Kairyu PortalKairyu Portal

Privacy Policy

Last updated: [DATE — fill in when published]

Before publishing: this draft has not been reviewed by a lawyer. Given this service handles ID documents under Japan's Act on the Protection of Personal Information (APPI) — which now includes administrative fines for serious violations — have this reviewed by a Japan-qualified lawyer before it goes live. Bracketed placeholders below need your actual company details filled in.

1. Who we are

This Privacy Policy explains how [COMPANY LEGAL NAME] ("IQBaseline," "we," "us") collects, uses, stores, and protects personal information submitted through our identity verification form at forms.iqbaseline.com. We are the "Personal Information Controller" under Japan's Act on the Protection of Personal Information (APPI) for the information described here.

Registered address: [COMPANY ADDRESS]
Representative: [REPRESENTATIVE NAME]
Contact for privacy matters: [PRIVACY CONTACT EMAIL]

2. Information we collect

3. Why we collect it

We collect this information solely to verify your identity as part of [DESCRIBE THE BUSINESS PROCESS — e.g. "onboarding you as a customer" or "verifying eligibility for a service"]. We do not use this information for marketing, and we do not sell it to third parties.

4. Where your information is stored and processed

Placeholder — depends on a decision still being made: this section must accurately state where the database and file storage are physically located. If data is stored outside Japan (e.g. on servers in the United States), APPI requires disclosing the destination country, a description of that country's data protection system, and the safeguards in place, and generally requires your prior opt-in consent to that transfer. Do not publish this policy until this section reflects the actual, current infrastructure.

5. How we protect your information

Uploaded documents are encrypted before storage using industry-standard encryption (AES-256), with each file protected by its own unique encryption key. Access to submitted documents is restricted to authorized personnel, who must authenticate using a password and a time-based one-time code (multi-factor authentication). All access to stored documents is logged.

6. How long we keep your information

We retain your information for [RETENTION PERIOD — e.g. "as long as necessary to complete verification, and for X months afterward for record-keeping purposes"], after which it is permanently deleted. You may request earlier deletion at any time (see Section 7).

7. Your rights

Under APPI, you have the right to request that we:

To make a request, contact us at [PRIVACY CONTACT EMAIL]. We will respond within a reasonable time and in accordance with APPI's procedural requirements.

8. Third-party service providers

We use third-party infrastructure providers to host our systems and store encrypted files (currently Render and Cloudflare). These providers do not have access to your unencrypted documents; files are encrypted before they are ever sent to storage.

9. Security incidents

In the event of a data breach affecting your personal information, we will notify the Personal Information Protection Commission (PPC) and affected individuals as required under APPI.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date.

11. Contact us

Questions about this policy or your personal information can be directed to [PRIVACY CONTACT EMAIL].