SFSSola Fileserver Service
Japanese/English← Back to home
Terms of UsePrivacy PolicyLegal Notice

SFS Privacy Policy

Last updated: 2026-07-26

Sola K.K. (Sola株式会社) (the "Company") handles personal information processed through SFS (Sola Fileserver Service) (the "Service") in accordance with Japan's Act on the Protection of Personal Information, other applicable law, and the Company's privacy policy.

The Japanese version is authoritative. If the English and Japanese versions differ, the Japanese version prevails.

1. Operator and Contact

  • Operator: Sola K.K. (Sola株式会社)
  • Address: VORT Suehirocho II 9F, 6-14-3 Sotokanda, Chiyoda-ku, Tokyo 101-0021, Japan
  • Representative: Keisuke Yoshimura, President and Representative Director
  • Personal Information Protection Manager: General Affairs Department Manager
  • Privacy contact: privacy@sola-air.com

Company-wide privacy policy: https://www.sola-air.com/privacy-policy/

2. Information We Collect

  • Account data: personal or organization name, email address, authentication method, and language setting. Passwords are hashed and are not retained in plaintext
  • External authentication data: provider identifier and email address or similar information supplied when Google or Microsoft sign-in is used
  • Subscription and payment data: selected plan, capacity, billing interval, subscription status, and Stripe customer and subscription identifiers. Stripe processes card numbers; the Company does not retain them
  • Service data: tenant URL, status, contracted capacity, usage, settings, operation history, and audit logs
  • Network and device data: IP address, access time, requested path, browser and device information, errors, and security logs
  • Inquiry data: the content of inquiries and contact details required to respond
  • Customer Data: files, folder names, sharing settings, Nextcloud user information, and other content stored in the Dedicated Environment
  • Public-page analytics: page path, sign-up method, location of a business-inquiry link, display language, referring domain, UTM parameters, and similar data. Full URL query strings and hashes, file names, and Customer Data are not stored in first-party analytics or sent to Google Analytics
  • Daily identifier for first-party analytics: the date, IP address, and User-Agent are HMAC-processed on the Company's server to suppress duplicate visits for that day. Raw IP addresses and User-Agent values are not stored in the analytics database

3. Purposes

  • Authentication and provision of the Service, including issuing environments and storing and sharing files
  • Pricing, payment, billing, cancellation, and subscription administration
  • Notices concerning the Service, failed payments, over-quota status, and scheduled deletion
  • Support, incident response, backup, and recovery
  • Prevention, investigation, and response concerning fraud, prohibited use, infringement, and security incidents
  • Aggregated service improvement and evaluation of registration flows without directly identifying an individual
  • Compliance with law, exercise of rights, and dispute handling

4. Customer Data

Customer Data is under the Customer's control. The Customer is responsible for notices, consent, permissions, and other requirements for personal information stored in the Dedicated Environment.

Only authorized Company personnel may access Customer Data, and only as necessary to provide, maintain, back up, support, or secure the Service or comply with law. Customer Data is not used for advertising.

5. Processors, External Services, and Disclosure

The Company uses the following external services where necessary or at the Customer's option. Each provider's terms and privacy policy also apply.

  • Stripe: payment, billing, and Customer Portal; name, email address, and subscription and payment data. https://stripe.com/privacy
  • Google: Google OAuth and Google Analytics on public pages; OAuth data, email address, and public-page usage data. https://policies.google.com/privacy?hl=en
  • Microsoft: Microsoft OAuth; OAuth data and email address. https://www.microsoft.com/en-us/privacy/privacystatement

The Company does not disclose personal data to a third party without consent, except where permitted by law, including where required by law or necessary to protect life, safety, or property and consent is difficult to obtain.

The Company limits data entrusted to a service provider to what is necessary and exercises appropriate contractual and other supervision.

6. Processing Outside Japan

Information may be stored or processed outside Japan through global services such as Stripe, Google, and Microsoft.

Where personal data is handled outside Japan, the Company takes steps required by applicable law, such as providing required information, obtaining consent, establishing contractual safeguards, and reviewing handling practices. Additional information about countries or safeguards will be provided on request where required by law.

7. Cookies, First-Party Analytics, and Google Analytics

The Service uses cookies for sign-in, security, one-time measurement of completed registration, and language settings. Disabling essential cookies may prevent features such as sign-in from working.

The Company aggregates use of public pages on its own servers without cookies or persistent device identifiers. Collection is limited to `/`, `/signup`, `/signup-complete`, and `/legal/*`; sign-in pages, dashboards, administration pages, pages containing verification or reset tokens, and dedicated Nextcloud environments are excluded. First-party analytics events are not sent when the browser enables Global Privacy Control or Do Not Track.

Google Analytics is used only on public pages (`/`, `/signup`, `/signup-complete`, and `/legal/*`). The analytics tag is not loaded on authenticated dashboards, administration pages, or pages containing verification or reset tokens. Analytics is not used for personalized advertising.

The Google Analytics opt-out browser add-on is available at https://support.google.com/analytics/answer/181881?hl=en

8. Retention and Deletion

Account information and Customer Data are generally retained while the Service is in use. On account deletion, sign-in email addresses, credentials, and OAuth links are removed, and deletion of the Dedicated Environment begins immediately.

A deleted tenant subdomain is held for 30 days to avoid misdelivery and is then released. Subscription, payment, audit, and anti-abuse records are retained only as long as necessary for legal retention, accounting, disputes, or security, and are then deleted or made less readily identifiable.

Encrypted backups are generally retained as 14 daily, eight weekly, and six monthly versions. Data removed from the active environment may remain in a backup until that retention cycle expires and is not used for ordinary service restoration.

A sign-in session lasts no longer than 30 days. Email verification links expire after 24 hours, and password reset links expire after 60 minutes. First-party analytics events are deleted automatically after 90 days, and the daily identifier changes when the date changes. Google Analytics data is retained according to the settings of the relevant Google Analytics property.

9. Security Measures

The Company applies risk-appropriate measures such as assigning responsibility and access permissions, personnel training, access controls, audit logging, encryption in transit, password hashing, encrypted backups, vulnerability and incident monitoring, service-provider oversight, and physical access controls.

Further information about security measures will be provided on request to the extent doing so does not compromise security.

10. Individual Rights and Changes

An individual may request notice of purpose, access, correction, addition, deletion, restriction, erasure, or cessation of third-party disclosure of their personal data held by the Company. After identity verification, the Company responds as required by law. Requests may be sent to privacy@sola-air.com.

The Company may update this Policy. A material change will be announced through the Service or by email before it takes effect.