Privacy Policy
Mezusphere Privacy Policy
Effective date: July 5, 2026
This Privacy Policy describes how Mezusphere, Inc., Tokyo, Japan (“Mezusphere”, “we”, “us”) handles personal data for which we determine the purposes and means of processing. It applies to visitors of our website, users of the Mezusphere console, and business contacts.
1. Two roles: our data and our customers’ data
Mezusphere processes personal data in two distinct roles:
- As a controller (this policy). We control personal data about our own website visitors, account administrators, billing and support contacts, and sales or marketing contacts, together with security and operational data we use to protect the platform.
- As a processor on behalf of customers (not this policy). Customer Content and Customer End-User Data, including traffic that customers route through the Mezusphere service and end-user directory or authentication data that customers configure, are processed on the customer’s behalf and under the customer’s instructions. The customer’s own privacy notice governs that data. If you are an end user of an application that uses Mezusphere, please contact the operator of that application; we will refer requests we receive about such data to the relevant customer.
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, business email, company name, role, login identifiers, authentication factors (for example passkey public keys), billing contact details | Provided by you |
| Usage Data | Console feature usage, error events, performance metadata tied to admin users | Generated by your use of the console |
| Security Data | IP addresses, request metadata, audit logs of administrative actions, abuse signals | Generated by your use of the website and Service |
| Warpgate Operational Data | Connector version, connection and authentication status, session metadata, error diagnostics | Generated by Warpgate connections, where we use it for platform protection |
| Support Data | Support requests, correspondence, diagnostics you choose to share | Provided by you |
| Marketing Data | Newsletter sign-ups, event registrations, sales correspondence | Provided by you |
We do not collect more than we need, and we do not log full request or response bodies of customer traffic by default.
3. Purposes of use
We use personal data for the following purposes:
| Category | Purposes |
|---|---|
| Account Data | Creating and administering accounts; authenticating users; billing; sending service and security notices; complying with legal obligations |
| Usage Data | Detecting product defects; prioritizing reliability and usability improvements; capacity planning; preventing abuse |
| Security Data | Authenticating requests; detecting, investigating, and preventing fraud, abuse, and security incidents; maintaining audit trails; protecting the platform and its customers |
| Warpgate Operational Data | Establishing, authenticating, maintaining, securing, and troubleshooting connector sessions; version support |
| Support Data | Responding to requests; diagnosing and resolving issues; improving support quality |
| Marketing Data | Sending requested communications; organizing events; measuring interest in the product |
We do not use these categories for purposes incompatible with the ones stated above without informing you and, where required, obtaining your consent.
4. Legal bases (EEA, UK, and similar regimes)
Where GDPR-style laws apply, we rely on: performance of a contract (Account Data, Support Data); legitimate interests in securing and improving the platform, preventing abuse, and conducting proportionate business communications (Usage Data, Security Data, Warpgate Operational Data, some Marketing Data); consent where required (for example newsletters and non-essential cookies); and legal obligations (tax and accounting records).
5. Sharing
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We disclose personal data only to:
- Subprocessors and vendors that host infrastructure or provide supporting services (for example cloud hosting and transactional email), under contracts restricting their use of the data. A public subprocessor list is in preparation; pilot customers can request the current list.
- Professional advisers and authorities where required by law, legal process, or to protect rights, safety, and the integrity of the platform. Where lawful and practicable, we will notify affected customers of government requests concerning their data.
- Successors in a merger, acquisition, or asset transfer, subject to this policy.
6. International transfers
We operate an edge network and use cloud subprocessors, so personal data may be processed outside your country, including outside Japan and the EEA. Where we transfer personal data internationally, we use recognized safeguards appropriate to the source jurisdiction, such as the EU Standard Contractual Clauses, and we disclose processing countries through our subprocessor documentation. We do not claim single-country processing unless the architecture enforces it.
7. Security
We apply technical and organizational measures appropriate to the nature of the data, including encryption in transit, mutual TLS between platform components, encryption at rest for relevant storage, multi-factor and hardware-backed authentication for administrative access, least-privilege access controls, logging and monitoring, and vulnerability management. Details are described in our security documentation.
8. Retention
We keep personal data only as long as needed for the purposes above: Account Data for the life of the account plus legally required retention periods; Security Data and audit logs for defined windows appropriate to security investigation; Support and Marketing Data until resolution or until you opt out. Backups expire on defined cycles. When retention ends, data is deleted or anonymized.
9. Your rights
Depending on your jurisdiction (including the APPI in Japan, the GDPR in the EEA and UK, and US state privacy laws), you may have rights to request disclosure, access, correction, deletion, restriction, portability, or to object to certain processing, and to withdraw consent where processing is based on consent. You also have the right to complain to a supervisory authority, including the Personal Information Protection Commission in Japan.
To exercise these rights, contact hello@mezusphere.com. We will verify your identity and respond within the periods required by applicable law. Withdrawing consent is as easy as giving it. We do not discriminate against you for exercising your rights.
10. Cookies
The website and console use cookies necessary for operation and security, such as session and consent cookies. We do not use advertising cookies in the console. Where we introduce non-essential cookies or analytics, we will request consent where required and provide a means to change your choice. A separate cookie notice with the current cookie list is in preparation.
11. Children
The website and Service are intended for business use and not directed to children. We do not knowingly collect personal data from children.
12. Changes
We may update this policy. For material changes we will notify account administrators and update the effective date above. Earlier versions are available on request.
13. Contact
Mezusphere, Inc., Tokyo, Japan Privacy contact: hello@mezusphere.com