1. Basic Policy
We regard the proper collection, use, and management of personal information as an important responsibility, and handle personal information in accordance with the following principles.
(1)We comply with the Act on the Protection of Personal Information, other applicable laws, relevant guidelines, and our internal rules.
(2)When collecting, using, or providing personal information, we identify the purposes of use and handle it only within the scope necessary to achieve those purposes.
(3)We take necessary and appropriate safeguards to prevent unauthorized access to, and the loss, destruction, alteration, or disclosure of, personal information.
(4)We respond appropriately and promptly to complaints and inquiries concerning our handling of personal information.
(5)We review and improve this Policy and our privacy practices on an ongoing basis.
2. Definition of Personal Information
In this Policy, personal information has the meaning given in Article 2, paragraph 1 of the Act on the Protection of Personal Information. It means information that identifies a specific individual, such as a name, address, telephone number, email address, employer, or job title, or information containing an individual identification code.
Special care-required personal information, as defined by that Act, is also handled in accordance with this Policy.
3. How We Collect Personal Information
We collect personal information by lawful and fair means, including in the following situations.
(1)when you contact us through an inquiry form on our website
(2)when you submit a free-consultation booking form
(3)when you subscribe to a newsletter
(4)when a consulting agreement is entered into or performed
(5)when business cards are exchanged, or in a meeting or business-development context
(6)when you attend a seminar, webinar, or other event
(7)when you respond to a survey or research request
(8)when you contact us by telephone, email, or social media
(9)when work is performed under a services agreement
Where we collect special care-required personal information, we obtain your consent in advance.
4. Categories of Personal Information We Collect
The main categories of personal information we collect are set out below.
(1)Basic information: name, company name, department, and job title
(2)Contact information: email address, telephone number, and address
(3)Inquiry and contract information: the content of inquiries and consultations, contract details, transaction history, and billing and payment information
(4)Engagement information: management, financial, marketing, and organizational information, and website, advertising, and CRM operational information, to the extent necessary to perform the consulting work
(5)Website usage information: IP address, cookie data, browsing history, device information, and referrer information
(6)Other information you choose to provide
5. Purposes of Use
We use the personal information we collect within the scope of the following purposes.
(1)responding to inquiries and consultation requests
(2)providing consulting services and performing the work
(3)entering into, performing, and administering agreements
(4)billing, payment, and related administration
(5)providing information about services, seminars, and events
(6)sending newsletters and other email communications
(7)developing and improving new services and content
(8)market research and statistical analysis (used as statistical data that does not identify individuals)
(9)analyzing website usage and improving our services
(10)conducting surveys and client-satisfaction research
(11)responding to requirements under law, contract, and our internal rules
(12)other purposes incidental to the above
Where we collect personal information from a job applicant, we use it within the scope necessary for selection, communication, onboarding formalities, and other recruitment activities.
6. Disclosure to Third Parties
We do not disclose personal information to a third party without consent except where permitted or required by law, including in the following cases.
(1)where disclosure is required by law
(2)where disclosure is necessary to protect a person's life, body, or property and obtaining consent is difficult
(3)where disclosure is particularly necessary to improve public health or promote the sound development of children and obtaining consent is difficult
(4)where cooperation with a national or local government body, or a person acting on its behalf, is necessary for duties prescribed by law and obtaining consent may impede those duties
(5)where a court, public prosecutor's office, police authority, tax authority, bar association, or other public body makes a lawful request
(6)where personal information is transferred as part of a merger, company split, business transfer, or other business succession
Entrusting the handling of personal information to a service provider does not constitute disclosure to a third party; it is handled in accordance with Section 7.
7. Service Providers
We may entrust the handling of personal information to service providers where necessary for our business. These may include cloud, AI, web-development, CRM, marketing-automation, system-development, translation, writing, design, professional-advisory, and other service providers. We take appropriate measures in light of the nature of the service, which may include the following.
(1)selecting providers with appropriate data-protection arrangements
(2)entering into appropriate contractual arrangements
(3)reviewing the provider's handling of personal information as necessary and requesting improvement
8. Use of AI Tools
We use generative AI and related tools to support the efficiency and quality of our work. To protect our clients' personal and confidential information, we follow the principles below.
(1)We do not enter client personal information or confidential information into an AI tool in identifiable form.
(2)Where information is used with an AI tool, we apply appropriate measures such as de-identification, summarization, masking, or sanitization before use.
(3)As a general rule, we use business or enterprise plans, APIs, or equivalent configurations under which submitted data is not used to train or improve a general-purpose model, where such controls are available.
(4)We review applicable tool specifications, terms, and settings at the time of use because they may change.
(5)AI-assisted output is subject to human review appropriate to its nature and intended use before it is provided to a client. Any legal liability relating to a deliverable provided under a client engagement is governed by the applicable agreement.
(6)Further information about our use of AI tools is available in our AI Transparency Policy. Please read it together with this Policy.
9. Security Measures
Taking into account the size of our business and the nature of the information we handle, we implement necessary and appropriate safeguards against unauthorized access, loss, destruction, alteration, or disclosure. Depending on the nature of the information and the associated risk, these include the following measures.
(1)role-based access controls
(2)multi-factor authentication
(3)password-management rules
(4)device-management measures, including encryption and remote-lock capabilities
(5)permission management and monitoring for cloud services
(6)encryption of communications using SSL/TLS
(7)anti-malware and security software kept reasonably up to date
(8)selection, management, and review of service providers
(9)internal rules governing the use of AI tools
(10)an incident-response process
(11)review of relevant privacy and data-protection rules in foreign jurisdictions
(12)review of the security arrangements of cloud service providers
10. Retention Periods
We retain personal information only for as long as reasonably necessary for its stated purpose. Our standard retention periods are as follows.
(1)Contract information: seven years after the agreement ends
(2)Billing and payment information: seven years, in accordance with applicable tax and accounting requirements
(3)Inquiry information: three years after the matter is closed
(4)Newsletter subscription information: until you unsubscribe, subject to any limited retention required to maintain a suppression record.
(5)Website usage information, including cookie-related data: up to two years from collection, except where a third-party provider applies a different retention period disclosed in its own policy.
After the applicable period expires, or when the purpose of use has been fulfilled, we delete, dispose of, or de-identify the information by an appropriate method. We may retain information for a longer period where required by law or reasonably necessary to establish, exercise, or defend legal rights or to meet other legitimate business requirements.
Requests to stop newsletter delivery or to delete personal information are handled promptly in accordance with applicable law and any applicable retention requirements.
11. Cloud Services and Cross-Border Handling
We use or may use cloud, AI, CRM, web-development, analytics, booking, form-management, and related services provided from outside Japan.
Where personal data is stored, processed, or accessed outside Japan, we take the steps required by the APPI and other applicable law. Depending on the circumstances, these steps may include reviewing the location and privacy framework of the recipient, reviewing the provider's safeguards, providing required information, obtaining consent, and implementing contractual or other security measures.
The principal foreign-based service providers we use or may use are listed below. The provider and country relevant to a particular processing activity may depend on the service, account, configuration, and contractual arrangement in use. Each provider's privacy information is available on its website.
(1)Google LLC (United States) — Google Workspace, Google Analytics 4, Google Tag Manager, Google Ads, Gemini, YouTube, and YouTube Studio
(2)OpenAI, L.L.C. (United States) — ChatGPT and API services
(3)Anthropic, PBC (United States) — Claude and API services
(4)Webflow, Inc. (United States) — website development and operation
(5)HubSpot, Inc. (United States) — CRM and marketing automation
(6)Calendly, LLC (United States) — booking management
(7)LinkedIn Corporation (United States) — LinkedIn Insight Tag and advertising
(8)Typeform S.L. (Spain) — form management
(9)Tally BV (Belgium) — form management
(10)n8n GmbH (Germany) — workflow automation
(11)Make, provided by the applicable Celonis group company (United States/Germany) — workflow automation
(12)Notion Labs, Inc. (United States) — document, knowledge, and project management
(13)Meta Platforms, Inc. (United States) — Facebook, Instagram, Meta Business Suite, advertising, and social-media operations
(14)X Corp. (United States) — X account, advertising, and social-media operations
(15)TikTok Pte. Ltd. (Singapore) — TikTok account, advertising, and social-media operations
(16)Buffer, Inc. (United States) — social-media publishing, scheduling, and content operations
(17)Zoom Communications, Inc. (United States) — online meetings, webinars, and client meetings
(18)tldx Solutions GmbH (Germany) — tl;dv meeting recording, transcription, and meeting notes
(19)Perplexity AI, Inc. (United States) — AI-assisted research and information gathering
(20)GitHub, Inc. and GitHub B.V. (United States/Netherlands) — code management, version control, and development support
(21)Vercel Inc. (United States) — web-application development and hosting, including v0 and related tools
(22)Figma, Inc. (United States) — design, wireframing, and prototyping
(23)Canva Pty Ltd (Australia) — images, documents, and social-media creative
(24)Midjourney, Inc. (United States) — image generation and visual-production support
(25)Microsoft Corporation (United States) — Microsoft 365, Teams, OneDrive, and related services
12. Your Rights
Subject to the conditions and exceptions provided by the APPI, you may request the following in relation to your personal information held by us.
(1)notification of the purpose of use
(2)disclosure of personal information, including disclosure in electronic form
(3)correction, addition, or deletion
(4)cessation of use or erasure
(5)cessation of disclosure to third parties
(6)disclosure of records concerning disclosure to third parties
Please contact us using the details at the end of this Policy. We will verify your identity and respond within a reasonable period in accordance with applicable law. A fee may apply where permitted by law.
13. Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate and improve the website, analyze usage, and provide relevant information. Please see our Cookie Policy for details.
You may also refuse or delete cookies through your browser settings. Some website functions may not operate correctly if cookies are disabled.
We provide a mechanism on our website through which you may accept, refuse, or change your choices for cookies other than strictly necessary cookies, and through which you may withdraw a choice previously given.
14. Analytics Tools
We use Google Analytics 4 to understand how our website is used and to support improvements. We do not intentionally send names, email addresses, or other directly identifying information to Google Analytics. Depending on its configuration and operation, Google Analytics may process device, usage, and pseudonymous identifier data in accordance with Google's documentation and privacy policy.
Google's privacy policy is available at https://policies.google.com/privacy. Google's browser opt-out add-on is available at https://tools.google.com/dlpage/gaoptout.
We may also use heatmap analytics, the LinkedIn Insight Tag, HubSpot tracking, and comparable tools. Please see our Cookie Policy for details.
15. Social Media Links and Features
Our website may provide links to or embedded features from LinkedIn, X, YouTube, note (note.com), and other platforms. If a third-party feature is embedded, the provider may collect information in accordance with its own privacy policy and the configuration in use. If the website provides only a link, the provider generally receives information when you follow that link and visit its service.
16. Response to a Personal Data Breach
If personal information is disclosed, lost, damaged, or otherwise compromised, or if there is a risk that this has occurred, we respond in accordance with the APPI and guidance issued by the Personal Information Protection Commission. Depending on the nature of the incident, we may take the following steps.
(1)investigate the facts and determine the scope of the impact
(2)take immediate measures to prevent further harm
(3)consider and implement measures to prevent recurrence
(4)notify affected individuals where required
(5)report to the Personal Information Protection Commission or another relevant authority where required by law
(6)make an appropriate public announcement where warranted by the circumstances
17. Corporate Information and Trade Secrets
We handle management, financial, commercial, technical, customer, marketing, and other confidential information received in connection with an engagement with appropriate care.
The handling of corporate confidential information and trade secrets is governed primarily by the applicable non-disclosure or services agreement. This Policy concerns personal information; if that agreement and this Policy differ in relation to corporate confidential information, the agreement prevails.
18. Personal Information of Minors
Our services are intended primarily for companies and individuals aged 18 or over. If we knowingly collect personal information from a minor, we obtain consent from a parent or guardian where required by applicable law.
19. Changes to This Policy
We may amend this Policy in response to changes in law, our business, our services, or relevant technology and risks.
An amended Policy takes effect when posted on our website. Where a change is material, we will provide notice by an appropriate method.
Where applicable law requires consent or another procedure for a change, we will complete the required procedure by an appropriate method.
20. Complaints and Inquiries
Please direct complaints or inquiries concerning our handling of personal information to the contact below. We will respond in good faith and without undue delay. If you are not satisfied with our response, you may also contact the Personal Information Protection Commission of Japan (https://www.ppc.go.jp/) or another competent authority where applicable.
21. Contact
For questions concerning this Policy or requests relating to your personal information, please contact us:
Japan Consulting Inc.
Privacy Officer:Wataru Sato, Representative Director
Email:info@j-consulting.co.jp
Hours:Monday to Friday, 9:00 a.m. to 6:00 p.m. JST, excluding Japanese public holidays and the year-end/New Year holiday period
Address:Kuwano Building 2F, 6-23-4 Jingumae, Shibuya-ku, Tokyo 150-0001, Japan
We may request appropriate identification before responding.
A response may take several business days depending on the nature of the request.
Additional Rules
This Policy takes effect on May 20, 2026.
This Policy was amended on July 31, 2026, and the amended Policy takes effect on the same date.
Established: May 20, 2026
Last updated: July 31, 2026
