Thank you for your interest in Xenoma and Xenoma’s products and services. As we believe strongly in fundamental privacy rights, this Privacy Policy describes how Xenoma collects, uses, and shares your personal data.

1. Scope of This Privacy Policy

This Privacy Policy describes our commitment to the protection of data privacy and how we treat all the personal data we receive. Laws and regulations we follow includes Japanese Personal Information Protection Act and General Data Protection Regulation (EU) 2016/679.

This Privacy Policy covers how Xenoma handles personal data whether you interact with us on our websites, through our services or apps, or in person. Aggregated data is considered non‑personal data for the purposes of this Privacy Policy.

2. Privacy Rights

2.1 Your Privacy Rights

We respect that you have the right to know, access, correct, delete, restrict the processing of and transfer your personal data, and to object to processing as well as the right to data portability. To exercise your privacy rights, send us a request as described in 9.1.

You also have the right to lodge a complaint with a competent supervisory authority if you consider that the processing of your personal data infringes the applicable personal data protection laws. For this purpose, you can contact in particular the supervisory authority of your habitual residence or the place of the alleged infringement.

2.2 Withdrawal of Consent

You may withdraw your consent at any time with effect for the future. It does not affect the lawfulness of processing personal data based on consent before its withdrawal.

2.3 Exceptions

There may be situations where we cannot grant your request based on Art. 2.1 or 2.2, for example, if you ask us to delete your transaction data and Xenoma is legally obligated to keep a record of that transaction to comply with law. We may also decline to grant a request where doing so would violate the privacy of others or undermine our legitimate use of data for anti-fraud and security purposes, such as when you request deletion of an account that is being investigated for security concerns.

3. Personal Data We Collect and Use

3.1 Personal Data We Collect

You may be requested or required to provide personal data when you order a product, request services, access certain areas of our website, participate in promotional activities or research studies or correspond with us.

We may collect your personal data not only through our website or service but also from third parties. Those includes publicly inaccessible distributors, sales agents, business operators and medical institutions who use our services and publicly accessible service providers of smartphone app platforms.

3.2 Use of Personal Data

Xenoma uses your personal data only when we have a valid legal basis. Depending on the circumstance, Xenoma may rely on your consent or the fact that the processing is necessary to fulfill a contract with you, protect your vital interests or those of other persons, or to comply with law. We may also process your personal data where we believe it is in our or others’ legitimate interests, taking into consideration your interests, rights, and expectations. If you have questions about the legal basis, you can contact the Data Protection Officer / the Data Protection Team from inquiry form as described in 9.1.

If certain personal data falls under the sensitive personal data such as biometric data, we use and process such data with an extra care.

We collect and use your personal data for the following purposes.

3.2.1 Process Your Transactions

When you use our services, we may need to collect information such as your name or nickname, email address, phone number, address and payment information. Depending on the content of the service, we may collect physical information such as height, exercise data and biometric data acquired by our products.

This information is used to provide you with our products and services including payment and product shipping, in addition to using the app and conducting appropriate measurement.

3.2.2 Power Our Services

When you use our services or access our apps or websites, Xenoma collects sensor data, height, app usage history, purchase history, web access history, user profile such as gender and age, access information (UUID, cookies, IP address etc.), location information, etc. which may include personal data.

This information is used to improve the quality of the products and services, for research and development, for market analysis, to analyze trends, usage and behavior related to our apps or websites of our services to properly promote our products and services.

3.2.3 Public Exposure

Some of our websites and pages on Social Networks offer publicly accessible blogs, articles and introductions as a customer case study. You should be aware that any information you agree to post in these areas may be read, collected, and used by others who access them. Examples of such information may include the names and contact information of those who works for our business partners.

3.2.4 Newsletters and Advertising

We may collect your email address, postal address, your affiliation, title and academic degree. We may use it for our own advertising purposes, in particular for sending offers and information and managing and operating events related to our products and services.

3.2.5 Share with Subcontractors

In case where it is necessary to respond to your inquiries or to deliver our products and services to you, we may share your information with distributors or subcontractors.

3.2.6 Comply with Law

To comply with applicable law, for example, to satisfy tax or reporting obligations and audits, to communicate about complaint, to comply with a lawful governmental request, for data security, loss prevention or to prevent fraud, including to protect individuals, employees and Xenoma for the benefit of all our users.

3.3 Decision by Automated Data Processing

Xenoma does not make a decision based solely on automated processing, including profiling, that would produce legal effects or significantly affect you without the opportunity for human review.

3.4 Obligation of Provision

When it is contractually required that you provide your personal data to fulfill the transaction, we will inform you such fact and about the possible consequences of failure to provide such data.

4. Sharing of Personal Data

4.1 Sharing with Third Parties

Xenoma may partner with third parties to provide products, services or other offerings. Xenoma requires its partners to protect your personal data.

Xenoma may also share personal data with subcontractors after thoroughly examining the eligibility as a subcontractor of personal data.

Those service providers are obligated to build a data security management system to ensure that your personal data is handled properly.

Other examples where we disclose your personal data with others are based on your direction, with your consent, or by law enforcement.

4.2 Interactions with Social Networks

Our websites and apps may offer plug-ins for social networks to easily share content with other people. When you access the websites, these plug-ins can potentially create a direct connection between your browser and the respective social networks.

In some cases, information is already exchanged with a social network when you visit the websites, regardless whether you interact with the plug-ins or not. You can prevent information from being shared with a social network by not allowing the corresponding Cookies and/or logging off from the social network before using the websites.

5. Transfer of Personal Data

To offer our products and services around the world, your personal data may be transferred to or accessed by entities outside the country to perform processing activities described in this Privacy Policy. To help ensure your data is protected, wherever it may be, Xenoma takes appropriate safeguards that complies with Standard Contractual Clauses to transfer your personal data between countries.

If you need a copy of documentation about data protection, please send a request from the inquiry form as described in 9.1.

6. Data Retention

We will retain and use your personal data as needed to provide you with services, comply with our legal obligations, resolve disputes, and enforce our agreements.

Information that has been appropriately processed and anonymized so that the individual customer cannot be identified – for example, the IP address or unique identifier of the device that used the app, may continue to be retained.

7. Cookies and Other Technologies

Xenoma's websites, online services, interactive applications, and advertisements may use Cookies. Cookies itself do not identify a specific individual, however, when used together with personal data, Cookie information will also be treated as personal data. Cookie helps us to better understand user behavior and enhance our communications with you, including our website, services and advertising, as well as for security and fraud prevention purposes.

If you prefer your Cookie not to be used, check your browser or OS system for the settings to block Cookies. Certain features may not be available if important cookies are disabled.

Our services also use cookies of Google Analytics provided by Google LLC. Please check the site “How Google uses data when you use our partners' sites or apps” to know how data is collected and processed by Google Analytics.

8. Data Security

Xenoma takes adequate technical and organizational security measures such as maintenance of security systems, development and continuous improvement of security management systems, thorough training of our employees in order to protect your personal data from being misused and to prevent the loss of your information. We are constantly working to improve on these safeguards to help keep your personal data secure.

9. Privacy Questions

9.1 Contact

To exercise your privacy rights, make an inquiry or submit a complaint or requests, our Data Protection Officer / Data Protection Team can be contacted from Inquiry Form selecting "User Information".

9.2 Data Controller

The Data Controller in relation to any personal data that is collected within the scope of this Privacy Policy is Xenoma Inc., 4-6-15 Omoriminami, Ota-ku, Tokyo, Japan.

Last Updated: September 30, 2022