Privacy policy
Dr. Bank Corporation (hereinafter referred to as "the Company") hereby establishes this Privacy Policy (hereinafter referred to as "this Policy") regarding the handling of personal information, including sensitive personal information, in its provided image diagnostic lounge service (hereinafter referred to as "the Service").
1. DefinitionsIn this Policy, "personal information" refers to what is defined as "personal information" under the Personal Information Protection Law. This includes information about a living individual that contains names, birth dates, addresses, phone numbers, contact information, and other descriptions which can identify the specific individual, as well as data related to physical features, fingerprints, voiceprints, and information such as the insurer number on health insurance cards that can identify a specific individual from the information alone (personal identification information).
2. Collection of User Information and Methods
The information regarding individuals subject to image diagnosis (hereinafter referred to as "diagnostic subject information") and information regarding the users of the Service (hereinafter referred to as "user information") collected by the Company in the Service are classified and collected according to the following methods and entities.
|
Category |
Diagnostic Subject Information |
User Information |
User Information |
|
Collection Method |
Provided by User |
Provided by User |
Provided by the Company's Partners |
|
Entity |
Diagnostic Subject |
User |
User |
|
Collected Information |
- Information related to the body such as gender, age, height, weight, blood pressure, etc. - Information related to medical history, visit history, etc. - Medical image information such as X-rays, CT, MRI, PET-CT, etc. - Other medical information |
- Information related to profile such as name, date of birth, gender, occupation, etc. - Contact information such as email addresses, phone numbers, addresses, etc. - Information related to payment methods such as credit card information, bank account information, e-money information, etc. - Information entered or transmitted by users through input forms or other methods determined by the Company |
- Transaction records - Information related to payment - Referrer (source web page) - IP address - Server access log information - Cookies, ADID, IDFA, and other identifiers |
3. Purpose of Use
The specific purposes of using the diagnostic subject information and user information related to the provision of the Service are as follows.
|
Category |
Purpose of Use |
|
Diagnostic Subject Information |
For conducting image diagnosis under the Service on behalf of the users |
|
User Information |
(1) For registration acceptance, identity verification, user authentication, user settings recording, payment of usage fees, etc., for the provision, maintenance, protection, and improvement of the Service (2) For measuring user traffic and behavior (3) For delivering, displaying, and measuring the effectiveness of advertisements (4) For responding to inquiries and notifications related to the Service (5) For addressing actions that violate the terms and policies of the Service (hereinafter referred to as "Terms and Policies") (6) For notifying users of changes to the Terms and Policies related to the Service (7) To allow users to view, modify, delete their registration information and view their usage status (8) For purposes incidental to the above purposes of use |
Users can request the suspension of collection or use of all or part of the diagnostic subject information and user information by making the settings specified in the Service. In such cases, the Company will promptly stop the use of information in accordance with the procedures established by the Company. However, for certain types of information, the nature of which is fundamental to the Service, the Company will stop the collection or use of such information only if the user withdraws from the Service in a manner prescribed by the Company.
5. Provision to Third Parties5-1 The Company will not provide diagnostic subject information to third parties (including those outside of Japan, hereinafter the same) without prior consent of the diagnostic subject and the medical institution to which the user belongs. The consent of the diagnostic subject will be obtained through the user.
5-2 The Company will not provide personal information contained in user information to third parties without prior consent of the user. However, the following are exceptions where the Company may provide personal information to third parties:
(1)When the Company delegates the handling of personal information, in whole or in part, within the scope necessary to achieve the purpose of use (in this case, the Company will impose a duty of confidentiality on such third parties)
(2)In case of business succession due to merger or other reasons where personal information is provided
(3)When personal information is provided to partners
(4) When the Company is requested to cooperate by national institutions or local public entities or their delegates in performing tasks prescribed by laws, and obtaining user consent would impede the execution of such tasks
(5)When necessary for the protection of human life, body, or property, and it is difficult to obtain user consent
(6)Other cases permitted under the Personal Information Protection Law and other laws
6. Disclosure of Personal InformationThe Company will disclose personal information without delay upon request from the user or diagnostic subject, after verifying that the request is from the individual, in accordance with the provisions of the Personal Information Protection Law (if the personal information does not exist, the Company will notify as such). However, in the following cases, the Company may not disclose all or part of the information, and will promptly notify the requester if it decides not to disclose:
(1)If there is a risk of harming the life, body, property, or other rights and interests of the individual or a third party
(2) If there is a risk of significant impediment to the proper execution of the Company's business
(3)If it would violate other laws
(4) If the Company is not obligated to disclose under the Personal Information Protection Law or other laws
7. Correction and Suspension of Use of Personal Information7-1 In cases where a user or a diagnostic subject requests the correction of their personal information on the grounds that it is not accurate, or requests the suspension of its use because it is being handled beyond the scope of the publicly announced purposes or collected by deceit or other wrongful means, the Company, upon confirming that the request is made by the user or the diagnostic subject themselves, will promptly conduct the necessary investigations. Based on the results, the Company will correct the content of the personal information or suspend its use and notify the user or the diagnostic subject of this action. If a decision is made not to correct or suspend the use, the Company will also notify the user or the diagnostic subject of this decision.
7-2 If a user or a diagnostic subject requests the deletion of their personal information, and the Company deems it necessary to comply with the request, upon confirming that the request is made by the person themselves, the Company will delete the personal information and notify the person of this action.
7-3 Provisions of 7-1 and 7-2 do not apply in cases where the Company is not obligated to correct, suspend the use, or delete personal information under the Personal Information Protection Law or other laws and regulations.
8. Inquiries
For inquiries, opinions, questions, complaints, or any other matters related to the handling of diagnostic subject information or user information, please contact us through the inquiry form.
9. Changes to the Privacy PolicyThe Company may amend this Policy as necessary. However, any changes to this Policy that require the user's consent under the law will only apply to users who have agreed to the changes through the Company's prescribed method. When the Company amends this Policy, it will make the implementation date and details of the amended Policy known by displaying it on the Company's website or through other appropriate methods, or by notifying the users.
[Established on November 11, 2023]