company") regards the personal information of data subjects as a matter of the utmost importance and seeks to be transparent about how such information is collected, used, and shared.

This Privacy Policy applies to information the Company collects when you use any of its products and services (collectively, the "Service"), or when you otherwise interact with the Company (such as attending Company events or communicating with the Company). Where a separate privacy policy applies, that policy shall prevail.

In order to protect the freedom and rights of data subjects, the Company processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act of the Republic of Korea (the "PIPA") and other applicable laws and regulations.

This Policy covers the categories of information the Company collects, how it is used and disclosed, how it is stored and protected, how long it is retained, how data subjects may access and control their information, and cross-border transfers.

This document is a privacy policy grounded in the laws of the Republic of Korea (including the PIPA). With respect to the processing of information relating to users residing in other jurisdictions, such as Europe, the United States, and Japan, the supplementary provisions of Article 17 apply in accordance with the relevant laws of those countries and regions (GDPR, CCPA, APPI, and the like).

If you do not agree to this Policy, please discontinue your use of the Service and any other form of interaction with the Company.

Where the Service is provided under an agreement with an organization to which the data subject belongs (for example, an employer), that organization may control the information processed within the Service. For details, please refer to the "End User Notice" in Article 15 of this Policy.

Article 1 (Purposes of Processing Personal Information)

1.1

The Company processes personal information for the purposes set out below. Personal information being processed will not be used for any purpose other than those set out below, and where the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the PIPA.

  • (1) Provision and customization of the Service: verifying intent to register, identifying and authenticating individuals in connection with membership-based services, maintaining and managing membership status, preventing fraudulent use of the Service, delivering notices and notifications, handling grievances, processing transactions, login authentication, operating, maintaining, and improving the Service, providing customized features and content recommendations, and supporting productivity and team collaboration
  • (2) Development of new services and research: developing new services and providing customized services, providing services and displaying advertisements based on demographic characteristics, verifying the effectiveness of the Service, ascertaining access frequency, compiling statistics on members' use of the Service, analyzing usage trends and patterns, and developing new products, features, and technologies
  • (3) Customer support: reviewing and responding to user inquiries, handling complaints, technical support, and problem resolution
  • (4) Marketing and communications: delivering information about the Company's services, features, and events, and providing customized advertising (where the data subject has consented)
  • (5) Integration with Meta platforms: where a user connects an account or grants access through Facebook Login or the Instagram Graph API, the Company may collect limited profile information (name, email address, and public Instagram account data) in order to provide login authentication, content management, and related Service features. Such data is used solely to provide the authorized features of the Service and for no other purpose.
  • (6) Payment processing and billing: processing payments for paid services, billing, subscription management, and the processing of related credit information
  • (7) Generation of Service outputs and data analysis: providing insights, reports, and analytics to users, and using personal information in anonymized and aggregated form for improving Service quality, developing new features, A/B testing, operating feature flags, and sending and analyzing the performance of CRM messages
  • (8) Collection of withdrawal reasons: reason information collected on an optional basis upon subscription cancellation or account withdrawal

Article 2 (Categories of Personal Information Processed and Methods of Collection)

2.1

The Company collects personal information when a data subject uses the Service or provides information directly to the Company, and when it receives information from other sources.

2.2

Categories of personal information collected

(1) Information you provide directly

  • Required items (for registration and provision of the Service): email address, password (stored as a hash)
  • Account and profile information: name, contact details, company name, job title, profile photograph, and other information the data subject optionally adds to a profile
  • Payment information (for paid services): billing contact name, billing email address, and payment card information. However, the Company does not directly store or collect sensitive payment information such as card numbers, expiry dates, or CVCs; such information is processed through its payment gateway (Toss Payments Co., Ltd.) (see Article 19 for details).
  • Content provided through the Service: content that the data subject posts, transmits, receives, or shares within the Service, together with automation settings (auto-reply templates, comment filter keywords, prize draw event settings, and the like)
  • Website content: feedback, survey responses, and event participation information submitted on the Company's websites (including social media)
  • Customer support channel information: contact details, problem summaries, related documents, and screenshots provided when requesting support to resolve an issue with the Service

(2) Information collected automatically through your use of the Service

  • Service usage information: features used, links clicked, files uploaded, search terms, and frequency of collaboration and communication
  • Device and connection information: IP address, cookies, operating system, browser and device information, access logs, page URLs, and error data
  • Notification and event records: records of in-Service notifications received, automation execution history, and subscription, payment, and credit usage history

(3) Information collected from connected third-party platforms (Meta)

  • Collected through the Instagram Graph API to the extent connected and authorized by the user: the username, profile photograph, account metrics (follower count, impressions, reach, and the like), source post data (content, captions, hashtags, and media metadata), per-post insights, source comments and their metadata, and follower demographics (anonymized and aggregated) of the connected account
  • Basic profile information obtained through Facebook Login
  • Public data of public Instagram Business/Creator accounts that a user requests to be analyzed or that the Company selects for analysis (limited to items made available by the Meta Graph API, such as account name, profile photograph, post content, and public metrics)

(4) Information collected from other sources

  • Other users: information provided when inviting members to, or designating members of, a workspace
  • Partners: billing and technical contact details and information on services of interest received from marketing and reseller partners
  • Public sources: publicly available databases and social media
  • Company affiliates: (not applicable at present)
2.3

Right to refuse consent and consequences of refusal

Users have the right to refuse to provide optional items. However, if you refuse to provide optional items, your use of certain Service features may be restricted. Required items (email address and password) are indispensable for registration and the provision of core Service functionality, and accordingly the Service cannot be used if you refuse to provide them.

2.4

Methods of collecting personal information

  • (1) Where a user consents to the collection of personal information and enters information directly in the course of registration or use of the Service
  • (2) Collection through web pages, email, facsimile, telephone, and similar channels in the course of consultation via customer support
  • (3) Automatic generation and collection of IP addresses, cookies, usage records, device information, and the like in the course of using the Service
  • (4) Receipt of information from a third-party service upon connecting that service

Article 3 (Retention and Use Period of Personal Information)

3.1

The Company processes and retains personal information within the retention and use period prescribed by law or within the retention and use period consented to by the data subject at the time of collection.

The processing and retention periods for each category of personal information are as follows.

  • (1) Membership registration and management (account information): destroyed without delay upon a request for withdrawal of membership. However, where an investigation or inquiry into a violation of applicable law is in progress, where claims or obligations arising from use of the Service remain outstanding, or where retention is otherwise necessary to comply with legal obligations, resolve disputes, or enforce agreements, the information is stored separately until the relevant grounds are resolved and is then destroyed.
  • (2) Information relating to the provision of the Service: until the supply of the Service and the payment and settlement of fees are complete
  • (3) Marketing information: until consent to receive marketing information is withdrawn
3.2

Where the Company is required by applicable law to preserve personal information rather than destroy it, the Company securely retains such personal information for the periods set out below.

In the Republic of Korea, the statutory grounds and periods for preservation are as follows.

(1) Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc.

  • Records on labelling and advertising: 6 months
  • Records on contracts and withdrawal of subscription: 5 years
  • Records on payment and the supply of goods: 5 years
  • Records on consumer complaints or dispute resolution: 3 years

(2) Article 15-2 of the Protection of Communications Secrets Act

  • Login records: 3 months
  • Service usage records: 3 months

(3) Article 22 of the Enforcement Decree of the Use and Protection of Credit Information Act

  • Records on the processing of credit information: 3 years

(4) Article 22 of the Electronic Financial Transactions Act

  • Payment-related transaction records: 5 years

(5) In other jurisdictions, including the European Union, the United States, and Japan, information is likewise retained for the periods prescribed by the applicable laws of the relevant region.

3.3

Personal information whose retention period has expired or whose purpose of processing has been achieved is destroyed without delay in accordance with Article 7, pursuant to the PIPA and other applicable laws.

Where immediate destruction is not technically possible, for example because the information resides in backup systems, the Company stores such information securely, isolates it from external access and further use, and destroys it immediately once deletion becomes possible.

Article 4 (Provision of Personal Information to Third Parties and Disclosure)

4.1

The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information) and, as a general rule, does not provide or disclose personal information externally without the prior consent of the data subject. The following are exceptions.

(1) Where the data subject has consented in advance

The Company follows a procedure of clearly informing the data subject of the recipient, the purpose of provision, the categories of personal information provided, and the retention and use period, and obtaining consent.

(2) Where information is disclosed to other users of the Service

  • Collaboration purposes: where a data subject creates content within the Service and chooses to share it with other users, that content and related profile information (such as name and profile photograph) may be displayed.
  • Workspace administration: the Owner or Admin of a workspace to which a data subject belongs may disclose the data subject's contact information to other members in order to support requests relating to the Service.
  • Community forums: where a data subject posts information on a public bulletin board or forum operated by the Company, that information and the associated profile information may be made public.

(3) Where required under the provisions of applicable law, or where a request is made by an investigative authority in accordance with the procedures and methods prescribed by law for investigative purposes

(4) Business transfers, etc.: in the event of a merger, sale of assets, financing, or acquisition of the business, collected personal information may be transferred, in which case the Company will provide notice to data subjects, including any available choices.

(5) Disclosure to affiliates: this is not applicable at present. Should information be disclosed to affiliates in the future, the protections set out in this Policy will apply.

4.2

Entrustment of personal information processing (Article 26 of the PIPA)

In order to provide the Service smoothly, the Company entrusts personal information processing tasks to external trustees as set out below. The Company enters into entrustment agreements with each trustee specifying the matters set out in each subparagraph of Article 26(1) of the PIPA, and supervises whether trustees process personal information securely.

  • Amazon Web Services (AWS) — Entrusted work: user authentication (Cognito) and operation and management of cloud servers (EKS, S3, SQS, Secrets Manager, and the like) / Items processed: email address, authentication tokens, and user data generated in the course of using the Service / Retention period: until withdrawal of membership
  • Toss Payments Co., Ltd. — Entrusted work: payment processing / Items processed: transaction ID, approval number, payment amount, payment method type, payment date and time, and billing contact email address (excluding card numbers and CVCs) / Retention period: 5 years under the Act on the Consumer Protection in Electronic Commerce, Etc.
  • Google LLC (Google Analytics 4) — Entrusted work: Service usage statistics / Items processed: anonymized visit data / Retention period: up to 26 months
  • Hotjar Ltd. — Entrusted work: session replay and UX analytics / Items processed: masked session data / Retention period: 1 year

The entrustment of personal information processing is governed by Article 26 of the PIPA and is legally distinct from the "provision to third parties" addressed in Article 5 of this Policy (Article 17 of the PIPA).

4.3

The Company does not currently provide personal information of data subjects to third parties for any purpose other than those specified in subparagraphs (2) through (5) of Article 4.1. Should this become necessary in the future, the Company will clearly inform data subjects of the recipient, purpose, items, and retention and use period and obtain their consent, or otherwise proceed in accordance with applicable law.

Article 5 (Provision of Personal Information to Third Parties)

5.1

The Company does not provide personal information to third parties for those third parties' own independent purposes.

5.2

Should provision to a third party become necessary in the future, the Company will, in accordance with Article 17 of the PIPA, clearly inform the data subject of (i) the recipient, (ii) the purpose of provision, (iii) the categories of personal information provided, and (iv) the retention and use period, and will follow a procedure of obtaining separate consent. Provision required under the provisions of applicable law is excepted.

5.3

Distinction from cooperation with service providers. The entrustment described in Article 4.2 (where a trustee processes personal information for the Company's purposes and under the Company's instructions) does not constitute "provision to a third party" under this Article. This Article applies where a third party processes personal information for its own independent purposes.

Article 6 (Cross-Border Transfer of Personal Information)

6.1

In order to process personal information smoothly, the Company provides and entrusts personal information processing tasks overseas as set out below. Toss Payments is a domestic operator in the Republic of Korea and is therefore not included among the cross-border transfers under this Article.

  • Amazon Web Services, Inc. — Country of transfer: United States (data processing facilities are located within the Seoul, Republic of Korea region, ap-northeast-2) / Items transferred: email address and authentication tokens, and user data generated in the course of using the Service / Purpose of use: user authentication (Cognito) and operation and management of cloud servers (EKS, S3, SQS, Secrets Manager, and the like) / Method and timing of transfer: in real time over HTTPS (upon use of the Service) / Retention period: until withdrawal of membership
  • Google LLC (GA4) — Country of transfer: United States / Items transferred: anonymized visit data / Purpose of use: Service usage statistics / Method and timing of transfer: in real time over HTTPS / Retention period: up to 26 months
  • Hotjar Ltd. — Country of transfer: United States / Items transferred: masked session data / Purpose of use: UX analytics / Method and timing of transfer: in real time over HTTPS / Retention period: 1 year

Legal basis for cross-border transfer: Article 28-8(1), subparagraph 3(a) of the PIPA, together with the consent of the data subject

6.2

When transferring personal information overseas, the Company implements the following legal safeguards.

  • (1) Execution of Standard Contractual Clauses (SCCs) with trustees
  • (2) Obtaining the express consent of data subjects
  • (3) Transfers to countries subject to an adequacy decision of the European Commission
  • (4) Application of other exceptional grounds permitted under applicable law
  • (5) Compliance with the Google API Services User Data Policy

Trustees are contractually bound to implement the legal and technical measures necessary for the protection of personal information, and the Company reviews compliance on an ongoing basis in order to safeguard the rights of data subjects and prevent infringements.

6.3

Data subjects may refuse the cross-border transfer of their personal information by contacting help@digitalog.ai. However, where a cross-border transfer is essential to the provision of the Service, refusal may result in restrictions on the use of part or all of the Service.

6.4

The Company may provide features that integrate with Google APIs (such as Google OAuth and Google Calendar). Information collected through such integrations is used in accordance with Google's API Services User Data Policy, including the Limited Use Requirements. The Company strictly complies with that policy and does not use personal information received through Google APIs for any purpose other than the specified functions, such as authentication and calendar access.

Article 7 (Procedures and Methods for Destroying Personal Information)

7.1

Where personal information becomes unnecessary, for example because the retention period has elapsed or the purpose of processing has been achieved, the Company destroys the personal information without delay.

7.2

Where personal information must continue to be preserved under other laws notwithstanding the expiry of the retention period consented to by the data subject or the achievement of the purpose of processing, the Company transfers such personal information to a separate database or preserves it in a different storage location. Such personal information is not used for any purpose other than preservation, except as required by law.

7.3

Destruction procedure. Information entered by users is destroyed either immediately or after being stored for a certain period in accordance with internal policies and other applicable laws, once the retention period has elapsed or the purpose of processing has been achieved. Personal information is destroyed with the approval of the Chief Privacy Officer.

7.4

Method of destruction. Personal information processed by the Company is destroyed by the following methods.

  • (1) Where in the form of an electronic file: permanent deletion by means that render restoration impossible
  • (2) Records, printed matter, documents, and other recording media other than electronic files: shredding or incineration

Article 8 (Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercise)

8.1

Data subjects may exercise the following rights relating to the protection of personal information against the Company at any time.

  • (1) Request to access personal information
  • (2) Request to correct errors and other inaccuracies
  • (3) Request for deletion
  • (4) Request to suspend processing
  • (5) Request to withdraw consent
  • (6) Request to refuse, or to obtain an explanation of, an automated decision
  • (7) Request for information concerning the processing of personal information
  • (8) Request to withdraw consent to the cross-border transfer of personal information
8.1A

Where the Company makes a fully automated decision that materially affects the rights or obligations of a data subject, the Company will provide notice of that fact in advance and will guarantee the data subject's right to refuse the decision or to request an explanation of it.

8.2

Method of exercising rights. Rights may be exercised in writing, by electronic mail, by facsimile, or by similar means pursuant to Article 41(1) of the Enforcement Decree of the PIPA, and the Company will act within the period prescribed by applicable law.

  • (1) Access, correction, deletion, and withdrawal of membership may be carried out directly by the user through the account settings within the Service.
  • (2) Other rights, such as suspension of processing and the refusal of, or request for an explanation of, an automated decision, may be exercised by contacting the Chief Privacy Officer or the responsible department identified in Article 12.
  • (3) The Company verifies the identity of the requesting party by reasonable means, and where a request is made by an agent, the Company may require a power of attorney and the agent's identification.
8.3

Requests to access personal information and to suspend processing may be subject to limitations on the data subject's rights under Article 35(4) and Article 37(2) of the PIPA.

8.4

Where other laws expressly specify that particular personal information is to be collected, deletion of that personal information may not be requested in a request for correction or deletion.

Article 9 (Processing of Children's Personal Information)

The Company does not process the personal information of children under the age of 16. This standard satisfies the requirements for the protection of children under all applicable laws, including Article 22-2 of the Korean PIPA, Article 8 of the EU GDPR, the UK Data Protection Act 2018, and the United States COPPA. Upon registration, users represent that they are at least 16 years of age and have the legal capacity to enter into this agreement. Where it is confirmed after registration that the age requirement is not met, the Company will immediately terminate the account and destroy the personal information collected.

Article 10 (Measures to Ensure the Security of Personal Information)

10.1

In order to ensure the security of personal information, the Company implements the following measures, including technical and organizational measures that meet industry standards.

(1) Administrative measures: establishment and implementation of an internal management plan, operation of a dedicated organization, regular staff training, and minimization of access privileges

(2) Technical measures:

  • Management of access privileges to personal information processing systems and access control systems
  • Data at rest: AES-256 encryption
  • Data in transit: encrypted communications using TLS 1.2 or above
  • Installation of security programs and periodic updates and inspections
  • Operation of intrusion prevention and detection systems

(3) Physical measures: access control for computer rooms, data storage rooms, and similar facilities, designation of secure areas, and establishment of disaster recovery plans

10.2

The Company makes its best efforts to manage users' personal information securely and undertakes additional privacy protection efforts beyond the security measures required by the PIPA. The Company conducts periodic security reviews, including penetration testing and code-level security issue reviews, and also carries out personal information management consulting and training.

10.3

No security system can be perfect, and it cannot be guaranteed that information in transit over the internet or stored on systems is entirely safe from external intrusion. However, the Company bears no liability for the leakage or exposure of personal information arising from a user's own intent or negligence, a user's failure to manage login credentials, or other causes outside the Company's scope of control.

10.4

Notification of personal information breaches. Upon becoming aware that personal information has been lost, stolen, or leaked, the Company will, pursuant to Article 34 of the PIPA and Article 40 of its Enforcement Decree, notify affected data subjects of the following matters without delay (or, where justifiable grounds exist, without delay after those grounds are resolved) by reasonable means such as email, in-Service notification, or written notice. Where the number of affected data subjects meets or exceeds the threshold prescribed by applicable law, the Company will report the breach to the Personal Information Protection Commission or the Korea Internet & Security Agency (KISA) and will post notice on its website for at least seven days.

  • (1) The categories of personal information leaked
  • (2) The time at which, and circumstances in which, the leak occurred
  • (3) Information on steps data subjects may take to minimize harm
  • (4) The Company's response measures and remediation procedures
  • (5) The department and contact details for receiving reports of harm from data subjects

Article 11 (Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof)

11.1

The Company uses "cookies" in order to provide users with conveniences essential to their use of the Service, such as maintaining login sessions.

11.2

Purposes of cookie use. The Company uses cookies for the following essential functions.

  • (1) Maintaining login sessions and managing authentication tokens (access, id, and refresh tokens)
  • (2) Storing language settings and user preferences
  • (3) Maintaining the selection state of a connected Instagram account
  • (4) Maintaining payment sessions, limited to payment screens
11.3

Analytics tools. The Company may use analytics tools such as Google Analytics and Hotjar in order to improve the quality of the Service. The items, purposes, and retention periods of the information collected by each tool are specified in the entrustment provisions of Article 4 and the cross-border transfer provisions of Article 6.

11.4

Refusal of cookies. Data subjects may allow or block cookies through their web browser settings. However, refusing essential cookies may cause difficulties in using the Service, including login and payment.

11.5

The Company does not currently take any specific action in response to Do Not Track (DNT) signals sent by certain web browsers. Should the Company introduce in-Service cookie and tracking consent management features in the future, the relevant provisions of this Article will be updated.

Article 12 (Chief Privacy Officer and Responsible Department)

12.1

The Company designates a Chief Privacy Officer as set out below, who assumes overall responsibility for matters relating to the processing of personal information and handles complaints and remediation for data subjects in connection with such processing.

Chief Privacy Officer

  • Name: Donggyu Son
  • Telephone: +82-70-4106-4243
  • Email: help@digitalog.ai

Department handling personal information grievances

  • Department: Development Office
  • Contact: Personal Information Protection Officer
  • Telephone: +82-70-4106-4243
  • Email: help@digitalog.ai
12.2

Data subjects may direct any inquiries, complaints, or requests for remediation relating to the protection of personal information arising from their use of the Company's Service to the Chief Privacy Officer or the responsible department. The Company will respond to and address such inquiries without delay.

12.3

Please take care not to provide sensitive personal information (such as resident registration numbers, health information, or political opinions) when making an inquiry.

Except where required by law or where the data subject has given express consent, the Company does not collect or process the following categories of sensitive information.

  • (1) Unique identifying information such as social security numbers and passport numbers
  • (2) Health information and medical records
  • (3) Political opinions, religion, and philosophical beliefs
  • (4) Race and ethnicity
  • (5) Biometric or genetic information
  • (6) Sexual orientation or information concerning sex life
  • (7) Criminal history or investigation records
  • (8) Trade union membership

Where a data subject voluntarily provides such sensitive information, that information is processed only within a strictly limited scope in accordance with this Policy and applicable law, and is destroyed immediately where it is not necessary.

12.4

Accessibility of this Policy: this Policy is made publicly available and may be viewed at any time without logging in. The latest version is available at the following links: www.conma.ai/en/privacy and www.digitalog.ai/en/terms-and-privacy?type=privacy

12.5

Language and governing text. This Policy is prepared in standard Korean, the official language of the Republic of Korea. Where a translation into English or any other language is provided, it is provided solely for the convenience of users; in the event of any inconsistency between the Korean version and a translation, the Korean version shall prevail. In any legal dispute, including litigation and arbitration, this Policy shall be construed on the basis of the Korean version, and no translation shall serve as a basis for its interpretation. This is subject to Article 17, where the language version of a particular region is required to prevail for data subjects in that region, or where applicable law so requires.

Article 13 (Remedies for Infringement of the Rights and Interests of Data Subjects)

13.1

Where a data subject has any concern about, or has suffered, an infringement relating to the protection of personal information, the data subject may contact the Company by the means set out below, or may request dispute resolution, consultation, or report the matter to the data protection supervisory authority of the relevant jurisdiction.

The Company respects the right of data subjects to informational self-determination and makes its best efforts to protect their rights and provide remedies. Data subjects may also contact the Chief Privacy Officer or the responsible department identified in Article 12 at any time to raise complaints, make inquiries, or exercise their rights.

13.2

Data subjects within the Republic of Korea

  • Personal Information Dispute Mediation Committee: 1833-6972 (no area code) / www.privacy.go.kr
  • Personal Information Infringement Report Center: 118 (no area code) / privacy.kisa.or.kr
  • Supreme Prosecutors' Office, Cyber Investigation Division: 1301 (no area code) / www.spo.go.kr
  • Korean National Police Agency, Cyber Investigation Bureau: 182 (no area code) / ecrm.police.go.kr
13.3

Residents of the European Union (EU): you may lodge a complaint with the supervisory authority (Data Protection Authority, DPA) of your Member State. A list of DPAs is available at edpb.europa.eu/about-edpb/about-edpb/members_en. Under the GDPR, you may lodge an objection with, or seek legal remedy through, the competent authority.

13.4

Residents of the United Kingdom (UK): Information Commissioner's Office (ICO) — ico.org.uk

13.5

Residents of California, United States: California Privacy Protection Agency (CPPA) — cppa.ca.gov

13.6

Residents of Japan: 個人情報保護委員会 (Personal Information Protection Commission, PPC) — www.ppc.go.jp

13.7

Other regions: data subjects may lodge a complaint with the data protection supervisory authority in their own jurisdiction and may pursue administrative or legal remedies available under applicable law.

Article 14 (Links to Other Websites or Services)

14.1

The Company's websites may contain links to other websites or services. In such cases, the Company is not responsible for the privacy practices of the linked external websites or services.

14.2

When you navigate to an external site, please be sure to review that site's privacy policy. This Privacy Policy applies only to the Service operated by the Company.

Article 15 (End User Notice)

15.1

Certain parts of the Company's Service may be designed for use by an organization (for example, a data subject's employer). Where the Service is provided through an organization, that organization holds administrative authority over the use of the Service as the Owner or Admin of the workspace, and inquiries relating to personal information should be directed to that organization's administrator. A data subject's use of the Service may be subject to that organization's policies, and the Company is not responsible for the privacy or security practices implemented by the administrating organization.

15.2

Owners and Admins may hold the following powers.

  • (1) Requiring a reset of a data subject's account password
  • (2) Restricting, suspending, or terminating access to the Service
  • (3) Accessing information within an account
  • (4) Installing or removing third-party applications and other integrations
15.3

Where a data subject uses the Service with an email address provided by an organization, the owner of that domain (such as an employer) may subsequently assert administrative authority over the account and the use of the Service, in which case the data subject will be separately notified. If you do not wish an administrator to hold administrative authority over your account or use of the Service, you must register for and access the Service using a personal email address.

Article 16 (Amendments to this Privacy Policy)

16.1

This Privacy Policy applies from the effective date stated herein. The Company may amend this Privacy Policy, including in order to reflect changes in law or in the Service.

Where this Privacy Policy is amended, the Company will post the changes on this page, and the amended Privacy Policy will take effect seven days after posting.

16.2

However, where changes materially affecting the rights of data subjects arise, as set out below, the Company will give prior notice by separate means at least 30 days in advance.

  • (1) Changes to the categories of personal information collected
  • (2) Additions to or changes in the purposes for which personal information is used
  • (3) Changes relating to provision to third parties or cross-border transfers
  • (4) Changes to retention periods, procedures for exercising rights, methods of consent, or other rights of data subjects
16.3

Such material changes will be notified in advance by one or more of the following methods.

  • (1) In-Service notification
  • (2) Posting of an announcement
  • (3) Individual notice sent to the email address registered at the time of sign-up
16.4

For relatively minor changes (such as editorial clarifications or corrections to statutory citations), posting on this page may suffice. The Company retains previous versions of the Privacy Policy so that data subjects may review them.

16.5

For material changes falling under any subparagraph of Article 16.2, the Company will seek the separate consent of data subjects to the changes, and where a data subject does not consent, the Company will not carry out the processing of personal information to which those changes relate. For minor changes, where the Company gives notice of the changes in accordance with Article 16.1 and the data subject does not expressly object before the date of application, the data subject shall be deemed to have consented to the amended Policy. A data subject who does not agree with the changes may discontinue use of the Service and withdraw their account at any time.

Article 17 (Supplementary Regional Provisions)

17.1

Notice of privacy rights for California residents (CCPA/CPRA)

  • (1) The Company complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) as amended. The Company does not sell personal information, and data subjects may exercise the following rights.
  • - The right to request access to, and a copy of, the personal information collected
  • - The right to request deletion of personal information
  • - The right to opt out of the sale or sharing of personal information (Do Not Sell or Share My Personal Information)
  • - The right not to be discriminated against for exercising these rights
  • (2) Requests under the CCPA may be submitted to help@digitalog.ai.
  • (3) The Company may request an email address or government-issued identification in order to verify identity, and rights may also be exercised through an authorized agent. Requests are generally processed within 45 days.
17.2

Residents of the European Economic Area (EEA) and Switzerland (GDPR)

  • (1) The Company complies with the General Data Protection Regulation (GDPR) and related national laws, and guarantees the rights conferred by Articles 15 to 22 of the GDPR (access, rectification, erasure, restriction of processing, portability, objection, and rights relating to automated decision-making).
  • (2) Allocation of roles: with respect to personal information the Company collects directly from users, the Company acts as a Data Controller. Where a user (for example, an agency) uses the Service to process the personal information of its own clients or followers, the Company acts as a Data Processor on behalf of that user, and a separate Data Processing Addendum may apply.
17.3

Residents of the United Kingdom (UK GDPR and the Data Protection Act 2018)

  • (1) Following Brexit in 2020, the United Kingdom is not subject to the EU GDPR; the UK GDPR and the Data Protection Act 2018 apply instead. The Company complies with those laws and guarantees the rights of data subjects (access, rectification, erasure, restriction of processing, portability, objection, and rights relating to automated decision-making).
  • (2) The supervisory authority for UK residents is the Information Commissioner's Office (ICO, ico.org.uk).
17.4

Residents of Japan (APPI)

  • (1) The Company complies with the laws and regulations of Japan, including the Act on the Protection of Personal Information (APPI).
  • (2) The Company assumes primary responsibility for the management of personal data used jointly with affiliates or third parties.
  • (3) The Company does not provide the personal information of Japanese residents to third parties for marketing purposes without prior consent.
17.5

Residents of the Republic of Korea

  • (1) The Company complies with applicable laws including the Personal Information Protection Act (PIPA), the Use and Protection of Credit Information Act, the Electronic Financial Transactions Act, the Act on the Consumer Protection in Electronic Commerce, Etc., the Protection of Communications Secrets Act, and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc.
  • (2) Where any provision of this Policy conflicts with a mandatory provision of the laws of the Republic of Korea, that mandatory provision shall prevail.

Article 18 (Use of Meta Platform Data and Requests for Data Deletion)

18.1

The Service may use Meta platforms, including Facebook Login and the Instagram Graph API, in order to provide certain login and data synchronization features. All data received from Meta platforms is processed in strict compliance with the Meta Platform Terms and related policies.

18.2

The Company adheres to the following principles.

  • (1) The Company accesses only data that the user has expressly authorized.
  • (2) The Company uses Meta data solely for the purpose of providing the Service features requested by the user.
  • (3) The Company does not sell data received from Meta to third parties.
  • (4) Users may withdraw access to Meta data at any time through their Meta account settings or the disconnection feature within the Service.
18.3

Users wishing to request deletion of data received from Meta platforms may contact help@digitalog.ai, and the Company will promptly delete such data in accordance with the Meta Platform Terms and applicable privacy laws.

Article 19 (Processing of Payment and Credit Information)

19.1

The Company entrusts the collection, storage, and processing of sensitive payment information, such as full card numbers, CVCs, and card expiry dates, to Toss Payments Co., Ltd. Toss Payments is a payment gateway registered under the Electronic Financial Transactions Act and complies with the Payment Card Industry Data Security Standard (PCI-DSS).

19.2

Information retained by Toss Payments

  • Full card number
  • Card expiry date
  • CVC
  • Cardholder name
19.3

Information retained by the Company

(1) Information relating to recurring payments — retained while the user uses paid services

  • Billing key (the payment identifier issued by Toss Payments): stored with AES-256 encryption
  • Masked card number (for example, **** **** **** 1234)

(2) Payment transaction metadata

  • Transaction ID and approval number
  • Payment amount and payment method type (card, account transfer, virtual account, or simple payment)
  • Payment date and time
  • Billing contact name and email address
19.4

Legal basis and retention periods

  • Payment transaction records: 5 years (Article 6 of the Act on the Consumer Protection in Electronic Commerce, Etc.)
  • Credit information processing records: 3 years (Article 22 of the Enforcement Decree of the Use and Protection of Credit Information Act)
  • Electronic financial transaction records: 5 years (Article 22 of the Electronic Financial Transactions Act)
19.5

Application of the Credit Information Act. Certain payment-related information constitutes "credit information" under the Use and Protection of Credit Information Act, and the Company complies with the obligations regarding collection, use, provision, and protection prescribed by that Act.

19.6

Handling of payment failures. Where an automatic payment fails, the Company may retry the payment for a certain period. During the retry period, the minimum information necessary to confirm the payment, such as the reason for failure, is temporarily retained and is then updated or deleted once the payment succeeds or the user changes their payment method. Where a user cancels a subscription or withdraws membership, the billing key and masked card number described in Article 19.3(1) are destroyed without delay unless a preservation obligation applies under applicable law.

Article 20 (Service Outputs)

20.1

The Company analyzes data from a user's own connected accounts, together with public data of IG Business/Creator accounts made publicly available through the Instagram Graph API, in order to provide insights, periodic reports, competitor comparison reports, and industry average and benchmark metrics. The composition of such outputs and the rights of use and ownership in them are governed by Article 5-2 (Service Outputs) of the Terms of Service.

20.2

Industry average and benchmark metrics are provided as statistically aggregated results processed so that individual data subjects cannot be identified.

20.3

Where the Company wishes to use the case of a particular data subject for the promotion of the Service, it will obtain that data subject's prior consent.

20.4

Inquiries or objections relating to this Article may be submitted to help@digitalog.ai.

Contact

  • Company: Digitalog Technologies Co., Ltd.
  • Chief Executive Officer: Donggyu Son
  • Address: Room 210, Jena-dong, 245 Dongbaekjungang-ro, Giheung-gu, Yongin-si, Gyeonggi-do, Republic of Korea
  • Email: help@digitalog.ai
  • Telephone: +82-70-4106-4243
  • Business Registration Number: 759-86-02818
  • Mail-Order Sales Registration Number: 2025-Yongin Giheung-0063