APOLLO11 Inc. (hereinafter referred to as "the Company") recognizes the importance of protecting the personal information of customers who use FusionBase (hereinafter referred to as "the Service") and endeavors to handle and protect it appropriately in accordance with the following Privacy Policy.
1. Collection of Personal Information
The Company collects the following personal information in providing the Service:
- Name, email address, company name, department, phone number
- Inquiry content, demo reservation information, document download history
- Usage history (login information, usage dates, features used, etc.)
- AI activity logs (tool call records from AI assistants)
- Payment information (credit card information, invoice information, etc.)
- Technical information such as IP address, browser information, and device information
2. Purposes of Use
The Company uses collected personal information for the following purposes:
- Provision, operation, maintenance, and improvement of the Service
- Responding to inquiries from customers and providing support
- Scheduling demo reservations and sending materials
- Contract management, billing, and payment processing
- Information provision regarding the Service and notification of new features
- Audit and security management of AI connections
- Statistical data analysis for service quality improvement (in a form that does not identify individuals)
- Prevention of fraudulent use and security measures
- Fulfillment of obligations under laws and regulations
3. Classification of User Data and Usage Data
The Service handles customer data as classified below:
3.1 User Data (Customer Content)
- All data input, registered, uploaded, or stored by the Customer on the Service
- Rights to User Data belong to the Customer (or the Customer's licensors)
- The Company only accesses and uses User Data for the purposes of providing, maintaining, improving, and optimizing the Service
- The Company does not use User Data for AI model training, improvement, or other purposes
3.2 Usage Data
- Statistical information and log information regarding the use of the Service
- Does not include User Data
- The Company may use Usage Data for business purposes such as service improvement, quality assurance, product development, and security measures
- Aggregated and anonymized Usage Data may be published or provided to third parties as statistical information
4. Data Processing in AI Connections
The Service provides a mechanism for AI assistants (such as Claude) to access databases through MCP (Model Context Protocol).
- Your Data Will Not Be Used for Training: The Company does not use database data stored by customers on the Service for AI model training, improvement, or fine-tuning purposes.
- No Direct Provision to AI Vendors: When customers connect AI assistants via API keys or OAuth, database data is accessed through MCP servers managed by the Company. Customers do not directly send data to AI vendors (OpenAI, Anthropic, etc.).
- Scope of OAuth Connections: AI assistants connected via OAuth access data with the same permissions as the connected team member. Permissions are set per database, and assistants cannot access masked fields or data outside the Row Scope.
- Supervised Write: When approval-based writing is enabled, AI assistant creations, updates, and deletions are finalized only after customer approval.
- AI Activity Logs: All tool calls from AI assistants are retained as audit logs for 31 days.
5. Semantic Search and Embedding Data
- The Service's Semantic Search feature generates embedding vectors from content in fields explicitly selected by the Customer.
- Embedding generation is performed by the Company's managed pipeline, and the Customer does not need to provide API keys to AI vendors.
- Generated embedding vectors are managed in an environment physically and logically separated from the Customer's team data.
- Embedding vectors are used solely for providing the Semantic Search feature.
- Embedding vectors are not used for AI model training or improvement.
6. Third-Party Provision
- Except as required by law, the Company does not provide personal information to third parties without customer consent.
- Personal information may be entrusted to the following third parties to the extent necessary for providing the Service:
- Payment processing agents (Stripe: credit card payment processing)
- Cloud service providers (data storage and server operation)
- Customer support business contractors
- The Company exercises appropriate management and supervision over contractors to ensure thorough personal information protection.
7. Security Measures
The Company implements the following security management measures to prevent leakage, loss, or damage of personal information and User Data:
- Complete data isolation per team (multi-tenant architecture)
- Encrypted communication (TLS/SSL) and encrypted storage for data retention
- Two-factor authentication (TOTP) and passkey provision
- Principle of least privilege for API keys (read-only by default), expiration dates, and rate limits
- IP address allowlist (firewall)
- Complete audit logs (AI activity logs retained for 31 days, record history retained permanently)
- Personal information protection education for employees
- Access privilege management and periodic security audits
8. Use of Cookies and Similar Technologies
The Company uses cookies and similar technologies to improve the convenience of the Service and for access analysis.
Customers may disable cookies through browser settings, but some features may not function properly.
Cookies used by the Company include:
- Strictly necessary cookies (login state maintenance, security functions)
- Settings storage cookies (language settings, theme settings, etc.)
- Access analysis cookies (Google Analytics, etc.)
For detailed cookie settings, please refer to the Company's Cookie Policy.
9. Data Retention
- The Company retains personal information and User Data only for the period necessary to achieve the purposes of collection.
- Longer retention may be necessary for legal obligations, dispute resolution, and compliance purposes.
- AI activity logs are retained for 31 days.
- Record history is retained permanently.
- Trash data is automatically and completely deleted after 30 days.
- When a customer cancels their account, User Data will be deleted after a certain period.
10. Disclosure, Correction, and Deletion of Personal Information
When a request for disclosure, correction, suspension of use, or deletion of personal information is made by the customer themselves, the Company will respond promptly.
- Request method: Please contact the inquiry desk below.
- The Company may require information to verify identity.
- Disclosure or deletion may not be possible under certain laws.
- Data portability (receiving data in a structured format) is also available upon request.
11. Contact Information
For inquiries regarding the handling of personal information, please contact:
- APOLLO11 Inc.
- Personal Information Protection Manager
- Email: [email protected]
- Business hours: Weekdays 10:00-18:00 (excluding Saturdays, Sundays, and holidays)
12. Changes to the Privacy Policy
- The Company may revise this Privacy Policy in response to amendments to laws, changes in service content, etc.
- The revised Privacy Policy takes effect from the time it is posted on this page.
- Important changes will be notified through the Service or by email.