GoSul
Back to Homepage

Privacy Policy

Last Updated: September 8, 2026

The GoSul Operations Secretariat (hereinafter referred to as the "Company") establishes this Privacy Policy (hereinafter referred to as the "Policy") regarding the collection, processing, and management of user information on the service "GoSul" (hereinafter referred to as the "Service").

Article 0 (Service Operator Information)

Article 1 (Purpose of the Service & Position)

The Service is designed and provided for managing business customer addresses and field sales operations. The Service does not actively target or gather personal data from individuals residing in the European Union (EU) or the United Kingdom (UK) under the GDPR scope.

Article 2 (Data Responsibility Split)

  1. User's Responsibility: The corporate client/employer using the Service (the "User") acts as the Data Controller for the customer lists, contact logs, and geolocation information they upload, enter, or sync. The User is responsible for ensuring that all uploaded customer personal data has been obtained lawfully.
  2. Company's Responsibility: The Company acts as a Data Processor. We process customer details solely on the instructions of the User to provide, maintain, secure, and improve the Service. We do not use the customer data uploaded by the User for our own marketing, profiling, or other independent business purposes.

Article 3 (Information We Collect)

The Company collects the following types of information when providing the Service:

Article 4 (Purpose of Use)

The Company uses the collected data for the following purposes:

Article 5 (Data Subprocessors & External Transfers)

To provide high-quality services, we utilize subprocessing services. Some user data may be transferred to or stored on servers located outside of Japan, under rigorous encryption and security standards. Below is our Subprocessor List:

Subprocessor Name Purpose of Processing Location of Servers
Supabase Database Hosting, User Authentication, and Session Storage Japan / USA
Mapbox Map Rendering, Geocoding Addresses, and Route Planning USA / Global
Stripe Payment Processing, Billing History, and Credit Card Validation USA / Japan

Article 5A (Data Processing for Optional AI Features)

AI features run when a User explicitly chooses to use them. Depending on the feature, activity notes, a limited set of recent activity records, status, next-action dates, or aggregate information are sent to the OpenAI API provided by OpenAI, L.L.C. in the United States. Customer profile names, addresses, coordinates, phone numbers, email addresses, and payment information are not automatically added to the AI input. Information written within a note may still be included.

When the User requests transcription, the recorded audio is sent to OpenAI for that purpose. GoSul does not retain the audio after processing. Detected phone numbers, email addresses, API keys, and certain other secrets in text notes and history are masked before transmission. Masking is not guaranteed to detect every item; do not enter sensitive information that is unnecessary for the task.

GoSul's AI usage records do not store note text, generated response text, or audio. They record operational information such as the feature used, usage counts, and processing results for as long as necessary for billing, usage limits, security, and support. Suggestions the User chooses to apply or save are stored as ordinary customer data or activity records.

Response-generation requests use the store: false setting where available. This does not eliminate all provider-side retention: OpenAI's published policy permits abuse-monitoring logs containing inputs and outputs to be retained for up to 30 days by default, and longer where legally required or necessary for safety. Retention varies by API feature. See OpenAI's API data controls.

The Company does not use this User Data for model training or opt in to sharing it for model improvement. OpenAI states that API inputs and outputs are not used to train its models unless the API customer explicitly opts in. Users can avoid transmission to the AI provider by not running AI features and continue using the non-AI features available under their plan.

Data may be processed outside Japan by OpenAI and its subprocessors. The Company reviews provider safeguards, terms, and published information and takes the information-provision, contractual, consent, or other steps required under applicable law. The Japanese privacy policy is the governing version.

Article 6 (Security Measures)

We implement appropriate technical, administrative, and organizational security measures to prevent unauthorized access, leakage, loss, or alteration of personal data. This includes SSL/TLS communication encryption, restricted administrative access, firewalls, server activity logs, and secure database configurations.

Article 7 (Data Retention & Deletion Requests)

Users may update their account details, request data exports, or delete their account directly through the settings panel in the Service. Upon account deletion, the uploaded customer lists and activity logs associated with the account will be permanently deleted from active production servers, except where retention is required by Japanese commercial laws or tax regulations.

Article 8 (Cookies & Analytics)

We use Cookies for session management and traffic analysis (Google Analytics). Users can decline cookies through browser settings, though some features of the Service may become unavailable. Google Analytics collects logs anonymously. You can opt out via Google's official opt-out extension.

Article 9 (Governing Law and Governing Language)

This Policy is governed by the laws of Japan. In the event of any discrepancy between the Japanese version of the Privacy Policy and this English version, the Japanese version shall prevail.