Skip to content

LEGAL

Privacy Policy

Effective date: 2026-07-29

Portrai Inc. (주식회사 포트래이; "Portrai," "we," "us") is committed to protecting your personal data and complying with the Personal Information Protection Act (PIPA) of Korea and other applicable laws. This Privacy Policy explains how we collect, use, and protect personal information through our website.

This website does not offer account registration or login. We process only the minimum personal data needed to respond to inquiries and to operate and analyze the website.

1. Purposes of Processing and Categories of Data Collected

We process personal data for the purposes below and do not use it for unrelated purposes.

ContextPurposeData collected
General / media inquiriesReceiving and responding to inquiriesName, email, subject, message
Business development / partnership / investmentProgressing discussions and repliesName, company, role/title, email, country/timezone, message
Demo requestsArranging a platform demoName, company, email, use case, preferred time
Careers / talent poolVerifying applicants and running the hiring processName, email, area of interest, LinkedIn URL, résumé file (optional)
Website operation & analyticsAccess statistics, service improvement, abuse/spam/bot preventionCookies, IP address, browser/device info, visit logs
  • We do not collect or process the personal data of children under the age of 14.

2. Processing and Retention Periods

We process and retain personal data within the period required by law or consented to by the data subject.

ContextRetention period
Inquiry records (general / BD / demo)1 year from the date the inquiry is received
Careers / talent-pool applications1 year from the date the application is received (separate period for talent-pool retention if consented)
Advertising / promotional / sales useDestroyed immediately (within 5 days) upon a request to opt out of marketing
Communication confirmation data (Protection of Communications Secrets Act)Access date/time and similar records: 1 year / computer-communication & internet log records: 3 months
  • Personal data is destroyed without delay once the retention period expires or the purpose is achieved.

3. Destruction of Personal Data

  • When personal data becomes unnecessary — due to expiry of the retention period or achievement of the purpose — we destroy it without delay.
  • Electronic files are deleted using methods that prevent recovery; paper documents are shredded or incinerated.
  • Where retention is required by other laws, such data is stored separately in a distinct database or location.

4. Provision to Third Parties

  • We process personal data only within the scope stated in Section 1 and provide it to third parties only where permitted by PIPA (e.g., your consent or a specific legal requirement).
  • We currently do not provide users' personal data to external parties. (Any change will be announced in advance through this Policy.)

5. International Transfers

To operate the service, we transfer personal data overseas (entrustment of processing / storage) as follows.

(1) Email delivery

  • Recipient: Mailgun Technologies, Inc. / Sinch AB (publ) (United States)
  • Legal basis: PIPA Article 28-8(1)(iii) (entrustment/storage necessary to conclude and perform a contract with the data subject); Article 28-8(1)(i) (separate consent obtained from the data subject)
  • Timing and method: transmitted over the network at the time of service use
  • Items transferred: email address, name, send logs
  • Purpose: email verification, service-related notices, marketing email delivery
  • Retention: send logs destroyed after 3 days; other data retained until the purpose of entrustment is achieved

(2) Error / incident monitoring

  • Recipient: Functional Software, Inc. d/b/a Sentry (United States)
  • Legal basis: PIPA Article 28-8(1)(iii)
  • Timing and method: transmitted over the network when an error or fault occurs during service use
  • Items transferred: IP address, browser and device information, error logs, stack traces, performance and fault-diagnostics data (under our current configuration we do not collect email, user ID, request body, query parameters, or file paths)
  • Purpose: error monitoring, fault analysis, security and service-quality improvement
  • Retention: destroyed after 30 days, or retained per the relevant configuration and Sentry's policy

(3) Website hosting / content delivery

  • Recipient: Cloudflare, Inc. (United States, etc.)
  • Legal basis: PIPA Article 28-8(1)(iii)
  • Timing and method: transmitted over the network when the website is accessed
  • Items transferred: IP address, browser and device information, access logs
  • Purpose: website hosting and content delivery (CDN), security and traffic management
  • Retention: until the purpose of service provision is achieved, or per Cloudflare's policy and configuration
  • Processors are supervised so that they cannot use personal data beyond the entrusted purpose.
  • You may refuse the overseas transfer of your personal data; in that case, some functionality may be limited. You may make such a request to our Data Protection Officer.

6. Cookies

  • Cookies are small pieces of information that the server sends to your browser and are stored on your device.
  • Beyond strictly necessary cookies, we use analytics and marketing cookies only with your consent (cookie banner).
  • You can refuse cookies via the cookie banner settings or your browser settings. Refusing necessary cookies may limit some functionality.

7. Security Measures

  • Administrative: internal management plan, least-privilege access, staff training
  • Technical: encryption in transit (HTTPS), access control, protection against unauthorized access
  • Physical: access control to systems that process personal data

8. Rights of Data Subjects and How to Exercise Them

  • You may at any time request access to, correction of, deletion of, or suspension of processing of your personal data.
  • Requests may be made in writing or by email to the Data Protection Officer in Section 9 (contact@portrai.io), and we will act without delay. Requests may also be made through a legal representative or a duly authorized agent.
  • Restrictions may apply where required by law (e.g., minors).

9. Data Protection Officer

  • Data Protection Officer: Daeseung Lee (CEO)
  • Department: PE Division
  • Email: contact@portrai.io
  • Phone: +82-2-766-2377
  • Address: 7F, 57 Seongsui-ro 22-gil, Seongdong-gu, Seoul, Republic of Korea

You may direct any inquiries, complaints, or remedy requests regarding personal-data processing to the contact above, and we will respond and act without delay.

10. Remedies for Rights Infringement

If you need to report or consult on a privacy matter, you may contact the following (Korea):

  • Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972)
  • Privacy Infringement Report Center, KISA (privacy.kisa.or.kr / 118)
  • Supreme Prosecutors' Office Cybercrime Investigation (www.spo.go.kr / 1301)
  • National Police Agency Cyber Bureau (ecrm.cyber.go.kr / 182)

11. Changes to This Policy

  • This Privacy Policy takes effect on July 29, 2026.
  • If the content is added to, deleted, or amended due to changes in law, policy, or the service, we will announce the changes in advance through the website.