1. Controller
This Privacy Policy describes how SAGBRAIN CORPORATION ("we", "us") processes personal data through AuditToDesk. It is written to comply with Japan's Act on Protection of Personal Information (APPI) and the EU General Data Protection Regulation (GDPR).
Registered address: 5F, Bell wood Eitai Bldg, 2-31-15, Eitai, Koto-ku, Tokyo, 135-0034, Japan
Representative: Kenya Sagara, Representative Director & CEO; Katsuhiro Kasahara, Executive Officer & COO
2. Information we collect
- Account data: email, hashed password, locale preference, plan tier.
- Scan data: URLs you submit and the resulting scan artifacts (DOM, screenshot, HTTP headers, network log).
- Usage logs: hashed IP, user-agent, action timestamps.
- Payment data: we do not store card numbers — payments are processed by Stripe.
3. Purposes
- Operating the Service (running scans, producing reports, matching agencies)
- Account management and authentication
- Billing and payment processing
- Abuse and threat detection
- Building anonymised benchmark statistics
- Legal compliance (court orders, tax filings, security incident reporting)
4. Sharing with third parties
We do not sell or rent personal data. If you choose to be introduced to a particular agency via our marketplace, we share your diagnostic results and contact details with that agency — this is your explicit, action-driven instruction to share.
5. Sub-processors
- AWS: hosting, database, storage. Primary region: ap-northeast-1 (Tokyo).
- Google Cloud (Gemini API):AI diagnosis engine (see “5-A. No use as AI training data” below)
- Stripe: payment processing
- Resend / AWS SES: transactional email
5-A. Use of Scanned Content for AI Training
AuditToDesk sends scanned website content (HTML, screenshots, and metadata) to the Google Gemini API solely for the purpose of generating your diagnosis report. This data is not used to train AI models. Retention follows Google's data retention policy, which may include temporary retention for abuse-monitoring purposes.
Google's Gemini API Terms of Service explicitly prohibit the use of API request data for training, improving, or fine-tuning AI models. AuditToDesk does not share scanned content with any other AI sub-processor for training purposes.
We do not use your scanned site content for:
- Training or fine-tuning any AI model
- Sharing with third parties for model improvement
- Any purpose beyond generating your diagnosis report
6. International transfers
The sub-processors we entrust with personal data are located in:
- Japan: AWS (ap-northeast-1, Tokyo). Account data and scan results are stored here and stay within Japan by default.
- United States: Google LLC (Gemini API / AI diagnosis), Stripe, Inc. (payments), and Resend, Inc. (transactional email).
About the US regime:the United States has no comprehensive federal data protection law comparable to Japan's APPI or the EU's GDPR. Protection comes from sector-specific federal statutes and state laws such as the California Consumer Privacy Act (CCPA/CPRA). Frameworks permitting government access to data, including section 702 of the Foreign Intelligence Surveillance Act (FISA), also apply. The US holds a GDPR adequacy decision only for organisations that participate in the EU-US Data Privacy Framework (DPF).
Safeguards we apply:we have a data processing agreement (DPA) in place with each sub-processor above, incorporating the European Commission's Standard Contractual Clauses (SCCs) or equivalent contractual protection. We also encrypt data in transit and at rest, minimise access rights, and review sub-processors periodically. Transfers of EU residents' data outside the EU likewise rely on the SCCs.
For information on foreign data protection regimes, see also the country surveys published by Japan's Personal Information Protection Commission. We will provide details of the safeguards we apply on request to the contact in Section 13.
7. Retention
- Account data: deleted within 30 days of account deletion.
- Scan artifacts: raw data (screenshots, captures) is deleted after 90 days; anonymised metadata is retained for benchmark statistics.
- Payment records: retained for 7 years to satisfy legal obligations.
- Audit logs (records of access to personal data and of administrative operations): retained for 3 years, then deleted automatically.
8. Your rights
You have the right to:
- access the personal data we hold about you;
- request correction, completion, or deletion;
- object to processing or restrict it (e.g., for direct marketing);
- data portability (GDPR residents);
- lodge a complaint with your supervisory authority.
Send requests to the contact in Section 13 — we acknowledge within 48 hours and fulfill your request within 14 days after verifying your identity.
Fees: we charge nothing for these requests — notification of purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or disclosure of third-party provision records.
10. Security
SAGBRAIN CORPORATION, which operates this service, has held ISO/IEC 27001 certification (ISMS, registration no. MSA-IS-532) since January 2022. The measures below — mapped to the categories the APPI guidelines require — are operated under that certified management system.
- Organisational: a named information security manager and personal-data handling owner under the ISMS, recorded and reviewed handling procedures, regular internal audits, a defined escalation path for incidents (including reporting to the Personal Information Protection Commission and notifying affected individuals), and data processing agreements with every sub-processor, reviewed periodically.
- Personnel: confidentiality obligations imposed on everyone handling personal data through employment contracts and internal policy, plus continuing information security training under the ISMS requirements.
- Physical: personal data is held in AWS data centres in the Tokyo region, whose physical controls (facility access, equipment management) we rely on. Our own work devices use lock management and full-disk encryption.
- Technical: tenant isolation enforced twice over — PostgreSQL row-level security plus application-layer ownership checks — encryption in transit (TLS 1.2+) and at rest (AES-256), password hashing (bcrypt), multi-factor authentication, least-privilege access control, and regular vulnerability scanning.
- Understanding the external environment:because we entrust personal data to sub-processors in the United States, our safeguards account for that country's data protection regime — see "6. International transfers".
See our Security page for the technical detail.
11. Children
The Service is not directed to anyone under 18. We do not knowingly collect personal data from minors.
12. Changes to this policy
We will notify you of material changes at least 30 days before they take effect.
13. Contact
For any privacy questions, contact our Data Protection lead at info@sagbrain.com.