Navigation

Data privacy policyおもてなし

v2.0 - Last Updated 2026.07.22

Data Privacy Policy

This Data Privacy Policy outlines Takara’s commitment to protecting personal information collected from users and clients. It details how data, including personal details, usage patterns, and client-provided information for AI development, is collected, used, and secured, emphasizing compliance with UK GDPR. The policy covers data security measures, retention periods, user rights regarding their data, and the processes for exercising those rights. It also addresses data processing agreements with clients, third-party processors, data breach response, and the use of cookies. Takara is transparent about its data handling practices and committed to maintaining user privacy.

This Policy applies to all users of our website (https://takara.ai), customers of our consulting and professional services, users of our API Service, and anyone who contacts us for support.

Takara is the Data Controller for the personal data described in this Policy, except where we act as a Data Processor on behalf of our clients (see Section 5).

1. Information Collection and Use

Information We Collect

We may collect the following types of information:

  • Personal Identification Information: Name, email address, phone number, billing address, and payment details when you create an account, purchase our services, or contact us in a business context.

  • Usage Data: Information on how you interact with our services, including access times, pages viewed, and features used, and API call metadata. API call metadata is limited to operational data such as request volumes, latency, and error rates; it does not include API payload content (i.e., input text or output vectors).

  • Device Information: Device type, operating system, browser type, IP address, and mobile device identifiers. This information is collected automatically via cookies and similar technologies.

  • Client-Provided Data: Where you engage Takara for AI consulting or professional services, you may provide us with datasets, documents, or other information as part of the engagement. Such data is processed in accordance with Section 5 of this Policy and any applicable Data Processing Agreement.

  • Support Interactions: When you contact our support team, we collect your name, email address, and the content of your support communications, including emails, support tickets, and chat messages.

  • API Service Data: Text submitted to our Embedding API Service is processed transiently and is NOT stored, retained, logged, or cached. See Section 6 of this Policy for a full explanation of our stateless processing architecture.

How We Use Your Information

We process your personal data only where we have a lawful basis to do so. We use your information for the following purposes:

  • To provide and maintain our services

  • To process transactions

  • To provide customer support

  • To send you service-related communications

  • To send you marketing communications

  • To improve our services

  • To provide the API service

  • To respond to your inquiries

  • To comply with legal obligations

  • Security and fraud prevention.

2. Customer Support Data

Given that customer support is a key area in which we process personal data as a Data Controller, this section provides specific detail about how we handle support-related data.

Aspect

Details

What we collect

Your name, email address, and the content of all support communications (emails, tickets, chat messages, telephone notes).

How we collect it

When you email our support team, submit a support ticket through our portal, use a live chat feature, or otherwise contact us for assistance.

Why we process it

To respond to your query; to resolve issues with our services; to maintain a record of interactions for continuity, quality assurance, and dispute resolution; and to improve our support services.

Lawful basis

Legitimate interest (Art. 6(1)(f) UK GDPR) — to respond to and resolve customer queries and maintain appropriate records of our support interactions.

Where it is stored

Support data may be processed in our support tools, including Linear, Notion, and email systems. See Section 7 for details of our sub-processors.

Retention period

Support correspondence is retained for 2 years from the date of last interaction, after which it is securely deleted or anonymised. Where a support query relates to an active contract, data is retained for the duration of the contract plus 2 years.

Your rights

You may request access to, correction of, or deletion of your support data at any time. See Section 10 of this Policy for details of how to exercise your rights.

3. Data Handling

Data Security

We deploy systems entirely on Amazon Web Services (AWS), adhering to the AWS Well-Architected Framework and AWS security best practices. Our security measures include:

  • Implementation of AWS’s robust security controls, including Virtual Private Clouds (VPCs), Security Groups, and Network Access Control Lists

  • Use of AES-256 encryption for data at rest via AWS’s native encryption services

  • Data in transit protection through TLS/SSL encryption

  • AWS IAM (Identity and Access Management) with role-based access controls and the principle of least privilege

  • Multi-factor authentication for all administrative access

  • Regular security assessments and audits of our AWS architecture

  • Real-time monitoring and logging using AWS CloudWatch and AWS CloudTrail

  • Automated security patching and updates for all infrastructure components

  • Regular backups with versioning to prevent data loss

  • For client-provided AI training data, we implement additional segregation controls through separate AWS accounts or isolated environments

  • API Service-Specific Measures

    • API Service payloads (input text and output vectors) are never logged, cached, or stored.

    • All API communications are encrypted using TLS 1.2 or higher.

    • No human operators have access to API payload data in transit.

Data Retention

We retain different types of data for specific periods:

  • Transaction Data: Retained for 7 years to comply with financial regulations.

  • Usage Logs: Retained for 90 days for security and analytics purposes.

  • Marketing Preferences: Retained until you opt out or request deletion.

  • Account data: Duration of account + 30 days after closure.

  • API Service payload data: Not retained (stateless processing).

  • Client-Provided Data for AI Development: Retained according to terms specified in our consulting agreement with each client. By default, this data is retained for the duration of the project plus 90 days, unless otherwise agreed upon in writing.

4. User Rights

Under the General Data Protection Regulation (GDPR) and UK data protection laws, you have rights over your personal data, including the right to access, correct, or delete your information. To exercise any of these rights, please email us at privacy@takara.ai. We will:

  • Verify your identity through our verification process (typically requiring account credentials or personal identifiers)

  • Respond to your request within 30 days

  • Extend this period by up to an additional 60 days if necessary, with notification

5. Client Data Processing

Where clients engage Takara for AI consulting or professional services and provide us with data containing personal information, Takara acts as a Data Processor on behalf of the client (who is the Data Controller). In such cases:

  • Processing Agreement: We enter into a formal data processing agreement that details the scope, purpose, and duration of processing.

  • Data Minimization: We work with clients to ensure only necessary data is provided for AI development.

  • Anonymization and Pseudonymization: Where appropriate, we implement anonymization or pseudonymization techniques to protect individual privacy when processing data for AI model training.

  • Specialized Handling: Client data used for AI training is segregated from other data and subject to enhanced security controls.

  • Return or Deletion: Upon project completion, client data is either returned or deleted according to the terms of our agreement, unless retention is required for model maintenance or agreed upon in writing.

  • On Instruction: We process such data only on the documented instructions of the client.

6. API Service - Stateless Processing

This section describes how personal data is handled in connection with our Embedding API Service specifically.

  • The Embedding API Service accepts text input and returns numerical vector representations (embeddings) of that text.

  • Processing is entirely transient. No input text or output vectors are stored, retained, logged, or cached following completion of the API Call.

  • Data exists in volatile memory only for the duration of the API Call. Upon completion, memory is released and data is irreversibly discarded.

  • No human operators have access to API payload data in transit.

  • Where API customers submit personal data via the API, the customer is the Data Controller and Takara is the Data Processor (governed by the DPA incorporated into the API Terms of Service at [URL]).

  • Takara collects only aggregated, anonymised usage metadata (request counts, latency, error rates) — never payload content.

This architecture is designed to implement the principles of privacy by design and data minimisation by default, as required by Article 25 of the UK GDPR.

7. Third-Party Services and Sub-Processors

We share your personal data with trusted third-party service providers ("sub-processors") where necessary to provide our services. We have entered into Data Processing Agreements with each sub-processor, ensuring that they process your data only according to our instructions and maintain appropriate security standards.

  1. Cloud Hosting Services (AWS): Store and process your data on secure servers.

  2. Payment Processors (Stripe): Process your payment information.

  3. Analytics Providers (Google Analytics): Help us understand service usage patterns.

  4. Email Service Providers (Monday.com): Facilitate email communications.

  5. Customer Support Tools (Linear, Notion, Microsoft, Slack): Manage project activities.

  6. Development and Operations: (GitHub): Manage code and CI / CD Pipelines.

We have executed Data Processing Agreements with each provider, ensuring they adhere to strict data protection standards and only process your data according to our instructions. These services are selected for their functionality and industry-standard security measures, but we encourage you to review their respective privacy policies for more details on how they handle your data.

Data Storage and Security

We take appropriate measures to protect your personal data. Any data we collect is stored securely and processed in compliance with applicable data protection laws. We ensure that any third-party services we use comply with high privacy and security standards, including GDPR requirements where applicable. We do not sell your personal data to third parties. We may disclose personal data to law enforcement or regulatory authorities where required by law.

International Data Transfers

Some of our sub-processors are based in the United States or other countries outside the United Kingdom and the European Economic Area. Where personal data is transferred to a country not covered by a UK adequacy decision, we ensure appropriate safeguards are in place, which may include:

  • UK International Data Transfer Agreement (IDTA);

  • UK Addendum to the EU Standard Contractual Clauses (EU SCCs);

  • Adequacy decisions by the UK Secretary of State; or

  • Other appropriate safeguards recognised under the Data Protection Act 2018.

8. General Provisions

Data Breaches

In the event of a data breach that risks your rights and freedoms, we will:

  1. Investigate and contain the breach promptly

  2. Notify affected individuals within 72 hours where feasible

  3. Provide clear information about the nature of the breach and steps we’re taking

  4. Notify relevant supervisory authorities as required by applicable law

  5. Take measures to mitigate potential adverse effects

  6. For client-provided data, notify the client according to the terms of our data processing agreement

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information. These are used for enhancing your experience, improving our website’s functionality, and supporting our marketing efforts. This includes cookies set by Google Analytics and Google Tag Manager for analytics purposes.

Changes to This Privacy Policy

We reserve the right to update or change our Privacy Policy at any time and without prior notice. Where changes are material, we will notify existing customers by email and/or prominent notice on our website at least 14 days before the changes take effect. Your continued use of our service after any modifications to the Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Data Privacy Policy. The "Last Updated" date and version number at the top of this document will be revised whenever changes are made. We encourage you to review this Policy periodically.

9. Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@takara.ai.

Ray graphicRay graphicRay graphic
Ray graphicRay graphicRay graphicRay graphic

Stay in the loop

Subscribe for the latest news & updates.