Legal

Privacy Policy

How Apia Business Affairs Co., Ltd. collects, uses and protects personal information in connection with Factdock.

Effective September 17, 2026

This document is published in English only. Its content is governed by the laws of Japan. No translation of this document is issued, and the English text is the sole authoritative version.

1. Who is responsible

Apia Business Affairs Co., Ltd., 1F, 4-8-17 Chuo, Aoba-ku, Sendai-shi, Miyagi 980-0021, Japan, is the operator of the Service and the entity responsible for the handling of personal information described in this policy (the "Company").

This policy is drawn up in accordance with the Act on the Protection of Personal Information of Japan (APPI). Where the General Data Protection Regulation (EU) 2016/679 or the UK GDPR applies to you, the Company acts as controller in respect of the processing described here.

2. Information we collect

  • Account information — e-mail address, password credential, display name, the language you use, and your plan and point balance.
  • Billing information — plan, transaction history and the identifier issued by our payment provider. Full card numbers are handled by the payment provider and are never received or stored by the Company.
  • User Input — the text, keywords, documents, images and settings you submit in order to run a search or an analysis.
  • Usage information — feature usage, point consumption, timestamps, and technical event logs required to operate and secure the Service. This includes execution records of each search or analysis (date and time, processing status, error type and points consumed), which contain none of the content of your input or its results.
  • Device and connection information — IP address, browser type and similar technical data recorded by our infrastructure for security and abuse prevention.

3. Purposes of use

The Company uses personal information only for the following purposes:

  • To provide, operate and maintain the Service, including running the searches and analyses you request.
  • To manage accounts, plans, points, billing and payment.
  • To provide support and to respond to enquiries.
  • To detect, prevent and investigate fraud, abuse, and security incidents.
  • To improve reliability and quality of the Service, using aggregated or de-identified information wherever the purpose can be achieved without personal information.
  • To send service notices, and — only where you have opted in, or where permitted by law — information about the Service.
  • To comply with legal obligations and to establish, exercise or defend legal claims.

4. Legal bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, processing is based on: performance of the contract with you (provision of the Service, billing and support); our legitimate interests (security, abuse prevention, service improvement), balanced against your rights; compliance with a legal obligation; and your consent, where consent is requested.

Where processing relies on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before withdrawal.

5. User Input, files and images

User Input is processed for the sole purpose of producing the result you requested. The Company does not use User Input, or the results derived from it, to train or improve AI or machine-learning models.

User Input and the results of searches and analyses are not stored in the Company's databases: they are held only for the duration of the request and discarded once the result has been returned. Images and documents that you upload for analysis are likewise processed transiently and are not written to a permanent image or document store.

Items that you choose to save yourself — for example saved reports or keywords you register — are stored in your account so that you can retrieve them, and are visible only to you. Database access control is enforced at row level, so no other user can read your records.

The Company does not sell User Input.

6. Service providers

The Company engages third-party providers to operate the Service, and discloses to them only the information necessary for the task entrusted to them.

AI language-processing providers are engaged under terms that do not permit the information they process to be used to train their models. Information retrieval providers receive only search keywords, never the text you enter or the documents you upload; their handling of those keywords is governed by their own terms.

The categories of provider are:

  • Cloud infrastructure, database and hosting providers.
  • Payment processing providers.
  • AI language-processing and translation providers, used to analyse and translate source material.
  • Information retrieval providers, used to locate publicly available sources.
  • Communication providers, used to deliver transactional e-mail.

7. International transfers

The Service is operated globally and the providers described above may process information in countries other than your own, including the United States and countries within the European Economic Area.

Where personal information is transferred out of the EEA, the UK, or Japan, the Company relies on an adequacy decision where one is available, and otherwise on Standard Contractual Clauses or an equivalent lawful transfer mechanism, together with the contractual and technical safeguards described in this policy.

8. Retention

Account information is retained for as long as the account exists. On deletion of the account, personal information is deleted or de-identified within a reasonable period, except where retention is required by law — for example, records required by tax and accounting legislation.

Transient uploads are not retained after the request completes. Technical and security logs are retained only for the period necessary for the purpose for which they were created.

Execution records of searches and analyses, which contain none of the content of your input or its results, are retained for 30 days for fault investigation, incident response and the accurate management of points, and are then deleted automatically.

9. Security

The Company applies technical and organisational measures appropriate to the risk, including encryption in transit, authenticated access to all functions that read or write user data, row-level access control in the database, least-privilege credentials, and server-side isolation of all keys and secrets.

No system can be guaranteed absolutely secure. If a breach affecting your personal information occurs, the Company will notify you and the competent supervisory authority where required by applicable law.

10. Your rights

Under the APPI you may request disclosure, correction, addition, deletion, cessation of use, or cessation of third-party provision of your retained personal data, and disclosure of records of third-party provision.

Where the GDPR or UK GDPR applies, you also have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, and the right to lodge a complaint with your supervisory authority.

Requests are made using the contact details in section 13. The Company will verify your identity before responding, and will respond within the period required by applicable law.

11. Cookies and similar technologies

The Service uses cookies and equivalent browser storage that are strictly necessary to operate it — in particular to keep you signed in, to remember your language, and to protect against abuse.

The Service does not use advertising cookies and does not sell or share personal information for cross-context behavioural advertising.

12. Children

The Service is intended for professional and business use and is not directed at children. The Company does not knowingly collect personal information from a child below the age at which consent is valid in their country of residence. If such information has been collected, it will be deleted on notice.

13. Contact and complaints

Enquiries relating to this policy, and requests under section 10, may be addressed to Apia Business Affairs Co., Ltd., 1F, 4-8-17 Chuo, Aoba-ku, Sendai-shi, Miyagi 980-0021, Japan. Contact details are published on the Company page and in the Legal Notice.

You may also contact the Personal Information Protection Commission of Japan, or your local supervisory authority, if you consider that your rights have not been respected.

14. Changes to this policy

This policy may be updated to reflect changes to the Service or to the law. The effective date shown at the top of this page indicates the current version, and material changes will be notified to registered users.