CLFY Co., LTD (the “Company”) values the personal information of users who use TurnFlow and its related websites (the “Service”) and complies with the Personal Information Protection Act of Korea and other applicable laws and regulations. The Company processes personal information lawfully and transparently, and makes best efforts to protect users’ rights and interests.
This Privacy Policy applies to the TurnFlow Service and its related websites, including the landing page, inquiry page, member page, and creator page. This Policy applies to services provided under the turnflow.link domain, and may apply in the same or similar form to the Company’s other official domains depending on how the service is provided.
1. Personal Information Collected and Collection Methods
A. Information provided directly by the user
The Company may collect the following personal information for membership registration, login, service use, inquiry handling, and payment processing.
1) Membership registration and account management
- Required: email address, password, name
- Optional: profile information, any additional information entered by the user
- When using social login: Google account email, name, profile identifiers, and other information necessary for providing the Service
2) Items planned for real-name verification
If required by law or for service operations, the Company may introduce an identity verification service in the future. In that case, the following information may be collected as provided by the verification 기관: name, date of birth, gender, mobile phone number, telecom carrier information, CI/DI, etc. If introduced, the Company will provide notice separately or through an amendment to this Policy.
3) When using inquiry/subscription features on a Creator page
If a user uses the inquiry or subscription feature on a creator’s TurnFlow page, the following information may be entered:
- name or nickname
- email address
- contact information (phone number)
- inquiry title and inquiry content
- other information voluntarily entered by the user
4) When using payment and subscriptions
To provide paid services, the Company may process:
- subscription product name, subscription status, payment date/time, payment amount, payment method (category)
- transaction number, recurring payment number, receipt URL, payment status
- minimal information necessary for refunds and customer support
However, sensitive payment information such as credit card number, expiry date, CVC, and bank account number is not stored by the Company and is processed by the payment gateway provider (PG), PayApp.
5) When connecting Instagram/Meta
When a user uses the Meta or Instagram connection feature within the Service, the Company may process:
- Instagram username
- Instagram account ID
- account type (Business/Creator, etc.)
- OAuth access token and token expiry information
- scope/permission information required for the connection
In addition, within the scope of the permissions granted and features used, the Company may process Instagram/Meta data for access, collection, storage, use, and deletion, including:
- profile information (e.g., profile name, profile photo URL)
- post/comment information (e.g., comment text, comment ID, author identifiers, timestamp)
- message information (e.g., message text, message ID, sender/recipient identifiers, timestamp)
Typical requested permissions may include basic, comments, messages. The actual scope of processed data may vary depending on the permissions consented to and features used.
6) When using AI features
To provide AI-based features such as bio generation, theme generation, copy generation, and block generation, the Company may process:
- user input data (concept, style, descriptions, existing page information, etc.)
- the final prompt combining system prompts and user inputs
- AI outputs such as text, blocks, colors, and layouts
The Company recommends that users avoid including personal information in free-form inputs. If personal information is included, it will be processed in accordance with this Policy and applicable laws.
B. Information collected automatically during service use
The Company may automatically collect:
- access time
- service usage records
- device information such as browser type and OS
- access logs
- cookies
- hashed IP address
- country code
- referrer information
- page views and click records
- service-related statistics
The Company does not store the raw IP address and stores only a value converted via SHA-256 one-way hashing. Country codes may be stored based on Cloudflare headers or GeoIP databases, and referrers may be stored at the domain/service level rather than the full URL. The Company may also process click target IDs, timestamps, country codes, IP hash, and referrer for analytics and fraud prevention purposes when blocks or links are clicked.
C. Collection methods
The Company collects personal information through:
- user input on the website, sign-up, login, inquiry, and payment screens
- external authentication flows such as Google login
- Meta/Instagram connection flows
- automatically generated information collected during service use
- customer support, email inquiries, and event/promotion participation
- inquiry/subscription features on creator pages
2. Purposes of Use
The Company uses collected personal information for:
- user identification, confirmation of sign-up intent, login, and account management
- handling external authentication such as Google login
- service provision, page creation/management, and workspace operations
- receiving and forwarding inquiries submitted via creator pages
- paid product provision, recurring payment management, payment confirmation, refunds, and receipt issuance
- providing Instagram/Meta connection features (including processing connected profile/comments/messages data)
- AI feature provision, quality improvement, incident response, regeneration, and history management
- statistical analysis (access, usage, clicks) and service quality improvement
- fraud prevention, abnormal access detection, security, and service stability
- dispute handling, complaint processing, notices, and legal compliance
The Company processes personal information only within the scope of the purposes for which it was collected.
3. Provision to Third Parties
In principle, the Company does not provide personal information to third parties. Exceptions include:
- where the user has consented in advance
- where disclosure is required by law
- where requested by investigative agencies, courts, or government agencies through lawful procedures
- where provision is necessary within the scope required for an external service that the data subject/user directly requests to connect for service provision
When using the Meta/Instagram connection feature, personal information may be linked to Meta systems to the extent necessary for the connection and related functionality. Also, inquiry/subscription information entered on a creator page may be viewed and managed by the creator who operates that page.
4. Outsourcing of Personal Information Processing
To provide services smoothly, the Company may outsource personal information processing or use external services as follows.
A. Current vendors
- Google LLC
- Scope: social login (Google login), business storage/management tools, and other Google services used for operations
- Data processed: email, name, authentication information, and user inputs as necessary for the feature
- Cloudflare, Inc.
- Scope: CDN, image delivery, security, traffic protection, frontend deployment, and network optimization
- Data processed: access information, IP-related information, country code, request/response information, and information processed during image/static resource delivery
- PayApp
- Scope: payment processing, recurring payment management, receipt issuance, and payment status notifications
- Data processed: payment-related identifiers, transaction number, recurring payment number, payment status, payment amount, receipt URL, etc.
B. Planned or additional vendors
- DeepSeek (if introduced)
- Scope: AI feature provision
- Data processed: user input text, prompts, generation request information, and other data necessary for AI feature provision
- Note: Applies from the date of actual integration; the Company will provide notice via amendments or separate notices as needed.
The Company enters into outsourcing agreements in accordance with applicable laws and supervises vendors to ensure safe processing.
5. Cross-border Transfer of Personal Information
During service provision, personal information may be transferred overseas as described below. The Company complies with legal notice and safeguard requirements, including the obligation to disclose cross-border outsourcing.
A. Transfer details
- Google LLC
- Recipient: Google LLC
- Destination country: United States and other countries where Google operates
- Items transferred: email, name, authentication information, and user inputs necessary for the feature
- Purpose: Google login; operation of business storage/management tools
- Timing/method: transmitted over the network upon login, information entry, or service use
- Retention period: until purpose is fulfilled or for the period required by law/contract
- Cloudflare, Inc.
- Recipient: Cloudflare, Inc.
- Destination country: United States and other countries where Cloudflare operates
- Items transferred: access information, IP-related information, country code, request information, static resource delivery information
- Purpose: CDN, traffic protection, security, frontend deployment, and image delivery
- Timing/method: transmitted over the network when accessing the Service
- Retention period: until purpose is fulfilled or per each provider’s policy
- DeepSeek (if introduced)
- Recipient: DeepSeek or its affiliates/infrastructure providers
- Destination country: where the service infrastructure operates
- Items transferred: input data, prompts, and generation request information necessary for AI features
- Purpose: AI feature provision
- Timing/method: transmitted over the network when using AI features
- Retention period: until purpose is fulfilled or per each provider’s policy
If the cross-border transfer structure changes, the Company will revise this Policy accordingly.
6. Retention and Use Period
In principle, the Company destroys personal information without delay once the purpose of collection and use is achieved. However, if required by applicable laws, the Company retains information for the required period.
A. General retention periods
- Member account information
- retained until membership withdrawal
- may be retained separately under applicable laws or internal criteria in cases such as legal violations, fraud, or dispute response needs
- Creator page inquiry/subscription information
- 3 years from collection date or until deletion requested by the data subject
- if managed directly by the creator, the Company retains/processes only within the scope necessary for service provision
- AI input data, prompts, and generated outputs
- 12 months from the date of generation
- may be destroyed without delay within the scope where there is no legal/dispute necessity if deleted by the user or upon membership withdrawal
- Instagram/Meta connected data (profile/comments/messages, etc.)
- until connection is removed or purpose is achieved
- if deletion is requested via the Service or customer support, processed without delay in accordance with applicable laws and platform policies
- Page visit and click analytics data
- 12 months from collection date
- Workspace invitation information
- 30 days after invitation acceptance, expiration, or cancellation
- Customer inquiry and complaint handling records
- 3 years from completion date
These periods are operational standards based on the current service structure and may change due to service or legal changes.
B. Retention required by law
The Company may retain the following for the periods required by law:
- records on 표시·광고: 6 months
- records on contracts or withdrawal of subscription: 5 years
- records on payment and supply of goods/services: 5 years
- records on consumer complaints or dispute resolution: 3 years
- service access logs: 3 months
7. Destruction Procedures and Methods
The Company destroys personal information without delay when it becomes unnecessary due to retention period expiration or purpose achievement.
- Procedure: immediate destruction after purpose achievement/retention expiration; if legally required, stored separately and destroyed after the retention period ends
- Method:
- electronic files: permanently deleted in a way that prevents recovery
- paper documents: shredded or incinerated
Upon membership withdrawal, the Company deletes or separately stores personal information related to the account without delay, except for information required to be retained by law.
8. Rights of Users and Legal Representatives; How to Exercise Rights
Users may request access, correction, deletion, suspension of processing, or withdrawal of consent regarding their personal information at any time. The Company provides a channel for exercising rights and for grievance handling in line with legal requirements.
- How to exercise rights: contact the person in charge of personal information protection or email the contact below
- Upon request, the Company will verify identity and process without delay
- Where permitted by law, the Company may restrict rights or extend processing time, and will inform the reason
If personal information of children under age 14 is processed, legal representatives may exercise the child’s rights.
Users may request deletion of personal information via the email below:
- Email: contact@clfy.ai.kr
- Subject example: Request for deletion of personal information
- For identity verification, the Company may request necessary information such as the email used for sign-up.
Users may also request deletion of Instagram/Meta connected data (profile/comments/messages, etc.) by disconnecting and/or contacting customer support; the Company will process requests without delay in accordance with applicable laws and platform policies.
9. Cookies; Installation/Operation and Opt-out
The Company may use cookies for service provision, security, maintaining login state, analytics, and service improvement.
- Cookies are small information files stored in the user’s browser.
- Cookies may be used for maintaining login state, analyzing access environments, and producing usage statistics.
- Users can refuse or delete cookies via browser settings.
- However, refusing cookies may limit certain login or service functions.
10. Measures to Ensure Security of Personal Information
The Company implements the following measures:
- Administrative: internal management plans, minimizing access rights, minimizing personnel handling personal information, training
- Technical: password hashing, access control, access log management, protection of tokens and other sensitive information, vulnerability response, encryption where applicable
- Physical: access control for systems and workspaces where personal information is stored
Passwords are stored in a non-reversible form. Tokens and other sensitive information required for operations are also protected. The Company minimizes data by not storing raw IP addresses and storing only hashed values.
11. Creator Pages and External Links
TurnFlow enables creators to create and operate their own pages. If a user enters inquiry/subscription information on a creator page, that information may be viewed and managed by the creator who operates the page, and the Company processes it only within a limited scope necessary for storage/delivery and security.
If external websites/services linked from the Service collect personal information separately, their respective policies apply.
12. AI Feature Notice
The Company may process user input data, final prompts, and generated outputs to provide AI features. The Company does not currently use user data directly for model training, and processes it only for purposes such as AI feature provision, quality control, error response, and history review. If external AI providers are used, information may be processed in accordance with their policies, and the Company will provide required notices based on the actual integration structure.
Users should avoid unnecessarily entering third-party personal information, sensitive information, or legally protected information when using AI features.
13. Personal Information Protection Officer and Contact
The Company designates the following person for personal information protection inquiries, complaint handling, and remedy:
- Officer: SiHyeon Kim
- Affiliation/Title: CLFY Co., LTD / Representative
- Phone: 070-8098-7102
- Email: contact@clfy.ai.kr
- Website: https://turnflow.link
For reporting or consultation on personal information infringement:
- Personal Information Dispute Mediation Committee: 1833-6972
- Privacy Infringement Report Center (KISA): 118
- Supreme Prosecutors’ Office: 1301
- National Police Agency: 182
14. Notice of Changes
If this Privacy Policy is amended, the Company will announce the effective date and reason for the change via in-service notices or the website.
- Version: v2.0
- Effective date: April 17, 2026
개인정보 처리방침 (Korean)
주식회사 씨엘에프와이(이하 “회사”)는 회사가 제공하는 TurnFlow 및 관련 웹사이트(이하 “서비스”)를 이용하는 이용자의 개인정보를 중요하게 생각하며, 「개인정보 보호법」 등 관계 법령을 준수합니다. 회사는 이용자의 개인정보를 적법하고 투명하게 처리하고, 이용자의 권익 보호를 위해 최선을 다합니다.
본 개인정보 처리방침은 회사가 제공하는 TurnFlow 서비스 및 이에 부속되는 웹사이트, 랜딩페이지, 문의 페이지, 회원 페이지, 크리에이터 페이지 이용에 적용됩니다. 본 방침은 turnflow.link 도메인에서 제공되는 서비스에 적용되며, 회사의 기타 공식 도메인에서도 서비스 제공 형태에 따라 동일 또는 유사한 내용으로 적용될 수 있습니다.
1. 수집하는 개인정보 항목 및 수집방법
가. 이용자가 직접 제공하는 정보
회사는 회원가입, 로그인, 서비스 이용, 문의 응대, 결제 처리 등을 위해 다음 개인정보를 수집할 수 있습니다.
1) 회원가입 및 계정 관리
- 필수항목: 이메일 주소, 비밀번호, 이름
- 선택항목: 프로필 정보, 이용자가 추가로 입력하는 정보
- 소셜 로그인 이용 시: 구글 계정의 이메일, 이름, 프로필 식별 정보 등 회사가 서비스 제공에 필요한 범위의 정보
2) 실명인증 도입 예정 항목
회사는 향후 관련 법령 또는 서비스 운영상 필요에 따라 본인확인 서비스를 도입할 수 있습니다. 이 경우 이름, 생년월일, 성별, 휴대전화번호, 통신사 정보, CI/DI 등 본인확인기관이 제공하는 정보가 수집될 수 있으며, 실제 도입 시 별도 고지 또는 본 방침 개정을 통해 안내합니다.
3) 크리에이터 페이지 문의/구독 기능 이용 시
이용자가 크리에이터의 TurnFlow 페이지에서 문의 또는 구독 기능을 이용하는 경우 다음 정보가 입력될 수 있습니다.
- 이름 또는 닉네임
- 이메일 주소
- 연락처(전화번호)
- 문의 제목 및 문의 내용
- 기타 이용자가 자율적으로 입력한 정보
4) 결제 및 구독 이용 시
회사는 유료 서비스 제공을 위하여 다음 정보를 처리할 수 있습니다.
- 구독 상품명, 구독 상태, 결제일시, 결제 금액, 결제 수단 정보(범주)
- 거래번호, 정기결제번호, 영수증 URL, 결제 상태
- 환불 처리 및 고객 응대를 위한 최소 정보
다만, 신용카드 번호, 카드 유효기간, CVC, 계좌번호 등 민감한 결제정보는 회사가 직접 저장하지 않으며, 전자결제대행사(PG사)인 PayApp이 처리합니다.
5) 인스타그램/Meta 연동 시
회사는 이용자가 서비스 내에서 Meta 또는 Instagram 연동 기능을 사용하는 경우 다음 정보를 처리할 수 있습니다.
- 인스타그램 사용자명
- 인스타그램 계정 ID
- 계정 유형(Business/Creator 등)
- OAuth 액세스 토큰 및 토큰 만료 정보
- 연동에 필요한 권한 범위(scope) 정보
추가로, 이용자가 연동 권한을 부여하고 서비스 기능을 사용하는 범위 내에서 회사는 다음과 같은 Instagram/Meta 데이터의 조회·수집·저장·이용·삭제를 처리할 수 있습니다.
- 프로필 정보(예: 프로필명, 프로필 사진 URL 등)
- 게시물/댓글 관련 정보(예: 댓글 내용, 댓글 ID, 작성자 식별정보, 작성 시각 등)
- 메시지 관련 정보(예: 메시지 내용, 메시지 ID, 발신/수신 식별정보, 전송 시각 등)
회사가 요청할 수 있는 대표적인 권한은 basic, comments, messages이며, 실제 처리되는 데이터의 범위는 이용자가 동의한 권한 및 이용 기능에 따라 달라질 수 있습니다.
6) AI 기능 이용 시
회사는 AI 기반 바이오 생성, 테마 생성, 문구 생성, 블록 생성 등 기능 제공을 위해 다음 정보를 처리할 수 있습니다.
- 이용자가 입력한 컨셉, 스타일, 설명, 기존 페이지 정보 등 입력 데이터
- 시스템 프롬프트와 이용자 입력을 조합한 최종 프롬프트
- AI가 생성한 텍스트, 블록, 색상, 구성안 등 결과 데이터
회사는 이용자가 자유롭게 입력한 내용에 개인정보가 포함되지 않도록 권장합니다. 이용자가 입력한 내용에 개인정보가 포함된 경우에도 본 방침 및 관련 법령에 따라 처리합니다.
나. 서비스 이용 과정에서 자동으로 수집되는 정보
회사는 서비스 이용 과정에서 다음 정보를 자동으로 수집할 수 있습니다.
- 접속 일시
- 서비스 이용기록
- 브라우저 종류 및 OS 등 기기 정보
- 접속 로그
- 쿠키
- IP 주소의 해시값
- 국가 코드
- 유입경로(Referer) 정보
- 페이지 조회 및 클릭 기록
- 서비스 이용 관련 통계 정보
이 중 IP 주소는 원문을 저장하지 않고, SHA-256 단방향 해시 방식으로 변환한 값만 저장합니다. 국가 코드는 Cloudflare 헤더 또는 GeoIP 데이터베이스 등을 바탕으로 저장될 수 있으며, Referer는 전체 URL이 아닌 도메인 또는 서비스명 수준으로 저장될 수 있습니다. 또한 회사는 블록 또는 링크 클릭 시 클릭 대상 ID, 일시, 국가 코드, IP 해시, Referer 등을 이용통계 및 부정 이용 방지 목적으로 처리할 수 있습니다.
다. 개인정보 수집방법
회사는 다음과 같은 방법으로 개인정보를 수집합니다.
- 홈페이지, 회원가입 화면, 로그인 화면, 문의 화면, 결제 화면 등에서 이용자가 직접 입력
- 구글 로그인 등 외부 인증 서비스 연동 과정
- Meta/Instagram 연동 과정
- 서비스 이용 과정에서 자동 생성되는 정보의 수집
- 고객센터, 이메일 문의, 이벤트/프로모션 참여 과정
- 크리에이터 페이지 내 문의/구독 기능 이용 과정
2. 개인정보의 이용목적
회사는 수집한 개인정보를 다음 목적을 위해 이용합니다.
- 회원 식별, 가입 의사 확인, 로그인 및 계정 관리
- 구글 로그인 등 외부 인증 연동 처리
- 서비스 제공, 페이지 생성 및 관리, 워크스페이스 운영
- 크리에이터 페이지를 통한 문의 접수 및 전달
- 유료 상품 제공, 정기결제 관리, 결제 확인, 환불 처리, 영수증 제공
- 인스타그램/Meta 연동 기능 제공(프로필·댓글·메시지 등 연동 데이터 처리 포함)
- AI 기능 제공, 결과 생성, 품질 개선, 장애 대응, 재생성 및 이력 관리
- 이용 통계 분석, 접속 분석, 클릭 분석, 서비스 품질 향상
- 부정 이용 방지, 비정상 접근 탐지, 보안 및 서비스 안정성 확보
- 분쟁 대응, 민원 처리, 공지사항 전달 및 법령상 의무 이행
회사는 이용자의 개인정보를 수집 목적 범위 내에서 처리하며, 그 범위를 초과하여 이용하지 않습니다.
3. 개인정보의 제공
회사는 이용자의 개인정보를 원칙적으로 외부에 제공하지 않습니다. 다만, 다음의 경우에는 예외로 합니다.
- 이용자가 사전에 동의한 경우
- 법령에 따라 제출의무가 발생한 경우
- 수사기관, 법원, 정부기관 등의 적법한 절차에 따른 요청이 있는 경우
- 서비스 제공을 위해 정보주체 또는 이용자가 직접 연동을 요청한 외부 서비스에 필요한 범위 내에서 제공되는 경우
이용자가 Meta/Instagram 연동 기능을 사용하는 경우, 해당 연동 및 기능 수행에 필요한 범위 내에서 정보가 Meta 측 시스템과 연계될 수 있습니다. 또한 크리에이터 페이지에서 이용자가 입력한 문의/구독 정보는 해당 페이지 운영자인 크리에이터가 확인하고 관리할 수 있습니다.
4. 개인정보 처리위탁
회사는 원활한 서비스 제공을 위하여 다음과 같이 개인정보 처리업무를 위탁하거나 외부 서비스를 이용할 수 있습니다.
가. 현재 이용 중인 수탁업체
- Google LLC
- 위탁업무: 소셜 로그인(구글 로그인), 업무용 저장·관리 도구, 기타 Google 제공 서비스 운영
- 처리 정보: 이메일, 이름, 인증 관련 정보, 이용자가 입력한 정보 중 해당 기능 제공에 필요한 범위의 정보
- Cloudflare, Inc.
- 위탁업무: CDN, 이미지 전송, 보안, 트래픽 보호, 프론트엔드 배포 및 네트워크 최적화
- 처리 정보: 접속 정보, IP 관련 정보, 국가 코드, 요청/응답 관련 정보, 이미지 및 정적 리소스 전송 과정에서 처리되는 정보
- PayApp
- 위탁업무: 결제 처리, 정기결제 관리, 영수증 발행, 결제 상태 통지
- 처리 정보: 결제 관련 식별정보, 거래번호, 정기결제번호, 결제 상태, 결제 금액, 영수증 URL 등
나. 도입 예정 또는 추가될 수 있는 수탁업체
- DeepSeek
- 위탁업무: AI 기능 제공
- 처리 정보: 이용자 입력 텍스트, 프롬프트, 생성 요청 정보 등 AI 기능 제공에 필요한 범위의 정보
- 비고: 실제 연동 개시 시점부터 적용되며, 회사는 필요 시 본 방침 개정 또는 별도 고지를 통해 안내합니다.
회사는 위탁계약 체결 시 관계 법령에 따라 개인정보가 안전하게 처리되도록 필요한 사항을 규정하고, 수탁업체를 관리·감독합니다.
5. 개인정보의 국외 이전
회사는 서비스 제공 과정에서 아래와 같이 개인정보가 국외로 이전될 수 있습니다. 회사는 관련 법령이 요구하는 고지사항 및 보호조치를 준수합니다. 국외 수탁이 수반되는 경우 처리방침 등을 통해 해당 사실을 알려야 한다는 점을 반영했습니다.
가. 국외 이전 내역
- Google LLC
- 이전받는 자: Google LLC
- 이전 국가: 미국 등 Google이 운영하는 국가
- 이전 항목: 이메일, 이름, 인증 관련 정보, 이용자가 입력한 정보 중 해당 기능 제공에 필요한 범위
- 이전 목적: 구글 로그인, 업무용 저장·관리 도구 운영
- 이전 시점 및 방법: 로그인, 정보 입력 또는 서비스 이용 시 네트워크를 통한 전송
- 보유 및 이용기간: 목적 달성 시까지 또는 관계 법령 및 계약에 따른 기간까지
- Cloudflare, Inc.
- 이전받는 자: Cloudflare, Inc.
- 이전 국가: 미국 등 Cloudflare가 운영하는 국가
- 이전 항목: 접속 정보, IP 관련 정보, 국가 코드, 요청 정보, 정적 자원 전송 관련 정보
- 이전 목적: CDN, 트래픽 보호, 보안, 프론트엔드 및 이미지 전송
- 이전 시점 및 방법: 서비스 접속 시 네트워크를 통한 전송
- 보유 및 이용기간: 목적 달성 시까지 또는 각 사업자의 정책에 따른 기간까지
- DeepSeek(도입 시)
- 이전받는 자: DeepSeek 또는 그 계열/인프라 제공자
- 이전 국가: 서비스 제공 인프라 운영 국가
- 이전 항목: AI 기능 제공에 필요한 입력 데이터, 프롬프트, 생성 요청 정보
- 이전 목적: AI 기능 제공
- 이전 시점 및 방법: AI 기능 이용 시 네트워크를 통한 전송
- 보유 및 이용기간: 목적 달성 시까지 또는 각 사업자의 정책에 따른 기간까지
회사는 실제 국외 이전 구조가 변경되는 경우 본 방침을 개정하여 안내합니다.
6. 개인정보의 보유 및 이용기간
회사는 원칙적으로 개인정보의 수집 및 이용목적이 달성되면 지체 없이 파기합니다. 다만, 관계 법령에 따라 보존할 필요가 있는 경우 해당 기간 동안 보관합니다.
가. 회사의 일반 보유기간
- 회원 계정 정보
- 회원 탈퇴 시까지 보관
- 다만, 관계 법령 위반, 부정 이용, 분쟁 대응 필요가 있는 경우 관련 법령 또는 내부 기준에 따라 별도 보관할 수 있습니다.
- 크리에이터 페이지 문의/구독 정보
- 수집일로부터 3년 또는 정보주체의 삭제 요청 시까지
- 다만, 해당 정보가 크리에이터가 직접 관리하는 정보인 경우 회사는 서비스 제공 범위 내에서만 제한적으로 보관·처리할 수 있습니다.
- AI 입력 데이터, 프롬프트, 생성 결과
- 생성일로부터 12개월
- 다만, 이용자가 직접 삭제하거나 회원 탈퇴 시 관련 법령 또는 분쟁 대응 필요성이 없는 범위에서 지체 없이 파기할 수 있습니다.
- 인스타그램/Meta 연동 데이터(프로필·댓글·메시지 등)
- 연동 해제 또는 이용 목적 달성 시까지
- 다만, 이용자가 서비스 내 기능 또는 고객센터를 통해 삭제를 요청하는 경우, 관련 법령 및 플랫폼 정책에 따라 지체 없이 처리합니다.
- 페이지 방문 및 클릭 통계 정보
- 수집일로부터 12개월
- 워크스페이스 초대 정보
- 초대 수락, 만료 또는 취소 후 30일
- 고객 문의 및 민원 처리 기록
- 처리 완료일로부터 3년
위 기간은 회사의 현재 서비스 구조를 기준으로 한 운영상 기준이며, 서비스 구조나 법령 변경 시 조정될 수 있습니다.
나. 관계 법령에 따른 보관
회사는 관계 법령에 따라 다음 정보를 일정 기간 보관할 수 있습니다.
- 표시·광고에 관한 기록: 6개월
- 계약 또는 청약철회 등에 관한 기록: 5년
- 대금결제 및 재화 등의 공급에 관한 기록: 5년
- 소비자의 불만 또는 분쟁처리에 관한 기록: 3년
- 서비스 이용 관련 로그기록: 3개월
7. 개인정보의 파기절차 및 방법
회사는 개인정보 보유기간의 경과, 처리 목적 달성 등으로 개인정보가 불필요하게 되었을 때 지체 없이 파기합니다.
- 파기절차: 목적 달성 또는 보유기간 경과 후 즉시 파기 또는 법령상 보관이 필요한 경우 분리 보관 후 기간 종료 시 파기
- 파기방법:
- 전자적 파일 형태: 복구 및 재생이 불가능한 방법으로 영구 삭제
- 종이 문서: 분쇄 또는 소각
회원 탈퇴 시 회사는 법령상 보관이 필요한 정보를 제외하고 해당 계정과 관련된 개인정보를 지체 없이 삭제 또는 분리 보관할 수 있습니다.
8. 이용자 및 법정대리인의 권리와 행사방법
이용자는 언제든지 자신의 개인정보에 대해 열람, 정정, 삭제, 처리정지, 동의철회 등을 요청할 수 있습니다. 회사는 관련 법령과 표준 지침이 요구하는 처리방침 기재사항을 반영해 권리행사 및 고충처리 창구를 두고 있습니다.
- 권리 행사 방법: 개인정보보호책임자 또는 아래 문의처 이메일로 요청
- 회사는 이용자의 요청이 접수되면 본인확인 절차를 거쳐 지체 없이 처리합니다.
- 회사는 법령상 허용되는 범위에서 권리행사를 제한하거나 처리기한이 연장될 수 있는 경우 그 사유를 안내할 수 있습니다.
- 만 14세 미만 아동의 개인정보를 처리하는 경우, 법정대리인은 아동의 개인정보에 대한 권리를 행사할 수 있습니다.
이용자는 아래 이메일을 통해 개인정보 삭제를 요청할 수 있습니다.
- 이메일: contact@clfy.ai.kr
- 제목 예시: 개인정보 삭제 요청
- 요청 시 본인 확인을 위해 회원가입 시 사용한 이메일 주소 등 필요한 정보 제출을 요청할 수 있습니다.
또한 이용자는 Instagram/Meta 연동 데이터(프로필·댓글·메시지 등)에 대해서도 연동 해제 및 삭제를 요청할 수 있으며, 회사는 관련 법령 및 플랫폼 정책에 따라 지체 없이 처리합니다.
9. 쿠키의 설치·운영 및 거부
회사는 서비스 제공, 보안 유지, 로그인 상태 유지, 이용 분석, 서비스 개선을 위해 쿠키를 사용할 수 있습니다.
- 쿠키란 웹사이트가 이용자의 브라우저에 저장하는 소량의 정보 파일입니다.
- 회사는 로그인 유지, 접속 환경 분석, 이용 통계 산출 등에 쿠키를 사용할 수 있습니다.
- 이용자는 브라우저 설정을 통해 쿠키 저장을 거부하거나 삭제할 수 있습니다.
- 다만 쿠키 저장을 거부할 경우 일부 로그인 또는 서비스 기능 이용에 제한이 있을 수 있습니다.
10. 개인정보의 안전성 확보조치
회사는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
- 관리적 조치: 내부관리계획 수립·시행, 접근권한 최소화, 개인정보 취급자 최소화, 교육
- 기술적 조치: 비밀번호 해시 저장, 접근통제, 접속기록 관리, 토큰 등 중요정보 보호, 보안 취약점 대응, 암호화 적용
- 물리적 조치: 개인정보 보관 시스템 및 업무공간에 대한 접근통제
회사는 비밀번호를 복호화 불가능한 방식으로 저장하며, 서비스 운영에 필요한 토큰 등 중요정보에 대해서도 보호조치를 적용합니다. 또한 원문 IP를 저장하지 않고 해시값만 저장하는 방식으로 최소화 원칙을 고려합니다.
11. 크리에이터 페이지 및 외부 링크에 관한 안내
TurnFlow는 크리에이터가 자신의 페이지를 생성·운영할 수 있는 서비스를 제공합니다. 크리에이터 페이지에서 이용자가 문의 또는 구독 정보를 입력하는 경우, 해당 정보는 해당 페이지 운영자인 크리에이터가 확인하고 관리할 수 있으며, 회사는 서비스 제공을 위한 저장·전달·보안 유지 등 제한된 범위에서 이를 처리할 수 있습니다.
또한 회사 서비스에 링크된 외부 웹사이트 또는 외부 서비스가 별도로 개인정보를 수집하는 경우, 해당 처리에 대해서는 각 외부 서비스의 정책이 적용됩니다.
12. AI 기능 관련 안내
회사는 AI 기능 제공을 위해 이용자가 입력한 데이터, 최종 프롬프트, 생성 결과를 처리할 수 있습니다. 회사는 현재 이용자의 데이터를 모델 학습에 직접 활용하지 않으며, AI 기능 제공, 품질 관리, 오류 대응 및 이력 확인 목적 범위 내에서만 처리합니다. 다만 외부 AI 서비스 제공자를 이용하는 경우 해당 제공자의 정책에 따라 정보가 처리될 수 있으며, 회사는 실제 연동 구조에 맞추어 필요한 고지를 제공합니다.
이용자는 AI 기능 이용 시 제3자의 개인정보, 민감한 정보 또는 법령상 보호가 필요한 정보를 불필요하게 입력하지 않도록 주의해야 합니다.
13. 개인정보보호책임자 및 문의처
회사는 개인정보 보호 관련 문의, 불만 처리, 피해구제 등을 위하여 아래와 같이 개인정보보호책임자를 지정합니다.
- 개인정보보호책임자: 김시현
- 소속/직위: 주식회사 씨엘에프와이 / 대표자
- 전화번호: 070-8098-7102
- 이메일: contact@clfy.ai.kr
- 홈페이지: https://turnflow.link
기타 개인정보 침해에 대한 신고 또는 상담이 필요한 경우 아래 기관에 문의할 수 있습니다.
- 개인정보분쟁조정위원회: 1833-6972
- 개인정보침해신고센터(KISA): 국번없이 118
- 대검찰청: 국번없이 1301
- 경찰청: 국번없이 182
14. 고지의 의무
회사는 본 개인정보 처리방침의 내용 추가, 삭제 또는 수정이 있는 경우 개정사항의 시행일자, 변경사유 등을 서비스 내 공지사항 또는 웹사이트를 통하여 안내합니다. 표준 지침은 처리방침에 필수 기재사항과 변경 공개를 요구하고 있습니다.
- 버전: v2.0
- 시행일자: 2026년 4월 17일