Privacy Policy
This policy describes how Pioneerwork Inc. (株式会社Pioneerwork) — "we" — handles your information in ZAG for Excel. It is the English reference version of our Japanese privacy policy; the Japanese text governs in the event of any discrepancy.
1Who we are
Published in accordance with Article 32(1) of Japan's Act on the Protection of Personal Information (APPI).
| Operator | 株式会社Pioneerwork (Pioneerwork Inc.) |
|---|---|
| Address | Kojima Building, 2-20-11 Kojima, Taito-ku, Tokyo 111-0056, Japan |
| Representative | Yoichi Goto, CEO |
| Data protection contact | See section 11 |
2What we process
Most of what this service handles is product data — specifications, model numbers, prices, JAN codes — which is not personal information. The only personal data we hold as a matter of course is the member directory below; beyond that, personal data appears only incidentally, where it happens to be present in a document or message you send.
| Category | What it covers |
|---|---|
| Workbook contents | The cells, headers, notes and validation rules the add-in's tools need to read, and the cells it writes back. The workbook file itself is never uploaded — only the ranges a tool reads travel over the network. |
| Uploaded documents | Catalogs and spec sheets you add (PDF, Excel, images, etc.), up to 100 MB per file. |
| Chat messages | Your instructions to the assistant and its responses. |
| Files put into the live demo | The price list or spec sheet a visitor tries on this website's live demo (PDF, Excel or CSV, one file up to 5 MB) and the request typed with it. To limit how often the demo can be run, the visitor's IP address and a cookie identifier are hashed and kept — for that purpose only. |
| Template settings | Structural information about a template — headers, notes, validation rules. Contains no product data of yours. |
| Member records | Display name, email address (optional, may be empty), organisation, account id, active/disabled status, creation date. |
| Operational records | Job history: counts, status, timestamps, exception reasons, log lines, model token counts. Result cell values are excluded. |
3Purposes of use
We use the information above only for the purposes listed here, and for nothing else.
- Workbook contents, uploaded documents, chat messages — to perform the template-filling and document-question work you request in the pane.
- Template settings — to keep fills against the same template accurate and reproducible.
- Member records — to issue, scope and revoke access tokens, to email the install file (manifest), to verify identity, and to operate, support and bill the service.
- Operational records — to monitor service health, investigate faults, answer support questions, and calculate usage.
We do not use your information for advertising, profiling, or resale. There is no secondary use.
4Where data lives, and for how long
All server-side processing and storage runs in Microsoft Azure's Japan East region. We do not store customer data outside Japan.
| Data | Where | How long |
|---|---|---|
| Chat history, settings | Your browser's local storage only | Until you clear it — it never reaches our servers |
| Uploaded documents | Azure Blob Storage, scoped per account | Until you delete them, from the Files pane or on request |
| Fill results (cell values) | Server memory only | Swept 30 minutes after completion; never written to disk |
| Live-demo files and results | Azure Blob Storage, a separate store used only by the live demo | Deleted automatically within 24 hours, enforced by a storage lifecycle rule |
| Live-demo usage records (hashed IP and cookie id) | Same store | Deleted automatically after 30 days |
| Website visit records | Same store (page viewed, language, referrer domain, browser and OS family, viewport width, hashed IP) | Deleted automatically after 90 days |
| Live-demo run records | Same store (file name, size and type, the kind of document and of products, a few product names, the request typed, columns chosen, counts, timings, outcome or error, hashed IP and cookie id — never the file's contents themselves) | Deleted automatically after 90 days |
| Extraction results | Server memory only | Reaped 30 minutes after creation; result caching is disabled by default |
| Template settings | Azure Blob Storage | Deleted at end of contract |
| Operational records | Azure Blob Storage | 180 days, enforced by a storage lifecycle rule |
| Member records | Azure Blob Storage | Deleted promptly at end of contract |
Operational records deliberately exclude result cell values, and any exception message that could quote a rejected value is redacted before it is written durably. Upload records hold the filename, size and account — not the file's contents.
5Disclosure to third parties
We do not disclose personal data to third parties without prior consent, except where required by law, where necessary to protect someone's life, body or property and consent cannot practicably be obtained, or where cooperation with a public authority is required and seeking consent would impede that duty.
We never sell your data, and we never share it with other customers. Uploaded documents and template settings are scoped per account.
6Subprocessors
We entrust processing to the following, under Article 27(5)(i) APPI, and supervise them as Article 25 requires. There is no other third party in the data path — no advertising network, no external search vendor, no external CDN or font service.
| Subprocessor | Service | Location of processing |
|---|---|---|
| Microsoft Corporation / Microsoft Japan Co., Ltd. |
Cloud infrastructure (Microsoft Azure) and AI platform (Azure OpenAI Service) | Japan (Japan East region) |
| HubSpot, Inc. | Hosting of our application and enquiry forms, and storage of what you submit through them (company, name, contact details, and the details you write in) | United States |
| PostHog Inc. | Product analytics for the add-in: usage events (which feature was used, when a fill started and finished and how many rows it wrote, what kind of error occurred) keyed by an account identifier, and session recordings of the add-in's task pane as it appeared on screen (layout, clicks, scrolling, timing, and the text visible in the pane — cell values the assistant displays, chat messages, file names, typed input; passwords excepted). Usage events never carry content; recordings do. No IP addresses. Both go by way of our server only | United States (Virginia) |
HubSpot is used for applications and enquiries only. Workbook contents, uploaded documents and chat messages never reach them.
7Cross-border access
Your data is stored and processed in Japan. One flow nonetheless warrants disclosure: under Microsoft's standard Azure OpenAI terms, prompts and completions may be retained for up to 30 days within the resource's own geography for abuse monitoring, and reviewed by authorised Microsoft personnel only where abuse is suspected.
| Country of the recipient | United States (Microsoft Corporation) |
|---|---|
| Information on that country's regime | See the Personal Information Protection Commission's published surveys of foreign data-protection systems. |
| Safeguards in place | The Microsoft Products and Services Data Protection Addendum (DPA), plus ISO/IEC 27001 and ISO/IEC 27018 certification. We hold the executed DPA on file as evidence of subprocessor supervision. |
We intend to apply to Microsoft for Modified Abuse Monitoring, which removes this retention and human-review flow entirely. This section will be revised if that is approved.
A second flow is the product analytics in section 6: usage events and session recordings from the add-in are held by PostHog Inc., a company in the United States, in its United States hosting region (Virginia).
| Information concerned | Usage events keyed by an account identifier (feature used, fill counts, error type, add-in version, Excel host, interface language), and session recordings of the task pane as displayed (layout, clicks, scrolling, timing, and on-screen text — cell values the assistant shows, chat messages, file names, typed input). Usage events carry no content; recordings carry what was on screen, which may include personal data typed into a chat. No IP addresses. |
|---|---|
| Country of the recipient | United States (PostHog Inc.); data stored in the United States (Virginia) |
| Information on that country's regime | See the Personal Information Protection Commission's published surveys of foreign data-protection systems. |
| Safeguards in place | PostHog's Data Processing Agreement, which we hold on file as evidence of subprocessor supervision. Events are deleted 12 months after capture and recordings no more than 90 days after capture. Your organisation may ask us to switch recording, or analytics as a whole, off for its members. |
Separately, as stated in section 6, what you submit through our application and enquiry forms is stored by HubSpot, Inc., a recipient outside Japan.
| Information concerned | The company, name, contact details and written details you enter in an application or enquiry form |
|---|---|
| How it is handled | Held in their customer-management service so that we can receive and respond to your enquiry. Workbook contents, uploaded documents and chat messages are not included. |
| Country of the recipient | United States (HubSpot, Inc.) |
| Information on that country's regime | See the Personal Information Protection Commission's published surveys of foreign data-protection systems. |
| Safeguards in place | Their published Data Processing Agreement, plus ISO/IEC 27001 certification. |
8No training on your data
We do not use your workbook contents, uploaded documents, or chat messages to train or tune AI models. Under Microsoft's published Azure OpenAI Service terms, your prompts and completions are likewise not used to train OpenAI or Microsoft foundation models.
9Security measures
Published under Article 23 APPI. The full description is on the Security page; in summary:
- All traffic is encrypted with HTTPS; the add-in refuses to start against a non-HTTPS endpoint.
- Every data request requires a signed bearer token, and the account embedded in that token scopes what it can reach. Tokens are individually revocable.
- Azure credentials — model API keys, storage connection strings — are held only server-side and never reach the browser.
- A Content-Security-Policy restricts the pane's network access to our own origin and the Microsoft Office script host. No third-party scripts load.
- Our operations console uses separate credentials from customer tokens, and has no ability to read uploaded file contents or result cell values.
- Model-authored analysis code runs in an isolated subprocess under time and memory limits.
- Physical security of the datacentres is Microsoft's responsibility under the Azure shared-responsibility model.
10Your rights
You (or your authorised representative) may request notification of purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, cessation of third-party provision, and disclosure of third-party provision records, in respect of retained personal data.
- Email the contact in section 11.
- We verify identity against the member directory. A representative must supply proof of authority.
- We aim to respond within two weeks of verification.
- We charge no fee for these requests.
You can delete uploaded documents yourself from the Files pane at any time, or ask us to do it.
11Contact
| Data protection desk | Pioneerwork Inc. — ZAG for Excel |
|---|---|
| yoichi@pioneerwork.co / rahul@pioneerwork.co | |
| Address | Kojima Building, 2-20-11 Kojima, Taito-ku, Tokyo 111-0056, Japan |
| Hours | Japanese business days |
12Breach notification
Where a leak, loss or damage of personal data occurs and meets the criteria set by the Personal Information Protection Commission, we report it to the Commission and notify affected individuals within the statutory deadlines. The desk in section 11 owns detection and notification.
13Cookies and external transmission
Disclosed under Japan's Telecommunications Business Act external-transmission rules.
- This website sets no analytics or advertising cookies and transmits nothing about your visit to any external party. Every asset — fonts, stylesheets, scripts — is served from our own origin. No external font service or CDN is contacted. To count visits, each page view records — on our own server only, with no cookie and no third-party analytics service — the page, its language, the referring domain, the browser and OS family, the viewport width and a hash of the IP address. These records are deleted after 90 days.
- The live demo (the home-page feature that fills a sample sheet from a file you choose) is the one exception, and only when you use it. The file and the request you type are processed in a dedicated area of our Azure environment (Japan East) and sent to Azure OpenAI Service (Japan East) for extraction. They are not used to train models and are deleted within 24 hours. To limit how often the demo can be run we set one functional cookie (
zag_demo, a random identifier only, our domain only, one year) and keep a hashed record of your IP address and that identifier for 30 days. For quality and troubleshooting we also keep, for 90 days and against those same hashes, the file's name, size and type, the kind of document and of products it holds, a few product names, the request you typed, and the outcome or error — never the file's contents themselves. Please do not put files containing personal information into the demo. - The add-in stores chat history and settings only in your browser's local storage; that information is never transmitted. The add-in does send usage events, by way of our own server, to PostHog Inc. (hosted in the United States): which feature was used, when a fill started and finished and how many rows it wrote, and what kind of error occurred, together with an account identifier, organisation label, add-in version, Excel host and interface language. We use this to understand and improve the add-in. No workbook contents, cell values, documents, chat text, names, email addresses or IP addresses are included, and events are deleted 12 months after capture. For the same purpose the add-in may also record how its task pane is used, as a replay of what was on screen — the layout, where you click, how you scroll, how long steps take, and the text visible in the pane: cell values the assistant shows, your chat messages and the assistant's answers, file names, and what you type (passwords excepted). Not recorded: your workbook outside the pane, uploaded file contents unless shown in the pane, network traffic, console output. Recordings go by way of our server, are viewable only by our operating team, and are deleted no more than 90 days after capture. Your organisation may ask us to switch recording off for its members, separately from analytics as a whole.
- The application forms are hosted by HubSpot, Inc. on a domain of its own. The buttons on this site are links to those forms: nothing reaches HubSpot until you follow one. What you then enter and submit there — company, name, contact details and the answers you give — reaches us through HubSpot. HubSpot's own privacy terms also apply once you are on that page.
14Changes
We may revise this policy to reflect changes in law or in the service. Where the substance of how we handle data changes, we post the revision here and notify customers in advance. Revisions take effect when posted.
End of document.