Privacy & Data Handling
1. Who handles the information
- Data controller / Operator
- ONREAL (Ryo Ozaki)
- Business address
- Mutsumi Building 3F
2-10-48 Kitasaiwai, Nishi-ku
Yokohama, Kanagawa 220-0004
Japan
ONREAL is responsible for deciding how information submitted for either of its services — the Japan Source & Accuracy Audit Sprint and Matcha Origin Verification — is used. Privacy questions and requests may be sent to [email protected].
2. Data minimization
Clients should provide only the materials needed for the agreed audit. Passwords and unnecessary personal, confidential, regulated, or security-sensitive information must not be submitted.
Where possible, supporting materials should be redacted before transfer.
3. Information handled
- Name, work email, organization, website, intended audience, publication timing, and fit-check answers.
- Existing content assets, editable transcripts, links, and publication context accepted in the written scope.
- Written questions, clarification messages, invoices, payment records, and delivery records.
- Limited technical and security information processed by the hosting provider, such as IP address, browser information, and request logs.
4. Purposes
- Evaluate fit, answer questions, define scope, and communicate before purchase.
- Perform and deliver an accepted audit and clarification round.
- Process payment, prevent fraud, maintain security, and resolve disputes.
- Keep records required for accounting, tax, and legal obligations.
- Improve the service using de-identified operational lessons. Neither client identity nor client content is used in a public case study without separate explicit written permission.
5. Email-based fit check
The website form validates entries in the browser and prepares an email. It does not transmit the entries to ONREAL or store them on the website. Nothing is received until the user reviews the prepared email and presses the Send button in the user’s email service.
The user’s email provider and Google, as ONREAL’s email provider, process the sent message under their respective terms and privacy notices.
A pre-purchase request for the telephone number or additional operator details may be identified by a fixed email-subject token and answered automatically through Google Apps Script. The automation uses the sender address only to reply, prevent duplicate or excessive responses, apply retention labels, and send a non-identifying failure alert. A mismatch between the From and Reply-To addresses is held for manual review.
5b. Supplier documents received for Matcha Origin Verification
To perform Matcha Origin Verification, ONREAL receives documents that the client chooses to send, which may include invoices, certificates, test reports, and correspondence naming the client’s suppliers and producers. These documents are used only to perform the agreed verification, to communicate with the client, and to meet legal and accounting obligations.
ONREAL does not contact the client’s supplier, publish the documents, or identify the client, its suppliers, or its products in any public material without separate explicit written permission. Documents are checked against publicly available Japanese-language sources; ONREAL does not send the client’s documents to those sources.
Clients are asked to remove information that is not needed for the verification, including personal contact details of individuals and unrelated commercial terms, before sending documents.
ONREAL does not submit the client’s original documents, or full transcriptions of them, to third-party generative AI services. Where AI-assisted research tools support the verification, their use is limited to the individual facts needed to check public records — such as a supplier’s registered corporate name, trade name, or public business name, a stated region, or a stated production step — and never the name of a natural person — after the client’s identity, contact details, prices, and other commercial terms have been removed. Original documents are handled only on ONREAL’s own equipment and within the services listed in section 6. Research threads and excerpts used with such tools are deleted within 30 days after the engagement ends.
6. Service providers and international processing
- Google Gmail and Apps Script — fit-check messages, project communication, agreed email attachments, and the automated pre-purchase telephone or additional-operator-details response.
- Stripe — checkout, payment, fraud prevention, refunds, and payment records. ONREAL does not receive the customer’s full card number.
- Cloudflare — website delivery, security, DNS, and limited technical logs.
These providers may process information in Japan, the United States, and other locations where they or their subprocessors operate. Their own terms and privacy notices also apply.
7. Retention and deletion
- Fit checks that do not become engagements
- Deleted within 90 calendar days after the last substantive contact.
- Client source materials and working files
- Deleted from ONREAL’s active workspace within 30 calendar days after final delivery or engagement closure.
- Final audit and essential project correspondence
- Retained for 12 months after final delivery, then deleted unless a longer period is needed for an active dispute or legal obligation.
- Payment, invoice, tax, and accounting records
- Retained for the period required by applicable law.
- Provider backups and security logs
- May remain until the provider’s ordinary backup rotation or security-log retention ends. They are not used for ordinary business activity after deletion from active systems.
8. Access, correction, and deletion requests
A person may request access to, correction of, or deletion of personal information by emailing [email protected] from the relevant address. ONREAL may request reasonable identity verification.
ONREAL will acknowledge the request within five business days and normally complete or substantively answer it within 30 calendar days. Information that must be retained by law or for an active legal claim may be restricted rather than deleted.
9. Security and incident response
ONREAL limits access to the operator, uses account access controls, minimizes collected information, rate-limits the automated telephone or additional-operator-details response, and asks clients to redact unnecessary sensitive information. No Internet transmission or storage system can be guaranteed completely secure.
If a reportable incident occurs, ONREAL will investigate and make notifications required by applicable law.
10. Cookies and analytics
This site does not use advertising cookies or third-party behavioral analytics. Cloudflare may process essential security and delivery information needed to operate and protect the site.
11. Age and changes
The service is intended for adults acting for themselves or an organization, not for children. Material changes to this notice will be posted on this page with a revised date.
Last updated: August 12, 2026. Effective August 12, 2026 (JST).