AkasicDB Cloud Privacy Policy
Effective Date: September 29, 2026
Last Updated: September 17, 2026
GraphAI Co., Ltd. (the "Company") complies with the Personal Information Protection Act of Korea ("PIPA"), related statutes, and the guidelines issued by the Personal Information Protection Commission and other authorities, and processes personal information lawfully and manages it securely in order to protect the freedoms and rights of data subjects. In accordance with Article 30 of PIPA, the Company establishes and publishes this Privacy Policy (this "Policy") to inform data subjects of the procedures and standards for processing and protecting personal information and to handle related grievances promptly and smoothly. This Policy applies to the AkasicDB Cloud service provided by the Company (the "Service").
This English version is provided for convenience. In the event of any inconsistency, the Korean version prevails.
Article 1 (Purposes of Processing Personal Information)
The Company collects personal information for the purposes set out below, including verifying the identity of users and their intent to use the Service and providing optimized, personalized services. The Company does not use personal information for any purpose other than the purposes for which it was collected, nor does it provide personal information to third parties without the user's consent, and it collects and uses only the minimum personal information necessary to provide the Service in accordance with PIPA. If a purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.
- Membership registration and management — Confirming intent to register, identifying and authenticating members for membership-based services, maintaining and managing membership status, preventing misuse of the Service, delivering notices, and handling grievances
- Service provision — Creating, operating, stopping, and deleting AkasicDB trial instances; providing SQL query functionality; issuing connection information and credentials
- New service development and use for marketing/advertising — Developing new services (products) and providing tailored services, displaying advertisements based on statistical characteristics, verifying service effectiveness, and compiling statistics on access frequency or members' use of the Service
- Grievance handling — Verifying the identity of complainants, confirming complaints, contacting/notifying for fact-finding, and communicating outcomes
- Compliance with legal obligations — Fulfilling obligations under applicable laws and retaining records for dispute resolution
Article 2 (Personal Information Items Processed)
2.1 Items Collected at Registration
| Category | Items | Legal Basis |
|---|---|---|
| Required | Email address, password (stored encrypted), name, company name | Data subject's consent (PIPA Art. 15(1)(1)) |
| Optional | Job title/role, intended use, referral source (how you heard about us) | Data subject's consent |
2.2 Registration via Social Login (OAuth)
If you register with a GitHub or Google account, the Company collects the following information from that provider. The Company receives only the information within the scope to which the data subject has consented in advance.
- GitHub: Email address, username (login), display name, profile image URL
- Google: Email address, display name, profile image URL
2.3 Items Automatically Generated or Collected During Use of the Service
- Service usage records, access logs, access IP address, cookies and session tokens
- Instance metadata (creation/start/stop/termination timestamps, assigned ports, etc.)
- Query usage patterns and frequency statistics (the text of individual SQL queries is logged only temporarily where operationally necessary and is not retained in identifiable form after statistical processing)
- Browser type and OS, device identifiers
2.4 Sensitive Information and Unique Identification Information
The Company does not collect sensitive information under Article 23 of PIPA (ideology, beliefs, trade union or political party membership, political opinions, health, sexual life, etc.) or unique identification information under Article 24 of PIPA (resident registration number, passport number, driver's license number, alien registration number).
2.5 New Service Development and Use for Marketing/Advertising
The Company processes the following personal information with the consent of the data subject.
| Legal Basis | Category | Purpose | Items | Retention Period |
|---|---|---|---|---|
| PIPA Art. 15(1) (data subject's consent) | New service development, marketing | Sending advertising information by email, such as new features, events, and promotions of the Company's services | (Optional) Email address | Destroyed upon withdrawal of consent or membership cancellation |
Article 3 (Processing and Retention Period of Personal Information)
- The Company processes and retains personal information within the retention and use period prescribed by PIPA and other applicable laws, the period set out in this Policy, or the period to which the data subject consented at the time of collection.
| Purpose | Retention Period | Basis |
|---|---|---|
| Membership registration and management | Until membership cancellation | Data subject's consent |
| Records of misuse | 1 year after cancellation | Prevention of misuse and dispute response |
| Computer communications and internet log records, access tracking data | 3 months | Enforcement Decree of the Protection of Communications Secrets Act, Art. 41(2)(2) |
| Records on labeling and advertising | 6 months | Enforcement Decree of the E-Commerce Act, Art. 6(1)(1) |
| Records on contracts or withdrawal of subscription | 5 years | Enforcement Decree of the E-Commerce Act, Art. 6(1)(2) |
| Records on payment and supply of goods, etc. | 5 years | Enforcement Decree of the E-Commerce Act, Art. 6(1)(3) |
| Records on consumer complaints or dispute resolution | 3 years | Enforcement Decree of the E-Commerce Act, Art. 6(1)(4) |
- The processing and retention period for each purpose and item is as set out in the table above. However, in the following cases, personal information is retained until the relevant cause ceases:
- Where an investigation or inquiry into a violation of applicable law is in progress, until the conclusion of that investigation or inquiry
- Where claims or obligations arising from use of the Service remain outstanding, until those claims or obligations are settled
Article 4 (Provision of Personal Information to Third Parties)
The Company processes personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information), and provides personal information to third parties only to the minimum extent necessary and only where permitted under Articles 17 and 18 of PIPA, such as with the prior consent of the data subject or under specific provisions of law. Otherwise, the Company does not provide personal information to third parties.
The Company does not currently provide personal information to any third party on a regular basis. Should third-party provision become necessary in the future, the Company will amend this Policy in advance and obtain separate consent from data subjects.
Article 5 (Outsourcing of Personal Information Processing)
To ensure smooth processing of personal information, the Company outsources personal information processing as follows.
| Processor | Outsourced Work | Basis |
|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure operation (EC2, EBS, S3, SES, etc.), provision of data storage and processing environment | Data subject's consent |
| GitHub, Inc. | Social login (OAuth) identity verification | Data subject's consent |
| Google LLC | Social login (OAuth) identity verification | Data subject's consent |
When entering into outsourcing agreements, the Company specifies in the contract or other documents, in accordance with Article 26 of PIPA, the prohibition on processing personal information beyond the outsourced purpose, technical and administrative safeguards, restrictions on sub-outsourcing, management and supervision of the processor, and liability for damages, and supervises whether the processor handles personal information securely.
In accordance with Article 26(6) of PIPA, where a processor sub-outsources the Company's personal information processing work, the Company's consent is obtained, and the sub-processor and the sub-outsourced work are disclosed through this Policy.
Article 6 (Cross-Border Transfer of Personal Information)
The Company outsources the processing of, or stores, personal information overseas as follows.
| Recipient | Country | Timing and Method | Items | Purpose | Retention Period |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. (Contact: aws-korea-privacy@amazon.com) | United States, Republic of Korea (Seoul Region), etc. | Transmitted over the network at the time of Service use | All items listed in Article 2 | Cloud infrastructure operation | Until termination of the outsourcing agreement or membership cancellation |
| GitHub, Inc. (Contact: privacy@github.com) | United States | API call at the time of OAuth authentication | Email, username, profile information | Social login identity verification | Period necessary for authentication processing |
| Google LLC (Contact: googlekrsupport@google.com) | United States, etc. | API call at the time of OAuth authentication | Email, display name, profile image URL | Social login identity verification | Period necessary for authentication processing |
In accordance with Article 28-8 of PIPA, the Company notifies data subjects in advance of cross-border transfers of personal information and obtains their consent. A data subject may refuse consent by not selecting the cross-border transfer consent item during registration; in that case, registration and login through the relevant OAuth provider may be restricted, and the data subject must register and log in directly using an email address. Even after registration, a data subject may withdraw consent to cross-border transfer by contacting the Privacy Officer (privacy@graphai.io), in which case the Company will cease the cross-border transfer of the relevant personal information without delay. However, due to the nature of the Service infrastructure (AWS), withdrawal of consent to cross-border transfer may result in restrictions on use of the Service.
Article 7 (Destruction of Personal Information)
The Company destroys personal information without delay when it becomes unnecessary, such as upon expiry of the retention period or achievement of the processing purpose.
7.1 Destruction Procedure
Information entered by data subjects is, after the purpose has been achieved, transferred to a separate database (DB) or file (or a separate document, in the case of paper) and either stored for a certain period in accordance with internal policies and applicable laws or destroyed immediately. Personal information transferred to a separate DB is not used for any other purpose except as required by law.
7.2 Destruction Method
- Electronic files: Permanently deleted using methods that make the records unrecoverable and unrestorable (e.g., low-level format, destruction of encryption keys)
- Paper documents: Shredded or incinerated
7.3 Handling upon Membership Cancellation
When a member cancels their membership, the Company destroys the member's personal information immediately or after the retention period set out in this Policy has elapsed. However, information subject to statutory retention obligations under the table in Article 3 is stored separately for the applicable period and then destroyed.
Article 8 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
8.1 Rights of Data Subjects
Data subjects may exercise the following rights against the Company at any time:
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
- Request transfer (portability) of personal information (to the extent implemented under Article 35-2 of PIPA)
- Refuse, or request an explanation of, automated decisions (Article 37-2 of PIPA)
8.2 How to Exercise Rights
Rights may be exercised by email (privacy@graphai.io), in writing, or by electronic mail, and the Company will take action without delay (within 10 days of receipt).
Where a data subject requests correction or deletion of errors in their personal information, the Company will not use or provide that personal information until the correction or deletion is completed.
8.3 Exercise through a Representative
Rights may be exercised through a representative, such as the data subject's legal representative or an authorized agent. In this case, a power of attorney in the form prescribed by Annex Form No. 11 of the Notification on the Methods of Processing Personal Information must be submitted.
8.4 Limitations
The exercise of data subjects' rights may be limited under Articles 35(4) and 37(2) of PIPA.
Article 9 (Measures to Ensure the Security of Personal Information)
In accordance with Article 29 of PIPA, the Company takes the following security measures:
- Administrative measures
- Establishment and implementation of an internal management plan
- Minimizing the number of staff handling personal information and providing regular training
- Technical measures
- Managing access rights to personal information processing systems
- Installing access control systems and storing passwords in encrypted form
- Encrypting personal information in transit (HTTPS/TLS) and at rest
- Installing security software and performing regular updates and inspections
- Retaining security logs and access records
- Physical measures
- Controlling access to server rooms, data storage rooms, etc.
- Leveraging the data center security controls of the cloud infrastructure provider (AWS)
Article 10 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
10.1 Purpose of Cookies
To provide personalized services to data subjects, the Company uses "cookies" and similar technologies that store and retrieve usage information. Cookies are used for the following purposes:
- Authentication cookie: Maintaining the AkasicDB Cloud session (required)
- Studio access token: HMAC-signed token for accessing instance subdomains (required)
- Usage analytics: Understanding service usage patterns, popular searches, access frequency, etc. (optional)
10.2 Installation, Operation, and Refusal of Cookies
Data subjects may allow or block cookies through their web browser settings. However, blocking required cookies may restrict use of some parts of the Service, such as login. Optional cookies such as usage analytics are used only where the data subject has separately consented, and data subjects may withdraw their consent at any time through the cookie settings within the Service or by contacting privacy@graphai.io.
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
Article 11 (Privacy Officer)
The Company designates the following Privacy Officer to take overall responsibility for personal information processing and to handle data subjects' complaints and remedies related to personal information processing.
▶ Privacy Officer
- Name: Donghyeong Han
- Title: Chief Technology Officer
- Contact: privacy@graphai.io
▶ Privacy Department
- Department: DB Engine Team
- Contact: privacy@graphai.io
Data subjects may direct all inquiries, complaints, and requests for remedies related to personal information protection arising from use of the Service to the Privacy Officer and the Privacy Department. The Company will respond to and handle data subjects' inquiries without delay.
Article 12 (Remedies for Infringement of Rights)
To obtain relief from infringement of personal information, data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the KISA Personal Information Infringement Report Center, and other bodies. For other reports or consultations regarding personal information infringement, please contact the following organizations:
| Organization | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | www.kopico.go.kr |
| Personal Information Infringement Report Center | 118 (no area code) | privacy.kisa.or.kr |
| Supreme Prosecutors' Office, Cyber Investigation Division | 1301 (no area code) | www.spo.go.kr |
| Korean National Police Agency, Cyber Bureau | 182 (no area code) | ecrm.police.go.kr |
Article 13 (Changes to this Privacy Policy)
This Policy applies from its effective date. Where there are additions, deletions, or corrections to its contents under applicable law or Company policy, the Company will provide notice through the in-Service announcements or by email at least 7 days before the change takes effect (or at least 30 days in advance for changes that materially affect data subjects' rights).
This Privacy Policy applies from September 29, 2026. Previous versions are available below.
| Version | Effective Date | Summary of Changes |
|---|---|---|
| 1.0 (Draft) | 2026-05-22 | Initial version |
| 1.1 | 2026-09-29 | Reflected product name (AkasicDB Cloud), added contact details for cross-border transfer recipients, revised marketing collection items, aligned effective dates |
Contact: privacy@graphai.io