Privacy Policy

The Japanese original is authoritative; this translation is provided for reference only.

Kurashi Tech Co., Ltd. (the “Company”) establishes this Privacy Policy (this “Policy”) as follows concerning the handling of information about customers who use the various services and websites provided by the Company (collectively, the “Services”).

Terms such as “personal information,” “personal data,” and “retained personal data” used in this Policy have the meanings prescribed in the Act on the Protection of Personal Information (Act No. 57 of 2003; the “APPI”).

Article 1 Information Collected through the Services

The Company may collect the following information from customers through the Services. If this information is not provided, customers may be unable to use all or part of the Services.

1. Information collected directly when a customer registers for the Services, changes registration details, or makes an inquiry or other communication (examples)

  • Information about the customer, such as name, email address, and telephone number
  • Information about the customer’s company, such as company name and department
  • Information about the customer’s use of the Services, including the selected plan (including contract details, billing date, and expiration date), purpose of use, and work to be outsourced
  • Information entered or transmitted by the customer through methods designated by the Company, including inquiries, evaluations, and complaints

2. Information collected through services operated by third parties

If a customer authorizes the Company to collect information about the customer through a service operated by a third party, the Company may collect that information. In such a case, the Company may combine information collected directly from the customer with information obtained from the third party to improve the Services and provide advertising suited to the customer’s interests.

Article 2 Purposes of Use of Personal Information

The Company uses personal information collected in connection with the Services for the following purposes:

  • To accept registrations, verify identity, calculate usage fees, and otherwise provide, maintain, protect, and improve the Services
  • To announce information about the Services, events and campaigns, and changes to terms and other rules
  • To perform operations, communicate, complete procedures, and respond to inquiries concerning the Services
  • To provide information and respond to inquiries concerning the Services and other services of the Company or third parties that the Company (including its partners and contractors) considers useful
  • To address violations of the Company’s terms and other rules concerning the Services, as well as complaints, disputes, and litigation
  • To create statistical data concerning use of the Services in a form that does not identify individuals
  • To plan, develop, or implement future Services
  • To deliver prizes to customers selected in campaigns and similar promotions
  • To research market and customer trends and carry out the Company’s marketing activities
  • For purposes incidental to the purposes above

Article 3 Provision to Third Parties

The Company may provide collected personal data to a third party in the following cases:

  1. When permitted by the APPI or other laws and regulations
  2. When the customer has given consent
  3. When the customer violates the Company’s terms and there are sufficient grounds to conclude that disclosure is unavoidable to protect the Company’s rights, property, services, or similar interests
  4. When necessary to protect a person’s life, body, or property and it is difficult to obtain the individual’s consent
  5. When cooperation with a national or local government body, or a person entrusted by such a body, is necessary for the performance of duties prescribed by law, and obtaining the customer’s consent could impede those duties
  6. When requested by a court or other public authority
  7. When the Company’s business, including personal information, is succeeded through a merger, company split, business transfer, or other cause

Article 4 Outsourcing the Handling of Collected Personal Data

Within the scope necessary to achieve the purposes of use, the Company may outsource all or part of the handling of collected personal data in connection with outsourcing operations to a contractor. The Company will thoroughly assess the contractor’s suitability, include confidentiality and other necessary provisions in the contract, and establish a system for appropriate information management.

Within the scope necessary to achieve the purposes of use, the Company may outsource all or part of the handling of collected personal data in connection with the use of external services. The Company will thoroughly assess the suitability of each external service, include confidentiality and other necessary provisions in the contract, and establish a system for appropriate information management.

In carrying out Paragraphs 1 and 2, the Company may store or process collected personal data outside Japan.

Article 5 Retention Period and Security Management of Personal Data

Within the scope necessary to achieve the purposes of use, the Company endeavors to keep personal data accurate and current and to delete it without delay when a legally required retention period has expired or the data is no longer needed. The Company has also established an Information Security Policy. The Company takes necessary and appropriate measures to prevent leakage, loss, or damage and otherwise securely manage personal data, including personal information that the Company has collected or intends to collect and plans to handle as personal data.

Article 6 Disclosure, Correction, Suspension of Use, and Other Handling of Retained Personal Data

If a customer requests disclosure of retained personal data under the APPI, the Company will, only where it is legally obligated to disclose the data, verify that the request is from the customer and disclose the data without delay. A disclosure fee may be charged under procedures separately prescribed by the Company.

If a customer requests correction under the APPI because retained personal data is inaccurate, or requests suspension of use because the data is handled beyond the previously published purposes of use or was obtained by deception or other improper means, the Company will verify that the request is from the customer, promptly conduct the necessary investigation, correct the data or suspend its use based on the results, and notify the customer.

If a customer requests deletion of retained personal data, the Company will, only where it determines that the request should be granted, verify that the request is from the customer, delete the data without delay, and notify the customer.

When making a request under the preceding paragraphs, the customer must submit the following details and any other information or materials prescribed by the Company:

  • Name, address, telephone number, and email address
  • Details and background of the request and supporting materials
  • Identity verification documents

The Company may be unable to grant a request under Paragraph 1 or 2 in any of the following cases. In such a case, the Company will notify the customer and explain the reason:

  • If there is a risk of harming the life, body, property, or other rights or interests of the customer or a third party
  • If there is a risk of materially impeding the proper conduct of the Company’s business
  • If granting the request would violate a law or regulation
  • If the Company cannot verify that the request was made by the customer

Article 7 Contact Point

For comments or questions about this Policy or the Services, other inquiries concerning the handling of personal information, or requests under Article 6, please contact the address listed on the Company’s website.

Last revised: March 1, 2025

Information Security Policy

Core Principles

Kurashi Tech Co., Ltd. (the “Company”) conducts its business under the principle of maximizing benefits for society and for itself by maximizing benefits for its customers.

Information assets handled in the Company’s business, including customer information, are critically important foundations of its management.

All persons who handle information assets, including officers and employees, recognize the importance of protecting them from risks such as leakage, damage, and loss, comply with this Policy, and carry out activities to maintain information security, including confidentiality, integrity, and availability.

Basic Policy

  • To protect information assets, the Company establishes and conducts its business in accordance with this Information Security Policy and related rules, and complies with laws, regulations, other standards concerning information security, and its contractual obligations to customers.
  • The Company defines criteria for analyzing and evaluating risks to information assets, including leakage, damage, and loss; establishes a systematic risk-assessment method; conducts assessments regularly; and implements necessary and appropriate security measures based on the results.
  • The Company establishes an information-security structure led by the responsible officer and clearly defines related authority and responsibility. It also regularly educates, trains, and raises awareness among all workers so they recognize the importance of information security and handle information assets appropriately.
  • The Company regularly inspects and audits compliance with its information-security policies and the handling of information assets, and promptly takes corrective action on identified deficiencies and areas for improvement.
  • The Company takes appropriate action in response to information-security events and incidents and establishes response procedures in advance to minimize harm if they occur. It responds promptly and takes appropriate corrective action in an emergency. In particular, it ensures business continuity by establishing and regularly reviewing a management framework for incidents that could disrupt operations.
  • The Company establishes and implements an information security management system with objectives designed to realize its core principles, and continuously reviews and improves that system.

Established May 26, 2026

Kurashi Tech Co., Ltd.

Representative Director: Ryota Ichioka