Required: name, email, request title/content. Optional: company, region. At payment: masked card approval data, transaction ID, amount — we never collect or store full card numbers, CVC, PIN, or expiry. AI agents: wallet public address, on-chain (x402) transaction data. Automatic: IP, access logs, browser language (localStorage).
To receive, generate and deliver advisory requests and provide self-service viewing; to process payment and refunds; to send email notifications; and to handle inquiries and disputes.
Deleted without delay once the purpose is met, except where Korean law requires retention: contract/withdrawal records 5 years, payment records 5 years, consumer-dispute records 3 years (Electronic Commerce Act); access logs 3 months (Protection of Communications Secrets Act).
We entrust processing to: Supabase (DB hosting, US), Render (server hosting, US), Anthropic (AI generation of results, US), Resend / Daou (email, US / Korea), NICE Payments (card payment, Korea), Coinbase CDP facilitator (x402 settlement, US). Request content is sent to AI processing (Anthropic) to generate results; please do not enter sensitive/national-ID data. We apply PII masking.
You may request access, correction, deletion, or suspension of processing at any time. Your results are viewable via a one-time magic link sent to your email. Data Protection Officer: Lee Young-do — ydlee@krsys.net, +82-2-1544-7668.
HTTPS in transit, access controls, secrets kept only in server environment variables (never in code/logs), PII masking, and DID-verified committee integrity measures.