Privacy Policy
Last updated: September 29, 2026
This English translation is provided for convenience. The Korean version governs.
1. Purposes of Collecting Personal Information
Indinity Inc. (the “Company”) collects personal information for the following purposes:
- Member registration and management
- Providing and operating the Service
- Payment, billing and refunds for paid plans
- Improving and developing the Service
- Performing and complying with laws and terms, and resolving disputes
- Customer support and responding to inquiries
2. Personal Information We Collect
The Company collects the following personal information to provide the Service:
| Item | Purpose | Retention period |
|---|---|---|
| Email address | Identifying members, creating accounts, sending notices and notifications | Until the member withdraws |
| Name (display name) | Identifying members and displaying them in the Service | Until the member withdraws |
| Password | Account security (stored encrypted) | Until the member withdraws |
| Access records (activity log) | Access control, preventing misuse, letting users view their activity log | 1 year (Standards for Ensuring the Safety of Personal Information) |
| Service usage records | Operating and improving the Service | Retention period required by law |
| Payment records | Billing and refunds for paid plans | Retention period required by law |
Payment method information such as credit card numbers is collected and processed directly by our payment provider (Paddle). The Company does not store it.
3. Retention and Use Period
In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, where relevant laws require retention, the Company keeps member information for the periods set by those laws, as follows.
- Records of contracts or withdrawal of offers: 5 years (Act on the Consumer Protection in Electronic Commerce)
- Records of payment and supply of goods: 5 years (Act on the Consumer Protection in Electronic Commerce)
- Records of consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce)
- Login records: 3 months (Protection of Communications Secrets Act)
- Access records of personal information processing systems: 1 year (Standards for Ensuring the Safety of Personal Information)
When a member withdraws, the Company immediately destroys the account and the documents in workspaces the member owns. Withdrawal is processed after the member confirms their identity with their password or the external account they signed up with. Destroyed information cannot be restored.
4. Procedure and Method of Destruction
The Company destroys personal information without delay when it is no longer needed, for example because the retention period has passed or the purpose of processing has been achieved.
- Procedure: When a member withdraws, the Company immediately destroys the account information and the documents in workspaces the member owns, then deletes the remaining original files from storage. Documents moved to the Trash are deleted from storage after 30 days.
- Method: Information in electronic file form is deleted using technical methods that make the records impossible to restore.
- Exception: Access records that the law requires us to keep are retained until the end of the retention period above, with identifying information removed so that no one can tell whose records they are.
5. Provision to Third Parties and Outsourcing of Processing
In principle, the Company processes users’ personal information within the scope of the purposes of collection, and does not process it beyond that scope or provide it to third parties without the user’s prior consent. However, to provide the Service smoothly, the Company outsources the processing of personal information as follows:
- Amazon Web Services: storing and processing data to operate the Service, sending notification emails (Seoul region, Republic of Korea)
- Cloudflare, Inc.: storing and transmitting document bodies and attachments (Cloudflare R2)
- Paddle.com: processing payments for paid plans (email address, payment information)
Of these processors, Cloudflare, Inc. (United States) and Paddle.com Market Ltd. (United Kingdom) are located outside Korea and process and store the items above abroad to the extent needed to provide the Service. Users may refuse the overseas transfer, but in that case they may be unable to use some or all of the Service, including document storage and paid plan payments.
The Company may also process personal information in accordance with applicable laws where provision is required by law.
5-1. Data Received Through Connected External Services (OAuth)
Workspace admins can connect Google (Google Ads, Search Console, Google Analytics) and Meta (Facebook and Instagram ads) accounts with OAuth under Settings > Data connections. Once connected, the Company receives that account’s advertising, search and traffic performance data on a read-only basis and stores it in the workspace’s datasets and documents. We do not receive account passwords. Access tokens we receive are stored encrypted and are never shown again on screen or to agents. For Meta ads, the Company receives the additional ads management permission (ads_management) only if an admin separately allows it. This permission is used only to apply changes the user requests in Docca or through an AI agent the user connected (turning campaigns, ad sets and ads on or off, changing budgets, duplicating) to that ad account.
- What we receive: lists of ad accounts and properties; impressions, clicks, cost and conversions by campaign; clicks, impressions and rankings by search query and page; sessions and users by channel and page
- How we use it: to create and update dashboard and report documents in the connected workspace. Except for changes the user requests, we do not modify advertising or analytics accounts, use the data for other purposes, or sell it to third parties.
- Google data: Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Disconnecting and deleting data: Clicking [Delete] under Settings > Data connections deletes the access token immediately. Datasets already received are deleted when removed from documents or when the workspace is deleted. You can also revoke Docca’s access in your Google account’s third-party access settings or in Facebook Settings > Business Integrations. Send deletion requests to support@indinity.co and we will process them within 30 days.
Sharing, transfer and disclosure
The Company does not sell Google user data, use it for advertising, or use it to train AI or machine learning models. It is passed elsewhere only in the following cases.
- Storage and processing providers: Access tokens and account lists are stored with Amazon Web Services (Seoul region, Republic of Korea), and the performance data received and the documents containing it are stored in Cloudflare, Inc. (United States) R2. Both companies only store and transmit the data under the processing agreements described in Section 5 and do not use the content for any other purpose.
- Members of the same workspace: Data from an account connected by an admin is visible, as datasets and documents, to members invited to that workspace. Access is limited by document and folder permission settings.
- AI agents the user connected: When a user connects Docca to an AI service such as ChatGPT or Claude and requests a report, the data needed for that request is sent to the AI service the user chose. It is not sent to AI services the user did not connect, and the processing of data sent is governed by the terms between the user and that AI service.
- Legal requirements: Provided only when investigative agencies, courts or similar bodies request it through lawful procedures under applicable law.
Except in the cases above, the Company does not provide, transfer or disclose Google user data to third parties. Only the minimum number of Company staff needed to operate the Service and respond to incidents have access rights, and they do not view the content of customers’ documents or datasets.
Protection measures
- Encryption in transit: All communication between Google APIs and Docca, and between users’ browsers or AI agents and Docca, is encrypted with TLS (HTTPS).
- Encryption at rest: Access tokens and refresh tokens are encrypted with AES-256-GCM and stored in the database, and are never displayed again on screen, in APIs or in logs. Stored datasets and documents are kept in storage encrypted with AES-256.
- Access control: Data is used only within the connected workspace, and access is limited by workspace membership and document permissions. AI connection keys cannot be used outside the workspace set when they were issued. Login attempts are limited to 10 per email every 15 minutes, and sessions expire after one week of inactivity.
- Access records: Logins, viewing and editing of documents and datasets, share setting changes and member invitations are recorded for 1 year together with the route (web, AI connection, share link) and IP address, and admins can view them in the app.
- Retention and deletion: Access tokens are deleted immediately on disconnection, and datasets and documents are deleted as soon as the user deletes them or deletes the workspace. Deletion requests are processed within 30 days.
- Incident response: If the Company becomes aware of a personal information breach, it will notify users and the supervisory authority without delay as required by applicable law. Vulnerability reports are accepted at support@indinity.co, and we confirm receipt within three business days.
6. Rights of Users and Legal Representatives and How to Exercise Them
Users and legal representatives may at any time view or correct the registered personal information of themselves or of a child under 14. If they do not agree to the Company’s processing of personal information, they may refuse consent or request termination of membership (withdrawal). In that case, it may be difficult to use some or all of the Service.
7. Installation, Operation and Refusal of Automatic Collection Tools
The Company uses cookies or browser storage to provide the Service, for example to keep users signed in. Users can refuse cookies by changing their web browser settings, but in that case it may be difficult to use services that require signing in.
8. Chief Privacy Officer
The Company has designated a Chief Privacy Officer, as follows, who is responsible for overseeing the processing of personal information and for handling complaints and remedies of data subjects related to that processing.
Name: Namhoon Lee · Title: CEO
Contact: support@indinity.co
9. Changes to This Privacy Policy
This Privacy Policy applies from August 25, 2026. If content is added, deleted or corrected due to changes in law or policy, we will announce it through notices at least 7 days before the change takes effect.