Version 1.3.0 • sha256:129293241703

Privacy Policy

Version: 1.3.0

Effective date: 2026-09-07

Authoritative language: Korean. In case of conflict, the Korean version governs.

Data Protection Officer (CPO): Kang In Wook / privacy@concourse.to / 070-4577-7512

⚠️ This is a draft document. Final review by a Korean medical law and data protection attorney is required before production use. The STRUCTURE of this document (sections, cross-border table, CPO block, intermediary disclaimer, retention periods) reflects PIPA §30 and GDPR Art. 13 requirements.

1. Information We Collect

Concourse Inc. ("Concourse", "we", "our") collects the following categories of information:

1.1 Required data

•Account information: name, email, phone number, nationality, password (hashed)
•Payment information: billing address, PortOne payment token (no full card number stored)
•Usage data: access logs, device information, IP address, cookies

1.2 Sensitive medical data (PIPA §23)

Concourse processes the following sensitive medical data for cross-border dental care matching. Separate explicit consent is required.

•Dental condition and subjective symptoms
•Dental treatment history
•X-ray, CBCT, panoramic imaging
•Intraoral photos
•Medical history, current medications, allergies

1.3 Users under 14

Personal data of users under 14 is collected only with verifiable parental/guardian consent (PIPA §22(6)).

2. Purposes

1.Cross-border patient solicitation intermediation — matching with Korean dental clinics, quote delivery, booking facilitation
2.Service fee billing, settlement, and refunds
3.Concierge services — airport pickup, accommodation guidance, visit coordination
4.Patient-clinic communication via in-app chat
5.Platform safety — fraud prevention, dispute resolution, legal obligations

3. Retention

CategoryPeriodBasis
Account dataUntil account deletionUser consent
Medical images (X-ray, intraoral)**10 years**Korean Medical Act §22, §23
Treatment records10 yearsKorean Medical Act §22
Payment & transaction records5 yearsE-commerce Act §6
Dispute resolution records3 yearsE-commerce Act §6
Access & audit logs3 yearsPIPA Enforcement Decree §48-2
Marketing records6 monthsE-commerce Act §6

Data is destroyed without undue delay once its retention period expires.

4. Data Sharing and Processing Delegation

4.1 Third-Party Sharing

Concourse does not share personal data with third parties except as follows:

•Matched Korean dental clinics: sensitive medical data necessary for consultation, quoting, and treatment
•Legal obligations (law enforcement warrants, court orders)
•With explicit prior user consent

4.2 Delegated Processing (PIPA §26)

Concourse delegates the following processing to a domestic processor. Delegation requires disclosure rather than separate consent, and is disclosed here.

ProcessorDelegated workData involved
PortOne Korea Inc.Payment processing and payment method verificationPayment data (billing address, payment token), name, email address
•Under PIPA §26 the delegation contract restricts processing to the delegated purpose and covers security measures, limits on sub-delegation, and supervision of the processor.
•PortOne routes payments through domestic acquirers (including Toss Payments) and, for international cards, Eximbay.
•Any change to the delegated work or the processor will be disclosed here.
•Processing delegated outside Korea is covered separately in Section 5.

5. Cross-Border Data Transfer

Concourse transfers personal data to the following non-Korean processors. Separate consent is required under PIPA §28-8.

ProcessorCountryPurposeData Categories
Railway (PaaS)미국 / United StatesApplication + database hostingAll application data (encrypted at rest)
Cloudinary미국 / United StatesImage storage + deliveryMedical images (X-rays, dental photos) — AES-256-GCM encrypted
Resend미국 / United StatesTransactional email deliveryEmail address, name, transaction details
Sentry미국 / United StatesError monitoring (PII scrubbed)Error payloads, stack traces (no medical content after Phase 5 scrubbing)
DeepL독일 / Germany (EU)Chat message translationChat message text (ephemeral)
•Transfer method: Real-time transfers over encrypted channels (TLS 1.2 or higher).
•Processor contacts: Available on each processor's official website; Concourse will provide on request.
•Right to refuse: You may refuse cross-border transfer. However, because core services (payments, email, translation) all go through US-based processors, refusing blocks account creation. Existing users may withdraw cross-border consent at any time via "My Data > Withdraw Consent"; some services (email alerts, international payments, auto-translation) will stop.

6. Data Subject Rights

You may exercise the following rights at any time (PIPA §35-39, GDPR Art. 15-22):

1.Right of access — view the personal data we hold about you
2.Right to rectification — correct inaccurate information
3.Right to erasure — request deletion (subject to statutory retention for medical records)
4.Right to restrict processing — pause processing for specific purposes
5.Right to data portability — export in machine-readable format (JSON, PDF)

Exercise these rights via the in-app "My Data" menu or by emailing privacy@concourse.to. We will respond within 30 days (GDPR) or 10 days (PIPA).

7. Security Measures

•Encryption: AES-256-GCM for sensitive data at rest; TLS 1.2+ for data in transit
•Access control: Role-based access, medical files visible only to the patient and matched doctor
•Audit logging: PHI read events retained for 3 years (PIPA §29, Enforcement Decree §48-2)
•Regular security reviews: Quarterly internal security audits
•Designated Data Protection Officer: Kang In Wook

8. Data Breach Notification

In the event of a personal data breach, Concourse will:

•Within 24 hours: Detect, assess scope, notify the CPO
•Within 72 hours: Notify the Personal Information Protection Commission and KISA (PIPA §34)
•Without undue delay: Notify affected users (categories affected, time, response, contact)
•Public disclosure: Post notice on the website

9. Cookies and Similar Technologies

Concourse uses cookies and similar storage technologies (local storage, session storage) to run and improve the service. Essential storage — sign-in session, security, and language preference — cannot be refused, because the service cannot work without it.

9.1 Analytics

Analytics and performance processing (following the pages you visit within one browser session) is your choice, made with an optional checkbox when you create your account. You can change it at any time afterwards under Profile → Preferences. Declining does not limit the service in any way. Your choice is stored in your browser; clearing your browser storage lets you choose again. Before you create an account, we do not do this processing at all.

9.2 Identifier-free record made before you choose

To find out how many people our advertising actually reaches, and how many of them get as far as each step of signing up, we record two facts even before you have made your analytics choice: that the site was opened, once per browser tab, and that the signup screen was opened, submitted and completed.

•What is recorded: the page path (without the query string), the language, the device type (phone, tablet or computer), the country you connect from, the domain of the site you were on immediately before, and any campaign tags carried by the link you followed (utm parameters and similar).
•The country is kept only as a country. It is derived from your IP address, but the IP address itself is never stored — only the country code (for example KR, US). We use it to see whether our advertising actually reaches people outside Korea.
•No identifier is included. This record stores no session identifier, no member identifier and no IP address, so it cannot be linked to your other activity or to an account.
•To keep the same record from being sent twice, a marker is stored in your browser's session storage. It is deleted when you close the tab.
•If you decline analytics when creating your account, we stop making this record as well.

10. Data Protection Officer

•Name: Kang In Wook
•Email: privacy@concourse.to
•Phone: 070-4577-7512

You may also report complaints to:

•Personal Information Infringement Report Center (privacy.kisa.or.kr, 118)
•Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972)

11. Changes to this Policy

Material changes will be announced in-app and via email at least 7 days before they take effect. Continued use after the effective date constitutes acceptance.


Effective date: 2026-09-07

Business information: Concourse Inc. | CEO: Jun Soo Kwon | Address: 11F #124 DD-12, 428 Seolleung-ro, Gangnam-gu, Seoul, Republic of Korea | Business Number: 150-81-04445 | E-commerce Registration: 제2026-서울강남-04415호 / No. 2026-Seoul Gangnam-04415 | Medical Tourism License: 제A-2026-01-01-07132호 (서울특별시) / No. A-2026-01-01-07132 (Seoul Metropolitan Government)