× Close 日本語

Privacy Policy

プライバシーポリシー

Value Transformation Laboratory Pte. Ltd. ("the Company") recognises the importance of protecting personal information. The Company complies with the Act on the Protection of Personal Information of Japan ("the Act") and handles and protects personal information in accordance with this Privacy Policy ("this Policy").

Unless this Policy provides otherwise, terms used in this Policy have the meanings given to them in the Act.

1. Definition of personal information, and compliance with laws

In this Policy, personal information means information about a living individual that falls under either of the following.

  1. Information that can identify a specific individual by the name, date of birth or other description contained in it (meaning anything written or recorded in a document, drawing or electromagnetic record, or expressed by voice, movement or any other method), including information that can readily be checked against other information and thereby identify a specific individual.
  2. Information that contains an individual identification code.

The Company also complies with the laws, government guidelines and other standards that apply to the handling of personal information.

2. Purposes of use

The Company uses personal information for the following purposes.

  1. To provide the services offered by the Company (together, "the Services").
  2. To bill for the Services, to give notices about them, and to respond to enquiries.
  3. For identity confirmation and authentication.
  4. To prevent conduct that is, or may be, improper or unlawful.
  5. To run surveys about the Services currently offered, or about services the Company is considering offering.
  6. To respond to enquiries from users of the Services ("Users").
  7. To plan and offer new services in the future.
  8. For system maintenance and for dealing with faults.
  9. To run draws for campaigns and to send prizes and goods.
  10. To send information about the Company's products and services.
  11. To deal with conduct that breaches the Company's terms, policies and similar rules relating to the Services ("the Terms").
  12. To give notice of changes to the Terms.
  13. To analyse information about how Users use the Services, in order to improve the Services and develop new ones.
  14. For employment administration and internal procedures (as regards the personal information of officers and employees), and for selection and contact in recruitment (as regards the personal information of applicants).
  15. For shareholder administration and for procedures required by the Companies Act and other laws (as regards the personal information of shareholders, holders of share options and the like).
  16. To create statistical data, processed so that no individual can be identified, in connection with the Services.
  17. For other purposes incidental to those listed above.

The information described in item 10 above is sent by email. If you do not wish to receive it, you can stop it at any time using the unsubscribe link included in those emails. Even after you have stopped it, the Company will continue to send messages that are necessary in order to provide the Services, such as confirmation of registration and notice of changes to the Terms.

3. Use of personal information

3.1 The Company does not handle personal information beyond the scope necessary to achieve the purposes of use without the consent of the person concerned, and takes measures to prevent use outside those purposes. This does not apply where the Act or other laws permit otherwise, or in the following cases.

  1. Where required by law.
  2. Where it is necessary in order to protect a person's life, body or property, and it is difficult to obtain the consent of the person concerned.
  3. Where it is especially necessary in order to improve public health or to promote the sound growth of children, and it is difficult to obtain the consent of the person concerned.
  4. Where it is necessary to co-operate with a national agency, a local government, or a party entrusted by either of them, in carrying out duties prescribed by law, and obtaining the consent of the person concerned is likely to impede those duties.
  5. Where personal data is provided to an academic research institution and that institution needs to handle it for the purpose of academic research (including where only part of the purpose is academic research, and excluding cases where the rights and interests of an individual would be unjustly infringed).

3.2 The Company does not use personal information in a way that may encourage or induce unlawful or unjust conduct.

3.3 The Company keeps personal information for the period necessary to achieve the purposes of use. Information relating to membership registration is deleted immediately upon a request to withdraw; it is not held for any grace period after withdrawal.

4. Proper acquisition

4.1 The Company acquires personal information properly, and does not acquire it by deception or other improper means.

4.2 Except in the following cases, the Company does not acquire special care-required personal information (as defined in Article 2, paragraph 3 of the Act) without obtaining the prior consent of the person concerned.

  1. Where any of items 1 to 4 of paragraph 3.1 applies.
  2. Where such information is acquired from an academic research institution and needs to be acquired for the purpose of academic research (limited to cases where the Company and that institution conduct the academic research jointly).
  3. Where such information has been made public by the person concerned, a national agency, a local government, an academic research institution, a party listed in any item of Article 57, paragraph 1 of the Act, or any other party prescribed by rules of the Personal Information Protection Commission.
  4. Where such information is acquired by observing or photographing the person concerned and is apparent from their outward appearance.
  5. Where such information is received from a third party and that provision falls under any item of paragraph 7.1.

4.3 When receiving personal information from a third party, the Company confirms the following matters as prescribed by rules of the Personal Information Protection Commission. This does not apply where the provision by that third party falls under any item of paragraph 3.1 or any item of paragraph 7.1.

  1. The name and address of the third party and, in the case of a corporation, the name of its representative.
  2. How the third party acquired the personal information.

4.4 In providing the Services, the Company may acquire your name, email address and other contact details, the answers you give at registration, information about your use of the Services, and other information necessary in order to provide the Services.

5. Security of personal information

Against the risks of loss, destruction, alteration and leakage of personal information, the Company takes reasonable security measures and corrective action, and exercises the necessary and appropriate supervision over its employees so that personal information is kept secure. Where the Company entrusts all or part of the handling of personal information to another party, it also exercises the necessary and appropriate supervision over that party so that personal information is kept secure there.

Basic policyThis Policy has been established as the basic policy for the proper handling of personal data, covering matters such as compliance with applicable laws and guidelines and the point of contact for questions and complaints.
Rules for handling personal dataRules for handling personal data have been established, setting out the method of handling, the person responsible, the person in charge and their duties, at each stage of acquisition, use, storage, provision, deletion and disposal.
Organisational measures1) A person responsible for the handling of personal data has been appointed; the employees who handle personal data and the scope of the personal data they handle have been made clear; and a route has been established for reporting to that responsible person any fact or sign of a breach of the Act or of the handling rules.
2) The state of handling of personal data is self-checked at regular intervals, and audits are carried out by other departments or by outside parties.
Personnel measures1) Employees receive regular training on the points to observe in handling personal data.
2) Confidentiality of personal data is provided for in the rules of employment.
Physical measures1) In areas where personal data is handled, entry and exit of employees is controlled and the equipment that may be brought in is restricted; measures are taken to prevent personal data from being seen by anyone without authority.
2) Measures are taken to prevent theft or loss of the equipment, electronic media and documents used to handle personal data; when such equipment or media is carried, including within an office, measures are taken so that the personal data cannot readily be identified.
Technical measures1) Access control is applied so that the persons in charge and the scope of the personal information databases they handle are limited.
2) Mechanisms are in place to protect the information systems that handle personal data from unauthorised external access and from malicious software.

6. Reporting of leaks

If a leak, loss, damage or similar incident occurs in relation to personal information handled by the Company, and the Act requires a report to the Personal Information Protection Commission and notice to the persons concerned, the Company will make that report and give that notice.

7. Provision to third parties

7.1 Except where any item of paragraph 3.1 applies, the Company does not provide personal information to a third party without obtaining the prior consent of the person concerned. However, the following do not constitute provision to a third party as described above.

  1. Where personal information is provided in connection with entrusting all or part of its handling to another party, within the scope necessary to achieve the purposes of use.
  2. Where personal information is provided in connection with a succession of business due to a merger or other cause.
  3. Where personal information is used jointly as provided for in the Act.

7.2 Notwithstanding paragraph 7.1, where the Company provides personal information to a third party in a foreign country, it obtains the prior consent of the person concerned to that provision.

7.3 When obtaining consent under paragraph 7.2, the Company provides the person concerned with the name of the foreign country, information about that country's system for the protection of personal information, and information about the measures that the third party takes to protect personal information.

7.4 When the Company has provided personal information to a third party, it creates and keeps records in accordance with Article 29 of the Act.

7.5 When the Company receives personal information from a third party, it makes the necessary confirmations and creates and keeps records of them in accordance with Article 30 of the Act.

7.6 In some of the Services, under a contract between the Company and a corporation or other organisation to which a User belongs, the Company may provide that organisation (including the person responsible for administering the contract) with the registration details and usage information of the Users concerned. The scope and conditions of such provision are set out in the terms of use for the service in question, and the Company makes such provision on the basis of the User's consent to those terms.

7.7 The Company is a corporation located in the Republic of Singapore, and users' personal information is handled in the Republic of Singapore. In addition, in providing the Services the Company uses infrastructure provided by businesses located in the United States and other countries (servers, email delivery, access analytics and the like), so personal information may be handled in those countries.

7.8 The Republic of Singapore has the Personal Data Protection Act, which sets out the obligations of businesses regarding the collection, use, disclosure, protection, retention and cross-border transfer of personal data. That Act is enforced by the Personal Data Protection Commission. The United States has no comprehensive federal law on the protection of personal information; it is governed by sector-specific federal laws and by the laws of each state. The Company applies the security measures set out in Article 5 to personal information handled in those countries as well.

8. Disclosure of personal information

8.1 Where a person requests disclosure of their personal information under the Act, the Company confirms that the request comes from that person and then makes the disclosure without delay. This does not apply where the Act or other laws do not place the Company under an obligation to disclose.

8.2 Requests for disclosure and similar matters should be made to the personal information enquiries desk below.

9. Correction of personal information

Where a person requests, under the Act, that the content of their personal information be corrected, added to or deleted on the ground that it is not true, the Company confirms that the request comes from that person, carries out the necessary investigation without delay within the scope necessary to achieve the purposes of use, corrects the content of the personal information on the basis of the result, and notifies that person accordingly.

10. Suspension of use of personal information

Where a person requests, under the Act, that use of their personal information be stopped or that it be erased, or that its provision to third parties be stopped, and it becomes clear that there are grounds for the request, the Company confirms that the request comes from that person, stops the use or the provision without delay, and notifies that person accordingly.

11. Cookies and other technologies

When you visit the Company's website, the Company may obtain technical information such as cookies, your IP address and the type of device you use. This information is used to analyse the environment in which users use the site, in order to provide a better service, and to prevent improper conduct that would interfere with the normal provision of the Services.

To understand how the website is used, the Company uses "Google Analytics", an access analysis tool provided by Google LLC. Google Analytics uses cookies to collect usage information in a form that does not identify individuals. The Company loads these analytics cookies only if you select "Accept" in the consent banner shown on your first visit to the site. If you select "Decline", analytics cookies are not used (your choice is remembered by your browser, and you will not be asked again). The information collected is managed in accordance with Google's privacy policy. You can also stop the collection of data by disabling cookies in your browser settings, or by using the Google Analytics Opt-out Browser Add-on.

The information sent from the Company's website to outside businesses is as follows.

RecipientInformation sentPurpose
Google LLC (Google Analytics)Identifiers such as cookies, the URL of the page viewed, information about your browser and device, and the date and time of accessTo understand how the website is used, and to improve the service
The Company (sign-in cookies and the like)Identifying information used for authenticationTo keep you signed in. This is necessary in order to provide the Services and is not subject to consent.

12. Contact

Requests for disclosure, comments, questions, complaints and other enquiries about the handling of personal information should be directed to the following.

13. Continuous improvement

The Company reviews how it handles personal information from time to time, works to improve it continuously, and may change this Policy as necessary.

In force from 7 September 2026

This is a translation of the Japanese original, provided for convenience. If the two differ, the Japanese version prevails.