Medisupporter Privacy Policy
FIRST FLUKE (hereinafter the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (개인정보 보호법) in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
- Effective date: August 31, 2026
- Last amended: August 31, 2026
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes. The personal information processed will not be used for any purpose other than those set out below, and where the purpose of use is changed, the Company will take necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
- Membership registration and management: Confirming intent to register, identifying and authenticating the individual, maintaining and managing membership status, and preventing fraudulent use of the service
- Service provision: Operating the features the Company provides, including inquiry channel connection and inbox operation, appointment intake and management, manual-grounded reply assistance, hospital homepage creation and publication, and AI auto-reply and suggested reply drafting
- Hospital (tenant) operation management: Inviting staff, managing roles, and recording audit history such as access and reply records
- Paid subscription billing: Processing subscription payments, managing payment records, and handling refunds
- Customer support: Receiving and handling inquiries and delivering notices and service change announcements
- Service improvement: Analyzing usage statistics, developing new features, and improving service quality
- Compliance with legal obligations: Retaining electronic commerce records and fulfilling other obligations prescribed by applicable law
Article 2 (Categories of Personal Information Processed)
The Company processes the following categories of personal information.
Mandatory items
- Email address — Member identification, sign-in, and delivery of notices
- Password — Authentication (stored using one-way encryption; the Company does not retain plaintext passwords)
- Name (display name) — Identification of staff within a hospital and recording of reply history
- Hospital profile information (hospital name, contact details, address, consultation hours, and the like) — Consultation operation and hospital homepage publication
- Payment and subscription information (subscription status, payment identifiers) — Paid subscription billing and settlement. Payment instrument details such as card numbers are held by the payment gateway and are not stored by the Company
Items processed only where the member requests a connection
- Inquiry channel connection information (Naver TalkTalk, KakaoTalk Channel, and Instagram account identifiers and connection tokens) — Receiving inquiry messages on, and sending replies through, the channels designated by the hospital. Connection tokens are stored encrypted
The Company processes the above items on the basis of Article 15(1)(4) of the Personal Information Protection Act (performance of a contract), and obtains separate consent to the terms of service and to the collection and use of personal information at the time of registration.
Automatically collected items
IP address, cookies, service usage records, access logs, and device information may be generated and collected automatically in the course of using the service.
Patient personal information entrusted by hospitals
For patients' personal information — consultation messages, names, contact details, dates of birth, and appointment details left by a patient through an inquiry channel or the inquiry form — the personal information controller is each hospital (the member), and the Company is an entrusted processor that processes such information only within the scope of providing the service on the hospital's behalf. Because consultation messages may contain sensitive information such as health-related inquiries, the Company stores message bodies encrypted (AES-GCM), controls access on a role basis, and keeps audit records of access to and copying of patient information. Notifying patients of, and obtaining their consent to, the collection and use of personal information is the responsibility of the hospital as the personal information controller.
Children under the age of 14
The Company does not accept membership registration from children under the age of 14 and confirms at registration that the member is at least 14 years old.
Article 3 (Processing and Retention Periods)
The Company processes and retains personal information within the retention and use period prescribed by law or consented to by the data subject.
| Processing activity | Retention period | Basis |
|---|---|---|
| Membership registration and management | Until withdrawal of membership or of consent | Consent of the data subject |
| Records on contracts and withdrawal of subscription | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on payment and supply of goods | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on consumer complaints or dispute resolution | 3 years | Act on Consumer Protection in Electronic Commerce |
| Service access logs | 3 months | Protection of Communications Secrets Act |
| Audit records of access to and handling of patient information | 1 year after withdrawal of membership | Dispute response and prevention of fraudulent use |
| Inquiry channel connection tokens | Destroyed immediately upon disconnection or withdrawal | Consent of the data subject |
| Patient consultation and appointment information entrusted by a hospital | Until the hospital's instruction or termination of the service agreement | Processing entrustment agreement |
Article 4 (Provision of Personal Information to Third Parties)
The Company processes personal information only within the scope specified in Article 1 and provides personal information to third parties only where Articles 17 and 18 of the Personal Information Protection Act apply, such as with the consent of the data subject or under specific provisions of law. The Company currently does not provide personal information to third parties.
Where a hospital connects an external channel such as Naver TalkTalk, KakaoTalk Channel, or Instagram on its own initiative, the Company accesses that channel on the hospital's instruction to perform the tasks the hospital requested (receiving inquiries and sending replies). This constitutes performance of the hospital's request and is not a discretionary provision of personal information by the Company.
Article 5 (Entrustment of Processing and Overseas Transfers)
The Company's service infrastructure and database are located in a region within the Republic of Korea (Microsoft Azure Korea Central). To provide the service smoothly, however, the Company entrusts part of its personal information processing to overseas providers, and discloses those overseas transfers pursuant to Article 28-8 of the Personal Information Protection Act as follows.
| Entrusted party | Entrusted work | Destination country | Method of transfer | Retention and use period |
|---|---|---|---|---|
| Polar Software Inc. | Processing paid subscription payments and holding payment instruments | United States | Transmission over an information and communications network | Until termination of the entrustment agreement or the retention period required by law |
| Microsoft Corporation (Azure OpenAI Service) | Large language model calls for AI auto-reply and suggested reply drafting | United States and other Azure regions | Transmission over an information and communications network | Immediately upon achievement of the processing purpose |
| Cloudflare, Inc. | Web delivery, CDN, and security | United States and global edge regions | Transmission over an information and communications network | Until termination of the entrustment agreement or achievement of the processing purpose |
In addition, the sending of patient guidance messages such as Kakao AlimTalk and SMS is entrusted to a domestic sending agency.
When entering into an entrustment agreement, the Company specifies in writing the prohibition of processing personal information beyond the purpose of the entrusted work, technical and administrative safeguards, restrictions on sub-entrustment, supervision of the entrusted party, and liability including damages, pursuant to Article 26 of the Personal Information Protection Act, and supervises whether the entrusted party processes personal information safely. Data submitted to AI features is not used to train the models of the entrusted parties.
Article 6 (Procedures and Methods for Destroying Personal Information)
The Company destroys personal information without delay once it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose. Personal information for which grounds for destruction have arisen is destroyed with the approval of the Chief Privacy Officer; information in electronic file form is permanently deleted by a method that makes recovery and reproduction impossible. Inquiry channel connection tokens registered by a hospital are destroyed immediately upon disconnection or withdrawal, and patient consultation and appointment information entrusted by a hospital is destroyed on the hospital's instruction or upon termination of the service agreement. Where personal information must be retained under applicable law, it is moved to a separate database or stored in a different location.
Content published to a hospital homepage can be managed and deleted directly by the hospital (the member) within the service.
Article 7 (Rights and Obligations of Data Subjects and How to Exercise Them)
Data subjects may exercise their rights to access, correct, delete, suspend the processing of, and request the transmission of their personal information at any time. Such rights may be exercised in writing, by email, and by other means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on such requests without delay. Requests concerning a patient's personal information may be directed to the relevant hospital as the personal information controller, and the Company cooperates without delay in accordance with the hospital's instructions.
How to exercise
- Email: hello@firstfluke.com
- Post: 25 Jowon-ro, Gwanak-gu, Seoul, Republic of Korea
- The account settings menu within the service
Right to request transmission of personal information
Data subjects may request that their personal information be transmitted to another personal information controller, and the Company will process legitimate requests within the period prescribed by applicable law.
Article 8 (Installation, Operation, and Refusal of Automatic Collection Devices)
The Company uses cookies and equivalent browser storage to provide the service and to maintain sign-in state. The Company does not issue a language cookie; the language of the interface is determined solely by the URL.
How to refuse
- Chrome: Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions > Manage cookies and site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
Refusing cookie storage may restrict the use of services that require signing in.
Article 9 (Measures to Secure the Safety of Personal Information)
The Company takes the following measures to secure the safety of personal information. Administratively, it establishes and implements an internal management plan, minimizes the number of employees who handle personal information, and conducts regular inspections. Technically, it manages access privileges to the personal information processing system on a role basis, retains access records, applies one-way encryption to passwords, stores consultation message bodies encrypted (AES-GCM), stores inquiry channel connection tokens in encrypted form, and encrypts data in transit (HTTPS/TLS). Access to and copying of patient information is retained as audit records. Physically, access to the systems where data is stored is controlled.
Article 10 (Chief Privacy Officer and Department for Access Requests)
The Company designates a Chief Privacy Officer as set out below to take overall responsibility for personal information processing and to handle complaints and provide remedies for data subjects in relation to personal information processing. Data subjects may direct requests to exercise rights, such as access to personal information, to the contact below.
Chief Privacy Officer
- Name: Kim Gahyun
- Title: Chief Executive Officer (Chief Privacy Officer)
- Email: hello@firstfluke.com
Article 11 (Automated Decisions)
The Company performs automated processing using artificial intelligence (AI) technology in the course of providing the service, as follows.
- Subject of processing: Drafting a first automated response to inquiries received outside consultation hours, and drafting suggested and quick replies for consultation staff
- Basis of processing: The inquiry content left by the patient, the response manuals registered by the hospital, and the response policies configured by the hospital (tone, forbidden topics, and the like)
- Procedure and method: Large language model calls via Microsoft Azure OpenAI Service
- Use as training data: Neither the Company nor its entrusted parties use member or patient data to train AI models
Out-of-hours auto-replies are sent only where the hospital has enabled the feature, and every auto-reply carries a notice that it was generated by AI. Where confidence is low or no basis exists in the response manuals, no auto-reply is sent and the inquiry is routed to staff review. Suggested and quick reply drafts for staff are reference material and reach the patient only after a staff member has reviewed, edited, and sent them. AI-generated content is not a medical diagnosis, prescription, or opinion. Data subjects may request an explanation of the criteria and results of automated processing or request reprocessing with human intervention, by email at hello@firstfluke.com.
Article 12 (Remedies for Infringement of Rights)
Data subjects may apply to the following bodies for dispute resolution or consultation in order to obtain relief from personal information infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
- Cybercrime Investigation Division, Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency Cyber Investigation Bureau: 182 (ecrm.police.go.kr)
Article 13 (Changes to This Privacy Policy)
This Privacy Policy applies from its effective date. Where there are additions, deletions, or corrections arising from changes in law or policy, the Company will give notice through announcements within the service from seven days before the changes take effect.