PRIVACY POLICY

Privacy Policy

U-Rec, Inc. (the “Company,” “we,” or “us”) handles personal information obtained in connection with inquiries; business discussions; the provision of its services; the recruitment of employees, interns, and co-founders; interactions at trade shows, events, and similar occasions; and the operation of its corporate website (https://u-rec.jp/, the “Site”) as set out below, in accordance with Japan’s Act on the Protection of Personal Information and other applicable laws and regulations.

  1. Scope and business operator information

    This policy applies to personal information that we obtain ourselves, including inquiry information, business partner contact information, information about applicants for employment, internships, or co-founder positions, information obtained through business card exchanges and similar interactions, information relating to credit checks and checks for relationships with anti-social forces, and information obtained through the operation of the Site. If separate handling terms apply to a particular service or recruitment process, please read them together with this policy. Data entrusted to us by customers is handled in accordance with applicable law and the customers’ contracts and instructions.

    • Company name: U-Rec, Inc.
    • Representative: Yoshihiro Kanno, Representative Director
    • Location: Utsunomiya, Tochigi, Japan

    We will provide the details of our business address without delay upon request made through the contact point on this page.

  2. Information we collect and how we collect it

    • The name, company name, affiliation and job title, contact details, inquiry type, and inquiry details that you provide through the contact form, by email, in business meetings, or by exchanging business cards at trade shows, events, or similar occasions, and the history of our correspondence with you. For form submissions, we also record the date and time of receipt and a submission ID.
    • The affiliation and contact details of contact persons at our business partners, and information about contracts, invoicing, and payments, as needed to propose, contract for, and perform our services. We will tell you which items are required for each procedure.
    • The name, contact details, background (such as education, work history, and qualifications), and application details that you provide by email, in application documents, in interviews, or through similar means when applying for employment, an internship, or a co-founder position, and records of the selection process and our communications with you. We collect this information within the scope necessary for selection.
    • Information needed for credit checks and for confirming whether there are any relationships with anti-social forces when we begin a business relationship. We obtain it, to the extent necessary, from declarations by you or our business partners, publicly available information, investigative information lawfully provided to us, and similar sources.
    • Communication information generated when you access the Site, such as your IP address, the date and time of access, the pages viewed, and your browser, as well as identifiers used to prevent fraudulent submissions.

    We obtain information by lawful and proper means, and only to the extent necessary for the purposes of use. If you do not provide required items, we may be unable to respond to your inquiry or provide our services. Company name is an optional field on the contact form.

  3. Purposes of use

    • Receiving inquiries and consultation requests, verifying your identity and contact details, responding, and managing correspondence history.
    • Proposing, quoting for, contracting for, and providing Custom AI Development, AI Security Consulting, AI Training, and other services, and handling related business communications, invoicing, and payment management.
    • Receiving applications for employment, internships, and co-founder positions, communicating with applicants, conducting interviews and selection, notifying applicants of results, and handling procedures for participation or contracting.
    • Sending information about our services, seminars, events, and the like to people we have been in contact with through inquiries, business card exchanges, or similar interactions. We obtain any consent and complete any other procedures required by law, and we act on requests to stop receiving such information.
    • Conducting credit checks and confirming whether there are any relationships with anti-social forces when beginning a business relationship, and deciding whether to do business.
    • Improving the quality of our responses to inquiries, and reviewing requests and reported problems to improve our services.
    • Operating the Site and our services securely, preventing unauthorized access and spam submissions, and investigating and responding to outages and security issues.
    • Responding to requests and complaints concerning personal information, fulfilling legal obligations, and handling disputes.

    You may ask us at any time to stop sending you information about our services, seminars, events, and the like, using the form or the email address given at the contact point on this page.

    If we change a purpose of use, we will do so only within the scope reasonably considered to be related to the original purpose, and we will notify you of or publicly announce the change. Before using personal information beyond that scope, we will obtain your consent in advance, except where permitted by law.

  4. Information you send us

    Our contact form does not ask you to enter special care-required personal information (such as medical history), your Individual Number (My Number), identity documents, passwords, private keys, unpublished source code, or similar information. Please do not enter personal information or information about third parties that is not necessary for your inquiry.

    Where our work requires us to handle special care-required personal information or similar information, we will confirm on a case-by-case basis the need to obtain it, the legal basis for doing so, and a secure method of transfer, and we will obtain any consent and complete any other procedures required by law.

  5. How contact form submissions are sent and stored

    The information you enter in the form is sent by email, through a submission process on XServer, to a recipient designated by us. The submission process itself does not save your input to a database, but we retain it as received email and in our subsequent records of correspondence.

    To limit the number of submissions, we use an identifier calculated from your IP address using a secret key, together with submission times. These are stored outside the publicly accessible web area, and records older than the limit period are cleared when the next submission is processed. Separately, IP addresses may be recorded in server access logs and similar records.

  6. Retention and deletion

    We have not set a uniform retention period for inquiry information; we keep it only for as long as necessary to respond to your inquiry and for subsequent follow-up. We keep information about contracted clients during the term of the contract and, after the contract ends, only for as long as we have a specific business need (for example, to fulfill contractual obligations, provide support, handle invoicing and accounting, or deal with disputes) or are required to retain it by law. We do not keep information indefinitely merely because it might be used in the future, and we review whether continued retention is necessary.

    We keep applicant information only for as long as needed to handle applications, conduct selection, notify results, complete procedures for participation or contracting, and deal with any necessary follow-up. Information obtained through business card exchanges and similar interactions, and information related to credit checks and confirming relationships with anti-social forces, is likewise kept only for as long as necessary for the purposes of use, and we regularly review whether continued retention is necessary.

    When we receive a request to stop sending information, we stop sending it. We may keep the minimum contact details and opt-out records needed to avoid sending it again by mistake.

    We endeavor to erase information without delay once it is no longer needed, except where retention is required by law or in similar cases. Deletion also covers received email and records of correspondence, and backups are processed in accordance with their retention and update procedures.

  7. Security control measures

    To prevent the leakage, loss, or damage of the information we handle, we take the following measures in accordance with the nature of the information and the risks involved.

    • We have appointed a person responsible for information security, manage our information assets and the services we use, and regularly review how these measures are working in practice.
    • We limit access rights to personal information to what is necessary for business purposes.
    • We impose confidentiality obligations on the officers, employees, interns, and contractor personnel who handle personal information, and we provide them with training on handling personal information.
    • We encrypt work devices, use screen locks, apply security updates, use multi-factor authentication for major cloud services, and back up important data.
    • We use HTTPS for communications with the Site, verify the origin of form submissions and prevent fraudulent submissions, and keep private configuration settings and submission-limit records separate from the publicly accessible web area.

    When we use services provided by foreign businesses (including services with servers located in Japan), or handle personal data outside Japan, we take the necessary measures after understanding the relevant countries’ systems for protecting personal information and other relevant conditions. We will respond without delay to inquiries about our security control measures, including the countries where providers and servers are located and the measures we have taken, except for information whose disclosure could interfere with maintaining security.

  8. Entrustment to service providers and their supervision

    We may entrust the handling of personal information to service providers, to the extent necessary to achieve the purposes of use, for tasks such as hosting the Site, sending, receiving, and storing email, and operating business systems.

    We select service providers after reviewing their security arrangements, set out the scope of handling and confidentiality obligations in contracts or similar instruments, and exercise necessary and appropriate supervision, including over any subcontracting. Handling that involves providers outside Japan is also subject to the section “Provision to third parties, joint use, and handling outside Japan” of this policy.

    Detailed information about the names of the services we use and our contractual and system arrangements is shared, where appropriate, under a non-disclosure agreement (NDA) after we confirm the purpose of and need for the request. However, we do not require you to explain the purpose of or need for your request, or to enter into an NDA, as a condition for receiving information that we are required by law to provide to you.

  9. Provision to third parties, joint use, and handling outside Japan

    Except as permitted by law, we do not provide personal data to third parties without your prior consent. Entrustment within the scope necessary to achieve the purposes of use is managed separately from provision to third parties as defined by law.

    If we use personal data jointly with others, we will notify you in advance of, or make readily accessible to you, the required information, including the items of personal data concerned, the scope of joint users, the purposes of use, and the name, address, and representative of the party responsible for managing the data.

    Where provision to a third party in a foreign country, or storage or handling outside Japan, is necessary, we check the relevant country’s system for protecting personal information and the protective measures in place at the recipient. Where consent is required for such provision, we obtain it after providing in advance the information required by law, including the name of the country, information on its system for protecting personal information, and the measures taken by the recipient. Where we provide personal data on the basis of a system under which the recipient continuously takes equivalent measures, we confirm that those measures are being implemented and, upon your request, provide the information required by law.

    Consent given on the contact form is not treated as blanket consent to provision to unspecified third parties or to transfers outside Japan.

  10. Use of generative AI services

    The Site’s contact form has no process that automatically sends submitted content to generative AI.

    We may use external generative AI services when responding to inquiries or performing work under contracts. Personal information may be entered only into services that we have contracted for as a company and for which we have confirmed both security control measures to prevent leakage and settings and contractual terms under which input data is not used to train models. We do not enter personal information into accounts other than those contracted for and managed by the Company (such as staff members’ private accounts) or into services for which we cannot confirm these points.

    Before entering any information, we confirm that doing so is consistent with the purposes of use and with our contracts with, and instructions from, clients, and we keep input to the minimum necessary, for example by removing unnecessary identifying information such as names and contact details. We do not consider a setting that excludes data from model training sufficient on its own; we also check the terms on data retention, access control, entrustment, provision to third parties, and handling outside Japan, and complete any necessary procedures. Where a contract with a client restricts the use of AI, we comply with that restriction.

  11. Cookies and analytics

    The Site uses a first-party cookie named “urec_contact_csrf” to prevent fraudulent contact form submissions. The cookie is valid for 30 minutes from issuance and is deleted when a submission is confirmed to carry a valid token. It is not used for advertising or for tracking browsing behavior.

    You can block or delete cookies in your browser, but you may then be unable to submit the form. Even if you cannot use the form, we accept requests, questions, and complaints about personal information at the email address given at the contact point on this page. The Site does not currently use analytics tools or cookies for advertising. If we introduce them, we will explain the information collected, where it is sent, the purposes, and other details, and will obtain consent or complete other procedures where necessary.

  12. Communications with external services

    The Site uses Google Fonts to display text, so your browser connects to Google’s delivery servers (fonts.googleapis.com and fonts.gstatic.com). In the process, communication information such as your IP address, information about your browser, and the referrer may be sent. We use this connection to display fonts. For how Google handles this information, please refer to Google’s own explanations.

    External websites you visit from the Site are governed by their operators’ policies. The company introduction video on the Site is served from the Site itself, and we do not use a player from any external video-sharing service.

  13. Requests for disclosure, correction, cessation of use, and other actions

    In accordance with applicable laws, you may request, with respect to retained personal data held by us, notification of the purposes of use; disclosure; correction, addition, or deletion; cessation of use or erasure; cessation of provision to third parties; and disclosure of records of provision to third parties.

    • Please contact us using the form or the email address given at the contact point on this page and tell us the type of request, the information concerned or when the relevant transaction or inquiry took place, and where we should send our reply. On the form, please select “Requests concerning personal information” as the inquiry type.
    • After receiving your request, we will explain the steps required to verify your identity. For requests made by an agent, we will also verify the agent’s authority and identity. We will not ask for more information than necessary. Please do not include identity documents or your Individual Number (My Number) in your initial inquiry, whether in writing or as attachments.
    • We will respond without delay, in accordance with applicable laws, by the method you request, such as electronic records or paper documents. If disclosure by your preferred method is difficult, for example because it would entail substantial costs, we will notify you and provide disclosure in writing.
    • If we cannot comply with all or part of a request on grounds permitted by applicable law, we will inform you of that and explain the reasons.

    We do not charge a fee for receiving or responding to these requests.

  14. Response to leakage and similar incidents

    If we become aware of the leakage, loss, or damage of personal data, or of the possibility that such an incident has occurred, we will work to prevent further harm, investigate the facts, identify the cause, and prevent recurrence. Where reporting or notification is required by law, we will report to the Personal Information Protection Commission or other relevant authorities and notify the individuals concerned, among other steps.

  15. Contact point for inquiries and complaints

    For inquiries about the handling of personal information, requests concerning retained personal data, questions about security control measures, or complaints, please contact U-Rec, Inc.’s personal information inquiry desk.

    Inquiries about personal information

    Contacting us by email does not require the Site’s cookies or the form. Please do not include identity documents or your Individual Number (My Number) in your first email, whether in writing or as attachments.

  16. Revisions and effective date

    We review this policy in response to changes in laws or in our business or operations. We will announce revisions and their effective date on this page and, where necessary, give separate notice of material changes. Where the law requires your consent to a change, posting the change on this page alone will not be treated as your consent.

    The Japanese version of this policy is the authoritative text, and the English version is a reference translation. In the event of any discrepancy between the Japanese and English versions, the Japanese version prevails.

    Revision and effective date: September 25, 2026

Start with an AI security assessment.

What risks does AI use pose to your organization? Talk to us about understanding your current exposure.

Book a free consultation