Privacy Policy
Witon Inc. (hereinafter "the Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (PIPA) to protect the personal information of data subjects and to promptly address related grievances.
This Policy applies to the survey form creation, distribution, response collection, analysis, and report generation services provided by the Company (hereinafter "the Service").
Article 1 (Role of the Company)
- The Company processes personal information in the capacity of a personal information controller in connection with the creation and authentication of accounts for Members (survey creators, administrators, collaborators, etc.) and the operation of the Service.
- With respect to respondent information collected through surveys created by Members using the Service, the Company processes personal information in the capacity of an entrusted party (processor), operating and providing the system in accordance with the purposes and settings determined by the Member. The content of the survey, the items collected, the purposes of collection and use, the retention period, and the legal basis are, in principle, determined by the Member who creates and operates the survey.
- Respondents shall first direct any inquiries, access requests, correction requests, deletion requests, or suspension-of-processing requests regarding personal information related to the survey in which they participated to the creator of that survey. The Company shall cooperate within the scope of applicable laws and contracts to assist Members in responding to such requests.
Article 2 (Purposes and Items of Personal Information Processing)
1. Personal Information Processed Without Consent
The Company may process the following personal information without consent based on the legal grounds set forth in each subparagraph of Article 15(1) of the Personal Information Protection Act.
| Items Processed | Purpose of Processing | Retention Period | Legal Basis |
|---|---|---|---|
| Email address, name, social login identifier, profile image (when linked), language settings | Membership registration, login, identity verification and authentication, account management, service provision | Until withdrawal of membership (stored separately for 90 days after withdrawal, then deleted) | Conclusion and performance of a contract (Article 15(1)(iv) of the Act) |
| Name, email address, inquiry details, consultation history | Customer support, responding to inquiries, delivering notices | 3 years after completion of processing | Conclusion and performance of a contract (Article 15(1)(iv) of the Act) |
| Access date and time, IP address, browser/OS/device information, service usage records, error logs | Ensuring service stability, security and prevention of unauthorized use, error analysis and incident response | Up to 1 year | Legitimate interests (Article 15(1)(vi) of the Act) |
| Session identifier during respondent survey participation (no cookies used, processed only within the browser session), page view and interaction events | Ensuring stability of the survey response service, incident detection | Destroyed immediately upon session termination (server-side aggregate data retained for up to 12 months) | Legitimate interests (Article 15(1)(vi) of the Act) |
| Legally required records related to transactions, payments, and dispute resolution | Statutory record retention, tax and accounting purposes, dispute resolution | Period prescribed by applicable laws | Compliance with legal obligations (Article 15(1)(ii) of the Act) |
2. Personal Information Processed With Consent
| Consent Item | Purpose of Processing | Items Processed | Retention Period |
|---|---|---|---|
| Optional analytics cookies/SDK consent | Analysis of service usage patterns, UI/UX improvement | Randomized identifiers, page view/click events, session information, device/browser information | Until consent is withdrawn or up to 12 months |
| Marketing communications consent | Service update notifications, new feature announcements, event and promotional information | Email address, name | Until consent is withdrawn |
Refusal of optional consent does not restrict the use of the essential features of the Service.
Article 3 (Respondent Personal Information Collected Through Member Surveys)
- Members may create various surveys using the Service, and in the process, information directly entered by respondents (such as name, email, and free-text responses) may be collected.
- The Service does not, in principle, require by default the collection of respondents' real names or account information. However, whether a particular survey is actually anonymous may vary depending on the question design, response settings, and tracking settings configured by the Member. Respondents should review the introductory notice of the relevant survey.
- Information submitted by respondents may be accessed and used by the creator of the survey and collaborators who have been granted access.
- Members are responsible for verifying that the information they intend to collect complies with applicable legal requirements, including notice and consent obligations, sensitive information processing requirements, and children's information protection requirements.
Article 4 (Processing of Personal Information When Using AI Features)
- Only when a Member explicitly executes an AI feature (such as question recommendations, response analysis, or report generation) may the Company process survey questions, prompts, response data, and similar items to the extent necessary for providing such features.
- As a matter of principle, the Company does not use raw survey responses of Members or respondents for the purpose of training, retraining, or fine-tuning its own or any third party's general-purpose AI models. However, exceptions may apply in the following cases:
- Where the Member has given separate explicit consent
- Where the data constitutes fully anonymized statistics permitted under applicable law
- Where minimal log processing is performed for the purposes of ensuring the safety of the AI service provider, AI workflow tracing, incident analysis, and debugging (see Article 11 on cross-border transfers for specific retention periods)
- Within the scope of the purposes set forth in the preceding paragraph, prompts, model inputs and outputs, execution traces, and error information may be processed. Depending on the manner in which the Service is used, raw survey responses may be included in such data.
- The Company does not use such log and trace data for the purpose of training, retraining, or fine-tuning its own or any third party's general-purpose AI models.
- Outputs from AI features are probabilistic in nature and may be inaccurate or incomplete. Members shall independently review such outputs before use.
- The AI features of the Company are provided as informational and assistive tools and are not designed for the purpose of automatically finalizing decisions that significantly affect the rights and obligations of individuals.
Article 5 (Sensitive Information and Unique Identification Information)
- The Company does not, by default, require Members or respondents to provide sensitive information or unique identification information (such as resident registration numbers or passport numbers).
- Where a Member intends to collect sensitive information through a survey, the Member shall independently assess the necessity, legality, and whether separate consent is required.
- The Company may restrict the collection and processing of unique identification information, except where permitted by applicable law.
Article 6 (Use of Anonymized Information)
- The Company may process collected data into anonymized information pursuant to Article 58-2 of the Personal Information Protection Act and use it for purposes such as improving AI analysis models, enhancing service quality, and developing business based on aggregate statistics.
- During anonymization, identifiers are removed or generalized, and the data is used only in forms from which individual respondents cannot be identified. The Company establishes and maintains internal standards to ensure the adequacy of its anonymization processes.
- Anonymized information does not constitute personal information under Article 58-2 of the Personal Information Protection Act and is therefore not subject to the exercise of data subject rights described in Article 12. Data subjects may, however, inquire with the Company regarding the adequacy of the anonymization process.
Article 7 (Retention and Use Period of Personal Information)
- The Company processes and retains personal information within the retention and use period prescribed by applicable law or agreed upon with the data subject.
| Category | Retention Period |
|---|---|
| Member account information | Until withdrawal of membership (stored separately for 90 days after withdrawal, then deleted) |
| Customer support and inquiry information | 3 years after completion of processing |
| Security, access, and error logs | Up to 1 year |
| Optional analytics cookies/SDK information | Until consent is withdrawn or up to 12 months |
| Marketing subscription information | Until consent is withdrawn |
- Respondent personal information is retained until the retention period set by the Member or until the Member takes deletion action. Upon deletion of the survey or responses, or upon the Member's withdrawal, the information is permanently deleted within a maximum of 90 days.
- Where retention is required under applicable law, the data is stored separately.
| Applicable Law | Items Retained | Retention Period |
|---|---|---|
| Act on the Consumer Protection in Electronic Commerce, Etc. | Records relating to contracts or withdrawal of offers | 5 years |
| Act on the Consumer Protection in Electronic Commerce, Etc. | Records relating to payment and supply of goods, etc. | 5 years |
| Act on the Consumer Protection in Electronic Commerce, Etc. | Records relating to consumer complaints or dispute resolution | 3 years |
| Act on the Consumer Protection in Electronic Commerce, Etc. | Records relating to labeling and advertising | 6 months |
| Protection of Communications Secrets Act | Communication fact confirmation data such as access logs | 3 months |
Article 8 (Destruction of Personal Information)
- The Company destroys personal information without delay when it is no longer needed due to the expiration of the retention period, achievement of the processing purpose, or other reasons. However, where retention is required under other applicable laws, the data is stored separately.
- Electronic files are deleted using technical methods that make the records irreproducible, and paper documents are shredded or incinerated.
- Upon withdrawal of membership, account information is immediately deactivated. To allow for recovery from erroneous withdrawal, prevention of unauthorized use, and response to legal disputes, the information is stored separately for 90 days before permanent deletion. Withdrawn accounts cannot be restored.
Article 9 (Provision of Personal Information to Third Parties)
- The Company does not, in principle, provide personal information of data subjects to external parties.
- Exceptions apply where the data subject has given prior consent, where there is a special provision under applicable law, or where necessary to protect the urgent interests of the life, body, or property of the data subject or a third party.
- The provision of information entered by respondents in a survey to the creator of that survey constitutes an essential function of the survey service.
Article 10 (Entrustment of Personal Information Processing)
The Company entrusts personal information processing tasks as follows to ensure smooth service provision.
| Entrusted Party | Entrusted Tasks |
|---|---|
| Supabase Inc. | Database hosting, user authentication, file storage |
| Google LLC | OAuth authentication, generative AI inference (when using applicable features) |
| E2B Inc. | Statistical analysis code execution (when using applicable features) |
| Functional Software, Inc. (Sentry) | Error monitoring, incident analysis |
| PostHog, Inc. | Service usage analysis (Members: upon optional consent / Respondents: cookieless mode for service stability assurance) |
| Upstash, Inc. | Request rate limiting |
| LangChain, Inc. (LangSmith) | AI agent workflow tracing, monitoring, debugging, and user feedback logging |
| Plus Five Five, Inc. (Resend) | Transactional welcome and form-invitation email delivery |
| Vercel Inc. | Web application hosting |
When entering into entrustment contracts, the Company specifies personal information protection matters in writing in accordance with applicable laws and supervises the entrusted parties to ensure the secure processing of personal information. Any changes to entrusted parties or entrusted tasks are disclosed without delay through this Policy.
Article 11 (Cross-Border Transfer of Personal Information)
The Company transfers personal information overseas as follows, in accordance with Article 28-8 of the Personal Information Protection Act, for the purpose of providing the Service.
| Recipient | Country | Purpose of Transfer | Method of Transfer | Retention Period | Protective Measures |
|---|---|---|---|---|---|
| Supabase Inc. | United States | Database and authentication services | Encrypted network transmission | Duration of service use (deleted within 90 days of withdrawal) | SOC 2 Type II certification |
| Google LLC (OAuth) | United States | Social login and authentication | Encrypted network transmission | Until unlinking or withdrawal | ISO 27001 certification |
| Google LLC (Gemini API) | United States | AI analysis and question recommendation | Encrypted API calls | Safety monitoring logs for up to 55 days | ISO 27001 certification |
| E2B Inc. | United States/EU | Statistical analysis code execution | Encrypted API calls | Deleted immediately upon completion of execution | Encrypted transmission |
| Functional Software, Inc. (Sentry) | United States | Error monitoring | Encrypted SDK transmission | Within 90 days | SOC 2 Type II certification |
| PostHog, Inc. | United States | Service usage analysis | Encrypted SDK transmission (Members: upon optional consent / Respondents: cookieless) | Until consent is withdrawn or up to 12 months | SOC 2 Type II certification |
| Upstash, Inc. | United States/EU | Request rate limiting | Encrypted API calls | Automatic expiration (up to 1 hour) | Encrypted transmission |
| LangChain, Inc. (LangSmith) | United States | AI agent workflow tracing, monitoring, debugging, and user feedback processing | Encrypted API calls | Within 14 days | Encrypted transmission |
| Plus Five Five, Inc. (Resend) | United States | Transactional welcome and form-invitation email delivery | Encrypted API calls whenever an email is requested | Email data: 30 days by default; remaining data deleted within 90 days after account termination | SOC 2 Type II compliant |
| Vercel Inc. | United States | Web hosting | Encrypted network transmission | Within 30 days | SOC 2 Type II certification |
Certain tracing and observability tools used in the provision of AI features may process data overseas for the purposes of service quality improvement, incident response, debugging, and user feedback processing. The Company limits the items transmitted to those necessary for such purposes and applies a short-term retention principle.
Resend receives recipient and sender email addresses, email metadata, subject lines, and message content for transactional welcome and form-invitation emails. Exceptions to the retention periods above may apply where retention is required or permitted by law.
If the data subject does not wish their personal information to be transferred overseas as required for service provision, the use of some or all features of the Service may be restricted. Cross-border transfers for optional analytics tools may be discontinued by withdrawing consent.
Article 12 (Rights and Obligations of Data Subjects and Methods of Exercise)
- Data subjects may exercise the following rights with respect to the Company at any time:
- Right to request access to personal information
- Right to request correction or deletion
- Right to request suspension of processing
- Right to withdraw consent
- Right to request an explanation of, refuse, or request a review of automated decisions (where prescribed by applicable law)
- Rights may be exercised through in-service settings or via email (contact@witform.app).
- Respondents shall, in principle, first submit rights requests to the creator of the survey in which they responded. The Company shall provide support to the extent necessary.
- When exercising rights through a representative, submission of a power of attorney as prescribed by applicable law may be required.
- The exercise of rights may be restricted or refused in accordance with applicable law.
Article 13 (Cookies and Similar Technologies)
| Category | Tool | Purpose | Legal Basis | Opt-Out Method |
|---|---|---|---|---|
| Essential | Authentication cookies (Supabase) | Login maintenance, security | Conclusion and performance of a contract | May be blocked via browser settings, but core functionality will be limited |
| Essential | Error monitoring (Sentry) | Incident analysis, ensuring service stability | Legitimate interests | May be blocked via browser settings, but service quality may be degraded |
| Essential | Respondent survey participation analytics SDK (PostHog, cookieless) | Ensuring stability of the survey response service, incident detection | Legitimate interests | May be blocked via browser settings, but service quality may be degraded |
| Optional | Analytics cookies/SDK (PostHog) | Usage pattern analysis, feature improvement | Data subject consent | May be refused or withdrawn via consent banner or in-service settings |
Article 14 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures in accordance with Article 29 of the Personal Information Protection Act.
- Administrative measures: Establishment and implementation of an internal management plan, access authority management, application of the principle of least privilege, employee training
- Technical measures: Encryption of data in transit (HTTPS/TLS), access control, secure management of authentication tokens, application of OAuth 2.0 PKCE, API request rate limiting, log monitoring
- Physical measures: Application of physical security measures by cloud infrastructure providers
Article 15 (Protection of Children's Personal Information)
- The Company does not permit membership registration by children under the age of 14. Children under the age of 14 are not eligible to register for the Service, and the membership registration process includes a procedure to verify that the applicant is 14 years of age or older.
- Where a Member intends to operate a survey that collects personal information of children under the age of 14, the Member shall independently fulfill the necessary requirements under applicable law, including obtaining consent from a legal guardian.
Article 16 (Personal Information Protection Officer)
The Company designates the following Personal Information Protection Officer to oversee the processing of personal information and to handle related complaints and remedies.
- Name: Jeongjin Lee
- Title: Chief Executive Officer
- Email: contact@witform.app
Data subjects may contact the above for any inquiries, complaints, or remedies related to personal information arising from the use of the Service.
Article 17 (Methods of Remedy for Infringement of Rights)
Data subjects may file for dispute resolution or consultation with the following organizations to obtain remedies for personal information infringement.
| Organization | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | +82-1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center | +82-118 | privacy.kisa.or.kr |
| Supreme Prosecutors' Office | +82-1301 | www.spo.go.kr |
| National Police Agency | +82-182 | ecrm.police.go.kr |
| Central Administrative Appeals Commission | +82-110 | www.simpan.go.kr |
Article 18 (Amendments to this Policy)
- This Privacy Policy takes effect from the date of implementation. In the event of any amendment, the Company shall provide notice through announcements beginning at least 7 days prior to the effective date.
- In the case of material amendments that are disadvantageous to data subjects, individual notice shall be provided via email and in-service announcements at least 30 days prior to the effective date.
Supplementary Provisions
This Policy takes effect on March 29, 2026.