Privacy Policy

Privacy Policy

Effective Date: December 20, 2025 | Last Updated: September 5, 2026

Sorai Tokyo Co., Ltd. (hereinafter referred to as "the Company") establishes this Privacy Policy (hereinafter referred to as "this Policy") regarding the handling of users' personal information in the services provided by the Company (including websites, property introductions, inquiry handling, automated response systems, real estate brokerage, etc.; hereinafter referred to as "the Services").

Article 1 (Basic Policy)

The Company complies with the Act on the Protection of Personal Information (hereinafter referred to as the "APPI"), related laws, regulations, and guidelines, and thoroughly implements the appropriate acquisition, use, and management of personal information entrusted to us by users. Furthermore, the Company implements security control measures to prevent leaks, loss, or damage of personal information and to ensure safe and appropriate data governance.

Article 2 (Information Acquired and Collection Methods)

The Company acquires the following personal information through lawful and fair means in providing the Services:

  • Information provided directly by users:
    • Basic contact details including name, date of birth, gender, nationality, address, telephone number, and email address
    • Housing preferences including desired area, rental budget, floor plan, and planned moving date
    • Information required for tenancy applications and screening (employment details, proof of income, residence status and Residence Card copy, identity verification documents, emergency contact, and joint guarantor information)
  • Information collected automatically through the use of the Services:
    • Voice call recordings from automated voice response systems and customer support operators (for quality enhancement, service verification, and accurate recordkeeping)
    • Chat logs, inquiry histories, submitted URLs, and uploaded files via external messaging tools and web forms
    • Device and technical information generated when visiting our website, including access logs, IP addresses, browser types, operating systems, referring URLs, cookies, and advertising identifiers

Article 3 (Purposes of Collection and Use)

The purposes for which the Company collects and uses personal information are as follows:

  • To introduce real estate properties, coordinate property viewings, process tenancy applications, conduct leasing screenings, and execute lease contracts and related communications
  • To receive inquiries, conduct preliminary hearing, provide automated answers, and smoothly hand off to human operators via AI technologies, automated processing systems, and automated voice response systems
  • To respond to customer consultations and inquiries, and verify the identity of the user
  • To provide post-contract customer support, contract renewal, cancellation procedures, and operational announcements
  • To improve service quality, analyze usage trends, compile statistical data, and plan, develop, and enhance new features and offerings
  • To detect, investigate, and prevent violations of terms of service, fraud, and unauthorized or malicious activities
  • To perform tasks incidental or related to the purposes specified above

Article 4 (Policy on AI and Automated Processing Technologies)

  • The Company operates automated processing systems utilizing AI technology, natural language processing, and automated voice response to provide prompt and high-quality customer support.
  • Personal information and customer inquiry data collected and processed through these systems are managed under strict access controls and security safeguards, and are utilized solely within the scope of the stated purposes of use (e.g., generating responses, summarizing inquiries, operator coordination, and service quality enhancement).
  • Personal data handled by the Company will never be provided to third parties or used for training public third-party generative AI models without prior explicit consent.

Article 5 (Security Control Measures)

Pursuant to Article 32 of the APPI, the Company takes necessary and appropriate organizational, human, physical, and technical security control measures to prevent the unauthorized disclosure, loss, or damage of personal data:

  • Organizational Security Measures: Appointment of a personal data protection officer, establishment of internal management rules, and maintenance of reporting procedures for handling any security incidents or potential violations.
  • Human Security Measures: Enforcement of confidentiality agreements for all personnel handling personal data, and continuous security awareness and training programs.
  • Physical and Technical Security Measures: Access control and principle of least privilege (PoLP) for information systems, anti-malware safeguards, data transmission encryption via SSL/TLS, and real-time monitoring against unauthorized external access.

Article 6 (Provision of Personal Data to Third Parties)

  • The Company will not provide personal data to third parties without obtaining the user's prior consent, except in the following cases:
    • When required by laws and regulations
    • When necessary to protect human life, body, or property, and obtaining consent is difficult
    • When particularly necessary to improve public health or promote the sound growth of children, and obtaining consent is difficult
    • When necessary to cooperate with national or local government agencies performing administrative affairs prescribed by law, and obtaining consent would hinder the execution of such affairs
    • When provision is essential due to real estate transactions, including property owners/landlords, management companies, rent guarantee companies, fire/tenant insurance companies, licensed real estate transaction agents, and utility referral providers
  • Notwithstanding the preceding paragraph, the recipient of personal data shall not be deemed a third party in the following circumstances:
    • When the Company entrusts the handling of personal data in whole or in part within the scope necessary to achieve the purposes of use
    • When personal data is transferred as a result of business succession due to a merger or other corporate reorganization

Article 7 (Entrustment to External Cloud Providers and Data Storage)

  • The Company may entrust all or part of the handling of personal data to trusted domestic and international cloud service providers within the scope necessary to achieve the purposes of use.
  • When selecting cloud providers, the Company ensures that they adhere to rigorous global security standards (such as ISO/IEC 27001 or SOC 2 certifications), executes appropriate data protection agreements, and maintains supervision over security operations.
  • In cases where personal data is stored or processed on overseas cloud infrastructure, the Company verifies local privacy regulations and implements necessary security measures.

Article 8 (Cookies and External Transmission of Device Information)

  • Our website utilizes cookies and related tracking technologies (such as local storage and web beacons) to improve user convenience, analyze access metrics, and deliver relevant information and advertisements.
  • Information transmitted externally may include IP addresses, browsing histories, behavioral logs, operating system and browser types, and referring URLs. This information does not directly identify specific individuals.
  • Users can refuse the use of cookies or delete saved cookies through their browser settings. However, disabling cookies may restrict the availability of certain features on our website.

Article 9 (Requests for Disclosure, Correction, Suspension of Use, and Deletion)

  • Users have the right to request disclosure, correction, addition, deletion, suspension of use, or cessation of third-party provision (hereinafter referred to as "Disclosure and Related Requests") regarding their retained personal data held by the Company in accordance with the APPI.
  • To submit a request, please contact our Inquiry Desk specified in Article 12. Upon verifying the applicant's identity (or authorized representative status), the Company will respond promptly in compliance with applicable laws.

Article 10 (Data Deletion Requests for Connected External Services)

If you use our Services in connection with external messaging tools or social networking accounts and wish to disconnect the integration or request data deletion, please follow these steps:

  • Navigate to the settings or authorized applications management page within the respective external service and disconnect or remove the integration with our service.
  • If you also wish to completely and permanently erase your associated data (such as chat histories and CRM records) from our internal systems, please email contact@soraitokyo.jp with the subject line "External Service Data Deletion Request". Upon confirming your identity, we will delete your records without delay.

Article 11 (Amendments to Privacy Policy)

  • The Company may amend this Policy from time to time in response to legislative changes, societal developments, or revisions to the Services.
  • Any revised Privacy Policy shall take effect from the moment it is published on this website or otherwise made known to users through appropriate channels.

Article 12 (Inquiry Desk)

For inquiries, consultations, or requests regarding this Policy and the handling of personal data, please contact the following desk:

Company Name: Sorai Tokyo Co., Ltd.

Representative: Shuhei Adachi

Address: Room 102, 1-7-14 Yanaka, Adachi-ku, Tokyo, 120-0006

Phone: 03-6161-8484

Email: contact@soraitokyo.jp