This document is an English translation of the original version for reference purposes only. The original version is written in the Japanese language. In the case of any discrepancy between the original Japanese version and this English translation, the original Japanese version shall prevail.
Personal Information Protection Policy
Enforced: November 1, 2004
Amended: June 24, 2014
Amended: March 1, 2022
Amended: October 1, 2022
Business Operator Handling Personal Information
For the address and the name of representative, please refer here:
MIXI, Inc. (hereinafter referred to as “MIXI”) is a company that operates with the mission to “create spaces and opportunities for hearts and minds to connect.” MIXI recognizes that, as it receives personal information from its customers in providing its services, taking great care and protecting personal information is an important social mission that MIXI is expected to carry out, and based on such recognition, all of its officers and employees are committed to complying with all laws and regulations concerning the protection of personal information, guidance set out by the State and other relevant rules and norms. Furthermore, to realize the fundamental policies of MIXI stated below, MIXI hereby establishes its Personal Information Protection Management System and declares that it will pay attention to changes in social demands at all times and improve its Personal Information Protection Management System on a continual basis with a unified effort by the entire company.
Establishment of Personal Information Protection Management System
With the recognition of the risks associated with handling personal information, including unauthorized access, loss, destruction, alteration and leakage to or of personal information, MIXI will take all necessary corrective and preventive measures. MIXI also establishes and implements its Personal Information Protection Management System setting forth standards, rules, procedures and other necessary matters for the proper handling and operation of personal information.
Organizational activities to protect personal information
MIXI will conduct the following activities to implement the fundamental policies in a concrete manner:
- All officers and employees comply with all laws and regulations concerning the protection of personal information, guidance set out by the State and other relevant rules and norms.
- MIXI appoints a Chief Privacy Officer and imposes on and grants to him/her the responsibility and authority to implement and operate its Personal Information Protection Management System.
- MIXI appoints a Certified Privacy & Security Auditor who shall be responsible for conducting internal audits concerning the implementation and operation of measures for the protection of personal information.
- MIXI requests cooperation from companies and individuals with whom MIXI has business in relation to the protection of personal information.
- The fundamental policies are published or posted on MIXI’s website, at the entrance of MIXI’s premises and on MIXI’s Groupware to allow everyone inside and outside MIXI to access and inspect them at any time.
- MIXI reviews its Personal Information Protection Management System from time to time to continually improve it.
Protecting personal information
- Respect for individual rights
MIXI respects individual rights related to personal information, and when you request that MIXI notify you of the purpose of use, disclose (including disclosure of records of third party provision), correct, add, or delete the content of your personal information, suspend or delete the use of your personal information, suspend the provision of your personal information to a third party, or submit complaints or requests for consultation concerning your personal information, MIXI will appropriately respond to such request within a reasonable period in accordance with laws and regulations.
- Collection, use and provision of personal information
When collecting, using and providing your personal information, MIXI expressly notifies you of the purpose of use and whether or not and/or to whom your personal information will be provided, uses such information within the scope of the purpose after obtaining your consent, and take necessary measures to prevent any unintended use.
- Implementation of security measures
MIXI establishes and maintains internal management rules to prevent any loss, leakage, unauthorized alteration or any other problem of or related to personal information in connection with its handling thereof, and establishes and implements reasonable security measures, such as implementing appropriate access controls in order to limit the scope of responsible persons who handle personal information, in addition to the activities stated in “2. Organizational activities to protect personal information”. Furthermore, MIXI provides periodic training to its employees on points of attention regarding the handling of personal information.
Handling Personal Information
Personal information means information that is about a living individual and falls under any of the following:
- information that is able to identify the specific individual by name, date of birth, or other description having the information (including the information as will verify other information easily, and thereby allow the identification of the specific individual); or
- information that contains an individual identification code.
Provision of personal information to third parties
1. When acquiring the personal information described in the document (*1)directly from you
Personal information about individuals who use services of MIXI
- To provide and announce services.
*If the specific purpose of use is announced separately upon the provision of individual services, the personal information will be used within the scope necessary for that purpose.
- To request payments of a usage fee for services.
- To customize services and advertisements delivered to you in accordance with your preferences based on an analysis of information such as your usage history, purchase history, and browsing history.
- To send notices to you.
- To send campaign presents and other presents to you.
- To utilize it for the improvement of services and the development of new services.
- To prevent any use of services in a manner not in compliance with the Terms and Conditions of Use.
- To create statistical data processed into a form by which no specific individual can be identified.
Personal information about corporate customers
- To send notices necessary for business, to perform a contract and to proceed business negotiations.
- To manage corporate customer information.
Personal information about individuals who make inquiries to MIXI
- To respond to inquiries.
Personal information about individuals who participate in seminars, events, etc.
- To provide information to, communicate with and send notices to job applicants.
- To send notices and materials concerning seminars, events, etc.
Personal information about individuals who apply for jobs posted by MIXI
- To provide information to, communicate with and send notices to job applicants.
- To make a decision to hire.
*1 “Document” includes a record made by an electronic method, a magnetic method, or any other method not recognizable to human senses (such as website and email).
2. When collecting personal information by a method other than the method described in 1.
Personal information provided by employment agencies
- To perform work contracted to MIXI.
For the purpose of use other than those set out above, please refer to “11. Contact” section below.
Contracting out the handling of personal information
MIXI may contract out the entire or partial handling of the personal information it collects from you to a third party within the scope necessary for the achievement of the purpose of use. In this case, MIXI will enter into a basic agreement concerning the entrustment of personal information or any other necessary agreement with the third party, and conduct necessary and appropriate supervision of the contractors.
Provision of personal information to third parties
MIXI may provide your account information to a financial institution through which deposits are made. If MIXI provides your personal information to a third party other than the aforementioned case, it will do so only after identifying the party to whom your personal information is to be provided and the contents of your personal information to be provided and obtaining your consent, except in the following cases.
- Cases in which the provision of personal information is based on the laws;
- Cases in which the provision of personal information is necessary for the protection of the life, body, or property of an individual and in which it is difficult to acquire the consent of the person;
- Cases in which the provision of personal information is specially necessary to improve public hygiene or promote the sound growth of children and in which it is difficult to acquire the content of the person, and
- Cases in which the provision of personal information is necessary for cooperating with a state institution, a local public body, or an individual or entity entrusted by one when executing the operations described by laws and in which acquiring the consent of the person may hinder the execution of the operations.
- Cases in which the third party is an academic research institution or the like, and such third party is required to handle the personal information for the purpose of academic research (including cases where a part of the purpose for handling the personal information is for the purpose of academic research, but excluding cases where the handling thereof is likely to cause unjust harm to the rights or interests of individuals).
Measures when handling personal information in a foreign country
MIXI may save and handle personal information in a cloud server or a data center managed by a foreign business operator. Upon selecting a foreign business operator, MIXI will confirm that technical measures are in place which prevent such business operator from accessing the saved data, as well as the data protection regulations that apply to such foreign business operator and the content of the data handling policy of such foreign business operator. MIXI selects business operators based in the United States or the European Union as its foreign business operators, and limits the location of the servers where personal information is saved to locations either in Japan, the United States, or the European Union.
Disclosure, etc. of personal information
When you request the acknowledgement of the purpose of use, disclosure (including disclosure of records of third party provision), correction, addition, or deletion of content, stopping or erasing of use, and the stopping of provision to a third party of your own personal information, MIXI responds to such request without delay. For specific procedures to request disclosure, etc., please refer to the “11. Contact” section below.
MIXI assumes no liability in the following cases. Where:
- You disclose your personal information to the third party yourself using a function of services of MIXI or any other means; or
- You are accidentally identified by the information disclosed by you on the website of services of MIXI.
Use of statistical data
MIXI may, based on the personal information collected from you, create statistical data processed into a form by which no specific individual can be identified and which has no corresponding relationship with any specific individual. MIXI may freely and without any restriction use such statistical data by which no specific individual can be identified.
Collection and use of attribute information, action history and other information
MIXI may collect and use information which cannot identify a specific individual including the following information in order to make existing services and advertisements more suitable for you. This includes use in the delivery of advertisements by its group companies. MIXI will not use the following information acquired from a third party in connection with personal information that MIXI or its group companies retain without your consent. Furthermore, for the same purpose, MIXI may provide such information to advertisers and information and service providers. However, MIXI will only provide such information when it has confirmed that it has obtained your consent in the case where it is anticipated that such information will be used by the receiving party thereof as personal information by which a specific individual can be identified.
- Cookies, URLs and contents accessed, reference order and other action history.
- Advertising identifiers.
- IP address information.
- Sex, occupation, age and other attribute information.
MIXI may revise this “Handling Personal Information” in whole or in part. Any important change will be announced on MIXI’s website.
Contact for inquiries, complaints or requests for consultation regarding personal information:
[On the Web] Inquiry form
[By mail] Shibuya Scramble Square 36F, 2-24-12 , Shibuya, Shibuya-ku, Tokyo, Japan 150-6136, MIXI Inc., Attention: Personal Information Personnel