Privacy Policy
This is an English translation provided for convenience.
The Japanese original is the authoritative version. If there is any discrepancy between the two, the Japanese version prevails.
1. Definition of personal information
“Personal information” means information about a living individual as defined in the Act on the Protection of Personal Information (name, date of birth, and other information by which a specific individual can be identified), as well as email addresses, user IDs, passwords, credit card details and similar information used in connection with a specific individual, and attribute information such as interests, family composition and age when combined with personal information.
2. Identifying the purposes of use
Clave LLC (“we”, “us” or “the Company”) identifies the purposes for which personal information is used as specifically as possible. We use personal information we obtain for the following purposes.
- (1) To provide and operate the Service and to verify the identity of members.
- (2) To respond to inquiries and requests from members and to provide support.
- (3) To process payments, issue invoices and manage subscriptions.
- (4) To provide members with the employee invitation feature and other features of the Service.
- (5) To notify members of maintenance of the Service, changes to the terms of use or this privacy policy, and other important announcements.
- (6) To provide members with information about new features, updates, campaigns and other announcements relating to the Service (including delivery by email).
- (7) To analyse how the Service is used, to improve its quality, and to develop and improve new services.
- (8) To respond to conduct that violates the terms of use or any other terms.
- (9) To analyse uploaded shift schedules and other files using AI in order to produce a draft of the initial shift configuration.
- (10) For purposes incidental or related to any of the above.
Members may at any time request that we stop sending the announcements described in item (6), using the method we designate (such as the unsubscribe procedure described in the email).
3. Cookies and IP address information
We use cookies so that our sites function correctly.
A cookie is information stored by your browser on the computer of a person using our sites. We use different types of cookies for different purposes.
- Functional cookies — cookies necessary for our sites to work correctly, including those required to create an account.
- Analytical cookies — cookies used to learn how visitors use (parts of) our sites. They allow us to improve our sites and to make them match the interests and priorities of our visitors as closely as possible. We use data obtained through these cookies solely to analyse how our sites are used.
- Advertising cookies — cookies used by third-party providers to serve advertisements on some pages of our sites.
We use the following third-party services to analyse how our sites are used, to improve quality, to detect defects and to deliver advertising. In connection with these services, the URL of the page being viewed, information about your browser and device, your IP address, cookies and other identifiers may be sent from your browser to each service provider.
- (1) Google Analytics (Google LLC) — used to analyse how our sites are used and to improve the Service. For the information transmitted and how it is handled, please see Google’s policy.
- (2) Google AdSense (Google LLC) — used to deliver advertising on some pages of our sites (such as publicly viewable shift schedule pages). Third-party vendors, including Google, use cookies to serve ads based on prior visits to our sites or other websites. You can disable personalised advertising in Ads Settings, and you can opt out of third-party vendors’ cookies used for personalised advertising at www.aboutads.info.
- (3) Sentry (Functional Software, Inc.) — used to detect defects (errors) on our sites and to improve quality. When an error occurs, details of the error, where it occurred, and information about your browser and device are transmitted.
- (4) External services used to provide the chatbot — see Section 16 (About the chatbot “Shii-chan”).
Most browsers are set to accept cookies by default. You can configure your browser to disable cookies or to display a prompt when a cookie is sent. Please note that if cookies are disabled, features and services on our sites and other websites may not function correctly.
4. Restrictions on the use of personal information
We do not handle personal information beyond the scope necessary to achieve the identified purposes of use without obtaining the individual’s prior consent. Where we obtain personal information through a merger or for any other reason, we likewise do not handle it beyond the scope of the purposes of use applicable before the succession without the individual’s prior consent. This does not apply in the following cases.
- (1) Where required by laws and regulations.
- (2) Where necessary to protect a person’s life, body or property, and it is difficult to obtain the individual’s consent.
- (3) Where particularly necessary to improve public health or to promote the sound growth of children, and it is difficult to obtain the individual’s consent.
- (4) Where it is necessary to cooperate with a national agency, a local government, or a party entrusted by either of them, in carrying out duties prescribed by law, and obtaining the individual’s consent is likely to impede the performance of those duties.
5. Proper acquisition of personal information
We acquire personal information properly and do not acquire it by deception or other improper means. We also take care not to collect personal information from children under 15 years of age without the consent of a person with parental authority.
6. Notice of the purpose of use upon acquisition
We publish the purpose of use in advance when acquiring personal information. This does not apply in the following cases.
- (1) Where notifying the individual of, or publishing, the purpose of use is likely to harm the life, body, property or other rights or interests of the individual or a third party.
- (2) Where notifying the individual of, or publishing, the purpose of use is likely to harm our rights or legitimate interests.
- (3) Where it is necessary to cooperate with a national agency or a local government in carrying out duties prescribed by law, and notifying the individual of, or publishing, the purpose of use is likely to impede the performance of those duties.
- (4) Where the purpose of use is clear in light of the circumstances of acquisition.
7. Changes to the purpose of use
Where we change the purpose of use of personal information, we do not do so beyond the scope that can reasonably be considered duly related to the purpose of use before the change, and we notify the individual of, or publish, the changed purpose of use.
8. Security control and supervision of employees
We establish internal rules for the protection of personal information and exercise necessary and appropriate supervision over our employees, so as to prevent leakage, loss or damage of personal information and otherwise ensure its security control.
9. Supervision of contractors
Where we entrust all or part of the handling of personal information to a contractor, we enter into an agreement including confidentiality obligations, or require agreement to terms we specify, and exercise necessary and appropriate supervision so that the contractor ensures the security control of personal information. The handling of personal data by contractors located outside Japan is governed by Section 18.
10. Restrictions on provision to third parties
Except in the following cases, we do not provide personal information to third parties without obtaining the individual’s prior consent.
- (1) Where required by laws and regulations.
- (2) Where necessary to protect a person’s life, body or property, and it is difficult to obtain the individual’s consent.
- (3) Where particularly necessary to improve public health or to promote the sound growth of children, and it is difficult to obtain the individual’s consent.
- (4) Where it is necessary to cooperate with a national agency, a local government, or a party entrusted by either of them, in carrying out duties prescribed by law, and obtaining the individual’s consent is likely to impede the performance of those duties.
- (5) Where we have given notice of, or published, the following in advance:
- 1. that provision to third parties is included in the purpose of use;
- 2. the items of data provided to third parties;
- 3. the means or method of provision to third parties;
- 4. that provision of personal information to third parties will be stopped at the individual’s request.
However, the following do not constitute third parties for the purposes above.
- (1) Where we entrust all or part of the handling of personal information within the scope necessary to achieve the purpose of use.
- (2) Where personal information is provided in connection with a business succession due to a merger or other reason.
- (3) Where personal information is used jointly with specific parties, and we have notified the individual in advance, or placed in a state where the individual can readily learn, of that fact, the items of personal information used jointly, the scope of the parties using it jointly, their purposes of use, and the name of the party responsible for managing that personal information.
11. Disclosure of matters relating to personal information
Where an individual requests disclosure of personal information, we disclose it to the individual without delay. However, where disclosure would fall under any of the following, we may decline to disclose all or part of it, and if we decide not to disclose, we notify the individual of that fact without delay.
- (1) Where disclosure is likely to harm the life, body, property or other rights or interests of the individual or a third party.
- (2) Where disclosure is likely to seriously impede the proper conduct of our business.
- (3) Where disclosure would violate other laws or regulations.
As a rule, we do not disclose information that is not personal information, such as access logs.
12. Rights of users in the EU
Where the processing of personal data is based on consent, users of our sites have the right to withdraw their consent relating to their personal data at any time.
Users of our sites have the right to request access to their personal data. This allows them to receive a copy of the personal data we hold about them.
Users of our sites have the right to request rectification of the personal data we hold about them. This allows any incomplete or inaccurate data we hold about them to be corrected.
Users of our sites have the right to request erasure of their personal data. This allows personal data that we continue to process without a legitimate reason to be deleted.
Users of our sites have the right to object to our processing of their personal data carried out for our legitimate interests. Where we process personal data for direct marketing purposes, we always accept such objections. Where we process personal data for other purposes, we will stop processing unless there are compelling legitimate grounds that (i) override the interests, rights and freedoms of the user, or (ii) relate to the establishment, exercise or defence of legal claims.
Users of our sites have the right to request restriction of the processing of their personal data.
Users of our sites have the right to request that their personal data be transferred to themselves or to a third party. We will provide their personal data to the user or to a third party they designate, in a structured, commonly used and machine-readable format. Please note that this right applies only to automated information that we use with the user’s initial consent or in order to perform a contract with the user.
There is no charge for exercising the rights above. We will provide information on the status of our response to a request promptly, and in any event within one month of receiving it. Depending on the complexity or number of requests, this period may be extended by a further two months. If the period is extended, we will notify the user within one month of receiving the request.
Where a request is manifestly unfounded or excessive, in particular where it is repetitive, we may charge a reasonable fee or decline to act on the request.
In addition to the rights above, users of our sites have the right to lodge a complaint with a supervisory authority at any time (in particular, the supervisory authority of their place of residence, place of work, or the EU member state where the alleged GDPR infringement occurred). We would, however, appreciate the opportunity to address the complaint before the user contacts the supervisory authority, and ask that they contact us first.
13. Correction of personal information
Where an individual requests correction, addition or deletion of the content of personal information on the grounds that it is not accurate (“correction etc.”), we conduct the necessary investigation without delay within the scope necessary to achieve the purpose of use, except where a special procedure is prescribed by other laws or regulations, make the correction etc. based on the results, and notify the individual accordingly.
14. Cessation of use of personal information
Where an individual requests that we stop using or erase their personal information (“cessation of use etc.”) on the grounds that it is being handled beyond the scope of the previously published purpose of use, or that it was acquired by deception or other improper means, we conduct the necessary investigation without delay, carry out the cessation of use etc. based on the results, and notify the individual accordingly. However, where the cessation of use etc. would involve substantial cost or is otherwise difficult, and alternative measures can be taken that are necessary to protect the rights and interests of the individual, we will take those alternative measures.
15. Explanation of reasons
Where, despite a request from an individual, we decide to do any of the following, we endeavour to explain the reasons when notifying the individual:
- (1) not to notify the purpose of use;
- (2) not to disclose all or part of the personal information;
- (3) not to carry out cessation of use etc. of personal information;
- (4) not to stop provision of personal information to third parties.
16. About the chatbot (“Shii-chan”)
We may provide a chatbot feature (“Shii-chan”) for support purposes within the Service.
In providing the chatbot feature we may use external services. In that case, the content a member enters into the chatbot, information identifying the member (such as a user ID) and other information necessary to provide the chatbot may be transmitted to and processed by those external services.
Members should take care not to enter personal information, confidential information, or other information that may infringe the rights or interests of third parties into the chatbot.
17. AI analysis of shift schedules
We may provide a feature in the Service that uses artificial intelligence (AI) to analyse files such as shift schedules uploaded by members (Excel files or image files), extract information about employees, work patterns and duties, and produce a draft of the initial shift configuration (a “draft”). We use those files and the information they contain (including employee names and work information) for the purpose of that analysis and the creation of drafts.
AI analysis in this feature is entrusted to the AI platform provided by Amazon Web Services. The analysis is performed in a region within Japan, and the data supplied is not used to train AI models. That data is also not provided to the AI model provider (Anthropic) or any other model provider.
For Excel files, we transmit data reconstructed from the cell values extracted from the uploaded file together with the sheet names selected by the member. The original Excel file itself, phonetic readings, cell comments, hidden rows and columns, shapes and similar elements are not transmitted for AI analysis. For image files, we remove metadata such as location and camera information (EXIF data) and transmit image data that has been resized or otherwise processed.
When using this feature, members should take care not to upload files containing My Number (individual numbers) or other specified personal information, or information constituting payslips. If we detect content that may fall into these categories, we may refuse to accept it or delete it promptly. We may also remove free-text data such as remarks columns before transmission for AI analysis, and remove terms indicating injury, illness, leave of absence or other health-related information from the results of the analysis.
Uploaded original files are deleted within 24 hours as a rule (deletion may take several days depending on system conditions). When a member discards a draft, we delete the corresponding original file promptly. Drafts produced by AI analysis are deleted when they are applied to the master data or discarded, and are automatically deleted after 30 days at the longest even if neither occurs. Please note that this data may remain in our database backups for a certain period after deletion, but it is erased from those backups in due course.
The results of AI analysis are drafts, and we do not guarantee their accuracy. Members must review the content of a draft before applying it to their master data.
For the countries in which our AI analysis contractors are located and the handling of personal data outside Japan, see Section 18.
18. Handling of personal data outside Japan and locations of contractors
In providing the Service, we carry out part of the storage and processing of personal data through contractors located outside Japan or using servers located outside Japan. We ascertain the external environment relating to the handling of personal data in those countries and take necessary and appropriate security control measures.
The principal contractors and the locations of personal data in the Service are as follows.
- (1) Data storage (databases of information about members and employees, and storage of uploaded files): Amazon Web Services. This data is stored on servers located in the United States.
- (2) AI analysis: Amazon Web Services. The analysis under Section 17 is performed in a region within Japan.
We exercise necessary and appropriate supervision so that these contractors ensure the security control of personal data, including by entering into agreements concerning the protection of personal data. Where a transfer constitutes provision of personal data to a third party located outside Japan, we take the measures prescribed by law.
Individuals, including employees, may request information about the handling of personal data by the overseas contractors we use, using the contact details at the end of this policy. In accordance with applicable law, we will inform the individual of the name of the country in which the contractor is located, the personal information protection regime in that country, an outline of the measures taken by the contractor, and similar matters.
For third-party services relating to cookies, see Section 3; for external services relating to the chatbot, see Section 16.
Contact
For inquiries about this privacy policy, please contact [email protected].
Last revised: 29 July 2026