Skip to content

Privacy Policy

01. Who we are and what this policy covers

MTechLab is responsible for the personal information processed through mtechlab.co.kr and its English and Korean pages. This policy covers browsing, product and technical inquiries, MR.Brain-Edu inquiries submitted on this website, meeting requests, account services, module launch notifications, AI assistance and optional usage analytics.

The separate education website at edu.mtechlab.co.kr has its own privacy policy. A link to that site does not send your main-site form submission to the education website. External websites, retailers, publications and services handle information under their own policies.

This website is not a patient-record system. Current interactive MRI demos use supplied sample images, not visitor-uploaded scans. Do not enter patient information, health records, identification numbers, payment details or other sensitive information in forms or chat.

Education website privacy policy ↗Back to contents ↑

02. Information we collect

Information comes from the details you enter, account providers you choose, necessary security requests and—only if you accept—optional analytics. Optional form fields may be left blank. Required fields are identified in each form.

Published professional information

Company, research and news pages may display professional names, affiliations, biographies and event photographs from published company/editorial records. These are not details collected from every visitor. Contact MTechLab about access, correction or removal concerns relating to published personal information. Publication permissions and retention for editorial materials should be included in the company’s review.

Product and technical inquiries

Required: name, email, product interest and message. Optional: company/institution, phone and country. We also store the submission time, inquiry source and handling status; an account identifier may be associated where supplied. The general inquiry service can draft an AI first reply.

MR.Brain-Edu inquiries and document requests

Required: name, institution, email, inquiry type, institution type and message. Optional: role, phone, country and timeline. A requested document/resource is recorded when selected. These inquiries use the main website’s inquiry, receipt-email and AI-response pipeline.

Meeting requests and appointments

Required: name, email and the topic/message required by the selected form. Optional: company, phone and country. Scheduling records include proposed and confirmed times, meeting format, online platform, status, secure booking-link tokens and, where applicable, the originating inquiry. The pads booking dialog and contact-page meeting mode do not use the AI first-reply pipeline. The separate appointment inquiry page uses the general inquiry service and may receive an AI reply.

Accounts and saved preferences

Personal accounts: email, password, first/last name and country, with institution, position and phone when provided. Organization accounts: organization name, type, country, contact person, position and phone, plus optional website, size and business registration number. Passwords are stored as hashes, not readable passwords. We store account role, verification status, saved product favorites and hashed refresh tokens. Google sign-in supplies your Google account identifier, email and name instead of a website password.

Module launch notifications

Email address, the module you selected, consent time and registration/update time. The purpose is to notify you about that module, not to enroll you in unrelated marketing. You can withdraw through MTechLab’s privacy contact.

AI chat

Your current message and up to ten recent conversation messages are sent to our API and Anthropic to generate a response. Conversation messages are held in the open chat’s browser memory; the current application does not save a chat transcript to its database. This does not mean the AI provider has zero retention. A chat connection also exposes necessary network metadata such as IP address.

Security, service logs and AI reply audit records

Requests may include IP address, browser/device information, requested URL, timestamp, error information and security-check tokens. Rate-limit and daily-quota systems use request identifiers or hashed identifiers. AI inquiry audit records can contain the inquiry reference, name, email, processing outcome and a reply excerpt of up to 300 characters; they are separate from chat transcripts.

Optional analytics and external media

After analytics consent, PostHog receives pseudonymous page-view/click events, random identifiers and browser/device information. YouTube receives connection and playback information only when you activate an embedded video. Google receives information when you choose Google sign-in. See the cookies and transfers sections for details.

Back to contents ↑

03. Why we use information and your choices

We use submitted information to answer inquiries, arrange meetings, provide requested education materials, operate accounts and favorites, verify email addresses, restore access, send selected module launch updates and protect the service from abuse. Optional analytics helps us understand aggregate site use and improve the website.

Inquiry, booking and notification forms require their indicated collection/use consent before submission. Where applicable, their notice also describes overseas processing. You may refuse and continue browsing, but the corresponding online request cannot be submitted. Creating an account requires the information necessary to provide that account; optional fields are not a condition of browsing.

Analytics consent is separate from inquiry and account processing. Declining analytics does not prevent forms, account access or browsing. You can choose not to use AI chat, Google sign-in or embedded videos and contact our team directly instead. AI helps provide general information and draft replies; it does not make medical diagnoses or binding commercial decisions.

Back to contents ↑

04. How long information is kept

The business retention periods below were approved by MTechLab for this policy. The current application does not automatically enforce the inquiry, confirmed-meeting, account or notification schedule. MTechLab must establish and verify deletion handling before this draft takes effect. Database expiry is asynchronous, not an exact-time deletion guarantee.

Inquiries, including MR.Brain-Edu

Approved period: 3 years from the last contact. This includes the inquiry record and related correspondence. The last-contact tracking and deletion procedure still require implementation or a verified operating procedure.

Confirmed meetings

Approved period: 1 year after the meeting. Unconfirmed booking records currently have a 14-day expiry after application, reset to 7 days when staff propose times. Confirmation removes that temporary expiry.

Accounts

Approved period: until account deletion. Deletion requests are handled through MTechLab; no self-service deletion or automatic dormant-account deletion is currently offered. Verification and reset credentials have their own expiry.

Launch notifications

Approved period: until the selected notification has been sent or consent is withdrawn, and no longer than 2 years from registration. The current database does not automatically expire these registrations.

AI reply audit records and temporary controls

AI inquiry audit records have a 90-day database expiry. Daily-quota and AI-budget records also have database expiry controls. Temporary in-memory rate-limit data lasts for the relevant request-limit window or process lifetime.

Provider records, analytics, logs and backups

MTechLab has confirmed that provider retention terms have been agreed. Their exact periods, the PostHog project settings and backup/log schedules have not been supplied for this draft and must be recorded before publication. We do not present a vendor’s general default as our agreed setting. Deleting a main database record does not instantly remove email copies, backups or provider records.

Back to contents ↑

05. Third-party disclosure

The website’s current data flows do not include selling submitted information or providing it to unrelated advertisers. Authorized MTechLab staff use it for the stated purposes. Providers listed below process information to deliver the services you use; their roles differ from independent websites you choose to visit.

If disclosure is required by an applicable law or valid legal request, MTechLab will assess the request and the information required. A new purpose, recipient or legal obligation requires an appropriate review and updated notice rather than relying on this policy as unrestricted permission.

Back to contents ↑

06. Service providers and outsourced processing

These are the services used by the current website. Infrastructure, email and AI providers support MTechLab’s processing; optional Google sign-in and YouTube interactions also involve a provider’s own terms. Their exact contractual roles and retention must be checked before this draft takes effect.

News media storage · where configured

The news publishing system supports local image storage or DigitalOcean Spaces where configured. Uploaded editorial images are converted to WebP for publication. A direct request to an external media host can expose connection metadata to that host; an image served through the website’s optimizer is requested by our server instead. The active storage provider, country and log retention must be confirmed before publication. This is not a destination for inquiry or account form payloads.

Provider privacy information
Anthropic, PBC · AI assistance

Receives inquiry content and selected context for classification and response drafting, or chat messages/recent history. Structured name, email and phone fields are not included in the inquiry AI payload. Free text is not guaranteed to be anonymous: anything you type in a message may be transmitted.

Provider privacy information
Resend (Plus Five Five, Inc.) · transactional email

Delivers receipt confirmations, replies, staff notifications, booking links and account verification/reset messages. Receives the recipient email address and relevant message content; inquiry emails can include the submitted name, organization, phone, country and message. This is not an unrelated newsletter subscription.

Provider privacy information
Cloudflare, Inc. · Turnstile

Where configured, processes IP address, browser/device characteristics and security tokens to check for automated abuse. The widget runs as a necessary form security check, not as optional PostHog analytics. It is not enabled on every page or in environments without configured keys.

Provider privacy information
PostHog, Inc. · optional analytics

Receives the minimized usage events described in the cookies section only after analytics consent and only where analytics is configured. The code defaults to its EU endpoint; the production project region and agreed retention must be confirmed separately.

Provider privacy information
Google Cloud and MongoDB Atlas · infrastructure

Host the application and its operational data. The existing deployment documentation identifies Google Cloud hosting in Seoul. MTechLab confirmed the production MongoDB Atlas database region as Seoul, Republic of Korea. Provider support access, subprocessors and backup locations still need to be checked against the agreed terms; local storage does not establish that all provider processing stays in Korea.

Provider privacy information
Google · sign-in and YouTube

Google sign-in is initiated only when you choose it. YouTube privacy-enhanced embeds connect only after you activate a video. These optional provider interactions can involve Google processing connection, account or playback information under its own terms.

Provider privacy information
Back to contents ↑

07. Overseas processing

Using a service may send information electronically over encrypted connections to the provider below. Transfer timing and items depend on the feature, not simply on visiting this policy. The recipient contact is available through its linked privacy information and MTechLab’s privacy contact.

The exact contract-specific retention periods, final processing countries, recipient contact details and legal basis for each transfer require completion before publication. MTechLab has confirmed agreements exist, but their precise settings were not supplied. The country of a provider’s headquarters is not proof of every processing location.

Anthropic · United States-based provider

When an inquiry AI pipeline or AI chat is used: message content, selected inquiry context or recent chat history, for classification and response generation. Structured inquiry name/email/phone fields are excluded; information typed into the message itself is not automatically excluded. Retention: agreed provider terms, exact period pending confirmation.

Resend · United States-based provider

When service emails are sent: recipient addresses and the relevant inquiry, booking or account message, for delivery and delivery monitoring. Retention: agreed provider terms, exact period pending confirmation.

Cloudflare · United States-based provider / global infrastructure

When an enabled Turnstile form security check runs: IP address, browser/device characteristics and challenge tokens, for abuse prevention. Exact processing locations and retention need confirmation for the configured service.

PostHog · EU endpoint configured by default

Only after optional analytics consent: minimized page/click events, random identifiers and browser/device information, to understand site use. Verify the production project country and retention setting before publication. Declining or withdrawing consent stops future capture on this browser.

Google · United States-based provider / global infrastructure

On Google sign-in or video activation: account/connection or playback information for the selected Google service. Countries and retention depend on Google’s service terms and your account settings.

Back to contents ↑

08. Deletion and exceptions

The approved policy is to remove information when its purpose and retention period end, or when a valid deletion/withdrawal request applies, unless an applicable law requires retention. Before launch, MTechLab must verify the responsible workflow for database records, correspondence, provider copies and backups. This page does not itself delete records or install deletion jobs.

Electronic deletion should make the record unavailable for ordinary use and follow the relevant storage system’s secure removal process. Any paper records should be shredded or otherwise securely destroyed. Where specific information must be preserved by law, its legal basis, items and period must be documented and access restricted rather than assigning a blanket retention period to every inquiry.

Back to contents ↑

09. Your rights and how to exercise them

You may ask MTechLab to access or correct your information, delete it, restrict/suspend processing where applicable, or withdraw consent. Tell us the relevant service and the request, using the contact below. Account profile details can also be edited in your profile. For account deletion or notification withdrawal, contact our team; a self-service deletion/unsubscribe tool is not currently provided.

We may need proportionate information to verify that you or your authorized representative may make the request. Do not attach identity documents to an initial email. If a request cannot be fulfilled because of an applicable legal obligation or another valid limitation, the reason should be explained. The relevant right and response deadline depend on the applicable law.

Withdrawing analytics consent stops future capture and removes PostHog identifiers from this browser. It does not automatically erase already-received provider events; contact MTechLab if you also seek deletion of existing information. Blocking necessary authentication cookies can prevent sign-in, but does not prevent public browsing.

Back to contents ↑

10. Children and sensitive information

The current website does not provide a parent/guardian consent-verification workflow for children under 14. Children under 14 should not register, submit personal information or use AI chat on this website; a parent/guardian or institution should contact MTechLab instead. If you believe a child’s information was submitted, contact us so it can be reviewed and handled appropriately.

MR.Brain-Edu is an educational product, but a school or museum inquiry on this website should be made by its adult contact person. These forms do not request student rosters, patient records or clinical images. This policy does not establish a legal basis to collect sensitive information accidentally entered into free text.

Back to contents ↑

11. Cookies, local storage and embedded media

Saved account display and route settings

mtechlab-auth in localStorage stores the signed-in user’s account ID, email, role and email-verification status, not access or refresh tokens. Signing out replaces the saved user with an empty value; browser storage can also be cleared manually. The mtechlab_admin route-hint cookie expires after 30 days and is removed on logout; it is not an authorization credential. Language preference may be remembered in a NEXT_LOCALE cookie.

Necessary account storage

The API refresh cookie mtechlab_rt is HttpOnly, secure in production and SameSite=Lax, with a 30-day expiry. It is cleared on logout. Access tokens are held in memory rather than localStorage. Browser/session settings such as the selected language may also be used for necessary site behavior.

Your analytics choice

mtechlab_analytics_consent in localStorage records granted or denied. It stays until you change your choice or clear browser storage. It stores a choice, not your contact form information. Use Cookie settings in the footer or the button below to change it.

Optional PostHog identifiers and events

PostHog is not loaded until consent is granted. Where configured, it uses ph_ / __ph_ storage identifiers and pseudonymous page/click events. Event URLs are stripped of query strings and fragments; booking tokens are excluded. Capture is disabled on authentication, account, admin, booking-confirmation and internal email-preview routes. Form values and element text are masked; session replay and heatmaps are disabled. The current integration does not identify visitors by email or name.

YouTube videos and external links

Video previews are hosted locally; a youtube-nocookie.com player loads only after you press play. Activating it contacts Google/YouTube, which may process IP address, browser details and playback data. Privacy-enhanced mode does not mean no personal information is processed. External links, including the education site and book retailer, start the destination’s own processing when visited.

Back to contents ↑

12. Safeguards

Implemented application controls include password hashing, hashed refresh tokens, HttpOnly authentication cookies, access-controlled administrative routes, input validation, rate limiting, conditional anti-abuse checks and analytics data minimization. Production authentication cookies use the Secure flag. These controls reduce risk but do not constitute a guarantee that every system or supplier is free from security incidents.

MTechLab must also maintain appropriate staff access management, processor oversight, backup handling and incident-response procedures. Organizational measures and contractual safeguards should be verified before publication rather than inferred from code alone.

Back to contents ↑

13. Privacy contact and independent help

MTechLab is the published organizational contact for this policy, as confirmed by the company. Requests can be sent using the email, telephone or head-office details below. This draft does not name an individual privacy officer; any legally required officer designation must be verified separately before publication.

In the Republic of Korea, independent complaint and dispute-resolution information is available from the Korea Internet & Security Agency’s Privacy Infringement Report Center (118) and the Personal Information Dispute Mediation Committee (1833-6972). You may also contact the appropriate authority in your jurisdiction where applicable.

Privacy Infringement Report Center

118 · privacy.kisa.or.kr

Privacy Infringement Report Center
Personal Information Dispute Mediation Committee

1833-6972 · kopico.go.kr

Personal Information Dispute Mediation Committee
Back to contents ↑

14. Version and changes

Version: local review draft dated 7 October 2026. No effective date has been assigned. The company-approved business retention schedule is included, but operational deletion controls and full provider/transfer details remain publication prerequisites.

When approved for publication, MTechLab should state the effective date and version here, describe material changes and give any advance notice or renewed consent required by applicable law. Previous versions should be retained for reference. This website policy does not replace a separate agreement for a future paid, clinical or patient-data service.

Back to contents ↑

Contact MTechLab about your information

For access, correction, deletion, consent withdrawal or questions about this policy, contact MTechLab using the details below. Please do not send identity documents or patient records with your initial request.

Privacy contact / data controller
MTechLab
Head office
Room B1027, 119 Songdo Munhwa-ro, Yeonsu-gu, Incheon (Songdo-dong, Incheon Global Campus)