Privacy Policy
Ballast (the “Company”) processes personal information lawfully and manages it securely in compliance with the Personal Information Protection Act of Korea (PIPA) and related laws. In accordance with Article 30 of PIPA, the Company establishes and publishes this privacy policy to inform data subjects of the procedures and standards for processing personal information and to handle related grievances promptly.
This policy applies to the website and the AWS infrastructure diagnostics / FinOps cost optimization service Ballast (currently operated atballast.io.kr — the “Service”). The Service is currently in beta and provides read-only diagnostic reports for AWS accounts and a waitlist for launch notices.
1. Purposes of Processing
- Member registration and management — confirming intent to register, identification and authentication, maintaining membership, preventing misuse, notices, and grievance handling
- Service provision — connecting AWS accounts (read-only), automated resource discovery, cost/configuration analysis, and generating diagnostic reports
- Waitlist operation and launch notices — confirming registration, sending launch/beta invitations, prioritizing invites, and responding to inquiries
- Billing and settlement — settling fees for paid services (bank transfer) and issuing tax invoices
- Grievance handling — verifying identity, receiving and investigating inquiries, and notifying results
- Service improvement — analyzing service usage and improving quality, stability, and new features
- Marketing and information — (only with consent) sending news, feature updates, and newsletters
2. Items of Personal Information Processed
2-1. Processed without separate consent (legal bases under PIPA)
| Processing activity | Legal basis | Items |
|---|---|---|
| Member services | PIPA Art. 15(1)4 (performance of contract) | (Required) email address, password / (Optional) name |
| Cloud account connection | PIPA Art. 15(1)4 (performance of contract) | Connected AWS account identifiers (AWS account ID, IAM role ARN) and connection settings (External ID, etc.) |
| Billing and settlement (paid) | PIPA Art. 15(1)4 (performance of contract) | Business information for tax invoices (company name, business registration number, contact person’s name/phone/email), settlement records |
| Inquiries and support | PIPA Art. 15(1)4 (performance of contract) | Name, email address, inquiry content |
| Automatically generated during use | PIPA Art. 15(1)6 (legitimate interest — abuse prevention, stable operation) | IP address, access timestamps and logs, usage records, device/browser info, cookies |
- Passwords are stored as one-way hashes; plaintext is never retained.
- The Company connects to cloud accounts on a read-only basis. The granted scope is the AWS managed audit policy (SecurityAudit) plus a small set of read actions needed for diagnostics, and within that scope the Company only calls the reads required for diagnostics. The current Service does not collect or hold write (execution) permissions that could modify your infrastructure.
- Payments are settled via bank transfer and tax invoices; the Company does not collect or store credit card details or other payment instrument data.
- Resource and cost metadata collected from connected accounts is mostly non-identifying infrastructure/billing information; where personal information is included, it is handled under this policy.
2-2. Processed with consent
| Processing activity | Legal basis | Items |
|---|---|---|
| Waitlist operation and launch notices | PIPA Art. 15(1)1 (consent) | (Required) email address / (Optional) company, role, monthly cloud spend range, primary cloud, dedicated DevOps status |
| Marketing/newsletter | PIPA Art. 15(1)1 (consent — optional) | Email address |
- Optional fields are not required for waitlist registration.
- Marketing consent can be withdrawn at any time and is not required to use the Service’s essential features.
3. Children Under 14
The Service is not directed at children under 14, and the Company does not collect or process their personal information.
4. Retention Periods
- Member registration and management: until account deletion — or until the end of any pending investigation or outstanding claims/obligations
- Cloud account connection data: destroyed without delay upon disconnection or account deletion
- Billing and settlement: until settlement is complete, except records retained under the E-Commerce Act Enforcement Decree — contracts/withdrawals (5 years), payments/supply (5 years), consumer complaints/disputes (3 years), display/advertising (6 months)
- Waitlist data: until the purpose is fulfilled (launch notices and waitlist operation end) or upon deletion request
- Access logs: telecommunications logs kept for 3 months under the Protection of Communications Secrets Act Art. 15-2; access records for personal information processing systems kept for at least 1 year under the safeguards standards
- Marketing consent data: until consent withdrawal or account deletion
5. Destruction of Personal Information
When personal information is no longer needed (retention expiry, purpose fulfilled), it is destroyed without delay with the approval of the privacy officer. Data that must be retained under other laws is moved to a separate database or storage. Electronic files are destroyed irrecoverably.
6. Provision to Third Parties
The Company does not provide personal information to third parties, except with separate consent or where required by law (PIPA Arts. 17(1)2 and 18(2)).
7. Additional Use or Provision
The Company does not currently engage in ongoing additional use/provision of personal information without consent within a scope reasonably related to the original purpose. Should this change, the criteria under PIPA Arts. 15(3)/17(4) and Enforcement Decree Art. 14-2 will be published in this policy first.
8. Outsourcing of Processing
| Processor | Outsourced work |
|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure for running the service servers and database — processed and stored in the Korea (Seoul) region, ap-northeast-2 |
- Usage analytics are performed with a self-hosted tool (Umami) operated directly by the Company — no separate analytics processor. The tool runs on the same Seoul-region servers as the Service, analytics data is stored there, and analytics requests are not sent to any external domain.
- Inquiries and support are handled directly by the Company via email — no separate support or email-delivery processor.
- The web font used on this site is delivered to your browser directly from an external open-source CDN (jsDelivr). The Company does not outsource personal information processing to that provider, but your IP address may be disclosed to it in the course of that request, which we state here for transparency.
- Outsourcing to the former processors Vercel Inc. and Neon, LLC (USA) ended on August 17, 2026, upon completion of the migration to Korea (AWS Seoul region).
Outsourcing contracts specify the prohibitions and safeguards required by PIPA Art. 26, and the Company supervises processors. Changes will be disclosed through this policy without delay.
9. Cross-Border Transfer
The Company does not currently transfer personal information abroad. All items collected under Section 2 are processed and stored on servers in the Korea (Seoul) region, ap-northeast-2, and usage analytics are processed on the same servers.
- Before August 17, 2026 (while versions 2.0–2.1 of this policy were in effect), the Service infrastructure was located in the United States and personal information was transferred to and stored with Vercel Inc. and Neon, LLC (USA). That cross-border transfer ended on August 17, 2026, upon completion of the migration to Korea and the clean-up of data previously stored abroad.
- Should a cross-border transfer become necessary in the future, the Company will disclose the recipient, country, items, timing, method, purpose and retention period in this policy in advance, as required by PIPA Art. 28-8.
- Disclosure of your IP address to the web font CDN provider is described in Section 8.
10. Safeguards
- Organizational: internal management plan, minimization of personnel handling personal information, access authorization management
- Technical: access control for processing systems; encryption of sensitive values such as cloud connection settings (TLS in transit, encryption at rest); one-way password hashing; retention and tamper-proofing of access logs; read-only cloud access only — scope limited to the AWS managed audit policy plus diagnostic reads, with only the required reads actually called; no write permissions over user infrastructure
- Physical: physical access controls and disaster safeguards of the cloud infrastructure providers
11. Sensitive Information
The Company does not process sensitive information under PIPA Art. 23(1) and provides no feature that discloses it.
12. Pseudonymized Information
The Company does not currently process pseudonymized information under PIPA Arts. 28-2 and 28-3. If it does in the future, details will be added to this policy.
13. Cookies
The Company uses cookies only to the extent essential for providing the Service, such as keeping you signed in, and does not use advertising or tracking cookies. Usage analytics are collected cookie-free with a self-hosted tool (Umami) without identifying individuals. You may refuse cookies in your browser settings, though sign-in persistence may be limited.
14. Behavioral Information Collected by Third Parties
The Company does not allow third parties to collect behavioral information for targeted advertising. If this changes, the collectors, items, purposes, and opt-out methods will be disclosed in this policy.
15. Rights of Data Subjects
You may at any time request access, transmission, correction, deletion, suspension of processing, or withdrawal of consent by email (kal6529@gmail.com). The Company responds within 10 days (transmission requests: without delay). Rights may be exercised through a legal representative or authorized agent with a power of attorney. Requests may be limited under PIPA Arts. 35(4) and 37(2).
16. Automated Decisions
The Company does not make fully automated decisions with legal or similarly significant effects under PIPA Art. 37-2. Diagnostic reports and cost optimization recommendations are provided as reference information based on the cloud providers’ official analysis engines.
17. Privacy Officer
- Name: Taeksoo Kim
- Title: Founder/CEO
- Contact: kal6529@gmail.com
18. Domestic Agent
The Company has its address/place of business in Korea and is not subject to the domestic agent designation requirement under PIPA Art. 31-2. (Not applicable)
19. Remedies for Infringement
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- KISA Privacy Report Center: 118 (privacy.kisa.or.kr)
- National Police Agency: 182 (ecrm.police.go.kr)
20. Voluntary Privacy Efforts
- Security by design: cloud connections are read-only (scope = AWS managed audit policy plus diagnostic reads; only the required reads are called) via temporary role assumption (AssumeRole) combined with an External ID — no long-lived access keys. Reads that could reach third parties’ personal data (IAM, Cognito, and SES user or identity listings) are barred by design rule.
- No durable write credentials: the Company does not store credentials capable of modifying user infrastructure.
- The Company plans to pursue certifications such as ISMS-P.
21. Changes to This Policy
This policy (v2) takes effect on July 15, 2026. This revision adds disclosures for processing that newly begins with the beta service (member registration, AWS account connection, diagnostic reports) and makes no unfavorable changes to the processing of existing data subjects (waitlist registrants), so it takes effect upon announcement. Future revisions are announced at least 7 days in advance (30 days for changes significantly affecting your rights).
Amendment v2.2 (effective August 17, 2026) — the location where personal information is processed and stored was corrected to match reality. Following completion of the migration to the Korea (Seoul) region, the processor named in Section 8 was replaced with AWS (Seoul region), and Section 9 now records that outsourcing to, and cross-border transfer to, the US providers (Vercel Inc., Neon, LLC) has ended. The visitor analytics tool (Umami) was also moved to the same Seoul-region servers, so analytics requests are no longer sent to an external domain. This amendment additionally discloses that the web font is delivered by an external CDN and that your IP address may be disclosed to that provider in the process. It does not change the personal data the Company collects or holds, and moving processing from abroad into Korea is not adverse to data subjects, so it takes effect upon publication.
Amendment v2.1 (effective August 17, 2026) — the description of cloud connection permissions was corrected to match the actual scope. The IAM role template we provide now uses the AWS managed audit policy (SecurityAudit), which broadens the granted scope. This amendment does not expand the personal data the Company collects or holds, and the reads the Company actually calls remain limited to what diagnostics require. As no new processing purpose is added and no change is adverse to data subjects, it takes effect upon publication.
Previous versions: