Data Retention & Security

This page explains how we retain and protect content and user data collected through generacontent.sbs for users in Japan.

1. Retention periods

We retain submitted content and account-related data for as long as needed to provide the service, maintain safety and integrity, comply with legal obligations, resolve disputes, and enforce our terms.

  • Submitted content: retained for the period necessary to provide the service and respond to user requests, and then deleted or anonymized when no longer needed.
  • Account and profile data: retained while your account is active, and then retained for a limited period after cancellation to support recordkeeping, security, and dispute handling, unless a shorter period is required by law.
  • Transaction and billing records (if applicable): retained for the period required to comply with applicable laws and tax/accounting requirements.
  • Logs and security data: retained for a limited period for monitoring, incident response, and abuse prevention, then deleted or aggregated.

Because retention can vary depending on your use of the service and legal needs, if you need specific retention details, contact us using the information in the footer.

2. Security measures

We implement reasonable administrative, technical, and organizational safeguards designed to protect user data from unauthorized access, loss, misuse, alteration, or disclosure. Measures may include:

  • Access controls and least-privilege permissions for systems handling user data.
  • Encryption in transit and, where appropriate, encryption at rest.
  • Secure handling practices for backups and system administration.
  • Monitoring and logging to detect and respond to security incidents and abuse.

No method of transmission over the Internet or electronic storage is completely secure. However, we continuously review and improve our security controls.

3. Privacy compliance (Japan)

If we collect and process personal information, we handle it in accordance with Japan’s Act on the Protection of Personal Information, including required notices and responding to data subject rights where applicable.

If our service uses third-party sharing mechanisms that constitute “outward transmission” of user information under Japan’s cookie/user-information rules, we provide required disclosures and, where applicable, obtain consent before such outward transmission, as set out in Telecommunications Business Act (Japan) (as amended; cookies/user information outward transmission rules).

If our SaaS is sold via internet sales to consumers and is categorized as “specified continuous services,” we provide required notices/disclosures under Act on Specified Commercial Transactions, including the additional written disclosures for Specified continuous services (特定継続的役務提供) when applicable.