Privacy Policy
Last updated August 2026
This policy describes how Provotive Co. LTD (“Provotive”, “we”, “us”), the company behind Packative One, collects, uses, and protects personal data on packative.one. It covers the website only; data processed inside the Packative One product on behalf of customers is governed by the customer's agreement with us.
Who Is Responsible
The controller is Provotive Co. LTD, 1414, B, Dangsan-dong 1-ga, Yeongdeungpo-gu, Seoul, Republic of Korea. Business registration number: 614-81-05201. Telephone: +82 2 707 0611. Email: one@packative.com.
Privacy Officer: Dominik Danninger, Founder and Technical CEO. Telephone: +82 2 707 0611. Email: one@packative.com, or write to the postal address above marked for the Privacy Officer. The Privacy Officer receives privacy requests and complaints and supervises the protection of personal data.
What We Collect
We process the following categories, and only these:
- Demo enquiries: name, work email, company, business segment, quote-volume range, region, and an optional message
- Contact enquiries: name, email, optional company, contact reason, and message
- ROI requests: name, work email, company, calculator inputs, calculated results, and the generated report
- Attribution: campaign parameters, advertising click identifiers, referrer, landing path, and a first-touch timestamp, kept in your browser for 90 days
- Analytics, after consent: a random identifier, the page path without query parameters, device and browser class, interaction events, and consent state
- Technical and security records: IP address, request headers, date and time, requested URL, response status, browser and device data, and abuse-prevention events
- Consent records: the categories chosen, the policy and banner version, the time of the choice, any withdrawal, and the country the request came from
Why We Use It, and on What Basis
We use enquiry data to take the steps you request, answer your message, arrange a demo, deliver an ROI report, and manage the resulting business relationship. Under PIPA Article 15(1)(4) and GDPR Article 6(1)(b), this processing is necessary to act at your request before a possible contract.
We use limited technical and security data to deliver and secure the site under PIPA Article 15(1)(6) and GDPR Article 6(1)(f). Our legitimate interests are reliable delivery, abuse prevention, and information security.
We use analytics only after separate Analytics consent. We use an email address for promotional email only after separate marketing consent. We use advertising and retargeting technologies only after separate Advertising consent.
We do not sell personal data. We share limited advertising data with Google, Meta, and any other platform named below only after Advertising consent. Those platforms may act as independent or joint controllers for their own advertising purposes.
Cookies and Consent
Before you choose, only strictly necessary technologies operate. PostHog does not load or receive an event until you enable Analytics. Google Ads, Meta Ads, and other advertising or retargeting technologies do not load or receive an event until you enable Advertising. Analytics and Advertising are separate choices. Rejecting either choice does not affect the site or its forms. Open Privacy choices in the footer to withdraw or change a choice, and see the Cookie Policy for the detail.
Advertising and Retargeting
If you choose Advertising in our privacy settings, we use Google Ads, Meta Ads, and any other advertising platform named in this policy to measure campaign performance, limit repeated ads, create website audiences, and show Packative One advertising on other services. These tools may collect an advertising or click identifier, IP address, device and browser data, consent status, the page path without query parameters, and an event such as “demo request completed”. They may associate that information with information held in their own accounts. We do not load or call an advertising or retargeting tag until you give separate Advertising consent.
With Advertising consent, Google LLC and, where applicable, Google Ireland Limited receive that data for conversion measurement, audience creation, frequency control, and retargeting, in the United States and Ireland. Google Consent Mode remains denied for ad storage, ad user data, and ad personalisation until you grant Advertising consent. We limit advertising click identifiers to 90 days and our own audience membership to 180 days. You may also use Google Ads Settings at adssettings.google.com.
Enhanced conversions are part of that measurement, and they apply only where you chose Advertising yourself. When you submit a form after making that choice, the conversion sent to Google may carry a one-way SHA-256 hash of the email address you typed. The hash is computed in your browser, so the readable address never leaves the page, and Google uses it to match the conversion to an ad click. Where Advertising applies by a regional default rather than by a choice you made, no hash is sent. A hashed email address is still personal data, which is why it is named here and covered by your Advertising consent.
With Advertising consent, Meta Platforms Ireland Limited and Meta Platforms, Inc. receive that data through the Meta Pixel for conversion measurement, audience creation, and retargeting, in Ireland and the United States. We limit our Meta audience membership to 180 days. Meta may retain event data for up to two years under its own terms. You may also manage off-Meta activity in your Meta account.
Advertising is optional. You may refuse or withdraw it without losing access to the site, a demo response, a contact response, or an ROI report. Withdrawal does not affect processing that was lawful before it.
We never send an advertising platform your name, telephone number, message, ROI inputs or results, quote volumes, prices, margins, customer or product data, CRM identifier, or any analytics identifier linked to your email. The one exception is the hashed email address described above, sent to Google alone, only with a chosen Advertising consent, and only to match a conversion to an ad click. A hash is still personal data, so it is named here rather than treated as anonymous.
Who Receives It, and Where
We share personal data only with the service providers below, only for the purpose stated, and only after the consent named where consent applies. Each entry gives the recipient, the country, the purpose, what is sent, and how long they keep it, as PIPA Article 28-8 requires.
- Vercel Inc. (United States), privacy@vercel.com: hosting, content delivery and security. Receives IP address, request headers, device and browser data, URL and timestamp on each request. Logs under our control are kept 30 days. Necessary to deliver the site; refusing means the site cannot be served
- PostHog Inc. (United States), privacy@posthog.com: website analytics, after Analytics consent only. Receives a random identifier, page path without query parameters, device class and event names. Kept 12 months. Refusing has no effect on the site or your enquiry
- Plus Five Five, Inc., trading as Resend (United States), privacy@resend.com: sends the reply to your enquiry and the ROI report, and holds the marketing list where you opted in. Receives name, email, company, enquiry type, the report, and for the list your consent status. Enquiry mail is kept 30 days; list membership lasts until withdrawal or 24 months of inactivity. Refusing marketing has no effect on your enquiry
- Amazon Web Services (Republic of Korea): hosts our own CRM and its lead records. Korean storage is not an overseas transfer; any support access from outside Korea is covered by our agreement with AWS
- Google LLC and Google Ireland Limited (United States and Ireland): advertising measurement and retargeting, after Advertising consent only, as described above. Receives an advertising or click identifier, the page path without query parameters, and the conversion event; where you chose Advertising yourself, also a one-way SHA-256 hash of your email address, used to match the conversion to an ad click. Google keeps conversion data under its own terms
- Meta Platforms Ireland Limited and Meta Platforms, Inc. (Ireland and United States): advertising measurement and retargeting, after Advertising consent only, as described above
Refusing an Overseas Transfer
You may refuse an optional overseas transfer by leaving the related consent off, or by withdrawing it in Privacy choices. Refusing analytics, marketing, or advertising transfers has no effect on the site or on an enquiry. A transfer that is necessary to deliver a requested reply is identified as such above. If you would rather that transfer did not happen, write to one@packative.com and we will reply directly. For EEA and UK data you may request a copy of the applicable transfer safeguard from the Privacy Officer.
How Long We Keep It
These are the periods we apply, not estimates:
- Demo, contact and ROI enquiry records: 24 months after the last substantive interaction, unless you become a customer or ask for deletion sooner
- ROI report and detailed inputs: 30 days after the report is delivered, apart from a summary held with the lead record
- Marketing contacts: until withdrawal, or 24 months after the last engagement, whichever comes first
- Marketing consent and withdrawal evidence: 3 years after withdrawal or the last commercial email
- Analytics events: 12 months from collection
- Attribution in your browser: 90 days from the first visit, after which it expires automatically
- Advertising click identifiers: 90 days. Audience membership we control: 180 days
- Security and access logs under our control: 90 days, unless an incident requires a legal hold
- Internal alerts and transactional email records: 30 days
- Your cookie choice on this device: 12 months, after which we ask again
How We Destroy It
When a retention period expires or a purpose is completed, we delete the personal data without undue delay. Electronic records are deleted using methods designed to prevent restoration. Data retained because a statute requires it is separated from active records and used only for that purpose. Backups expire through the normal backup rotation and are not restored except for disaster recovery. The Privacy Officer supervises destruction.
Marketing Email
We send promotional email only after a separate, unticked marketing consent. The sender is Provotive Co. LTD. The messages contain Packative One product news, educational content, event invitations, and offers, no more than once a month. Each commercial email is clearly marked as advertising in the subject line and states our name, email address and business address. Each message provides a free unsubscribe method that needs no login and no additional personal data.
We stop commercial email after refusal or withdrawal, tell you the result within 14 days, and reconfirm consent every two years. Refusing changes nothing about the answer to your enquiry, your demo, or your ROI report.
Your Rights
You may request access to, correction or deletion of, or suspension of processing of your personal data under PIPA Articles 35 to 37, and you may use an authorised agent. You may withdraw consent at any time, and withdrawal does not affect processing that was lawful before it. Where the GDPR or UK GDPR applies you may also request erasure, restriction, portability, and objection, and you may object to direct marketing at any time. We do not make decisions with legal or similarly significant effects about you by automated means on this website.
Send a request to one@packative.com or to the Privacy Officer at the postal address above. We may verify your identity and authority. We respond within the period the applicable law requires, and we explain any lawful limit or refusal and how to challenge it.
You may refuse optional Analytics, Advertising, and marketing consent without losing access to the site or a response. You may refuse the data a form needs, but we may then be unable to answer that form; you can instead email one@packative.com with whatever information you choose to give.
You may complain to the Personal Information Infringement Report Center at privacy.kisa.or.kr or 118, the Personal Information Dispute Mediation Committee at kopico.go.kr or 1833-6972, or the Korean National Police at ecrm.police.go.kr or 182. In the EEA you may complain to your national supervisory authority, and in the United Kingdom to the Information Commissioner's Office at ico.org.uk.
How We Protect It
We apply access controls, least-privilege permissions, transport encryption, vendor security review, logging, incident procedures, staff confidentiality obligations, and encryption at rest where the service supports it. We maintain the safeguards required by PIPA Article 29 and its Enforcement Decree, and review them in proportion to the risk.
Children
This is a business website and is not directed at children. We do not knowingly collect personal data from anyone under 14. If you believe a child has sent us personal data, write to one@packative.com and we will delete it.
Changes to This Policy
We update this policy when our processing changes. The date at the top is the version in force. Where a change introduces a new purpose that needs your consent, we ask for that consent before the purpose begins rather than relying on the update alone.
Questions about this policy? Email one@packative.com.