Privacy Policy

SB Telecom America Corp. 

CCPA Privacy Policy 

Last Updated: May 1, 2024

 

Scope 

This Privacy Notice explains how SB Telecom America Corp. (collectively, the “Company,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes personal information within the scope of the California Consumer Privacy Act of 2018 (including amendments thereto, the “CCPA”).  Although the CCPA only provides privacy-related rights and obligations with respect to residents of California, referred to throughout as “consumers”, this Privacy Notice shall also apply to those who reside in U.S. states other than California other than our employees (including full- or part-time employees, officers, directors, owners, contractors or other staff and job applicants).

Unless otherwise expressly stated, all terms in this Privacy Notice have the same meaning as defined in the CCPA.  

 

Assistance For Disabled Persons

Alternative formats of this Privacy Notice are available to individuals with a disability.  Please email the Privacy Security Team for assistance at the following address: stsgrp-privacyus@g.softbank.co.jp.

 

What is personal information?

When we use the term “personal information”, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, which information the Company collects. 

For the purposes of this Privacy Notice, personal information does not include the following: 

 

Our Collection and Use of Personal Information

The below table specifies all categories of personal information which we collect or have collected in the past twelve (12) months, from California residents who interact with our website and/or apply for a job with us, and for each category of personal information, the sources from which we collect such information and our commercial and/or business purposes for its collection and use.

 

Categories of Personal Information Collected

Categories of Sources

Commercial and/or Business Purposes for Collection

and Use of Personal Information

Identifiers, such as full name, home address, email address, telephone number, IP address, etc.

  • Direct from consumers in connection with your job application.
  • Automated collection when you email us.
  • Third-party service providers such as recruitment agencies. 
  • Direct from consumers in connection with the internal procedures for the recording of sales and expenses

Business Purposes 

  • Performing services on behalf of the business for hiring purposes (including reviewing job applications, screening job candidates for specific roles and opportunities, communicating with job applicants and conducting applicant background checks and issuing job offers).
  • Performing services on behalf of the business, including providing customer service, processing, or fulfilling requests for information and content, verifying customer information, analyzing and improving our websites and services.
  • Helping to ensure security and integrity to the extend the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes.
  • To provide free support to the consumer.
  • To introduce digital marketing services.
  • To provide digital marketing support directly to potential clients or via a service provider.
  • To market digital marketing services.
  • To send consumers newsletters.
  • To provide AI services directly to customers or via a service provider.
  • To provide security service directly to customers or via a service provider.
  • To gather market information, propose new businesses and to do consultation.
  • To provide Microsoft license services in a more effective way.
  • To provide SE services in a more effective way.
  • To carry out payment for the consumers.
  • To communicate with and share information with the consumer.
  • To hold video or voice recording of webinars or internal events.

Other identifiers, such as passport no., visa no., bank account no.

  • Direct from consumers in connection with the payment

Business Purposes 

  • To carry out payment for the consumers

Personal information categories listed in the California Customer Records (Cal. Civ. Code § 1798.80(e)), such as full name, social security number, etc.

  • Direct from consumer in connection with your job application.
  • Third-party service providers such as recruitment agencies. 

Business Purposes 

  • Performing services on behalf of the business for hiring purposes, including reviewing job applications, screening job candidates for specific roles and opportunities, conducting applicant background checks and issuing job offers.
  • Performing services on behalf of the business, including providing customer service, processing, or fulfilling requests for information and content, verifying customer information, analyzing, and improving our websites and services.
  • Helping to ensure security and integrity to the extend the use of the consumer’s personal information is reasonably necessary and proportionate for these purposes.

Internet or other electronic network activity information, such as information regarding interactions with our website.

  • Automated collection when you interact with our website.
  • Direct from consumer in connection with global security governance

Business Purposes 

  • Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
  • To be compliant with global security governance.

Geolocation data, such as IP address

  • Automated collection when you email us.

Business Purposes 

  • Performing services on behalf of the business for hiring purposes, including communicating with job applicants.

Professional/Employment

Information, such as job title/role, employment history, salary, etc.

  • Direct from consumer in connection with your job application.
  • Third-party service providers such as recruitment agencies.

Business Purposes

  • Performing services on behalf of the business for hiring purposes, including reviewing job applications, screening job candidates for specific roles and opportunities, conducting applicant background checks and issuing job offers.

Biometric information, including video and voice recordings

  • Direct from consumers in connection with carrying out video or voice recording of webinar or internal events.

Business Purposes

  • To provide the consumers video or voice recording of webinars or internal events.

Non-Public Education

Information (20 U.S.C. § 1232g, 34 C.F.R. Part 99), such as academic transcripts, educational disciplinary records, academic counseling records, etc.

  • Direct from consumer in connection with your job application.
  • Third-party service providers such as recruitment agencies.

Business Purposes

  • Performing services on behalf of the business for hiring purposes, including reviewing job applications, screening job candidates for specific roles and opportunities, conducting applicant background checks and issuing job offers.

Inferences, such as character determinations made during interviews.

  • Direct from consumer in connection with your job application.

Business Purposes

  • Performing services on behalf of the business for hiring purposes, including screening job candidates for specific roles and opportunities and issuing job offers.

 

Retention of Personal Information

We retain each category of personal information for only so long as is reasonably necessary to achieve the purpose(s) disclosed above, or as required by applicable law or regulation. 

 

Disclosure and Sale/Sharing of Personal Information

In the last twelve (12) months, we have not sold or shared personal information about you, but we have, at times, disclosed certain categories of personal information for business purposes.  In the last twelve (12) months, we have disclosed for a business purpose the categories of personal information to the categories of third parties, listed below.

 

Category of Personal Information

Disclosures for a Business Purpose

& Categories of Recipients

Identifiers

Recruiting agencies (for hiring) 

Data storage service provider (for keeping in a secured manner)
Affiliated group companies (for distribution of Company benefits, evaluation and mobility processes and corporate governance as well as for providing new business to potential customers) 

Personal information categories listed in the California Customer Records (Cal. Civ. Code § 1798.80(e))

Data storage service provider (for keeping in a secured manner)
Affiliated group companies (for distribution of Company benefits, evaluation and mobility processes and corporate governance as well as for providing new business to potential customers)

Internet or other electronic network activity information

No disclosure

Geolocation data

No disclosure

Professional/Employment Information

Data storage service provider (for keeping in a secured manner)

Affiliated group companies (for evaluation and mobility process and corporate governance

Non-Public Education Information

 (20 U.S.C. § 1232g, 34 C.F.R. Part 99)

Recruiting agencies (for hiring) 

Data storage service provider (for keeping in a secured manner)



Minors Under Age 16

Except in limited circumstances which are disclosed above, we do not intentionally or knowingly collect the personal information of consumers less than 16 years of age. Furthermore, we do not and will not “sell” or “share” the personal information of consumers we know to be less than 16 years of age. 

 

Your Privacy Rights

You may be able to exercise the following rights in relation to the personal information that we have collected about you (subject to certain limitations at law): 

The Right to Know

You have the right to request any or all of the following information relating to the personal information we have collected about you or disclosed, upon verification of your identity: 

  • The specific pieces of personal information we have collected about you; 
  • The categories of personal information we have collected about you; 
  • The categories of sources from which the personal information about you is collected; 
  • The categories of your personal information that we have disclosed to third parties for a business purpose, and the categories of recipients to whom this information was disclosed; 
  • The categories of your personal information we have sold and/or shared (if any), and the categories of third parties to whom this information was sold and/or shared; and 
  • The business or commercial purposes for collecting or, if applicable, selling or sharing personal information about you.

The Right to Request Deletion

You have the right to request the deletion of personal information that we have collected from you, subject to certain exceptions and following verification of your identity.

The Right to Request Correction of Inaccurate Personal Information

You have the right to request the correction of any inaccurate personal information which we might maintain about you, taking into account the nature of the personal information and our processing purposes, and following verification of your identity.

The Right to Opt-Out of Sale/Sharing

You have the right to direct us not to sell or share personal information we have collected about you to third parties now or in the future. 


If you are under the age of 16, the CCPA provides you with the right to “opt in” to sales or sharing of personal information by providing consent, or to have a parent or guardian provide verifiable consent on your behalf. Please note that we do not sell or share the personal information of consumers who we know to be less than 16 years of age. 

The Right to Limit Use and Disclosure of Sensitive Personal Information

In certain cases, the CCPA provides you with the right to direct us to limit our use and disclosure of your sensitive personal information to specified uses and purposes prescribed by law. 


Sensitive personal information that is collected or processed without the purpose of inferring characteristics about a consumer is not subject to the right to limit.

The Right to 

Non-Discrimination

You have the right not to receive discriminatory treatment or retaliation for exercising any of the rights described above. 


However, please note that if your exercise of the rights described above limits our ability to process personal information (such as in the case of a deletion request), fulfilment of that right may mean that we are no longer able to provide you with our products or services or engage with you in the same manner.

 

How to Exercise Your Privacy Rights 

How To Exercise Your Right to Know, Right to Correction or Right to Deletion

To exercise your right to know, right to correction and/or right to deletion, please submit a request by: 

 

SUBMITTING A REQUEST THROUGH YOUR AUTHORIZED AGENT

You may have the option to designate an authorized agent to submit a request on your behalf, so long the authorized agent has your written permission to do so and you have taken steps to verify your identity directly with us. If you would like to designate an agent, your agent must register as such with the California Secretary of State and submit a copy of this registration along with your consumer request to us. We may need to contact you directly to verify the request.

 

HOW WE VERIFY YOUR REQUEST

We cannot fulfill your request or provide you with your personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us.

To verify your identity, we will ask that you provide the following personal information when you submit your request:

You may need to provide additional information as part of your responses to our identity verification questions. We will only use this information to confirm your identity.  Depending on your type of request or the information requested by you, we may require additional information in order to verify your identity and fulfill your request.

If we cannot successfully verify your identity, we will inform you of that fact.

We will respond to your request within forty-five (45) days. However, in certain circumstances, we may require additional time to process your request, as permitted by the CCPA or other applicable law. We will advise you within forty-five (45) days after receiving your request if such an extension is necessary and why it is needed. Any disclosures we provide will only cover the 12-month period preceding our receipt of your verifiable consumer request.

If we cannot fulfill your request, our response to you will also explain the reason why we cannot fulfill your request.

We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

You may only make a verifiable consumer request to know about or access your personal information twice within a 12-month period.

 

How To Exercise Your Right to Opt-Out of Personal Information Sales or Sharing and to Limit the Use of Your Sensitive Personal Information

As explained above, we do not currently sell or share your personal information, as such terms are defined by the CCPA. However, if at any point we begin selling or sharing your personal information to or with third parties (a change which will be reflected in this Privacy Notice), then you have a right to opt-out of such sales/sharing activities.  Unless you exercise this right to opt-out of sales/sharing, the third parties to or with whom we may, in the future, sell or share personal information may then use such information for their own purposes in accordance with their own privacy policies, which might include further reselling or resharing this information to/with additional third parties. 

Furthermore, we do not collect, use or disclose your sensitive personal information for purposes other than those authorized under CCPA Section 1798.121(a). In other words, we do not collect, use or disclose your sensitive personal information except to the extent reasonably necessary and proportionate to do our businesses. However, if at any point we begin using or disclosing your sensitive personal information for additional business or commercial purposes which are subject to the right to limit (which change(s) will be reflected in this Privacy Policy), then you will have the right to limit our use and disclosure of your sensitive personal information.  Please note, however, that sensitive personal information that is collected or processed without the purpose of inferring characteristics about a consumer is not subject to the right to limit under the CPRA. 

 

Updates to This Privacy Notice

We will update this Privacy Notice from time to time. When we make changes to this Privacy Notice, we will change the “Last Updated” date at the beginning of this Privacy Notice. 

 

Contact Us

If you have any questions or requests in connection with this Privacy Notice or other privacy-related matters, please send an email to our Privacy Security team at stsgrp-privacyus@g.softbank.co.jp.

Alternatively, inquiries may be addressed to:

SB Telecom America Corp.
Privacy Security Team
12130 Millennium Drive 3F

Los Angeles, CA 90094

 

 

EEA/UK Privacy Policy

Last updated: May 1, 2024

 

01 Our EEA/UK Privacy Policy

The protection of your personal data is of great importance to SB Telecom America Corp. (“STA”, “we”, “us”), a subsidiary of the SoftBank Corp. This EEA/UK privacy policy (the “EEA/UK Privacy Policy”) therefore intends to inform you who are in the European Economic Area (“EEA”) or the United Kingdom (the “UK”) about how we collect, use, share, store and otherwise process your personal data when you use our website (“Site”), in connection with your relationship with us as a STA customer/recipient of our services, vendor or your general interest in our services.  It also explains your rights under applicable data protection laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”), the United Kingdom General Data Protection Regulation, which is the GDPR as incorporated into UK domestic law by virtue of section 3 of the European Union (Withdrawal) Act 2018 and amended by The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (“UK GDPR”).

If you have any queries or comments relating to this EEA/UK Privacy Policy, please contact sbtmgrp-gdpruk@g.softbank.co.jp.

 

02 Who is responsible for your personal data?

Where the GDPR or the UK GDPR applies to the processing of your personal data, and you are a visitor to the Site, the data controller for your personal data is STA, unless we advise you otherwise. The data controller decides how personal data about you is processed.

In providing you with digital marketing support services, we work closely with SB Telecom Europe Limited (“SB Telecom Europe”), established in WeWork 184 Shepherds Bush Road, London W6 7NL, United Kingdom. In this regard, SB Telecom Europe and we jointly determine the purposes and means of processing of your personal data. Therefore, SB Telecom Europe and we are acting as joint controllers responsible for the protection of your personal data.

Upon your requests, the respective roles and relationships of the joint controllers vis-à-vis the data subjects will be made available to you.

 

03 How do we use your personal data?

We always process your personal data based on one of the legal bases provided for under the GDPR/UK GDPR.  In addition, we process your sensitive personal data, for example, data concerning your trade union membership, religious views, or health condition in accordance with the special rules provided for under the GDPR/UK GDPR. 

In providing digital marketing support services and system integration/network integration services and solutions, we may collect and process personal data of employees and/or other staff members of our customers and suppliers for the purposes detailed below, which are required for us to pursue our legitimate interests:

In very specific circumstances such as the processing for the purposes below, we rely on your consent to process your personal data.to carry out marketing activities such as sending newsletters; and

 

04 What types of personal data do we use?

We process the following categories of personal data for the respective categories of data subjects.  

Categories of data subjects

Sources

Categories of personal data

  • employees and/or other staff of our customers and suppliers
  • You
  • SB Telecom America (Joint Controller)
  • Name:
  • E-mail address:
  • Address (including country): and
  • Phone number.
  • Business communications with you including business discussions and inquiries:
  • User identification information: and
  • Access logs, cookie information, browsing history.

 

05 Who do we share your personal data with?

We may share your personal data with SoftBank Corp.’s affiliates and with third parties in accordance with the GDPR/UK GDPR.  Where we share your data with a data processor, we will put the appropriate legal framework in place in order to cover such transfer and processing.  Furthermore, where we share your data with any entity outside the EEA/UK, we will put the appropriate legal framework in place, notably controller-to-controller and controller-to-processor Standard Contractual Clauses approved by the European Commission for the EEA as well as the UK International Data Transfer Agreement and UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses for international data transfers, in order to cover such transfers.

Strategic Partners

Subject to your prior consent, your personal data may be transferred to, stored, and further processed by strategic partners that work with us to provide our products and services or help us market to customers.

Service Providers

We share your personal data with companies which provide services on our behalf, such as hosting, maintenance, support services, email services, marketing, auditing, fulfilling your orders, processing payments, data analytics, providing customer service, and conducting customer research and satisfaction surveys.  These companies include Lead Forensics Platform, Hubspot CRM, MailChimp, OrangeScape (United States and other jurisdictions), Box (United States and other jurisdictions), and Google (United States and other jurisdictions).

SoftBank Corp. Affiliates and Corporate Business Transactions

We may share your personal data with SoftBank Corp. affiliates. In the event of a merger, reorganization, acquisition, joint venture, assignment, spin-off, transfer, or sale or disposition of all or any portion of our business, including in connection with any bankruptcy or similar proceedings, we may transfer any and all personal data to the relevant third party.

Legal Compliance and Security

It may be necessary for us – by law, legal process, litigation, and/or requests from public and governmental authorities within or outside your country of residence – to disclose your personal data.  We may also disclose your personal data if we determine that, due to purposes of national security, law enforcement, or other issues of public importance, the disclosure is necessary or appropriate.

We may also disclose your personal data if we determine in good faith that disclosure is reasonably necessary to protect our rights and pursue available remedies, enforce our terms and conditions, investigate fraud, or protect our operations or users.

Data Transfers

Such disclosures may involve transferring your personal data out of the United States to the following countries: Japan, the EEA and the UK. Such transfer may take place for internal reporting, management and business purposes.  For each of these transfers, we are based on the European Commission’s adequacy decisions on Japan and the UK respectively.  For the transfer to the EEA, the data transfer restriction under the GDPR is not triggered because that transfer is not concerning one outside the EEA.  

 

06 Our records of data processes

We handle records of all processing of personal data in accordance with the obligations established by the GDPR/UK GDPR, both where we might act as a controller or as a processor.  In these records, we reflect all the information necessary in order to comply with the law and cooperate with the supervisory authorities as required. 

 

07 Security measures

We process your personal data in a manner that ensures their appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction or damage.  We use appropriate technical or organizational measures to achieve this level of protection. 

We retain your personal data for as long as it is necessary to fulfill the purposes outlined in this EEA/UK Privacy Policy unless a longer retention period is required or permitted by law.

 

08 Notification of data breaches to the competent supervisory authorities

In case of breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed, we have the mechanisms and policies in place in order to identify it and assess it promptly.  Depending on the outcome of our assessment, we will make the requisite notifications to the supervisory authorities and communications to the affected data subjects, which might include you. 

 

09 Processing likely to result in high risk to your rights and freedom

We have mechanisms and policies in place in order to identify data processing activities that may result in a high risk to your rights and freedom.  If any such data processing activity is identified, we will assess it internally and either stop it or ensure that the processing is compliant with the GDPR/UK GDPR or that appropriate technical and organizational safeguards are in place in order to proceed with it. 

In case of doubt, we will contact the competent data protection supervisory authorities in order to obtain their advice and recommendations.

 

10 Your rights

Provided that certain conditions are met, you have the following rights regarding personal data collected and processed by us.

If you intend to exercise such rights, please refer to the contact section below.

If you are not satisfied with the way in which we have proceeded with any request, or if you have any complaint regarding the way in which we process your personal data, you may lodge a complaint with data protection supervisory authorities such as the UK Information Commissioner’s Office and the Northline-Westphalia State Data Protection Supervisory Authority.

 

11 Children

Our products and services are intended for adult customers.  Thus, we do not knowingly collect and process information on children under sixteen (16). If we discover that we have collected and processed the personal data of a child under sixteen (16), or the equivalent minimum age depending on the concerned jurisdiction, we will take steps to delete the information as soon as possible. If you become aware that a child under sixteen (16) has provided us with personal data, please contact us immediately by using the contact address specified under this EEA/UK Privacy Policy.

 

12 Links to other sites

We may propose hypertext links from the Website to third-party websites or Internet sources. We do not control and cannot be held liable for third parties’ privacy practices and content. Please read carefully their privacy policies to find out how they collect and process your personal data.

 

13 Updates to privacy policy

Contact

For any questions or requests relating to this Privacy Policy, you can contact us by email sbtmgrp-gdpruk@g.softbank.co.jp.