AkasicDB Playground Privacy Policy

The Korean version is the controlling text for regulatory compliance purposes; this English version is provided for the convenience of non-Korean speakers.

Effective date: May 22, 2026 (draft)

GraphAI, Co., Ltd. ("GraphAI", "we", "us") complies with the Personal Information Protection Act and related laws and regulations of the Republic of Korea, and is committed to protecting the personal information and rights of data subjects. This Privacy Policy (the "Policy") explains how we collect, use, store, and disclose personal information in connection with the AkasicDB Playground service (the "Service").


1. Purposes of Processing

We process personal information for the following purposes only. Personal information will not be used for any purpose other than those listed below; if the purpose of processing changes, we will obtain separate consent or take other measures required by PIPA Article 18.

  1. Account registration and management — verifying intent to register, identifying and authenticating users, maintaining accounts, preventing fraudulent use, sending notices, and handling grievances.
  2. Provision of the Service — creating, operating, stopping, and deleting AkasicDB trial instances; providing SQL query functionality; issuing access credentials.
  3. Product improvement and marketing — developing new features and tailored services; serving demographic-based notices; measuring service effectiveness and usage statistics.
  4. Grievance handling — verifying complainant identity, confirming complaint details, contacting complainants for fact-finding, and notifying them of outcomes.
  5. Legal compliance — fulfilling obligations under applicable laws and retaining records for the resolution of disputes.

2. Categories of Personal Information Processed

2.1 Collected at sign-up

TypeItemsLegal basis
RequiredEmail address, password (stored hashed), full name, companyConsent of the data subject (PIPA §15(1)(1))
OptionalJob role, intended use case, how the user heard about the ServiceConsent of the data subject

2.2 Collected via social sign-in (OAuth)

When you sign in with GitHub or Google, we receive the following items from the identity provider, limited to the scopes you authorize.

2.3 Automatically generated or collected during use

2.4 Sensitive information and unique identifiers

We do not collect "sensitive information" under PIPA Article 23 (ideology, beliefs, union or political-party affiliation, political opinions, health, sex life, etc.) or "unique identifiers" under PIPA Article 24 (resident registration number, passport number, driver's license number, foreigner registration number).


3. Retention and Use Periods

We retain personal information for the period agreed to by the data subject or required by law, whichever applies.

PurposeRetention periodBasis
Account registration and managementUntil account deletionData subject consent
Records of fraudulent use1 year after account deletionFraud prevention and dispute response
Service usage logs, access logs, IP addresses3 monthsEnforcement Decree of the Protection of Communications Secrets Act §41
Records concerning advertising and labeling6 monthsAct on the Consumer Protection in Electronic Commerce §6
Records of contracts or withdrawal of subscriptions5 yearsAct on the Consumer Protection in Electronic Commerce §6
Records of consumer complaints or dispute resolution3 yearsAct on the Consumer Protection in Electronic Commerce §6

4. Provision of Personal Information to Third Parties

We process personal information only within the scope of the purposes stated in Section 1, and provide personal information to third parties only with the data subject's prior consent or where specifically permitted by law under PIPA Articles 17 and 18.

At present, we do not routinely provide personal information to any third party. If third-party provision becomes necessary in the future, we will amend this Policy in advance and obtain separate consent from data subjects.


5. Outsourcing of Personal Information Processing

We outsource the following personal information processing activities for the efficient operation of the Service.

ProcessorOutsourced activitiesBasis
Amazon Web Services, Inc. (AWS)Cloud infrastructure operation (EC2, EBS, S3, SES, etc.); data storage and processing environmentData subject consent
GitHub, Inc.Identity verification via OAuth social sign-inData subject consent
Google LLCIdentity verification via OAuth social sign-inData subject consent

In accordance with PIPA Article 26, our outsourcing agreements specify in writing the prohibition of processing for purposes other than the outsourced work, technical and administrative safeguards, restrictions on sub-outsourcing, supervision of processors, and liability for damages. We supervise processors to ensure that personal information is handled securely.


6. Cross-Border Transfer of Personal Information

We transfer or store personal information outside the Republic of Korea as follows.

RecipientCountryTime and method of transferItems transferredPurposeRetention/use period
Amazon Web Services, Inc.United States, Republic of Korea (Seoul region), and othersTransmitted over the network when the Service is usedAll items listed in Section 2Cloud infrastructure operationUntil the outsourcing contract ends or the account is deleted
GitHub, Inc.United StatesAPI calls at the time of OAuth authenticationEmail, username, profile informationOAuth identity verificationDuration necessary for authentication
Google LLCUnited States and othersAPI calls at the time of OAuth authenticationEmail, display name, profile image URLOAuth identity verificationDuration necessary for authentication

In accordance with PIPA Article 28-8, we provide prior notice of cross-border transfers and obtain consent from data subjects. Data subjects may refuse consent; in that case, sign-up via the relevant OAuth provider may be unavailable.


7. Destruction of Personal Information

When personal information becomes unnecessary because the retention period has elapsed or the purpose of processing has been achieved, we destroy it without delay.

7.1 Procedure

Information provided by the data subject is, after the purpose has been achieved, moved to a separate database or file (or to separate paper documents) and either stored for a defined period pursuant to internal policy and applicable law, or destroyed immediately. Information moved to a separate database is not used for any purpose other than as required by law.

7.2 Method

7.3 On account deletion

When a member withdraws, we destroy personal information either immediately or after the retention period specified in this Policy. Information for which retention is required by law (per the table in Section 3) is stored separately for the prescribed period and then destroyed.


8. Rights of Data Subjects and How to Exercise Them

8.1 Rights

Data subjects may exercise the following rights against us at any time:

  1. Right to request access to personal information.
  2. Right to request correction in case of errors.
  3. Right to request deletion.
  4. Right to request suspension of processing.
  5. Right to data portability (within the scope provided by PIPA Article 35-2).
  6. Right to refuse, or request an explanation of, automated decisions (PIPA Article 37-2).

8.2 How to exercise

Rights may be exercised by email (privacy@graphai.io), written notice, or electronic communication. We will respond and take action without delay (within 10 days of receipt).

If a data subject requests correction or deletion of personal information that contains errors, we will not use or provide the personal information until the correction or deletion is complete.

8.3 Through a representative

Rights may be exercised through a statutory representative or a duly authorized agent. In such cases, a power of attorney conforming to Form No. 11 of the Enforcement Rules of PIPA must be submitted.

8.4 Limitations

Rights of data subjects may be limited under PIPA Article 35(4) and Article 37(2).


9. Security Measures

In accordance with PIPA Article 29, we implement the following safeguards:

  1. Administrative measures — internal management plans; minimization and regular training of personnel handling personal information.
  2. Technical measures — access-control management for systems processing personal information; access-control systems and password hashing (e.g., bcrypt one-way hashes); encryption of personal information in transit (HTTPS/TLS) and at rest; installation and regular updates of security software; retention of security and access logs.
  3. Physical measures — access control for server rooms and document storage areas; reliance on the security controls of our cloud infrastructure provider (AWS).

10. Cookies and Similar Technologies

10.1 Purposes

We use cookies and similar technologies for the following purposes:

10.2 How to opt out

You can configure cookie acceptance and blocking in your browser settings. Blocking required cookies may prevent you from logging in or using parts of the Service.


11. Data Protection Officer

We have designated a Data Protection Officer ("DPO") who is responsible for overseeing personal information processing and for handling complaints and remedies from data subjects.

▶ Data Protection Officer

▶ Data Protection Department

Data subjects may direct any inquiry, complaint, or remedy request related to personal information arising from the use of the Service to the DPO or the responsible department. We will respond without delay.


12. Remedies for Infringement of Rights

Data subjects may apply to the following Korean authorities for dispute resolution, consultation, or remedy in connection with personal information infringement:

AuthorityTelephoneWebsite
Personal Information Dispute Mediation Committee1833-6972www.kopico.go.kr
Personal Information Infringement Report Center (KISA)118privacy.kisa.or.kr
Cyber Investigation Division, Supreme Prosecutors' Office1301www.spo.go.kr
Cyber Bureau, Korean National Police Agency182ecrm.police.go.kr

A person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to a request under PIPA Articles 35 (access), 36 (correction/deletion), or 37 (suspension of processing) may file an administrative appeal under the Administrative Appeals Act.


13. Changes to this Policy

This Policy applies from its effective date. Any addition, deletion, or correction in response to changes in laws or our practices will be announced through the in-service notice board or by email at least 7 days before the change takes effect (30 days in the case of changes that materially affect the rights of data subjects).

VersionEffective dateSummary
1.0 (draft)2026-05-22Initial draft

Contact: privacy@graphai.io