Privacy Policy
2025.11.06
※ This policy takes effect on November 13, 2025.
ESTsoft Corp. (hereinafter the 'Company') places great importance on users' personal information, and processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act and related legislation in order to protect it.
Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses the following Privacy Policy for users of the PERSO service (including mobile and web), in order to inform users of the procedures and standards for processing personal information and to enable prompt and smooth handling of related grievances.
1. Purpose of Processing Personal Information
The Company uses personal information only for the purposes set out below, including member management for the PERSO service (including mobile and web) and the development, provision and improvement of the service.
- We use personal information for member management, including confirming intent to sign up, verifying age and obtaining legal representative consent, verifying the identity of users and legal representatives, identifying users, and confirming intent to withdraw membership.
- In addition to providing existing services such as content (including advertising), we use personal information to discover new service features and improve existing ones through demographic analysis and analysis of service visits and usage records.
- We collect personal information provided by members, including text, voice, scripts, images, video and biometric information. This is used to generate video, avatars and other forms of output, and metadata related to the input is collected along with it. We may also use the input you provide to improve our services or train our models.
- We use personal information to protect users and operate the service, including restricting the use of accounts that violate the law or the PERSO Terms of Service, preventing and sanctioning fraudulent use and other conduct that disrupts smooth service operation, delivering notices such as amendments to the terms, and handling complaints.
- We use personal information for identity verification, purchases and payment settlement in connection with paid services.
- We use personal information for marketing and promotional purposes.
- We use personal information to analyze service usage records and access frequency, and for service usage statistics, service analysis and statistics.
- We use personal information to build a service environment users can rely on in terms of security, privacy and safety.
2. Notice on the Collection and Use of Personal Information
1. The Company collects the minimum personal information necessary to use the service.
2. The Company processes users' personal information as follows.
Personal information processed without the consent of the data subject
ESTsoft Corp. processes the following personal information items without the consent of the data subject.
Legal basis | Category | Purpose of collection | Items collected | Retention and use period |
|---|---|---|---|---|
Personal Information Protection Act, Article 15(1)4 (performance of a contract) | Membership registration and service use | Membership registration and user identification | Email, password | Destroyed one month after the date of withdrawal |
Handling inquiries and complaints | Name, mobile number, email | Up to 3 years, in accordance with applicable law | ||
Password reset | Email, password | One month after withdrawal of membership | ||
Social (SNS) sign-up | Google, Microsoft name/email | One month after withdrawal of membership | ||
Service operation and management | ||||
Service development, provision and improvement | Images, video, audio recordings and voice data, text, scripts, biometric information, etc. | Retained for the period permitted by applicable law | ||
Model generation and interpretation | Images, video, audio recordings and voice data, text, scripts, biometric information, etc. | Retained for the period prescribed by applicable law | ||
Verification of input data | Images, video, audio recordings and voice data, text, scripts, etc. | Retained for the period prescribed by applicable law |
Personal information processed with the consent of the data subject
Category | Purpose of collection | Items collected | Retention and use period |
|---|---|---|---|
Marketing | Sending information on PERSO marketing and benefits, and service-related updates and information | Email, name | Until consent is withdrawn |
Notice on processing personal information without consent
- For personal information that may be processed without the consent of the data subject, the Company informs the data subject of the items and the legal basis for processing by email or another method prescribed by Presidential Decree.
The following information may be generated or additionally collected in the course of using the service and of processing service provision tasks.
- IP address, cookies, access logs, date and time of visit, service usage records, records of improper use
In order to provide specialized services, when certain services are used the Company may collect additional personal information beyond what is collected commonly for a PERSO account, after obtaining the data subject's consent.
When collecting personal information, we always inform the data subject in advance and obtain consent. The Company collects personal information through the following methods.
- Where the data subject consents to the collection of personal information and enters the information directly while creating a PERSO account on the website
- Where personal information is provided to us by a partner service or organization
- Where the data subject provides information by email, fax, telephone or written form in the course of a service consultation
3. Processing of Personal Information of Children Under 14
1. The Company does not collect the personal information of children under the age of 14. However, where consent is required in order to process such information, we obtain consent from the child's legal representative.
2. When obtaining a legal representative's consent to the processing of a child under 14's personal information, the Company may request minimal information from the child, such as the legal representative's name and contact details. The Company has the legal representative indicate whether they consent on the website where the terms of consent are posted, and confirms this by notifying the legal representative's mobile phone number by text message that their indication of consent has been verified.
4. Installation of Automatic Personal Information Collection Devices and Refusal of Their Operation
To provide a personalized, tailored service, the Company uses 'cookies', which store the data subject's information and retrieve it as needed.
What a cookie is
A cookie is a small text file that the server running the website sends to the data subject's browser and that is stored on the data subject's computer hard disk.
Purpose of use
Cookies help the data subject use the website conveniently, with the settings they have configured, when they visit it. We also use cookies to provide a personalized and tailored service based on the data subject's visit history and usage patterns.
Refusing cookies
Cookies do not store information that identifies an individual, and the data subject may choose whether to use them. Through web browser settings, the data subject may allow cookies, require confirmation each time a cookie is stored, or refuse the storage of cookies.
Examples of how to configure cookies
[Web]
Internet Explorer: Tools menu at the top of the browser > Internet Options > Privacy > Settings
Chrome: Settings menu on the right of the browser > Show advanced settings at the bottom > Content settings button under Privacy > Cookies
[App]
(1) (Android) ① Settings → ② Privacy → ③ Ads → ④ Reset advertising ID or delete advertising ID
(2) (iPhone) ① Settings → ② Privacy → ③ Tracking → ④ Turn off Allow Apps to Request to Track
※ Menus and methods may differ somewhat depending on the mobile OS version.
Collection of behavioral information
Legal basis | Behavioral information collected | Method of collection | Purpose of collection | Retention and use period |
|---|---|---|---|---|
Personal Information Protection Act, Article 15(1)4 (performance of a contract) | IP address, cookies, access logs, date and time of visit, service usage records, records of improper use | Collected automatically when the data subject visits the website | To provide a personalized and tailored service | Until consent is withdrawn or membership is terminated |
Users may direct questions about behavioral information, exercise their right to refuse, and report harm to the contact below.
Personal Information Protection Department
Department: Information Security Team, IT Infrastructure Division
Contact: 02-583-4620 / privacy@estsoft.com
5. Retention and Use Period of Personal Information, and Destruction
1. When personal information becomes unnecessary — because the retention period consented to by the user has elapsed, the purpose of processing has been achieved, or for similar reasons — the Company destroys it without delay. Information stored as an electronic file is deleted so that it cannot be recovered or reproduced; records, printed materials, documents and the like are shredded or incinerated.
2. However, where personal information must be retained under the Company's internal policies or applicable law, it is stored securely and separately in a dedicated database for the period specified below, for the reasons given. During this period the Company retains the personal information as required by law and never uses it for any other purpose.
3. The reasons for and periods of retention are as follows.
Retention under the Company's internal policies
Information retained | Reason for retention | Retention period |
|---|---|---|
User information (email, password, service usage records) | To prevent fraudulent sign-up and use after withdrawal (stored and processed in a non-identifiable state) | One month from the date of withdrawal |
User records (payment history, refund records, inquiry/complaint handling records, etc.) | To retain materials for resolving service-related disputes, handling complaints and processing refunds | One month from the date processing is completed |
Retention required by applicable law
Information retained | Governing law | Retention period |
|---|---|---|
Records of contracts and withdrawal of subscription | Act on Consumer Protection in Electronic Commerce | 5 years |
Records of payment and the supply of goods | Act on Consumer Protection in Electronic Commerce | 5 years |
Records of consumer complaints or dispute resolution | Act on Consumer Protection in Electronic Commerce | 3 years |
Records of labeling and advertising | Act on Consumer Protection in Electronic Commerce | 6 months |
Books and supporting documents for all transactions prescribed by tax law | Framework Act on National Taxes | 5 years |
Records of electronic financial transactions | Electronic Financial Transactions Act | 5 years |
Access logs | Protection of Communications Secrets Act | 3 months |
6. Entrustment of Personal Information Processing
1. The Company entrusts certain personal information processing tasks to third parties in order to handle personal information smoothly.
2. When entering into an entrustment contract, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in the contract and other documents matters such as the prohibition on processing personal information beyond the purpose of the entrusted work and technical and administrative protection measures, and supervises whether the trustee processes personal information safely.
3. If the content of the entrusted work or the trustee is added or changed, we will disclose this without delay through prior notice of consent as required by applicable law, or through this Privacy Policy.
Entrusted personal information processing tasks and trustees
Trustee | Entrusted work |
|---|---|
Google LLC | Web usability analysis and improvement; account verification and service provision for membership services |
ESTsoft Inc. | Payment processing for paid services |
Stripe, Inc. | Payment processing for paid services |
MS Azure | Data storage and the operation and management of IT systems |
Microsoft | Account verification and service provision for membership services; provision of the PERSO AI Presenters service |
Hotjar | Analysis of service usage behavior |
Slashpage | Provision and operation of community services; storage and management of user-generated content |
Amplitude | User behavior analysis and service usage statistics |
7. Cross-Border Transfer of Personal Information
The Company does not provide personal information to other overseas businesses. However, in order to perform contracts for the provision of information and communications services and to improve user convenience, we transfer personal information processing tasks overseas as set out below. If you do not wish your personal information to be transferred overseas, you may notify us of your refusal by contacting the Personal Information Protection Department by email (privacy@estsoft.com); in that case, however, you will no longer be able to use the related services.
Overseas transfer of personal information
Legal basis | Purpose | Items | Time and method | Retention and use period | Company and country |
|---|---|---|---|---|---|
Personal Information Protection Act, Article 28-8(1)3 (entrustment and storage for performance of a contract) | Web usability analysis and improvement | Date and time of visit, service usage records, Cookie ID | Transmitted over an encrypted network when the service is provided | Until the earlier of contract termination or 5 years from the date of collection | Google LLC / United States |
Personal Information Protection Act, Article 28-8(1)3 (entrustment and storage for performance of a contract) | Provision of paid services | Transaction amount, card number, expiry date, first two digits of the card password, date of birth/business registration number, email | Transmitted over an encrypted network when the service is provided | Until withdrawal of membership, or up to 5 years as required by applicable law | ESTsoft Inc. / United States |
Personal Information Protection Act, Article 28-8(1)3 (entrustment and storage for performance of a contract) | Provision of paid services | Transaction amount, card number, expiry date, first two digits of the card password, date of birth/business registration number, email | Transmitted over an encrypted network when the service is provided | Until withdrawal of membership, or up to 5 years as required by applicable law | Stripe, Inc. / United States |
Personal Information Protection Act, Article 28-8(1)3 (entrustment and storage for performance of a contract) | Account verification and service provision for membership services | Transmitted over an encrypted network when the service is provided | Microsoft / United States |
8. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information.
1. Administrative measures: establishing and implementing an internal management plan, and regular staff training
2. Technical measures: managing access rights to the personal information processing system and similar systems, installing access control systems, encrypting personal information, and installing and updating security programs
3. Physical measures: access control for the server room, document storage room and similar areas
9. Rights of Users and Legal Representatives, and How to Exercise Them
1. Users may exercise their rights against the Company at any time — including the right to access, correct, delete or suspend the processing of their personal information — and may withdraw their consent to the use of the personal information they provided by applying to terminate their account.
- You can view and edit your personal information in the 'Account Settings' menu.
- You can terminate your use of the service and withdraw your membership through the 'Account Settings > Withdraw Membership' menu.
2. The rights in paragraph 1 may be exercised against the Company in writing, by email or by fax, in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on them without delay.
3. The rights in paragraph 1 may also be exercised through an agent, such as the user's legal representative or a duly authorized person. In that case, a power of attorney in the form of Annex No. 11 of the Notice on Methods of Processing Personal Information (No. 2020-7) must be submitted.
4. A user's right to request access to personal information or suspension of its processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.
5. Deletion of personal information may not be requested where that personal information is expressly designated for collection under other legislation.
6. When a user exercises the right to request access, correction, deletion or suspension of processing, the Company verifies that the person making the request is the user themselves or a duly authorized agent.
Department receiving and handling requests for access to personal information
Department: ESTsoft Customer Center
Contact: 1544-8209
FAX: (02)-882-1155
Email: perso.info@estsoft.com
10. Personal Information Protection Officer and Responsible Department
1. The Company takes overall responsibility for personal information processing and has designated a Personal Information Protection Officer, as set out below, to handle user complaints and provide remedies in relation to personal information processing.
2. Users may direct any question, complaint or request for remedy relating to personal information protection that arises while using the Company's services to the Personal Information Protection Officer and the responsible department. The Company will respond and act without delay.
Personal Information Protection Officer
Name: Kwon Taek-soon
Title: CTO
Personal Information Protection Department
Department: Information Security Team, IT Infrastructure Division
Phone: 02-583-4620
Email: privacy@estsoft.com
11. Remedies for Infringement of User Rights
To obtain redress for infringement of personal information, users may apply for dispute resolution or counseling to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center and similar bodies.
For other reports of, or counseling on, personal information infringement, please contact the organizations below.
Personal Information Dispute Mediation Committee | |
|---|---|
Website https://www.kopico.go.kr/ | Phone 1833-6972 (no area code) |
Personal Information Infringement Report Center (operated by KISA) | |
Website https://privacy.kisa.or.kr/ | Phone 118 (no area code) |
Supreme Prosecutors' Office Cyber Crime Investigation Unit | |
Website https://www.spo.go.kr/ | Phone 1301 (no area code) |
Korean National Police Agency | |
Website https://ecrm.police.go.kr/ | Phone 182 (no area code) |
Where content is added to, deleted from or amended in this Privacy Policy, the Company will give notice of the changes at least 7 days in advance.
However, where there is a material change to users' rights — such as a change to the personal information items collected or the purpose of use — we will give notice at least 30 days in advance and may obtain users' consent again if necessary.
1. This Privacy Policy applies from October 23, 2025.
2. If the Privacy Policy is amended, we will post notice without delay in the 'Announcements' section of the Company website.
- Date of announcement: November 06, 2025
- Effective date: November 13, 2025
