개인정보 처리방침
발효일:
목차
This document describes how Folk (hereinafter “We”, “Us”) collects, uses, stores, and protects the personal data (“Personal Data”) You, or your employees using the Platform (the “Users”) provide to Us through the platform “Folk” (the “Platform”).
We are committed to comply with the provisions of the General Data Protection Regulation (GDPR).
By accessing the Platform and using the Services, You and the Users acknowledge that You and the Users have read this privacy policy (the “Privacy Policy”). The Privacy Policy applies to the processing of personal data performed when using the Platform and Services.
The Privacy Policy supplements the Platform's terms of service (“TOS”). Capitalized terms not defined in the Privacy Policy have the meaning given to them in the TOS.
By using the Platform and the Services, the Users and You are bound by the Privacy Policy, which can be modified or updated at any time. Any modification will be posted on the Platform. If the modifications or updates concern elements for which Your consent of was required, We will inform You in order to obtain Your consent again.
1. Data Controller
We, Folk Inc., a Delaware corporation, whose registered office is located at 1209 North Orange Street, Wilmington, Delaware 19801, is the Data Controller, within the meaning of the GDPR, of Your personal data, as well as the Users’ Personal Data.
For any question or request relating to this Privacy Policy or to the processing of Your or the Users’ Personal Data, You can contact Us at the following address: privacy@folk.app
2. Conditions for processing Your personal data
귀하가 자발적으로 당사에 전송한 개인정보를 수집 및 이용하며, 이는 서비스 가입 및 당사로부터의 정보(뉴스레터)가 포함된 이메일을 수신하는 데 필요합니다.
귀하는 정확하고 진실되며 올바른 개인 정보 및 세부 사항을 제공해야 하며, 해당 정보가 진실되고 완전하게 유지되도록 필요할 때마다 이를 업데이트해야 합니다.
We collect and process Your Personal Data in a fair and lawful manner, while respecting Your rights.
Under no circumstances do We (i) sell Your Personal Data and (ii) use Your Personal Data to train AI models.
3. Information collected
We collect information about You and the Users including information that You and the Users provide in connection with the Service, information from Third Parties, and information that is collected automatically such as through cookies and other technologies:
- personal information including, but not limited to, full names, postal address, email address;
- payment information, including, but not limited to, payment card number, expiration date, security code and billing address, invoices;
- information that Your and Users’ browser sends whenever the Services and Platform are used;
- third-party services that We use and that collect, monitor and analyze data to provide analytics and other data to help us to improve Our Platform and Services;
- third-party services (including, but not limited to, Microsoft Outlook, Gmail, iCloud) used by You and the Users to import data in the Platform including, but not limited to, Contacts Personal Data (email, name, address, phone number, calendar events, etc.), being specified that We process Contacts Personal Data as Your processor and in compliance with our Data Processing Agreement;
- inquiries and feedbacks provided by You and/or the Users, including contact information and content of the inquiries and feedbacks; and
- Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding an interaction with the Platform.
We requested Your Google data access or Your Microsoft data with the following scope:
- Access to the contacts in Your Google Contacts after you authenticate (auth/contacts);
- Read email resources metadata including Your labels, history records, and email messages (…/auth/Gmail.read-only – or Microsoft);
- Read events in Your calendars (…/auth/calendar.read-only);
- Send emails using Your Gmail account (…/auth/gmail.send).
The only way our Service access Your Google data is after You explicitly accept our Privacy Policy and provide us with the right to access Your Google data, as defined above. We are fully compliant with Google requirements. We will use reasonable efforts to protect Your information collected through Google API and we will not use this data to develop, improve or train generalized AI or LM models.
Folk Mobile Application
When you use the folk mobile application on iOS or Android, we additionally collect:
- Device identifiers including the iOS Identifier for Vendor (IDFV) and an Android Application ID. These are used to associate a session with Your and the Users’ folk account, for crash reporting, and for diagnostics. They are not used for advertising and are not shared with advertising networks.
- Crash and performance diagnostics, including stack traces, operating system version, device model, app version, and anonymized usage events. This data is used solely to identify and fix bugs and to improve mobile app performance.
- In-app activity, such as which screens you visited and which features you used, used to improve the product. This data is associated with Your and the Users’ folk account.
The folk mobile application does not access the contacts stored in your device’s native address book. CRM contacts are imported only from the third-party services you explicitly connect (Google, Microsoft, and the others listed in our List of Sub-Processors).
The folk mobile application does not currently send push notifications and does not collect push notification tokens.
The folk mobile application does not include cross-app advertising or tracking SDKs and does not display third-party advertising. The iOS app does not request App Tracking Transparency permission.
4. Purpose of processing and legal basis
We collect information, including Personal Data, for the purpose following purposes and legal bases:
- deliver the Platform and Services to You and the Users (legal basis: performance of the TOS);
- identifying and communicating with You, including newsletters and marketing materials (legal basis: Our legitimate interests to communicate with You and the Users);
- responding to Your requests, including customer service inquiries (legal basis: performance of the TOS);
- processing Your payments (legal basis: performance of the TOS);
- improving the Services and analyzing Your and the Users’ usage of the Platform and Services (legal basis: Our legitimate interests to improve the Platform and Services); and
- responding to valid legal processes and valid requests from government authorities (legal basis: legal obligation).
The way we use Your and the Users’ data obtained through Google API is explicitly limited to the use defined below:
- Providing the Platform and Service;
- Access to the contacts in Your Google contacts and read resources metadata to synchronize Your contacts and metadata so You can access them on Our Service. Our use of Google data is limited to the practices explicitly disclosed in this Privacy Policy. We must obtain Google’s express consent for using Google data beyond the limits set in this Privacy Policy.
5. Recipient of Personal Data and transfer outside European Union
Within the framework of the management of the Platform and Services, We may transmit Personal Data to several recipients, in particular:
- 서비스 제공업체: 당사는 귀하에 대해 수집한 정보를 제3자 서비스 제공업체에 공개할 수 있습니다. 당사가 귀하의 정보를 위탁하는 서비스 제공업체의 범주는 다음과 같습니다: (i) 서비스 제공; (ii) 귀하가 요청한 정보, 제품 및 기타 서비스(본 계약에서 정의된folk 포함) 제공; (iii) 마케팅 및 광고; (iv) 결제 및 거래 처리; (v) 고객 서비스 활동; (vi) IT 및 관련 서비스 제공; (vii) 사기 방지 및 사용자 인증.
- Advertising Partners: We do not disclose or use your information to advertise any third party’s products or services via the Services. We may disclose your information to third-party advertising partners to market our own Services and grow our Services’ user base, such as to provide targeted marketing about our own Services via third-party services. Please see the “Your Choices” and “Your Rights” sections below for more information and to opt out.
- 당사 또는 타인을 보호하기 위한 정보 공개: 당사는 다음의 목적을 위해 선의로 필요하거나 적절하다고 판단될 경우, 귀하와 관련하여 저장한 모든 정보에 접근, 보존 및 제3자에게 공개할 수 있습니다: (i) 법 집행 기관 또는 국가 안보 요청 및 법적 절차(예: 법원 명령 또는 소환장)에 응하기 위함; (ii) 귀하, 당사 또는 타인의 권리, 재산 또는 안전을 보호하기 위함; (iii) 당사의 정책 또는 계약 이행; (iv) 당사에 대한 채권 회수; 또는 (v) 의심되거나 실제 불법 행위에 대한 수사 및 기소 지원.
- 합병, 매각 또는 기타 자산 양도 시 정보 공개: 당사가 합병, 인수, 자금 조달 실사, 구조 조정, 파산, 관리인 선임, 일부 또는 전체 자산 매매, 또는 서비스 제공업체 변경에 관여하는 경우, 귀하의 정보는 법률 및/또는 계약이 허용하는 범위 내에서 해당 거래의 일부로 판매되거나 양도될 수 있습니다.
The recipients of Personal Data are the following:
| 프로세서 | 데이터 유형 | 이유 | 지역 | 거부할 수 있음 |
| 터보퍼퍼 | 연락처 정보 | 검색 | 미국 | 아니 |
| Apollo.io | 연락처 정보 | 풍요화 | 미국 | 아니 |
| AWS | PII, Contact data | 호스팅 (서버 / 데이터베이스 / 스토리지) | 미국 | 아니 |
| 턴키 | 개인 식별 정보 | 이탈 관리 | 미국 | 아니 |
| 유합된 | 연락처 정보 | 이벤트 스트리밍 | 미국 | 아니 |
| Datadog | Diagnostics, logs | Infrastructure monitoring | EU | 아니 |
| 데이터그마 | 연락처 정보 | 풍요화 | 미국 | 아니 |
| DropContact | 연락처 정보 | 풍요화 | EU | 아니 |
| ElevenLabs | 연락처 정보 | Note dictation (speech-to-text) | 미국 | 네 |
| Google 애널리틱스 | 쿠키 | 마케팅 | 미국 | Yes (decline cookie banner) |
| Google Workspace | 연락처 정보 | 연락처 및 상호작용 동기화 | 미국 | 네 |
| 인터콤 | 개인 식별 정보 | 고객 지원 | 미국 | 아니 |
| 선형 | 개인 식별 정보 | 버그 추적 | 미국 | 아니 |
| 만들다 | 연락처 정보 | User-configured automations | EU | 네 |
| Microsoft 365 | 연락처 정보 | 연락처 및 상호작용 동기화 | 미국 | 네 |
| 오픈에이아이 | 연락처 정보 | Enrichment, Formatting | 미국 | 아니 |
| 피플 데이터 랩스 | 연락처 정보 | 풍요화 | 미국 | 아니 |
| 당혹감 | 연락처 정보 | 풍요화 | 미국 | 네 |
| 프로스페오 | 연락처 정보 | 풍요화 | EU | 아니 |
| RevenueCat | 개인 식별 정보 | Mobile payments / subscription management | 미국 | 아니 |
| Sendgrid | 연락처 정보 | 이메일 발송 | 미국 | 네 |
| Sentry | Technical data | Service quality | ||
| 스트라이프 | 개인 식별 정보 | 청구 | 미국 | 아니 |
| 스티치 | 개인 식별 정보 | 인증 | 미국 | 아니 |
| 자피어 | 연락처 정보 | 자동화 | 미국 | 네 |
| 연락처 정보 | 연락처 및 상호작용 동기화 | 미국 | 네 |
We may also share, transmit, disclose, grant access to, make available, and provide Personal Data with and to Third Parties if in accordance with this Privacy Policy. Under no circumstances will We share Your Google data with Third Parties, except in accordance with this Privacy Policy. We commit not to communicate, sell, or transfer Personal Data to Third Parties (aside from Our service providers) without Your express consent, but may communicate them if the law so requires, or upon judicial or government request.
When Personal Data are transferred to countries outside of the European Union, We ensure that the following safeguards are taken:
- Processors are certified under the Data Privacy Framework, which benefit from an adequacy decision from the European Commission pursuant to article 45 of the GDPR and the transfer falls within the scope of such adequacy decision; or
- We have concluded a contract with the recipient of Personal Data that contains the Standard contractual protection clauses adopted by the European Commission pursuant to article 47 of the GDPR.
6. Rights of Data Subjects
Pursuant to GDPR, You and the Users have the following rights:
- The right to access, modify, delete and transfer Personal Data;
- The right to oppose or restrict the processing of Personal Data;
- The right to obtain communication of Personal Data in a structured, commonly-used, readable format (data portability, unless legitimately impossible);
- The right to withdraw consent at any time, when processing relies on consent. In such case, the withdrawal of the consent will not affect the lawfulness of the processing carried out prior to the withdrawal of such consent.
If You are located in the European Union, You also have the right to lodge a complaint with the competent supervisory authority for data protection matters. In France, this is the Commission nationale de l’Informatique et des Libertés (CNIL). You also have the right to define directives pertaining to your digital testament.
You and the Users may exercise these rights by sending an email to privacy@folk.app. We undertake to respond to Your and the Users’ request within thirty (30) days from the receipt of the request. Subject to a possible extension of two additional two months, We reserve the right to object to any requests considered unreasonable due to the repetitive nature thereof.
You may delete your folk account at any time reaching out to support@folk.app. In the folk mobile app (iOS or Android), you can request the deletion by navigating to Settings → Delete account. More information available at https://help.folk.app/en/articles/5701307-how-do-i-delete-my-account
You and the Users are informed that We may, in the event of a doubt as to Your or the Users’ identity, ask for proof of identity in order to prevent any unauthorized access to Personal Data.
7. Communication
We may send You emails to the address associated to Your Account and to the Users’ account, to inform You and the Users of the Services changes or its activities, or to communicate technical or administrative information.
You and the Users may opt out of receiving any, or all, of these marketing communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. Please note that We may still send You transactional or administrative messages related to the Services even after You have opted out of receiving marketing communications.
8. Data retention, security, and deletion
Personal Data are hosted by Amazon Web Services inside Aurora database that is fully-secured and not accessible outside our servers. Our AWS services are located in the US. We implement technical and organisational measures designed to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
귀하의 이메일 주소 및 Google 고유 리소스 ID를 포함한 개인 데이터를 제외하고 귀하의 Google 데이터는 저장하지 않습니다.
All data transmitted between your browser, desktop application, or mobile device and folk’s servers is encrypted in transit using TLS 1.2 or higher. Data at rest in our databases and S3 storage is encrypted using AES-256.
We keep Personal Data as long as Your account remains active.
Your account and the Users’ account will be deleted within one week of the deletion request. However, Personal Data associated with the account will be kept for as long as necessary for the purposes for which they are processed.
Personal Data will be removed:
- from Our databases within 7 days after the deletion request date;
- from Our database backups within 730 days after the deletion request date;
- from Our application logs within a maximum of 930 days after the deletion request date.
Independently from deletion requests, We apply specific retention periods depending on the purposes pursued, in particular: (i) customer account data are kept for the duration of the contractual relationship, then archived for up to five (5) years in intermediate storage for the establishment, exercise or defence of legal claims; and (ii) accounting documents are kept for ten (10) years in accordance with Our legal obligations. At the end of the applicable retention periods, the Personal Data are deleted or irreversibly anonymized.
However, requests to delete Personal Data may be refused, in whole or in part, where such deletion would prevent Us from complying with a legal obligation, or where the processing remains necessary, in particular (i) for the establishment, exercise or defense of legal claims, (ii) for compliance with statutory retention periods (in particular in accounting and tax matters), (iii) for reasons of important public interest (including the detection and prevention of fraud or security incidents), (iv) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, to the extent that the deletion of the data is likely to render impossible or to seriously impair the achievement of the objectives of such processing, or (v), where applicable, comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546).
9. 쿠키
A cookie is a file that can be recorded on the hard drive of Your and the Users’ terminals when accessing and using the Platform and Services. Cookies may collect information to improve the Services and Platform. Depending on the purposes of the cookies, consent is necessary for the deposit of cookies.
We use cookies:
- of navigation, which are cookies necessary for the proper technical functioning of the Platform as they allow for the optimization of the display of the content from each terminal and for the application of security parameters (“_cfuid” cookies), which expire when You and the Users close the browser;
- functional cookies, which are not essential to the proper functioning of the Platform but optimize the experience by allowing it to be adapted to You and the User’s terminal and by saving the choice regarding the deposit of cookies. These cookies expire after one year;
- analytics and audience measurement, which allow to follow the navigation of the Users for the purpose of optimization. We use:
- Google Analytics, a web analytics service provided by Google to improve the operation of the Platform. Google Analytics uses the data collected, including the number of visitors, the origin and the details of the pages that were visited, to track and study the use of the Platform, to prepare reports on activities. Google’s privacy policy is available under this link. The main cookies used are the following:
| Name of the cookies | Function, recipient and retention period | 목적 |
| _ga | This cookie is used for Google Analytics. It allows to follow the performance of the pages consulted by the users. This cookie expires after 13 months. | Performance |
- Twilio (Segment)
We do not keep tracking cookies or cookies containing IP addresses for more than thirteen (13) months after their initial deposit on the terminal(s). You and the User may at any time delete cookies from the browser and set it up to block their storage on terminals. We invite You and the Users to refer to the help file of the browser software to establish the appropriate setup.
Rejecting the use of cookies may prevent optimal use of the Platform and Services. Traffic data are generated when the terminal is connected to the internet and the Platform and Services. These data may be used to improve Our Service. We never use personal names in traffic data analyses.
10. Stipulations for US Users
10.1. Children's privacy
당사의 서비스는 일반 대중을 대상으로 하며, 13세 미만 사용자("아동")를 대상으로 하지 않습니다. 당사는 미국 아동 개인정보 보호법("COPPA")에서 정의한 개인정보를 COPPA가 허용하지 않는 방식으로 수집할 의도가 없습니다.
부모 또는 보호자이신 분께서 당사가 해당 정보를 보유하고 있다고 생각되시면, 여기로 연락주시기 바랍니다. 당사는 COPPA에서 요구하는 범위 내에서 해당 정보를 삭제해 드리겠습니다.
COPPA에 대한 자세한 내용은 여기를 클릭하거나 www.FTC.gov을 방문하여 아동 온라인 안전 및 개인정보 보호에 관한 부모 지침을 확인하십시오.
10.2. Non-Discrimination: we will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- 상품이나 서비스를 제공하지 않음.
- 상품이나 서비스에 대해 할인이나 기타 혜택을 제공하거나 불이익을 부과하는 등 다양한 가격이나 요금을 부과합니다.
- 다른 수준 또는 품질의 상품이나 서비스를 제공합니다.
- 상품이나 서비스에 대해 다른 가격이나 요금을 받거나, 다른 수준이나 품질의 상품이나 서비스를 제공받을 수 있음을 시사합니다.
질문 있으신가요?
Questions regarding this policy may be sent to security@folk.app. We also invite you to contact us with suggestions for improvements.