Privacy Policy
Karma Intelligence Co., Ltd. (“we”, “us” or “our”) has established this Privacy Policy (this “Policy”) in accordance with the Act on the Protection of Personal Information of Japan and other applicable laws and regulations, and endeavours to handle personal data appropriately.
1. Name, Address and Representative of the Company
Name: Karma Intelligence Co., Ltd.
Registered address: 1-6-13 Kyobashi, Chuo-ku, Tokyo, Japan
Representative: Yuya Kuratomi, Representative Director
2. Personal Data We Collect
We collect personal data to the extent necessary for the operation of our business, by lawful and fair means. The main categories are as follows:
- Information you provide when making an enquiry or request (company name, department, name, email address, telephone number and the contents of your enquiry);
- Information provided in connection with the conclusion or performance of a contract for our services (names, affiliations, job titles and contact details of the personnel of our clients and business partners);
- Information provided in connection with seminars, webinars and training (names, affiliations, contact details and attendance records of participants);
- Information obtained during meetings, interviews and hearings;
- Information provided in connection with recruitment (information contained in CVs, work histories and other application materials); and
- Information collected automatically when you use our website (cookies, access logs, IP addresses and similar information).
Where we do not obtain personal data directly from you, we obtain it from your employer or the organisation you represent, from the organisers or co-hosts of events, from recruitment agencies, or from publicly available sources such as corporate websites and public registers.
In addition, in the course of pre-employment screening, we may receive information about individuals other than the applicant from the applicant themselves.
3. Purposes of Use
We use personal data for the purposes set out below and, save where permitted by law, do not use it beyond the purposes notified or published in advance.
- (1) Responding to enquiries, requests and consultations, and managing the related records.
- (2) Performing our services, including security consulting and audit, security assessment and testing, security monitoring, operations and incident response, the development and provision of security-related software and services, and security education and training.
- (3) Concluding and performing contracts, invoicing, settlement and other transaction management.
- (4) Planning, operating and providing information about seminars, webinars, training and information services, and managing participants.
- (5) Providing, operating and improving our website and our services, including web analytics, security measures and usability improvements.
- (6) Providing information about services and events offered by us or our partners, and conducting marketing activities.
- (7) Excluding anti-social forces and taking other measures required under applicable laws, regulations and guidelines.
- (8) Sending greetings and seasonal correspondence.
- (9) Disclosing personal data to third parties in the manner described in this Policy.
- (10) Exercising rights and performing obligations under contract or applicable law, and dealing with related matters.
- (11) Otherwise conducting transactions with you appropriately and smoothly.
- (12) Recruitment activities (including screening, responding to applicants, communications and the management of application materials), and, for applicants for certain positions, screening conducted to verify their suitability and trustworthiness and to establish our information management arrangements following their employment (including checks on information about individuals other than the applicant).
4. Personal Data Processed on Behalf of Our Clients
In performing security assessment and testing, security monitoring and operations, incident response support, digital forensics and similar services, we may handle information contained in our clients’ systems, including logs, communication records and other data which may contain personal data. In relation to such data we act on behalf of and under the instructions of our client, as a processor for the purposes of the GDPR and as an entrusted party for the purposes of the APPI. We handle such data only to the extent necessary to perform the services, manage it in accordance with our contract with the client and applicable law, and securely delete or return it at the end of the contract in accordance with its terms. If you wish to exercise rights in relation to data processed in this context, please contact the relevant client, which is the controller of that data.
5. Security Measures
We implement organisational, human, physical and technical measures to prevent the leakage, loss or damage of personal data. These include the classification of information according to its confidentiality and the adoption of handling rules for each class, encryption of stored and transmitted data using industry-standard methods, access control based on the principle of least privilege and multi-factor authentication, and the maintenance of backups. Personal data is, in principle, stored on servers located in Japan. We supervise our employees appropriately in relation to the handling of personal data and, where we entrust the handling of personal data to a service provider, we supervise that provider so that the data is managed appropriately.
6. Disclosure of Personal Data to Third Parties
We do not provide personal data to third parties without your prior consent, except in the cases set out below.
- (1) where required by laws or regulations;
- (2) where urgently necessary for the protection of the life, body or property of a person and it is difficult to obtain your consent;
- (3) where particularly necessary for the improvement of public health and it is difficult to obtain your consent;
- (4) where it is necessary to cooperate with a national or local government body, or a party entrusted by such a body, in performing duties prescribed by law, and obtaining your consent is likely to impede the performance of those duties; or
- (5) where the provision is otherwise permitted by applicable law.
7. Service Providers
In order to conduct our business smoothly, we may entrust all or part of our operations to external service providers and provide them with personal data as necessary. Such providers include:
- providers of cloud services, hosting and enquiry-form services (our enquiry form is operated using an external form service, and the information you enter is received and stored by that provider);
- IT vendors responsible for website operation, system maintenance, infrastructure operation and information security;
- professional advisers providing legal, financial, tax and human resources services (attorneys, certified public accountants, tax accountants and labour and social security attorneys);
- service providers responsible for email distribution, event operation and marketing support; and
- recruitment agencies and similar providers engaged in connection with our recruitment activities.
We supervise such providers appropriately and manage them so that personal data is handled securely.
8. Requests for Disclosure of Retained Personal Data
Where you or your authorised representative make any of the following requests (including any other request under the APPI) in relation to retained personal data we hold, we will verify that you are the individual concerned, or their representative, in accordance with our prescribed procedure and respond in accordance with the APPI.
- (1) notification of the purpose of use;
- (2) disclosure (the contents of the retained personal data we hold);
- (3) correction, addition or deletion;
- (4) cessation of use or erasure; and
- (5) cessation of provision to third parties.
To make a request, please contact us at the address set out in section 9 below.
9. Contact
If you have any questions or complaints regarding our handling of personal data, or wish to make a request under section 8, please contact us at privacy@karmaintelligence.com.
10. Cookies
The Website uses cookies and similar technologies for purposes including improving our services, improving convenience for users and analysing usage trends.
For details, please see our Cookie Policy.
11. Changes to This Policy
We may amend this Policy in response to changes in applicable laws, our business or otherwise. Where we do so, we will promptly publish the amended Policy on our website. Where the change is material, we will notify or otherwise inform you by appropriate means.
12. Individuals Located in the EEA and the United Kingdom
Where the EU General Data Protection Regulation (the “GDPR”) or the UK GDPR applies to our processing, this section applies in addition to sections 1 to 11 above and prevails in the event of any conflict.
(1) Legal Bases for Processing
Where you interact with us on behalf of your employer or another organisation and are not yourself a party, or a prospective party, to a contract with us, we rely on our legitimate interests in responding to enquiries, providing and administering our services to our clients, maintaining our business relationships, complying with the laws to which we are subject, keeping our systems and information secure, and establishing, exercising or defending legal claims.
Where you are personally a party, or a prospective party, to a contract with us, including where you apply to us for employment, we rely on the performance of that contract or on steps taken at your request before entering into it.
Where we are subject to an obligation under the law of the European Union, a Member State or the United Kingdom, we rely on compliance with that legal obligation.
We rely on your consent for non-essential cookies and for electronic marketing. You may withdraw your consent at any time, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
(2) Provision of Your Personal Data
Information marked as required on our forms is necessary for us to respond to your enquiry or to conclude and perform the relevant contract; other information is optional. If you do not provide the required information, we may be unable to respond to your enquiry or to conclude or perform the contract.
(3) International Transfers of Personal Data
Information collected through the analytics services described in our Cookie Policy is transmitted to the relevant service provider in the United States. Where we provide personal data to a service provider located in a country that has not been recognised as providing an adequate level of protection, we put in place the standard contractual clauses approved by the European Commission or the equivalent safeguards recognised under the UK GDPR. You may obtain a copy of those safeguards by contacting us at the address set out in section 9.
(4) Retention of Personal Data
We retain personal data only for as long as necessary to achieve the purposes described in this Policy. In determining the retention period, we take into account the nature of the data, the purpose for which it was obtained, the duration of our relationship with you or your organisation, and any retention period required under applicable law.
(5) Your Rights
Subject to the conditions and exceptions in applicable law, in addition to the rights set out in section 8 you have the right to request access to your personal data, its rectification or erasure, the restriction of processing and data portability, and the right to object to processing carried out on the basis of our legitimate interests and to processing for direct marketing purposes.
(6) Complaints to a Supervisory Authority
You have the right to lodge a complaint with the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
Effective date: September 16, 2026