1. Scope
This policy applies to MRAG website visitors, prospects, and customer organizations using the service.
It explains what personal information is processed, why it is processed, and how requests are handled.
2. Data we process
We may process account contact details (such as email addresses), operational logs, support interactions, and configuration metadata needed to deliver the platform.
Customer-uploaded business content — including documents, queries, and knowledge base materials — is handled under customer instructions and contract terms.
We do not sell, rent, or share personal data with third parties for advertising or profiling purposes.
3. Usage and retention
Data is used for service delivery, security operations, abuse prevention, and product reliability.
Retention periods vary by contract, legal obligation, and operational necessity. Customers may request deletion at any time through their account representative.
We retain account contact data for the duration of the active service relationship. Operational logs are retained for a limited period consistent with security and compliance requirements.
4. Data protection
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent industry-standard algorithms.
Access to customer data is restricted through role-based access controls (RBAC). Administrative access requires multi-factor authentication and is logged for audit purposes.
We conduct periodic security reviews and vulnerability assessments. In the event of a data breach affecting personal information, we will notify affected customers and relevant authorities in accordance with applicable law.
Customer-uploaded content is logically isolated per tenant. No customer can access another customer's data through the platform.
5. Google API data usage
MRAG's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect Google Drive to MRAG, we access: (a) file metadata (name, type, modification date) for display in the file picker, and (b) file contents of documents you explicitly select, solely for the purpose of indexing into your organization's knowledge base for search and retrieval.
We do not access files you have not explicitly selected. We do not scan, crawl, or index your entire Drive.
Google user data is never used for: advertising or ad targeting; sale or transfer to data brokers; credit, lending, or insurance eligibility decisions; profiling or behavioral tracking unrelated to the core MRAG service.
Human access to Google user data by our personnel is prohibited except: (a) with the user's affirmative agreement to view specific data for support purposes, (b) as necessary for security incident investigation, or (c) to comply with applicable law or legal process.
You may request deletion of all Google user data held by MRAG at any time by contacting your account representative or emailing the address in Section 9. Upon receiving a verified deletion request, we will remove the data within 30 days and confirm completion.
6. Third-party services
MRAG integrates with LLM providers (including but not limited to OpenAI, Anthropic, Google) and cloud infrastructure services to deliver the platform. These providers operate under their own privacy policies.
Customer data submitted to MRAG may be processed by these providers solely for the purpose of fulfilling the requested service. We do not permit providers to use customer data for their own model training without explicit consent.
We recommend reviewing the privacy policies of any third-party services connected to your MRAG deployment.
7. Cross-border data transfer
MRAG is operated by a Japan-based entity. Data may be processed in Japan and in regions where our infrastructure and LLM providers operate.
For customers subject to GDPR, APPI, or other data protection regulations, we support contractual arrangements to address cross-border transfer requirements.
8. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data we hold about you.
You may also have the right to withdraw consent or object to certain processing activities.
To exercise these rights, contact us using the details in Section 9.
9. Contact
Privacy and data requests can be submitted to: datadriven@musashino.jp
Operator: Musashino Co., Ltd. — https://mrag.jp/