UPWARD Co., Ltd. (hereinafter referred to as “the Company”) has established the following Privacy Policy, built a framework for the protection of personal information (Personal Information Protection Management System), and promotes the protection of personal information by ensuring that all employees fully understand the importance of protecting personal information and are committed to its protection.
1. Collection, Use, and Disclosure of Personal Information
Recognizing that personal information is a vital asset to individuals, and given that our business—providing cloud services and applications—necessitates the handling of such information, we will appropriately collect, use, and disclose personal information. When collecting personal information, we will strive to specify the purpose of use as much as possible and do so through lawful and fair means.
We collect personal information in the following cases.
(1) When you enter the information yourself in connection with the use of our services
(2) When we collect information about you in connection with the use of our services
(3) When you provide the information directly to us or through written or other media
(4) In addition to the above, when we obtain the information lawfully, such as when we receive it from a third party with your consent, when we receive it in connection with a subcontracting arrangement, or when we receive information through you from a third party that has obtained your consent to provide such information to us
2. Management of Personal Information
We will manage the personal information we collect in compliance with laws and regulations regarding the handling of personal information—including the Act on the Protection of Customers’ Personal Information—as well as government guidelines and other relevant standards.We will appoint a Personal Information Protection Manager and grant them the responsibility and authority to implement and operate the Personal Information Protection Management System. We will also appoint a Personal Information Protection Audit Manager and strive to continuously review and improve the Personal Information Protection Management System. Furthermore, to prevent unauthorized access, loss, damage, tampering, or leakage of personal information, we will take necessary measures such as maintaining security systems, establishing management frameworks, and thoroughly training our employees.
3. Purposes of Use of Personal Information
Purposes of Use for Major Personal Information Collected by Our Company
A. Personal Information Regarding Customers and Prospective Customers (including personal information collected by customers and provided to us)
(1) To maintain and manage customer relationships
(2) To configure and provide our services
(3) To plan and host promotions, events, seminars, etc.
(4) To send the latest information about our services and company, as well as newsletters
(5) To collect service usage fees
(6) To investigate technical issues
(7) To monitor service usage and use that data to improve quality
(8) To improve service quality and to develop and enhance new features
(9) To provide information and recommendations tailored to individual circumstances
B. Personal Information Regarding Job Candidates, Employees, and Former Employees
(1) For recruitment screening and administrative communications
(2) For business communications and human resources and labor management
(3) To streamline and improve business processes
C. Personal Information Regarding Website Visitors
(1) To analyze website and service usage and improve quality
(2) For advertising and marketing activities
D. Personal Information Regarding Employees of Contractors, Business Partners, and Other Cooperating or Related Companies
(1) To maintain and manage relationships
(2) To conduct related transactions and business operations
(3) To plan and host events
(4) To process payments for service usage and related procedures
E. Personal Information Regarding Visitors to Our Company
(1) To contact the Company employee the visitor is meeting with and to confirm the purpose of the visit, etc.
(2) For security purposes
F. Personal Information Regarding Individuals Who Have Submitted Inquiries About Our Company, Our Products, or Our Services
(1) To respond to inquiries
(2) To record and manage the details of our responses to inquiries
(3) To improve the quality of our responses to inquiries and analyze trends
G. Location information for the use of products and services
To provide features that utilize location information in our products and services (however, unless uploaded through intentional user action, location data is stored only on the user’s device, such as a smartphone)
4. Use of Cookies and Acquisition of Usage Status/Attribute Information
Cookies (including similar technologies, hereinafter referred to as "Cookies") are classified into two types: those set by the domain of our website and those set by third parties that we use or have partnered with. Cookies set by third parties may be used by advertising distribution service providers to display our online advertisements on the most suitable platforms.
We use Cookies, IP addresses, access counts, browser types, operating systems, and other usage information to improve customer convenience, obtain statistical data, and provide appropriate advertising.
We may combine personal information obtained from third parties through Cookies with personal information we already possess, after obtaining consent from the individual and in compliance with this Privacy Policy.
You can refuse the acceptance of Cookies by changing your browser settings, but this may prevent you from using some of our services. For information on how to disable Cookies set by third parties that we use or have partnered with, please refer to the respective third party's website.
5. Disclosure of Personal Information
(1) Disclosure to Third Parties
We may provide personal data to third parties (including those located overseas) with your consent in order to deliver advertisements and content based on your interests and browsing history, as well as to measure effectiveness and conduct analysis.
We manage the personal information entrusted to us by you appropriately and will not disclose such information to third parties without your consent, except in the following cases:
1. When we have the customer’s consent
2. When disclosure is required by law
3. When disclosure is permitted in accordance with other laws, regulations, or our company policies
(2) Supervision of Contractors
We may outsource the handling of some or all of the personal information we collect to external contractors for the purposes specified in “3. Main Purposes of Use of Personal Information Collected by Us.”In such cases, we will exercise necessary and appropriate supervision over the contractors to ensure the secure management of the outsourced personal data.
6. Requests for Disclosure, etc., of Personal Information
We have established procedures as described below and will appropriately respond to requests for the disclosure, correction, addition, deletion, cessation of use, erasure, and cessation of provision to third parties (hereinafter referred to as "Requests for Disclosure, etc.") regarding "Retained Personal Data" (personal data over which we have the authority to disclose, correct, add to or delete content from, cease use of, erase, and cease provision to third parties; the same applies hereinafter) and records of third-party provision of personal data (hereinafter referred to as "Third-Party Provision Records"), in compliance with applicable laws. Please understand that in the following cases, the information will not be subject to disclosure in accordance with the law.
[Retained Personal Data]
(1) Cases where there is a risk of harming the life, body, property, or other rights and interests of the individual or a third party.
(2) Cases where there is a risk of significant impediment to the proper implementation of our business operations.
(3) Cases where it would violate laws and regulations.
[Third-Party Provision Records]
(1) Cases where the existence or non-existence of the record would endanger the life, body, or property of the individual or a third party.
(2) Cases where the existence or non-existence of the record is likely to encourage or induce illegal or unjust conduct.
(3) Cases where the existence or non-existence of the record is likely to harm national security, damage relationships of trust with other countries or international organizations, or cause disadvantages in negotiations with other countries or international organizations.
(4) Cases where the existence or non-existence of the record is likely to impede the prevention, suppression, or investigation of crimes, or the maintenance of public safety and order.
7. Security Measures for Personal Information
The Company will take necessary and appropriate measures to prevent and rectify unauthorized access to personal information, as well as the leakage, loss, or damage of personal information, and to ensure the security of personal information in general. The security measures taken by the Company include the following:
(1) Formulation of Basic Policy
To ensure the proper handling of personal information, we have formulated a basic policy (meaning this Personal Information Protection Policy) regarding compliance with relevant laws, regulations, and guidelines, as well as procedures for handling inquiries and complaints.
(2) Establishment of Rules Governing the Handling of Personal Information
We have established regulations for the handling of personal information that specify handling methods, responsible parties and personnel, and their duties for each stage of the process, including collection, use, storage, provision, deletion, and disposal.
(3) Organizational Security Measures
We have appointed a person in charge of handling personal information. We have clearly defined the employees who handle personal information and the scope of personal information they handle, and have established a reporting and communication system to the person in charge in the event that any facts or signs of violations of laws or handling regulations are identified. In addition, the person in charge conducts regular self-inspections regarding the status of personal information handling.
(4) Personnel Security Measures
We conduct regular training for employees on matters to be observed regarding the handling of personal information. Furthermore, provisions regarding the confidentiality of personal information are stipulated in our employment regulations.
(5) Physical Security Measures
In areas where personal information is handled, we have implemented measures to ensure that individuals other than authorized employees and the data subjects themselves cannot easily access the personal information.Furthermore, to prevent theft or loss of equipment, electronic media, and documents containing personal information, we store them in lockable cabinets and filing cabinets. When transporting such equipment or electronic media—including within our business premises—we implement measures to ensure that personal information cannot be easily identified, such as setting passwords or sealing the items in envelopes and placing them inside bags.Furthermore, when personal information is deleted or devices and electronic media containing such information are disposed of, we have measures in place for the person in charge to verify this.
(6) Technical Security Measures
We implement access controls to limit the scope of personnel and the personal information databases they handle; furthermore, we use user control functions to identify and authenticate employees who use information systems that handle personal information databases.In addition, we install security software on information systems and devices that handle personal information, keep it up to date by utilizing automatic update functions, and maintain the operating systems at the latest version. Furthermore, when sending files containing personal information via email or other means, we set a password for those files.
(7) Understanding the External Environment
We implement security management measures based on a thorough understanding of the personal information protection system in Japan, where personal information is stored. If we handle personal data in a foreign country, we will announce this on our website.
8. Handling of Personal Information in Connection with the Use of AI Technology
The Company may use AI technology in its operations to improve operational efficiency and service quality. When using AI technology, the Company will manage the handling of personal information as follows.
(1) Scope of Use
The Company may process data, including personal information, using AI technology within the scope of the purposes of use specified in Article 3. The use of AI shall be limited to the extent necessary for business operations as a substitute for processing using existing tools.
(2) Prohibited Acts
The use of AI in the following cases is prohibited.
1 Profiling that leads to unfair discriminatory treatment (including analysis of personality, beliefs, and convictions in the recruitment selection process)
2 Inputting data containing sensitive personal information (such as race, beliefs, social status, medical history, criminal history, or facts regarding harm suffered as a result of a crime)
3 Use that exceeds the scope of the purposes of use specified in Article 3
(3) Human Verification and Judgment
AI processing results are used as supplementary information; important decisions that affect an individual’s rights and interests (such as recruitment screening, performance evaluations, and contract execution) must always be verified and judged by a human as the final step. We do not automatically make important decisions based solely on AI processing results.
(4) Security Measures
We use only approved AI tools that are configured not to utilize personal information for training.Furthermore, to ensure that the personal information entered is not provided to third parties, we verify the terms and conditions and settings of the AI services we use before utilizing them.
(5) Incident Response
If any inappropriate handling or unintended leakage of personal information related to AI is discovered, we will immediately report and respond to it as an information security incident in accordance with internal regulations, and take necessary measures (including reporting to supervisory authorities and notifying the individual) in compliance with laws and regulations.
(6) Compliance with Foreign Laws and Regulations (Global Governance)
When handling the personal information of customers or stakeholders outside Japan, the Company will comply with the laws and regulations of the relevant country regarding the protection of personal information. When processing sensitive personal data or other sensitive information—which is subject to particularly strict management requirements under the laws of various countries—using AI technology or similar means, the Company will implement strict security management measures and ensure that appropriate measures, such as providing adequate information and obtaining necessary consent, are carried out in accordance with legal requirements.
9. How to Request Disclosure, etc., of Personal Information
With regard to the personal information we collect—specifically, retained personal data and records of disclosures to third parties—if you wish to inquire about, correct, or delete your personal information, we will process your request after verifying your identity. Please note that a fee set by our company (1,000 yen per request) is required for processing requests regarding retained personal data and records of disclosures to third parties.
(1) Requirements for Requests for Disclosure, etc. The personal information subject to the request must be personal data held by our company and must not fall under any of the items listed in Section 6.
1. Where there is a risk of infringing upon the life, body, property, or other rights and interests of the individual or a third party
2. Where there is a risk of causing significant hindrance to the proper conduct of our business
3. Where compliance would violate laws and regulations
(2) Procedures and Contact Information for Requests Regarding the Disclosure, etc., of Retained Personal Data
Please fill out the application form designated by our company and mail it to the address listed in Section 9(3), along with the identity verification documents specified in Section 9(3) (in the case of an application by a representative, a power of attorney or other documents confirming the representative’s authority). Please write “Request for Disclosure, etc., Enclosed” in red ink on the envelope. Please note that we are unable to process such requests by telephone.We appreciate your understanding. Our response will be provided via mail, email, or other methods designated by our company. While the method of response is at your discretion, if disclosure via your preferred method is not feasible, we may, in accordance with applicable laws and regulations, provide the response using a method other than your preferred one.
(3) Documents for Identity Verification or Proof of Authority
Please submit one copy of each of the following official documents as proof of identity (one document if it includes a photo; otherwise, two or more documents).
Driver’s license, driving history certificate, passport, health insurance card, My Number Card or Basic Resident Register Card (showing address), Residence Card, Special Permanent Resident Certificate or Alien Registration Certificate deemed equivalent to a Special Permanent Resident Certificate, Certificate of Residence
When applying through a representative, please submit one copy of the documents specified below as proof of the representative’s authority and as identification for the representative.However, regarding identification documents, if the document includes a photograph, only one type is required; otherwise, two or more types must be submitted.
A. In the case of a legal representative for a minor or an adult ward
Documents confirming legal representative authority (certified copy of family register, extract from family register, certificate of registered matters for adult guardianship, or other documents proving legal representative status)
B . In the case of an agent acting by power of attorney
1 The Company’s prescribed power of attorney form
2 A copy of the principal’s registered seal certificate (issued within the last 3 months) or a copy of a document issued exclusively to the principal, such as a driver’s license or Individual Number Card (however, an Individual Number Notification Card is not acceptable)
3 Proof of the agent’s identity (driver’s license, driving history certificate, passport,Health Insurance Enrollment Certificate, My Number Card or Basic Resident Register Card (showing address), Residence Card, Special Permanent Resident Certificate or Alien Registration Certificate deemed equivalent to a Special Permanent Resident Certificate, or Certificate of Residence)
(4) As a general rule, we do not charge a fee for processing requests for disclosure, etc. However, the requester is responsible for any communication costs, such as postage, incurred when mailing documents to us.
10. Contact Information
For requests regarding the disclosure of personal information, as well as complaints and inquiries regarding the handling of personal information, please contact us using the following methods:
・By mail to the following address:
UPWARD Co., Ltd. (Representative Director and CEO: Ryusuke Kaneki)
Corporate Planning Department, Attn: Personal Information Protection Manager
26th Floor, Marunouchi Eiraku Building, 1-4-1 Marunouchi, Chiyoda-ku, Tokyo 100-0005
11. Voluntary Nature
Providing personal information to our company is voluntary. However, please be aware in advance that if you do not provide such information, you may experience disadvantages, such as being unable to properly receive our various services.
12. Revisions to These Guidelines
The Company may revise this policy as necessary. When revising this policy, the Company will announce the effective date and details of the revised policy on its website or notify affected parties individually, and will implement such revisions in accordance with applicable laws and regulations.
End
Revised June 30, 2026
UPWARD Co., Ltd.