AvoLabs Inc. Privacy Policy

AvoLabs Inc. Privacy Policy

AvoLabs Co., Ltd. (hereinafter "the Company") values the personal information of members (hereinafter "Users" or "Data Subjects") who use the AvoLingo service (hereinafter "the Service") operated by the Company, and complies with relevant laws and regulations including the Personal Information Protection Act (PIPA) and the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this Privacy Policy, the Company informs Users of the purposes and methods by which their personal information is processed and the measures taken to protect their personal information.

Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes and does not use processed personal information for any purposes other than those listed below. If the purpose of use is changed, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

Performance of Service Contracts and Settlement of Fees: Content provision, identity verification, purchase and payment, billing, and settlement

Member Management: Identity verification for member-based services, personal identification, prevention of fraudulent use by unauthorized users, confirmation of intent to join, age verification, confirmation of legal guardian consent when collecting personal information of children under 14, customer consultation, delivery of notices, and record retention for dispute resolution

New Service Development and Customized Service Provision: Verification of service effectiveness, analysis of access frequency, and provision of services based on demographic characteristics

Marketing and Advertising: Provision of event and promotion information, delivery of advertising information (with separate consent), provision of customized advertising through third-party advertising platforms, and customer surveys

Use of Pseudonymized Information: Pseudonymization and use of pseudonymized data for statistical purposes, scientific research, and preservation of public interest records

Article 2 (Items and Methods of Personal Information Collection)

The Company collects personal information for purposes such as member registration, service provision, customer consultation, and marketing as follows. If a User does not consent to the collection and use of personal information, membership registration may be restricted or use of certain services may be limited.

1. Member Registration and Service Use

The Company collects the following personal information during member registration and service use.

Standard Registration

Required

Email, password, gender, year of birth

Social Registration (Common)

Required

SNS identifier (SNS ID)

Social Registration (Kakao)

Required

Nickname, profile picture, email, year of birth, Kakao Talk channel addition status and history, phone number

Optional

Gender, age range

Social Registration (Google)

Required

Email

Social Registration (Apple)

Optional

Email

2. Payment and Settlement

During the app or web payment process, payment information may be collected and processed by payment gateway (PG) companies, and the Company does not directly store Users' payment information such as card numbers. However, for the purposes of payment history and refund processing, information such as payment date, payment amount, and payment method (card issuer name, etc.) is transmitted to and stored by the Company.

3. Customer Consultation

During the consultation process through the customer center, the following information may be collected via web pages, email, chat (Kakao Business, Channel Talk), and phone.

Items collected: Email address, consultation content (including text, images, and videos), and call recording information

4. Marketing and Advertising

Personal information may be collected upon obtaining separate consent during events, promotions, and surveys conducted for marketing purposes. When additional collection occurs, the Company will inform members in advance of the items, purposes, and retention period and obtain separate consent at that time.

5. Information Automatically Collected During Service Use

The following information may be automatically generated and collected during the use of the mobile app and web service.

IP address, visit date and time, service usage records, abuse records

Purpose of Collection

Prevention of fraudulent use, security incident response, statistical analysis

Cookies, browser type and OS, device information

Purpose of Collection

Service usage statistics and provision of customized services

Advertising identifiers (Android AAID, iOS IDFA)

Purpose of Collection

Provision of customized advertising and analysis of advertising effectiveness

Search terms, service usage records

Purpose of Collection

Service improvement and statistical analysis

6. Restrictions on Collection of Sensitive Information and Unique Identification Information

The Company collects only the minimum personal information necessary for service provision and, in principle, does not collect sensitive information (race, religion, ideology, place of origin, place of family register, political views and criminal records, health status, genetic information, etc.) or unique identification information (resident registration number, passport number, driver's license number, alien registration number) that may infringe upon Users' fundamental human rights. Exceptions apply when collection is permitted by law or the User has provided separate consent.

Article 3 (Retention and Use Period of Personal Information)

The Company processes and retains personal information within the retention and use period prescribed by law or the period consented to by the data subject when collecting personal information. When the purpose of use is achieved or the member directly withdraws, the personal information is destroyed without delay using methods that prevent recovery.

1. Member Information

Personal information collected at the time of member registration: Retained until membership withdrawal, then destroyed

However, in accordance with the Company's internal policy, the following information will be retained for one (1) year after membership withdrawal for the reasons below.

Reasons for retention: Prevention of re-registration by abusive users, dispute resolution related to defamation and other rights violations, and cooperation with investigations

Retained items: Email, SNS identifier, and reason for withdrawal

2. Retention in Accordance with Relevant Laws

Act on the Consumer Protection in Electronic Commerce

Retained Items

Records on contracts or withdrawal of subscription

Retention Period

5 years

Act on the Consumer Protection in Electronic Commerce

Retained Items

Records on payment and supply of goods

Retention Period

5 years

Act on the Consumer Protection in Electronic Commerce

Retained Items

Records on consumer complaints or dispute resolution

Retention Period

3 years

Act on the Consumer Protection in Electronic Commerce

Retained Items

Records on labeling and advertising

Retention Period

6 months

Protection of Communications Secrets Act

Retained Items

Service usage logs (access records)

Retention Period

3 months

Electronic Financial Transactions Act

Retained Items

Records on electronic financial transactions

Retention Period

5 years

Framework Act on National Taxes

Retained Items

All books and supporting documents related to transactions stipulated by tax law

Retention Period

5 years

Note

The validity period system for personal information (mandatory separate storage of dormant accounts) under the Act on Promotion of Information and Communications Network Utilization and Information Protection was abolished as of September 15, 2023.

However, the Company may operate a separate dormancy policy based on its own internal standards to protect the personal information of long-term inactive members, in which case prior notice will be given to members.

Article 4 (Provision of Personal Information to Third Parties)

The Company uses Users' personal information within the scope notified in Article 1 and, in principle, does not use it beyond that scope or disclose it externally without the prior consent of the User. However, the following are exceptions.

When the User has consented to third-party provision in advance

When required by law or when there is a request from an investigative agency in accordance with the procedures and methods prescribed by law for investigative purposes

When providing pseudonymized information for statistical purposes, scientific research, or preservation of public interest records (pseudonymized information)

When transferring or succeeding rights and obligations of the service provider due to the transfer of all or part of the business, mergers and acquisitions, etc. (In such cases, the Company will provide detailed notice in advance and grant the right to withdraw consent on personal information collection and use.)

Note: Currently, the Company does not regularly provide Users' personal information to third parties. When third-party provision becomes necessary in the future, the Company will inform Users in advance of the recipient, purpose of provision, items provided, and retention and use period, and obtain separate consent.

Article 5 (Consignment of Personal Information Processing)

The Company outsources personal information handling tasks to external specialized companies as follows for smooth service provision. When entering into consignment contracts, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies matters such as the prohibition of processing personal information beyond the purpose of the consigned work, technical and managerial protection measures, restrictions on re-consignment, supervision of the consignee, and liability for damages.

Domestic Consignment

Consignee

Consigned Work

Retention and Use Period

Google Cloud Platform

Server operation and data storage

Until membership withdrawal or termination of consignment contract

Amazon Web Services, Inc.

Server operation and data storage

Until membership withdrawal or termination of consignment contract

Microsoft Azure

Server operation and data storage

Until membership withdrawal or termination of consignment contract

Danal Co., Ltd.

Identity verification service

In accordance with the retention period provided by the company

Kakao Corp.

SMS and notification message delivery

Until membership withdrawal or termination of consignment contract

Kakao Pay Corp. / KG INISIS, Inc. / Naver Finance Inc.

Electronic payment and billing service

Until membership withdrawal or termination of consignment contract

Channel Corporation

Chat and customer consultation service

Until membership withdrawal or termination of consignment contract

When the contents of consigned work or consignee changes, the Company will disclose this through this Privacy Policy.

Article 6 (Overseas Transfer of Personal Information)

The Company consigns personal information to global companies (overseas transfer) as follows for service use and marketing efficiency, and in accordance with Article 28-8 of the Personal Information Protection Act, prior notice is provided to the data subject and consent is obtained.

Recipient (Contact)

Country

Date and Method of Transfer

Items Transferred

Purpose of Transfer

Retention and Use Period

Braze, Inc. (privacy@braze.com)

United States

Transmission via network during service use

Email, phone number, device ID

Mobile app usage analysis, push notifications, and email delivery

Until membership withdrawal or termination of consignment contract

Google AdMob, Inc.

United States

Transmission via network during service use

Advertising identifiers, service usage records, etc.

Provision of customized advertising and analysis of advertising effectiveness

In accordance with Google's Privacy Policy

Amazon Web Services, Inc.

United States

Transmission via network during service use

All member information necessary for service operation

Cloud infrastructure (server) operation

Until membership withdrawal or termination of consignment contract

How to Refuse Overseas Transfer: Data subjects may refuse overseas transfer by sending an email to the Privacy Protection Officer (deniz@avo-lingo.com). However, refusing overseas transfer may limit the use of services that include the relevant functions.

Article 7 (Procedure and Method of Destroying Personal Information)

In principle, the Company destroys the relevant personal information without delay when the purpose of processing personal information has been achieved. The procedures, deadlines, and methods of destruction are as follows.

Destruction Procedure: Information entered by the User is transferred to a separate database (or a separate document file in the case of paper) after the purpose is achieved and is destroyed after being stored for a certain period in accordance with internal policy and other relevant laws. Personal information transferred to the DB will not be used for any other purpose except as required by law.

Destruction Deadline: Users' personal information will be destroyed within 5 days from the end of the retention period when the retention period has elapsed, and within 5 days from the date when the personal information is deemed unnecessary due to the achievement of the purpose of processing, abolition of the service, or termination of the business.

Method of Destruction:

Personal information stored in electronic file format will be deleted using technical methods (such as Low Level Format) that prevent the records from being recovered.

Personal information printed on paper will be destroyed by shredding or incineration.

Article 8 (Rights and Obligations of Data Subjects and Legal Representatives and Methods of Exercise)

Data subjects may exercise the following personal information protection-related rights against the Company at any time.

Request to view personal information

Request for correction in case of errors

Request for deletion

Request to suspend processing

Withdrawal of consent (membership withdrawal)

The exercise of rights against the Company may be made through the in-app settings menu directly, or by writing, telephone, email, or fax, and the Company will take action without delay.

If the data subject requests correction or deletion of errors in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.

Rights may also be exercised through a legal representative or an authorized agent of the data subject. In this case, a power of attorney in accordance with Form No. 11 attached to the Notice on Methods of Personal Information Processing (Notice No. 2020-7) must be submitted.

Data subjects shall not violate the Personal Information Protection Act and other relevant laws regarding the personal information and privacy of themselves or others processed by the Company.

Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

The Company uses "cookies" and "advertising identifiers" that store and retrieve usage information to provide customized services to Users.

1. Cookies

Cookies are small pieces of information sent by the server operating the website to the User's browser and are sometimes stored on the hard disk of the User's PC.

Purpose of Use: To understand the visit and usage patterns of each service and website visited by the User, popular search terms, and secure access status, and to provide optimized information to the User.

How to Refuse: Users have the option to choose whether to install cookies. Therefore, by setting options in the web browser, Users may allow all cookies, confirm each time a cookie is saved, or refuse to save all cookies.

Internet Explorer: Tools menu → Internet Options → Privacy → Settings

Chrome: Settings menu → Privacy and security → Cookies and other site data

Safari: Preferences menu → Privacy → Cookies and website data

Edge: Settings menu → Cookies and site permissions → Manage and delete cookies and site data

However, refusing to save cookies may cause difficulties in using some services that require login.

2. Advertising Identifiers

In the mobile app environment, the Company may collect Android's AAID and iOS's IDFA for customized advertising and statistical analysis.

How to Refuse (Operating System Settings):

Android: Settings → Privacy → Ads → Delete advertising ID (or Opt out of Ads Personalization)

iOS: Settings → Privacy & Security → Tracking → Disable "Allow Apps to Request to Track"

Article 10 (Processing of Pseudonymized Information)

The Company may process pseudonymized information without the consent of the data subject for statistical purposes, scientific research, and preservation of public interest records. In such cases, the Company takes safety measures in accordance with Articles 28-2 through 28-7 of the Personal Information Protection Act and does not process pseudonymized information for the purpose of identifying specific individuals.

Purpose of Processing Pseudonymized Information: Development of new services and improvement of existing services through analysis of service usage patterns, and academic research

Items of Pseudonymized Information: Pseudonymized information of service usage records, learning activity data, and demographic information (gender, year of birth), etc.

Retention Period of Pseudonymized Information: Until the purpose of processing pseudonymized information is achieved

Security Measures: Separate storage of pseudonymized information and additional information, access control, and retention of access records

Article 11 (Measures to Ensure the Safety of Personal Information)

In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, managerial, and physical measures necessary to ensure safety.

Managerial Measures

Establishment and implementation of an internal management plan

Minimization of personnel handling personal information and regular employee training

Operation of a dedicated personal information protection organization

Technical Measures

Access rights management and installation of access control systems for personal information processing systems

Encryption of personal information (one-way encrypted storage of passwords, encrypted storage and transmission of key personal information)

Application of SSL/TLS security server certificates when transmitting and receiving personal information

Installation of security programs and periodic updates and inspections

Operation of security systems such as firewalls and intrusion detection systems against hacking

Retention of access records and prevention of forgery and falsification

Physical Measures

Access control to computer rooms, data storage rooms, etc.

User Precautions

The Company shall not be held responsible for any problems caused by the User's own negligence (such as sharing passwords or transferring them to others) or problems on the Internet. Users are responsible for properly managing their accounts and passwords to protect their personal information.

Article 12 (Personal Information of Children Under 14)

When the Company collects personal information of children under 14, the consent of the legal representative must be obtained. Registration cannot be completed without the consent procedure of the legal representative.

To obtain the consent of the legal representative, minimum information such as the name and contact information of the legal representative may be collected from the child, and will not be used for any purpose other than confirming consent.

Legal representatives may request to view, correct, delete, suspend processing, or withdraw consent regarding the child's personal information, and the Company will respond to such requests without delay.

Article 13 (Privacy Protection Officer and Department)

The Company has designated a Privacy Protection Officer as follows to take overall responsibility for the handling of personal information and to handle complaints and damage relief related to personal information processing.

Privacy Protection Officer

Name: Deniz Albayrak

Affiliation/Title: AvoLabs / CEO

Contact: deniz@avo-lingo.com

Privacy Protection Manager

Name: İsmail Ozan KAYACAN

Affiliation/Title: AvoLabs / CTO

Contact: ismail@avo-lingo.com

Data subjects may contact the Privacy Protection Officer or the responsible department for any inquiries, complaints, or damage relief related to personal information protection that arise while using the Company's services. The Company will respond to and process inquiries from data subjects without delay.

Article 14 (Remedies for Infringement of Data Subjects' Rights and Interests)

Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, etc. to receive relief for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following institutions.

Institution

Website

Phone

Personal Information Dispute Mediation Committee

www.kopico.go.kr

1833-6972

Personal Information Infringement Report Center

privacy.kisa.or.kr

118 (no area code required)

Supreme Prosecutors' Office Cyber Investigation Division

www.spo.go.kr

1301 (no area code required)

National Police Agency Cyber Investigation Bureau

ecrm.police.go.kr

182 (no area code required)

In addition, persons whose rights or interests have been infringed by the disposition or omission of the head of a public agency in response to a request under Articles 35 (View of Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.

Central Administrative Appeals Commission: 110 (no area code required), www.simpan.go.kr

Article 15 (Changes to the Privacy Policy)

This Privacy Policy shall be effective from the date of enforcement, and in the event of additions, deletions, or corrections of changes in accordance with laws and policies, notice will be given through announcements at least 7 days before the implementation of the changes.

However, in the event of important changes to User rights, notice will be given at least 30 days in advance, and the consent of Users may be obtained again if necessary.

Supplementary Provisions

This Privacy Policy shall be effective from June 1, 2026.