TRIDOT / LEGAL
Privacy Policy
Effective Sep 18, 2026 · Operated by Tridot Inc.
- Effective
- Sep 18, 2026
- Operated by
- Tridot Inc.
- Contact
- hello@tridot.io
Tridot Inc. (the “Company”) establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act of the Republic of Korea (PIPA) to protect the personal information of data subjects and to handle related complaints promptly. This Policy applies to the website tridot.io and the developer portal (developer.tridot.io, tridot.io/portal). The privacy policy for the game “Love, Lies and Memories.” is published at tridot.io/products/llm/privacy-policy, and the policy for the mobile app AVADOT is published in the app and on its store pages.
Article 1 (Purposes of Processing)
The Company processes personal information for the following purposes and, if a purpose changes, takes the necessary measures such as obtaining separate consent under Article 18 of PIPA.
- Responding to inquiries: confirming and replying to inquiries about collaboration, adoption, hiring and similar matters, and following up
- Providing developer accounts and company workspaces: identifying and authenticating members, managing workspace members and roles, sending invitations, notices
- Operating developer services: managing projects and API keys, measuring usage and enforcing limits, responding to incidents, keeping audit records
- Security and prevention of misuse: analysing access records, detecting abnormal use, protecting accounts
- Complying with legal obligations and handling disputes
Article 2 (Items of Personal Information Processed and Collection Methods)
| Category | Items | Collection method |
|---|---|---|
| Inquiry form | (required) name, e-mail (optional) phone, company, position, area of interest, message, language | Entered by the user at tridot.io/demo |
| Developer account | Google account e-mail address, name, profile image URL, Google account identifier, sign-in time | Provided by Google when signing in with Google |
| Company workspace | company name, member e-mails and roles, allowed e-mail domains, invitee e-mail addresses | Entered by the member in the portal |
| Developer services | project names and settings, API key hash and first 12 characters, scopes, API call records (time, service, status code, latency, units), audit records (who changed which setting) | Generated automatically during use. API request and response bodies are not stored |
| Automatic collection | IP address, browser and device information, access time, request path, error information | Generated automatically in hosting logs when the website or portal is accessed |
The Company processes only the minimum personal information needed to provide the Service. It does not collect Google account passwords, and it will collect payment information only after separate notice when paid services are introduced. The Company does not collect personal information from children under 14.
Article 3 (Processing and Retention Periods)
The Company processes and retains personal information within the period required by law or agreed to by the data subject.
| Category | Retention period |
|---|---|
| Inquiry information | 1 year after the reply and any follow-up have ended |
| Developer account and workspace information | Until the member withdraws or the workspace is deleted. Accounts with no sign-in for 3 years are destroyed after prior notice |
| API call records (raw) | 90 days after creation; afterwards only daily aggregates that cannot identify an individual are kept |
| Audit records | 1 year after creation |
| Access records (IP address and similar) | Up to 1 year after creation |
| Retention required by law | The periods set by laws such as the Act on the Consumer Protection in Electronic Commerce (only for the relevant records once paid services are introduced) |
Personal information whose retention period has ended or whose purpose has been achieved is destroyed without delay, except while an investigation is pending or a claim or debt remains outstanding.
Article 4 (Provision to Third Parties)
The Company processes personal information only within the purposes in Article 1 and does not provide it to third parties except with the data subject’s separate consent or where specifically permitted by law, including Articles 17 and 18 of PIPA. There are currently no third-party recipients.
Article 5 (Outsourcing of Processing and Overseas Transfer)
The Company outsources processing as follows to provide the Service. Because the processors are located abroad, the overseas-transfer disclosures required by Article 28-8 of PIPA are given together.
| Processor | Country | Outsourced work | Items transferred | Time and method | Retention |
|---|---|---|---|---|---|
| Vercel Inc. | United States | Website and portal hosting, server processing, access logs | Access records, input passed during processing | Encrypted transmission during use | Until the contract ends (access logs per Article 3) |
| Supabase Inc. | United States (data stored in the Seoul region, Republic of Korea) | Database operation, sign-in authentication | Account, workspace, inquiry and developer-service information | Encrypted transmission and storage during use | Until the contract ends |
| Google LLC | United States | Google account sign-in | Google account e-mail, name, profile identifier | At sign-in | Per Google account policies |
| Resend, Inc. | United States (sending servers in the Tokyo region, Japan) | E-mail delivery (workspace invitations, inquiry notifications) | Recipient e-mail, inquiry content included in the mail | At sending | Short-term provider logs after delivery |
| Slack Technologies, LLC | United States | Internal notification to the Company when an inquiry arrives | Inquiry form items | When an inquiry is received | Until the Company deletes it from the channel |
The legal basis for transfer is Article 28-8(1)(iii) of PIPA (outsourcing and storage necessary to perform a contract with the data subject). The Company’s contracts with processors specify the prohibition of processing beyond the purpose, technical and organisational safeguards, restrictions on sub-processing, supervision and liability, and the Company supervises its processors. Changes to outsourced work or processors are disclosed through this Policy. Data subjects may object to overseas transfer at hello@tridot.io; if they do, services that depend on the processing (portal sign-in, e-mail replies and so on) may be unavailable.
Article 6 (Destruction of Personal Information)
- The Company destroys personal information without delay when it is no longer needed because the retention period has ended or the purpose has been achieved.
- Where another law requires continued retention, the information is moved to a separate database or storage location.
- Electronic files are deleted in a way that prevents recovery; paper documents are shredded or incinerated. Destruction is carried out with the approval of the Privacy Officer.
Article 7 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)
- Data subjects may at any time request access to, correction or deletion of, or suspension of processing of their personal information, and may withdraw consent.
- Requests may be made by e-mail to hello@tridot.io; the Company acts without delay and within the statutory 10 days. Members can edit or delete workspace information and API keys directly in the developer portal.
- Rights may be exercised through a legal representative or an authorised agent, in which case a power of attorney in the form of Annex 11 of the Enforcement Rules of PIPA must be submitted.
- The Company may verify that the requester is the data subject or a lawful agent, and explains the reason where access is restricted by law.
- Data subjects must not infringe the personal information or privacy of others processed by the Company in violation of applicable law.
Article 8 (Measures to Ensure Security)
- Organisational measures: an internal management plan, minimising and training staff who handle personal information, supervision of processors
- Technical measures: role-based access control, row-level access control (RLS) in the database, encryption in transit (TLS), hashed storage of API keys, retention of access records, application of security updates
- Physical measures: use of cloud providers’ physically access-controlled facilities (such as AWS)
Article 9 (Installation, Operation and Refusal of Automatic Collection Devices)
- The Company uses only the authentication cookie that keeps a developer-portal session signed in (Supabase auth session). It does not use advertising or behavioural-analytics cookies or third-party trackers.
- Users can allow or block cookies in their browser settings. Blocking the authentication cookie prevents signing in to the developer portal; the rest of the website remains usable.
- Chrome: Settings > Privacy and security > Third-party cookies
- Safari: Settings > Privacy > Block all cookies
- Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
- The website’s language is selected by URL (/kr) and stores no separate cookie.
Article 10 (Privacy Officer)
- The Company designates the following Privacy Officer to oversee personal-information processing and handle related complaints and remedies.
- Privacy Officer: the Chief Executive Officer
- Department in charge: Operations Team
- Contact: hello@tridot.io
- Data subjects may direct all inquiries, complaints and requests for remedy concerning personal information arising from use of the Service to the contact above; the Company responds and acts without delay.
Article 11 (Requests for Access)
Data subjects may submit requests for access under Article 35 of PIPA to the department in Article 10 (Operations Team, hello@tridot.io). The Company strives to process such requests promptly.
Article 12 (Remedies for Infringement of Rights)
Data subjects may contact the following bodies for remedies and advice regarding infringements of personal information.
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- Personal Information Infringement Report Center: 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301, www.spo.go.kr
- Korean National Police Agency: 182, ecrm.police.go.kr
A person whose rights or interests are infringed by the Company’s disposition or inaction in response to a request under Articles 35 (access), 36 (correction or deletion) or 37 (suspension of processing) of PIPA may file an administrative appeal under the Administrative Appeals Act.
Article 13 (Effect and Amendment of this Policy)
- This Policy takes effect on September 18, 2026 and replaces the “Privacy information” notice in effect since September 11, 2026.
- Changes are announced on the website at least 7 days before they take effect (30 days for changes with a material effect on data subjects’ rights). Previous versions are available on request.
- Business information: Tridot Inc. / Suite 604, 217 Yeoksam-ro, Gangnam-gu, Seoul, Republic of Korea / Business registration no. 372-81-01941
