AvoLabs Co., Ltd. (hereinafter "the Company") values the personal information of members (hereinafter "Users" or "Data Subjects") who use the AvoLingo service (hereinafter "the Service") operated by the Company, and complies with relevant laws and regulations including the Personal Information Protection Act (PIPA) and the Act on Promotion of Information and Communications Network Utilization and Information Protection. Through this Privacy Policy, the Company informs Users of the purposes and methods by which their personal information is processed and the measures taken to protect their personal information.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes and does not use processed personal information for any purposes other than those listed below. If the purpose of use is changed, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
Performance of Service Contracts and Settlement of Fees: Content provision, identity verification, purchase and payment, billing, and settlement
Member Management: Identity verification for member-based services, personal identification, prevention of fraudulent use by unauthorized users, confirmation of intent to join, age verification, confirmation of legal guardian consent when collecting personal information of children under 14, customer consultation, delivery of notices, and record retention for dispute resolution
New Service Development and Customized Service Provision: Verification of service effectiveness, analysis of access frequency, and provision of services based on demographic characteristics
Marketing and Advertising: Provision of event and promotion information, delivery of advertising information (with separate consent), provision of customized advertising through third-party advertising platforms, and customer surveys
Use of Pseudonymized Information: Pseudonymization and use of pseudonymized data for statistical purposes, scientific research, and preservation of public interest records
Article 2 (Items and Methods of Personal Information Collection)
The Company collects personal information for purposes such as member registration, service provision, customer consultation, and marketing as follows. If a User does not consent to the collection and use of personal information, membership registration may be restricted or use of certain services may be limited.
1. Member Registration and Service Use
The Company collects the following personal information during member registration and service use.
Standard Registration
Required
Email, password, gender, year of birth
Social Registration (Common)
Required
SNS identifier (SNS ID)
Social Registration (Kakao)
Required
Nickname, profile picture, email, year of birth, Kakao Talk channel addition status and history, phone number
Optional
Gender, age range
Social Registration (Google)
Required
Social Registration (Apple)
Optional
2. Payment and Settlement
During the app or web payment process, payment information may be collected and processed by payment gateway (PG) companies, and the Company does not directly store Users' payment information such as card numbers. However, for the purposes of payment history and refund processing, information such as payment date, payment amount, and payment method (card issuer name, etc.) is transmitted to and stored by the Company.
3. Customer Consultation
During the consultation process through the customer center, the following information may be collected via web pages, email, chat (Kakao Business, Channel Talk), and phone.
Items collected: Email address, consultation content (including text, images, and videos), and call recording information
4. Marketing and Advertising
Personal information may be collected upon obtaining separate consent during events, promotions, and surveys conducted for marketing purposes. When additional collection occurs, the Company will inform members in advance of the items, purposes, and retention period and obtain separate consent at that time.
5. Information Automatically Collected During Service Use
The following information may be automatically generated and collected during the use of the mobile app and web service.
IP address, visit date and time, service usage records, abuse records
Purpose of Collection
Prevention of fraudulent use, security incident response, statistical analysis
Cookies, browser type and OS, device information
Purpose of Collection
Service usage statistics and provision of customized services
Advertising identifiers (Android AAID, iOS IDFA)
Purpose of Collection
Provision of customized advertising and analysis of advertising effectiveness
Search terms, service usage records
Purpose of Collection
Service improvement and statistical analysis
6. Restrictions on Collection of Sensitive Information and Unique Identification Information
The Company collects only the minimum personal information necessary for service provision and, in principle, does not collect sensitive information (race, religion, ideology, place of origin, place of family register, political views and criminal records, health status, genetic information, etc.) or unique identification information (resident registration number, passport number, driver's license number, alien registration number) that may infringe upon Users' fundamental human rights. Exceptions apply when collection is permitted by law or the User has provided separate consent.
Article 3 (Retention and Use Period of Personal Information)
The Company processes and retains personal information within the retention and use period prescribed by law or the period consented to by the data subject when collecting personal information. When the purpose of use is achieved or the member directly withdraws, the personal information is destroyed without delay using methods that prevent recovery.
1. Member Information
Personal information collected at the time of member registration: Retained until membership withdrawal, then destroyed
However, in accordance with the Company's internal policy, the following information will be retained for one (1) year after membership withdrawal for the reasons below.
Reasons for retention: Prevention of re-registration by abusive users, dispute resolution related to defamation and other rights violations, and cooperation with investigations
Retained items: Email, SNS identifier, and reason for withdrawal
2. Retention in Accordance with Relevant Laws
Act on the Consumer Protection in Electronic Commerce
Retained Items
Records on contracts or withdrawal of subscription
Retention Period
5 years
Act on the Consumer Protection in Electronic Commerce
Retained Items
Records on payment and supply of goods
Retention Period
5 years
Act on the Consumer Protection in Electronic Commerce
Retained Items
Records on consumer complaints or dispute resolution
Retention Period
3 years
Act on the Consumer Protection in Electronic Commerce
Retained Items
Records on labeling and advertising
Retention Period
6 months
Protection of Communications Secrets Act
Retained Items
Service usage logs (access records)
Retention Period
3 months
Electronic Financial Transactions Act
Retained Items
Records on electronic financial transactions
Retention Period
5 years
Framework Act on National Taxes
Retained Items
All books and supporting documents related to transactions stipulated by tax law
Retention Period
5 years
Note
The validity period system for personal information (mandatory separate storage of dormant accounts) under the Act on Promotion of Information and Communications Network Utilization and Information Protection was abolished as of September 15, 2023.
However, the Company may operate a separate dormancy policy based on its own internal standards to protect the personal information of long-term inactive members, in which case prior notice will be given to members.
Article 4 (Provision of Personal Information to Third Parties)
The Company uses Users' personal information within the scope notified in Article 1 and, in principle, does not use it beyond that scope or disclose it externally without the prior consent of the User. However, the following are exceptions.
When the User has consented to third-party provision in advance
When required by law or when there is a request from an investigative agency in accordance with the procedures and methods prescribed by law for investigative purposes
When providing pseudonymized information for statistical purposes, scientific research, or preservation of public interest records (pseudonymized information)
When transferring or succeeding rights and obligations of the service provider due to the transfer of all or part of the business, mergers and acquisitions, etc. (In such cases, the Company will provide detailed notice in advance and grant the right to withdraw consent on personal information collection and use.)
Note: Currently, the Company does not regularly provide Users' personal information to third parties. When third-party provision becomes necessary in the future, the Company will inform Users in advance of the recipient, purpose of provision, items provided, and retention and use period, and obtain separate consent.
Article 5 (Consignment of Personal Information Processing)
The Company outsources personal information handling tasks to external specialized companies as follows for smooth service provision. When entering into consignment contracts, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies matters such as the prohibition of processing personal information beyond the purpose of the consigned work, technical and managerial protection measures, restrictions on re-consignment, supervision of the consignee, and liability for damages.
Domestic Consignment
Consignee
Consigned Work
Retention and Use Period
Google Cloud Platform
Server operation and data storage
Until membership withdrawal or termination of consignment contract
Amazon Web Services, Inc.
Server operation and data storage
Until membership withdrawal or termination of consignment contract
Microsoft Azure
Server operation and data storage
Until membership withdrawal or termination of consignment contract
Danal Co., Ltd.
Identity verification service
In accordance with the retention period provided by the company
Kakao Corp.
SMS and notification message delivery
Until membership withdrawal or termination of consignment contract
Kakao Pay Corp. / KG INISIS, Inc. / Naver Finance Inc.
Electronic payment and billing service
Until membership withdrawal or termination of consignment contract
Channel Corporation
Chat and customer consultation service
Until membership withdrawal or termination of consignment contract
When the contents of consigned work or consignee changes, the Company will disclose this through this Privacy Policy.
Article 6 (Overseas Transfer of Personal Information)
The Company consigns personal information to global companies (overseas transfer) as follows for service use and marketing efficiency, and in accordance with Article 28-8 of the Personal Information Protection Act, prior notice is provided to the data subject and consent is obtained.
Recipient (Contact)
Country
Date and Method of Transfer
Items Transferred
Purpose of Transfer
Retention and Use Period
Braze, Inc. (privacy@braze.com)
United States
Transmission via network during service use
Email, phone number, device ID
Mobile app usage analysis, push notifications, and email delivery
Until membership withdrawal or termination of consignment contract
Google AdMob, Inc.
United States
Transmission via network during service use
Advertising identifiers, service usage records, etc.
Provision of customized advertising and analysis of advertising effectiveness
In accordance with Google's Privacy Policy
Amazon Web Services, Inc.
United States
Transmission via network during service use
All member information necessary for service operation
Cloud infrastructure (server) operation
Until membership withdrawal or termination of consignment contract
How to Refuse Overseas Transfer: Data subjects may refuse overseas transfer by sending an email to the Privacy Protection Officer (deniz@avo-lingo.com). However, refusing overseas transfer may limit the use of services that include the relevant functions.
Article 7 (Procedure and Method of Destroying Personal Information)
In principle, the Company destroys the relevant personal information without delay when the purpose of processing personal information has been achieved. The procedures, deadlines, and methods of destruction are as follows.
Destruction Procedure: Information entered by the User is transferred to a separate database (or a separate document file in the case of paper) after the purpose is achieved and is destroyed after being stored for a certain period in accordance with internal policy and other relevant laws. Personal information transferred to the DB will not be used for any other purpose except as required by law.
Destruction Deadline: Users' personal information will be destroyed within 5 days from the end of the retention period when the retention period has elapsed, and within 5 days from the date when the personal information is deemed unnecessary due to the achievement of the purpose of processing, abolition of the service, or termination of the business.
Method of Destruction:
Personal information stored in electronic file format will be deleted using technical methods (such as Low Level Format) that prevent the records from being recovered.
Personal information printed on paper will be destroyed by shredding or incineration.
Article 8 (Rights and Obligations of Data Subjects and Legal Representatives and Methods of Exercise)
Data subjects may exercise the following personal information protection-related rights against the Company at any time.
Request to view personal information
Request for correction in case of errors
Request for deletion
Request to suspend processing
Withdrawal of consent (membership withdrawal)
The exercise of rights against the Company may be made through the in-app settings menu directly, or by writing, telephone, email, or fax, and the Company will take action without delay.
If the data subject requests correction or deletion of errors in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
Rights may also be exercised through a legal representative or an authorized agent of the data subject. In this case, a power of attorney in accordance with Form No. 11 attached to the Notice on Methods of Personal Information Processing (Notice No. 2020-7) must be submitted.
Data subjects shall not violate the Personal Information Protection Act and other relevant laws regarding the personal information and privacy of themselves or others processed by the Company.
Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
The Company uses "cookies" and "advertising identifiers" that store and retrieve usage information to provide customized services to Users.
1. Cookies
Cookies are small pieces of information sent by the server operating the website to the User's browser and are sometimes stored on the hard disk of the User's PC.
Purpose of Use: To understand the visit and usage patterns of each service and website visited by the User, popular search terms, and secure access status, and to provide optimized information to the User.
How to Refuse: Users have the option to choose whether to install cookies. Therefore, by setting options in the web browser, Users may allow all cookies, confirm each time a cookie is saved, or refuse to save all cookies.
Internet Explorer: Tools menu → Internet Options → Privacy → Settings
Chrome: Settings menu → Privacy and security → Cookies and other site data
Safari: Preferences menu → Privacy → Cookies and website data
Edge: Settings menu → Cookies and site permissions → Manage and delete cookies and site data
However, refusing to save cookies may cause difficulties in using some services that require login.
2. Advertising Identifiers
In the mobile app environment, the Company may collect Android's AAID and iOS's IDFA for customized advertising and statistical analysis.
How to Refuse (Operating System Settings):
Android: Settings → Privacy → Ads → Delete advertising ID (or Opt out of Ads Personalization)
iOS: Settings → Privacy & Security → Tracking → Disable "Allow Apps to Request to Track"
Article 10 (Processing of Pseudonymized Information)
The Company may process pseudonymized information without the consent of the data subject for statistical purposes, scientific research, and preservation of public interest records. In such cases, the Company takes safety measures in accordance with Articles 28-2 through 28-7 of the Personal Information Protection Act and does not process pseudonymized information for the purpose of identifying specific individuals.
Purpose of Processing Pseudonymized Information: Development of new services and improvement of existing services through analysis of service usage patterns, and academic research
Items of Pseudonymized Information: Pseudonymized information of service usage records, learning activity data, and demographic information (gender, year of birth), etc.
Retention Period of Pseudonymized Information: Until the purpose of processing pseudonymized information is achieved
Security Measures: Separate storage of pseudonymized information and additional information, access control, and retention of access records
Article 11 (Measures to Ensure the Safety of Personal Information)
In accordance with Article 29 of the Personal Information Protection Act, the Company takes the following technical, managerial, and physical measures necessary to ensure safety.
Managerial Measures
Establishment and implementation of an internal management plan
Minimization of personnel handling personal information and regular employee training
Operation of a dedicated personal information protection organization
Technical Measures
Access rights management and installation of access control systems for personal information processing systems
Encryption of personal information (one-way encrypted storage of passwords, encrypted storage and transmission of key personal information)
Application of SSL/TLS security server certificates when transmitting and receiving personal information
Installation of security programs and periodic updates and inspections
Operation of security systems such as firewalls and intrusion detection systems against hacking
Retention of access records and prevention of forgery and falsification
Physical Measures
Access control to computer rooms, data storage rooms, etc.
User Precautions
The Company shall not be held responsible for any problems caused by the User's own negligence (such as sharing passwords or transferring them to others) or problems on the Internet. Users are responsible for properly managing their accounts and passwords to protect their personal information.
Article 12 (Personal Information of Children Under 14)
When the Company collects personal information of children under 14, the consent of the legal representative must be obtained. Registration cannot be completed without the consent procedure of the legal representative.
To obtain the consent of the legal representative, minimum information such as the name and contact information of the legal representative may be collected from the child, and will not be used for any purpose other than confirming consent.
Legal representatives may request to view, correct, delete, suspend processing, or withdraw consent regarding the child's personal information, and the Company will respond to such requests without delay.
Article 13 (Privacy Protection Officer and Department)
The Company has designated a Privacy Protection Officer as follows to take overall responsibility for the handling of personal information and to handle complaints and damage relief related to personal information processing.
Privacy Protection Officer
Name: Deniz Albayrak
Affiliation/Title: AvoLabs / CEO
Contact: deniz@avo-lingo.com
Privacy Protection Manager
Name: İsmail Ozan KAYACAN
Affiliation/Title: AvoLabs / CTO
Contact: ismail@avo-lingo.com
Data subjects may contact the Privacy Protection Officer or the responsible department for any inquiries, complaints, or damage relief related to personal information protection that arise while using the Company's services. The Company will respond to and process inquiries from data subjects without delay.
Article 14 (Remedies for Infringement of Data Subjects' Rights and Interests)
Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, etc. to receive relief for personal information infringement. For other reports and consultations regarding personal information infringement, please contact the following institutions.
Institution
Website
Phone
Personal Information Dispute Mediation Committee
1833-6972
Personal Information Infringement Report Center
privacy.kisa.or.kr
118 (no area code required)
Supreme Prosecutors' Office Cyber Investigation Division
1301 (no area code required)
National Police Agency Cyber Investigation Bureau
ecrm.police.go.kr
182 (no area code required)
In addition, persons whose rights or interests have been infringed by the disposition or omission of the head of a public agency in response to a request under Articles 35 (View of Personal Information), 36 (Correction and Deletion of Personal Information), and 37 (Suspension of Processing of Personal Information) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
Central Administrative Appeals Commission: 110 (no area code required), www.simpan.go.kr
Article 15 (Changes to the Privacy Policy)
This Privacy Policy shall be effective from the date of enforcement, and in the event of additions, deletions, or corrections of changes in accordance with laws and policies, notice will be given through announcements at least 7 days before the implementation of the changes.
However, in the event of important changes to User rights, notice will be given at least 30 days in advance, and the consent of Users may be obtained again if necessary.
Supplementary Provisions
This Privacy Policy shall be effective from June 1, 2026.