Privacy Policy
How we handle personal information for Japan operations and for visitors in the United States.
Red Ark Laboratories LLC (レッドアークラボラトリーズ合同会社; a Japan-registered godo kaisha (limited liability company), doing business internationally as Red Ark Laboratories LLC; "we," "us," or "our") provides infrastructure operations, security assessment, software development, and related services. This Privacy Policy explains how we collect, use, disclose, and protect personal information.
For our Japan operations and personal information handled in connection with Japanese law, we comply with Japan's Act on the Protection of Personal Information (APPI) and related guidelines. For California residents and other U.S. visitors, we also describe rights consistent with the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA-style rights), even where we may not yet meet statutory "business" thresholds. Contact: contact@rals.space.
This English version is provided for convenience for international readers. For contracts and regulatory matters governed by Japanese law, the Japanese originals prevail unless we execute a separate English agreement with you.
Who We Are
Personal Information We Collect
Depending on how you interact with us, we may collect:
- └Identifiers and contact data (name, email, company, role, phone if you provide it)
- └Commercial and contract data (quotes, invoices, service tickets, correspondence)
- └Professional / employment application data (resumes, interview notes)
- └Online activity data (IP address, pages viewed, referrer, device/browser signals, cookie identifiers) when you use the Site or online tools
- └Security and support logs necessary to operate and protect services
We do not intentionally collect sensitive personal information beyond what is needed for employment, security, or legal compliance, and we do not use Site analytics to build cross-context behavioral advertising profiles for sale.
Purposes of Use
We use personal information to:
- └Provide, bill for, and support services; verify identity where needed
- └Respond to inquiries, proposals, and documentation requests
- └Improve service quality, troubleshoot incidents, and harden security
- └Send service notices or, where permitted, marketing about our offerings (you may opt out of marketing emails)
- └Recruit and manage employees and contractors
- └Comply with law, enforce agreements, and protect rights, safety, and security
Cookie and embedded third-party transmissions (e.g., YouTube / Google) are described in Third-Party Cookies & Data Transmission.
Japan (APPI) Practices
Under APPI, we acquire personal information by lawful and fair means, use it within stated purposes, and implement organizational, human, physical, and technical security measures. We do not provide personal data to third parties without consent except as permitted by APPI (for example, legal obligation, or protection of life, body, or property where obtaining consent is difficult).
When we engage processors (vendors) to handle personal data on our behalf, we select providers with adequate safeguards and supervise them by contract. Individuals in Japan may request disclosure, correction, addition, deletion, suspension of use, or cessation of third-party provision of retained personal data as provided by APPI. We will respond within a reasonable period after verifying identity.
We are working toward industry-aligned personal information management and information security controls (including practices consistent with ISO/IEC 27001-style ISMS). We do not currently hold Privacy Mark or ISO 27001 certification; we will update this Policy if that changes.
U.S. Visitors & California CCPA/CPRA-Style Rights
If you are a California resident (or another U.S. consumer to whom similar state privacy laws apply), you may have rights to:
- └Know / Access — request categories and specific pieces of personal information we collected about you, and the purposes and parties involved
- └Delete — request deletion of personal information, subject to legal exceptions (e.g., completing a transaction, security, legal compliance)
- └Correct — request correction of inaccurate personal information
- └Opt out of sale / sharing — we do not sell personal information and do not "share" it for cross-context behavioral advertising as those terms are commonly understood under CCPA/CPRA. If our practices change, we will update this Policy and provide an opt-out mechanism
- └Limit use of sensitive personal information — where applicable, we use sensitive data only as needed for the services requested or as permitted by law
- └Non-discrimination — we will not discriminate against you for exercising privacy rights
To exercise these rights, email contact@rals.space with the subject line "Privacy Request" and enough detail for us to locate your data and verify you are the consumer (or an authorized agent). We may ask for additional information to confirm identity. We aim to respond within 45 days, or as otherwise required by applicable law.
Categories of personal information we may collect align with those listed above (identifiers, commercial information, internet/electronic activity, professional information). We collect them from you directly, from your organization, from service interactions, and automatically from the Site.
Security Measures
We implement reasonable safeguards, including:
- └Role-based access control and least-privilege practices
- └Encryption in transit where appropriate; endpoint and malware defenses
- └Staff awareness and handling procedures for personal data
- └Retention limits and secure disposal or deletion when no longer needed
No method of transmission or storage is perfectly secure. Please use unique credentials and report suspected incidents to contact@rals.space.
International Transfers
We are based in Japan. If you contact us or use the Site from the United States or elsewhere, your information may be processed in Japan and in countries where our processors operate. We take steps appropriate under APPI and, where relevant, contractual and technical measures with vendors.
Children
The Site is directed to business and professional audiences. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will take appropriate steps.
Contact
Privacy questions, APPI requests, and CCPA/CPRA-style requests:
We accept privacy requests by email. Complex matters may take additional time. Postal address is listed under "Who We Are."
Updates
We may revise this Policy for legal, operational, or certification progress. Material changes will be posted on this page. Established: January 4, 2024. English convenience version aligned for international readers: 2026.