This Privacy Policy explains how we collect, use, retain, disclose, delete, and otherwise handle personal information when you use WorksCove ERD and related billing, support, and collaboration features.
This Policy should be read together with our Terms of Service. Where the Terms explain workspace ownership and service rules and this Policy explains data handling, both apply together.
Some information (name, email, password) is required to create and maintain an account. Other information (profile details, avatar) is optional. You may decline to provide optional information; doing so will not affect core service functionality, but certain optional features may be limited.
We use information to:
If you are located in the European Economic Area or the United Kingdom, we process your personal information on the following legal bases under the GDPR:
The AI assistant feature provides suggestions based on automated processing of your ERD data. These suggestions are advisory only and do not produce legal effects or similarly significant decisions affecting you. You are not subject to decisions based solely on automated processing.
If you join or use a team workspace, the workspace owner or customer organization may control the workspace and its assets. That means:
We do not sell personal information. We may disclose or entrust processing of information only as needed to the following categories of recipients:
The restrictions in this section apply only to identifiable personal information. Information that has been de-identified or anonymized to a point where it can no longer reasonably identify a specific individual, or aggregate or statistical information derived by combining data from multiple members, may be used for lawful purposes such as service improvement, statistical analysis, security enhancement, and market analysis. We do not attempt to re-identify such information, and we do not use identifiable personal information, project data, or content for separate AI model training or improvement.
| Provider | Purpose | Data Processed |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, file storage | All service data, uploaded files |
| OpenAI, Inc. | AI assistant feature | ERD schema data, project name, DBMS information, conversation prompts, user-provided AI API key (where applicable) |
| Paddle.com Market Ltd. | Payment processing (international) | Billing information, payment data |
| TossPayments (Korea) | Payment processing (Korea) | Billing information, payment data |
| MailPlug (Korea) | Transactional email delivery | Email address, name |
| Google LLC | OAuth authentication | OAuth tokens, email (if Google login is used) |
| GitHub, Inc. | OAuth authentication | OAuth tokens, email (if GitHub login is used) |
| Category | Retention Period | Basis |
|---|---|---|
| Account and profile information | Duration of active membership; deleted or de-identified upon account deletion | Service provision |
| Free accounts inactive for 12 months or more | Deactivated, or data deleted or de-identified, after prior notice | Korean PIPA Article 39-6 |
| Billing, payment, tax, and invoice records | 5 years after the transaction | Tax law (Korean Framework Act on National Taxes) |
| Security and audit logs | 1 year | Security, fraud prevention |
| Login attempt records | 90 days | Security monitoring |
| AI conversations and suggestion logs | Deleted upon account deletion | Service provision |
| User-provided AI API key | Deleted when AI settings are deleted or upon account deletion | AI request authentication |
| Consumer complaint and dispute records | 3 years | Consumer protection law (Korean E-Commerce Act) |
| Email verification and password reset tokens | 24 hours / 1 hour respectively (auto-expire) | Security |
| Session data | 12 hours (auto-expire) | Security |
For free accounts that have been inactive for 12 months or more, we will notify you by email to your registered address and by in-service notification at least 30 days before the scheduled deactivation, deletion, or de-identification. The notice will include the scheduled date, the categories of data affected, and the actions you may take to avoid deactivation (such as logging in or submitting a separate retention request). If you log in to the service or submit a retention request before the scheduled date, deactivation or deletion will not be carried out.
Short-lived verification, reset, and session data may expire automatically under our security controls.
If a deleted account is the sole owner of a personal workspace or other owned workspace that is being closed, the related workspace data may be deleted as part of that closure.
When personal information is no longer needed and the retention period has expired, electronic records are permanently deleted using methods that prevent recovery. Physical records, if any, are shredded or incinerated.
We use technical and organizational safeguards appropriate to the nature of the data and service, including access controls, encryption in transit, password hashing, session controls, logging, and abuse-prevention measures. No service can guarantee absolute security.
If we become aware of a personal information breach that is likely to cause harm to users, we will notify affected individuals without undue delay as required by applicable law. The notification will include the nature of the breach, the types of information affected, and the measures taken or proposed to address it. For breaches that meet statutory reporting thresholds under Korean data-protection law (for example, leakage affecting 1,000 or more data subjects, or leakage involving sensitive information or unique identifying information), we will additionally report to the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) within 72 hours of becoming aware. For users in the EEA or the United Kingdom subject to the GDPR, we will report to the competent supervisory authority within the same time frame.
We may process information in countries other than the country where you reside. Specifically, personal information may be transferred to the following countries and recipients:
| Recipient | Country | Items Transferred | Purpose |
|---|---|---|---|
| OpenAI, Inc. | United States | ERD schema data, project name, DBMS information, AI conversation prompts, user-provided AI API key (where applicable) | AI assistant feature processing |
| Paddle.com Market Ltd. | United Kingdom / United States | Billing and payment information | International payment processing |
| Google LLC | United States | OAuth authentication tokens, email | Social login authentication |
| GitHub, Inc. | United States | OAuth authentication tokens, email | Social login authentication |
We apply contractual and operational safeguards as required by applicable law to protect transferred data. Where a data processing agreement is available from the recipient, we use it.
You have the right to refuse the cross-border transfer of your personal information. You may submit your refusal to [email protected] or to the contact addresses set out in Section 13, together with documents sufficient to verify your identity. We will respond to your request within a reasonable period of receipt (ordinarily within 10 days), and the features that depend on the relevant transfers (such as the AI assistant, international payment processing, and social login) will be permanently disabled either immediately or at a time agreed with you. For paid subscriptions that include disabled features, refunds may be considered on a pro-rata basis after deducting the period already used; the specific calculation method and refund eligibility will follow the policies of the relevant payment processor and applicable law. If you withdraw your refusal, we will reactivate the affected features after a fresh consent process.
Depending on your location and applicable law, you may have rights to:
To exercise these rights, contact us at the addresses listed in Section 13. We will respond to your request within 10 days of receipt. Where there is a justified reason, we may extend the response period together with notice of the reason, to the extent permitted by applicable law (up to 30 days under Korean PIPA). We may request additional information for identity or authority verification, and the time during which we await your response will not count toward the response deadline. We may decline or charge a reasonable fee for requests that are manifestly unfounded, repetitive, or restricted by law, with notice of the reason.
The service is not directed to children under 16 years of age. Even where applicable law permits a lower minimum age of consent, we reserve the right to apply stricter age requirements at our discretion.
At sign-up we rely on the user's self-declaration and acceptance of these Terms and this Policy; we do not perform any separate age verification. You are therefore responsible for representing and warranting at sign-up that you are at least 16 years of age, and any liability arising from a false declaration rests with you or, where applicable, your parent or legal guardian.
If we learn that personal information of a child below the applicable minimum age has been collected in violation of this Policy, or if we receive a notification supported by reasonable grounds from a parent or legal guardian, we will, without undue delay, deactivate the account in question and delete or de-identify the related personal information. Parents or legal guardians may submit such a notification, together with documents sufficient to verify identity, to [email protected].
We use cookies, session identifiers, and similar technologies for the following purposes:
We do not use third-party tracking or analytics cookies.
You may configure your browser to reject cookies, but doing so may impair service functionality such as maintaining your login session.
We may update this Policy from time to time. Routine changes will be communicated through the service, by email, or by posting an updated version on this page with a new effective date at least 7 days before the changes take effect. Changes that are unfavorable to members or that may have a material impact on members (such as expansion of processing purposes, extension of retention periods, expansion of third-party disclosure, or restriction of member rights) will be communicated by the same means at least 30 days before the effective date, with a clear statement of the reasons for the change and the effective date.
Your continued use of the service after the effective date will be deemed acceptance of the updated Policy. If you do not agree to the revised Policy, you may discontinue use of the service or close your account before the announced effective date, in which case we will delete or de-identify your personal information to the extent permitted by applicable law. We will treat continued use after the effective date as acceptance only where you have not expressly objected.
If you have questions about this Policy, deletion requests, billing records, or workspace ownership handling, contact us at:
Company: NewBreed Co., Ltd.
CEO: Minwoo Jeong
Business Reg. No.: 184-87-00968
E-commerce License: 2018-강원원주-00602
Customer Service: (+82) 1661-2697
Email: [email protected]
Seoul: 1138, Gasan Tera Tower, 78 Digital-ro 10-gil, Geumcheon-gu, Seoul 08517, Korea
Wonju: 401, H Tower, 19 Hyeoksin-ro, Wonju-si, Gangwon 26460, Korea
If you believe your personal information rights have been violated, you may file a complaint with the following organizations. If you are located in the EEA or UK, you may also lodge a complaint with your local data protection authority.