Privacy Policy
Version 1.0.0 • sha256:1812472cceb2
Privacy Policy
Version: 1.0.0
Effective date: 2026-04-11
Authoritative language: Korean. In case of conflict, the Korean version governs.
Data Protection Officer (CPO): Kang In Wook / privacy@concourse.to / [PLACEHOLDER: CPO 전화번호]
⚠️ This is a draft document. Final review by a Korean medical law and data protection attorney is required before production use. The STRUCTURE of this document (sections, cross-border table, CPO block, intermediary disclaimer, retention periods) reflects PIPA §30 and GDPR Art. 13 requirements.
1. Information We Collect
[PLACEHOLDER: Concourse Inc.] ("Concourse", "we", "our") collects the following categories of information:
1.1 Required data
1.2 Sensitive medical data (PIPA §23)
Concourse processes the following sensitive medical data for cross-border dental care matching. Separate explicit consent is required.
1.3 Users under 14
Personal data of users under 14 is collected only with verifiable parental/guardian consent (PIPA §22(6)).
2. Purposes
3. Retention
| Category | Period | Basis |
|---|---|---|
| Account data | Until account deletion | User consent |
| Medical images (X-ray, intraoral) | **10 years** | Korean Medical Act §22, §23 |
| Treatment records | 10 years | Korean Medical Act §22 |
| Payment & transaction records | 5 years | E-commerce Act §6 |
| Dispute resolution records | 3 years | E-commerce Act §6 |
| Access & audit logs | 3 years | PIPA Enforcement Decree §48-2 |
| Marketing records | 6 months | E-commerce Act §6 |
After the retention period expires, data is auto-destroyed (encryption key destruction + DB soft delete → physical deletion). Destruction events are written to the audit log.
4. Data Sharing
Concourse does not share personal data with third parties except as follows:
5. Cross-Border Data Transfer
Concourse transfers personal data to the following non-Korean processors. Separate consent is required under PIPA §28-8.
| Processor | Country | Purpose | Data Categories |
|---|---|---|---|
| Railway (PaaS) | 미국 / United States | Application + database hosting | All application data (encrypted at rest) |
| Cloudinary | 미국 / United States | Image storage + delivery | Medical images (X-rays, dental photos) — AES-256-GCM encrypted |
| Resend | 미국 / United States | Transactional email delivery | Email address, name, transaction details |
| Sentry | 미국 / United States | Error monitoring (PII scrubbed) | Error payloads, stack traces (no medical content after Phase 5 scrubbing) |
| DeepL | 독일 / Germany (EU) | Chat message translation | Chat message text (ephemeral) |
6. Data Subject Rights
You may exercise the following rights at any time (PIPA §35-39, GDPR Art. 15-22):
Exercise these rights via the in-app "My Data" menu or by emailing privacy@concourse.to. We will respond within 30 days (GDPR) or 10 days (PIPA).
7. Security Measures
8. Data Breach Notification
In the event of a personal data breach, Concourse will:
9. Cookies
Concourse uses cookies and similar storage technologies to maintain your session. Essential cookies cannot be refused; analytics cookies can be opted out in settings.
10. Data Protection Officer
You may also report complaints to:
11. Changes to this Policy
Material changes will be announced in-app and via email at least 7 days before they take effect. Continued use after the effective date constitutes acceptance.
Effective date: 2026-04-11
Business information: [PLACEHOLDER: Concourse Inc.] | CEO: Jun Soo Kwon | Address: [PLACEHOLDER: Seoul, South Korea] | Business Number: [PLACEHOLDER: 사업자등록번호] | E-commerce Registration: [PLACEHOLDER: 통신판매업신고번호] | Medical Tourism License: [PLACEHOLDER: 외국인환자 유치업자 등록번호 — 등록 진행 중]