Privacy Policy
Updated: June 27, 2026
Article 1 (General Provisions)
Power Office G.K. (hereinafter “the Company”) recognizes the protection of customers’ personal information as an important responsibility and complies with the Act on the Protection of Personal Information (hereinafter “APPI”) and other applicable laws and regulations. This Policy has been prepared with the Japanese version as the authoritative text. Versions in English or other languages are translations for reference purposes only, and in the event of any discrepancy between the Japanese version and any other language version, the Japanese version shall prevail. Depending on your location, rights under regional laws described below may apply to you (including the EU/UK General Data Protection Regulation, the California Consumer Privacy Act and other U.S. state laws, and the privacy laws of Canada, Brazil, Australia, and South Korea, etc.) (see Article 14 “Region-Specific Additional Disclosures”).
This Policy sets forth the handling of personal information in the following services provided by the Company.
- Software Products — Various software products published and provided by the Company
- Member Portal — A portal site for managing product and plan subscriptions
The data controller responsible for the handling of personal information is as follows:
Power Office G.K. Location: Yatsushiro City, Kumamoto Prefecture, Japan Contact: info@poweroffice-kato.com
Article 2 (Information We Collect)
The Company may collect the following information.
(1) Information You Provide
- Account Information: Email address, name, organization name, job title, and other information provided when registering for our services (including the Member Portal)
- Contract and Billing Information: Payment information collected by FastSpring in connection with product and plan purchases (the Company does not directly store payment information such as card numbers)
- Inquiry Content: Information provided when contacting our support
(2) Information Collected Automatically
- Usage Logs: Date and time of access to our services, operation history, and history of contract and purchase-related operations
- Technical Information: IP address, browser or application type and version, OS type, and device information
- Cookies and Similar Technologies: Cookies necessary for maintaining login sessions, and cookies or similar technologies for access analytics (Google Analytics) (see Article 6 for details)
(3) Information Obtained from Third Parties
The Company may obtain purchase-related information (purchase details, billing status, etc.) from FastSpring (Bright Market, LLC), which handles payment processing, to the extent necessary for purchase and billing processing.
(4) Regarding Our Software Products
The Company handles personal information in accordance with the principles set forth in this Policy also in its software products. If the type of information collected or its handling differs from this Policy due to the features or nature of a product, or if additional provisions are necessary, such information will be provided in the product description or individual contract terms as a supplement to this Policy.
Article 3 (Purposes of Use)
Collected personal information is used for the following purposes.
- Provision, operation, and improvement of services
- Account authentication and prevention of unauthorized use
- Management of product and plan contracts
- Responding to inquiries
- Notification of important announcements (policy changes, service suspensions, etc.)
- Compliance with legal obligations
Article 4 (Legal Basis for Processing)
For customers in the EU/UK and other regions where applicable law requires disclosure of the legal basis for processing, the Company processes personal information on the following legal bases.
- Performance of a Contract: Providing accounts, managing product and plan contracts, and processing purchases and billing (relating to service provision and contract management under Article 3)
- Compliance with Legal Obligations: Meeting retention obligations and other obligations under applicable laws
- Legitimate Interests: Improving services, ensuring security, and preventing unauthorized use (to the extent that it does not unduly harm customers’ rights and interests)
- Consent: Processing for which consent is the legal basis, such as cookies for access analytics (consent may be withdrawn at any time)
Article 5 (Disclosure to Third Parties)
The Company will not provide customers’ personal information to third parties except in the following cases.
- Service Providers (Data Processors): Information is provided to FastSpring (Bright Market, LLC), the Merchant of Record handling payment processing, to the extent necessary for purchase and billing processing. FastSpring’s handling of personal information is governed by FastSpring’s Privacy Policy.
- Cloud Infrastructure (Hosting) Providers: The Company uses Microsoft Azure (Microsoft Corporation) as its cloud infrastructure for operating its services and storing data, and personal information managed by the Company is stored in Microsoft’s data centers. Microsoft acts as a data processor that processes personal information under the Company’s instructions (see Article 8 for storage location details).
- Access Analytics Service Providers: Access-related information is transmitted to Google LLC through Google Analytics for the purpose of analyzing website usage (see Article 6 for details).
- As Required by Law: When disclosure is requested by courts, police, or other public authorities pursuant to applicable laws
- With Customer Consent
The Company does not sell or rent customers’ personal information. For the relationship with the definitions of “sale” and “sharing” under U.S. state laws, please refer to Article 14(B).
Article 6 (Cookies and Tracking)
Cookies or similar technologies are used in our services for the following purposes.
- Essential Cookies: Those indispensable for service provision, such as maintaining login sessions. Cookies used in the Member Portal are primarily these essential cookies.
- Analytics Cookies: Those used to understand how the website is used (using Google Analytics; see Article 7 for details). Analytics cookies are primarily used on our product sites and, in applicable regions, are only activated after obtaining prior consent (opt-in).
The Company does not use advertising or tracking cookies for purposes other than those described above (maintaining login sessions and access analytics via Google Analytics).
You may disable cookies through your browser settings, but some features may not function properly as a result.
Article 7 (Access Analytics Tools)
The Company uses Google Analytics, provided by Google LLC, for the purpose of understanding the number of visitors and usage of our website. Google Analytics collects access-related information using cookies. As a result, access information such as pages viewed, referral sources, IP addresses, and browser/OS types is transmitted to Google LLC and processed by Google for the aforementioned analytics purposes. The Company does not transmit personally identifiable information such as names or email addresses to Google through Google Analytics.
For information on how Google handles such information, please refer to “How Google uses information from sites or apps that use our services” and the Google Privacy Policy.
If you wish to opt out of data collection by Google Analytics, you may use the Google Analytics Opt-out Browser Add-on provided by Google, or disable cookies in your browser settings. In applicable regions, you may also refuse analytics cookies through consent management tools (such as cookie banners).
Article 8 (International Data Transfers)
The Company is located in Japan. Collected personal information is stored in the data centers of Microsoft Azure (Microsoft Corporation), which the Company uses as its cloud infrastructure; storage locations include the Japan region as well as the East Asia region. As described in Article 5, personal information may also be transferred to service providers located in the United States (FastSpring = Bright Market, LLC, and Google LLC) to the extent necessary for processing.
For cross-border transfers from the EU/UK and other regions, the Company implements appropriate safeguards in accordance with applicable laws. Specifically, transfers from the EU to Japan are subject to the European Commission’s adequacy decision. Transfers to the East Asia region (other than the Japan region) and to the United States are not covered by an adequacy decision; accordingly, transfers to the United States rely on appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, and transfers to the East Asia region rely on Standard Contractual Clauses (SCCs). For details on the safeguards applicable to transfers, please contact us at the address provided in Article 15.
Article 9 (Data Retention and Protection)
The Company stores collected personal information on a cloud infrastructure with appropriate security measures (Microsoft Azure, as described in Article 8). The Company retains personal information only for the period necessary to achieve the purposes of use, and promptly deletes or anonymizes personal information that is no longer needed, subject to any mandatory retention periods required by law.
The main retention periods are as follows.
- Account Information: During the period of account use and for 3 years after termination of the contract
- Contract and Billing Information: For 7 years in accordance with mandatory retention obligations under applicable laws
- Usage Logs and Technical Information: For 13 months after collection
Article 10 (Customer Rights)
Customers may exercise the following rights with respect to their personal information held by the Company, in accordance with applicable laws. The scope of rights available may vary depending on your location (see Article 14 for details).
- Right to access (disclosure)
- Right to rectification and supplementation
- Right to erasure (deletion)
- Right to restriction of use or processing
- Right to object to third-party disclosure
- Right to data portability
- Right to object to processing
- Right to withdraw consent (for processing based on consent; withdrawal does not affect the lawfulness of processing prior to withdrawal)
To exercise these rights, please contact us at the address provided in Article 15. We will verify your identity and respond within the period required by applicable law. In principle, no fees will be charged for exercising your rights. Customers will not be treated unfavorably for exercising their rights.
Article 11 (Automated Decision-Making and Profiling)
The Company does not engage in automated decision-making (including profiling) without human involvement that produces legal effects or similarly significant impacts on customers. If the Company intends to do so in the future, it will revise this Policy and notify customers of the content, logic, and implications.
Article 12 (Children’s Privacy)
Contracts with the Company (including product and plan purchases) are intended for individuals aged 18 and older. From a data protection perspective, the Company does not intentionally collect personal information from individuals under the age of 16 (or a lower age if required by the law of your jurisdiction, or under the age of 13 in the United States). If we discover that we have inadvertently collected information from someone below the applicable age, we will promptly delete it.
Article 13 (Data Breach Response)
Upon becoming aware of a leak, loss, or damage of customers’ personal information (hereinafter “data breach”), the Company will work to prevent further damage and investigate the cause, and will report to supervisory authorities and notify affected customers within the prescribed timeframes in accordance with applicable laws.
Article 14 (Region-Specific Additional Disclosures)
The following provisions apply only to customers in the respective regions and supplement the other provisions of this Policy. In the event of a conflict with other provisions of this Policy, the provisions of this Article shall prevail for customers in the applicable region.
A. Customers in the EEA (European Economic Area) and the UK (GDPR / UK GDPR)
- Controller: The Company as described in Article 1 is the data controller. The Company has not appointed a representative in the EU/UK.
- Legal Basis: The legal bases used by the Company for processing are as set forth in Article 4.
- International Transfers: Cross-border transfers and their safeguards are as described in Article 8.
- Customer Rights: You have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing, and withdrawal of consent (Article 10).
- Right to Lodge a Complaint with a Supervisory Authority: You have the right to lodge a complaint with the supervisory authority in your place of residence, place of work, or place where the alleged infringement occurred (the data protection authority of an EU member state, or the Information Commissioner’s Office [ICO] in the UK).
- Retention Periods: As set forth in Article 9.
B. Customers in the State of California, USA (CCPA / CPRA)
The statutory categories of personal information collected by the Company in the past 12 months, their sources, purposes of use, and categories of third parties with whom they are shared are as follows.
- Categories of Personal Information Collected: Identifiers (name, email address, IP address, etc.), commercial information (purchase and contract history), internet or other electronic network activity information (usage logs, access information), professional or employment-related information (organization name, job title).
- Sources: Directly from customers, from customers’ devices/browsers, from the payment service provider (FastSpring).
- Business or Commercial Purposes: As set forth in Article 3.
- Categories of Third Parties with Whom Information is Shared: Payment service providers (FastSpring), access analytics service providers (Google), cloud infrastructure (hosting) providers (Microsoft), public authorities as required by law.
- “Sale” and “Sharing”: The Company does not “sell” personal information for monetary consideration. However, the use of Google Analytics and similar services may constitute “sharing” (providing for cross-context behavioral advertising) under California law. Customers may opt out of this through the Google Analytics Opt-out Browser Add-on, disabling cookies in the browser, or through a consent management tool.
- Sensitive Personal Information: The Company does not use or disclose sensitive personal information for the purpose of inference or similar purposes.
- Customer Rights: Right to know, right to delete, right to correct, right to opt out of sale/sharing, and right to limit use of sensitive personal information.
- Exercising Rights: Please contact us at the address provided in Article 15. Requests may also be submitted through an authorized agent. We will verify your identity before responding.
- Non-Discrimination: Customers will not be discriminated against for exercising their rights.
C. Customers in Other U.S. States (Virginia, Colorado, Connecticut, Utah, Texas, etc.)
Under applicable state laws, customers have the right to access, correct, delete, and port their personal information, as well as the right to opt out of the sale of personal information, targeted advertising, and certain profiling. Customers also have the right to appeal if they are dissatisfied with the Company’s response. Please contact us at the address provided in Article 15 to exercise these rights.
D. Other Regions
- Canada (PIPEDA): Customers may request access to and correction of their personal information held by the Company. Collection, use, and disclosure are subject to consent in accordance with applicable laws.
- Brazil (LGPD): Customers may request access, correction, deletion, portability, information regarding processing, withdrawal of consent, and other rights.
- Australia (Privacy Act / APPs): Customers may request access to and correction of their personal information. Complaints may be lodged with the Company or with the Office of the Australian Information Commissioner (OAIC).
- South Korea (Personal Information Protection Act / PIPA): Customers may request access to, correction or deletion of, and suspension of processing of their personal information. Cross-border transfers are handled in accordance with applicable laws.
Article 15 (Contact)
For questions about this Policy, requests relating to personal information, or to exercise your rights, please contact us at the following. We will verify your identity and respond in accordance with applicable laws.
Power Office G.K. Email: info@poweroffice-kato.com
Article 16 (Changes to This Policy)
This Policy is managed by version. When changes are made, a new version of the document will be created and published on the Company’s website. Significant changes will be announced through the Company’s website or other appropriate means.
Article 17 (External Links)
Our website and services may contain links to external sites. The Company is not responsible for the handling of personal information on external sites.