Keizok

Personal Data Protection Policy

Effective Date: April 27, 2026

TimeTechnologies Co., Ltd. (the "Company") provides an AI-powered Social Networking Services (SNS) content generation SaaS service (including Instagram) called Keizok (the “Service”). The Company operates in compliance with applicable laws and regulations and respects the privacy of its users. Recognizing the importance of protecting and securing Personal Data, the Company uses reasonable efforts to ensure that the Personal Data it collects is used appropriately, securely, and in compliance with applicable personal data protection laws and regulations. This Personal Data Protection Policy (this "Policy") applies to users of the Service as well as to individuals who provide information through the Company's website (including the service landing page), such as by registering for the Waiting List. This Policy has been established to inform users, as Data Subjects, of the purposes and details of the collection, use, and/or disclosure of their Personal Data, and of their rights under applicable laws and regulations.

Article 1. Introduction

1.1 This Policy is established by TimeTechnologies Co., Ltd. (located at Roppongi T-Cube, 3-1-1 Roppongi, Minato-ku, Tokyo, Japan).

1.2 This Policy applies together with the Privacy Policy separately established by the Company (the “Common Policy”). If there is any inconsistency between them, this Privacy Policy prevails.

1.3 In this Policy, "Personal Data" means information relating to an identified or identifiable natural person, including directly identifying information such as names and email addresses, as well as information that may identify a specific individual when combined with other information, such as IP addresses, Cookies, Device IDs, and other technical identifiers.

Article 2. Information We Collect

The Company collects the following information.

(a) Information Provided Directly by Users

The Company collects the following information upon account registration for the Service:

  • Email address
  • Password (stored in hashed form)

The Company does not collect names, addresses, or telephone numbers as standard account registration items. If a User contacts the Company with an inquiry, support request, or other communication, the Company may record the content of such communication, contact information, and correspondence history.

(b) Information Collected through Waiting List Registration

The Company collects the following information from companies or individuals who register for pre-launch access to the Service (the "Waiting List"):

  • Email address
  • Type of business conducted
  • User’s website URL

No account is created at the time of Waiting List registration. If a registrant subsequently creates an account for the Service, the Company may, with the registrant's consent, link the information collected at Waiting List registration with the registrant's account information.

(c) Information Collected through External Authentication Services

Users may log in to the Service using Google or other external authentication services. In such cases, the Company may receive email addresses and other authentication-related information to the extent that the User has authorized sharing within the relevant external authentication service.

(d) Information Collected through Instagram Integration

If a User connects their Instagram account to the Service, the Company collects the following information through the Meta Graph API provided by Meta Platforms, Inc.:

  • Instagram user ID
  • Account name and display name
  • Profile image URL
  • Post images and videos
  • Post insight data (including, but not limited to, impressions, reaches, likes, saves, and shares)
  • Access token (stored in encrypted form)

The Company does not collect Users' Instagram passwords or direct message content. Instagram integration is subject to the terms of use and privacy policy of Meta Platforms, Inc.

The information above is used solely for the purpose of providing the features of the Service (including brand analysis, post content generation, and automatic posting) based on Users' instructions. The Company does not use such information for its own independent purposes.

(e) Website Information Collected through Automated Means

If a User enters the URL of their own store's website into the Service, the Company collects the following information from that website based on the User's instructions and with the User's consent:

  • Store name, brand concept, logo, and site images
  • Product images and product descriptions

(f) Payment and Contract-Related Information

If a User uses a paid plan, the Company processes payments through Stripe, Inc. or other payment-related service providers. Sensitive information relating to payment methods, such as credit card numbers, is not held by the Company and is managed by the relevant payment service provider. The Company holds the following information:

  • Payment history
  • Transaction ID
  • Subscription plan information

(g) Information Automatically Collected by the Company

When a User accesses the Service or related websites, the Company may automatically collect the following information:

  • IP address
  • Browser type and version
  • Language settings and time zone
  • Referring URL and access date/time
  • Operating system
  • Device identification information (Device ID, etc.)
  • Connection logs
  • Application logs (clicks, features used, access time and frequency, error information, performance data, etc.)

The Company may use Cookies, beacons, tags, and other similar technologies for the purpose of maintaining login status, ensuring security, improving convenience, and enhancing features.

Article 3. Purposes of Use

3.1 The Company uses collected information for the following purposes:

  • (a) Providing, operating, and maintaining the Service
  • (b) Setting up, authenticating, and managing Users' accounts
  • (c) Instagram integration, brand analysis, planning of posting strategies, and automatic content generation
  • (d) Providing paid plans, payment processing, billing management, and handling refunds
  • (e) Sending notices of important changes, updates, and notifications regarding the Service
  • (f) Providing customer support and improving the quality of responses
  • (g) Improving the features of the Service and developing new features
  • (h) Ensuring security, and detecting, preventing, and investigating unauthorized use and unauthorized access
  • (i) Handling failures, log analysis, internal auditing, and troubleshooting
  • (j) Analyzing usage patterns
  • (k) Notifications for marketing purposes
  • (l) Fulfilling accounting, tax filing, and other legal obligations
  • (m) Responding to and defending against legal claims

3.2 For certain features of the Service, information entered by Users may be sent to third-party AI services contracted by the Company for the purpose of content generation and analysis.

Article 4. Legal Basis for Processing of Personal Data

4.1 The Company processes Personal Data based on the following legal bases.

(a) Account Registration, Authentication, and Management — Performance of a Contract
The Company uses email addresses and passwords (hashed) for account registration, login authentication, account management, notification delivery, and language display.

(b) Providing and Operating the Service — Performance of a Contract
The Company uses Instagram integration information (user ID, account name and display name, profile image URL, post images and videos, and access token), as well as store information and product information collected through website scraping, for Instagram integration, brand analysis, planning of posting strategies, and automatic content generation.

(c) Payment Processing, Billing Management, and Handling Refunds — Performance of a Contract
The Company uses payment history, transaction IDs, and subscription plan information for payment processing, billing management, and handling refunds.

(d) Providing Customer Support — Performance of a Contract
The Company uses inquiry content, contact information, and correspondence history for providing support and improving the quality of responses.

(e) Accounting, Tax Processing, and Regulatory Compliance — Legal Obligation
The Company uses payment history and transaction IDs to fulfill legal obligations including accounting, tax filing, and responding to regulatory authorities.

(f) Ensuring Security and Preventing Unauthorized Use — Legitimate Interest
The Company uses IP addresses, usage history, and technical logs for detecting, preventing, and investigating unauthorized access, unauthorized use, and spam, as well as for handling failures, log analysis, and internal auditing. The Company determines that this processing is based on its legitimate interest in ensuring the safety of the Service and its Users, and does not unjustifiably infringe on Users' privacy interests.

(g) Improving the Service and Enhancing Features — Legitimate Interest
The Company uses strictly necessary Cookies and functional Cookies, Device IDs, and application logs for improving the features of the Service, enhancing the user experience, and conducting limited usage analysis.

(h) Waiting List Registration — Consent
With the registrant's consent, the Company processes email addresses, industry information, and shop URLs collected at Waiting List registration for the purposes of sending the Service notifications and analyzing prospective user demographics. Registrants may withdraw their consent and request removal from the Waiting List at any time. However, such withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

(i) Detailed Analysis of Usage Patterns — Consent
With Users' consent, the Company conducts detailed analysis of usage patterns through analytics Cookies. Users may withdraw their consent at any time. However, such withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

(j) Marketing Notifications — Consent
With Users' consent, the Company sends marketing notifications using email addresses. Users may unsubscribe at any time.

(k) Responding to and Defending Against Legal Claims — Legitimate Interest
The Company may use relevant Personal Data to the extent necessary to establish, exercise, or defend against legal claims.

4.2 The legal bases described above reflect the Company's general framework for lawful processing. In jurisdictions where a particular legal basis described in this section (such as legitimate interest) is not recognized or available under applicable local law, the Company processes the relevant Personal Data on the basis of the User's consent or other legal basis permitted under the laws of that jurisdiction. Where additional consent is required, the Company will obtain such consent before commencing the relevant processing.

Article 5. Entrustment and Disclosure of Data

5.1 The Company may disclose or entrust Personal Data to the following recipients only to the extent necessary for the purposes described in this Policy.

(a) Employees and Contractors
The Company's employees and contractors access Personal Data only to the extent necessary for business purposes. These persons are subject to appropriate confidentiality obligations.

(b) Service Providers
The Company may entrust or disclose Personal Data to the following service providers to the extent necessary for providing the Service:

  • Stripe, Inc. (United States): For payment processing, billing management, and tax compliance.
  • Meta Platforms, Inc. (United States): For providing the Instagram API integration feature.
  • Generative AI service providers: For generating and analyzing post content. The Company ensures, under data processing agreements entered into with the generative AI services it uses, that Personal Data sent by the Company is not used for model training by such service providers.
  • Access analytics tool providers: For analyzing usage patterns and improving the Service (based on Users' consent).

5.2 The Company implements necessary contractual, technical, and organizational safeguards with these service providers in accordance with applicable laws and regulations.

Article 6. International Data Transfers

6.1 The Company is based in Japan. In connection with the provision of the Service, Personal Data may be stored, processed, and transferred in Japan, the United States, Canada, Malaysia, and other countries where the Company or its service providers operate.

6.2 The Company implements the following contractual, technical, and organizational safeguards for such transfers in accordance with applicable laws and regulations:

  • (a) Entering into data processing agreements with service providers that include obligations relating to data protection, confidentiality, and security no less protective than those described in this Policy;
  • (b) Confirming that the destination country or the recipient maintains an adequate standard of personal data protection, or, where such standard has not been confirmed, implementing appropriate contractual safeguards; and
  • (c) Where required by applicable law, obtaining the User's consent prior to transferring Personal Data to a country that does not provide an adequate level of protection, after informing the User of the possible risks of such transfer, or establishing appropriate safeguards which supplement the User's consent in accordance with the applicable law.

Article 7. Retention Period

7.1 The Company retains Personal Data only for the period necessary for each processing purpose. In determining the appropriate retention period, the Company considers the nature and sensitivity of the data, the processing purpose, legal retention obligations, the need for dispute resolution, and other relevant circumstances. The target retention periods are as follows:

  • (a) Account information and service usage data: Deleted from active databases immediately after account cancellation and deleted from backups within [30] days thereafter.
  • (b) Waiting List registration information: If the registrant creates an account for the Service, this information is retained in accordance with the retention periods applicable to account information. If the registrant does not create an account, this information is deleted within [6] months after the general release of the Service. If the registrant withdraws consent, this information is deleted promptly.
  • (c) Access logs and technical logs: Deleted within [6] months from collection.
  • (d) Payment history, transaction IDs, and contract information: Retained in accordance with legal retention obligations (up to [7] years under Japanese tax and accounting laws and regulations).

7.2 Notwithstanding the above, the Company may retain Personal Data beyond the periods above if required by legal obligation, security needs, dispute resolution, or contractual necessity.

Article 8. Cookies and Tracking Technologies / Consent Management

8.1 The Company uses Cookies and other similar technologies (beacons, tags, scripts, etc.) for operating the Service, maintaining login status, ensuring security, analyzing usage patterns, and improving features.

8.2 The Cookies used by the Company are classified as follows:

  • (a) Strictly necessary Cookies: Cookies necessary for providing the basic features of the Service.
  • (b) Functional Cookies: Cookies used for maintaining login status, remembering language settings, and other convenience improvements.
  • (c) Analytics Cookies: Cookies used for detailed analysis of usage patterns.

These Cookies are processed on the applicable legal basis described in Article 4 of this Policy (legitimate interest for strictly necessary Cookies and functional Cookies, and consent for analytics Cookies, or such other legal basis as applicable in the User's jurisdiction).

8.3 The Company provides Users with the ability to manage Cookie settings through a CMP (Consent Management Platform) or other appropriate means. Users may change or manage Cookie settings in their browser or the CMP. However, if strictly necessary Cookies are disabled, some features of the Service may not function properly.

Article 9. Users' Rights

9.1 Under applicable data protection laws and regulations, Users may have the following rights with respect to Personal Data held by the Company:

  • (a) Right of access: The right to request confirmation of Personal Data being processed by the Company and to obtain a copy.
  • (b) Right to rectification: The right to request correction or completion of inaccurate or incomplete Personal Data.
  • (c) Right to erasure: The right to request deletion of Personal Data if certain conditions are met.
  • (d) Right to restriction of processing: The right to request restriction of the processing of Personal Data if certain conditions are met.
  • (e) Right to object: The right to object at any time, on grounds relating to a User's particular situation, to processing based on legitimate interest as its legal basis.
  • (f) Right to data portability: The right to receive Personal Data in a structured, commonly used, and machine-readable format, and to transfer it to another controller, to the extent permitted by applicable laws and regulations.
  • (g) Right to withdraw consent: The right to withdraw consent at any time for processing based on consent as its legal basis. However, such withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • (h) Right to lodge a complaint with a supervisory authority: The right to lodge a complaint with the competent supervisory authority if a User objects to the Company's processing of Personal Data.

9.2 Depending on the User's jurisdiction, additional rights may be available under applicable local law, including the right to request information about the categories of Personal Data collected and the categories of third parties to whom it has been disclosed, the right to direct the Company not to sell or share Personal Data, and the right not to receive discriminatory treatment for exercising data protection rights. As of the effective date of this Policy, the Company does not sell Personal Data and does not share Personal Data for advertising purposes. The specific rights available to each User are determined by the applicable law of the User's jurisdiction.

9.3 To exercise any of these rights, please contact the inquiry desk described in Article 16. The Company will respond within the period required by the applicable law of the User's jurisdiction, after verifying the User's identity and completing any other necessary verifications, in accordance with applicable laws and regulations.

Article 10. Children's Privacy

10.1 The Company does not knowingly collect Personal Data of individuals who are minors under applicable law without the consent of a parent or other legal guardian where required by such applicable law.

10.2 If the Company becomes aware that Personal Data of an individual who is a minor under applicable law has been provided without the consent of a parent or other legal guardian, the Company will promptly delete such information and take any other necessary measures. If you believe this may be the case, please contact the inquiry desk in Article 16.

Article 11. Security and Data Breach Notification

11.1 The Company implements appropriate administrative, technical, and physical security measures to prevent unauthorized access to, use of, alteration of, disclosure of, or destruction of Personal Data. However, data transmission over the internet and electronic storage methods cannot, by their nature, guarantee complete security. The Company implements reasonable measures, but does not guarantee absolute security.

11.2 In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (a "Data Breach"), the Company will comply with applicable breach notification obligations under the laws and regulations of the relevant jurisdiction, including notification to the competent supervisory authority and to affected Users where required. The Company maintains internal procedures for detecting, assessing, and responding to Data Breaches.

Article 12. Disclosure Required by Law / Disclosure for Protection of Rights

The Company may retain or disclose Personal Data if necessary to comply with applicable laws, regulations, court orders, legal proceedings, or requests from government authorities. The Company may also disclose Personal Data if it reasonably determines that such disclosure is necessary to prevent fraud, investigate illegal activities, enforce its terms of use or policies, or protect the rights, safety, or property of the Company, Users, or third parties.

Article 13. Business Transfer

If the Company's business is subject to a sale, acquisition, merger, business succession, or similar transaction, the Company will take reasonable measures to cause the acquiring entity to assume the obligations under this Policy. If there are material changes to the handling of Personal Data, the Company will notify Users in advance by email, notification through the Service, or other appropriate means, in accordance with applicable laws and regulations.

Article 14. Changes to This Policy

Unless otherwise stated, a revised Policy takes effect from the time it is published on the Service. If there are changes that materially affect Users' rights, the Company will notify Users in advance by email or notification through the Service.

Article 15. Complaints to Supervisory Authorities

If a User believes that the Company's processing of Personal Data violates the data protection laws of their place of residence, the User has the right to lodge a complaint with the data protection supervisory authority of their place of residence, place of work, or the place where the alleged violation occurred. The Company recommends that Users first contact the inquiry desk below to give the Company an opportunity to resolve the issue before lodging a complaint with a supervisory authority.

Article 16. Contact Information

For questions regarding this Policy, requests to exercise rights, complaints, or other inquiries regarding the handling of Personal Data, please contact:

Personal Data Inquiry Contact

Roppongi T-Cube, 3-1-1 Roppongi, Minato-ku, Tokyo 106-0032, Japan

TimeTechnologies Co., Ltd.

Personal Data Inquiry Contact Person

e-mail: privacy@timetechnologies.ltd

Personal Data Protection Manager

TimeTechnologies Co., Ltd., CEO, Tsuyoshi Shibata

e-mail: privacy@timetechnologies.ltd