Grace imaging Privacy Policy
Grace imaging, Inc. ("we", "us" or "our") has established this Privacy Policy (this "Policy") to describe how we handle user information, including personal information about users, on our website and in the cloud applications for sports and healthcare that we provide, including "Sukonavi" (the "Service").
1. Information Collected on Our Website
We collect the following information on our website (the "Website"). How we handle User Information in the Service is set out in Article 2 and the following Articles.
1-1 Contact Form
Our contact form collects:
- Name
- Company name or affiliation
- Email address
- Phone number (optional)
- The content of the inquiry
We use this information only to respond to the inquiry and to contact the sender as needed. We do not provide it to third parties without the sender's consent, except in the cases described in Article 6(4) and 6(5).
1-2 Analytics (Google Analytics)
The Website uses Google Analytics, a web analytics service provided by Google LLC, to understand and improve how the Website is used. Google Analytics uses cookies to collect information such as the pages viewed, the date and time of visits, referrers, device and browser type, and approximate location estimated from the IP address. This information does not include information that directly identifies individuals, such as names.
The collected information is sent to Google LLC (United States) and managed under Google's Privacy Policy (https://policies.google.com/privacy). Visitors can refuse this collection by disabling cookies in their browser or by using the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout).
1-3 Application of Other Provisions
Articles 7 to 10 and Article 12 of this Policy also apply to information collected on the Website.
2. User Information We Collect and How We Collect It
In this Policy, "User Information" means information that we collect under this Policy, including information that identifies corporations and organizations and the users registered by them (collectively, "Users"), records of their activity on communication services, and other information generated or stored in connection with Users or their devices.
Depending on how it is collected, the User Information we collect in the Service is as follows.
(1) Information provided by Users
Users provide us with the following information in order to use the Service or through their use of the Service:
- Profile information, such as the name of the corporation or organization, the user's name, date of birth and sex
- Contact information designated by the corporation or organization or provided by the User, such as email address, telephone number and address
- User attributes designated by the corporation or organization
- Information needed for examinations and diagnoses (such as height, weight, blood pressure, sleep condition, stress condition and medical condition)
- Information obtained from examinations and diagnoses (such as sweat lactate level, heart rate, fatigue level, speed and pulse)
- Still images, including images of the User
- History of use of the Service (such as browsing history and usage history)
- Information that Users enter or send through input forms or other methods specified by us
Of this information, special care-required personal information as defined in the APPI (such as medical conditions and examination and diagnosis results) is obtained only with the prior consent of the individual user.
(2) Information provided by other services that Users allow to connect with the Service
If a User allows the Service to connect with another service, such as a social networking service, we collect the following information from that external service, based on what the User agreed to when giving permission:
- Account information that the User uses on the external service
- Other information that the User has allowed to be disclosed through the privacy settings of the external service
How we handle information obtained through the Google Health API is set out in Article 11.
(3) Information we collect when Users use the Service
We may collect information about access to the Service and how it is used. This includes:
- Referrer
- IP address
- Server access logs
- Cookies, ADID, IDFA and other identifiers
(4) Information we collect with the User's individual consent
If a User individually consents in the manner described in 4-1, we collect the following information from the device the User is using:
- Location information
3. Purposes of Use
We use User Information in connection with providing the Service for the following purposes:
- (1) To provide, maintain, protect and improve the Service, including accepting registrations, verifying identity, authenticating users, recording user settings and calculating fees
- (2) To measure traffic and user behavior
- (3) To serve and display advertising and measure its effectiveness
- (4) To provide information to our partners
- (5) To analyze information together with examination and medical results provided by our partners
- (6) To provide health and exercise guidance
- (7) To send information about the Service, conduct surveys and respond to inquiries
- (8) To respond to violations of our terms, policies and other rules relating to the Service (the "Terms")
- (9) To notify Users of changes to the Terms
4. Notice, Publication, Consent and Requests to Stop Use
4-1 We obtain the User's consent before collecting the following User Information:
- Location information
4-2 Users can ask us to stop collecting or using all or part of their User Information by changing the relevant settings in the Service. In that case, we will promptly stop using it in accordance with our procedures. For some items of User Information, collection or use is a prerequisite of the Service; for those items, we will stop collection or use only when the User withdraws from the Service by the method we specify.
5. External Transmission and Information Collection Modules
Our partners may store cookies on Users' devices and use them to accumulate and use User Information. In that case, we will inform Users of the partners and URLs involved. The Service may also include information collection modules. In that case, we will provide User Information to the provider of the module (including providers located outside Japan) after informing Users.
6. Provision to Third Parties
We do not provide personal information included in User Information to third parties (including third parties located outside Japan) without the User's prior consent, except in the following cases:
- (1) When we entrust all or part of the handling of personal information to doctors, medical institutions, research institutions or other partners, to the extent necessary to achieve the purposes of use
- (2) When personal information is provided as part of a business succession due to a merger or other reason
- (3) When personal information is provided to partners or information collection module providers in accordance with Article 5
- (4) When we need to cooperate with a national or local government body, or a party entrusted by one, in carrying out duties prescribed by law, and obtaining the User's consent would likely interfere with those duties
- (5) Other cases permitted by the Act on the Protection of Personal Information of Japan (the "APPI") or other laws
7. Security Measures
We take necessary and appropriate measures to prevent the leakage, loss or damage of User Information and otherwise keep it secure. For details of these measures, please contact us at the address in Article 12 (Contact).
8. Requests for Disclosure of Personal Information
8-1 When a User asks us to disclose their personal information under the APPI, we will disclose it to the User without delay after confirming that the request comes from the User (or notify the User if no such personal information exists). This does not apply where we are not obliged to disclose it under the APPI or other laws.
8-2 We charge a fee of JPY 1,000 (excluding consumption tax) per request for notifying the purposes of use or disclosing retained personal data or records of provision to third parties.
9. Correction and Suspension of Use of Personal Information
9-1 If a User asks us, under the APPI, (1) to correct their personal information because it is inaccurate, or (2) to stop using it because it is being handled beyond the purposes of use published in advance or was collected by deception or other wrongful means, we will conduct the necessary investigation without delay after confirming that the request comes from the User. Based on the results, we will correct the personal information or stop using it, and notify the User. If we decide not to correct it or stop using it, we will notify the User of that decision.
9-2 If a User asks us to delete their personal information and we determine that we should comply, we will delete it after confirming that the request comes from the User, and notify the User.
9-3 9-1 and 9-2 do not apply where we are not obliged to make corrections or stop use under the APPI or other laws.
10. Changes to This Policy
We will change this Policy as necessary. If a change requires Users' consent under applicable law, the revised Policy will apply only to Users who have agreed to the change in the manner we specify. When we change this Policy, we will announce the effective date and content of the revised Policy on our website or by other appropriate means, or notify Users.
11. Handling of Information Obtained from the Google Health API
This Article describes how we handle information that "Sukonavi" (すこナビ), part of the Service, obtains through the Google Health API with the User's consent ("Google User Data"). With respect to Google User Data, this Article takes precedence over the other provisions of this Policy.
11-1 Information We Obtain
We obtain the following Google User Data:
- Step count (per-minute values and daily totals)
- Heart rate (per-minute averages)
- Model name, battery level and last sync time of the devices the User has connected to Google Health
- Google Health user identifiers (Google user ID and Fitbit user ID)
11-2 How We Obtain It
We obtain Google User Data only when the User selects "Connect" on the Sukonavi settings screen, and only within the scope the User has authorized on Google's consent screen. We do not obtain or store the User's Google account password.
11-3 How We Use It
We use Google User Data only for the following purposes:
- To display the User's step count and heart rate as charts in Sukonavi.
- To provide exercise-support features, such as showing progress toward the User's exercise goal and counting steps taken above the User's target heart rate.
- To notify the User when the device battery is low or the device has not synced.
- With the User's consent, to allow the User's care team (the medical institution the User belongs to) to view the same information as items 1 to 3 in order to support the User's exercise.
11-4 Limitations on Use
We do not do any of the following with Google User Data, including any data aggregated, anonymized or derived from it. Article 3(3), Article 3(4) and Article 5 of this Policy do not apply to Google User Data.
- Use it to serve, display or measure advertising, including personalized or interest-based advertising.
- Sell it, or transfer it to third parties such as advertising platforms, data brokers or information resellers.
- Use it to determine creditworthiness or for lending purposes.
- Use it to train machine-learning or AI models.
- Use it for research, including medical research or research involving human subjects.
We do not transfer Google User Data to third parties except:
- when the User's care team views it with the User's consent, as described in 11-3 item 4;
- when necessary for security purposes, such as investigating abuse;
- to comply with applicable laws; or
- as part of a merger, acquisition or sale of assets, after obtaining the User's explicit prior consent.
Our employees do not read Google User Data except:
- with the User's explicit consent (for example, to respond to an inquiry);
- when necessary for security purposes, such as investigating abuse;
- to comply with applicable laws; or
- when the data is aggregated and anonymized and used for internal operations in accordance with applicable laws.
11-5 Security
We obtain Google User Data over encrypted connections (HTTPS) and store it encrypted at rest. The credentials used to access the Google Health API (access tokens and refresh tokens) are also stored encrypted, and access to them is limited to those who need it.
11-6 Disconnection and Deletion
- Users can revoke our access to Google User Data at any time from "Third-party apps & services" in their Google Account. If "Disconnect" is shown on the Sukonavi settings screen, Users can also revoke access there. After access is revoked, we stop obtaining Google User Data. Users who are unsure how to revoke access can contact us at the address in Article 12.
- Users can request deletion of the Google User Data we store by contacting us at the address in Article 12. After verifying that the request comes from the User, we will delete the data promptly.
- We keep Google User Data only as long as necessary for the purposes above, and delete it promptly when it is no longer needed or when the User withdraws from the Service.
11-7 Compliance with Google API Policies
The use of information received from Google Health API will adhere to the Google Health API Developer and User Data Policy, including the Limited Use requirements.
12. Contact
For comments, questions, complaints or other inquiries about the handling of User Information, please contact:
CRIK Shinanomachi, 9F Building 2, Keio University Shinanomachi Campus
35 Shinanomachi, Shinjuku-ku, Tokyo 160-8582, Japan
Personal Information Manager: Yoji Kishi
Email: info@gr-img.com
Revised: November 8, 2024
Revised: October 1, 2026
