1. 事業者情報
オミコア株式会社(以下「当社」といいます)は、本サイト(https://omi-core.com 及び
https://genom.omi-core.com)の運営者であり、本ポリシーに基づき個人情報を適切に取り扱います。
お問い合わせ先: [email protected]
2. 取得する情報
- お問い合わせフォーム経由: 氏名、メールアドレス、組織名、ご質問の種類、ご質問内容、送信時刻、送信元 IP アドレス
- 認証経由(科学ツール利用時): ログインに使用したメールアドレス、ログイン日時、IP アドレス、ロール(admin / user)
- 科学ツール利用ログ: ジョブ ID、入力された遺伝子記号、ジョブの実行結果(誰がいつ何を投入したかの監査記録)
- Cookie: Cloudflare Access の認証セッション Cookie(
CF_Authorization)、アプリケーションのセッション Cookie。アクセス解析・広告 Cookie は一切使用しません
3. 利用目的
- お問い合わせへの返答・ご連絡
- 科学ツールの認証・認可・不正アクセス防止
- ジョブ実行履歴の保管とユーザーへの結果提供
- システムの安全運用、障害対応、不正利用調査のための監査ログ保持
4. 第三者提供
取得した個人情報を第三者に提供することは原則ありません。ただし、サービス運営のため次の 処理委託先 を利用しており、これらは個人情報保護法上の「委託」に該当します:
- Cloudflare, Inc.(米国)— CDN・通信トンネル・認証エッジ(DNS / TLS / Zero Trust Access)
- Zoho Corporation(インド・日本)— メール送受信(
[email protected]の SMTP / IMAP)
上記委託先には、当該業務遂行に必要な範囲でのみ個人情報を取り扱わせ、適切な監督を行います。 それ以外の目的での第三者提供は、ご本人の同意がある場合または法令に基づく場合を除き行いません。
5. 安全管理措置
- 全通信を TLS で暗号化
- 本番認証は Cloudflare Access (Zero Trust) による多要素相当の認証
- パスワードは Argon2 アルゴリズムでハッシュ化保存(平文保存しない)
- 管理画面へのアクセスは事前承認制(限定された管理者メールのみ)
- サーバはオンプレミス運用、データベースはローカル NVMe に保存、外部送信なし
- 監査ログによる管理操作・ログイン履歴の記録
6. 保管期間
- お問い合わせ: 対応完了後、原則 2 年間保管(または削除請求時まで)
- ジョブ実行履歴 / ジョブ成果物: 7 日間保管後、自動削除(
JOB_RETENTION_DAYS) - 監査ログ: 原則 1 年間保管
- データベースバックアップ: 直近 14 世代を保管
7. 開示・訂正・削除等のご請求
ご自身の個人情報について、開示・訂正・追加・削除・利用停止・第三者提供停止のご請求が可能です。 [email protected] までご連絡ください。ご本人確認のうえ、合理的な期間内に対応いたします。
8. Cookie の利用
本サイトでは、必要最低限の機能 Cookie のみを使用します(認証セッション維持等)。トラッキング Cookie・アクセス解析 Cookie・広告 Cookie は使用しません。
9. お子様の個人情報
本サービスは 16 歳未満の方を対象としていません。意図せず取得した場合は速やかに削除します。
10. 国際的データ移転
Cloudflare の通信処理および Zoho のメール処理に際し、データが日本国外の処理拠点を経由する場合があります。 各社は GDPR / APPI に準拠した標準的契約条項またはそれに相当する保護策を講じています。
11. 本ポリシーの改定
本ポリシーは予告なく改定されることがあります。重要な変更がある場合は本ページ上部の「最終改定」日を更新します。
12. お問い合わせ・苦情の申出先
本ポリシー及び個人情報の取扱いに関するお問い合わせ・苦情は、[email protected] までお寄せください。
1. Operator
OmiCore Inc. (the "Company"), operator of https://omi-core.com and
https://genom.omi-core.com, handles personal information in accordance
with this policy. Contact: [email protected]
2. Information We Collect
- Via the contact form: name, email, organization, topic, message, submission timestamp, source IP address.
- Via authentication (when using the scientific tools): login email, login timestamp, IP address, role (admin / user).
- Tool-use logs: job IDs, submitted gene symbols, job outcomes, and audit records of who submitted what and when.
- Cookies: Cloudflare Access authentication session cookie (
CF_Authorization) and application session cookie. No analytics or advertising cookies are used.
3. Purpose of Use
- Responding to inquiries.
- Authenticating and authorizing access to the scientific tools and preventing unauthorized access.
- Retaining job execution history and delivering results to the submitting user.
- Operating the system safely, responding to incidents, and conducting abuse investigations via audit logs.
4. Third-Party Sharing
We do not share personal information with third parties for marketing or unrelated purposes. We do entrust limited processing to the following service providers (data processors under APPI):
- Cloudflare, Inc. (USA) — CDN, tunnel, and authentication edge (DNS / TLS / Zero Trust Access).
- Zoho Corporation (India / Japan) — Email send/receive for
[email protected].
These processors handle only what is necessary for the contracted task and are supervised by us.
5. Security Measures
- All traffic is encrypted with TLS.
- Production authentication is Cloudflare Access (Zero Trust) with email-OTP / SSO.
- Passwords are hashed with Argon2 (never stored in plaintext).
- Administrative access is allow-listed to a small number of pre-approved emails.
- Servers are operated on-premises; data resides on local NVMe; no external transmission for primary workloads.
- Audit logs record administrative actions and login events.
6. Retention
- Inquiries: retained for 2 years after the matter is resolved (or until deletion is requested).
- Job records and outputs: retained for 7 days, then auto-deleted (
JOB_RETENTION_DAYS). - Audit logs: retained for 1 year.
- Database backups: most recent 14 daily snapshots.
7. Your Rights
You may request disclosure, correction, addition, deletion, suspension of use, or suspension of third-party sharing of your personal information by contacting [email protected]. We will respond within a reasonable period after verifying your identity.
8. Cookies
Only strictly-necessary functional cookies are used (authentication session). No tracking, analytics, or advertising cookies.
9. Children's Data
This service is not intended for individuals under 16. Any personal information unintentionally collected from such individuals will be deleted promptly.
10. International Data Transfer
Through Cloudflare and Zoho, data may transit processing locations outside Japan. Both providers offer protections consistent with GDPR / APPI standards via standard contractual clauses or equivalent safeguards.
11. Updates to This Policy
This policy may be updated without prior notice. The "Last updated" date at the top of this page reflects material changes.
12. Contact and Complaints
For questions or complaints concerning this policy or our handling of personal information, please contact [email protected].