Our Terms of Service and Privacy Policy are changing on September 29, 2026. New Terms · New Privacy Policy

이용약관 및 개인정보 처리방침2026년 9월 29일부터 변경됩니다. 새 이용약관 · 새 개인정보 처리방침

This version takes effect on September 29, 2026. Until then the current version applies. Privacy Policy (1.0)

AkasicDB Cloud Privacy Policy

Effective Date: September 29, 2026

Last Updated: September 17, 2026

GraphAI Co., Ltd. (the "Company") complies with the Personal Information Protection Act of Korea ("PIPA"), related statutes, and the guidelines issued by the Personal Information Protection Commission and other authorities, and processes personal information lawfully and manages it securely in order to protect the freedoms and rights of data subjects. In accordance with Article 30 of PIPA, the Company establishes and publishes this Privacy Policy (this "Policy") to inform data subjects of the procedures and standards for processing and protecting personal information and to handle related grievances promptly and smoothly. This Policy applies to the AkasicDB Cloud service provided by the Company (the "Service").

This English version is provided for convenience. In the event of any inconsistency, the Korean version prevails.


Article 1 (Purposes of Processing Personal Information)

The Company collects personal information for the purposes set out below, including verifying the identity of users and their intent to use the Service and providing optimized, personalized services. The Company does not use personal information for any purpose other than the purposes for which it was collected, nor does it provide personal information to third parties without the user's consent, and it collects and uses only the minimum personal information necessary to provide the Service in accordance with PIPA. If a purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.

  1. Membership registration and management — Confirming intent to register, identifying and authenticating members for membership-based services, maintaining and managing membership status, preventing misuse of the Service, delivering notices, and handling grievances
  2. Service provision — Creating, operating, stopping, and deleting AkasicDB trial instances; providing SQL query functionality; issuing connection information and credentials
  3. New service development and use for marketing/advertising — Developing new services (products) and providing tailored services, displaying advertisements based on statistical characteristics, verifying service effectiveness, and compiling statistics on access frequency or members' use of the Service
  4. Grievance handling — Verifying the identity of complainants, confirming complaints, contacting/notifying for fact-finding, and communicating outcomes
  5. Compliance with legal obligations — Fulfilling obligations under applicable laws and retaining records for dispute resolution

Article 2 (Personal Information Items Processed)

2.1 Items Collected at Registration

CategoryItemsLegal Basis
RequiredEmail address, password (stored encrypted), name, company nameData subject's consent (PIPA Art. 15(1)(1))
OptionalJob title/role, intended use, referral source (how you heard about us)Data subject's consent

2.2 Registration via Social Login (OAuth)

If you register with a GitHub or Google account, the Company collects the following information from that provider. The Company receives only the information within the scope to which the data subject has consented in advance.

2.3 Items Automatically Generated or Collected During Use of the Service

2.4 Sensitive Information and Unique Identification Information

The Company does not collect sensitive information under Article 23 of PIPA (ideology, beliefs, trade union or political party membership, political opinions, health, sexual life, etc.) or unique identification information under Article 24 of PIPA (resident registration number, passport number, driver's license number, alien registration number).

2.5 New Service Development and Use for Marketing/Advertising

The Company processes the following personal information with the consent of the data subject.

Legal BasisCategoryPurposeItemsRetention Period
PIPA Art. 15(1) (data subject's consent)New service development, marketingSending advertising information by email, such as new features, events, and promotions of the Company's services(Optional) Email addressDestroyed upon withdrawal of consent or membership cancellation

Article 3 (Processing and Retention Period of Personal Information)

  1. The Company processes and retains personal information within the retention and use period prescribed by PIPA and other applicable laws, the period set out in this Policy, or the period to which the data subject consented at the time of collection.
PurposeRetention PeriodBasis
Membership registration and managementUntil membership cancellationData subject's consent
Records of misuse1 year after cancellationPrevention of misuse and dispute response
Computer communications and internet log records, access tracking data3 monthsEnforcement Decree of the Protection of Communications Secrets Act, Art. 41(2)(2)
Records on labeling and advertising6 monthsEnforcement Decree of the E-Commerce Act, Art. 6(1)(1)
Records on contracts or withdrawal of subscription5 yearsEnforcement Decree of the E-Commerce Act, Art. 6(1)(2)
Records on payment and supply of goods, etc.5 yearsEnforcement Decree of the E-Commerce Act, Art. 6(1)(3)
Records on consumer complaints or dispute resolution3 yearsEnforcement Decree of the E-Commerce Act, Art. 6(1)(4)
  1. The processing and retention period for each purpose and item is as set out in the table above. However, in the following cases, personal information is retained until the relevant cause ceases:
    • Where an investigation or inquiry into a violation of applicable law is in progress, until the conclusion of that investigation or inquiry
    • Where claims or obligations arising from use of the Service remain outstanding, until those claims or obligations are settled

Article 4 (Provision of Personal Information to Third Parties)

The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only to the minimum extent necessary and only where permitted under Articles 17 and 18 of PIPA, such as with the prior consent of the data subject or under specific provisions of law. Otherwise, the Company does not provide personal information to third parties.

The Company does not currently provide personal information to any third party on a regular basis. Should third-party provision become necessary in the future, the Company will amend this Policy in advance and obtain separate consent from data subjects.


Article 5 (Outsourcing of Personal Information Processing)

To ensure smooth processing of personal information, the Company outsources personal information processing as follows.

ProcessorOutsourced WorkBasis
Amazon Web Services, Inc. (AWS)Cloud infrastructure operation (EC2, EBS, S3, SES, etc.), provision of data storage and processing environmentData subject's consent
GitHub, Inc.Social login (OAuth) identity verificationData subject's consent
Google LLCSocial login (OAuth) identity verificationData subject's consent

When entering into outsourcing agreements, the Company specifies in the contract or other documents, in accordance with Article 26 of PIPA, the prohibition on processing personal information beyond the outsourced purpose, technical and administrative safeguards, restrictions on sub-outsourcing, management and supervision of the processor, and liability for damages, and supervises whether the processor handles personal information securely.

In accordance with Article 26(6) of PIPA, where a processor sub-outsources the Company's personal information processing work, the Company's consent is obtained, and the sub-processor and the sub-outsourced work are disclosed through this Policy.


Article 6 (Cross-Border Transfer of Personal Information)

The Company outsources the processing of, or stores, personal information overseas as follows.

RecipientCountryTiming and MethodItemsPurposeRetention Period
Amazon Web Services, Inc. (Contact: aws-korea-privacy@amazon.com)United States, Republic of Korea (Seoul Region), etc.Transmitted over the network at the time of Service useAll items listed in Article 2Cloud infrastructure operationUntil termination of the outsourcing agreement or membership cancellation
GitHub, Inc. (Contact: privacy@github.com)United StatesAPI call at the time of OAuth authenticationEmail, username, profile informationSocial login identity verificationPeriod necessary for authentication processing
Google LLC (Contact: googlekrsupport@google.com)United States, etc.API call at the time of OAuth authenticationEmail, display name, profile image URLSocial login identity verificationPeriod necessary for authentication processing

In accordance with Article 28-8 of PIPA, the Company notifies data subjects in advance of cross-border transfers of personal information and obtains their consent. A data subject may refuse consent by not selecting the cross-border transfer consent item during registration; in that case, registration and login through the relevant OAuth provider may be restricted, and the data subject must register and log in directly using an email address. Even after registration, a data subject may withdraw consent to cross-border transfer by contacting the Privacy Officer (privacy@graphai.io), in which case the Company will cease the cross-border transfer of the relevant personal information without delay. However, due to the nature of the Service infrastructure (AWS), withdrawal of consent to cross-border transfer may result in restrictions on use of the Service.


Article 7 (Destruction of Personal Information)

The Company destroys personal information without delay when it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.

7.1 Destruction Procedure

Information entered by data subjects is, after the purpose has been achieved, transferred to a separate database (DB) or file (or a separate document, in the case of paper) and either stored for a certain period in accordance with internal policies and applicable laws or destroyed immediately. Personal information transferred to a separate DB is not used for any other purpose except as required by law.

7.2 Destruction Method

7.3 Handling upon Membership Cancellation

When a member cancels their membership, the Company destroys the member's personal information immediately or after the retention period set out in this Policy has elapsed. However, information subject to statutory retention obligations under the table in Article 3 is stored separately for the applicable period and then destroyed.


Article 8 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)

8.1 Rights of Data Subjects

Data subjects may exercise the following rights against the Company at any time:

  1. Request access to personal information
  2. Request correction of errors
  3. Request deletion
  4. Request suspension of processing
  5. Request transfer (portability) of personal information (to the extent implemented under Article 35-2 of PIPA)
  6. Refuse, or request an explanation of, automated decisions (Article 37-2 of PIPA)

8.2 How to Exercise Rights

Rights may be exercised by email (privacy@graphai.io), in writing, or by electronic mail, and the Company will take action without delay (within 10 days of receipt).

Where a data subject requests correction or deletion of errors in their personal information, the Company will not use or provide that personal information until the correction or deletion is completed.

8.3 Exercise through a Representative

Rights may be exercised through a representative, such as the data subject's legal representative or an authorized agent. In this case, a power of attorney in the form prescribed by Annex Form No. 11 of the Notification on the Methods of Processing Personal Information must be submitted.

8.4 Limitations

The exercise of data subjects' rights may be limited under Articles 35(4) and 37(2) of PIPA.


Article 9 (Measures to Ensure the Security of Personal Information)

In accordance with Article 29 of PIPA, the Company takes the following security measures:

  1. Administrative measures
    • Establishment and implementation of an internal management plan
    • Minimizing the number of staff handling personal information and providing regular training
  2. Technical measures
    • Managing access rights to personal information processing systems
    • Installing access control systems and storing passwords in encrypted form
    • Encrypting personal information in transit (HTTPS/TLS) and at rest
    • Installing security software and performing regular updates and inspections
    • Retaining security logs and access records
  3. Physical measures
    • Controlling access to server rooms, data storage rooms, etc.
    • Leveraging the data center security controls of the cloud infrastructure provider (AWS)

Article 10 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

10.1 Purpose of Cookies

To provide personalized services to data subjects, the Company uses "cookies" and similar technologies that store and retrieve usage information. Cookies are used for the following purposes:

10.2 Installation, Operation, and Refusal of Cookies

Data subjects may allow or block cookies through their web browser settings. However, blocking required cookies may restrict use of some parts of the Service, such as login. Optional cookies such as usage analytics are used only where the data subject has separately consented, and data subjects may withdraw their consent at any time through the cookie settings within the Service or by contacting privacy@graphai.io.


Article 11 (Privacy Officer)

The Company designates the following Privacy Officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.

▶ Privacy Officer

▶ Privacy Department

Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from use of the Service to the Privacy Officer and the Privacy Department. The Company will respond to and handle data subjects' inquiries without delay.


Article 12 (Remedies for Infringement of Rights)

To obtain relief from infringement of personal information, data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the KISA Personal Information Infringement Report Center, and other bodies. For other reports or consultations regarding personal information infringement, please contact the following organizations:

OrganizationPhoneWebsite
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Personal Information Infringement Report Center118 (no area code)privacy.kisa.or.kr
Supreme Prosecutors' Office, Cyber Investigation Division1301 (no area code)www.spo.go.kr
Korean National Police Agency, Cyber Bureau182 (no area code)ecrm.police.go.kr

Article 13 (Changes to this Privacy Policy)

This Policy applies from its effective date. Where there are additions, deletions, or corrections to its contents under applicable law or Company policy, the Company will provide notice through the in-Service announcements or by email at least 7 days before the change takes effect (or at least 30 days in advance for changes that materially affect data subjects' rights).

This Privacy Policy applies from September 29, 2026. Previous versions are available below.

VersionEffective DateSummary of Changes
1.0 (Draft)2026-05-22Initial version
1.12026-09-29Reflected product name (AkasicDB Cloud), added contact details for cross-border transfer recipients, revised marketing collection items, aligned effective dates

Contact: privacy@graphai.io

Version history