Legal
Privacy Notice
Atmark (“the service”) processes personal information in accordance with the Personal Information Protection Act of Korea and other applicable laws. This notice explains what we process, why, and how we protect it.
1. What we collect
Atmark processes only the information it needs to run the service.
- Sign-up email
- The organization owner’s email address, used to sign up and log in. We send service mail such as sign-up confirmations and login links to this address.
- Organization name
- The name you enter at sign-up. Shown in the console and used for operator review.
- Invitee email
- When an organization owner invites someone to their organization, we use that person’s email address to send the invite and their login link.
- HMAC of the requesting IP address
- To detect sign-up and login requests that come too often, we store only a keyed hash of the requesting IP address. The IP address itself is not stored in our database.
- Mail your agents send and receive
- The raw messages and attachments are kept in file storage; metadata such as sender, recipients, subject and time is kept in our database. This includes the email addresses and message content of the people your agents correspond with.
- Audit records
- Actions taken in the console (who did what, when, to which item) and the decisions of the sending gate. Secret values such as tokens are never recorded.
- Access logs
- For security and troubleshooting, server access logs record the request time, path, result and the requesting IP address.
This website (atmark.ai) does not use cookies. The console uses only the cookies it needs to keep you logged in and to confirm the browser that made a request. We use no analytics or advertising cookies and no third-party trackers.
2. Why we process it
- Sign-up, identity confirmation, login and account management
- Sending, receiving and storing your agents’ mail, and letting your agents read it
- Applying receive and send policy (allow and block lists), quarantining and recording blocked inbound mail, and controls such as the kill switch
- Preventing spam, impersonation and abuse, responding to security incidents, and reviewing new organizations
- Service notices and answering your inquiries
3. How long we keep it
We keep personal information until you close your account or the purpose it was collected for has been fulfilled. Where a law requires us to keep it for a set period, we keep it for that period and use it for that purpose only. Retention periods by category:
- Mail bodies
- The raw mail and attachments your agents receive, and the body of mail your agents send, are automatically deleted one year after they are stored. Metadata such as sender, recipients, subject and time, and the sending-gate decision record, are kept separately from the body for as long as needed to run the service.
- Access logs
- Server access logs (request time, path, result, and requesting IP address) are kept for three months and then deleted.
- Invitee email
- If someone is invited but never joins the organization, we erase their email address 30 days after their last invite was revoked or expired.
- Unfinished sign-ups
- If someone requests a sign-up but never uses the confirmation link, we delete the email address and organization name 30 days after the link expired.
- Audit records
- Console actions (who did what, when) and sending-gate decisions never include mail bodies. We keep them until you close your account or we stop running the service.
Two things are kept separately from the periods above.
- Bounce and complaint lists
- Email addresses that bounced permanently or whose recipient marked our mail as spam are kept on a suppression list as the address itself, so that we never send to them again. They stay on this list even after the address is erased elsewhere. Temporary bounces are kept until their set expiry; permanent bounces and spam complaints are kept until removal is requested or we stop running the service.
- Backups
- The database is backed up automatically every day for disaster recovery, and backups are kept for 14 days. Information we have deleted remains in backups for that period and disappears as backups are replaced. Backups are used only to recover from failures.
So that anyone can verify audit records have not been altered after the fact, we are preparing a transparency log that publishes hashes of audit records externally (planned — not yet running). Only hashes are published, never mail content or personal information. Published copies are locked for at least one year so that no one can delete or alter them.
4. Sharing with third parties
Atmark does not provide personal information to third parties, except where a law specifically requires it or an investigative authority requests it through legally prescribed procedures.
Mail your agents send is delivered to the recipients chosen by you and your agents. That is how the service works; it is not Atmark sharing your data.
5. Service providers
We use the following providers to run the service.
- Amazon Web Services, Inc.
- Servers, database and file storage. Data is stored in the AWS Seoul Region (ap-northeast-2).
- Amazon Web Services, Inc. (Amazon SES)
- Sending and receiving email (Seoul Region).
Our agreements with these providers require them to handle personal information securely. If a provider changes, we will update this notice.
6. Your rights
You can ask at any time to access, correct or delete your personal information, or to stop us processing it. Send your request to the contact below; we will verify your identity and act without delay. Information we are legally required to keep may not be deleted, and we will tell you why.
7. Destruction
When the retention period ends or the purpose has been fulfilled, we destroy the information without delay. Electronic files are deleted in a way that cannot be recovered.
8. How we protect it
- Encryption in transit (HTTPS) and at rest
- Least-privilege access split by function — sending, reading and administration run under separate permissions
- A keyed hash instead of raw IP addresses; single-use, short-lived login and sign-up links
- Audit records of console actions and sending decisions
9. Contact
Questions about how we handle personal information, requests to access, correct or delete it, and complaints are handled here.
Contact: support@atmark.ai
You can also report a privacy violation or seek advice from the Korea Internet & Security Agency’s Privacy Infringement Report Center (118, within Korea) or the Personal Information Dispute Mediation Committee (1833-6972).
10. Changes to this notice
This notice applies from September 24, 2026. If it changes, we will post the update on this page before it takes effect.
This English version is provided for convenience. If it differs from the Korean version, the Korean version prevails.