01. Who we are and what this policy covers
MTechLab is responsible for the personal information processed through mtechlab.co.kr and its English and Korean pages. This policy covers browsing, product and technical inquiries, MR.Brain-Edu inquiries submitted on this website, meeting requests, account services, module launch notifications, AI assistance and optional usage analytics.
The separate education website at edu.mtechlab.co.kr has its own privacy policy. A link to that site does not send your main-site form submission to the education website. External websites, retailers, publications and services handle information under their own policies.
This website is not a patient-record system. Current interactive MRI demos use supplied sample images, not visitor-uploaded scans. Do not enter patient information, health records, identification numbers, payment details or other sensitive information in forms or chat.
Education website privacy policy ↗Back to contents ↑02. Information we collect
Information comes from the details you enter, account providers you choose, necessary security requests and—only if you accept—optional analytics. Optional form fields may be left blank. Required fields are identified in each form.
- Published professional information
Company, research and news pages may display professional names, affiliations, biographies and event photographs from published company/editorial records. These are not details collected from every visitor. Contact MTechLab about access, correction or removal concerns relating to published personal information. Publication permissions and retention for editorial materials should be included in the company’s review.
- Product and technical inquiries
Required: name, email, product interest and message. Optional: company/institution, phone and country. We also store the submission time, inquiry source and handling status; an account identifier may be associated where supplied. The general inquiry service can draft an AI first reply.
- MR.Brain-Edu inquiries and document requests
Required: name, institution, email, inquiry type, institution type and message. Optional: role, phone, country and timeline. A requested document/resource is recorded when selected. These inquiries use the main website’s inquiry, receipt-email and AI-response pipeline.
- Meeting requests and appointments
Required: name, email and the topic/message required by the selected form. Optional: company, phone and country. Scheduling records include proposed and confirmed times, meeting format, online platform, status, secure booking-link tokens and, where applicable, the originating inquiry. The pads booking dialog and contact-page meeting mode do not use the AI first-reply pipeline. The separate appointment inquiry page uses the general inquiry service and may receive an AI reply.
- Accounts and saved preferences
Personal accounts: email, password, first/last name and country, with institution, position and phone when provided. Organization accounts: organization name, type, country, contact person, position and phone, plus optional website, size and business registration number. Passwords are stored as hashes, not readable passwords. We store account role, verification status, saved product favorites and hashed refresh tokens. Google sign-in supplies your Google account identifier, email and name instead of a website password.
- Module launch notifications
Email address, the module you selected, consent time and registration/update time. The purpose is to notify you about that module, not to enroll you in unrelated marketing. You can withdraw through MTechLab’s privacy contact.
- AI chat
Your current message and up to ten recent conversation messages are sent to our API and Anthropic to generate a response. Conversation messages are held in the open chat’s browser memory; the current application does not save a chat transcript to its database. This does not mean the AI provider has zero retention. A chat connection also exposes necessary network metadata such as IP address.
- Security, service logs and AI reply audit records
Requests may include IP address, browser/device information, requested URL, timestamp, error information and security-check tokens. Rate-limit and daily-quota systems use request identifiers or hashed identifiers. AI inquiry audit records can contain the inquiry reference, name, email, processing outcome and a reply excerpt of up to 300 characters; they are separate from chat transcripts.
- Optional analytics and external media
After analytics consent, PostHog receives pseudonymous page-view/click events, random identifiers and browser/device information. YouTube receives connection and playback information only when you activate an embedded video. Google receives information when you choose Google sign-in. See the cookies and transfers sections for details.
03. Why we use information and your choices
We use submitted information to answer inquiries, arrange meetings, provide requested education materials, operate accounts and favorites, verify email addresses, restore access, send selected module launch updates and protect the service from abuse. Optional analytics helps us understand aggregate site use and improve the website.
Inquiry, booking and notification forms require their indicated collection/use consent before submission. Where applicable, their notice also describes overseas processing. You may refuse and continue browsing, but the corresponding online request cannot be submitted. Creating an account requires the information necessary to provide that account; optional fields are not a condition of browsing.
Analytics consent is separate from inquiry and account processing. Declining analytics does not prevent forms, account access or browsing. You can choose not to use AI chat, Google sign-in or embedded videos and contact our team directly instead. AI helps provide general information and draft replies; it does not make medical diagnoses or binding commercial decisions.
Back to contents ↑04. How long information is kept
The business retention periods below were approved by MTechLab for this policy. The current application does not automatically enforce the inquiry, confirmed-meeting, account or notification schedule. MTechLab must establish and verify deletion handling before this draft takes effect. Database expiry is asynchronous, not an exact-time deletion guarantee.
- Inquiries, including MR.Brain-Edu
Approved period: 3 years from the last contact. This includes the inquiry record and related correspondence. The last-contact tracking and deletion procedure still require implementation or a verified operating procedure.
- Confirmed meetings
Approved period: 1 year after the meeting. Unconfirmed booking records currently have a 14-day expiry after application, reset to 7 days when staff propose times. Confirmation removes that temporary expiry.
- Accounts
Approved period: until account deletion. Deletion requests are handled through MTechLab; no self-service deletion or automatic dormant-account deletion is currently offered. Verification and reset credentials have their own expiry.
- Launch notifications
Approved period: until the selected notification has been sent or consent is withdrawn, and no longer than 2 years from registration. The current database does not automatically expire these registrations.
- AI reply audit records and temporary controls
AI inquiry audit records have a 90-day database expiry. Daily-quota and AI-budget records also have database expiry controls. Temporary in-memory rate-limit data lasts for the relevant request-limit window or process lifetime.
- Provider records, analytics, logs and backups
MTechLab has confirmed that provider retention terms have been agreed. Their exact periods, the PostHog project settings and backup/log schedules have not been supplied for this draft and must be recorded before publication. We do not present a vendor’s general default as our agreed setting. Deleting a main database record does not instantly remove email copies, backups or provider records.
06. Service providers and outsourced processing
These are the services used by the current website. Infrastructure, email and AI providers support MTechLab’s processing; optional Google sign-in and YouTube interactions also involve a provider’s own terms. Their exact contractual roles and retention must be checked before this draft takes effect.
- News media storage · where configured
The news publishing system supports local image storage or DigitalOcean Spaces where configured. Uploaded editorial images are converted to WebP for publication. A direct request to an external media host can expose connection metadata to that host; an image served through the website’s optimizer is requested by our server instead. The active storage provider, country and log retention must be confirmed before publication. This is not a destination for inquiry or account form payloads.
Provider privacy information- Anthropic, PBC · AI assistance
Receives inquiry content and selected context for classification and response drafting, or chat messages/recent history. Structured name, email and phone fields are not included in the inquiry AI payload. Free text is not guaranteed to be anonymous: anything you type in a message may be transmitted.
Provider privacy information- Resend (Plus Five Five, Inc.) · transactional email
Delivers receipt confirmations, replies, staff notifications, booking links and account verification/reset messages. Receives the recipient email address and relevant message content; inquiry emails can include the submitted name, organization, phone, country and message. This is not an unrelated newsletter subscription.
Provider privacy information- Cloudflare, Inc. · Turnstile
Where configured, processes IP address, browser/device characteristics and security tokens to check for automated abuse. The widget runs as a necessary form security check, not as optional PostHog analytics. It is not enabled on every page or in environments without configured keys.
Provider privacy information- PostHog, Inc. · optional analytics
Receives the minimized usage events described in the cookies section only after analytics consent and only where analytics is configured. The code defaults to its EU endpoint; the production project region and agreed retention must be confirmed separately.
Provider privacy information- Google Cloud and MongoDB Atlas · infrastructure
Host the application and its operational data. The existing deployment documentation identifies Google Cloud hosting in Seoul. MTechLab confirmed the production MongoDB Atlas database region as Seoul, Republic of Korea. Provider support access, subprocessors and backup locations still need to be checked against the agreed terms; local storage does not establish that all provider processing stays in Korea.
Provider privacy information- Google · sign-in and YouTube
Google sign-in is initiated only when you choose it. YouTube privacy-enhanced embeds connect only after you activate a video. These optional provider interactions can involve Google processing connection, account or playback information under its own terms.
Provider privacy information
07. Overseas processing
Using a service may send information electronically over encrypted connections to the provider below. Transfer timing and items depend on the feature, not simply on visiting this policy. The recipient contact is available through its linked privacy information and MTechLab’s privacy contact.
The exact contract-specific retention periods, final processing countries, recipient contact details and legal basis for each transfer require completion before publication. MTechLab has confirmed agreements exist, but their precise settings were not supplied. The country of a provider’s headquarters is not proof of every processing location.
- Anthropic · United States-based provider
When an inquiry AI pipeline or AI chat is used: message content, selected inquiry context or recent chat history, for classification and response generation. Structured inquiry name/email/phone fields are excluded; information typed into the message itself is not automatically excluded. Retention: agreed provider terms, exact period pending confirmation.
- Resend · United States-based provider
When service emails are sent: recipient addresses and the relevant inquiry, booking or account message, for delivery and delivery monitoring. Retention: agreed provider terms, exact period pending confirmation.
- Cloudflare · United States-based provider / global infrastructure
When an enabled Turnstile form security check runs: IP address, browser/device characteristics and challenge tokens, for abuse prevention. Exact processing locations and retention need confirmation for the configured service.
- PostHog · EU endpoint configured by default
Only after optional analytics consent: minimized page/click events, random identifiers and browser/device information, to understand site use. Verify the production project country and retention setting before publication. Declining or withdrawing consent stops future capture on this browser.
- Google · United States-based provider / global infrastructure
On Google sign-in or video activation: account/connection or playback information for the selected Google service. Countries and retention depend on Google’s service terms and your account settings.
08. Deletion and exceptions
The approved policy is to remove information when its purpose and retention period end, or when a valid deletion/withdrawal request applies, unless an applicable law requires retention. Before launch, MTechLab must verify the responsible workflow for database records, correspondence, provider copies and backups. This page does not itself delete records or install deletion jobs.
Electronic deletion should make the record unavailable for ordinary use and follow the relevant storage system’s secure removal process. Any paper records should be shredded or otherwise securely destroyed. Where specific information must be preserved by law, its legal basis, items and period must be documented and access restricted rather than assigning a blanket retention period to every inquiry.
Back to contents ↑09. Your rights and how to exercise them
You may ask MTechLab to access or correct your information, delete it, restrict/suspend processing where applicable, or withdraw consent. Tell us the relevant service and the request, using the contact below. Account profile details can also be edited in your profile. For account deletion or notification withdrawal, contact our team; a self-service deletion/unsubscribe tool is not currently provided.
We may need proportionate information to verify that you or your authorized representative may make the request. Do not attach identity documents to an initial email. If a request cannot be fulfilled because of an applicable legal obligation or another valid limitation, the reason should be explained. The relevant right and response deadline depend on the applicable law.
Withdrawing analytics consent stops future capture and removes PostHog identifiers from this browser. It does not automatically erase already-received provider events; contact MTechLab if you also seek deletion of existing information. Blocking necessary authentication cookies can prevent sign-in, but does not prevent public browsing.
Back to contents ↑10. Children and sensitive information
The current website does not provide a parent/guardian consent-verification workflow for children under 14. Children under 14 should not register, submit personal information or use AI chat on this website; a parent/guardian or institution should contact MTechLab instead. If you believe a child’s information was submitted, contact us so it can be reviewed and handled appropriately.
MR.Brain-Edu is an educational product, but a school or museum inquiry on this website should be made by its adult contact person. These forms do not request student rosters, patient records or clinical images. This policy does not establish a legal basis to collect sensitive information accidentally entered into free text.
Back to contents ↑12. Safeguards
Implemented application controls include password hashing, hashed refresh tokens, HttpOnly authentication cookies, access-controlled administrative routes, input validation, rate limiting, conditional anti-abuse checks and analytics data minimization. Production authentication cookies use the Secure flag. These controls reduce risk but do not constitute a guarantee that every system or supplier is free from security incidents.
MTechLab must also maintain appropriate staff access management, processor oversight, backup handling and incident-response procedures. Organizational measures and contractual safeguards should be verified before publication rather than inferred from code alone.
Back to contents ↑13. Privacy contact and independent help
MTechLab is the published organizational contact for this policy, as confirmed by the company. Requests can be sent using the email, telephone or head-office details below. This draft does not name an individual privacy officer; any legally required officer designation must be verified separately before publication.
In the Republic of Korea, independent complaint and dispute-resolution information is available from the Korea Internet & Security Agency’s Privacy Infringement Report Center (118) and the Personal Information Dispute Mediation Committee (1833-6972). You may also contact the appropriate authority in your jurisdiction where applicable.
- Privacy Infringement Report Center
118 · privacy.kisa.or.kr
Privacy Infringement Report Center- Personal Information Dispute Mediation Committee
1833-6972 · kopico.go.kr
Personal Information Dispute Mediation Committee
14. Version and changes
Version: local review draft dated 7 October 2026. No effective date has been assigned. The company-approved business retention schedule is included, but operational deletion controls and full provider/transfer details remain publication prerequisites.
When approved for publication, MTechLab should state the effective date and version here, describe material changes and give any advance notice or renewed consent required by applicable law. Previous versions should be retained for reference. This website policy does not replace a separate agreement for a future paid, clinical or patient-data service.
Back to contents ↑