Privacy Policy
TR-55 Inc. ("we", "us") provides Nproc (the "Service"). We handle the personal data of users of the Service in accordance with Japan's Act on the Protection of Personal Information (APPI), the GDPR, the UK GDPR, the CCPA/CPRA, PIPEDA, and other applicable laws, under this Privacy Policy.
1. Information We Collect
- Information we collect at registration (name and email address; we receive these automatically to the extent they are registered in your Google account)
- Information you optionally set after registration (e.g. profile image)
- Information provided through OAuth sign-in (provider identifier, session information)
- Information collected automatically when you use the Service (IP address, the country you connect from as derived from your IP address, User-Agent, activity logs, cookie information)
- Information used to deliver push notifications (the device's push registration token, the device type, the identifier of the authentication session that registered the device, and the times of first and most recent registration), collected only where notifications are enabled in the mobile application
- Information you provide when you contact us or send feedback
- Payment-related information (collected through our payment processor; we do not store card numbers)
When a team administrator invites or adds you, we may receive your name and email from that administrator. The purposes and your rights described in this Policy apply in that case as well.
2. How We Use Information
- Providing, maintaining, and improving the Service
- Authentication and account management
- Responding to inquiries and sending service-related notices
- Preventing abuse and ensuring security
- Analyzing usage and improving quality of the Service
- Complying with legal or regulatory requirements
- Other purposes specified in this Policy
We do not use your account information, usage history, or billing history for selling to third parties, behavioural targeted advertising, retargeting, or other sales/marketing purposes. The only emails we send are communications necessary to provide and operate the Service (such as notices relating to team invitations and notices of material changes to this Policy or the Terms of Service) and announcements about new features, improvements, and how to use the Service. Every announcement email includes a way to stop receiving them, and you may stop receiving them at any time.
3. Legal Bases for Processing
For users in the EEA / UK, we process personal data on these bases:
- Performance of a contract: account creation, authentication (including Google OAuth sign-in), workspace collaboration, subscription billing, responding to your inquiries, sending notices necessary to provide the Service (such as security, billing, and account notices), and other processing necessary to provide the Service.
- Legitimate interests: security, fraud/abuse prevention, rate limiting, collection and analysis of server logs, internal investigation, understanding how the Service is used in order to maintain and improve its quality, sending announcements about new features, improvements, and how to use the Service, and retention of records that applicable law requires us to keep (including tax and accounting records). The legitimate interests we pursue are the secure and stable operation of the Service, the maintenance and improvement of its quality, keeping users informed about the Service, and compliance with the legal obligations that apply to us. The right to object applies to these processing activities. If you object to receiving announcements, we will no longer process your personal data for that purpose.
- Legal obligation: compliance with obligations imposed on us by EU or UK law (such as responding to the exercise of your rights and notifying personal data breaches).
- Consent: we do not currently carry out any processing that relies on consent as its legal basis (the only cookies used on the Service are the essential and functional cookies listed in section 12, and we use no advertising or analytics cookies; the announcements described in section 2 rely on legitimate interests). If we introduce processing based on consent in the future, we will ask for your consent separately at that time, and you may withdraw that consent at any time (section 8).
Whether you are required to provide personal data: you are under no statutory obligation to provide personal data to us. To create an account, providing your OAuth provider identifier through Sign in with Google is a contractual requirement. We receive your name and email address automatically to the extent they are registered in your Google account. For paid plans, providing payment information and a billing address is likewise a contractual requirement (payment information is processed by our payment processor; we do not store card numbers). If information that is a contractual requirement is not provided, we cannot create your account or provide the paid plan. Providing other information, such as a profile image, is optional.
4. Data Controllership (Controller / Processor Split)
Because Nproc is a collaborative B2B workspace, different data sets are controlled by different parties. Understanding this split is important for exercising your rights under the GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and Japan's APPI.
- Account Layer (Nproc is the controller): data that identifies you as an individual, such as your profile, authentication records, login session history, team-membership records, account preferences, and the audit records, server logs, and records of usage and security monitoring that we create and keep in operating the Service, together with your team's billing data. Requests for access, correction, restriction, deletion, or portability (export) of this data should be directed to us.
- Workspace Layer (your team is the controller; we are the processor): content you and your teammates create inside a workspace - issues, documents, canvases, comments, and related shared data - is controlled by the team that owns the workspace. We process this data on behalf of the team and assist the team in responding to data subject requests. Requests for access, portability, or deletion of workspace content should be directed to the team's administrator. If you cannot reach the team administrator, please contact us and we will assist in routing the request.
If you use the Service on behalf of an organization, the Data Processing Addendum (DPA) applies as part of the Terms of Service to the processing of personal data between that organization and us. If you would like to enter into a separate written DPA, please contact us at the address in section 17.
5. Disclosure to Third Parties
Except as described in this Policy, we do not disclose personal data to third parties. The cases described in this Policy are where disclosure is required by law, where you have consented, the recipients described in section 6, and the transfer on a business succession described below. We do not share personal data with advertising partners.
If we transfer our business in a merger, a business transfer, bankruptcy, or another such event, account-layer personal data may pass to the successor, on condition that the successor handles it in accordance with this Policy. The successor will not handle personal data beyond the purposes for which it was collected before the transfer. If the successor materially changes how it handles personal data, the successor will notify you in advance. Workspace-layer information is handled in accordance with our agreement with, and the instructions of, the team that controls it.
6. Vendors We Engage
We engage the following vendors to provide the Service. Those that handle content within your workspaces are subprocessors as referred to in the DPA, which sets out the classification for each vendor in section 4.1. We enter into an appropriate agreement with each such vendor for the protection of personal data (a data processing agreement or equivalent, and standard contractual clauses for international transfers where applicable), to the extent applicable to the nature of the services that vendor provides, and we supervise them. An up-to-date list is available on request.
- Cloudflare, Inc. (United States) - cloud infrastructure: hosting, CDN, Cloudflare Workers, databases, storage, log aggregation.
- Stripe, Inc. (United States) - payment processing and subscription billing. We are the controller of billing data, and Stripe handles it on our instructions. For its own purposes - such as monitoring, preventing, and detecting fraud, complying with legal obligations (including AML / KYC), and improving its own products and services - Stripe processes payment-related data as an independent controller, not on our instructions; that processing is governed by Stripe's own privacy policy.
- Google LLC (United States) - (1) OAuth authentication (Sign in with Google); (2) FCM (Firebase Cloud Messaging) for delivering push notifications to the Android mobile application only.
- Apple Inc. (United States) - APNs (Apple Push Notification service) for delivering push notifications to the iOS mobile application only.
Push notification data handling (Google FCM / Apple APNs): For push notifications to the mobile application, Android delivery transits Google (Firebase Cloud Messaging, FCM) and iOS delivery transits Apple (APNs); iOS notifications are sent directly to APNs, so Google's involvement is limited to Android delivery. Data passing through these channels is handled as follows. We do not use push notifications to send promotions or direct marketing.
- Notification content: under the Firebase Data Processing and Security Terms, Google acts as a data processor (GDPR) and service provider (CCPA/CPRA) and processes notification content only within the instructions the contract defines (to provide, secure and monitor the services and technical support services). Use for advertising or marketing purposes is not part of those instructions and is not permitted under the contract. We send iOS notification data to Apple APNs solely to deliver the notification.
- Operational data generated in delivery: for data that Google collects or generates in providing and administering the delivery service (which may include registration tokens and similar delivery metadata), we keep disabled the Firebase data privacy setting that allows such data to be used to analyze, improve, and make recommendations about Google services other than Firebase. Even with that setting disabled, such data continues to be used by Google for purposes such as providing and improving the Firebase services. We do not link advertising-related Google services (such as Google Ads or Google Analytics for Firebase) to our Firebase project.
- Payload minimization: the information in a push notification will be limited to the team name, the issue number, the notification type, and our internal identifiers for the item it refers to and for the recipient; notifications will not carry comment or message bodies, issue titles, or the acting user's name. Delivered notifications remain on the device beyond the reach of our deletion, so we will keep what is placed in a notification to the minimum necessary. Note that notifications include the team name, so if a team name contains an individual's name, that information appears in notifications.
Position of AI / LLM providers: We do not call AI or LLM providers from within the Service. When you choose to use a third-party AI client (Claude, ChatGPT, Gemini, etc.) to access the Service through the MCP (Model Context Protocol) integration, the AI provider is an AI tool that you have selected and contracted with. It is not a subprocessor of ours. Your relationship with that AI provider is governed by the terms and privacy policy you have agreed to with the provider directly. Data sent over the MCP integration is designed to be limited to structured, PII-minimized fields; however, free-text content you enter into issues, documents, or other bodies may contain personal data such as names, so we do not represent this data as containing no personal data.
No use for AI model training: We do not use the information that you and your team handle in the Service (including content such as issues, documents, canvases, comments, and attachments, as well as account information and usage history) to train AI / LLM models, for fine-tuning (including additional training methods such as LoRA), for distillation, for building evaluation datasets, or for similar purposes - now or in the future. Nor do we provide such information to third parties for the purpose of training AI models. This is a commitment about how we (TR-55 Inc.) ourselves handle data. How the provider of an AI client you choose to use (see "Position of AI / LLM providers" above) handles data is governed by your own contract and settings with that provider and is outside the scope of this commitment.
Internal use of AI tooling (incident investigation, operational monitoring, and usage analysis): Our internal administrators may use an AI tool (Claude Code, provided by Anthropic) to assist in analyzing operational data that they access through our internal monitoring tool, for the purpose of investigating incidents, monitoring the operation of the Service, and analyzing usage of the Service. This use is limited to those purposes; we do not use this path for sales, marketing, AI model training, or any similar purpose. This path is designed as follows.
- Restricted access path: the internal monitoring tool runs inside our internal network (Cloudflare Zero Trust) and reads data solely through read-only APIs to each system. Data cannot be modified or deleted through this path.
- Structural exclusion: when these APIs read the databases that hold user information, columns holding direct personal information (such as email addresses, names, access tokens, and IP addresses) and free-text columns (such as the bodies and titles of issues, documents, and notes, and team names) are excluded column-by-column, so, by design, they are not retrieved in the first place. In addition, when the operational log aggregation database is read, the columns holding IP addresses, browser identification information (the user agent), and the city, region, and network operator of the access source are likewise excluded column-by-column. Queries that retrieve those columns are rejected before they are run, and the columns are also removed from the results. Queries that use those columns only as a filter condition for counting may still be run, because the values themselves are not retrieved.
- Data that is sent: pseudonymized identifiers (user IDs issued by Nproc itself, customer reference IDs used for payment processing, and the like), error information such as error messages, operational figures such as counts and timestamps, and coarse-grained information such as the country of the access source and the data center it connected to are sent to the AI tool through this path. Because pseudonymized identifiers are still treated as personal data under the GDPR, we disclose this handling here.
- Partial redaction of free text and similar values: error information such as error messages, and free-text values that are not subject to the column-level exclusion above, may contain information relating to an individual, so strings matching URLs, email addresses, authentication tokens, and IP addresses are automatically replaced, and the text is truncated to a fixed length before it is sent. This replacement is a partial, pattern-based safeguard; it does not guarantee that strings that do not match these patterns - for example, a person's name - are removed.
- Handling by the AI tool provider: How data sent to the AI tool is handled by its provider (including whether it is used for training and how long it is retained) is governed by that provider's policies and contract terms.
Services we do not use (for reference): Our use of Firebase in providing the Service is limited to push notification delivery through FCM. We do not use Firebase Analytics, Crashlytics, Google Analytics, retargeting / advertising platforms, or other third-party analytics or advertising services.
7. International Transfers
Operating the Service may involve transferring and processing personal data outside Japan. Depending on the data category, processing locations include Japan and the United States (the Cloudflare D1 and storage services), the Cloudflare global edge network (Durable Objects), and the Asia-Pacific region (internal audit logs). We carry out transfers with the following safeguards:
- Transfers from the EU / EEA to Japan (to us) rely on the EU's adequacy decision for Japan (Implementing Decision (EU) 2019/419).
- Transfers from the UK to Japan (to us) rely on the same adequacy decision for Japan, which the UK carried over into its own law when it left the EU.
- Transfers of personal data received from the EU / EEA to US vendors (those listed in section 6) rely on each provider's EU-US Data Privacy Framework certification, or on the 2021 Standard Contractual Clauses together with a transfer impact assessment.
- Transfers of personal data received from the UK to US vendors (those listed in section 6) rely on each provider's UK Extension to the Data Privacy Framework, or on the Standard Contractual Clauses with the UK Addendum, or on the IDTA.
- For provision from Japan to a third party located in a foreign country, we rely on establishing by contract, through appropriate and reasonable means, a framework under which the recipient's handling of personal data is secured in line with the purpose of the obligations that Japan's Act on the Protection of Personal Information imposes on personal information handling business operators. The safeguards described above for transfers from the EU / EEA and from the UK do not substitute for the framework described here.
A copy of the safeguards is available on request.
You may ask us for the following information about the framework for provision from Japan to a third party located in a foreign country. On receiving such a request we will provide it without delay, except that we may withhold all or part of it where providing it would seriously impede the proper conduct of our business, in which case we will tell you so.
- How that third party has established the framework
- An outline of the measures that third party implements
- The frequency and method of our confirmation
- The name of the foreign country concerned
- Whether that country has any system that may affect the implementation of those measures, and an outline of it
- Whether there is any impediment to the implementation of those measures, and an outline of it
- An outline of the measures we take in respect of any such impediment
We receive such requests directly, in both layers, because it is we who provide the data to the third party located in a foreign country, so we respond ourselves. Other rights over Workspace Layer data (access, correction, deletion, and the like) are handled by your team's administrator, as described in section 4.
8. Your Rights
You may exercise the following rights under applicable law:
- Access: you may request access to your personal data. Access covers all personal data we process about you and is broader than the portability export below.
- Portability: you can obtain a copy of your account-layer data in a structured, commonly used, and machine-readable format. You can export it yourself at any time from your account settings: once requested, your export is prepared asynchronously and is available for download from the history screen for 7 days. You may submit one export request per 24-hour period.
- Rectification, restriction, erasure: you may request correction, restriction, or erasure. Note that records subject to a legal retention obligation (e.g. tax/accounting) may be exempt from erasure. The name, email address, country, and postal code registered as billing information are subject to such a legal retention obligation and are retained for as long as applicable law requires them to be kept, including after account deletion (section 11).
- Objection: you may object to certain processing and request restriction.
- Withdrawal of consent: where we rely on your consent as the legal basis for processing your personal data (section 3), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. To withdraw your consent, contact us using the details in section 17. For cookies, you can also refuse or delete them in your browser settings (section 12).
- Automated decision-making: we do not carry out solely-automated decisions producing legal or similarly significant effects, including profiling.
- Complaint to a supervisory authority: you may lodge a complaint with the Personal Information Protection Commission (Japan), an EEA data protection authority, or the UK ICO.
Response time: we respond within one month of receipt; for complex or numerous requests we may extend by a further two months and will tell you why within one month. Responses are, in principle, free of charge.
Where to send your request: for the account layer (profile, authentication, membership records), contact us using the details in section 17 or use the data export in your account settings. For workspace-layer content (issues, documents, canvases, comments), contact your team's administrator, who is the controller of that data. We may need to verify your identity before responding.
9. Notice at Collection (CCPA / CPRA)
This section consolidates, in one place, the information California residents are entitled to receive at or before the point of collection. It summarizes the detail set out in the "Information We Collect", "How We Use Information", "California Privacy Rights", and "Data Retention" sections, which remain the authoritative statements.
- Categories of personal information we collect: identifiers (name, email, OAuth provider identifier, IP address, cookie identifiers); internet or other electronic network activity (User-Agent, activity logs, cookie information); geolocation data (the country you connect from, inferred from your IP address; security monitoring records also include the city and region you connect from. Neither is the precise location of your device); commercial information (subscription and payment records; card numbers are handled by our payment processor and are not stored by us); and other information you voluntarily provide (profile image, inquiry and feedback content). See "Information We Collect".
- Sensitive personal information (SPI): we do not intentionally collect or request SPI. Because free-text fields may contain information you choose to enter, we do not state this as an absolute guarantee.
- Purposes of use: providing, maintaining, and improving the Service; authentication and account management; responding to inquiries and sending service-related notices; preventing abuse and ensuring security; analyzing usage and improving quality; and complying with legal or regulatory requirements. We do not use this information for selling, behavioural targeted advertising, or retargeting. See "How We Use Information".
- Sale or sharing: we do not sell or share (as those terms are defined by the CCPA/CPRA) your personal information, and have not done so in the preceding 12 months. See "California Privacy Rights".
- Retention: we retain each category of personal data only for as long as needed to fulfil the purpose of collection, or for the period required by law (for example, tax/accounting records (including the name, email address, country, and postal code registered as billing information) for as long as applicable law requires them to be kept for tax and accounting purposes, retained even after account deletion; the audit records, server logs, and records of usage and security monitoring for the periods set out in "Data Retention" below, retained even after account deletion; other account-layer data for the life of the account, deleted within 30 days after account deletion; workspace-layer data per the controlling team's instructions; cookies per each cookie's lifetime). See "Data Retention".
10. California Privacy Rights (CCPA / CPRA)
Sale / sharing of personal information: We do not sell or share (as those terms are defined by the CCPA/CPRA) your personal information, and have not done so in the preceding 12 months. We place no third-party advertising or analytics tags or pixels on our site, and we do not upload customer lists or transmit behavioural data to third parties. Accordingly, we do not provide a "Do Not Sell or Share My Personal Information" link. If we ever add advertising tags to our site, we will re-evaluate this.
Do Not Track / Global Privacy Control (GPC): because we do not sell or share, there is no sale/sharing processing for a GPC or other opt-out preference signal to stop, so honoring such signals is not required. We do not track you across third-party websites.
Sensitive personal information (SPI): We do not intentionally collect or request SPI (as defined by the CCPA/CPRA), so we do not provide a "Limit the Use of My Sensitive Personal Information" link. Because free-text fields may contain information you choose to enter, we do not state this as an absolute guarantee.
Non-discrimination: we will not discriminate or retaliate against you for exercising your privacy rights.
11. Data Retention
We retain personal data only for as long as needed to fulfil the purposes of collection, or for the period required by law. The retention period or criteria and the handling of deletion for each main category are as follows.
- Account-layer data (profile, authentication information, personal settings, etc., including the country recorded on the account record): retained while your account is active; deleted within 30 days after account deletion. How the user IDs that remain in our records are handled after deletion is described later in this section.
- Information used to deliver push notifications (the device's push registration token and similar): retained while your account is active and deleted when the account is deleted. It is also deleted at sign-out and when the delivery provider tells us the destination is no longer valid. Information last registered more than 30 days ago is not used for delivery and is removed in the course of subsequent delivery processing.
- Workspace-layer data (issues, documents, canvases, comments, etc.): retained and deleted by us as a processor, on the instructions and contract of the controlling team. When you or your team delete data, that data is deleted; its remaining presence in backups after deletion is described below. Note that content created by a user who has been removed from a team or workspace remains unchanged under that team's control, including the display of the creator's name (this is handled separately from the processing performed on account deletion). When you delete your account, your user name, email address, and similar account information are themselves deleted; content you created remains under the team's control, but your name is no longer displayed as its creator or editor. The user ID that remains on content and in logs is an identifier issued by Nproc itself and is not linked to any external service ID, such as your Google account. When you delete your account, the registration data that connects that ID to you is deleted and the link is lost. If you sign up again, even with the same Google account, a new, separate user ID is issued and is not connected to the deleted account (subject to the legally retained records described at the end of this section).
- Tax / accounting records (billing and payment records): retained for as long as applicable law requires them to be kept for tax and accounting purposes. That period is determined by reference to the accounting period to which the transaction belongs, not to the date of account deletion. This information includes the name, email address, country, and postal code registered as billing information, which we and our payment provider retain after account deletion.
- Server logs and audit logs (records of errors, security events, and important operations, etc.): retained for as long as necessary to ensure security, prevent abuse, respond to system failures, and comply with legal obligations (operational logs for up to 14 days; error logs for up to one year; audit records of important operations for up to 3 years). To ensure the integrity of our records, audit records may include server logs generated by the same systems (including error log entries); these are retained as part of the audit records for the same period (up to 3 years). Team-level operation history (such as member additions and removals), and the country recorded on the team record, are retained for as long as the team exists.
- Team deletion records (team name, pseudonymized ID of the user who performed the deletion, payment-related customer ID, etc.): retained after the team is deleted, for as long as the related legal obligations and our legitimate interests continue, in order to prevent abuse and for audit and legal compliance.
- Backups for disaster recovery: retained for up to 30 days, after which they expire automatically. Deleted data may also remain in backups for up to 30 days.
- Temporary copies created to provide the Service, such as caches: those created by us and by the vendors we engage are retained only for as long as is necessary to provide it, and then expire automatically. Those created on your device so that content can be displayed are kept according to your browser's settings and can be deleted by you.
- Records and statistical information for usage and security monitoring (including IP addresses, the country, city, and region you connect from, and pseudonymized user IDs): retained for up to three months. Of these, IP addresses, the country you connect from, and pseudonymized user IDs may also be included in the server logs and audit records described above, in which case they are retained for up to one year as error logs and up to 3 years as audit records.
- Cookies: per each cookie's lifetime (section 12)
Even after account deletion, (i) records subject to a legal retention obligation (including the name, email address, country, and postal code registered as billing information), and audit records retained to prevent abuse and to ensure the integrity of our records, and (ii) pseudonymized user IDs contained in team records and audit records, remain in accordance with the criteria above. Account-layer data export files you have requested stop being downloadable 7 days after the request and are then deleted automatically.
12. Cookies
The Service uses only cookies that are strictly necessary to provide the Service (including payment fraud-prevention cookies set on the billing page by the script of our payment provider Stripe), plus functional cookies for your language and display preferences. We use no third-party advertising or analytics trackers. Strictly-necessary cookies do not require a prior-consent banner under law; for transparency we list them below:
- nproc_auth: maintains your authenticated session (essential, 7-day lifetime)
- nproc_oauth_state: CSRF protection during OAuth sign-in (essential, 10-minute lifetime)
- NEXT_LOCALE: stores your display language (functional, 1-year lifetime)
- np-color-mode: stores your display theme (functional, 1-year lifetime)
- np-contrast-mode: stores your display contrast preference (functional, 1-year lifetime)
- __stripe_mid: set by our payment provider Stripe's script (Stripe.js) when you open the billing page; used by Stripe to assess the risk of attempted payments and prevent fraud (essential, 1-year lifetime; see section 6)
- __stripe_sid: set by Stripe's script (Stripe.js) when you open the billing page; used by Stripe to assess the risk of attempted payments and prevent fraud (essential, 30-minute lifetime; see section 6)
You can configure your browser to refuse cookies, but some parts of the Service may then be unavailable.
13. Data Security
We implement appropriate organizational and technical measures to protect personal data against unauthorized access, leakage, alteration, and loss. These include encryption at rest (Cloudflare R2 / D1 / Durable Objects), TLS in transit, pseudonymized identifiers in logs, least-privilege access control, and point-in-time recovery. No system is completely infallible.
What we do if personal data is leaked or otherwise compromised depends on the capacity in which we hold that data and on the law that applies.
- For account-layer information (see section 4), we act as the controller. Where an incident falls within the cases for which the APPI requires a report, we report it to the Personal Information Protection Commission and also notify the individuals concerned. Where notifying individuals is difficult, we take alternative measures necessary to protect their rights and interests.
- For workspace-layer information, we act as a processor (see section 4). In that case we promptly notify the team, as the controller, of the matters required by law. Where we have given that notification as the law requires, the team is responsible for reporting to the authority and for responding to the individuals concerned. Where that notification does not relieve us of our own obligations, we report to the authority ourselves; and as regards notifying the individuals concerned, where we have no means of contacting them directly we take alternative measures necessary to protect their rights and interests.
- Where notification of a personal data breach is required under the law of the European Economic Area, the United Kingdom, or a comparable jurisdiction, then for information we handle as the controller we will, without undue delay and where feasible within 72 hours, notify the relevant supervisory authority, and will inform affected individuals where the breach is likely to result in a high risk to their rights and freedoms. For information we handle as a processor, we notify the team that controls it.
14. Third-Party Websites / Services
The Service may link to external sites or apps that we do not control. We recommend reviewing the privacy terms of any external platform you access through us. We are not responsible for the content or privacy practices of those third-party sites.
15. Children's Privacy
The Service is intended primarily for business use and is available only to users who are 18 years of age or older (see our Terms of Service). If we learn that we have collected information from a person under 18, we will delete it promptly.
16. Changes to this Policy
We may amend this Privacy Policy in response to changes in laws or regulations or to other reasonable circumstances. For material changes, we will notify you at least 30 days before the effective date, within the Service or by email to your registered address. If you continue to use the Service after the revised Policy takes effect, you are deemed to have agreed to the changes.
17. Contact Us
For questions about this Privacy Policy or to exercise your rights, please contact:
TR-55 Inc.
Kazumi Hirooka, Representative Director
Shibuya Mark City West 22F, 1-12-1 Dogenzaka, Shibuya-ku, Tokyo
150-0043, Japan
Email:
nproc-info@tr-55.com
Effective date: September 14, 2026