Work2

Privacy Policy

Effective · 2026-09-04

HUBB1E Inc. ("we") operates Work2 (the "Service"), a work operations workspace. We comply with the Personal Information Protection Act of Korea (PIPA) and publish this policy to protect the personal information of the people who use the Service.

This policy explains what personal information the Service processes and why, how long we keep it, whom we entrust it to or share it with, and how you can exercise your rights.

Work2 is an internal tool for company crew members and for customer or partner contacts the company invites. We do not offer sign-up to the general public.

Article 1. Personal information we process and whyArticle 2. Retention periodsArticle 3. Destruction procedure and methodArticle 4. Sharing with third partiesArticle 5. ProcessorsArticle 6. Cross-border transfersArticle 7. Your rights and how to exercise themArticle 8. Cookies and automatic collectionArticle 9. Security measures and privacy officerArticle 10. Data breach responseArticle 11. RemediesArticle 12. Changes to this policy

Article 1. Personal information we process and why

The Service processes the items below. They come from what you enter, what a workspace admin registers, or from external services you choose to connect. We do not process anything not listed here.

Crew account
ItemsGoogle Workspace account identifier, email, display name, profile image; or email address with a one-time sign-in link, two-factor (TOTP) secret; workspace membership and role
PurposeIdentity verification, sign-in, access control, workspace assignment
SourceEntered by you at Google or email sign-in
Access records
ItemsIP address, browser and device information, sign-in time, security events (failed sign-in, sign-out everywhere)
PurposePreventing unauthorized access, investigating incidents, keeping the Service stable
SourceGenerated automatically while you use the Service
HR
ItemsLegal name, local-script name, date of birth, address, contact details, hire date, title, pay, attendance and leave requests, resident registration number (stored encrypted)
PurposePerforming the employment contract; payroll, social insurance, and withholding obligations; issuing employment certificates
SourceEntered by a workspace admin or by you
Travel
ItemsPassport number, expiry, nationality, date of birth, flight details, contact details, arrival-card entries (Taiwan TWAC, China CNAC, Japan VJW)
PurposeBooking trips, ticketing flights, rail, and bus, filing arrival cards on your behalf, keeping trip records
SourceEntered by you or a workspace admin
Customers and partners
ItemsContact name, email, phone, company, title, business-card image, customer-portal sign-in email
PurposeManaging accounts, collaboration, customer-portal sign-in
SourceEntered by crew, business-card upload, or by the contact at portal sign-in
Finance
ItemsCorporate bank and card transactions, sales slips, tax invoices, business registration certificate, HomeTax, customs, and bank certificates and access credentials (stored encrypted), transfer payee name and account number, payer date of birth and mobile number at checkout
PurposeSpend management, preparing tax filings, corporate payments
SourceFinancial and government integrations you configure; entered by you at checkout
Mail and inbox
ItemsHeaders, bodies, and attachments of Gmail or Proton mailboxes you connect; mail delivered to the Service's receiving address; Raindrop bookmarks you connect
PurposeReading work email, drafting (Gmail), organizing the inbox
SourceMail integrations you configure
AI
ItemsText and audio you submit to AI features; business-card images you upload; name and email for AI seat assignment
PurposeAI assistance such as summarizing and drafting; managing AI service seats
SourceEntered by you

Resident registration numbers are processed only for labor and tax obligations that statute specifically requires or permits, and are encrypted at rest with a dedicated key. We process no other unique identifiers or sensitive information.

The Service is not directed at children under 14 and we do not knowingly collect their personal information.

Article 2. Retention periods

We destroy personal information without delay once its purpose is fulfilled or one of the events below occurs. Items another statute requires us to keep are stored separately for that period.

Crew account and access records
RetentionUntil departure or account deletion. Sign-in sessions renew every 8 hours and require a fresh sign-in 30 days after the first sign-in.
HR
RetentionAfter departure, for the statutory period (3 years for employment records under the Labor Standards Act; 5 years for tax records under the Framework Act on National Taxes and Income Tax Act)
Travel
RetentionUntil the trip is settled; items that serve as tax evidence for 5 years
Customers and partners
RetentionUntil the relationship ends or deletion is requested
Finance
RetentionStatutory periods under the Framework Act on National Taxes, Corporate Tax Act, and Commercial Act (5 years for transaction records, 10 years for commercial books)
Mail, inbox, and AI input
RetentionUntil you disconnect the integration or delete the item
Customer-portal session
Retention8 hours

Article 3. Destruction procedure and method

  • Procedure: when a retention period ends or the purpose is fulfilled, the privacy officer confirms and we destroy the data. Items with a statutory retention duty are moved to restricted storage.
  • Method: electronic records in the database and object storage are deleted irrecoverably; encrypted items have their encryption keys destroyed with them. Printed copies are shredded.

Article 4. Sharing with third parties

We process your personal information only for the purposes in Article 1 and do not share it with third parties except in these cases:

  • To carry out a booking, ticketing, filing, or lookup you request inside the Service, we pass the minimum items to the relevant institution or vendor (see the table in Article 6). For example, passenger details go to the airline for a flight booking, and passport details go to the destination country's immigration authority for an arrival card.
  • When you give separate consent.
  • When a statute requires it or a law-enforcement agency requests it through lawful procedure.

Article 5. Processors

We entrust the following work to external processors. Contracts include personal-information protection duties and we supervise each processor.

Kakao Cloud (Kakao Enterprise)
Entrusted workServer and database hosting (Korea, kr-central-2 region)
Cloudflare, Inc.
Entrusted workObject storage for attachments and PDFs (encrypted before upload)
Functional Software, Inc. (Sentry)
Entrusted workError monitoring (personal information masked before sending)
Google LLC
Entrusted workGoogle Workspace sign-in, Gmail integration, business-card OCR (Gemini model via OpenRouter)
Resend, Inc.
Entrusted workSending sign-in links and notification email; receiving mail at the Service's inbound address
Proton AG
Entrusted workProton mail integration (when you configure it)
Slack Technologies, LLC / Telegram FZ-LLC
Entrusted workOperational notifications (when you configure them)
Kakao Mobility (Kakao T Business)
Entrusted workBusiness mobility integration and verification SMS
GitHub, Inc.
Entrusted workSyncing tickets and todos to GitHub issues (when you connect a repository to a project)
Zhipu AI (Z.ai)
Entrusted workWorkspace default text model: Slack conversation summaries, partner-profile drafts. Only what you submit is sent.
Anthropic, PBC / OpenAI, LLC / xAI Corp. / OpenRouter, Inc. / Deepgram, Inc.
Entrusted workAI assistance (text generation, summarization, speech recognition, business-card OCR). Only what you submit is sent over the API, under each provider's API terms.
Anysphere, Inc. (Cursor) / Volcengine (ByteDance) / Moonshot AI
Entrusted workAI seat usage lookups (only the registered account email and API key or session token are sent; nothing you submit to AI features)

Article 6. Cross-border transfers

The Service's primary storage is in Korea. Personal information leaves Korea in the cases below. You may refuse a cross-border transfer; refusing disables the related feature (attachment storage, AI assistance, external notifications, overseas bookings and filings). To refuse, contact us under Article 9 or disconnect the integration.

Cloudflare, Inc. (United States)
ItemsAttachments and PDFs (encrypted)
When and howNetwork transfer at upload
Purpose and retentionFile storage. Until you delete the file or its retention period ends
Functional Software, Inc. (United States)
ItemsMasked request details when an error occurs
When and howNetwork transfer at error time
Purpose and retentionError analysis. Sentry's event retention period (90 days by default)
Google LLC (United States) / Resend, Inc. (United States) / Proton AG (Switzerland)
ItemsAccount email and name; mail in connected mailboxes; mail delivered to the Service's receiving address
When and howNetwork transfer at sign-in and when reading, drafting, or receiving mail
Purpose and retentionSign-in and mail features. Until you disconnect
Slack Technologies, LLC (United States) / Telegram FZ-LLC (United Arab Emirates)
ItemsNames and work details contained in notifications
When and howNetwork transfer when a notification is sent
Purpose and retentionOperational notifications. Retention under each service's terms
GitHub, Inc. (United States)
ItemsTitle, body, and assignee names of tickets and todos synced to GitHub issues
When and howNetwork transfer when a project with a connected repository syncs
Purpose and retentionIssue-tracking integration. Until deleted from the repository
Zhipu AI (Z.ai) (China)
ItemsText submitted to Slack summaries and partner-profile generation
When and howNetwork transfer when you use those AI features
Purpose and retentionAI assistance. After the request, each provider's abuse-monitoring window under its API terms
Anthropic, PBC / OpenAI, LLC / xAI Corp. / OpenRouter, Inc. / Deepgram, Inc. (United States)
ItemsText, audio, and business-card images you submit to AI features
When and howNetwork transfer when you use an AI feature
Purpose and retentionAI assistance. After the request, each provider's abuse-monitoring window under its API terms
Anysphere, Inc. (Cursor) (United States) / Volcengine / Moonshot AI (China)
ItemsAccount email and credentials registered for AI seats
When and howNetwork transfer at usage lookups
Purpose and retentionAI seat management. Until the seat is removed
Counterparties of bookings and filings you request: airlines, OTAs (Trip.com, Yeogi), rail (Korail), bus (Kobus, Bustago); Taiwan, China, and Japan immigration authorities; overseas sellers and carriers (Alibaba, JLCPCB, SF Express, FedEx, DHL, USPS, and others)
ItemsPassenger or applicant name, date of birth, contact details, and passport details; recipient name, address, and contact details
When and howNetwork transfer when you execute the booking, filing, or order
Purpose and retentionFulfilling the requested transaction. Retention set by each institution or vendor

Article 7. Your rights and how to exercise them

You may at any time request access to, correction or deletion of, or suspension of processing of your personal information, and withdraw consent.

  • In Settings → Security you can manage two-factor authentication and sign out on every device. In the crew detail panel you can edit your own profile and travel documents.
  • Mail, finance, and AI integrations can be disconnected from their own screens at any time; disconnecting deletes the credentials the Service stored for them.
  • For anything you cannot do yourself, contact us under Article 9. After verifying your identity we respond within 10 days. Items with a statutory retention duty are access-restricted instead of deleted, and we tell you why.
  • A representative acting for you must submit a power of attorney in the form prescribed by the PIPA enforcement rules.
  • You are responsible for keeping your own information accurate. When you enter another person's personal information into the Service, you must inform that person of this policy and obtain any required consent.

Article 8. Cookies and automatic collection

The Service uses only the essential cookies needed to keep you signed in and remember your language. We use no advertising or behavioral-analytics cookies and no third-party tracking scripts.

w2_session
PurposeCrew sign-in session (HttpOnly, tamper-proof signature)
Lifetime8 hours, at most 30 days after first sign-in
w2_client_session
PurposeCustomer-portal sign-in session (HttpOnly, tamper-proof signature)
Lifetime8 hours
w2_totp_challenge
PurposeTwo-factor sign-in in progress (HttpOnly)
Lifetime5 minutes
oauth_state, gmail_oauth_state, work2_raindrop_oauth_state
PurposeForgery protection while Google sign-in or an external connection is in progress (HttpOnly)
LifetimeDeleted when the flow completes, at most 30 minutes
work2-locale
PurposeDisplay language
Lifetime1 year

You can block cookies in your browser settings, but blocking the session cookie means you will not stay signed in.

Article 9. Security measures and privacy officer

  • Encryption: resident registration numbers, passport details in crew profiles, financial certificates and credentials, and attachments are stored with AES-256-GCM envelope encryption; data keys are wrapped by a master key. Arrival-card records you file (name, passport number, itinerary) are kept as filed so you can review the submission. All traffic is protected with TLS.
  • Access control: data is partitioned per workspace with database row-level security. Access is limited by role (admin, crew, customer), and finance and HR data are visible only to crew with a dedicated permission.
  • Authentication: sign-in through a Google Workspace organization account or a one-time email link, with optional two-factor authentication (TOTP). Sessions renew every 8 hours and expire after 30 days.
  • Logging and monitoring: sign-in and security events are recorded, and personal information is masked in anything sent to error monitoring.
  • Operations: we keep the number of people with access to personal information to a minimum and review permissions regularly. Automated checks keep secrets out of logs.

Privacy officer and responsible team: HUBB1E Inc. engineering team (contact email below). Privacy inquiries, complaints, and requests for remedy are received at this address.

Article 10. Data breach response

If we learn that personal information has been, or may have been, lost, stolen, or leaked, we notify the affected users without delay under Article 34 of PIPA — stating the items involved, when and how it happened, how to minimize harm, what we are doing, and how to reach us — and report to the Personal Information Protection Commission or the Korea Internet & Security Agency when the statutory threshold is met.

Article 11. Remedies

For counseling or to report a privacy violation, you may contact these Korean authorities:

  • Personal Information Infringement Report Center (KISA) — privacy.kisa.or.kr / 118
  • Personal Information Dispute Mediation Committee — kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office Cyber Investigation — spo.go.kr / 1301
  • National Police Agency Cyber Bureau — ecrm.police.go.kr / 182

Article 12. Changes to this policy

This policy applies from the effective date. It is the first edition written to the Personal Information Protection Act format and replaces the earlier English notice. When statute or the Service changes and we add, remove, or amend content thereafter, we announce it inside the Service at least 7 days before it takes effect, and at least 30 days before for changes that materially affect your rights. Earlier versions are available on request.

Contact

Send privacy questions, access, correction, or deletion requests, and breach reports to the address below. dev@hubb1e.com