← Back to top

Privacy Policy

Privacy Policy

ChordOne supports HR, organizational management, IT/SaaS administration, surveys, evaluations, and culture building. We handle your organization and employee information, as well as data obtained from integrated services, appropriately.

Established: May 4, 2026 / Last updated: October 2, 2026

Operator Information

The ChordOne service is developed and operated by ChordOne. ChordOne provides an all-in-one backend AI workspace to support HR, IT, back office, performance, and organizational improvement.

Company name / Company name
ChordOne
Product name / Product name
ChordOne
Website / Website
https://chordone.jp/
Contact / Contact
info@chordone.jp

1. Information We Collect

We collect the following information as needed to provide ChordOne.

  • Account information (name, email address, organization, permissions, login details, etc. If you log in with a Google or Microsoft work account, this includes the email address and name from that account.)
  • Information you register, enter, or upload to the service (employee and organization details, skills and career history, hiring and candidate information, evaluations and goals, OKRs (objectives, key results, progress records, linked notes, comments, visibility settings), survey responses (including attached files), recognition and culture data, home announcements, polls and responses, contracts and documents, internal notes (page titles, content, space or folder descriptions, cover images, page icon images, database row cover and icon images, sharing settings, display settings (font, text size, width, lock), favorites, section names in the left menu, database rows and columns, row content, saved views, comments, notifications to mentioned users, guest invitation email addresses and open status. Database columns may automatically display items visible in the employee directory. Includes documents imported as internal notes from other note tools if you have rights to them), custom emojis shared in your company (name, image, added by), SaaS and device information, and requests entered in internal forms.
  • For the reception (visitor management) feature, information entered by visitors on the reception screen (company name, name, number of visitors, selected contact person or department, visit date and time, etc.)
  • For the meeting room booking feature, information entered by external guests on the booking page (name, email address, optional attendee email addresses, optional message, selected date and time)
  • For the document sharing feature, viewing information of those who access shared documents (pages viewed, viewing time, number of views, referrer, browser info, hashed IP address, recipient identifier assigned at sharing, etc.), and information entered by viewers as required by document settings (name, email address, optional company name)
  • For the quiz feature, participant nicknames, group names created or selected by participants, selected answers, and time taken to answer (including cases where participants join without logging in, depending on the organizer's settings)
  • For the icebreaker feature, participant nicknames, responses to prompts, and votes on 'whose answer' (including cases where participants join without logging in, depending on the organizer's settings)
  • Information obtained from integrated external services within the scope you authorize (including employee and attendance data—clock-in/out, breaks, overtime, etc.—from HR systems such as SmartHR and freee)
  • For human capital disclosure (such as ratio of female managers, male parental leave rates, gender pay gap), wage data you link or upload (monthly pay, wage amount, commuting allowance, retirement allowance per employee, and, if enabled, base salary details from HR systems like freee. Includes imports from freee or CSVs you create). This data is used only for aggregate calculations and individual wage amounts are not shown in the service (base salary is visible only to your organization's top administrator).
  • For visualizing departmental costs and ROI, monthly sales and cost of sales per department that you link, upload, or enter (including imports from freee accounting, CSVs you create, or manual entry). This is company accounting data and does not display individual amounts.
  • For turnover prediction and analysis, metadata obtained from integrated services like Google Workspace (number of sent/received emails, interactions with external recruiters or job sites, email forwarding settings, number of file downloads/exports from Drive, and audit logs of files created or renamed for handover—file names and dates only. Email bodies, attachments, and file contents are not included.)
  • For turnover prediction and analysis, public profile items (name, headline, employer, location, job-seeking status, etc.) and changes to them, from employees you register for monitoring (e.g., LinkedIn). Includes the same public items obtained when your HR staff views such profiles via browser extension (raw profile page data is not saved).
  • For the sourcing feature, public information of candidates obtained from publicly available web pages or search engine results as instructed by you (name, job title, employer, location, profile URL, etc.)
  • Usage information for this service and the service website (operation history, access logs, device, browser, IP address, browsing data obtained via cookies, etc.)
  • Monthly aggregate data when your company admin uses career market campaigns (views and responses per campaign, usage count of agent extension, etc.). Aggregates do not include employee, candidate, or viewer names, personal profiles, or individual browsing history.
  • Information you enter during initial setup after account creation (name, display language, your role, purpose of use, and, optionally, how you heard about the service). Used to optimize and improve service guidance.
  • Information you provide through inquiries, document downloads, or scheduling online meetings or demos (name, email address, company name, reservation date and time, etc.)
  • Information you provide when subscribing to the ChordOne Mag. newsletter (email address, optionally selected job type or topics of interest, consent date, registration page, delivery confirmation and unsubscribe records, etc.). Newsletter subscriber data is managed separately from service users, inquiries, document requests, and free assessments, and is not auto-registered for those reasons.
  • Email address you enter to continue using the demo environment, and access information for verification (such as hashed IP address).
  • For the free assessments on our website (such as organization type, personality, or compatibility diagnostics), you may optionally enter your company name, company website URL, and email address, along with your assessment results (trends and types on four axes). To standardize the assessment, we may obtain your corporate number and name from an external corporate information service (gBizINFO), and use identifiers (such as an anonymous ID stored in your browser or a hashed IP address) to prevent duplication and misuse. Entering your email address is optional; you can view your results without it. If you provide your email, we may use it to send your results (result card and explanation page) and related information, and to simplify email verification when providing a demo environment. If you choose to receive updates when requesting your results, we may send you information about our service (you can unsubscribe at any time).
  • Information required for billing and payment

Entering company information for the free assessment on our website is optional. If you provide a company name, we will standardize it to a corporate number using an external service (gBizINFO) and use it to display the distribution of responses within the same company (aggregated anonymously). Distributions are shown only when enough responses are collected to prevent identification of individuals. You can use the assessment without entering any company information.

Sample data (such as example employees and departments) shown immediately after creating a new workspace is fictional and provided for trial purposes. It does not contain real personal information. You can delete all sample data at any time from the on-screen instructions.

The demo environment is a read-only space for experiencing ChordOne. All data shown (employees, organizations, culture, etc.) is fictional and does not include real personal information. You cannot create, edit, or delete data in the demo. After certain actions, we may ask you to verify your email (by sending a code) to continue using the demo. Any email address you provide will be used to contact you about the demo.

2. Purpose of Use

We use the information we collect for the following purposes.

  • To provide, operate, and improve our services
  • For identity verification, authentication, and access control
  • For external service integration, data sync, notifications, reminders, and report creation
  • To provide AI-powered features such as extraction, summarization, classification, translation, and estimation (see section 3 for details)
  • For internal analysis to support organizational management for client companies, such as analyzing culture trends, turnover prediction and signs, and engagement trends, as well as to improve our services and analysis models (see section 4 for details)
  • For responding to inquiries, sending materials, and providing information and updates about our services
  • For ChordOne Mag. newsletter registration, confirmation, article recommendations based on selected topics, managing delivery, and handling unsubscribe requests
  • For usage analysis, troubleshooting, security, and fraud prevention
  • To invite external guests to internal notes (sending invitation emails that include the page title and link, but not the page content; guest display names and comments are used for sharing the page)
  • For managing fees, billing, payments, and usage restrictions
  • For purposes incidental to the above

3. Use of AI

To improve operational efficiency, we may input documents, text, images/screenshots (including price lists, product lists, customer and contract info, usage records, CSVs, receipts, etc.), survey responses, email content, audio/transcriptions, internal note titles and content, and database rows uploaded or entered by customers into third-party generative AI models. For internal note search, we may send relevant text to external generative AI services (such as OpenAI) to generate numeric representations for search, which are stored in our database. Pages you cannot view will not appear in search results. Sent content is not used for AI service training. For candidate/employee career searches, we may send career text (name, title, skills, work history, etc.) to external AI services for search purposes; this content is not used for AI training. If your admin enables AI goal checks in evaluations, saved company, department, and individual goals and admin instructions may be sent to external AI services to provide feedback on specificity and criteria. Goals are still saved even if AI checks are unavailable. The employee home AI assistant may send your questions and, within your access rights, internal data (org charts, 1on1s, surveys, recognition, etc.) to external AI services to generate answers. Data you cannot access (including salary info) is not sent. We ensure, by contract, that your input and responses are not used for model retraining by these providers. AI-generated, summarized, or estimated results are for reference only; you are responsible for final review, publication, and HR decisions. Please use discretion when entering sensitive or confidential information.

4. Use of Data for Internal Analysis

We may use information obtained or generated through our services (including records of meetings/interviews/online meetings, notes (including minutes), recordings, transcriptions, summaries, screenshots taken during meetings, survey responses, evaluation and goal management data, and usage information) for internal analysis to support organizational management for client companies (such as analyzing culture trends, turnover prediction and signs, and engagement trends).

We may also use this information to improve our service quality, enhance features, and increase the accuracy of our analysis and estimation models. In such cases, we limit use to what is necessary for business, and, where possible, process and aggregate data to prevent direct identification of individuals. We do not provide this information to third parties for the development or training of general-purpose AI or machine learning models.

5. Cookies and Access Analytics

We use Google Analytics only if users explicitly allow it, to understand and improve usage. Analytics is disabled by default. You can change your consent at any time in the privacy settings. Even if you decline, cookies and saved data needed for login, security, and language preferences will still be used, and core functions are unaffected. Details on what is sent to Google Analytics, the purpose, and recipients are listed in About External Data Transfers.

We do not currently provide information to third-party advertisers, show personalized ads or announcements, or send data externally for ad measurement. If we introduce these in the future, "Personalized Ads & Announcements" and "Ad Measurement" will be presented as separate, optional items from analytics, and will not begin without your consent. Consent can be withdrawn individually at any time in privacy settings. Before starting any data transfer, we will inform you of the provider, items sent, purpose, and recipients in About External Data Transfers or similar. Granting future permission in settings will not trigger data transfer before such disclosure. In all cases, HR data, employee/candidate names, contact details, profiles, and evaluation or work activity data handled in your company workspace will not be used or provided for ad targeting or measurement.

6. Integration with External Services

This service can integrate with Slack, Google Workspace, Microsoft 365 (Entra ID / Microsoft Graph, including user lists and metadata on Teams/email usage, but not message or email content), Zoom, SmartHR, freee HR (for importing employee, attendance, and payroll data), freee Accounting (for importing department-level sales and cost of sales), various recruitment platforms, and other external services, within the permissions you approve. Only one HR system, chosen by you, will be used as the source for the employee master (basic employee info). When logging in with a Microsoft work account, we only obtain the email address and name; we do not access email content, calendars, or files. For Slack integration, with your approval, we collect timestamps for posts/replies/edits in channels, character counts, reactions and their times, member online status, status displays (leave, busy, etc.), and scheduled notification-off times, for organizational activity and turnover analysis. To avoid missing data, our bot may auto-join public channels (never private channels unless invited). Data obtained via integrations is used only to provide and improve service features, not for advertising or resale. You can disconnect integrations anytime from this service's settings or from the external service's admin panel.

Your administrators can issue a dedicated link (integration setup request link) to assign integration setup tasks to designated staff (such as IT personnel). The recipient can enter and confirm connection details without creating an account for this service. Employee data cannot be viewed from this link, and entered connection info is used only for the integration. The link has an expiration date and can be disabled by your administrator at any time.

If you use our browser extension for integration setup guidance, the extension displays setup steps on the external service's admin screen and assists with input and registration, with your confirmation. If the guide cannot display instructions correctly due to screen changes, only menu structure info (button/field names, not entered values, names, or emails) may be sent to our service to rebuild the guide and improve quality. Some of this info may be sent to external AI services for guide reconstruction.

For the PC attendance tracking (PC agent) feature, if your administrator installs our agent on employees' PCs, we collect and store the types and times of PC usage changes (logon/logoff, screen lock/unlock, sleep/resume/shutdown, start/end of inactivity, and periodic heartbeat checks), device name, OS type, and agent version. We do not collect screen content, open apps/files, typed text, browsing history, or location data (inactivity is judged only by time since last input). These records are used to suggest attendance/break times (attendance is only recorded if approved by the user), display total PC attendance time, and analyze turnover risk (by comparing current attendance patterns to past trends). Analysis is for reference only; final evaluation and decisions are made by you. Administrators manage agent installation/removal, and employees can check their device registration status in the service.

The engineering analytics feature collects and stores development activity data—such as commit counts, pull requests (titles, descriptions, line changes, status), and issue progress—when you enable integration with GitHub, Linear, or similar tools. If your admin enables AI review of work, pull request diffs may be sent to an external generative AI service at review time to generate and save summaries and evaluations (score, notes); diffs themselves are not stored in our database. If you set up admin integrations with OpenAI, Anthropic, Cursor, or Manus, we collect and display AI usage per member or API key (token usage, request counts, agent task counts, credits spent; not conversation, prompts, or code content), and show usage costs per department/member. If per-member costs are unavailable, we estimate based on usage ratios. For AI tool invoices/receipts imported into contract/document management, we extract and display vendor, service, amount, and period as AI tool payments (prioritizing admin integration data to avoid duplication). If the provider or your CSV import includes breakdowns by product/feature, we save and display usage by category. If your admin enables AI usage telemetry and configures the target AI tool (Claude Code, Cowork, etc.), the tool sends per-member usage and status (interaction counts, user-issued commands, token usage by type, reported costs, time spent, task starts, AI suggestion adoption, code line changes, AI task counts and failures, provider error counts, AI-created commits/PRs, and email addresses; not conversation, prompts, code, or task content) directly to our service for storage and display. For AI review accuracy, basic employee info (tenure, position, etc.) may be used as context, and analytics may display estimated attendance from Slack and evaluation results alongside development metrics. In AI usage analytics, we compare trends for users vs. non-users, AI-involved vs. other work, and before/after AI adoption, based on usage and activity data. For before/after comparisons, the adoption date is determined from development records (AI tool signatures); users without sufficient records are excluded. These comparisons are shown only as aggregate values for groups of three or more, not individuals. We also display estimated time and cost savings based on admin-set assumptions (time saved per AI interaction, hourly labor cost); these are estimates, not actuals. Analytics results are viewable only by your admins and designated development insights staff. AI-generated evaluations and usage types are for reference only; final evaluation and decisions are made by you.

The offboarding feature allows your administrators, through explicit actions, to perform operations such as disabling accounts for departing employees, setting up email forwarding, transferring file ownership, and removing users from groups/shared mailboxes in integrated external services, within the approved permissions. These actions are performed only when individually instructed on screen, and the details, executor, date/time, and results are recorded.

The Single Sign-On (SSO) feature allows users to log in to connected external applications with their account from this service, by sending user information (email address, and, if set by the admin, name, employee number, department, position, etc.) to the application at login. The admin sets which items are sent for each application, and data is sent only when the user logs in. Login records (including success and failure) are saved and viewable by your admin. Users whose accounts are deactivated or offboarded can no longer log in via SSO.

The account provisioning feature automatically creates or deactivates accounts in connected external applications, sending employee information (email, name, identifier) as set by your admin for all members or specific departments, during daily automatic sync, manual sync, or offboarding. Access tokens used for connection are stored encrypted. All account creation/deactivation events (including failures) are recorded and viewable by your admin.

The account automation feature uses rules set by your admin for each application to identify accounts with no activity for a set period, based on last usage data from integrated external services. Accounts without last usage data are excluded. For identified users, a Slack direct message or email is sent as advance notice. If a contact person is specified, only they receive the notice, with a list of affected users, application names, and days unused. If there is still no activity after the grace period, the account is suspended. For applications with account provisioning, suspension is also executed in the application. For others, your IT staff receives a list of accounts to suspend.

The usage review feature helps your admin review SaaS seat contracts by displaying lists of seats and last usage dates from integrated external services, along with employee status and per-app pricing. If last usage dates are not provided per seat, we use member lists (name, email, role, status) and sign-in records (sign-in times only, not source or actions) or usage records imported into this service. The display includes seats still linked to former employees and seats in external services not matched to any employee (account name, display name, email, last usage date). This feature only displays lists; it does not suspend or cancel accounts.

For GitHub, if you install our GitHub app and allow member management, we remove the affected user's GitHub account from your organization as a suspension process, using only the account name and membership status. We do not delete repository or commit content. Organization owners are not subject to automatic removal. If the user reapplies, an invitation to rejoin is sent.

When a user requests access to an application from the app portal, we save the applicant, target application, and any reason provided, and notify the designated approver (manager, IT, or specified user) via Slack direct message or email for approval. Requests matching admin-set criteria (department, position, etc.) are approved automatically. The applicant is notified of the result. All decisions, notifications, suspensions, and issuances (including failures) are recorded with details and viewable by your admin.

The approval workflow feature saves application details entered by users (title, type, amount, type-specific fields, body), approval routes, circulation recipients, comments and action history for returns/approvals/rejections. Attached files (quotes, contracts, etc.) are stored in a tenant-specific area and viewable only by related parties (applicant, approver, circulation, admin). When it's your turn to approve, or for returns, final approval, or reminders, you may receive notifications in the service and (if Slack integration is enabled) via Slack direct message. Proxy approvals are also recorded in the history.

The 1on1 feature saves meeting schedules (participants, date/time, duration), frequency, agenda, shared notes, private notes for each participant, action items, weekly check-ins (mood, progress, blockers, requests for help), and topics users want to discuss next. Weekly check-ins and discussion topics are visible to the 1on1 partner (usually the manager) and may appear in the next agenda. Shared notes are visible to both and accessible from the notes feature. Private notes are visible only to the author. If Google Workspace calendar integration is enabled, 1on1 events (title, date/time, participants) are imported and shown in the same 1on1 view. If a user enables this, a link to the 1on1 screen is written in the calendar event notes (no invitation email is sent; this can be stopped anytime). Some agenda items are auto-generated from available employee data (behavior signals, received recognition, survey trends, evaluation goals, carryover items). Items based on behavior/survey trends and private notes are visible only to the user (and HR admins), not to the partner. If a manager writes thoughts or messages to generate sample questions and talking points, the manager's input, agenda titles, previous topics, and weekly check-ins are sent to an external AI service. Generated questions/examples are visible only to the manager, not to the partner, and the input text is not saved. If a user records a 1on1 via the Chrome extension, the transcript and summary are saved as a private note and linked to the 1on1. Only the recorder can access this note; it is not shown to others. When a 1on1 or discussion topic is set manually, the partner is notified in the service (not for calendar-imported events, as invitations are already sent via calendar).

If you enable push notifications (browser or home screen app), we store the info needed to send notifications (browser-issued address and encryption key, environment type). This info is used only to deliver notifications to your device and is deleted when notifications are turned off or the subscription expires.

For the free assessment on our website, company names you enter may be checked with an external corporate information service (gBizINFO, operated by METI) to normalize to a corporate number. No assessment results or personal identifiers are included in the query.

If you use the feature to send Slack messages (such as survey reminders) in your own name, your Slack account's access token is securely stored with your consent (OAuth authorization) and used only for sending messages. You can disconnect this integration anytime from the settings, and the token will be deleted upon disconnection.

For AI assistant integration (external AI client connection), with your consent (OAuth authorization), you can connect external AI assistants (such as Claude MCP-compatible clients) to this service. The connected AI assistant can only view or send data (employee info, org chart, recognition, surveys, etc.) and submit feedback within your permissions; it cannot access data beyond your rights. Handling of data obtained by the AI assistant follows the provider's privacy policy. You can disconnect anytime from the settings, after which the AI assistant will no longer have access. Usage records (which features were used and when) are saved for monitoring.

The meeting scheduling feature allows you to connect only your own Google Calendar (without organization-wide Google Workspace integration) with your consent (OAuth authorization). We only access your calendar's free/busy info and create events (including web meeting URLs) as needed; we do not access Gmail content or inbox. Access tokens are securely stored and used only for these purposes. You can disconnect anytime from the scheduling screen, and tokens are deleted upon disconnection. If you start using the free scheduling tool, your consent to connect Google Calendar may create a dedicated workspace, collecting only your Google account email and name. The free tool screen is separate from your company's ChordOne workspace, and even if your Google account is a company member, the data is not shared. When a booking is made, changed, or canceled, notifications are sent to the creator and participants' registered emails (for the free tool, the connected Google account email). The personal/free tool screen may display ChordOne company feature info (in-house ads); no third-party ads are shown. When you create a booking link, a unique management link (hard to guess) is issued to the creator. Anyone with this link can change conditions, stop bookings, or view the booking list without registering for ChordOne. Keep the management link safe; it is different from the public booking link.

Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including Limited Use requirements. Specifically, data from Google APIs (such as calendar free/busy info) is used only to provide and improve the above features, and not for advertising, resale, or credit decisions. Except as required by law, for security investigations, or with explicit user consent, humans do not view this data. It is not used for training general AI models. ChordOne's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The applicant tracking (ATS) feature allows you to set up a dedicated Slack integration separate from general management. If enabled, notifications about interviewers being assigned, offer approvals/results, and overdue actions (such as exceeding stage deadlines) are sent to relevant staff via Slack direct message and posted to specified channels. Notifications include candidate name, department, job title, date/time, and responsible staff. You can disconnect this integration anytime from the settings, and the token will be deleted, stopping further notifications.

In the applicant tracking (ATS) feature, users can configure notification settings for recruitment updates (such as candidate email replies, new applications, document submissions via the candidate portal, stage changes, mentions in internal notes, and AI screening results). You can choose whether to receive notifications, the delivery method (email or Slack), the recipient (an email address other than your login, or a designated Slack channel instead of a direct message), and the scope (only candidates you manage or all candidates) from the settings screen. Notifications include candidate names, job titles, email subjects and excerpts, and AI screening results. Please specify recipients or channels that are authorized to access this information. Notifications are only sent to users with ATS permissions and can be turned off at any time from the settings screen.

The applicant tracking (ATS) feature may provide automated email scheduling to candidates based on your settings, as well as follow-up emails if there is no reply within a set period. These automated emails are only sent if you enable them for each message and can be canceled before sending. For record-keeping, a company-managed email address may be CC'd on candidate or agent emails, and replies sent to 'reply all' will be received and stored as part of the candidate's email history. Original emails are deleted within 30 days of receipt, and only ATS users can view stored content. You can disable this feature at any time from the settings. You may also be issued a dedicated application intake email address on our domain, which you can add as a recipient for job board notifications. Emails sent to this address (including subject, body, sender, and attachments) are received and applicant details (name, contact, job applied for, resume, etc.) are saved as candidate information. Original emails are deleted within 30 days. You can recreate or disable this address anytime from the settings. If you enable the AI screening agent, the AI will compare candidate documents and profiles with job requirements and generate reference information (recommendation, needs review, etc. with reasons). These results and summaries are saved as internal notes and activity logs for your team (not shown to candidates). These are for reference only; all hiring decisions are made by you.

With the applicant tracking (ATS) feature, you can set custom check items and tasks for each stage of a job or selection template, and save candidate-specific entries, task status, assignees, and completion records. For each item, you can choose to share it with all hiring team members who can view the candidate, or restrict it to users with special permissions. The current settings are displayed for applications that reach the relevant stage, and entered values and completion status are retained.

In the applicant tracking (ATS) feature, resumes and other documents submitted by candidates via their portal are used only for your recruitment process and securely stored in your managed area. If you enable the dedicated Slack integration, interviewers may receive Slack notifications to submit evaluations after interviews, and their input (such as recommendation and comments) may be saved as part of the selection record.

The applicant tracking (ATS) feature allows you to issue a login-based candidate portal where candidates can log in with their email and password. We send a guidance email (including a password setup link) to the candidate on your behalf, and passwords are stored in a non-recoverable format (we do not retain the actual password). Candidates can use this portal to check their application status, schedule or reschedule interviews, view feedback and company materials you publish, submit documents, and send questions to recruiters. If you publish an offer (job terms) on the portal, candidates can review the details and respond with acceptance or decline. You are notified of their response, which is saved in the selection record. Interviewer names and workspace profile images may be shown on the portal. Messages exchanged between candidates and recruiters on the portal are saved as part of your selection record and shown to your recruiters. Feedback visible to candidates is limited to content you create, review, and publish for them; internal interview evaluations are never shown as-is. To ensure smooth communication, the last access date to the portal and the first time an offer is viewed may be recorded and shown to your recruiters (and may trigger notifications if an offer is not opened for a certain period). You can disable access to the portal at any time. Candidate login accounts (email and name) are managed separately from your environment to allow future use across multiple companies’ portals.

If you enable candidate experience surveys in the applicant tracking (ATS) feature, a survey invitation may be automatically sent to candidates after their selection process ends, using your company name. You can prepare multiple survey templates and select which to send per job. Survey responses are optional and are shown to you as anonymous aggregates for process improvement, not for evaluating individual candidates. We may also provide a feature to use AI to organize interview notes or transcripts and generate draft evaluations; these drafts are for reference and must be reviewed and edited by your team. All hiring decisions remain with you. Weekly summaries of recruitment activity (new applications, interviews, offers, hires, etc.) may also be sent to your recruiters by email.

With the applicant tracking (ATS) feature, you can issue accounts for your recruitment agency contacts to access a dedicated portal for job postings and candidate recommendations. When you register an agency contact’s name and email, or import them from another ATS and send an invitation, we send a login email with a password setup link and your custom message (e.g., notice of ATS change). The contact sets their own password, which we do not retain. If you resend the invitation, previous password links are invalidated. Delivery records (recipient, date, message) are saved in your ATS dashboard, and you can delete or deactivate accounts at any time. If enabled by your admin, the portal can display aggregate trends from selection results (number of applications, pass rates, common current roles, high-scoring evaluation points), but only as summaries—no candidate names or identifying details are shown, and nothing is displayed if there are too few results.

In the applicant tracking (ATS) feature, you may look up company names registered as candidate information with an external corporate information service (gBizINFO, operated by the Ministry of Economy, Trade and Industry) to standardize company name formats. Only company names are used for lookups; no candidate names or other personal information is included.

If you enable the organization report feature, aggregate results based on linked data (overall organization score, communication activity and positivity, interdepartmental collaboration, recognition activity, turnover risk, headcount changes, period comparisons, key changes and recommended actions, and culture trend analysis from activity data such as communication and calendars) may be regularly delivered by Slack direct message or email to HR and management contacts you specify. Reports contain only aggregated data by organization or department. You can change recipients, frequency, or stop delivery anytime from the organization report screen.

The organization report feature displays estimated turnover costs as organization-level aggregates. Calculations are based on the number of departures in a period, number of at-risk employees, admin-set assumptions (hourly labor cost, handover time, replacement hiring cost, ramp-up period, etc.), and media/agency costs registered in ATS. These are estimates only and do not guarantee actual or future costs. No individual employee cost is calculated or shown.

In culture trend analysis, Slack channel structure data (ratio of public/private channels, proportion of public conversations, channel size, etc.) may be analyzed as an indicator of organizational transparency. This analysis is handled as statistics aggregated by channel or organization; individual message content is never distributed or disclosed.

For communication analysis, frequently used words and their counts may be aggregated from Slack messages to identify trending topics within the organization. To refine the results, only the aggregated words and counts (not message content or speaker) may be sent to external AI services (such as OpenAI) to remove generic terms, merge synonyms, and classify topics.

In the talent management skill registration feature, to assist employees in registering their skills, the service may periodically extract potential work skills from their posts in public Slack channels (excluding DMs and private channels). The message content is sent to external generative AI services (Anthropic, OpenAI, etc.) only for skill extraction (not for AI training). Suggested skills are shown only as proposals on the employee’s profile and are not registered unless approved by the employee or your admin.

For company-wide feedback (feature requests and bug reports), submitted titles, content, attachments, and replies are used to improve the service. If you use AI help or the AI post assistant, your questions, conversations, and any attached screenshots are sent to external generative AI services (Anthropic, OpenAI, etc.) only for generating answers or drafts (not for AI training). If 'attach current screen' is enabled, a screenshot is automatically taken and sent only for answer generation, not stored on our servers. You can remove the screenshot before sending. AI-generated fixes may be created for reported issues, and status updates (in progress, fixed, released, etc.) are sent as replies. You are notified in the service and, for key updates, by email. For major changes, a test screen (temporary URL) may be provided for your review before release; this uses your normal login and production data, and the URL is deleted after review. To verify fixes, our system may automatically open the same screen as you saw and capture its content and screenshot for a short, read-only session (20 minutes); no save, change, or delete actions are performed. Screenshots are used only to re-run AI fixes if needed and may be sent to external AI services (not for AI training). For issues like incorrect list counts, our database may be queried for counts only (no data changes). If your AI help request is deemed a bug or feature request, it is recorded as such, visible only to you and our staff, and can be deleted by you. When your request is resolved, ChordOne points are added to your balance as a thank you.

To share progress on collaborative improvements, anonymous aggregate statistics (such as the number of reports, resolved cases, deployments to production, and days to resolution) may be shown to users of the service. No individual titles, content, or company names are included.

When you open the feature request or bug report form, a screenshot of your current screen is automatically taken and attached as a candidate image to help identify the context. This image is kept only in your browser until you submit the form. You can review or delete it before sending. If deleted or not submitted, the image is discarded and never sent to us. If sent, it is handled like any other user-attached image.

In culture surveys, employee responses (choices, scores, free text) and response times are saved. If the creator enables 'allow multiple responses per person,' multiple responses from the same employee are saved. For named surveys, the creator and authorized viewers can see each response and submission time. For anonymous surveys, responses are saved and displayed as aggregates with no identifying information.

In the culture (recognition) feature, messages and points sent between employees are saved. Depending on your settings, these may be posted to a designated Slack channel or sent as Slack direct messages to recipients. If you enable weekly point reset reminders, employees with unused points receive a Slack DM reminder (including your custom message, if set) at a set time each week. You can change reminder settings or content anytime. If you enable 'AI gratitude suggestions,' the service analyzes Slack channel activity (reply and mention counts, posts with many reactions, celebratory events, and registered birthdays) to suggest colleagues you may want to thank this week, shown only on your recognition screen. To generate suggested messages, the service may send the candidate's name, interaction counts, excerpts from relevant posts, recent completed work titles (if dev tool integration is enabled), and recent public recognition messages to external AI services (Anthropic, OpenAI, etc.; not for AI training). 'Internal channels' refers to public channels and large private channels (30+ members); DMs and small private channels are excluded. Suggestions are visible only to you and can be disabled anytime.

On the employee home, announcements and polls (including quick questions) posted by users in the same company are saved and shown in the home timeline. Posts limited to a department are shown only to its members. Based on existing data in the employee directory and leave features, new hires, birthdays, and people on leave this week may be displayed on the home. If a photo is included in a new hire announcement, it is saved as their profile photo.

In the culture mini-app (group message board), messages (author name and content) written by logged-in employees are saved and, at the creator's direction, may be delivered to the recipient via Slack direct message. By default, only invited employees can view or write messages, but the creator can make it visible to all employees. When inviting members or requesting messages, the creator can send Slack DMs (including custom request text) to selected employees. When delivering (publishing), the creator can optionally enter the recipient's personal email, which is used only to send a viewing link and is not stored. After delivery, anyone with the special link (QR code) can view the board without logging in. The link is hard to guess, and pre-delivery boards are not shown. The creator can upload images for the background or cover photo, which are used for display (including via shared links) and deleted if the creator removes them or deletes the board. Admins can add company-wide background images for use and can delete them. The creator can delete the board, which also deletes all messages.

If the creator enables a 'participation link' for the group message board, anyone with the link (including external users) can write their name (free input) and a message without logging in. For company boards using ChordOne, users with accounts are encouraged to log in; if logged in, their directory name and photo are used for display (otherwise, name is free input). Only the entered name, message, chosen icon (emoji or uploaded image), and any attached photo are collected and used for display. If 'surprise protection' is on, message content and photos from other participants are hidden until delivery (names are shown); if off, all messages are visible before delivery. Uploaded icons and photos are deleted if the message or board is deleted. If 'AI draft' is used, only the selected relationship, optional keywords, title, and recipient name are sent to an external AI service for draft generation; input is not stored or used for AI training. The participation link is hard to guess and can be disabled anytime; messages via this link can be deleted. Participants can edit/delete their message before delivery using a personal edit link (saved in their browser). If an email is entered, it is used only to send the edit link and is not stored. Free boards can be created without an account; only the title, recipient name, and any uploaded images are stored. The creator receives a management link (hard to guess) for editing, deleting, or delivering the board. If the creator enters emails for invitees, only those addresses are used to send invitation links (including custom text) and are not stored. For delivery, the creator can enter the recipient's email to send a viewing link (used only for sending, not stored). The creator can delete the board from the management link, which deletes all messages and images. Boards with no messages for 30 days or judged as test entries may be auto-deleted (including messages and images). Paid ChordOne boards are not auto-deleted. Optionally, you can register with a Google account for identity verification; only your Google email and name are collected (no calendar access). If the creator links the board to their account while logged in, it becomes manageable from their in-app board list (no new data collected).

If you use the anonymous pulse survey tool for free, you can create surveys without registering an account. Only the survey title and questions are collected and stored. You receive a management link (hard to guess) for viewing results, closing responses, or deleting the survey. Respondents can answer via the link without logging in; only their selected rating (5-point scale) and any free comments are collected. No names, emails, or identifiers are collected or stored. Results are shown only as anonymous aggregates. The creator can delete the survey and all responses at any time from the management link.

In the culture mini-app (meeting scheduling), guests outside your organization can book available slots via a reservation link without logging in. To calculate availability, the app checks the free/busy status of the specified members’ Google calendars (not event titles or details). If specified, additional calendars not in your workspace may also be checked for availability via a connected Google account (again, only free/busy status, not event details; these calendars are not auto-added to invites). When booking, guest names, emails, co-attendee emails, and messages are used for confirmations, updates, calendar invites, and generating meeting URLs (Google Meet, Zoom) as set. Depending on settings, a shared email address may be added to the calendar invite. Guests and co-attendees may receive confirmation and reminder emails (with date, URL, and links for changes/cancellation). Change/cancellation links may also appear in the calendar event description. Whether guests can change/cancel and the deadline depend on settings; all changes trigger notifications and calendar updates. Confirmed or canceled bookings may trigger Slack DMs to participants. Reservation links are hard to guess and can be disabled anytime. Guest users do not see internal assignment rules (group structure, priorities).

In the culture mini-app (date poll), employees designated as organizers can set event date options, and selected participants can log in to respond (yes/maybe/no). The poll title, date options, participants, each participant’s responses, comments, and response times are saved and used to show organizers and participants who chose which dates. When organizers create a poll, add participants, or finalize a date, Slack DMs may be sent to participants. Organizers can delete polls, which also deletes all participant responses.

In the Culture mini app (Document Sharing), employees can upload PDF files that anyone with the share link can view without logging in. To track document access, we record which pages were viewed, viewing time, number of views, referrer, browser details, a hashed value of the IP address, and link identifiers (recipient name and notes) set by the creator. Document creators and admins can review this data for each file. Depending on the document settings, viewers may be asked to enter their name and email (and optionally company name) to access certain pages. This information is shared with the document provider (your company) and may be used for access management or follow-up. The viewing page can display your company logo, and share links may use your company’s custom domain. Share links are generated in a format that is hard to guess, and creators or admins can stop or delete sharing at any time.

The document sharing feature can be used from the service site without account registration. PDFs uploaded without registration are stored on our servers, and the uploader receives a management link to review access analytics, change settings, or delete the file. The access data recorded (pages viewed, viewing time, number of views, referrer, browser info, hashed IP address, and any name/email entered by viewers) is the same as when logged in. Files uploaded without registration are not linked to an account, so only those with the management link can manage them. We may delete files that violate laws or have not been accessed for a long period.

In the Culture mini app (Virtual Office), employees can log in and enter a 2D office view. Presence information (location in the office, mic on/off, screen sharing status, entry time) is temporarily stored and shown to other members in the same company. This data is deleted when users leave (including when the last person exits) or after a period of inactivity, and is not kept as activity logs. Audio and shared screens are exchanged directly between users’ browsers and are not stored, recorded, or relayed through our servers. Only the information needed to establish the connection is temporarily relayed and deleted immediately after. Microphone access permission is required to use audio, but entry is possible without it.

In the Culture mini app (Quiz), anyone with the participation link (QR code) can join and answer quizzes created by the host. Logged-in employees participate with their real name; if the host allows anonymous participation, users can join with just a nickname without logging in. We save the nickname (or name), selected answers, and time taken to answer. Rankings and answer distributions (how many chose each option) based on correct answers and total points (set by the host) are shown to participants and the host. If group competition is enabled, group names and affiliations are also saved, and group rankings are displayed. Images attached by the host for questions or answers are stored on our servers and shown to those with the link (answer images are shown after the correct answer is revealed). Participation links are hard to guess, and correct answers are not revealed before the deadline. If a participant selects a language other than Japanese, quiz titles, questions, and options may be auto-translated by AI, and this content is sent to external AI services (like OpenAI) for translation (names and answers are not sent). Hosts can delete quizzes and attached images; deleting a quiz also deletes all responses and images.

In the Culture mini app (Icebreaker), anyone with the participation link (QR code) can join sessions created by the organizer. Logged-in employees participate with their real name; if the organizer allows anonymous participation, users can join with just a nickname without logging in. We save the nickname (or name), answers to prompts, and votes for "whose answer it is." Answers are first shown anonymously, then after the reveal, participant names, vote distributions, and rankings based on correct guesses are shown to participants and the organizer. Participation links are hard to guess, and answer authors are not revealed before the announcement. Organizers can delete sessions, which also deletes all responses and votes.

The personality assessment feature saves the results of a 4-group, 16-type analysis and the answers based on a self-reported 5-point questionnaire completed by employees or candidates (or entered by an admin). The results are intended to support mutual understanding, placement, and development, not to be used alone for hiring or evaluation decisions. Organization-level summaries (talent portfolios) are for role design and understanding, not for individual ranking or evaluation.

The company culture assessment feature saves the results of a self-reported 5-point questionnaire about "how you see your company culture" and the resulting type classification (based on decision-making, results and evaluation, risk, and communication axes). The answers are used to visualize what your company values and to identify gaps between individual and group perceptions (shown only as anonymous summaries when enough people have responded). Individual answers are never disclosed. This feature is intended to support understanding and dialogue, not for individual evaluation or HR decisions.

For surveys and internal note databases, if your admin sets a destination URL (such as an external system, spreadsheet, or automation tool), responses or row changes (creation, update, deletion) will be automatically sent to that URL. For surveys, this includes answers and employee IDs (unless the survey is anonymous). The destination is managed by your company, not by us. Admins can delete these settings at any time; after deletion, no further data is sent. Survey requests and reminders can be sent via Slack or email (to registered employee addresses) by admin action, and we record the recipient, date, and delivery status.

The development culture assessment feature saves the results of a self-reported 5-point questionnaire and the resulting type classification (based on purpose, decision-making, speed, collaboration, and AI utilization). The answers are used to visualize development team culture and AI usage, and to support team understanding and dialogue. This feature is for organizational understanding only, not for individual evaluation or HR decisions.

7. Third-Party Sharing and Subcontracting

We do not share personal information with third parties except as required by law, with the consent of the individual or client company, or when providing only the minimum necessary information to subcontractors for service delivery.

We may use external services or subcontractors selected by us for cloud infrastructure, email delivery, authentication, payments, analytics, third-party AI models, customer support, and more. Main subcontractors and services are located in Japan or the US. When providing personal data to overseas third parties, we take necessary legal safeguards. Subcontractors are required to implement appropriate security measures. Credit card information is processed by payment providers and we do not store full card details.

For details on external transmissions related to analytics, see About External Transmissions.

8. Security Management

We take reasonable security measures to prevent unauthorized access, leaks, loss, damage, or alteration of collected information, including access control, authentication, encryption, log management, and permission management.

9. Data Retention and Deletion

We retain information for as long as needed to fulfill its purpose or as required by law or contract. Upon request for deletion, unlinking, or account removal, we will respond within reasonable limits, except for data that must be retained by law. Pages moved to the internal note trash are permanently deleted after about 30 days (including comments and external guest invites for that page). To stop communications or request data deletion, contact info@chordone.jp.

10. Requests for Disclosure, Correction, or Deletion

If you or your company request disclosure, correction, suspension, or deletion of personal information, we will confirm your identity or authority and respond in accordance with the law.

If your information was recorded by a recruiter's browser extension

When a recruiting agent merely opens your profile on LinkedIn, Wantedly or a similar platform with our Chrome extension (ChordOne for Agent), your name, career and other details are not stored; we keep only non-reversible identifiers (derived from the profile URL, and from your name and employer using our secret key, used only to match your contact history across platforms within the same workspace) and the date and number of views. Only when the agent presses "Save to CRM", or drafts or sends a message to you, are the items published on that platform (name, profile URL, title, employer, location, headline and about text, education and work history, skills, and the location of your profile photo) saved in the candidate CRM of that agent's workspace. We use this to help the agent avoid contacting you twice, to show how your profile matches their open roles and a salary estimate based on public information, and to manage their contact with you. Only agents in that workspace can see it; we do not disclose or sell it to your employer or any other third party.

To have these records deleted or their use stopped, email info@chordone.jp with the subject "Candidate data deletion request" and the URL of the profile concerned (for example https://www.linkedin.com/in/…). After confirming that you are the person concerned, we will delete every record about that profile from all workspaces (CRM records, attached files, photos, contact records and salary-estimate records) and let you know when it is done. If an agent opens your profile again afterwards, it may be recorded again.

11. Contact

For questions about this policy, handling of personal information, or unlinking external services, please contact us below.

12. Revisions

We may revise this policy as needed due to legal changes, service updates, or operational requirements. If there are important changes, we will notify you through the service or by other appropriate means.

Try the demo Try for free now