Openisec Privacy Policy

Openisec is an open-source initiative designed to support decision accountability and organizational knowledge creation when using AI, large language models, and AI agents.

In this Privacy Policy, "Openisec Operator" means any individual, group, organization, or legal entity that develops, provides, operates, maintains, supports, manages the community for, or provides related services in connection with Openisec.

At present, Affection LLC is the operating entity of Openisec and the entity handling personal information in connection with Openisec.

The Openisec Operator will handle users’ personal information obtained in connection with the provision, operation, improvement, and related activities of Openisec appropriately, in accordance with the Act on the Protection of Personal Information of Japan and other applicable laws, regulations, and guidelines of Japan.

Unless expressly stated otherwise, Openisec is not intended to comply with the EU General Data Protection Regulation (GDPR) or other personal data protection laws outside Japan.

1. Information We Collect

The Openisec Operator may collect the following information in connection with the provision of Openisec:

  • Registration information, such as name, company name, department, title, email address, and other account information
  • Login information, authentication information, and account settings
  • User data entered into Openisec, including decision topics, background information, considerations, reasons for decisions, target dates, logs, and other usage data
  • Technical information, such as service usage date and time, access logs, IP address, browser information, device information, cookies, and similar technologies
  • Information related to inquiries, feedback, support requests, and related communications
  • Information related to applications for seminars, newsletters, product updates, or other communications

2. Purposes of Use

The Openisec Operator uses the information collected for the following purposes:

  • To register accounts, verify users, authenticate users, and manage the use of Openisec
  • To provide Openisec features, including decision support, record management, history display, and related services
  • To maintain, operate, troubleshoot, secure, and prevent unauthorized use of Openisec
  • To analyze usage, improve functionality, enhance quality, develop new features, and improve user experience
  • To respond to inquiries, requests, complaints, consultations, and support needs from users
  • To provide important notices, including changes to terms, security notifications, and maintenance information
  • To provide information about Openisec, seminars, events, product updates, and related information where the user has consented to receive such communications
  • To comply with laws, regulations, guidelines, contractual obligations, or requests from public authorities
  • To use input information, usage data, logs, and other information, after processing or aggregating them so that individuals cannot be identified, for Openisec improvement, research, development, statistical analysis, explanatory materials, public materials, or community activities

3. Handling of Information in AI Processing

Openisec may use information entered by users to perform AI-based organization, analysis, recommendation generation, and other forms of decision support.

The Openisec Operator will handle information used for AI processing to the extent necessary for providing Openisec, improving quality, maintaining security, preventing unauthorized use, conducting research and development, and improving features. Users are responsible for ensuring that they input only information that they or their organization have the right and authority to use. Users should avoid entering unnecessary personal information, confidential information, authentication credentials, passwords, API keys, private keys, or other sensitive information.

4. Provision to Third Parties

Except for information that has been processed or aggregated so that individuals cannot be identified, the Openisec Operator will not provide users’ personal data to third parties except in the following cases:

  • Where the user has given consent
  • Where required or permitted by law
  • Where necessary to protect the life, body, or property of a person and it is difficult to obtain the user’s consent
  • Where particularly necessary for improving public health or promoting the sound growth of children and it is difficult to obtain the user’s consent
  • Where necessary to cooperate with a national government agency, local public authority, or a person entrusted by them in performing legally prescribed duties, and obtaining the user’s consent may interfere with the performance of such duties
  • Where handling of personal data is entrusted to a third party within the scope necessary to achieve the purposes of use
  • Where personal data is transferred due to business succession, merger, company split, business transfer, or similar transaction

5. Outsourcing and Cross-Border Handling

The Openisec Operator may use external services or service providers for the provision, operation, maintenance, authentication, email delivery, data storage, AI processing, log analysis, inquiry handling, and other activities related to Openisec.

Where the Openisec Operator uses service providers located outside Japan, or servers or systems located outside Japan, and personal data is handled outside Japan, the Openisec Operator will, to the extent reasonably practicable, review matters such as the country or region where the service provider is located, the applicable personal information protection framework, security management practices, contractual terms, and other reasonably verifiable matters, and will make efforts to ensure that user information is handled appropriately in accordance with the Act on the Protection of Personal Information of Japan and other applicable laws, regulations, and guidelines of Japan.

6. Security Measures

The Openisec Operator will make efforts to take necessary and appropriate security measures to prevent leakage, loss, damage, unauthorized access, or unauthorized use of personal data, taking into account the operational status of Openisec, the nature of the information handled, and the external services used.

7. Retention Period and Data Retention

The Openisec Operator may retain user information for the period necessary to achieve the purposes of use, or for the period reasonably necessary for legal, contractual, accounting, audit, dispute resolution, or other legitimate purposes.

The Openisec Operator does not guarantee the continuous retention, preservation, restoration, backup, export, or availability of any information entered, stored, or recorded in Openisec. The Openisec Operator may change the retention period, retention method, scope of retained data, deletion method, or data management policy for operational, technical, security, legal, or other reasonable reasons.

Information whose retention period has expired or that is no longer necessary for the purposes of use may be deleted, anonymized, aggregated, or suspended from use by the Openisec Operator in an appropriate manner at its discretion.

8. Requests for Disclosure, Correction, Suspension of Use, and Other Rights

Users may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties of their retained personal data in accordance with applicable law. Users who wish to make such a request should contact the Openisec Operator through the designated contact method. The Openisec Operator will verify the identity of the requester and respond within a reasonable scope in accordance with applicable law.

9. Use of Cookies and Similar Technologies

The Openisec Operator may use cookies and similar technologies to improve convenience, analyze usage, maintain security, prevent unauthorized use, and improve Openisec. Users may restrict the use of cookies through their browser settings; however, some Openisec features may not function properly if cookies are disabled.

10. Changes to This Privacy Policy

The Openisec Operator may update this Privacy Policy due to changes in laws and regulations, changes to Openisec, operational needs, or other reasons. In the case of material changes, the Openisec Operator will notify users by displaying a notice on Openisec, sending an email, or using another appropriate method.

11. Contact

Openisec Operator: Affection LLC

Contact: admin@openisec.com