Privacy Policy
600 Inc.
600 Inc. (the “Company”) sets out the following privacy policy (this “Policy”) regarding the handling of privacy information in the services it provides on this website (the “Service”).
Article 1 Privacy information
Among privacy information, “personal information” means personal information as defined in the Act on the Protection of Personal Information: information about a living individual by which a specific individual can be identified through the name, date of birth, address, telephone number, contact details or other descriptions contained in it. “History and characteristic information” means privacy information other than the personal information defined above, such as the services used and products purchased, the history of pages and advertisements viewed, search keywords entered, dates and times of use, methods of use, usage environment, postal code, gender, occupation, age, the user’s IP address, cookie information, location information and device identifiers.
Article 2 How privacy information is collected
When a user registers, the Company may ask for personal information such as name, date of birth, address, telephone number, email address, bank account number, credit card number and driver’s licence number. The Company may also collect transaction records containing the user’s personal information made between the user and partners, and payment-related information, from the Company’s partners (including information providers, advertisers and advertising destinations; “Partners”). The Company collects history and characteristic information about the user — the services and software used, products purchased, the history of pages and advertisements viewed, search keywords, dates and times of use, methods of use, usage environment (including, when used through a mobile device, that device’s communication status and settings), IP address, cookie information, location information and device identifiers — when the user uses the services of the Company or its Partners or views their pages.
Article 3 Purposes of collecting and using personal information
The Company collects and uses personal information for the following purposes.
- (1) To display registration details such as name, address, contact details and payment method, the services used and products purchased, and their charges, so that users can view and correct their own registration details and view their usage.
- (2) To use email addresses for notices and communication, and to use contact details such as name and address to ship products to users and contact them as needed.
- (3) To verify a user’s identity using information such as name, date of birth, address, telephone number, bank account number, credit card number, driver’s licence number and the delivery result of certified mail.
- (4) To bill users, using payment-related information such as the names and quantities of products purchased, the type, period and count of services used, the amount billed, name, address, bank account number and credit card number.
- (5) To make data entry easier for users by displaying information registered with the Company on input screens, and to transfer it to other services (including those provided by Partners) at the user’s instruction.
- (6) To refuse use by users who have violated the Service’s terms of use — for example by delaying payment or causing damage to third parties — or who attempt to use the Service for improper or unlawful purposes, using the manner of use and identifying information such as name and address.
- (7) To respond to enquiries from users, using the content of the enquiry, billing-related information and other information the Company needs to provide the Service, as well as the user’s usage and contact details.
- (8) Purposes incidental to the above.
Article 4 Provision of personal information to third parties
Except in the following cases, the Company does not provide personal information to third parties without the user’s prior consent, save where permitted by the Act on the Protection of Personal Information or other laws.
- (1) Where required by law.
- (2) Where necessary to protect a person’s life, body or property and it is difficult to obtain the person’s consent.
- (3) Where especially necessary to improve public health or promote the sound upbringing of children and it is difficult to obtain the person’s consent.
- (4) Where it is necessary to cooperate with a national agency, a local government or a party entrusted by them in performing duties prescribed by law, and obtaining the person’s consent is likely to impede those duties.
- (5) Where the following matters have been announced or made public in advance:
- that the purposes of use include provision to third parties;
- the items of data provided to third parties;
- the means or method of provision to third parties;
- that provision of personal information to third parties will be stopped at the person’s request.
Notwithstanding the preceding paragraph, the following cases do not constitute provision to a third party.
- (5-1) Where the Company entrusts all or part of the handling of personal information within the scope necessary to achieve the purposes of use.
- (5-2) Where personal information is provided in connection with a business succession due to a merger or other cause.
- (5-3) Where personal information is used jointly with a specific party, and that fact, the items of personal information used jointly, the scope of the joint users, their purposes of use and the name of the party responsible for managing the personal information have been notified to the person in advance or placed where the person can easily learn of them.
Article 5 Disclosure of personal information
When a person requests disclosure of their personal information, the Company discloses it to the person without delay. However, where disclosure would fall under any of the following, the Company may decline to disclose all or part of it, and will notify the person without delay of a decision not to disclose. A fee of 1,000 yen per request is charged for disclosure of personal information.
- (1) Where it is likely to harm the life, body, property or other rights or interests of the person or a third party.
- (2) Where it is likely to seriously impede the proper conduct of the Company’s business.
- (3) Where it would otherwise violate laws or regulations.
Notwithstanding the preceding paragraph, information other than personal information, such as history and characteristic information, is in principle not disclosed.
Article 6 Correction and deletion of personal information
Where personal information held by the Company about a user is incorrect, the user may request that the Company correct or delete it through the procedure the Company prescribes. Where the Company receives such a request and determines that it must be granted, it corrects or deletes the personal information without delay and notifies the user.
Article 7 Suspension of use of personal information
Where a person requests that the Company suspend the use of or erase their personal information (“suspension of use”) on the grounds that it is being handled beyond the scope of the purposes of use or was obtained by improper means, the Company promptly conducts the necessary investigation, suspends the use of the personal information based on the result and notifies the person. However, where suspension of use would involve substantial cost or is otherwise difficult, and alternative measures necessary to protect the person’s rights and interests can be taken, the Company takes those alternative measures.
Article 8 Changes to this Privacy Policy
The content of this Policy may be changed without notice to users. Unless the Company provides otherwise, the changed privacy policy takes effect from the time it is posted on this website.
Article 9 Handling of information obtained from Google APIs
At the user's direction, the Service imports files from Google Drive and Google Sheets. D2B's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information obtained this way is stored in that user's own workbook and is used solely to carry out the analyses that user requests. It is not disclosed to other users, not sold or transferred to third parties for their own purposes, and not used to train machine-learning models.
A user may revoke the Service's access at any time from the permissions settings of their Google Account.
Article 10 Security measures for personal information and user data
The Company takes the following measures to protect personal information, and the files and data users upload to the Service or import through Google APIs ("User Data"), against leakage, loss and damage.
(1) Encryption in transit: communication between users and the Service, and between the systems that make up the Service, is encrypted with TLS.
(2) Encryption at rest: User Data, databases and their backups are encrypted at rest (AES-256).
(3) Access control: User Data is isolated per workspace and is accessible only to that workspace's members. API keys are issued with limited scopes and can be revoked by the user at any time. Access by Company staff is limited to the minimum needed for operations and support, and is logged.
(4) Audit logging: access to User Data is recorded in audit logs and monitored for unauthorized access.
(5) Retention and deletion: users may delete a workbook or their account at any time. Deleted User Data, including backups and earlier versions, is erased within 90 days of deletion.
(6) Incident response: if personal information or User Data is leaked or otherwise compromised, the Company notifies affected users without delay and reports to the relevant authorities as required by law.
Article 11 Third-party services used by the AI features
To carry out the analyses users request, the Service uses third-party AI services that provide large language models. To the extent needed for an analysis, parts of User Data (including information obtained from Google APIs) — such as table structures, data excerpts and the user's instructions — are sent to those services.
The Company uses only AI service providers whose agreements or terms with the Company state that the data sent is not used to train or improve their models. The current provider is OpenRouter (a relay to several model providers; every request is configured to exclude providers that may store the data sent or use it for training).
The Company does not use, transfer or sell User Data — raw, aggregated or derived — to create, train or improve foundational or generalized machine-learning or AI models.
For operating and troubleshooting the Service, the Company may store records of its communication with AI services in a third-party monitoring service (LangSmith). Those records are used only for troubleshooting and quality review, never for model training.
The Company does not operate self-hosted AI models for the Service. This Policy will be updated if the providers above change or others are added.
Article 12 Contact
Enquiries about this Policy should be directed to the contact below.
600 Inc., Personal Information Enquiries — mail: hello@600.jp
End of document