Privacy Policy

Last updated: 2026-07-23

Introduction

TrustedAI株式会社 ("we", "our") sets out this Privacy Policy for the handling of personal information of those who use our Makaseba service (the "Service"). We build a personal-information-protection framework, make our officers and staff aware of its importance, and enforce it to protect personal information. The Service also covers information collected through agents you deploy to your own end users.

Article 1 (Personal Information)

"Personal information" means personal information as defined in Japan's Act on the Protection of Personal Information (Act No. 57 of 2003, the "APPI"): information about a living individual that can identify the individual by name, date of birth, or other description, or that contains an individual identification code.

Article 2 (Purposes of Use & Legal Basis)

We collect and use your personal information within the scope necessary for the following purposes; to use it beyond this scope we obtain your prior consent by an appropriate method. - To register you, authenticate you, and manage your account - To provide, improve, and develop the Service - To read (read-only) the files you select from a connected account (Google Drive, Microsoft OneDrive) to build and update your agent's knowledge base - To send you new features, updates, and important notices - To respond to your inquiries (including identity verification) - To analyze usage in order to improve and develop the Service - To identify and refuse users who violate the terms or use the Service for improper purposes Our legal bases are performance of our contract, your consent (including the OAuth grant for connected accounts), our legitimate interests, and compliance with legal obligations. We do not sell your data and do not use your documents or conversations to train models shared across organizations.

Article 3 (Management & Protection of Personal Information)

We manage personal information strictly and, except in the following cases, do not disclose or provide it to third parties without your consent. We also take preventive and corrective measures against unauthorized access, loss, destruction, alteration, and leakage. - Where necessary to protect a person's life, body, or property and consent is difficult to obtain - Where specially necessary for public health or the sound development of children and consent is difficult to obtain - Where cooperation with a government body performing statutory duties would be impeded by obtaining consent - Where a business is succeeded through merger or otherwise - Where otherwise permitted by law

Article 4 (Outsourcing / Sub-processors)

Within the scope necessary to achieve the purposes of use, we may outsource all or part of the handling of personal information to vetted providers. In such cases we screen the provider, set confidentiality obligations by contract, and exercise necessary and appropriate supervision. Provider categories include cloud hosting/storage, database, vector search, LLM and embedding providers, reranking, OCR, web retrieval, payments, email, and error/telemetry. Our current sub-processor list is published at makaseba.com/subprocessors.

Article 5 (Cross-border Transfers)

We process and store personal data in the region we designate for our infrastructure; some providers (such as LLM providers) may process data outside that region. For users in Japan, this constitutes provision of personal data to a third party in a foreign country. Where a transfer to a third party in a foreign country applies, we rely on appropriate safeguards such as Standard Contractual Clauses (or equivalent measures), rather than on your consent. Information about the destination countries and their data-protection frameworks is available on request.

Article 6 (Cookies)

The Service uses cookies as necessary to keep you signed in and to secure the product. Our marketing-site analytics do not use advertising or cross-site tracking cookies. You can disable cookies in your browser settings, but disabling necessary cookies may impair sign-in and other functions.

Article 7 (Disclosure of Personal Information)

When you (the individual) request disclosure of the personal information we hold, we disclose it without delay, except where disclosure would: (i) harm the life, body, property, or other rights of you or a third party; (ii) significantly impede the proper conduct of our business; or (iii) violate law. If we decide not to disclose, we notify you without delay. We respond within a reasonable period (in principle within two weeks) and may charge a reasonable fee for disclosure to the extent permitted by law.

Article 8 (Correction, etc.)

If the personal information we hold is inaccurate, you may request its correction, addition, or deletion. We investigate without delay and notify you of the outcome without delay.

Article 9 (Suspension of Use, etc.)

You may request that we suspend use, erase, or stop third-party provision of the personal information we hold. We investigate without delay and notify you of the outcome without delay. These requests also satisfy the GDPR rights of access, rectification, erasure, data portability, restriction, objection, and withdrawal of consent, in addition to APPI rights. After identity verification, request via makaseba@trusted-ai.co. You may also complain to a supervisory authority (in Japan, the Personal Information Protection Commission). Account holders can disconnect integrations and delete content in-product at any time.

Article 10 (Changes to this Policy)

We review and improve this Policy from time to time. Except where law or this Policy provides otherwise, we may change it; the amended Policy takes effect when we notify you by our prescribed method or post it on our website.

Article 11 (Compliance with Laws)

We comply with applicable Japanese laws and norms regarding the personal information we hold, and with the GDPR to the extent applicable for EU users.

Article 12 (Complaints & Consultation)

We receive and respond promptly and appropriately to complaints and consultations regarding the handling of personal information, and to requests for disclosure, correction, addition, deletion, or refusal of use or provision.

Article 13 (Security Measures & Breach Notification)

We apply organizational, physical, personnel, and technical measures — access controls on personal-information files, access logging, protection against unauthorized external access, encryption in transit (TLS), encryption at rest for connected-account tokens, tenant isolation, and rate limiting — to prevent unauthorized access, loss, destruction, alteration, and leakage. If a leakage or similar incident occurs, we promptly notify the relevant authority and affected users and take necessary measures in accordance with the APPI and its guidelines (and GDPR Arts. 33-34 where applicable).

Article 14 (Data Sources & Retention)

This Article applies to content you provide or connect as a knowledge source for Makaseba ("Data Sources") and prevails over the more general provisions of this Policy. - Data Sources and derived data (search index, embeddings) are logically isolated per workspace and never shared with other customers. - Data Sources and derived data are encrypted in transit and at rest using industry-standard encryption. - Agents answer using retrieval-augmented generation (RAG). When we send content to an LLM provider to generate an answer, we set data controls so those inputs/outputs are not used to train the provider's base models. We do not train AI models on your content. - Access to Data Sources and indexes is limited to the minimum authorized staff and is logged for security and compliance. - You may disconnect and delete Data Sources from your workspace at any time. On deletion we remove the original content, purge derived data (index/embeddings) in the same operation or within our normal operational window, and any residual copies in encrypted backups age out under our normal backup rotation. - Site-usage events are retained for 90 days and security/audit logs for 365 days, then deleted. Account and agent data is retained for the life of your account and deleted on closure. - We use vetted sub-processors (including model API providers) to deliver parts of the Service, remain responsible for their performance, and publish the list at makaseba.com/subprocessors. - If we become aware of a security incident involving Data Sources, we notify your designated contact without delay. - Google user data (Limited Use): files you select from Google Drive are treated as Proprietary Data Sources subject to this Article. To let you select them we read folder and file names and your Google account email. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Selected file contents are used solely to provide that user's chatbot functionality, are not used for advertising, are not used to train or improve generalized or shared AI/ML models, and are never used to generate responses for any other user. Our personnel do not access this data except (1) with your consent, (2) as needed for security or legal compliance, or (3) where aggregated and anonymized. On disconnect we revoke the grant at Google (which supports programmatic revocation); for Microsoft, which does not, you can remove our access in your Microsoft account settings. Access and refresh tokens are stored encrypted at rest.

Article 15 (Children's Data)

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us personal data, contact makaseba@trusted-ai.co and we will delete it.

Article 16 (Operator, Representative & Privacy Manager)

Our name, address, representative, and personal-information protection manager are: Name: TrustedAI株式会社 Address: 2F-C Shibuya Dogenzaka Tokyu Building, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo, Japan Representative Director: Le Thai Anh Personal Information Protection Manager: Le Thai Anh

Article 17 (Contact)

For inquiries about this Policy and the handling of personal information, and for disclosure and related requests, contact: TrustedAI株式会社 — Customer Support 2F-C Shibuya Dogenzaka Tokyu Building, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo, Japan Email: makaseba@trusted-ai.co