ntriq
Privacy policy
Effective 3 October 2026
This document is based on the Korean original.
1. Information collected and how it is processed
When you sign up by email, your email address and password are sent to Supabase for authentication. Supabase manages your account and login session. If you choose Google or GitHub login, Supabase receives the authentication result and any email address provided by that provider to manage your account and login session. We store the terms of service version, the time you accepted those terms and the applicable privacy policy version in your account.
Gateway customer registration first verifies the signed-in account, then forwards the company name, contact name and email address. A phone number is also forwarded if one is present in the account. If a company or contact name is missing, the email address or another fallback value is used. The resulting customer identifier and API key prefix are stored in the Supabase account information.
When you register a payment card, we send the contact name, email address and mobile phone number saved in the contract holder details to our payment processors to request a billing key for recurring payments. Card details such as the card number are entered directly in the payment processor's window and are not received by us. We store the issued billing key, together with the card issuer name and the last four digits of the card number reported by the payment processor, in the contract information and use them to charge service fees.
API keys entered in the playground and usage screen are held in that screen’s memory. Requests send the key in the X-YAP-Key header through this site’s server to the gateway. The usage screen retrieves gateway usage records to show daily, monthly and per-layer call counts. Transfer volume is shown when recorded by the gateway. API key management retrieves key prefixes, labels, creation and expiry times, and active status.
We receive and store your email address and inquiry on our server to respond to and handle your request. If provided, we also receive your name, company, desired outcome, work environment and additional requirements. Submission identifiers, language, entry page, product, signed-in account identifier, notice version and consent time, and connection identifiers support inquiry management and duplicate prevention. Staff emails sent through Resend include inquiry content and contact details. This route does not send an automatic receipt email to the customer.
We receive and store the email address, industry and chosen topic you submit when joining a waitlist. We also store the version of the consent text you accepted and when, whether you agreed to receive alert emails, and a connection identifier (a hash of your IP address), which we use only to prevent duplicate or abusive sign-ups. We process this information on the basis of your consent (Article 15(1)1 of the Personal Information Protection Act). Alert and launch emails are sent only to those who separately agreed to receive them.
When enabled in the service configuration, Google Analytics measures visits and Sentry processes errors, performance information and session replay records. If conversion pixels are configured and loaded, registration completion events are sent to Meta and Kakao. Authentication cookies maintain login sessions. Intro visit status and sound preferences are kept in browser storage.
2. AI consultation
AI responses are generated by DeepSeek (China). Do not enter names or contact details. Details: Privacy Policy. Before sending the conversation, we automatically mask detected email addresses and phone numbers. Names and contact details in other formats may remain, so please do not enter them in the chat. The reply address entered in the dedicated email field after the consultation is not included in the conversation sent to the AI model. If you do not want this overseas transfer, use the inquiry form instead of starting an AI consultation. You can end an ongoing consultation to stop sending further messages. AI consultation will then be unavailable, but ordinary inquiries remain available. For access, deletion or restriction requests concerning data already sent, contact support@ntriq.co.kr.
| Recipient legal entity | Hangzhou DeepSeek Artificial Intelligence Co., Ltd. |
|---|---|
| Recipient contact | api-service@deepseek.com |
| Destination countries | China |
| Timing and method of transfer | When you request an AI consultation, our server sends data through an encrypted HTTPS API connection as needed to generate responses and consultation summaries. |
| Personal data transferred | Current and previous consultation messages with automatic masking applied. They may still contain names or other information that can identify a person. The reply address from the dedicated email field is not included in these messages. |
| Recipient's purposes of use | Generating the AI responses and summaries requested by the user. Ntriq does not commission separate model training. The provider’s public terms concerning improvement using de-identified data are described separately below. |
| Recipient's retention and use period | The provider’s public policy describes retaining data for as long as needed for the processing purpose and deleting data no longer needed when the period expires or the purpose is fulfilled, subject to legally required retention. This public principle is not a confirmed deletion period for each API request concerning Ntriq customers. |
| How to decline and consequences | If you do not want this overseas transfer, use the inquiry form instead of starting an AI consultation. You can end an ongoing consultation to stop sending further messages. AI consultation will then be unavailable, but ordinary inquiries remain available. For access, deletion or restriction requests concerning data already sent, contact support@ntriq.co.kr. |
| Legal basis for the transfer | Overseas processing delegated as necessary to enter into or perform the AI consultation service requested by the user, with disclosure in this Privacy Policy under Article 28-8(1)(3)(a) of Korea’s Personal Information Protection Act. |
DeepSeek’s public general terms describe using inputs and outputs to maintain and improve its services subject to encryption and de-identification preventing identification of individuals. Ntriq not commissioning training does not guarantee exclusion from all provider training uses.
Based on DeepSeek’s public terms and privacy policy (checked on 2026-09-27).
This notice is based on the provider’s public criteria and API terms. Its consumer privacy policy does not replace Ntriq’s policy for its customers, and this notice does not guarantee fixed API deletion deadlines or exclusion from training.
3. Purposes
Account and authentication data support sign-in and service delivery. Customer registration data, API keys and usage records support API access, key management and usage reporting. Payment method data and payment records support charging service fees, confirming payments and handling payment inquiries. Inquiry and consultation data support responses, request handling, contract discussions and related follow-up inquiries. AI supports response generation and summaries. Consent records show which notice was accepted. Configured measurement and diagnostics features support usage measurement and identification of service problems. Waitlist data is used to register sign-ups, gauge demand by industry and prevent duplicate or abusive sign-ups and, where you agreed to receive emails, to send information about the topic you signed up for and news about service launches and pricing.
4. Retention
Inquiry and AI consultation records are retained for responses and follow-up inquiries for up to three years from the later of the last substantive response activity and consultation closure. If there is no follow-up activity, the submission date is used. Notification retries and administrative edits do not restart this period. Data no longer needed after its purpose is fulfilled is deleted earlier. Account data is deleted when no longer needed following withdrawal or the end of the service relationship. Usage and security records are limited to the scope and duration needed for those purposes. Where the relevant laws apply, contract and payment records are retained separately for five years, consumer complaint and dispute records for three years, and advertising records for six months. These are not mandatory retention periods for every ordinary inquiry. Waitlist data is kept for one year from sign-up; if the trial service is closed earlier, it is destroyed within 30 days of that decision, and on withdrawal of consent without delay. The connection identifier is destroyed 90 days after sign-up. Overseas provider criteria appear in the table below.
5. Deletion procedures and methods
We identify data for deletion when the retention period ends or the processing purpose is fulfilled. Electronic data is deleted so it cannot be recovered or processed so individuals can no longer be identified; paper records are shredded or similarly destroyed. Staff handle omissions and failures in automated processing. Mailboxes, attachments, external copies and backups are managed separately from the company database. Legally retained records are kept separately.
6. External service processing and third-party disclosure
We use Supabase for authentication and accounts, Vercel for hosting, Resend for emails to inquiry staff, and Cloudflare for gateway request delivery and security. Card registration and service fee payments are processed on our behalf by PortOne Korea Corp. (주식회사 코리아포트원, payment integration) and KG Inicis (주식회사 케이지이니시스, card payments and billing key issuance). Transaction records that the payment processors retain themselves under Korean electronic financial transaction laws are governed by their own privacy policies. DeepSeek generates the AI consultation responses and summaries requested by users. For this overseas delegated processing, we disclose the information below under Article 28-8(1)(3)(a) of Korea’s Personal Information Protection Act. We do not sell customer personal information. Uses outside the delegated scope or third-party provision require an appropriate basis and notice for their purpose.
7. Overseas providers and transfers
Based on each provider’s public terms and policies (checked on 2026-09-27). Location descriptions reflect published operations, not a measurement of every request’s complete route.
| Recipient contact | privacy@vercel.com |
|---|---|
| Destination countries | The public DPA identifies the United States as the primary processing location and permits facilities in other countries for service delivery. A Seoul function region does not mean all processing occurs in Korea. |
| Recipient's purposes of use | Website hosting and request processing |
| Personal data transferred | Connection data and account or inquiry data contained in requests, as needed to process them |
| Timing and method of transfer | Data is transmitted over the network when the relevant feature is used or a request is processed. |
| Recipient's retention and use period | The public DPA for Pro and Enterprise provides for deletion of customer data within a commercially reasonable time after termination, except legally required retention. The separate privacy notice retains account and service-use information for as long as needed for its purposes. |
| Legal basis for the transfer | Delegated processing or storage necessary for the site, account services or steps to enter into or perform a contract requested by the user, disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. This basis does not cover independent uses outside those purposes. |
| How to decline and consequences | You may avoid the relevant feature or request that processing stop at support@ntriq.co.kr. Stopping processing may limit the relevant site, account or request-handling feature. |
| Sources | https://vercel.com/legal/dpahttps://vercel.com/legal/privacy-notice |
| Recipient contact | privacy@supabase.io |
|---|---|
| Destination countries | The ntriq project uses the Seoul, Republic of Korea region. The public DPA provides for storage and primary processing in the selected region, with processing elsewhere when needed to deliver services. Singapore is the provider’s corporate location, not this project’s storage region. |
| Recipient's purposes of use | Authentication and account database operation |
| Personal data transferred | Authentication email and credentials, account identifiers, sessions and consent records |
| Timing and method of transfer | Data is transmitted over the network when the relevant feature is used or a request is processed. |
| Recipient's retention and use period | Processing lasts for the contract term, with earlier deletion available through service functions. Under the public DPA, copies of the covered data are deleted after the 30-day return-request period following contract expiry. |
| Legal basis for the transfer | Delegated processing or storage necessary for the site, account services or steps to enter into or perform a contract requested by the user, disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. This basis does not cover independent uses outside those purposes. |
| How to decline and consequences | You may avoid the relevant feature or request that processing stop at support@ntriq.co.kr. Stopping processing may limit the relevant site, account or request-handling feature. |
| Sources | https://supabase.com/legal/customer-resources/data-processing-addendum |
| Recipient contact | privacy@resend.com |
|---|---|
| Destination countries | The public DPA identifies the United States as the primary processing country. An email sending region does not determine every storage location. |
| Recipient's purposes of use | Sending and processing emails that deliver inquiries to our staff |
| Personal data transferred | Recipient and reply addresses, supplied name and company, inquiry content and submission records |
| Timing and method of transfer | Data is transmitted over the network when the relevant feature is used or a request is processed. |
| Recipient's retention and use period | The public DPA provides for processing during the contract and deletion of customer data within 90 days after account termination, unless further retention is required or permitted by law. The 90 days do not run from each email’s sending date. |
| Legal basis for the transfer | Delegated processing or storage necessary for the site, account services or steps to enter into or perform a contract requested by the user, disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. This basis does not cover independent uses outside those purposes. |
| How to decline and consequences | You may avoid the relevant feature or request that processing stop at support@ntriq.co.kr. Stopping processing may limit the relevant site, account or request-handling feature. |
| Sources | https://resend.com/legal/dpa |
| Recipient contact | privacyquestions@cloudflare.com; legal@cloudflare.com |
|---|---|
| Destination countries | The public policy describes primary storage in the United States and the European Economic Area, with transfers and access elsewhere for global operations. This does not mean every transit request is stored in those locations. |
| Recipient's purposes of use | Request delivery, security, performance and availability in front of the gateway |
| Personal data transferred | Connection and request data needed for delivery and security |
| Timing and method of transfer | Data is transmitted over the network when the relevant feature is used or a request is processed. |
| Recipient's retention and use period | The public DPA provides for processing until the earlier of contract termination or the end of the contractual processing need, followed by return or deletion at the customer’s choice, subject to legally required retention. |
| Legal basis for the transfer | Delegated processing or storage necessary for the site, account services or steps to enter into or perform a contract requested by the user, disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act. This basis does not cover independent uses outside those purposes. |
| How to decline and consequences | You may avoid the relevant feature or request that processing stop at support@ntriq.co.kr. Stopping processing may limit the relevant site, account or request-handling feature. |
| Sources | https://www.cloudflare.com/cloudflare-customer-dpa/https://www.cloudflare.com/privacypolicy/ |
| Recipient contact | api-service@deepseek.com |
|---|---|
| Destination countries | China |
| Recipient's purposes of use | Generating the AI responses and summaries requested by the user. Ntriq does not commission separate model training. The provider’s public terms concerning improvement using de-identified data are described separately below. |
| Personal data transferred | Current and previous consultation messages with automatic masking applied. They may still contain names or other information that can identify a person. The reply address from the dedicated email field is not included in these messages. |
| Timing and method of transfer | When you request an AI consultation, our server sends data through an encrypted HTTPS API connection as needed to generate responses and consultation summaries. |
| Recipient's retention and use period | The provider’s public policy describes retaining data for as long as needed for the processing purpose and deleting data no longer needed when the period expires or the purpose is fulfilled, subject to legally required retention. This public principle is not a confirmed deletion period for each API request concerning Ntriq customers. |
| Legal basis for the transfer | Overseas processing delegated as necessary to enter into or perform the AI consultation service requested by the user, with disclosure in this Privacy Policy under Article 28-8(1)(3)(a) of Korea’s Personal Information Protection Act. |
| How to decline and consequences | If you do not want this overseas transfer, use the inquiry form instead of starting an AI consultation. You can end an ongoing consultation to stop sending further messages. AI consultation will then be unavailable, but ordinary inquiries remain available. For access, deletion or restriction requests concerning data already sent, contact support@ntriq.co.kr. |
| Sources | https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.htmlhttps://cdn.deepseek.com/policies/ko-KR/deepseek-privacy-policy.htmlhttps://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html |
8. Contentless operational alerts
Supplementary Discord alerts are limited to a generic new-inquiry notification and a fixed instruction to check the support@ntriq.co.kr mailbox. They do not include customer identifiers, individual record links, summaries, message content or contact details. We do not request separate consent to transfer customer inquiry content for this contentless alert. Previously transmitted records that remain are assessed for retention need and managed for deletion.
9. Cookies and browser storage
Authentication cookies maintain sign-in, while browser storage records intro visits and sound preferences. You can delete or block cookies and stored information through browser settings, which may limit sign-in or other features. Optional measurement functions follow their respective settings and notices.
10. Security measures
Access is assigned to staff who need it for their work, and transmission channels are protected. We manage account and API-key access and investigate security issues. Measures are operated according to the data and services concerned.
11. Your rights
You may request access, correction, deletion or restriction, and withdraw consent for processing based on consent, at support@ntriq.co.kr. After verifying your identity or authority, we handle requests under applicable law and explain any restrictions. The ordinary inquiry form remains available without AI consultation. Requests concerning data already sent are also subject to provider procedures and legal retention exceptions.
12. Policy changes
We update the document version and effective date and explain changes to purposes, providers, retention criteria or other content. Changes requiring fresh consent are handled separately. Earlier consent records are not overwritten with a new version.
13. Privacy contact
Privacy inquiries and rights requests: ntriq customer support, support@ntriq.co.kr. Our business identity, representative and address appear below.
14. Contact
ntriq
Representative Daehwan Kim
Business registration number 790-12-02763
Mail-order business registration No. 2026-Changwon Seongsan-0357
Unit 513, 70 Yongji-ro, Seongsan-gu, Changwon-si, Gyeongsangnam-do 51522, Republic of Korea