Privacy Policy
Effective: May 3, 2026 · Last updated: May 25, 2026
Gemini Group K.K. (株式会社GEMINI GROUP) (“PolicyHQ,” “we,” “us,” “our”) operates the PolicyHQ service at policyhq.ai. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights. We comply with the Japanese Personal Information Protection Act (APPI) and apply equivalent protections for users subject to the EU General Data Protection Regulation (GDPR).
Operator details
- Company Name: Gemini Group K.K. (株式会社GEMINI GROUP)
- Postal address: 〒102-0083 東京都千代田区麹町 4-8-1 THE MOCK-UP BY PORTAL POINT #103 (Japan)
- Representative: Mickey Langley, Representative Director
- Privacy contact: privacy@policyhq.ai
1. Data we collect
1.1 Account data
- Email address, display name, profile photo
- Organization affiliation, role, invite history
- Authentication credentials (hashed) and session tokens
- OAuth identifiers when you sign in with a supported third-party single sign-on provider
1.2 Usage data
- Pages viewed, features used, search queries, monitor definitions, watchlist contents
- Chat queries you submit to the “Ask the corpus” feature, together with the corpus passages retrieved to answer them
- Comments, mentions, and notifications you send or receive
- Standard request metadata: IP address, user-agent, timestamp
1.3 Customer content
- Notes, tags, project structure, custom monitors, and any text you input into the Service.
- Customer Content is stored in databases provisioned in the Tokyo region (Japan).
1.4 What we do NOT collect
- Payment card data — billing is processed by our payment processor and we never see your card number.
- Sensitive personal data (race, religion, health, etc.) unless you voluntarily include it in Customer Content.
2. How we use data
- To provide, maintain, and improve the Service;
- To authenticate you, route notifications, and personalize the briefing surface to your interests;
- To process Customer Content through AI providers (see § 4) for summarization, classification, and translation;
- To send transactional email (invitations, monitor matches, weekly digests) and account-related notices;
- To investigate and prevent fraud, abuse, or security incidents;
- To comply with legal obligations.
3. Legal bases (GDPR)
For users in the EU/EEA, we rely on the following bases under GDPR Article 6:
- Contract (Art. 6(1)(b)) — to deliver the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent fraud, and conduct aggregated analytics.
- Consent (Art. 6(1)(a)) — for optional email channels (e.g., comment-mention notifications) you can opt into / out of in Settings.
- Legal obligation (Art. 6(1)(c)) — when required to respond to lawful government requests.
4. Subprocessors and AI providers
We do not sell your personal information. We do not share customer lists, subscriber data, or Customer Content with marketing partners, data brokers, or any third party for their own use. We treat user information as confidential and keep it internal, except as described below (service providers acting on our behalf, professional advisors, and lawful requests).
We use third-party processors to deliver the Service. The complete list — including what data each receives, region, and certifications — is published at policyhq.ai/security/subprocessors.
Notable providers:
- A third-party provider (database, auth) — Tokyo region
- A third-party provider (hosting) — Tokyo (hnd1) for the application; global edge for static assets
- Third-party AI providers (AI summarization, classification, embeddings, chat answers) — content sent to these providers is NOT used for model training per their API terms. Prompt caching is enabled on selected high-volume cron jobs: cached prompts persist in the provider’s infrastructure for up to 5 minutes to amortize repeated requests, then expire.
- A third-party provider (translation) — Pro-tier API; no training retention
- A third-party provider (web search) — receives search query strings derived from tracked policy issues for news ingestion. No customer-identifying data is transmitted.
- A third-party provider (transactional email) — recipient email + message body
5. Data retention
- Active accounts: retained for the life of the account.
- Closed accounts: Customer Content deleted or anonymized within 30 days of cancellation. Backups purged within 90 days.
- Audit logs: retained for 12 months for security and operational investigation.
- Cost / billing records: retained for 7 years per Japanese tax law.
6. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request deletion (“right to be forgotten” under GDPR Art. 17 / disclosure-cessation under APPI Art. 30);
- Export your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent for optional processing at any time via Settings → Notifications.
To exercise any of these rights, email privacy@policyhq.ai. We may need to verify your identity before fulfilling requests. We respond within 30 days.
6.1 Japan (APPI) requests
If you are in Japan, you may have rights under the Act on the Protection of Personal Information (APPI) — including disclosure of retained personal data, correction of inaccurate data, suspension of use, and deletion. Send APPI requests to privacy@policyhq.ai.
6.2 EEA / UK complaints
If you are in the EEA or UK and believe our processing of your personal data violates GDPR or UK GDPR, you have the right to lodge a complaint with your local supervisory authority (your national data protection authority) in addition to contacting us.
7. International transfers
7.1 Data Storage
Your Customer Content is, in principle, stored in a database provisioned within Japan (Tokyo Region).
7.2 Overseas Transfer
Notwithstanding the preceding paragraph, we may transmit your data (such as search queries and corpus passages) to third parties (subprocessors such as AI providers) located outside of Japan (such as the United States) and entrust them with processing, strictly limited to the extent necessary to provide specific features within the Service (such as AI-driven summarization, classification, translation, and chat answers).
7.3 Security Measures
We select only providers that implement appropriate security control measures after understanding the personal information protection systems of the foreign countries to which the data is transferred.
7.4 Overview of Personal Information Protection Systems in Each Country
Information regarding the overview of the personal information protection systems in the United States (Federal) and the states where each AI provider is located, which are the primary transfer destinations, as well as the measures taken by such third parties, can be found in the information published by the Personal Information Protection Commission (or our separately designated list page [https://www.ppc.go.jp/enforcement/infoprovision/laws/]).
8. Security
8.1 Security Control Measures
We will take necessary and appropriate security control measures as follows to prevent leakage, loss, or damage of personal data and to otherwise securely manage personal data:
- Organizational Security Control Measures: We have appointed a person responsible for the handling of personal data and established a reporting and communication system for cases where violations of laws or regulations are discovered.
- Personnel Security Control Measures: We conduct regular training for employees regarding the handling of personal data.
- Physical Security Control Measures: We manage the areas where personal data is handled and implement measures to prevent the theft or loss of electronic devices and documents.
- Technical Security Control Measures: We protect personal data using TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access control, audit logs, and the controls documented at policyhq.ai/security.
- Understanding of the External Environment: We implement security control measures after understanding the personal information protection systems in the foreign countries (such as the United States) where personal data is stored and processed.
8.2 Notification to Supervisory Authorities
In the unlikely event that an incident such as a leakage of personal data occurs, we will notify the relevant supervisory authority and the affected users promptly in accordance with the provisions of the GDPR if the GDPR applies (within 72 hours as stipulated therein), or promptly in accordance with the provisions of the Japanese Act on the Protection of Personal Information and related laws and regulations if the Japanese Act on the Protection of Personal Information applies.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@policyhq.ai and we will delete it.
10. Cookies and similar technologies
The Service and our marketing site may use cookies and similar technologies (for example, localStorage, session cookies, and analytics pixels) for the following purposes:
- Strictly necessary: authentication, session management, CSRF protection, and security. These cannot be disabled without breaking the Service.
- Functional: remembering preferences such as language (EN/JP), active project scope, and UI state.
- Analytics: understanding how the Service is used in aggregate so we can improve it.
You can typically control cookies through your browser settings. Transactional emails we send may include tracking pixels and tracked links to measure deliverability and engagement (for example, whether a digest was opened or a link clicked), depending on your email client and security settings.
External transmission (Telecommunications Business Act). Some of the cookies and similar technologies described above transmit information stored on or generated by your device — such as access logs, cookie identifiers, and IP address — to third-party analytics and infrastructure providers acting on our behalf, for the purpose of measuring and improving how the Service is used. The current list of recipients, the information transmitted to each, and the purpose of use are published and kept up to date at policyhq.ai/legal/external-transmission.
11. Changes
We will post any changes to this policy on this page and update the “Last updated” date. Material changes will be communicated by email at least 30 days before they take effect.
12. Contact
- Gemini Group K.K. (株式会社GEMINI GROUP)
- 〒102-0083 東京都千代田区麹町 4-8-1 THE MOCK-UP BY PORTAL POINT #103 (Japan)
- Privacy inquiries: privacy@policyhq.ai