Privacy Notice
Last updatedSeptember 1, 2026
1. Identity of the controller
ORGO Inc. ("ORGO," "we," or "us") provides the movement analysis service "MYoACT" (the "Service"). This Privacy Notice (the "Notice") describes how we handle personal information and health-related data in the Service.
Where an account registration screen or any other screen of the Service displays a request for your "consent" to this Notice, that display means that you confirm the contents of this Notice. For processing that requires consent under applicable law, we obtain separate, specific consent on the relevant screen or in the relevant procedure.
- Name: ORGO Inc.
- Address: 2F Aji Estate Odori-Nishi Plaza, 18-2-7 Odori-Nishi, Chuo-ku, Sapporo, Hokkaido 060-0042, Japan
- Representative: Ryo Ueno, Representative Director
- Contact point for inquiries and requests: support@myoact.com (please send questions about this Notice, requests that require identity verification, complaints, and other inquiries through the Service screens or to that contact point).
- Security measures: We implement technical and organisational security measures including encryption at rest and in transit, encryption key management, access permission management (least privilege, role-based access control, multi-factor authentication, and individually assigned accounts), audit logging, tenant separation, backup and recovery, vulnerability management, workforce training and confidentiality obligations, vendor management, management of data location, and incident response procedures. The details of these measures are set out in the technical and organisational measures (TOMs) annexed to our customer contracts. For specific measures whose public disclosure may impair security, we will respond within a reasonable scope upon request from the data subject.
- Procedures for disclosure and other requests: Requests for disclosure, correction, addition, deletion, suspension of use, suspension of third-party provision, and similar rights are accepted through the Service screens or at our contact point (support@myoact.com). The request method, identity verification documents, procedure for requests made through a representative, whether a fee applies, the response method, and the standard response period follow our designated request procedure. We provide information about that procedure on our website and through the contact point.
2. Scope and applicable laws
This Notice applies to the handling of personal information and health-related data in the Service. The main abbreviations and applicable laws used in this Notice are as follows. The application of each law depends on the location of the user (a person issued an account for the Service; the same applies below) or customer organization, the type of data, and the context of processing.
- APPI (Act on the Protection of Personal Information; Japan): applies to users in Japan and to processing subject to Japanese law.
- GDPR (General Data Protection Regulation; EU): may apply to processing relating to data subjects located in the European Economic Area (EEA). In this Notice, the individuals who exercise rights, including "data subjects" under the GDPR and the UK GDPR, are collectively referred to as data subjects.
- UK GDPR / DPA 2018 (UK General Data Protection Regulation and Data Protection Act 2018): may apply to processing relating to data subjects located in the United Kingdom. The supervisory authority in the UK is the Information Commissioner's Office (ICO). References in this Notice to the GDPR apply, for data subjects located in the UK, as references to the UK GDPR and the DPA 2018.
- Privacy Act 1988 / APPs (Privacy Act 1988 (Cth) and the Australian Privacy Principles): may apply to processing relating to individuals located in Australia, or in relation to customer organizations established in Australia (healthcare institutions, research institutions, sports businesses, and the like). The supervisory authority in Australia is the OAIC (Office of the Australian Information Commissioner).
- HIPAA (Health Insurance Portability and Accountability Act; United States): may apply in relation to customers that are U.S. Covered Entities or their Business Associates. ORGO acts as a Business Associate in relation to such customers, and this Notice is not a Notice of Privacy Practices (NPP) that a Covered Entity issues to patients.
- CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act): may apply to processing relating to California consumers.
- COPPA (Children's Online Privacy Protection Act; United States): may apply where personal information of children under 13 is handled in the United States.
These applications are conditional on the location of the customer or subject and similar factors. Listing these laws in this Notice does not mean that all rights under all laws uniformly arise for every user. The specific handling by jurisdiction follows the relevant sections of this Notice.
The Service is provided in the form of use through a customer organization: a healthcare institution, research institution, educational institution, sports business, general company, or other customer organization (including a sole proprietor using the Service for business) deploys the Service and selects the subjects to be analyzed. In this case, that customer organization is the controller (personal information handling business operator) and we process the data as its entrusted service provider. Processing that we carry out as an independent controller is described in "4.2 Our role."
3. Categories of data processed
We process the following health-related data to the extent necessary to achieve the purposes of use of the Service.
- Raw video: Recorded video files, which may contain faces, voices, and surrounding information.
- Skeletal and pose data: Skeletal coordinates, joint angles, and other derived data generated from movement analysis.
- Analysis results: Scores, reports, evaluation values, and other internal metrics derived from analysis. The scope disclosed to users is determined under our standards, and internal analysis parameters are in principle not included in what is disclosed.
- Physical attributes: Height, weight, age, sex, and other information necessary for analysis or display.
- Linked metadata: Recording date and time, device information, Service account identifier (MYoACT account ID), organization identifier (organization ID), analysis identifier (analysis ID), information about the purpose of use, and similar metadata.
In medical and rehabilitation, research, training, worker load measurement, and similar contexts, these data may constitute personal information or special care-required personal information under the APPI, health data or special category data under the GDPR, or protected health information (PHI) under HIPAA. We therefore handle them with a high level of protection.
4. Purposes of processing
We use data in the Service for the following purposes.
- Performing movement analysis, managing analysis jobs, and checking analysis quality.
- Providing analysis results, reports, dashboards, and related support.
- Responding to inquiries from customer organizations or users, investigating failures, monitoring security, and preventing misuse.
- Improving Service quality, evaluating analysis models, analyzing statistical usage trends, and improving features (collectively, "Service Improvement, etc.").
- Retaining records necessary under laws, contracts, audits, and security requirements.
- Sending notices about the Service, such as new features, updates, and campaigns, as well as advertising relating to ORGO's products and services. Such communications use only the contact information of customers and users, and do not use patient identifiers or health-related data. For marketing communications, we provide the opportunity to give prior consent or to opt out, in accordance with applicable law.
4.1 Special rule for use of health-related data for Service Improvement, etc.
For health-related data originating from a customer organization, we do not use such data as AI model training material, in externally published materials, case studies, or sales materials, for provision or sale to third parties, or for commercial statistics or other statistics provided to third parties, regardless of whether the data is identifiable, de-identified, anonymized, or statistically aggregated. Such use will be made only where there is separate explicit consent, a written contract, or a legal basis. Handling health-related data to monitor and evaluate the quality of the Service and to analyze failures, and creating statistical information consisting solely of aggregate figures from which no individual, subject, or customer organization can be identified or inferred and using it to maintain and improve the quality of the Service, are carried out as part of providing the Service.
However, business statistics that do not include any health-related data, such as the monthly number of active customers or the overall operating rate of the Service, are outside the scope of this special rule. Such business statistics are limited to aggregate figures from which no individual, subject, or customer organization can be identified or inferred, and publication of customer names and case studies requires the separate consent of the customer concerned. Data other than health-related data may be used for Service Improvement, etc. within the scope of the published purposes of use and applicable consent.
4.2 Our role
The Service is provided in the form of use through a customer organization, as set out in "2. Scope and applicable laws."
Where the Service is used through a customer organization and that customer determines the selection of subjects, the purpose of analysis, and how results are used in its operations, we generally conduct the analysis processing as the customer's entrusted service provider or processor (GDPR Art.28).
In addition, misuse detection, security monitoring, audit logs, retention of contractual evidence, and our own business statistics are treated as processing for which we are responsible as an independent controller.
5. Legal bases
Where the APPI applies, we process data based on the publication of purposes of use, consent given by the data subject or the customer organization, entrusted processing, processing necessary under law or contract, and the implementation of security control measures.
Where the GDPR applies, movement analysis and provision of analysis results are performed with the customer organization or similar customer acting as controller. We primarily process the data as processor under GDPR Art.28. For our own processing such as Service Improvement, security monitoring, audit logs, and business statistics, we apply the appropriate legal basis for each processing purpose, including consent, performance of a contract, legal obligation, legitimate interests, or an exception for special category data relating to medical care, research, or security management.
Where we process data as an independent controller, the legal bases are as follows for each processing purpose. Security monitoring, misuse prevention, and audit logs are based on legitimate interests under GDPR Art.6(1)(f), namely the security, integrity, and misuse prevention of the Service. Legal and audit responses are based on Art.6(1)(c). Contract management and support are based on Art.6(1)(b) or Art.6(1)(f). Analysis and improvement purposes for which explicit consent is obtained are based on Art.6(1)(a). Marketing communications such as notices and campaign emails are based on consent (Art.6(1)(a)) or legitimate interests (Art.6(1)(f)), and the data subject may opt out at any time. Where we independently process health-related data or other special category data, such processing is limited to GDPR Art.9(2)(a) (explicit consent), Art.9(2)(h) (medical care, etc.), Art.9(2)(j) (research, etc.), or another exception permitted under applicable law. For security monitoring and misuse prevention, legitimate interests under Art.6(1)(f) are the primary basis, and if special category data is included, we separately confirm an exception basis described above.
Where we do not collect data directly from the data subject, the data source is the customer organization, the user, or a service provider designated by them.
Where HIPAA applies in relation to a United States healthcare institution or similar customer, we act as a Business Associate and handle electronic protected health information (ePHI) under the instructions of the customer, which is the Covered Entity, the Business Associate Agreement (BAA), and the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
Where HIPAA applies, we use and disclose PHI/ePHI within the scope of the permitted purposes in accordance with the BAA and 45 CFR Parts 160 and 164, and we implement administrative, physical, and technical safeguards under the Security Rule. If a breach of PHI/ePHI or a security incident occurs, we will notify the customer Covered Entity in accordance with the BAA and the Breach Notification Rule, and cooperate with data subject responses, record provision, and regulatory responses.
If a breach, loss, damage, or other incident involving personal data occurs, we will, in accordance with the APPI, the GDPR, and other applicable laws, report to the supervisory authority (such as the Personal Information Protection Commission or an EU member-state supervisory authority) and notify the data subject to the extent necessary, or cooperate with such reporting and notification by the customer organization acting as controller.
6. Analytics
We use a web analytics service and a data warehouse to understand Service usage, improve quality and operations, and measure the effectiveness of advertising and user flows. We may send the Service account identifier (MYoACT account ID) to the web analytics service. Outside the Service, this identifier does not by itself directly identify an individual, but to the extent it may be matched with other information, it is handled as personal data or personal information.
The web analytics event data is retained in the analytics service, and the same event data is exported to the data warehouse and managed under our internal standards. The specific retention periods and deletion handling are as described in "14. Retention and deletion"; if a data subject or customer requests deletion, we identify the relevant scope and delete the applicable data.
7. AI assistant
The Service provides a text-based AI assistant feature. The AI assistant uses an external large language model (LLM) provided through the LLM inference platform we use. The specific model and provider name are set out in the subprocessor list that we publish on our website. We operate this inference in a configuration that limits the regions in which inference is executed to regions within Japan. However, because the provider of that inference platform is a third party in a foreign country, we continue to manage this path within the framework of APPI Article 28. The transfer bases and safeguards are as set out in the separately published cross-border transfer statement.
By design, the AI assistant receives only text entered by users, conversation context, analysis metadata such as analysis identifiers, dates, and chart labels, and numerical series such as skeletal coordinates and joint angles. The invocation path to the LLM inference platform is designed not to receive original video files, image files, analysis artifacts, original binary files, or user email addresses. In addition, data sent to the LLM inference platform is not used to train the platform provider's or the model provider's foundation models, and is not provided to third parties, in accordance with the inference platform provider's data protection policy.
The AI assistant path uses the LLM inference platform only and does not send data to other third-party AI services. For details on the content sent to the AI assistant, log retention operations, additional rules for medical-sector customers, and BAA application for HIPAA Covered Entity customers, please refer to the separately published AI assistant and third-party AI disclosure.
8. Vendors and subprocessors
We use vendors and subprocessors to the extent necessary to provide the Service. This Notice and the cross-border transfer statement describe the main functional categories, processing purposes, categories of data handled, transfer country or region categories, and safeguards. Individual vendor names, main countries and regions, and safeguards are set out in the subprocessor list that we publish on our website.
- Cloud infrastructure, authentication, database, storage, log monitoring, and delivery: cloud infrastructure platform. The main processing location is in Japan, but processing may occur at content delivery points near users or in other countries or regions due to the nature of delivery and security functions.
- AI assistant inference: AI inference platform. The data sent and the details of the processing location are as described in "7. AI assistant."
- Video analysis processing: video analysis processing platform. It may technically access videos, physical attributes, skeletal and pose data, and analysis results.
- Usage analytics, advertising and user-flow analysis, and data warehousing: web analytics and data warehouse platform. Specific handling is described in "6. Analytics."
- Error monitoring: error monitoring platform. It may handle technical information at the time of an error, account identifiers, and recordings of on-screen activity before and after an error occurs.
- Consent management: consent management platform (the cookie consent banner on the Service's web application). It handles consent state, consent record identifiers, consent timestamps, IP addresses, browser information, URLs visited, and coarse location. It does not handle health-related data. Consent records are stored and processed within the EU; banner delivery and edge processing involve a US delivery provider as that vendor's own subprocessor.
- Advertising measurement: advertising measurement platform (including web beacon / pixel and conversion-measurement-type advertising measurement technologies). It may handle cookies, IP addresses, browser identifiers, hashed contact identifiers, and other advertising measurement data. We do not send health-related data, video, images, or analysis numerical series to the advertising measurement platform. Opt-out under the CCPA/CPRA and similar laws is described in "13. Data subject rights."
- Payment processing: Payment service providers and similar providers. They handle payment amounts, billing information, payment identifiers, and similar data. Payment method information such as card numbers is generally processed by the payment provider.
- Customer support, sales response, and inquiry management: Support management services and similar providers. In support channels, our basic operation is not to include health-related data or patient identifiers in message bodies or attachments beyond the authorized scope.
- Email delivery: Email delivery services and similar providers. They may handle contact information for customer representatives and other contacts, and delivery history.
- Internal document sharing, knowledge management, and project management: internal document sharing and knowledge management platform. Where files containing health-related data are handled, they are managed according to designated channels, access permissions, and retention and deletion standards.
- Development, maintenance, security operations, and incident response support: Our contractors or sub-contractors may access the Service cloud environment from outside Japan.
For PHI of United States HIPAA Covered Entity customers, including video, we receive and store the PHI through cloud infrastructure storage paths covered by a Business Associate Agreement, and do not store it in generally available internal document sharing tools that are not covered by a HIPAA BAA.
We manage operations so that health-related data is not shared outside authorized paths, and we conduct vendor management including vendor selection, contracts, access permission management, audits or reviews, and other controls. With vendors, we use data processing agreements, Business Associate Agreements, standard contractual clauses, and other reasonably appropriate data processing terms according to the processing details and applicable laws.
Even if vendors or services are added, replaced, renamed, or otherwise changed, this Notice maintains a category-level explanation where the change does not materially affect the processing purposes, data categories, substance of cross-border processing, or exercise of data subject rights. Material changes are handled under "16. Updates to this notice."
9. Status of analysis results
Analysis results provided by the Service are reference values based on objective measurements of movement. They are not medical diagnoses, treatment recommendations, or substitutes for medical judgment. Final responsibility for diagnostic and treatment decisions rests with the responsible healthcare professional. The scope of analysis results disclosed to users is determined under our standards, and internal analysis parameters are in principle not included in what is disclosed.
We reflect cautions regarding analysis accuracy and displayed content in contracts, terms of use, the UI, and explanatory materials.
10. Exclusion of direct patient identifiers from file names, metadata, and similar fields
The Service's video analysis flow is designed on the assumption that information directly identifying a patient, such as patient names, case IDs, medical record IDs, insurance card numbers, dates of birth, and addresses, is not included in file names, metadata, or text attached to videos. Raw video itself may contain the face or voice of the recorded individual, but we handle such content with the high level of protection described in "3. Categories of data processed," and do not require it to be written in file names, metadata, or attached text.
Identification of patients and other subjects is managed in the customer organization's own systems. In the Service, analysis data is managed using organization identifiers and other identifiers that do not directly identify individuals. If direct identifiers are inadvertently included, we mask the information and, where necessary, evaluate the event under our breach and incident response procedures.
11. Minors and parental consent
Where the Service processes data relating to minors, responsibility for obtaining consent from a parent or legal representative generally rests with the customer organization or other service provider that deploys and operates the Service.
The customer organization represents and warrants to us that it has obtained consent from minors or legal representatives required under COPPA, GDPR Art.8, and the APPI before using the Service (the age at which consent is valid under GDPR Art.8 varies between 13 and 16 depending on member-state law). We state this allocation of responsibility in contracts and operational flows. Identifying minors is the responsibility of the customer organization or other party that deploys and operates the Service. For an individual whom such a party designates as a minor or as represented by a parent or legal representative, we do not use that individual's personal data for advertising or profiling purposes and do not include it in advertising audiences that we manage.
The Service is not provided as a general-audience service directed to children under 13. However, if we handle personal information of children under 13 as an operator under COPPA, we will clearly state online, before collecting the child's data, the types of information collected, purposes of use, disclosure recipients, method for obtaining parental consent, methods by which parents may review and delete the information and refuse future collection, and contact information. We will directly notify parents using a method permitted by COPPA and obtain verifiable parental consent. Where consent is obtained through a customer organization, we will confirm consent records and the handling of deletion requests through our contracts and operational flows, only to the extent such approach is permitted under applicable law.
12. Cross-border transfers
The Service uses vendors and subprocessors that may be located outside Japan or accessed from outside Japan for cloud infrastructure, AI inference, video analysis processing, usage analytics, advertising measurement, payment, support, email delivery, internal document sharing, knowledge management, development and maintenance, and other purposes. The transfer countries or country categories, vendor categories, transfer bases, and safeguards are set out in the separately published cross-border transfer statement.
For processing involving cross-border transfers, we use data processing agreements, Business Associate Agreements, standard contractual clauses, supplementary measures, and other reasonably appropriate safeguards according to applicable laws and the processing details. Vendor selection, management, and confirmation of subprocessors are conducted on an ongoing basis under our vendor management procedures.
12.1 Cross-border transfer statement
For the transfer countries, recipients or recipient categories, transfer bases, and methods of consent or information provision for cross-border transfers, please refer to the separately published cross-border transfer statement.
13. Data subject rights
Data subjects may exercise rights over their personal data under applicable law, including access, correction, addition, deletion, suspension of use, suspension of third-party provision, data portability, objection, withdrawal of consent, and other available rights.
- Under Japan's APPI, we respond to requests for disclosure, correction and similar actions, and suspension of use and similar actions under APPI Articles 33-35.
- Where the GDPR applies, we respond to rights under GDPR Art.15-Art.22, including access, rectification, erasure, restriction of processing, portability, objection, and rights relating to automated decision-making.
- Where the CCPA/CPRA applies, we provide notice of the categories of personal information and sensitive personal information collected, purposes of use, categories of disclosure recipients, whether personal information is sold or shared, and disclosures made during the preceding 12 months. Consumers may exercise the right to know, access, correct, delete, opt out of sale or sharing, limit the use and disclosure of sensitive personal information, and not receive discriminatory treatment for exercising rights. For sharing that may constitute cross-context behavioral advertising, a data subject may request to opt out of sale or sharing through the contact point set out in "15. Contact and complaints," in accordance with applicable law. We handle such requests in accordance with applicable law.
- Where the Privacy Act 1988 / APPs apply, individuals may request access to their personal information under APP 12 and correction under APP 13. We respond to such requests, or cooperate with the customer organization or similar customer that is the APP entity for the relevant processing. The complaint channel is as set out in "15. Contact and complaints."
Requests should be sent through the Service screens or to the contact point set out in "15. Contact and complaints." Where the customer organization is the controller, we cooperate with that customer to identify, export, correct, or delete the relevant data.
14. Retention and deletion
We set retention periods according to the type of data, storage location, purpose of use, and legal or contractual necessity. The retention of the main categories of data is as follows.
| Category of data | Retention |
|---|---|
| Raw video, skeletal and pose data, analysis results, physical attributes, and linked metadata | Retained while the contract or the account remains in effect, and deleted upon deletion of the analysis, deletion of the account, termination of the contract, or a deletion request. There is no automatic deletion on expiry of a retention period. Raw video is retained for display of analysis results and re-analysis; temporary copies in the analysis processing environment are deleted after processing is completed. |
| Temporary storage of video and other files containing health-related data (for delivery purposes) | Deleted within 30 days after receipt or sharing. Where retention is necessary due to case continuation or similar reasons, the period is extended only as long as necessary. |
| AI assistant conversations | Retained while the account remains in effect, and deleted upon deletion of the account or a deletion request. |
| Application and infrastructure runtime logs | Retained only for the period necessary for failure analysis and incident investigation, and deleted within a short period in line with the data minimization principle. |
| Audit logs | Retained for the period necessary as legal retention obligations (including the six-year requirement under U.S. HIPAA 45 CFR §164.316(b)(2)), and as audit and security evidence. |
| Web analytics events | Retained in the analytics service for 2 months. |
| Raw web analytics events exported to the data warehouse | Retained without an expiration setting; where a request for disclosure or a similar right is made, the applicable scope is identified and the data is deleted. |
| Support records | Retained after the support case is completed, for the period necessary as evidence for contractual, incident response, or dispute handling purposes. |
Where deletion becomes necessary as a result of a deletion request, termination of the contract, or deletion of the account, we delete the target data from accessible production resources (including databases, storage, caches, search indexes, and derived data).
For backups, we generally rely on natural deletion through completion of backup rotation rather than immediate record-by-record deletion, and complete this within 90 days of receiving the deletion request. Where target data is contained in a long-term snapshot created separately for disaster recovery or similar purposes, we delete that snapshot or delete the target data individually. Where retention is necessary for legal retention obligations, audits, incident response, or dispute handling, we may continue to retain the data to the extent necessary.
15. Contact and complaints
For questions about this Notice, data processing, the exercise of data subject rights, deletion requests, or complaints, please contact us through the Service screens or at our contact point (support@myoact.com). Where identity verification is required, we or the customer organization will verify identity to the extent necessary.
When we receive a complaint about the handling of personal data, we acknowledge receipt of the complaint, investigate it, and inform the complainant of the outcome without undue delay. For individuals located in the United Kingdom, we acknowledge receipt of the complaint within 30 days of receipt in accordance with the UK GDPR / DPA 2018 (as amended by the Data (Use and Access) Act 2025).
Users may lodge complaints with the Personal Information Protection Commission in Japan, an EU supervisory authority, the ICO (Information Commissioner's Office) in the United Kingdom, a United States state authority, the OAIC (Office of the Australian Information Commissioner) in Australia, or another competent authority under applicable law. For processing where a customer organization is the controller, users should also contact that customer organization.
16. Updates to this notice
We may update this Notice when the service, vendors, data processing, applicable laws, or operating policies change. If a material change is made, we will notify users through the Service, our website, contractual notices, or another appropriate method.
Last updated: September 1, 2026
Revision history
| Date | Changes |
|---|---|
| September 1, 2026 | Initial publication |