Privacy Policy
This policy describes how Pioneerwork Inc. (株式会社Pioneerwork) — "we" — handles your information in ZAG for Excel. It is the English reference version of our Japanese privacy policy; the Japanese text governs in the event of any discrepancy.
1Who we are
Published in accordance with Article 32(1) of Japan's Act on the Protection of Personal Information (APPI).
| Operator | 株式会社Pioneerwork (Pioneerwork Inc.) |
|---|---|
| Address | Kojima Building, 2-20-11 Kojima, Taito-ku, Tokyo, Japan |
| Representative | Yoichi Goto, CEO |
| Data protection contact | See section 11 |
2What we process
Most of what this service handles is product data — specifications, model numbers, prices, JAN codes — which is not personal information. The only personal data we hold as a matter of course is the member directory below; beyond that, personal data appears only incidentally, where it happens to be present in a document or message you send.
| Category | What it covers |
|---|---|
| Workbook contents | The cells, headers, notes and validation rules the add-in's tools need to read, and the cells it writes back. The workbook file itself is never uploaded — only the ranges a tool reads travel over the network. |
| Uploaded documents | Catalogs and spec sheets you add (PDF, Excel, images, etc.), up to 100 MB per file. |
| Chat messages | Your instructions to the assistant and its responses. |
| Template settings | Structural information about a template — headers, notes, validation rules. Contains no product data of yours. |
| Member records | Display name, email address (optional, may be empty), organisation, account id, active/disabled status, creation date. |
| Operational records | Job history: counts, status, timestamps, exception reasons, log lines, model token counts. Result cell values are excluded. |
3Purposes of use
We use the information above only for the purposes listed here, and for nothing else.
- Workbook contents, uploaded documents, chat messages — to perform the template-filling and document-question work you request in the pane.
- Template settings — to keep fills against the same template accurate and reproducible.
- Member records — to issue, scope and revoke access tokens, to email the install file (manifest), to verify identity, and to operate, support and bill the service.
- Operational records — to monitor service health, investigate faults, answer support questions, and calculate usage.
We do not use your information for advertising, profiling, or resale. There is no secondary use.
4Where data lives, and for how long
All server-side processing and storage runs in Microsoft Azure's Japan East region. We do not store customer data outside Japan.
| Data | Where | How long |
|---|---|---|
| Chat history, settings | Your browser's local storage only | Until you clear it — it never reaches our servers |
| Uploaded documents | Azure Blob Storage, scoped per account | Until you delete them, from the Files pane or on request |
| Fill results (cell values) | Server memory only | Swept 30 minutes after completion; never written to disk |
| Extraction results | Server memory only | Reaped 30 minutes after creation; result caching is disabled by default |
| Template settings | Azure Blob Storage | Deleted at end of contract |
| Operational records | Azure Blob Storage | 180 days, enforced by a storage lifecycle rule |
| Member records | Azure Blob Storage | Deleted promptly at end of contract |
Operational records deliberately exclude result cell values, and any exception message that could quote a rejected value is redacted before it is written durably. Upload records hold the filename, size and account — not the file's contents.
5Disclosure to third parties
We do not disclose personal data to third parties without prior consent, except where required by law, where necessary to protect someone's life, body or property and consent cannot practicably be obtained, or where cooperation with a public authority is required and seeking consent would impede that duty.
We never sell your data, and we never share it with other customers. Uploaded documents and template settings are scoped per account.
6Subprocessors
We entrust processing to the following, under Article 27(5)(i) APPI, and supervise them as Article 25 requires. There is no other third party in the data path — no advertising network, no external search vendor, no external CDN or font service. Customer-facing deployments use no analytics provider either; session analytics for interface improvement is enabled only on our own internal test deployment.
| Subprocessor | Service | Location of processing |
|---|---|---|
| Microsoft Corporation / Microsoft Japan Co., Ltd. |
Cloud infrastructure (Microsoft Azure) and AI platform (Azure OpenAI Service) | Japan (Japan East region) |
7Cross-border access
Your data is stored and processed in Japan. One flow nonetheless warrants disclosure: under Microsoft's standard Azure OpenAI terms, prompts and completions may be retained for up to 30 days within the resource's own geography for abuse monitoring, and reviewed by authorised Microsoft personnel only where abuse is suspected.
| Country of the recipient | United States (Microsoft Corporation) |
|---|---|
| Information on that country's regime | See the Personal Information Protection Commission's published surveys of foreign data-protection systems. |
| Safeguards in place | The Microsoft Products and Services Data Protection Addendum (DPA), plus ISO/IEC 27001 and ISO/IEC 27018 certification. We hold the executed DPA on file as evidence of subprocessor supervision. |
We intend to apply to Microsoft for Modified Abuse Monitoring, which removes this retention and human-review flow entirely. This section will be revised if that is approved.
8No training on your data
We do not use your workbook contents, uploaded documents, or chat messages to train or tune AI models. Under Microsoft's published Azure OpenAI Service terms, your prompts and completions are likewise not used to train OpenAI or Microsoft foundation models.
9Security measures
Published under Article 23 APPI. The full description is on the Security page; in summary:
- All traffic is encrypted with HTTPS; the add-in refuses to start against a non-HTTPS endpoint.
- Every data request requires a signed bearer token, and the account embedded in that token scopes what it can reach. Tokens are individually revocable.
- Azure credentials — model API keys, storage connection strings — are held only server-side and never reach the browser.
- A Content-Security-Policy restricts the pane's network access to our own origin and the Microsoft Office script host. No third-party scripts load.
- Our operations console uses separate credentials from customer tokens, and has no ability to read uploaded file contents or result cell values.
- Model-authored analysis code runs in an isolated subprocess under time and memory limits.
- Physical security of the datacentres is Microsoft's responsibility under the Azure shared-responsibility model.
10Your rights
You (or your authorised representative) may request notification of purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, cessation of third-party provision, and disclosure of third-party provision records, in respect of retained personal data.
- Email the contact in section 11.
- We verify identity against the member directory. A representative must supply proof of authority.
- We aim to respond within two weeks of verification.
- We charge no fee for these requests.
You can delete uploaded documents yourself from the Files pane at any time, or ask us to do it.
11Contact
| Data protection desk | Pioneerwork Inc. — ZAG for Excel |
|---|---|
| yoichi@pioneerwork.co / rahul@pioneerwork.co | |
| Address | Kojima Building, 2-20-11 Kojima, Taito-ku, Tokyo, Japan |
| Hours | Japanese business days |
12Breach notification
Where a leak, loss or damage of personal data occurs and meets the criteria set by the Personal Information Protection Commission, we report it to the Commission and notify affected individuals within the statutory deadlines. The desk in section 11 owns detection and notification.
13Cookies and external transmission
Disclosed under Japan's Telecommunications Business Act external-transmission rules.
- This website sets no analytics or advertising cookies and transmits nothing about your visit to any external party. Every asset — fonts, stylesheets, scripts — is served from our own origin. No external font service or CDN is contacted.
- The add-in stores chat history and settings only in your browser's local storage. Customer-facing deployments carry no analytics. On our own internal test deployment we may enable Microsoft Clarity session analytics (clicks, scrolls and similar interaction events) to improve the interface; workbook content, uploaded documents and chat text are never sent to it.
14Changes
We may revise this policy to reflect changes in law or in the service. Where the substance of how we handle data changes, we post the revision here and notify customers in advance. Revisions take effect when posted.
End of document.