Data Processing Addendum (DPA)
This revised Data Processing Addendum will take effect on October 16, 2026 (JST).
1. Definitions and Scope
- 1.1“Applicable Data Protection Law” means data-protection or privacy law that applies to the processing of Customer Personal Data under this DPA, including Japan’s Act on the Protection of Personal Information (APPI) and applicable U.S. state privacy laws, in each case only to the extent applicable.
- 1.2“Customer Content” means User Content as defined in the Terms, together with other content, data, or information submitted, stored, transmitted, or processed through the Service by or on behalf of Customer or its Users in connection with the applicable Team.
- 1.3“Customer Personal Data” means Personal Information contained in Customer Content that Company processes on behalf of Customer in providing the Service. It does not include information that Company processes for its own independent purposes, such as account administration, contracting, billing, fraud and abuse prevention, security, legal compliance, or protection of Company’s rights, to the extent Company determines the purposes and means of that processing.
- 1.4“Personal Information” means personal information, personal data, or comparable information protected by Applicable Data Protection Law.
- 1.5“Subprocessor” means a third party engaged by Company to process Customer Personal Data on behalf of Company in providing the Service.
- 1.6Capitalized terms not defined in this DPA have the meanings given in the Terms.
- 1.7This DPA applies only to processing for which Company acts as a processor, service provider, contractor, or equivalent role on behalf of Customer. Company’s independent processing is governed by the MONJI Privacy Policy and Applicable Data Protection Law, not by the processor obligations in this DPA.
2. Processing Instructions and Restrictions
- 2.1Company will process Customer Personal Data only to provide, operate, maintain, secure, and support the Service; to comply with documented instructions from Customer; and as otherwise permitted or required by Applicable Data Protection Law.
- 2.2Documented instructions include the Terms, this DPA, Customer’s configuration and authorized use of the Service, instructions submitted through the Service, and other written or electronic instructions accepted by Company.
- 2.3To the extent required by Applicable Data Protection Law for Company to qualify as a processor, service provider, contractor, or equivalent role, Company will not sell or share Customer Personal Data for cross-context behavioral advertising, retain, use, or disclose Customer Personal Data outside the specified business purposes and direct business relationship except as permitted by law, or combine Customer Personal Data with personal information received from another person or collected from Company’s own interactions with an individual except as permitted by law.
- 2.4To the extent required by Applicable Data Protection Law for Company to qualify as a processor, service provider, contractor, or equivalent role, Company will notify Customer if Company determines that it can no longer meet the obligations that such law directly requires Company to meet in that role.
- 2.5To the extent required by Applicable Data Protection Law, Customer may, upon reasonable notice, take reasonable and appropriate steps to verify that Company processes Customer Personal Data consistently with Customer’s obligations under that law or to stop and remediate unauthorized use. Any such steps are subject to Article 10, must be proportionate to the legal requirement and risk, must protect Company and third-party security and confidentiality, and do not entitle Customer to direct system or facility access except where expressly required by law and not reasonably satisfiable by another means.
- 2.6If Company believes an instruction violates Applicable Data Protection Law, Company may suspend the affected processing and notify Customer where legally permitted.
3. Customer Responsibilities
- 3.1Customer determines the purposes for which Customer Personal Data is submitted to or processed through the Service and is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all required notices and obtaining all required rights, consents, approvals, and other legal bases.
- 3.2Customer must comply with the Terms, including the Restricted Regions provisions, and must not instruct Company to process data in a manner prohibited by the Terms, Restricted Regions List, or Applicable Data Protection Law.
- 3.3Customer is responsible for configuring User permissions, AI Integration Features, and Customer-selected Third-Party Services in accordance with Customer’s legal and security obligations.
4. Security
- 4.1Company will implement and maintain technical and organizational measures appropriate to the nature of Customer Personal Data and the risks of processing, designed to protect Customer Personal Data against unauthorized or unlawful access, use, disclosure, alteration, loss, destruction, or damage.
- 4.2Such measures include, as appropriate, access controls, authentication and authorization controls, encryption in transit, logging and monitoring, personnel controls, incident response measures, and measures for secure use of service providers.
- 4.3Customer acknowledges that no system can be guaranteed to be completely secure and that security measures may evolve over time in response to changes in technology, risk, and the Service.
5. Subprocessors and Customer-Selected External Services
- 5.1Customer generally authorizes Company to engage Subprocessors as reasonably necessary to provide the Service.
- 5.2Company will select and oversee Subprocessors in accordance with Applicable Data Protection Law and, to the extent required by that law, will impose written data-protection obligations appropriate to the services they perform and the information they process.
- 5.3Current categories and principal providers used in operating the Service are described in the Privacy Policy or other materials made available by Company. Company may change Subprocessors. Where Applicable Data Protection Law requires advance notice, an opportunity to object, or another procedure for a material Subprocessor change, Company will provide that procedure as required by law.
- 5.4An AI Client, connector, integration, or other Third-Party Service that Customer or a User independently selects and authorizes to access the Service is not, merely because of that connection, a Subprocessor engaged by Company. Customer is responsible for evaluating and authorizing such external service and for its subsequent handling of information after it obtains information from the Service.
- 5.5If Company itself selects and uses an AI or other provider to process Customer Personal Data in order to provide an in-product Service feature, that provider may act as a Subprocessor and will be handled under this Article.
6. International Processing and Restricted Regions
- 6.1The Service is not offered to Customers in the Restricted Regions identified in the Restricted Regions List, and use in, from, or primarily for the benefit of such regions is prohibited except where expressly approved by Company and lawful.
- 6.2Company and its Subprocessors may process Customer Personal Data outside Japan where reasonably necessary to provide the Service, including for cloud infrastructure, email delivery, payment processing, AI functionality, security, or support, as described in the Privacy Policy.
- 6.3Where Applicable Data Protection Law requires a transfer mechanism, consent, information provision, contractual safeguard, or other measure for an international transfer, Company will implement the measure required by that law.
- 6.4Nothing in this DPA authorizes processing prohibited by the Restricted Regions List or Applicable Data Protection Law.
7. Data Subject Requests and Regulatory Assistance
- 7.1Taking into account the nature of the processing and the information available to Company, Company will provide reasonable assistance required by Applicable Data Protection Law for Customer to respond to legally valid requests by data subjects concerning Customer Personal Data.
- 7.2If Company receives a request directly from a data subject relating primarily to Customer Personal Data processed on behalf of Customer, Company may refer the requester to Customer unless Applicable Data Protection Law requires Company to respond directly.
- 7.3Customer is responsible for determining whether and how to respond to a request, except to the extent Applicable Data Protection Law places a direct obligation on Company.
- 7.4Unless Applicable Data Protection Law requires Company to bear the cost, material assistance beyond the standard functionality of the Service may be subject to reasonable fees agreed with Customer in advance.
8. Security Incidents
- 8.1Company will investigate a confirmed security incident involving Customer Personal Data and will notify Customer to the extent and within the period required by Applicable Data Protection Law.
- 8.2A notice under this Article does not constitute an admission of fault or liability.
- 8.3Customer is responsible for any notification or other action required of Customer as controller or business, except to the extent Applicable Data Protection Law directly requires Company to perform it.
9. Return, Deletion, and Retention
- 9.1Upon termination or expiration of the relevant Paid Plan Agreement or other applicable business relationship, access to the relevant Team will cease as provided in the Terms.
- 9.2Upon termination or expiration, Customer Content, including Customer Personal Data, will be made unavailable through the Service and will be deleted from active Service systems according to the methods and timing designated by Company under the Terms. Company does not guarantee or undertake restoration after termination or deletion, including restoration from backups. Paragraphs 9.4 and 9.5 apply to retained records and backup or disaster-recovery copies.
- 9.3Unless required by law or separately agreed in writing or electronic form, Company has no obligation after termination to retain, return, restore, export, convert, migrate, or otherwise provide individualized handling of Customer Personal Data or Customer Content.
- 9.4Company may retain information for as long as reasonably necessary for legal obligations, billing or payment records, security, fraud or abuse prevention, dispute resolution, backups, audit, or other legitimate operational purposes, as described in the Terms and Privacy Policy.
- 9.5Data remaining in backup or disaster-recovery systems may be overwritten or deleted according to Company’s ordinary retention cycles and will not be used to restore Customer Content for Customer after termination unless Company separately agrees.
10. Information and Audits
- 10.1Company will make available information reasonably necessary to demonstrate compliance with processor obligations under Applicable Data Protection Law to the extent required by law.
- 10.2Company may satisfy reasonable verification or audit requests by providing questionnaires, written descriptions, policies, certifications, summaries of independent assessments, or other documentation that Company reasonably considers sufficient.
- 10.3Customer is not entitled to direct access to Company systems, source code, facilities, security-sensitive information, other customers’ information, or confidential information of Company or third parties, except to the extent such access is expressly required by Applicable Data Protection Law and cannot reasonably be satisfied by another means.
- 10.4Any audit or additional verification not required to be provided at Company’s cost by Applicable Data Protection Law must be reasonable in scope and frequency, scheduled in advance, avoid unreasonable disruption, be subject to appropriate confidentiality and security requirements, and may be charged to Customer at reasonable cost.
11. Order of Precedence; Liability
- 11.1If this DPA conflicts with the Terms regarding processing of Customer Personal Data on behalf of Customer, this DPA controls solely for that processing. The Terms control in all other respects.
- 11.2This DPA does not expand the scope of the Service or create any service-level, export, restoration, support, audit, transition, or other obligation except as expressly stated in this DPA.
- 11.3All exclusions, limitations, caps, procedures, and remedies relating to liability in the Terms apply to this DPA and to processing under this DPA to the fullest extent permitted by Applicable Data Protection Law.
12. Term and Governing Law
- 12.1This DPA applies while Company processes Customer Personal Data on behalf of Customer under the Terms and continues to apply to retained Customer Personal Data for as long as such processing continues.
- 12.2This DPA is governed by the same law and jurisdiction provisions as the Terms.
13. Acceptance
- 13.1This DPA forms part of the Terms and applies automatically where its scope requirements are met. No separate signature or click-through is required unless Company and Customer agree otherwise.
- 13.2For Customers subject to a separately countersigned data-processing agreement with Company, that separately signed agreement controls to the extent of an express conflict with this DPA.
Schedule 1 — Processing Details
| Item | Description |
|---|---|
| Subject matter | Provision, operation, maintenance, security, and support of MONJI, including collaboration, feedback, file/Wiki functions, analytics integrations, AI features, and AI Integration Features where enabled. |
| Duration | For the term of the applicable agreement and any additional period during which Customer Personal Data is retained as permitted by the Terms, this DPA, the Privacy Policy, or applicable law. |
| Nature and purpose | Hosting, storage, organization, retrieval, transmission, display, access control, logging, troubleshooting, security, support, and other processing necessary to provide the Service on Customer’s documented instructions. |
| Categories of data subjects | Customer’s Users, administrators, employees, contractors, customers, business contacts, website users, and other individuals whose information Customer or its Users include in Customer Content. |
| Types of Customer Personal Data | Names, email addresses, business contact information, comments, website-related information, images, attachments, files, Wiki content, project information, identifiers, and other personal information contained in Customer Content. |
| Customer-selected external services | Where Customer or a User independently authorizes an AI Client or other Third-Party Service, that external service is selected by Customer and is not a Subprocessor engaged by Company merely by reason of the connection. |
Version History
- Version 1.0 — January 23, 2025 (JST), Established and effective
- Version 2.0 — October 16, 2026 (JST), Revised, scheduled to take effect