Privacy Policy
Version 1.0.1 • sha256:e9ffc6135319
Privacy Policy
Version: 1.0.0
Effective date: 2026-04-11
Authoritative language: Korean. In case of conflict, the Korean version governs.
Data Protection Officer (CPO): Kang In Wook / privacy@concourse.to / 070-4577-7512
⚠️ This is a draft document. Final review by a Korean medical law and data protection attorney is required before production use. The STRUCTURE of this document (sections, cross-border table, CPO block, intermediary disclaimer, retention periods) reflects PIPA §30 and GDPR Art. 13 requirements.
1. Information We Collect
Concourse Inc. ("Concourse", "we", "our") collects the following categories of information:
1.1 Required data
1.2 Sensitive medical data (PIPA §23)
Concourse processes the following sensitive medical data for cross-border dental care matching. Separate explicit consent is required.
1.3 Users under 14
Personal data of users under 14 is collected only with verifiable parental/guardian consent (PIPA §22(6)).
2. Purposes
3. Retention
| Category | Period | Basis |
|---|---|---|
| Account data | Until account deletion | User consent |
| Medical images (X-ray, intraoral) | **10 years** | Korean Medical Act §22, §23 |
| Treatment records | 10 years | Korean Medical Act §22 |
| Payment & transaction records | 5 years | E-commerce Act §6 |
| Dispute resolution records | 3 years | E-commerce Act §6 |
| Access & audit logs | 3 years | PIPA Enforcement Decree §48-2 |
| Marketing records | 6 months | E-commerce Act §6 |
After the retention period expires, data is auto-destroyed (encryption key destruction + DB soft delete → physical deletion). Destruction events are written to the audit log.
4. Data Sharing
Concourse does not share personal data with third parties except as follows:
5. Cross-Border Data Transfer
Concourse transfers personal data to the following non-Korean processors. Separate consent is required under PIPA §28-8.
| Processor | Country | Purpose | Data Categories |
|---|---|---|---|
| Railway (PaaS) | 미국 / United States | Application + database hosting | All application data (encrypted at rest) |
| Cloudinary | 미국 / United States | Image storage + delivery | Medical images (X-rays, dental photos) — AES-256-GCM encrypted |
| Resend | 미국 / United States | Transactional email delivery | Email address, name, transaction details |
| Sentry | 미국 / United States | Error monitoring (PII scrubbed) | Error payloads, stack traces (no medical content after Phase 5 scrubbing) |
| DeepL | 독일 / Germany (EU) | Chat message translation | Chat message text (ephemeral) |
6. Data Subject Rights
You may exercise the following rights at any time (PIPA §35-39, GDPR Art. 15-22):
Exercise these rights via the in-app "My Data" menu or by emailing privacy@concourse.to. We will respond within 30 days (GDPR) or 10 days (PIPA).
7. Security Measures
8. Data Breach Notification
In the event of a personal data breach, Concourse will:
9. Cookies
Concourse uses cookies and similar storage technologies to maintain your session. Essential cookies cannot be refused; analytics cookies can be opted out in settings.
10. Data Protection Officer
You may also report complaints to:
11. Changes to this Policy
Material changes will be announced in-app and via email at least 7 days before they take effect. Continued use after the effective date constitutes acceptance.
Effective date: 2026-04-11
Business information: Concourse Inc. | CEO: Jun Soo Kwon | Address: 11F #124 DD-12, 428 Seolleung-ro, Gangnam-gu, Seoul, Republic of Korea | Business Number: 150-81-04445 | E-commerce Registration: 신고 예정 (2026) | Medical Tourism License: 외국인환자 유치업자 등록 진행 중