Alleo Privacy Policy

Effective Date: May 4, 2026


Kroffle Inc. (the "Company") establishes and publishes this Privacy Policy in accordance with the Personal Information Protection Act and applicable laws in order to protect the personal information of data subjects and to promptly and smoothly handle related grievances.


Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. Personal information being processed will not be used for purposes other than those listed below. If the purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

  1. Membership registration and management

    • Identity verification and personal identification for use of membership services
    • Prevention of unauthorized use by bad-faith members and prevention of unauthorized access
    • Confirmation of intent to register, age verification, and record retention for dispute mediation
    • Handling complaints and civil inquiries, and delivering notices
  2. Provision of the Service

    • Provision of AI search optimization (AEO/GEO) analysis and automation services
    • Provision of content and customized services
    • Identity authentication and service usage notices
  3. Use for marketing and advertising

    • Development of new services and provision of customized services
    • Provision of event and advertising information and opportunities to participate, only where separate consent has been obtained
    • Verification of service effectiveness, analysis of access frequency, and statistics on members' service usage
  4. When providing Paid Services

    • Processing payments and refunds
    • Providing content and identity authentication

Article 2 (Items of Personal Information Processed)

The Company processes the following personal information items.

1. Items collected during membership registration

  • Required items: email address, name, phone number, company name, password
  • Optional items: job title, industry, and other additional information related to use of the Service

2. Items automatically collected during use of the Service

  • IP address, cookies, service usage records, visit records, access logs, device information (OS, browser type, etc.), and records of improper use

3. Items collected when using Paid Services

  • Payment information, including payment method information and transaction history. However, detailed payment information such as card numbers is directly processed by the payment gateway provider, Toss Payments, and is not stored by the Company.

4. User-entered analysis data

  • Domains, URLs, text content, and other analysis target data entered by Members to use the Service

Article 3 (Processing and Retention Period of Personal Information)

  1. The Company processes and retains personal information within the period of retention and use prescribed by law or within the period of retention and use agreed to by the data subject when the personal information was collected.

  2. Member information: retained until membership withdrawal, and destroyed without delay upon withdrawal. However, in the following cases, information will be retained for the specified period.

    • If an investigation or inquiry due to violation of applicable laws is ongoing: until the relevant investigation or inquiry is completed
    • If any claim-debt relationship remains due to use of the Service: until the relevant claim-debt relationship is settled
  3. Items retained under applicable laws

    • Records on contracts or withdrawal of subscription: 5 years (Act on the Consumer Protection in Electronic Commerce)
    • Records on payment and supply of goods or services: 5 years (Act on the Consumer Protection in Electronic Commerce)
    • Records on consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce)
    • Records on display and advertising: 6 months (Act on the Consumer Protection in Electronic Commerce)
    • Website visit records (login records): 3 months (Protection of Communications Secrets Act)

Article 4 (Provision of Personal Information to Third Parties)

  1. The Company processes data subjects' personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as consent from the data subject or special provisions of law.

  2. The Company does not currently provide personal information to third parties. If third-party provision becomes necessary in the future, the Company will provide such information only after obtaining consent from the data subject and will give prior notice through the Terms of Service or this Privacy Policy.


Article 5 (Outsourcing of Personal Information Processing)

  1. The Company outsources personal information processing tasks as follows for smooth provision of the Service.
Recipient (Processor) Details of Outsourced Tasks
Cloudflare, Inc. Web service delivery, security, caching, and related infrastructure operations
Google LLC (Google Analytics 4) Analysis of service usage statistics
Toss Payments Co., Ltd. Payment processing and payment-related identity authentication
Anthropic, PBC Calling AI analysis model (Claude)
OpenAI, L.L.C. Calling AI analysis model (GPT)
xAI Corp. Calling AI analysis model (Grok)
Google LLC Calling AI analysis model (Gemini)
Perplexity AI, Inc. Calling AI search analysis model
  1. When entering into outsourcing agreements, the Company specifies in documents such as contracts matters concerning prohibition of personal information processing for purposes other than the outsourced work, technical and managerial safeguards, restrictions on re-outsourcing, management and supervision of processors, and liability for damages, in accordance with Article 26 of the Personal Information Protection Act. The Company also supervises whether processors safely process personal information.

  2. If the details of outsourced tasks or processors change, the Company will disclose such changes through this Privacy Policy without delay.


Article 6 (Overseas Transfer of Personal Information)

The Company transfers personal information overseas as follows for purposes such as providing AI analysis services.

Recipient Country Transferred Items Timing and Method of Transfer Purpose of Use Retention and Use Period
Cloudflare, Inc. United States Member information and all service usage data Transferred over the network when the Service is used Web service delivery, security, caching, and related infrastructure operations Until termination of the outsourcing agreement
Google LLC United States IP address, cookies, service usage records Transferred over the network when the Service is used Statistical analysis (GA4), AI analysis (Gemini) Until termination of the outsourcing agreement
Anthropic, PBC United States User-entered analysis data, including domains and content Transferred over the network when API calls are made Calling AI analysis model Destroyed immediately after processing, in accordance with Anthropic policy
OpenAI, L.L.C. United States User-entered analysis data, including domains and content Transferred over the network when API calls are made Calling AI analysis model Destroyed immediately after processing, in accordance with OpenAI policy
xAI Corp. United States User-entered analysis data, including domains and content Transferred over the network when API calls are made Calling AI analysis model Destroyed immediately after processing, in accordance with xAI policy
Perplexity AI, Inc. United States User-entered analysis data, including domains and content Transferred over the network when API calls are made Calling AI search analysis model Destroyed immediately after processing, in accordance with Perplexity policy

In connection with the overseas transfers above, the Company obtains consent from data subjects or processes personal information safely based on applicable law in accordance with Article 28-8 of the Personal Information Protection Act, and imposes contractual obligations for personal information protection on recipients.

Data subjects have the right to refuse overseas transfer of personal information by the Company, and refusal may restrict use of certain services.


Article 7 (Rights and Obligations of Data Subjects and How to Exercise Them)

  1. Data subjects may exercise the following personal information protection rights against the Company at any time.

    • Request to access personal information
    • Request correction if there is an error
    • Request deletion
    • Request suspension of processing
  2. Rights under Paragraph 1 may be exercised against the Company in writing, by email, by fax, or by other methods in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.

  3. If a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.

  4. Rights under Paragraph 1 may be exercised through a legal representative of the data subject or an authorized agent. In such case, a power of attorney in the form prescribed in Appendix No. 11 of the Public Notice on Personal Information Processing Methods must be submitted.

  5. Requests to access personal information and requests to suspend processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act.

  6. If other laws specify that certain personal information must be collected, the data subject may not request deletion of such personal information.


Article 8 (Destruction of Personal Information)

  1. When personal information becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose, the Company destroys the relevant personal information without delay.

  2. If the Company must continue to retain personal information under other laws even after the retention period agreed to by the data subject has expired or the processing purpose has been achieved, the Company will move the personal information to a separate database or store it in a different location.

  3. The destruction procedure and method for personal information are as follows.

    • Destruction procedure: The Company selects personal information for which the reason for destruction has occurred and destroys it with approval from the Company's Chief Privacy Officer.
    • Destruction method: Personal information recorded and stored in electronic file format is destroyed using methods such as low-level formatting so that the records cannot be restored. Personal information recorded and stored in paper documents is shredded or incinerated.

Article 9 (Measures to Ensure Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

  1. Managerial measures: establishment and implementation of an internal management plan, regular employee training, etc.
  2. Technical measures: management of access rights to personal information processing systems, installation of access control systems, encryption of unique identification information, installation and operation of security programs
  3. Physical measures: access control for computer rooms, data storage rooms, and similar facilities

Article 10 (Use and Refusal of Cookies)

  1. The Company uses cookies, which store and frequently retrieve usage information, to provide individually customized services to Users.

  2. Cookies are small pieces of information sent by the server used to operate a website to the User's computer browser, and may be stored on Users' PCs or mobile devices.

  3. Purpose of using cookies: analyzing access frequency and visit time for each service visited by Users, identifying Users' preferences and areas of interest, tracking traces, identifying participation in events and number of visits, and providing targeted marketing and personalized services

  4. Installation, operation, and refusal of cookies: Users have the option to allow or refuse cookie installation. Users may configure their web browser options to allow all cookies, confirm each time a cookie is stored, or refuse storage of all cookies.

    • How to configure (Chrome): Settings > Privacy and security > Cookies and other site data
    • How to configure (Edge): Settings > Cookies and site permissions > Manage and delete cookies and site data
    • How to configure (Safari): Preferences > Privacy > Cookies and website data
  5. However, refusing to store cookies may make it difficult to use some services.

  6. The Company collects and analyzes statistics on service usage behavior through Google Analytics 4 (GA4). Users may refuse GA4 collection by installing the GA4 opt-out browser add-on (https://tools.google.com/dlpage/gaoptout).


Article 11 (Processing Personal Information of Children Under 14)

The Company does not accept membership registration from children under the age of 14. If it is confirmed that personal information of a child under 14 has been collected, the Company will destroy the relevant personal information without delay.


Article 12 (Chief Privacy Officer)

  1. The Company designates the following Chief Privacy Officer to take overall responsibility for personal information processing and to handle complaints and remedy damages related to personal information processing.

    Chief Privacy Officer

  2. Data subjects may contact the Chief Privacy Officer regarding any personal information protection inquiries, complaint handling, or damage relief arising while using the Company's services. The Company will respond to and handle data subjects' inquiries without delay.


Article 13 (Remedies for Infringement of Rights)

Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, or similar organizations to seek relief for personal information infringement. For other reports or consultations regarding personal information infringement, please contact the following organizations.

  • Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  • Korean National Police Agency: 182 (ecrm.cyber.go.kr)

A person whose rights or interests have been infringed by a disposition or omission by the head of a public institution regarding requests under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.


Article 14 (Changes to the Privacy Policy)

  1. This Privacy Policy applies from May 4, 2026.

  2. If this Privacy Policy is added to, deleted from, or amended, the Company will announce the change through notices at least 7 days before the amendment. However, if there is an important change to Users' rights, the Company will announce it at least 30 days in advance.


Kroffle Inc.

  • CEO: Ho-beom Lim
  • Business Registration Number: 877-81-02144
  • Mail-order Business Registration Number: No. 2026-Seongdong-0773, Seoul
  • Address: 209, 38 Achasan-ro, Seongdong-gu, Seoul
  • Representative Email: imdojeon@kroffle.com
  • Chief Privacy Officer Email: mint@kroffle.com