Privacy Policy

GraphAI Co., Ltd. ("GraphAI", "we", "us") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act of the Republic of Korea ("PIPA"), in order to protect the personal information of data subjects and to handle related grievances promptly and effectively.

This Policy applies to personal information processed through the websites we operate (graphai.io, blog.graphai.io) and the products and services we provide (AkasicIN, AkasicDB, AkasicON, AkasicAI, collectively the "Services").

Effective date: 21 September 2026


Article 1. Purposes of Processing Personal Information

We process personal information for the purposes set out below. Personal information is not used for any purpose other than those listed. Where the purpose of use changes, we take the measures required under Article 18 of PIPA, including obtaining separate consent.

Category Purpose
Product and solution inquiries Verifying and responding to inquiries, providing technical materials and proposals, follow-up sales activities
Press and marketing inquiries Verifying and responding to media, partnership and event inquiries
Newsletter and marketing communications Sending the newsletter, providing information on products, services, technical materials and events (webinars, exhibitions), and transmitting advertising information
Service provision and contract performance Concluding, maintaining and performing contracts, issuing and managing product licences, technical support and incident response, billing and settlement
Recruitment Identifying applicants, verifying qualifications, conducting the hiring process and communicating results
Website operation Analysing service usage statistics, measuring access frequency, preventing misuse, improving the Services

Article 2. Categories of Personal Information Processed and Methods of Collection

1. Website inquiry form

Type Items
Required Name, company name, email address, inquiry details
Optional Inquiry category
Collected automatically IP address, access date and time, browser and device information, cookies, service usage records

2. Newsletter subscription

Type Items
Required Name, email address, company and department
Collected automatically Subscription date and time, IP address
Generated during delivery Email delivery, open and link-click records

Open and click records are used to improve newsletter quality and to determine distribution lists. They are not used to identify or profile individual subscribers.

3. Service provision and contract performance

Type Items
Customer contact information Name, department and job title, business email address, business phone number
Contract and settlement information Name, affiliation, phone number and email address of the contracting representative
Generated during technical support Support history, contents of technical support requests, remote support records

4. Recruitment

Type Items
Required Name, phone number, email address, education and career history, application contents
Optional Portfolio, certifications and similar materials

5. Methods of collection

  • Direct entry by the data subject through the website inquiry form, the newsletter subscription form and recruitment channels
  • Business cards received and registrations submitted at exhibitions, seminars and webinars, both offline and online
  • Inquiries by email, telephone or in writing
  • Information generated and collected automatically during use of the website

6. Sensitive information and unique identifiers

We do not process sensitive information, including information on ideology or belief, joining or withdrawing from a trade union or political party, political opinions, health, sexual life, genetic information or criminal records. Accordingly, provisions on the possibility of sensitive information being disclosed and on how to opt out of such disclosure do not apply.

We do not process unique identifiers such as resident registration numbers or passport numbers. For successful candidates only, we may process them to the extent required by law for employment contracts and social insurance registration.


Article 3. Retention and Use Periods

We process and retain personal information within the retention period required by law or the period consented to by the data subject at the time of collection.

Processing activity Retention period
Product and solution inquiries 3 years after the inquiry is resolved; where the data subject has consented to ongoing sales contact, until that consent is withdrawn
Press and marketing inquiries 3 years after the inquiry is resolved
Newsletter subscription Until unsubscription. Data is destroyed immediately upon request, except that the opt-out record (email address) is retained as required by law to prevent further sending
Contracts and service provision 5 years after termination of the contract (record retention periods under the Framework Act on National Taxes, the Corporate Tax Act and related statutes)
Recruitment Destroyed within 1 year after the hiring process ends; for successful candidates, retained under our HR rules
Website access logs 3 months (Protection of Communications Secrets Act)

Retention required by other laws

Where retention is required under other statutes, we retain the information for the period prescribed and do not use it for any other purpose.

  • Records on contracts and withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce, where applicable)
  • Records on payment and supply of goods: 5 years (same Act, where applicable)
  • Records on consumer complaints or dispute resolution: 3 years (same Act, where applicable)
  • Website access logs: 3 months (Protection of Communications Secrets Act)
  • Tax invoices and other transaction records: 5 years (Framework Act on National Taxes)

Article 4. Provision to Third Parties

We process personal information only within the scope specified in Article 1, and provide it to third parties only where Article 17 or Article 18 of PIPA applies, such as with the data subject's consent or under a specific provision of law.

We currently do not provide personal information to third parties.

Should third-party provision become necessary, we will disclose the recipient, the purpose, the items provided and the retention period in advance through this Policy and obtain the required consent.


Article 5. Entrustment of Personal Information Processing

We entrust the processing of personal information as follows.

Entrusted party Entrusted work Retention period
Stibee, Inc. Newsletter email delivery and subscriber management Until termination of the service agreement or unsubscription
Inblog Collection of newsletter subscription form entries on the blog Until termination of the service agreement
Cafe24 Corp. Website hosting and server operation (including storage of information collected in the course of website use) Until termination of the service agreement
Tally BV Operation of the job application form and storage of applicant information Until termination of the service agreement
Microsoft Corporation Provision of business collaboration and document management tools, and storage of inquiry-related information Until termination of the service agreement
Notion Labs, Inc. Recording and management of job applicant information Until termination of the service agreement

In accordance with Article 26 of PIPA, our agreements with entrusted parties set out, in writing, the prohibition on processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on sub-entrustment, supervision of the entrusted party and liability for damages. We supervise whether entrusted parties handle personal information securely.

Any change to the entrusted work or to the entrusted parties will be disclosed through this Policy.


Article 6. Overseas Transfer of Personal Information

We transfer personal information overseas as follows.

Recipient Country Timing and method of transfer Items transferred Purpose Retention period
Microsoft Corporation United States Transmitted over the network when staff enter and store inquiry details in our business systems Name, email address, inquiry details Use of business collaboration and document management tools Until termination of the service agreement
Google LLC United States Transmitted automatically on website access Cookies, access records, device information Website usage analytics Per the data retention setting configured in Google Analytics
Tally BV Belgium Transmitted over the network when a job application is submitted Name, phone number, email address, application contents Receiving job applications and managing applicant information Until termination of the service agreement
Notion Labs, Inc. United States Transmitted automatically via integration when a job application is submitted Name, phone number, email address, application contents Recording and management of job applicant information Until termination of the service agreement

Data subjects may refuse consent under Article 28-8(1)1 of PIPA. If consent is refused, use of the relevant service may be restricted.

For overseas transfers we implement the protective measures required under Article 28-8(4) of PIPA.

Direct collection of Korean data subjects' personal information from outside Korea

Not applicable. We collect and process personal information within the Republic of Korea.


Article 7. Destruction of Personal Information

We destroy personal information without delay once it is no longer necessary, for example when the retention period has elapsed or the purpose of processing has been achieved.

1. Procedure

Where personal information must be retained under other statutes even after the consented retention period has elapsed or the purpose of processing has been achieved, we move it to a separate database or storage location and retain it there.

2. Method

  • Electronic files: permanently deleted by means that render recovery impossible
  • Paper documents: shredded or incinerated

Article 8. Rights of Data Subjects and Legal Representatives, and How to Exercise Them

1. Rights

Data subjects may exercise the following rights in relation to us at any time.

  1. Request access to their personal information
  2. Request correction of errors
  3. Request deletion
  4. Request suspension of processing
  5. Refuse, or request an explanation of, an automated decision (where applicable)

2. How to exercise

Rights may be exercised in writing, by email or by fax, and we will act on such requests without delay.

  • Contact: privacy@graphai.io
  • Phone: +82-42-716-1239

Where a data subject requests correction or deletion on the grounds of error, we will not use or provide the personal information concerned until the correction or deletion is complete.

3. Exercise through a representative

Rights may be exercised through a legal representative or an authorised agent. In such cases, a power of attorney in the form prescribed by the Notice on Personal Information Processing Methods (Attached Form No. 11) must be submitted.

4. Limitations on exercise

Requests for access and for suspension of processing may be restricted under Articles 35(4) and 37(2) of PIPA.

5. Limitations on deletion

Deletion may not be requested where another statute expressly provides that the personal information concerned is to be collected.


Article 9. Security Measures

We take the following measures to ensure the security of personal information.

1. Administrative measures

  • Establishment and implementation of an internal management plan
  • Minimising the number of staff handling personal information and providing regular training
  • Designating staff responsible for personal information processing and managing their access rights

2. Technical measures

  • Access rights management and access control for personal information processing systems
  • Encryption of unique identifiers and other important information at rest, and encryption in transit (SSL/TLS)
  • Retention of access logs and measures against forgery or alteration
  • Installation and periodic updating and inspection of security software
  • Installation and operation of intrusion prevention systems and other access control devices

3. Physical measures

  • Access control for server rooms, document storage rooms and other areas where personal information is kept

Article 10. Installation and Operation of Automatic Collection Devices, and Refusal

We use cookies, which store and retrieve usage information, in order to provide individually tailored services.

1. Purpose of cookies

To understand visit history for each page, access frequency and patterns of service use, and thereby improve the website experience and content.

2. Operation and refusal of cookies

Users may refuse or delete cookies through their web browser settings. Refusing cookies may make some services difficult to use.

  • Chrome: Settings > Privacy and security > Third-party cookies
  • Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
  • Safari: Preferences > Privacy > Cookies and website data

3. Principal cookies and analytics tools in use

Category Tool Purpose
Essential wp-wpml_current_language Retaining the language (Korean or English) selected by the visitor
Analytics Google Analytics 4 (_ga, _ga_*) Website usage analytics

4. Use of Google Analytics and how to opt out

We use Google Analytics 4 to analyse website usage statistics. Google Analytics collects a randomly generated identifier stored in a cookie, together with access records and browser and device information. We do not use this information to identify individual users. The information collected is retained according to the data retention setting configured in Google Analytics and is deleted once that period elapses.

Users may refuse collection by Google Analytics in the following ways.

  • Installing the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout)
  • Blocking cookies through web browser settings

Article 11. Collection, Use and Provision of Behavioural Information, and Refusal

We do not collect or use online behavioural information for the purpose of delivering optimised advertising to data subjects in the course of their use of the Services.


Article 12. Processing of Pseudonymised Information

We do not currently process pseudonymised information.

Should we process pseudonymised information for statistical purposes, scientific research or archiving in the public interest, we will disclose the purpose of processing, the processing period, whether it is provided to third parties, whether processing is entrusted, the categories of pseudonymised information and the security measures taken through this Policy.


Article 13. Automated Decision-Making

We do not make fully automated decisions that significantly affect the rights or obligations of data subjects.


Article 14. Chief Privacy Officer and Department Handling Access Requests

We designate a Chief Privacy Officer as set out below, who takes overall responsibility for personal information processing and handles complaints and remedies for data subjects in relation to such processing.

Chief Privacy Officer

Item Detail
Name Kim Min-soo
Title Chief Executive Officer
Phone +82-42-716-1239
Email privacy@graphai.io

Data subjects may direct to the Chief Privacy Officer and the responsible department any inquiry, complaint or remedy request relating to personal information protection arising from their use of our Services. We will respond to and handle such inquiries without delay.


Article 15. Remedies for Infringement of Rights

Data subjects may apply to the following bodies for dispute resolution or counselling in order to obtain redress for infringement of personal information.

Body Function Contact
Personal Information Infringement Report Centre Reporting infringements, counselling 118 / privacy.kisa.or.kr
Personal Information Dispute Mediation Committee Applications for dispute mediation and collective dispute mediation +82-1833-6972 / kopico.go.kr
Supreme Prosecutors' Office, Cyber Investigation Division Investigation of infringements 1301 / spo.go.kr
National Police Agency, Cyber Bureau Investigation of infringements 182 / ecrm.police.go.kr

A person whose rights or interests are infringed by a disposition or omission by the head of a public institution in respect of a request under Article 35 (access), Article 36 (correction or deletion) or Article 37 (suspension of processing) of PIPA may file an administrative appeal as provided by the Administrative Appeals Act.

  • Central Administrative Appeals Commission: 110 / simpan.go.kr

Article 16. Changes to This Privacy Policy

This Privacy Policy applies from 21 September 2026.

Where content is added, deleted or amended in response to changes in law, policy or security technology, we will give notice on our website at least seven days before the change takes effect.


This English version is provided for reference. In the event of any discrepancy with the Korean version, the Korean version shall prevail.





    This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.