1. Controller / 管理者・運営者情報
Operator name (事業者名 / 運営者氏名 DBA):Romano Ningrat Moesa, operating under the unincorporated pre-launch business name "QinetiK Labs" (キネティック・ラブズ / 事業準備中).
Planned post-incorporation entity (設立予定法人):合同会社 QinetiK Labs / 合同会社キネティック・ラブズ (GK formation scheduled Q4 2026, Osaka-fu registration).
Address / 所在地:Osaka Prefecture, Japan (大阪府). Full exact street-level / building / floor address will be published here immediately upon GK incorporation and registration at the Osaka Legal Affairs Bureau (大阪法務局).
Primary contact for privacy + data inquiries (個人情報・データに関するお問い合わせ窓口):info@qinetik.jp →.
Response SLA (回答所要期間):Within five (5) business days (Mon–Fri JST 10:00–18:00, excluding Japanese public holidays / 祝日除く) from receipt of a properly addressed, complete inquiry. Complex requests (formal 開示請求 under APPI, erasure, objection, cross-border transfer detail requests) may require up to 30 calendar days; in that case an interim response will be sent within the 5-business-day window acknowledging the request and stating the expected finalisation date.
2. Personal Data We Collect on QinetiK.jp /本サイトで収集する個人データ
QinetiK.jp is, at time of policy publication, aread-only brochure / marketing site. There isno user registration, no login, no customer account portal, no embedded comment system, no embedded video player, no Google Maps embed, and NO PUBLIC CONTACT FORM deployed on QinetiK.jp. Japanese business prospects who wish to contact us are expected to locate the statutory operator disclosure (Tokushoho) page on this site and contact the operator via the published email address, in accordance with normal B2B practice in Japan.
// ITEMISED INVENTORY · PROCESSING ACTIVITIES ON QinetiK.jp
2.1 · Direct Email Correspondence (お問い合わせメール直接送信)
When a business prospect or third party sends us an inbound email to info@qinetik.jp, the following data categories may be present in the inbound message, and are received and stored solely in the operator email account inbox:
- Full name / 氏名: Sender's display name or given + family name, as written by the sender in the email signature body or From header.
- Email address / メールアドレス: The sender's From: address (RFC 5322).
- Company / Employer / 会社名・所属・役職:Any affiliation, brand name, DBA, corporate title, or customer-company reference the sender voluntarily includes in their signature or body text.
- Phone number / 電話番号 (完全任意): Any contact phone number the sender voluntarily includes in their email signature. This field is NOT requested and is NEVER required for a response.
- Free-form message body / 問合せ内容本文:The contents of the inbound email body, attachments, and any embedded inline quotation, which may include project details, requirements, budgets, deadlines, RFP attachments, or other B2B enquiry context submitted by the sender.
2.2 · Umami Self-Hosted Cookieless Analytics (Umami 自動ホスト型クッキーレス解析データ)
We deploy Umami Analytics, self-hosted by QinetiK Labs on Vercel infrastructure, to collectstrictly aggregated, anonymised, cookieless website usage data on every visitor to QinetiK.jp.
NO COOKIES ARE PLACED ON ANY VISITOR DEVICE BY THIS SITE OR BY THE ANALYTICS SCRIPT.No LocalStorage, no IndexedDB, no CacheStorage fingerprinting, no ETag-based tracking, no browser storage of any kind, and no unique persistent identifier is written to the visitor's device. Each page-view event is summarised as a non-identifiable aggregate counter entry on the server side and the raw IP address is never persisted to the analytics datastore (it is consumed only transiently by the script server for geolocation lookups, then discarded without being written to disk).
// DATA POINTS COLLECTED PER PAGEVIEW (AGGREGATE ONLY):
| Datapoint | Example value | Identifiable? | Retention |
|---|---|---|---|
| Page URL path | /legal/privacy, / | No | See §9 |
| HTTP Referrer / 流入元URL | search engine results page, link shared link from industry platform profile, bookmark | No | See §9 |
| Browser / UA family | Chrome, Safari on iOS 17 | No | See §9 |
| OS | macOS 15, Android 14 | No | See §9 |
| Device type | mobile, desktop, tablet | No | See §9 |
| Country-level geo | JP, US, SG | No | See §9 |
| Screen dimensions (w×h, logical) | 390×844, 1440×900 | No | See §9 |
| Unique daily visitor COUNTER | Aggregated integer only; no user ID stored | No — counter is aggregated, and daily dedupe uses a non-persistent, short-lived hash of (IP + UA + site_id), computed fresh each 24h window and discarded the next day. | 24h; aggregate counter integer remains |
2.3 · POTENTIAL FUTURE PROCESSING · MAILEROO SG (NOT CURRENTLY DEPLOYED / 現時点で未導入)
At the time this policy is published, QinetiK Labs hasNOT deployed an outbound newsletter / marketing mailing list on QinetiK.jp. There is no newsletter signup widget, no Mailchimp/ConvertKit/Beehiiv form, no embedded email-capture input, and no personal data is sent to any mailing platform by the QinetiK.jp site today.
Forward-looking disclosure only: We are evaluating Maileroo (operated by Digital Endpoints Pte Ltd, Singapore, registered at 10 ANSON ROAD, #11-12, INTERNATIONAL PLAZA, SINGAPORE 079903) as a potential future outbound SMTP provider for transactional operator emails and/or, at a later date, an invitation-only opt-in newsletter. If and when Maileroo or an alternative is actually deployed on QinetiK.jp or on the operator's sending infrastructure for correspondence originating from this site, this §2.3 and the sub-processor list at §4e will be updated to reflect the active deployment, lawful basis of processing, any consent collection mechanism (double opt-in where legally required), and the data subject will be provided with a mechanism to unsubscribe in every mailing. No personal data has been transmitted to Maileroo by QinetiK.jp as of the last-updated date at the top of this page.
【将来的な処理に関する予告的開示(現時点で未実施)】Maileroo (Singapore所在 Digital Endpoints Pte Ltd 提供のSMTPサービス) を、将来的に事業者からの連絡メール送信、または招待制オプトイン ニュースレター配信に利用する可能性を検討しておりますが、本プライバシーポリシー最終更新日現在、Mailerooは QinetiK.jp 上に一切導入されておらず、いかなる個人データも Mailerooに送信されておりません。今後導入の際には、本条および第4条e号のサブプロセッサ一覧を 更新するとともに、日本の個人情報保護法(APPI)および 適用あるGDPRに準拠した適法な処理根拠・同意取得手続(必要な 場合はダブルオプトイン)を別途実施いたします。
2.4 · COOKIES · ZERO COOKIE DECLARATION (クッキー一切不使用宣言)
QinetiK Labs confirms, as of the last-updated date above, that this QinetiK.jp marketing website places ZERO cookies on visitor devices.
- No
document.cookiewrites are issued by any script loaded on the site. - No
Set-CookieHTTP response headers are emitted by the origin server on any page or static asset response. - No third-party tracking cookie (Google Analytics/GA4, Meta Pixel, Hotjar, Microsoft Clarity, Segment, mPulse, RUM agents, ad-tech tags) is loaded on QinetiK.jp.
- No consent management platform (CMP) script, cookie banner, or "accept cookies" modal is deployed because no cookies exist to consent to.
- Fonts, stylesheets, static assets, and the favicon are all served first-party from QinetiK.jp via Vercel's origin + Cloudflare's edge network. No Google Fonts CDN, no Typekit, no external web font service is used. All web fonts are self-hosted WOFF2 files under the operator's control at
/public/fonts/*.woff2.
3. Lawful Bases of Processing (APPI + GDPR where applicable) /処理の適法根拠
- Inbound email correspondence (§2.1): Processed on the basis oflegitimate interests pursued by the controller(GDPR Art.6(1)(f)), namely the legitimate commercial interest of a B2B engineering studio in receiving, reviewing, and responding to unsolicited enquiries and RFP submissions from prospective clients and collaborators; and additionally on the basis of pre-contractual measures taken at the request of the data subject (GDPR Art.6(1)(b)), where the content of the email comprises a request for quotation, an invitation to tender, or negotiations toward a potential statement of work. Under the APPI, the processing falls within the statutory exception for "the acquisition of personal data directly from the data subject in writing or by electromagnetic record for the purpose of concluding or performing a contract between the operator and the data subject," with the purposes of use explicitly disclosed in this policy.
- Umami cookieless analytics (§2.2):Processed on the basis of the controller's legitimate interests (GDPR Art.6(1)(f)), specifically the legitimate interest in understanding aggregate, non-identifiable visitor traffic to a brochure marketing website in order to improve site structure, page copy, and regional marketing allocation. This processing is explicitly balanced against the data subject's rights by the absence of any persistent identifier, the absence of cookies, non-retention of IP addresses, aggregation-only output, and the data subject's ability to block all scripts in their browser (which prevents processing entirely without degrading the core content of the brochure site, which is 100% readable with scripts disabled). Under APPI no personal data is acquired by Umami on QinetiK.jp in the first place, as the set of collected fields enumerated in §2.2 does not include any "Personal Information" within the meaning of Art.2(1) of the APPI.
- Sub-processor infrastructure (§4):Hosting, edge, CDN, DNS, and static-asset delivery services named in §4 process data strictly as necessary for the performance of a contract for the hosting and provision of the website (GDPR Art.6(1)(b)), or alternatively on the basis of the controller's legitimate interest in operating a performant, globally accessible brochure website (GDPR Art.6(1)(f)). Under APPI this constitutes outsourcing of information-handling business to a commissioned sub-contractor, compliant with the requirements of APPI Art.23, with the necessary supervision and (where applicable) cross-border transfer safeguards described in §7.
4. Sub-Processors & Third Parties /外部委託先・再委託先一覧
The following named entities may process data originating from QinetiK.jp visitors in the course of their commissioned services. All processing is governed by written contract (or, in the case of self-service click-through SaaS platform terms, by the operator's binding clickwrap service agreement) containing the controller/processor duties required under APPI Art.23 and, where EU/EEA data subjects are concerned, under Article 28 GDPR.
// ACTIVE SUB-PROCESSORS · LAST VALIDATED 2026-10-05
| Entity / 事業者名 | Service / 役割 | Jurisdiction / 所在地 | Data categories / 対象データ項目 | DPA / SCC / 再委託契約状況 |
|---|---|---|---|---|
| Vercel Inc. | Primary origin hosting + static build-time rendering + edge-function runtime for QinetiK.jp | USA (HQ Delaware); edge POPs global incl. Tokyo region edge caches for visitor traffic | All inbound HTTP request data (transient); generated static site response bodies (persistent static assets, HTML, CSS, JS, images, self-hosted WOFF2 fonts at /public/fonts) | Clickwrap SaaS agreement; GDPR Standard Contractual Clauses (2021 SCC module C2) opted-in via Vercel Data Processing Addendum account-level setting by controller. |
| Cloudflare Inc. | Authoritative DNS hosting for QinetiK.jp zone; optional CDN / edge WAF / DDoS mitigation layer at operator's election; reverse proxy cache POP | USA (HQ Delaware); DNS answers served globally from 300+ anycast POPs incl. JP edge nodes | DNS query metadata (transient); pass-through HTTP request metadata for cacheable assets; DDoS/WAF log metadata (short retention) | Clickwrap SaaS agreement; Cloudflare Data Processing Addendum signed in Cloudflare dashboard; SCC/UK IDTA add-ons enabled for covered transfers. |
| QinetiK Labs — self-hosted Umami instance on Vercel (controller-operated sub-component) | Aggregate cookieless analytics server (receives POST events from the in-browser Umami script on QinetiK.jp pages) | Same Vercel POP regions as primary hosting (see §4a) | Only the 8 anonymised, aggregate fields enumerated in §2.2 Table (no cookie identifier, no user ID, no stored IP address). | Internal controller-internal processing; no further sub-contracting from the Umami instance to any third party beyond the Vercel runtime in 4a. |
| Email service provider for info@qinetik.jp inbox operator | IMAP/SMTP mailbox hosting for the operator-facing info@qinetik.jp account | Disclosed on the QKay.jp Privacy Policy §4 (operator uses the same mailbox provider across both QKay.jp and QinetiK.jp operator addresses); updated in this §4 on provider change. | Inbound and outbound email messages, headers, attachments relating to QinetiK.jp correspondence (§2.1 processing activity) | Provider-specific DPA / SCC annex to be appended here on GK incorporation; current processing is covered by the provider's general public terms and, where an EU/EEA transfer is concerned, by the provider's signed GDPR SCC programme as described in their published public DPA page. |
| Maileroo (Digital Endpoints Pte Ltd)⚠ LISTED FOR TRANSPARENCY ONLY · NOT ACTIVE. No personal data transmitted as of LAST_UPDATED date. | Potential future outbound SMTP relay for transactional operator email or opt-in newsletter. | Singapore (10 ANSON ROAD #11-12 INTERNATIONAL PLAZA, SINGAPORE 079903) | Not applicable (no data processed yet). If activated, processing inventory is: sender/recipient email addresses, message body, headers — limited strictly to outbound delivery initiated by the operator or by an explicit double-opt-in confirmed newsletter subscriber. | Not applicable; Maileroo DPA + APEC CBPR/APPI cross-border transfer assessment document set to be reviewed prior to activation, and this §4e row updated from "NOT ACTIVE" to "ACTIVE" together with policy version number, before any data is sent. |
【上記委託先一覧に関する注意】(e)Mailerooは将来的な導入検討に基づく 予告的な透明性開示のため記載しており、本ポリシー最終更新日現在、 実際に運用は開始しておらず、いかなる個人データも同社に送信・処理 されておりません。導入決定・稼働開始の際には、本第4条の対応する行を 「NOT ACTIVE」 から 「ACTIVE」 に更新するとともに、 個人情報保護法第23条に基づく委託契約・APPI域外移送の安全性確保措置 (APPI 第24条の4 同等水準国ではないシンガポール宛のため、別途 移転先における義務的措置の遵守を確保するための契約条項付与) を実施の上、本方針に反映いたします。
5. Purposes of Use /利用目的
Personal data received on QinetiK.jp (§2.1 direct email) is usedONLY for the following enumerated purposes of use, which are published in accordance with APPI Art.18 (Notification or public announcement of Purpose of Use):
- To receive, review, reply to, and process inbound business enquiries, RFP submissions, partnership proposals, and client correspondence sent to info@qinetik.jp (including scoping, quotation, scheduling of calls, and pre-contractual negotiation).
- Where the sender requests and consents in writing, to add the sender to the operator's internal CRM / vendor / client contact list for the duration of any ongoing or proposed business engagement and for a statutory retention tail afterwards.
- To fulfil obligations imposed on the operator by mandatory applicable law, Japanese civil code, Japanese tax code, 特定商取引法書面保存義務, and lawful requests from competent Japanese governmental authorities.
- Aggregate analytics counters (§2.2 Umami fields) are used only for internal traffic quality, page copy improvement, regional marketing spend allocation, and regional SEO entity signal verification. Aggregate counters are never combined with any personal identifier, never matched against email sender data, and are never sold, rented, syndicated, or shared with any advertiser or data broker.
【利用目的の範囲外使用の禁止】上記(1)〜(4)に定める利用目的の範囲を 超えて個人データを取り扱う必要が生じた場合は、個人情報保護法第18条 第3項の規定に従い、当該データ主体に対し事前に変更後の利用目的を 通知または公表するまでは、目的外利用を行いません。
6. Non-disclosure to Third Parties /第三者提供の禁止
QinetiK Labs (controller, QinetiK.jp site) does notsell, rent, syndicate, swap, or otherwise discloseany personal data received from visitors to QinetiK.jp to any third party for their own independent direct marketing, advertising, user-profiling, or any other purpose outside the sub-contracted processing strictly listed at §4 above.
Disclosure to a third party shall occur only in the following four enumerated cases, the first three of which are carve-outs that do not require prior consent under APPI Art.27:
- Pursuant to mandatory applicable law, including in response to a lawful subpoena, 捜索差押令状, disclosure order from a Japanese court or 警察庁/国税庁 competent governmental authority having jurisdiction over the matter.
- Where necessary for the protection of the life, body, or property of an individual and it is difficult to obtain the consent of the person (APPI Art.27(1)(iii)).
- Where there are prior arrangements for the commissioned outsourcing of information-handling business in accordance with APPI Art.23, being strictly the sub-processor entities named in §4a–§4d above, operating under written or clickwrap DPA/SCC contracts for processing exclusively on behalf of and under the instruction of QinetiK Labs.
- In any other case, only after obtaining the prior explicit written or digitally-signed consent of the data subject (APPI Art.27(1)(iv)).
7. International Cross-border Transfers /国外移送
Because QinetiK.jp is hosted on globally replicated infrastructure operated by Vercel Inc. (USA) and fronted by Cloudflare Inc.'s anycast edge POP network (USA-headquartered global network, including Japan edge nodes), any access to QinetiK.jp by any visitor anywhere in the world results in transit of data packets across international network links and may result in transient or persistent processing in jurisdictions outside the visitor's country of origin, including the United States of America and Singapore (for the potential future Maileroo sub-processor once active), depending on edge POP routing and the specific processing activity.
- Transfers to the USA via Vercel + Cloudflare:Both are US-headquartered companies. The European Data Protection Board has not issued a positive adequacy decision for the United States. Safeguards implemented by QinetiK Labs: (a) Vercel Data Processing Addendum with Article 28 GDPR controller-processor terms, with the EU 2021 Standard Contractual Clauses (Module C2 — controller to processor with controller established outside EU/EEA, processor established outside EU/EEA) opted-in at the account level; (b) Cloudflare public Data Processing Addendum with EU SCC/UK IDTA annexes enabled; and (c) technical minimisation: static assets and self-hosted fonts on QinetiK.jp do not contain personal data, so the primary cross-border transfer is transient HTTP request metadata (IP, UA, Accept headers) consumed only by the edge for routing, TLS termination, and optional WAF/CDN functions — none of which constitute Personal Information under APPI unless cross-referenced with other data, which the controller does not perform and instructs the sub-processors not to perform.
- Japan-side POP preference:Where operationally supported by Cloudflare and Vercel at the time of a request, traffic originating from IP addresses geolocated to Japan is served first from Tokyo-region edge POPs in order to minimise cross-border hops. The operator has configured "prefer APAC edge" options in both dashboards where exposed, and will continue to select the most Japan-local storage region options when they become available on the respective platforms.
- Potential future transfer to Singapore (Maileroo SG):Singapore is NOT listed as an APPI "equivalent level of protection" equivalent country under Cabinet Office Ordinance. If Maileroo is activated at a future date per §2.3, the following safeguards will be implemented in addition to the contractual arrangements required under APPI Art.23 (Outsourcing): a written contract with Maileroo ensuring compliance with the APPI Art.24-4 personal information protection system requirements equivalent to the Japanese standard, including technical and organisational security measures, onward-transfer restrictions, and enforceable data-subject third-party-beneficiary rights where legally available; plus a documented transfer impact assessment (TIA) retained by the controller for 10 years or the lifetime of the processing, whichever is longer, and available on request to competent data protection authorities. No activation occurs before the TIA is completed. Maileroo is not currently active (see §2.3 / §4e).
8. Security Measures (安全管理措置)
- Organisational: single named controller (Romano Ningrat Moesa) with personal accountability for the QinetiK.jp scope; processing inventory documented at §2 §4; access by any future staff to operator email accounts and the Umami analytics dashboard restricted to authenticated, named personnel only via per-user login and, where available, hardware MFA.
- Technical: HSTS-enabled HTTPS with TLS 1.2 minimum and TLS 1.3 preferred for all QinetiK.jp traffic; HTTP → HTTPS 301 permanent redirect at edge; Cloudflare DNSSEC signed zone; operator email account protected by strong unique password + 2FA; Umami dashboard admin account protected by strong unique password + TOTP; static assets served via cacheable immutable file-naming with long-cache TTL and integrity-verified build output.
- Personnel / Physical: QinetiK.jp static content does not contain personal data and therefore does not require physical access controls beyond the operator's own IT equipment controls; operator email and Umami dashboard access are restricted to devices under the exclusive physical control of the controller or named delegate; no remote access to email/analytics from shared/public devices without full-disk encryption + screen lock and session expiry after 15 idle minutes.
- Breach notification: Any incident that creates a reasonable likelihood of unauthorised access to, or loss or alteration of, personal data in scope of this policy will be reported by internal procedure within 72 hours of awareness to the data subjects affected (where feasible) and, where mandated, to the 個人情報保護委員会 (PPC / Japan Personal Information Protection Commission) and competent EU supervisory authority within the GDPR 72h window where EU/EEA data subjects are affected and the incident is likely to result in a high risk to the rights and freedoms of natural persons.
9. Retention Periods /保存期間
- §2.1 Direct email correspondence: retained for12 calendar months from the date of the last substantive reply if no written commercial engagement (MSA / SOW / NDA / PO) is signed with the sender. If a written commercial engagement is signed, correspondence forming part of that engagement file is retained for 10 full calendar years from the end-date of the engagement, consistent with Japanese Civil Code Art.167 (10-year ordinary extinctive prescription period for contractual claims) and with the statutory book-and-document retention obligations under the Corporation Tax Act and 特定商取引法 where applicable, whichever is longer.
- §2.2 Umami aggregate analytics: raw (non-personal) page-event counters are retained for365 calendar days in the analytics dashboard; after 365 days the individual per-page event records are aggregated into annual totals and the raw daily event records are deleted; the short-lived (24h) hash used for daily deduplication is never persisted and disappears at the conclusion of each UTC day rollover window; no stored IP addresses exist to delete as they are never written to the analytics datastore in the first place.
- Cloudflare + Vercel transient request logs:retained for ≤ 30 days per the respective platform default log retention settings configured by the operator; older logs are purged automatically.
- Where mandatory applicable law (e.g., a pending court order, a 税務調査 tax audit hold notice, an ongoing PPC investigation) requires a longer retention period for any specific item, the statutory retention period overrides the ordinary schedule in this §9 and the affected records are retained until the legal hold is formally lifted, at which point they are deleted within 30 days.
10. Data Subject Rights /データ主体の権利
Where a data subject's personal data is actually within scope of this policy (i.e., direct email contact data at §2.1 — analytics counters are not personal data), they may exercise the following rights by sending a signed, authenticated request to the contact address in §1. All response SLAs in this §10 are without prejudice to the operator's general 5-business-day acknowledgment SLA in §1.
- Right of access / 開示請求 (APPI Art.28; GDPR Art.15): confirm whether we hold any personal data about the requester and receive a copy of it, together with the purposes of use, categories of recipients, retention period, source of the data, and any cross-border transfer safeguards. Initial response within 30 calendar days; complex multi-record requests may require up to 60 calendar days with interim notice.
- Right of rectification / 訂正請求 (APPI Art.29; GDPR Art.16): correct inaccurate or incomplete personal data held about the requester.
- Right of erasure / 削除請求 (APPI Art.30; GDPR Art.17): request deletion of personal data held about them, subject to the statutory retention carve-outs in §9 which apply when the data must be retained for a mandatory legal purpose (in which case it will be retained only for that purpose, de-linked from active processing where feasible).
- Right to restriction of processing / 利用停止請求 (APPI Art.31; GDPR Art.18): suspend active processing on contested records while a rectification or objection claim is being determined.
- Right to object to processing / 処理への異議申立 (GDPR Art.21): where processing is based on legitimate interests (§3.1, §3.2), the data subject may object at any time on grounds relating to their particular situation. We will cease the objected processing unless we can demonstrate compelling legitimate overriding grounds for the continued processing which are explicitly documented and communicated back to the objector.
- Right to data portability (GDPR Art.20): where processing is based on consent or on a contract and is carried out by automated means (not applicable to the email-inbox processing of QinetiK.jp at time of writing, which is manual), receive their personal data in a structured, commonly used, machine-readable format or have it transmitted to another controller.
- Right to withdraw consent (GDPR Art.7(3)): where consent is used as a legal basis at any future stage (e.g., a future Maileroo-based newsletter double opt-in per §2.3), consent previously given can be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to lodge a complaint with a supervisory authority (GDPR Art.77; APPI 個人情報保護委員会への申出): data subjects who consider that processing of their personal data infringes APPI or the GDPR have the right to lodge a complaint with the PPC in Japan or their EU/EEA local supervisory authority, respectively, in addition to or instead of any of the internal remedies above.
Verification of identity before disclosure: before acting on any request under this §10 the operator will carry out reasonable steps to verify the identity of the requester (e.g., confirmation of matching From: address from the original inbound email thread; or production of two registered identification documents with address line for an original letter request) to prevent fraudulent disclosure of another person's records. This identity-check processing is itself carried out strictly for the purpose of complying with the statutory response duty and is not used for any secondary purpose.
11. Children / 未成年者のデータ
QinetiK.jp is a B2B engineering-studio brochure site directed at adult business decision-makers, procurement officers, product owners in registered corporate entities, and industry professionals. It is not directed to children, and no services are offered to children. The controller does not knowingly collect or solicit personal data from children under the age of majority in their jurisdiction (in Japan: 18 years pursuant to the amended Civil Code as of April 1, 2022; EU/EEA: 16 years, or 13 years where the relevant member state has set a lower age under GDPR Art.8(1)). If the operator becomes aware that personal data has been submitted by or about a child without verifiable parental consent, that data will be deleted from all systems without undue delay, and a confirmation of deletion will be sent to the reporting contact if one is provided.
12. Links to Third-Party Sites /第三者サイトへのリンク
QinetiK.jp links to external third-party websites (including, without limitation: the QKay product site at QKay.jp; our code-hosting organisation profile; operator industry-platform profiles we may publish in future; and real client-project references hosted on customer domains, where published in case-study / portfolio sections). Following a link from QinetiK.jp to any external site, including QKay.jp, transfers the visitor onto a domain governed by that third-party's own privacy policy. This policy applies only while the visitor remains on a page rendered under QinetiK.jp. The operator of QinetiK.jp is not responsible for the content, privacy practices, or processing activities of any externally linked site. Always review the published privacy policy of each site before submitting personal data to it.
13. Changes to this Privacy Policy /本方針の変更手続
- This policy is subject to periodic revision. Material revisions (i.e., any change to the identity of the controller; scope of processing enumerated in §2; sub-processor list §4; purposes of use §5; cross-border transfer regime §7; retention schedule §9; or data-subject rights response SLAs §10) will be published on this page with an updated "Last updated" date at least thirty (30) calendar days before becoming active, provided that no urgent legal/regulatory mandate requires an earlier effective date, in which case the minimum notice period permitted by the overriding law will be used and the reason for the accelerated change will be documented on this page.
- Non-material revisions (typographical corrections, formatting-only changes, a new postal-code addition to an address field already listed in §1, clarifying footnotes that do not change the substantive scope of a processing activity) may be published without a 30-day advance notice period; the Last-updated date will still be incremented and the change summarised in a short changelog at the bottom of this page for transparency.
- In the case of material changes to processing based on consent (e.g., a future newsletter deployment under §2.3), re-consent will be obtained from any already-registered data subject in accordance with the consent-obtaining procedure described at the point of original collection.
14. Contact / お問い合わせ先
Send privacy-related requests, access/rectification/erasure requests, objection requests, breach reports, and any other inquiries concerning personal data processing on the QinetiK.jp site to:
// CONTROLLER CONTACT · PRIVACYTo the attention of: Romano Ningrat Moesa (Responsible Controller / 運営責任者)Email: info@qinetik.jp →(日本語でのお問い合わせも承ります。メールタイトルに【プライバシーポリシーに関する問合せ】と明記の上、お送りください。)