Privacy Policy
Last revised: September 7, 2026
In providing the cloud infrastructure service "UGOEMO Cloud" (the "Service"), Ugoemo Inc. (the "Provider") complies with the Act on the Protection of Personal Information and other applicable laws, and sets out this Privacy Policy (the "Policy") regarding the personal information it collects.
Article 1 (Details of the business operator)
The business operator handling personal information for the Service is as follows.
Operator: Ugoemo Inc. Personal information manager: Naoya Iida Address: 70 Wing Tsuchiya, Narita-shi, Chiba 286-0029, Japan Contact: [email protected]
Article 2 (Definitions)
In this Policy, the following words have the meanings set out below.
- "Personal information" means personal information as defined in Article 2, paragraph 1 of the Act on the Protection of Personal Information.
- "Retained personal data" means retained personal data as defined in Article 16, paragraph 4 of that Act.
- "User" means a person who has registered for the Service, or who uses the contact form on the Service.
- "User Content" means data that a User stores on a virtual machine, database, bucket or other resource, or transmits through the Service.
- "Cookie" means a small identifying piece of data that a website asks the browser to store.
Article 3 (Information we collect)
1. In providing the Service, we collect the following information.
- Account information — name, email address, password (stored as a hash; never in plain text), the Ugo Account user identifier, the date the email address was verified, notification preferences, the referral code and the referring account
- Billing information — recipient name, company name, billing email address, postal code, prefecture, city, street address, building name, telephone number and qualified invoice issuer registration number
- Payment information — the PayPal account identifier and the linked email address; for card payments, the customer identifier, the payment method identifier, the card brand and the last four digits. Full card numbers and security codes are held by the payment providers and are not collected by us.
- Transaction information — invoices and their line items, records of payments and refunds, the history of point credits and debits, and redemption code usage
- Operation history — sign-ins and failed sign-ins, password changes, creation, deletion, start, stop and restart of resources, console connections, bucket creation, issue and revocation of access keys, database creation and other operations, together with their content, timestamp and source IP address
- Operational information — resource state, resource usage, data transfer volumes, the IP and MAC addresses assigned to resources, database connection counts, query rates, cache hit rates and data size, and Object Storage capacity in use
- Enquiry information — name, email address, the category and content of the enquiry, and the record of correspondence with us
- Device and browsing information — IP address, browser and OS type, referrer, pages viewed, times of access, and identifiers stored in cookies
2. We do not collect special care-required personal information. Please take care not to send such information through enquiries or elsewhere.
Article 4 (How we collect it)
We collect the information in the preceding Article through entry by the User, linkage from the Ugo Account, notifications from payment providers, and automatic recording that accompanies use of the Service.
Article 5 (Purposes of use)
We use the information we collect for the following purposes.
- To provide the Service and to build and operate resources
- To verify identity, authenticate Users and manage accounts
- To calculate fees, issue invoices, and process and collect payments
- To grant and manage points and to calculate referral benefits
- To respond to enquiries, provide support and investigate incidents
- To give notice of billing, incidents, maintenance and other important matters
- To send announcements and incident information to Users who have opted in
- To analyse usage in order to maintain and improve quality and develop new features
- To keep the platform stable and allocate capacity appropriately
- To detect, prevent and respond to misuse, breaches of the terms and attacks
- To comply with the law and to respond in the event of a dispute
Article 6 (Changes to the purposes of use)
We may change the purposes of use within a scope that can reasonably be regarded as related to the purposes before the change. Any such change will be notified by publication within the Service.
Article 7 (Handling of User Content)
1. In normal operation we do not inspect the contents of User Content stored on virtual machines, databases or buckets.
2. Notwithstanding the preceding paragraph, we may inspect it to the extent necessary where the law requires it, where we are responding to a rights infringement report, where we have the User's consent for incident investigation, or where there is another legitimate reason.
3. Where User Content contains personal information, the User is responsible for managing that information, and we handle it only to the extent necessary to provide the Service.
Article 8 (Provision to third parties)
We do not provide personal information to third parties without the User's prior consent, except in the following cases.
- Where required by law
- Where necessary to protect the life, body or property of a person and it is difficult to obtain the User's consent
- Where particularly necessary to improve public health or promote the sound growth of children and it is difficult to obtain the User's consent
- Where cooperation is needed for a national or local government body, or a party commissioned by one, to carry out statutory duties, and obtaining consent would impede those duties
- Where the information is provided in connection with outsourcing under Article 9
- Where the information is transferred in connection with a merger or other succession of business
Article 9 (Outsourcing)
We may outsource the handling of personal information to the extent necessary to achieve the purposes of use. In that case we verify the suitability of the contractor and exercise necessary and appropriate supervision over security management by contract.
Article 10 (Third-party services we use)
1. We use the following third-party services to provide the Service, and the information listed for each is sent to that provider. How each provider handles that information is governed by its own privacy policy.
- Ugo Account (single sign-on) — the user identifier, name, email address and its verification status
- PayPal (payments) — the amount required for payment, the order identifier and PayPal account details
- Stripe (card payments) — the amount required for payment, the customer and payment method identifiers, and card details (card details are collected by Stripe directly)
- Google reCAPTCHA (preventing automated access) — IP address, browser information and information about your interactions
- Google Analytics (usage analytics) — pages viewed, times of access, referrer, IP address and identifiers stored in cookies
- Cloudflare (DNS and content delivery) — source IP address and request information
- The SMTP server used to deliver email — the recipient's email address and the body of the message
2. Apart from the preceding paragraph, we do not jointly use personal information with external providers without the User's consent.
Article 11 (Use of cookies)
1. We use cookies for the following purposes.
- Keeping you signed in (session identification; this is essential to use the Service)
- Remembering your display language and other preferences
- Understanding usage through analytics
2. You can refuse cookies in your browser settings. However, if you refuse the cookie used to keep you signed in, you will not be able to sign in to the console.
Article 12 (Analytics)
We use Google Analytics for usage analytics on our public pages. Google Analytics collects information using cookies, but this does not identify you personally. You can opt out by installing the browser add-on that Google provides for that purpose.
Article 13 (Transfers to third parties overseas)
Some of the third-party services listed in Article 10 are operated outside Japan, and the information described in that Article may be sent to servers in those countries. We use these providers having confirmed that they have measures in place to protect personal information.
Article 14 (Security measures)
To prevent the leakage, loss or damage of personal information and otherwise keep it secure, we take the following measures.
- Organisational — defining who handles personal information and the scope of that handling, and maintaining a structure in which handling can be reviewed
- Personnel — making those involved aware of the points to observe when handling personal information
- Physical — installing equipment in locked areas and restricting the removal of equipment and storage media
- Technical — setting access privileges according to the level of administration, encrypting communications, hashing passwords, encrypting database credentials, and recording operations
Article 15 (Retention and deletion)
1. We retain personal information for as long as is necessary to achieve the purposes of use.
2. Invoices, transaction records and other information we are required by law to keep are retained for the statutory period, including after the contract ends.
3. When a resource is deleted, the User Content stored on it is lost immediately and cannot be restored.
4. Information whose retention period has passed is deleted, or erased in a way that cannot be reversed, without delay.
Article 16 (Disclosure, correction and suspension of use)
1. Users may request notification of the purposes of use, disclosure, disclosure of third-party provision records, correction, addition, deletion, suspension of use, erasure, and suspension of provision to third parties in respect of their own retained personal data.
2. Requests should be sent to the contact in Article 21. We will confirm that the request comes from the person concerned or their representative and respond without delay in accordance with the law.
3. We may be unable to comply where the subject of the request is not retained personal data, where the law does not permit compliance, or where complying would breach another law. In that case we will tell you, with reasons.
4. Responses to disclosure requests are given by email as a rule.
Article 17 (Minors)
If a minor uses the Service, please obtain the consent of their legal representative before providing personal information.
Article 18 (Secrecy of communications)
We protect the secrecy of communications learned in the course of providing the Service, in accordance with the Telecommunications Business Act. We do not handle the contents of communications except where the law so provides or the act is otherwise justified.
Article 19 (Response to a data breach)
If personal data is leaked, lost or damaged, or a comparable event occurs, we will promptly investigate the facts, report to the Personal Information Protection Commission and notify the individuals concerned as the law requires, and take the measures needed to prevent recurrence.
Article 20 (Changes to this Policy)
We may amend this Policy in response to changes in the law or in the Service. Significant amendments will be announced in advance on the news page of the Service or by other appropriate means. The amended Policy takes effect when it is published within the Service.
Article 21 (Contact)
Enquiries about this Policy, requests for disclosure and complaints about our handling of personal information should be sent through the contact form on the Service or to the contact below.
Operator: Ugoemo Inc. Personal information manager: Naoya Iida Address: 70 Wing Tsuchiya, Narita-shi, Chiba 286-0029, Japan Email: [email protected]