Privacy Policy
Effective Date: January 1, 2026
Last Updated: July 16, 2026
IMPACTLAKE Pte. Ltd. and IMPACTLAKE Co. Ltd. (each individually and collectively referred to as “IMPACTLAKE,” “we,” “us,” or “our”) comply with the Act on the Protection of Personal Information of Japan, the Personal Data Protection Act of Singapore, other applicable laws and regulations, governmental guidelines, and applicable contractual obligations. We appropriately manage personal data and other information that we collect or process.
This Privacy Policy is adopted by both entities as a common personal data protection policy. The adoption of a common policy does not mean that both entities jointly own, jointly use, or have unrestricted mutual access to all personal data. Each entity is responsible for personal data that it collects or processes in the course of its own operations.
This Privacy Policy applies to the handling of personal data in connection with our websites, services, products, platforms, inquiries, sales activities, contract and billing administration, support, and internal business operations.
Certain services, including impactlake Platform, may be subject to separate terms of use, privacy supplements, data processing agreements, API terms, acceptable use policies, research and benchmarking appendices, or individual agreements (collectively, “Service-Specific Terms”). This Privacy Policy supplements such Service-Specific Terms. To the extent of any conflict, the Service-Specific Terms will prevail with respect to the relevant service, unless prohibited by applicable law.
1. Entities Adopting this Privacy Policy
IMPACTLAKE Pte. Ltd.
Address: 11 Keng Cheow Street, #04-10, The Riverside Piazza, Singapore 059608
Representative: Reona Sekino
IMPACTLAKE Co. Ltd.
Address: GM Building 5F, 6-11-16 Sotokanda, Chiyoda-ku, Tokyo 101-0021, Japan
Representative: Reona Sekino, Representative Director
Each entity is independently responsible, in accordance with applicable law, for personal data that it collects or processes in the course of its own operations.
The roles of each entity in connection with a particular service, contract, or activity are determined by the applicable Service-Specific Terms, individual agreement, and Section 9 of this Policy.
2. Information We Collect or Process
Depending on the operations conducted by each entity, we may collect or process the following categories of information:
- Name, company name, department, title, email address, telephone number, and other contact information
- Account ID, email address, authentication information, identifiers used by external identity providers, multi-factor authentication information, and other account administration information
- Inquiries, chat communications, sales communications, contracts, and support records
- Contract, quotation, order, billing, payment, and billing-contact information
- Service usage history, operation logs, access logs, device information, cookies, IP addresses, and other technical information
- Personal data incidentally included in documents or materials provided by customers or business partners in the course of business
- Impact assessments, logic models, KPIs, reports, analytical results, and other information generated in connection with our services
- Personnel, labor, payroll, tax, social insurance, account administration, and training information relating to officers and personnel
- Individual Numbers processed by IMPACTLAKE Co. Ltd. for legally permitted tax and social insurance procedures in Japan
- Audio, video, chat, and transcript information collected from interviews or meetings with the participants’ permission
- Information obtained or generated from public information, corporate disclosures, integrated reports, statutory filings, official websites, and other publicly available sources
- Other information necessary for the provision of our services or the conduct of our business
Except where required by law or necessary for legitimate business operations, we do not collect sensitive personal information, special-category data, information relating to children, Individual Numbers, or other information requiring special care.
Unless expressly permitted by us or the relevant service operator, users and customers must not input sensitive personal information, Individual Numbers, passwords, API keys, authentication credentials, or other confidential information into data submitted for analysis through our services or into AI or API services.
3. Purposes of Use
Each entity may use personal data that it collects or processes for the following purposes:
- Providing, operating, maintaining, and improving our services, products, platforms, APIs, and related functions
- User registration, identity verification, account administration, and access control
- Responding to inquiries, chats, document requests, consultations, support requests, and service incidents
- Sales activities and the administration of contracts, quotations, orders, invoices, payments, and transactions
- Communications, proposals, implementation support, and customer support for customers and business partners
- Impact assessment, analysis, advice, report preparation, logic model and KPI design, and other contracted services
- Security, prevention of unauthorized use, log management, audits, and incident response
- Analysis of the use of our websites and services and improvement of their quality
- Preparation of statistical information, aggregated information, analytical results, and benchmark information that does not identify an individual or a specific customer
- Analysis, assessment, summarization, report preparation, and operational efficiency using AI and API services
- Personnel, labor, payroll, tax, social insurance, business communications, training, and account administration relating to officers and personnel
- Tax, social insurance, and other procedures for which IMPACTLAKE Co. Ltd. is legally permitted to use Individual Numbers in Japan
- Recording interviews or meetings and preparing recordings, minutes, and transcripts with the participants’ permission
- Compliance with laws, contracts, and terms of use, and protection of our rights
- Activities incidental or reasonably related to the purposes above
We will not use personal data beyond the scope necessary to achieve these purposes, except with the individual’s consent or as otherwise permitted by applicable law.
4. Relationship with impactlake Platform and Other Services
impactlake Platform is generally provided and operated by IMPACTLAKE Pte. Ltd.
For customers in Japan, IMPACTLAKE Co. Ltd. may perform contracting, billing, collection, payment acceptance, implementation support, inquiry handling, customer communications, or customer support based on an individual agreement, application form, order form, quotation, invoice, or other arrangement or practice.
Each entity processes information provided directly to it for the activities it performs, or information necessary to perform those activities, in accordance with this Privacy Policy, the applicable Service-Specific Terms, individual agreements, and applicable law.
The terms of use and policies applicable to impactlake Platform govern Platform-specific matters, including use of the Platform, account administration, usage logs, user content, data processing, subprocessors, international transfers, deletion and return, audits, and other Platform-specific matters.
Account and technical information necessary for user registration, authentication, contracts and billing, inquiry handling, security, and Platform operations may be processed in connection with the Platform.
Unless expressly permitted by us or the Platform operator, users and customers must not include personal data in data that they analyze, assess, or manage through the Platform.
5. Use of AI and API Services
We may use third-party AI and API services for service delivery, analysis, assessment, summarization, report preparation, and operational efficiency.
Before using an AI or API service, we review the applicable contractual or legal basis, whether submitted information may be used for model training, prohibited information, retention periods, logs, access controls, and allocation of responsibilities, and implement appropriate safeguards.
As a general rule, we do not input sensitive personal information, Individual Numbers, non-anonymized sensitive information, passwords, API keys, authentication credentials, customer-prohibited information, or other inappropriate information into AI or API services.
Where processing personal data is necessary, we confirm in advance the relevant consent, contractual or legal basis, use for model training, retention period, and applicable safeguards.
6. Anonymized, Statistical, and Analytical Information
We may use or retain statistical information, aggregated data, analytical results, benchmark information, and similar information that has been processed so that individuals or specific customers cannot be identified, for service improvement, research, analysis, quality improvement, and benchmarking.
When processing such information, we consider the risk of re-identification, the possibility that an individual or customer may be inferred from a small sample, contractual restrictions, and legal obligations.
Where information could identify or reasonably permit the inference of a specific individual or customer, we manage it with protections appropriate for personal data or customer confidential information.
7. Disclosure to Third Parties
We do not disclose personal data to third parties without the individual’s consent, except:
- Where required or permitted by law
- Where necessary to protect a person’s life, body, or property and obtaining consent is difficult
- Where especially necessary for public health or the sound development of children and obtaining consent is difficult
- Where cooperation with a national or local government authority is necessary for the performance of duties prescribed by law and obtaining consent may interfere with those duties
- Where processing is outsourced within the scope necessary to achieve the relevant purpose
- In connection with a merger, company split, business transfer, or other business succession
- Where matters required by law concerning joint use have been notified to the individual or publicly announced in advance
- Where otherwise permitted by applicable law
8. Outsourcing
We may outsource the following operations to third-party service providers within the scope necessary to achieve the purposes described in this Policy:
- Cloud and hosting services
- Authentication, email, chat, and customer relationship management
- Payment processing, billing, accounting, and tax services
- Website operations and access analytics
- Online meetings and transcription
- AI and API services
- System development, maintenance, operations, and security management
- Legal, labor, and social insurance services
- Other operations necessary for our business
We select service providers according to the nature of the outsourced operations and the information involved. We review contractual terms, confidentiality, security measures, access scope, subcontracting, incident notification, and return or deletion upon termination, and exercise necessary and appropriate supervision.
9. Roles of the Two Entities and Intercompany Processing
IMPACTLAKE Pte. Ltd. and IMPACTLAKE Co. Ltd. adopt this Privacy Policy as a common personal data protection policy. Each entity, however, remains independently responsible for personal data that it collects or processes in the course of its own operations.
Personal data is not automatically shared, jointly used, or made mutually accessible solely because the two entities are affiliated. At present, the two entities do not engage in continuous and comprehensive joint use of personal data solely on the basis of their corporate affiliation.
IMPACTLAKE Pte. Ltd. generally performs the provision and operation of impactlake Platform, account administration, security management, and other Platform-specific activities.
IMPACTLAKE Co. Ltd. generally performs sales, contracting, billing, implementation support, consulting, inquiry handling, and other activities conducted by the Japanese entity in Japan.
Where one entity needs to process personal data held by the other entity for a specific activity, including service delivery, contracting, billing, implementation support, inquiry handling, incident response, or security response, the entities will confirm the relevant purpose, categories of information, respective roles, access scope, and applicable law, and limit the processing to what is necessary.
Depending on the specific activity and flow of information, the legal relationship may be structured as outsourcing, processing on behalf of another party, disclosure to a third party, joint use, or another relationship permitted under applicable law.
Where the entities jointly use personal data, they will notify the individual or publicly announce in advance the categories of information jointly used, the scope of joint users, the purposes of use, the party responsible for management, and other matters required by applicable law.
10. Processing Outside the Country and International Transfers
We may use cloud services, SaaS, AI and API services, subprocessors, and other external services located outside the country in which personal data was collected. As a result, personal data may be stored or processed in another country or region.
Where IMPACTLAKE Co. Ltd. provides personal data to IMPACTLAKE Pte. Ltd. or makes personal data accessible from Singapore, or where either entity transfers personal data to another third party located outside the relevant country, we implement any notices, consents, contractual safeguards, or other measures required by applicable law.
We review the relevant legal system of the country or region, safeguards implemented by the service provider, contractual terms, and access controls, and implement necessary and appropriate security measures.
11. Cookies, Web Analytics, and External Transmission
We may use cookies, similar technologies, logs, and telemetry on our websites and services for authentication, session management, security, usage analysis, and quality improvement.
Google Analytics
We use Google Analytics, provided by Google LLC, to measure and analyze website usage and improve our services.
As a result, cookie identifiers, IP addresses, pages viewed, referrers, device information, browser information, and similar data are transmitted to Google LLC.
- Recipient: Google LLC
- Destination countries or regions: The United States and other countries or regions in which Google LLC processes information
- Information transmitted: Cookie identifiers, IP addresses, pages viewed, referrers, device information, browser information, and similar data
- Purpose: Measurement and analysis of website usage and service improvement
We do not use Google Signals or other functions that associate cookie information with individuals for advertising purposes.
Users may prevent Google Analytics from collecting information through their browser cookie settings or the Google Analytics Opt-out Browser Add-on.
Google Analytics Opt-out Browser Add-on:
https://tools.google.com/dlpage/gaoptout
Google Privacy Policy:
https://policies.google.com/privacy
HubSpot
We use HubSpot, provided by HubSpot, Inc., for inquiry handling, chat functions, customer communication history, and analysis of website access.
As a result, cookie identifiers, IP addresses, browsing and operation information, and information entered into chats or forms are transmitted to HubSpot.
- Recipient: HubSpot, Inc.
- Destination countries or regions: The United States and other countries or regions in which HubSpot, Inc. processes information
- Information transmitted: Cookie identifiers, IP addresses, browsing and operation information, information entered into chats or forms, and similar data
- Purpose: Responding to inquiries and chats, managing communication history, quality assurance, customer management, and measurement and analysis of website usage
HubSpot Privacy Policy:
https://legal.hubspot.com/privacy-policy
Where consent is required by applicable law, we obtain consent through a cookie banner or another appropriate method.
12. Security Measures
We implement measures to prevent leakage, loss, damage, unauthorized access, alteration, and misuse of personal data and customer confidential information, including:
- Policies and rules concerning personal data protection and information security
- Inventories of personal data, information assets, cloud services, and service providers
- Risk assessments concerning the processing of personal data
- Least-privilege access controls and procedures for granting, changing, removing, and periodically reviewing access
- Multi-factor authentication and management of authentication information, passwords, API keys, and secrets
- Encryption in transit and at rest, logging, audits, and vulnerability management
- Training and confidentiality obligations for officers and personnel
- Appropriate selection, contracting, and supervision of service providers
- Incident response, corrective action, and prevention of recurrence
- Controls for remote work, personally owned devices, and mobile devices
- Restrictions on information submitted to AI and API services and management of their use
13. Retention and Deletion
We retain personal data only for the period necessary to achieve the relevant purposes, comply with legal or contractual obligations, or satisfy legitimate business needs.
When personal data is no longer necessary, we delete, destroy, anonymize, or cease using it through appropriate methods.
We retain account information and usage records for the period necessary to provide services, maintain security, respond to inquiries, comply with contractual obligations, and address disputes.
We retain inquiry information and customer contact information for the period necessary for response handling, transaction administration, contractual obligations, statutory retention, and dispute resolution.
Audio, video, and transcript information is deleted after the purpose of the relevant meeting or interview has been achieved, unless retention remains necessary for contractual performance, preparation of deliverables, dispute resolution, or another legitimate purpose.
Individual Numbers processed by IMPACTLAKE Co. Ltd. are retained only while necessary for legally permitted procedures and for the applicable statutory retention period. When retention is no longer necessary, they are deleted in a manner that prevents restoration.
Information may be retained to the extent and for the period necessary for backups, statutory retention, audits, incident investigations, or dispute resolution.
14. Individual Rights and Requests
Subject to applicable law, an individual may make the following requests or inquiries concerning personal data processed by us:
- Information concerning the purpose or manner of processing
- Disclosure or access
- Correction, supplementation, or deletion
- Suspension, restriction, or erasure of processing
- Suspension of disclosure to third parties
- Disclosure of records relating to disclosure to third parties
- Withdrawal of consent
- Other requests or objections permitted by applicable law
To submit a request, please contact the Privacy Inquiry Desk specified in Section 15.
After verifying that the requester is the individual concerned or an authorized representative, we will respond in accordance with applicable law.
For requests submitted to IMPACTLAKE Co. Ltd., a fee of JPY 1,000 per request applies to requests for disclosure or notification of the purpose of use. The requester is responsible for bank transfer fees and other payment-related costs. No fee applies to requests for correction, supplementation, deletion, suspension of use, erasure, or suspension of disclosure to third parties.
15. Inquiries and Complaints
For questions, complaints, consultations, or requests concerning the processing of personal data, please contact:
IMPACTLAKE Pte. Ltd. / IMPACTLAKE Co. Ltd.
Privacy Inquiry Desk
Email: privacy@impactlake.com
For Platform-specific legal notices, notice-and-takedown requests, API matters, data processing agreements, or notices under the Platform terms, please use the contact specified in the terms of use and policies applicable to impactlake Platform.
16. Accredited Personal Information Protection Organization
IMPACTLAKE Co. Ltd. is not currently a covered business operator of an accredited personal information protection organization in Japan.
If IMPACTLAKE Co. Ltd. becomes a covered business operator of such an organization, its name and complaint-resolution contact information will be published in this section.
17. Changes to this Policy
We may revise this Privacy Policy in response to changes in laws, services, business operations, security requirements, or other circumstances.
Where a revision is material, we will provide notice by publishing it on our website or through another appropriate method.
18. Language
If there is any conflict or inconsistency between the Japanese and English versions of this Privacy Policy:
- The Japanese version will prevail with respect to the processing of personal data by IMPACTLAKE Co. Ltd. in Japan and the Matters to Be Publicly Announced Concerning Retained Personal Data set out below.
- The English version will prevail with respect to other matters governed by this common Privacy Policy.
- The language and priority provisions of the applicable Service-Specific Terms will apply to the use of impactlake Platform and other specific services.
Matters to Be Publicly Announced Concerning Retained Personal Data Held by IMPACTLAKE Co. Ltd.
The following matters apply to retained personal data held by IMPACTLAKE Co. Ltd. in Japan.
1. Name, Address, and Representative of the Business Operator
IMPACTLAKE Co. Ltd.
Address: GM Building 5F, 6-11-16 Sotokanda, Chiyoda-ku, Tokyo 101-0021, Japan
Representative: Reona Sekino, Representative Director
2. Personal Information Protection Manager
Personal Information Protection Manager: Representative Director
Contact: Privacy Inquiry Desk specified in Section 15 of this Policy
3. Purposes of Use of Retained Personal Data
Customer and Business Partner Contact Information
Conclusion and performance of contracts, provision of services, implementation support, customer support, billing and payment, proposals, and business communications.
Service User Information
Provision of services, identity verification, account administration, access control, security, quality improvement, support, and important notices.
Inquiry and Chat User Information
Responding to inquiries, consultations, document requests, sales communications, and support, and managing communication history.
Audio, Video, and Transcript Information from Interviews and Meetings
Recording meetings or interviews with participants’ permission and preparing minutes and deliverables.
Officer and Personnel Information
Personnel, labor, payroll, tax, social insurance, account administration, training, and business communications.
Individual Numbers of Officers and Personnel
Tax, social insurance, and other Individual Number-related procedures permitted by law.
4. Security Control Measures for Retained Personal Data
We implement the security measures described in Section 12 of this Policy.
Where external services located outside Japan are used, we review the personal data protection system of the relevant country or region and the measures implemented by the service provider, and use the service after understanding the external environment.
5. Procedures for Requests
Application contact: Privacy Inquiry Desk specified in Section 15 of this Policy.
Application method: Requests may be submitted using our prescribed request form or by email or another method accepted by us that includes the required information.
Identity verification: We verify the identity of the requester or the requester’s authorized representative using identification documents or another reasonable method. Where we receive a copy of an identification document, we promptly dispose of it after verification unless retention is necessary.
Requests through representatives: We verify a power of attorney or other document establishing the representative’s authority and identification documents for the representative.
Fee: JPY 1,000 per request for disclosure or notification of the purpose of use. The requester is responsible for bank transfer fees and other payment-related costs.
Response method: We respond without undue delay by the method specified by the individual, unless it is difficult to do so by that method.
6. Contact for Complaints and Consultations
IMPACTLAKE Co. Ltd.
Privacy Inquiry Desk
Email: privacy@impactlake.com
7. Accredited Personal Information Protection Organization
IMPACTLAKE Co. Ltd. is not currently a covered business operator of an accredited personal information protection organization.
