Privacy Policy
This English version is provided for convenience only. The Korean version of this document is the authoritative text.
Effective: August 6, 2026 Operator: Walrus Lab (CEO: Jungmin Han, Business Registration No.: 399-56-00926, Address: 17 Mandeok-daero, Buk-gu, Busan, Republic of Korea) Contact: attacca@walruslab.org
Pursuant to Article 30 of the Personal Information Protection Act, Walrus Lab (the "Company") establishes and publishes the following privacy policy in order to protect users' personal information and to promptly handle related complaints.
Article 1 (General)
- The Company processes users' personal information in accordance with the Personal Information Protection Act and applicable laws, and guarantees data subjects' right to self-determination over their personal information.
- This policy applies to the artificial intelligence (AI) agent service "Attacca" operated by the Company (websites attacca.cc / app.attacca.io, hereinafter the "Service").
- Matters not set forth in this policy are governed by applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, and by the Company's Terms of Service.
Article 2 (Items of Personal Information Collected and Methods of Collection)
The Company collects the following personal information in order to provide the Service. In principle, the Company does not collect sensitive information (health, beliefs, political opinions, etc.).
| Category | Items collected | Method |
|---|---|---|
| Account registration & service use (required) | Email (login ID), password | Entered directly by the user at sign-up |
| Account registration & service use (optional) | Name/nickname, profile image | Entered directly by the user |
| Waitlist | Email, language (locale), referral source, referral code, marketing consent | Entered directly when applying to the waitlist |
| Information generated and collected during use | Conversation (chat) content, uploaded files, projects, documents and long-term memory (user information learned from past conversations), job and sub-agent execution records, plan and billing records, IP address, device and browser information, service usage records (logs), cookies | Automatically generated and collected during service use |
| Payment information | Payment method information such as credit cards, billing information | When paying through a payment gateway (PG); the Company does not directly store the original payment method information |
| Device connection (Zyris node) | Connected device information, records of commands and file access performed on the device | Collected within the scope of nodes the user installs, connects, and grants permission to |
Article 3 (Purposes of Collection and Use of Personal Information)
The Company uses the collected personal information solely for the following purposes.
| Purpose | Items processed |
|---|---|
| Provision of the Service | Conversation and task execution, AI response generation, storage and reuse of long-term memory (personalized responses), sub-agents and the Service's own computer, features such as projects, documents, Kanban, and scheduled jobs |
| Provision of device connection services | Access to and work on the files, terminals, etc. of nodes (devices) connected by the user, within the scope permitted by the user |
| Member management | Registration and authentication, account management, account termination, prevention of duplicate registration and fraudulent use |
| Billing | Subscription plan payment and settlement, receipt issuance, management of overdue and unpaid fees |
| Customer support and complaints | Handling inquiries and complaints |
| Marketing and notices | Informational emails such as waitlist news and product updates; advertising messages (with separate consent) |
| Service improvement and development | Usage statistics analysis, service quality improvement, new feature development, incident response |
Article 4 (Retention and Use Period of Personal Information)
In principle, the Company destroys personal information without delay once the purpose of collection and use has been achieved (account termination, deletion request, etc.). However, where retention is required by applicable law, the information is retained for the following periods.
| Items retained | Retention period | Legal basis |
|---|---|---|
| Account information, conversation content, long-term memory, uploaded files, projects and documents, work records | Destroyed without delay upon account termination (except items subject to statutory retention obligations) | Article 21 of the Personal Information Protection Act |
| Records of contracts or withdrawal of subscription | 5 years | Article 6 of the E-Commerce Act |
| Records of payment and supply of goods or services | 5 years | Article 6 of the E-Commerce Act |
| Records of consumer complaints or dispute resolution | 3 years | Article 6 of the E-Commerce Act |
| Records of labeling and advertising | 6 months | Article 6 of the E-Commerce Act |
| Access logs (IP, device information, etc.) | 3 months | Article 15-2 of the Protection of Communications Secrets Act |
| Waitlist information | Until the purpose is achieved or the user requests deletion/termination, up to 1 year | Company internal policy |
Article 5 (Provision of Personal Information to Third Parties)
- The Company does not provide users' personal information to third parties. The following cases are excepted:
- Where the user has given prior consent
- Where specially provided by law or where investigative agencies request in accordance with law
- In principle, the Company does not use users' personal information for model training or similar purposes. If user content is to be used for model training or similar purposes, separate consent will be obtained.
Article 6 (Entrustment of Personal Information Processing)
For the smooth provision of the Service, the Company may entrust personal information processing as set out below, and supervises the processors to ensure compliance with the Personal Information Protection Act. Processors may change; any change will be announced by updating this policy.
| Processor | Entrusted work | Items entrusted |
|---|---|---|
| AI model providers (multiple, including overseas providers) | AI response generation | Conversation content, uploaded files, project and document content |
| PortOne (payment gateway) | Payment processing and settlement | Payment method information, billing information |
| Email delivery service | Sending waitlist and informational emails | Email addresses |
※ The Company's service infrastructure (servers and databases) is hosted on the Company's own on-premises servers, and user data is in principle stored and managed directly by the Company.
Article 7 (Overseas Transfer of Personal Information)
- To generate AI responses, conversation content and other data may be transmitted to and processed by model providers located overseas (countries: the United States, etc.). Transmission occurs at the time the user sends a message, and the Company takes the measures required under the overseas transfer provisions of the Personal Information Protection Act.
- When a user uses an API key that the user configured directly (BYOK), the user's conversation content is transmitted directly to the model provider designated by the user, and the management of and responsibility for such transmission lies with the user.
- Details of overseas transfers (country, recipient, timing, method) will be announced through this policy and in-service notices when they change.
Article 8 (Rights of Data Subjects and How to Exercise Them)
- Users may exercise the following rights over their personal information at any time:
- Request access to personal information
- Request correction or deletion of personal information
- Request restriction of processing
- Withdraw consent (account termination, opting out of marketing)
- Rights may be exercised through the in-service settings screen, email (attacca@walruslab.org), or in writing, and the Company will process such requests without delay (in principle within 10 days).
- In principle, the Company does not collect personal information of children under 14, and children under 14 may not use the Service.
Article 9 (Procedure and Method of Destruction of Personal Information)
- The Company destroys personal information without delay once the retention period has elapsed or the purpose of processing has been achieved.
- Personal information in electronic form is destroyed in an irrecoverable manner (physical shredding or incineration of storage media, permanent deletion after encryption, etc.), and paper documents are shredded or incinerated.
- Upon account termination, user data such as conversation content, long-term memory, uploaded files, projects and documents is destroyed without delay, except for items subject to statutory retention obligations.
Article 10 (Measures to Secure the Safety of Personal Information)
Pursuant to Article 29 of the Personal Information Protection Act, the Company takes the following technical, administrative, and physical measures to secure the safety of personal information:
- Establishment and implementation of internal management plans
- Minimization of access authority to personal information and access control
- Encryption of data in transit and at rest (TLS, storage encryption, etc.), encrypted storage of passwords
- Retention of access logs, anti-tampering measures, and regular inspections
- Malware and intrusion prevention and operation of security programs
- Minimization of staff handling personal information and regular training
Article 11 (Automated Decision-Making (AI Processing))
- This Service uses AI technology to generate conversation responses and to automatically perform tasks directed by the user. Personal information may be processed in this process.
- In accordance with Article 37-2 of the Personal Information Protection Act, where a decision made through fully automated processing has a significant impact on a user's rights or obligations, the user may refuse such decision or request an explanation, and the Company will take necessary measures such as reprocessing with human intervention or providing an explanation, unless there are legitimate grounds not to.
- Automated processing in this Service occurs within the scope directed and approved by the user, and work that may have a significant impact (deletion, distribution, payment, etc.) in principle requires user approval. Matters concerning the criteria and procedures of automated decision-making are disclosed through this policy and in-service notices.
Article 12 (Installation and Operation of Automatic Collection Devices and Refusal)
- The Company uses cookies to provide individualized, personalized services. The cookies used are for essential functions of the Service, such as login authentication and session maintenance.
- Users may refuse cookie storage through their browser settings. However, refusing essential cookies may restrict use of some services, such as login.
- If analytical or advertising cookies or similar technologies are introduced, this policy will be updated and announced, and separate consent will be obtained where required.
Article 13 (Privacy Officer and Responsible Department)
The Company designates the following privacy officer and responsible department to oversee personal information processing and to handle data subjects' grievances.
| Classification | Details |
|---|---|
| Privacy officer | Jungmin Han (CEO) |
| Contact | attacca@walruslab.org |
Data subjects may report all privacy-related inquiries, complaints, and grievances arising from service use to the above contact, and the Company will respond to and process them promptly.
Article 14 (Changes to the Privacy Policy)
- This policy may be added to, deleted from, or modified due to changes in laws, policies, or security technology.
- When the Company changes this policy, it will announce the reasons and content from 7 days before the effective date (30 days for changes unfavorable to users) through in-service notices and email.
- If a user does not raise an objection before the amended policy takes effect, the user is deemed to have consented to the change. Users who object may stop using the Service and terminate their accounts.
Article 15 (Remedies for Infringement of Data Subjects' Rights)
If you need to report or consult about a personal information infringement, you may contact the following agencies.
| Agency | Contact |
|---|---|
| Personal Information Infringement Reporting Center (KISA) | 118 |
| Personal Information Dispute Mediation Committee | 1833-6972 |
| Korean National Police Agency Cyber Bureau | 182 |
| Supreme Prosecutors' Office Cyber Investigation Department | 1301 |
Supplementary Provisions
- This policy takes effect on August 6, 2026.