Nproc

Privacy Policy

TR-55 Inc. ("we", "us") provides Nproc (the "Service"). We handle the personal data of users of the Service in accordance with Japan's Act on the Protection of Personal Information (APPI), the GDPR, the UK GDPR, the CCPA/CPRA, PIPEDA, and other applicable laws, under this Privacy Policy.

1. Information We Collect

When a team administrator invites or adds you, we may receive your name and email from that administrator. The purposes and your rights described in this Policy apply in that case as well.

2. How We Use Information

We do not use your account information, usage history, or billing history for selling to third parties, behavioural targeted advertising, retargeting, or other sales/marketing purposes. The only emails we send are communications necessary to provide and operate the Service (such as notices relating to team invitations and notices of material changes to this Policy or the Terms of Service) and announcements about new features, improvements, and how to use the Service. Every announcement email includes a way to stop receiving them, and you may stop receiving them at any time.

3. Legal Bases for Processing

For users in the EEA / UK, we process personal data on these bases:

Whether you are required to provide personal data: you are under no statutory obligation to provide personal data to us. To create an account, providing your OAuth provider identifier through Sign in with Google is a contractual requirement. We receive your name and email address automatically to the extent they are registered in your Google account. For paid plans, providing payment information and a billing address is likewise a contractual requirement (payment information is processed by our payment processor; we do not store card numbers). If information that is a contractual requirement is not provided, we cannot create your account or provide the paid plan. Providing other information, such as a profile image, is optional.

4. Data Controllership (Controller / Processor Split)

Because Nproc is a collaborative B2B workspace, different data sets are controlled by different parties. Understanding this split is important for exercising your rights under the GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and Japan's APPI.

If you use the Service on behalf of an organization, the Data Processing Addendum (DPA) applies as part of the Terms of Service to the processing of personal data between that organization and us. If you would like to enter into a separate written DPA, please contact us at the address in section 17.

5. Disclosure to Third Parties

Except as described in this Policy, we do not disclose personal data to third parties. The cases described in this Policy are where disclosure is required by law, where you have consented, the recipients described in section 6, and the transfer on a business succession described below. We do not share personal data with advertising partners.

If we transfer our business in a merger, a business transfer, bankruptcy, or another such event, account-layer personal data may pass to the successor, on condition that the successor handles it in accordance with this Policy. The successor will not handle personal data beyond the purposes for which it was collected before the transfer. If the successor materially changes how it handles personal data, the successor will notify you in advance. Workspace-layer information is handled in accordance with our agreement with, and the instructions of, the team that controls it.

6. Vendors We Engage

We engage the following vendors to provide the Service. Those that handle content within your workspaces are subprocessors as referred to in the DPA, which sets out the classification for each vendor in section 4.1. We enter into an appropriate agreement with each such vendor for the protection of personal data (a data processing agreement or equivalent, and standard contractual clauses for international transfers where applicable), to the extent applicable to the nature of the services that vendor provides, and we supervise them. An up-to-date list is available on request.

Push notification data handling (Google FCM / Apple APNs): For push notifications to the mobile application, Android delivery transits Google (Firebase Cloud Messaging, FCM) and iOS delivery transits Apple (APNs); iOS notifications are sent directly to APNs, so Google's involvement is limited to Android delivery. Data passing through these channels is handled as follows. We do not use push notifications to send promotions or direct marketing.

Position of AI / LLM providers: We do not call AI or LLM providers from within the Service. When you choose to use a third-party AI client (Claude, ChatGPT, Gemini, etc.) to access the Service through the MCP (Model Context Protocol) integration, the AI provider is an AI tool that you have selected and contracted with. It is not a subprocessor of ours. Your relationship with that AI provider is governed by the terms and privacy policy you have agreed to with the provider directly. Data sent over the MCP integration is designed to be limited to structured, PII-minimized fields; however, free-text content you enter into issues, documents, or other bodies may contain personal data such as names, so we do not represent this data as containing no personal data.

No use for AI model training: We do not use the information that you and your team handle in the Service (including content such as issues, documents, canvases, comments, and attachments, as well as account information and usage history) to train AI / LLM models, for fine-tuning (including additional training methods such as LoRA), for distillation, for building evaluation datasets, or for similar purposes - now or in the future. Nor do we provide such information to third parties for the purpose of training AI models. This is a commitment about how we (TR-55 Inc.) ourselves handle data. How the provider of an AI client you choose to use (see "Position of AI / LLM providers" above) handles data is governed by your own contract and settings with that provider and is outside the scope of this commitment.

Internal use of AI tooling (incident investigation, operational monitoring, and usage analysis): Our internal administrators may use an AI tool (Claude Code, provided by Anthropic) to assist in analyzing operational data that they access through our internal monitoring tool, for the purpose of investigating incidents, monitoring the operation of the Service, and analyzing usage of the Service. This use is limited to those purposes; we do not use this path for sales, marketing, AI model training, or any similar purpose. This path is designed as follows.

Services we do not use (for reference): Our use of Firebase in providing the Service is limited to push notification delivery through FCM. We do not use Firebase Analytics, Crashlytics, Google Analytics, retargeting / advertising platforms, or other third-party analytics or advertising services.

7. International Transfers

Operating the Service may involve transferring and processing personal data outside Japan. Depending on the data category, processing locations include Japan and the United States (the Cloudflare D1 and storage services), the Cloudflare global edge network (Durable Objects), and the Asia-Pacific region (internal audit logs). We carry out transfers with the following safeguards:

A copy of the safeguards is available on request.

You may ask us for the following information about the framework for provision from Japan to a third party located in a foreign country. On receiving such a request we will provide it without delay, except that we may withhold all or part of it where providing it would seriously impede the proper conduct of our business, in which case we will tell you so.

We receive such requests directly, in both layers, because it is we who provide the data to the third party located in a foreign country, so we respond ourselves. Other rights over Workspace Layer data (access, correction, deletion, and the like) are handled by your team's administrator, as described in section 4.

8. Your Rights

You may exercise the following rights under applicable law:

Response time: we respond within one month of receipt; for complex or numerous requests we may extend by a further two months and will tell you why within one month. Responses are, in principle, free of charge.

Where to send your request: for the account layer (profile, authentication, membership records), contact us using the details in section 17 or use the data export in your account settings. For workspace-layer content (issues, documents, canvases, comments), contact your team's administrator, who is the controller of that data. We may need to verify your identity before responding.

9. Notice at Collection (CCPA / CPRA)

This section consolidates, in one place, the information California residents are entitled to receive at or before the point of collection. It summarizes the detail set out in the "Information We Collect", "How We Use Information", "California Privacy Rights", and "Data Retention" sections, which remain the authoritative statements.

10. California Privacy Rights (CCPA / CPRA)

Sale / sharing of personal information: We do not sell or share (as those terms are defined by the CCPA/CPRA) your personal information, and have not done so in the preceding 12 months. We place no third-party advertising or analytics tags or pixels on our site, and we do not upload customer lists or transmit behavioural data to third parties. Accordingly, we do not provide a "Do Not Sell or Share My Personal Information" link. If we ever add advertising tags to our site, we will re-evaluate this.

Do Not Track / Global Privacy Control (GPC): because we do not sell or share, there is no sale/sharing processing for a GPC or other opt-out preference signal to stop, so honoring such signals is not required. We do not track you across third-party websites.

Sensitive personal information (SPI): We do not intentionally collect or request SPI (as defined by the CCPA/CPRA), so we do not provide a "Limit the Use of My Sensitive Personal Information" link. Because free-text fields may contain information you choose to enter, we do not state this as an absolute guarantee.

Non-discrimination: we will not discriminate or retaliate against you for exercising your privacy rights.

11. Data Retention

We retain personal data only for as long as needed to fulfil the purposes of collection, or for the period required by law. The retention period or criteria and the handling of deletion for each main category are as follows.

Even after account deletion, (i) records subject to a legal retention obligation (including the name, email address, country, and postal code registered as billing information), and audit records retained to prevent abuse and to ensure the integrity of our records, and (ii) pseudonymized user IDs contained in team records and audit records, remain in accordance with the criteria above. Account-layer data export files you have requested stop being downloadable 7 days after the request and are then deleted automatically.

12. Cookies

The Service uses only cookies that are strictly necessary to provide the Service (including payment fraud-prevention cookies set on the billing page by the script of our payment provider Stripe), plus functional cookies for your language and display preferences. We use no third-party advertising or analytics trackers. Strictly-necessary cookies do not require a prior-consent banner under law; for transparency we list them below:

You can configure your browser to refuse cookies, but some parts of the Service may then be unavailable.

13. Data Security

We implement appropriate organizational and technical measures to protect personal data against unauthorized access, leakage, alteration, and loss. These include encryption at rest (Cloudflare R2 / D1 / Durable Objects), TLS in transit, pseudonymized identifiers in logs, least-privilege access control, and point-in-time recovery. No system is completely infallible.

What we do if personal data is leaked or otherwise compromised depends on the capacity in which we hold that data and on the law that applies.

14. Third-Party Websites / Services

The Service may link to external sites or apps that we do not control. We recommend reviewing the privacy terms of any external platform you access through us. We are not responsible for the content or privacy practices of those third-party sites.

15. Children's Privacy

The Service is intended primarily for business use and is available only to users who are 18 years of age or older (see our Terms of Service). If we learn that we have collected information from a person under 18, we will delete it promptly.

16. Changes to this Policy

We may amend this Privacy Policy in response to changes in laws or regulations or to other reasonable circumstances. For material changes, we will notify you at least 30 days before the effective date, within the Service or by email to your registered address. If you continue to use the Service after the revised Policy takes effect, you are deemed to have agreed to the changes.

17. Contact Us

For questions about this Privacy Policy or to exercise your rights, please contact:

TR-55 Inc.
Kazumi Hirooka, Representative Director
Shibuya Mark City West 22F, 1-12-1 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
Email: nproc-info@tr-55.com

Effective date: September 14, 2026