Privacy Policy
How Galpi's public website handles visitor information and email inquiries
Version: 0.2-draft · Prepared and draft published: October 8, 2026 · Final policy effective date: not yet set
1. Scope and operator
This policy applies to the public service introduction website at galpi.space and inquiries received at admin@galpi.space. Galpi is operated by Lee Taekyung (이태경), who is also the privacy contact. Contact: admin@galpi.space.
The current website provides service information and example screens. It does not offer registration, sign-in, manuscript entry, upload or storage, AI generation, point purchases or payments. Before making those features available, we will update the policy and required notices to reflect their actual processing.
2. Information and purposes
| Activity | Information and collection method | Purpose |
|---|---|---|
| Website access | IP address, requested URL, access time, browser and device information, and request headers sent to the web delivery and security provider when accessing the site | Deliver pages and static assets; maintain service availability and security |
| Email inquiries initiated by visitors | Sender email address, any name supplied, subject, message, attachments and correspondence | Review and answer inquiries, handle requests and maintain relevant correspondence |
Please do not send unnecessary national identification numbers, payment information, health information or private manuscripts. There is no required inquiry form, and you can read the website without emailing us. We may be unable to answer or handle an inquiry if necessary contact details or information are missing.
For actions requested during the process of entering a contract, we assess the applicability of Article 15(1)(4) of Korea's Personal Information Protection Act. General inquiries, rights requests and security processing require their respective purposes and legal grounds to be distinguished. [Verification required: confirm the grounds and any required notice or consent for general inquiries and access-security information]
3. Retention and deletion
General inquiry emails and correspondence are retained for no more than 90 days after resolution, then deleted. This covers the related Inbox, Sent and Trash items and copies separately held by the operator. Electronic files are deleted to make recovery difficult; any paper copies are shredded.
If a legal obligation or an actual dispute requires retention, we distinguish the affected records, grounds and period and retain only what is necessary. Payment-record retention periods are not applied to all inquiries.
The public website has no custom visitor database or application request-log storage. Cloudflare Free security analytics and events provide historical records for up to 31 days; this is not a retention limit for every provider record. Other processing under its DPA lasts until the contract ends or processing is no longer needed for contractual obligations. [Verification required: retention and deletion conditions for the remaining visitor records]
Under the Private Email terms, daily server backups are kept for up to four weeks. Email deletion and server-backup expiry are separate; deletion does not guarantee immediate removal from every provider copy. [Verification required: actual conditions for residual mailbox data, backup expiry and support access]
4. Providers and international processing
| Provider | Work performed | Relevant information |
|---|---|---|
| Cloudflare, Inc. | Static website hosting, DNS, web delivery and security | Web requests and related delivery and security information |
| Namecheap, Inc., through Private Email | Sending, receiving and storing inquiry emails | Messages, attachments, sender and recipient information, and correspondence |
These external providers support website delivery and email operations. Their contractual roles, subprocessors, independent security processing and applicable conditions are assessed using their contracts and privacy materials together with Galpi's actual settings. This public website has no feature for selling inquiries or providing them for advertising.
Cloudflare operates an international network. Its default settings impose no log-storage boundary, so customer logs may be stored in core data centers globally. We therefore do not limit the destination countries to the United States alone. Namecheap identifies Phoenix, United States, as the location of Private Email servers. The scope of backups, support access and subprocessors requires separate verification.
[Verification required: actual destination countries, recipient contacts, transferred items, timing, methods, purposes and retention; the applicable transfer grounds and refusal procedures and consequences]
Provider materials are available in the Cloudflare DPA, Cloudflare service subprocessor list, Namecheap DPA and Private Email terms.
5. Cookies, browser storage and automation
This public website does not use login sessions, advertising or analytics trackers, localStorage or IndexedDB. The preview is a static example, not a visitor's manuscript. Inquiry links open your email application.
The site operator does not set browser cookies. Cloudflare visitor analytics (Real User Measurements, RUM), email address obfuscation and Browser Integrity Check have been disabled. Ordinary public-page access does not require sign-in or JavaScript execution. Web delivery and basic security processing take place as described above.
Bots, including Claude, may read and collect the public introduction and policy pages. This permission does not include visitors' emails or private manuscripts. The website does not make automated decisions about individuals or initiate AI-generation requests.
6. Rights and contact
You may request access to, correction or deletion of, or restrictions on processing your personal information by emailing admin@galpi.space. If a legal restriction applies, we will explain the reason and handling result. We may request the minimum information needed to verify your identity or an authorized representative.
The current website has no member accounts or account-deletion feature. We do not guarantee that the operator can immediately erase every record and backup held by providers. For relevant requests, we check the provider's processing scope and procedures.
Korean privacy advice and dispute-resolution information is available through the Privacy Portal and Personal Information Dispute Mediation Committee.
7. Safeguards
Private inquiries and manuscripts are not published on the website. Operational access is limited to what is necessary. We review administrator-account security and inquiry deletion procedures. HTTPS and email authentication are checked through actual deployment and DNS verification.
8. Changes and languages
When processing changes, the updated policy, version and effective date will be published here. Separate notices or consent procedures will be provided where required. The Korean version describes the same processing as this translation.