Legal
Privacy policy
Enacted: 8 October 2026Version: 2026-10-08
This English text is a reference translation. The Japanese version is the binding one and prevails if the two differ. 日本語版
Contents
- 1. Who we are
- 2. Who this policy covers
- 3. What we collect
- 4. Why we use it
- 5. Disclosure to third parties
- 6. Processors
- 7. Visitors to your site
- 8. Transfers to and handling in other countries
- 9. Security measures
- 10. How long we keep it
- 11. Your requests
- 12. Cookies and similar
- 13. Minors
- 14. Changes to this policy
- 15. Contact
株式会社Bekito (“we”, “us”) handles personal information entrusted to us through Hanasite (the “Service”), our website builder, under Japan's Act on the Protection of Personal Information (APPI) and related laws and guidelines. This policy explains what we handle, why, where and how.
1. Who we are#
- Name
- 株式会社Bekito
- Address
- 〒170-0013 東京都豊島区東池袋2丁目62番8号 BIGオフィスプラザ池袋1206
- Representative
- 代表取締役 伊藤 秀明
- Privacy contact
- Loading…
The Service was developed by Masterbek LLC (Tashkent, Republic of Uzbekistan; the “Operator”), to which we have entrusted its development and operation (section 6). We are responsible for your personal information 【To be confirmed:roles to be confirmed (we as the business handling personal information, the Operator as our processor)】.
2. Who this policy covers#
- Customers of the Service (account holders, including people on the free trial)
- Visitors to the Service's website (https://hanasite.bekito.co.jp) and people who contact us
Personal information of visitors to sites you build with the Service (for example messages sent through a site's form) is the responsibility of the customer who runs that site; we handle it on their behalf (section 7).
3. What we collect#
We collect the following, as far as needed to provide the Service.
| Type | What | How |
|---|---|---|
| Account | Name (optional), e-mail address, phone number (optional), password (stored only as a one-way hash, never the password itself), display language, notification settings, the version of the terms you accepted and when | You register |
| LINE (only if you link LINE) | LINE user ID, display name, profile picture URL, LINE language, whether you added or blocked us, and the messages, photos, videos, files and voice messages you send on LINE | LINE Login, chatting with our LINE Official Account |
| Business and site | Shop name, address, phone, opening hours, prices, menu, services and other things to show on your site; public information read from URLs you give us (such as your old site) | You enter, say or point us to it |
| Conversations | Text messages you send in the Studio or on LINE and your conversations with the AI | You enter them |
| Voice | See “Voice” below | You record or talk |
| Uploaded files | Photos, logos, PDFs, Word/Excel/PowerPoint files, videos, audio and what the AI read from them (summaries, extracted text …) | You upload them |
| Your sites | Texts, images, code, change history and thumbnails of your sites | Created in the Service |
| Form messages | What site visitors send through your site's forms (section 7) | Site visitors send them |
| Payments | Order number, amount, plan, payment date and status, the payment provider's transaction and customer IDs, receipt contents. We may receive the card brand, last four digits and expiry date from the payment provider to show them to you 【To be confirmed:whether card details are received】 | Payment provider; your order |
| Usage | Sites you created, actions you took, credits used, AI processing costs | Using the Service |
| Technical | IP address, browser and device type, access times, error records | Accessing the Service |
| Where you came from | Ad or referral parameters of your first visit (utm, ref, promo), the first page, referrer and time of the first visit; linked to your account when you create it | Browser storage (section 12) |
| Analytics | Pages viewed, referrer, browser/device type, country | Umami analytics (section 12) |
| Support | Exchanges with the AI and staff, what you asked and how it was handled | You contact support |
| E-mail enquiries | E-mail address, name, the content of your enquiry | Your e-mail |
Card numbers: you enter them directly on the payment provider's page or in the input field it provides. They never pass through our servers and we do not store them.
Automatic masking of secrets: if a message seems to contain a password, API key, card number or the like, we store that part masked and do not send it to the AI. Enter keys your site needs in the dedicated secure form (values are stored encrypted).
Voice
| Use | Audio | What we keep |
|---|---|---|
| Voice conversation in the Studio (real time) | Streamed in real time to OpenAI's voice AI. We do not store the audio. | The transcript |
| Voice notes recorded and sent in the Studio | Stored as an uploaded file. | The recording and its transcript |
| Voice messages sent on LINE | Fetched from LINE for transcription and deleted after it. | The transcript |
4. Why we use it#
- To create your account, verify you and let you log in
- To create, change, publish and host sites and provide the AI features
- To charge, take payments, refund, issue receipts, and for accounting and tax
- To send notices about the Service (form messages, finished work, upcoming payments and renewals, upcoming data deletion, important changes …) by e-mail or LINE
- To provide support by the AI and staff
- To prevent abuse, keep the Service secure, and investigate and fix faults
- To deal with breaches of the terms and to comply with the law
- To improve the Service and plan new features (analysed as statistics that identify no one)
- To learn which ads or referrals brought you to the Service
- With your consent, to e-mail you about new features and campaigns
We do not use your content or conversations to train AI models, and we do not sell personal information or give it to third parties for advertising.
5. Disclosure to third parties#
We do not give personal information to third parties without your consent, except:
- where the law requires it
- where it is needed to protect someone's life, body or property and your consent is hard to obtain
- where we must cooperate with public authorities carrying out duties set by law and asking for consent would hinder them
- in other cases the APPI allows
Entrusting work to processors (section 6) and the transfer of a business by merger or the like are not “disclosure to third parties”.
6. Processors#
We entrust the handling of personal information to the following companies, as far as needed to provide the Service. The Operator, Masterbek LLC, runs the Service and uses the companies below for that work (sub-processing).
| Company | Country (storage/processing) | Work | Main information |
|---|---|---|---|
| Masterbek LLC | Uzbekistan | Developing, running and maintaining the Service, incident response, support | Everything the Service handles; staff look only at what operations and support need |
| Hetzner Online GmbH | Germany (company), 【To be confirmed:server location (planned: Finland)】 | Servers, database, files and backups | Everything the Service handles (storage only) |
| OpenAI 【To be confirmed:contracting entity】 | United States | AI conversations, creating and changing sites, reading files and images, transcription, voice conversations, image generation, AI support | Conversations, audio, uploaded files, business and site information, form messages when you ask the AI about them |
| Anthropic 【To be confirmed:contracting entity】 | United States | Creating and changing sites with AI | Build instructions, business and site information, recent conversation, files used on the site, the site's code |
| GitHub, Inc. | United States | Storing site code (private repositories) | Your sites' texts, images and code |
| Cloudflare, Inc. | United States (relays traffic through locations worldwide) | DNS, relaying and protecting traffic to the Service | Traffic content (while relayed), IP addresses |
| Purelymail 【To be confirmed:company's legal name】 | United States | Sending e-mail | E-mail addresses and notice contents (including form-message notices and data-download links) |
| LY Corporation (LINEヤフー株式会社) | Japan | LINE chats, LINE Login, LINE notifications (only if you link LINE) | LINE user ID, message contents |
| 【To be confirmed:payment provider to be confirmed】 | Japan | Card payments | Order number, amount and what the payment needs 【To be confirmed:data sent for 3-D Secure】 |
We sign contracts on the handling of personal information with our processors and supervise them, including checking their safeguards 【To be confirmed:data processing agreement between us and the Operator to be signed】.
Notices to our operators (sign-ups, payments, incidents …) do not contain customers' e-mail addresses, phone numbers, names or messages.
External services you use directly, such as the LINE app or a payment provider's payment page, handle information under their own privacy policies.
7. Visitors to your site#
- For information sent through the forms of a site you built with the Service (names, phone numbers, e-mail addresses, messages …), the customer running the site is responsible under the APPI.
- We handle it on your behalf only to:
- store it and show it in your inbox
- notify you of new messages by e-mail or LINE (on LINE only a summary and a link to the inbox, not the full text by default)
- send it to the AI when you ask the AI about it
- detect spam and file it as spam
- You can delete messages in your inbox at any time (one by one, several at once, or all spam). Deleted messages cannot be restored. When you delete a site, its messages are deleted with it.
- Site visitors with questions about their own information should first contact the business running the site. If they cannot reach it, they can contact us and we will pass the request on.
- We count visits to your site for you with Umami analytics, without cookies and without identifying visitors (section 12).
- Your site may load external services such as maps (Google Maps) or web fonts (Google Fonts); visitors' browsers then connect to those companies directly. See Cookies and analytics.
Sample text for your site
You can put something like this in your site's privacy policy (replace the parts in brackets):
[Shop name] uses the name, contact details and message you send through the contact form only to answer you. This site and its form run on the website builder Hanasite (operated by 株式会社Bekito); what you send is stored and processed on that service's servers. The service entrusts part of its operation to companies in Uzbekistan, the United States and other countries (see its privacy policy). This site counts visits with an analytics tool that uses no cookies, and may load Google services to show maps and fonts. To request disclosure, correction or deletion of your information, contact [contact details].
8. Transfers to and handling in other countries#
The Service stores and processes personal information outside Japan. During the current test and trial phase its servers are outside Japan 【To be confirmed:server location (planned: Finland)】; we plan to move them to Japan and will update this policy when we do.
Countries involved
| Country | Company | What |
|---|---|---|
| 【To be confirmed:server location (planned: Finland, EU)】 | Hetzner Online GmbH | Where the servers are (database, files, backups) |
| Germany (EU) | Hetzner Online GmbH | Where the hosting company is based |
| United States | OpenAI, Anthropic, GitHub, Cloudflare, Purelymail | AI processing, storing site code, relaying traffic, sending e-mail |
| Republic of Uzbekistan | Masterbek LLC | Running the Service; staff access it from Uzbekistan for operations and support |
How we transfer
When we provide personal data to a third party abroad, we first make sure, by contract or otherwise, that the recipient has measures in place consistent with the obligations of the APPI (APPI Article 28(1), Enforcement Rules Article 16). We regularly check how the recipient handles the data and how the laws of its country affect it, act on problems, and stop the transfer if a problem cannot be solved.
On request we tell you the information the law requires about the recipients' measures (contact the address in section 15).
Data protection laws of those countries
- European Union (Finland, Germany): the General Data Protection Regulation (GDPR) applies. Japan's Personal Information Protection Commission recognises the EU as having a level of protection equivalent to Japan's.
- United States: there is no comprehensive federal privacy law; there are sector-specific federal laws and state laws (such as the California Consumer Privacy Act). Government agencies can require companies to provide information for national security and other purposes.
- Republic of Uzbekistan: the Law on Personal Data (No. ZRU-547 of 2 July 2019) covers processing based on consent, processing within its purpose, security measures and the rights of data subjects. It requires the personal data of Uzbek citizens to be stored on servers in Uzbekistan; we consider that this does not apply to our Japanese customers' information.
9. Security measures#
We take the following measures against leaks, loss and damage of personal information. See also Security.
Policy and rules
- We have this policy and internal rules on how personal information is handled 【To be confirmed:internal rules to be written】.
Organisational measures
- We appoint a person responsible for personal information and define the staff and permissions at our company and the Operator 【To be confirmed:responsible person and staff to be named】.
- We have a procedure for reporting and handling leaks or suspected leaks 【To be confirmed:procedure to be written】.
- Leaks that meet the legal criteria are reported to the Personal Information Protection Commission and the people affected are notified.
Human measures
- Staff handling personal information sign a confidentiality pledge and are trained 【To be confirmed:pledges and training to be done】.
Physical measures
- Servers are in the data centre of Hetzner Online GmbH; there are none in our or the Operator's offices.
- We protect devices that handle personal information against loss and theft 【To be confirmed:device encryption and screen-lock practice】.
Technical measures
- All traffic to the Service is encrypted (TLS).
- Passwords are stored only as one-way hashes. Login links that open the Studio from LINE expire quickly and work only once.
- Secrets set for your site are stored encrypted in the database; secrets in messages are masked before they reach the AI.
- Access to the admin and the servers is limited 【To be confirmed:list of people with access; two-factor authentication for the admin】.
- Servers have a firewall allowing only the traffic needed and block repeated failed logins; security updates are applied automatically.
- The AI builds sites in an isolated environment that cannot reach other customers' data or the Service's keys.
- Previews of sites being built open only on an address with a random string unique to the site and are set not to be indexed by search engines. Anyone you share the address with can open it; Settings gives the preview a new address at any time, and the old one stops working.
- Logins, sign-ups, form submissions and the like are rate-limited.
- Database and files are backed up daily, and backups are deleted after at most 30 days.
Understanding the environment abroad
- Personal information is stored and processed in the countries in section 8; we take the measures in section 8 knowing their data protection laws.
10. How long we keep it#
We keep personal information only as long as its purpose requires and delete it without delay when it is no longer needed (APPI Article 22). Transaction records the law requires us to keep are kept for that period.
- Account, conversations, uploaded files (voice notes included), sites, form messages, support records, LINE link
- While your contract runs. When you delete your account, your sites go offline at once and the data is deleted within 30 days.
- Free-trial data
- Publishing stops when the trial ends; 30 days later everything is deleted, account included. We e-mail you 7 days before.
- Data after a paid period ends
- Your site is paused 7 days after the paid period ends; 30 days later everything is deleted, account included, except transaction records. We e-mail you 7 days before.
- Deleted sites
- Offline at once; deleted 30 days after you delete them.
- Site code repositories (GitHub)
- Deleted together with the site's data (not kept as an archive).
- Form messages
- Until you delete them in your inbox or delete the site (section 7).
- Data-download files
- Deleted 7 days after they are made; never included in backups.
- Backups
- At most 30 days; deleted data leaves the backups within 30 days.
- Payment and transaction records (orders, payments, receipts, refunds, final-confirmation screens, and the name and e-mail address they need)
- For the period the law requires (Corporation Tax Act, Electronic Books Maintenance Act, Consumption Tax Act: in principle 7 years, 10 years for years with losses carried forward). For a deleted account, the name and e-mail address are deleted 10 years after the account.
- Notices from the payment provider (payment status updates)
- We keep only what is needed to confirm a transaction (number, type, amount, status, time), never names or e-mail addresses. Notices not tied to an order are deleted after 90 days, or at once when the account is deleted; the notices of an order are kept as long as that transaction record.
- Technical records (access and error logs, processing history)
- At most 90 days
- Events received from LINE
- Contents cleared after processing; deleted after 14 days
11. Your requests#
You can ask us about the personal data we hold about you (retained personal data) for:
- notification of the purposes of use
- disclosure (including records of provision to third parties)
- correction, addition or deletion
- suspension of use or erasure
- stopping provision to third parties
What you can do yourself: under Account → “Data and account” you can download your data (site files, uploaded files, form messages, conversations) and delete your account at any time. You can change your name, e-mail address and notification settings on the account page.
How to make a request
- E-mail your request to Loading… — no LINE or AI support needed. By post, write to the address in section 1. A person always handles requests; the AI never decides or processes them.
- To confirm it is you, please write from your registered e-mail address. If you have no e-mail address registered (for example if you use only LINE), we verify you another way 【To be confirmed:verification method】.
- Agents must send documents showing their authority, such as a power of attorney.
- There is no fee 【To be confirmed:fee】.
- We respond without delay and tell you the result by e-mail (or in writing if you prefer). If we cannot comply, we tell you why.
13. Minors#
The Service is for people running a business. If you are under 18, use it with the consent of your parent or other legal guardian.
14. Changes to this policy#
We may revise this policy for changes in law or in the Service, and publish revisions on this page with the date. Important changes (new purposes, new recipients or countries abroad …) are announced beforehand by e-mail and in the Service; where the law requires your consent, we ask for it.
15. Contact#
Send questions, comments and complaints about how we handle personal information to:
- Desk
- 株式会社Bekito, Hanasite privacy desk
- Loading…
- Address
- 〒170-0013 東京都豊島区東池袋2丁目62番8号 BIGオフィスプラザ池袋1206
We are not a member of an accredited personal information protection organisation.
Enacted: 8 October 2026