풀롱(Pullong) 개인정보처리방침
시행일: 2026년 9월 24일
풀롱(Pullong, 이하 “서비스”)은 대화(채널/스레드), 이슈(칸반보드), 문서(실시간 위키)를 통합 제공하는 올인원 워크스페이스 서비스로서, 이용자의 개인정보를 소중히 보호하며 아래와 같이 투명하게 처리합니다.
1. 수집·처리하는 개인정보
- 회원가입 및 계정 관리: 이메일 주소, 암호화된 비밀번호(BCrypt/Argon2 해시), 표시 이름(프로필명), 프로필 이미지 URL(선택).
- 워크스페이스 및 협업 데이터: 이용자가 직접 작성한 워크스페이스 정보, 채널 메시지, 이슈/태스크 카드, 문서 페이지 블록 및 첨부 링크.
- 서비스 접속 및 기기 로그: 접속 일시, IP 주소, 브라우저/기기 환경 정보(안정적인 실시간 SignalR 웹소켓 연결 유지 및 보안 목적).
2. 개인정보 이용 목적
- 워크스페이스 멤버십 관리 및 권한(RBAC) 제어.
- 실시간 채널 메시지 전송, 칸반 드래그 앤 드롭 정렬 동기화, 실시간 문서 협업 동기화.
- 멘션(@), 태스크 할당, 댓글 반응에 따른 인앱/푸시 알림 제공.
- 비정상적인 접근 차단 및 서비스 보안 강화.
3. 제3자 제공 및 처리위탁
- 풀롱은 이용자의 동의 없이 개인정보를 외부에 판매하거나 무단 제공하지 않습니다.
- Cloudflare Inc.: 안전한 HTTPS 암호화 통신, DDoS 방어 및 글로벌 엣지 네트워크 가속.
4. 개인정보의 보관 및 파기
- 이용자의 개인정보와 작성 데이터는 회원 탈퇴 또는 워크스페이스 삭제 요청 시 지체 없이 복구 불가능한 방법으로 영구 파기됩니다.
- 관계 법령에 따라 보존 의무가 있는 경우(접속 기록 등) 법정 기간 동안만 안전하게 분리 보관 후 파기합니다.
5. 이용자의 권리 및 행사 방법
- 이용자는 언제든지 본인의 프로필 정보를 열람·수정하거나 회원 탈퇴(계정 및 작성 데이터 삭제)를 요청할 수 있습니다.
- 워크스페이스 관리자는 워크스페이스 내 프로젝트, 채널, 문서의 삭제 및 내보내기 권리를 행사할 수 있습니다.
6. 개인정보의 안전성 확보 조치
- 모든 통신은 TLS/HTTPS 1.3 암호화 프로토콜을 적용합니다.
- 비밀번호는 복호화가 불가능한 단방향 솔트 해싱 방식으로 안전하게 저장됩니다.
- JWT 인증 토큰 기반의 무상태 세션 관리 및 엄격한 워크스페이스 권한 검증을 수행합니다.
7. 문의처
8. 방침의 변경
- 본 개인정보처리방침이 변경되는 경우 개정 최소 7일 전 본 페이지를 통해 사전 공지합니다.
Pullong Privacy Policy
Effective Date: September 24, 2026
Pullong (“Service”) is an all-in-one workspace uniting chat channels, kanban issue tracking, and real-time wiki documents. We are deeply committed to protecting your privacy and handling personal data with utmost transparency.
1. Information We Collect
- Account Credentials: Email address, securely salted/hashed passwords, display name, and optional avatar image URL.
- Workspace & Collaboration Content: Workspace structures, channel messages, issue cards, wiki document blocks, and interconnected entity links created by users.
- Connection & Diagnostic Data: Timestamp, IP address, device/browser metadata (used strictly for secure SignalR WebSocket connections and service integrity).
2. Purpose of Processing
- Managing workspace membership, roles, and access controls (RBAC).
- Synchronizing real-time channel messages, kanban drag-and-drop ranks, and debounced wiki block updates.
- Delivering instant in-app notifications for @mentions, task assignments, and thread replies.
- Preventing unauthorized intrusions and guaranteeing platform security.
3. Third-Party Sharing & Processors
- We do not sell, rent, or trade your personal data to any third parties.
- Cloudflare Inc.: Global edge CDN, DDoS mitigation, and end-to-end HTTPS encryption.
4. Data Retention & Deletion
- Your personal information and workspace data are permanently purged upon account termination or workspace deletion.
- Legal compliance records (e.g., access logs) are stored strictly for the legally mandated period and permanently deleted thereafter.
5. User Rights
- Users may view, edit, or request complete deletion of their account and associated data at any time.
- Workspace owners retain full authority to export or delete channels, boards, and pages.
6. Security Measures
- All data in transit is encrypted using modern TLS/HTTPS protocols.
- Passwords are stored using irreversible one-way cryptographic hashing.
- Access is strictly secured via signed JWT tokens with multi-tenant workspace isolation.
7. Contact Us
8. Policy Amendments
- Any revisions to this policy will be announced on this page prior to taking effect.