Your data, handled with integrityand transparency
As a service handling confidential business documents, DATAPIQ has adopted the principles of Japan's Act on Protection of Personal Information, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) as design guidelines for handling personal and corporate data.
DATA COLLECTION
Information We Collect
We explain the types of information DATAPIQ handles and why we handle it.
Account Information
- Email address
- Password (bcrypt hash)
- Company name / representative name
- Role and permission settings
Required for service delivery and authentication
Uploaded Data
- PDF and image files
- AI-extracted results (journal entry data)
- Edit and review history
- File metadata
Required to provide AI analysis and data management services
Billing Information
- Plan and subscription status
- Billing history
- Page usage
Credit card details are never stored on our servers. Payments are processed by Stripe.
Usage Logs
- IP address / device ID
- Login and activity history
- Error logs
- AI API usage
- Page access data (Google Analytics)
Used for security monitoring, service improvement, and access analysis
PURPOSE OF USE
Purpose of Use
Information you provide is used solely for the following purposes. We will not use it beyond these purposes or sell it to third parties without your consent.
THIRD-PARTY SERVICES
Third-Party Services We Use
DATAPIQ uses the following external services. Only the minimum necessary information is sent to each service.
Stripe
Used for payment processing and subscription management. Card numbers and payment details never pass through our servers — Stripe processes them directly.
PCI DSS Level 1 Certified US & EU compliantAI Analysis Engine
Used for AI analysis of uploaded PDFs and images. Document content (text and image data) is transmitted to the analysis engine's servers.
Data Processing Agreement (DPA) applied Not used for training purposesGoogle OAuth
Used for social login with Google accounts. Only email address and Google account ID are retrieved.
Authentication only Profile information is not collectedAmazon SES (AWS)
Used for sending email verification, password reset, and two-factor authentication codes. Only the email address and message content are processed. Data is processed on AWS servers in the United States.
Authentication emails only SOC 2 / ISO 27001 certifiedCloudflare
Used as CDN, DDoS protection, and WAF (Web Application Firewall). All HTTP requests pass through Cloudflare's edge servers, so data such as IP addresses and HTTP headers are processed.
GDPR DPA signed US & EU edge serversVPS Hosting
Used to run the application and database. All data is stored on this server.
Domestic / overseas data centersFIDO2 / Passkey
Used for passwordless login via biometric authentication (passkey). Biometric data is stored only on your device and is never transmitted to our servers.
Biometric data is not collected FIDO2 compliantGoogle Analytics
Used for website access analytics. Collects anonymized usage data including page views, session duration, and referral sources. Operating in Cookieless mode (client_storage: 'none'), no tracking cookies such as _ga are set. Data is sent to Google's US servers and processed under Google's Privacy Policy.
Cookie-free (Cookieless mode) IP addresses anonymized Ad features disabledGoogle Search Console
Used to analyze this service's performance in search engines (search queries, impressions, click-through rates, etc.). We access aggregated data provided by Google and do not collect data that identifies individual visitors.
No personal data collected SEO analysis onlyYOUR RIGHTS
Your Rights
We guarantee the following rights based on Japan's Act on Protection of Personal Information, GDPR (EU), and CCPA (California).
Right to Access / Disclosure
You may request disclosure of the types of personal data we hold and the purposes for which it is used.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
You may request erasure of your data upon account deletion, except for data we are legally required to retain.
Data Portability
You have the right to receive your data in a machine-readable format (e.g., CSV).
Right to Restrict Processing / Object
Where there is a legitimate reason, you may request restriction or suspension of data processing.
Right to Opt-Out of Sale
We do not sell your personal information to third parties under any circumstances.
To exercise your rights, please submit a request via our contact form. We will respond within 30 days as a general rule.
DATA RETENTION
Data Retention Periods
Data is deleted promptly once its purpose is fulfilled, except where legally required to be retained.
| Data Type | Retention Period | Deletion Timing |
|---|---|---|
| Account information (email address, etc.) | Immediately upon cancellation or expiry | Anonymization is performed simultaneously with subscription termination (upon reaching the cancellation period end or after all payment retries fail). The original email address is replaced in an irrecoverable format. |
| Uploaded files and extracted data | Until user deletes | At the point the user performs a deletion operation. Data is retained after subscription termination (data access upon re-registration is not supported). |
| Billing and payment history | 7 years | Retained under legal obligation (e.g., Electronic Books Preservation Act equivalent) |
| Operation and authentication logs | 90 days | Automatically deleted after 90 days for security monitoring purposes |
| Inquiry contents | 3 years | Deleted 3 years after resolution |
INTERNATIONAL TRANSFERS
International Data Transfers
For some features (AI analysis, payment processing), data is transferred to servers outside Japan. Each service applies EU Standard Contractual Clauses (SCCs) or equivalent protective measures.
COOKIES
Use of Cookies
We explain the types of cookies DATAPIQ uses. We do not use cookies for advertising or marketing purposes.
CONTACT & REQUESTS
Privacy Inquiries
For requests regarding disclosure, correction, deletion, or suspension of use of personal information, or for questions about this Privacy Policy, please contact us via the inquiry form. After verifying your identity, we will respond within 30 days as a general rule.
If we make changes to this policy, we will notify you in advance through the service or by email. For significant changes, we may request your renewed consent.
Contact Form
List of national DPAs (European Data Protection Board)