Arqen ("we," "us," or "our") complies with Japan’s Act on the Protection of Personal Information and other applicable laws when handling personal information. This policy explains how we handle personal information and business data entrusted to us in connection with AI Training, Custom SaaS, Automation, Business Systems, Deal Desk, consultations, and this website.
1. Information we collect
- Consultation and booking data: company, industry, company size, name, role, email address, optional telephone number, service interest, optional challenges and notes, and requested meeting time.
- Training data: participant identity and affiliation, attendance and training records, training-side subsidy documentation, and approved work samples used in exercises.
- Implementation data: documents, quotations, invoices, reports, inventory data, messages, and other business information required for agreed Custom SaaS, Automation, or Business Systems work.
- Deal Desk data: international inquiry messages, attachments, and agreed case-ledger information.
- Website data: pages viewed, referrer, UTM parameters, browser language, screen size, device category, approximate country/region/city determined at the Cloudflare edge, time on page, and scroll events. We store only a salted hash of the IP address, not the raw IP address.
- Billing data: billing details. Payment processors hold card numbers; Arqen does not store complete card numbers.
2. Purposes of use
- Provide, scope, implement, maintain, and support the contracted service.
- Schedule meetings, respond to inquiries, and send proposals or service communications.
- Prepare training-side information for the customer’s own subsidy process. We do not file subsidy applications.
- Evaluate and improve services using data processed so individuals are not identified where practicable.
- Manage contracts, billing, records, security, misuse prevention, and legal compliance.
- Provide relevant service information where permitted, with an unsubscribe option.
3. Disclosure to third parties
We do not provide personal information to third parties except with consent, when required by law, or when necessary to protect life, physical safety, or property and obtaining consent is difficult.
4. Processors and external services
Depending on the contracted scope, we may use service providers including Anthropic or OpenAI for AI processing; Google Workspace for email, calendar, and collaboration; Slack, Notion, or Google Sheets for agreed operations; Make or Zapier for workflow automation; Stripe or Square for payments; Cloudflare for hosting, edge processing, and analytics; and Google Apps Script for booking operations. Some services listed here may be included for future readiness and are not used in every engagement.
| Purpose | Example provider / region |
|---|---|
| AI processing | Anthropic Claude API / OpenAI API · primarily United States |
| Email, calendar, collaboration | Google Workspace / Slack · United States |
| Knowledge and workflow records | Notion / Google Sheets · United States |
| Workflow automation | Make / Zapier · EU / United States |
| Payments | Stripe / Square · Japan / United States |
| Hosting and edge processing | Cloudflare Pages / Workers / Analytics Engine · global including Japan and United States |
| Booking operations | Google Apps Script / Calendar / Gmail · United States |
| Web fonts | Google Fonts · United States; the visitor IP address is transmitted when fonts are requested |
5. International transfer and AI processing
We use business/API configurations that state submitted API data is not used to train general AI models. Provider terms and controls may change, so applicable settings are confirmed for the selected service and contract.
6. Customer business data
- Confidentiality terms are included in the services agreement or a separate NDA.
- Entrusted data is used only for the agreed service purpose.
- Customers should control internal disclosure and mask personal data or trade secrets where practicable.
- After service cancellation, the standard retention period for business data is 30 days, excluding backups and records required by law or contract.
- For Custom SaaS, customer business data belongs to the customer. Deliverable and export terms are defined in the contract.
- AI-produced candidate issues, summaries, or checklists are not legal advice. Consult qualified counsel for legal decisions.
7. Security measures
Measures include responsible-person assignment, confidentiality obligations, TLS encryption, protected secret storage, multi-factor authentication where available, access logging, encrypted work devices, screen locking, and avoiding transport of business data on removable physical media.
8. Retention
- Inquiry information: three years from collection.
- Customer and contract records: five years after contract end, subject to tax and recordkeeping requirements.
- Operational business data: normally 30 days after contract end, except backups and required records.
- Website event data: 90 days; access logs may be retained for six months.
- Invoices and accounting records: the period required by applicable law, normally seven years.
9. Access, correction, deletion, and restriction
You may request access, correction, addition, deletion, suspension of use, or suspension of third-party provision for your personal information. After identity verification, we normally respond within two weeks. When deletion is requested, we delete promptly under our defined procedure, except where laws or contracts require retention.
Contact hello@arqen.jp with the subject “Personal Information Request.”
10. Cookies and analytics
Our first-party analytics uses Cloudflare Workers and Analytics Engine and stores an anonymous browser identifier in localStorage/sessionStorage rather than a first-party analytics cookie. Raw IP addresses are not stored. Event data may include page views, scrolls, and clicks. Cloudflare Web Analytics provides aggregate, cookie-free statistics.
If Google advertising is activated, Google conversion-measurement cookies may be used for visits from advertisements under Google’s policies. As stated in the Japanese policy, this was not active as of August 1, 2026. We will update this policy and implement consent where required before materially expanding cookie-based tracking.
To reset our browser identifier, remove localStorage/sessionStorage items beginning with arqen_. To request exclusion, contact hello@arqen.jp.
11. Children
Our services are intended for businesses and sole proprietors, not primarily for minors. If we learn that we have collected a minor’s personal information, we will handle it after confirming appropriate guardian consent where required.
12. Changes to this policy
We may update this policy for legal, service, or operational changes. Material changes will be announced on this website or sent to the registered contact where appropriate. The revised policy takes effect when published.
13. Contact
Operator: Arqen
Email: hello@arqen.jp
Address: see the Commercial Transactions Disclosure.