Privacy Policy
Last updated: 18 July 2025
Tokeiya takes data protection seriously. This policy describes what personal information is collected when you use this website, why it is collected, how it is used, and what rights you hold in relation to it. Reading this page takes around five minutes and we have tried to keep the language direct rather than obscure.
This policy applies to the website operated by Tokeiya and covers all interactions via contact forms, cookies, and standard server logs.
What data we collect
-
Contact form submissions: When you use the contact form, we collect your name, email address, and the content of your message. Submitting the form is voluntary.
-
Cookies and analytics: If you accept analytical cookies, aggregated data about page visits and navigation patterns may be recorded. No data of this kind is linked to your identity. See our Cookie Policy for full detail.
-
Server logs: Standard web server logs may record your IP address, browser type, and pages accessed. These logs are used for security and operational purposes and are not shared.
-
Legal basis: Data submitted via forms is processed on the basis of legitimate interest (responding to enquiries). Analytical cookies require your prior consent. Retention period for form data is up to 24 months from last contact; server logs are retained for 90 days.
How we use your data
-
Responding to messages: Contact form data is used solely to reply to your enquiry and, if the conversation continues, to manage the scoping process.
-
Website improvement: Anonymised analytics data helps us understand which pages are useful and where the content can be made clearer. No individual profiles are built.
-
Third-party sharing: We do not sell personal data. Anonymised analytics data may be processed by a third-party analytics platform under a data processing agreement. No identifying information is transferred.
-
Marketing: We do not send marketing emails unless you have explicitly requested information about a service. There is no mailing list sign-up on this site.
How we protect your data
-
Encryption: Data in transit is protected by HTTPS/TLS. Stored form data is held on servers with access controls and encrypted at rest.
-
Access controls: Access to personal data is restricted to the individuals directly responsible for responding to enquiries. No broad internal access is granted.
-
Breach notification: In the unlikely event of a data breach affecting your personal information, we will notify affected parties within 72 hours where required by applicable law.
-
Monitoring: Server access logs are reviewed periodically to detect unusual patterns or unauthorized access attempts.
Your rights
-
Right to access: You can request a copy of any personal data we hold about you at any time.
-
Right to rectification: If any information we hold is inaccurate, you can ask us to correct it.
-
Right to erasure: You may request deletion of your personal data. We will process such requests promptly unless retention is required for legal reasons.
-
Right to portability: You can request your data in a structured, machine-readable format for transfer to another controller.
-
Right to object: You may object to processing based on legitimate interest. We will cease processing unless compelling grounds exist.
-
Exercising your rights: To exercise any of the above, contact us via the form on our Contact page. We aim to respond within 30 days.
Your rights and opt-out instructions
You are not required to provide any personal information when using this website. If you prefer not to share your data, you may: avoid filling out contact forms, account registrations, or any data-submitting features; disable cookies through your browser settings (see our Cookie Policy for more details); or contact us directly to request the deletion of any previously shared personal data. We respect your privacy choices. If you would like us to delete your data, please reach out to us at the contact details provided on our Contact page. We will process your request promptly.