Privacy Policy
The personal information protection policy of Seirai Group Japan Ltd.: how we handle the personal information entrusted to us.
This English text is a translation for reference. If the Japanese and English versions differ, the Japanese version prevails.
Seirai Group Japan Ltd. (the "Company", "we" or "us") handles the personal information of guests, business partners and others in the course of its business, including the operation of accommodation under the ACOE brand. We comply with the Act on the Protection of Personal Information (the "Act"), other applicable laws and regulations, and the guidelines of the Personal Information Protection Commission, and handle personal information as set out below.
Basic policy
Our management philosophy is "Keeping the promise is how we earn trust." We regard the proper handling of the personal information entrusted to us as a foundation of that trust, and adopt the following policy.
1. Compliance: We comply with the Act and other applicable laws, regulations and guidelines.
2. Proper acquisition and use: We acquire personal information by proper means and use it only within the purposes of use we have specified in advance.
3. Security: We take necessary and appropriate security measures to prevent the leakage, loss or damage of personal information.
4. Supervision of contractors: When we entrust the handling of personal information to others, we supervise them as necessary and appropriate.
5. Requests and complaints: We respond to requests for disclosure and other requests, complaints and enquiries in accordance with the law.
6. Review and improvement: We review and improve our handling of personal information as necessary.
1. Personal information we acquire
We acquire the following personal information by proper means.
(1) Guests
For guests staying at accommodation we operate, we acquire the following information.
• Reservation details: name, email address, telephone number, dates of stay, number of guests, reservation number, booking channel, etc.
• Guest register details: the items that applicable laws require to be recorded in the guest register (name, address, contact details and, for foreign nationals with no address in Japan, nationality and passport number, etc.)
• A copy of the passport (for foreign nationals with no address in Japan)
• Stay details: check-in and check-out records, the content of enquiries and messages before, during and after the stay, requests, information about lost property, etc.
• Payment information: records of payments and refunds and similar information (payment is made through booking sites or payment services, and we do not keep card numbers)
• Questions asked on in-room tablets and in the online guidebook, and security camera footage (only at the entrances and similar areas of properties where cameras are installed), and similar information
We acquire this information directly from guests or through booking sites and other booking channels. Information about accompanying guests (including children) may be provided by the lead guest who made the booking. Information acquired through a booking site is also handled in accordance with that site's terms.
(2) People who contact us by email
The name, email address, organisation, content of the enquiry and any other information included in the email.
(3) Business partners and property owners
For business partners (including clients of our hotel consulting services) and their staff, and the owners of properties we operate as accommodation: name, company name, department, job title, contact details, information about the property, and information needed for contracts, invoicing and payment (such as bank account details).
(4) Job applicants
Name, date of birth, address, contact details, education and employment history, information in CVs and other application documents, information obtained during selection, and, on hiring, a copy of the residence card to confirm residence status (except for Japanese nationals)
The personal information of our employees is handled under our internal rules, separately from this policy.
Special care-required personal information
Except where permitted by law, we do not acquire special care-required personal information (personal information specified by law as requiring special care in its handling, such as race, creed, social status and medical history) without the prior consent of the individual.
2. Purposes of use
We use the personal information we acquire within the following purposes. Except where permitted by law, we do not use it beyond these purposes without the individual's consent.
(1) Guests
• To accept, confirm, change and cancel reservations
• To prepare and keep the guest register and otherwise meet our legal obligations
• To handle check-in
• To provide information needed for the stay, including how to enter the accommodation
• To respond to enquiries and requests before, during and after the stay
• To invoice, settle charges and make refunds
• To operate the accommodation, including cleaning, inspection and handling lost property
• To contact guests and respond if an accident, a problem, damage to the facilities or a similar event occurs
• To improve the quality of our services
• To ask for your feedback or a review after your stay
(2) People who contact us by email
• To reply to enquiries and make any contact needed for that purpose
• To keep a record of enquiries and our responses
(3) Business partners and property owners
• To respond to consultations about the operation of accommodation
• To provide consulting services
• To conclude and perform contracts
• To report on operations
• To invoice and make payments
• To make other contact needed for our business
(4) Job applicants
• To carry out recruitment selection and related contact
• To complete employment procedures after a hiring decision
Retention
We keep personal information for the period needed to achieve the purposes of use and for any period required by law, and then erase or dispose of it by appropriate means. The guest register is kept for three years from the date it is made, as required by law.
3. Provision to third parties
Except in the following cases, we do not provide personal data to third parties without the prior consent of the individual.
1. Where the provision is based on laws or regulations (for example, responding to an enquiry made under the law by an investigative authority)
2. Where necessary to protect a person's life, body or property and it is difficult to obtain the individual's consent
3. Where especially necessary to improve public health or to promote the healthy development of children and it is difficult to obtain the individual's consent
4. Where necessary to cooperate with a national government body, a local government or a person entrusted by either of them in carrying out duties prescribed by law, and obtaining the individual's consent would be likely to impede those duties
5. Other cases permitted by the Act
The following do not constitute provision to a third party. However, where we entrust the handling of personal data to a business in a foreign country, section 5 applies.
• Entrusting the handling of personal data within the scope necessary to achieve the purposes of use (see section 4)
• Provision in connection with the succession of a business as a result of a merger or otherwise
• Joint use: at accommodation that we run on behalf of a property owner, we jointly use personal data as follows. (a) Items: name, address, contact details, dates of stay, number of guests and the other items in the guest register. (b) Joint users: the owner of that property. (c) Purposes: preparing and keeping the guest register and other steps required by law, and running and managing the property. (d) Party responsible: the Company (name, address and representative as in section 9).
4. Entrustment
We may entrust all or part of the handling of personal data to external businesses within the scope necessary to achieve the purposes of use. When we do so, we select businesses that handle personal information appropriately, set out the matters necessary for its security in contracts or otherwise, and supervise them as necessary and appropriate.
The main categories of entrustment are as follows.
• Reservation and room management systems (including the exchange of reservation data with booking sites)
• Email, document, spreadsheet and other business cloud services
• The infrastructure on which online check-in and our other business systems run (server, database and file storage services)
• AI services used to answer guests' questions, draft replies and translate (used under contracts or settings that keep the information entered from being used to train the AI)
• Messaging services used for communication between staff
• Payment services
• Contractors for cleaning, linen and similar work (where this work is outsourced)
• Tax accountants and other professionals
Booking sites are not our contractors. Information held by each booking site is handled under that site's own terms.
5. Provision of personal data to third parties in foreign countries
Some of the contractors described in section 4 are located outside Japan, and personal data may be handled in a foreign country.
• Countries: mainly the United States (a list of the countries is available on request)
• Contractors: providers of cloud, AI and messaging services (their names are available on request)
When we entrust the handling of personal data to a business in a foreign country, we ensure by contract or similar means that the business has a system that meets the standards set by the rules of the Personal Information Protection Commission, and take the steps needed to ensure that equivalent measures continue to be taken. On request, we will provide information about those steps.
6. Security measures
We take the following measures to prevent the leakage, loss or damage of personal data and otherwise to keep it secure.
1. Basic policy: We have established this policy to ensure the proper handling of personal data.
2. Handling rules: We have set rules covering the methods of handling, the persons responsible and in charge, and their duties, at each stage of acquisition, use, storage, provision, deletion and disposal.
3. Organisational measures: We have appointed a person responsible for the handling of personal data, defined which employees handle personal data and the scope of the data they handle, and set up a reporting line for any fact or sign of a breach of the law or our rules. We check how personal data is handled regularly.
4. Human measures: We train employees regularly on points to note in handling personal data, and set out confidentiality obligations concerning personal data in our work rules or similar documents.
5. Physical measures: In areas where personal data is handled, we control employees' entry and exit and restrict the equipment brought in, and take steps to prevent unauthorised persons from viewing personal data. We take steps to prevent the theft or loss of equipment, electronic media and documents that contain personal data, and to ensure that personal data cannot easily be revealed when they are carried, including within our premises. Guest registers and passport copies are kept as electronic data in systems that only authorised staff can open.
6. Technical measures: We control access so as to limit the persons who handle personal data and the scope of the databases they handle. We have introduced systems to protect the information systems that handle personal data from unauthorised external access and malicious software, and we encrypt communications.
7. Understanding the external environment: We handle personal data in the United States and other countries. We take security measures after understanding those countries' systems for the protection of personal information.
Where a leak or other incident involving personal data occurs and falls within the cases specified by law, we report it to the Personal Information Protection Commission and notify the individuals concerned, in accordance with the law.
7. Requests for disclosure, correction, suspension of use, etc.
You, or your representative, may make the following requests concerning our retained personal data, as provided in the Act.
• Notification of the purposes of use
• Disclosure (including provision as an electronic record)
• Disclosure of records of provision to third parties
• Correction, addition or deletion of content
• Suspension of use or erasure
• Suspension of provision to third parties
(1) How to make a request
Please contact the contact point in section 9 by email, and we will explain our procedure.
(2) Identity verification
To confirm your identity, we will ask you to submit a copy of a driving licence, passport or other identity document. If a representative makes the request, please also submit a letter of authorisation (or, for a legal representative, a document proving that status) and a copy of the representative's own identity document. If a document you submit shows an Individual Number (My Number), please cover that number before submitting it. Please send the copies by the method we tell you.
(3) Fees
We charge no fee for requests for notification of the purposes of use or for disclosure (including disclosure of records of provision to third parties).
(4) How we respond
In accordance with the law, we respond by the method you specify (such as provision of an electronic record or delivery of a document). Where disclosure by that method would involve considerable cost or is otherwise difficult, we respond by delivering a document.
(5) Where we may be unable to comply
We may be unable to comply with all or part of a request for disclosure in the following cases.
• Where compliance is likely to harm the life, body, property or other rights or interests of you or a third party
• Where compliance is likely to seriously interfere with the proper conduct of our business
• Where compliance would violate other laws
We may be unable to comply with a request for correction, suspension of use or the like where the requirements set by law are not met. If we do not comply with all or part of a request, we will notify you of that and the reasons.
Because the law requires the guest register to be kept, we may be unable to erase it during the retention period. For information held by a booking site, please contact that booking site.
8. Cookies and access logs (this website)
This section covers our website (https://seiraigroup.jp/, the "Website").
• The Website has no forms. If you contact us by email, we handle the information as described in sections 1(2) and 2(2).
• The Website does not set any cookies of its own and, as at the date this policy was established, uses no analytics or advertising tools. If we introduce any, we will revise this section.
• For display purposes, the Website stores two values in your browser's temporary storage (session storage): whether the opening animation has already been shown, and whether you have paused the video on the home page. These values are not sent anywhere and are normally deleted when you close the browser tab or window.
• The Website is published using a service provided by GitHub Pages (GitHub, Inc., United States). The hosting provider's servers may record access logs, including visitors' IP addresses, for purposes such as security. These logs are handled under the provider's own privacy policy. We do not receive these access logs.
• The Website links to external sites, such as the official ACOE website, Instagram and TikTok. Personal information on those sites is handled under the terms of each site's operator.
9. Company information and contact point
Please send questions, complaints and enquiries about our handling of personal information, and requests for disclosure and the like, to the contact point below. We ask that you contact us by email.
• Name: Seirai Group Japan Ltd. (株式会社セイライグループジャパン)
• Address: Iidabashi Grand Bloom 9F, 2-10-2 Fujimi, Chiyoda-ku, Tokyo 102-0071, Japan
• Representative: ASAWA SIRIKAN, Representative Director
• Corporate Number: 5011103009014
• Email: office@seiraigroup.com
• Person responsible for personal information: Representative Director
• Accredited personal information protection organisation: We are not a covered business of any accredited personal information protection organisation.
10. Revisions
We may revise this policy in response to changes in the law, changes in our business or as otherwise necessary. Unless otherwise stated, a revised policy takes effect when it is posted on the Website. However, where the law requires the individual's consent for a change, we will obtain that consent.
Dates
• Established: 1 October 2026