Communitio Corporation (hereafter referred to as “we”) recognizes, in providing our products/services and website, the importance of protecting the personal information of those who avail of our products/services and website (hereafter referred to as “user”) and will protect that information in accordance with the following privacy policy (hereafter referred to as “this privacy policy”) and the Act on the Protection of Personal Information (hereafter referred to as “APPI”) as well as related regulations and guidelines. For users from the EU/EEA/UK, please refer to the EU/EEA/UK Users Privacy Policy. This privacy policy uses the same definition of “personal information” as defined in the APPI Article 2, paragraph 1. More specifically, personal information is defined as information about a living individual which contains a name, date of birth, or other descriptions etc. whereby a specific individual can be identified (including those which can be readily collated with other information and thereby identify a specific individual) or information about a living individual which contains an individual identification code.
1. Purpose of Use
The personal information we collect can be used for the following purposes:
・Providing our services or improving our services
・Providing campaign information relating to our services
・Responding to user inquiries
・Producing statistical and/or analytic documents
Excluding cases when it is allowed by the APPI and related regulations, we will not utilize user personal information beyond the necessary scope to achieve the above purposes without obtaining in advance the user’s consent.
2. Appropriate Data Collection
We will not acquire user personal information by deceit or other improper means. All data collection will be conducted via fair and appropriate means.
3. Providing Information to Third Parties
We will not provide user personal information to third parties without obtaining in advance the user’s consent except in the following cases:
・cases based on laws and regulations
・cases in which there is a need to protect a person’s life, body, or property, and when it is difficult to obtain the individual’s consent
・cases in which there is a special need to enhance public hygiene or promote fostering healthy children, and when it is difficult to obtain the individual’s consent
・cases in which there is a need to cooperate in regard to a central government organization or a local government, or a person entrusted by them performing affairs prescribed by laws and regulations, and when there is a possibility that obtaining the individual’s consent would interfere with the performance of the said affairs
We will endeavor to implement necessary and appropriate measures, such as concluding contracts on the protection of personal information with third parties, when we provide or disclose user personal information to third parties in the case of obtaining in advance the user’s consent or in any of the cases above.
4. Security Measures
In order to protect personal information from unauthorized access, data loss, destruction, alteration, and leakage, we take appropriate security measures. If we entrust the handling of personal information to a subcontractor, we will carefully select a subcontractor with the necessary security safeguards in place as well as conduct appropriate supervision to ensure personal information is being properly protected.
5. Personal Information Access, Correction, and Deletion
When a user requests the disclosure, correction, deletion or suspension of use of their personal information, except in cases where disclosure, etc. is deemed unnecessary based on laws and regulations, we will respond to requests without delay after confirming the identity of the user. However, the user may lose access to our services during or after processing such requests.
6. Inquiries
For inquiries regarding this privacy policy (including the Special Provisions for NewCommunicator Users set forth below), requests regarding personal information, complaints, or questions regarding the use of the personal information, please contact us at the contact details below.
Communitio Corporation
Personal Information Team
e-mail: privacy@communitio.net
7. Changes to this Privacy Policy
This privacy policy (including the Special Provisions for NewCommunicator Users set forth below) is subject to change at any time in accordance with social conditions as well as developments regarding the APPI and other laws, regulations, and guidelines. To see when this privacy policy was last updated, please refer to the bottom of this page. Any changes to this privacy policy will be published on this page, and any major changes will be clearly outlined and publicly announced.
Supplementary Provisions
Established on May 15, 2019
Revised on November 6, 2019
Revised on August 1, 2026
<Special Provisions for NewCommunicator Users>
The Special Provisions for NewCommunicator Users set forth matters concerning information relating to users of NewCommunicator (hereinafter referred to as the “Service”) that we acquire from persons who use the Service (including contracting corporations and their officers, employees, and other personnel, hereinafter referred to as “Service Users”) (such information hereinafter referred to as “User Information”).
1. Items of User Information and Sources of Acquisition
In providing the Service, we may acquire User Information, including the types and specific items set out below, from the corresponding sources indicated therein.
Type of User Information
Specific Items
Source
Information derived from Microsoft Entra ID
・Surname, given name, display name
・Email address
・User Principal Name (an identifier specifying the individual and their affiliation)
・User Object ID (a unique string identifier specific to an individual)
Service User (contracting corporation)
2. Purposes of Processing and Legal Bases
If we process User Information as a controller that determines the purposes and means of processing, we will process User Information for the purposes and on the legal bases set out below, as applicable to the relevant processing. If we process User Information as a processor for a contracting corporation or other Service User as the controller, we will process User Information in accordance with the data processing agreement and other agreements entered into with such Service User.
(1) Where processing is necessary for the performance of a contract to which the Service User is a party, or in order to take steps at the request of the Service User prior to entering into a contract
a. Purpose of providing the Service to Service Users
Information necessary for use of the Service
b. Purpose of maintaining and improving the Service
Information concerning Service Users’ use of the Service that is necessary for maintaining and improving the Service
c. Purpose of responding to inquiries from Service Users
Information necessary to respond to inquiries from Service Users
(2) Where processing is necessary for our compliance with legal obligations
Information whose processing is necessary for us to comply with obligations under applicable laws and regulations
(3) Where processing is necessary to protect the vital interests of Service Users or third parties
Information whose processing is necessary for us to protect vital interests, such as the life or body, of Service Users or third parties
(4) Where processing is necessary for the performance of tasks carried out in the public interest or in the exercise of official authority
Information whose processing is necessary when we carry out tasks performed in the public interest or in the exercise of official authority under applicable laws and regulations
(5) Where processing is necessary for the legitimate interests of the controller or a third party
a. Purpose of researching and analyzing the Service
Information necessary for analyzing the use of the Service and preparing statistics
b. Purpose of promoting use of the Service
Information necessary to provide information about campaigns related to the Service
3. Sharing of User Information and Processing by Entrusted Parties
For the purpose of providing the Service, we have the following entrusted parties process User Information.
Entrusted Party / Sub-processor
Entrusted Processing Operations
Primary Storage Regions
Microsoft Corporation and its affiliates
Processing relating to the storage, computing, and operation of User Information by Microsoft Azure (hosting of the Service)
Azure data centers in the Japan region, the United States region, or the Europe region, depending on the service environment used by the Service User
In the past 12 months, we have not sold or shared User Information with third parties.
4. Rights of Service Users
(1) Service Users have the following rights. We will respond to Service Users’ requests without delay after confirming that the requests satisfy the applicable requirements.
a. Right to be informed (right to receive information)
b. Right of access (right to request disclosure)
c. Right to rectification
d. Right to erasure
e. Right to restriction of processing
f. Right to data portability
g. Right to object
h. Rights concerning automated decision-making (including profiling)
i. Right to opt out of the sale or sharing of personal information
j. Right not to be discriminated against for exercising rights
(2) If a Service User wishes to exercise any of the rights in (1), please contact the inquiry contact in Section 6 of the main body of this Privacy Policy. If a request is made through an authorized agent, a power of attorney must be submitted to us directly or through the agent.
(3) Service Users have the right to lodge a complaint with a supervisory authority where permitted under applicable laws and regulations. Contact details of supervisory authorities in the EU and EEA are available in the list of supervisory authorities published by the European Data Protection Board (EDPB) (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). UK users may also lodge a complaint with the UK Information Commissioner’s Office (ICO). Contact details of the ICO and information on how to lodge a complaint are available on the ICO website (https://ico.org.uk/make-a-complaint/).
5. Consent
We may collect and use User Information based on the consent of Service Users. Service Users may withdraw their consent at any time; however, if consent is withdrawn, Service Users may become unable to use some or all of our services. If a Service User is under 16 years of age, the Service User must consent to the processing of User Information after obtaining the consent or permission of the Service User’s guardian.
6. Retention Period
We will delete User Information of Service Users in accordance with the following retention periods.
Category
Retention Period / Criteria for Determination
Entra ID / Account Data
Retained during the term of the service agreement and, after termination of the agreement, either retained for 30 days and then deleted where there are no specific instructions from the Service User, or deleted immediately, in accordance with the Service User’s choice.
7. Cross-border Transfer of User Information
In order to achieve the purposes of use above, we may transfer User Information of Service Users to countries or regions that are treated as outside the territory, foreign countries, third countries or similar jurisdictions under applicable personal data protection laws, if the Service User has consented or if such transfer is permitted by laws and regulations. When transferring User Information, we will implement necessary and appropriate measures, such as concluding contracts concerning the protection of personal data, including User Information, with the transfer destination.
8. AI Features
The Service includes functions that use artificial intelligence or machine learning (hereinafter referred to as “AI Features”). The details of such AI Features and the data processed by them are as set out in the table below.
Item
Details
Name of AI Feature
AI Summary Feature
AI Service Used to Provide the Feature
Azure OpenAI Services
Data Processed by AI
Text content entered by Service Users
Purpose of Processing
To generate a summary of the text content entered by Service Users
Storage of Input/Output Data in AI
None
Use of Input/Output Data for AI Model Training
None
Sharing of Input/Output Data
None (provided, however, that processing by Microsoft Corporation and its affiliates, as entrusted parties, will occur)
<EU/EEA/UK Users Privacy Policy>
The following EU/EEA/UK Users Privacy Policy applies to all users (hereafter referred to as “EU/EEA/UK user”) from the European Union, Iceland, Liechtenstein, Norway, and the United Kingdom (hereafter collectively referred to as “EU/EEA/UK”). The processing of personal data described in this privacy policy were set out in accordance with the General Data Protection Regulation (hereafter referred to as “GDPR”), meaning, as applicable, the EU General Data Protection Regulation and the UK General Data Protection Regulation, and, with respect to UK users, the Data Protection Act 2018.
1. Purpose of Processing and Legal Bases
We may process EU/EEA/UK user personal data for the purposes and on the legal bases set out below, as applicable to the relevant processing:
(1) Where processing is necessary for the performance of a contract to which the EU/EEA/UK user is a party, or in order to take steps at the request of the EU/EEA/UK user prior to entering into a contract
a. Purpose of providing our services to the EU/EEA/UK user
Name, telephone number, email address, date of birth, and other profile information registered by EU/EEA/UK users when using our services, and other information necessary for using our services
b. Purpose of maintaining and improving our services
Information concerning EU/EEA/UK users’ use of our services that is necessary for maintaining and improving our services
c. Purpose of responding to inquiries from EU/EEA/UK users
Information necessary to respond to inquiries from EU/EEA/UK users
(2) Where processing is necessary for our compliance with legal obligations
Information whose processing is necessary for us to comply with obligations under applicable laws and regulations
(3) Where processing is necessary to protect the vital interests of EU/EEA/UK users or third parties
Information whose processing is necessary for us to protect vital interests, such as the life or body, of EU/EEA/UK users or third parties
(4) Where processing is necessary for the performance of tasks carried out in the public interest or in the exercise of official authority
Information whose processing is necessary when we carry out tasks performed in the public interest or in the exercise of official authority under applicable laws and regulations
(5) Where processing is necessary for the legitimate interests of the controller or a third party
a. Purpose of researching and analyzing our services
Information necessary for analyzing the use of our services and preparing statistics
b. Purpose of promoting use of our services
Information necessary to provide information about campaigns related to our services
2. EU/EEA/UK User Rights
(1) EU/EEA/UK users have the following rights in accordance with the GDPR.
a. Right to be informed (right to receive information)
b. Right of access (right to request disclosure)
c. Right to rectification
d. Right to erasure
e. Right to restriction of processing
f. Right to data portability
g. Right to object
h. Rights concerning automated decision-making (including profiling)
(2) If an EU/EEA/UK user wishes to exercise any of the rights in (1), please contact us at the contact details set out in Section 6. If a request is made through an authorized agent, a power of attorney must be submitted to us directly or through the agent. We will respond to the EU/EEA/UK user’s requests without delay after confirming that the request satisfies the requirements of the GDPR.
(3) EU/EEA/UK users have the right to lodge a complaint with the supervisory authorities in the country of their residence, place of work, or place where the alleged infringement took place. Contact details of supervisory authorities in the EU and EEA are available in the list of supervisory authorities published by the European Data Protection Board (EDPB) (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). UK users may also lodge a complaint with the UK Information Commissioner’s Office (ICO). Contact details of the ICO and information on how to lodge a complaint are available on the ICO website (https://ico.org.uk/make-a-complaint/).
3. Consent
We may collect and use EU/EEA/UK users’ personal data based on the consent of the EU/EEA/UK users. EU/EEA/UK users may withdraw their consent at any time; however, if consent is withdrawn, the EU/EEA/UK user may become unable to use some or all of our services. If an EU/EEA/UK user is under sixteen years of age, the EU/EEA/UK user must consent to the processing of personal data after obtaining the consent or permission of the EU/EEA/UK user’s guardian.
4. Retention Period
When it is no longer necessary for us to use EU/EEA/UK users’ personal data, we will endeavor to promptly delete it, except where we are required by law to retain it or where similar grounds apply.
5. Transferring Personal Data outside the EU/EEA/UK
In order to achieve the purposes of use above, we may transfer EU/EEA/UK user personal data to countries outside the EU/EEA/UK, including Japan, if the EU/EEA/UK user has consented or if such transfer is permitted under the GDPR. When transferring personal data, we will implement necessary and appropriate measures, such as concluding contracts concerning the protection of personal data with the transfer destination.
6. Inquiries
For inquiries regarding this EU/EEA/UK Users Privacy Policy, requests regarding data processing, complaints, or questions regarding how data is processed, please contact us at the contact details below.
Communitio Corporation
Personal Information Team
e-mail: gdpr@communitio.net
7. Changes to this EU/EEA/UK Users Privacy Policy
This EU/EEA/UK Users Privacy Policy is subject to change at any time in accordance with social conditions as well as developments regarding GDPR and other laws, regulations, and guidelines governing personal data. To see when this EU/EEA/UK Users Privacy Policy was last updated, please refer to the bottom of this page. Any changes to this privacy policy will be published on this page, and any major changes will be clearly outlined and publicly announced.
Supplementary provisions
Established on May 15, 2019
Revised November 6, 2019
Revised August 1, 2026

