Privacy Policy

[Legal name of the operating company] (hereinafter the "Company") establishes this Privacy Policy (hereinafter this "Policy") as set out below regarding the handling of information relating to users and other individuals in the service it provides, "[Service name]" (hereinafter the "Service").

This Policy applies to the handling of information relating to users and other individuals that the Company obtains in connection with the Service.

1. Basic Policy

  1. 1.The Company complies with the Act on the Protection of Personal Information (hereinafter the "APPI"), related laws and regulations, guidelines and other standards, and handles personal information appropriately.
  2. 2.The Company uses the personal information it obtains within the scope necessary to achieve the purposes of use, and takes appropriate security control measures.
  3. 3.Unless otherwise provided in this Policy, the terms used in this Policy follow the definitions under the APPI and other applicable laws and regulations.

2. Information We Collect

The Company may collect the following information in providing the Service.

2.1 Account and Registration Information

The Company may collect the following information in order to register, authenticate and manage user accounts.

  • User ID
  • Email address
  • Hashed password and other authentication information
  • Display name or user name
  • Registration date and time and last login date and time
  • Account status
  • Settings such as language, country or region
  • Profile information registered voluntarily by the user
  • History of consent to the Terms of Service, this Policy and other rules

The Company does not store user passwords in plain text.

2.2 Identity Verification and KYC Information

The Company may collect the following information for identity verification, age verification, verification of country of residence, anti-money laundering and counter-terrorist financing measures, economic sanctions compliance and other legal compliance purposes.

  • Full name
  • Date of birth
  • Gender
  • Nationality
  • Country or region of residence
  • Address
  • Phone number
  • Occupation
  • Type, number, expiry date and images of identity documents
  • Information stated on a driver's license, passport, residence card or other identity document
  • Photographs, selfie images or videos taken for identity verification
  • Results and review status of identity verification
  • Date and time of the identity verification application and of the review
  • Reason for rejection where identity verification is not approved
  • Information on source of funds or purpose of transactions
  • Other information necessary for legal compliance or the prevention of misuse

Where the Company outsources identity verification operations to an external provider, the Company selects such provider appropriately and exercises necessary and appropriate supervision over it.

2.3 Wallet Information

The Company may collect the following information in order to connect wallets, verify ownership, process deposits and withdrawals and carry out airdrops.

  • Wallet address
  • Deposit wallet address assigned to the user
  • Type of the connected wallet
  • Blockchain network used
  • History of wallet connection, change and disconnection
  • Information relating to signatures or verification of wallet ownership
  • Connection information obtained through WalletConnect or other wallet connection services
  • Information linking the wallet to the account

The Company does not collect users' private keys, seed phrases or recovery phrases.

A wallet address may not identify a specific individual on its own; however, where a specific individual can be identified by readily cross-referencing it with account information, identity verification information or other information, it is handled as personal information.

2.4 Deposit and Transaction Information

The Company may collect the following information in order to detect, confirm, reconcile, credit and display deposits.

  • Source and destination wallet addresses
  • Deposit wallet address assigned to the user
  • Transaction hash
  • Type of crypto asset or token
  • Quantity of crypto asset or token
  • Blockchain network used
  • Date and time the transaction was executed
  • Block number
  • Number of confirmations
  • Gas fees and other network fees
  • Processing status of the transaction such as success, failure or pending
  • Balance on the Service and the crediting status of deposits
  • History of manual confirmation or additional review
  • Smart contract execution history
  • Other information necessary to confirm and manage transactions

The Company confirms and manages deposits per user through the deposit wallets and related systems it operates.

2.5 Mission and Point Information

The Company may collect the following information in order to provide missions, determine their completion and manage points.

  • Mission participation status
  • Mission completion status
  • Date and time of mission completion
  • Information used to determine mission completion
  • History of grant, deduction, cancellation and expiry of points
  • Point balance
  • Source of points
  • Participation status in seasons or campaigns
  • Results of checks for misuse relating to missions or points
  • Other information necessary to manage missions and points

2.6 Airdrop Information

The Company may collect the following information in order to determine airdrop eligibility, calculate distribution amounts and process token claims.

  • Number of points at the time of the snapshot
  • Mission completion status at the time of the snapshot
  • Airdrop eligibility
  • Results of the eligibility assessment
  • Results of the conversion from points to tokens
  • Scheduled distribution amount
  • Claim period
  • Status of token claim requests
  • Wallet address used for the claim
  • Hash of the claim transaction
  • Processing status of the claim such as success, failure or pending
  • History of corrections and cancellations of eligibility or distribution amounts
  • Other information necessary to run and manage airdrops

2.7 Referral Program Information

The Company may collect the following information in order to provide the referral program, verify referral relationships and prevent misuse.

  • Referral code
  • Referral link
  • User ID of the referrer
  • User ID of the referred user
  • Information linking the referrer and the referred user
  • Date and time the referral link was used
  • Date and time of registration through a referral
  • Status of fulfilment of the referral conditions
  • Whether the referred user has made a deposit
  • Information necessary to aggregate referral results
  • Results of checks for misuse relating to the referral program

The Company does not display or provide to a referrer the email address, wallet address, identity verification information, deposit amounts, transaction history or any other information that could identify a referred user.

Where the Company displays referral results to a referrer, it limits them to aggregated information that cannot identify an individual, or to masked information.

2.8 Information from Linked Social Media and External Services

Where a user links the Service with X, Discord, Telegram, LINE or another social media or external service, the Company may collect the following information based on the user's consent and the settings of that external service.

  • Account ID on the external service
  • User name
  • Display name
  • Profile image
  • Public profile information
  • Status of the link with the external service
  • Participation status in communities, groups or channels on the external service
  • Follows, posts, shares, reposts, reactions and other information necessary to confirm mission completion
  • OAuth access token
  • OAuth refresh token
  • Issue date and time and expiry of the access token
  • Access permissions granted by the user
  • History of linking to and unlinking from external services
  • Other information necessary to link external services or to confirm mission completion

The Company uses OAuth access tokens and other authentication information only within the scope necessary to link external services and to provide the functions permitted by the user.

A user may be able to unlink a service through the settings of that external service or of the Service. Where a link is removed, mission completion checks and other related functions may become unavailable.

2.9 Access and Device Information

The Company may collect the following information in order to provide the Service, ensure security, investigate incidents and analyse usage.

  • IP address
  • Access date and time
  • Pages viewed
  • Operation history
  • Referrer URL
  • Browser type and version
  • OS type and version
  • Device type
  • Screen size
  • Language settings
  • Time zone
  • Session ID
  • Cookies
  • Identifiers and settings stored in local storage
  • Error and system logs
  • History of successful and failed logins
  • Other information generated automatically through access to and use of the Service

At present, the Company does not use device fingerprinting, which combines device-specific characteristics to track a user on an ongoing basis, for the prevention of misuse.

At present, the Company does not use wallet clustering, which infers relationships between multiple wallets, for the prevention of misuse.

If the Company introduces these technologies in the future, it will amend this Policy and, where necessary, notify users or obtain their consent.

2.10 Inquiry and Support Information

Where the Company receives an inquiry, complaint or claim from a user, it may collect the following information.

  • Full name
  • Email address
  • User ID
  • Wallet address
  • Content of the inquiry
  • Date and time of the inquiry
  • Content of the Company's response
  • Attached images, documents or files
  • Information necessary for identity verification
  • History of the handling of the inquiry
  • Other information necessary to respond to the inquiry

3. How We Collect Information

The Company collects information by the following methods.

  1. 1.Information the user enters or submits on the registration screen, identity verification screen, inquiry form or other screens of the Service
  2. 2.Information obtained when the user connects a wallet, social media or another external service to the Service
  3. 3.Information obtained automatically through the user's use of the Service
  4. 4.Information obtained from public blockchains, smart contracts or blockchain nodes
  5. 5.Information obtained from WalletConnect, Helius, X, Discord, Telegram, LINE or other external services based on the user's consent or the settings of that external service
  6. 6.Information obtained from contractors for identity verification operations, cloud services, system operations and other outsourced work
  7. 7.Information obtained from administrative agencies, investigative authorities or other third parties under laws and regulations or lawful procedures
  8. 8.Information obtained from other users through the referral program

4. Purposes of Use

The Company uses the information it collects for the following purposes.

4.1 Providing and Operating the Service

  • To create accounts and to perform authentication, login and account management
  • To manage users' registration information
  • To provide the various functions of the Service
  • To verify users' eligibility to use the Service
  • To display usage status of the Service
  • To process withdrawal from membership and other account operations

4.2 Identity Verification and Legal Compliance

  • To carry out KYC and other identity verification
  • To verify age, country of residence, nationality and other eligibility requirements
  • To prevent money laundering and terrorist financing
  • To comply with economic sanctions and other transaction restrictions
  • To verify source of funds and purpose of transactions
  • To respond to requests from laws and regulations, courts, administrative agencies or investigative authorities
  • To perform the legal obligations borne by the Company

4.3 Wallet Connection and Management

  • To connect wallets to the Service
  • To verify ownership of, or authority to use, a wallet
  • To verify signatures made with a wallet
  • To associate a connected wallet with a user account
  • To manage wallet connection status and change history

4.4 Processing Deposits and Transactions

  • To assign a deposit wallet address to each user
  • To detect, confirm and reconcile deposit transactions
  • To credit deposits to user accounts
  • To display balances and transaction history on the Service
  • To manage the success, failure or pending status of transactions
  • To investigate and respond to misdirected transfers, uncredited deposits or processing errors
  • To review fraudulent or suspicious transactions

4.5 Managing Missions and Points

  • To manage participation in missions
  • To verify and determine the completion conditions of missions
  • To grant, deduct, correct, cancel or expire points
  • To display point balances and history
  • To investigate and prevent the fraudulent acquisition of missions or points

4.6 Carrying Out Airdrops

  • To take snapshots
  • To determine airdrop eligibility
  • To calculate the quantity of tokens to be distributed
  • To process token claim requests
  • To manage claim status and transactions
  • To prevent duplicate claims, fraudulent claims and other misuse
  • To respond to inquiries or objections relating to airdrops

4.7 Operating the Referral Program

  • To verify the relationship between a referrer and a referred user
  • To determine whether the referral conditions have been met
  • To aggregate referral results
  • To investigate and prevent misuse of the referral program

4.8 Linking Social Media and External Services

  • To link the Service with the social media or external service selected by the user
  • To confirm mission completion on social media
  • To maintain OAuth authentication
  • To use the functions on external services permitted by the user
  • To manage the linking to and unlinking from external services

4.9 Prevention of Misuse and Security Measures

  • To detect, investigate and prevent multiple accounts, bots, unauthorised access, impersonation, fraud and other misconduct
  • To secure the safety of accounts, wallets and systems
  • To respond to security incidents, system failures and unauthorised access
  • To restrict or suspend accounts or processing suspected of misuse
  • To analyse the causes of security issues and prevent recurrence

4.10 Improving and Analysing the Service

  • To analyse usage of the Service
  • To improve the quality, usability and convenience of the Service
  • To plan and develop new functions, missions or campaigns
  • To investigate system failures and errors
  • To create statistical information aggregated in a form that cannot identify an individual

At present, the Company does not use Google Analytics or any other third-party access analysis service.

4.11 Contacting Users

  • To send important notices regarding the Service
  • To notify the processing status of deposits, missions, points, airdrops and other matters
  • To notify changes to the Terms of Service, this Policy and other rules
  • To notify maintenance, failures or security issues
  • To respond to inquiries, complaints or claims from users
  • To request necessary confirmations or the submission of materials from users

4.12 Disputes and Protection of Rights

  • To respond to disputes, claims or complaints relating to the Service
  • To protect the rights and interests of the Company, users or third parties
  • To perform and enforce the Terms of Service and other agreements
  • To bring or defend legal claims or to preserve evidence

5. Use of Cookies and Similar Technologies

  1. 1.The Company may use cookies, local storage, session IDs and other similar technologies for the following purposes.
    • To keep users signed in
    • To store user settings
    • To ensure the security of the Service
    • To manage sessions
    • To prevent unauthorised access
    • To understand usage of the Service
    • To investigate system failures and errors
  2. 2.At present, the Company does not use cookies for behavioural targeting advertising.
  3. 3.At present, the Company does not use Google Analytics or any other third-party access analysis tool.
  4. 4.Users can disable cookies through their browser settings. However, if cookies are disabled, login and certain other functions of the Service may become unavailable.

6. Information on the Blockchain

  1. 1.Wallet addresses, transaction hashes, transaction details, smart contract execution history and other information may be recorded on a public blockchain.
  2. 2.Information recorded on a public blockchain is in principle made public, and may be difficult or impossible to change or delete.
  3. 3.The Company cannot change or delete information recorded on a public blockchain at its sole discretion.
  4. 4.Wallet addresses and transaction information may be viewed, obtained or analysed by third parties.
  5. 5.By combining information on the blockchain with other public information, social media information, exchange information or other information, a third party may infer a user's activity or a connection to that individual.
  6. 6.Account information, identity verification information, mission information, point information, referral information and other off-chain data managed by the Company are handled in accordance with applicable laws and regulations and this Policy.
  7. 7.Even where the Company receives a request from a user to delete or suspend the use of off-chain data, it may be unable to delete or change information already recorded on the blockchain.

7. Outsourcing the Handling of Personal Information

  1. 1.The Company may outsource all or part of the handling of personal information to external providers within the scope necessary to achieve the purposes of use set out above.
  2. 2.The outsourced operations may include the following.
  3. 3.Provision of cloud infrastructure and databases
  4. 4.System development, maintenance and operation
  5. 5.Wallet connection
  6. 6.Provision of blockchain nodes and RPC
  7. 7.Identity verification and KYC review
  8. 8.Email delivery
  9. 9.Linking with social media and external services
  10. 10.Customer support
  11. 11.Security and measures against misuse
  12. 12.Data backup and recovery
  13. 13.Legal, accounting, auditing and other professional services
  14. 14.The Company selects contractors appropriately, concludes agreements on the handling of personal information and other necessary agreements with them, and exercises necessary and appropriate supervision over them.
  15. 15.The principal external services used by the Company are as follows.
ServiceMain purposeInformation that may be handled
Google Cloud PlatformProvision of servers, databases, storage and other infrastructureAccount information, KYC information, transaction information, mission and point information, logs and other information on the Service
WalletConnectConnection with walletsWallet address, connection information, session information, device and communication information
HeliusProvision of blockchain data and RPC servicesWallet address, transaction information, public information on the blockchain
XSocial account linking and confirmation of mission completionSocial account ID, public information, link information, OAuth tokens, mission verification information
DiscordSocial account linking and confirmation of mission completionSocial account ID, public information, participation status, OAuth tokens, mission verification information
TelegramSocial account linking and confirmation of mission completionSocial account ID, user name, participation status, authentication and link information
LINESocial account linking and confirmation of mission completionSocial account ID, profile information, OAuth tokens, mission verification information
[KYC provider name]Identity verification and KYC reviewFull name, date of birth, address, identity documents, facial photographs, review results and other information necessary for identity verification
  1. 1.The content of the preceding paragraph may change in line with changes to the specifications of the Service, contractual relationships or external services.

8. Provision to Third Parties

  1. 1.The Company does not provide personal data to third parties without obtaining the prior consent of the individual, except in any of the following cases.
    • Where required by laws and regulations
    • Where necessary for the protection of the life, body or property of a person and it is difficult to obtain the consent of the individual
    • Where particularly necessary for improving public health or promoting the sound growth of children and it is difficult to obtain the consent of the individual
    • Where it is necessary to cooperate with a national agency, a local government or a party entrusted by them in performing statutory duties, and obtaining the consent of the individual is likely to impede the performance of those duties
    • Where otherwise permitted by the APPI or other laws and regulations
  2. 2.In the following cases, the recipient may not constitute a third party under the APPI.
    • Where the handling of personal information is outsourced within the scope necessary to achieve the purposes of use
    • Where personal information is provided in connection with a business succession due to a merger, company split, business transfer or other reason
    • Where personal information is jointly used in a manner that satisfies the requirements set out in the APPI
  3. 3.Where the Company provides personal data to a third party or receives personal data from a third party, the Company makes the confirmations and keeps the records required by laws and regulations.

9. Provision to Third Parties in Foreign Countries

  1. 1.WalletConnect, Helius, X, Discord, Telegram, LINE and other external services used by the Service may be operated by foreign entities, or may handle information through servers or personnel located outside Japan.
  2. 2.For the principal servers and databases of the Service on Google Cloud Platform, the Company uses regions within Japan in principle.
  3. 3.Notwithstanding the preceding paragraph, information may be handled outside Japan in connection with the provision, support, security, backup or other processing of external services.
  4. 4.Where the Company provides personal data to a third party in a foreign country based on the consent of the individual, the Company provides the following information and obtains the necessary consent in accordance with the APPI and other applicable laws and regulations.
    • The name of the country or region in which the recipient is located
    • Information on the personal information protection regime in that country or region
    • Information on the personal information protection measures taken by the recipient
  5. 5.Where personal data is provided on the basis that a third party in a foreign country has established a system to continuously take measures equivalent to those required by the APPI, the Company periodically confirms the implementation of those measures and provides the individual with the information required by laws and regulations.
  6. 6.Details of the handling of personal information outside Japan can be obtained through "19. Contact Point".

10. Joint Use

At present, the Company does not jointly use personal data.

If the Company jointly uses personal data in the future, it will publish the following matters on the Service before the joint use begins.

  • The fact that personal data will be jointly used
  • The items of personal data to be jointly used
  • The scope of the parties that will jointly use the data
  • The purposes of use of the parties that will jointly use the data
  • The name, address and representative of the party responsible for the management of the personal data

11. Personal Related Information

  1. 1.Cookies, IP addresses, browsing history, device information, wallet addresses and other information may constitute personal related information under the APPI depending on how they are handled.
  2. 2.Where the Company provides personal related information to a third party and it is anticipated that the third party will obtain that information as personal data, the Company confirms that the consent of the individual has been obtained and takes other necessary steps in accordance with the APPI and other applicable laws and regulations.

12. Security Control Measures

  1. 1.The Company takes necessary and appropriate security control measures to prevent unauthorised access to, leakage, loss or damage of personal data, and to manage personal data appropriately.
  2. 2.The security control measures taken by the Company include the following.

12.1 Basic Policy and Internal Rules

  • Establishment of a basic policy on the proper handling of personal information
  • Establishment of internal rules on the collection, use, storage, provision, deletion and disposal of personal data
  • Clarification of the persons responsible for, and the persons handling, personal data

12.2 Organisational Security Control Measures

  • Clarification of the employees who handle personal data and of the scope of their handling
  • Management of access rights to personal data
  • Management of logs and records for confirming the status of the handling of personal data
  • Establishment of a reporting and response structure for leakage and other incidents
  • Periodic confirmation and review of security control measures

12.3 Human Security Control Measures

  • Training of employees on personal information protection and information security
  • Conclusion of confidentiality agreements with employees or establishment of related internal rules
  • Necessary and appropriate supervision of employees who handle personal data

12.4 Physical Security Control Measures

  • Appropriate management of devices and media that handle personal data
  • Prevention of access to devices and data by unauthorised persons
  • Management of the removal, disposal and reuse of devices and media

12.5 Technical Security Control Measures

  • Authentication of users and administrators
  • Control of access rights
  • Encryption of communications
  • Encryption of stored data where necessary
  • Hashing of passwords
  • Measures against unauthorised access, malware and other threats
  • Vulnerability management for systems and software
  • Collection of access logs and operation logs
  • Establishment of data backup and recovery procedures
  • Appropriate protection of OAuth access tokens and other authentication information

12.6 Management of Contractors

  • Confirmation of the contractor's security control structure
  • Conclusion of agreements on personal information protection
  • Confirmation of the handling status at the contractor
  • Review of contractors where necessary
  • Due to the nature of the internet, blockchains and external services, the Company does not guarantee complete security of the Service or of data transmission. This does not, however, release the Company from the security control obligations it bears under laws and regulations.
  • Details of the security control measures, other than matters that cannot be disclosed for legal or security reasons, can be obtained through "19. Contact Point".

13. Retention Period of Personal Data

  1. 1.The Company retains personal information for the period necessary to achieve the purposes of use.
  2. 2.Where a user deletes their account or withdraws from membership, the Company retains the personal information relating to that user in principle for one year from the date on which the account deletion or withdrawal is completed.
  3. 3.After the period in the preceding paragraph has elapsed, the Company deletes personal information or processes it into a form that cannot identify an individual, except for information that must be retained due to statutory retention obligations, dispute handling, prevention of misuse, security or other legitimate reasons.
  4. 4.The following information may be retained for more than one year.
    • Information whose retention is required by laws and regulations
    • Information that must be retained as accounting, tax, audit or transaction records
    • Information necessary for investigations into money laundering, terrorist financing, misuse or other matters
    • Information necessary to respond to litigation, disputes, complaints or the exercise of rights
    • Information necessary to investigate security incidents and prevent recurrence
    • Information necessary to protect the rights of the Company or third parties
  5. 5.OAuth access tokens and other information relating to links with external services are retained for the period necessary to provide the link and, after the link is removed, are deleted or invalidated within a reasonable period, except where retention is required for legal or security reasons.
  6. 6.Identity documents and KYC information are retained for the period required by laws and regulations and within the scope necessary for identity verification, prevention of misuse and dispute handling.
  7. 7.Information stored in backups may remain for a certain period after ordinary deletion processing, until the backup rotation cycle is completed.
  8. 8.Information recorded on a public blockchain is outside the scope of the Company's retention periods and may remain on the blockchain even after an account is deleted.

14. Use of Statistical Information

  1. 1.The Company may use the information it collects as statistical information aggregated in a form that cannot identify a specific individual.
  2. 2.The Company may use or publish statistical information that cannot identify an individual for the improvement of the Service, business analysis, the preparation of reports and other purposes.
  3. 3.Where the Company creates and uses anonymously processed information or pseudonymously processed information under the APPI, it handles such information in accordance with the APPI and other applicable laws and regulations.

15. Requests Regarding Retained Personal Data

  1. 1.In accordance with the APPI, users may make the following requests with respect to retained personal data held by the Company.
    • Notification of the purposes of use
    • Disclosure of retained personal data
    • Disclosure of records of provision to third parties
    • Correction of the content
    • Addition to the content
    • Deletion of the content
    • Suspension of use
    • Erasure
    • Suspension of provision to third parties
  2. 2.A user who wishes to make a request under the preceding paragraph shall contact the Company through "19. Contact Point".
  3. 3.In order to confirm that the requester is the individual or a duly authorised representative, the Company may require the submission of the following information or documents.
  4. 4.User ID
  5. 5.Registered email address
  6. 6.A signature made with the wallet
  7. 7.Identity documents
  8. 8.Documents evidencing the authority of the representative
  9. 9.Other information necessary to verify the individual or the representative
  10. 10.Upon receiving a request, the Company responds within a reasonable period in accordance with the APPI and other applicable laws and regulations.
  11. 11.The Company may decline all or part of a request in any of the following cases.
    • Where there is a risk of harm to the life, body, property or other rights and interests of the individual or a third party
    • Where there is a risk of significant hindrance to the proper implementation of the Company's business
    • Where responding would violate laws and regulations
    • Where the Company cannot confirm that the requester is the individual or a duly authorised representative
    • Where the Company does not bear an obligation to respond under the APPI or other laws and regulations
  12. 12.Where the Company declines all or part of a request, it notifies the reason to the extent possible under laws and regulations.
  13. 13.Due to its nature, information already recorded on the blockchain may not be capable of deletion, correction, suspension of use or suspension of provision to third parties.
  14. 14.Where the Company sets a fee for disclosure requests, it publishes the amount and the payment method together with the request procedure.

16. Information of Minors

  1. 1.The Service is in principle not intended for persons under 18 years of age.
  2. 2.A person under 18 years of age who uses the Service must obtain the consent of their legal representative. The Company may, however, prohibit the use of all or part of the Service by persons under 18 years of age.
  3. 3.Where the Company confirms that it has obtained the personal information of a person under 18 years of age without the necessary consent, it deletes that information and takes other necessary measures in accordance with applicable laws and regulations.

17. Response to Leakage of Personal Data

  1. 1.Where the Company becomes aware that a leakage, loss, damage, unauthorised access or other incident involving personal data has occurred or is likely to have occurred, it takes the following measures.
    • Investigation of the facts and the scope of impact
    • Prevention of the spread of damage
    • Protection of the affected systems or accounts
    • Analysis of the cause
    • Formulation and implementation of measures to prevent recurrence
    • Coordination with the relevant contractors or external services
  2. 2.Where required by laws and regulations, the Company reports to the Personal Information Protection Commission and other relevant authorities.
  3. 3.Where required by laws and regulations, the Company notifies the affected individuals of the outline of the incident, its impact, the response and other necessary matters.
  4. 4.The Company may ask users to change their password, remove links with external services, check their wallet or take other necessary measures.

18. Amendments to This Policy

  1. 1.The Company may amend this Policy in any of the following cases.
    • Where laws, regulations or guidelines are amended
    • Where the content or specifications of the Service change
    • Where the information collected or the purposes of use change
    • Where the contractors or external services used change
    • Where it becomes necessary to strengthen security or personal information protection
    • Where there is otherwise a reasonable need to amend this Policy
  2. 2.Where the Company amends this Policy, it notifies or publishes the amended content and its effective date by posting on the Service, sending an email to the registered email address or another appropriate method.
  3. 3.For material changes, the Company notifies users in principle by the effective date.
  4. 4.The amended Policy applies from the effective date specified by the Company.
  5. 5.For changes that require user consent under laws and regulations, the Company obtains user consent by the method it prescribes.

19. Contact Point

For inquiries regarding this Policy, the handling of personal information or requests concerning retained personal data, please contact the following.

Personal Information Handling Business Operator

Company name: [Legal name of the operating company] Address: [Registered head office address] Representative: [Name of the representative]

Personal Information Protection Manager

Department or title: [Name of the department or title]

Contact Point

Department: [Support team or personal information inquiry desk] Email address: [Inquiry email address] Inquiry form: [Inquiry form URL] Opening hours: [Opening hours]

Depending on the content of an inquiry, the Company may require the submission of information or documents necessary to confirm that the requester is the user.

Enactment and Revision History

Enacted on: 28 July 2026 Effective from: [Day] [Month] 2026 Last revised on: [Day] [Month] 2026