第1条(事業者情報)
| 項目 | 内容 |
|---|---|
| 事業者名 | HEROES合同会社(HEROES LLC) |
| 所在地 | 東京都台東区浅草(番地を含む正式表記は未確定) |
| 代表者氏名 | 登記上の代表社員名義での表記を確定する |
| 個人情報取扱いに関する窓口 | 第12条に定めるメールアドレス |
本条は、個人情報の保護に関する法律(以下「個人情報保護法」)**第32条(保有個人データに関する事項の公表等)**が求める公表事項に対応する(同条の項・号番号は本ドラフトでは未確認)。
Article 1 (Operator information) — The Service is operated by HEROES LLC (HEROES合同会社), located in Asakusa, Taito-ku, Tokyo, Japan. The full registered address and the name of the representative member are to be finalised before publication. Inquiries about personal information are received at the address in Article 12. This Article corresponds to the publication requirements of Article 32 of Japan's Act on the Protection of Personal Information ("APPI").
第2条(適用範囲)
本ポリシーは、HEROES合同会社が提供する Asakusa Travel(以下「本サービス」)における情報の取扱いに適用される。本サービスの Phase 1 は、決済・物販を含まない無料の情報メディアである 。
本サービスの利用者は次の2類型に分かれ、取り扱う情報の内容が異なる。
- 旅行客(guest): 会員登録なしで記事を閲覧する利用者。Phase 1 では認証フロー自体が存在しない
- 店舗(merchant)/運営(admin): メールアドレスとパスワードでログインするアカウント利用者
本サービスから外部サイト(Google マップ等)へ遷移した後の情報の取扱いは、当該サイトの運営者のポリシーに従う。
Article 2 (Scope) — This Policy applies to Asakusa Travel ("the Service"), operated by HEROES LLC. In Phase 1 the Service is a free information medium with no payments and no e-commerce. Users fall into two groups: travellers, who read articles without any registration or sign-in, and shop and operator accounts, which sign in with an email address and password. Once you follow a link to an external site such as Google Maps, that site's own privacy policy applies.
第3条(取得する情報と、その法的性質)
本サービスが実際に取得する情報は、以下の表に記載したものが全てである。本表は実装仕様(データモデル・API 仕様)に存在する項目のみを記載しており、記載のない情報(氏名以外の属性、年齢、性別、位置情報、端末識別子、決済情報等)は取得しない。
3.1 取得する情報の一覧
| # | 情報 | 取得の有無 | 個人情報保護法上の位置づけ | 実装上の根拠 |
|---|---|---|---|---|
| 1 | 店舗・運営アカウントのメールアドレス/パスワード | 取得する | 個人情報(保有個人データに該当すると整理。最終確認は) | |
| 2 | 店舗の公開プロフィール(店名・住所・地図リンク・営業時間) | 取得する | 原則は法人・事業所の情報。ただし個人事業主の場合は個人情報に該当しうる(§3.3) | |
| 3 | 審査結果メールの受信設定 | 取得する | 個人情報(上記1と一体) | |
| 4 | 店舗が入稿した記事の本文・タイトル(日本語/英語) | 取得する | コンテンツ。本文に個人に関する記述が含まれる場合は個人情報を含みうる | |
| 5 | 記事写真(最大5枚)・動画(1本) | 取得する | 人物が写り込む場合は個人情報・肖像に関する権利の問題を生じうる | |
| 6 | 行動イベントログ(閲覧・ブックマークの記録) | 取得する | 個人識別子を持たない設計。個人情報には該当しないと整理(§3.4) | |
| 7 | IP アドレス | 保存しない(一時的に処理する) | §3.5 のとおり | |
| 8 | 旅行客のブックマーク一覧 | 取得しない(端末内で完結) | 事業者は取得しないため取扱いが発生しない(§3.6) | |
| 9 | 旅行客の氏名・メールアドレス等 | 取得しない | 会員登録機能が存在しない | |
| 10 | 決済情報・クレジットカード情報 | 取得しない | Phase 1 に決済機能がない |
3.2 店舗・運営アカウント情報(個人情報)
店舗の担当者および運営者は、メールアドレスとパスワードで本サービスにログインする 。認証は Supabase Auth を用い、パスワードは同基盤においてハッシュ化して保管される。メールアドレスは特定の個人(店舗の担当者)への連絡先であり、個人情報保護法第2条(定義)にいう個人情報として取り扱う。
これらは当社が開示・訂正・利用停止等を行う権限を有するため、保有個人データとして第10条の開示等請求の対象になると整理する(該当性の最終確認は)。
3.3 店舗の公開プロフィール
店舗ページには、店名(日本語・英語)・住所(日本語表記)・Google マップリンク・営業時間を掲載する 。これらは店舗を紹介するための公開情報であり、原則として事業所に関する情報である。
ただし、掲載店舗が個人事業主である場合、店名が個人の氏名(屋号)と一致したり、店舗住所が自宅住所と一致したりすることがある。この場合、当該情報は個人情報に該当しうる。当社は掲載前に店舗の同意を得て掲載するが、店舗は掲載内容の変更・削除を第10条の窓口から求めることができる。
3.4 行動イベントログ(個人識別子を持たない設計)
本サービスは、記事の閲覧(view)とブックマーク(bookmark)の発生件数を記録する。記録される項目は次の4つのみである 。
| 列 | 内容 |
|---|---|
| id | 連番 |
| event_type | view または bookmark |
| slug | 対象記事の URL 識別子 |
| created_at | 発生時刻 |
このテーブルは、利用者 ID・IP アドレス・端末 ID のいずれの列も持たない。設計方針にも「events は個人識別子(user id・IP・端末 ID)を列に持たない(計測は件数集計が目的)」と明記されている 。記録を送信する API の入力も { type, slug } の2項目のみで、識別子を含まない 。また、このテーブルは他テーブルへの外部キーを持たない独立したテーブルであり、他の情報と結合して個人を特定する経路を設計上持たない 。
以上から、当社は行動イベントログを特定の個人を識別できない情報と整理し、個人情報としては取り扱わない。ログを個人単位で分析することはなく、記事ごとの件数集計にのみ用いる。
なお、個人情報保護法**第31条(個人関連情報の第三者提供の制限等)**が定める「個人関連情報」への該当性については、当該ログが特定の個人との対応関係を持たないことから該当しないと整理しているが、最終確認はとする。また当社は本ログを第三者に提供しない(第7条)。
3.5 IP アドレスの取扱い(保存しない/一時的に処理する)
行動イベントを記録する公開エンドポイントには、大量送信によるログ肥大を防ぐためのレート制限を設けている。この制限は IP アドレス単位で 1分あたり60リクエストとし、実装はアプリケーションサーバー内のメモリ上のカウンタで行う 。
したがって IP アドレスの取扱いは次のとおりである。
- データベースには保存しない。行動イベントログのテーブルに IP アドレスの列は存在しない
- レート制限のためにメモリ上で一時的に処理し、集計期間の経過とともに失われる
- 当社はこれを個人を特定する目的で利用せず、他の情報と照合しない
IP アドレスは、それ単体では通常特定の個人を識別できないが、他の情報と容易に照合できる場合には個人情報に該当しうる。本サービスでは照合先となる利用者情報を保持していないため個人情報には当たらないと整理するが、最終確認はとする。
**なお、本サービスが利用するホスティング事業者およびデータベース事業者が、当社の設定とは別に自社のアクセスログとして IP アドレスを保持するか否かは、本ドラフト作成時点の設計文書に記載がなく未確認である。**として第14条一覧に記載し、事業者の仕様を確認のうえ本条を補訂する。
3.6 旅行客のブックマーク(当社は取得しない)
旅行客が「保存」した記事の一覧は、旅行客の端末のブラウザ内(LocalStorage)にのみ保存される。当社のサーバーには送信されず、当社はその内容を知りえない 。保存件数の上限は30件である 。
ブラウザの閲覧データを消去すると、ブックマークも消える。端末を変えると引き継がれない。
Article 3 (Information we collect) — The table in §3.1 lists everything the Service collects; anything not listed there (age, gender, location data, device identifiers, payment details, and so on) is not collected.
- Shop and operator accounts. We collect an email address and a password, used to sign in. Passwords are stored in hashed form by our authentication provider. This is personal information under the APPI and is subject to the disclosure requests described in Article 10.
- Shop profiles. Shop name, address, a map link and opening hours are published on the shop page. These normally describe a business, but where the shop is a sole trader they may also be personal information; such shops may ask us to change or remove them.
- Article text and photographs submitted by shops. Photographs may contain images of people.
- Activity logs. We record only that an article was viewed or bookmarked. Each record contains four fields: a serial number, the event type, the article's URL identifier and a timestamp. There is no user ID, no IP address and no device ID, and the table has no link to any other table. We therefore cannot tell who viewed what; we only count how many times each article was read. We do not share these logs with anyone.
- IP addresses. To stop the activity-log endpoint being flooded, we limit requests to 60 per minute per IP address. That check runs in the server's memory and expires with the counting window. We do not store IP addresses in our database. Whether our hosting and database providers keep their own access logs is not yet confirmed and will be clarified before publication.
- Bookmarks. The list of articles you save stays in your own browser (LocalStorage) on your own device, up to 30 items. It is never sent to us, and we cannot see it. Clearing your browser data deletes it, and it does not follow you to another device.
- Travellers are never asked to register, so we hold no name, email address or payment details for travellers.
第4条(利用目的)
当社は、取得した情報を次の目的の範囲内で利用する。個人情報保護法**第17条(利用目的の特定)**に基づき利用目的を特定し、**第21条(取得に際しての利用目的の通知等)**に基づき本ポリシーの掲示によりこれを公表する。**第18条(利用目的による制限)**のとおり、本人の同意なく下記の範囲を超えて利用しない。
| 情報 | 利用目的 |
|---|---|
| 店舗・運営アカウントのメールアドレス | ①アカウントの認証 ②記事の審査結果(承認・却下)の通知 ③本サービスの運用に関する連絡 |
| 店舗の公開プロフィール | 本サービス上での店舗紹介の掲載 |
| 記事の本文・タイトル・写真 | ①本サービス上での掲載 ②掲載可否の審査 ③英語への翻訳(第8条) |
| 行動イベントログ | ①本サービスの改善 ②Phase 2 の指標設計の材料としての件数集計 |
| IP アドレス | 不正な大量送信の防止(レート制限) |
利用目的を変更する場合は、変更前の目的と関連性を有すると合理的に認められる範囲で行い、変更後の目的を本サービス上に掲示する。
Article 4 (Purposes of use) — We use account email addresses to authenticate sign-ins, to notify shops of review decisions and to contact them about running the Service; shop profiles and articles to publish and review listings and to translate them into English; activity logs to improve the Service and to count article reads as input for future planning; and IP addresses solely to block abusive volumes of requests. We will not use information beyond these purposes without consent. This corresponds to APPI Articles 17, 18 and 21.
第5条(Cookie および類似技術)
本サービスにおける端末側の記録技術の利用状況は次のとおりである。
| 技術 | 利用目的 | 対象 |
|---|---|---|
| Cookie(認証セッション) | 店舗・運営アカウントのログイン状態の保持 | 店舗・運営のみ |
| LocalStorage | ブックマークの端末内保存 | 旅行客 |
- 認証セッション用の Cookie は、ログインする利用者(店舗・運営)に対してのみ発行される。ログインを行わない旅行客には発行されない
- 広告・行動ターゲティングのための Cookie、および第三者のアクセス解析タグは利用していない。 設計文書上、外部解析サービスの導入は記載されておらず、コンテンツセキュリティポリシーも自ドメインのスクリプトのみを許可する方針である
- LocalStorage の内容は当社に送信されない(第3条6項)
Cookie 同意バナーの要否は未確定である。 認証に必要な Cookie に限られる場合と、将来アクセス解析を導入する場合とで結論が変わりうる。日本の電気通信事業法におけるいわゆる外部送信規律(条番号未確認)および EU の ePrivacy 規律(指令番号・条番号とも未確認)の該当性を含めて、公開前に判定する。
Article 5 (Cookies and similar technologies) — We use a cookie to keep shop and operator accounts signed in; travellers, who never sign in, do not receive it. We use LocalStorage only to keep your bookmarks on your own device. We do not use advertising or tracking cookies, and we do not run third-party analytics tags. Whether a cookie consent banner is required has not yet been decided and will be settled before launch.
第6条(保存期間)
各情報の保存期間は次のとおりとする。下表の値は本ドラフトにおける仮確定であり、事業オーナーの確認を要する。
| 情報 | 保存期間(案) | 根拠・考え方 |
|---|---|---|
| 店舗・運営アカウント(メールアドレス等) | アカウント有効期間中。無効化(active / is_active を false に設定)後 1年で削除 |
掲載再開の可能性と、掲載内容に関する問い合わせ対応の期間を見込む |
| 店舗の公開プロフィール | 同上 | アカウントと一体で管理する |
| 記事(本文・タイトル) | 掲載中は無期限。非公開化(取り下げ・却下)後 1年で削除 | 店舗による再申請の余地を残す |
| 記事写真・動画(Storage) | 記事本体と同一。記事削除時に併せて削除 | 写真は記事に紐づくため(削除は連動する設計) |
| 行動イベントログ | 26か月 | 前年同月との比較が1回行える最短期間。経過後は件数の集計値のみを残し、明細行は削除する |
| IP アドレス(レート制限) | 保存しない(メモリ上・集計期間の経過とともに消滅) | 永続化する設計を持たない |
| 開示等請求への対応記録 | 3年 | 対応の適正性を説明できる期間を確保する |
| ホスティング事業者・データベース事業者のアクセスログ | 未確認 | 当社の設定ではなく事業者の仕様に依存する(第3条5項) |
法令により保存が義務づけられる場合は、当該法令の定める期間保存する。
Article 6 (Retention periods) — Account information is kept while the account is active and deleted one year after it is deactivated. Articles remain while published and are deleted one year after being unpublished or rejected; photographs are deleted together with their article. Activity logs are kept for 26 months, after which only aggregate counts remain. IP addresses are not stored at all. Records of disclosure requests are kept for three years. Retention by our hosting and database providers is still to be confirmed. These periods are provisional in this draft and require the operator's confirmation.
第7条(第三者提供)
当社は、あらかじめ本人の同意を得ることなく、個人情報を第三者に提供しない。個人情報保護法**第27条(第三者提供の制限)**が定める例外(法令に基づく場合等)に該当する場合を除く。
ただし、次の取扱いは同条にいう「第三者提供」には当たらないものとして整理している。
- 利用目的の達成に必要な範囲での業務委託に伴う提供(第8条の翻訳事業者、およびサーバー・データベースの提供事業者)。この場合、当社は個人情報保護法**第25条(委託先の監督)**に基づき委託先に対する必要かつ適切な監督を行う(同条の例外規定の項・号番号は本ドラフトでは未確認)
- 事業の承継に伴う提供
当社は、行動イベントログ(第3条4項)を第三者に提供しない。また当社は、個人情報を第三者に販売しない。
Article 7 (Provision to third parties) — We do not provide personal information to third parties without prior consent, except where the APPI permits it (for example, where required by law). Providing information to contractors acting for us — the translation provider in Article 8 and our server and database providers — is treated as outsourcing rather than third-party provision; we supervise those contractors as required by APPI Article 25. We do not share activity logs with anyone, and we never sell personal information.
第8条(外国にある第三者への提供・AI 翻訳のための送信)
8.1 送信する内容
本サービスは、店舗が日本語で入稿した記事を英語に自動翻訳したうえで公開する 。この翻訳のため、記事のタイトルと本文(日本語)を外部の AI 翻訳 API に送信する。送信されるのは次の2項目のみである 。
| 送信する項目 | 送信しない項目 |
|---|---|
| 記事タイトル(日本語) | 店舗・運営のメールアドレス/パスワード |
| 記事本文(日本語) | 店舗の住所・営業時間・地図リンク |
| — | 記事写真・動画 |
| — | 行動イベントログ・IP アドレス |
送信はサーバー内部で行われ、認証キーはサーバー側の環境変数にのみ保持する。ブラウザから外部へ記事が送信されることはない 。
記事本文に店主の氏名・経歴などの記述が含まれる場合、この送信は個人情報の取扱いを含むことになる。その場合の本人は店舗の関係者であり、旅行客ではない。
8.2 翻訳事業者の位置づけ(未選定)
翻訳 API のベンダーは本ドラフト作成時点で選定されていない(DeepL / OpenAI / Gemini 等を比較検討中)。ベンダーの所在国と処理場所によって適用される規律が変わるため、以下のとおり場合分けし、選定後に確定した内容を本条に反映する。
| 場合 | 位置づけ | 必要な対応 |
|---|---|---|
| (i) 国内事業者が国内で処理する | 第25条の委託 | 委託契約の締結と委託先の監督のみ。第28条は適用されない |
| (ii) 外国にある事業者だが、個人情報保護委員会規則が定める指定国に所在する | 第28条の「外国」から除外される取扱い(指定国の範囲は要確認) | 第25条の委託先監督に準じた対応 |
| (iii) 上記以外の外国にある事業者 | **第28条(外国にある第三者への提供の制限)**の対象 | ①本人の同意(移転先国の制度等の情報提供を伴う)または ②相当措置を継続的に講ずるための体制の整備(契約条項・認証等)のいずれかが必要 |
(iii) に該当する場合、本人は店舗の関係者であるため、同意の取得は旅行客ではなく店舗に対して行う設計が適切である。具体的には、店舗向け掲載規約への記載および記事入稿時の説明により対応することを想定する。この設計の適否は。
Article 8 (Transfers abroad and AI translation) — Articles submitted in Japanese are translated into English by an external AI translation API. Only the article title and body are sent. Account credentials, shop addresses, photographs, activity logs and IP addresses are not sent. The request is made from our server; the API key never reaches your browser. The translation vendor has not yet been chosen. Depending on where the vendor is established, this may be treated as outsourcing under APPI Article 25 or as a cross-border transfer under APPI Article 28, which requires either informed consent or a contractual framework ensuring equivalent protection. Because the person described in an article is usually someone connected with the shop, any consent would be obtained from the shop, not from travellers. This will be finalised when the vendor is selected.
第9条(安全管理措置)
当社は、個人情報保護法**第23条(安全管理措置)**に基づき、取り扱う個人データの漏えい・滅失・毀損の防止その他の安全管理のため、次の措置を講じる。
| 区分 | 措置の概要 |
|---|---|
| 組織的安全管理措置 | 本サービスの運営は運営者1名の体制で行い、取扱権限を運営アカウントに限定する 。運営アカウントは無効化フラグにより権限を停止できる |
| 人的安全管理措置 | 個人情報保護法**第24条(従業者の監督)**に基づき、取扱者に対して守秘義務および取扱ルールを課す。(現時点では運営者1名のため運用規程は未整備) |
| 物理的安全管理措置 | 自社でサーバーを設置せず、クラウド事業者の設備を利用する |
| 技術的安全管理措置 | ①データベースの行単位アクセス制御(RLS)を全テーブルで有効化し、アプリケーション側の権限確認と併せた二層で認可を行う ②通信の暗号化(HTTPS の常時使用) ③パスワードのハッシュ化保存 ④認証キーは環境変数で管理し、リポジトリ・ドキュメントに平文で記載しない ⑤公開エンドポイントのレート制限 ⑥コンテンツセキュリティポリシー等のセキュリティヘッダーの設定 |
| 委託先の監督 | 第25条に基づき、委託先の選定基準を定め、契約により取扱いを制限する(第7条・第8条) |
| 外的環境の把握 | 本サービスはクラウド事業者(データベース・ホスティング)の設備上で稼働する。**これらのサービスのデータ保存先リージョン(国)は、本ドラフト作成時点の設計文書に記載がなく未確認である。**外国で個人データを取り扱う場合は当該国の制度を把握したうえで本条に記載する |
Article 9 (Security measures) — Under APPI Article 23 we take organisational, personnel, physical and technical measures: access is limited to the single operator account, which can be disabled; we use cloud infrastructure rather than our own servers; database access is restricted row by row and checked again in the application; traffic is encrypted with HTTPS; passwords are stored hashed; API keys live only in server-side environment variables; the public endpoint is rate-limited; and security headers are set. The country in which our cloud providers store the data has not yet been confirmed and will be documented here before publication, as required for the "understanding of the external environment" element of Article 23.
第10条(開示・訂正・利用停止等の請求)
本人は、当社が保有する保有個人データについて、個人情報保護法に基づき次の請求を行うことができる。
| 請求の種類 | 根拠条文 |
|---|---|
| 保有個人データに関する事項(利用目的等)の通知 | 第32条(保有個人データに関する事項の公表等) |
| 開示(第三者提供記録の開示を含む) | 第33条(開示) |
| 訂正・追加・削除 | 第34条(訂正等) |
| 利用停止・消去・第三者提供の停止 | 第35条(利用停止等) |
手続
- 第12条のメールアドレス宛に、請求の内容を記載して連絡する
- 当社は、なりすまし防止のため本人確認を行う。具体的な確認方法(登録済みメールアドレスからの送信を確認する等)は未整備であり、公開前に定める
- 当社は、請求内容を確認のうえ、遅滞なく回答する
- 請求の全部または一部に応じない場合は、個人情報保護法**第36条(理由の説明)**に基づき、その理由を説明するよう努める
- 手数料は徴収しない(開示等の請求に係る手数料の定めの要否は)
旅行客については、当社が旅行客個人を識別する情報を保有していないため(第3条)、開示等の請求に応じるための本人の特定ができない。この点の説明の適否は。
Article 10 (Your rights: disclosure, correction and suspension) — If you hold a shop or operator account, you may ask us to tell you the purposes for which we hold your data, to disclose it, to correct, add to or delete it, or to stop using it or providing it to others. These rights arise under APPI Articles 32 to 35. Write to the address in Article 12; we will verify your identity before responding, and if we cannot grant a request we will explain why, as APPI Article 36 requires. No fee is charged. Because we hold no information that identifies individual travellers, we are not able to link such a request to a traveller.
第11条(漏えい等が発生した場合)
個人データの漏えい・滅失・毀損その他の個人データの安全の確保に係る事態が生じた場合、当社は個人情報保護法**第26条(漏えい等の報告等)**に基づき、個人情報保護委員会への報告および本人への通知を行う。報告・通知の対象となる事態の範囲および期限の詳細については。
社内での検知から報告までの手順(連絡体制・記録様式)は未整備であり、公開前に定める。
Article 11 (Data breaches) — If personal data is leaked, lost or damaged, we will report the incident to the Personal Information Protection Commission and notify the people affected, as APPI Article 26 requires. Our internal incident-handling procedure is still to be written.
第12条(苦情・お問い合わせ窓口)
本ポリシーおよび個人情報の取扱いに関するお問い合わせ・苦情は、本サービスのフッターに掲載するメールアドレス宛に受け付ける。当社は、個人情報保護法**第40条(個人情報取扱事業者による苦情の処理)**に基づき、苦情の適切かつ迅速な処理に努める。
- 掲載するメールアドレスは yoshihiro.taguchi@heroes-tokyo.asia(オーナー確定 2026-07-28)。実装はフッターの
ADMIN_CONTACT_EMAILで出し分ける - 問い合わせ管理機能(フォーム・チケット管理)は本サービスの機能に含まれず、フッターへのメールアドレス記載のみとする
Article 12 (Contact and complaints) — Questions and complaints about this Policy or about how we handle personal information may be sent to the email address shown in the footer of the Service. We aim to handle complaints promptly and appropriately, as APPI Article 40 requires. The address is yoshihiro.taguchi@heroes-tokyo.asia (fixed 2026-07-28). There is no contact form; email is the only channel.
第13条(EU および英国の居住者の方へ)
本サービスは日本国内(浅草)を訪れる旅行客に向けたものであり、当社は日本法人であって EU 域内に拠点を有しない。もっとも、渡航前に EU または英国から本サービスを閲覧する利用者が存在しうることから、当社は EU 一般データ保護規則(GDPR)および英国 GDPR の適用可能性を検討している。適用の有無についての最終的な判断は専門家によるレビューを経て確定する。
GDPR が適用される場合の取扱いは次のとおり整理している。
- 処理の法的根拠: 店舗アカウント情報は契約の履行および正当な利益、行動イベントログは(仮にこれが個人データに当たる場合には)GDPR 第6条1項(f)「the legitimate interests pursued by the controller」による。同意を根拠とする処理は現時点で予定していないが、Cookie 同意が必要と判断される場合は同項(a)「the data subject has given consent」による
- データ主体の権利: アクセス・訂正・消去・処理の制限・異議・データポータビリティの各権利(GDPR 第3章。個別の条番号は本ドラフトでは未確認)。行使は第12条の窓口から受け付ける
- EU 域内代理人: GDPR 第27条1項は「Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union」と定める。もっとも同条2項(a)は、処理が「occasional」であり、大規模な特別カテゴリの処理を含まず、かつ自然人の権利・自由に対するリスクを生じるおそれが低い場合を義務の対象外とする。本サービスがこの例外に該当するかは
- 監督機関への苦情申立て: EU / 英国の居住者は、居住地の監督機関に苦情を申し立てる権利を有する
Article 13 (For residents of the EU and the UK) — The Service is aimed at travellers visiting Asakusa in Japan, and we have no establishment in the EU. Because people may read the Service from the EU or the UK before travelling, we are assessing whether the GDPR and UK GDPR apply; that assessment is not final and is subject to legal review. If they do apply: we rely on the performance of a contract and on our legitimate interests under Article 6(1)(f) — activity logs, if they were to count as personal data, would rest on legitimate interests — and we would rely on consent under Article 6(1)(a) only if a cookie banner proves necessary. You would have the rights of access, rectification, erasure, restriction, objection and portability set out in Chapter III of the GDPR; write to the address in Article 12 to exercise them. Whether we must appoint an EU representative under Article 27 is still being assessed, as the exemption in Article 27(2)(a) may apply. You may also complain to your local supervisory authority.
第14条(本ポリシーの改定)
当社は本ポリシーを変更することがある。重要な変更を行う場合は、本サービス上での掲示により周知する。変更後のポリシーは、本サービス上に掲示した時点から効力を生じる。本ポリシーの末尾に最終更新日を記載する。
Article 14 (Changes to this Policy) — We may revise this Policy. Significant changes will be announced on the Service, and the revised Policy takes effect when posted. The date of the most recent update is shown at the end.