関連法務文書

Review the privacy context alongside related legal resources.

PRIVACY REVIEW ESSENTIALS

Executive summary for privacy and procurement review.

Start here for the six topics most legal, privacy, security and procurement teams need before reviewing the full policy.

What data we collect

Account, billing, support, usage, workspace configuration and customer messaging data needed to operate Verbum.

See data categories

Why we process it

To provide the platform, support approved workflows, protect the service, manage subscriptions and respond to requests.

Review purposes

Your rights

Access, correction, deletion, portability, objection and restriction requests are routed through privacy/legal review.

Review rights

Retention

Retention depends on data category, workspace configuration, plan terms, approved DPA or written agreement.

Open retention matrix

Security

Security materials describe access controls, encryption context, incident response, audit history and qualified review.

Review security

Subprocessors

Confirmed public subprocessors and qualified-review provider categories are linked for procurement review.

Review subprocessors

ENTERPRISE PRIVACY MAP

Roles, transfer context and safeguards at a glance.

Use these cards to find the part of the policy procurement, privacy and security teams usually review first.

Controllers

Controller identity details for website, account, billing, support and contact-form data are coordinated through the Verbum legal/privacy review path.

Review roles

Processors

For customer messaging content and workspace workflow data, Verbum processes according to customer instructions and applicable terms.

Review roles

Transfers

International transfer context depends on configuration, providers and applicable data protection requirements.

Review transfers

Rights requests

Access, correction, deletion, portability, objection and restriction requests are routed through the legal/privacy contact path and reviewed after verification.

Review rights

Retention

Retention depends on data category, workspace configuration, plan terms, customer instructions and applicable agreement.

Review retention

Security measures

Security measures and review materials support qualified privacy, procurement and security evaluation.

Review security

Verbumについて

Verbumは、エンタープライズチーム向けに構築されたガバナンス対応オムニチャネルメッセージングプラットフォームです。WhatsApp、メール、チームメッセージングツールなど複数チャネルでAI支援の下書き、人の承認ワークフロー、監査対応のメッセージ履歴を提供します。

チームが扱うコンテンツについてはデータ処理者として、アカウント情報とプラットフォーム使用データについてはデータ管理者として機能します。

For website, account administration, billing, support, security and contact-form data, Verbum provides a legal/privacy contact path for privacy questions and data protection requests.

For privacy or data protection requests, use the Verbum legal/privacy contact path.

プライバシーまたはデータ保護に関するリクエストは、Contactページの法務/プライバシー経路からお問い合わせください。

LGPDおよびGDPRのデータ権利

Verbumは、LGPDおよびGDPR要件の下で運用する組織に向けて、プライバシーを意識したデータ処理を支援します。お客様および権限のあるユーザーは、プライバシー照会、データ権利、データ処理条件、サブプロセッサーレビュー、セキュリティ文書に関するサポートをリクエストできます。

プライバシーリクエストのサポート領域

  • データアクセスと透明性

    Verbumを通じて処理される可能性がある個人データのカテゴリと、ワークスペース記録の扱いを確認できます。

  • Correction, deletion and retention

    Ask for support correcting account or workspace data, or request context on deletion, retention and backup handling under applicable terms.

  • Restriction, objection and portability

    Raise restriction, objection or portability questions where applicable under LGPD, GDPR or similar frameworks.

  • Data processing, subprocessors and security review

    Request data processing terms, public subprocessor context and security materials for qualified privacy or procurement review.

Related review resources:

プライバシーまたはデータ保護に関するリクエストは、Contactページの法務/プライバシー経路からVerbumにお問い合わせください。

収集する情報

Verbumプラットフォームの提供と改善に必要な情報のみを収集します。

Data categories overviewThis table summarizes the main data categories described in this Privacy Policy for procurement and privacy review.
Data categoryWhat it includes
アカウントデータアカウント作成時または管理者から招待された際の氏名、業務用メールアドレス、ワークスペース内の役割。
請求データサブスクリプションプラン、請求担当者、支払い方法識別子。カード全データはStripeが処理し、Verbumサーバーには保存されません。
使用状況とテレメトリ製品改善のためのプラットフォーム使用シグナル(ページビュー、機能操作、セッション時間)。広告目的での個人プロファイリングは行いません。
Support/contact dataMessages submitted through support, contact, privacy, legal or security forms, plus routing context needed to respond to the request.
会話データ受信・送信メッセージのコンテンツ、AI生成の下書き、編集、承認決定、ワークスペースチャネルを通じた配信イベント。
Googleユーザーデータ(Gmail連携)お客様がGoogleログインで接続したGmailまたはGoogle Workspaceメールボックスに関する、Googleアカウントのメールアドレスとプロフィール名、およびメッセージ、ヘッダー、本文、添付ファイル。範囲、利用、共有、保持については「Googleユーザーデータ」セクションをご覧ください。
ワークスペース設定ルーティングルール、承認ワークフロー、チャネル資格情報(保存時に暗号化)、ワークスペース設定。

情報の利用方法

収集したデータは、プラットフォームの運営、契約の履行、法的義務の遵守、製品改善のためにのみ使用します。

  • Verbumプラットフォームの提供: ルーティング、下書き、承認ワークフロー、メッセージ配信
  • ワークスペース設定に従った監査レコードと履歴の維持
  • 決済処理業者Stripeを通じた請求とサブスクリプション管理
  • アカウント、プラン変更、重要な製品アップデートに関する連絡
  • 集約・匿名化された使用シグナルを使ったプラットフォームの改善
  • 適用法の遵守および有効な法的要請への対応

メッセージのコンテンツや顧客データをマーケティング、広告、またはプラットフォーム運営に無関係な目的に使用することはありません。

AI支援メッセージングデータ

Verbumは、ガバナンスされたAIメッセージング機能を提供するために、お客様の設定および適用条件に従って、メッセージコンテキスト、下書き内容、承認判断、ワークフローメタデータ、監査履歴を処理する場合があります。

AI data-use restriction

Verbum does not use customer business messages to train public AI models unless explicitly stated and contractually allowed.

  • Customer message content is processed to provide configured AI-assisted drafting, routing, review and Verbum Automate workflows.
  • Customer message content is not used to train public or general-purpose AI models unless explicitly stated and contractually allowed.
  • Fine-tuning or training on customer message content requires explicit written authorization in the applicable agreement.
  • AI subprocessors may process prompts, message context and outputs only to provide the configured service, subject to applicable provider terms and approved customer configuration.
  • Retention of prompts, outputs and related workflow context follows the applicable workspace settings, plan terms, provider configuration, DPA, order form or written agreement.

Operation and drafting context

  • AI下書きは、リクエストされたワークフローを支援するために必要なメッセージコンテキストとワークスペース設定から生成されます。
  • Verbumは、設定されたプロバイダーおよび契約条件に従い、顧客の会話データがAIモデルのトレーニングやファインチューニングに使用されないよう設計されています。

Audit and workflow metadata

  • AIコンテキストは、顧客ワークスペースデータが分離された状態を保てるよう、関連するワークスペーススレッドにスコープされる設計です。
  • Verbum Assist Modeでは、AI生成コンテンツはそのモードで配信前の人間レビュー用ドラフトとして提示されます。Verbum Automate Modeでは、承認済みのルール、制限、ガードレール内でのみ自動送信できます。各アクションは記録されます。

Provider and retention context

  • Provider configuration and contractual terms can affect how AI data is handled, retained and protected where applicable.

Googleユーザーデータ

お客様は、Googleログイン(OAuth)を通じてGmailまたはGoogle WorkspaceのメールボックスをVerbumに接続できます。このセクションでは、VerbumがアクセスするGoogleデータ、その利用方法、共有先、保持期間、アクセスの取り消し方法を説明します。

接続とアクセスの取り消し

  • 接続はワークスペース管理者がGoogleの同意画面で作成します。VerbumがGoogleアカウントのパスワードを受け取ることはありません。
  • アクセスはいつでも Googleアカウントの権限ページ から、またはVerbumコンソールでメールチャネルを切断することで取り消せます。

アクセスするGoogleデータ

  • 接続したGoogleアカウントのメールアドレスとプロフィール名(openid、email、profileスコープ):接続されたメールボックスを識別し、どのアカウントがチャネルに紐づいているかを表示するために使用します。
  • 接続したメールボックスのメールメッセージ(ヘッダー、本文、添付ファイルを含む。gmail.modifyスコープ):Inboxで会話を表示し、同じメールボックスから返信を送信し、Verbumで開いたメッセージをGmailで既読にし、お客様が有効にした場合はAIによる分析と下書きを生成するために使用します。

Googleデータに対して行わないこと

  • Googleユーザーデータを販売しません。
  • Googleユーザーデータを広告目的で使用しません。
  • サービス運用に必要なサブプロセッサー(保存と処理のためのAWS、お客様がAI分析を有効にした場合のAIプロバイダー)を除き、Googleユーザーデータを第三者に転送しません。
  • Googleユーザーデータを、汎用的なAIまたは機械学習モデルの開発、改善、トレーニングに使用しません。
  • 人がGoogleユーザーデータを閲覧するのは、お客様の同意がある場合、サポートのため、セキュリティ上の目的、または法令で求められる場合に限ります。

保持と削除

  • 接続したメールボックスから取り込んだメッセージと添付ファイルは、チャネルが接続されている間、ワークスペースの保持設定に従って保存されます。
  • チャネルを切断すると、Googleのアクセストークンは取り消され、削除されます。
  • 取り込んだメッセージと添付ファイルの削除は、Contactページの法務/プライバシー経路を通じたお客様のリクエストに従います。

Limited Use(限定的な使用)に関する表明

Verbum's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

監査履歴とプライバシー

監査履歴は、誰がメッセージを下書き、レビュー、承認、自動化、送信したかをお客様が理解するために役立ちます。これらの記録は、ガバナンス、セキュリティレビュー、説明責任を支援します。

  • 承認、拒否、編集、自動化、配信イベントは、担当者、判断、タイムスタンプの文脈とともに記録される場合があります。
  • 監査レコードは、お客様のレビューと説明責任のため、イベント後もワークフローの文脈を保持するよう設計されています。
  • 監査エクスポートワークフローは、プランと設定で利用可能な場合にJSONまたはCSV形式をサポートすることがあります。
  • ログ保持期間はサブスクリプションプランの範囲内で設定可能です。

ワークスペースがエンドカスタマーに代わってメッセージを処理する場合、適用されるプライバシー法に基づきその処理の適法な根拠を確保する責任はお客様にあります。

共有とサブプロセッサー

お客様のデータを販売、賃貸、取引することはありません。プラットフォーム運営を支援する信頼できるサービスプロバイダーとのみ、厳格な契約上の義務の下でデータを共有します。

  • クラウドインフラプロバイダー: プラットフォーム運営のためのホスティング、ストレージ、データベースサービス。
  • AIモデルプロバイダー: ワークスペースのコンテキスト内でメッセージ下書きを生成するためにのみ使用。
  • 決済処理業者(Stripe): 請求とサブスクリプション管理。
  • 分析プロバイダー: 製品改善のみを目的とした匿名化された使用データ。

サブプロセッサーの概要については、サブプロセッサー一覧 をご覧ください。EnterpriseプランのチームはセキュリティまたはDPAレビュー時に追加情報をリクエストできます。重要なサブプロセッサーの変更については事前にお客様へ通知します。正式なDPA条件は法務承認と該当する契約スコープの対象です。お問い合わせフォームの法務/プライバシー経路よりレビューをリクエストしてください。

支払いデータ

Verbumは決済処理にStripeを使用しています。支払いカードデータをVerbumのサーバーに保存することはありません。

  • クレジットカードやデビットカードの番号は、第三者決済処理業者であるStripeが収集・保存します。
  • VerbumはStripe顧客ID、サブスクリプションプラン、請求連絡先メールアドレスなど非機密の請求識別子のみを保存します。
  • Stripeのプライバシーポリシーが決済データの取り扱いを規定しています。stripe.com/privacyでご確認ください。

CookieとAnalytics

認証、セッションセキュリティ、ユーザー設定、匿名化された使用状況分析のために限定的なCookieセットを使用します。

  • verbum-locale: Stores the selected public-site language preference in localStorage.
  • verbum-cookie-preferences: Stores the visitor's cookie preference-center choices in localStorage, including analytics and marketing status.
  • verbum-analytics-consent: Stores whether analytics consent has been accepted before optional analytics dispatch can run.
  • Stripe checkout cookies and similar technologies: Supports secure checkout and payment session continuity when checkout is opened.

Optional analytics runs only after consent and only when an approved provider is configured.

vrbm.appで使用されるCookieの詳細リストについては、 Cookieポリシー for the current inventory.

データ保持

サービス提供と法的要件を満たすために必要な期間のみデータを保持します。ワークスペースのほとんどの保持設定はお客様が管理できます。

The matrix below is a public overview for procurement and privacy review. Specific retention commitments may be defined by workspace settings, plan terms, an approved DPA, an order form or another written agreement.

Retention overview by data categoryDefault retention depends on the data category, customer configuration, plan terms and applicable legal or contractual requirements.
Data categoryPurposeDefault retentionControlDeletionNotes
Plan-level conversation historyProvide governed messaging, routing, review, delivery context and customer workflow history.Defined by workspace settings, plan terms, customer instructions, approved implementation scope or written agreement.Customers control business messaging data and workspace configuration; Verbum processes it to provide the service.Handled through workspace configuration, offboarding, customer instruction or verified request, subject to operational, legal and security constraints.Customers remain responsible for the lawful basis and retention choices for their own business messages.
Account dataCreate, authenticate, administer and support Verbum accounts and workspace membership.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls account administration data; customer administrators control workspace membership where applicable.Deleted, deactivated or minimized through account closure, verified privacy request or customer offboarding, subject to required records.Some references may remain where required for billing, security, dispute, legal or contractual purposes.
Contact, demo and signup leadsRespond to demo, signup, legal, privacy, security, procurement and support requests.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls public website and contact-form lead records.Deleted, suppressed or minimized after a verified privacy request unless retention is required for legal, security or dispute purposes.Lead records are separate from customer workspace message content.
Security logsProtect the platform, investigate abuse, monitor access and support incident response.Defined by approved security policy, applicable agreement, legal requirements and operational security needs.Verbum controls security logging required to protect the service.Deleted through log lifecycle controls when no longer required for security, legal or operational purposes.Security logs may be retained despite account deletion requests where necessary to protect the service or comply with law.
Billing recordsManage subscriptions, invoices, billing contacts, payment processor references and accounting obligations.Retained as required for tax, accounting, chargeback, legal, contractual or payment-processing obligations.Verbum controls billing metadata; Stripe handles full payment card data under its own terms.Removed or minimized when no longer required, subject to accounting, payment, legal and contractual retention requirements.Verbum does not store full payment card numbers on its servers.
BackupsSupport resilience, recovery and business continuity.Managed under approved operational backup lifecycle, infrastructure policy or applicable agreement.Verbum controls backup lifecycle and recovery processes.Deleted through backup lifecycle controls; immediate item-level deletion from backups may not be technically available.Restored data remains subject to the same deletion and retention rules after recovery.
Support and procurement communicationsRespond to support, legal, privacy, procurement, security and vendor review requests.Retention depends on the applicable agreement, customer instructions, legal requirements, security obligations and operational lifecycle.Verbum controls support, procurement and review communications submitted to Verbum.Deleted, minimized or archived through support lifecycle controls or verified privacy request where applicable.Security package, DPA review and vendor review materials may require confidentiality review or applicable agreement terms.

Deletion and retention requests are reviewed subject to applicable law, customer instructions, security obligations, backup lifecycle controls and the applicable agreement. This overview does not replace a signed DPA or order form.

データに関する権利

お客様の所在地によっては、個人データに関して特定の権利が認められる場合があります。これらの権利を尊重することをお約束します。

Privacy rights overviewRights availability depends on location, Verbum's role, data category and verification requirements.
RightWhat it meansHow to request
アクセス権Verbumが保有するお客様の個人データのコピーをリクエストできます。Use the legal/privacy path on the Contact page; verification may be required.
訂正権不正確な個人データの訂正をリクエストできます。Use the legal/privacy path on the Contact page; verification may be required.
消去権法的な保持要件に従い、個人データの削除をリクエストできます。Use the legal/privacy path on the Contact page; verification may be required.
データポータビリティ権機械読み取り可能な形式でのデータエクスポートをリクエストできます。Use the legal/privacy path on the Contact page; verification may be required.
異議申し立て権正当な利益に基づく処理に異議を申し立てることができます。Use the legal/privacy path on the Contact page; verification may be required.
処理制限権特定の状況においてデータの処理方法を制限するよう求めることができます。Use the legal/privacy path on the Contact page; verification may be required.

これらの権利を行使するには、Contactページの法務/プライバシー経路をご利用ください。確認済みのリクエストには、適用法と確認要件に従って対応します。

国際的なデータ転送

Verbumはお客様の国外に所在する可能性のあるクラウドインフラで運営されています。転送の詳細は、お客様の構成、プロバイダー、適用されるデータ保護要件によって異なる場合があります。

  • 必要な場合、適切な転送メカニズムはDPAまたはEnterpriseセキュリティレビューで確認できます。
  • データ所在地要件は、構成とプロバイダーの可用性でサポートされる場合にEnterpriseプランでレビューできます。
  • 国際転送の文脈は、データ処理およびセキュリティ資料を通じて確認できます。

セキュリティ

お客様のデータを不正アクセス、紛失、悪用から保護するための技術的・組織的措置を実施しています。

  • 転送中のデータはTLSで保護されます。保存時の暗号化は、該当するプラットフォームストレージについて文書化されます。
  • 顧客データへのアクセスはロールベースのアクセス制御(RBAC)によって制限され、認証が必要です。
  • 文書化されたインシデント対応プロセスを運用しています。個人データに影響するインシデントが発生した場合、適用法および契約上の義務に従って影響を受けたお客様に通知します。
  • セキュリティ脆弱性の報告はお問い合わせフォームのセキュリティ経路をご利用ください。セキュリティ対応プロセスに沿って確認します。

完全に安全なシステムはありません。Verbumアカウントでは強力なパスワードの使用とMFAの有効化をお勧めします。

子どものプライバシー

Verbumはエンタープライズチーム向けのBtoBプラットフォームであり、16歳未満の個人を対象としていません。

16歳未満の方から意図的に個人データを収集することはありません。未成年者がVerbumに個人データを提供したと思われる場合は、Contactページの法務/プライバシー経路からご連絡ください。リクエストを確認します。

本ポリシーの変更

プラットフォームや法的要件の変更に伴い、このプライバシーポリシーを更新することがあります。

お問い合わせ

このプライバシーポリシーまたはVerbumのデータ取り扱いについてご質問がありますか?

プライバシーまたはデータ保護に関するリクエストは、Contactページの法務/プライバシー経路からVerbumにお問い合わせください。

プライバシーについてのご質問は?

Verbumチームにお問い合わせください。

プライバシーに関するすべてのお問い合わせに1営業日以内にお答えします。