Last updated: August 8, 2026
Enable Inc. (μ£Όμνμ¬ μ΄λ€μ΄λΈ, "Company" or "we") operates CloudGallery (the "Service"). This Privacy Notice describes how we collect, use, disclose, and protect your personal information when you use the Service. This Privacy Notice is published in accordance with the Personal Information Protection Act of the Republic of Korea (κ°μΈμ 보 보νΈλ², "PIPA").
We process your personal information for the following purposes: (a) Account creation and management β providing access to the Service, authentication, and account administration. (b) Service provision β storing and managing artwork metadata, images, exhibition data, and contact information you enter. (c) Communication β sending service notifications, trial expiration notices, and responding to inquiries. (d) Security β monitoring unauthorized access, fraud detection, rate limiting, and audit trail maintenance. (e) Service improvement β analyzing usage patterns for bug fixes and feature development.
3.1 Account Information. When you register: email address (account identifier), bcrypt-hashed password (plaintext is never stored), name, preferred language (Korean or English), account role, and workspace information. 3.2 Usage and Security Data. When you use the Service: IP address, user agent string, login timestamps, session identifiers, API request metadata (method, path, status code, duration). Authentication events (login attempts, OTP requests, password reset requests) are logged with your IP address and email for security monitoring, brute-force detection, and audit trail purposes. Security logs are retained for 90 days. 3.3 Content Data. Artwork metadata, images, exhibition information, and contact records you create and manage within the Service. 3.4 Email Communication. Records of emails sent to and from you (recipient address, subject, status, timestamp).
4.1 Active Accounts. Your personal information is retained while your account is active. 4.2 Security Logs. Audit event logs (IP address, email, event type, timestamp) are retained for 90 days for security monitoring and abuse prevention, then automatically deleted. 4.3 Account Deletion. You may request account deletion at any time via email. Upon deletion, your user records, artwork data, and associated content are permanently removed. Audit log entries referencing your account are anonymized to preserve audit integrity. 4.4 Session Data. Session tokens expire and are periodically cleaned up. 4.5 Legal Retention. Where retention is required by law, data is retained for the period specified by the relevant statute.
Under PIPA, you have the following rights: (a) Right to access your personal information. (b) Right to request correction of inaccurate personal information. (c) Right to request deletion of your personal information. (d) Right to withdraw consent to processing at any time. To exercise these rights, contact gracehahmart@gmail.com. We will respond within 30 days. If we refuse your request, we will inform you of the reason and your right to file a complaint with the supervisory authority.
We provide the following personal information to third-party service providers for the purposes described: (a) AI Providers (Ollama Cloud, AtlasCloud) β artwork image URLs and analysis prompts are sent for AI-powered analysis and image enhancement. No account credentials or personal information other than image data is transmitted. (b) Cloudflare R2 β artwork images are stored in Cloudflare R2 (US region) for CDN delivery. (c) Gmail SMTP β email address and email content for sending service notifications and contact form submissions. We do not sell, rent, or share your personal information for marketing or advertising purposes.
The following personal information processing functions are consigned to third parties: (a) Cloud image storage β Cloudflare R2 (S3-compatible, US region). (b) Session storage β Redis (in-memory, self-hosted). (c) AI processing β Ollama Cloud and AtlasCloud (image data only). (d) Email delivery β Gmail SMTP. Each consignee is bound by appropriate data processing agreements.
Personal information is destroyed when: (a) The retention period expires or the processing purpose is achieved. (b) You request account deletion. (c) The Service is terminated. Destruction is performed by permanent deletion from the database and associated storage. Backups containing the data are overwritten within 3 days. Audit log entries are anonymized rather than deleted to preserve audit integrity.
Your personal information may be transferred to and processed in the following countries: (a) United States β Cloudflare R2 (image storage), AtlasCloud (AI image processing), Ollama Cloud (AI vision analysis), Gmail SMTP (email delivery). (b) The destination country, recipient name, transferred data items, purpose, and retention period are as described in the relevant sections above. (c) You may refuse cross-border transfer by contacting gracehahmart@gmail.com. However, refusing transfer may limit your ability to use certain features of the Service.
We implement the following security measures to protect your personal information: (a) Password hashing β all passwords are hashed with bcrypt before storage. (b) Encryption in transit β all connections use TLS 1.2/1.3 via Let's Encrypt certificates. (c) Session security β session tokens stored in Redis with automatic expiration. (d) CSRF protection β all forms are protected with CSRF tokens. (e) Rate limiting β API endpoints are rate-limited to prevent abuse. (f) Access control β role-based access control within each workspace. (g) Security headers β Content-Security-Policy, X-Frame-Options, X-Content-Type-Options applied. Despite these measures, no method of transmission or storage is 100% secure.
Designated Privacy Protection Officer (κ°μΈμ 보 보νΈμ± μμ): Title: Privacy Protection Officer, Email: gracehahmart@gmail.com. The Privacy Protection Officer is responsible for overseeing the handling of personal information and responding to data subject requests.
If you believe your personal information has been infringed, you may report it to the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center: Phone: 1336 (toll-free), Website: privacy.kisa.or.kr. You may also file a complaint with the Personal Information Protection Commission (PIPC): Website: pipc.go.kr.
We may update this Privacy Notice from time to time. Material changes will be posted on this page with an updated revision date. Continued use of the Service after changes constitutes acceptance of the updated Privacy Notice.
For questions, concerns, or requests regarding this Privacy Notice or your personal information, contact: Privacy Protection Officer, Enable Inc. (μ£Όμνμ¬ μ΄λ€μ΄λΈ), Business Registration No. 377-86-04287, Email: gracehahmart@gmail.com
Card registration for subscription billing is handled by Toss Payments (ν μ€νμ΄λ¨ΌμΈ ), a licensed payment gateway provider under Korea's Electronic Financial Transactions Act. CloudGallery does not store full card numbers, expiration dates, or security codes (CVC/CVV). We store only masked card display information (e.g., "Card ending 1234") and payment gateway-issued billing tokens that cannot be reversed to obtain your card data. Payment transaction records (amount, date, status) are retained for 5 years as required by the Electronic Commerce Act. Real-name identity verification (λ³ΈμΈμΈμ¦) is performed by Toss Payments during the card registration process, not by CloudGallery. You can request deletion of your registered card at any time by contacting us or removing it from your account settings.