Privacy Notice
Last updated: 19 August 2026
DAMSORA is operated from the Republic of Korea. This notice explains how we collect, use, share, and protect your personal data. Our processing is primarily governed by the Korean Personal Information Protection Act (PIPA). Region-specific notices for users in the EEA/UK (Section 10) and Japan (Section 11) appear at the end of this document.
1. Who We Are
Service Operator: DAMSORA (담소라)
Representatives: Sehyun Park, Junhwi Nam
Business Registration No.: 813-16-02934
Business Address: 113-dong 2002-ho, 311 Anyangcheonseo-ro, Manan-gu, Anyang-si, Gyeonggi-do, Republic of Korea
Phone: +82-50-6929-4289
Privacy Contact: support@damsora.com
Under Article 30-3 of the amended Korean PIPA (effective 11 September 2026), our representatives are designated as the ultimate parties responsible for personal information protection.
2. Data We Collect and Why
| Data | Purpose | Required? |
|---|---|---|
| Name, email, date of birth, password | Account creation and authentication | Required |
| Google account ID, email | Social login (OAuth) | Required if using Google sign-in |
| Payment records (handled by our payment provider; no card data stored by us) | Subscription billing and refunds | Required for paid plans |
| Session records, reviews, learning notes, time-zone | Core service delivery | Auto-generated by service use |
| Partner display name, bio, profile photo, intro video, specialty tags | Partner application and profile listing | Required for partner applicants (video optional) |
| Support inquiry content, attached photos (up to 3) | Customer support | Required when contacting support (photos optional) |
| Push notification token, device platform (iOS/Android) | Mobile app notifications | Optional (only if you enable notifications) |
| IP address, browser type, access logs | Security, abuse prevention, statutory log keeping | Auto-collected |
| Analytics data (anonymised) | Service improvement | Optional (consent-based) |
| Marketing preferences | Promotional communications | Optional (consent-based) |
Video Session Quality Metadata (Service improvement & dispute resolution)
We collect the following metadata to analyse video call quality, ensure accurate session completion / incompletion judgements, and provide objective evidence in the event of a dispute. This metadata does not include the audio or video content of the call itself.
- Join / leave timestamps and counts
- Co-presence duration (time both participants were in the session together)
- Disconnect and reconnect counts
- Average RTT (Round-Trip Time, network latency)
- Packet loss rate
- Media device (camera / microphone) error messages
- Audio / video active time
Resident Registration Numbers (Korean Partners only)
To comply with Korean tax law (withholding, tax payment and payment-statement filing under the Income Tax Act, Articles 127, 128, 164 and 164-3), we process the resident registration number of Partners who receive payouts, on the legal basis of Article 24-2(1)1 of the Personal Information Protection Act. This applies to payout-receiving Partners only — never to learners. The number is stored encrypted (Article 24-2(2)), used solely for withholding and tax filing, and destroyed after the statutory retention period (5 years under the Framework Act on National Taxes). Collection begins on September 16, 2026 (the effective date of withholding-based payouts) through the payout settings screen, as announced to Partners in advance.
3. Data Retention and Deletion
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (name, email, date of birth) | 30 days after account deletion, then deleted | Service contract |
| Payment & session records | 5 years after account deletion, then anonymised | Korean E-Commerce Act §6 |
| Support inquiries | 3 years after account deletion, then deleted | Consumer dispute resolution |
| Video call connection logs | 3 years after account deletion, then anonymised | Dispute defence (PIPA §15(1)(4)) |
| Community posts & comments | Author anonymised 3 years after deletion; content retained | Service operation |
| Access logs (IP, browser) | 3 months | Korean Communications Privacy Act |
| Video session media | Deleted at session end | Contract performance |
| Session event log (session_events) | 6 months, then anonymised | Statistics & quality analysis, dispute resolution |
| Session participation summary (session_participants) | 1 year, then anonymised | No-show pattern detection, analytics |
| Error diagnostics (personal data masked) | 90 days once resolved, 180 days maximum | Service stability |
| Push notification tokens | Deleted immediately upon account deletion | Service provision (notifications) |
Payment identifiers (transaction ID, subscription ID) are deleted from our database 5 years after account deletion. Records held by the payment provider itself are subject to that provider's own privacy policy.
Deletion procedure and method
Personal data whose retention period has expired is automatically purged from the database row (or the identifier column is replaced with random values for anonymisation) via a scheduled batch job. Records that must be retained under applicable law (e.g. payment and withdrawal records) are moved to a separate retention area and deleted once the statutory period ends. Database backups are rotated and discarded within 30 days; any paper printouts are shredded or incinerated.
4. Sharing, Processors and International Transfers
We do not sell or rent your personal data. We do share data with the following processors strictly to operate the service. Because our infrastructure is global, your data may be processed outside your country of residence. Transfers are protected by data processing agreements with each provider and (where applicable) safeguards such as EU standard contractual clauses (SCCs) or the provider's EU-U.S. Data Privacy Framework certification.
| Processor | Country | Purpose | Data Transferred |
|---|---|---|---|
| Supabase, Inc. | USA | Database & authentication | Account data, service records |
| Payment service provider (being selected) | To be announced | Payment processing — the provider will be named in this notice before payment features go live | Payment records |
| Resend, Inc. | USA | Transactional email delivery | Email, name |
| Vercel, Inc. | USA | Service hosting and edge delivery | IP address, request logs |
| Google LLC | USA | Social login (OAuth) and analytics | Email, Google ID, anonymised usage |
| LiveKit, Inc. | USA | Video call infrastructure | Real-time audio/video stream |
| Cloudflare, Inc. | USA | File storage and delivery (CDN) | Profile photos, intro videos, support attachments |
| Expo (650 Industries, Inc.) | USA | Mobile push notification delivery | Push tokens, notification title/body |
When you play a partner's intro video in our mobile app, the YouTube player (Google LLC) is loaded and Google may collect your IP address and related connection data directly. That processing is governed by Google's own privacy policy.
If you do not consent to these transfers, the service may be unavailable to you. For questions about international transfers, email support@damsora.com.
5. Your Rights
You can exercise the following rights with respect to your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data (also available directly on My Page).
- Erasure — request deletion of your account and associated data.
- Restriction — ask us to suspend processing of your data.
- Data portability — receive your data in a structured, machine-readable format (JSON/CSV). This corresponds to the right to data transfer under Korean PIPA §35-2.
- Withdraw consent — at any time for processing based on consent (e.g. marketing). Withdrawal does not affect prior processing.
- Account closure — via My Page → Account Settings.
To exercise any right, email support@damsora.com. We respond within 10 days where required by Korean law, and within 30 days at the latest. You may also contact the Korea Internet & Security Agency (KISA) at privacy.kisa.or.kr (call 118 from within Korea) or your local data protection authority if you wish to lodge a complaint.
5-bis. Automated Decisions and Your Rights
Pursuant to Article 37-2 of the Korean Personal Information Protection Act, we operate the following automated decisions and guarantee you the rights to refuse, demand explanation, and request human review.
1. Automated decisions in operation
- Session completion / incompletion judgement — When a session ends, a LiveKit webhook measures the time during which both participants' cameras were simultaneously active (camera overlap). If the overlap reaches 80% of the scheduled session length, the session is judged completed and the partner receives compensation. If the overlap falls below 80% or no join events were recorded, the session is judged incomplete: the learner's credit is refunded and no compensation is paid to the partner.
- 24-hour auto-finalisation — If no dispute is raised within 24 hours after a session ends, a scheduled job (cron) automatically finalises the judgement above.
- Automated no-show classification — If one party fails to join within 5 minutes of the scheduled start time, or if neither party has any join record, the session is automatically classified as a no-show based on a cross-reference of multiple sources (LiveKit webhooks, client-side telemetry, and an administrative cron job).
- Automatic credit refund / forfeiture — Based on the automated judgements above, the learner's credit is automatically refunded or kept in a forfeited state, and the partner's compensation is either paid out or withheld.
2. Your rights
- Right to refuse — refuse the application of the automated decision where it has a significant impact on your rights or obligations.
- Right to explanation — request an explanation of the criteria (e.g. the 80% overlap threshold) and the procedure used.
- Right to human intervention — request manual review by our staff.
3. How to exercise these rights
Within 24 hours of the session end, email support@damsora.com stating the session ID and the reason. Our staff will review the LiveKit logs and session records manually within 10 days and notify you of the outcome. Unless there is a justified reason, we will not apply the automated decision or will correct it accordingly.
6. Security Measures
- Password hashing with bcrypt (handled by Supabase Auth)
- Encryption in transit via HTTPS/TLS
- Database access control via Row Level Security (RLS); administrative service-role keys are isolated
- Card information is never stored on our servers — payment data is handled solely by our payment service provider
7. Cookies
We use essential cookies for login sessions and, with your consent, analytics cookies (Google Analytics). For details and how to manage your preferences (including how to opt out of behavioural tracking and reset advertising identifiers), see our Cookie Policy.
8. Children
Our service is not directed to persons under 16. We verify date of birth at sign-up and block under-16 registration. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
9. Changes to This Notice
We may update this notice to reflect changes in law or our services. Material changes will be communicated at least 30 days in advance via in-app notice or email. The latest version is always available at this page.
10. Notice for Users in the EEA and the United Kingdom (GDPR)
If you are located in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data, and the following additional information supplements this notice. DAMSORA is the data controller; contact details are set out in Section 1. We have not appointed a Data Protection Officer or an EU/UK representative (Art. 27) at this stage — for all privacy matters, please contact us directly at support@damsora.com.
Legal bases for processing (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the service — account, session booking, video calls, credits, partner profiles, customer support | Performance of a contract (Art. 6(1)(b)) |
| Billing records and statutory record-keeping | Legal obligation (Art. 6(1)(c)) and contract |
| Security, fraud and abuse prevention, session-quality metadata, dispute evidence, error diagnostics | Legitimate interests (Art. 6(1)(f)) — keeping the platform safe and resolving disputes fairly |
| Marketing communications and analytics cookies | Consent (Art. 6(1)(a)) — withdrawable at any time |
We do not intentionally collect special categories of personal data (Art. 9 GDPR), and we do not use your data for profiling that produces legal or similarly significant effects other than the session judgements described in Section 5-bis.
International transfers
Your data is processed in the Republic of Korea, a country covered by an EU adequacy decision (and deemed adequate under UK law). Onward transfers to the processors listed in Section 4 (USA, UK) are protected by SCCs, adequacy decisions, or the provider's EU-U.S. Data Privacy Framework certification, as applicable.
Your GDPR rights
In addition to the rights in Section 5, you have the right to object to processing based on legitimate interests and to object at any time to direct marketing (Art. 21), the right to restrict processing (Art. 18), the right to data portability (Art. 20), and the right not to be subject to a solely automated decision with legal or similarly significant effects (Art. 22 — see Section 5-bis for the automated decisions we operate and how to obtain human review). We respond to requests within one month. You may also lodge a complaint with the supervisory authority of your country of residence (see the EDPB member list or, in the UK, the ICO), or with the Korean Personal Information Protection Commission.
Children
Consistent with Art. 8 GDPR, our service is not offered to anyone under 16, and we verify age at sign-up (see Section 8).
11. Notice for Users in Japan (日本のお客様向け)
Pursuant to the Japanese Act on the Protection of Personal Information (個人情報保護法) and the Act on Specified Commercial Transactions (特定商取引法), DAMSORA — operating from the Republic of Korea — provides the following disclosures to Japanese consumers:
- The service operator and contact information are as set out in Section 1 above.
- Payments are processed through a payment service provider designated by DAMSORA; the provider will be disclosed before payment features go live.
- Subscription terms, cancellation, and refund conditions are set out in the Terms of Service.
- For privacy inquiries, contact support@damsora.com.
日本のお客様からの個人情報に関するお問い合わせは、上記アドレスまで英語または韓国語でご連絡ください。
12. Contact
Data Protection Contact: Sehyun Park
Email: support@damsora.com
