本サービスは、ログイン状態の維持等、サービスの提供に必要なCookieを使用します。現在、アクセス解析ツールや広告配信のためのCookie・タグは使用していません。導入する場合は、本ポリシーを改定し、必要な同意取得の仕組みとあわせてお知らせします。なお、本サービスは、ブラウザのDo Not Track信号には応答しません。
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice. This English version is provided for reference; the Japanese version prevails.
Privacy Policy
Bank Invoice Corporation (the "Company") handles users' information, including personal information, in connection with its digital invoice service "BankInvoice" (the "Service") as follows, in accordance with the Act on the Protection of Personal Information of Japan and other applicable laws.
1. Data Controller
Bank Invoice Corporation
Representative: Taro Teshima, CEO
Address: 1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japan
Contact: / contact form (https://biv.jp/chfJV0)
2. Information We Collect
Account information: organization name, department, name, email address and other information provided at registration.
Invoice Data: invoices and associated messages and histories created, sent, received or stored through the Service (which may include names and contact details of your counterparties' staff).
Usage information: operation logs, access logs, device and browser information.
Payment information: for credit card payments, card details are handled by our payment processor; the Company does not itself store card numbers.
The Service is intended for business-to-business use. The personal data we process generally relates to officers and employees acting on behalf of organizations in the course of their work, rather than to individuals acting as consumers.
The Service is not intended for use by children under 16. We do not intentionally collect or process special categories of personal data (or sensitive personal information under Japanese law); please do not enter such information into Invoice Data or elsewhere in the Service.
3. Purposes of Use
We use the information to: (i) provide the Service, verify identity and bill fees; (ii) respond to inquiries and provide support; (iii) address incidents and misuse and maintain security; (iv) send important notices such as amendments and maintenance; (v) send information about new features and use cases (you can opt out of such emails at any time); (vi) compile statistics in a form that does not identify any individual or organization, to improve the Service; and (vii) comply with laws.
4. Transmission and Sharing of Invoice Data
The purpose of the Service is to exchange Invoice Data with your counterparties. Accordingly, Invoice Data and associated messages and statuses are transmitted to and shared with the counterparties you designate, including via the Peppol access point providers used by those counterparties.
Once Invoice Data has been delivered to a counterparty, its handling is subject to the control of that counterparty and of the access point provider they use. We do not control, and are not responsible for, how those parties handle personal data.
5. Cookies
The Service uses cookies necessary to provide the Service, such as maintaining login sessions. We do not currently use analytics or advertising cookies or tags. If we introduce them, we will update this Policy and implement any required consent mechanisms. The Service does not respond to browser Do Not Track signals.
6. Outsourcing
We may entrust the handling of information to external providers to the extent necessary for the purposes above (e.g., cloud infrastructure providers, payment processors), selecting them appropriately and supervising them as necessary.
The terms on which we entrust the processing of personal data are set out in the Data Processing Addendum. Our current providers are listed on the Subprocessors page.
7. Provision to Third Parties
We do not provide personal information to third parties except: (i) with your consent; (ii) transmission and sharing with counterparties inherent in the nature of the Service (Section 4); or (iii) as required by law.
8. International Transfers
Where you exchange invoices with counterparties located outside Japan, Invoice Data is transmitted to the Peppol access point provider and the counterparty in the relevant country. Such transfers are made at your instruction and are necessary for the performance of the Service. We take the measures required by applicable law with respect to such transfers.
9. Retention
We retain information for as long as necessary for the purposes above. Invoice Data is retained during the contract period and may be exported for thirty (30) days after termination, after which it is deleted within ninety (90) days unless retention is required by law (data contained in backups is erased no later than one hundred and eighty (180) days after the deletion). Account information is deleted after termination, except to the extent and for the period required for statutory retention or the handling of disputes. Usage information such as operation logs is retained only for as long as necessary for security and the other purposes above.
10. Security
We take necessary and appropriate measures to prevent leakage, loss or damage of information, including the following.
Encryption in transit (TLS), encryption at rest, role-based access control on a least-privilege basis, two-factor authentication for sign-in, operation logging, periodic backups, and monitoring.
Data is stored at multiple geographically separate locations within Japan.
11. Your Requests
You may request disclosure, correction, addition, deletion or suspension of use of your personal information held by us via the contact form. We will respond in accordance with applicable law after verifying your identity.
12. For Users in the EU/EEA, UK and Similar Jurisdictions
Where the GDPR or similar laws apply, we process personal data on the following legal bases: performance of a contract (providing the Service), legitimate interests (security, service improvement, communications with existing customers), compliance with legal obligations (such as record-keeping and tax requirements) and consent (where processing is based on consent). You have the rights of access, rectification, erasure, restriction, data portability and objection under applicable law, and the right to lodge a complaint with a supervisory authority. To exercise these rights, please use the contact form. Transfers of personal data from the EU/EEA or the United Kingdom to Japan are made on the basis of the adequacy decisions for Japan, and we comply with the Supplementary Rules issued by Japan's Personal Information Protection Commission.
US state privacy notice: We do not sell or share personal information.
13. Business Transfers
If we transfer our business through a merger, corporate split, transfer of business or otherwise, we may transfer information to the successor within the scope of the purposes set out in this Policy. In that case, we will require the successor to handle the information in a manner equivalent to this Policy.
14. Amendments
We may amend this Policy in response to changes in law or the Service. Material changes will be announced by posting on the Service or other appropriate means.
15. Contact
For inquiries regarding this Policy or our handling of personal information, please email or use the contact form (https://biv.jp/chfJV0).
Established: July 12, 2026
Bank Invoice Corporation
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice. This English version is provided for reference; the Japanese version prevails (Article 21).
Terms of Service
These Terms of Service (the "Terms") set out the conditions for use of the digital invoice service "BankInvoice" (the "Service") provided by Bank Invoice Corporation (the "Company"). By using the Service, you (the "User") agree to these Terms.
Article 1 (Application)
These Terms apply to all relationships between the Company and Users concerning use of the Service.
The Service is intended for use by businesses (organizations and individuals using the Service for business purposes).
Guidelines, help pages and other rules posted by the Company within the Service (the "Individual Provisions") form part of these Terms. If the Individual Provisions conflict with these Terms, the Individual Provisions prevail.
Article 2 (Definitions)
"Invoice Data" means invoices (including quotations, purchase orders and other transaction documents) and associated messages, statuses and histories created, sent, received or stored through the Service.
"Registered Organization" means a corporation, other entity or individual that has completed registration for the Service.
"Peppol Network" means the international document exchange network managed by OpenPeppol.
Article 3 (Registration)
A person wishing to use the Service shall register through the method prescribed by the Company after agreeing to these Terms.
The Company may decline a registration where it determines that any of the following applies, without any obligation to disclose its reasons: (i) the registration contains false statements, errors or omissions; (ii) the applicant has previously breached these Terms; (iii) the applicant breaches the representation in Article 15 (Exclusion of Anti-Social Forces); or (iv) the Company otherwise reasonably considers the registration inappropriate.
Article 4 (Account Management)
Users shall manage their account credentials (IDs, passwords, etc.) appropriately at their own responsibility.
Any act performed on the Service using an account is deemed the act of the User holding that account.
Where a Registered Organization allows its officers or employees to use the Service, it shall cause them to comply with these Terms and shall be responsible for their acts.
Article 5 (Fees and Payment)
Fees for paid plans are as displayed on the application screens and the Company's pricing page. Receiving invoices is free of charge.
Payment shall be made by credit card or by invoice. Credit card payments are made in advance at the start of each contract period; invoice payments are due by the payment deadline stated in the Company's invoice.
If a User delays payment, the Company may charge late payment interest at a rate of 14.6% per annum.
The Company does not charge for receiving invoices on a per-invoice basis and does not impose a limit on the number of invoices received. However, if a User's use continues to significantly exceed the range of normal use for a comparable plan, the Company may contact the User to discuss moving to an individual agreement (the Enterprise plan). In such a case, the Company shall notify the User at least thirty (30) days before the change takes effect, and the change shall apply from the next renewal. The Company shall not suspend or delay the receipt of invoices on the basis of this paragraph.
Article 6 (Term, Renewal and Cancellation)
The term of a paid plan is one (1) year and automatically renews for successive one-year periods on the same conditions, unless either party gives notice of non-renewal no later than thirty (30) days before the expiry date.
Users may cancel mid-term at any time through the method prescribed by the Company; however, fees already paid will not be refunded, and where payment is by invoice, the obligation to pay fees for the remaining contract period is not extinguished.
Free use of the Service may be terminated by the User at any time.
Cancellation of a paid plan does not terminate the agreement; use continues on the free plan. The agreement terminates (the termination referred to in Article 8) when the User requests, through the method prescribed by the Company, the cancellation of all use of the Service (account closure), or when the agreement is terminated in accordance with these Terms.
Article 7 (Nature of the Service)
The Service enables Users to send, receive and share Invoice Data with counterparties designated by the User, via the Peppol Network or via email-based notifications.
Email notifications sent by the Service may fail to arrive due to the recipient mail server’s settings, spam filtering or other factors outside the Company’s control. The Company does not guarantee the delivery of email.
By the nature of the Service, Invoice Data and associated messages and statuses are transmitted to, and shared with, the counterparties designated by the User.
Where a counterparty uses another provider's Peppol-ready service, some functions or information (such as messages) may not be displayed on the counterparty's screen, depending on the specifications of that service.
Article 8 (Handling of Data)
Rights in Invoice Data belong to the User or the User's Registered Organization.
The Company handles Invoice Data to the extent necessary to provide, maintain and troubleshoot the Service, to comply with laws, and to compile statistics and analyses in a form that does not identify any individual or organization, for the purpose of improving the Service.
Statutory obligations to preserve books and records (including under Japan's Electronic Bookkeeping Act) rest with the User; the Company provides functions for such preservation but does not guarantee the User's own compliance.
For thirty (30) days after termination, Users may export their Invoice Data through the method prescribed by the Company. After that period, the Company will delete Invoice Data within ninety (90) days, except where retention is required by law. Data contained in backups is erased in the ordinary rotation of backups, and in any event within one hundred and eighty (180) days of the deletion.
Article 9 (Intellectual Property)
Rights in Invoice Data and other data entered or stored in the Service by Users belong to the User or the registered organization to which the User belongs, as set out in the preceding article.
All intellectual property rights in the Service, including its software, screens, documentation and trademarks, belong to the Company or to third parties that license those rights to the Company.
These Terms grant Users the right to use the Service in accordance with these Terms. They do not assign the intellectual property rights referred to in the preceding paragraph or transfer any other rights to Users.
The Company may use any suggestions, requests or other feedback provided by Users in connection with the Service, for improving the Service or otherwise, without any obligation to the User, including any obligation of payment.
Article 10 (Prohibited Acts)
Users shall not: (i) violate laws or public order and morals; (ii) send false Invoice Data or otherwise deceive third parties; (iii) infringe the intellectual property, privacy or other rights or interests of the Company or third parties; (iv) place excessive load on, or interfere with, the Service's servers or networks; (v) gain unauthorized access to, reverse engineer or otherwise analyze the Service; (vi) transfer or lend accounts to third parties; (vii) use the Service in violation of applicable export control or economic sanctions laws (including use in or from sanctioned countries or regions, or by persons on sanctions lists); or (viii) engage in any other act the Company reasonably considers inappropriate.
Article 11 (Suspension of the Service)
The Company may suspend or interrupt all or part of the Service without prior notice where: (i) maintenance or updates are performed (planned maintenance will be announced in advance where possible); (ii) provision becomes difficult due to earthquake, lightning, fire, power outage, other force majeure, or failures of telecommunication lines or cloud infrastructure; or (iii) the Company otherwise determines suspension is necessary.
The Company is not liable for damage arising from such suspension beyond the scope of Article 14.
Article 12 (Changes to and Termination of the Service)
The Company may change the content of, or terminate, the Service with reasonable prior notice to Users.
Where the Service is terminated, the Company will in principle give at least thirty (30) days' notice and provide an opportunity for Users to export their Invoice Data.
Article 13 (Disclaimer of Warranties)
The Company does not warrant that the Service is free from defects in fact or in law (including as to safety, reliability, accuracy, completeness or fitness for a particular purpose).
The Company is not liable for delays, non-delivery or malfunction of transmissions caused by the Peppol Network, telecommunication lines, services used by counterparties, or other factors outside the Company's control.
The Company does not control, and is not responsible for, the availability, operational policies or specification changes of OpenPeppol, other Peppol authorities, or the access point providers used by counterparties.
The Company does not warrant that the Service will operate without interruption. No uptime or other service level is guaranteed unless separately agreed in writing between the Company and the User.
The Company is not liable for damage caused by force majeure, including natural disasters, epidemics, war or terrorism, cyberattacks, power outages, failures of telecommunications lines or cloud infrastructure, or changes in law or government action.
Article 14 (Limitation of Liability)
Where the Company is liable to a User for default or tort, the Company shall compensate only direct and ordinary damage actually incurred, up to the total fees actually received by the Company from that User for the Service during the twelve (12) months preceding the occurrence of the damage. The Company is not liable for lost profits or indirect, incidental or special damage, except in cases of the Company's willful misconduct or gross negligence.
For use of the Service free of charge, the Company is not liable except in cases of its willful misconduct or gross negligence.
This Article does not apply to damage caused by the Company's willful misconduct or gross negligence, or to liability that cannot be excluded under applicable law.
If a third party brings a claim against the Company arising from a User's breach of these Terms or unlawful use of the Service, the User will resolve the claim at its own responsibility and expense and will compensate the Company for resulting damage, including reasonable attorneys' fees.
Article 15 (Exclusion of Anti-Social Forces)
Users represent and warrant that they are not, and have no socially condemnable relationship with, organized crime groups, their members or equivalent persons. The Company may terminate the agreement without notice if a User is found to be in breach of this representation.
Article 16 (Confidentiality)
The Company and Users shall not disclose or divulge the other party's confidential information obtained in connection with the Service to third parties without prior consent, except for disclosure required by law and transmission or sharing with counterparties inherent in the nature of the Service.
Article 17 (Personal Information)
The Company handles personal information obtained through the Service appropriately in accordance with its Privacy Policy.
Article 18 (No Assignment)
Users may not assign or pledge their contractual status or rights or obligations under these Terms to third parties without the Company's prior written consent.
Article 19 (Amendment of these Terms)
The Company may amend these Terms in accordance with Article 548-4 of the Civil Code of Japan.
When amending these Terms, the Company will announce the amended Terms and their effective date by posting on the Service or other appropriate means a reasonable period before the effective date (in principle, at least thirty (30) days for changes that materially affect Users).
Article 20 (Governing Law and Jurisdiction)
These Terms are governed by and construed in accordance with the laws of Japan.
The Tokyo District Court has exclusive jurisdiction as the court of first instance over any dispute concerning the Service.
Article 21 (Language)
The Japanese text of these Terms is the authentic text. Where a translation is prepared for reference, the Japanese version prevails in the event of any inconsistency.
Established: July 12, 2026
Bank Invoice Corporation
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Legal Notice
This page provides legal information about Bank Invoice Corporation, the provider of the BankInvoice service, as required by applicable e-commerce and information laws.
Company
Bank Invoice Corporation (Bank Invoice株式会社)
Representative
Taro Teshima, CEO
Registered Address
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japan
Business
Development and operation of a digital invoicing platform
Contact
Email:
Contact form: https://biv.jp/chfJV0
A telephone number will be disclosed without delay upon request.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Informazioni sul fornitore
Questa pagina riporta le informazioni legali su Bank Invoice Corporation, fornitore del servizio BankInvoice, ai sensi della normativa applicabile.
Società
Bank Invoice Corporation (Bank Invoice株式会社)
Rappresentante
Taro Teshima, CEO
Sede
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Giappone
Attività
Sviluppo e gestione di una piattaforma di fatturazione digitale
Contatti
E-mail:
Modulo di contatto: https://biv.jp/chfJV0
Il numero di telefono viene comunicato senza indugio su richiesta.
Registrazione
Numero di società (Giappone): 7010001167632 (verifica su gBizINFO (METI))
Numero di registrazione come emittente di fatture qualificato (Giappone): T7010001167632 (verifica sul registro della NTA)
Partita IVA: non applicabile (società giapponese)
In caso di difformità tra la versione giapponese e quella italiana di questa pagina, prevale la versione giapponese.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Informações do prestador
Esta página apresenta as informações legais sobre a Bank Invoice Corporation, fornecedora do serviço BankInvoice, nos termos da legislação aplicável.
Empresa
Bank Invoice Corporation (Bank Invoice株式会社)
Representante
Taro Teshima, CEO
Sede
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japão
Atividade
Desenvolvimento e operação de uma plataforma de faturação digital
Contactos
E-mail:
Formulário de contacto: https://biv.jp/chfJV0
O número de telefone é comunicado sem demora mediante pedido.
Registo
Número de sociedade (Japão): 7010001167632 (verificar no gBizINFO (METI))
Número de registo como emitente de faturas qualificado (Japão): T7010001167632 (verificar no registo da NTA)
N.º de IVA: não aplicável (sociedade japonesa)
Em caso de divergência entre as versões japonesa e portuguesa desta página, prevalece a versão japonesa.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Bedrijfsgegevens
Deze pagina bevat de wettelijke gegevens over Bank Invoice Corporation, aanbieder van de dienst BankInvoice, zoals vereist door toepasselijke wetgeving.
Bedrijf
Bank Invoice Corporation (Bank Invoice株式会社)
Vertegenwoordiger
Taro Teshima, CEO
Adres
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japan
Activiteit
Ontwikkeling en exploitatie van een platform voor digitale facturen
Contact
E-mail:
Contactformulier: https://biv.jp/chfJV0
Een telefoonnummer wordt op verzoek onverwijld verstrekt.
Registratie
Ondernemingsnummer (Japan): 7010001167632 (controleren op gBizINFO (METI))
Registratienummer als gekwalificeerde factuuruitgever (Japan): T7010001167632 (controleren in het NTA-register)
Btw-nummer: niet van toepassing (Japanse onderneming)
Bij verschillen tussen de Japanse en de Nederlandse versie van deze pagina prevaleert de Japanse versie.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Upplýsingar um þjónustuveitanda
Á þessari síðu eru lögboðnar upplýsingar um Bank Invoice Corporation, veitanda þjónustunnar BankInvoice.
Fyrirtæki
Bank Invoice Corporation (Bank Invoice株式会社)
Fyrirsvarsmaður
Taro Teshima, CEO
Heimilisfang
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japan
Starfsemi
Þróun og rekstur stafræns reikningakerfis
Tengiliður
Netfang:
Eyðublað fyrir fyrirspurnir: https://biv.jp/chfJV0
Símanúmer er veitt án tafar sé þess óskað.
Skráningarupplýsingar
Fyrirtækjanúmer (Japan): 7010001167632 (staðfesta á gBizINFO (METI))
Skráningarnúmer sem hæfur reikningsútgefandi (Japan): T7010001167632 (staðfesta í skrá NTA)
VSK-númer: á ekki við (japanskt félag)
Ef misræmi er á milli japönsku og íslensku útgáfu þessarar síðu gildir japanska útgáfan.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Dane usługodawcy
Ta strona zawiera wymagane prawem informacje o Bank Invoice Corporation, dostawcy usługi BankInvoice.
Firma
Bank Invoice Corporation (Bank Invoice株式会社)
Przedstawiciel
Taro Teshima, CEO
Adres
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japonia
Działalność
Rozwój i prowadzenie platformy faktur cyfrowych
Kontakt
E-mail:
Formularz kontaktowy: https://biv.jp/chfJV0
Numer telefonu udostępniamy niezwłocznie na żądanie.
Dane rejestrowe
Numer spółki (Japonia): 7010001167632 (sprawdź w gBizINFO (METI))
Numer rejestracyjny kwalifikowanego wystawcy faktur (Japonia): T7010001167632 (sprawdź w rejestrze NTA)
Numer VAT: nie dotyczy (spółka japońska)
W razie rozbieżności między japońską a polską wersją tej strony rozstrzygająca jest wersja japońska.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Údaje o poskytovateli
Tato stránka obsahuje zákonem vyžadované údaje o společnosti Bank Invoice Corporation, poskytovateli služby BankInvoice.
Společnost
Bank Invoice Corporation (Bank Invoice株式会社)
Zástupce
Taro Teshima, CEO
Sídlo
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japonsko
Předmět činnosti
Vývoj a provoz platformy pro digitální faktury
Kontakt
E-mail:
Kontaktní formulář: https://biv.jp/chfJV0
Telefonní číslo sdělíme bez zbytečného odkladu na vyžádání.
Registrační údaje
Číslo společnosti (Japonsko): 7010001167632 (ověřit v gBizINFO (METI))
Registrační číslo kvalifikovaného vystavitele faktur (Japonsko): T7010001167632 (ověřit v registru NTA)
DIČ: nepoužije se (japonská společnost)
V případě rozporu mezi japonskou a českou verzí této stránky má přednost japonská verze.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Informații despre furnizor
Această pagină conține informațiile legale despre Bank Invoice Corporation, furnizorul serviciului BankInvoice.
Societate
Bank Invoice Corporation (Bank Invoice株式会社)
Reprezentant
Taro Teshima, CEO
Sediu
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japonia
Obiect de activitate
Dezvoltarea și operarea unei platforme de facturare digitală
Contact
E-mail:
Formular de contact: https://biv.jp/chfJV0
Numărul de telefon este comunicat fără întârziere, la cerere.
Date de înregistrare
Număr de societate (Japonia): 7010001167632 (verificați pe gBizINFO (METI))
Număr de înregistrare ca emitent calificat de facturi (Japonia): T7010001167632 (verificați în registrul NTA)
Cod TVA: nu se aplică (societate japoneză)
În caz de neconcordanță între versiunea japoneză și cea română a acestei pagini, prevalează versiunea japoneză.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Paslaugų teikėjo informacija
Šiame puslapyje pateikiama teisės aktų reikalaujama informacija apie Bank Invoice Corporation, paslaugos BankInvoice teikėją.
Bendrovė
Bank Invoice Corporation (Bank Invoice株式会社)
Atstovas
Taro Teshima, CEO
Adresas
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Japonija
Veikla
Skaitmeninių sąskaitų faktūrų platformos kūrimas ir priežiūra
Kontaktai
El. paštas:
Kontaktų forma: https://biv.jp/chfJV0
Telefono numerį pateikiame nedelsdami pagal prašymą.
Registracijos duomenys
Bendrovės numeris (Japonija): 7010001167632 (patikrinti gBizINFO (METI))
Kvalifikuoto sąskaitų faktūrų išrašytojo registracijos numeris (Japonija): T7010001167632 (patikrinti NTA registre)
PVM kodas: netaikoma (Japonijos bendrovė)
Esant neatitikimų tarp šio puslapio japonų ir lietuvių kalbos versijų, pirmenybė teikiama japonų kalbos versijai.
⚠️ This is an AI-generated draft. Have it reviewed by a qualified lawyer before publication and remove this notice.
Maklumat penyedia
Halaman ini memaparkan maklumat perundangan tentang Bank Invoice Corporation, penyedia perkhidmatan BankInvoice.
Syarikat
Bank Invoice Corporation (Bank Invoice株式会社)
Wakil
Taro Teshima, CEO
Alamat
1-14-10 Kyobashi, Chuo-ku, Tokyo 104-0031, Jepun
Aktiviti
Pembangunan dan pengendalian platform invois digital
Hubungi
E-mel:
Borang hubungan: https://biv.jp/chfJV0
Nombor telefon akan diberikan tanpa berlengah atas permintaan.
Maklumat pendaftaran
Nombor syarikat (Jepun): 7010001167632 (sahkan di gBizINFO (METI))
Nombor pendaftaran pengeluar invois berkelayakan (Jepun): T7010001167632 (sahkan dalam daftar NTA)
Nombor VAT: tidak berkenaan (syarikat Jepun)
Sekiranya terdapat percanggahan antara versi bahasa Jepun dan bahasa Melayu halaman ini, versi bahasa Jepun akan diguna pakai.
⚠️ This document is an AI-generated draft. Have it reviewed by a qualified professional before publication, then remove this notice.
Data Processing Addendum
This Addendum sets out the terms on which Bank Invoice Corporation (the "Company") processes personal data on behalf of Users in providing BankInvoice (the "Service"). This Addendum forms part of the Terms of Service. It is intended to address the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and the corresponding provisions of the UK GDPR, and the requirement under Japan's Act on the Protection of Personal Information (APPI) to supervise parties entrusted with the handling of personal data.
1. Definitions
In this Addendum:
Personal Data means information entered into the Service, or sent or received through it, that identifies an individual.
Controller means the party that determines the purposes and means of processing.
Processor means the party that processes Personal Data on behalf of a Controller.
Subprocessor means a third party engaged by the Company to carry out part of the processing.
Invoice Data has the meaning given in Article 2 of the Terms of Service and includes returns and other messages attached to invoices, and records of their status.
Account Information means information the Company collects for the registration, authentication and billing of Users (such as the name and email address of the registrant and payment-related information).
Service Metadata means records the Company generates in operating the Service (such as sending and receiving timestamps, message IDs, operation logs and system logs).
2. Scope and Roles
For Personal Data contained in Invoice Data, the User is the Controller and the Company is the Processor.
For Account Information and Service Metadata (in each case, to the extent they constitute Personal Data), the Company acts as its own Controller and processes them in accordance with its Privacy Policy, for the purposes of operating the Service, ensuring security, preventing misuse, troubleshooting, billing and complying with law. That processing is outside the scope of this Addendum. However, records provided to Users as part of Invoice Data (such as status records), including timestamps and similar Service Metadata, are covered by this Addendum as Invoice Data.
The Service may send and receive Invoice Data through the Peppol Network. The service provider (access point provider) that the Company uses to connect to the Peppol Network and to register receiving capability (SMP) is a Subprocessor of the Company and is listed in the Subprocessor List. The operators of the Peppol Network (OpenPeppol and the operator of the SML), as well as the access point providers and SMP operators used by counterparties, are not Subprocessors of the Company and are not under its direction or control.
Once Invoice Data has been delivered to a counterparty, its handling is subject to the control of that counterparty and of the access point provider they use. The counterparty is an independent Controller, and the Company is not responsible for that processing.
3. Details of Processing
Purpose: provision of the Service, namely sending, receiving, storing, viewing and returning Invoice Data and recording its status.
Types of data: counterparty names, names of staff, department names, contact details and other information appearing on invoices.
Categories of data subjects: officers and employees of Users and their counterparties. The Service is intended for business-to-business use and does not primarily concern individuals acting as consumers.
Duration: the term of the contract and the period after termination set out in Article 8 of the Terms of Service.
4. Obligations of the Company
The Company processes Personal Data only on the User's instructions and in accordance with this Addendum. The User gives instructions through its use of the Service and through operations performed in accordance with the Terms of Service and this Addendum; any different instructions require the written agreement (including by electronic means) of the Company and the User.
Where the law requires processing that differs from this Addendum or from the User's instructions, the Company will inform the User before processing, unless prohibited from doing so by law. The Company will also inform the User if, in its view, an instruction infringes the law. In that case, the Company is not obliged to follow that instruction.
The Company ensures that Personal Data is processed only by personnel who are bound by contractual or statutory obligations of confidentiality.
The Company implements the technical and organizational security measures set out in Annex 1.
The Company does not use Personal Data beyond what is necessary to provide the Service. In particular, the Company does not use Personal Data for advertising, for sale to third parties, or for training machine-learning models.
The Company keeps records of its processing of Personal Data to the extent required by law.
Where the Company is required by law to disclose Personal Data, it will notify the User unless prohibited from doing so by law. In that case, the Company will limit the disclosure to what is required by law.
Where the California Consumer Privacy Act (CCPA) applies, the Company acts as a "service provider" under that law and does not sell or share Personal Data, or retain, use or disclose it beyond what is necessary to provide the Service.
5. Subprocessors
The User authorizes the Company to engage Subprocessors for the provision of the Service. Current Subprocessors are listed on the Subprocessors page.
Where the Company adds or replaces a Subprocessor, it will give advance notice by posting on the Service or by other appropriate means.
Within thirty (30) days of such notice, the User may object on reasonable grounds. If the parties cannot resolve the matter through discussion, the User may terminate the contract before the change takes effect.
The Company imposes obligations equivalent to this Addendum on its Subprocessors and remains responsible to the User for their acts as for its own.
6. Assistance with Data Subject Rights and Compliance
Where a data subject makes a request for access, correction, deletion, restriction or any similar right, the Company will provide reasonable assistance, including through the functions of the Service, so that the User can respond. If the Company receives such a request directly, it will forward it to the User, and will not respond to the request without the User's prior authorization, except where the Company is itself required to respond by law.
Where the User carries out a data protection impact assessment (DPIA) or a prior consultation with a supervisory authority, the Company will provide reasonable assistance, including information about the processing.
7. Notification of Incidents
If the Company becomes aware of any leakage, loss or damage of Personal Data, or a risk of the same, it will notify the User without undue delay and, where feasible, within seventy-two (72) hours of becoming aware. The notification will include, so far as known, an outline of the incident, the types and volume of data affected, and the measures the Company has taken.
The Company will investigate the cause of the incident and take reasonable measures to prevent recurrence. Where the User is required by law to report to a supervisory authority or to notify data subjects, the Company will cooperate reasonably.
8. Audits and Information
On the User's request, the Company will provide, in writing, the information necessary to verify compliance with this Addendum.
Such information will be provided no more than once per year, except following an incident involving Personal Data or where required by law.
Whether an on-site audit is carried out, and its scope, method and allocation of costs, will be agreed separately between the parties.
9. International Transfers
The Company may transfer Personal Data outside Japan, including by reason of the location of a Subprocessor. Where it does so, the Company takes the measures required by the law of the relevant jurisdiction.
Transfers from the European Economic Area or the United Kingdom to Japan are made on the basis of the adequacy decisions for Japan. For Personal Data transferred from those jurisdictions, the Company complies with the Supplementary Rules issued by Japan's Personal Information Protection Commission.
Where a Subprocessor outside Japan processes Personal Data, the Company applies the obligations set out in Article 5 and takes any protective measures required by law for that transfer.
Where standard contractual clauses or another transfer mechanism must be agreed separately (including if an adequacy decision ceases to have effect), the Company and the User will negotiate and agree them in good faith.
10. On Termination
The treatment of Personal Data after termination follows Article 8 of the Terms of Service. For thirty (30) days after termination, Users may export their Invoice Data through the method prescribed by the Company. After that period, the Company will delete the Personal Data within ninety (90) days, except where retention is required by law. Personal Data contained in backups is erased in the ordinary rotation of backups, and in any event within one hundred and eighty (180) days of the deletion. On the User's reasonable request, the Company will provide written confirmation (including by electronic means) that deletion has taken place.
11. Responsibilities of the User
The User is responsible for having a lawful basis for the collection of Personal Data and for its provision to the Company.
The User is responsible for notices to data subjects, for obtaining any necessary consent, and for any other steps required of a Controller by law.
The User will ensure that its instructions to the Company comply with the law.
12. Relationship to the Terms of Service
This Addendum forms part of the Terms of Service. In the event of any inconsistency between this Addendum and the Terms of Service or any other document concerning the processing of Personal Data, this Addendum prevails. The liability of the parties under this Addendum is subject to Article 14 (Limitation of Liability) of the Terms of Service.
13. Governing Law
This Addendum is governed by the laws of Japan.
Annex 1 (Technical and Organizational Measures)
The Company implements the following measures to protect Personal Data. The Company may update the measures in this Annex, provided that the level of protection is not materially reduced.
Encryption in transit: encryption of communication channels (TLS).
Encryption at rest: encryption of stored data.
Access control: role-based access with least privilege.
Authentication: two-factor authentication for sign-in to the Service. Multi-factor authentication is required for administrative access by Company personnel to the underlying infrastructure.
Logging: recording of operation logs.
Backups: regular backups; data is stored at multiple geographically separated locations within Japan, supporting recovery from failures.
Monitoring: monitoring of system operation.
Vulnerability management: software updates and response to vulnerabilities.
Personnel: confidentiality obligations (Article 4) and training.
Physical security: reliance on the physical controls and third-party certifications of the data centers of the Company's cloud infrastructure (see the Subprocessors page).
Incident response: the notification and response procedures set out in Article 7.
Subprocessor management: equivalent obligations imposed on Subprocessors under Article 5.
Security contact: for security reports and inquiries, please contact .
Established: July 26, 2026
Bank Invoice Corporation
⚠️ This document is an AI-generated draft. Have it reviewed by a qualified professional before publication, then remove this notice.
Subprocessors
This page lists the providers to which the Company entrusts part of the processing of personal data in providing BankInvoice (the "Service"). It is published under Article 5 of the Data Processing Addendum.
Email addresses and the contents of notification emails
Data for the Service is stored in regions within Japan. Payment, email-delivery and Peppol Network processing takes place at the locations shown above. Each Subprocessor is provided only with the data necessary for its service. The safeguards for transfers outside Japan are set out in Article 9 of the Data Processing Addendum.
About the Peppol Network
The service provider that the Company uses to connect to the Peppol Network and to register receiving capability (SMP) — Datajust B.V. (Storecove) — is a Subprocessor of the Company and is listed in the table above. The operators of the Peppol Network (OpenPeppol and the operator of the SML), as well as the access point providers and SMP operators used by counterparties, are not Subprocessors of the Company, because they do not process Personal Data on the Company's instructions. The allocation of roles is set out in Article 2 of the DPA.
Changes
Where the Company adds or replaces a Subprocessor, it will give advance notice by posting on the Service or by other appropriate means. Within thirty (30) days of such notice, Users may object on reasonable grounds. The procedure is set out in Article 5 of the Data Processing Addendum.
Contact
For questions about this page, please email () or use the contact form (https://biv.jp/chfJV0).
⚠️ This is an AI-generated draft. Have it reviewed by a qualified professional before publication and remove this notice.
Security
This page summarizes how BankInvoice (the "Service") approaches information security. Our commitments as a processor are set out in the Data Processing Addendum (DPA) and its Annex 1; our vendors are listed in the Subprocessor List.
Principles
Rights in Invoice Data and other data entered by Users belong to the User or the User's registered organization. We do not use Personal Data beyond what is necessary to provide the Service — in particular, not for advertising, not for sale to third parties, and not for training machine-learning models.
Where data is stored
Service data is stored in regions within Japan, across geographically separated locations for recovery. Exchanges with the Peppol Network pass through an access point within the EU (see the Subprocessor List).
Encryption
Traffic is encrypted in transit (TLS) and data is encrypted at rest.
Access control and authentication
Permissions follow the principle of least privilege by role. Sign-in to the Service uses two-factor authentication, and administrative access to our infrastructure by our staff requires multi-factor authentication. Personal Data is handled only by staff bound by contractual or statutory confidentiality obligations.
Monitoring, logging and backups
We keep operation logs, monitor availability, take regular backups, and run a redundant configuration that can fail over to standby systems.
Vulnerability handling and reporting
We keep software up to date and respond to vulnerabilities on an ongoing basis. Please report vulnerabilities to (a machine-readable contact is published at /.well-known/security.txt). When testing, please stay within your own account and data, and refrain from accessing other users' data, destroying or altering data, or disrupting the Service. We review and reply to reports we receive.
Connection to the Peppol Network
We provide Peppol Network connectivity and receiving registration (SMP) in partnership with Datajust B.V. (Storecove), an OpenPeppol-certified service provider (access point). Processing takes place within the EU. The allocation of roles and cross-border safeguards are set out in Articles 2 and 9 of the DPA.
Payments
For card payments, card details are handled by our payment processor; we do not hold card numbers ourselves.
Third-party certification
Physical security relies on the physical controls and third-party certifications of the data centres of our cloud infrastructure.
If an incident occurs
If we become aware of a leak, loss or damage of Personal Data (including a risk thereof), we will notify Users without undue delay — where possible within 72 hours of becoming aware (Article 7 of the DPA).
⚠️ This is an AI-generated draft. Have it reviewed by a qualified professional before publication and remove this notice.
Accessibility Statement
Bank Invoice K.K. works to make this site (about.bankinvoice.com) usable by as many people as possible, under the following policy.
Target level
We aim for Level AA of JIS X 8341-3:2016 (equivalent to WCAG 2.1) and improve in stages. We will state conformance only after testing against the standard; this statement expresses a target, not a test result.
Scope
The public pages of this site. Product screens and exported files such as PDFs will be brought into scope progressively.
What we do today
Document structure with headings and landmarks; full keyboard operation (tabs, disclosures, menus); alternative text for images and diagrams; lang attributes matching the display language (29 language/region variants); respect for the "reduce motion" setting (prefers-reduced-motion) — animations stop and the original text is shown; readable printing (disclosures open on paper; marks drawn with backgrounds are redrawn with borders); and contrast in both light and dark themes.
Known limitations
Detailed descriptions for some diagrams, avoiding reliance on colour alone for every state, and comprehensive testing with assistive technologies remain on our roadmap.
Feedback
If anything is hard to use, please tell us via the contact form (https://biv.jp/chfJV0) or .