Skip to main content

Customer Data Policy

GlossVation Inc. (hereinafter 'the Company') handles data created or uploaded by customers (Subscribers) through NocodilySuite (hereinafter 'the Service') as set forth below. This Policy forms part of the Terms of Service.

1. Data Covered

This Policy applies to the following data (collectively, 'Customer Data'). Account registration information, inquiry content, and other information collected directly by the Company is handled in accordance with the Privacy Policy.
· Input Data: applications, records, files, comments, and other data created or uploaded by the Subscriber and users authorized by the Subscriber on the Service
· Usage Data: data concerning the operation and usage of the Service (e.g., number of applications, number of records, API call counts, error occurrences). This does not include the content of Input Data.

2. Handling of Input Data

The Company does not access or handle Input Data. However, the Company may access Input Data only to the minimum extent necessary in the following cases:
· When explicitly requested and consented to by the Subscriber for support or similar purposes
· When receiving a disclosure request based on law (Section 7)
· When urgently and unavoidably necessary to respond to a serious failure or security incident of the Service (in which case the Company will promptly notify the Subscriber afterward)

When accessing Input Data under the preceding cases, access privileges are limited to designated personnel of the Company, and access records are retained.

The Company does not use Input Data to create statistical information, to train artificial intelligence or machine learning models, for advertising, or for any other purposes of the Company.

3. Handling of Usage Data

The Company uses Usage Data to provide and operate the Service, to detect and respond to failures, to calculate usage fees, and to improve the Service after processing into statistical information in a form that does not identify individuals.

4. Storage Location

Customer Data is stored in the following locations:
· Country/region of storage: Japan (East Japan and West Japan regions)
· Backup storage location: Japan

5. Security

To protect Customer Data, the Company implements the following measures:
· Encryption of communications (TLS)
· Logical separation of data by Subscriber
· Restriction of access privileges to production environments and retention of access records
· Backups (retained for a period consistent with the terms of your subscription)
· Vulnerability assessments

6. Notification of Security Incidents

If the Company becomes aware of any leakage, loss, damage, or other security incident involving Customer Data, the Company will promptly notify the Subscriber of the known facts, the scope of impact, and the status of response, and will continue to provide necessary information thereafter. The Company will cooperate as necessary to enable the Subscriber to report to the Personal Information Protection Commission.

7. Disclosure Requests Based on Law

If the Company receives a request from a public authority to disclose Customer Data based on law, the Company will verify the legality of such request and respond only to the minimum extent necessary. Unless prohibited by law, the Company will notify the Subscriber in advance.

8. Handling upon Termination

After termination of the agreement, the Company will delete Customer Data upon the lapse of the period provided in Article 11, Paragraph 3 of the Terms of Service, and will sequentially erase it from backups.

9. Subscriber's Responsibilities

If Input Data contains personal information, the Subscriber shall, as the personal information handling business operator, be responsible for notifying and publishing the purposes of use, implementing security measures, responding to requests from individuals, and fulfilling other obligations.