Effective date: 2026-06-24
Flux (the "Service"), operated by POSTMEDIA Co., Ltd. (the "Company"), establishes this Privacy Policy in accordance with the Personal Information Protection Act (PIPA) of the Republic of Korea to protect the personal information of its users and safeguard their related rights. The Service is an internal RAG platform in which data is processed in isolation on a per-organization basis. The Service is intended for employees and organization members aged 14 or older and is not directed at children under the age of 14.
The Service collects the following items.
Sign-up & Authentication
Contact Inquiry
Automatically Collected
In the Course of Using the Service
The processing of anonymous aggregate usage-behavior data is based on the legitimate interest ground under PIPA. We perform only the minimum non-identifying aggregation necessary to achieve the purpose of service-quality improvement (necessity); we do not identify individuals and do not store raw IPs or original view-path text, thereby minimizing any infringement of user rights (balance); and we disclose in advance the fact of collection, the items, and the opt-out method through this Policy (predictability).
The Service destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved.
Destruction Procedure
Destruction Method
A. Outsourcing to External AI Providers via Organization API Keys
Where an organization (the using party) registers an external provider’s API key to use a given feature, data entered by users (such as questions and document excerpts) may be transmitted to and processed by the providers below. Many providers operate servers overseas, so an overseas transfer of personal information may occur.
If only self-hosted (internal) models (e.g., Qwen3, SigLIP2) are used, the relevant data is not transmitted externally. Each external provider’s data-processing practices are governed by that provider’s own terms. Organization administrators can control which external providers are used in the settings.
In addition, when a contact inquiry is received, the inquirer’s email and name are transmitted to the email-delivery provider (Resend, United States) in order to send an automated reply to the inquirer and a notification email to the operator. Member authentication and notification emails may also be sent via the same provider.
The PIPA Article 28-8 overseas-transfer disclosures for the above external providers are as follows.
B. Overseas Transfer for Service-Operation Analytics (Google Analytics)
For operational statistical analysis, the Service may mirror and transmit self-collected anonymous aggregate usage-behavior data to Google Analytics (GA4). This constitutes an overseas transfer under PIPA Article 28-8, and the relevant disclosures are as follows.
Service-operation analytics targets only anonymous aggregates that do not identify individuals; information that can directly identify a user, such as name, email, or original IP, is not transmitted to Google.
Under PIPA Articles 35 through 37, users may at any time request access to, correction of, deletion of, or suspension of processing of their personal information.
Procedure and Processing Timeline
However, data owned and managed by the organization (employer) — such as shared documents and intra-organization conversations — cannot be deleted by an individual alone, pursuant to the proviso of PIPA Article 36(1) and related provisions, and is governed by the organization’s management policy.
Responses generated by the Service’s RAG chatbot and agents are assistive tools premised on review and use by the user; they do not, in themselves, constitute a fully automated decision under PIPA Article 37-2 that produces legal effects on or similarly significantly affects the data subject. Responsibility for verifying the accuracy of generated responses is as provided in the Terms of Service.
Automated processing such as anomalous-access detection and request-rate limiting for security purposes is intended to protect the Service, and measures that may significantly affect a user, such as account suspension, are carried out following administrator review. If we introduce a feature that constitutes a fully automated decision in the future, we will disclose its criteria and the data subject’s right to refuse and to request an explanation in advance.
The Service uses essential cookies (session tokens) to maintain login sessions. These cookies are essential to providing the Service, and login functions cannot be used if they are refused. The Service also uses Google Analytics (GA4) analytics cookies (e.g., _ga) for usage statistics (see Section 5). We do not use cookies for advertising or retargeting purposes.
Among usage-behavior analyses for service improvement, our self-collection is by default performed as an anonymous aggregate that does not identify users, without cookies or tracking identifiers (storing page-view/event counts aggregated by time unit), and we do not place any separate advertising analytics cookie. However, where user-level analysis is enabled, events may be collected with a pseudonymous identifier (a one-way hash of the user identifier and a session identifier); even then, directly identifying information such as name, email, or original IP is not stored for analytics purposes.
The Google Analytics (GA4) described in Section 5 is collected and transmitted directly from the user’s browser via Google’s gtag.js; in this process Google sets analytics cookies (e.g., _ga), and information such as IP address, page URL, and device/browser details is transmitted to Google (see Section 5 for the overseas-transfer disclosure).
The operator of the Service and the Personal Information Protection Officer who oversees personal-information processing and handles complaints and remedies for data subjects are as follows.
Reports and consultations regarding infringement of personal information may be directed to the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Center (118), the Supreme Prosecutors’ Office (1301), or the National Police Agency (182).
If this Policy is changed, we will provide notice of the changes and the effective date within the Service at least 7 days before the effective date. Changes that materially affect data subjects’ rights (such as to collected items, purpose of use, retention period, or outsourcing/overseas-transfer recipients) will be notified 30 days before the effective date and, where feasible, communicated individually via email or similar means.