개인정보처리방침
시행일: 2026년 8월 7일 (개정) | 종전 시행일: 2026년 3월 27일 | 알파카랩 (ALPS)
알파카랩(이하 "회사")은 ALPS 건축 법규검토 서비스(이하 "서비스")를 운영하면서 이용자의 개인정보를 아래와 같이 처리합니다.
1. 수집하는 개인정보 항목
가. 로그인 없이 이용하는 경우 — 다음 입력값만 처리하며 계정 정보는 수집하지 않습니다.
- 부지 주소 — 이용자가 입력한 검토 대상 주소
- 건축 계획 정보 — 용도, 연면적, 층수, 주차 대수 등 이용자가 입력한 계획 수치
나. 네이버 계정으로 로그인하는 경우(일정표·사업성 등 계정 기능, ChatGPT·Claude 계정 연결 포함) — 네이버 로그인 동의 항목에 따라 다음을 제공받아 저장합니다.
- 네이버 회원 식별자(provider ID), 이름, 이메일, 휴대전화번호 — 계정 식별·중복 가입 방지 목적
- 로그인 세션·인증 토큰 — 로그인 유지 및 외부 앱(ChatGPT 등) 계정 연결. 토큰은 원문을 저장하지 않고 해시 형태로 보관
- 저장한 검토 — 이용자가 명시적으로 저장을 요청한 검토의 주소·계획 정보·리포트
다. 서비스 운영상 자동 생성·처리되는 정보
- 주소→좌표 변환 결과 캐시(공공 API 호출 절감 목적)
- 접속 IP(요청 빈도 제한 목적, 저장하지 않고 처리 시점에만 사용)
- 오류·진단 로그 및 이용 통계
2. 개인정보의 처리 목적
- 입력된 주소를 기반으로 필지 정보 조회 (브이월드 API, SGIS API 경유)
- 건축 법규 검토 리포트 생성 및 3D 매스 시각화
- 계정 식별·로그인 유지, 외부 앱 계정 연결(OAuth), 이용자별 검토 저장·불러오기
- 중복 가입 방지 및 부정 이용 방지(휴대전화번호 기반)
- 서비스 품질 개선을 위한 사용 통계 및 장애 대응
3. 제3자 제공 및 처리 위탁
주소 기반 필지 조회를 위해 다음 공공 API에 주소 또는 좌표 정보를 전달합니다.
- 브이월드 (국토교통부 공간정보 오픈플랫폼) — vworld.kr
- 브이월드 지도 타일 — 3D 지형·위성 화면을 열 때 이용자의 브라우저가
브이월드 타일 서버에 직접 요청합니다. 이 과정에서 접속 IP 등 통신에
필요한 정보가 해당 서버에 전달되며, 회사는 이를 수집·저장하지 않습니다.
- SGIS (통계지리정보서비스) — sgis.kostat.go.kr
계정 인증을 위해 네이버(네이버㈜) 로그인 서비스를 이용합니다. 이 외에 이용자 정보를 제3자에게 제공하거나 판매하지 않습니다.
처리위탁 — 서비스 운영을 위해 다음에 개인정보 처리를 위탁합니다.
수탁자가 변경되면 본 방침을 통해 공개합니다.
- Cloudflare, Inc. — 서비스 실행(엣지 컴퓨팅)·데이터베이스(D1)
- Oracle Corporation — 데이터베이스(OCI, 대한민국 춘천 리전)
- 네이버㈜ — 로그인 인증
국외 이전 — 서비스는 Cloudflare(글로벌 엣지, 미국 등)에서 실행되며, 데이터베이스는 Cloudflare D1(아시아·태평양 리전) 및 Oracle Cloud Infrastructure(대한민국 춘천 리전)에 저장됩니다.
- 이전 항목 — 위 1항의 저장 항목
- 이전 국가·시기·방법 — 미국 및 아시아·태평양 리전, 서비스 이용 시점에 네트워크를 통해 전송
- 이전받는 자 — Cloudflare, Inc. (개인정보 문의 privacyquestions@cloudflare.com) · Oracle Corporation (개인정보 문의 privacy_ww@oracle.com)
- 이용 목적·보유 기간 — 서비스 제공, 위 4항의 보유기간과 같음
- 거부 방법 — 국외 이전을 원하지 않으시면 아래 연락처로 요청해 주십시오. 다만 서비스 실행과 저장이 해당 인프라에서 이루어지므로, 거부하시는 경우 서비스 이용이 불가능합니다.
4. 보유 및 이용 기간
- 로그인 없이 입력한 주소·계획 정보 — 검토 요청 처리 후 영구 저장하지 않습니다.
- 계정 정보(식별자·이름·이메일·전화번호) — 회원 탈퇴 시까지 보관 후 지체 없이 파기
- 로그인 세션 — 최대 30일(만료 시 삭제)
- 인증 토큰 — 액세스 토큰 1시간, 갱신 토큰 최대 30일
- 저장한 검토 — 이용자가 삭제하거나 탈퇴할 때까지
- 주소 좌표 캐시 — 최대 90일
- 오류·진단 로그 — 최대 1일
보유기간이 지난 정보는 자동 삭제되며, 관계 법령에 따라 보존이 필요한 경우 해당 기간 동안 분리 보관합니다.
파기 절차 및 방법 — 보유기간이 끝나거나 처리 목적이 달성된 정보는 별도의 승인 절차 없이
자동으로 파기합니다. 전자적 파일 형태의 정보는 복구·재생할 수 없는 방법으로 삭제하며
(레코드 삭제 및 보존 기간 경과 후 백업본 만료), 출력물이 생기는 경우 분쇄하거나 소각합니다.
5. 이용자의 권리와 행사 방법
이용자는 언제든지 본인 정보의 열람·정정·삭제·처리정지를 요청할 수 있습니다.
- 저장한 검토 삭제 — 서비스 내에서 직접 삭제할 수 있습니다.
- 연결 해제 — ChatGPT 등 외부 앱의 계정 연결을 해제하면 해당 토큰이 무효화됩니다.
- 회원 탈퇴·전체 삭제 — 아래 연락처로 요청하시면 계정 정보, 저장한 검토, 세션·토큰을 모두 삭제합니다(지체 없이, 늦어도 10일 이내).
권리 행사는 법정대리인이나 위임받은 자를 통해서도 할 수 있으며, 이 경우 위임 사실을 확인할 수 있는
서류를 함께 보내주십시오. 만 14세 미만 아동의 정보는 법정대리인이 권리를 행사합니다.
회사는 이용자 본인 또는 정당한 대리인인지 확인한 뒤 지체 없이 처리합니다. 법령에 따라 요청을
거절하는 경우 그 사유를 알려드리며, 이용자는 그 결정에 대해 위 연락처로 이의를 제기하거나
아래 10항의 기관에 분쟁조정을 신청할 수 있습니다.
6. 개인정보 보호책임자
7. 자동 수집 장치의 설치·운영 및 거부
서비스는 광고·행태정보 수집 목적의 쿠키를 사용하지 않습니다. 다음 저장소만
이용자의 브라우저에 사용합니다.
- 로그인 세션 토큰 — 로그인 상태 유지. 브라우저 저장소를 비우거나
로그아웃하면 삭제됩니다.
- 표시 설정 — 언어 선택 등 화면 설정값. 개인을 식별하지 않습니다.
브라우저 설정에서 저장소를 차단하거나 삭제할 수 있으며, 이 경우 로그인 유지 등
일부 기능이 제한될 수 있습니다.
8. 안전성 확보조치
- 전송 구간 암호화(HTTPS) 적용
- 인증 토큰·세션은 원문을 저장하지 않고 해시로 보관합니다.
- 접근 권한을 최소한으로 부여하고, 보유기간이 지난 정보는 자동 삭제합니다.
- 진단 로그에는 주소·좌표를 그대로 남기지 않고 비식별 처리합니다.
9. 만 14세 미만 아동
서비스는 건축 실무를 위한 도구로, 만 14세 미만 아동을 대상으로 하지 않으며
아동의 개인정보를 의도적으로 수집하지 않습니다. 아동의 정보가 수집된 사실을 알게
되면 지체 없이 파기합니다.
10. 권익침해 구제방법
개인정보 침해로 인한 상담·분쟁조정이 필요한 경우 아래 기관에 문의할 수 있습니다.
- 개인정보분쟁조정위원회 — 1833-6972 (kopico.go.kr)
- 개인정보침해신고센터 — 118 (privacy.kisa.or.kr)
- 대검찰청 사이버수사과 — 1301 · 경찰청 사이버수사국 — 182
11. 변경 사항
본 방침이 변경되는 경우 시행일 최소 7일 전에 서비스 내 공지합니다.
Privacy Policy
Effective: 2026-08-07 (revised) | Previous: 2026-03-27 | Alpaka Lab (ALPS)
Alpaka Lab ("we") operates the ALPS architectural regulation review service ("the Service") and processes user information as described below.
1. Information We Collect
a. Without sign-in — we process only the following inputs; no account data is collected.
- Site address — Korean parcel address entered by the user
- Planning parameters — building use, gross floor area, floor counts, parking spaces
b. When signing in with a Naver account (account features such as Schedule/Feasibility, including account linking from ChatGPT or Claude) — we receive and store, per the Naver consent scope:
- Naver member identifier, name, email, mobile phone number — for account identification and duplicate-signup prevention
- Login sessions and authentication tokens — tokens are stored hashed, never in plaintext
- Saved reviews — address, planning inputs and report for reviews the user explicitly saves
c. Automatically generated in operation — address-to-coordinate cache, request IP (used at request time for rate limiting, not stored), error/diagnostic logs and usage statistics.
2. Purposes of Processing
- Parcel lookup based on the entered address (via V-World and SGIS, operated by the Korean government)
- Generation of regulation review reports and 3D mass visualizations
- Account identification, session maintenance, external app account linking (OAuth), per-user saved reviews
- Duplicate-signup and abuse prevention (phone-number based)
- Usage statistics and incident response for service quality
3. Third-Party Disclosure and Processing
For address-based parcel lookup we transmit the address or coordinates to the following public APIs:
- V-World (Ministry of Land, Infrastructure and Transport) — vworld.kr
- V-World map tiles — when the 3D terrain or satellite view opens, your
browser requests tiles from the V-World tile server directly. Connection
information such as your IP address reaches that server; we neither collect nor store it.
- SGIS (Statistics Korea) — sgis.kostat.go.kr
Account authentication uses Naver Login (NAVER Corp.). We do not otherwise sell or disclose user information to third parties.
Processing entrusted to others — we entrust personal data processing to
the following. Changes are disclosed through this policy.
- Cloudflare, Inc. — service execution (edge compute) and database (D1)
- Oracle Corporation — database (OCI, Chuncheon, Republic of Korea)
- NAVER Corp. — login authentication
Cross-border transfer — the Service runs on Cloudflare (global edge, including the United States); databases are Cloudflare D1 (Asia-Pacific) and Oracle Cloud Infrastructure (Chuncheon, Republic of Korea).
- Items transferred — those listed in Section 1
- Destination, timing and method — United States and Asia-Pacific regions, transmitted over the network at the time of use
- Recipients — Cloudflare, Inc. (privacy contact privacyquestions@cloudflare.com) · Oracle Corporation (privacy contact privacy_ww@oracle.com)
- Purpose and retention — providing the Service; retention as in Section 4
- How to refuse — contact us below if you do not wish your data to be transferred abroad. Because the Service executes and stores data on that infrastructure, refusal means the Service cannot be used.
4. Retention Periods
- Inputs without sign-in — not persisted after the review request is served
- Account data (identifier, name, email, phone) — until account deletion, then erased without delay
- Login sessions — up to 30 days
- Authentication tokens — access 1 hour, refresh up to 30 days
- Saved reviews — until the user deletes them or deletes the account
- Address coordinate cache — up to 90 days
- Error/diagnostic logs — up to 1 day
Data past its retention period is deleted automatically; where law requires retention, it is
stored separately for that period.
Erasure procedure — data whose retention period has ended or whose purpose has
been fulfilled is destroyed automatically, with no separate approval step. Electronic records are
deleted by means that make them unrecoverable (record deletion, with backups expiring
after their retention window); any printed material is shredded or incinerated.
5. Your Rights
You may request access, correction, deletion, or suspension of processing at any time.
- Delete saved reviews — directly in the Service
- Unlink — disconnecting the app in ChatGPT or Claude invalidates the associated tokens
- Account deletion — contact us below; account data, saved reviews, sessions and tokens are all deleted without delay (within 10 days at the latest)
Rights may also be exercised through a legal representative or an authorised agent;
please attach documentation evidencing the authority. For children under 14, the legal representative
exercises these rights.
We act without delay once we have verified that the requester is the data subject or a duly
authorised representative. Where a request is refused under applicable law we state the
reason, and you may object via the contact below or apply for dispute mediation to the bodies
listed in Section 10.
6. Data Protection Officer
- Operator: Alpaka Lab
- Data protection officer: the representative of Alpaka Lab
- Access / correction / deletion requests: the contact below (no separate department is maintained)
- Contact: douglaskim91@gmail.com
7. Cookies and local storage
We do not use cookies for advertising or behavioural tracking. Only the following
browser storage is used:
- Session token — keeps you signed in. Removed when you sign out or
clear browser storage.
- Display preferences — language and similar view settings. These do
not identify you.
You can block or clear this storage in your browser settings; sign-in persistence and
some features will then be limited.
8. Security measures
- Encryption in transit (HTTPS).
- Session and authentication tokens are stored as hashes, never in plain text.
- Access is granted on a least-privilege basis; data past its retention period is deleted
automatically.
- Diagnostic logs carry de-identified locations rather than raw addresses or coordinates.
9. Children under 14
The Service is a professional tool for architectural practice. It is not directed at
children under 14 and we do not knowingly collect their personal data. If we learn that we
have, we delete it without delay.
10. Where to raise a complaint
For advice or dispute mediation regarding personal data in Korea:
- Personal Information Dispute Mediation Committee — 1833-6972 (kopico.go.kr)
- Privacy Infringement Report Center — 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime — 1301 · National Police Cyber Bureau — 182
11. Changes
We will provide notice within the Service at least 7 days before any changes to this policy take effect.