Back to Trust & Policies
Legal

Privacy Policy

Flotic LC. (유한회사 플로틱) · Effective: August 8, 2026 (announced July 29, 2026) · Previous version: May 1, 2026

Language: 한국어 English

1. General

Flotic LC. (유한회사 플로틱, the "Company") processes personal information in accordance with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., the Framework Act on E-Commerce and other applicable laws, and publishes this Privacy Policy for the Bok mobile application and related services (the "Service") to protect users and facilitate the exercise of their rights.

2. Collection and use of personal information

To provide the Service, the Company collects and uses personal information as described below. Information will not be used for purposes other than those stated; if purposes change, we will obtain your consent in advance. a. Items and purposes Membership and identity verification — Items: legal name, mobile number, six-digit date of birth, and identity-verification results (CI/DI). Purposes: identifying users, preventing duplicate sign-ups, family matching, and authentication. Welfare information lookup and application support — Items: (for self/family) name, relationship, residential address and administrative district code, income and asset information, household composition, etc. (when linked); (application drafts) all information entered in application forms (JSON). Purposes: personalized welfare recommendations, public-service application assistance, and automated drafting support. Device and service usage records — Items: device unique ID (UUID), FCM push token, service usage logs, access timestamps, and timestamp of the last successful identity verification. Purposes: fraud prevention; service and transactional notifications (including security alerts and notifications you enable for welfare benefits and schedules); push delivery infrastructure; security; and service quality improvement. Promotional or advertising messages (e.g. promotions, events, membership benefits) are sent only if you give separate optional consent under "Marketing communications consent" below. Automated intelligent services and document assistance — Items: document or handwriting images captured or selected from the gallery, and consent records for use of automated intelligent services. Purposes: OCR-based field mapping and legal/drafting support assisted by automated intelligent services. Payment and membership (where applicable) — Items: payment amount, payment method identifiers, order numbers, etc. Purposes: paid features and payment/refund processing. Mail and reminders — Items: name and address needed for mailing, and family schedule/care reminder settings. Purposes: e-Green Post and similar dispatch, and shared family schedules/notifications. b. How we collect Direct input: information you enter on Service screens. Technical linkage: information obtained with your consent from public data (Government24, Bokjiro, etc.) and MyData APIs (including external welfare inquiry services). Automatic generation: logs and device information generated during operation. File upload: document images you photograph or select for application support. Cookies and similar technologies: we use cookies, etc., to operate the Service and provide personalized experiences. You may refuse as below; refusal may limit some features. Android: Settings > Privacy > Ads > Reset or delete advertising ID iOS: Settings > Privacy & Security > Tracking > Allow Apps to Request to Track (OFF) Browser: Settings > Privacy and security > Cookies and other site data c. Special technical processing Pseudonymization: we may use pseudonymized data for statistics, usage patterns, and UI/UX improvement. Server-side automation: for in-app application assistance, automated input may run in an isolated session on a secure server; it does not share your device login session, and safe authentication procedures apply. Device permissions: calendar (welfare deadlines), microphone (speech recognition), etc., are used only when you explicitly grant permission in the app for those features. d. Information we do not collect The Company does not collect or track users' real-time GPS location. e. Marketing communications consent (optional) This consent is optional. Declining it will not prevent you from using core Service features such as signup, welfare lookup, or application support (offers or notices that require this consent may not be provided). Items: name, mobile phone number, email address (when provided), FCM push token (used for promotional pushes only when you have consented), and minimal service-usage attributes needed for tailored offers. Purposes: promotional notices about events, discounts, and benefits, including membership coupons, precision analysis packages, registered-mail support fees, seasonal or themed campaigns, new-feature introductions, and promotional in-app banners or notices. Retention: until you withdraw consent or close your account, or longer only where required by law. Withdrawal: you may withdraw at any time through in-app marketing preferences (when available) or by contacting customer support; after withdrawal, use for marketing purposes will stop without affecting the lawfulness of processing based on consent before withdrawal.

3. Third-party disclosure and entrustment of processing

a. Third-party disclosure In principle we do not provide personal information to third parties without consent. However, under Articles 17 and 18 of the Personal Information Protection Act, information may be provided without consent where there is a statutory basis, or where clearly necessary for the urgent protection of the life, body or property of the data subject or a third party (disasters, infectious diseases, etc.). Even then, only the minimum items necessary are provided. Where you proceed with a welfare application in the app and submit application information to a competent administrative or public institution, that submission is made on your express action and consent, and the receiving institution and the items submitted are displayed on the screen immediately before submission. b. Entrustment of processing (domestic) We entrust processing as set out below. In each contract we specify the prohibition on processing outside the entrusted purpose, restrictions on sub-entrustment, security measures, supervision of the processor and liability for damages, and we supervise compliance. 1) Korea Post (e-Green Post) · Entrusted task: postal dispatch (e-Green Post, registered mail) — printing, enveloping and mailing the documents you request · Items: recipient name, address and contact details required for dispatch, and the document dispatched · Retention: until the purpose is achieved (dispatch records for any statutory preservation period) 2) Hyphen Corporation (HYPHEN) · Entrusted task: relaying consented lookups of public and financial information, and relaying simple authentication (PASS, Kakao, Naver, Toss, KB, Shinhan, PAYCO, etc.) · Items: name, date of birth, mobile number and carrier required for identity verification; results of the lookups you request · Retention: destroyed immediately upon completion of the authentication or lookup 3) NAVER Corporation · Entrusted task: map display (locations of nearby welfare facilities and institutions) · Items: coordinates of the area you look up, and map usage logs. Your real-time GPS location is not collected or transmitted. · Retention: until the purpose is achieved If a processor or an entrusted task changes, we will disclose it in this Policy without delay. c. Notice regarding in-app purchases For in-app purchases through the Apple App Store or Google Play, payment credentials (such as card numbers) are not collected by the Company; they are collected and processed directly by the relevant store operator under its own privacy policy. We receive only the minimum information required to verify the purchase, such as payment success, product identifier and order identifier.

3-2. Overseas transfer of personal information

Under Article 28-8 of the Personal Information Protection Act, and to the extent necessary for the conclusion and performance of our contract with you, we transfer personal information overseas (entrustment of processing and storage) as set out below. We disclose the matters listed in Article 28-8(2) as follows, and where the recipients, items or purposes change we will give notice in advance and obtain any consent required. 1) Google LLC (United States) · Contact: support.google.com/policies / 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA · Countries: the United States and the countries in which Google operates data centres · Timing and method: transmitted over the network under encryption (TLS) at the time you use the relevant feature · Items and purposes: (i) Firebase Cloud Firestore — storage and synchronisation of user data needed to operate the Service (ii) Firebase Cloud Messaging — device push token; delivery of notifications (iii) Firebase Crashlytics — device model, OS version, error stack logs; error diagnosis and stability (iv) Firebase Remote Config / App Check — device identifier, app integrity token; remote configuration and blocking of tampered or fraudulent clients (v) Gemini API (generative AI) — the consultation messages and application information you enter, and text recognised from documents; AI-based welfare consultation responses, analysis and generation of draft application wording. The document images themselves are not transferred overseas; optical character recognition (OCR) is performed solely on your device. (vi) Firebase Hosting — IP address, browser and device information and access timestamps when you visit our website (floticinfo.com); website hosting, delivery and security · Retention: destroyed when the purpose of each service is achieved, or immediately upon our deletion request; otherwise for the period set by our agreement with Google and Google's API data processing policy 2) Safeguards applied to overseas transfers · Before transfer we remove or replace directly identifying information such as name, resident registration number, connecting information (CI/DI) and contact details, and limit the items transferred to the minimum necessary. · Transmission is encrypted (TLS), and our contracts with recipients provide for the security, complaint-handling and dispute-resolution measures required by the Personal Information Protection Act and Article 29-10 of its Enforcement Decree. · We do not enter into transfer agreements that breach that Act, and we require an equivalent standard of protection where a recipient onward-transfers to a third country (Article 28-11). · Under our agreements with the recipients and each provider's API terms and data-processing policy, transferred personal information is not used to train artificial intelligence models. We use each API only on a paid tier, where non-use for training is assured; we do not use free tiers, on which inputs may be used for model training. 3) How to refuse an overseas transfer, and the effect of refusing · How to refuse: decline or withdraw consent on the in-app AI consent screen, or notify us at hello@floticinfo.com / +82-10-4831-4686. Closing your account also constitutes refusal. We handle a refusal identically whichever channel you use. · Effect: you will be unable to use the AI welfare consultation feature in 1)(v), but you may continue to use the remaining features, including welfare information lookup and application support. Items 1)(i)–(iv) and (vi) are essential to the operation and security of the app and website; if you refuse them, performance of the service contract becomes impossible and the Service may be restricted or the contract terminated. · Refusal does not affect the lawfulness of processing carried out before the refusal.

4. Retention period and destruction

We retain personal information for the consented retention period or as required by law, then destroy it without undue delay (typically within five days) once the purpose is achieved. a. Information preserved under statute The following is kept separately for the period prescribed by the relevant statute even after you close your account, and is not used for any purpose other than preservation during that period. · Records of contracts and withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce, Etc.) · Records of payment and supply of goods or services: 5 years (same Act) · Records of consumer complaints and dispute resolution: 3 years (same Act) · Records of indications and advertisements: 6 months (same Act) · Records of electronic financial transactions: 5 years (Electronic Financial Transactions Act) · Tax invoices and transaction evidence: 5 years (Framework Act on National Taxes) · Service access (login) logs: 3 months (Protection of Communications Secrets Act) b. Method of destruction Electronic files are deleted irrecoverably; paper documents are shredded or incinerated. c. AI analysis outputs Analysis outputs generated through a paid service are retained for re-access for 24 hours from commencement of delivery and are destroyed automatically thereafter. Processing and destruction of inputs transferred to overseas processors is governed by section 3-2. d. Local (on-device) data To reduce repeated identity verification on the same device, the timestamp of the last successful verification may be stored on that device for up to one year (365 days); it is destroyed when app data or the app is deleted. That information is not transmitted off the device.

5. Security safeguards

Administrative measures: internal management plans, minimizing access to personal information, and training Technical measures: encryption of stored and transmitted personal information, access logs, security software installation and periodic checks Physical measures: access control for server rooms, document storage, and other places where personal information is kept

6. Location information

The Company does not collect, use or provide personal location information within the meaning of the Act on the Protection and Use of Location Information. The app does not request device location permission (GPS or network location) and does not track your location in real time. The map showing nearby welfare facilities and institutions is rendered from the administrative district or address you select or enter yourself; the coordinates processed are those of the area being looked up, not personal location information. Entrustment of map display is described in section 3(b)(4).

7. Connected Information (CI)

With your consent, we process Connected Information (CI) for identity verification, identification across services, and fraud prevention. CI is encrypted and stored separately, with access limited to authorized personnel.

8. Rights of data subjects and legal representatives

(1) You may at any time request access, correction or deletion, suspension of processing, or withdrawal of consent in respect of your personal information. For children under 14, those rights are exercised by their legal representative. (2) Requests may be made in writing, by email, by telephone or through in-app customer support. We will act on a request and inform you of the outcome within 10 days of receiving it (Articles 44 and 46 of the Enforcement Decree of the Personal Information Protection Act). We do not delay processing without justification or require a particular channel. (3) On request to customer support you may obtain your personal information in a structured, commonly used format (CSV, JSON, etc.), and we will provide it within 10 days of the request. Where an in-app data download feature is provided, you may also use that feature. (4) Department receiving and handling access requests · Department: Customer Support (reporting to the data protection officer) · Contact: hello@floticinfo.com · +82-10-4831-4686 (5) If you disagree with our response, you may report the matter to, or seek counselling from, the bodies listed in section 9.

8-2. AI disclosure and rights regarding automated decisions

a. Prior disclosure of artificial intelligence In accordance with Article 31 of the Framework Act on the Development of Artificial Intelligence and the Establishment of a Basis for Trust, we disclose that Bok's welfare information guidance, document recognition (OCR), eligibility analysis and drafting features are operated on the basis of generative artificial intelligence. We label outputs generated by AI as such, on the results screen and in generated documents. Overseas transfer of personal information used for AI analysis is described in section 3-2; withdrawal of consent is described in section 3-2(3). b. Rights of data subjects regarding automated decisions Under Article 37-2 of the Personal Information Protection Act: · What is decided: we analyse household composition, income and asset information, area of residence and similar data that you enter or link, using a rule-based evaluation engine and artificial intelligence, and produce an indication of likely eligibility (a recommendation or suitability score) for each welfare programme. · Criteria and procedure: the published eligibility requirements of each programme (income thresholds, household size, age, residency, etc.) are compared condition by condition, and the items and threshold values relied on are shown alongside the result. · Nature of the result — important: the output is guidance for reference only and is not a final decision producing legal or similarly significant effects. Actual eligibility, amounts and application outcomes are determined solely by the review and decision of the competent authority. A negative result from our analysis does not restrict your right to apply for the programme in any way. · Your rights: you may request an explanation of the automated analysis, refuse it, or request human review. Requests may be made through in-app customer support or to the data protection officer in section 9, and we will notify you of the outcome and reasons within 30 days of receipt. · Effect of refusal: if you refuse automated analysis you may still use the remaining features, including searching and reading welfare information and obtaining application forms.

9. Data protection officer and complaints

For inquiries and complaints about personal information processing, contact the data protection officer below.

Data protection officer

Name: Park Ju-seong (CEO)
Phone: +82-10-4831-4686
Email: hello@floticinfo.com
Address: 3F 301, Munin-ro 57, Suji-gu, Yongin-si, Gyeonggi-do (Samik Sangga), South Korea

For other reports or counseling on personal information infringement, you may contact the following institutions (independent of the Company): Personal Information Infringement Report Center: 118 (no area code) Personal Information Dispute Mediation Committee: 1833-6972 Cyber Investigation Department, Supreme Prosecutors' Office: 1301 (no area code) Cyber Investigation Bureau, National Police Agency: 182 (no area code)

10. Changes to this Policy

(1) This Policy may be revised in line with changes in law or in Service features. Material changes are announced in the Service and by in-app notification at least seven days before they take effect (at least 30 days in advance where the change is unfavourable to users). (2) We keep previous versions so that users can compare the text before and after a revision; you may request an earlier version from customer support. (3) Principal changes in the revision of August 8, 2026 1. New and corrected overseas-transfer disclosure (section 3-2) — the previous statement that "we do not transfer personal information overseas at this time" was inaccurate and has been removed. Transfers to Google LLC (Firebase and Gemini) are now disclosed in detail, together with the items, purposes, retention periods and how to refuse. 2. The list of domestic processors is now disclosed specifically (section 3(b)). 3. It is made clear that the Company does not collect payment credentials for in-app purchases (section 3(c)). 4. Statutory preservation periods (5 years / 3 years / 6 months / 3 months) are specified (section 4(a)). 5. New prior disclosure of the use of artificial intelligence, and rights to explanation, refusal and human review of automated decisions (section 8-2). 6. The department receiving access requests, and how to download your data, have been added (section 8).

Effective date

This Privacy Policy takes effect on August 8, 2026 (announced July 29, 2026). The previous policy (effective May 1, 2026) ceases to have effect on that date. This English text is a courtesy translation of the Korean original. If there is any discrepancy, the Korean version prevails, except where the English version is more favourable to the user.