INVECTOR
Privacy Policy
Privacy Policy
Toggle Campus Co., Ltd.
Announcement Date: August 4, 2026
Effective Date: September 3, 2026
Version: v2.0 (Previous version v1.0, effective June 10, 2025)
Article 1 (General Provisions and Scope of Application)
Toggle Campus Co., Ltd. (hereinafter referred to as the "Company") complies with relevant laws and regulations, such as the "Personal Information Protection Act," and has established and disclosed this Privacy Policy (hereinafter referred to as "this Policy") to protect the personal information of information subjects and to promptly resolve any related grievances.
This Policy applies to the websites operated by the Company (invector.co, app.invector.co), Excel plug-in services, and all accompanying services provided by the Company (hereinafter referred to as the "Services").
Among the terms used in this Policy, the meanings of "Customer," "User," "Input Data," and "Generated Data" shall be as defined in the Company's Invector Service Terms of Service.
Article 2 (Status of the Company and Classification of Processed Data)
This Article is intended to clarify that the roles of the Company and the Customer differ depending on the nature of the data.
Information Processed by the Company as a Personal Information Controller (Account Information, etc.)
The Company processes contact person's name, email, contact details, department/position, access logs, etc., which are directly collected by the Company for the conclusion and performance of the Service Use Agreement, in its capacity as a Personal Information Controller in accordance with this Policy.Information Processed by the Company as a Trustee (Input Data, etc.)
With respect to the Input Data uploaded or entered into the Services by the Customer and the Generated Data created therefrom, the Personal Information Controller is the Customer, and the Company holds the status of a trustee processing such data on behalf of and under the entrustment of the Customer. The Company processes such data only within the scope of the purpose directed by the Customer.Customer's Responsibility
If personal information is included in the Input Data, the Customer, as the Personal Information Controller, shall bear all obligations under relevant laws and regulations, such as securing the legal basis for collecting such personal information, notifying and obtaining consent from the information subjects, and notifying them of cross-border transfers. The Customer must not enter personal information beyond what is necessary to use the Services, which is an obligation of the Customer under Article 11, Paragraph 7 of the Terms of Service.Information concerning corporations, such as financial data, does not constitute personal information under the Personal Information Protection Act; however, the Company treats such information as the Customer's trade secrets and protects it in accordance with Article 29 of the Terms of Service.
Article 3 (Items of Personal Information Collected and Method of Collection)
The Company collects the minimum amount of information required to provide the Services, and the collected items are as follows.
Account Information (Mandatory) — Company name, business registration number, contact person's name, email address, contact details, department/position
Authentication Information (Mandatory) — Login identifier, authentication token
Billing and Contract Information (Mandatory for Paid Use) — Billing information, tax invoice issuance information, contact person's information
Inquiry and Support History (Optional) — Inquiry details, consultation records, attached materials
Automatically Generated Information (Automatically Collected) — Access timestamp, IP address, browser/device information, operating system, feature usage history, error records (logs)
Metadata (Automatically Generated) — File name, file size, creation/modification timestamp, processing elapsed time
Input Data and Generated Data are materials voluntarily uploaded and entered by the Customer, and the Company processes them in its capacity as a trustee in accordance with Article 2, Paragraph 2. The Company does not require personal information to be included in the Input Data.
Method of Collection
Direct entry by the user during sign-up, conclusion of service agreements, or customer inquiry processes
Automatic generation and collection in the course of using the Services
Account issuance through partners or customer administrators
The Company does not collect personal information of children under the age of 14, and the Services are intended for business customers. Furthermore, the Company does not collect sensitive information such as thoughts/beliefs, health, genetic information, or resident registration numbers.
Article 4 (Purpose of Processing Personal Information)
The Company processes collected personal information only for the following purposes. If the purpose changes, necessary measures such as obtaining separate consent in accordance with relevant laws and regulations will be implemented.
Conclusion, maintenance, performance of the service agreement, and identity verification and authentication
Provision of Services, execution of features, and generation of outputs
Payment processing such as fee settlement, billing, and tax invoice issuance
Receipt of customer inquiries, troubleshooting, technical support, and dispute resolution
Security purposes such as ensuring service stability, preventing unauthorized use, and managing access logs
Service usage analysis and quality improvement (processed in statistical form)
Delivery of mandatory notices such as service changes and amendments to the Terms of Service
Performance of obligations under relevant laws and regulations
Article 5 (Processing and Retention Period of Personal Information)
The Company processes and retains personal information within the retention/use period required by law or agreed upon by the information subject at the time of collection. The retention period for each item is as follows.
Account Information / Authentication Information — Until the termination of the service agreement
Input Data / Generated Data — From the date of termination of the service agreement
AI Processing Records (Requests and Processing Results) — From the date of termination of the service agreement
Access Logs / Error Records — From the date of termination of the service agreement
Inquiry / Consultation Records — From the date of termination of the service agreement
Backup Data — Until the backup retention cycle expires (Article 10, Paragraph 3)
When an information subject or customer requests deletion, the Company destroys the personal information in accordance with Article 10, except for information that is required to be preserved under relevant laws and regulations.
Information Preserved in Accordance with Relevant Laws and Regulations
Records on contracts or withdrawal of subscription, etc. — 5 years (Act on Consumer Protection in Electronic Commerce, etc.)
Records on payment and supply of goods, etc. — 5 years (Act on Consumer Protection in Electronic Commerce, etc.)
Records on consumer complaints or dispute handling — 3 years (Act on Consumer Protection in Electronic Commerce, etc.)
Transaction evidence such as tax invoices — 5 years (Framework Act on National Taxes / Value Added Tax Act)
Access logs related to service usage — 3 months (Protection of Communications Secrets Act)
Article 6 (Provision of Personal Information to Third Parties)
The Company processes the personal information of information subjects only within the scope specified in Article 4, and does not provide personal information to third parties except in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as separate consent of the information subject or special provisions of the law.
The Company does not currently provide personal information to third parties. If provision is required in the future, we will notify you in advance of the recipient, purpose of provision, items provided, and period of retention/use, and obtain your consent.
Even when requested by investigative agencies, etc., the Company will only provide information after confirming a lawful warrant or statutory grounds.
Article 7 (Entrustment of Personal Information Processing)
The Company entrusts personal information processing tasks as follows to ensure smooth service provision.
Google Cloud (Google LLC) — Cloud infrastructure operation, data storage / Entrusted items: Account information, logs, input/generated data
Google Firebase (Google LLC) — Login and authentication processing / Entrusted items: Email, authentication information, device information
MongoDB, Inc. — Database storage and operation / Entrusted items: Account information, input/generated data
Functional Software, Inc. (Sentry) — Error log collection and monitoring / Entrusted items: Device information, logs, error records
OpenAI OpCo, LLC — Natural language processing and tagging inference / Entrusted items: Processing request text within input data
Anthropic PBC — Natural language processing and tagging inference / Entrusted items: Processing request text within input data
When concluding entrustment contracts, the Company clearly specifies matters in the contract such as the prohibition of processing personal information outside the purpose of performing the entrusted tasks, technical and managerial protective measures, restrictions on re-entrustment, management and supervision of trustees, and liability for damages in accordance with Article 26 of the Personal Information Protection Act, and supervises whether the trustee processes personal information safely.
If the details of the entrusted task or the trustee change, the Company will disclose it without delay through this Policy.
Article 8 (Overseas Transfer of Personal Information)
The Company transfers personal information overseas as follows to provide the Services. This transfer corresponds to the entrustment and storage of processing required for contract performance and enhancement of information subjects' convenience in accordance with Article 28-8, Paragraph 1, Item 3 of the Personal Information Protection Act, and the Company discloses the following details through this Policy in accordance with Paragraph 3 of the same Article.
Google LLC (Google Cloud, Firebase)
Country of Transfer: United States / South Korea
Time and Method of Transfer: Transmitted via information and communications network at the time of using the Services
Items Transferred: Account information, authentication information, logs, input/generated data
Purpose of Transfer: Cloud infrastructure operation, authentication
Retention and Use Period: Until the termination of the entrustment agreement
MongoDB, Inc.
Country of Transfer: United States / South Korea
Time and Method of Transfer: Transmitted via information and communications network at the time of using the Services
Items Transferred: Account information, input/generated data
Purpose of Transfer: Database storage and operation
Retention and Use Period: Until the termination of the entrustment agreement
Functional Software, Inc. (Sentry)
Country of Transfer: United States / South Korea
Time and Method of Transfer: Transmitted via information and communications network when an error occurs
Items Transferred: Device information, logs, error records
Purpose of Transfer: Error monitoring
Retention and Use Period: Until the termination of the entrustment agreement
OpenAI OpCo, LLC
Country of Transfer: United States / South Korea
Time and Method of Transfer: Transmitted via API at the time of executing features
Items Transferred: Processing request text
Purpose of Transfer: Natural language processing and tagging inference
Retention and Use Period: Period in accordance with the operator's policy after completion of processing
Anthropic PBC
Country of Transfer: United States / South Korea
Time and Method of Transfer: Transmitted via API at the time of executing features
Items Transferred: Processing request text
Purpose of Transfer: Natural language processing and tagging inference
Retention and Use Period: Period in accordance with the operator's policy after completion of processing
In the event of an overseas transfer, the Company implements necessary protective measures such as encrypted transmission and access authority control in accordance with Article 28-8, Paragraph 4 of the Personal Information Protection Act.
Refusal of Overseas Transfer — Information subjects may refuse the overseas transfer of personal information. However, since overseas transfer is essential for providing the Services, you may not be able to use all or part of the Services if you refuse. Please submit your refusal of consent to the contact point specified in Article 12.
Article 9 (Use of Artificial Intelligence Services and Exclusion of Use for Training Purposes)
The Company uses APIs of the artificial intelligence service providers described in Articles 7 and 8 to provide the Services, and in this case, all or part of the Input Data may be transmitted to and processed by the relevant providers.
The Company does not use the Customer's Input Data and Generated Data for the purpose of training artificial intelligence models of the Company or third parties.
The Company may store processing requests and their results for the period specified in Article 5 for service provision, error analysis, quality improvement, and dispute response, and the Customer may request their deletion.
The Company may use statistical information anonymized so that individual customers or users cannot be identified for the purpose of service improvement and quality management. Statistical information does not contain identifiable information such as customers' financial figures or document content.
Matters Concerning Automated Decisions — The tagging and verification results generated by the Services through artificial intelligence are reference materials in accordance with Article 6 of the Terms of Service and do not constitute automated decisions that directly affect the rights or obligations of information subjects. The final judgment and confirmation are performed by the Customer.
Article 10 (Procedure and Method of Destruction of Personal Information)
When personal information becomes unnecessary, such as the expiration of the retention period or attainment of the processing purpose, the Company destroys the personal information without delay (within 5 days from the date the cause occurs).
Procedure and Method of Destruction
Destruction Procedure: The Company selects the personal information for which the cause of destruction occurred and destroys it upon approval of the Personal Information Protection Officer.
Electronic Files: Permanently deleted in a way that recovery or reproduction is impossible.
Printouts, etc.: Shredded or incinerated.
Backup Data — The Company performs regular daily backups to ensure service continuity, and data included in the backup storage is sequentially destroyed at the time the backup retention cycle expires. Until then, backup data is not used for purposes other than disaster recovery. The backup retention cycle is until the termination date of the respective enterprise's contract.
Information that must be preserved in accordance with laws and regulations is stored in a separate storage detached from other personal information, and then destroyed when the relevant period expires.
The Company does not bear the obligation to recover personal information that has been completely destroyed.
Article 11 (Rights and Obligations of Information Subjects and Legal Representatives and How to Exercise Them)
The information subject may exercise the following rights against the Company at any time.
Request to access personal information
Request correction in case of errors, etc.
Request deletion
Request suspension of processing
Refusal of overseas transfer of personal information
The rights may be exercised in writing, by email, fax, etc., and the Company will take action on this without delay (within 10 days from the request date). If the processing takes time, the reasons and the scheduled processing time will be notified.
If an information subject requests correction of errors, etc., in personal information, the Company will not use or provide the relevant personal information until the correction is completed.
The rights may be exercised through an agent such as a legal representative or a person who has been delegated, in which case a power of attorney in accordance with Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
In the following cases, the Company may refuse requests for access, deletion, or suspension of processing, and will notify the reason without delay.
Where access is prohibited or restricted by law
Where there is an apprehension of causing harm to another person's life or body, or unfairly infringing upon another person's property and other interests
Where the personal information is explicitly designated as a subject of collection in other laws and regulations
Where other laws and regulations prescribe that personal information cannot be deleted
Demands regarding personal information included in the Input Data must be made to the Customer, who is the Personal Information Controller. The Company processes it according to the Customer's instructions as a trustee, and if it receives a direct request from an information subject, it will deliver it to the Customer.
Article 12 (Personal Information Protection Officer and Access Request Department)
The Company takes general responsibility for tasks related to personal information processing and has designated a Personal Information Protection Officer as follows to handle complaints and remedy damages of information subjects related to personal information processing.
Personal Information Protection Officer
Name: Philip Choi
Position: Tech Lead
Email: philipchoi@togglecampus.com
Phone: 02-6010-0731
Personal Information Access Request and Grievance Handling Department
Department Name: Operations Team
Email: contact@togglecampus.com
Phone: 02-6010-0731
Address: 2nd floor, 33-10 Gangnam-daero 78-gil, Gangnam-gu, Seoul (Yeoksam-dong)
Information subjects may inquire with the Personal Information Protection Officer and the reception department regarding all inquiries, complaint handling, damage relief, etc., related to personal information protection that occurred while using the Services. The Company will answer and process them without delay.
Article 13 (Measures to Ensure Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
Administrative Measures
Establishment and implementation of internal management plans
Regular training for personnel handling personal information
Minimization of personnel handling personal information and control of access authority
Technical Measures
Encryption of personal information during transmission and storage
Installation/operation of access control systems and preservation/inspection of access logs
Differential granting of authority by account and immediate withdrawal of authority upon retirement or change of duty
Installation and periodic update/inspection of security programs
Physical Measures
Access restriction to systems where personal information is stored
Entry/exit control of offices and data storage locations
The Company implements the above measures, but is not responsible for accidents that occur due to the information subject's own carelessness or problems on the Internet outside the scope of the Company's management.
Article 14 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
The Company uses cookies to provide customized services to individual users and to maintain their login status.
Purpose of Using Cookies
Maintaining login sessions and security authentication
Service improvement through analysis of users' service usage patterns
Users can refuse to store or delete cookies through their web browser settings. However, if cookie storage is refused, restrictions may occur in using some services that require login. (In Chrome: Settings > Privacy and security > Third-party cookies)
Article 15 (Remedies for Rights Infringement)
Information subjects can apply for dispute resolution or consultation with the following organizations to receive remedies for personal information infringement.
Personal Information Infringement Report Center — (Without Area Code) 118 / privacy.kisa.or.kr
Personal Information Dispute Mediation Committee — 1833-6972 / www.kopico.go.kr
Supreme Prosecutors' Office Cyber Crime Investigation Division — (Without Area Code) 1301 / www.spo.go.kr
National Police Agency Cyber Bureau — (Without Area Code) 182 / ecrm.police.go.kr
In addition, any person whose rights or interests have been infringed upon due to a disposition or omission made by the head of a public agency in response to a demand under Article 35 (Access), Article 36 (Correction/Deletion), and Article 37 (Suspension of Processing) of the Personal Information Protection Act may file an administrative appeal as prescribed by the Administrative Appeals Act.
Article 16 (Amendment to Personal Information Processing Policy)
If there is any addition, deletion, or modification of the contents of this Policy, it will be notified through website notices or email at least 7 days before the effective date. However, if there are significant changes to the rights of information subjects, it will be notified at least 30 days in advance.
The Company manages the revision history of this Policy as follows, and previous versions are provided upon request.
v1.0 (Effective 2025-06-10) — Initial enactment
v2.0 (Effective 2026-09-03) — Clarified retention periods, updated status of entrustment/overseas transfer, specified status as trustee, established new clauses for AI training exclusion and automated decisions, and supplemented destruction procedures and remedies for rights infringement
Toggle Campus Co., Ltd.
Address: 2nd floor, 33-10 Gangnam-daero 78-gil, Gangnam-gu, Seoul (Yeoksam-dong)
Representative: Gyutae Bae
Business Registration Number: 809-81-03005
Email: contact@togglecampus.com
Phone: 02-6010-0731
© 2026 Toggle Campus Co., Ltd. All Rights Reserved.
Periodic reports,
don't hold onto them for too long anymore
Reduce your burden with Invector
and increase your efficiency
Toggle Campus Co., Ltd.
Address
2nd Floor, 33-10 Gangnam-daero 78-gil, Yeoksam-dong, Gangnam-gu, Seoul
Business Registration Number:
809-81-03005
CEO
Bae Gyu-tae
baegyutae@togglecampus.com
TEL
02-6010-0731