Data Handling and International Transfers
We do not choose a tool first and fit your data around it. We begin with the work, the minimum information it needs, and the people who must remain in control.
External AI, cloud services, paid tools, and overseas processing are never assumed. We explain the provider, purpose, cost, and storage location, then use only what has been agreed in writing.
1. Roles and scope
Before work begins, we identify the data, purpose, storage, access, subprocessors, retention, and the likely controller or processor roles. We do not claim blanket GDPR or SCC compliance before the actual project and transfer route are known.
2. Data minimisation
- We do not ask for personal or confidential information the work does not need.
- Credentials are kept out of ordinary email, chat, deliverables, and logs.
- Anonymous or test data is preferred whenever it can prove the same thing.
3. External services
Where a service is needed, we review its terms, data use, model-training policy, storage region, deletion method, and cost. Confidential client information is not placed in public AI tools without written permission.
4. International transfers
If information will be stored or processed outside Japan, we identify the destination, recipient, purpose, applicable law, and contractual safeguards for that project. EU- or UK-related transfers may require specialist legal review.
5. Security and incidents
Controls are proportionate to the work and may include least privilege, separate secret storage, backups, change records, and recovery steps. If an incident is suspected, new processing is paused while the scope and evidence are checked.
6. Contract priority
This page states our baseline. A signed service agreement, data-processing agreement, and mandatory law take priority where they apply.
Last reviewed: 3 August 2026
