Privacy Policy

Mezusphere Privacy Policy

Effective date: July 5, 2026

This Privacy Policy describes how Mezusphere, Inc., Tokyo, Japan (“Mezusphere”, “we”, “us”) handles personal data for which we determine the purposes and means of processing. It applies to visitors of our website, users of the Mezusphere console, and business contacts.

1. Two roles: our data and our customers’ data

Mezusphere processes personal data in two distinct roles:

  • As a controller (this policy). We control personal data about our own website visitors, account administrators, billing and support contacts, and sales or marketing contacts, together with security and operational data we use to protect the platform.
  • As a processor on behalf of customers (not this policy). Customer Content and Customer End-User Data, including traffic that customers route through the Mezusphere service and end-user directory or authentication data that customers configure, are processed on the customer’s behalf and under the customer’s instructions. The customer’s own privacy notice governs that data. If you are an end user of an application that uses Mezusphere, please contact the operator of that application; we will refer requests we receive about such data to the relevant customer.

2. Personal data we collect

CategoryExamplesSource
Account DataName, business email, company name, role, login identifiers, authentication factors (for example passkey public keys), billing contact detailsProvided by you
Usage DataConsole feature usage, error events, performance metadata tied to admin usersGenerated by your use of the console
Security DataIP addresses, request metadata, audit logs of administrative actions, abuse signalsGenerated by your use of the website and Service
Warpgate Operational DataConnector version, connection and authentication status, session metadata, error diagnosticsGenerated by Warpgate connections, where we use it for platform protection
Support DataSupport requests, correspondence, diagnostics you choose to shareProvided by you
Marketing DataNewsletter sign-ups, event registrations, sales correspondenceProvided by you

We do not collect more than we need, and we do not log full request or response bodies of customer traffic by default.

3. Purposes of use

We use personal data for the following purposes:

CategoryPurposes
Account DataCreating and administering accounts; authenticating users; billing; sending service and security notices; complying with legal obligations
Usage DataDetecting product defects; prioritizing reliability and usability improvements; capacity planning; preventing abuse
Security DataAuthenticating requests; detecting, investigating, and preventing fraud, abuse, and security incidents; maintaining audit trails; protecting the platform and its customers
Warpgate Operational DataEstablishing, authenticating, maintaining, securing, and troubleshooting connector sessions; version support
Support DataResponding to requests; diagnosing and resolving issues; improving support quality
Marketing DataSending requested communications; organizing events; measuring interest in the product

We do not use these categories for purposes incompatible with the ones stated above without informing you and, where required, obtaining your consent.

4. Legal bases (EEA, UK, and similar regimes)

Where GDPR-style laws apply, we rely on: performance of a contract (Account Data, Support Data); legitimate interests in securing and improving the platform, preventing abuse, and conducting proportionate business communications (Usage Data, Security Data, Warpgate Operational Data, some Marketing Data); consent where required (for example newsletters and non-essential cookies); and legal obligations (tax and accounting records).

5. Sharing

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We disclose personal data only to:

  • Subprocessors and vendors that host infrastructure or provide supporting services (for example cloud hosting and transactional email), under contracts restricting their use of the data. A public subprocessor list is in preparation; pilot customers can request the current list.
  • Professional advisers and authorities where required by law, legal process, or to protect rights, safety, and the integrity of the platform. Where lawful and practicable, we will notify affected customers of government requests concerning their data.
  • Successors in a merger, acquisition, or asset transfer, subject to this policy.

6. International transfers

We operate an edge network and use cloud subprocessors, so personal data may be processed outside your country, including outside Japan and the EEA. Where we transfer personal data internationally, we use recognized safeguards appropriate to the source jurisdiction, such as the EU Standard Contractual Clauses, and we disclose processing countries through our subprocessor documentation. We do not claim single-country processing unless the architecture enforces it.

7. Security

We apply technical and organizational measures appropriate to the nature of the data, including encryption in transit, mutual TLS between platform components, encryption at rest for relevant storage, multi-factor and hardware-backed authentication for administrative access, least-privilege access controls, logging and monitoring, and vulnerability management. Details are described in our security documentation.

8. Retention

We keep personal data only as long as needed for the purposes above: Account Data for the life of the account plus legally required retention periods; Security Data and audit logs for defined windows appropriate to security investigation; Support and Marketing Data until resolution or until you opt out. Backups expire on defined cycles. When retention ends, data is deleted or anonymized.

9. Your rights

Depending on your jurisdiction (including the APPI in Japan, the GDPR in the EEA and UK, and US state privacy laws), you may have rights to request disclosure, access, correction, deletion, restriction, portability, or to object to certain processing, and to withdraw consent where processing is based on consent. You also have the right to complain to a supervisory authority, including the Personal Information Protection Commission in Japan.

To exercise these rights, contact hello@mezusphere.com. We will verify your identity and respond within the periods required by applicable law. Withdrawing consent is as easy as giving it. We do not discriminate against you for exercising your rights.

10. Cookies

The website and console use cookies necessary for operation and security, such as session and consent cookies. We do not use advertising cookies in the console. Where we introduce non-essential cookies or analytics, we will request consent where required and provide a means to change your choice. A separate cookie notice with the current cookie list is in preparation.

11. Children

The website and Service are intended for business use and not directed to children. We do not knowingly collect personal data from children.

12. Changes

We may update this policy. For material changes we will notify account administrators and update the effective date above. Earlier versions are available on request.

13. Contact

Mezusphere, Inc., Tokyo, Japan Privacy contact: hello@mezusphere.com