International Data Transfers
Last updatedSeptember 1, 2026
Scope
ORGO Inc. ("ORGO," "we," or "us") establishes this statement on cross-border transfers and consent (this "Statement") for the movement analysis service "MYoACT" (the "Service") that it provides.
This Statement explains, to users and customers, the overseas processing paths that the Service uses for cloud infrastructure, AI inference, video analysis processing, web analytics, error monitoring, advertising measurement, payment processing, customer support, document sharing, and email delivery.
The main terms and abbreviations used in this Statement are as follows.
- Health-related data: data relating to the physical and mental condition of the persons analyzed (raw video, skeletal/pose data, analysis results, physical attributes and related metadata).
- User: a person issued an account for the Service.
- Subprocessor: a provider to which we entrust processing necessary for the provision of the Service.
- APPI: the Act on the Protection of Personal Information of Japan.
- GDPR: the EU General Data Protection Regulation.
- HIPAA: the U.S. Health Insurance Portability and Accountability Act.
- PHI / ePHI: Protected Health Information under HIPAA and its electronic form.
- CCPA: the California Consumer Privacy Act.
- DPA: a data processing agreement governing the handling of personal data.
- BAA: a Business Associate Agreement under HIPAA.
- SCC: the standard contractual clauses adopted by the European Commission.
- UK IDTA: the UK International Data Transfer Agreement.
- Swiss Addendum: an addendum for compliance with Swiss data protection law.
- TOMs: the technical and organisational measures implemented to protect personal data.
- DSR: a request for disclosure, correction, cessation of use, or similar.
- LLM: a Large Language Model.
This Statement explains overseas processing paths by functional category. The individual company names, main countries/regions, and types of safeguards of the vendors and subprocessors corresponding to each functional category are set out in the subprocessor list that ORGO publishes on its website.
Cross-border transfers under Japan's APPI
The Service uses service providers that may be located outside Japan, accessed from outside Japan, or that process data outside Japan. The functional categories concerned are: cloud infrastructure (hosting, authentication, database, storage, logs, content delivery), AI inference, video analysis processing, web analytics and data warehouse, error monitoring, advertising measurement, payment processing, customer support, document sharing and knowledge management, email delivery, and development/maintenance/operations subcontracting. The processing location, basis under APPI §28, and safeguards for each functional category are managed in accordance with the "Main overseas processing paths" table below, and paths that constitute cross-border transfers are addressed in the respective sections of this Statement. Email delivery uses a domestic provider and is operated without sending patient identifiers or health-related data. Where the processing, backups, or similar for that delivery involve overseas processing, it is treated as a cross-border transfer in the same way as the other paths in this Statement.
We also use a development, maintenance, and operations subprocessor (Philippines). Access by that subprocessor from the Philippines to the Service's systems is treated as a Japan → Philippines cross-border transfer; for EU customer matters, it is also treated as an EU → Philippines cross-border transfer.
When personal data is provided to a third party in a foreign country, ORGO, in accordance with APPI §28, obtains the data subject's consent where necessary, or relies on a framework that continuously ensures equivalent safeguards or another applicable basis. Where consent under APPI §28 is obtained, ORGO presents the following items on the consent screen or in an individual notice before obtaining consent.
- The name of the foreign country. Where the destination country cannot be identified, in place of the country name we present, in accordance with the Personal Information Protection Commission's guidelines (handling where the destination country cannot be identified): (i) the fact that the destination country cannot be identified, (ii) the reason, and (iii) alternative information useful to the data subject (the destination country/region category [the United States, the EU, the Asia-Pacific area, or other regions] and the safeguards taken).
- An overview of the personal data protection system in that foreign country (presented based on the Personal Information Protection Commission's published information, including its "Guidelines on the Act on the Protection of Personal Information (Provision to Third Parties in Foreign Countries)" and "Systems concerning the protection of personal information").
- The contractual and supplementary measures taken by the recipient.
Not all overseas processing is based on consent under APPI §28; some is managed through contractual measures, the continuous assurance of equivalent safeguards, or another applicable basis. The APPI §28 basis category for each functional category is shown in the "Main overseas processing paths" table below. The individual names of the recipients corresponding to each category are set out in the subprocessor list that ORGO publishes on its website.
Advertising measurement is the only path based on data subject consent. We present items 1-3 above in the consent management tool on the Service's web application before consent is obtained. That consent is not a condition of using the Service; the Service remains available to those who do not give it. This provision of information at the time of obtaining consent is not delegated to the publication of the subprocessor list.
Where the Service is used through a customer organization, obtaining consent from the persons analyzed is the responsibility of that customer organization, and we do not present a consent screen to them. We provide the information the customer organization needs, and cooperate with it, so that it can address Article 28 of the Act on the Protection of Personal Information of Japan.
If a data subject requests suspension of use, erasure, suspension of third-party provision, or another request, ORGO responds in accordance with applicable law, including APPI §35, without undue delay.
Cross-border transfers under the EU / UK / Swiss GDPR, etc.
Where the GDPR applies, transfers outside the EEA are managed under GDPR Art.44-46 through vendor-specific standard contractual clauses (SCCs), the UK IDTA where applicable, the Swiss Addendum (including amendments for the FADP/FDPIC), and supplementary technical and organizational measures.
In applying the SCCs, we use SCC Module 3 for paths where we subcontract as the processor for an EU customer, and SCC Module 2 for transfers from the customer (controller) to us (processor). For the UK we additionally use the UK IDTA or UK Addendum, and for Switzerland the Swiss Addendum (including amendments for the FADP/FDPIC).
For each path, we conclude or accept a DPA and SCC (including the UK IDTA and Swiss Addendum) as appropriate to the processing, and, for paths to which HIPAA applies, a BAA. The external LLM used by the AI inference platform is treated as part of the cloud infrastructure provider's service and subprocessor chain, and is handled within the framework of our contracts, DPA, and BAA with the cloud infrastructure provider. The individual company names for each path are set out in the subprocessor list that ORGO publishes on its website.
US / HIPAA-related handling
Whether HIPAA applies is not uniform across all uses of the Service. We assess whether HIPAA applies based on the customer's attributes, the purpose of use, the nature of the data, and whether a Covered Entity / Business Associate relationship exists.
Where we provide the Service to U.S. hospitals or other HIPAA Covered Entities and a Business Associate relationship arises, we confirm a HIPAA-compliant configuration and whether a BAA is required. For customers that are HIPAA Covered Entities, the cloud infrastructure is configured on the basis of using only HIPAA-eligible services, and it is handled within the scope of the BAA with the cloud infrastructure provider. The AI inference platform is handled within the cloud infrastructure provider's BAA framework. For the video analysis processing path, we apply safeguards through a BAA, DPA, SCC (including the UK IDTA and Swiss Addendum), and TOMs.
Additional conditions for medical-sector customers
For hospitals, healthcare institutions, and other customers in a medical or rehabilitation context ("medical-sector customers"), the following stricter premises apply in addition to the general cross-border transfer explanation.
- By design, the AI assistant does not receive original binaries such as original videos, images, or other source files. Invocation of the AI inference platform is limited to text and numeric series (user-entered text, conversation context, analysis metadata, skeletal coordinates, joint angles, and explanatory text).
- For the video analysis processing path, we apply safeguards through a BAA, DPA, SCC (including the UK IDTA and Swiss Addendum), and TOMs.
- AI assistant inputs, outputs, and operational logs are retained only for the periods set out in "14. Retention and deletion" of the Privacy Notice.
- Disclosure and other requests (DSRs) are handled under ORGO's response procedures, addressing the right to deletion under APPI §35, GDPR Art.17, and the CCPA.
- The individual company names in the subprocessor chain are set out in the subprocessor list that ORGO publishes on its website.
Main overseas processing paths
The location (country/region category), handling, basis under APPI §28, and type of safeguard for each main functional category used by the Service are as follows. The individual company names and main countries/regions corresponding to each category are set out in the subprocessor list that ORGO publishes on its website.
| Functional category | Main country/region category | Main handling and transfer purpose | Basis under APPI §28 | Main type of safeguard |
|---|---|---|---|---|
| Cloud infrastructure (hosting, authentication, DB, storage, logs, content delivery) | The primary processing location is in Japan. Content delivery and delivery security are served through a global content delivery network from points near the user | Core infrastructure, storage, delivery, logs, authentication | Ongoing assurance of equivalent safeguards | DPA, BAA (where HIPAA applies) |
| AI inference platform (external LLM) | Japan (operated in a configuration that limits the execution of inference to regions within Japan) | LLM inference for the AI assistant. Original binaries are not sent; limited to text and numeric series | Ongoing assurance of equivalent safeguards | DPA, SCC, UK IDTA, Swiss Addendum, and the cloud infrastructure provider's subprocessor chain. Managed as a cross-border transfer because the provider is a third party located in a foreign country |
| Video analysis processing | Processed in multiple countries/regions (the United States, Canada, the EU, the Asia-Pacific area, etc.), so health-related data may be processed outside Japan | Video analysis processing. Videos, physical attributes, skeletal data, and analysis results technically pass through. Patient-identifier exclusion and temporary processing environments apply | Ongoing assurance of equivalent safeguards | BAA, DPA, SCC, UK IDTA, Swiss Addendum, TOMs |
| Web analytics and data warehouse | Web analytics in the provider's processing environment (United States); the data warehouse is in Japan | Web analytics, advertising operations analysis, and export to the data warehouse. The transmitted identifier is treated as a pseudonymous identifier | Ongoing assurance of equivalent safeguards | DPA, SCC (including UK and Swiss supplementary clauses) |
| Error monitoring | EU (data stored in the provider's EU region). The provider is located in the United States | Error and performance monitoring for the application and API, and recording of on-screen activity before and after an error occurs. Technical information at the time of an error, account identifiers, and IP addresses are handled | Ongoing assurance of equivalent safeguards | Vendor DPA, SCC |
| Consent management | EU (consent records stored and processed in Ireland and the Netherlands). Banner delivery and edge processing involve a US CDN provider as the vendor's own subprocessor | Display of the cookie consent banner on the Service's web application and retention of consent records. Consent state, consent record identifier, consent timestamp, IP address, browser information, URL visited and coarse location are handled; no health-related data, video, images or numeric series are sent | Outside the scope of Art.28 (the recipient is located in the EU, a country designated by the rules under that Article) | Vendor DPA (processing within the EU/EEA, prior authorisation of subprocessors with notice of changes, SCC where a transfer outside the EEA occurs). Supervision of the entrusted party under APPI Art.25 |
| Advertising measurement | United States | Web beacon/pixel and conversion-measurement-type advertising measurement. Health-related data, video, images, and numeric series are not sent, but because cookies, IP addresses, browser identifiers, and hashed contact identifiers are received, we do not assert non-contact with personal information | Data subject consent | Each provider's data protection terms, SCC |
| Payment processing | Ireland or the United States (depending on the contracting entity) | Payment processing. Card information is held by the payment provider; the Service handles only payment status | Ongoing assurance of equivalent safeguards | DPA, SCC, PCI-DSS AOC |
| Customer support | United States | Support tickets. PHI and patient identifiers are not included in the ticket subject or body | Ongoing assurance of equivalent safeguards | DPA |
| Document sharing (file exchange and case storage) | United States (including global processing) | Exchange and per-case storage of video and analysis-related files. Deleted within 30 days by default, extended only for the period necessary when a case continues. PHI of HIPAA Covered Entity customers is received and stored only via storage paths covered by a HIPAA BAA, and is not stored on a document-sharing platform that is not covered by a BAA | Ongoing assurance of equivalent safeguards | DPA, SCC |
| Knowledge management (internal knowledge and operational memos) | United States (including global processing) | Internal knowledge and operational memos. Kept separate from the PHI storage locations covered by a BAA (document sharing and cloud infrastructure) and not used as a PHI storage location. If health-related data or patient identifiers are inadvertently included, they are removed or moved to an appropriate path | Ongoing assurance of equivalent safeguards | DPA, SCC |
| Development, maintenance, and operations subcontracting | Philippines | Development, maintenance, security operations, and incident response. Depending on the task, may involve access to ePHI or health-related data | Ongoing assurance of equivalent safeguards | Services agreement (provisions corresponding to APPI Art.25, GDPR Art.28, and, where HIPAA applies, a Subcontractor BAA), SCC (for transfers of personal data originating in the EEA). Information on the Philippine data protection regime (Data Privacy Act of 2012 (RA 10173) / National Privacy Commission) is provided on request |
| Email delivery | Japan (a domestic provider; may involve overseas processing depending on the location of processing, backups, etc.) | Email delivery to customer contacts. Operated without sending patient identifiers or health-related data | Delivery by a domestic provider. Where processing, backups, etc. involve overseas processing, it is treated as a cross-border transfer | Services agreement, supervision of the entrusted party (APPI Art.25) |
Vendor contracts and safeguards
We confirm the contractual terms and safeguards required for each path according to the type of data, the nature of processing, and the possibility of contact with health-related data or direct identifiers.
For paths that handle health-related data, payment data, or payloads containing direct identifiers (cloud infrastructure, AI inference, video analysis processing, payment, web analytics and data warehouse, customer support, advertising measurement, document sharing and knowledge management), we apply the necessary safeguards through a DPA, SCC (including the UK IDTA and Swiss Addendum), TOMs, and, for paths to which HIPAA applies, a BAA.
For the video analysis processing path, we minimize identifiers by combining a patient-identifier exclusion rule (not including direct identifiers such as patient names, patient IDs, or medical record IDs in file names or metadata) with temporary processing environments.
The AI inference platform (external LLM) is handled as a sub-service of the cloud infrastructure provider, under the cloud infrastructure provider's contracts (DPA, BAA, etc.). The text and numeric series sent from the AI assistant to the AI inference platform are classified as highly sensitive health-related data, so we do not assert non-contact with personal information for this path.
The individual company names and main countries/regions corresponding to each functional category are set out in the subprocessor list that ORGO publishes on its website.
Last updated: September 1, 2026
Revision history
| Date | Changes |
|---|---|
| September 1, 2026 | Initial publication |