Privacy Policy
Effective · 2026-09-04
HUBB1E Inc. ("we") operates Work2 (the "Service"), a work operations workspace. We comply with the Personal Information Protection Act of Korea (PIPA) and publish this policy to protect the personal information of the people who use the Service.
This policy explains what personal information the Service processes and why, how long we keep it, whom we entrust it to or share it with, and how you can exercise your rights.
Work2 is an internal tool for company crew members and for customer or partner contacts the company invites. We do not offer sign-up to the general public.
Article 1. Personal information we process and why
The Service processes the items below. They come from what you enter, what a workspace admin registers, or from external services you choose to connect. We do not process anything not listed here.
- Crew account
- ItemsGoogle Workspace account identifier, email, display name, profile image; or email address with a one-time sign-in link, two-factor (TOTP) secret; workspace membership and rolePurposeIdentity verification, sign-in, access control, workspace assignmentSourceEntered by you at Google or email sign-in
- Access records
- ItemsIP address, browser and device information, sign-in time, security events (failed sign-in, sign-out everywhere)PurposePreventing unauthorized access, investigating incidents, keeping the Service stableSourceGenerated automatically while you use the Service
- HR
- ItemsLegal name, local-script name, date of birth, address, contact details, hire date, title, pay, attendance and leave requests, resident registration number (stored encrypted)PurposePerforming the employment contract; payroll, social insurance, and withholding obligations; issuing employment certificatesSourceEntered by a workspace admin or by you
- Travel
- ItemsPassport number, expiry, nationality, date of birth, flight details, contact details, arrival-card entries (Taiwan TWAC, China CNAC, Japan VJW)PurposeBooking trips, ticketing flights, rail, and bus, filing arrival cards on your behalf, keeping trip recordsSourceEntered by you or a workspace admin
- Customers and partners
- ItemsContact name, email, phone, company, title, business-card image, customer-portal sign-in emailPurposeManaging accounts, collaboration, customer-portal sign-inSourceEntered by crew, business-card upload, or by the contact at portal sign-in
- Finance
- ItemsCorporate bank and card transactions, sales slips, tax invoices, business registration certificate, HomeTax, customs, and bank certificates and access credentials (stored encrypted), transfer payee name and account number, payer date of birth and mobile number at checkoutPurposeSpend management, preparing tax filings, corporate paymentsSourceFinancial and government integrations you configure; entered by you at checkout
- Mail and inbox
- ItemsHeaders, bodies, and attachments of Gmail or Proton mailboxes you connect; mail delivered to the Service's receiving address; Raindrop bookmarks you connectPurposeReading work email, drafting (Gmail), organizing the inboxSourceMail integrations you configure
- AI
- ItemsText and audio you submit to AI features; business-card images you upload; name and email for AI seat assignmentPurposeAI assistance such as summarizing and drafting; managing AI service seatsSourceEntered by you
Resident registration numbers are processed only for labor and tax obligations that statute specifically requires or permits, and are encrypted at rest with a dedicated key. We process no other unique identifiers or sensitive information.
The Service is not directed at children under 14 and we do not knowingly collect their personal information.
Article 2. Retention periods
We destroy personal information without delay once its purpose is fulfilled or one of the events below occurs. Items another statute requires us to keep are stored separately for that period.
- Crew account and access records
- RetentionUntil departure or account deletion. Sign-in sessions renew every 8 hours and require a fresh sign-in 30 days after the first sign-in.
- HR
- RetentionAfter departure, for the statutory period (3 years for employment records under the Labor Standards Act; 5 years for tax records under the Framework Act on National Taxes and Income Tax Act)
- Travel
- RetentionUntil the trip is settled; items that serve as tax evidence for 5 years
- Customers and partners
- RetentionUntil the relationship ends or deletion is requested
- Finance
- RetentionStatutory periods under the Framework Act on National Taxes, Corporate Tax Act, and Commercial Act (5 years for transaction records, 10 years for commercial books)
- Mail, inbox, and AI input
- RetentionUntil you disconnect the integration or delete the item
- Customer-portal session
- Retention8 hours
Article 3. Destruction procedure and method
- Procedure: when a retention period ends or the purpose is fulfilled, the privacy officer confirms and we destroy the data. Items with a statutory retention duty are moved to restricted storage.
- Method: electronic records in the database and object storage are deleted irrecoverably; encrypted items have their encryption keys destroyed with them. Printed copies are shredded.
Article 4. Sharing with third parties
We process your personal information only for the purposes in Article 1 and do not share it with third parties except in these cases:
- To carry out a booking, ticketing, filing, or lookup you request inside the Service, we pass the minimum items to the relevant institution or vendor (see the table in Article 6). For example, passenger details go to the airline for a flight booking, and passport details go to the destination country's immigration authority for an arrival card.
- When you give separate consent.
- When a statute requires it or a law-enforcement agency requests it through lawful procedure.
Article 5. Processors
We entrust the following work to external processors. Contracts include personal-information protection duties and we supervise each processor.
- Kakao Cloud (Kakao Enterprise)
- Entrusted workServer and database hosting (Korea, kr-central-2 region)
- Cloudflare, Inc.
- Entrusted workObject storage for attachments and PDFs (encrypted before upload)
- Functional Software, Inc. (Sentry)
- Entrusted workError monitoring (personal information masked before sending)
- Google LLC
- Entrusted workGoogle Workspace sign-in, Gmail integration, business-card OCR (Gemini model via OpenRouter)
- Resend, Inc.
- Entrusted workSending sign-in links and notification email; receiving mail at the Service's inbound address
- Proton AG
- Entrusted workProton mail integration (when you configure it)
- Slack Technologies, LLC / Telegram FZ-LLC
- Entrusted workOperational notifications (when you configure them)
- Kakao Mobility (Kakao T Business)
- Entrusted workBusiness mobility integration and verification SMS
- GitHub, Inc.
- Entrusted workSyncing tickets and todos to GitHub issues (when you connect a repository to a project)
- Zhipu AI (Z.ai)
- Entrusted workWorkspace default text model: Slack conversation summaries, partner-profile drafts. Only what you submit is sent.
- Anthropic, PBC / OpenAI, LLC / xAI Corp. / OpenRouter, Inc. / Deepgram, Inc.
- Entrusted workAI assistance (text generation, summarization, speech recognition, business-card OCR). Only what you submit is sent over the API, under each provider's API terms.
- Anysphere, Inc. (Cursor) / Volcengine (ByteDance) / Moonshot AI
- Entrusted workAI seat usage lookups (only the registered account email and API key or session token are sent; nothing you submit to AI features)
Article 6. Cross-border transfers
The Service's primary storage is in Korea. Personal information leaves Korea in the cases below. You may refuse a cross-border transfer; refusing disables the related feature (attachment storage, AI assistance, external notifications, overseas bookings and filings). To refuse, contact us under Article 9 or disconnect the integration.
- Cloudflare, Inc. (United States)
- ItemsAttachments and PDFs (encrypted)When and howNetwork transfer at uploadPurpose and retentionFile storage. Until you delete the file or its retention period ends
- Functional Software, Inc. (United States)
- ItemsMasked request details when an error occursWhen and howNetwork transfer at error timePurpose and retentionError analysis. Sentry's event retention period (90 days by default)
- Google LLC (United States) / Resend, Inc. (United States) / Proton AG (Switzerland)
- ItemsAccount email and name; mail in connected mailboxes; mail delivered to the Service's receiving addressWhen and howNetwork transfer at sign-in and when reading, drafting, or receiving mailPurpose and retentionSign-in and mail features. Until you disconnect
- Slack Technologies, LLC (United States) / Telegram FZ-LLC (United Arab Emirates)
- ItemsNames and work details contained in notificationsWhen and howNetwork transfer when a notification is sentPurpose and retentionOperational notifications. Retention under each service's terms
- GitHub, Inc. (United States)
- ItemsTitle, body, and assignee names of tickets and todos synced to GitHub issuesWhen and howNetwork transfer when a project with a connected repository syncsPurpose and retentionIssue-tracking integration. Until deleted from the repository
- Zhipu AI (Z.ai) (China)
- ItemsText submitted to Slack summaries and partner-profile generationWhen and howNetwork transfer when you use those AI featuresPurpose and retentionAI assistance. After the request, each provider's abuse-monitoring window under its API terms
- Anthropic, PBC / OpenAI, LLC / xAI Corp. / OpenRouter, Inc. / Deepgram, Inc. (United States)
- ItemsText, audio, and business-card images you submit to AI featuresWhen and howNetwork transfer when you use an AI featurePurpose and retentionAI assistance. After the request, each provider's abuse-monitoring window under its API terms
- Anysphere, Inc. (Cursor) (United States) / Volcengine / Moonshot AI (China)
- ItemsAccount email and credentials registered for AI seatsWhen and howNetwork transfer at usage lookupsPurpose and retentionAI seat management. Until the seat is removed
- Counterparties of bookings and filings you request: airlines, OTAs (Trip.com, Yeogi), rail (Korail), bus (Kobus, Bustago); Taiwan, China, and Japan immigration authorities; overseas sellers and carriers (Alibaba, JLCPCB, SF Express, FedEx, DHL, USPS, and others)
- ItemsPassenger or applicant name, date of birth, contact details, and passport details; recipient name, address, and contact detailsWhen and howNetwork transfer when you execute the booking, filing, or orderPurpose and retentionFulfilling the requested transaction. Retention set by each institution or vendor
Article 7. Your rights and how to exercise them
You may at any time request access to, correction or deletion of, or suspension of processing of your personal information, and withdraw consent.
- In Settings → Security you can manage two-factor authentication and sign out on every device. In the crew detail panel you can edit your own profile and travel documents.
- Mail, finance, and AI integrations can be disconnected from their own screens at any time; disconnecting deletes the credentials the Service stored for them.
- For anything you cannot do yourself, contact us under Article 9. After verifying your identity we respond within 10 days. Items with a statutory retention duty are access-restricted instead of deleted, and we tell you why.
- A representative acting for you must submit a power of attorney in the form prescribed by the PIPA enforcement rules.
- You are responsible for keeping your own information accurate. When you enter another person's personal information into the Service, you must inform that person of this policy and obtain any required consent.
Article 9. Security measures and privacy officer
- Encryption: resident registration numbers, passport details in crew profiles, financial certificates and credentials, and attachments are stored with AES-256-GCM envelope encryption; data keys are wrapped by a master key. Arrival-card records you file (name, passport number, itinerary) are kept as filed so you can review the submission. All traffic is protected with TLS.
- Access control: data is partitioned per workspace with database row-level security. Access is limited by role (admin, crew, customer), and finance and HR data are visible only to crew with a dedicated permission.
- Authentication: sign-in through a Google Workspace organization account or a one-time email link, with optional two-factor authentication (TOTP). Sessions renew every 8 hours and expire after 30 days.
- Logging and monitoring: sign-in and security events are recorded, and personal information is masked in anything sent to error monitoring.
- Operations: we keep the number of people with access to personal information to a minimum and review permissions regularly. Automated checks keep secrets out of logs.
Privacy officer and responsible team: HUBB1E Inc. engineering team (contact email below). Privacy inquiries, complaints, and requests for remedy are received at this address.
Article 10. Data breach response
If we learn that personal information has been, or may have been, lost, stolen, or leaked, we notify the affected users without delay under Article 34 of PIPA — stating the items involved, when and how it happened, how to minimize harm, what we are doing, and how to reach us — and report to the Personal Information Protection Commission or the Korea Internet & Security Agency when the statutory threshold is met.
Article 11. Remedies
For counseling or to report a privacy violation, you may contact these Korean authorities:
- Personal Information Infringement Report Center (KISA) — privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee — kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office Cyber Investigation — spo.go.kr / 1301
- National Police Agency Cyber Bureau — ecrm.police.go.kr / 182
Article 12. Changes to this policy
This policy applies from the effective date. It is the first edition written to the Personal Information Protection Act format and replaces the earlier English notice. When statute or the Service changes and we add, remove, or amend content thereafter, we announce it inside the Service at least 7 days before it takes effect, and at least 30 days before for changes that materially affect your rights. Earlier versions are available on request.
Contact
Send privacy questions, access, correction, or deletion requests, and breach reports to the address below. dev@hubb1e.com