Privacy Policy
Effective date: July 17, 2026 (Version 0.3, Draft)
The Japanese version is the authoritative text. This English translation is provided for convenience.
Cor. Inc. (hereinafter referred to as "the Company") recognizes the importance of the personal information it handles and, in accordance with the Act on the Protection of Personal Information (hereinafter the "APPI") and other relevant laws and regulations and guidelines, as well as the information security management system based on ISO/IEC 27001:2022 (JIS Q 27001:2023), handles the personal information of customers, employees, job applicants, and all other individuals appropriately. The Company protects personal information in accordance with the following policy.
1. Business Information
| Business name | Cor. Inc. |
|---|---|
| Location | Fukuoka Prefecture (Head Office) |
| Representative | Representative Director Kosuke Terada |
| Business activities | Planning, requirements definition, development, and operation of AI solutions, and the accounting and financial operations incidental thereto |
| Personal Information Protection Manager | ISMS Management Officer Nagisa Terada |
| Inquiries | Through the contact point set forth in Section 10. |
2. Personal Information We Collect and Purposes of Use
When collecting personal information, the Company specifies the purpose of use as far as possible and collects such information by lawful and fair means. Except where the prior consent of the individual has been obtained, the Company does not handle personal information beyond the scope necessary to achieve the specified purpose of use. The types of personal information handled by the Company and the purposes of use are as follows.
(1) Customers (including business partners and prospects)
- Information collected
- Name, company name, department, job title, email address, telephone number, information relating to transactions, and the like
- Purpose of use
- Responding to inquiries and requests / concluding and performing contracts, and providing the development, operation, and maintenance of AI solutions / billing, payment, and other accounting and financial processing / communications and notifications regarding services / management of transactions and contracts and the performance of obligations under laws and regulations
(2) Employees (including officers, part-time, fixed-term, and interns)
- Information collected
- Name, contact details, date of birth, address, bank account, My Number (Specific Personal Information), social insurance-related information, personnel evaluations, attendance records, work-related logs, and the like
- Purpose of use
- Personnel and labor management (recruitment, placement, evaluation, salary, bonuses, retirement, etc.) / payroll calculation, withholding tax and other tax processing, and procedures for social insurance and labor insurance (including Specific Personal Information; see Section 4) / objective ascertainment of working hours and fulfillment of health management and the duty of care for safety / log collection and monitoring for information security management (detection of and response to unauthorized access, information leakage, malware infection, etc.; the scope of collection is governed by Section 9 and internal regulations) / emergency contact, employee benefits, and other management based on the employment contract
(3) Job Applicants
- Information collected
- Name, contact details, resume, curriculum vitae, interview records, information collected during the selection process, and the like
- Purpose of use
- Recruitment selection (receipt of applications, selection, communication, and decisions on acceptance or rejection) / preparation of post-hire onboarding procedures / management of application information for a certain period in the case of rejection (including matters relating to future contact; limited to cases based on the consent of the individual)
Note: In addition to being provided by this Policy, internal notification of the purposes of use to employees and job applicants is separately stated through the notice of working conditions, written pledges, and guidance provided at the time of hiring. In particular, the Company states, through this Policy and the "Notice and Consent Form Regarding Employee Monitoring," that the purposes of use include log collection and monitoring for the personnel and labor management and information security management of employees.
3. Provision to Third Parties and Outsourcing
Except where any of the following applies, the Company does not provide personal data to third parties without obtaining the prior consent of the individual.
- Where based on laws and regulations.
- Where it is necessary for the protection of the life, body, or property of an individual and it is difficult to obtain the consent of the individual.
- Where it is particularly necessary for improving public health or promoting the sound upbringing of children and it is difficult to obtain the consent of the individual.
- Where it is necessary to cooperate with a state organ or the like in carrying out affairs prescribed by laws and regulations, and obtaining the consent of the individual is likely to impede the performance of such affairs.
Within the scope necessary to achieve the purpose of use, the Company may outsource all or part of the handling of personal information to external businesses (outsourcing contractors, cloud service providers, etc.). In such cases, the Company exercises necessary and appropriate supervision over the outsourcing contractor in accordance with the internal rule "Supplier and Outsourcing Management Regulations."
When the Company has provided personal data to a third party or has received personal data from a third party, the Company records and retains the necessary matters in accordance with Articles 29 and 30 of the APPI.
4. Use of Cloud Services and Provision to Third Parties Located Overseas (Article 28 of the APPI)
The Company handles personal information using cloud services such as Google Workspace (shared drives), Google Cloud (GCP / Secret Manager), GitHub, and Bitwarden.
In connection with the use of these cloud services, personal data may be handled in foreign countries (cross-border transfer). When the Company provides personal data to a third party located overseas (including cases where data is handled overseas through cloud services), the Company handles such data appropriately in accordance with Article 28 of the APPI, by means such as obtaining the prior consent of the individual, or by confirming that the relevant third party has established a system conforming to the standards prescribed by said Act, or by other means prescribed by laws and regulations.
When carrying out a cross-border transfer, the Company provides, upon the request of the individual and as prescribed by laws and regulations, information regarding the name of the country in which the transferee is located, the systems for the protection of personal information in that country, and the measures taken by the transferee.
* With respect to Specific Personal Information (My Number), the Company does not provide it to third parties located overseas, in accordance with the My Number Act.
5. Use of Cookies and Website Analytics Tools
The Company uses website analytics tools that employ identifiers such as cookies in order to understand how its website is used and to improve its presentation and quality. Through these tools, the Company obtains information such as IP addresses, browser and device information, pages viewed, referral sources, time spent, and on-screen interactions (clicks, scrolling, etc.).
The analytics tools used by the Company are as follows.
- Microsoft Clarity (provider: Microsoft Corporation / United States): Records page views and interactions such as clicks and scrolling, and analyzes them as heatmaps and session replays. The information obtained is handled outside Japan, including in the United States.
- Cloudflare Web Analytics (provider: Cloudflare, Inc. / United States): Obtains statistical information such as page view counts. It does not use cookies that track individuals.
The Company does not use the information obtained through these tools for the purpose of identifying individuals, nor does it combine such information with other information held by the Company to identify individuals. The handling of the information obtained is also subject to the privacy policies of each provider.
Because the handling of information by Microsoft Clarity involves a cross-border transfer to the United States, the Company handles such data appropriately by the methods set out in Section 4 (Use of Cloud Services and Provision to Third Parties Located Overseas).
In session replays, text entered into input forms is masked and configured so that it cannot be viewed by the Company. Session replay is not used for the purpose of recording sensitive information such as the content of inquiries.
If you wish to stop the collection of information, the following methods are available: (1) sending a Global Privacy Control (GPC) signal via your browser or an extension (Microsoft Clarity supports GPC); or (2) selecting Microsoft on the opt-out page provided by the Digital Advertising Alliance. Please note that Microsoft Clarity does not respond to browser Do Not Track (DNT) signals. In addition, even if you disable cookies, basic information such as page view counts continues to be collected, and recorded sessions are simply fragmented. If you disable cookies, some functions of the website may become unavailable.
The opt-out under method (2) is stored in a cookie, so deleting or disabling cookies also clears that setting. To keep it, please use method (1), Global Privacy Control (GPC), or the browser extension provided by the Digital Advertising Alliance linked below (available only in the United States, Canada and Argentina).
6. Security Control Measures
In order to prevent the leakage, loss, or damage of the personal information it handles and to otherwise ensure security control, the Company implements the following measures (details are governed by the internal rules "Personal Information and Specific Personal Information Handling Regulations" and "Information Security Management Regulations").
- Organizational and human security control measures: The Company appoints a Personal Information Protection Manager (ISMS Management Officer) to ascertain and inspect the status of handling. The Company provides education to employees regarding their confidentiality obligations and compliance with relevant laws and regulations.
- Access control: Based on the zero-trust approach, the Company controls access to personal data through multi-factor authentication (MFA), device posture verification, and the principle of least privilege. For Specific Personal Information, access privileges are configured so that only the personnel in charge of the relevant affairs can access it.
- Encryption: Disk encryption (FileVault) is enabled on business devices, and communications are encrypted using TLS or the like. Encryption at rest is enabled for data stored in the cloud.
- Logging and detection: Access to personal data is subject to minimal logs relevant to business operations (which do not collect private content), and is recorded and monitored.
- Disposal: Personal data that is no longer needed is disposed of by a method that renders it irrecoverable.
7. Requests for Disclosure of Retained Personal Data
An individual or their agent (meaning a statutory agent or an agent appointed by the individual) may request the Company, with respect to the retained personal data by which that individual is identified, to provide notification of the purpose of use, to disclose, to correct, add to, or delete the content, to suspend or erase the use, or to suspend provision to third parties.
The Company accepts such requests by the method prescribed by the Company, accompanied by documents that can confirm the identity of the individual or the agent.
The Company decides the content of its response and notifies the individual, in principle, within 30 days from the date on which it accepted such a request. If, due to unavoidable circumstances, it cannot respond within that period, the Company notifies the individual of the reason and the expected timing of its response.
When complying with a request for disclosure, the Company may collect a fee prescribed by the Company within a range deemed reasonable in light of the actual costs.
In certain cases prescribed by laws and regulations (where there is a risk of harming the rights or interests of the individual or a third party, where there is a risk of significantly impeding the proper execution of the Company's business, where it would result in a violation of other laws and regulations, etc.), the Company may decline to disclose all or part of the data. In such cases, the Company notifies the individual to that effect together with the reason.
8. Response in the Event of a Data Breach
In the event that a situation involving the leakage, loss, or damage of personal data, or otherwise relating to the assurance of security, occurs, and where it falls under a certain situation prescribed in Article 26 of the APPI, the Company promptly reports to the Personal Information Protection Commission (preliminary report) and reports within the prescribed period (final report), and also notifies the individual promptly in accordance with the circumstances of the situation. Where notification to the individual is difficult, the Company takes the necessary alternative measures to protect the rights and interests of the individual. With respect to leakage or the like relating to Specific Personal Information, the Company separately makes the necessary reports and notifications in accordance with the My Number Act and the rules of the Personal Information Protection Commission.
9. Handling of Log Collection and Monitoring (For Employees)
For the purposes of information security management, labor management, and the objective ascertainment of working hours, the Company collects and monitors business-related logs (authentication, process execution, communication metadata, access to internal data, software configuration, and attendance/usage time) on the devices and cloud services used for business. The Company does not collect private content (the content of personal browsing, the content of personal accounts, or keystrokes).
The purposes, scope, persons responsible, viewing conditions, and retention periods for log collection and monitoring are governed by the internal rules "Log Collection and Monitoring Regulations" and the "Notice and Consent Form Regarding Employee Monitoring."
10. Contact Point for Inquiries
Requests for the disclosure of retained personal data and complaints or consultations regarding the handling of personal information are accepted at the following contact point.
| Contact point | Cor. Inc. Personal Information Protection Manager (ISMS Management Officer Nagisa Terada) |
|---|---|
| How to contact | For requests for disclosure and the like (Section 7), please contact us at [email protected], attaching documents that verify your identity. Complaints and consultations regarding the handling of personal information are also accepted via Cloudia (AI chat) or by phone on our contact page. |
11. Revision of This Policy
The Company may revise this Policy due to amendments to laws and regulations, changes in business activities, or other circumstances. When revised, the Company will publish the revised content on the Company's website or by other means. When making important changes, the Company will make them known by appropriate means.
For our information security framework, see also our Security page.
Version 0.3 (Draft) / Effective date: July 17, 2026 / Prepared by: Cor. Inc. / Responsible: Personal Information Protection Manager (ISMS Management Officer, Nagisa Terada)
* This Policy is a summary and mapping of the internal rule "Personal Information and Specific Personal Information Handling Regulations" for the purpose of external publication. Where the content of the two differs, it shall be interpreted in accordance with laws and regulations and the intent of said regulations.