How Tamats collects, uses, shares and protects personal data.
Last updated July 17, 2026
Tamats (“Tamats,” “we,” “us”) is a cosmetics research workspace where users chat with a specialized agent to search cited literature, analyze ingredients, build formulations, check regional compliance and prepare manufacturer outreach. This policy explains what personal data we process and the choices you have. It applies to tamats.org and app.tamats.org.
Tamats is operated by Axion AI Lab (registered as Axion AI / 엑시온 에이아이), a sole proprietorship (개인사업자) in the Republic of Korea, at 10, Olympic-ro 30-gil, Songpa-gu, Seoul, Republic of Korea. Axion AI Lab is the data controller for the account and usage data described below. For data you enter while using the product (your research, uploads and formulations), you direct the processing and we act on your behalf as described in our Data Processing Addendum.
We process personal data to:
Legal bases (EEA/UK, GDPR). We rely on: performance of a contract (providing the service); legitimate interests (securing and improving the service); consent (analytics cookies and optional marketing); and legal obligation (accounting, responding to lawful requests). You may withdraw consent at any time.
To answer your questions, the content you submit is sent to our large-language-model provider for inference and to retrieval sources you invoke. We do not use your private content to train our own models. Our providers process this content under their terms as our subprocessors — see the Data Processing Addendum.
AI output can be incomplete or wrong and is not professional, regulatory, medical or legal advice. Factual and regulatory claims are cited to sources where available; verify before relying on them.
We share personal data only with:
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
We and our subprocessors may process data in the United States and other countries. Where data leaves the EEA, UK, Korea or Japan, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK addendum), the consent and disclosure required under Korea’s PIPA and Japan’s APPI, or an equivalent lawful transfer mechanism. Contact us for details of the transfer and the relevant safeguards.
We keep personal data while your account is active and as needed to provide the service, then delete or anonymize it within a reasonable period, except where longer retention is required for legal, accounting or security reasons. You can delete workspace content at any time, and request account deletion as described in section 8.
We use organization-scoped access controls (row-level security), encryption in transit, least-privilege access and audit logging to protect data. No method is perfectly secure, but we work to protect your information and to notify you of incidents where required.
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, and to data portability. To exercise any right, email team@tamats.org. Where the GDPR applies we respond within one month (extendable for complex requests); elsewhere we respond within the period required by law. You may also lodge a complaint with your local data-protection authority — in the EEA your national authority, and in the UK (where the same rights apply under the UK GDPR) the Information Commissioner’s Office (ICO).
Marketing. We only send marketing email where permitted, and you can opt out at any time using the unsubscribe link in the email or by contacting us. Opting out of marketing does not stop essential service, security or transactional messages.
If a personal-data breach is likely to affect you, we will notify you and the relevant supervisory authority within the timeframes required by applicable law (for example, without undue delay under the GDPR, and as required under Korea’s PIPA). Our notice will describe the breach, the data involved, the steps we are taking, and what you can do to protect yourself.
The service and its cited sources may link to third-party websites we do not control. We are not responsible for their content or privacy practices; review their policies before providing personal data.
If you are a California resident, you have the right to know the categories of personal information we collect, to access and delete it, to correct inaccuracies, and to be free from discrimination for exercising these rights.
We do not sell your personal information and do notshare it for cross-context behavioral advertising, so no “Do Not Sell or Share My Personal Information” action is required. Submit a rights request to team@tamats.org; we will verify and respond as required by law. You may use an authorized agent.
Do Not Track.We do not currently respond to browser “Do Not Track” or Global Privacy Control signals. Analytics cookies stay off for every visitor unless you opt in (see our Cookie Policy), and we do not sell or share personal data, so there is no sale or sharing for such signals to opt you out of.
Residents of other US states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah and Texas) have similar rights to access, correct, delete and obtain a copy of their personal information, and to appeal our decision. Contact us at the same address to exercise them.
For users in the Republic of Korea, we process personal information in accordance with the Personal Information Protection Act (PIPA). We collect only the information needed for the purposes above, obtain consent where required, and entrust processing to subprocessors in the categories listed in our DPA(including transfer of personal information overseas for hosting and AI inference). Details of entrusted parties and overseas recipients are available on request.
You may request to access, correct, delete or suspend processing of your personal information, and withdraw consent, by contacting team@tamats.org. You may also file a complaint with the Personal Information Protection Commission (PIPC).
Privacy Officer (개인정보 보호책임자). Axion AI Lab designates a privacy officer responsible for handling personal information and your requests, reachable at team@tamats.org.
For users in Japan, we handle personal information under the Act on the Protection of Personal Information (APPI). We use personal information for the purposes described in section 3, and do not use it beyond those purposes without consent or as permitted by law.
Cross-border transfer. Providing the service involves transferring your personal information to our subprocessors in the United States and other countries (see our DPA). By using the service you consent to this transfer; we provide information about the recipients and the data-protection systems of the destination countries on request.
You may request disclosure, correction, addition, deletion, suspension of use or cessation of third-party provision of your retained personal data by contacting team@tamats.org. You may also consult the Personal Information Protection Commission (PPC) of Japan.
Tamatsis a business tool not directed to children. We do not knowingly collect personal data from children — anyone under 16, or the lower age set by local law where applicable (for example 14 under Korea’s PIPA). If you believe a child has provided us data, contact us and we will delete it.
We may update this policy; we will change the “last updated” date and, for material changes, provide additional notice. Continued use after an update means you accept the revised policy.
Questions or requests: team@tamats.org.