Privacy Policy (APPI – Japan)
Last updated:
This Privacy Policy explains how C & M Navigation Systems (“we”, “us”, “our”) handles personal information in accordance with the Act on the Protection of Personal Information (APPI) of Japan. It describes what we collect, how we use and share it, international transfers, security measures, and the rights available to individuals in Japan.
1. Personal Information Handling Business Operator
Operator: C & M Navigation Systems
Address: PO BOX 31, Pontefract, United Kingdom
Website: https://cmnav.co.uk
Email (Contact point): contact@cmnav.co.uk
Telephone: 07533088132
We designate the above contact point for inquiries, complaints, and requests under APPI. We are not obliged to appoint a Data Protection Officer under APPI; if this changes, we will update this policy.
2. Scope
This policy applies to personal information we handle in connection with individuals located in Japan when they visit our website, make enquiries, purchase products, or receive support. It covers data collected directly (e.g., forms, checkout), automatically (e.g., cookies, logs, analytics), and from service providers where relevant.
3. Key definitions
Personal information: information about a living individual that can identify the person (e.g., name, email, address, identifiers), including personal identification codes, as defined in APPI.
Personal data: personal information constituting a personal information database, etc., as defined in APPI.
Anonymously processed information: information processed so individuals cannot be identified and cannot be restored.
Pseudonymously processed information: information processed so individuals cannot be identified unless combined with additional information kept separately.
Entrustment: sharing personal data with a service provider that processes it on our behalf under our instructions.
Third-party provision: providing personal data to a third party for their own purposes (not as our entrusted processor).
4. Information we collect
4.1 Provided by you
- Identity and contact details (name, email, phone, billing and delivery address).
- Account details (if you register), passwords (hashed), preferences.
- Order details, enquiries, and support communications.
- Marketing preferences (subscriptions, opt-outs).
4.2 Collected automatically
- IP address, device identifiers, browser/OS, language, referral URLs.
- Pages viewed, timestamps, session duration, diagnostic logs.
4.3 From service providers
- Payment/fraud-prevention data from payment processors (e.g., Shopify Payments, PayPal).
- Delivery and tracking updates from couriers (e.g., Royal Mail).
- Platform analytics and ecommerce platform data relevant to your transactions.
5. Purposes of use
We handle personal information for the following purposes and will not use it beyond these without your consent unless permitted by APPI:
- Providing our website and services; processing orders, payments, delivery, returns, and support.
- Account creation and management; customer communications.
- Preventing fraud and misuse; ensuring security and reliability of our systems.
- Improving products, services, and user experience (including quality assurance and analytics).
- Sending information about our products/services and promotions where permitted; respecting your opt-out choices.
- Complying with laws, regulations, and requests from competent authorities.
If we change a purpose in a manner that is reasonably considered related to the original purpose, we may continue to use the data. Otherwise, we will obtain consent before new uses, as required by APPI.
6. Cookies & similar technologies
We use cookies and similar technologies (e.g., pixels, local storage) for essential functionality (security, checkout), preferences, performance/analytics, and—where you agree—marketing. On first visit you can accept or reject non-essential cookies. You can change settings anytime via our cookie banner or your browser. See our Cookie Policy for details.
7. Entrustment, third-party provision & records
Entrustment (processors). We may entrust personal data to service providers (hosting/ecommerce platform, payments, fraud screening, couriers, analytics, communications). We instruct them by contract to handle data securely and only for our purposes.
Third-party provision. We do not sell personal data. If we provide personal data to third parties for their own purposes, we will obtain your prior consent or rely on another APPI-permitted ground and will keep required records. Where we adopt an opt-out scheme permitted by APPI, we will publicly announce the categories of data provided, the method of provision, the means to stop provision, and we will conduct required filings.
Business transfers. In case of merger, acquisition, or transfer of business, personal data may be transferred as permitted by APPI, continuing the existing purposes of use.
Legal requests. We may disclose information if required by laws or necessary to protect rights, property, or safety, consistent with APPI.
8. International transfers outside Japan
When we provide personal data to third parties or entrust processors located in foreign countries, we will:
- Obtain your prior consent after providing information on the foreign country’s personal information protection systems and the recipient’s measures; or
- Ensure the recipient continuously implements measures equivalent to APPI by contract or other arrangements and provide information on such measures upon request; or
- Rely on other APPI-permitted exceptions where applicable.
Upon request, we will provide details of the foreign country/region, the recipient category, and safeguards in place to protect your personal data.
9. Retention
We retain personal data only as long as necessary for the purposes above and for legal/accounting obligations. Typical periods:
- Order records: generally up to 7 years (tax/accounting).
- Support correspondence: typically up to 3 years after resolution, unless needed longer for disputes or legal obligations.
- Analytics data: kept for shorter periods where feasible and aggregated/anonymised where possible.
Data that is no longer needed is securely deleted or irreversibly anonymised.
10. Security measures (outline)
We implement appropriate security controls to prevent leakage, loss, or damage of personal data, including:
- Organisational: governance policies, role-based access, vendor due diligence, incident response procedures.
- Personnel: confidentiality obligations and awareness training for staff handling personal data.
- Physical: restricted access to facilities and devices, secure storage and disposal.
- Technical: encryption in transit, access controls, logging/monitoring, backups, vulnerability management.
- External environment: when data is handled in foreign countries, we assess the local legal environment and apply appropriate safeguards as per APPI.
11. Minors
Our services are intended for general audiences. Where we rely on consent and the individual is a minor under Japanese law (generally under 18; for certain online contracts under 20), we will seek consent or authorisation from a legal guardian, as applicable.
12. Requests for disclosure, correction, cessation of use, etc.
Individuals in Japan have the following rights under APPI regarding retained personal data:
- Disclosure of retained personal data and records of third-party provision.
- Correction, addition, or deletion where data is inaccurate.
- Cessation of use or erasure where data is handled beyond stated purposes, obtained improperly, or where a leak or similar incident has occurred and rights/interests may be harmed.
- Cessation of third-party provision in certain circumstances.
To make a request, contact us at contact@cmnav.co.uk. We will respond without delay in accordance with APPI, after verifying your identity. We may decline requests where a statutory ground applies and will provide reasons. A reasonable fee may be charged where permitted by law.
13. Anonymously & pseudonymously processed information
Anonymously processed information. If we create or receive anonymously processed information, we will publish the items of information included, take security measures to prevent re-identification, and not attempt to re-identify individuals or combine datasets to do so. When providing such information to a third party, we will disclose the items and the provision method.
Pseudonymously processed information. Where we use pseudonymously processed information, we manage the linking information separately with strict controls, limit internal use, and will not use it to identify individuals unless permitted by APPI.
14. Links to other sites
Our website may contain links to third-party sites or services. Their handling of personal information is governed by their own policies.
15. Changes to this policy
We may revise this policy to reflect operational or legal changes. Material changes will be announced on this website and, where appropriate, notified directly. The “Last updated” date indicates the latest revision.
16. Contact point & supervisory authority
Questions, complaints, or requests under APPI:
Email: contact@cmnav.co.uk
Address: C & M Navigation Systems, PO BOX 31, Pontefract, United Kingdom
Telephone: 07533088132
If you are not satisfied with our response, you may contact the Personal Information Protection Commission (PPC): https://www.ppc.go.jp/.
This policy is intended to meet transparency obligations under the Act on the Protection of Personal Information (APPI). It should be read alongside our Terms & Conditions and Cookie Policy.