PRIVACY POLICY

Last Updated: July 17, 2026

Reference Translation / Governing Language

This English translation of the Privacy Policy has been prepared solely for reference and convenience. The original Japanese version is the official and governing version. If any discrepancy, inconsistency, or conflict arises between the Japanese version and this English translation, the Japanese version shall prevail.

SORABITO Inc. (the “Company”) recognizes the importance of protecting Personal Information, complies with the Act on the Protection of Personal Information of Japan (the “APPI”), and endeavors to handle and protect Personal Information appropriately in accordance with this Privacy Policy (this “Privacy Policy”). Unless otherwise provided in this Privacy Policy, terms used herein shall have the meanings prescribed in the APPI.

Article 1. Definition of Personal Information

For purposes of this Privacy Policy, “Personal Information” means personal information as defined in Article 2, paragraph (1) of the APPI.

Article 2. Purposes of Use of Personal Information

The Company uses Personal Information for the following purposes:

  1. (1) To analyze information regarding the use of the Company’s services and use the results to improve the Company’s services, develop new services, and for similar purposes;
  2. (2) To process applications for contracts concerning the Company’s services, withdrawals, changes to registered information, and notices and confirmation procedures concerning contract renewals or continuation;
  3. (3) To invoice fees for the Company’s services or prices for products sold by the Company in accordance with applicable terms of use;
  4. (4) To confirm and investigate the content of, and respond to, inquiries received concerning the Company or the Company’s services;
  5. (5) To provide information concerning technical support, including incident and maintenance information relating to the Company’s services;
  6. (6) To achieve any purpose of use disclosed in connection with the provision of the Company’s services and to which consent has been obtained;
  7. (7) To respond to conduct that violates the Company’s terms, policies, or other rules concerning the Company’s services;
  8. (8) To provide proposals concerning services, including notices, advertisements and promotions regarding new services, new products, feature improvements, and other information considered useful to customers, the delivery of direct mail, and introductions by telephone;
  9. (9) To ship products, prizes, gifts, and similar items, and to request cooperation with surveys conducted by the Company;
  10. (10) To compile registered Personal Information into statistical information within a scope that does not identify individuals and use such information as reference material for developing services useful to customers;
  11. (11) To provide the Company’s services and related services and to manage users of the Company’s services;
  12. (12) To provide Personal Information to third parties where the relevant customer has given prior consent in connection with the provision of the Company’s services;
  13. (13) For employment management and internal procedures (with respect to Personal Information of officers and employees);
  14. (14) For screening and communications in recruitment activities (with respect to Personal Information of applicants);
  15. (15) For shareholder administration and procedures required under the Companies Act and other laws and regulations (with respect to Personal Information of shareholders, holders of share acquisition rights, and similar persons);
  16. (16) To carry out procedures required for rental car services operated by the Company, including services operated in partnership with third parties (the “Rental Car Services”), such as membership screening, identity verification, and verification of driver’s license information, and to manage rental car reservations and use, calculate fees, and conduct billing procedures;
  17. (17) To conduct insurance and compensation procedures, investigate causes, and respond to and process accidents, problems, and similar events arising in connection with the Rental Car Services;
  18. (18) To carry out procedures required to provide car-sharing services, including services operated in partnership with third parties (the “Car-Sharing Services”), membership screening and identity verification, verification of driver’s license information, and management of reservations and usage history and billing procedures for car-sharing vehicles;
  19. (19) To conduct insurance and compensation procedures and investigate, respond to, and process accidents, problems, and similar events arising in connection with the Car-Sharing Services;
  20. (20) To use speech recognition, optical character recognition, natural language processing, and other artificial intelligence (“AI”) technologies to perform optical character recognition, information extraction, automatic data entry, automated analysis, summarization, response generation, and other processing of documents, images, text, audio, conversations, and other data entered or uploaded by users, and Personal Information contained therein, for the purposes of providing the Company’s services, enabling service functions, improving response quality, improving services, and accurately understanding the content of interactions; and
  21. (21) For purposes incidental to the foregoing purposes of use.

Article 3. Changes to Purposes of Use of Personal Information

The Company may change a purpose of use of Personal Information to the extent reasonably considered relevant to the purpose before the change. If the Company changes a purpose of use, it will notify the individual who is the subject of the Personal Information (the “Principal”) or publicly announce the change.

Article 4. Use of Personal Information

1. Except as permitted by the APPI or other laws and regulations, the Company will not handle Personal Information beyond the scope necessary to achieve the purposes of use without the Principal’s consent. This restriction does not apply in any of the following cases:

  1. (1) Where required by laws and regulations;
  2. (2) Where necessary to protect a person’s life, body, or property and it is difficult to obtain the Principal’s consent;
  3. (3) Where particularly necessary to improve public health or promote the sound development of children and it is difficult to obtain the Principal’s consent;
  4. (4) Where it is necessary to cooperate with a national government agency, local government, or a person entrusted thereby in performing affairs prescribed by laws and regulations, and obtaining the Principal’s consent is likely to impede the performance of those affairs; or
  5. (5) Where Personal Data is provided to an Academic Research Institution, etc. and the Academic Research Institution, etc. needs to handle the Personal Data for academic research purposes, including where part of the purpose of handling the Personal Data is an academic research purpose, except where there is a risk of unjustly infringing the rights and interests of an individual.

2. The Company will not use Personal Information in a manner that may facilitate or induce unlawful or improper conduct.

3. Unless separately stated, the Company will not newly generate a voiceprint or other biometric identifier from audio data and use it to identify or authenticate a Principal. “Biometric identifier” means data capable of identifying a specific individual and includes an Individual Identification Code under Article 2, paragraph (2) of the APPI. The Company will handle audio data and biometric identifiers in accordance with applicable laws and regulations.

Article 5. Proper Acquisition of Personal Information

1. The Company will acquire Personal Information properly and will not acquire it by deception or other wrongful means.

2. Except in any of the following cases, the Company will not acquire Special Care-Required Personal Information, as defined in Article 2, paragraph (3) of the APPI, without the Principal’s prior consent:

  1. (1) Where any of Article 4, paragraph 1, items (1) through (4) applies;
  2. (2) Where the Company acquires Special Care-Required Personal Information from an Academic Research Institution, etc. and needs to acquire it for academic research purposes, including where part of the purpose of acquisition is an academic research purpose, except where there is a risk of unjustly infringing the rights and interests of an individual, and only where the Personal Information Handling Business Operator and the Academic Research Institution, etc. jointly conduct academic research;
  3. (3) Where the Special Care-Required Personal Information has been made public by the Principal, a national government agency, a local government, an Academic Research Institution, etc., a person listed in any item of Article 57, paragraph (1) of the APPI, or another person prescribed by the rules of the Personal Information Protection Commission;
  4. (4) Where the Company acquires Special Care-Required Personal Information that is apparent from the Principal’s external appearance by observing or photographing the Principal; or
  5. (5) Where the Company receives Special Care-Required Personal Information in a manner that does not constitute provision to a third party pursuant to the proviso to Article 8, paragraph 1.

3. When receiving Personal Information from a third party, the Company will verify the following matters in accordance with the rules of the Personal Information Protection Commission, except where the provision falls under any item of Article 4, paragraph 1 or is made in a manner that does not constitute provision to a third party pursuant to the proviso to Article 8, paragraph 1:

  1. (1) The name and address of the third party and, if the third party is a corporation, the name of its representative, or, if the third party is an unincorporated association with a representative or administrator, the name of that representative or administrator; and
  2. (2) The circumstances in which the third party acquired the Personal Information.

4. Except as permitted by laws and regulations, the Company will not request the entry, recording, photographing, or uploading of Special Care-Required Personal Information, an Individual Number (“My Number”), bank account numbers, credit card numbers, passwords, or other information requiring particularly careful handling beyond the scope necessary to provide the Company’s services.

Article 6. Security Management of Personal Information

The Company provides necessary and appropriate supervision of its employees to ensure the secure management of Personal Information against risks such as loss, destruction, alteration, and leakage. When the Company entrusts all or part of the handling of Personal Information to a contractor, the Company also provides necessary and appropriate supervision to ensure that the contractor securely manages the Personal Information. The specific security control measures for Retained Personal Data held by the Company are as follows:

Establishment of a Basic Policy

The Company has established this Privacy Policy as its basic policy for ensuring the proper handling of Personal Data, including compliance with applicable laws, regulations and guidelines and the establishment of a contact point for questions and complaints.

Establishment of Rules for Handling Personal Data

The Company has established rules for handling Personal Data that prescribe handling methods, responsible persons, personnel in charge, and their duties.

Organizational Security Control Measures

The Company appoints a person responsible for handling Personal Data, identifies employees who handle Personal Data and the scope of Personal Data handled by them, and establishes a reporting and communication system for cases where a fact or indication of violation of the APPI or the Company’s handling rules is identified.

Physical Security Control Measures

The Company uses card keys to unlock and lock its offices at the start and end of business and manages the relevant access logs.

Personnel Security Control Measures

  1. 1) The Company regularly trains employees regarding matters requiring attention in the handling of Personal Data.
  2. 2) The Company’s work rules include provisions concerning confidentiality of Personal Data.

Technical Security Control Measures

  1. 1) The Company implements access controls to limit the personnel and the scope of Personal Information databases, etc. that may be handled.
  2. 2) The Company has implemented mechanisms to protect information systems that handle Personal Data from unauthorized external access and malicious software.

Understanding the External Environment

Where Personal Data is handled in a foreign country, including where handling is entrusted to a third party in a foreign country, the Company implements security control measures after understanding the personal information protection system of that country. The foreign countries in which the Company handles Personal Data and in which its contractors are located are the countries for which the Company provides information to Principals by the method specified in Article 8, paragraph 3, namely the countries listed as the “destination countries” in the “Information Regarding the Provision of Personal Information to Third Parties in Foreign Countries” posted on the Company’s website.

Article 7. Reporting in the Event of Leakage, etc.

If leakage, loss, damage, or another incident involving Personal Information handled by the Company occurs and the APPI requires the Company to report to the Personal Information Protection Commission and notify the Principal, the Company will make the required report and notification.

Article 8. Provision to Third Parties

1. Except where any item of Article 4, paragraph 1 applies, the Company will not provide Personal Information to a third party without the Principal’s prior consent. The following cases, however, do not constitute provision to a third party as described above:

  1. (1) Where Personal Information is provided in connection with entrusting all or part of its handling within the scope necessary to achieve a purpose of use; or
  2. (2) Where Personal Information is provided in connection with a succession of business due to a merger or other reason.

2. Notwithstanding paragraph 1 of this Article, except where any item of Article 4, paragraph 1 applies, if the Company provides Personal Information to a third party in a foreign country, excluding a country designated by the rules of the Personal Information Protection Commission under Article 28 of the APPI, and excluding a third party that has established a system conforming to the standards designated by those rules, the Company will obtain the Principal’s prior consent to such provision to a third party in a foreign country.

3. When obtaining the Principal’s consent under the preceding paragraph, the Company will provide the Principal with the following information. If the matter in item (1) cannot be identified, then instead of the matters in items (1) and (2), the Company will provide notice that the matter in item (1) cannot be identified, the reason it cannot be identified, and any alternative information that may be useful to the Principal:

  1. (1) The name of the foreign country;
  2. (2) Information concerning the personal information protection system in that foreign country; and
  3. (3) Information concerning the measures taken by the third party to protect Personal Information, or, if such information cannot be provided, a statement to that effect and the reason.

4. When the Company provides Personal Information to a third party, it will create and retain records in accordance with Article 29 of the APPI.

5. When the Company receives Personal Information from a third party, it will conduct the required verification and create and retain records of that verification in accordance with Article 30 of the APPI.

6. In connection with providing the Rental Car Services and Car-Sharing Services, the Company may entrust or provide Personal Information to business partners, such as insurance companies, payment processors, and vehicle providers, within the scope necessary to achieve the purposes of use. In doing so, the Company will comply with the APPI and other laws and regulations and appropriately manage the Personal Information so that it is not handled beyond the scope set out in this Privacy Policy.

7. In connection with providing the Company’s services, the Company may entrust the handling of Personal Information to external service providers, including providers located outside Japan, that provide speech recognition, optical character recognition, natural language processing, or other AI technologies, within the scope necessary to achieve the purposes of use, in order to perform optical character recognition, information extraction, automatic data entry, automated analysis, summarization, response generation, and other processing of documents, images, text, audio, conversations, and other data entered or uploaded by users and Personal Information contained therein. The Company will provide necessary and appropriate supervision of such contractors in accordance with the APPI and other laws and regulations. If a contractor is located outside Japan, the Company will comply with paragraph 2 or paragraph 8 of this Article.

8. Notwithstanding paragraph 2 of this Article, where the Company entrusts the handling of Personal Information to a third party in a foreign country within the scope necessary to achieve a purpose of use, and that third party has established a system conforming to the standards prescribed in Article 28 of the APPI and the rules of the Personal Information Protection Commission regarding the handling of Personal Information, the Company may provide the Personal Information to that third party without obtaining the Principal’s prior consent. In this case, the Company will take measures required by the APPI to ensure the third party’s continuous implementation of Equivalent Measures, as defined in Article 28, paragraph (1) of the APPI, and will provide information concerning those measures at the Principal’s request.

9. If the Company provides Personal Information to a third party in a foreign country under the preceding paragraph, the name of that foreign country and other information required by laws and regulations will be provided in advance or at the Principal’s request by a method prescribed by laws and regulations or by a method designated by the Company, including, without limitation, the “Information Regarding the Provision of Personal Information to Third Parties in Foreign Countries” posted on the Company’s website.

Article 9. Disclosure of Personal Information, etc.

1. When the Company receives a request from a Principal for disclosure of Personal Information under the APPI, the Company will verify that the request is made by the Principal and disclose the Personal Information to the Principal without delay. If no such Personal Information exists, the Company will notify the Principal accordingly. This does not apply where the Company has no obligation to disclose under the APPI or other laws and regulations. A fee of JPY 500 per request applies to the foregoing disclosure.

2. The preceding paragraph applies mutatis mutandis to records concerning provision to third parties created under Article 8, paragraph 4 and records concerning receipt from third parties created under Article 8, paragraph 5, in each case relating to Personal Information by which the Principal is identified.

3. Requests for disclosure under paragraphs 1 and 2 and other requests under Articles 9 through 11 of this Privacy Policy (collectively, “Requests for Disclosure, etc.”) must be submitted to the inquiry desk specified in Article 15 in accordance with a method separately designated by the Company or posted on the Company’s website.

4. Upon receiving a Request for Disclosure, etc., the Company will verify that the request was made by the Principal or the Principal’s representative by requesting identification documents or by another method designated by the Company. If the requester does not cooperate with this verification, the Company may be unable to respond to the Request for Disclosure, etc.

5. A Request for Disclosure, etc. may be made by the Principal, a statutory representative of a minor or an adult ward, or an authorized representative entrusted by the Principal to make such request. The Company may request documents verifying the representative’s authority.

Article 10. Correction, etc. of Personal Information

If a Principal requests correction, addition, or deletion of the content of Personal Information on the grounds that it is inaccurate (collectively, “Correction, etc.”) under the APPI, the Company will verify that the request is made by the Principal, promptly conduct any investigation necessary within the scope required to achieve the purposes of use, make the Correction, etc. based on the results, and notify the Principal accordingly. If the Company decides not to make the Correction, etc., it will notify the Principal of that decision. This does not apply where the Company has no obligation to make the Correction, etc. under the APPI or other laws and regulations.

Article 11. Cessation of Use, etc. of Personal Information

If a Principal requests, under the APPI: (1) cessation of use or deletion of the Principal’s Personal Information (collectively, “Cessation of Use, etc.”) on the grounds that it is being handled beyond the scope of a previously disclosed purpose of use, is being used in a manner that may facilitate or induce unlawful or improper conduct, or was acquired by deception or other wrongful means; (2) cessation of provision of Personal Information (the “Cessation of Provision”) on the grounds that it has been provided to a third party without the Principal’s consent; or (3) Cessation of Use, etc. or Cessation of Provision on the grounds that the Company no longer needs to use the Principal’s Personal Information, that an incident specified in the main clause of Article 26, paragraph (1) of the APPI has occurred with respect to the Principal’s Personal Information, or that the handling of the Principal’s Personal Information may otherwise harm the Principal’s rights or legitimate interests, and the Company determines that the request is well-founded, the Company will verify that the request is made by the Principal, promptly carry out the Cessation of Use, etc. or Cessation of Provision, and notify the Principal accordingly. This does not apply where the Company has no obligation to carry out the Cessation of Use, etc. or Cessation of Provision under the APPI or other laws and regulations.

Article 12. Handling of Anonymously Processed Information

1. If the Company creates Anonymously Processed Information, meaning information relating to an individual obtained by processing Personal Information in accordance with measures prescribed by laws and regulations so that a specific individual cannot be identified and the Personal Information cannot be restored, the Company will:

  1. (1) Properly process the information in accordance with standards prescribed by laws and regulations;
  2. (2) Take security control measures in accordance with standards prescribed by laws and regulations to prevent leakage of information concerning deleted information and processing methods;
  3. (3) Publicly announce the categories of information contained in the Anonymously Processed Information created; and
  4. (4) Refrain from any act intended to identify the Principal of the Personal Information from which the Anonymously Processed Information was created.

2. If the Company provides Anonymously Processed Information to a third party, the Company will publicly announce the categories of information relating to individuals contained in the Anonymously Processed Information to be provided and the method of provision, and expressly inform the recipient that the information provided is Anonymously Processed Information.

Article 13. Use of Cookies and Other Tools

1. The Company’s services may use cookies, similar technologies, and other tools designated by the Company (collectively, “Cookies, etc.”). Cookies, etc. help the Company understand how its services are used and contribute to service improvement. Users who wish to disable cookies may do so by changing their web browser settings. Disabling cookies may, however, make some functions of the Company’s services unavailable. Tools other than cookies used in the Company’s services are listed below.

(1) Google Analytics

  1. 1) Tool provider: Google LLC
  2. 2) Google Analytics Terms of Service: https://www.google.com/analytics/terms/jp.html
  3. 3) Google Privacy Policy: https://policies.google.com/privacy?hl=ja

(2) Zoho CRM

  1. 1) Tool provider: ZOHO Japan Corporation
  2. 2) Zoho CRM Terms of Service: https://www.zoho.com/jp/crm/terms.html
  3. 3) Zoho Privacy Policy: https://www.zoho.co.jp/privacy/

(3) Mixpanel

  1. 1) Tool provider: Mixpanel, Inc.
  2. 2) Mixpanel Terms of Use: https://mixpanel.com/legal/terms-of-use
  3. 3) Mixpanel Privacy Policy: https://mixpanel.com/legal/privacy-policy/

(4) Microsoft Clarity

  1. 1) Tool provider: Microsoft Corporation
  2. 2) Microsoft Clarity Terms of Use: https://clarity.microsoft.com/terms
  3. 3) Microsoft Privacy Statement: https://privacy.microsoft.com/ja-jp/privacystatement

2. The Company may use behavioral advertising services that use Cookies, etc. to deliver advertisements optimized for customers and other users. Under agreements with third parties to which the Company outsources advertising distribution, the Company may disclose all or part of the information collected through Cookies, etc. to those third parties; such information does not include information that identifies an individual. Such third parties may use information such as the history of pages viewed on websites provided by the Company to display advertisements of the Company that may be of interest to customers on websites other than those provided by the Company that participate in the relevant advertising network. To disable these services, follow the procedures specified by the relevant advertising service provider below.

  1. (1) Google: https://policies.google.com/technologies/ads?hl=ja
  2. (2) LINE Yahoo Advertising: https://btoptout.yahoo.co.jp/optout/index.html
  3. (3) Facebook: https://www.facebook.com/ads/website_custom_audiences/
  4. (4) X: https://x.com/settings/security
  5. (5) Microsoft: https://account.microsoft.com/privacy/ad-settings/signedout?lang=ja-jp

3. In providing the Rental Car Services and Car-Sharing Services, the Company may acquire location information, such as GPS data, and information regarding users’ vehicle usage as necessary. The Company uses this information to improve service quality, safely manage vehicles, respond to accidents, verify the accuracy of usage fee billing, and for similar purposes.

4. If the Company provides to a third party information obtained through Cookies, etc. that does not constitute Personal Information but constitutes Personal Related Information, and the third party is expected to acquire that Personal Related Information as Personal Data, the Company will provide it only after confirming, in accordance with Article 31 of the APPI, that the Principal’s prior consent has been obtained and that other applicable requirements have been satisfied. If the third party is located in a foreign country, the Company will also take measures required by laws and regulations under Article 31, paragraph (1), item (2) of the APPI, including providing the Principal in advance with the name of that foreign country and other legally required information.

Article 14. Disclosures Concerning Information Transmission Instruction Communications (External Transmission)

The services operated by the Company that may be subject to the external transmission rules for information transmission instruction communications under Article 27-12 of the Telecommunications Business Act, and the disclosures required under those rules for such services, are set out below. If the Company adds or changes an external transmission tool used in its services, it will update the required disclosures in accordance with applicable laws and regulations.

All Services Operated by the Company

Function or service using information transmission instruction communicationsGoogle Analytics
User-related information transmitted
  • Information concerning systems, devices, networks, and communications ordinarily used for internet communications
  • Location information
  • Data concerning behavior on websites and applications
  • Data concerning pages viewed
  • User identifiers (cookies, device identifiers, etc.)
Name of recipientGoogle LLC and its affiliates
Purpose of use (Company)To analyze users’ browsing trends and history
Purpose of use (Recipient)To analyze users’ browsing trends and history

Article 15. Inquiries

For Requests for Disclosure, etc., opinions, questions, complaints, and other inquiries concerning the handling of Personal Information, please contact the following inquiry desk.

Name, Address, and Representative of the Personal Information Handling Business Operator

SORABITO Inc.

Representative Director: Kazuaki Hakata

Inamura Building 8F, 1-9-2 Nihonbashi-Kayabacho, Chuo-ku, Tokyo 103-0025, Japan

Inquiry Desk

Email: privacy@sorabito.com

Attn: Personal Information Protection Manager, SORABITO Inc.

Article 16. Continuous Improvement

The Company will review the operational status of its handling of Personal Information as appropriate, endeavor to make continuous improvements, and may amend this Privacy Policy as necessary.

Information Regarding the Provision of Personal Information to Third Parties in Foreign Countries

Last Updated: July 17, 2026

Reference Translation / Governing Language

This English translation of the Information Regarding the Provision of Personal Information to Third Parties in Foreign Countries has been prepared solely for reference and convenience. The original Japanese version is the official and governing version. If any discrepancy, inconsistency, or conflict arises between the Japanese version and this English translation, the Japanese version shall prevail.

(Related to Article 8, paragraphs 2, 3, and 7 of the Privacy Policy)

This document discloses information under Article 28 of the APPI where SORABITO Inc. (the “Company”) provides Personal Information to a third party in a foreign country based on the Principal’s consent in connection with the provision of the Company’s services. The Company will post this document on its website and make it available for review by the Principal before obtaining consent. The Company will update this document from time to time in response to changes in external service providers used, processing configurations, or other relevant circumstances. If the Company makes a material change to the contents of this document, it will obtain the Principal’s consent again as necessary in accordance with applicable laws and regulations.

1. GENBAx Inspection for Construction (Optical Character Recognition and Automatic Data Entry for Documents and Images)

  • External service used: Paid-tier Gemini API provided by Google LLC
  • Name of recipient: Google LLC
  • Destination country: United States of America (United States). Google LLC, the recipient, is an entity located in the United States. For the paid-tier Gemini API, submitted data, including prompts and files such as images and documents, may also be temporarily stored or cached in countries other than the United States where Google or its agents operate facilities. Because the relevant countries are determined by Google LLC, the Company is unable to specifically identify them.
  • Information concerning the personal information protection system in the destination country: The United States does not have a comprehensive federal privacy law generally applicable to Personal Information in the private sector. Personal Information is protected through sector-specific federal laws and state laws. The United States also participates in the APEC Cross-Border Privacy Rules (CBPR) system. For details concerning the personal information protection system in the United States, please refer to the information on the United States in the “Survey of Personal Information Protection Systems in Foreign Countries” published by Japan’s Personal Information Protection Commission (https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/). For additional reference, data processed through Gemini may be transferred to potential Google Cloud locations (https://cloud.google.com/about/locations?hl=ja#clf-section), and materials concerning personal information protection systems in foreign countries published by the Personal Information Protection Commission are available at https://www.ppc.go.jp/enforcement/infoprovision/laws/.
  • Measures taken by the recipient to protect Personal Information: Measures under Google’s Data Processing Addendum. Under that addendum and related terms, measures include limitation of processing purposes, security controls, obligations imposed on subprocessors, assistance with data subject requests, audits and information provision, and safeguards for international transfers. Under the paid-tier Gemini API, submitted data and generated responses are not used to improve Google’s products and are logged for a limited period only for safety and security maintenance and legally required disclosures. For details, please refer to Google’s Data Processing Addendum (https://cloud.google.com/terms/data-processing-addendum) and Gemini API Additional Terms of Service (https://ai.google.dev/gemini-api/terms?hl=ja).

The Company provides Personal Information to third parties in foreign countries in connection with this service (GENBAx Inspection for Construction) based on the Principal’s consent under Article 8, paragraph 2 of the Privacy Policy.

2. TakumiX (Voice AI Agent Service)

Background:TakumiX is based on the platform of Eleven Labs Inc. (“ElevenLabs”) and uses a selected large language model (“LLM”) to generate responses. Available LLMs include models hosted by ElevenLabs and models provided by Anthropic PBC, Google LLC, and OpenAI OpCo, LLC. The recipients to which the Company may provide Personal Information in connection with this service (TakumiX) are limited to the entities listed in items (1) through (4) below. If the Company adds or changes a recipient, it will update this document and obtain the Principal’s consent again as necessary in accordance with applicable laws and regulations.

  • Recipients that may be selected and used:
    1. (1) Eleven Labs Inc. (voice processing platform and LLMs hosted by ElevenLabs, including Qwen-family models. These Qwen-family models are hosted by ElevenLabs; the recipient is ElevenLabs, not Alibaba or another provider.)
    2. (2) Anthropic PBC (Claude-family models)
    3. (3) Google LLC (Gemini-family models)
    4. (4) OpenAI OpCo, LLC (GPT-family models)

    If a Custom LLM is used, the provider of the relevant endpoint will be an additional recipient.

  • Destination country: United States of America (United States). Each of the entities listed in items (1) through (4) is located in the United States. The actual locations where data is stored or processed may vary depending on each provider’s contractual terms, region settings, and service configuration, including those of its subprocessors. To the extent known to the Company, such storage or processing may occur in multiple countries, including the United States. Because the relevant countries are determined by each provider, the Company is unable to specifically identify them.
  • Information concerning the personal information protection system in the destination country: Please refer to Section 1 above for information concerning the personal information protection system in the United States. For additional reference, data processed through Gemini may be transferred to potential Google Cloud locations (https://cloud.google.com/about/locations?hl=ja#clf-section); information concerning ElevenLabs’ data handling is available at https://compliance.elevenlabs.io/; information concerning Anthropic PBC’s subprocessors is available at https://trust.anthropic.com/subprocessors; information concerning OpenAI OpCo, LLC’s subprocessors is available at https://openai.com/policies/sub-processor-list/; and materials concerning personal information protection systems in foreign countries published by the Personal Information Protection Commission are available at https://www.ppc.go.jp/enforcement/infoprovision/laws/.
  • Measures taken by the recipients to protect Personal Information: Measures are taken under the data processing agreements (“DPAs”) and similar terms applicable between the Company and each provider. Specifically: (i) for Eleven Labs Inc., its DPA provides for processing based on the Company’s instructions, confidentiality, security controls, equivalent protection obligations imposed on subprocessors, and application of Standard Contractual Clauses (“SCCs”) for international transfers (https://elevenlabs.io/dpa and https://compliance.elevenlabs.io/); (ii) for Anthropic PBC, its DPA provides for limitation of processing purposes, confidentiality, security controls, protection obligations imposed on subprocessors, and application of SCCs (https://www.anthropic.com/legal/data-processing-addendum); (iii) for Google LLC, the measures described in Section 1 above apply (https://cloud.google.com/terms/data-processing-addendum and https://ai.google.dev/gemini-api/terms?hl=ja); and (iv) for OpenAI OpCo, LLC, its DPA provides for processing based on the Company’s instructions, security controls, equivalent protection obligations imposed on subprocessors, safeguards for international transfers, and return or deletion of data after termination of the agreement (https://openai.com/policies/data-processing-addendum/).

The Company provides Personal Information to third parties in foreign countries in connection with this service (TakumiX) based on the Principal’s consent under Article 8, paragraph 2 of the Privacy Policy, after presenting all of the entities listed in items (1) through (4) above as the scope of potential recipients.