Draft — pending legal review
This page is a working draft grounded in this application's actual code and data flows. It has not yet been reviewed by counsel qualified in GDPR and Japan's APPI, and must not be relied upon as final legal advice or a finished policy until that review is complete.
Privacy Policy
Effective July 21, 2026 — version 2026.1
This Privacy Policy explains what personal data Adlerwacht collects, why, and how it is protected, for both the organizations that send attachments through our service and the recipients who register an account to view them.
Who is responsible for your data
[Company legal name, address, and company registration number — Japan entity — to be finalized before this page leaves draft status] is the controller responsible for the personal data described in this policy.
EU representative (Art. 27 GDPR)
As a company established outside the European Union that processes personal data of individuals in the EU, we are required to designate a representative established in the EU. [EU representative name and contact details — to be appointed and added before this page leaves draft status].
Data Protection Officer
[Data Protection Officer name and contact details, or a statement that one is not currently required and who to contact instead — to be finalized before this page leaves draft status].
What we collect
We collect only what is necessary to operate the service:
- Account identity: your email address and a device-bound passkey credential (WebAuthn) — we never collect or store a password.
- Attachment data: the recipient's email address, the sending organization's member email (where provided), the filename, file type, and the file content itself, for attachments routed to you through the service. We do not open, scan, or inspect the content of any attachment — see "How we store and protect attachment content" below.
- Billing data (organizations only): company name, billing address, VAT ID, and billing email, used to issue invoices.
- Technical data limited to what is strictly required to run the service (e.g. a session cookie to keep you signed in). We do not use analytics, advertising, or tracking cookies, and we do not log or store IP addresses except transiently, in memory, to check access to our administrative panel.
Why we process this data
We process this data to provide the service you or your organization requested: creating and securing your account, delivering attachments to their intended recipient, and invoicing the organization that contracted with us. Where you are a recipient, our legal basis is the performance of the contract between us and the sending organization, which necessarily involves you as the intended recipient. Where you are a sender, organization admin, or member, our legal basis is performance of our contract with you or your organization, and, for billing records, our legal obligation to maintain accounting records.
How long we keep it
We retain account and attachment data for as long as your account or your organization's account remains active, plus any period required by applicable bookkeeping or tax law for billing records. We do not currently have an automated deletion schedule for attachments after they have been downloaded — an explicit retention period is one of the items still to be finalized as part of our ongoing compliance work (see docs/compliance/ in our source repository, if you are a technical reviewer).
Where your data is stored
Each geographic deployment of our service (for example, our Germany-based deployment and, separately, a Japan-based deployment) runs on its own independent server with its own database and file storage. Data collected through one deployment is not copied, replicated, or shared with any other deployment. This means that, in practice, data submitted via a given deployment stays in that deployment's hosting region.
Sub-processors
We use a small number of third-party service providers strictly to operate the infrastructure the service runs on: a hosting/server provider, and an SMTP relay provider used only to send transactional emails such as invitation links. We do not share your data with any advertising, analytics, or data-broker service, because we do not use any.
International data transfers
Because our company is based in Japan and our customers include both EU and Japan-based organizations, personal data may in some circumstances be accessed from Japan even where it is stored on an EU-based server (for example, by authorized personnel operating the service). Japan and the European Union are each recognized by the other as providing an adequate level of data protection under a mutual adequacy arrangement in place since 2019, which is the mechanism we rely on for such access, subject to Japan's supplementary rules for handling data originating in the EU. We will update this section once counsel has confirmed our specific arrangements meet those supplementary rules.
Your rights
Depending on where you are located, you may have some or all of the following rights over your personal data:
- Access — to obtain a copy of the personal data we hold about you.
- Rectification — to have inaccurate data corrected.
- Erasure — to have your data deleted, subject to any legal retention obligations.
- Restriction or objection — to limit or object to certain processing.
- Portability — to receive your data in a portable format, where applicable.
- Withdrawal of consent — where processing is based on consent, at any time, without affecting processing carried out before withdrawal.
- Complaint — to lodge a complaint with your local data protection authority (in the EU) or the Personal Information Protection Commission (in Japan).
How we protect your data
Our service is passwordless by design — there is no password database that can be stolen or guessed. Every account, whether a recipient, a sending organization's member, or a platform operator, authenticates using a device-bound WebAuthn passkey. Administrative access to the service is further restricted by network-level access controls. A full technical description of our security measures is maintained internally and available to customers or auditors on request.
In the event of a data breach
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, within the timeframes required by applicable law (72 hours under GDPR, without undue delay under Japan's APPI).
Children's privacy
Our service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy as our service or legal obligations change. Material changes will be reflected in the version number shown at the top of this page; where a change materially affects how we use data you have already provided, we will take reasonable steps to notify you.
Contact us
For any question about this policy or to exercise your rights, contact us at [privacy contact email — to be finalized before this page leaves draft status].