Data Policy
Black AI Inc. (the Company) regards the proper protection of data entrusted to us by our customers as a top management priority and establishes the following policy.
1. Basic Policy
We strictly protect all data entrusted to us by customers in our AI development and implementation support business. We comply with applicable laws and guidelines, including Japan's Act on the Protection of Personal Information (APPI), and strive to ensure data confidentiality, integrity, and availability.
2. Scope
This policy applies to all data we handle through commissioned work, joint research, product provision, and other activities with customers, including personal information, business data, technical information, and training datasets.
3. Data Handling
- Customer data is used only for the purposes specified in the applicable contract.
- As a rule, we do not use customer data to train our own AI models. If such use is necessary, we obtain the customer's written consent in advance.
- We do not retain logs of prompts, outputs, or similar data unless necessary for the work. Retention periods and deletion methods are specified in individual contracts.
- After project completion, we delete customer data within the period specified in the contract and notify the customer when deletion is complete.
4. Security Measures
We implement the following security measures to help prevent the leakage, loss, or damage of customer data.
- Organizational measures: Appointing a data protection officer, establishing internal rules, and regularly reviewing data handling practices
- Personnel measures: Enforcing confidentiality obligations for all employees and providing regular security training
- Physical measures: Controlling access to work areas and properly managing equipment and storage media
- Technical measures: Encrypting communications with TLS 1.2 or higher, encrypting stored data, minimizing access permissions, and recording access logs
5. Cloud Services and AI APIs
- We use only cloud AI services that guarantee enterprise-grade data isolation to process customer data.
- We select services that guarantee customer data will not be used to train AI foundation models.
- When using cloud services located outside Japan, we take appropriate measures under Article 28 of the APPI.
6. Subcontractor Management
When outsourcing part of our work, we select providers with security standards equivalent to ours, enter into agreements on security measures, and regularly review their data handling practices. We obtain the customer's consent in advance before any further subcontracting.
7. Incident Response
If a data security incident occurs, we promptly notify customers, investigate its cause, determine the scope of its impact, and establish measures to prevent recurrence.
8. Continuous Improvement
We regularly review the implementation of this policy and continuously improve it in response to changes in laws and the technological environment.
Established: July 1, 2025
Black AI Inc.
Representative Director & CEO: Xunran Li