1. Introduction
3H Medi Solution Co., Ltd. (“3H”, “we”, “our”, or “us”) is a healthcare company dedicated to connecting people’s health and well-being. We operate services including:
- Patient recruitment for clinical trials and research
- Healthcare media platforms
- Life sciences research and data services
- System development and operation
- Personal Health Record (PHR) utilization in clinical practice and trials
- Contract research and site support services
In the course of our business, we handle personal information, including sensitive health-related data, of:
- Service users and members
- Business partners
- Individuals using our services and platforms
- Other stakeholders
We recognize that personal information belongs to the individual and is entrusted to us. We are committed to protecting it through appropriate governance and safeguards.
2. Scope of Individuals Covered
This Policy applies to all individuals whose personal data we process, including:
- Registered users and service participants
- Representatives (e.g., parents/guardians or legal proxies acting on behalf of individuals)
- Business contacts and partners
- Employees, officers, and job applicants
3. Collection and Use of Personal Information
We collect personal information through lawful and fair means and use it only within the scope of specified purposes.
3.1 Purposes of Use
(A) Life Sciences Services
- Operation and management of websites and applications
- Recruitment and management of clinical trial participants
- Eligibility screening and communication
- Payment of stipends or reimbursements
- Provision of healthcare-related information
- Responding to inquiries and requests
- Conducting surveys and research
- Providing information about relevant products/services (including third-party offerings)
- Statistical analysis and service improvement
(B) Business Activities
- Business communications and inquiries
- Contract negotiation and execution
- Service delivery and partner coordination
(C) HR and Recruitment
- Recruitment screening and hiring processes
- Employment administration and payroll
- Training, welfare, and compliance management
(D) Call Recordings
- Ensuring accuracy of communications
- Quality control and service improvement
4. Legal Basis and Compliance
We comply with:
- Applicable data protection laws (including Japan’s Act on the Protection of Personal Information – APPI)
- Government guidelines and industry standards
- ISO/IEC 27701 (Privacy Information Management System)
We maintain internal policies and ensure employees have access to updated legal and regulatory requirements.
5. Data Sharing and Third-Party Provision
We may provide personal data to third parties in the following cases:
5.1 With User Consent
- Medical institutions, research organizations, and sponsors for clinical trial participation
- Service providers supporting healthcare services
- Insurance providers (when requested by the user)
5.2 Legal or Safety Requirements
- When required by law
- When necessary to protect life, health, or property
We do not share personal data without consent unless legally permitted.
6. Joint Use of Personal Data
We may jointly use personal data with affiliated companies, including:
Shared Data Includes:
- Contact information
- Health and clinical data
- Service usage and participation history
Purpose:
- Service delivery and improvement
- Research and analytics
- Communication and notifications
7. Outsourcing
We may outsource data processing to third-party vendors within the scope of intended use.
- Vendors are selected through strict evaluation
- Contracts ensure appropriate data protection standards
- Ongoing supervision is conducted
8. Security Measures
We implement appropriate technical and organizational safeguards, including:
- Access controls and authentication
- Encryption and system security measures
- Monitoring for unauthorized access
- Employee training and confidentiality agreements
- Incident response procedures
We conduct regular risk assessments and continuously improve our security framework.
9. International Data Transfers
We do not transfer personal data outside Japan without user consent, except where necessary.
Data may be stored on secure cloud infrastructure (e.g., Google data centers), with:
- Restricted access controls
- Encryption and global compliance standards
10. Cookies and Tracking Technologies
We collect information such as:
- Cookies
- IP addresses
- Access logs and browsing behavior
Purpose:
- Website operation and troubleshooting
- Security monitoring
- Usage analytics and service improvement
This data does not identify individuals unless combined with other personal data.
11. Retention of Personal Data
We retain personal data only as long as necessary:
- Service data: retained during service operation unless deletion is requested
- Business data: retained during business relationships
- Employee data: retained per legal requirements
- Call recordings: retained for up to 10 years
After retention periods, data is securely deleted or disposed.
12. Data Subject Rights
Users have the right to:
- Access their personal data
- Request correction, deletion, or restriction
- Withdraw consent
- Request suspension of processing or third-party sharing
Requests may be declined in limited cases (e.g., legal obligations, risk to safety, operational integrity).
13. Voluntary Provision of Data
Providing personal data is voluntary. However, failure to provide required information may limit access to services.
14. Anonymized Data
We may create anonymized data in accordance with applicable laws.
- Proper de-identification measures are applied
- Re-identification is strictly prohibited
- Anonymized data may be shared for research and analytics
15. Contact Information
For inquiries or requests regarding personal data:
Privacy Contact Desk
3H Medi Solution Co., Ltd.
TEL: +81-3-5928-0929
Email: privacy@c-trial.com
Hours: Weekdays 10:00–16:00
16. Updates to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this website.
Established: April 22, 2019
Last Updated: July 1, 2024