일부 외부 서비스의 국외 이전 관련 정보와 적용 근거는 확인 중입니다. 아래 해당 항목에 표시하며, 확인이 필요한 내용이 남아 있는 문서입니다.
1. 사진과 제목
선택한 사진과 입력한 제목은 브라우저에서 크롭, 카드 편집과 PNG 생성에 사용됩니다. 현재 편집 코드는 사진과 제목을 PAKEL 서버나 Supabase에 전송하지 않으며, 이를 서버나 브라우저의 영구 저장소에 보관하는 기능도 없습니다.
편집 데이터는 페이지 실행 중 브라우저에서 사용합니다. 코드에서 사진 교체·취소와 결과 재생성 시 일부 임시 Blob URL을 해제합니다. 페이지 종료 후의 메모리 정리는 브라우저가 관리하며 물리적 데이터의 즉시 완전 삭제를 보장하지 않습니다. 사용자가 저장한 PNG는 기기에 남고, 직접 삭제할 수 있습니다.
2. 냄새 인기순 집계 · Supabase
인기순 조회에는 빈 요청 본문을 보냅니다. PNG 생성과 결과 미리보기가 성공하면 생성 건마다 만든 무작위 이벤트 UUID인 p_event_id와 선택한 냄새 이름 목록인 p_scents를 Supabase API에 전송합니다. 사진, 제목, 이메일이나 계정 ID는 이 요청에 포함하지 않습니다. UUID는 지속적인 사용자 식별자가 아니라 중복 집계를 방지하기 위한 이벤트 식별자입니다.
집계에는 이벤트 UUID와 서버에서 생성한 기록 시각이 저장됩니다. 선택한 냄새는 항목별 누적 횟수로 집계하며, 현재 집계 구조에는 이벤트별 선택 냄새 목록을 별도로 저장하는 구조가 없습니다. 집계 데이터베이스는 호주 시드니 리전(ap-southeast-2)을 사용합니다. API 접속 과정에서 IP 주소 등 접속 정보가 서비스 제공자에게 처리될 수 있으며, 현재 집계 구조에는 집계 테이블의 IP 저장 항목이 없습니다.
이벤트 UUID와 기록 시각은 7일을 보관 기준으로 합니다. 7일이 지난 기록을 매일 한국시간 오전 3시(GMT 오후 6시)에 삭제하도록 Cron 작업이 등록되어 있습니다. 일일 실행 주기로 인해 삭제는 7일 경과 후 다음 정리 작업까지 지연될 수 있습니다. 냄새별 누적 통계는 이 삭제 대상에 포함되지 않으며 유지됩니다.
정리 작업의 실패나 서비스 일시정지로 삭제가 지연될 수 있으며, 운영자는 이를 확인하여 조치합니다.
Supabase 접속 로그 및 백업 사본의 보관 기간·삭제 조건 확인. DB의 시드니 리전은 확인됐지만 운영 로그·지원 접근 등 모든 처리가 호주에서만 이루어진다고 단정하지 않습니다. 계약·수탁자·처리 국가와 국외 이전의 법적 근거 및 필요한 고지는 별도 확인이 필요합니다.
scent_usage의 냄새별 누적 사용 횟수는 PAKEL 서비스의 통계 기능을 운영하는 동안 유지합니다. 통계 기능이 종료되거나 해당 정보가 더 이상 필요하지 않으면 삭제합니다. 이 보관 기준은 냄새별 누적 통계에 적용하며, 개별 이벤트 UUID와 생성 시각의 7일 초과 정리 기준과는 별개입니다. 개별 이벤트는 매일 한국시간 오전 3시에 7일 초과 기록을 삭제하도록 설정되어 있습니다.
3. 사이트 제공 및 분석 · Cloudflare
운영자가 Cloudflare 대시보드에서 확인한 현재 설정은 Web Analytics 활성화, Bot Fight Mode 비활성화이며, Security Events에는 확인 당시 표시된 이벤트가 없습니다. 이는 해당 화면의 확인 결과이며, Cloudflare가 접속 로그를 수집하지 않거나 네트워크·보안 처리를 수행하지 않는다는 의미가 아닙니다. Web Analytics의 방문·성능 분석과 사이트 제공 과정의 일반적인 네트워크·보안 데이터 처리는 구분됩니다.
PAKEL은 Cloudflare Pages를 통해 제공되며, 운영 사이트에서 Cloudflare Web Analytics 계열 분석 스크립트가 포함된 것을 확인했습니다. 방문 및 페이지 로딩 시간 등 성능 분석에 사용됩니다.
Cloudflare 공식 RUM 문서는 페이지 식별자, 유입 페이지 주소, 방문 페이지 주소와 성능 측정값 등을 처리한다고 설명합니다. RUM은 분석용 쿠키나 localStorage를 사용하지 않으며, HTTP 요청 과정에서 받은 IP 주소는 가까운 데이터센터에서 폐기하고 핵심 데이터베이스나 로그에 저장하지 않는다고 설명합니다. 이는 RUM에 대한 설명으로, 별도의 호스팅·보안 로그에 그대로 적용되는 설명은 아닙니다.
사이트 제공·보안 처리 과정에서는 IP 주소와 요청·접속 관련 정보가 Cloudflare에 처리될 수 있습니다. PAKEL 자체 코드에는 쿠키를 설정하는 코드가 없지만, 보안 기능에 따른 쿠키 사용은 실제 설정 확인이 필요합니다. 데이터가 처리되는 국가도 요청 경로와 서비스 설정에 따라 달라질 수 있습니다. Cloudflare RUM 설명 · Cloudflare 개인정보 정책
확인 중 · 별도 접속 로그 항목, 로그·관련 데이터의 보관 기간과 삭제 절차, 외부 내보내기 및 처리 지역 확인. 확인되지 않은 보관 기간은 명시하지 않습니다. 계약 관계, 위탁·제공 및 국외 이전 관련 법적 근거와 고지 사항도 별도 확인해야 합니다.
4. 언어 설정 · localStorage
선택한 언어를 다음 방문에도 유지하기 위해 브라우저 localStorage의 pakel-language에 ko 또는 en을 저장합니다. 코드상 자동 만료는 없습니다. 브라우저 설정에서 pakel.page의 사이트 데이터를 삭제하면 제거할 수 있습니다. 저장을 차단해도 카드 제작에 이 설정을 필수로 요구하지 않습니다.
5. 저장과 공유
사용자가 공유 기능을 실행하면 완성된 PNG가 운영체제의 공유 메뉴에 전달됩니다. 이후 선택한 앱에서 전송·저장하는 방식은 해당 서비스의 정책을 따릅니다. 저장·공유한 이미지는 사용자가 기기나 해당 앱에서 직접 관리해야 합니다.
6. 보유·삭제와 개인정보 요청
사진과 제목을 서버에 저장하는 기능은 없습니다. 저장한 PNG는 사용자가 기기에서 삭제할 수 있으며 언어 설정은 브라우저의 사이트 데이터 삭제로 제거할 수 있습니다. 생성 이벤트에는 위의 7일 초과 기록 정리 기준을 적용합니다. 냄새별 누적 횟수는 유지되며, 이벤트 삭제가 접속 로그나 백업 사본의 동시 삭제를 의미하지는 않습니다.
개인정보 문의 및 권리 행사
개인정보 문의와 열람·정정·삭제·처리정지 요청은 [email protected]으로 보내 주세요. 이 주소는 개인정보 관련 요청을 접수하는 공식 이메일입니다.
요청 접수. 요청 종류, 확인하려는 내용, 관련 이용 시점 등 알고 있는 정보를 적어 주세요. 사진 원본, 주민등록번호나 신분증 사본은 먼저 보내지 않아도 됩니다.
대상 및 본인 확인. 운영자는 요청 대상 정보가 실제로 보관되어 있는지와 요청자와의 관련성을 확인합니다. 필요한 경우 그 확인에 필요한 최소한의 추가 정보만 요청합니다. 이메일 발신 주소나 이용 시점만으로 특정 생성 기록의 소유자임을 확정하지 않습니다.
확인 가능한 범위에서 처리. 관련 법령과 실제 데이터의 식별 가능성을 검토하여 열람·정정·삭제·처리정지 요청을 처리합니다. 외부 서비스의 로그·백업은 해당 서비스의 기능과 절차를 확인해야 하며, 모든 사본의 즉시 삭제를 약속하지 않습니다.
결과 안내. 요청에 대한 조치 결과를 이메일로 안내합니다. 처리할 수 없거나 추가 확인이 필요한 경우에는 그 사유와 확인 가능한 범위를 설명합니다.
개별 기록을 찾기 어려운 경우
PAKEL에는 사용자 계정이나 지속적인 사용자 식별자가 없으며, 이벤트 UUID는 생성 건마다 만든 값입니다. 현재 이용자가 자신의 이벤트 UUID를 다시 조회하는 기능도 없습니다. 따라서 특정 이용자와 개별 생성 이벤트를 연결하지 못할 수 있습니다. 식별 가능한 기록이 없는 경우 특정 기록을 찾아 열람·정정·삭제하거나 개인별 통계를 분리할 수 있다고 보장하지 않습니다.
냄새 통계는 항목별 누적 횟수이며, 현재 집계 구조에는 각 이벤트와 선택 냄새의 연결을 저장하지 않습니다. 이벤트 UUID를 삭제해도 해당 이벤트가 증가시킨 냄새별 횟수를 정확히 찾아 되돌릴 수 없습니다. 이러한 한계는 요청별로 설명하며, 개인을 식별할 수 없다는 이유로 모든 요청을 일괄 거절하는 방식으로 안내하지 않습니다.
문의 이메일의 처리
이메일을 보내는 경우 발신 이메일 주소, 이메일에 포함한 이름 등 정보와 문의 내용, 수신·회신 시각을 요청 확인 및 답변에 사용합니다. 개인정보 문의는 Gmail을 통해 수신·회신하며, 문의 이메일은 브라우저 안에서만 처리되는 사진 편집 데이터와 별개입니다. 불필요한 개인정보나 사진 원본은 보내지 말아 주세요.
PAKEL 운영자는 문의 이메일과 문의 처리에 관련된 개인정보를 문의 처리 완료 후 30일 이내 삭제하는 것을 운영 기준으로 합니다. 법령상 보존 의무가 있는 경우에는 해당 법령에 따라 별도로 보관할 수 있습니다. 이 기준은 PAKEL이 관리하는 문의 메일과 관련 개인정보에 적용하며, Supabase의 생성 이벤트 UUID·기록 시각에 적용되는 7일 초과 자동 정리 기준과는 별개입니다.
이메일 삭제는 PAKEL이 관리할 수 있는 메일함 및 관련 보관 자료를 대상으로 합니다. Google Gmail 서비스 자체의 백업이나 로그가 같은 시점에 삭제된다는 뜻은 아니며, 해당 사본의 삭제 시점을 PAKEL이 직접 통제하거나 보장하지 않습니다. Google의 일반 보관·삭제 정책은 검토했지만 PAKEL 문의 데이터의 로그·백업별 적용 조건은 아직 미확정입니다. 30일 삭제 기준을 위해 휴지통 영구 삭제와 운영자가 관리하는 답장·첨부파일·별도 사본도 함께 관리합니다.
서비스 운영: PAKEL (개인 운영 프로젝트). 개인정보 문의 담당: PAKEL 운영자. 개인정보 문의 이메일: [email protected]. 운영자 실명은 현재 공개하지 않습니다. 확인 중 · Gmail 자체 백업·로그의 보관·삭제 조건, 계약 관계·처리 지역·국외 이전 관련 사항과 안전한 계정 관리 절차: 확인 필요. 확인 중 · 접속 로그·백업 사본의 보관·삭제 조건, 처리의 법적 근거: 별도 확인과 한국 법률 검토 필요.
외부 서비스 이용·처리위탁·국외 이전
PAKEL 운영자는 개인정보 상담 창구에서 Cloudflare Pages, Supabase, Cloudflare Web Analytics와 Gmail의 해외 처리위탁·보관에 대해 개인정보 보호법 제28조의8 제1항 제3호 요건을 충족하는 경우 개인정보처리방침 공개 방식으로 고지할 수 있다는 안내를 받았습니다. PAKEL은 이 기준에 따라 서비스별 처리 목적과 이전 정보를 아래에 안내합니다. 상담 안내만으로 모든 법적 요건이 충족된다는 뜻은 아니며, 사이트 제공·문의 대응과 통계·분석 목적을 구분합니다. 확인되지 않은 필수 정보는 해당 항목에 표시합니다.
회원가입·회원 인증·회원 탈퇴 기능은 없습니다. 사진과 카드 제목은 브라우저에서 처리합니다. 아래 정보는 PAKEL의 실제 처리와 제공업체의 일반 정책을 구분하며, 확인 중인 필수 항목은 명시합니다.
Gmail · 개인정보 문의
수령자·연락처
실제 계정에 적용되는 계약상 법인명과 개인정보 연락처: 미확정. 일반 Gmail에 Workspace DPA가 적용된다고 가정하지 않습니다.
이전 국가
실제 문의 메일 처리·보관 국가: 미확정.
항목
발신 이메일 주소, 문의 내용과 포함된 개인정보·첨부파일, 수신·회신 시각.
시기·방법
이용자가 문의 이메일을 보내거나 운영자가 답변할 때 Gmail을 통해 수신·전송합니다. 제공자 내부 복제·이전의 상세 범위는 미확정입니다.
목적·위탁 관계
개인정보 문의 접수·답변. 실제 계약에 따른 처리위탁·제공자 자체 처리 구분은 확인 필요.
보유·이용 기간
PAKEL 관리 자료는 문의 처리 완료 후 30일 이내 삭제. 법령상 보존 의무가 있으면 해당 법령에 따라 별도 보관. Google 내부 로그·백업은 일반 정책을 따르며 문의별 확정 삭제일은 확인되지 않았습니다.
한국법상 근거 검토
상담에서 안내받은 제28조의8 제1항 제3호의 고지 방식을 기준으로 문의 접수·답변 목적의 해외 처리를 안내합니다. 실제 계약 관계와 누락된 필수 이전 정보는 확인이 필요합니다.
실제 DB 저장 국가: 호주, 시드니(ap-southeast-2). 공식 문서는 DB 백업도 선택 리전에 위치한다고 설명하지만 실제 백업 생성·보유 조건은 별도입니다. 공식 일반 안내: 로그는 EU 데이터센터, 필요 시 미국 계열사 지원·운영 접근. EU의 구체 국가와 PAKEL의 추가 접근 범위는 미확정이며 법인 소재지와 데이터 저장 국가는 다릅니다.
항목
요청: 이벤트 UUID와 선택 냄새 목록. DB: UUID·서버 생성 시각·냄새별 누적 횟수. 사진·제목·이메일·계정 ID는 집계 요청에 포함하지 않습니다. API 접속 정보는 제공자에게 처리될 수 있습니다.
시기·방법
PNG 생성·미리보기 성공 시 HTTPS API로 전송하고 서버에서 시각과 집계를 기록합니다. 인기순 조회도 API 요청을 사용합니다.
목적·위탁 관계
중복 집계 방지와 인기순 통계 운영. 공개 DPA는 대상 데이터에 대한 처리자 관계를 규정합니다.
보유·이용 기간
이벤트 UUID와 생성 시각은 매일 한국시간 오전 3시에 7일 초과 기록을 정리하도록 설정되어 있습니다. 누적 통계는 통계 기능 운영 중 유지하고 종료·불필요 시 삭제. 제공자 로그·백업은 별도 조건으로 모든 사본에 7일 기준을 적용하지 않습니다.
한국법상 근거 검토
상담에서 안내받은 제28조의8 제1항 제3호의 고지 방식을 기준으로 중복 집계 방지·인기순 통계 목적을 안내합니다. 카드 제작과 통계의 필요성을 구분하며 실제 처리 범위에 대한 요건 충족과 필수 이전 정보는 확인이 필요합니다.
제공업체 일반 정책의 개인정보 항목이 모두 PAKEL에서 실제 수집되는 것은 아닙니다. 위 표는 PAKEL의 요청·저장 항목과 제공업체의 일반 처리를 구분합니다. 문의·국외 처리 거부 의사·처리정지 요청은 [email protected]으로 접수합니다. 운영자는 적용 근거와 가능한 처리 범위를 확인해 결과를 안내하며 모든 해외 처리가 즉시 중단된다고 보장하지 않습니다.
Gmail 문의를 보내지 않으면 해당 문의는 접수되지 않으며 현재 대체 접수 수단은 없습니다. Pages 호스팅 처리를 중단하면 그 경로로 사이트를 제공할 수 없습니다. 선택적 Web Analytics와 Supabase 통계에는 현재 이용자별 전송 거부 스위치가 없습니다. 별도 동의가 필요한 처리라면 동의 전 처리 제한과 거부 방법·효과를 확정해야 합니다. 이 문구는 동의 기능을 대신하지 않습니다.
안전성 조치와 방침 변경
사진과 제목의 서버 전송을 제한하고 통계 요청에는 필요한 항목만 포함합니다. 통계 요청에는 HTTPS를 사용합니다. 개인정보 열람·삭제 등의 요청에는 대상 정보와 요청자의 관련성을 확인하고 필요한 최소한의 정보만 요청합니다.
현재 개인정보처리방침은 홈페이지 하단 링크와 /privacy/ 페이지에서 공개합니다. 변경한 내용은 이 페이지의 한국어·영어 문서와 변경 적용일에 반영합니다. 법령상 별도 고지·동의가 필요한 변경은 페이지 수정만으로 충족된다고 보지 않으며 적용 전에 해당 절차를 확인합니다.
시행일 및 변경 적용일
최초 시행일: .
이번 수정본의 변경 적용일: . 최초 시행일은 유지하며 이번 수정본의 변경 적용일은 위와 같이 별도로 표시합니다.
7. 광고 및 향후 변경
현재 AdSense 등 광고 서비스를 사용하지 않습니다.
광고 도입 전에는 실제 광고 제공자, 쿠키·웹 비콘·IP 주소 등 처리 항목, 이용 목적, 외부 제공·위탁과 국외 이전, 보관 기간 및 맞춤 광고 선택·거부 방법을 확인하고 이 방침을 갱신해야 합니다. 이용 지역과 실제 설정에 따른 고지·동의 요구도 검토해야 합니다.
Privacy policy
How photo editing, usage statistics and browser preferences are handled.
Some international-transfer details and applicable legal grounds remain under review and are identified below. Required information is not yet fully confirmed.
1. Photos and titles
Your selected photo and entered title are used in your browser for cropping, editing and PNG creation. The current editor does not send them to PAKEL servers or Supabase, and has no feature to store them on a server or in persistent browser storage.
Editing data is used while the page is running. The code releases some temporary Blob URLs when replacing or cancelling photos and generating another result. The browser manages memory after the page closes; immediate, complete physical erasure is not guaranteed. PNGs you save remain on your device and can be deleted there.
2. Scent popularity · Supabase
Popularity queries send an empty request body. After successful PNG creation and result preview, PAKEL sends a random event UUID, p_event_id, and selected scent names, p_scents, to the Supabase API. Photos, titles, email addresses and account IDs are not included. A new UUID is generated for each creation to prevent duplicate counting; it is not a persistent user identifier.
The statistics store the event UUID and a server-generated timestamp. Selected scents contribute to cumulative counts by scent; the current statistics structure does not store a separate list of selected scents for each event. The database uses the Sydney, Australia region (ap-southeast-2). Connection information such as IP addresses may be processed when the API is accessed. The current statistics structure has no IP-address field in its statistics tables.
Event UUIDs and timestamps have a seven-day retention threshold. A Cron job has been registered to delete records older than seven days daily at 03:00 Korea Standard Time (18:00 GMT). Daily scheduling means deletion may occur at the next cleanup after the seven-day threshold. Cumulative scent counts are excluded from this deletion and retained.
Cleanup failures or service pauses may delay deletion; the operator checks and addresses these situations.
Confirm retention and deletion for Supabase connection logs and backup copies. Sydney is the confirmed database region, but this does not establish that all operational logs and support access are processed only in Australia. Contracts, processors, processing countries, and the legal basis and disclosures for international transfers require separate confirmation.
Cumulative usage counts by scent in scent_usage are retained while PAKEL operates its statistics feature. They are deleted when the feature ends or the information is no longer needed. This retention policy applies to cumulative scent statistics and is separate from the cleanup threshold for individual event UUIDs and creation timestamps older than seven days. Individual events are configured for daily cleanup at 03:00 Korea Standard Time.
3. Hosting and analytics · Cloudflare
The operator confirmed the following Cloudflare dashboard settings: Web Analytics enabled and Bot Fight Mode disabled. Security Events displayed no events at the time of checking. This describes the dashboard observation; it does not establish that Cloudflare collects no connection logs or performs no network or security processing. Web Analytics visit/performance measurement is distinct from general network and security data processing used to provide the site.
PAKEL is served through Cloudflare Pages. A Cloudflare Web Analytics-related script was observed on the live site for visit and performance analytics, including page-load measurements.
Cloudflare's RUM documentation describes processing page identifiers, referring and landing-page URLs and performance metrics. It states that RUM does not use analytics cookies or localStorage and discards the IP address received during HTTP handling at the nearest data center without storing it in core databases or logs. This describes RUM, not all separate hosting and security logs.
IP addresses and request or connection information may be processed for hosting and security. PAKEL's own code does not set cookies; security-feature cookies require verification of actual settings. Processing countries may vary with routing and service settings. Cloudflare RUM documentation · Cloudflare privacy policy
Under review · Verify separate connection-log fields, retention and deletion of logs and related data, exports and processing locations. No unconfirmed retention period is stated. Contracts, processing or disclosure relationships, and international-transfer grounds and disclosures also require review.
4. Language preference · localStorage
The browser stores ko or en in localStorage under pakel-language to remember your language on future visits. There is no automatic expiry in the code. You can remove it by clearing site data for pakel.page in browser settings. The editor does not require storage of this preference to create cards.
5. Saving and sharing
When you use sharing, the finished PNG is passed to the operating system's share menu. Further transmission and storage are handled by the app you choose under its own policies. You manage saved and shared images on your device or in that app.
6. Retention, deletion and privacy requests
There is no server-storage feature for photos or titles. You can delete saved PNGs on your device and remove the language preference by clearing browser site data. Individual events follow the cleanup threshold described above. Cumulative scent counts are retained. Event deletion does not mean that connection logs or backup copies are deleted at the same time.
Privacy inquiries and exercising your rights
Send privacy inquiries and requests for access, correction, deletion or restriction of processing to [email protected]. This is PAKEL's official email address for privacy requests.
Submit your request. Describe the request, the information concerned and any relevant usage time you know. You do not need to send an original photo, national ID number or ID-document copy initially.
Identify the data and requester. The operator checks whether the data is actually retained and whether it can be associated with the requester. Only the minimum additional information necessary for verification will be requested if needed. A sender address or usage time alone does not establish ownership of a generation event.
Handle the identifiable scope. Requests are handled according to applicable law and whether the relevant data can be identified. External-service logs and backups require checking the provider's capabilities and procedures; immediate deletion of every copy is not promised.
Explain the outcome. The operator replies by email with the action taken. If action is unavailable or further verification is necessary, the reason and identifiable scope will be explained.
When individual records cannot be identified
PAKEL has no user accounts or persistent user identifiers. A new event UUID is created for each generation, and users currently cannot retrieve their event UUID through the site. It may therefore be impossible to associate a particular user with an individual event. When no identifiable record exists, locating a specific record for access, correction or deletion, or separating an individual's statistics, cannot be guaranteed.
Scent statistics are cumulative counts by scent. The current statistics structure does not retain a link between each event and its selected scents. Deleting an event UUID does not allow its contribution to each scent count to be located and reversed accurately. These limitations will be explained for each request; this is not a blanket refusal of all requests on the grounds that users cannot be identified.
Privacy inquiry emails
If you email us, the sender's email address, information such as a name included in the message, inquiry content and receipt or reply times are used to review and answer the request. Inquiries are received and answered through Gmail. Inquiry emails are separate from photo-editing data processed only in your browser. Please do not send unnecessary personal information or original photos.
The PAKEL operator uses deletion within 30 days after an inquiry has been resolved as the operational standard for inquiry emails and associated personal information. Where retention is required by law, the information may be retained separately in accordance with that law. This standard applies to inquiry emails and related information managed by PAKEL. It is separate from the cleanup threshold for Supabase generation-event UUIDs and timestamps older than seven days.
Email deletion concerns the mailbox and related retained materials that PAKEL can manage. It does not mean that Google Gmail service backups or logs are deleted at the same time. PAKEL does not directly control or guarantee when those copies are deleted. Google general retention and deletion policies have been reviewed, but applicable conditions for logs and backups containing PAKEL inquiry data remain unconfirmed. The 30-day standard includes permanent deletion from Trash and management of replies, attachments and separate copies.
Service operator: PAKEL (an individually operated project). Privacy inquiries handled by: PAKEL operator. Privacy inquiry email: [email protected]. The operator's real name is not currently disclosed. Under review · Gmail service backup/log retention and deletion, contracts, processing locations and international-transfer requirements, and secure account-management procedures: require confirmation. Under review · Connection-log and backup retention/deletion, legal basis: require separate confirmation and Korean legal review.
External services, processing and international transfers
The operator received guidance from a privacy consultation service that overseas processing or storage involving Cloudflare Pages, Supabase, Cloudflare Web Analytics and Gmail may be disclosed through a published privacy policy when the requirements of Article 28-8(1)(3) of the Korean Personal Information Protection Act are met. PAKEL provides purpose-specific processing and transfer information below on that basis. The guidance does not establish automatic compliance with every legal requirement. Site delivery and inquiry handling are distinguished from statistics and analytics, and unconfirmed required fields are identified.
PAKEL has no registration, member authentication or account-withdrawal feature. Photos and card titles are processed in your browser. The tables distinguish PAKEL processing from provider-wide policies and identify required information still under review.
Gmail · Privacy inquiries
Recipient/contact
Account-specific legal entity and privacy contact: unconfirmed. A Workspace DPA is not assumed to cover general Gmail.
Countries
Actual inquiry-mail processing/storage countries: unconfirmed.
Data
Sender address; message content, included personal information and attachments; receipt/reply times.
Timing/method
When users send inquiries or the operator replies, emails are received/transmitted through Gmail. Internal replication and transfer details are unconfirmed.
Purpose/role
Receiving and answering privacy inquiries. Contract-specific processor versus provider-own-processing roles require confirmation.
Retention
PAKEL-managed materials: deleted within 30 days after resolution, except separate retention required by law. Google internal logs/backups follow general policies; inquiry-specific deletion dates are unconfirmed.
Korean legal basis
Inquiry processing is disclosed using the Article 28-8(1)(3) framework described in the consultation. Actual contractual roles and missing required transfer information still need confirmation.
Actual database storage country: Australia, Sydney (ap-southeast-2). Official guidance places database backups in the selected region; actual backup creation/retention is separate. General official guidance: logs in EU data centers; US affiliate support/operational access when needed. Specific EU countries and additional PAKEL access scope are unconfirmed. Entity domicile is not storage location.
Data
Request: event UUID and selected scents. Database: UUID, server timestamp and cumulative scent counts. No photos, titles, email or account IDs in statistics requests. API connection information may be processed by the provider.
Timing/method
HTTPS API requests after successful PNG generation/preview; server records timestamp/counts. Rankings also use API requests.
Purpose/role
Duplicate prevention and popularity statistics. Public DPA defines processor roles for covered data.
Retention
Event UUIDs and creation timestamps are configured for daily cleanup at 03:00 KST when older than seven days. Cumulative counts retained during statistics operation, deleted when ended/unnecessary. Provider logs/backups are separate; seven days is not a deadline for every copy.
Korean legal basis
Duplicate prevention and popularity statistics are disclosed using the Article 28-8(1)(3) consultation framework. Statistics are distinguished from card creation; applicability to the actual processing scope and required transfer details still need confirmation.
Recipient in obtained materials: Cloudflare, Inc. Contact: [email protected].
Countries
Global network processing. Specific PAKEL request/analytics transfer countries are unconfirmed. US incorporation does not imply US-only storage.
Data
Hosting/network/security: IP addresses and request/connection information. RUM: page identifiers, landing/referring URLs and performance metrics. RUM IP discarding does not describe every other log.
Timing/method
Requests processed through Cloudflare on site access. Enabled RUM scripts transmit visit/performance measurements.
Purpose/role
Pages: hosting/network/security necessary to deliver the site. Web Analytics: visit/performance analysis distinct from card creation. Confirm contract coverage and provider-own-processing roles.
Retention
Past six months of Web Analytics accessible; not a guarantee that all internal data is deleted after six months. General retention depends on purpose/legal obligations; PAKEL-specific blanket log/backup deadlines are unconfirmed.
Settings
Web Analytics enabled; Bot Fight Mode disabled. Security Events displayed no events when checked. This does not establish no logging or no security processing.
Korean legal basis
Pages hosting and Web Analytics visit/performance measurement are disclosed separately using the Article 28-8(1)(3) consultation framework. Analytics is not equated with hosting; actual conditions and any separate notice or consent requirements still need confirmation.
Overseas processing inquiries and refusal requests
Provider-wide personal-data categories do not mean all are actually collected by PAKEL. The tables distinguish PAKEL requests/storage from general provider processing. Send inquiries, objections and restriction requests to [email protected]. The operator assesses applicable grounds and feasible scope and explains the outcome; immediate cessation of all overseas processing is not guaranteed.
Not sending a Gmail inquiry means that inquiry is not received; there is currently no alternative channel. Stopping Pages hosting processing prevents site delivery through that route. Optional Web Analytics and Supabase statistics currently have no per-user transmission opt-out switch. Where separate consent is required, processing limits before consent and refusal methods/effects must be established. This text does not replace a consent mechanism.
Safeguards and policy updates
The editor does not send photos or titles to a server, and statistics requests include only necessary fields and use HTTPS. For privacy requests, the operator checks the relationship between the requester and the relevant data and requests only the minimum information needed.
The policy is available through the homepage footer and /privacy/. Updates are reflected in the Korean and English text and revision date on this page. Where separate notice or consent is legally required, updating this page alone is not treated as sufficient; the applicable procedure must be checked before the change takes effect.
Effective date and revision date
Original effective date: .
Effective date of this revision: . The revision date is shown separately above. The original effective date remains unchanged.
7. Advertising and future changes
PAKEL does not currently use AdSense or other advertising services.
Before introducing ads, verify the actual providers, cookies, web beacons, IP addresses and other processed data, purposes, third-party processing and international transfers, retention and personalized-ad choices. Update this policy and review disclosure and consent requirements for the actual settings and visitor locations.