cloud-itonamisafety first
ProductOverviewSolutionsAppsTrust & statusGet accessGet startedSign inPartners

cloud-itonami — Privacy Policy

Governing law: Japan

Effective / last updated: 2026-07-24

This Privacy Policy explains how the cloud-itonami service ("the Service") handles personal data. cloud-itonami is a B2B business operating system. In most cases the Service processes personal data contained in a Customer's business records as a processor on the Customer's behalf; the Customer is the controller for that data. The operator acts as controller only for limited account and operational data.

Data controller / business operator: AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996). Gftd Japan 株式会社 (Gftd Japan K.K.) acts as infrastructure processor for Cloudflare/kotobase hosting and related infrastructure, on the operator's documented instructions, and is not the controller. AWAI Network applies APPI obligations to its handling of personal information connected with services supplied to persons in Japan, including where APPI applies extraterritorially.

1. Data We Collect

  • Customer Data (processed on behalf of the Customer). Business facts that the Customer ingests or generates in its tenant graph ({org}/{repo}), including mail, calendar, documents, Teams/chat, CRM, contracts, invoices and billing, financial/accounting records, HR/people records, and PLM/ERP/MES records, together with derived activities, decisions, proposed and executed effects, artifacts and append-only audit events. This may contain personal data about the Customer's own staff, customers and counterparties.
  • Account and tenant data. Organizations (itonami.org), repositories (itonami.repo), members (itonami.member) and permissions (itonami.permission).
  • Authentication data. Operator tokens and CACAO/did:key actor credentials.
  • Operational/technical data. Standard web/edge request logs (e.g. IP address, timestamps, request paths) generated by Cloudflare for security, abuse-prevention and reliability purposes. The Service does not use third-party advertising or cross-site tracking analytics.
  • Research participant data (operator as controller). When the Service runs a usability study on its research panel (ADR-0035), panellists are screened by occupation, industry and region, are identified only by an opaque participant reference, and consent at /study/ before anything is recorded. For consenting participants, for the duration of that session only, we record: pages visited on the Service; the buttons, links and controls clicked, identified by their visible label and element identity; which form fields were focused and whether they were left empty; time on page and scroll depth; any JavaScript error encountered; and the participant's own post-task answers.

We do not record the contents of any input, textarea or editable field, and there is no screen, camera, microphone or keystroke recording. The participant reference format cannot contain an @ or a ., and the panel schema has nowhere to store a name, e-mail, phone number, address, date of birth or national identifier. We therefore hold no contact details for a panellist and cannot re-identify one from this data alone.

No cookies are set for this purpose and nothing is shared with any advertising network.

2. Purposes of Processing

  • To provide, operate and secure the Service.
  • To run the activity → decision → effect → audit flow and agent proposals for the Customer.
  • To maintain the audit ledger for accountability and traceability.
  • To manage accounts, tenants, seats and permissions.
  • To evaluate and improve the usability of the Service through consented research studies, and to verify and pay research participants.
  • To comply with legal obligations.

3. Legal Bases (GDPR, where applicable)

  • For Customer Data processed as a processor: the Customer's legal basis as controller; the operator processes per the Customer's instructions and the DPA.
  • For account/operational data as controller: performance of a contract (Art. 6(1)(b)) and legitimate interests in operating and securing the Service (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)).
  • For research participant data as controller: consent (Art. 6(1)(a)), given explicitly at /study/ before any recording begins and withdrawable at any time. Withdrawal never affects a participant's payment — work already done is owed regardless.

4. Sharing and Disclosure

We do not sell personal data. We share personal data only with subprocessors (Section 5), within the Customer's own organization per its permission model, and where required by law or to protect rights and safety.

5. Subprocessors

  • Cloudflare, Inc. — Pages/Workers/KV hosting and edge network (United States / global edge).
  • net-kotobase (kotobase.net) — business-state graph persistence, operated within the same corporate group; see kotobase.net's own privacy documentation.
  • Stripe, Inc. — payment processing, where Customer subscribes to a paid plan (United States).
  • Resend — transactional/notification email delivery, where enabled (United States).
  • External recruitment panels, where a study sources participants from one rather than from the Service's own panel. Such a panel holds the participant's identity and pays them; the Service receives only an opaque participant reference. No participant contact detail is transferred to the Service in either direction.

This list may be updated from time to time; material changes will be notified per Section 12.

6. International Transfers

Customer Data may be stored and processed on infrastructure located outside the Customer's country (e.g. Cloudflare's global edge and the kotobase PDS, Stripe's and Resend's respective US-based infrastructure). Where GDPR/UK GDPR applies to a transfer outside the EEA/UK, the operator relies on the European Commission's Standard Contractual Clauses (or successor mechanism) as incorporated into the relevant subprocessor's own data processing terms.

7. Retention

Customer Data other than the audit ledger is retained for the term of the Customer's use plus a thirty (30)-day export window, then deleted or irrecoverably de-identified within a further thirty (30) days. Audit-ledger records are retained for the term of use and for seven (7) years following termination, or such longer period as required by applicable law (see Terms of Service Section 5.2), for legal, accounting and dispute-resolution purposes.

Research participant data is retained for ninety (90) days and then expires automatically. A participant may request earlier erasure at any time, with no reason required and no effect on their payment; on receipt we delete every record held against their participant reference. Because the panel schema holds no contact details, erasure is complete rather than partial — there is no residual profile to leave behind.

8. Security

The Service uses tenant isolation (per-{org}/{repo} graph separation), capability-based permissions, and authenticated writes (operator token and/or CACAO/did:key). All traffic to the Service is encrypted in transit via TLS. Data at rest is encrypted using the security features of the underlying storage providers (Cloudflare KV/R2 and, where enabled, kotobase.net). Access to Customer Data is restricted to authenticated, capability-scoped operator tokens and CACAO/did:key credentials as described in Section 1. In the event of a security incident affecting Customer Data, the operator will notify affected Customers without undue delay after becoming aware of the incident, consistent with applicable law.

9. Your Rights

  • APPI (Japan): rights to disclosure, correction, addition or deletion, cessation of use, and cessation of third-party provision of retained personal data. Where the operator acts as a processor, requests from data subjects are generally directed to the Customer as the handling business.
  • GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection, and rights regarding automated decision-making. Note that AI output is proposal-only and executed effects require human approval (see Terms Section 4).
  • CCPA/CPRA (California): right to know, delete, correct, and opt out of sale/sharing; we do not sell personal data.

Research participants. Consent may be withdrawn at any time, and erasure requested, through the panel that recruited you — no reason required, and neither affects payment for work already done. We hold no contact details for a panellist, so a request must arrive with the participant reference; that reference is the only key by which the data can be found, and equally the only key by which it can be deleted.

To exercise rights, contact us (Section 11); if the operator is a processor, we will refer or assist the Customer as controller.

10. Children

The Service is a B2B product and is not directed to children.

11. Contact

Controller / operator: AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996). Gftd Japan 株式会社 (Gftd Japan K.K.) is the infrastructure processor, not the controller. Email: hello@gftd.co.jp. No DPO or EU-UK GDPR Art. 27 representative is designated at this time. See legal/company.md for the full operator record and open items requiring counsel/owner completion.

12. Changes

We may update this Policy and will provide notice of material changes.

AWAI Network, L.L.C.Delaware file number 10704996Infrastructure and software supplied by Gftd Japan 株式会社 (Gftd Japan K.K.)cloud-itonami is source-available under AGPL-3.0-or-later.
Contact: hello@gftd.co.jpTrust & statusPartnersTerms of ServicePrivacy PolicyData Processing AddendumOperator recordSource (AGPL)