attacca

Privacy Policy

This English version is provided for convenience only. The Korean version of this document is the authoritative text.

Effective: August 6, 2026 Operator: Walrus Lab (CEO: Jungmin Han, Business Registration No.: 399-56-00926, Address: 17 Mandeok-daero, Buk-gu, Busan, Republic of Korea) Contact: attacca@walruslab.org

Pursuant to Article 30 of the Personal Information Protection Act, Walrus Lab (the "Company") establishes and publishes the following privacy policy in order to protect users' personal information and to promptly handle related complaints.


Article 1 (General)

  1. The Company processes users' personal information in accordance with the Personal Information Protection Act and applicable laws, and guarantees data subjects' right to self-determination over their personal information.
  2. This policy applies to the artificial intelligence (AI) agent service "Attacca" operated by the Company (websites attacca.cc / app.attacca.io, hereinafter the "Service").
  3. Matters not set forth in this policy are governed by applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, and by the Company's Terms of Service.

Article 2 (Items of Personal Information Collected and Methods of Collection)

The Company collects the following personal information in order to provide the Service. In principle, the Company does not collect sensitive information (health, beliefs, political opinions, etc.).

CategoryItems collectedMethod
Account registration & service use (required)Email (login ID), passwordEntered directly by the user at sign-up
Account registration & service use (optional)Name/nickname, profile imageEntered directly by the user
WaitlistEmail, language (locale), referral source, referral code, marketing consentEntered directly when applying to the waitlist
Information generated and collected during useConversation (chat) content, uploaded files, projects, documents and long-term memory (user information learned from past conversations), job and sub-agent execution records, plan and billing records, IP address, device and browser information, service usage records (logs), cookiesAutomatically generated and collected during service use
Payment informationPayment method information such as credit cards, billing informationWhen paying through a payment gateway (PG); the Company does not directly store the original payment method information
Device connection (Zyris node)Connected device information, records of commands and file access performed on the deviceCollected within the scope of nodes the user installs, connects, and grants permission to

Article 3 (Purposes of Collection and Use of Personal Information)

The Company uses the collected personal information solely for the following purposes.

PurposeItems processed
Provision of the ServiceConversation and task execution, AI response generation, storage and reuse of long-term memory (personalized responses), sub-agents and the Service's own computer, features such as projects, documents, Kanban, and scheduled jobs
Provision of device connection servicesAccess to and work on the files, terminals, etc. of nodes (devices) connected by the user, within the scope permitted by the user
Member managementRegistration and authentication, account management, account termination, prevention of duplicate registration and fraudulent use
BillingSubscription plan payment and settlement, receipt issuance, management of overdue and unpaid fees
Customer support and complaintsHandling inquiries and complaints
Marketing and noticesInformational emails such as waitlist news and product updates; advertising messages (with separate consent)
Service improvement and developmentUsage statistics analysis, service quality improvement, new feature development, incident response

Article 4 (Retention and Use Period of Personal Information)

In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved (account termination, deletion request, etc.). However, where retention is required by applicable law, the information is retained for the following periods.

Items retainedRetention periodLegal basis
Account information, conversation content, long-term memory, uploaded files, projects and documents, work recordsDestroyed without delay upon account termination (except items subject to statutory retention obligations)Article 21 of the Personal Information Protection Act
Records of contracts or withdrawal of subscription5 yearsArticle 6 of the E-Commerce Act
Records of payment and supply of goods or services5 yearsArticle 6 of the E-Commerce Act
Records of consumer complaints or dispute resolution3 yearsArticle 6 of the E-Commerce Act
Records of labeling and advertising6 monthsArticle 6 of the E-Commerce Act
Access logs (IP, device information, etc.)3 monthsArticle 15-2 of the Protection of Communications Secrets Act
Waitlist informationUntil the purpose is achieved or the user requests deletion/termination, up to 1 yearCompany internal policy

Article 5 (Provision of Personal Information to Third Parties)

  1. The Company does not provide users' personal information to third parties. The following cases are excepted:
    • Where the user has given prior consent
    • Where specially provided by law or where investigative agencies request in accordance with law
  2. In principle, the Company does not use users' personal information for model training or similar purposes. If user content is to be used for model training or similar purposes, separate consent will be obtained.

Article 6 (Entrustment of Personal Information Processing)

For the smooth provision of the Service, the Company may entrust personal information processing as set out below, and supervises the processors to ensure compliance with the Personal Information Protection Act. Processors may change; any change will be announced by updating this policy.

ProcessorEntrusted workItems entrusted
AI model providers (multiple, including overseas providers)AI response generationConversation content, uploaded files, project and document content
PortOne (payment gateway)Payment processing and settlementPayment method information, billing information
Email delivery serviceSending waitlist and informational emailsEmail addresses

※ The Company's service infrastructure (servers and databases) is hosted on the Company's own on-premises servers, and user data is in principle stored and managed directly by the Company.

Article 7 (Overseas Transfer of Personal Information)

  1. To generate AI responses, conversation content and other data may be transmitted to and processed by model providers located overseas (countries: the United States, etc.). Transmission occurs at the time the user sends a message, and the Company takes the measures required under the overseas transfer provisions of the Personal Information Protection Act.
  2. When a user uses an API key that the user configured directly (BYOK), the user's conversation content is transmitted directly to the model provider designated by the user, and the management of and responsibility for such transmission lies with the user.
  3. Details of overseas transfers (country, recipient, timing, method) will be announced through this policy and in-service notices when they change.

Article 8 (Rights of Data Subjects and How to Exercise Them)

  1. Users may exercise the following rights over their personal information at any time:
    • Request access to personal information
    • Request correction or deletion of personal information
    • Request restriction of processing
    • Withdraw consent (account termination, opting out of marketing)
  2. Rights may be exercised through the in-service settings screen, email (attacca@walruslab.org), or in writing, and the Company will process such requests without delay (in principle within 10 days).
  3. In principle, the Company does not collect personal information of children under 14, and children under 14 may not use the Service.

Article 9 (Procedure and Method of Destruction of Personal Information)

  1. The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved.
  2. Personal information in electronic form is destroyed in an irrecoverable manner (physical shredding or incineration of storage media, permanent deletion after encryption, etc.), and paper documents are shredded or incinerated.
  3. Upon account termination, user data such as conversation content, long-term memory, uploaded files, projects and documents is destroyed without delay, except for items subject to statutory retention obligations.

Article 10 (Measures to Secure the Safety of Personal Information)

Pursuant to Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative, and physical measures to secure the safety of personal information:

  • Establishment and implementation of internal management plans
  • Minimization of access authority to personal information and access control
  • Encryption of data in transit and at rest (TLS, storage encryption, etc.), encrypted storage of passwords
  • Retention of access logs, anti-tampering measures, and regular inspections
  • Malware and intrusion prevention and operation of security programs
  • Minimization of staff handling personal information and regular training

Article 11 (Automated Decision-Making (AI Processing))

  1. This Service uses AI technology to generate conversation responses and to automatically perform tasks directed by the user. Personal information may be processed in this process.
  2. In accordance with Article 37-2 of the Personal Information Protection Act, where a decision made through fully automated processing has a significant impact on a user's rights or obligations, the user may refuse such decision or request an explanation, and the Company will take necessary measures such as reprocessing with human intervention or providing an explanation, unless there are legitimate grounds not to.
  3. Automated processing in this Service occurs within the scope directed and approved by the user, and work that may have a significant impact (deletion, distribution, payment, etc.) in principle requires user approval. Matters concerning the criteria and procedures of automated decision-making are disclosed through this policy and in-service notices.

Article 12 (Installation and Operation of Automatic Collection Devices and Refusal)

  1. The Company uses cookies to provide individualized, personalized services. The cookies used are for essential functions of the Service, such as login authentication and session maintenance.
  2. Users may refuse cookie storage through their browser settings. However, refusing essential cookies may restrict use of some services, such as login.
  3. If analytical or advertising cookies or similar technologies are introduced, this policy will be updated and announced, and separate consent will be obtained where required.

Article 13 (Privacy Officer and Responsible Department)

The Company designates the following privacy officer and responsible department to oversee personal information processing and to handle data subjects' grievances.

ClassificationDetails
Privacy officerJungmin Han (CEO)
Contactattacca@walruslab.org

Data subjects may report all privacy-related inquiries, complaints, and grievances arising from service use to the above contact, and the Company will respond to and process them promptly.

Article 14 (Changes to the Privacy Policy)

  1. This policy may be added to, deleted from, or modified due to changes in laws, policies, or security technology.
  2. When the Company changes this policy, it will announce the reasons and content from 7 days before the effective date (30 days for changes unfavorable to users) through in-service notices and email.
  3. If a user does not raise an objection before the amended policy takes effect, the user is deemed to have consented to the change. Users who object may stop using the Service and terminate their accounts.

Article 15 (Remedies for Infringement of Data Subjects' Rights)

If you need to report or consult about a personal information infringement, you may contact the following agencies.

AgencyContact
Personal Information Infringement Reporting Center (KISA)118
Personal Information Dispute Mediation Committee1833-6972
Korean National Police Agency Cyber Bureau182
Supreme Prosecutors' Office Cyber Investigation Department1301

Supplementary Provisions

  1. This policy takes effect on August 6, 2026.