Privacy Policy

Aitane Inc. has established this Privacy Policy regarding the handling of personal information of customers provided to the Company.

This English translation is provided for reference only. In the event of any discrepancy, the Japanese version shall prevail.

Aitane Inc. (hereinafter the "Company") hereby establishes the following privacy policy (hereinafter this "Policy") regarding the handling of personal information in the sales support, customer management, AI assistant, email and calendar integration, meeting bot, business card import, OCR, transcription and other related services provided by the Company (hereinafter the "Service"), in compliance with the Act on the Protection of Personal Information and other applicable laws, regulations and guidelines.

Article 1 (Definitions)

The terms used in this Policy shall have the following meanings.

  • "Personal Information" means personal information as defined in the Act on the Protection of Personal Information, namely information relating to a living individual which can identify a specific individual by name, company name, department name, job title, email address, telephone number, address, photograph, voice, video or other descriptions contained therein, or which contains an individual identification code.
  • "Personal Data" means Personal Information constituting a personal information database, etc.
  • "Retained Personal Data" means Personal Data with respect to which the Company has the authority to disclose, correct, suspend use of, etc.
  • "Special Care-Required Personal Information" means information regarding the principal's race, creed, social status, medical history, criminal record, the fact of having suffered damage from a crime, and other information prescribed by laws and regulations.
  • "User" means a corporation, organization, sole proprietor or individual that uses the Service.
  • "Contracting Company" means a corporation, organization or business operator that concludes a service agreement for the Service with the Company.
  • "Customer Data" means information that a Contracting Company or User registers, sends, stores, integrates or uploads to the Service, including company information, contact person information, business card information, deal information, tasks, notes, emails, calendars, meeting information, audio and video recordings, transcripts, instructions to AI, attached files, etc.
  • "External Integration Services" means Google Workspace, Gmail, Google Calendar, Google Meet, Google Drive, Microsoft Outlook, Microsoft 365, Slack, Zoom, Microsoft Teams, HubSpot, Salesforce, Stripe, Recall.ai, SendGrid, Postmark and other third-party services that the Company provides as integration features on the Service.

Article 2 (Scope of Application)

This Policy applies to the handling of Personal Information in the Service, the Company's website, applications and APIs provided by the Company, support, sales activities, requests for materials, inquiries, recruitment activities and other business activities conducted by the Company.

The Service is primarily intended for Users in Japan; however, it may be used by overseas companies, persons residing overseas or individual Users. Nevertheless, unless otherwise expressly indicated by the Company, the Company does not actively market the Service toward the EU, the United Kingdom or any other specific jurisdiction outside Japan.

Where a Contracting Company registers or integrates into the Service the Personal Information of its own customers, business partners, employees, meeting participants or other third parties, the Company shall handle such Personal Information in accordance with its agreement with the Contracting Company, the instructions of the Contracting Company and this Policy. In such case, the Contracting Company shall provide the necessary notices, obtain the necessary consents and carry out any other procedures required by laws and regulations regarding the acquisition, use, provision to third parties, audio and video recording, transcription, email sending, AI processing, etc. of such Personal Information.

Article 3 (Information Collected)

The Company may collect the following information to the extent necessary to provide the Service.

  1. Information obtained directly from Users or Contracting Companies
  • Name, company name, department name, job title, email address, telephone number, address and other contact information
  • Account ID, login information, authentication information, password hashes, OAuth credentials, access tokens, refresh tokens
  • Contracting Company, workspace, team, role, permissions, invitation history, affiliation information
  • Information relating to inquiries, requests for materials, support requests, deals, applications, contracts, billing, payments and subscription plans
  • Names, contact information, work history, resumes, portfolios, interview records and other information of job applicants necessary for recruitment screening

2. Information entered or uploaded by Users on the Service

  • CRM information such as companies, contact persons, deals, contracts, products, tasks, notes, saved views, tags, activity history
  • Business card images, scanned PDFs, OCR results, and names, company names, job titles, email addresses, telephone numbers, addresses, etc. printed on business cards
  • Email bodies, subjects, senders and recipients, CC/BCC, dates and times sent and received, threads, attached files, scheduled sends, drafts, sending results, and statuses such as opens, clicks and replies
  • Calendar events, meeting titles, participants, participant email addresses, meeting URLs, start and end dates and times, meeting notes, agendas
  • Meeting bots, audio and video recordings, audio, video, transcripts, summaries, minutes, follow-up drafts, post-meeting email drafts
  • AI chat, inputs in Ask/Agent mode, @mentions, attached files, AI output results, execution proposals, approval history
  • Data referenced or operated on through external LLMs, MCP, APIs, Webhooks, etc.
  • Operation logs, audit logs, approval logs, error information, notification history, external transmission history

3. Information obtained from External Integration Services

Where a User or Contracting Company enables an external integration, the Company may obtain the following information within the scope of the permissions indicated on the OAuth consent screen, the administration screen, the integration settings or an individual agreement.

  • Account profiles, names, email addresses, icons and organization information for Google, Microsoft, Slack, etc.
  • Email information from Gmail, Outlook, etc., including email bodies, subjects, senders and recipients, CC/BCC, dates and times, attached files, threads, labels and metadata
  • Information necessary for sending emails, creating drafts, managing replies, changing labels, changing read/unread status, deleting, and other operations performed by the User on the Service in Gmail, etc.
  • Events, participants, meeting URLs, availability, reminder settings, and information necessary for creating, updating and deleting events in Google Calendar, Outlook Calendar, etc.
  • File names, metadata, file contents or attached files from Google Drive, OneDrive and other file services
  • Meeting URLs, meeting participation information, and information necessary for audio and video recording and transcription in Google Meet, Zoom, Microsoft Teams, etc.
  • Notification destinations, channels, messages and integration settings in Slack, etc.
  • Customer, company, contact person, deal, activity history and other information necessary for integration with HubSpot, Salesforce and other CRM and sales support services
  • Payment status, billing information, payment identifiers, subscription plans, usage volume, payment errors and other information obtained through Stripe and other payment services. Payment information such as credit card numbers is, in principle, obtained and stored directly by the payment service provider, and the Company does not store card numbers themselves.

4. Information collected automatically

  • IP address, cookies, device identifiers, browser, OS, device type, language, time zone
  • Access dates and times, pages viewed, features used, clicks, searches, API requests, responses, errors, crash logs
  • Information relating to usage volume, number of emails sent, number of AI uses, token counts, audio and video recording time, storage capacity, estimated costs and plan limits
  • Information relating to email open confirmation, link clicks and reply detection. This may include information obtained through open-tracking pixels, tracking URLs, reply detection and other similar technologies.
  • Logs necessary for investigating fraudulent use, spam, security and failures

5. Information obtained from third parties or public sources

For purposes such as providing the Service, identity verification, sales support, supplementing company information, preventing duplicates and security measures, the Company may obtain company information, contact person information, contact details, job information, domain information, payment status, information relating to fraudulent use, etc. from Contracting Companies, Users, business partners, public websites, corporate websites, social media, business cards, email signatures, external databases, payment service providers, authentication providers, security providers and other third parties.

Article 4 (Purposes of Use)

The Company uses the Personal Information it obtains for the following purposes.

  • To provide, operate, maintain and improve the Service
  • To create accounts, log in, verify identity, authenticate, authorize, manage roles and permissions such as Admin/Member, and manage workspaces
  • To provide functions such as CRM, company and contact person management, deal management, task management, notes, search, saved views, import and export
  • To perform email integration, email composition, email sending, scheduled sending, reply management, unanswered-email reminders and follow-up support
  • To ascertain email open, click and reply status and use it for sales activities, follow-up, task creation, notifications and analysis
  • To perform calendar integration, availability calculation, event creation, updating and deletion, meeting management, meeting participant management and reminder notifications
  • To have the meeting bot join meetings, and to perform audio and video recording, transcription, summarization, preparation of minutes and post-meeting follow-up
  • To perform OCR and structured extraction of business card images or PDFs, automatic registration to companies and contact persons, duplicate checking, record matching (name identification) and provision of a review UI
  • To support the creation of thank-you emails, follow-up emails, tasks, deals, appointments, etc. after business card import; provided, however, that this is premised on a function whereby emails are sent after User confirmation, and where fully automatic sending is performed, the Company will separately make the necessary settings or provide the necessary notice.
  • To provide AI chat, AI summarization, text generation, email draft creation, task suggestions, research support, Ask/Agent functions, MCP/API integration, etc.
  • To connect with External Integration Services and perform synchronization, data acquisition, data transmission, notifications, integration disconnection and token management
  • To provide, or provide in the future, meeting-related functions for Google Meet, Zoom, Microsoft Teams, etc.
  • To provide, or provide in the future, data integration with external CRM and sales support services such as HubSpot and Salesforce
  • To bill and settle usage fees, manage plans, measure usage volume, issue invoices and receipts, and prevent fraudulent payments
  • To provide notices regarding the Service, specification changes, maintenance, failures, security, contracts, and changes to the terms of use or this Policy
  • To respond to inquiries, requests for materials, support, complaints, disputes and requests for the exercise of rights
  • To prevent, investigate and respond to unauthorized access, fraudulent use, spam, impersonation, exceeding of permissions, information leaks and other acts that infringe the rights or interests of the Company or third parties
  • To obtain logs, audit trails, approval history and operation history to ensure governance, compliance, security and internal control
  • To analyze the usage status of the Service and perform functional improvements, quality improvements, failure response, UI/UX improvements and performance improvements
  • To create statistical information that cannot identify individuals and use it for business analysis, service improvement and research and development
  • To provide information on service notices, product updates, seminars, campaigns, materials and marketing information; provided, however, that Users may request to opt out of such communications at any time.
  • To screen, contact and onboard job applicants and manage recruitment
  • To respond to laws and regulations, requests from administrative or judicial authorities, and contractual obligations
  • For purposes incidental or related to each of the above purposes

Article 5 (Changes to Purposes of Use)

The Company may change the purposes of use within a scope reasonably recognized as being relevant to the purposes of use prior to the change. Where the purposes of use are changed, the Company will publish or notify the changed purposes of use through the Service, the Company's website, email or other appropriate means.

Article 6 (Special Provisions on Information Obtained from Google Workspace APIs, etc.)

With respect to information obtained by the Company from the Google Workspace API, Gmail API, Google Calendar API, Google Drive API, Google Meet-related APIs and other Google APIs (hereinafter "Google User Data"), this Article shall take precedence over the other provisions of this Policy.

  • The Company uses Google User Data only to the extent necessary to provide or improve user-facing features that are clearly displayed on the Service, namely email, calendar, meetings, CRM, business card import, tasks, notifications, AI assistance, workflows, etc.
  • The Company does not use Google User Data for serving advertisements, retargeting, personalized advertising, interest-based advertising, provision to advertising platforms, or provision to data brokers.
  • The Company does not use Google User Data for credit assessment, lending decisions, insurance underwriting, employment decisions or other similar determinations.
  • The Company does not use Google User Data to create, train or improve generalized AI models, machine learning models or foundation models of the Company or any third party.
  • The Company does not sell Google User Data.
  • The Company does not provide Google User Data to third parties; provided, however, that this shall not apply where necessary to provide or improve user-facing features of the Service within the scope consented to by the User, for security purposes, for compliance with laws and regulations, or where the Company takes necessary measures in accordance with applicable laws and regulations and Google's policies in connection with a business transfer, merger, company split or other business succession.
  • The Company's officers and employees and the personnel of its subcontractors do not view the contents of Google User Data except where the User has explicitly requested or consented, where necessary for security or fraudulent-use investigations, or where necessary for legal compliance.
  • The Company protects Google User Data in transit and at rest through appropriate encryption and other security control measures.
  • Where a User disconnects the Google integration or requests deletion of Google User Data, the Company will delete or invalidate such data or tokens within a reasonable period, except where retention is required by laws and regulations or by contract.
  • Aitane's use and transfer of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Article 7 (AI, OCR, Transcription and Automated Processing)

The Company may, to the extent necessary to provide the Service, perform processing such as AI, OCR, speech recognition, transcription, summarization, text generation, classification, duplicate determination, record matching (name identification), recommendations and workflow automation.

The Company does not use Customer Data, emails, calendars, meeting content, business card images, audio and video recordings, transcripts, attached files, etc. entered, stored, integrated or uploaded to the Service by Users or Contracting Companies for the purpose of training generalized AI models of the Company or any third party.

The Company may use statistical information that cannot identify individuals for service improvement, quality improvement and statistical analysis.

Where the Company outsources processing such as AI, OCR, transcription or meeting bots to an external provider, the Company restricts such subcontractor from using the data for other purposes, retraining or re-providing it, by means of contracts, settings or other reasonable methods. At present, the Company may use Recall.ai for meeting bots, audio and video recording, transcription, etc.

Content generated by AI may contain errors, incomplete information or speculation. When using AI-generated email drafts, minutes, summaries, tasks, suggestions, text to be sent to customers, etc., Users shall review the content themselves and revise it as necessary.

Article 8 (Notes on Meetings, Audio and Video Recording, and Transcription)

Where a User or Contracting Company uses the meeting bot, audio recording, video recording, transcription, summarization, sending of minutes or other meeting-related functions, the names, email addresses, voices, video, statements, meeting URLs, participation status, etc. of meeting participants may be collected and processed.

As a rule, the Company's meeting bot joins only meetings that a User or Contracting Company has explicitly enabled. Support for Google Meet is the baseline, and support for Zoom, Microsoft Teams, etc. may be provided or provided in the future.

Users and Contracting Companies shall appropriately notify meeting participants that audio recording, video recording, transcription, AI summarization, etc. will be performed, and shall obtain the consent or approval required by laws and regulations, contracts, internal rules and their relationships with meeting participants. The Company may display notices regarding audio recording, video recording, transcription, etc. on the screens of the Service.

Article 9 (Email Sending and Tracking)

The Company provides functions on the Service for Users to compose emails, create drafts, send, schedule sending, manage replies, receive unanswered-email reminders, follow up, create thank-you emails after business card import, etc.

Thank-you emails after business card import and other emails sent to customers are, in principle, sent after the User has confirmed the content and recipients.

The Company may use open-tracking pixels, tracking URLs, reply detection and other similar technologies to ascertain email open, link click and reply status. This information is used for managing sales activities, follow-up, task creation, notifications, analysis and improvement of the Service.

When using the email sending and tracking functions, Users and Contracting Companies shall comply with applicable laws and regulations, industry rules, agreements with recipients and internal rules.

Article 10 (Provision to Third Parties)

The Company does not provide Personal Data to third parties without obtaining the prior consent of the principal, except in the following cases.

  • Where based on laws and regulations
  • Where it is necessary for the protection of the life, body or property of a person and it is difficult to obtain the consent of the principal
  • Where it is particularly necessary for improving public health or promoting the sound growth of children and it is difficult to obtain the consent of the principal
  • Where it is necessary to cooperate with a national government organ, a local government or a person entrusted thereby in performing affairs prescribed by laws and regulations, and obtaining the consent of the principal is likely to impede the performance of such affairs
  • Where all or part of the handling of Personal Data is entrusted to the extent necessary to achieve the purposes of use
  • Where Personal Data is provided in connection with a merger, company split, business transfer or other business succession
  • Where Personal Data is provided, based on the instructions, settings or consent of a User or Contracting Company, to External Integration Services, APIs, Webhooks, MCP, external LLM clients or other integration destinations designated or enabled by the User or Contracting Company
  • Other cases permitted under the Act on the Protection of Personal Information or other laws and regulations

Article 11 (Entrustment and Subprocessors)

The Company may entrust the handling of Personal Information or Customer Data to external providers to the extent necessary to achieve the purposes of use. Subcontractors include providers of cloud infrastructure, hosting, databases, authentication, email delivery, payment, billing, AI, OCR, transcription, meeting bots, notifications, analytics, monitoring, support, security, legal and accounting services, etc.

The main services used by the Company may include Google Cloud, Vercel, Google Workspace, Microsoft 365, Slack, Zoom, Microsoft Teams, HubSpot, Salesforce, Stripe, Recall.ai, SendGrid, Postmark, Google Analytics, etc. These services may process information necessary for the provision of the Service through locations, servers, sub-subcontractors or support structures inside and outside Japan.

When selecting a subcontractor, the Company confirms the subcontractor's security control system, concludes necessary and appropriate agreements, and exercises necessary and appropriate supervision over the subcontractor.

The Company may publish or provide a list of its main subcontractors or subprocessors on a page designated by the Company, in the administration screen, in contract documents or by other appropriate means.

Article 12 (Handling in Foreign Countries)

The Company may, to the extent necessary to provide the Service, use cloud services, hosting services, AI/OCR/transcription services, meeting bot services, External Integration Services, payment services, email delivery services, analytics services, support services and other subcontractors or sub-subcontractors located inside and outside Japan.

Accordingly, part of the Personal Information, Customer Data, logs, metadata, payment-related information, meeting-related information, support information and other information necessary for the provision of the Service may be processed, stored or viewed outside Japan.

The external services used by the Company may include Google Cloud, Vercel, Google Workspace, Microsoft 365, Slack, Zoom, Microsoft Teams, HubSpot, Salesforce, Stripe, Recall.ai, SendGrid, Postmark, Google Analytics, etc. The providers, servers, processing locations or support locations of these services may be located outside Japan.

Where the Company handles Personal Data in a foreign country, it takes necessary and appropriate security control measures after ascertaining the personal information protection system and other external environment of that foreign country. In addition, where the Company provides Personal Data to a third party in a foreign country, it takes measures such as providing information to the principal, obtaining consent, confirming equivalent measures and other necessary measures in accordance with the Act on the Protection of Personal Information and other applicable laws and regulations.

Due to the specifications of the external services used, cloud configurations, sub-subcontractors, failure response, support structures, etc., the Company may not always be able to identify the country or region in which Personal Data is stored or processed. In such case, the Company will endeavor to publish or provide the reason why the country or region cannot be identified and information useful for reference by the principal, on the Company's website, in the administration screen, in contract documents, in the subprocessor list or by other appropriate means.

Article 13 (Joint Use)

The Company does not currently engage in joint use of Personal Data.

Where the Company engages in joint use, it will publish or notify the principal in advance of the items of Personal Data to be jointly used, the scope of joint users, the purposes of use, the name, address and representative's name of the party responsible for management, and other matters prescribed by laws and regulations.

Article 14 (Use of Cookies, Google Analytics, etc.)

The Company may use cookies, local storage, access analytics tools, log analytics tools and other similar technologies on the Service and the Company's website.

The Company uses these technologies to maintain login status, ensure security, save settings, analyze usage, investigate failures, improve functions and prevent fraudulent use.

The Company may use access analytics tools such as Google Analytics. Through these, the Company may obtain page views, usage status, device information, browser information, IP addresses, cookies and other information necessary for access analytics.

The Company does not use Google User Data for serving advertisements, retargeting, personalized advertising or interest-based advertising. Furthermore, the Company does not provide obtained Personal Data to third parties for marketing purposes.

Users can disable cookies through their browser settings. However, if cookies are disabled, some functions of the Service may not be available.

Article 15 (Marketing Communications)

The Company may send service notices, product updates, seminars, campaigns, materials and other marketing information to Users, Contracting Companies, persons who have requested materials, persons who have made inquiries, job applicants and other persons who have a point of contact with the Company.

Marketing emails will include instructions on how to unsubscribe. Users may request to unsubscribe from marketing emails at any time. However, notices necessary for the provision of the Service, such as those regarding contracts, accounts, security, failures, billing and important announcements, may continue to be sent after unsubscribing.

The Company does not provide Personal Data to third parties for marketing purposes without the consent of the principal.

Article 16 (Special Care-Required Personal Information)

The Company does not provide the Service for the purpose of intentionally collecting Special Care-Required Personal Information.

However, emails, meetings, notes, business cards, attached files, transcripts, inputs to AI, etc. may contain Special Care-Required Personal Information. Where Users and Contracting Companies enter, store, integrate or upload Special Care-Required Personal Information to the Service, they shall obtain the consent and carry out any other procedures required by laws and regulations.

Where the Company handles Special Care-Required Personal Information, it takes necessary and appropriate security control measures in accordance with the Act on the Protection of Personal Information and other applicable laws and regulations.

Article 17 (Security Control Measures)

The Company takes necessary and appropriate security control measures to prevent the leakage, loss, damage, unauthorized access and fraudulent use of Personal Data. The measures taken by the Company include the following.

  • Establishment of a basic policy and internal rules on the protection of personal information
  • Clarification of the persons responsible for handling Personal Data, their authority and the scope of handling
  • Training of employees, confidentiality and access permission management
  • Selection, contracting and supervision of subcontractors
  • Account management, authentication, authorization, role permissions such as Admin/Member, least privilege, deletion of unnecessary accounts
  • Encryption in transit and at rest, protection of tokens and credentials
  • Collection and monitoring of audit logs, operation logs and access logs
  • Vulnerability countermeasures, dependency library management, security updates
  • Backup, recovery, failure response and incident response structure
  • Ascertaining the external environment where foreign cloud services or foreign subcontractors are used
  • Physical security controls, device management, restrictions on removal from premises
  • Other reasonable security control measures deemed necessary by the Company

The Company endeavors to ensure security; however, due to the nature of the Internet and information systems, it does not guarantee complete security.

Article 18 (Retention Period)

The Company retains Personal Information for the period necessary to achieve the purposes of use, the period required by contract, the period required by laws and regulations, or the period reasonably necessary for dispute resolution, audits and prevention of fraudulent use.

  • Account information and contract information is retained during the period of use of the Service and, after termination of the contract, for the period required by laws and regulations or by contract.
  • CRM Customer Data is retained for approximately 90 days after termination of the contract, and is thereafter deleted or anonymized in accordance with the contract, the settings in the administration screen, laws and regulations or individual agreements.
  • Meeting audio and video recording data is retained, in principle, for approximately 30 to 90 days in accordance with the contract, subscription plan, settings in the administration screen or individual agreements, and is deleted or anonymized upon expiration of that period.
  • Transcripts, minutes, AI summaries, meeting notes, etc. are retained, deleted or anonymized in accordance with the contract, subscription plan, settings in the administration screen or the User's deletion operations.
  • OAuth tokens and other credentials necessary for external integrations are retained while the integration is active, and where the User or Contracting Company disconnects the integration, they are deleted or invalidated within a reasonable period, except where required by laws and regulations or by contract.
  • Logs, audit logs, security logs and usage information are retained, in principle, for approximately one year for security, audit, billing, failure response and prevention of fraudulent use.
  • Backup data is retained, in principle, for approximately 30 to 90 days, and is thereafter deleted or overwritten in sequence.
  • Information relating to billing, payments, accounting, tax, contracts and legal claims is retained for the period required by applicable laws and regulations.

The Company may use statistical information that cannot identify individuals without any time limitation.

Article 19 (Disclosure, Correction, Suspension of Use, etc.)

A principal may, in accordance with laws and regulations, request notification of the purposes of use, disclosure, disclosure of records of provision to third parties, correction, addition, deletion, suspension of use, erasure, and suspension of provision to third parties with respect to Retained Personal Data concerning that principal held by the Company.

To make a request, please contact the contact point set forth in Article 24. After verifying the identity of the principal, the Company will respond without delay in accordance with laws and regulations. In the case of a request by an agent, the Company may require the submission of documents necessary to confirm the authority of the agent.

However, the Company may decline to respond to all or part of a request in the following cases.

  • Where there is a risk of harm to the life, body, property or other rights or interests of the principal or a third party
  • Where there is a risk of serious hindrance to the proper conduct of the Company's business
  • Where responding would violate laws and regulations
  • Where the subject of the request does not fall under Retained Personal Data
  • Other cases where the Company is not obligated to respond under laws and regulations

For requests for notification of the purposes of use, disclosure of Retained Personal Data or disclosure of records of provision to third parties, the Company may charge an administrative fee of JPY 1,000 (tax included) per request.

For requests concerning Customer Data managed by a Contracting Company, please contact the relevant Contracting Company in principle. Where an inquiry is made directly to the Company, the Company will, as necessary, contact the relevant Contracting Company and support the Contracting Company's response.

Article 20 (Disconnection of External Integrations and Data Deletion)

Users or Contracting Companies may disconnect external integrations through the administration screen of the Service, the administration screen of the External Integration Service, or the method designated by the Company.

Where an external integration is disconnected, the Company will delete or invalidate the tokens necessary for that integration. Data stored or synchronized into the Service prior to disconnection will be retained, deleted or anonymized in accordance with the Contracting Company's settings, the contract, laws and regulations or this Policy.

Where the Google integration is disconnected, the Company will delete or invalidate Google User Data or the credentials necessary for the Google integration within a reasonable period, except where retention is required by laws and regulations or by contract.

Article 21 (Response to Leakage and Similar Incidents)

Where a leakage, loss or damage of Personal Data or any other incident concerning the security of Personal Data occurs, or where the Company becomes aware of the risk thereof, the Company will investigate the facts, confirm the scope of impact, prevent the spread of damage and consider measures to prevent recurrence.

Where the incident is one that is likely to harm the rights and interests of individuals or otherwise falls under an incident prescribed by laws and regulations, the Company will, in accordance with laws and regulations, report to the Personal Information Protection Commission, notify the principal, notify the Contracting Company and take other necessary measures.

Article 22 (Minors)

Where a minor uses the Service, the minor shall obtain the consent of a legal representative.

Where the Company becomes aware that a minor is using the Service without the consent of a legal representative, the Company may suspend or delete the relevant account or take other necessary measures.

Where a Contracting Company allows a minor to use the Service, the Contracting Company shall obtain the consent of the legal representative and carry out any other procedures required by laws and regulations.

Article 23 (Third-Party Sites and External Apps)

The Service or the Company's website may contain links to, or integration functions with, third-party websites, external apps, external LLMs and External Integration Services. The handling of Personal Information by third-party services is governed by the terms of use and privacy policies of those third parties.

Where a User personally enables an external LLM, MCP client, API integration, Webhook or other third-party integration, data may be provided to that integration destination. Users and Contracting Companies shall review the terms of use, security and privacy policies of the integration destination before using it.

Article 24 (Contact Point)

For inquiries regarding the handling of Personal Information, disclosure, correction, suspension of use, deletion, disclosure of records of provision to third parties, complaints, consultations and other matters relating to this Policy, please contact the following contact point. [Contact] Aitane Inc. Personal Information Inquiry Desk Email: support@aitane.co.jp

For identity verification, the Company may verify identity by means of a driver's license, identification documents, authentication via the registered email address, or other methods the Company reasonably deems necessary.

Article 25 (Changes to this Policy)

The Company may change this Policy due to amendments to laws and regulations, changes to the content of the Service, the addition of External Integration Services, security needs or other reasons. Where this Policy is changed, the Company will publish or notify the changed content and its effective date on the Company's website, within the Service, by email or by other appropriate means. For material changes, the Company will notify Users or Contracting Companies by reasonable means.

Article 26 (Business Operator Information)

Business name: Aitane Inc. Representative: Junichiro Aita Address: Kudanshita Tokyu Shin Sakura Building 6F, 1-3-3 Kudankita, Chiyoda-ku, Tokyo 102-0073, Japan Contact: support@aitane.co.jp

Established: November 5, 2023 Last revised: May 14, 2026