Privacy Policy

Privacy Policy

Last updated: March 1, 2026

Article 1 (Introduction)

DXSpec, Inc. (hereinafter "the Company") hereby establishes this Privacy Policy (hereinafter "this Policy") regarding the handling of personal information in connection with the service "DXSpec" (hereinafter "the Service") provided by the Company.

The Company shall comply with the Act on the Protection of Personal Information and other applicable laws and regulations, and shall appropriately protect the personal information of our customers.

Article 2 (Information We Collect)

The Company collects the following information in the course of providing the Service.

[Account Information] Name, email address, company name, department, phone number, password (stored encrypted)

[Usage Information] Login timestamps, access logs, operation history, features used, browser information, IP address, cookie data

[Payment Information] Credit card information (processed through payment processors; the Company does not retain card numbers), billing address, transaction history

[Content Information] Design documents, documents, comments, and other data created or stored by customers through the Service

[Inquiry Information] Inquiry details, support correspondence history

Article 3 (Purpose of Use)

The Company uses collected personal information for the following purposes.

(1) Provision, operation, maintenance, and improvement of the Service

(2) User authentication and account management

(3) Billing and payment processing for service fees

(4) Responding to inquiries and providing support

(5) Notification of important service announcements

(6) Service quality improvement through usage analysis

(7) Development of new features and services

(8) Detection and prevention of unauthorized use

(9) Compliance with legal requirements

Article 4 (Disclosure to Third Parties)

The Company shall not provide personal information to third parties without customer consent, except in the following cases.

(1) When required by law

(2) When necessary for the protection of life, body, or property and obtaining consent is difficult

(3) When particularly necessary for improving public health or promoting the sound development of children and obtaining consent is difficult

(4) When cooperating with governmental agencies in performing legally prescribed duties

Article 5 (Outsourcing)

The Company may outsource the handling of personal information to external parties to the extent necessary for achieving the purposes of use.

In selecting contractors, the Company selects those with adequate levels of personal information protection and exercises appropriate oversight through contractual provisions regarding the secure management of personal information.

[Primary Contractor Categories] Cloud infrastructure (AWS Tokyo Region), payment processing (Stripe), email delivery services, customer support tools

Article 6 (Data Storage Location)

Customer data is stored and processed in data centers located within Japan (AWS Tokyo Region).

As a rule, personal information is not transferred outside Japan. In cases where outsourcing to overseas operators is unavoidable, appropriate measures shall be taken in accordance with the Act on the Protection of Personal Information.

For data storage, appropriate technical security measures are implemented, including AES-256 encryption and TLS 1.3 communication encryption.

Article 7 (Retention Period)

The Company retains personal information only for the period necessary for the purposes of use.

Account information: 90 days after account deletion (for recovery support)

Usage logs: 1 year from the date of collection

Payment information: Period prescribed by law (up to 7 years)

Inquiry history: 3 years after resolution

After the retention period, personal information shall be promptly deleted or anonymized.

Article 8 (Security Measures)

The Company implements the following measures for the prevention of leakage, loss, and damage of personal information and other secure management thereof.

[Organizational Measures] Appointment of a personal information protection officer, establishment of information security policies, employee training, regular internal audits

[Technical Measures] AES-256 encryption, TLS 1.3 communication encryption, WAF/IDS deployment, access control, two-factor authentication, regular vulnerability assessments

[Physical Measures] Use of domestic data centers (ISO 27001 certified), entry/exit management, surveillance camera installation

Article 9 (Customer Rights)

Customers may make the following requests to the Company.

(1) Request for disclosure of personal information

(2) Request for correction, addition, or deletion of personal information

(3) Request for suspension or erasure of personal information

(4) Request to cease provision of personal information to third parties

Request method: Please contact us through the Service settings page or via our inquiry form. After identity verification, we will respond within the period prescribed by law.

If we are unable to comply for legal or other reasons, we will notify you with an explanation.

Article 10 (Cookies and Similar Technologies)

The Company uses cookies and similar technologies in the Service for the following purposes.

[Essential Cookies] Maintaining login status, session management, security measures (cannot be disabled)

[Analytics Cookies] Understanding service usage patterns, collecting statistical information for improvement (Google Analytics, etc.)

[Functional Cookies] Saving user preferences (language, display settings, etc.)

Analytics cookies and functional cookies can be disabled through browser settings. However, some features may become unavailable.

Article 11 (AI Data Processing)

The Service may process user content through AI features.

AI processing is executed only when customers explicitly use the feature. Content is not automatically used as training material.

In providing AI features, external AI API services may be utilized. In such cases, data sent is limited to the minimum scope necessary for processing, and data protection agreements are established with such service providers.

For details on AI processing, please refer to the separate "AI Terms of Use."

Article 12 (Minors' Personal Information)

The Service is not intended for individuals under the age of 16.

If it becomes known that personal information of individuals under 16 has been inadvertently collected, such information shall be promptly deleted.

Parents or guardians who believe their child may have provided personal information to the Company should contact us.

Article 13 (Changes to This Policy)

The Company may modify this Policy due to changes in laws, service modifications, or other circumstances.

For material changes, the Company shall notify customers of the content and effective date through the Service or by email.

The amended Policy shall take effect from the time it is posted on the Service.

Article 14 (Contact Information)

For inquiries, complaints, or consultations regarding the handling of personal information, please contact the following.

DXSpec, Inc. — Personal Information Protection Officer

Email: [email protected]

Address: 1-1-1 Marunouchi, Chiyoda-ku, Tokyo 100-0005, Japan

Hours: Weekdays 9:00–18:00 (excluding weekends, national holidays, and year-end/New Year holidays)