fastovia Privacy Policy

패스토비아(FASTOVIA)protects business clients' contact persons' personal information under applicable law.
Ad measurement notice updated: October 6, 2026
Business details updated: October 4, 2026
Changes: information processed and cookies used by automatic advertising measurement on public pages. Previously saved measurement rejections are retained.

1. Purposes2. Information processed3. Collection methods4. Retention5. Destruction6. Rights7. Security measures8. Cookies & automatic collection9. External processing

1. Purposes of processing

Information is processed for registration and sign-in, company and contact management, quote requests, consultation and quotes, contracts and regulatory projects, document review and follow-up requests, inquiries and disputes, security, incident response, abuse prevention and password resets. Any future AI review support is subject to the separate conditions below.

2. Personal information processed

We may process company and contact names, email, phone, account identifiers, secure password hashes, business certificates, quote and contract information, project and inquiry history, access records, IP addresses, browser and device details, and personal information in uploaded files. Plain-text passwords, FDA Direct passwords and API keys are not stored in ordinary personal-information fields or exposed in public responses.

3. Collection methods

Information is collected through registration, quote requests, inquiries, document uploads, automatically generated security records, separate contracts and email consultations.

4. Retention

TypeCurrent retention principles
Account informationUntil account closure or fulfillment of the purpose. Items needed for contracts, disputes or legal retention are kept separately and destroyed when no longer required.
Quote requestRetained until the quote process ends or converts to a contract, and thereafter as needed for contractual matters or disputes.
Contracts, projects, cancelled projects & uploaded documentsRetained as needed for contract performance, regulatory records, client requests and disputes. Cancellation alone does not immediately delete these records.
InquiryRetained until consultation, follow-up and dispute-resolution purposes are fulfilled.
Access, security & audit logsRetained with restricted access as needed for security incidents and verification of work integrity.

We do not publish arbitrary fixed periods that have not been approved. Once specific retention periods and automatic destruction schedules are approved, this policy and actual D1, R2 and backup destruction policies will be updated together.

5. Destruction of personal information

When retention is no longer necessary, D1 data is deleted or irreversibly anonymized and R2 files are deleted. Legally retained materials are separated and access is restricted. Backup deletion schedules are not yet finalized, and automatic destruction is not currently enabled. Once schedules are approved, deletion, anonymization and R2 deletion results will be recorded without sensitive source content.

6. Your rights

Contact persons may request access, correction, deletion, restriction of processing, withdrawal of consent or account closure. We verify identity or authorized representation and explain the outcome. Requests may be sent to [email protected]. Where legal retention duties or protection of other rights require a restriction, we explain the reason.

7. Security measures

Safeguards include least-privilege and role-based access, TLS, encryption of important stored information, password hashes, masking, Worker Secrets for API keys and credentials, access and audit logs, staff permission changes and prompt revocation, download authorization checks, client-tenant separation and periodic security reviews.

8. Cookies & automatic collection

Sign-in sessions use authentication tokens and displayed user information stored in the browser's localStorage or sessionStorage. The server stores token hashes and expiry times. Request times, hashed IP addresses or limited access information, and browser information may be processed for security and troubleshooting. OpenAI's ChatGPT Ads measurement pixel runs automatically on the public home, services, quote-request and privacy pages. No separate ad measurement choice panel is displayed. Previous measurement rejections saved in this browser are retained. After a quote request is accepted, we send a lead event and a receipt identifier to prevent duplicate counting. Quote contents, company names and attachments are not added directly to the event.

The pixel processes ad click identifiers (oppref), browser identifiers, website origin and event timestamps. When automatic advanced matching is enabled, contact information detected in forms may be transformed into SHA-256 hashes in the browser and sent to OpenAI. Hashing does not guarantee anonymity and is not encryption of the original text.

Measurement cookies are __oppref (30 days after writing) and __obref (365 days after creation); browser settings may remove them earlier. Duplicate-prevention receipts are stored in the tab's sessionStorage. Previous measurement rejections remain effective while stored in the browser. Browser settings can manage cookies and site data or enable tracking protection. Clearing browser data does not delete records already sent. Quote requests remain available when measurement is blocked.

Your language preference is saved in your browser's localStorage and can be reset by clearing site data. On a first visit without a saved preference, we use the country information Cloudflare provides with the web request: Korean for South Korea and English for other or unknown countries. The detected language is stored in sessionStorage for that browser session. This language feature does not separately store or return your IP address or country to the browser, and does not send customer materials to a translation service. A VPN or proxy may affect the default language; you can change it using the language controls at the top.

9. External services & processors

ServiceActual useProcessing & storage
Cloudflare (Pages, Workers, D1, R2)Website delivery, APIs, database and uploaded-file storage, securityProcesses web requests, account and project information and uploaded materials. The contracting entity, processing countries, retention periods and subprocessors are to be confirmed against the account contract, DPA and deployment settings.
OpenAI ChatGPT AdsAutomatic ad measurement on public pagesProcesses ad and browser identifiers, completed quote-request events, origin and timestamps, and hashed contact information when automatic advanced matching is enabled. See Section 8 for measurement cookie lifetimes and browser storage management.
ResendCurrently used for password-reset emailsProcesses recipient email addresses and one-time reset links. It is not used to send quotes or contracts automatically. The contracting entity, processing countries, retention periods and subprocessors are to be confirmed against the account contract and DPA.
Future organizational AI servicesPlanned support for text recognition and regulatory review of product materialsRequired notices, consents and separate procedures must be completed after organizational accounts and actual processing conditions are confirmed. This does not mean a particular plan or automated API analysis is in operation. Personal AI accounts are not used for client materials.

We do not currently request consent for AI analysis during registration or quote requests. If AI analysis is introduced, we will explain the actual processing conditions and complete any required separate procedures. Earlier consents are retained with their original scope and do not automatically apply to new providers, purposes or processing. Only necessary materials are used, with unnecessary personal information removed or masked. RA staff compare analysis results with originals; results are not automatically approved, finalized or published to clients. Not collecting AI consent does not mean that existing providers such as Cloudflare perform no processing or international transfers. Questions about consent history or withdrawal may be sent to [email protected].

Data controller & privacy officer

Data controller: 패스토비아(FASTOVIA) · Representative and privacy officer: 김관용 · Business registration number: 494-63-00821
Privacy inquiries [email protected]

View the notice before the measurement panel change · View the notice before ad measurement was added · Previous document before the business update (Korean) · Previous document before the AI intake change (v116, Korean) · Earlier privacy policy (v99, Korean)