Information regarding personal data protection in the EU (or EEA)
1. Purpose of Processing EU Personal Data Acquired from Customers and Other Subjects Concerned GMO Internet, Inc. (hereinafter referred to as "Company", "we", "our" and "us"), as the entire company processing EU personal data, in accordance with the General Data Protection Regulation (effective on May 25, 2018) prescribed by the European Commission, we shall process customers' EU personal data only within the scope necessary for the intended use that is specified and publicized in advance. However, in the case where it is required by laws and regulations, we may process EU personal data of customers and other subjects beyond the scope necessary for achieving the intended use specified and publicized in advance. Moreover, providing EU personal data is indispensable for fulfilling contractual agreement, and therefore if EU personal data cannot be provided at each customer's own discretion, providing services to such customer may be hindered.
We uses personal information to the extent necessary to achieve the following each usage purposes for providing our services relating cryptocurrency (hereafter "our services") .
2. Rights of Customers and Other Subjects Concerned
Each customer or the other subject concerned has the following rights regarding EU personal data about himself or herself.
- Right to access to his or her own EU personal data and other information relating to its personal data.
- Right to rectify inaccuracies of his or her EU personal data without undue delay
- Right to erase his or her EU personal data without undue delay
- Right to restrict processing of his or her EU personal data
- Right to receive EU personal data provided by customer or other concerned subject by himself or herself in a general format that is readable on computers, and right to transfer (i.e. data portability) the EU personal data to other organizations in order for them to manage without hindering transferring process.
- Right to object to public interest; processing for the interests of Company, a third party or both; and processing for direct marketing for EU personal data of customers and other subjects concerned.
- Right not to be subjected to assessments conducted or decisions made through automatic processing such as profiling that have serious impact including legal effects on individuals.
- Right to lodge a complaint with a supervisory authority
3. Conditions for Processing of EU personal data
We may process EU personal data when any one of the following cases is applicable, even if we have not obtained consents from customers and/or others concerned.
- When the processing is necessary for the execution of the contract where a customer or other subject concerned himself or herself is the contracting party. Or when the processing is necessary in accordance with request from a customer or other subject concerned at the stage when the contract is not concluded yet.
- When the processing is necessary to comply with the legal obligation that we shall abide by; for example, when following information disclosure orders based on laws and regulations from government agencies etc.
- When the processing is necessary to protect serious interests of customers, other subjects concerned, or both.
- When it is deemed appropriate to investigate, prevent, or take measures against illegal acts or suspicious acts.
- When the processing is necessary for legitimate interests pursued by a third party or us to the extent that it is processing does not infringed right, profit, and freedom concerning the privacy of a customer or other subject concerned.
4. Special Types of EU Personal Data
In principle, in order to conduct various procedures concerning the services providing, we shall obtain prior consent from customers and other subjects concerned.
Moreover, we collect, use and transfer special types of EU personal data belonging to customers and other subjects concerned such as health conditions and physical characteristics that are necessary in relation to the scope of the purpose; and its EU personal data shall not be processed except for its purpose.
5. International Transfer of EU Personal Data
EU personal data is transferred to our group companies and outsourcing contractors such as cloud provider and IT service vendor; and may be stored in servers located in those respective country.
We manage EU personal data of customers and other subjects concerned appropriately.
In order to appropriately manage EU personal data of customers and other subjects concerned and prevent leakage, loss and damage of those EU personal data, including other safety management approaches, we carry out technical, physical, organizational and human related safeguards.
7. Joint Control
We jointly control EU personal data customers and other subjects concerned that we hold with our group companies in order to promote activities such as service development and service guidance; and communication with customers and other subjects concerned.
In addition, when we jointly control EU personal data with our group companies, the scope of responsibility relating to the processing of the personal data of customers and other subjects concerned, and the contact point for inquiries shall be clearly defined among us and group companies.
Items of EU personal data that we jointly control are stated as follows:
- Email address;
- Phone number;
- Contract details;
- Any other items necessary in accordance with the purpose of use (*)
* For details, please refer to the above section 1, "Purpose of Processing EU Personal Data Acquired from Customers and Other Subjects Concerned".
The joint controllers are the group companies of us that are listed on:
Note: Group companies may be changed in the future due to new establishment, consolidation, abolishment and other reasons.
8. Transfer of EU Personal Data
EU personal data belonging to customers and other subjects concerned are transferred to our group companies and outsourcing contractors such as cloud provider and IT service vendor to which we have subcontracted our business operation to the extent necessary for service provision.
In addition, we request appropriate processing of the transferred EU personal data to those outsourcing contractors, and manage EU personal data of customers and other subjects concerned appropriately.
9. Archiving, Deletion, Disposal of EU personal data
Except where otherwise specified by laws and regulations, we define the retention period of EU personal data of customers and other subjects concerned within the scope necessary for the purpose of use.
After the defined retention period has expired or the purpose of use has been achieved, we erase EU personal data of customers and other subjects concerned without delay.
10. About Cookies and Other Similar Technologies.
A cookie is an information used to transmit information from this site to your browser. When you, as a customer or other visitor, visit this site again, the cookie helps you to use this site more conveniently and is stored in your personal computers/devices.
Furthermore, the stored information does not include information such as your name, your residential address, your phone number and your email address which can be used to identify an individual.
Cookie does not also have negative effects on your computers/devices.
Cookie information that is collected from customers and other visitors will be transmitted to and stored in servers at Google LLC, Adobe Systems Incorporated and some other entities from our web servers.
We also obtain statistical data concerning access information such as the number of accesses and stay period for this site from stored data by using Google Analytics service, Adobe Analytics that is provided by Adobe Systems Incorporated and some other services.
It is possible to block cookie, if you, as a customer or other visitor, change the setting of your web-browser. In such cases, you will not have a trouble viewing this site except for some functions. Please make contact with the developer and/or distributor of the web-browser that you are using for its setting procedure.
11. Group-wide Data Protection Officer and Group-wide Representative for EU Personal Data
<Group-wide Data Protection Officer for EU Personal Data (G-DPO)>
GMO Internet, Inc.,
Cerulean Tower 4-14F, 26-1 Sakuragaokacho, Shibuya ku, Tokyo, 150-8512 , Japan.
Email address: email@example.com
<Group-wide Representative for EU Personal Data>
GMO GlobalSign Ltd.
Sandling Road, Maidstone, Kent
ME14 2LP, United Kingdom
E-mail address: firstname.lastname@example.org
12. Claims and Inquiries
13. Disclosure and other requests of EU personal data
Requests for Disclosure, correction, addition, deletion, suspension of use, suspension of provision of third party, transferring (data portability) shall be dealt with in the following manner.
Please be aware that we will not accept requests by telephone, fax, email, verbally or by any method other than that laid out below.
Please print out our prescribed form and fill in necessary information.
After filling in, please enclose the necessary documents, and send them to the following address by certified mail.
Cerulean Tower, 26-1 Sakuragaoka-cho, Shibuya-ku Tokyo
Disclosure and Other Requests Form is below,
Disclosure and Other Requests on EU Personal Data