Privacy Policy

Findy Korea Inc.
Representative Director: Yuichiro Yamada

Findy Korea Inc. (hereinafter referred to as the "Company") complies with personal information protection provisions under relevant laws such as the "Personal Information Protection Act," protects your personal information, and has established and disclosed the following Privacy Policy to ensure that complaints related thereto can be handled quickly and smoothly.

1. Personal Information

Personal information refers to information regarding a living individual that falls under any of the following items:
1. Information that can identify an individual through name, resident registration number, video/images, etc., contained in said information.
2. Information that may not identify a specific individual on its own but can be easily combined with other information to identify them.

2. Items, Purpose, Retention, and Processing Period of Personal Information

The Company processes personal information within the scope of the purposes defined below, having obtained the consent of the data subject as follows:

Collected Items

Purpose of Processing

Retention and Use Period

Personal information of members using the Company's service ("the Service")
Specific Items: Name, Email address, Phone number

To confirm the usage status of the Service.
To improve the Service and develop new services.
To respond to inquiries (including identity verification).
To provide information and deliver advertisements regarding the Service (new features, etc.).
To provide information on seminars/events, etc.
To conduct surveys.
For statistical processing of member profiles, etc.

1 year from membership withdrawal, unless the personal information must be preserved according to relevant laws.

Personal information of business partners
Specific Items:
Name, Email address, Phone number

To consider transactions with business partners (including potential ones).
To properly implement and manage contracts with business partners.
To conduct business negotiations, meetings, and communication.
To manage entry and exit to Company offices, etc.

1 year from the end of the transaction, unless the personal information must be preserved according to relevant laws.

Personal information of shareholders, etc.
Specific Items: Name, Email address, Phone number

To exercise rights and fulfill obligations based on the Companies Act and Commercial Code.
To implement various measures aimed at smoothing the relationship between shareholders and the Company.
For shareholder management.

1 year from the end of the transaction, unless the personal information must be preserved according to relevant laws.

Personal information of job applicants
Specific Items: Name, Email address, Phone number

To contact applicants regarding Company recruitment activities.
To evaluate the suitability of applicants during selection (including background checks, reference checks, and other verification procedures).
To improve the Company's recruitment process.
To determine suitability for business assignments and ensure health.
To provide information about Company employment opportunities and events.
For satisfaction surveys and improvement of employment opportunities/events.
For purposes incidental to recruitment activities, such as formulating recruitment plans.
To manage applicant information.

2 years from the end of the selection process, unless the personal information must be preserved according to relevant laws.

Personal information of persons wishing to be entrusted with business
Specific Items: Name, Email address, Phone number

To evaluate suitability when concluding a contract.
To improve the Company's contract conclusion process.
To provide information about Company seminars/events, etc.
To improve and conduct satisfaction surveys for seminars/events.
To contact applicants regarding Company contract-related activities.
To manage information of persons wishing to be entrusted.

1 year from the end of the transaction, unless the personal information must be preserved according to relevant laws.

Personal information of Company employees
Specific Items: Name, Email address, Phone number, Health check results

For business communication, creation of employee rosters, procedures required by law, and other employment management.
For personnel selection, and determination of assignments, secondments, or dispatch destinations.
For determination and payment of remuneration, tax processing, social insurance procedures, and providing welfare.
For safety management measures in online monitoring, etc.
For Company PR or promotional activities in advertising materials (individual consent will be obtained in advance).
For appropriate health management (health information such as results will not be acquired, used, or provided except as based on laws).

1 year from resignation, unless the personal information must be preserved according to relevant laws.

Personal information of retirees
Specific Items: Name, Email address, Phone number

For social insurance procedures, other legally required procedures, and post-resignation contact for alumni recruitment.
For creating various statistical data and improving the work environment/efficiency.

1 year from resignation, unless the personal information must be preserved according to relevant laws.

Personal info of persons inquiring/requesting materials/participating in events/answering surveys
Specific Items: Name, Email address, Phone number

To accurately understand and handle inquiry/contact details.
To provide information on the Service, seminars, and events.
To provide recruitment/hiring info and contact.
To conduct surveys and distribute email magazines.
To analyze marketing for selling the Service, etc.
To use as non-identifying statistical data for PR, sales, and recruitment.
To record and use photos/videos/audio from events ("Event Records") for PR and sales.

1 year from the end of the transaction, unless the personal information must be preserved according to relevant laws.


Additionally, the Company processes the following personal information items without the consent of the data subject:
・Item: Income tax withholding, issuance and delivery of receipts.
・Processing Items: Name of officers and employees, Resident registration number.
・Legal Basis: "Value Added Tax Act" Article 32, "Enforcement Decree of the Value Added Tax Act" Article 67, "Income Tax Act" Articles 145 and 164, "Corporate Tax Act" Article 116.

Regardless of the above retention and use periods, if the following reasons apply, personal information may be retained and used until the end of said reason:
・In the event of an ongoing investigation for violation of relevant laws (until the end of said investigation).
・If credit/debt relationships remain from the use of the service (until settlement of the relationship).
・Necessary for the storage of withholding tax payment records (5 years from the deadline for statutory filing).
・Storage according to the "Act on the Consumer Protection in Electronic Commerce, etc." (Electronic Commerce Act) :
  ・Records on contracts or withdrawal of applications, etc.: 5 years. (Article 6, Paragraph 1, Item 2 of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, etc.)
  ・Records on payment settlement and supply of goods, etc.: 5 years. (Article 6, Paragraph 1, Item 3 of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, etc.)
  ・Records on consumer complaints or dispute processing: 3 years. (Article 6, Paragraph 1, Item 4 of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce, etc.)
・Storage of communication fact confirmation data based on Article 15-2, Paragraph 2 of the Protection of Communications Secrets Act:
  ・Login records: 3 months.

3. Restrictions on the Use of Personal Information

The Company does not handle personal information beyond the range necessary to achieve the purpose of use without obtaining prior consent. However, except when there is a risk of unfairly infringing upon the interests of the data subject or a third party, the Company may use personal information for purposes other than the intended use or provide it to a third party in the following cases:
1. When separate consent is obtained from the data subject.
2. When there are special provisions in other laws.
3. When it is recognized as clearly necessary for the urgent benefit of life, body, or property of the data subject or a third party.
4. When urgently necessary for public safety and order, such as public health.

4. Matters Concerning the Rights of Data Subjects and Their Exercise

Users may exercise rights related to personal information protection, such as requests for viewing, correction, deletion, and suspension of processing against the Company, as determined by relevant laws such as the Personal Information Protection Act.
The Company will take measures without delay in response to the exercise of rights by users; however, rights may be restricted if there are mandatory obligations set by law. If a data subject requests correction or deletion of errors in personal information, that information will not be used or provided until the correction or deletion is completed.

For the exercise of rights, please contact the following:
・Request to: Personal Information Handling Dedicated Desk
・Email: personal.info@findy.co.jp

5. Outsourcing of Personal Information Processing

The Company may entrust the handling of personal information to contractors for business operations. In this case, the Company confirms that the contractor has a management system to protect personal information appropriately and satisfies the level necessary for prevention of leakage.
The Company entrusts personal information processing as follows for smooth business handling:

Trustee (Contractor)

Content of Entrusted Business

Google LLC
Microsoft Corporation
X Corp.
Criteo
Meta
LINE Yahoo Corporation
Interspace Co., Ltd.,
STUDIO Inc.
SmartNews, Inc.

Advertising distribution business

HubSpot Japan K.K.
Salesforce, Inc.

Customer management business

When concluding an entrustment contract, the Company specifies matters such as the prohibition of processing personal information outside the purpose of the business, technical/managerial protection measures, restrictions on re-entrustment, management/supervision of the trustee, and liability for damages in documents such as contracts, and supervises whether the trustee processes personal information safely.

6. Provision of Personal Information to Third Parties

The Company provides personal information to third parties as follows for the transmission of personalized advertisements, etc., with the consent of the data subject:

Recipient

Purpose of Provision

Provided Items

Retention and Use Period

Meta Platforms, Inc.,
Google LLC,
LINE Yahoo Corporation, LinkedIn Corporation,
CRITEO K.K.,
Microsoft Ireland Operations Limited

Transmission of personalized advertisements and analysis of marketing results

Hashed email address and phone number

Until the purpose of personal information processing is achieved

Recipient

Purpose of Provision

Provided Items

Retention and Use Period

Recipient

Meta Platforms, Inc.,
Google LLC,
LINE Yahoo Corporation, LinkedIn Corporation,
CRITEO K.K.,
Microsoft Ireland Operations Limited

Purpose of Provision

Transmission of personalized advertisements and analysis of marketing results

Provided Items

Hashed email address and phone number

Retention and Use Period

Until the purpose of personal information processing is achieved

7. Overseas Transfer of Personal Information

The Company transfers personal information overseas (Legal basis: Personal Information Protection Act Article 28-8, Paragraph 1, Item 3). The Company implements protection measures according to relevant laws such as the Personal Information Protection Act. If overseas transfer is refused, use of the website may become difficult. Contact personal.info@findy.co.jp to refuse.

Recipient (Country, Contact)

Transfer Timing/Method

Transfer Items

Recipient's Purpose

Recipient's Retention Period

Meta Platforms, Inc. (USA, https://www.facebook.com/privacy/policy/),
Google LLC (USA, https://policies.google.com/privacy),
LINE Yahoo Corporation (Japan, ​​https://www.lycorp.co.jp/ja/company/privacypolicy/),
X Corp. (USA, https://privacy.x.com/en),
LinkedIn Corporation (USA, https://www.linkedin.com/legal/privacy-policy),
CRITEO K.K. (France, https://www.criteo.com/privacy/),
Microsoft Ireland Operations Limited (Ireland, https://www.microsoft.com/ja-jp/privacy/privacystatement)

Via communication network when necessary

Hashed email address and phone number

Transmission of personalized advertisements and analysis of marketing results

Until the purpose of personal information processing is achieved

Findy Inc. (Japan, https://findy.co.jp/privacy/)

Via communication network when necessary

Name, Email address, Phone number

Each purpose defined in "2. Items, Purpose, Retention, and Processing Period of Personal Information"

Until the purpose of personal information processing is achieved

Recipient (Country, Contact)

Meta Platforms, Inc. (USA, https://www.facebook.com/privacy/policy/),
Google LLC (USA, https://policies.google.com/privacy),
LINE Yahoo Corporation (Japan, ​​https://www.lycorp.co.jp/ja/company/privacypolicy/),
X Corp. (USA, https://privacy.x.com/en),
LinkedIn Corporation (USA, https://www.linkedin.com/legal/privacy-policy),
CRITEO K.K. (France, https://www.criteo.com/privacy/),
Microsoft Ireland Operations Limited (Ireland, https://www.microsoft.com/ja-jp/privacy/privacystatement)

Transfer Timing/Method

Via communication network when necessary

Transfer Items

Hashed email address and phone number

Recipient's Purpose

Transmission of personalized advertisements and analysis of marketing results

Recipient's Retention Period

Until the purpose of personal information processing is achieved

Recipient (Country, Contact)

Findy Inc. (Japan, https://findy.co.jp/privacy/)

Transfer Timing/Method

Via communication network when necessary

Transfer Items

Name, Email address, Phone number

Recipient's Purpose

Each purpose defined in "2. Items, Purpose, Retention, and Processing Period of Personal Information"

Recipient's Retention Period

Until the purpose of personal information processing is achieved

8. Destruction of Personal Information

In principle, the Company destroys personal information without delay when it becomes unnecessary, such as the expiration of the retention period or achievement of the processing purpose. If information must be preserved due to other laws despite the expiration of the period, it is moved to a separate database (DB) or storage location.
・Destruction Procedure: Personal information with a reason for destruction is selected and destroyed with the approval of the personal information destruction manager.
・Destruction Method: Paper records are shredded or incinerated; electronic files are destroyed using technical methods that prevent reproduction of the record.

9. Measures to Ensure Safety of Personal Information

The Company provides necessary and appropriate supervision to its employees who handle personal information to ensure the secure management of such information against risks such as loss, destruction, falsification, and leakage. Furthermore, the Company may entrust the handling of personal information to third-party contractors for business operations. In selecting such contractors, the Company requires that they have a management system in place capable of appropriately protecting personal information, and stipulates necessary matters in contracts, etc., such as the proper management of personal information, confidentiality, and prevention of leakage. Specific details of the security management measures for personal data held by the Company are as follows:

・Rules for Handling: Rules for acquisition, use, storage, and disposal.
・Managerial Measures: Appointment of a manager, clarifying the scope of employee access, and regular self-inspections/audits.
・Physical Measures: Entry/exit control and measures to prevent theft/loss of devices and documents.
・Technical Measures: Access control and introduction of systems to protect against unauthorized access/malware.
・Grasping External Environment: Implementing safety measures after understanding the personal data protection systems of foreign countries where cloud services are used.

Establishment of Basic Policies

Establishment of Basic Policies: Established this Privacy Policy as a basic policy regarding "compliance with relevant laws, regulations, and guidelines," "contact point for inquiries and complaint handling," etc., to ensure the proper handling of personal data.

Establishment of Rules for Handling Personal Data

Establishment of Rules for Handling Personal Data: Established personal data handling regulations regarding handling methods, responsible persons/persons in charge, and their duties for each stage, including acquisition, use, storage, provision, deletion, and disposal.

Administrative Security Measures

・Appointment of Responsible Persons: Appointed a person responsible for the handling of personal data, clarified the employees who handle personal data and the scope of personal data handled by such employees, and established a reporting and communication system to the responsible person in case facts or signs of violations of laws or handling regulations are identified.
・Self-Audits and External Audits: Conduct periodic self-audits regarding the status of personal data handling, while also conducting audits by other departments or external parties.
・Employee Training: Conduct periodic training for employees regarding matters to be noted in the handling of personal data.
・Confidentiality Obligations: Included matters concerning confidentiality regarding personal data in employment rules or internal regulations.

Physical Security Measures

・Access Control and Prevention of Unauthorized Viewing: Implement entry and exit management for employees in areas where personal data is handled and restrict equipment brought in, while implementing measures to prevent unauthorized persons from viewing personal data.
・Prevention of Theft or Loss: Prepared measures to prevent theft or loss of equipment, electronic media, and documents used for handling personal data, and implemented measures to ensure that personal data is not easily identifiable when transporting such equipment or electronic media, including movement within the place of business.

Technical Security Measures

・Access Control: Implement access control to limit the scope of the persons in charge and the personal information databases handled.
・Protection from External Attacks: Introduced a system to protect information systems handling personal data from unauthorized external access or malicious software.

Understanding of External Environments

Understanding of External Environments: When storing personal data in cloud services located in foreign countries, implement appropriate security management measures after understanding the systems regarding personal data protection in the relevant countries.

10. Installation, Operation, and Refusal of Automatic Collection Devices

The Company uses cookies, which store and periodically retrieve user information, to provide personalized services to individual users.
A cookie is a small piece of information sent by the server (http) used to operate a website to the user’s computer browser and may be stored on the hard disk within the user’s PC.
Cookies are used to understand the patterns of visits and usage for each service and website visited by the user, popular search terms, the presence of secure connections, etc., in order to provide optimized information to the user.
You may refuse to save cookies through your web browser's option settings. However, if you refuse to save cookies, you may experience difficulty using personalized services.
・Chrome: Select the ":" mark at the top right of the web browser → New Incognito Window (Shortcut: Ctrl+Shift+N)
・Edge: Select the "..." mark at the top right of the web browser → New InPrivate Window (Shortcut: Ctrl+Shift+N)

11. Personal Information Protection Officer and Relief Methods

The Company has designated the following officer to take responsibility for processing and handling complaints/remedies:
Personal Information Protection Officer: Yuichiro Yamada
Personal Information Protection Department: Yuichiro Yamada (Executive)
Contact: personal.info@findy.co.jp You may also contact the Personal Information Dispute Mediation Committee (1833-6972), KISA Personal Information Infringement Report Center (118), or the National Police Agency (182) for relief.

12. Changes to the Privacy Policy

If there are additions, deletions, or modifications to the policy due to changes in laws or security technology, the Company will notify the reasons and content via the website before enforcement.

Enacted/Enforced: March 1, 2026