Place Haejo Privacy Policy
FIRST FLUKE (hereinafter the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (개인정보 보호법) in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
- Effective date: June 18, 2026
- Last amended: June 18, 2026
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information processed will not be used for any purpose other than those set out below, and where the purpose of use is changed, the Company will take necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
- Membership registration and management: Confirming intent to register as a member, identifying and authenticating the individual, maintaining and managing membership status, and preventing fraudulent use of the service
- Provision of the service: Operating the features provided by the Company, including collection and analysis of store reviews, generation of AI review-reply drafts, competitor tracking, provision of reports and predictions, and menu board generation
- Paid subscription payments: Processing subscription payments, managing payment records, and handling refunds
- Customer support: Receiving and handling inquiries and delivering notices and notifications of service changes
- Service improvement: Analyzing usage statistics, developing new features, and improving service quality
- Marketing use (optional): Providing information on events and benefits (only where separate consent has been obtained)
Article 2 (Items of Personal Information Processed)
The Company processes the following items of personal information.
Mandatory Items
- Email address — Member identification, login, and delivery of notices and notifications
- Password — Authentication of the individual (stored using one-way encryption; the Company does not retain plaintext passwords)
- Store information (trade name, address, business type, and other information entered or linked by the user) — Store analysis and provision of the service
- Linked platform authentication information (access tokens for linking review channels such as Naver, Kakao, and Google Business) — Collection of review and store data from external platforms that the user has requested to link
- Payment and subscription information (subscription status, payment identifier) — Paid subscription payment and settlement. Information on payment methods, such as card numbers, is retained by the payment gateway and is not stored by the Company
The Company processes the required items above under Article 15(1)4 (performance of a contract) of the Personal Information Protection Act (개인정보 보호법) without separate consent, and processes optional items, such as for marketing, only where the data subject's prior consent has been obtained.
Automatically Collected Items
In the course of using the service, the IP address, cookies, service usage records, access logs, and access device information may be automatically generated and collected.
Third-Party Personal Information Collected in the Course of Service Processing
In the course of collecting and analyzing reviews from external platforms linked by a user (a store operator), the Company may process the author's nickname and the body of the review contained in such reviews. This information is processed solely for the purpose of managing store reviews on behalf of the user, and is destroyed in accordance with the retention periods set out in this Policy once the purpose of analysis has been achieved.
The Company does not collect the personal information of children under the age of 14, and this service is intended for business operators (store operators).
Article 3 (Processing and Retention Periods of Personal Information)
The Company processes and retains personal information within the retention and use period prescribed by statute or the retention and use period consented to by the data subject.
| Processing Activity | Retention Period | Basis |
|---|---|---|
| Membership registration and management | Until membership withdrawal or withdrawal of consent | Consent of the data subject |
| Records on contracts and withdrawal of subscription, etc. | 5 years | Act on the Consumer Protection in Electronic Commerce, etc. |
| Records on payment and supply of goods, etc. | 5 years | Act on the Consumer Protection in Electronic Commerce, etc. |
| Records on consumer complaints or dispute resolution | 3 years | Act on the Consumer Protection in Electronic Commerce, etc. |
| Service access log records | 3 months | Protection of Communications Secrets Act |
| Records for the prevention of fraudulent use | 1 year | Consent of the data subject |
Article 4 (Provision of Personal Information to Third Parties)
The Company processes the personal information of data subjects only within the scope specified in Article 1, and provides personal information to third parties only where the case falls under Articles 17 and 18 of the Personal Information Protection Act, such as the consent of the data subject or special provisions of statute. The Company does not currently provide personal information to third parties.
Article 5 (Outsourcing of Personal Information Processing and Cross-Border Transfer)
For the smooth provision of the service, the Company outsources the processing of personal information to overseas operators as set out below, and discloses the fact of cross-border transfer as follows pursuant to Article 28-8 of the Personal Information Protection Act.
| Trustee | Outsourced Work | Country of Transfer | Method of Transfer | Retention and Use Period |
|---|---|---|---|---|
| Google LLC (Google Cloud Platform) | Review analysis and generation of reply drafts through AI analysis (Vertex AI Gemini), cloud infrastructure, and content storage | United States and Google global regions | Transmission via information and communications networks | Until termination of the outsourcing agreement or achievement of the processing purpose |
| Polar Software Inc. | Processing of paid subscription payments and storage of payment methods | United States | Transmission via information and communications networks | Until termination of the outsourcing agreement or expiry of the preservation period under applicable statutes |
When entering into an outsourcing agreement, the Company specifies in the document, pursuant to Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information beyond the purpose of performing the outsourced work, technical and administrative protective measures, restrictions on re-outsourcing, management and supervision of the trustee, and liability such as damages, and supervises whether the trustee processes personal information safely. Data input for AI analysis is not used to train the models of the trustee (Google).
Article 6 (Procedures and Methods for Destroying Personal Information)
When personal information becomes unnecessary—such as upon the expiry of the retention period or the achievement of the processing purpose—the Company destroys the relevant personal information without delay. Personal information for which a cause for destruction has arisen is destroyed with the approval of the personal information protection officer; information in electronic file form is permanently deleted using a method that renders recovery and reproduction impossible. Where personal information must be preserved pursuant to statute, the Company preserves it by transferring it to a separate database or by storing it in a different location.
Article 7 (Rights and Obligations of Data Subjects and Methods of Exercising Them)
A data subject may, at any time, exercise the rights to access, correct, delete, suspend the processing of, and request the transfer of their personal information with respect to the Company. These rights may be exercised in writing, by email, and through other means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action thereon without delay.
Methods of Exercise
- Email: hello@firstfluke.com
- Mail: 25 Jowon-ro, Gwanak-gu, Seoul, Republic of Korea
- The account and personal information management menu on the My Page section of the service
Right to Request the Transfer of Personal Information
A data subject may request that their personal information be transferred to another personal information controller, and the Company will process legitimate requests within the period prescribed by applicable statutes.
Article 8 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
The Company uses cookies to provide users with customized services and to maintain login status. Cookies are used to ascertain users' access frequency, visit times, usage patterns, and the like.
How to Refuse
- Chrome: Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Manage Cookies and Website Data
- Edge: Settings > Cookies and site permissions > Manage cookies and site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
If you refuse to store cookies, there may be restrictions on the use of certain services that require login.
Article 9 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information. Administratively, the Company establishes and implements an internal management plan, minimizes the number of staff handling personal information, and conducts regular inspections. Technically, the Company manages access rights to the personal information processing system, retains access records, encrypts important information such as passwords, and encrypts transmission channels (HTTPS/TLS). Physically, the Company controls access to the systems in which data is stored.
Article 10 (Personal Information Protection Officer and Department for Access Requests)
The Company designates a personal information protection officer as set out below to take overall responsibility for matters relating to the processing of personal information and to handle complaints from and provide remedies to data subjects in connection with the processing of personal information. Data subjects may submit requests to exercise their rights, such as access to personal information, to the contact below.
Personal Information Protection Officer
- Name: Kim Gahyeon
- Title: Representative (Personal Information Protection Officer)
- Email: hello@firstfluke.com
Article 11 (Matters Concerning Automated Decisions)
In the course of providing the service, the Company carries out automated processing using artificial intelligence (AI) technology as follows.
- Subject of processing: Classification of whether a review is malicious, prediction of sales and visits, store improvement suggestions, and generation of review-reply drafts
- Criteria for processing: Information provided or linked by the user, such as the body of reviews, star ratings, and store data
- Procedures and methods of processing: Natural language analysis, classification, and generation through the Google Vertex AI (Gemini) model
- Whether training data is used: Neither the Company nor the trustee (Google) uses users' data to train AI models
The results of the automated processing described above are reference materials intended to assist the decision-making of the user (the store operator), and the user themselves makes the final judgment and takes the resulting action. A data subject may request an explanation of the criteria and results of the automated processing, or request reprocessing through human intervention; the method of exercise is by email (hello@firstfluke.com).
Article 12 (Methods of Remedy for Infringement of Data Subjects' Rights)
To obtain remedy for infringements of their personal information, data subjects may apply for dispute resolution, consultation, or the like to the following agencies.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
- National Police Agency Cyber Investigation Bureau: 182 (no area code) (ecrm.police.go.kr)
Article 13 (Changes to the Privacy Policy)
This Privacy Policy applies from its effective date, and where there are additions, deletions, or corrections to its contents in accordance with statute or policy, the Company will give notice through the notices section of the service from 7 days before the effective date of such changes.