This Data Processing Agreement ("DPA") sets out the commitments between the Customer (as defined in Section 1(1)) and Launchers Co., Ltd. ("we", "us" or "our") regarding the processing of Customer Data (including Personal Data) that we hold in IceShore Workspaces.

This English version is a translation provided for convenience. The Japanese version is the governing text (see Section 15).

Section 1. Definitions

The terms used in this DPA have the meanings set out below. Terms not defined here have the meanings given in the IceShore Terms of Service (the "Terms of Service").

  1. For the purposes of this DPA, "Customer" means, for each Workspace, the corporation or individual that is party to this DPA, whether the Workspace is on a Paid Plan or the Free plan. For a Workspace that has a Customer as defined in Section A.12 of the Terms of Service (the person who subscribes to the Paid Plan), that person is the Customer. For any other Workspace, the Customer is the corporation or individual that holds a Workspace owner's account (if there is more than one owner, each of them).
  2. "Customer Data" means data stored in the Customer's Workspace, or processed by us through the use of the Customer's Workspace. It includes architecture diagrams (ADL), comments, information about Workspace members, records of invitations and join requests, and records of activity in the Workspace. However, account registration information (user name, name, email address, profile, language preference and similar information) is not Customer Data; we process it in accordance with the IceShore Privacy Statement.
  3. "Personal Data" means any Customer Data that relates to a living individual and that can identify that individual. It includes "personal data" as defined in Japan's Act on the Protection of Personal Information (Act No. 57 of 2003) (the "APPI") and "personal data" as defined in the GDPR (EU General Data Protection Regulation) and other applicable laws.
  4. "Data Protection Laws" means the laws that apply to the processing of Personal Data, including the APPI, the GDPR, the UK GDPR, and the regulations made under them.
  5. "Sub-processor" means a third party to which we entrust the processing of Customer Data.
  6. "Security Incident" means any accidental or unlawful destruction, loss or alteration of, or unauthorized disclosure of or access to, Customer Data managed by us or a Sub-processor. A Security Incident involving Personal Data is a "personal data breach" under the GDPR.
  7. "In writing" includes email.
  8. "Workspace administrator" means a member who has been given the administrator role in a Workspace.

Section 2. Roles and Scope

  1. With respect to Personal Data contained in Customer Data, the Customer determines the purposes and means of processing (a "controller" under the GDPR), and we process it on the Customer's instructions (a "processor" under the GDPR). Under the APPI, we are a person to whom the Customer entrusts the handling of Personal Data.
  2. Sections 4, 5, 6 and 8, Section 9(2) to (4), Section 10(1) and Section 11 apply to all Customer Data, whether or not it contains Personal Data. These commitments apply even if no Personal Data is written in an architecture diagram. All other provisions of this DPA apply to the Personal Data described in the preceding paragraph.
  3. Information that we process for our own purposes (such as account registration, billing and payment, website analytics, and responding to inquiries, except Customer Data that the Customer includes in or attaches to a support request) is outside the scope of this DPA. We process that information in accordance with the IceShore Privacy Statement.
  4. The details of processing (categories of data subjects, types of data, purposes and duration) are set out in Annex 1.

Section 3. Customer Instructions

  1. We process Personal Data only on the Customer's documented instructions (in writing). Transfers outside Japan are also carried out within the scope of those instructions. The Terms of Service, this DPA, and the actions the Customer takes in the IceShore interface or API are deemed to be the Customer's documented instructions.
  2. If the law requires us to process Personal Data in another way, we will notify the Customer before that processing, unless the law prohibits such notice.
  3. If we believe that an instruction from the Customer violates Data Protection Laws, we will promptly notify the Customer. We may suspend processing under that instruction until we reach agreement with the Customer.
  4. The Customer is responsible for having a lawful basis (such as notice to, or consent from, data subjects) for including Personal Data in Customer Data.

Section 4. Our Obligations

  1. We process Customer Data only for the purpose of providing IceShore to the Customer.
  2. We do not sell Customer Data.
  3. We treat Customer Data as confidential, and we ensure that our personnel and anyone else processing Customer Data under our authority are bound by an obligation of confidentiality.
  4. Our personnel view non-public Customer Data only in the following cases:
    • When necessary to respond to a support request from the Customer.
    • When necessary to maintain the security and integrity of IceShore, or to respond to outages or misuse.
    • When necessary to comply with the law.
    • When the Customer has consented.
    Having an AI provided by a Sub-processor listed in Annex 3 read Customer Data at the direction of our personnel also counts as viewing under this paragraph.
  5. We automatically scan Customer Data by machine to mask credentials and to detect improper content. No person views the content during this scanning.

Section 5. Security Measures

  1. We implement technical and organizational measures to protect Customer Data. Our current measures are set out in Annex 2.
  2. We may review and change the measures in Annex 2, but we will not make any change that lowers the overall level of protection.

Section 6. Sub-processors

  1. The Customer authorizes in advance our engagement of the Sub-processors listed in Annex 3 to process Customer Data.
  2. We enter into a contract with each Sub-processor that provides protection for Customer Data at least equivalent to this DPA. We are responsible to the Customer for the acts of our Sub-processors.
  3. When we add or replace a Sub-processor, we will update Annex 3 at least 30 days in advance. Customers who have requested such notice in advance by email to legal@iceshore.ai will also be notified by email.
  4. The Customer may object in writing, with reasonable grounds, within 30 days of the notice described in the preceding paragraph. In that case, we and the Customer will consult in good faith. If we cannot reach agreement, the Customer may end its Paid Plan without penalty by written notice, with effect from the date specified in the notice (or, if none, the date of the notice), and we will refund any prepaid fees for the period after the end date.

Section 7. Assistance with Data Subject Requests

  1. If we receive a request directly from a data subject to access, correct, delete or otherwise act on Personal Data, we will direct the data subject to contact the Customer and notify the Customer of the request. We will not respond to the request without the Customer's instructions, unless the law requires us to do so.
  2. We will assist the Customer, to the extent necessary for the Customer to respond to data subject requests, by providing IceShore features and by other reasonable means. If we provide additional assistance for a request that cannot be handled with IceShore features, the Customer will bear the cost to the extent permitted by law.

Section 8. Security Incident Notification

  1. We will notify the Customer without undue delay after becoming aware of a Security Incident. We will investigate the cause and take remedial measures to the extent within our reasonable control.
  2. The preceding paragraph does not apply to incidents caused by the Customer or any member of the Workspace or other User.
  3. Notices are sent to the email addresses of the Workspace owner and the Workspace administrators. On a Paid Plan, they are also sent to the account email address of the user registered as the Customer.
  4. We will provide the information the Customer needs to report to supervisory authorities or data subjects, and cooperate to a reasonable extent.
  5. Our notification of a Security Incident is not an acknowledgment of fault or liability by us.

Section 9. Assistance with Impact Assessments and Audits

  1. We will cooperate to a reasonable extent, taking into account the nature of the processing and the information available to us, when the Customer carries out a data protection impact assessment or carries out a prior consultation with a supervisory authority.
  2. We will provide the information the Customer needs to verify compliance with this DPA.
  3. Up to once a year, the Customer may send us a questionnaire about our security measures and ask us to answer it in writing. We will answer in writing within a reasonable period.
  4. If Data Protection Laws or a supervisory authority require it, the Customer (including an auditor appointed by the Customer) may request an audit at our premises. The Customer must make the request in writing at least 30 days before the audit and bear the costs of the audit. The date, time and scope of the audit will be agreed in writing in advance.

Section 10. Storage Location and International Transfers

  1. We store and process Customer Data in Japan (the Amazon Web Services Tokyo region). However, the Sub-processors listed in Annex 3 process Customer Data in the countries listed there.
  2. Transfers of Personal Data from the European Economic Area (EEA) to Japan rely on the European Commission's adequacy decision for Japan. Transfers from the United Kingdom to Japan rely on the adequacy regulations for Japan that continue to have effect under the UK Data Protection Act 2018. We comply with the Supplementary Rules issued by Japan's Personal Information Protection Commission for Personal Data received through these transfers.
  3. With Sub-processors outside Japan, we establish by contract a system conforming to the standards referred to in Article 28(1) of the APPI, and we take the necessary measures referred to in Article 28(3) of the APPI. When we transfer Personal Data received from the EEA or the UK to a Sub-processor outside Japan, we include in our contract with that Sub-processor, as applicable, the Standard Contractual Clauses adopted by the European Commission, the International Data Transfer Addendum issued by the UK Information Commissioner, or other measures, in accordance with the Supplementary Rules.

Section 11. Export and Deletion of Customer Data

  1. The Customer may export architecture diagrams in ADL format at any time while this DPA is in effect. The ADL language specification and schema are public, and exported files can be read outside IceShore. Customer Data other than architecture diagrams (such as comments and member lists) will be provided in a machine-readable format upon the Customer's written request.
  2. Ending a Paid Plan does not delete the Workspace or Customer Data. The Workspace remains on the Free plan.
  3. When an architecture diagram or Workspace is deleted in the IceShore interface, it is no longer visible to or usable by Users. However, this action alone does not erase the data from our storage.
  4. When the Customer requests in writing to legal@iceshore.ai that Customer Data be erased, we will erase that Customer Data from our storage within a reasonable period, except as set out in the following paragraph. Copies remaining in backups are erased when the backup retention period ends.
  5. Data that the law requires us to retain, and records of connections to and operations on our databases (Annex 2), are excluded from erasure under the preceding paragraph. While we retain such data, this DPA continues to apply, and we will not process it for any purpose other than retention.
  6. If the Customer requests, we will confirm in writing that we have completed the erasure described in paragraph 4.

Section 12. Relationship to the Terms of Service; Liability

  1. This DPA forms part of the Terms of Service. If this DPA and the Terms of Service conflict regarding the processing of Customer Data, this DPA prevails.
  2. Our liability in connection with this DPA is subject to Section M (Limitation of Liability) of the Terms of Service.

Section 13. Formation, Term and Changes

  1. This DPA is entered into when the Customer agrees to the Terms of Service on or after the effective date. For Customers who agreed to the Terms of Service before the effective date, this DPA is entered into on the effective date.
  2. This DPA remains in effect while we process the Customer's Customer Data. Section 11 survives the end of this DPA. Sections 4 to 9 survive for as long as we retain Customer Data.
  3. Customers who wish to sign a written copy of this DPA may contact legal@iceshore.ai.
  4. We may change this DPA through the change procedure set out in the Terms of Service. Previous versions will remain available from this page.

Section 14. Governing Law and Jurisdiction

This DPA is governed by the laws of Japan. The Tokyo District Court has exclusive jurisdiction as the court of first instance over any dispute relating to this DPA.

Section 15. Governing Language

This DPA is written in Japanese, and the Japanese version is the governing text. If there is any inconsistency between the Japanese version and a translation, the Japanese version prevails.

Annex 1. Details of Processing

ItemDetails
Data subjectsMembers and guests of the Customer's Workspace. Individuals whom the Customer writes about in architecture diagrams or comments
Types of Personal DataUser name, name, email address, profile image, role in the Workspace, activity records (audit logs), records of invitations and join requests, comments, and content the Customer writes in architecture diagrams. User name, name, email address and profile image here mean those contained in records such as the Workspace member list, invitation and join request records and activity records; account registration information itself is not included (Section 1(2))
Special categories of Personal DataNot intended to be processed. The Customer should not include health, beliefs, race or other sensitive personal information in Customer Data
Purpose of processingProviding IceShore to the Customer (creating, saving, sharing and rendering architecture diagrams, managing Workspaces, sending notification emails, and connecting with AI clients), and responding to the Customer's support requests
Processing operationsStorage, viewing, rendering, search, copying (backup), transmission and deletion; summarizing support requests and drafting replies
Duration of processingWhile this DPA is in effect. Deletion is handled as set out in Section 11

Annex 2. Security Measures

We implement measures in each of the areas below. We review the technologies and settings we use within the scope of Section 5(2). Details of the measures are described on the Data & trust page of our Help Center, which we update from time to time.

AreaMeasures
OrganizationWe appoint a person responsible for personal information protection and require personnel who handle Customer Data to keep it confidential
Encryption in transitCustomer Data is encrypted in transit between users and IceShore, and within our systems
Encryption at restCustomer Data stored in databases, backups and file storage is encrypted
AuthenticationPasswords are stored in a form that cannot be decrypted. We provide multi-factor authentication and protect accounts against repeated failed sign-in attempts
Access controlActions are restricted by role in each Workspace. Our personnel view non-public Customer Data only in the cases set out in Section 4(4)
Credential maskingCredentials contained in architecture diagrams are detected and masked before they are saved
AvailabilityDatabases are redundant, and backups are taken regularly (kept for 7 days)
LoggingActivity in Workspaces, and connections to and operations on our databases, are recorded and retained for a set period

Annex 3. Sub-processors

ProviderProcessingData involvedCountry of processing
Amazon Web ServicesOperating the service and storing dataAll Customer DataJapan (Tokyo region)
Amazon Web ServicesDelivering the service, and storing access logsCustomer Data being delivered; request URLs (including query strings), IP addresses, browser information and referrersEdge locations in various countries (delivery); United States (access logs)
Amazon Web ServicesReceiving, storing and replying to support request emailsCustomer Data that the Customer includes in or attaches to a support requestUnited States
Twilio Inc. (SendGrid)Sending notification emailsRecipient email address, user names, Workspace names, architecture diagram titles, and parts of commentsUnited States
Google LLC (Google Workspace)Receiving and storing support request emailsCustomer Data that the Customer includes in or attaches to a support requestUnited States and other countries
Anthropic, PBC (Claude)Reviewing and summarizing support request emails and drafting replies; investigating and responding to outages and misuseCustomer Data that the Customer includes in or attaches to a support request, and, in the cases set out in Section 4(4), Customer Data to the extent necessary to investigate and respond to outages and misuseUnited States

Payment processing (Stripe, Inc.) and website analytics (Google Analytics 4) are processing that we carry out for our own purposes. They are described in the IceShore Privacy Statement.

Contact: legal@iceshore.ai

Launchers Co., Ltd. (10F Shibadaimon Center Bldg, 1-10-11 Shibadaimon, Minato-ku, Tokyo 105-0012, Japan)