Skip to main content
KOMOSKorea · MoscowCenter for Culture and Education한국 러시아 교육 문화 센터

Privacy Policy

How KOMOS handles personal information from submission through deletion.

Effective: September 13, 2026

1. Information we process

The required information is your name, message, submitter role (an adult aged 18 or over, or a parent or legal guardian of a minor), either a phone number or an email address, and consent to collection and use. Inquiry type, topic, and preferred timing are optional. Infrastructure logs may temporarily process an IP address, request time and path, and error data for security. We do not request a date of birth, national identification number, passport or identity-document copy, proof of family relationship, or medical information for a general inquiry.

2. Purposes

We use data to review and reply to inquiries, assess cultural, language, educational or collaboration proposals, consider education-related connections, and protect the service. Information needed later for admission, visa, contract, or another official process is requested separately and securely, limited to what is necessary.

3. Minors

A person aged 18 or over may inquire directly. An inquiry about a person under 18 must be submitted by a parent or legal guardian; a minor may not submit personal information directly. We do not request identity or family-relationship documents from a parent or guardian at this stage. Future paid contracts, program participation, or admission or visa document work will use a separate age-appropriate verification, consent, and contracting process.

4. Retention and deletion

Inquiry information is retained for one year from completion. Marking an inquiry Resolved, Closed, or Spam records its completion date; direct email inquiries follow the same completion-date rule. The Privacy Officer reviews expired records monthly and manually deletes them from the administrator interface and email. Deletion is not currently automatic. Database deletion also removes the inquiry's related third-party disclosure-consent records so they cannot be recovered by ordinary means. Gmail messages moved to Trash are normally permanently deleted by Google within 30 days under its Trash policy. A specific legal duty or dispute may justify restricted, separately flagged retention with a recorded reason and end date; the record is deleted promptly when that reason ends.

5. Third-party disclosure

KOMOS does not disclose personal information to third parties as a rule. Where possible, we give the user an instructor's, adviser's, experienced person's, immigration business's, or institution's contact details so the user contacts them directly. If KOMOS must send user data for a requested connection, we first identify the recipient, purpose, data fields, recipient's retention, right to refuse, and consequences. We obtain separate consent at that time and disclose only the minimum. General inquiry consent is not blanket disclosure consent. Unless specifically required by law, we do not disclose a name, phone number, email, or inquiry content without separate consent.

6. Processing providers and external services

Cloudflare, Inc. provides public web delivery, security, and Workers hosting. Render Services, Inc. provides the API and server environment. Neon, LLC provides the PostgreSQL database in the AWS eu-central-1 (Frankfurt, Germany) region. GitHub, Inc.'s GitHub Actions provides the execution environment for generating and processing scheduled database backups and is not used as a backup repository. Cloudflare R2 stores the encrypted backup files. Google LLC's Gmail is the external email service used when a user emails KOMOS or KOMOS replies; form submissions are not automatically forwarded to Gmail. These processing services are managed separately from a third party who may receive user information for an introduction.

7. International processing

Public-page IP address, request time and path, browser data, and security events may be processed over HTTPS on Cloudflare's global infrastructure; Workers Observability logs have a maximum seven-day retention. Form data, submitter role, and consent are transmitted immediately over HTTPS to the Frankfurt, Germany API region operated by Render Services, Inc., a United States company, and stored in Neon's PostgreSQL database in AWS eu-central-1 (Frankfurt, Germany) for intake and administration. The Neon project currently retains point-in-time restore history for six hours. Scheduled backups are operated separately as described in section 7-1 below. One manual snapshot created before the production change is retained until it is separately deleted. Deleted database information may remain in the restore history for up to six hours before it expires; if a restore reintroduces deleted information, KOMOS deletes it again. If email is used, address, headers, body, and attachments may be processed in Google LLC data centres worldwide. KOMOS deletes inquiry data under section 4; infrastructure logs rotate under service policies and account settings. HTTPS, administrator authentication, and access restrictions apply. A user may refuse international processing by not using the form or email, but those channels then cannot be used; the public phone number can be used to ask about an alternative.

7-1. Scheduled backup processing and retention

For disaster recovery, a database backup using PostgreSQL pg_dump is scheduled once a day and compressed. This job runs on a GitHub Actions hosted runner; the confirmed execution environment is Microsoft Azure in the United States. During backup generation, inquiry data, program applications, consultation records, consent history and administrator account information remaining in the production database may be temporarily processed in that environment. The confirmed execution location does not mean that all future jobs are fixed to that location. Generated backups are encrypted with AES-256-GCM before upload to Cloudflare R2 and stored in a private bucket in the European Union (EU). Encryption keys are managed separately from the backup repository. R2 backup files are retained for 30 days after storage and then automatically deleted under a lifecycle rule. The provider's asynchronous deletion process may delay actual deletion. Information deleted from the production database may remain in a backup file until that backup is deleted. This 30-day retention applies to R2 backup files; it does not change the one-year retention from completion of inquiry handling in section 4 or the Neon point-in-time recovery and manual snapshot retention in section 7. If a restore reintroduces deleted information, it is deleted again.

8. Your rights

You may request access, correction, deletion, or restriction. You may refuse consent, but required information is necessary to submit an inquiry. Send requests to the email below; only the minimum information needed to verify the requester or authorized representative is checked.

9. Security

We use administrator authentication and access controls, CSRF protection, HTTPS, size and rate limits, security logs, and completion and retention-exception records. Separate disclosure-consent records contain the consenting user, time, recipient, purpose, fields, retention, refusal notice, and text version.

Applications and inquiry records

Program applications include the selected program and application status. Inquiry notes, replies, assigned administrator, follow-up dates and status history support responses and participation management and follow the inquiry retention period. Deleting an inquiry also deletes its notes and separate consent records. Rate-limit identifiers use keyed IP hashes and are cleared on subsequent requests once their time window is more than 10 minutes old.

10. Operations and Privacy Officer

Moscow operations and inquiries: Yi Ki Youn

Privacy Officer: Yi Ki Youn (Russian: Йи Ки Юн)

Access, correction, deletion, or restriction requests: inquiry form or komos.center@gmail.com.