Sign In
or
Click Here to Join!
         user name:
password:
       English   Русский   Spanish   中文   日本語 Home Heiwa Stock About Heiwa Auto

Privacy Policy

Last Updated: 1 September 2026  |  Version: 1.0

This Privacy Policy explains how HEIWA AUTO CO., LTD. ("Company") collects, uses, discloses, and protects personal data in connection with the Service. For the purposes of this Privacy Policy, "Service" means the Company's vehicle export, sales, quotation, transaction management, customer account, inquiry, and related services. This policy applies to personal data of individuals who act as representatives, contact persons, or authorized users on behalf of corporate customers, as well as to personal data of sole trader (individual business operator) customers who register and use the Service in their own name (collectively, "Applicants" or "Users"). For the purposes of this Privacy Policy, "Personal Data" means personal information (個人情報) as defined under the Act on the Protection of Personal Information of Japan ("APPI"), and, where the GDPR applies, personal data as defined under Regulation (EU) 2016/679 ("GDPR").

Data Controller

HEIWA AUTO CO., LTD.
6-1 Nagisa-cho, Izumiotsu-city, Osaka 595-0055, Japan
CEO: Junji Abe
Privacy Contact: [email protected]

Categories of Personal Data Collected

2.1 — Business Identity Data

To facilitate cross-border trade and for contract execution, we collect:

  • Full name of the contact person or sole trader
  • Professional email address
  • Job title and department
  • Business telephone number
  • Business address (which may include residential addresses for sole traders)
  • User ID and Password

2.2 — Corporate, Business, and Financial Data

For credit assessment and compliance purposes, we may collect:

  • Company registration number, business registration certificates, or tax identification number, or equivalent documentation for sole traders
  • Financial statements or tax returns or credit history (with explicit consent)
  • Bank details for payment processing
  • Trade references

2.3 — Individual Identification Data (Sole Traders)

Where the Applicant is a sole trader, we may additionally collect personal identification data for identity verification and counterparty risk management purposes (KYC/AML), including:

  • Government-issued photo identification (e.g., passport, driver's license, national ID card), limited only to the sections required for verification
  • Date of birth
  • Nationality
  • Proof of residential address (e.g., utility bill, bank statement)

Such data is collected only to the extent necessary to verify the identity of our contracting counterparty and to manage counterparty and transaction risk, including the prevention of fraud and the establishment and defense of legal claims that may arise from a transaction. This collection also supports identity verification or screening required by the financial institutions that process our transactions, and our compliance with applicable trade control laws. We will retain copies of identification documents in accordance with the retention periods specified in Article 8.

2.4 — Information Obtained from Third Parties

For the purposes of counterparty and transaction risk management (KYC/AML), sanctions screening, creditworthiness assessment, and compliance with applicable laws, we may obtain personal data about you from the following categories of third-party sources, in addition to information provided directly by you:

  • Sanctions lists published by governmental and international bodies (e.g., the U.S. OFAC Specially Designated Nationals List, EU Consolidated Sanctions List, United Nations Security Council Sanctions Lists): names, aliases, dates of birth, nationalities, and other identifying information.
  • Public corporate registries (e.g., national commercial registers, companies registries): names and details of directors and officers, dates of appointment, and registered addresses.
  • Credit reference agencies: corporate credit ratings, representative officer information, and financial soundness assessments.
  • Publicly available sources (e.g., news media, public databases, industry body publications): information relevant to the assessment of transaction-related risks.

All such information is obtained from publicly accessible sources or from sources made available pursuant to applicable law. The legal bases for this processing are our legitimate interests in preventing fraud and managing counterparty and transaction risk (Article 6(1)(f) GDPR) and/or compliance with legal obligations to which we are subject (Article 6(1)(c) GDPR). We do not obtain personal data from third-party sources beyond what is necessary for the purposes stated above.

2.5 — Usage and Technical Data

We automatically collect:

  • IP address, browser type, and device information
  • Log data including pages visited, timestamps, and session duration
  • Cookie and tracking data (see Article 6)

2.6 — Special Category Data

We do not intentionally collect special category personal data (e.g., health, racial or ethnic origin, political opinions, religious beliefs, criminal record). If such data is inadvertently submitted, it will be deleted as soon as reasonably practicable.

Legal Basis for Processing

We process personal data on the following legal bases:

  • Contract performance (GDPR Art. 6(1)(b)): data necessary to execute a transaction or respond to a pre-contractual inquiry where the Applicant is a sole trader (as the direct contracting party).
  • Legitimate interest (GDPR Art. 6(1)(f)): Fraud prevention, system security, business analytics, the management of business communications and transactions with representatives, contact persons, or authorized users of our corporate customers, verifying the identity of sole trader counterparties and managing counterparty and transaction risk (including the establishment and defense of legal claims), and identity verification or screening required by financial intermediaries (such as banks and payment processors) to secure and process international transactions.
  • Legal obligation (GDPR Art. 6(1)(c)): compliance with the Foreign Exchange and Foreign Trade Act of Japan (including export control and economic sanctions screening), tax, and other applicable laws.
  • Consent (GDPR Art. 6(1)(a)): credit inquiries and any marketing communications (separate opt-in required).

We are committed to data minimization. Especially when processing personal data of sole traders for business purposes (such as names and addresses used as business contact details), we apply enhanced measures to ensure that only data strictly necessary for the stated purposes is collected and retained.

Purpose and Use of Personal Data

Personal data is used for the following purposes. Unless otherwise permitted or required by applicable law, we will obtain the user's prior consent before using personal information beyond the scope of these purposes of use:

  • Account registration and identity verification (including KYC checks for sole traders for counterparty risk management)
  • Credit assessment and counterparty risk management
  • Execution of purchase/sale contracts and related logistics
  • Compliance with applicable laws and regulations (including export controls, economic sanctions, anti-money laundering and counter-terrorist financing requirements, and tax laws)
  • Cooperation with identity verification and screening requirements requested by financial institutions
  • Responding to inquiries, requests, and other communications from counterparties and their representatives
  • Sending operational notifications necessary for the administration of our services, including maintenance notices, system updates, changes to terms or policies, and other important announcements
  • Detecting, investigating, preventing, and responding to fraud, unauthorized transactions, breaches of contract, violations of our terms of use, or other unlawful or improper conduct
  • Provision of personal data to third parties in accordance with the terms set out in this Policy (see Article 5)
  • Customer support and communication
  • Service improvement and security monitoring
  • Sending transactional notifications (invoices, shipping updates)

We will not use personal data for purposes incompatible with those listed above without obtaining fresh consent, except where such use is permitted or required by applicable law.

Disclosure to Third Parties

5.1 — General Principle

We do not provide personal data to third parties without the data subject's prior consent, except in the following circumstances permitted by applicable law:

  • Where required or expressly permitted by laws and regulations (APPI Article 27, Paragraph 1, Item 1; GDPR Article 6(1)(c)).
  • Where necessary to protect the life, body, or property of a person, and it is difficult to obtain the data subject's consent (APPI Article 27, Paragraph 1, Item 2; GDPR Article 6(1)(d) concerning vital interests).
  • Where particularly necessary for the improvement of public health or the promotion of the sound growth of children, and it is difficult to obtain the data subject's consent (APPI Article 27, Paragraph 1, Item 3).
  • Where necessary to cooperate with a national agency, local government, or a person entrusted by either, in executing affairs prescribed by laws and regulations, and obtaining the data subject's consent is likely to impede the execution of such affairs (APPI Article 27, Paragraph 1, Item 4).

Where any of the above exceptions do not apply, we share personal data only as necessary and only with the following categories of recipients:

  • Affiliated companies involved in the execution of vehicle purchase and export transactions (e.g., preparation of shipping documents, coordination of auction purchases)
  • Credit reporting agencies and financial institutions (with explicit consent for credit assessments)
  • Logistics and shipping partners involved in fulfilling transactions
  • IT service providers and cloud infrastructure operators acting as data processors (subject to data processing agreements)
  • Legal, audit, and compliance advisors bound by confidentiality obligations
  • Government authorities or law enforcement where required by applicable law

5.2 — Data Processing Agreements

Where third-party service providers process personal data on our behalf, we enter into written data processing agreements that require them to: (a) process data only on our documented instructions; (b) implement appropriate technical and organizational security measures; (c) not engage sub-processors without our prior written consent.

5.3 — Entrustment of Personal Data Handling

Among the categories of recipients listed in Section 5.1, where the Company entrusts the handling of personal data, in whole or in part, to external service providers (such as affiliated companies involved in transaction execution, logistics partners, IT service providers, and cloud infrastructure operators) within the scope necessary to achieve the specific purposes of use, such disclosure constitutes "entrustment" (and not "third-party provision") under the APPI. In such cases, we ensure appropriate supervision over such providers in accordance with Section 5.2.

5.4 — Joint Use

The Company does not jointly use personal data with any specific third parties within the meaning of Article 27, Paragraph 5, Item 3 of the APPI.

Cookies

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By continuing to use our website, you acknowledge the use of strictly necessary cookies. For analytical cookies, your consent will be sought separately.

6.1 — What Are Cookies?

Cookies are data files stored on your computer or mobile device when you visit a website. These cookies recognize you the next time you visit the same website. With the stored cookies, website owners can provide you with better information and an enhanced experience.

6.2 — How Do We Use Cookies?

We use cookies to distinguish you from other users of our website and to provide a browsing experience that is unique to you. The use of cookies helps us improve our site usage and performance, and helps us better understand your needs and preferences when visiting our website. We use a third-party service provider for the analysis of our site's usage and performance. The collected information will be used for the purpose of analyzing site usage and performance.

6.3 — Cookies We Use

The following cookies are strictly necessary for the operation of the Service and do not require prior consent:

Cookie Name Type Purpose Duration
ASPSESSIONID Strictly necessary Maintains your login session and authentication state Session
remember_token Strictly necessary Keeps you logged in if you select "Remember me" 30 days

We do not use advertising cookies or third-party tracking cookies.

6.4 — How Do You Block Cookies?

Most browsers allow you to refuse cookies and you are always free to decline our cookies. You may block our cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. Please note that blocking session cookies will prevent you from logging in to the Service, and may restrict the functionality of this website and affect your user experience.

Guidance for common browsers:

Cross-Border Transfers of Personal Data

Our headquarters and primary servers are located in Japan. When we transfer personal data to third parties located in foreign countries — including entities to which we entrust the handling of personal data (data processors) located outside Japan — we ensure such transfers are lawful and protected by appropriate safeguards, including:

  • Adequacy decisions by relevant authorities (e.g., EU Commission adequacy decision for Japan; recognition of the European Economic Area and the United Kingdom under Article 28 of the APPI, where applicable)
  • Standard Contractual Clauses (SCCs) as approved by the European Commission for transfers to jurisdictions without an adequacy decision
  • Binding Corporate Rules or other approved transfer mechanisms where required

Information regarding the specific foreign countries where your personal data is stored or processed, and the personal information protection systems of those countries, will be provided to you without delay upon request to: [email protected]

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:

  • Active account data: for the duration of the business relationship, plus 5 years after account closure
  • Transaction records: 7 years in accordance with Japanese accounting and tax laws
  • Credit assessment data: 3 years from the date of the assessment, unless a longer retention period is required by law
  • Identity verification documents (sole traders): retained for the same period as the related transaction records (7 years), so that, in the event a transaction is later disputed or investigated, we are able to evidence the identity of the counterparty and the verification performed. This retention also reflects verification requirements of the financial institutions that process our transactions and applicable trade control record-keeping.
  • Log and technical data: 1 year

Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized.

Data Subject Rights and Request Procedures

9.1 — Your Rights

Subject to applicable law (including the APPI and the GDPR, where applicable), individuals whose personal data we process have the following rights. Rights to request suspension of use, erasure, or cessation of third-party provision apply specifically to retained personal data (保有個人データ) as defined under the APPI:

  • Right of access/disclosure: to request a copy or disclosure of retained personal data we hold about you
  • Right to rectification/correction: to request correction, addition, or deletion of inaccurate personal data with respect to retained personal data
  • Right to erasure/suspension of use: to request deletion or suspension of use of personal data in certain circumstances
  • Right to restriction of processing: to request that we limit how we use personal data
  • Right to data portability: to receive personal data in a structured, machine-readable format
  • Right to object / withdraw consent: to object to processing based on legitimate interests, or to withdraw consent at any time without affecting prior lawfulness
  • Right to lodge a complaint: with the relevant supervisory authority (e.g., Personal Information Protection Commission of Japan / EU data protection authority)

9.2 — Procedures for Exercising Your Rights

If you or your authorized representative wish to exercise any of the rights listed above (including requests for disclosure, correction, or suspension of use), please contact us at: [email protected]

Upon receiving your request, we will proceed as follows:

  • Identity Verification: We will verify that the request is made by the data subject in question (or their legitimate representative).
  • Investigation and Action: We will conduct the necessary investigation without delay. If we determine that the request is justified under applicable law (e.g., if the data is indeed inaccurate or processed unlawfully), we will carry out the disclosure, correction, erasure, or suspension of use without delay.
  • Notification: We will notify you without delay of the actions taken, or of our decision and the reasons if we decide not to take action as permitted under applicable law.

Where a user (including sole traders and representatives of corporate clients) exercises the right to erasure, deletion, or suspension of use, please note that certain personal data (such as identity verification documents, transaction records, and communication logs) may need to be retained by the Company notwithstanding the request. This is because retention is necessary for the establishment, exercise, or defense of legal claims and for compliance with our statutory record-keeping obligations, and, where applicable, to meet trade control requirements and the compliance requirements of the financial institutions that process our transactions.

Security Measures

We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest
  • Access controls and least-privilege principle
  • Regular security assessments and penetration testing
  • Employee training on data protection
  • Incident response and breach notification procedures

In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware (as required by GDPR), and affected individuals without undue delay.

Children's Data

The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected such data, we will delete it promptly.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or prominent notice on the Service at least 30 days before the changes take effect. The updated policy will include the effective date at the top of the document.


  Contact         Report problem