This policy explains what personal data RIKAI株式会社 ("we") collects when you use RirekiHub at rirekihub.com, why, and the choices you have.
1. Who we are
RirekiHub is operated by RIKAI株式会社, 東京都新宿区西新宿6-12-1 パークウエストビル5階. For any question about your personal data, write to rirekihub@rikai.co.jp.
2. Two roles
Sending organizations put their candidates' data into RirekiHub: CVs, photos, videos and documents. For that data, the organization decides why and how it is used, and we process it on its behalf, only to provide the service. For the other data in this policy, such as accounts, website visits and messages to us, we are responsible.
3. What we collect
- Accounts: name, email address, password (stored only as a hash), your company's details and workspace settings.
- Candidate data, on behalf of your organization: what your staff enter or import, which can include names, date of birth, nationality, contact details, education, work history, family, health, photos and videos.
- Client viewers: the name and email a link asks for, which pages and videos were opened and when, the IP address and the type of device. The organization that sent the link sees this.
- Website visitors: the pages you visit and the campaign that brought you (for example utm_source or an ad click ID), kept with your workspace if you sign up.
- Messages: what you write in the contact form and the contact details you give.
- Technical logs: IP address, browser and times of requests, to keep the service secure and fix errors.
4. Why we use it
To provide and secure the service (accounts, workspaces, share links, emails and the audit log), to answer your messages, to learn which ads bring new workspaces, and to meet legal obligations. We do not sell personal data, and we never use candidate data for advertising.
5. Cookies
Necessary cookies keep you signed in, remember your language and your cookie choice, and keep a viewer's session on a share link. A first-party cookie remembers the campaign that brought you for 90 days.
Advertising cookies from Google (Analytics and Ads), Meta, TikTok and Zalo are set only on our public pages, and only if you accept them. They tell us which ads lead to visits, sign-ups and messages. You can change your choice at any time with "Cookie settings" at the bottom of each page.
6. Who receives data
Service providers that work for us under contract: hosting and storage, email delivery, and an AI provider (Anthropic) that reads imported CVs to fill in the 履歴書 and does not use them to train its models. Advertising platforms receive data only from website visitors who accept cookies. The clients you send links to see what each link shows. We disclose data to authorities only when the law requires it.
7. Transfers abroad
Our providers may process data in other countries, for example in the United States when reading CVs. We choose providers that protect data under contract and as the law requires.
8. How long we keep it
We keep workspace data while the workspace exists. When an organization asks us to delete its workspace, we delete its data within 30 days, and from backups within 6 months. We keep contact messages for up to 2 years, and technical logs only as long as needed to secure and fix the service.
9. Security
Encrypted connections (HTTPS), hashed passwords, role-based access, an audit log in every workspace, and view-only links with optional watermarks. No system is perfectly secure; if a breach affects your data, we will inform you and the authorities as the law requires.
10. Your rights
You can ask to see, correct, export or delete your personal data, to restrict or object to its use, and to withdraw a consent you gave. Write to rirekihub@rikai.co.jp; we answer within the time the law allows. You can also complain to your data protection authority.
If you are a candidate whose data a sending organization keeps in RirekiHub, please contact that organization first: it decides about your data. We will help it answer you.
11. Changes
We may update this policy. We post the new version here with its date and, for important changes, tell workspace administrators by email.