Data Processing Agreement (DPA).
Last updated: July 24, 2026
Enterprise customers can request a signed DPA. Contact us at the address below. info@sagbrain.com
This DPA supplements the Privacy Policy. For customers in the Japan market, entrustment of personal data is governed by Japan's Act on the Protection of Personal Information (APPI), under which we act as an entrusted processor on the Controller's instructions. The GDPR-based clauses below apply additionally where the Controller or data subjects are subject to the GDPR (e.g., the EEA/UK). Governing law and language follow the Privacy Policy (the Japanese version prevails).
1. Definitions
"Personal Data"
Information relating to an identified or identifiable natural person, as defined under the GDPR and other applicable data protection laws.
"Processing"
Any operation or set of operations performed on Personal Data (including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, restriction, erasure).
"Controller"
The customer (legal entity or individual) using the Service who determines the purposes and means of Processing Personal Data.
"Processor"
SAGBRAIN CORPORATION (株式会社サグブレイン), processing Personal Data on behalf of and under the instructions of the Controller.
2. Subject Matter of Processing
Nature and Purpose
The Processor processes Personal Data solely to the extent necessary to provide the Nokoru service (wiki.sagbrain.com) in accordance with the Controller's instructions.
Types of Personal Data
Name, email address, IP address, browser/device information, and content stored by the Controller in the Service (documents, comments, etc.).
Categories of Data Subjects
The Controller's team members, invited users, and any other individuals who access content through the Service.
Duration of Processing
For the duration of the Service subscription and any additional retention period required by the Processor under applicable law.
3. Processor Obligations
Processing on Instructions
The Processor processes Personal Data only on documented instructions from the Controller, unless required to do so by EU or Member State law.
Confidentiality
Personnel of the Processor who access Personal Data are subject to confidentiality obligations.
Security Measures
The Processor implements appropriate technical and organisational security measures pursuant to GDPR Article 32, including encryption at rest and in transit, access controls, and regular security testing.
Data Breach Notification
Upon becoming aware of a Personal Data breach, the Processor will notify the Controller without undue delay (and within 72 hours where feasible).
Assistance with Data Subject Rights
The Processor assists the Controller in fulfilling obligations regarding data subject rights (access, rectification, erasure, portability, etc.) through appropriate technical and organisational measures.
Return or Deletion of Data
Within 90 days of service termination, the Controller may request an export of Personal Data. After this period, the Processor will securely delete the Controller's data, unless retention is required by applicable law.
4. Sub-Processors
Current Sub-Processors
The Processor uses the following sub-processors: Amazon Web Services (cloud infrastructure and storage; data is primarily stored in the Tokyo region); Anthropic and Google/Gemini (AI processing, USA); Stripe (payment processing, USA); Sentry (error monitoring, USA); SMTP provider (email delivery); Google/FCM and Apple/APNs (push notification delivery); Google Analytics/GA4 (analytics, USA); and group companies for development/support (Singapore, Bangladesh). In addition, only where enabled by the Controller, external integrations: Google Drive/Calendar, Atlassian/Jira, and chat notifications via Slack/Microsoft Teams/Google Chat. This list is maintained consistently with Article 5 (Entrustment) of the Privacy Policy.
Changes to Sub-Processors
The Processor will give the Controller 30 days' prior notice of any intended addition or replacement of sub-processors.
5. International Data Transfers
Transfer Mechanisms
For cross-border transfers under Japan's APPI, we comply with APPI Article 28 (obtaining consent, or verifying an adequate framework at the destination; see Privacy Policy §7). Transfers outside the EEA are conducted on the basis of the European Commission's Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms. Data is primarily stored in the AWS Tokyo region.
6. Audit Rights
Information and Audits
The Controller may request information necessary to demonstrate the Processor's compliance with applicable data protection law. Audits may be conducted once per year upon 30 days' written notice.
7. Contact & Signed DPA
Request a Signed DPA
Enterprise plan customers may request a signed DPA. Please contact us at info@sagbrain.com. We typically respond within 5 business days.