KeizAI

KeizAI Privacy Policy

Privacy Policy

Draft — not in force

This document is a draft prepared for review by counsel. It has not been adopted, no version number has been assigned and no effective date has been set. Until it is adopted and published as in force, it creates no rights and no obligations.

Operator
CybermetriQ GK / サイバーメトリック合同会社
Governing law · venue
Laws of Japan · Courts of Tokyo
Contact
legal@kza.jp
Version · effective date
Unset — draft

Operator

Personal information handled in connection with the KeizAI service (the "Service") is handled by CybermetriQ GK, hereinafter referred to as "KeizAI" — Marunouchi Nijubashi Building 2F, 2-3-2 Marunouchi, Chiyoda-ku, Tokyo 100-0005, Japan; corporate number 1010003035578. KeizAI handles personal information under the laws of Japan, including the Act on the Protection of Personal Information (APPI).

Information collected

  • account and profile information the user registers — name, contact details, and for companies the registered company details;
  • records the Service exists to keep — objectives, proposals, nominations, decision records, engagements and their commercial records;
  • communications with KeizAI, including requests sent to the contact address;
  • technical information generated by use — device and browser information, log records, and identifiers needed to keep sessions and the Service secure.

Purposes of use

KeizAI uses personal information for the following purposes (利用目的), and for no others without prior publication of the change:

  • providing and operating the Service, including keeping the records of decisions and engagements that the Service exists to keep;
  • verifying identity and authority, and attributing decision records to the persons who made them;
  • responding to enquiries and requests;
  • maintaining the safety of the Service — preventing fraud, abuse and unauthorised access;
  • improving the Service, including the training described in section 04;
  • complying with legal obligations and responding to lawful requests from public authorities.

Training of systems

KeizAI reserves the right to use data generated in the Service to train the algorithms and systems with which the Service operates — for example fraud-prevention systems and the predictive tools that produce proposals and explanations.

This reservation is limited to those purposes. It is not a licence to use personal information for unrelated purposes, and it does not permit selling personal information or providing it to third parties beyond what this Policy states.

No sale, no sharing

KeizAI does not sell user data and does not share it with third parties, except as this Policy states: to vendors under section 06, with the user's consent, or where Japanese law requires or permits provision without consent.

Should any commitment in this section or section 06 cease to hold, KeizAI will amend this Policy and publish the changed details — with a dated notice on this page — before the change takes effect, so that users can decide whether to continue using the Service.

Vendors

KeizAI entrusts (委託) parts of its processing to vendors — for example hosting and infrastructure — solely so that they can perform actions necessary to provide the Service. KeizAI has expressly entered into agreements only with vendors bound to those conditions, supervises that entrustment as the APPI requires, and does not permit vendors to use the data for their own purposes.

The published list of vendors that process personal information is pending and will be published on this page once finalised. pending counsel

Whether any data flow constitutes joint use (共同利用) under the APPI, and the corresponding notice if so, is under review by counsel and will be published here before any joint use begins. pending counsel

Cross-border handling

Where a vendor under section 06 is located outside Japan, KeizAI takes the measures the APPI requires for provision to a third party in a foreign country — including confirming the vendor's data-protection arrangements and binding the vendor contractually to handling equivalent to this Policy. The allocation of processing responsibilities per data flow is under review by counsel. pending counsel

Security

KeizAI takes organisational and technical safety measures (安全管理措置) appropriate to the data it holds: access on a deny-by-default basis, records of access to authoritative data, encryption in transit, and separation between the authoritative store and derived systems. Details that would weaken security if published are available to the extent the APPI requires on request to the contact address.

Retention

Personal information is kept only as long as necessary for the purposes in section 03 and as required by Japanese law, and is then deleted or anonymised. Statutory retention periods for specific record classes are under review by counsel and will be published here when set. pending counsel

Your requests

A user may request, under the APPI: disclosure of their personal information; correction, addition or deletion of inaccurate information; suspension of use; and suspension of provision to third parties. Requests go to legal@kza.jp. KeizAI will verify the requester's identity, respond without undue delay, and explain any ground on which a request is declined.

Complaints

Complaints about the handling of personal information go to legal@kza.jp. KeizAI will address them in good faith. A user may also raise the matter with the Personal Information Protection Commission of Japan.

Changes to this policy

KeizAI may amend this Policy. Amendments, their reasons where material, and their effective date are published on this page before they take effect. The commitments in section 05 change only by the mechanism section 05 describes.

Contact

All contact concerning this Policy: legal@kza.jp — CybermetriQ GK, Marunouchi Nijubashi Building 2F, 2-3-2 Marunouchi, Chiyoda-ku, Tokyo 100-0005, Japan. Corporate number 1010003035578.