Legal
Privacy Policy
Service: COMPASS Japan Gate
Operator: Rush bbit LLC (合同会社Rush bbit)
Effective Date: May 5, 2026
Last Updated: May 5, 2026
1. Introduction
Rush bbit LLC (“Rush bbit,” “we,” “our,” or “us”) operates the COMPASS Japan Gate service (the “Service”). We are committed to protecting the privacy and security of personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with the Service. It applies to all users of the Service, including business clients, their employees and representatives, and visitors to our website.
This Policy is designed to comply with:
- Japan's Act on the Protection of Personal Information (Act No. 57 of 2003, as amended; “APPI” / 個人情報保護法)
- The EU General Data Protection Regulation (Regulation (EU) 2016/679; “GDPR”), to the extent applicable
- Other applicable privacy laws
A Japanese-language summary of this policy is available upon request at ssakai@rushbbit.com.
2. Data Controller Information
Data Controller: Rush bbit LLC (合同会社Rush bbit)
Address: Dogenzaka 1-16-6, Futaba Building 8b, Shibuya-ku, Tokyo 150-0043, Japan
Privacy Contact: ssakai@rushbbit.com
Response Time: Within 10 business days of receipt
3. Information We Collect
3.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Business contact information | Name, job title, company name, business email | Service delivery, account management, communications |
| Billing information | Name, billing address, payment method (processed via Stripe — we do not store card numbers) | Payment processing |
| Service communications | Messages, inquiries, feedback | Service delivery, support |
| Campaign brief data | Target market information, ICP definitions, product descriptions | Campaign design and execution |
3.2 Information Collected Automatically
When you visit our website, we may collect usage data (pages visited, time spent), device information (IP address, browser type), and analytics data via Vercel Analytics. Vercel Analytics is privacy-focused and does not use cookies or store personally identifiable information.
3.3 Information About Outreach Campaign Targets
In providing the Service, Rush bbit processes business contact information of prospective Japanese companies on behalf of our clients. This data consists of company name, address, department, job function, business email addresses, and phone numbers sourced from publicly available business registries and company websites. We do not collect sensitive personal data (要配慮個人情報) about outreach targets.
4. How We Use Your Information
4.1 Service Delivery
- Executing Japan market entry campaigns on behalf of clients
- Providing reports, analysis, and recommendations
- Communicating about campaign status and results
4.2 Business Operations
- Processing payments and managing billing
- Managing client accounts and relationships
- Responding to inquiries and providing support
- Improving the Service based on usage patterns and feedback
4.3 Legal Bases for Processing (GDPR Art. 6)
Where GDPR applies, we rely on the following legal bases:
- Legitimate Interest (Art. 6(1)(f)): B2B outreach and business development activities — balanced against your rights and interests. You may object to processing on this basis at any time (see Section 8).
- Contract (Art. 6(1)(b)): Processing necessary for the performance of our service agreement with you.
- Legal Obligation (Art. 6(1)(c)): Compliance with applicable Japanese legal requirements.
- Consent (Art. 6(1)(a)): Where we have obtained your consent (e.g., marketing emails). You may withdraw consent at any time by emailing ssakai@rushbbit.com.
5. Disclosure to Third Parties
Rush bbit does not sell personal information. We may share data with the following categories of service providers under data processing agreements:
| Provider Category | Purpose | Examples |
|---|---|---|
| Payment processing | Billing and payment | Stripe, Inc. (USA) |
| Cloud infrastructure | Hosting and storage | Vercel, Inc. (USA) |
| Analytics | Service usage analysis | Vercel Analytics (privacy-focused, no cookies) |
| Email / communication | Client communications | Standard email providers |
We may also disclose personal information if required by applicable law, regulation, or governmental request.
6. International Data Transfers
Rush bbit is headquartered in Japan. Personal data is processed and stored primarily in Japan and the United States (via Vercel infrastructure).
EU/EEA to Japan transfers: Japan has received an EU adequacy decision (European Commission, January 2019), enabling free data flows between the EU and Japan for personal data covered by APPI. Where the adequacy decision does not apply, we rely on Standard Contractual Clauses (EU Commission Decision 2021/914).
Japan to USA transfers (Vercel/Stripe): These providers maintain appropriate data protection safeguards (SCCs for EU data).
7. Data Retention
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Client account data | Contract duration + 7 years | Japanese commercial law / tax records |
| Campaign data and reports | Contract duration + 3 years | 特定電子メール法 (Act on Regulation of Transmission of Specific Electronic Mail) compliance |
| Contact form inquiries | 3 years from submission | Legitimate interest / business records |
| Payment records | 7 years | Japanese tax law (国税通則法) |
| Website analytics | 26 months | Industry standard |
After the applicable retention period, personal information is securely deleted or anonymized.
8. Your Rights
8.1 Rights Under APPI (Japanese Residents)
- Access (開示, Art. 33): Request disclosure of personal information held about you
- Correction (訂正, Art. 34): Request correction of inaccurate information
- Deletion (利用停止・消去, Art. 35): Request cessation of use or deletion
- Opt-out of Third-Party Disclosure: Request cessation of provision to third parties (Art. 35)
8.2 Rights Under GDPR (EU/EEA/UK Data Subjects)
- Access (Art. 15): Obtain a copy of your personal data
- Rectification (Art. 16): Correct inaccurate personal data
- Erasure (Art. 17): Request deletion (“right to be forgotten”)
- Object (Art. 21): Object to processing based on legitimate interests
- Portability (Art. 20): Receive your data in a structured, machine-readable format
- Restrict Processing (Art. 18): Request restriction of processing in certain circumstances
8.3 How to Exercise Your Rights
Submit requests to: ssakai@rushbbit.com
We will respond within 10 business days (APPI) or one month (GDPR, extendable to 3 months for complex requests). We may require identity verification before processing requests.
8.4 Right to Lodge a Complaint
- Japan: Personal Information Protection Commission (PPC): www.ppc.go.jp
- EU/EEA: Your local data protection authority
- UK: Information Commissioner's Office (ICO): ico.org.uk
9. Security Measures
Rush bbit implements appropriate technical and organizational security measures, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest
- Access controls limiting data access to authorized personnel only
- Regular security assessments and monitoring
- Incident response procedures for data breaches
10. Cookie Policy
This website uses Vercel Analytics for understanding visitor traffic. Vercel Analytics is designed to be privacy-compliant: it does not use cookies and does not store personally identifiable information. No additional cookie consent mechanism is required for this tool.
If you use contact forms on this site, session-level functional data may be processed to deliver your inquiry. This data is not used for advertising or profiling.
11. Children's Privacy
The Service is intended for business users only and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a new “Last Updated” date and, for clients, by sending email notice to the address on file. Your continued use of the Service after the effective date constitutes acceptance of the updated terms.
13. Contact Us
Rush bbit LLC (合同会社Rush bbit)
Attn: Privacy / 個人情報相談窓口
Dogenzaka 1-16-6, Futaba Building 8b, Shibuya-ku, Tokyo 150-0043, Japan
Email: ssakai@rushbbit.com
Response time: Within 10 business days of receipt
Annex A
Information for EEA / UK Data Subjects (GDPR Article 13 Notice)
This Annex provides information required by GDPR Article 13 for data subjects in the European Economic Area and United Kingdom whose data is collected via this website or our outreach activities.
- Identity and contact details of the Data Controller
- Rush bbit LLC (合同会社Rush bbit), Dogenzaka 1-16-6, Futaba Building 8b, Shibuya-ku, Tokyo 150-0043, Japan. Email: ssakai@rushbbit.com
- Purposes and legal basis of processing
- See Section 4. Primary legal basis: Legitimate Interest (Art. 6(1)(f)) for B2B outreach and business development. Contract (Art. 6(1)(b)) for service delivery. Legal Obligation (Art. 6(1)(c)) for compliance.
- Legitimate interests pursued
- Service delivery, fraud prevention, security, service improvement, and business development through B2B outreach to companies whose contact information is publicly available.
- Recipients of personal data
- See Section 5. Key processors: Stripe (payments), Vercel (hosting/analytics).
- Transfers to third countries
- See Section 6. Japan has an EU adequacy decision. US transfers (Vercel, Stripe) are covered by SCCs.
- Retention periods
- See Section 7. Contact inquiry data: 3 years. Campaign data: contract + 3 years.
- Data subject rights
- You have the right to access, rectification, erasure, objection, and portability. See Section 8.2 for details.
- Right to lodge a complaint
- You may lodge a complaint with your local EU/EEA supervisory authority or the UK ICO.
- Right to withdraw consent
- Where processing is based on consent, you may withdraw at any time by emailing ssakai@rushbbit.com. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Automated decision-making
- Rush bbit does not use solely automated decision-making (including profiling) that produces legal or similarly significant effects on you.