Legal / Privacy Policy
Privacy Policy
SG Group (“the operator”) treats the handling of personal information as a core operating responsibility. Personal information is collected, used, and managed in accordance with Japan’s Act on the Protection of Personal Information, the related Cabinet Orders and Rules, the relevant guidelines, and this policy. The policy applies, on a consolidated basis, across every website, daily market publication, thematic analytical and explanatory publication including global-macro reports, financial-research tool, calculator, template, indicator, web tool, landing-page audit or fix pack, development engagement, goods sale, marketing service, external-marketplace linkage, and other service or item of content operated by the operator.
01 — Definitions
Defined terms
- Personal information
- Information concerning a living individual from which the individual can be identified by a name, date of birth, email address, or other description, or which contains an individual identification code.
- User
- An individual who browses or uses the operator’s websites, content, or services, and an individual who contacts the operator in writing, by email, or through a form.
- Operated business lines
- The bespoke systems-engineering services (design, implementation, and maintenance of software, websites, and business systems), the physical-goods sale, the marketing and SNS-operation services, the affiliate and tie-up arrangements, and incidental operations conducted by the operator. The operator’s business lines also include daily market publications, thematic analytical and explanatory publications including global-macro reports, and the provision of digital products, templates, subscription-based services, and non-advisory technical or functional customisation — including analytical-support tools, indicators, scripts, visual studies for TradingView, MetaTrader, and other charting platforms, Macro Research Workbench, FX/CFD calculators, Trade Cost Calculator, and Financial Templates Hub. Such customisation is intended to implement display items, formulas, UI, template wording, export formats, data imports, alert conditions, code structure, and similar features; it is not intended to recommend or optimise investment decisions according to a user’s financial situation, investment objectives, risk tolerance, holdings, positions, trading experience, or other individual circumstances.
- Consent-management interface
- The banner, settings panel, settings icon, or other mechanism made available on the operator’s websites through which a user may consent to, reject, select, or withdraw consent for cookies and similar technologies by category, including strictly necessary, functional, analytics, advertising, and measurement categories.
- Third-Party Data
- Information, documents, figures, transaction information, personal data, or confidential information concerning any individual, entity, customer, prospect, counterparty, or other third party that a user enters, stores, imports, generates, uploads, shares, or submits through the Services.
- Business User
- A corporation, sole proprietor, financial-media operator, financial planner, IFA, securities firm, bank, insurer, financial institution, fintech business, educational institution, or any other person using the Services in the course of a business or profession.
- Controller and processor
- A “controller” determines the purposes and means of processing personal data, while a “processor” processes personal data for and on the documented instructions of a controller. The role of the operator or a Business User is determined by applicable law and the specific processing relationship.
- Financial & Market Publications
- Daily market publications, thematic analytical and explanatory articles including global-macro reports, features, electronic reports, and back issues supplied by the operator to an unspecified readership and purchaser base as common content for the same issue, language, and edition.
- Publication Access Data
- An email address, transaction or customer identifier, Checkout Session, purchased product, subscription or trial status, billing interval, access period, session identifier, device or browser information, one-time code, two-factor-authentication result, entitlement determination, and other information necessary for the purchase of, access to, and misuse prevention concerning Publications.
Current service coverage
This policy applies to all operator services, including daily market publications, thematic analytical and explanatory publications including global-macro reports, Macro Research Workbench, the FX & CFD Lot Size Calculator, the Trade Cost Calculator, Financial Templates Hub, TradingView Free Indicators, MetaTrader-related tools, Free WebP Converter, Landing Page Audit / LP Copy-Paste Fix Pack, the external CodeSter marketplace, systems-engineering engagements, physical-goods sale, marketing, and affiliate or tie-up arrangements.
The TradingView indicators published by the operator are completely free public scripts for which the operator charges no usage fee and, subject to TradingView’s terms, are available to an unspecified number of persons through the SG Group TradingView profile. Where the operator collects a TradingView username or similar information, it is limited to what is necessary for installation, technical support, defect verification, and the other purposes stated in this policy.
02 — Information collected
Categories of personal information collected
The operator collects information supplied directly by the user, and information generated automatically through the user’s use of the services, only to the extent necessary for the stated purposes. Not every category is collected from every user; the items collected depend on how the service is engaged with.
Information supplied directly
- Name (in the case of corporate engagements, the name of the designated contact), trade name or company name
- Email address, telephone number, postal address, and messaging IDs used for contact
- Delivery address and recipient name in the physical-goods business
- Information related to settlement, limited to what is needed for invoicing (credit-card numbers are not collected or retained by the operator)
- Whether agreement was given at a Stripe or other checkout, the applicable terms version, time of consent, transaction identifier, customer identifier, selected plan, payment result, subscription status, and history of cancellation, plan changes, and customer-portal actions
- Identity-verification information required under the relevant service contract
- Content supplied by the user through inquiries, meetings, or similar communications
Information collected automatically
- IP address, browser type, operating system, referrer, pages visited, and access timestamps
- Identifiers obtained through cookies, local storage, and similar technologies
- Records of consent, rejection, category selection, and withdrawal through the consent-management interface, including consent ID, time, policy or settings version, region, browser or device information, and other evidence of consent
- Statistical data captured via analytics tools and measurement tags
- Session identifiers, device or browser information, authentication links, one-time codes, two-factor-authentication status, access times, authentication results, and misuse-detection information necessary to verify access to Publications
Information collected in connection with the financial-analysis tools
In connection with the provision of the financial-analysis tools, the operator may collect the following information.
- Name or display name
- Email address
- Information on settlement status, subscription status, and billing history
- Status and action results concerning payment methods, billing information, plans, automatic renewal, cancellation, and changes through the Stripe customer portal, excluding card numbers, expiry dates, and security codes, which are not stored by the operator
- TradingView username
- Information on the MetaTrader operating environment
- Screenshots, configuration details, error messages, display conditions, formulas, UI requirements, code requirements, and desired export formats to the extent necessary for product installation, defect verification, and non-advisory customisation
- The content of inquiries, support history, and communications regarding cancellation and refunds
Information collected for individual publication purchases, subscriptions, and back issues
For the sale, delivery, automated entitlement determination, correction notices, and misuse prevention of Financial & Market Publications, the operator may collect or process the following information according to the access method.
- Email address, transaction identifier, customer identifier, Checkout Session, payment result, and payment time
- The individually purchased publication, specialist analytical article, or Back Issue; Bundle composition; Publication Plan; trial; billing interval; renewal date; cancellation status; and access period
- Session identifiers, device or browser information, authentication links, one-time codes, two-factor-authentication results, access times, access results, and misuse-detection information
- Delivery, receipt, and handling records for notices concerning corrections, replacements, withdrawal, material source changes, payment, or access incidents
Authentication data is not used to personalise articles
Publication Access Data is used to verify purchased products, covered plans, access periods, payment, security, and misuse. The operator does not use it to generate or change user-specific instruments, market views, investment decisions, recommendations, article conclusions, or order of presentation. As an operating principle, editorial-generation processing is not supplied with the purchaser’s email address, payment information, reading history, location, device information, or other customer information that identifies or may identify the individual.
Information collected for research, calculators, templates, web tools, and LP audits
Depending on the nature of the service, the operator may collect or process the information below. For processes designed to complete within the user’s browser, information may not be transmitted to the operator’s server unless the user submits, saves, or sends it as part of an inquiry.
- Display settings, watchlists, saved views, data-source information that the user adds locally or to the dashboard in Macro Research Workbench, and specifications for custom displays or custom imports
- Inputs, calculation histories, values embedded in share URLs, locally stored information, encrypted Vault or dashboard usage information, and specifications for custom formulas, display items, rounding methods, and export formats for lot-size and trade-cost calculations
- Selected templates, variable inputs, generated documents, QA-check history, language and export-format settings, version history, custom requests, and subscription status in Financial Templates Hub
- System logs, action logs, error information, storage status, version information, export information, and restoration-response history to the extent necessary for updates, upgrades, data migration, incident recovery, and compatibility verification of online tools
- Client-side processing information for Free WebP Converter and, where voluntarily submitted in an error report, filenames, screenshots, and environment information. In ordinary image conversion, the tool is designed not to transmit image files themselves to the operator’s server.
- Target URL, email address, name, page goal, CMS/platform, preferred tone, expressions to avoid, payment status, automated-check logs, and information read from the HTML such as meta tags, OGP, headings, and links in Landing Page Audit / LP Copy-Paste Fix Pack
- Purchase, licence, inquiry, and support-related information supplied to the operator by external platforms such as CodeSter, to the extent made available by that platform
Do not enter confidential or sensitive information
Do not enter unnecessary confidential information, third-party personal information, unpublished trade information, financial-account login credentials, identity documents, health, criminal, political-opinion, or other sensitive information into calculators, templates, LP audit forms, or inquiry forms. Information voluntarily entered by users is handled within the scope necessary for this policy and the provision of the services.
Third-Party Data submitted by Business Users
Where a financial-media operator, financial planner, IFA, securities firm, bank, insurer, financial institution, or other Business User enters Third-Party Data concerning its own customer, prospect, counterparty, or principal into the Services, that Business User must minimise the data entered and establish in advance all authority, consent, notice, legal basis, contract, internal approval, and safeguards required for collection, use, outsourcing, storage, sharing, and cross-border transfer. The Business User is responsible for the lawfulness, accuracy, and scope of Third-Party Data and the operator does not request unnecessary Third-Party Data.
Payment credentials such as the credit-card number, expiry date, and security code are obtained and processed directly by Stripe, the payment-service provider, and are not stored by the operator.
Subscription management and payment information
Users of paid services may manage subscriptions, payment methods, billing information, plans, and cancellation, to the extent made available in the portal, through the Stripe customer portal. In connection with that management, the operator may receive the customer identifier, plan, billing interval, renewal date, payment status, cancellation status, plan change, and action result, but does not store the card number, expiry date, or security code. Contract terms for cancellation, refunds, and plan changes are governed by the Terms of Service and the Notice under the Act on Specified Commercial Transactions.
Information not collected
The operator does not collect special-care-required personal information — including race, creed, social status, medical history, criminal record, and the fact of being a victim of a crime — except where such collection is operationally necessary and either permitted under law or made with the user’s consent. The operator does not request credit-card credentials used for settlement, login information for securities, FX, or crypto-asset accounts, API secrets, identity documents, real-account balances, positions, order histories, investment objectives, risk tolerance, investment experience, desired return, individual instrument requests, portfolio composition, or similar information. The operator does not use such information to personalise a Financial & Market Publication, assess suitability, or generate an investment decision. Credit-card information is obtained directly by the payment-service provider (Stripe and the like) and is not stored on the operator’s servers. From the relevant payment-service provider, the operator receives only transaction metadata — settlement status, transaction identifiers, settlement timestamps, and similar.
03 — Purposes of use
Purposes for which personal information is used
Personal information that has been collected is used only to the extent necessary to achieve the purposes set out below. Where a purpose is amended, the amendment will be limited to a purpose reasonably related to the original, and will be notified on this page.
Legal bases for processing
Where the GDPR, UK GDPR, or another law requiring identification of a legal basis applies, the operator processes personal data on one or more of the following bases, according to the nature of the processing.
- Processing necessary to take pre-contractual steps, perform a contract, provide the Services, verify identity, process payment, administer subscriptions, and provide support
- Processing necessary to comply with legal obligations concerning tax, accounting, consumer protection, law enforcement, sanctions, payment, data protection, and similar matters
- Processing for the legitimate interests of the operator or a third party in fraud prevention, security, service improvement, incident response, proof of contract and consent, establishment or defence of legal claims, business operation, and similar purposes, subject to a balancing assessment against the user’s rights and interests
- The user’s consent for optional analytics, advertising or measurement, marketing, and other processing requiring consent
- Processing necessary to protect life, physical safety, or other vital interests, and any other basis permitted by applicable law
For processing based on consent, the user may withdraw consent at any time with future effect. Withdrawal does not affect the lawfulness of processing before withdrawal. Processing necessary for contract performance or a legal obligation may not cease solely because consent is withdrawn.
| Business area | Primary purpose |
|---|---|
| Systems development | Estimating, contracting, scoping, delivering, maintaining, and revising development engagements; identity verification; invoicing and collection; engagement-related communications |
| Physical-goods business | Order intake, settlement (including processing through payment-service providers such as Stripe), dispatch, delivery-status communications, returns/exchanges/refunds/complaint handling, and issuing receipts and delivery notes |
| Marketing business | Content production, SNS operation, reporting, communications with talent and rights-holders, and fee settlement under the service contract |
| Affiliate & tie-up | Communications with partner programmes and tie-up counterparts, fee settlement, and compliance-related verification |
| Financial-analysis tools | Accepting subscription applications, identity verification, and settlement confirmation; providing information on public or open-source TradingView scripts; providing MetaTrader files and installation instructions; confirming, implementing, accepting, publishing, or delivering non-advisory customisation; subscription renewal, cancellation, refunds, and billing management; defect investigation, installation support, and operating-environment verification; preventing misuse, unauthorised sharing, redistribution, and resale; notifying the Terms of Service, the Disclaimer, and important notices; and responding to verifications required by law, payment-service providers, card companies, and platform operators |
| Financial & Market Publications | Individual sale of daily publications, specialist analytical articles, Bundles, and Back Issues; administration of monthly, annual, and other subscriptions and free trials; payment confirmation; automated entitlement determination; operation of authentication links, one-time codes, and two-factor authentication; prevention of misuse and unauthorised sharing; and communications concerning corrections, replacements, withdrawal, and access incidents. Publication Access Data is not used to generate user-specific investment decisions, instruments, market views, or body content. |
| Research & calculators | Visualising public data; producing estimates based on inputs; providing saved views, local settings, share URLs, encrypted Vault functions, and similar; confirming usage; preventing misuse; and improving functions |
| Templates & document generation | Template search; variable merging; document generation; QA checks; translation and export; version control; custom-request handling; and subscription management |
| Web tools & LP audit | Browser-side image conversion; defect investigation; automated checks of public URLs; review of meta tags, OGP, headings, links, and similar elements; delivery of PDF and copy-paste-ready text; and refund or defect handling |
| External marketplaces | Listing products on external platforms such as CodeSter; handling inquiries; confirming licences; support; and responding to disputes or misuse |
| Checkout consent & contract evidence | Confirming agreement to terms at checkout; recording the applicable version, time, and transaction information; evidencing contract formation, application authority, payment, automatic renewal, cancellation, and plan changes; and handling chargebacks, disputes, and misuse |
| Cookie-consent management | Category-based choices for strictly necessary, functional, analytics, advertising, and measurement technologies; applying consent, rejection, and withdrawal; retaining evidence of consent; region-specific display; compliance; and enabling or suppressing tags and scripts |
| Updates, incidents & data migration | Updating, upgrading, maintaining, and checking compatibility of online tools; data migration; incident investigation and restoration; security response; material notices to users; log retention; and maintaining service continuity |
| Common | Handling inquiries; improving the services; preventing misuse; fulfilling statutory obligations; retaining tax and accounting records; and responding to disputes |
Separation of editorial generation and customer authentication
The operator generates and stores one common body for the same issue, language, and edition and then determines access using Publication Access Data only. The body is not regenerated according to payment method, Individual Purchase, Bundle, or subscription status, customer attributes, reading history, or device information, except where the language, issue edition, correction edition, or an expressly identified editorial edition differs.
04 — Disclosure to third parties & outsourcing
Scope of third-party disclosure and outsourcing
The operator does not disclose personal information to third parties without the user’s consent, except in the cases listed below.
- Where required by law
- Where necessary for the protection of life, body, or property, and obtaining the user’s consent is impracticable
- Where particularly necessary for the improvement of public health or the wholesome upbringing of children, and obtaining consent is impracticable
- Where cooperation with a national or local government body, or its delegate, is required for the performance of statutory duties
- Where the business is succeeded by way of merger, business transfer, or similar event, and personal information is provided to the successor
Outsourced processing
To the extent necessary to achieve the stated purposes, the operator may outsource activities such as payment handling (Stripe and the like), delivery (Yamato Transport, Sagawa Express, Japan Post, and similar), server and cloud infrastructure, edge processing such as Cloudflare Workers, email distribution, analytics, external marketplaces such as CodeSter, accounting, tax, system development and maintenance, template, audit and support operations, and consulting. The operator exercises necessary and appropriate oversight of such contractors to maintain the secure management of personal information.
Allocation of controller and processor roles
Where the operator processes personal information for purposes it determines, including account, contract, payment, support, security, fraud prevention, service improvement, and compliance purposes, the operator acts as a controller or equivalent entity. Where a Business User causes the operator to process Third-Party Data concerning that Business User’s customers within a separately agreed scope, the operator may act as a processor or service provider in accordance with applicable law, the individual agreement, and documented lawful instructions. Where a separate data-processing agreement is required for role allocation, processing details, subprocessors, international transfers, safeguards, and deletion, the parties shall enter into that agreement.
The Business User represents and warrants that it is the controller of, or otherwise lawfully authorised in relation to, Third-Party Data and has the legal basis, notices, consents, and contracts necessary for outsourcing or disclosure to the operator and processing by the operator’s contractors. The Business User must provide the operator with the information and lawful instructions needed for data-subject requests, complaints, regulator responses, correction or deletion instructions, and breach communications and remains responsible for responding.
Independent processing by third-party services
Where Stripe, TradingView, MetaTrader, a broker, an external marketplace, carrier, authentication provider, analytics or advertising provider, or another third party processes personal information for its own purposes under its own terms, that third party may act as an independent controller. Users should review the third party’s privacy policy and settings. The operator does not control or warrant such independent processing.
05 — Cross-border transfer
Provision to recipients located outside Japan
Some of the cloud services, payment processors (Stripe and the like), email-distribution services, analytics tools, and contractors used by the operator have servers or business locations outside Japan. Where personal information is handled outside Japan via such infrastructure, the operator takes the measures required by Article 28 of the Act on the Protection of Personal Information and other applicable laws. Users may, through the designated contact channel, request information — within the scope defined by the operator — on the country to which information is transferred and the relevant personal-information-protection regime of that country.
Where the GDPR, UK GDPR, or another cross-border-transfer regime applies, the operator endeavours to use an appropriate transfer mechanism, including an applicable adequacy decision, standard contractual clauses, binding corporate rules, contractual, organisational, or technical supplementary measures, explicit consent, contractual necessity, or another transfer basis permitted by law. Destinations, contractors, and legal regimes may change; current information is made available within a reasonable scope through the contact channel or the consent-management interface.
Where a Business User enters Third-Party Data into the Services, that Business User is responsible for giving any required cross-border-transfer notice to its customers, explaining the possible use of the operator and its contractors, and implementing any necessary contract, consent, transfer-impact assessment, or other measure.
06 — Cookies and similar technologies
Cookies, measurement tags, and analytics
The operator’s websites may use cookies and similar technologies to understand usage, maintain functionality, improve usability, and prevent misuse. Where third-party analytics tools (for example, web-analytics services) are deployed, those services collect and process information in accordance with their own privacy policies.
Cookies can be disabled via the browser’s settings, although some functionality of the website may become unavailable. Use of tracking cookies for advertising-related purposes may be refused via the opt-out mechanisms provided by the relevant advertising operators.
Consent-management interface and prior consent
The operator’s websites provide a consent-management interface for cookies and similar technologies. In regions where consent is required by applicable law, the operator’s general approach is not to activate cookies, tags, or scripts in optional categories such as analytics, advertising, or measurement until the user gives affirmative consent, except for technologies strictly necessary to provide the website. A user who does not consent can use the website with optional tracking refused, subject to strictly necessary functionality.
Category-based choices
Depending on usage and applicable law, the consent-management interface generally displays the following categories. The specific cookies, providers, purposes, duration, and third-party disclosure within each category can be reviewed in the interface or the related detailed display.
- Strictly necessary: technologies required for security, networks, recording consent status, authentication, load balancing, forms, payment, or another website function requested by the user. They cannot be disabled to the extent consent is not legally required.
- Functional and preferences: technologies that remember language, display, region, input assistance, and other settings selected by the user.
- Analytics and performance: technologies used to measure usage, errors, speed, navigation, and aggregated statistics and to improve the Services.
- Advertising and measurement: technologies used for ad delivery, frequency control, effectiveness measurement, audience measurement, third-party-site integration, and other marketing purposes.
Freely given, granular, and symmetrical choice
Where consent is the legal basis, optional categories are, as a general rule, not preselected, and the user can choose “accept all,” “reject all,” or category-specific settings in a clear and intelligible manner. Consent to an optional category is not made a condition of using the Services unless the processing is necessary for contract performance. The operator endeavours not to make rejection or access to settings unjustifiably less prominent or more difficult than consent.
Withdrawal and resetting of consent
Through cookie settings, a settings icon, the consent-management interface, or another displayed method, a user may change or withdraw category-based consent at any time with future effect. The operator endeavours to make withdrawal as easy as giving consent. Withdrawal does not affect the lawfulness of processing before withdrawal, and processing based on strictly necessary cookies, statutory retention, security, dispute handling, or another legal basis may continue after withdrawal.
Consent records
For compliance and proof of consent, the operator may retain evidence within the necessary scope, including the consent or rejection choice, categories, consent ID, time, policy or settings version, region, and browser or device information. Consent records are used to apply the user’s choice, avoid unnecessary repeat displays, support audits, and comply with legal obligations, rather than to identify the user directly for advertising purposes.
Browser signals and third-party settings
The operator responds to Do Not Track, Global Privacy Control, and other browser or device privacy signals to the extent recognition is required by applicable law and the signal is technically detectable. Where a signal is not uniformly defined by law or cannot be technically recognised, users should use the consent-management interface or the relevant third party’s opt-out mechanism. Deletion or rejection of third-party cookies also depends on the third party’s settings and browser settings.
07 — Security measures
Safeguarding personal information
The operator implements necessary and appropriate organisational, personnel, physical, and technical measures to prevent the leakage, loss, or damage of personal information and otherwise to maintain secure management. These measures include restriction of handling privileges, access control to storage environments, encryption of communications, appropriate deletion of information that is no longer required, control of external storage media, and education of personnel engaged in the relevant work.
It is acknowledged that internet communications and the use of external services entail inherent security risks; the operator does not warrant absolute security, but endeavours to maintain a reasonable security posture.
Incident response
Where leakage, loss, damage, unauthorised access, or another security event involving personal information is suspected, the operator reasonably investigates the scope, data categories, cause, risk, and necessary containment and recovery measures. Where notification to a supervisory authority or data subject is required by the Act on the Protection of Personal Information, GDPR, UK GDPR, or another applicable law, the operator responds in accordance with the statutory conditions and period. The content or timing of disclosure may be limited by an investigation, prevention of further exploitation, protection of third-party rights, or legal restriction.
User-side safeguards
Users must implement reasonable safeguards, including strong and unique credentials, updated devices and browsers, access control, logout from shared devices, phishing prevention, avoidance of unnecessary data entry, and regular export and backup. The operator cannot control misuse or leakage arising from the user’s credential management, device, communications environment, sharing settings, misdirection, onward transfer to a third party, or external service selected by the user.
Online-service updates and data preservation
Maintenance, updates, upgrades, data migration, incident recovery, suspension, cancellation, non-payment, account deletion, storage-limit overrun, or service termination may cause in-process, unsaved, or temporarily stored inputs, generated documents, settings, history, share URLs, or other data to be lost, corrupted, overwritten, changed, or rendered unavailable. The Services are not a backup service, permanent archive, statutory book, regulatory recordkeeping system, or disaster-recovery environment. Users must regularly save, export, and back up all necessary information in their own controlled environment.
The operator’s liability is governed by the Terms of Service, Disclaimer, individual agreement, and applicable mandatory law. Those documents do not restrict any non-waivable right or remedy available to a user or data subject under the Act on the Protection of Personal Information, GDPR, or other applicable law.
Safeguards for publication access authentication
For Publication access not using a member account, the operator may nevertheless use signed or time-limited credentials, session management, one-time codes, two-factor authentication, misuse detection, access limits, and other reasonable measures. The precise composition, decision criteria, and security specification of authentication data may not be disclosed in order to prevent misuse.
08 — Retention period
How long personal information is retained
Personal information is retained for the period necessary to achieve the stated purposes and for the period of statutorily required preservation. Where the purpose has been fulfilled and no statutory retention obligation applies, the information is erased or anonymised within a reasonable period. Records subject to a statutory retention obligation — such as accounting books and transaction-related documents — are retained for the duration of that obligation.
Criteria used to determine retention
Where a uniform fixed retention period cannot be specified, the operator determines the period by considering the duration of the contract or subscription, support needs, proof of transactions, consent, and billing, security and fraud prevention, backup cycles, statutory retention periods, limitation periods, disputes, audits, and regulatory responses, the nature and volume of the data, and the technical feasibility of deletion.
Data after cancellation or account termination
After cancellation, expiry, suspension for non-payment, account deletion, or service termination, the operator may delete, anonymise, or make inaccessible stored data, generated documents, settings, history, shared information, and other content no longer needed for service provision within a reasonable period, except to the extent required for law, disputes, security, backups, or an individual agreement. Users should export required data before cancellation or termination. Unless expressly required by law or an individual agreement, the operator does not guarantee permanent post-termination retention, return, migration, restoration, or regeneration.
Backups and legal holds
Information scheduled for deletion may remain in isolated backups for a limited period until the normal backup rotation completes. During that period, it is not used for ordinary business purposes and is handled only where necessary for restoration, security, or legal obligations. Where litigation, investigation, audit, chargeback, a preservation order, or another legal hold applies, information may be retained beyond the normal deletion schedule.
Entitlement records for individual purchases and back issues
To verify access to an individually purchased Publication or Bundle, the operator may retain a transaction identifier, purchased product, payment result, email address, authentication or access history, and other minimum necessary entitlement records for the period needed to provide access, meet accounting and tax requirements, handle chargebacks or disputes, prevent misuse, and comply with law. Transaction evidence may be retained separately for the necessary period even where the Publication itself is withdrawn or the service ends.
09 — Rights of the user
User rights and procedure for requests
Under the Act on the Protection of Personal Information, users may submit the following requests in relation to their own personal information.
- Notification of the purpose of use
- Disclosure of retained personal data (including provision in electronic form)
- Correction, addition, or deletion where the content is inaccurate
- Suspension of use, erasure, or suspension of provision to third parties
- Disclosure of records of provision to third parties
Requests should be submitted in writing — by email included — to the contact channel set out at the foot of this page. To verify that the requester is the user or a duly authorised representative, the operator may request the production of designated identification documents. Once such verification is complete, the operator responds within a reasonable period. Where a request cannot be honoured due to a statutory provision, the operator will state the reason.
Fees
For requests for notification of the purpose of use or disclosure of retained personal data, the operator may charge an amount corresponding to the actual costs incurred — including the costs of verifying identification documents and preparing and dispatching the written or electronic records. Other requests — correction, suspension of use, erasure, and disclosure of third-party-provision records — are handled, in principle, without charge.
Additional notice for international users
Where the GDPR, UK GDPR, CCPA/CPRA, or other data-protection laws of the user’s location mandatorily apply, users may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, opt-out, and other rights recognised under those laws. As a personal-information handling business operator under Japanese law, the operator responds reasonably to the extent applicable. A request may be declined in whole or in part for identity verification, prevention of abusive requests, statutory retention obligations, dispute handling, contract performance, or security reasons.
Additional GDPR and UK GDPR information
Where applicable, a user may request information concerning the legal basis and legitimate interests, recipients or categories of recipients, safeguards for cross-border transfers, the retention period or criteria, the source of the data, whether provision is statutory or contractual, and the existence of solely automated decision-making producing legal or similarly significant effects.
A user may have the right to lodge a complaint with the data-protection supervisory authority responsible for the user’s residence, workplace, or alleged infringement. Prior contact with the operator is not mandatory, but users are encouraged to contact the channel at the foot of this page first to allow an opportunity to resolve the issue. The operator does not discriminate against a user for exercising a privacy right.
For a request that is manifestly unfounded, excessive, repetitive, or prejudicial to the rights of another person, the operator may charge a reasonable fee, limit the scope, or refuse the request in accordance with applicable law. Information required for identity verification is used only to handle the request and prevent misuse.
10 — Minors
Use by minors
Minors should use the operator’s services only with the consent of a person holding parental authority or a statutory representative. Where a user is recognised as a minor, the operator endeavours not to receive personal information supplied on the minor’s own judgement alone, and asks for the cooperation of the user and of the parent or statutory representative concerned.
11 — Amendment
Amendments to this policy
This policy may be amended without prior notice in response to legislative change, changes in business activities, or other circumstances. Amendments take effect when posted to this page. Where the change is material, the operator endeavours to provide advance notice through a reasonable means.
Where advance notice is given of a material change, cookie-setting change, online-service update or upgrade, or similar matter, the operator may use publication on the notice page, a notice on this page, the consent-management interface, or the service interface as a reasonable notice method. Where a change requires new consent, the consent-management interface is displayed again and the required choice is requested. If mandatory law requires individual notice, that method is followed.
12 — Contact
Inquiries regarding the handling of personal information
Questions about this policy, requests for disclosure or related rights, and other inquiries concerning the handling of personal information may be sent through the contact form or the email address below. The operator responds within a reasonable period after receipt.
- Operator handling personal information
- SG Group
- Personal-information protection manager
- Sole proprietor of SG Group
- Contact channel
- SG Group · Privacy & Data Protection Desk
- Contact form
- Open form
- contact@sggroup.jp
- Channels accepted
- To ensure accurate records and reliable follow-through, communications via the contact form or by email are recommended. Urgent telephone enquiries are taken on a best-efforts basis during the response hours of weekdays 10:00 – 18:00 (JST). Social media and public comments are not handled as a formal intake channel, as their nature makes reliable, traceable handling of individual cases impracticable.

