LEGAL
Privacy Policy
Last updated 12 July 2026
INTRODUCTION
Manwa IPMC ('we', 'us', 'our') operates gyouji (gyouji.io and app.gyouji.io, together the 'Services'). We are committed to protecting the privacy of our users and customers. This privacy policy explains how we collect, use, share, and protect personal information in accordance with the EU General Data Protection Regulation (GDPR) and the Japanese Act on the Protection of Personal Information (APPI).
DATA CONTROLLER AND CONTACT
- Data Controller: Manwa IPMC
- Address: Izu City, Shizuoka Prefecture, Japan
- Email: legal@gyouji.io
DATA COLLECTION
We collect personal data when you visit our website, use our services, or interact with us. This includes:
- Account information: your name, email address, and language preference, collected when you create an account, sign in (including via one-time sign-in links sent by email), or contact us.
- Billing information: your subscription plan, billing history, and transaction records, collected when you purchase a subscription or AI token top-up. Card payments are processed by Stripe; we do not store your full card number.
- Content you create: the projects, tasks, budgets, checklists, schedules, files, messages, event landing pages, requests for work, pitches, and supplier or venue profiles you create in the Services. Some of this content, such as published event pages, requests for work, and supplier or venue profiles, is intended to be visible to other users or to the public.
- Guest and recipient data you upload: names, email addresses, and related details of guests and email recipients that you add to guest lists or invite to collaborate. For this data, you are the data controller and we process it on your behalf (see 'Guest data: our role as processor' below).
- Event registration data: where you register to attend an event through a public event page, the name, email address, telephone number (if the organiser requires one), the names of any additional attendees you add, any notes you provide, and the details of your registration and payment status. For this data the event's organiser is the data controller and we process it on their behalf (see 'Event registration data' below).
- Preferences and settings: for example your timezone and display preferences.
- Usage data and cookies: technical information such as IP address, browser type, device type, and pages visited, and the cookies described in 'Use of cookies' below.
- Inquiry data: information you submit through our contact and corporate inquiry forms.
PURPOSE OF PROCESSING
Your data is processed for the following purposes:
- To provide and improve our services: managing your account, storing and displaying your content, enabling collaboration between you and the people you invite, and enhancing the Services' features.
- To provide AI-assisted features: when you use an AI feature (such as AI plan generation or the AI assistant), the text and project context you submit is sent to our AI provider solely to generate the response, and your usage is metered against your token allowance.
- To send transactional email on your behalf and ours: account sign-in links, collaboration invitations, assignment notifications, calendar invitations, pitch and inquiry notifications, and the email campaigns you compose and send to your guest lists.
- To process payments and manage subscriptions: through our payment processor, Stripe.
- For customer support and communication: responding to inquiries and keeping you updated on your requests.
- To protect the Services: detecting and preventing abuse, spam, and fraudulent form submissions (including through Google reCAPTCHA on our contact forms).
- To comply with legal obligations: retaining information for tax, accounting, and other legal requirements.
We do not sell your personal data, and we do not use your content for advertising.
LEGAL BASIS FOR PROCESSING
We process your personal data based on the following legal grounds:
- The need to fulfil a contract with you: most of our processing (providing your account, storing your content, sending transactional email, processing payments) is necessary to deliver the Services you signed up for.
- Your consent: for example, when a prospective customer confirms a corporate inquiry via an email link, or where consent is otherwise requested. You can withdraw consent at any time.
- Our legitimate business interests: for example, securing the Services against abuse and analysing usage to improve our features, where these interests are not overridden by your rights.
- Legal requirements: for example, tax reporting, audits, or responding to legal requests.
GUEST DATA: OUR ROLE AS PROCESSOR
When you upload guest lists or recipient data, or invite collaborators, you may be providing us with personal data about other people. For that data, you are the data controller and we act as your processor: we store it and use it only to provide the features you direct (for example, sending a campaign you compose, or an invitation you trigger). You are responsible for having a lawful basis, such as the recipients' consent, before uploading their data or emailing them through the Services. If a person contacts us about data that appears in your guest lists, we may refer them to you and/or assist you in honouring their request.
EVENT REGISTRATION DATA
When you register to attend an event through a public event page, the organiser of that event is the data controller for your registration and we act as their processor. We store your registration and use it only to provide the features the organiser has enabled: showing them their attendee list, sending you a confirmation, and, where the event is paid, passing the amount and your email address to Stripe so that payment can be taken.
What this means in practice:
- The organiser can see the details you submit, including the names of anyone you register alongside you.
- Your registration is visible to the organiser of that event only. It is not shared with other organisers, and it is not used for our own marketing.
- To exercise your rights over your registration data (access, correction, deletion), contact the organiser. You may also contact us and we will refer you to them and assist them in honouring your request.
- Cancelling your registration using the link in your confirmation email records the cancellation. The organiser retains the record; it is not immediately erased, because they need it to reconcile their event and, where a payment was taken, to meet their own accounting obligations.
If you are an organiser using these features, you are responsible for having a lawful basis for collecting your attendees' data, for telling them how you will use it, and for honouring their rights over it.
DATA SHARING AND SERVICE PROVIDERS
We share personal data only with the service providers we use to run the Services, and only to the extent needed:
- Amazon Web Services (AWS): hosting, database, file storage, and email delivery (Amazon SES). Our infrastructure is located in the AWS Tokyo region (Japan).
- Stripe: payment processing, subscription billing, and payment-related fraud prevention. Stripe also provides the connected accounts through which organisers receive ticket payments; where you buy a ticket, your payment details are handled by Stripe and the payment is made to the organiser's own Stripe account, not to us. Stripe acts as an independent controller for the payment data it processes.
- Anthropic: processing of the inputs you submit to AI-assisted features, solely to generate the requested output.
- Google reCAPTCHA: abuse prevention on our public contact forms.
We may also disclose personal data where required by law or to protect our rights, and in connection with a merger, acquisition, or sale of assets (in which case this policy will continue to apply to your data).
Content you deliberately publish through the Services, such as event landing pages, requests for work, and supplier or venue profiles, is visible to its intended audience, which may include other users or the public.
DATA TRANSFER OUTSIDE THE EU
Our Services are hosted in Japan. If you are in the European Union or European Economic Area, your personal data is transferred to Japan, a country recognised by the European Commission as providing an adequate level of data protection (adequacy decision). Where a service provider processes data outside Japan or the EU/EEA, we ensure the transfer is carried out in compliance with the GDPR, relying on adequacy decisions, standard contractual clauses, or other appropriate safeguards.
USE OF COOKIES
Our website and application use a small number of cookies that are strictly necessary to operate the Services:
- Session cookie: keeps you signed in.
- Security tokens: protect forms against cross-site request forgery.
- View preference cookie: remembers whether you prefer the mobile or desktop view (retained for up to one year).
Our public contact forms use Google reCAPTCHA, which may set its own cookies for the purpose of distinguishing humans from automated abuse.
We do not use advertising or cross-site tracking cookies. You can manage or delete cookies through your browser settings; blocking the strictly necessary cookies may prevent you from signing in.
DATA SUBJECT RIGHTS
Under the GDPR (and, where applicable, the APPI), you have the right to:
- Access your personal data: request a copy of the personal information we hold about you.
- Rectify incorrect data: ask us to correct inaccurate or incomplete details.
- Erase your data in certain circumstances: request deletion when your data is no longer needed or you withdraw consent.
- Restrict or object to processing: limit or stop how we use your data.
- Data portability: receive your data in a machine-readable format to transfer to another provider.
- Lodge a complaint: with your local supervisory authority, or with the Personal Information Protection Commission of Japan.
To exercise any of these rights, contact us at legal@gyouji.io. We will respond within the timeframes required by applicable law.
DATA SECURITY
We take appropriate measures to protect your personal data against unauthorised access, including:
- Technical measures: encryption of data in transit (HTTPS), authenticated API access, time-limited signed links for file downloads and email attachments, and signature verification on payment webhooks.
- Organisational measures: restricting data access to those who need it and separating billing data from account credentials.
No method of transmission or storage is completely secure; if we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
DATA RETENTION
Personal data is retained for as long as your account is active and as long as necessary for the purposes stated above. When you delete content in the Services, it is removed from view immediately and purged from our active systems and backups in due course. Billing and transaction records are retained for the periods required by tax and accounting law. Event registration data is retained for as long as the organiser keeps the event, and its deletion is the organiser's decision: see 'Event registration data' above. You may request deletion of your account and associated personal data at any time via legal@gyouji.io.
CHANGES TO THIS POLICY
We may update this policy. We will notify you of significant changes and update the effective date at the top of the policy.
CONTACT US
For questions or to exercise your data protection rights, please contact us at:
- Data Controller: Manwa IPMC
- Address: Izu City, Shizuoka Prefecture, Japan
- Email: legal@gyouji.io