dodamai
Create account
All documents

Dodam AI Privacy Policy

What personal data we process, why, for how long, who we entrust it to, where it goes, and how you exercise your rights. Written to the standard of Korea's Personal Information Protection Act (PIPA).

Effective
Last revised
Version
1.0
한국어로 읽기

These statutory details are not final yet. Replace each placeholder with the real value before the documents are published.

  • {{개인정보보호책임자}}Privacy officer name and title

    Name and title of the officer designated under PIPA Article 31.

  • {{결제대행사}}Payment gateway provider

    The payment gateway you contract with before paid billing starts; also add it to the processor table.

Article 1 (General)

VanillaX Inc. ("the Company") establishes and publishes this Privacy Policy under Article 30 of the Personal Information Protection Act ("PIPA") to protect the personal data of data subjects and to handle related complaints promptly. It applies to "Dodam AI", the cross-border marketplace listing inspection service the Company operates.

The Company processes business data of the traders and staff who use the Service. It does not collect personal data of children under 14.

Article 2 (What we collect and how)

(1) We collect only the minimum needed to provide the Service.

Categories collected
  • Context
    Sign-up
    Data collected
    Email address, password (stored one-way hashed), name
    Method
    Entered on the sign-up screen
    Required
    Required
  • Context
    Workspace creation
    Data collected
    Organization name, default destination country, default marketplace
    Method
    Entered during onboarding
    Required
    Required
  • Context
    Running an inspection
    Data collected
    Uploaded image files, product title, key features, description, product category
    Method
    Entered or uploaded on the inspection screen, or sent via the API
    Required
    Required
  • Context
    Team invitations
    Data collected
    Email address of the invitee
    Method
    Entered on the members screen
    Required
    Optional
  • Context
    Generated automatically in use
    Data collected
    IP address, timestamp, request path and response code, browser and OS information, cookies, records of inspections, downloads and API calls
    Method
    Generated automatically while you use the Service
    Required
    Required
  • Context
    Marketing messages
    Data collected
    Email address, consent flag and the time consent was given
    Method
    Optional consent on the sign-up screen
    Required
    Optional
  • Context
    Support and complaints
    Data collected
    Email address, the content of your enquiry, attachments
    Method
    Received by email
    Required
    Optional

(2) We do not collect sensitive data such as beliefs, political opinions, health or sex life, and we do not collect resident registration numbers. Please avoid including sensitive or unique identifying information in your uploads.

(3) Declining the optional items does not restrict sign-up or inspection in any way.

(4) When paid billing begins, payment method details and transaction records will additionally be processed through a payment gateway ({{결제대행사}}). We will amend and announce this Policy before that starts. The Company does not itself store card numbers or other payment credentials.

Article 3 (Purposes of processing)

We process personal data only for the following purposes, and will obtain consent in advance if a purpose changes.

  1. 1.Identifying and authenticating users, managing accounts and organizations, granting roles.
  2. 2.Running listing inspections, producing findings, applying automatic fixes and re-inspecting, delivering reports and outputs.
  3. 3.Issuing API keys, authenticating calls, metering usage and enforcing allowances.
  4. 4.Retaining your usage history so you can re-open your own results.
  5. 5.Handling enquiries and complaints and delivering announcements.
  6. 6.Preventing abuse, detecting intrusion attempts, keeping the Service stable.
  7. 7.Statistical analysis for product improvement, in a form that cannot identify anyone.
  8. 8.Telling users who opted in about new features and events.
  9. 9.Meeting obligations imposed by law.

Article 4 (Retention periods)

(1) We destroy personal data without delay once the purpose of collection has been achieved. The standard periods are as follows.

Standard retention
  • Data
    Account data (email, name, password) and organization data
    Retention
    While the agreement is in force; destroyed within 30 days of a deletion request
  • Data
    Uploaded images and product text, inspection results, fixed outputs
    Retention
    While the agreement is in force; destroyed within 30 days of a deletion request (immediately on an individual deletion request)
  • Data
    API keys
    Retention
    Until revoked; kept 90 days after revocation for audit, then destroyed
  • Data
    Access logs (IP, request path, response code)
    Retention
    3 months from creation
  • Data
    Marketing consent records
    Retention
    Until consent is withdrawn; after withdrawal only the fact of withdrawal is kept for 3 years
  • Data
    Records of consent to the Terms and this Policy
    Retention
    5 years after the agreement ends, to handle disputes

(2) The 30-day grace period after account deletion is the minimum needed to recover from mistaken deletion and to prevent abusive re-registration. If you ask for immediate destruction, we destroy everything except items we must keep by law.

(3) The following are kept separately for the periods set by law.

Retention required by law
  • Records
    Contracts and withdrawal of subscription
    Period
    5 years
    Legal basis
    E-Commerce Consumer Protection Act, Article 6
  • Records
    Payment and supply of goods or services
    Period
    5 years
    Legal basis
    E-Commerce Consumer Protection Act, Article 6
  • Records
    Consumer complaints and dispute handling
    Period
    3 years
    Legal basis
    E-Commerce Consumer Protection Act, Article 6
  • Records
    Labelling and advertising
    Period
    6 months
    Legal basis
    E-Commerce Consumer Protection Act, Article 6
  • Records
    Electronic financial transactions
    Period
    5 years
    Legal basis
    Electronic Financial Transactions Act, Article 22
  • Records
    Tax invoices and transaction evidence
    Period
    5 years
    Legal basis
    Framework Act on National Taxes, Article 85-3
  • Records
    Access (login) logs
    Period
    At least 3 months
    Legal basis
    Protection of Communications Secrets Act, Article 15-2

(4) Data kept under law is used only for that retention purpose and for nothing else.

Article 5 (Disclosure to third parties)

(1) We do not provide your personal data to third parties.

(2) The exceptions are:

  1. 1.You gave separate, prior consent.
  2. 2.A specific provision of law requires it.
  3. 3.An investigative authority requests it by presenting a warrant or equivalent under the procedure and in the manner prescribed by law.

(3) Even under paragraph (2)3, we verify that the request is lawful and in scope, provide only the minimum necessary, and tell you about it unless the law forbids us from doing so.

(4) Processors needed to operate the Service are disclosed in Article 6 and cross-border transfers in Article 7. Entrusting processing and transferring abroad are distinct from disclosure to a third party.

Article 6 (Processors)

(1) To run the Service we entrust processing as follows.

Processors engaged by Dodam AI
  • Processor
    Supabase Inc.
    Purpose of the entrusted work
    Database, account authentication and uploaded-file storage
    Processing location
    Seoul region (ap-northeast-2), Republic of Korea; operational support accesses remotely from the United States
    Retention
    Until the processing agreement ends, or within 30 days of account deletion
  • Processor
    Vercel Inc.
    Purpose of the entrusted work
    Web application hosting, request routing, access logging
    Processing location
    United States (global edge network)
    Retention
    Until the processing agreement ends. Access logs for up to 30 days
  • Processor
    Google LLC (Gemini API)
    Purpose of the entrusted work
    Analysis of product images and product copy to enrich inspection results
    Processing location
    United States
    Retention
    Deleted as soon as the request is served. Not used to train models
  • Processor
    OpenAI, L.L.C.
    Purpose of the entrusted work
    Generation of example images for fix suggestions
    Processing location
    United States
    Retention
    Deleted as soon as the request is served. Not used to train models
  • Processor
    Brave Software, Inc. (Brave Search API)
    Purpose of the entrusted work
    Search for marketplace rule sources
    Processing location
    United States
    Retention
    Only the search query is sent; no personal data or uploaded content is sent

(2) Our processing agreements set out, in writing, technical and organisational safeguards, restrictions on sub-processing, supervision of the processor, and liability including damages.

(3) If the entrusted work or the processor changes, we publish the change in this Policy.

Article 7 (Cross-border transfers)

(1) To provide the Service we transfer personal data abroad as follows.

Cross-border transfers (PIPA Article 28-8)
  • Recipient
    Supabase Inc. (support@supabase.io)
    Country
    United States (data stored in the Seoul region, Republic of Korea)
    Time and method of transfer
    Transmitted over TLS when you use the service
    Data transferred
    Email, name, organization name, uploaded images, product text, access logs
    Purpose
    Operating the database, authentication and storage, and incident response
    Retention
    Deleted within 30 days of account deletion
  • Recipient
    Vercel Inc. (privacy@vercel.com)
    Country
    United States
    Time and method of transfer
    Transmitted over TLS with each page or API request
    Data transferred
    IP address, timestamp, request path, browser information
    Purpose
    Hosting the web application, security and error handling
    Retention
    Up to 30 days
  • Recipient
    Google LLC (represented by Google Ireland Ltd., privacy-emea@google.com)
    Country
    United States
    Time and method of transfer
    Sent over the API when an inspection runs
    Data transferred
    Uploaded images, product title and description text
    Purpose
    AI enrichment of rule-based inspection results
    Retention
    Deleted as soon as the request is served
  • Recipient
    OpenAI, L.L.C. (privacy@openai.com)
    Country
    United States
    Time and method of transfer
    Sent over the API when an example image is requested
    Data transferred
    The image to be fixed and the fix instruction text
    Purpose
    Generating example images for fix suggestions
    Retention
    Deleted as soon as the request is served
  • Recipient
    Brave Software, Inc. (privacy@brave.com)
    Country
    United States
    Time and method of transfer
    Sent over the API when rule sources are searched
    Data transferred
    Search terms (marketplace, country, rule keywords)
    Purpose
    Collecting citations for marketplace rules
    Retention
    No transfer (contains no personal data)

(2) Supabase stores data in the Seoul region of the Republic of Korea, but staff located in the United States may access it remotely for operational support, so it is disclosed here as a cross-border transfer.

Article 8 (How we destroy personal data)

(1) We destroy personal data without delay once the retention period ends or the purpose is achieved.

(2) Procedure: data due for destruction is identified and destroyed with the approval of the privacy officer. Data that must be retained by law is moved to a separate database with restricted access and destroyed when its period ends.

(3) Method: electronic records are permanently deleted by a method that prevents recovery; uploaded images and outputs are deleted from storage objects and removed from backups. Printed records are shredded or incinerated.

(4) Anything remaining on backup media is overwritten and lost once the backup retention cycle (up to 30 days) has passed.

Article 9 (Your rights and how to exercise them)

(1) You may exercise the following rights at any time.

  1. 1.Request access to your personal data.
  2. 2.Request correction of anything inaccurate.
  3. 3.Request deletion.
  4. 4.Request suspension of processing.
  5. 5.Withdraw consent, including consent to marketing messages.

(2) Exercise them directly in the settings screens, or by emailing admin@vanillax.co. We act within 10 days of receiving a request and tell you the outcome.

What you can do yourself in the Service
  • Right
    Access and correction
    How
    Settings › Profile for your name and language; Settings › Organization for organization details
  • Right
    Deletion
    How
    Deleting an inspection from the list also deletes its uploads and results
  • Right
    Suspension and account deletion
    How
    Use account deletion in Settings, or email admin@vanillax.co
  • Right
    Withdrawing marketing consent
    How
    Turn it off in the 'Your consent record' card at /legal, use the unsubscribe link in any message, or email admin@vanillax.co

(3) You may act through a legal representative or an authorised agent. In that case a power of attorney in the form of Annex 11 to the Notice on Personal Information Processing Methods must be submitted.

(4) Access and suspension requests may be restricted where the law allows, and data that another law requires us to collect cannot be deleted. We tell you the reason if that happens.

Article 10 (Cookies and other automatic collection)

(1) We use only the cookies the Service needs to work. We use no advertising or behavioural-profiling cookies and no third-party tracking scripts.

Cookies in use
  • Cookie
    sb-access-token · sb-refresh-token
    Purpose
    Keeps you signed in (session authentication)
    Lifetime
    Until the session expires or you sign out
  • Cookie
    dodam_locale
    Purpose
    Remembers your interface language (English or Korean)
    Lifetime
    1 year
  • Cookie
    dodam_org
    Purpose
    Remembers the organization you last selected
    Lifetime
    1 year

(2) You can refuse cookies in your browser settings. Refusing the authentication cookies means you cannot stay signed in, and the Service cannot be used.

(3) For example — Chrome: Settings › Privacy and security › Third-party cookies; Safari: Settings › Privacy › Block cookies; Edge: Settings › Cookies and site permissions.

Article 11 (Security measures)

We take the following measures to keep personal data safe.

  1. 1.Organisational: an internal management plan, the smallest possible number of staff handling personal data, separated access rights, and regular training.
  2. 2.Technical: access-right management, row-level security in the database so organizations are isolated from each other, one-way password hashing, TLS in transit and encryption at rest.
  3. 3.Access control: uploads are stored in a private bucket and can be opened only through short-lived signed URLs.
  4. 4.Log retention: access logs of the personal-data processing system are kept for at least 3 months and protected against tampering.
  5. 5.Physical: we follow the data-centre security policies of our cloud providers and operate no server room of our own.

Article 12 (Privacy officer and access requests)

(1) The Company designates a privacy officer to oversee personal data processing and to handle complaints and remedies for data subjects.

Privacy officer
  • Item
    Name and title
    Detail
    {{개인정보보호책임자}}
  • Item
    Team
    Detail
    VanillaX Inc. Operations
  • Item
    Email
    Detail
    admin@vanillax.co
  • Item
    Phone
    Detail
    +82 10-4953-0235
  • Item
    Address
    Detail
    Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea

(2) Requests for access, correction, deletion or suspension go to the same contact. We act immediately on receipt and report the outcome within 10 days.

Article 13 (Where to seek redress)

You may apply to the following bodies for mediation or advice about a privacy infringement. They are independent of the Company; use them if you are not satisfied with our handling or need further help.

Redress bodies
  • Body
    Personal Information Dispute Mediation Committee
    Role
    Privacy dispute mediation, collective mediation
    Phone
    +82-1833-6972
    Website
    www.kopico.go.kr
  • Body
    Privacy Infringement Report Centre (KISA)
    Role
    Reporting infringements, advice
    Phone
    118 (in Korea)
    Website
    privacy.kisa.or.kr
  • Body
    Supreme Prosecutors' Office, Cyber Investigation Division
    Role
    Criminal investigation of privacy offences
    Phone
    1301 (in Korea)
    Website
    www.spo.go.kr
  • Body
    Korean National Police Agency, Cyber Bureau
    Role
    Criminal investigation of privacy offences
    Phone
    182 (in Korea)
    Website
    ecrm.police.go.kr

If your rights or interests are harmed by a disposition or omission by the Company in response to a request under PIPA Articles 35 (access), 36 (correction or deletion) or 37 (suspension), you may also file an administrative appeal under the Administrative Appeals Act. (Central Administrative Appeals Commission, 110 in Korea, www.simpan.go.kr)

Article 14 (Changes to this Policy)

(1) This Policy applies from its effective date. Additions, deletions or corrections are announced inside the Service at least 7 days beforehand, or at least 30 days beforehand where user rights change materially.

(2) Earlier versions are available on request. The change history is as follows.

Change history
  • Version
    1.0
    Effective
    2026-09-03
    Change
    First published
  • Version 1.0First published

Other terms and policies that apply together with this document.

Questions

Send questions or correction requests about these documents to the address below. We reply within 3 business days.

admin@vanillax.co

VanillaX Inc. · Room 801, 8F Woochang Plaza, 295 Cheonho-daero, Dongdaemun-gu, Seoul, Republic of Korea