Privacy

Privacy notice

What ChoiceMosaic processes to deliver the site and respond to email, with a low-tracking and data-minimization baseline.

Last reviewed

Who is responsible

ChoiceMosaic is an independent publication operated from Japan. ChoiceMosaic is responsible for personal information that you choose to send to its role-based email addresses. Privacy questions and requests may be sent to privacy@choicemosaic.com. Individuals whose personal information ChoiceMosaic retains may use that address to exercise rights available under applicable data-protection law, including Japan's Act on the Protection of Personal Information where it applies.

Website delivery

The public site is a static website delivered by Amazon Web Services using Amazon CloudFront and a private Amazon S3 origin in the US East (N. Virginia) Region. AWS necessarily processes network and request information, such as an IP address, requested URL, time, browser or protocol details, and security signals, to route and protect a request through its global delivery network.

ChoiceMosaic does not enable CloudFront standard access logs, connection logs, user-level analytics, or advertising pixels for the initial launch. ChoiceMosaic therefore does not receive or retain a visitor-level website access log in its AWS account. CloudWatch receives only an aggregate CloudFront 5xx error-rate metric. AWS may process service data under its own service terms; see the AWS Privacy Notice.

Email you choose to send

ChoiceMosaic uses Google Workspace for its role-based mailboxes. If you email us, Google and ChoiceMosaic process your name or chosen identifier, email address, message headers, message content, attachments, and any other information you provide. We use that information to route and answer the request, investigate an editorial correction or security report, handle a privacy request, evaluate a partnership inquiry, and preserve an appropriate audit record. See the Google Cloud Privacy Notice for information about Google's service-data practices.

Do not send passwords, identity documents, payment-card data, affiliate-account exports, vulnerability payloads, or other sensitive material in an initial email. We will request a safer channel if additional information is genuinely necessary.

Purposes and legal grounds

ChoiceMosaic limits processing to operating and securing the publication, answering a request, correcting the editorial record, managing a prospective commercial relationship, and meeting legal obligations. Where EU or UK data-protection law applies, the expected grounds are our legitimate interests in those activities, steps you request before entering an arrangement, and compliance with legal obligations. A different purpose or technology requires a new review and, where applicable, consent before collection.

Cookies, analytics, and outbound links

ChoiceMosaic does not set cookies or use local storage, analytics identifiers, session replay, behavioral advertising, profiling, or retargeting at initial launch. See the cookie notice. When you follow an external link, your browser contacts the destination and normally sends the ChoiceMosaic origin under the site's strict-origin-when-cross-origin referrer policy. The destination controls its own processing and privacy notice.

Sharing and international processing

ChoiceMosaic does not sell personal information or share it for cross-context behavioral advertising. Information may be processed by AWS for site delivery and Google Workspace for email, by a professional adviser under confidentiality, or when reasonably necessary to comply with law or protect rights and security. Because ChoiceMosaic operates from Japan and these providers use global infrastructure, processing may occur outside your country, including in Japan and the United States, subject to the providers' applicable contractual safeguards.

Retention

ChoiceMosaic does not retain visitor-level website access logs at initial launch. Routine general and partnership correspondence is scheduled for deletion no later than 12 months after the last substantive exchange. Editorial-correction, privacy-request, and security-report records may be retained for up to three years after closure to preserve an accountability and response record. A record may be kept longer only when reasonably necessary for a legal obligation, active dispute, fraud or security investigation, or the establishment, exercise, or defense of a legal claim. Provider backup deletion may follow the provider's documented lifecycle.

Your choices and requests

Depending on applicable law, you may request access, correction, deletion, restriction, or a copy of personal information, or object to particular processing. Send the request to privacy@choicemosaic.com and identify the mailbox or interaction involved. We may ask for proportionate information to verify that we are responding to the correct person. After that verification, ChoiceMosaic will provide legally required operator information and respond to the request only to the extent required by applicable law. This process does not provide access to private personal information for unrelated inquiries. You may also contact the privacy or data-protection authority available in your jurisdiction.

Security, children, and changes

Access to site infrastructure and mailboxes is restricted to authorized operators, and the site uses HTTPS and private storage. No system is completely secure. ChoiceMosaic is a general-audience research publication, does not provide accounts, and is not directed to children. If we learn that a child sent personal information without appropriate authorization, we will assess and delete it where required.

This notice changes only after a substantive review. A new analytics, advertising, consent, account, or data-collection feature must be documented and approved before activation. The review date at the top identifies the version currently presented.