← FaceMatch AI 홈으로

개인정보처리방침 / Privacy Policy — FaceMatch AI 매칭 서비스

문서 버전: 2025-07-15 (코드의 MatchingConsentStore.currentPolicyVersion 와 반드시 일치시킬 것. 방침 변경 시 버전을 올리고 재동의를 받아야 함.)

⚠️ 이 문서는 개발자가 서비스에 맞게 채워 넣기 위한 초안 템플릿입니다. 실제 배포 전 반드시 개인정보 보호 전문 변호사의 검토를 받으세요. 특히 회사명·연락처·서버 위치·보관기간·수탁사는 실제 값으로 교체해야 합니다.


0. 왜 이렇게까지 하는가 (근거 요약)

얼굴 사진에서 생성한 특징정보(embedding)는 각국에서 가장 강하게 규제되는 데이터입니다.

우리 서비스의 동의 화면(matching_consent_screen.dart)은 위 요건을 만족하도록 ①항목별 분리 동의 ②사전 체크 없음(모두 기본 해제) ③목적·보관·파기·철회 고지 ④만 14세 미만 차단 ⑤본인 얼굴만 등록을 구현합니다.


1. 처리 목적 (Purpose)

2. 처리하는 개인정보 항목 (Items)

3. 수집 방법 및 동의 (Collection & Consent)

4. 보유·이용 기간 및 파기 (Retention & Destruction) — BIPA/GDPR 필수

5. 제3자 제공 (Third-party sharing)

6. 처리 위탁 및 국외 이전 (Processors & Cross-border transfer)

7. 정보주체(이용자)의 권리 (Your rights)

8. 만 14세 미만 아동 (Under 14 / Children)

9. 안전성 확보 조치 (Security)

10. 개인정보 보호책임자 및 연락처 (Contact)


글로벌 체크리스트 (개발/운영자용)

항목 KR(PIPA) EU(GDPR) US(BIPA) 앱 반영 여부
분리된 별도/명시적 동의 ✅(서면) ✅ 화면 구현
사전 체크 금지 권장 ✅ 필수 ✅ 기본 해제
목적·보관기간·파기 고지 ✅ 필수 ✅ 화면+방침
만 14세 미만 차단 연령 상향 필요 ✅ 확인 항목
동의 철회·삭제권 ✅ revoke()
생체정보 판매 금지 ✅ 방침 명시
DPIA(영향평가) 권장 ⛔ 서버측 별도
국외이전 근거(SCC 등) ⛔ 서버측 별도
동의 기록 서버 저장(입증) ⛔ 백엔드 필요

⛔ 표시는 백엔드/운영 단계에서 별도로 갖춰야 하는 것으로, 앱 클라이언트만으로는 완결되지 않습니다.

---

Privacy Policy (English) — FaceMatch AI Matching Service

Document version: 2025-07-15 (Must always match MatchingConsentStore.currentPolicyVersion in code. Bump the version and re-collect consent whenever this policy changes.)

⚠️ This is a draft template for the developer to fill in with real values. Have it reviewed by qualified privacy counsel before launch. In particular, replace the company name, contact details, server locations, retention periods, and processors with real values.

0. Why this matters

Features (embeddings) generated from a face photo are among the most heavily regulated data categories worldwide.

Our consent screen (matching_consent_screen.dart) is built to satisfy the above via: ① itemized separate consent ② no pre-checked boxes (all default off) ③ disclosure of purpose/retention/destruction/withdrawal ④ blocking under-14 signup ⑤ requiring the enrolled photo to be the user's own face.

1. Purpose

2. Data we process

3. Collection & consent

4. Retention & destruction — required under BIPA/GDPR

5. Third-party sharing

6. Processors & cross-border transfer

7. Your rights

8. Users under 14 / children

9. Security measures

10. Data protection contact


Global compliance checklist (for developers/operators)

Item KR (PIPA) EU (GDPR) US (BIPA) Reflected in app
Separate / explicit consent ✅ (written) ✅ Screen implemented
No pre-ticked boxes Recommended ✅ Required ✅ Off by default
Purpose/retention/destruction disclosure ✅ Required ✅ Screen + policy
Block under-14 signup Raise min. age ✅ Confirmation item
Withdrawal & deletion rights ✅ revoke()
No sale of biometric data ✅ Stated in policy
DPIA Recommended ⛔ Separate, server-side
Cross-border transfer basis (SCCs, etc.) ⛔ Separate, server-side
Server-side proof of consent record ⛔ Backend required

⛔ marks items that must be handled separately at the backend/operations level — the app client alone cannot complete them.