Last Updated: 1 September 2026 | Version: 1.0
This Privacy Policy explains how HEIWA AUTO CO., LTD. ("Company") collects, uses, discloses, and protects personal data in connection with the Service. For the purposes of this Privacy Policy, "Service" means the Company's vehicle export, sales, quotation, transaction management, customer account, inquiry, and related services. This policy applies to personal data of individuals who act as representatives, contact persons, or authorized users on behalf of corporate customers, as well as to personal data of sole trader (individual business operator) customers who register and use the Service in their own name (collectively, "Applicants" or "Users"). For the purposes of this Privacy Policy, "Personal Data" means personal information (個人情報) as defined under the Act on the Protection of Personal Information of Japan ("APPI"), and, where the GDPR applies, personal data as defined under Regulation (EU) 2016/679 ("GDPR").
HEIWA AUTO CO., LTD.
6-1 Nagisa-cho, Izumiotsu-city, Osaka 595-0055, Japan
CEO: Junji Abe
Privacy Contact: [email protected]
To facilitate cross-border trade and for contract execution, we collect:
For credit assessment and compliance purposes, we may collect:
Where the Applicant is a sole trader, we may additionally collect personal identification data for identity verification and counterparty risk management purposes (KYC/AML), including:
Such data is collected only to the extent necessary to verify the identity of our contracting counterparty and to manage counterparty and transaction risk, including the prevention of fraud and the establishment and defense of legal claims that may arise from a transaction. This collection also supports identity verification or screening required by the financial institutions that process our transactions, and our compliance with applicable trade control laws. We will retain copies of identification documents in accordance with the retention periods specified in Article 8.
For the purposes of counterparty and transaction risk management (KYC/AML), sanctions screening, creditworthiness assessment, and compliance with applicable laws, we may obtain personal data about you from the following categories of third-party sources, in addition to information provided directly by you:
All such information is obtained from publicly accessible sources or from sources made available pursuant to applicable law. The legal bases for this processing are our legitimate interests in preventing fraud and managing counterparty and transaction risk (Article 6(1)(f) GDPR) and/or compliance with legal obligations to which we are subject (Article 6(1)(c) GDPR). We do not obtain personal data from third-party sources beyond what is necessary for the purposes stated above.
We automatically collect:
We do not intentionally collect special category personal data (e.g., health, racial or ethnic origin, political opinions, religious beliefs, criminal record). If such data is inadvertently submitted, it will be deleted as soon as reasonably practicable.
We process personal data on the following legal bases:
We are committed to data minimization. Especially when processing personal data of sole traders for business purposes (such as names and addresses used as business contact details), we apply enhanced measures to ensure that only data strictly necessary for the stated purposes is collected and retained.
Personal data is used for the following purposes. Unless otherwise permitted or required by applicable law, we will obtain the user's prior consent before using personal information beyond the scope of these purposes of use:
We will not use personal data for purposes incompatible with those listed above without obtaining fresh consent, except where such use is permitted or required by applicable law.
We do not provide personal data to third parties without the data subject's prior consent, except in the following circumstances permitted by applicable law:
Where any of the above exceptions do not apply, we share personal data only as necessary and only with the following categories of recipients:
Where third-party service providers process personal data on our behalf, we enter into written data processing agreements that require them to: (a) process data only on our documented instructions; (b) implement appropriate technical and organizational security measures; (c) not engage sub-processors without our prior written consent.
Among the categories of recipients listed in Section 5.1, where the Company entrusts the handling of personal data, in whole or in part, to external service providers (such as affiliated companies involved in transaction execution, logistics partners, IT service providers, and cloud infrastructure operators) within the scope necessary to achieve the specific purposes of use, such disclosure constitutes "entrustment" (and not "third-party provision") under the APPI. In such cases, we ensure appropriate supervision over such providers in accordance with Section 5.2.
The Company does not jointly use personal data with any specific third parties within the meaning of Article 27, Paragraph 5, Item 3 of the APPI.
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By continuing to use our website, you acknowledge the use of strictly necessary cookies. For analytical cookies, your consent will be sought separately.
Cookies are data files stored on your computer or mobile device when you visit a website. These cookies recognize you the next time you visit the same website. With the stored cookies, website owners can provide you with better information and an enhanced experience.
We use cookies to distinguish you from other users of our website and to provide a browsing experience that is unique to you. The use of cookies helps us improve our site usage and performance, and helps us better understand your needs and preferences when visiting our website. We use a third-party service provider for the analysis of our site's usage and performance. The collected information will be used for the purpose of analyzing site usage and performance.
The following cookies are strictly necessary for the operation of the Service and do not require prior consent:
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
| ASPSESSIONID | Strictly necessary | Maintains your login session and authentication state | Session |
| remember_token | Strictly necessary | Keeps you logged in if you select "Remember me" | 30 days |
We do not use advertising cookies or third-party tracking cookies.
Most browsers allow you to refuse cookies and you are always free to decline our cookies. You may block our cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. Please note that blocking session cookies will prevent you from logging in to the Service, and may restrict the functionality of this website and affect your user experience.
Guidance for common browsers:
Our headquarters and primary servers are located in Japan. When we transfer personal data to third parties located in foreign countries — including entities to which we entrust the handling of personal data (data processors) located outside Japan — we ensure such transfers are lawful and protected by appropriate safeguards, including:
Information regarding the specific foreign countries where your personal data is stored or processed, and the personal information protection systems of those countries, will be provided to you without delay upon request to: [email protected]
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized.
Subject to applicable law (including the APPI and the GDPR, where applicable), individuals whose personal data we process have the following rights. Rights to request suspension of use, erasure, or cessation of third-party provision apply specifically to retained personal data (保有個人データ) as defined under the APPI:
If you or your authorized representative wish to exercise any of the rights listed above (including requests for disclosure, correction, or suspension of use), please contact us at: [email protected]
Upon receiving your request, we will proceed as follows:
Where a user (including sole traders and representatives of corporate clients) exercises the right to erasure, deletion, or suspension of use, please note that certain personal data (such as identity verification documents, transaction records, and communication logs) may need to be retained by the Company notwithstanding the request. This is because retention is necessary for the establishment, exercise, or defense of legal claims and for compliance with our statutory record-keeping obligations, and, where applicable, to meet trade control requirements and the compliance requirements of the financial institutions that process our transactions.
We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:
In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware (as required by GDPR), and affected individuals without undue delay.
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected such data, we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or prominent notice on the Service at least 30 days before the changes take effect. The updated policy will include the effective date at the top of the document.
|
|