§0 · Pre-Launch Invitation-Only Phase Effectiveness Override | プレローンチ招待制フェーズ適用除外条項
// APPLIES DURING PRE-LAUNCH INVITATION-ONLY PHASE · SUPERSEDES CONFLICTING CLAUSES BELOW
From the effective date above until the official General Availability ("GA") launch date as published at the top of this document, this §0 overrides any conflicting provision elsewhere in this Privacy Policy for every registrant who participates by invitation in this pre-launch phase:
- No binding commercial processing. No processing performed during this phase creates a Controller / Processor commercial relationship with attendant APPI/GDPR fee-bearing obligations. All data submitted is pre-launch invite-scope provisional data.
- Data is provisional, with tiered handling. Financial Data · 財務データ: Test-mode order records, test invoices, Stripe/4242-test-card receipt metadata, onboarding consent audit ledger rows, APPI/GDPR consent capture artefacts, and JCT-relevant test records are intentionally preserved during this pre-launch phase and are NOT subject to arbitrary cluster rebuilds, unless retention becomes inconsistent with mandatory applicable law. Config Data · 設定データ: Theme preferences, catalog entries, token placeholders, sample passwords, demo storefront layouts, and non-financial tenant configuration MAY be anonymized, reset, or deleted at any time in connection with a scheduled test-cluster rebuild; where commercially reasonable and operationally feasible, QKay will provide advance notice via the registered Merchant contact email before a non-emergency rebuild.
- Retention carve-out. The tiered retention schedule in §9 applies in full at GA. During this invitation-only pre-launch phase, Financial Data (as tiered above) follows the §9 statutory retention floors, while Config Data tiers may be destroyed on a shorter cadence at QKay's sole operational discretion, with no obligation to produce an export or record prior to destruction, except as otherwise required by mandatory applicable law.
- Forward-looking references. All references to 1.0% platform usage fee donation programmes, 5% subscription allocation streams, signed fincode Platform Sub-Account DPA annexes, and production-tier signed SCC/IDTA copies elsewhere in this document describe the intended GA-launch state and do not create any processing commitment during this invitation-only pre-launch phase.
- Suspensions. Breach-notification, data-subject-rights response SLA, and DPA annex fee-bearing commitments are fully SUSPENDED during this invitation-only pre-launch phase to the maximum extent permitted by mandatory applicable law; QKay will still respond commercially reasonably and in good faith to any report or request from an invited test participant.
【日本語参考】上記発効日から正式GAリリース日までの招待制プレローンチフェーズ中は、本項§0が本プライバシーポリシーの他の条項に優先して適用されます。商用の管理責任者・処理者関係・料金債務は一切発生しません。提出された個人データは招待テスト限定の暫定データであり、階層的に取り扱われます:財務関連データ(テスト注文・テスト請求書・Stripe 4242テストカード受領メタデータ・オンボーディング同意監査証跡・APPI/GDPR同意取得記録・JCT関連のテスト記録)は、強行法規に反しない限り、本フェーズ中は原則として保存され、無差別なクラスタ再構築の対象とはなりません。設定データ(テーマ設定・カタログ・トークンプレースホルダー・デモ店舗レイアウト・パスワード等)は、テストクラスタ再構築に伴い、随時リセット・削除・匿名化される場合があります。非緊急時の再構築については、商業的に合理的かつ運用可能な範囲で、登録メールアドレス宛に事前通知を行うよう努めます。第9条の保存期間(財務データは法定保存期間下限を準用)、第10条の権利行使SLA、第12.5条の漏えい通知の一部確定型コミットメントは、強行法規に反しない限度において招待制プレローンチフェーズ中は全面的に適用停止します。寄付・SCC/IDTA等に関する記述はGAリリース時の予定実装状態を説明したものであり、本フェーズ中の法的拘束力ある処理義務を構成しません。
1. Operator | 事業者情報
QKay | operated by QinetiK Labs 「キネティック・ラブズ / 事業準備中」
Contact for privacy / data inquiries 「個人情報・データに関するお問い合わせ先」: support@qkay.jp
Pre-GA operator disclosure 「事業準備中」: Operating entity is scheduled for incorporation as a 合同会社 QinetiK Labs (planned registered head office: Osaka Prefecture, Japan) during Q4 2026. Upon incorporation this §1 will be updated with the final registered 法人名 (planned: 合同会社QinetiK Labs / 合同会社キネティック・ラブズ), 本店所在地, and 代表者氏名 of the incorporated operator, with a §14 policy update notice if required. No processing performed during this invitation-only pre-launch phase relies on the yet-unincorporated entity as a Controller party for APPI purposes.
2. Scope | Components Covered by this Policy / 適用範囲「対象サービス構成要素」
This Privacy Policy applies to personal data processed across the following publicly identifiable components of the QKay platform.
| Component / 構成要素 | Purpose / 役割 | Processes PII? |
|---|---|---|
| QKay「this site: qkay.jp」 | Merchant registration, Terms/PP presentation, Stripe checkout initiation, onboarding webhooks. | YES 「merchant onboarding data」 |
| QKay Management Dashboard「kanri.qkay.jp | admin dashboard」 | Merchant administration panel: product catalog, order management, integration token storage & toggles, customer list, refund actions. | YES 「merchant admin actions + customer data as Processor」 |
QKay Tenant Storefronts「tenant-facing storefronts:your-store.**.qkay.jppattern + Merchant custom domains」 | Renders the Merchant's public headless storefront 「product pages, cart, checkout」. Pulls content from microCMS and product data from a Shopify storefront preview evaluation or from the Merchant's QKay native catalog, as configured. | YES 「storefront end-customer orders, guest checkout PII」 |
3. Personal Data We Collect | 収集する個人データ
3.1 Merchant onboarding 「QKay → QKay Management Dashboard」
When a Merchant applicant submits the registration form on qkay.jp and completes Stripe checkout, we collect and store the following merchant-account data 「tenant-scoped」 for the lifetime of the account, plus applicable statutory retention windows:
// ENCRYPTION & TRANSPORT · GDPR Art.32(1)(a) | APPI 安全管理措置準拠
Data Storage Encryption | データストレージの暗号化 · Storage architectures utilize industry-standard advanced encryption. Persistent data-at-rest within the managed relational database infrastructure and user-authentication stores are secured using AES-256 cryptographic standards.
データストレージの暗号化 · ストレージ構成には、業界標準の高度な暗号化技術が採用されています。管理対象のトポロジーを構成するリレーショナルデータベース基盤およびユーザー認証ストア内のすべての永続データ(静的データ)は、AES-256暗号化規格によって保護されています。
Network & Endpoint Communication | ネットワーク通信 · All network communication to and within platform endpoints forces the exclusive use of TLS 1.3 encryption protocols. Unencrypted HTTP traffic is redirected to HTTPS with HSTS headers where supported by the edge infrastructure.
ネットワーク通信 · プラットフォームのエンドポイントへ向かう、およびその内部で行われるすべてのネットワーク通信は、TLS 1.3暗号化プロトコルの使用を強制しています。エッジインフラストラクチャが対応する範囲で、非暗号HTTP通信はHTTPSへリダイレクトされ、HSTSヘッダーが付与されます。
| Data item | 項目 | Example | Source | 取得元 |
|---|---|---|
| First + last name | 氏名 | Tarō Tanaka | Registration form |
| Email | メールアドレス | you@example.com | Registration form; Clerk auth, MFA, onboarding email |
| Brand | 屋号・ブランド名 | ACME Store | Registration form |
| Password | パスワード | 「hashed, never stored by QKay」 | Clerk only |
| Subdomain slug | サブドメイン | acme → acme.**.qkay.jp | Registration form |
| Platform type | プラットフォーム種別 | Native catalog, or Shopify storefront preview evaluation | Registration form 「radio」 |
| Base cluster domain | ベースクラスタドメイン | Assigned from an expanding list of QKay-operated cluster domains | Registration form 「select」 |
| Security telemetry | セキュリティテレメトリ | CAPTCHA result, honeypot, request IP, UA | Turnstile + server logs 「14-day default · see §9 Retention · footnote exception for APT / fraud / active-incident forensic retention beyond 14 days」 |
| Checkout consents | Terms, PP, cross-border transfer acceptance | Registration form checkboxes |
3.2 Payment data at registration 「QKay marketing site | Stripe」
Cardholder name, PAN, CVC, expiry are processed on Stripe's PCI-DSS hosted checkout only. QKay never sees or stores them, only receives confirmation ID, email, and billing-address anti-fraud fields.
3.3 Payment data at customer checkout 「QKay Tenant Storefronts | fincode byGMO」
Merchants who enable a Platform Sub-Account on GMO/fincode consent to the 1.0% gross-sales usage fee and donation programme allocation detailed in theTerms §X 「Article X」.
- Customer payment tokens captured directly by fincode components, QKay never stores PAN/CVC.
- Upon capture, fincode auto-deducts the 1.0% platform fee via revenue-share offset before deposit to Merchant's bank.
- Order-level records 「order ID, gross amount, fee %, fincode transaction ID, last-mask card brand, customer email」 are stored tenant-scoped for refunds, reconciliation, and fee auditing.
3.4 Integration credentials 「QKay Management Dashboard」
When a Merchant optionally toggles a connected-service integration, we store the corresponding tenant-scoped secrets and identifiers 「access tokens, API keys, service URLs, sub-account keys」 in an encrypted, tenant-isolated credential store. The integrated services offered at launch are:
- Shopify Admin API 「opt-in preview evaluation」: store URL + access token, for headless catalog sync during a Shopify storefront preview-evaluation mode.
- microCMS 「opt-in, supported headless content provider」: service domain + API key.
- Payment gateways 「opt-in per Merchant」: Stripe account keys, and 「subject to Platform Sub-Account onboarding」 fincode sub-account keys.
- Optional newsletter-sending service API key.
3.5 Customer order data on Merchant's behalf 「Processor role」
QKay stores 「as Processor acting strictly on the Merchant Controller's documented instruction」: customer email, phone, full name, shipping/billing address, order lines, total amount, custom checkout notes. See §12 for the Processor/Controller split and each Merchant's legal obligation to post their own storefront Tokushoho and storefront privacy policy on their tenant domain.
3.6 Transactional email 「single onboarding + account recovery」
Exactly one onboarding welcome email is sent after Stripe's checkout.session.completed, from support@qkay.jp. It contains a login link to the QKay Management Dashboard at kanri.qkay.jp and a mandatory first-login MFA notice. No marketing email is sent without a separate, granular opt-in. All outbound transactional and onboarding SMTP delivery is sub-contracted to the MXroute email delivery platform as a separately contracted USA-located third-party sub-processor (see §6 processor table + §7 international transfers).
4. Purposes of Use | 利用目的
- Authentication & security, Clerk login + mandatory first-login MFA, password reset.
- Tenant provisioning, subdomain/cluster-domain routing, Shopify storefront preview evaluation expiry windows, custom domain verification, dashboard access gating.
- Fees, Subscriptions, & Refunds, processing the one-time Stripe registration fee; executing platform subscription tiers; tracking the fincode 1.0% platform usage fee perTerms §X; and processing Merchant-initiated refunds via the fincode API 「Terms §W」.
- Donation programme, discretionary allocation of §X usage fees to charitable/community initiatives per Terms §X.2.
- Transactional email, onboarding welcome, security alerts, outages, 30-day fee-change notices per Terms §Z.
- Integration operation, Shopify preview evaluation toggles, microCMS content toggles, Stripe account toggles, fincode Platform Sub-Account toggles.
- Anti-fraud & abuse defense, Turnstile, honeypots, rate limits, login anomaly detection, database-layer tenant access controls.
- Enforcement & defense, Terms enforcement, legal claims.
- Legal compliance, lawful subpoenas, court orders, tax/audit records 「消費税法」, breach reporting.
- Subscription Donation Allocation, tracking and aggregating the 5% subscription revenue pledge for internal allocation to community and charitable initiatives.
5. Legal Bases for Processing | GDPR / 処理の法的根拠
- Art.6(1)(b) Contractual necessity, data required to perform the Merchant Terms contract, including the §X revenue-share platform fee programme and §W fincode refund integration.
- Art.6(1)(c) Legal obligation, 10-year 消費税 invoice retention, breach-reporting logs, APPI/GDPR records.
- Art.6(1)(f) Legitimate interests, anti-fraud, anti-spam, abuse defense, non-sensitive security telemetry.
- Art.6(1)(a) Explicit consent, cross-border transfers 「§7 checkbox」 and any marketing email beyond the onboarding welcome.
6. Third-Party Sharing & Sub-Processors | 第三者提供・下請処理者
| Processor | Purpose | Data shared | Host | Jurisdiction |
|---|---|---|---|
| Clerk | Identity | MFA | authenticated sessions | Email, name, password hash, tenant metadata | US 「primary」 | JP edge |
| Stripe Payments | One-time signup fee; optional own-account Stripe checkout | Merchant email/name/brand/slug/amounts; customer PCI data handled exclusively on Stripe | US 「primary」 | JP |
| GMO Payment Gateway | fincode | Platform Sub-Account capture, 1.0% revenue-share auto-deduction, API-triggered refunds | Merchant fincode sub-account identifiers, order/customer payloads, refund requests | Japan |
| Managed relational DB 「Postgres DBaaS」 | Persistent, tenant-scoped storage for merchant account data, integrations metadata, order records | All categories above, encrypted at rest and in transit | SG · Singapore 「primary region」 + additional replicated regions as required for performance |
| Cloudflare | Edge CDN | WAF | DDoS protection | Turnstile bot screening | IP address, UA, CAPTCHA pass/fail, bot-score signals | Global anycast | JP edge |
| SSR application host | Marketing-site SSR, /api/register endpoint, onboarding webhooks | Full signup-form POST body, connecting IP, short-term diagnostic logs 「≤14 days」 | JP | US |
| Shopify Inc. 「opt-in preview evaluation only」 | Headless product/inventory-preview sync for Shopify storefront preview-evaluation mode | Merchant-connected Shopify store URL, least-privilege Merchant Admin access token | CA | US | JP edge |
| microCMS Co., Ltd. 「opt-in, supported content backend」 | Headless storefront content backend | Service domain, least-privilege API key, Merchant-authored content payloads | Japan |
| MXroute 「transactional email delivery」 | Onboarding welcome, provisioning, security-alert, and storefront transactional email routing & delivery | Merchant contact email, first name, tenant dashboard URL, email subject & body (onboarding instructions / storefront receipts) | US (Ashburn, Virginia primary; additional DE / FI / AU / NL satellite as per provider published topology) |
// No personal data is sold or rented to advertisers or data // brokers. All processors are bound by DPAs equivalent to Art.28 // GDPR | APPI Art.24 委託 requirements.
7. International Transfers | 国外移転
Data is transferred to the US 「Clerk identity, Stripe primary, SSR host, MXroute transactional email delivery」, Singapore 「managed relational DB primary region」, Canada 「Shopify preview-evaluation infrastructure」, and Japan 「GMO PG | fincode, microCMS, Cloudflare JP edge」.
Transfer safeguards 「GDPR Art.44–49 | APPI 国外移転」 · Cross-region transfers occur over TLS 1.3 channels only. Persistent data written to the managed relational database infrastructure's primary Singapore region is secured at rest using AES-256 cryptographic standards consistent with the architecture-level encryption statement above; tenant records are logically separated from one another at the data-access layer by the platform's row-level tenant isolation design. Transactional email payloads relayed through the MXroute US primary region are additionally protected by TLS 1.2+ negotiated SMTP transport per RFC 3207 where the receiving MX advertises support. Standard Contractual Clauses 「SCCs」 / equivalent Japanese international-transfer documentation apply where required between QKay 「Controller」 and each named sub-processor listed under §6.
国外移転に係る safeguards 「GDPR第44条~第49条・APPI 国外移転」 · 地域をまたぐデータ移転はTLS 1.3暗号化通信路のみを経由して行われます。管理対象リレーショナルデータベース基盤のシンガポール・プライマリリージョンに書き込まれる永続データは、上記「アーキテクチャレベルの暗号化」記載に従い、AES-256暗号化規格で静的時に保護されます。トランザクションメールの中継先であるMXroute米国プライマリリージョンに転送されるメールペイロードは、宛先MXが対応する場合、RFC 3207に準拠したTLS 1.2以上のSMTPトランスポート暗号化で追加保護されます。テナントごとのレコードは、プラットフォームの行レベル・テナント分離設計により、データアクセス層で論理的に分離されます。QKay(管理責任者)と§6に記載の各サブプロセッサーとの間では、必要に応じて標準契約条項(SCCs)または相当する日本の国外移転書面が適用されます。
- EEA/UK → non-adequate: explicit checkbox consent at registration/storefront checkout; OR EU SCCs 2021/914 | UK IDTA signed with each sub-processor, plus supplementary technical measures 「TLS 1.3, at-rest enc, tenant access controls, key rotation」.
- JP → non-JP: contractual APPI-equivalent obligations on each processor; explicit data-subject consent where PPC adequacy list does not apply.
SCC/IDTA copies available on request tosupport@qkay.jp.
8. Cookies | クッキー等
Only strictly necessary cookies. No ad/tracking cookies.
| Cookie | Purpose | Retention | Set by |
|---|---|---|---|
| system_fault | Brief UX error message to /error screen | 15s max | qkay.jp 1st-party |
| Clerk __session etc. | Authenticated Merchant session on kanri.qkay.jp | Per Clerk defaults | kanri via Clerk SDK |
| End-customer storefront sessions | Cart, guest-checkout state, CSRF, CSP nonces | Session or 30 days | Merchant tenant domain |
9. Retention | 保存期間
| Category | Retention |
|---|---|
| Merchant account + Clerk user | Lifetime + 90 days post-deletion, then hard-delete |
| Stripe/fincode payment/tax records 「消費税」 | 10 years 「statutory invoice retention」 |
| End-customer order/shipping records 「Processor role」 | Account lifetime + 90 days 「default; Merchant may purge earlier via kanri export」 |
| Access logs, CAPTCHA, IPs | 14 days · Security telemetry exception: logs strictly used for fraud prevention, malicious-threat / APT intelligence, and active-incident forensics may be retained beyond 14 days if required to investigate, contain, remediate, or enforce against an ongoing or credible platform-integrity threat. |
| Onboarding SMTP logs | 30 days max |
| Integration secrets 「Shopify preview evaluation, microCMS, Stripe, fincode」 | Hard-deleted ≤ 30 days of account closure or integration disconnection |
10. Data Subject Rights | 本人の権利行使
- Disclosure | 開示 「JSON, JP or EN」
- Correction | Supplementation | Deletion, 訂正・追加・削除
- Suspension of use | 利用停止・第三者提供の停止
- Withdrawal of consent 「cross-border, marketing」, retroactive effect only to the extent legally permissible
- Data portability 「GDPR Art.20, JSON export」
- Objection to automated decision-making 「anti-fraud heuristics subject to human review on request」
- Right to complain to national DPA | PPC 「個人情報保護委員会」 without prejudice
Response: ≤ 30 calendar days after authenticated request. Emailsupport@qkay.jp, send from your registered email, or attach signed ID proof if using a different address. QKay reserves the right to require advanced, multi-factor verification methods — including requiring the request to be authorized directly through an active kanri.qkay.jp authenticated session with active Clerk MFA — before disclosing, exporting, or deleting any account data, in order to block impersonation, social-engineering Denial-of-Privacy requests, and AI-generated spoofed ID submissions.
For end-customer data held as Processor, we direct the request to the Merchant Controller within 10 business days.
11. Children | 未成年者の取扱い
- Merchant signup forbidden under 16 「EU/GDPR」 or under 20 「Japan 成年年齢」, whichever is higher. Merchants aged 18–19 domiciled in Japan require prior written statutory-agent consent.
- Merchant storefronts must enforce their own parental/guardian consent gates per their own storefront policy. QKay, as Processor, does not knowingly retain PII of children under 16, prompt deletion on discovery.
12. Storefront Customer Data | Controller vs Processor / 管理責任分界
- Merchant = Controller | 管理者, decides what end-customer data is collected and why.
- QKay = Processor | 処理者, acts strictly on documented Merchant instructions 「Management Dashboard toggles, storefront checkout field configuration, Terms §W refund/void/capture API-initiated actions」.
- Merchant MUST publish their own storefront-level Privacy Policy AND 「once incorporated/selling to consumers」 their own 特定商取引法に基づく表記 「Tokushoho」 page on the root of their tenant subdomain or custom domain. That storefront policy MUST reference
https://qkay.jp/legal/privacyas a named sub-processor to satisfy the APPI/GDPR 下請先開示 requirement. - Merchant is responsible for obtaining required end-customer consents on the storefront 「marketing, profiling, cookies, cross-border transfers」 under their own storefront policy.
- Processor duties QKay performs: database-layer tenant access controls; no end-customer data access except for ticketed support at Merchant's explicit written request; return/port/delete data on authenticated Merchant instruction within 30 days; reasonable assistance responding to Merchant's data-subject requests; notify Merchant of a suspected tenant-specific breach without undue delayafter internal confirmation, consistent with GDPR Art.33(2) / APPI downstream notification requirements.
12.5 Incident Response & Breach Notification | インシデント対応・漏えい通知
QKay maintains a written, internally documented information-security incident-response procedure covering 「detection, triage, containment, eradication, recovery, and lessons-learned post-incident review」 for personal-data incidents, including unauthorized access, accidental destruction, alteration, loss, or leakage of Merchant or storefront end-customer personal data 「collectively a "Security Incident"」.
- Merchant Notification. Where a Security Incident materially affects a specific Merchant's tenant-scoped personal data or their storefront end-customer personal data held as Processor, QKay will notify the affected Merchant without undue delay after internal confirmation and containment 「taking into account the scope, severity, and forensic state of the incident」, using the Merchant's registered administrative contact email. Where required by applicable law 「including but not limited to GDPR Art.33, Art.34, or APPI prompt notification obligations」, notification shall be completed within the applicable statutory timelines.
- Regulator & Supervisory-Authority Notification. Where a Security Incident gives rise to a mandatory notification obligation to a Japanese 「PPC 個人情報保護委員会」, EU/EEA national supervisory authority 「GDPR Art.33(1)」, or other competent regulator, QKay will submit such notification without undue delay and within the applicable statutory timelines, consistent with the scope and severity of the incident as classified under internal incident-response runbooks and the requirements of the applicable law.
- End-Customer Data-Controller Notification. Where the Security Incident concerns end-customer personal data for which a Merchant is the independent Controller under §12, QKay will act strictly as Processor: QKay will notify the Merchant Controller without undue delay per clause (1) above, and will reasonably cooperate with the Merchant Controller 「at the Merchant's documented written instruction and expense」 in issuing Controller-level end-customer notifications, Controller-required regulator notifications, and public statements — QKay does NOT issue direct Controller-level end-customer notifications on the Merchant's behalf unless explicitly instructed in writing by the Merchant Controller, as QKay has no direct contractual nexus with Merchant storefront end-customers.
- Information Provided in Notification. Merchant notifications will include, to the extent then known and operationally feasible without compromising ongoing containment: (i) a factual description of the Security Incident; (ii) categories and approximate volume of personal data affected, insofar as ascertainable; (iii) the measures QKay has taken or intends to take to contain, remediate, and prevent recurrence; (iv) recommended protective actions for the affected Merchant; and (v) dedicated point-of-contact details for ongoing coordination. A factual root-cause summary, insofar as it can be produced without compromising ongoing forensic investigation, law-enforcement sealed-work, or future platform security, may be provided to the affected Merchant upon authenticated post-incident request.
- Scope Exclusion — Low-Impact / Non-Identifying Events. Notwithstanding the above, routine unsuccessful brute-force credential-stuffing attempts blocked at WAF or authentication edge, routine bot screening, routine scanner probing blocked under Terms §6, or other events that, after internal triage, are reasonably assessed as not resulting in or posing a significant risk of resulting in unauthorized access to or processing of identifiable personal data, shall not give rise to Merchant-specific incident notification unless separately required by applicable statute.
【日本語参考訳】QKay は、内部文書化された情報セキュリティインシデント対応手順(検知・トリアージ・封じ込め・根絶・回復・事後検証・再発防止レビュー)を維持しており、マーチャントまたはストアフロントエンドユーザーの個人データに対する不正アクセス、滅失、毀損、改ざん、漏えいその他の個人データ事故(総称「セキュリティインシデント」)に対応します。テナントスコープのデータに影響する場合は、内部での確認および封じ込め後、著しく不当な遅延なくマーチャントに通知します。法的強制通知期間(GDPR 第33条、同第34条、APPI 関連通知義務)が適用される場合、当該法の下で要求される法定の期間内に通知を完了します。以前のドラフトに記載されていた固定時間(48時間 / 72時間等)のカウントダウンは、多段階APTや法執行機関の密封捜査等において悪用される可能性を避けるため、公的契約文言からは意図的に削除されています。具体的な内部目標値は、QKay の運用インシデント対応ランブックに記載され、インシデント分類に応じてケースバイケースで適用されます。なお、WAF や認証エッジでブロックされた通常の不正ログイン試行・ボットスクリーニング・スキャナプローブ等、個人データに対するアクセス・処理の重大なリスクがないと内部トリアージで合理的に判断された事象は、別途法令上要求されない限り、マーチャント個別のインシデント通知の対象とはなりません。
13. Security | 安全管理措置
- Technical | 技術的措置, Database-layer tenant isolation with row-level access controls; Clerk password hashing + mandatory first-login MFA; signed HMAC verification on all Stripe and fincode inbound webhook payloads; Turnstile + server-side honeypot anti-spam; TLS 1.3 on all public and internal endpoints; at-rest and backup encryption on all persistent managed storage; integration secrets stored exclusively as server-side environment variables; automated and manual rotation cadence for all upstream API keys and signing secrets.
- Organisational | 組織的措置, Strict need-to-know production access; written NDA + documented data-handling instructions for all staff and any outsourced operators; quarterly least-privilege access reviews and offboarding checklist; security patches applied on receipt or next maintenance window depending on severity.
- Incident | インシデント対応, In the event of a confirmed personal-data breach, QKay will notify competent data protection authorities without undue delay and within the applicable statutory timelines 「including the 72-hour window under GDPR Art.33 where it applies, and the prompt-notification requirements of APPI where they apply」; suspected tenant-specific breaches are notified to the affected Merchant without undue delay after internal confirmation and containment, taking into account the scope, severity, and forensic state of the incident; written root-cause and remediation summary is provided to the affected Merchant on authenticated request once investigation is complete.
14. Updates | 本ポリシーの変更
Material changes 「reduced rights, expanded purposes, new sub-processors, extended retention, changed cross-border transfer scope」 receive: ≥30 calendar-day prior posting on this page with a new effective date, consistent with the Terms of Service §16 heightened material-change notice window; one-time email to registered Merchant contacts; re-consent prompt at next QKay Management Dashboard login where required by law. Non-material changes 「typos, formatting, added equivalent platform component scopes, added equivalent sub-processors of the same jurisdiction and processing scope」 take effect on the "Effective date" shown above.
15. Contact | お問い合わせ
// EMAIL:support@qkay.jp
// RESPONSE_WINDOW: 3–10 business days 「Mon–Fri JST; 祝日除く」
Pre-GA operator contact disclosure 「事業準備中」: Following operator incorporation as a 合同会社 in Q4 2026, this §1 and §15 will be updated together with the Terms §1/§18 refresh to include the final registered 法人名, 本店所在地 full postal address, 代表者氏名, dedicated operator phone number for privacy correspondence, and named 個人情報保護管理者 (Hozon Sekininsha / Data Retention Officer) identity and contact line, with a §14 material-change notice posting if required.