AI Disclosure
Last updatedSeptember 1, 2026
1. Function overview and inputs
ORGO Inc. ("we" or "ORGO") provides this disclosure (this "document") regarding the AI assistant and third-party AI use in our movement-analysis service "MYoACT" (the "Service").
To explain analysis results and help users use the Service, the Service offers a text-based AI assistant. The AI assistant generates answers using the question or instruction text entered by the user (a person issued an account for the Service under the management of a customer (an entity or individual that uses the Service under a contract with us; the same applies below); the same applies below), the conversation context, analysis metadata, and numeric series extracted from biomechanical analysis.
The AI assistant uses an external Large Language Model ("LLM") through an inference platform provided by our cloud infrastructure provider (the "LLM inference platform").
1.1 Scope of input data
The analysis metadata used by the AI assistant includes analysis identifiers, analysis names, analysis dates, and chart identifiers. The numeric series include time series such as skeletal coordinates and joint angles. These numeric series are limited to numeric data used to explain analysis results and are designed not to include direct identifiers such as user names, email addresses, patient IDs, or medical record IDs. Analysis names and chart labels are operated so as to be limited to opaque identifiers or management labels that do not contain direct identifiers such as patient names, and free-text clinical information is not entered into the AI assistant.
1.2 Relationship to health-related data
In the Service, we manage data relating to the physical and mental condition of the persons analyzed ("health-related data") in the categories of raw video, skeletal/pose data, analysis results, physical attributes, and related metadata. The information sent to the AI assistant is limited to the text information and numeric series necessary for explanation; original videos, images, and other source files are not included in the AI assistant's inputs.
2. Payload sent to the external LLM inference platform
2.1 Scope of the transmitted payload
The payload sent from the AI assistant to the LLM inference platform is designed to be limited to text and numeric series. Video files, image files, and other analysis-artifact binaries, originals in storage, links that can access original files (including temporary access URLs), and users' email addresses are not included in the payload sent to the LLM inference platform.
By this payload-limitation design, the AI assistant processes within the scope of the question text, conversation context, analysis metadata, and numeric series necessary to explain analysis results. A path that passes original data or attachments directly to the external LLM is not part of the Service's basic design, including for use by hospitals, healthcare institutions, and other customers in a medical or rehabilitation context ("medical-sector customers").
3. LLM provider configuration
3.1 LLM inference platform path
The AI assistant's external LLM call uses only a single LLM designated by us, via a connection point in Japan. The specific model and provider are set out in the subprocessor list that ORGO publishes on its website. We operate the LLM inference platform in a configuration that limits the execution of inference to regions within Japan.
Accordingly, the actual model inference is performed in regions within Japan, and we do not use regions outside Japan as the execution location for inference. However, because the provider of the LLM inference platform is a third party located in a foreign country, we continue to manage this path within the framework of Article 28 of the Act on the Protection of Personal Information of Japan ("APPI") (ongoing assurance of equivalent safeguards). If we change this configuration, we will revise this document and the subprocessor list and disclose the revised handling.
3.2 Scope of third-party AI provider use
The AI assistant path is solely the single external LLM via the LLM inference platform; no other third-party AI provider is called. We do not send AI assistant traffic to any third-party AI outside that path.
3.3 Contractual handling
The LLM inference platform is used under the cloud infrastructure provider's contract and data-protection documents. On that path, the cloud infrastructure provider is the starting point, and the external LLM is used via the LLM inference platform. Under the provider's published data-protection terms, the prompts and responses sent from the AI assistant to the LLM inference platform are not used to train the foundation model of the inference-platform provider or the model provider, and are not provided to third parties. We rely on the provider's published terms on this point and confirm it as part of our contractor management.
4. Log retention and deletion operations
4.1 Storage location
The AI assistant's inputs, outputs, and related metadata are stored in a database in Japan. Logs necessary to operate the Service are also recorded.
4.2 Retention period
Operational logs are retained only for the period necessary for fault analysis and incident investigation (see "14. Retention and deletion" of the Privacy Notice).
4.3 Reflection in contract annexes
Log retention and deletion operations are specified in a contract annex or the use description for medical-sector customers. For use by medical-sector customers, we clearly explain the storage location, retention period, operation upon a deletion request, and handling of audit logs for the AI assistant's inputs, outputs, and metadata.
5. Additional rules for medical-sector customers
For use by medical-sector customers, in addition to the Service's basic design, we operate the AI assistant with a more limited scope.
5.1 Exclusion of original binaries
By design, the AI assistant does not receive original videos, images, or other original binaries. The call to the LLM inference platform is limited to text and numeric series. That payload consists of the user's input text, conversation context, analysis metadata, and numeric series such as skeletal coordinates and joint angles.
5.2 Minimization of direct identifiers
The text sent to the AI assistant is minimized to the scope necessary for an answer. We limit the user's questions, conversation context, analysis metadata, and numeric series to the necessary scope, and maintain an operation that does not include direct identifiers such as patient names, contact details, patient IDs, or medical record IDs. Analysis names and chart labels are limited to opaque identifiers or management labels that do not contain direct identifiers, and free-text clinical information is not entered into the AI assistant.
5.3 Numeric series and masking design
We define the scope of the numeric series and the handling that excludes direct identifiers as follows. The numeric series are limited to numeric data necessary to explain analysis results, such as time series of skeletal coordinates or joint angles, and are handled in a form that does not contain direct identifiers. Analysis names and chart labels are limited to opaque identifiers or management labels that do not contain direct identifiers such as patient names, and free-text clinical information is not entered into the AI assistant.
5.4 Explanation of retention, deletion, and cross-border processing
The retention periods, deletion operations, and handling of audit logs for the managed database and the operational logging platform are specified in a contract annex. The details of the LLM inference platform's connection point and processing location are as described in §3.1; at the time of onboarding a medical-sector customer, we also disclose that we operate in a configuration that limits the execution of inference to regions within Japan.
5.5 Handling for HIPAA-covered customers
Where a customer that handles Protected Health Information ("PHI") as a Covered Entity, a Business Associate, or a Subcontractor under the U.S. Health Insurance Portability and Accountability Act ("HIPAA") uses the AI assistant, this is governed by the Business Associate Agreement ("BAA") concluded with us. Where the counterparty is a Business Associate or a Subcontractor, that BAA functions as the subcontractor agreement required by 45 CFR §164.504(e)(5).
Where PHI is handled in connection with the AI assistant, it is used only within the scope of the BAA or subcontractor agreement, and we operate so as to prohibit or minimize the entry of direct identifiers and free-text clinical information. Procedures for deletion and notification if PHI is entered by mistake follow our breach and incident response procedures. The handling of PHI on the LLM inference platform path (including processing in regions within Japan) is operated in accordance with the BAA and the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
Last updated: September 1, 2026
Revision history
| Date | Changes |
|---|---|
| September 1, 2026 | Initial publication |