Handling of Personal Information
3H Medi Solution Inc. (hereinafter referred to as “3H”) is a healthcare company that connects people’s health and happiness by operating a range of services including participant recruitment for clinical trials and surveys, healthcare media, life sciences research, system development and management, the use of Personal Health Records (PHR) in actual medical care and clinical trials, contract research organization (CRO) services, and site management organization (SMO) services (collectively referred to as the “Life Science Service Business”).
In the course of providing these services, 3H obtains personal information from members, users of various services, business partners, and other stakeholders (collectively “users” *), which may include sensitive personal information, especially health-related data.
3H fully understands that such personal information belongs to the individuals themselves and recognizes that its
Contact Form
Name (Required)
Email Address (Required)
Inquiry Type (Required) ・Request for Explanation ・Request for Materials ・Other
Please describe the content if you selected “Other”
•
Organization Name (Required)
Department Name (Required)
Phone Number
Agree to the handling of personal information and make an inquiry
business activities rely on the proper handling of that information. Accordingly, 3H has established and implements the following privacy policy to protect personal information company-wide.
*Note: “Users” also includes individuals registered on behalf of someone else by a proxy (e.g., a parent for a minor, or a family member acting in the best interest of someone unable to provide consent due to illness).
When handling personal information for the Life Science Service Business, 3H ensures lawful and appropriate acquisition. Usage and provision of such information are managed according to established procedures and monitoring rules to prevent misuse or use beyond the stated purpose.
•
3H ensures all executives and employees have access to the laws, government guidelines, and other specified standards concerning personal information. These are kept up to date to ensure compliance.
•
3H regularly conducts risk assessments and implements appropriate security measures. It also takes the necessary corrective actions to prevent leaks, loss, or damage of personal information.
•
3H has established a Personal Information Protection Management System and is committed to its implementation, maintenance, and continuous improvement.
•
3H has set up a “Personal Information Inquiry Desk” to respond to questions, complaints, and consultations related to its privacy policy.
Established: April 22, 2020 Revised: July 1, 2024 3H Medi Solution Inc. CEO: Hirotaka Takizawa Privacy Information Management System Certification https://isms.jp/isms-pims/lst/ind/CR_PR0041.html
Handling of Personal Information This is to explain how 3H Medi Solution Inc. (hereinafter referred to as “3H”) handles personal information.
a) Business Entity Information
1.
Name: 3H Medi Solution Inc.
2.
Address: JRE Minami-Ikebukuro Building, 1-13-23 Minami-Ikebukuro, Toshima-ku, Tokyo
3.
Representative: Hirotaka Takizawa, President and CEO
b) Personal Information Protection Administrator / Inquiry Desk
1.
Personal Information Protection Administrator (Title): Head of IT Solutions
2.
Contact Information – 3H Personal Information Inquiry Desk TEL: (03) 5928-0929 FAX: (03) 5928-0982 (Reception hours: Weekdays 10:00–16:00) Email: privacy@c-trial.com
c) Purpose of Use of Personal Information
When acquiring and retaining personal information, 3H defines the following purposes of use and handles personal information within the scope of these purposes, unless permitted by law or individually consented to by the user after clear explanation.
1.
Personal Information Obtained from Users
Personal information obtained via websites, applications operated by 3H, as well as through telephone, fax, postcards, written forms in person, etc. (hereinafter referred to as “personal information related to life science services”) will be used for the following purposes:
①
Website administration and management (including email newsletter distribution, target extraction, and point allocation)
②
Recruitment and management of participants for clinical trials (including clinical research, trials, and related events; same hereafter)
③
Contacting and confirming eligibility of prospective clinical trial participants
④
Payment of participant compensation (honoraria) for clinical trial involvement
⑤
Provision of life science service-related information
⑥
Responding to inquiries and requests from users
⑦
Conducting surveys via questionnaires
⑧
Providing information deemed beneficial to users from third-party companies or organizations
⑨
Execution of tasks entrusted by business partners
⑩
Statistical aggregation and analysis, and planning or proposing new services
2.
Personal Information Obtained from Business Partners Personal information obtained from individuals affiliated with companies, facilities, or organizations that have business dealings or partnerships with 3H (including sole proprietors), through websites, business card exchanges (including online), events, or other designated procedures by 3H (hereinafter referred to as
“business activity personal information”) will be used for the following purposes:
①
Responding to various inquiries and requests
②
Business negotiations, meetings, and contract execution
③
Execution of tasks entrusted to 3H
④
Provision of information and communication with business partners
3.
Personal Information of Employees and Applicants Personal information provided by current or former employees, executives, and their families through prescribed procedures by 3H, as well as information provided by applicants through recruitment processes or third-party staffing services (hereinafter referred to as “employee-related personal information”) will be used for:
①
Evaluation, decision-making, and communication regarding hiring, as well as employment onboarding procedures
②
HR management including employment and retirement processes, payroll, and other labor management tasks
③
Benefits administration, training and education, occupational health and safety management
4.
Recorded Phone Conversations and Interviews Audio recordings conducted by 3H’s contact center and help desk (hereinafter referred to as “call recordings”) will be used for:
①
Accurate understanding of conversation content
②
Quality control and improvement within life science services
d) Joint Use of Personal Information
3H Medi Solution Inc. (“3H”) may jointly use personal information within the scope necessary to provide comprehensive services as a “healthcare company connecting people with health and happiness.”
In the event of such joint use, 3H will comply with the Act on the Protection of Personal Information and other applicable laws and regulations. If any items other than those listed in the table below are to be jointly used, 3H will notify the contact provided by the user or make a public announcement via its website.
1. Personal Information Related to Life Science Services
•
Purpose of Use
o
To provide services operated by joint users
o
To improve services operated by joint users or conduct market research and data analysis for new service development
o
To distribute surveys, notices, and other communications via email, direct mail, etc., from joint users
o
To distribute ads based on anonymized user attributes
•
Method of Acquisition
o
Directly obtained through the internet, telephone, or written documents (including email and fax)
•
Items to Be Jointly Used
o
Name, contact information (address, telephone number, fax number, email address, etc.), medical conditions/symptoms, clinical test results, medications used, treatment history, participation history in studies/trials, content of inquiries, requests, etc.
•
Responsible Party for Management
o
3H Medi Solution Inc.
•
Scope of Joint Users
o
M3, Inc.
o
QLife, Inc.
2. Personal Information Related to Business Activities
•
Purpose of Use
o
For business communications and responses to inquiries by joint users
•
Method of Acquisition
o
Directly obtained through business card exchange, seminars, exhibitions, or written documents (including email and fax)
•
Items to Be Jointly Used
o
Name, affiliated organization, contact information (address, telephone number, fax number, email address, etc.)
•
Responsible Party for Management
o
3H Medi Solution Inc.
•
Scope of Joint Users
o
M3, Inc.
o
QLife, Inc.
3. Personal Information of Employees, etc.
•
Purpose of Use
o
For corporate management by joint users
•
Method of Acquisition
o
Directly obtained through HR systems or written documents (including email and fax)
•
Items to Be Jointly Used
o
Name, contact information (address, telephone number, fax number, email address, etc.), health examination results, and other necessary items for employee management
•
Responsible Party for Management
o
3H Medi Solution Inc.
•
Scope of Joint Users
o
M3, Inc.
o
QLife, Inc.
e) Personal Information Protection Framework and Security Measures
1.
3H has established a personal information protection framework based on the international privacy information management system ISO 27701 (Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines). The company strives to maintain and continuously improve this system.
2.
The main security control measures implemented by 3H include: ① Establishment of a personal information protection policy ② Formulation of internal regulations, rules, and procedures to comply with relevant laws, government-
issued guidelines, ISO 27701 requirements, and other specified standards ③ Clarification of responsibilities, establishment of a responsibility system, and organization of an emergency contact structure ④ Employee education and training; conclusion of confidentiality agreements upon hiring and separation; and inclusion of such matters in employment rules ⑤ Entry/exit control and restriction of access to personal data ⑥ Implementation of protection measures against unauthorized access or malware from external sources
f) Provision of Personal Information to Third Parties
3H may provide personal information entrusted by users (e.g., name, address, health-related information) to third parties via 3H’s management systems in the following cases:
1.
When the user applies to participate in a clinical trial (including clinical research, etc.) [Recipients] ・Medical institutions, Site Management Organizations (SMOs), universities, and other research institutions conducting the clinical trial ・Companies or research institutions that have signed a personal information handling agreement with 3H
2.
When the user provides information through Life Science Services [Recipients] ・Companies, medical institutions, and research institutions that have signed a personal information handling agreement with 3H
3.
When the user considers applying for insurance products [Recipients] ・Companies or organizations that have signed a personal information handling agreement with 3H
Other than the above, 3H will not provide personal information to third parties without the user’s consent, except in cases required by law or when necessary to protect life or physical safety and obtaining consent is difficult.
g) Outsourcing of Personal Information Handling 3H may outsource the handling of personal information to external parties within the scope necessary to achieve the intended use of the personal information. When outsourcing, we select contractors who sufficiently meet the required level of personal information protection through strict evaluation, and we exercise necessary and appropriate supervision. These contractors are obligated by contract to maintain the required level of protection.
h) Data Measured During Participation in Life Science Services 3H may receive health-related information, such as blood test data and data from wearable devices, from the aforementioned recipients (f-1, 2) in relation to users participating in life science services.
i) Procedures for Disclosure or Suspension of Use of Personal Information Subject to Disclosure 3H will respond to requests from users concerning notification of the purpose of use, disclosure, correction, addition or deletion of content, suspension of use, erasure, suspension of provision to third parties, or disclosure of records related to personal information subject to disclosure (hereinafter referred to as “Disclosure, etc.”). To make such a request, please contact the following inquiry desk. Please note that in cases where deleting the personal information of a clinical trial participant could hinder the identification of health-related harm related to their participation in the study, or where the nature of the personal information makes it difficult to comply, 3H may not be able to accommodate the request. In such cases, 3H will instead take measures such as suspending use or terminating membership and will explain the actions taken to the user.
1. Contact for Personal Information Subject to Disclosure 3H Personal Information Inquiry Desk TEL: (03) 5928-0929 FAX: (03) 5928-0982 E-mail: privacy@c-trial.com (Office hours: Weekdays 10:00–16:00)
2. Administrative Fee for Disclosure Requests If you request written disclosure, a processing fee of ¥1,000 per request will be charged in accordance with 3H’s regulations.
3. Cases Where Disclosure May Not Be Provided Please note that we may not respond to disclosure requests in the following cases: ① If the identity of the requester cannot be verified ② If the authority of a proxy acting on behalf of the individual cannot be verified ③ If the requested information does not qualify as personal information subject to disclosure ④ If there is a risk of harm to the life, body, or property of the individual or a third party ⑤ If there is a risk of encouraging or inducing illegal or unjust acts ⑥ If there is a risk of harm to national security or adverse effects on relations with other countries or international organizations ⑦ If there is a risk of interference with crime prevention, investigation, or other public safety and order maintenance
⑧ If it would significantly interfere with the proper execution of 3H’s business operations
j) Voluntariness of Providing Personal Information and Consequences of Not Providing It Providing personal information to 3H is voluntary. However, if necessary personal information is not provided for clinical trials (including clinical studies and research), life science service operations, sales, recruitment, or employment management, 3H may be unable to provide appropriate services or responses to the user.
k) Acquisition of Information Related to Individuals in a Manner Not Easily Recognizable by Users When users browse 3H’s website or view HTML-format email newsletters issued by 3H, certain information related to the user (such as cookies, access logs, IP addresses, time spent on the site, and page view data) is automatically and mechanically collected and handled. This information is used for the following purposes:
1.
To identify and resolve issues that occur on servers
2.
To implement security measures such as detection of unauthorized access or intrusions
3.
For website management
4.
To survey email newsletter readership and manage related content
5.
To analyze information and consider or propose new services
6.
To manage sessions on web forms
7.
To enable integration with social media through embedded content and share buttons (e.g., LINE, Facebook, Yahoo!)
Unless the user voluntarily provides personally identifiable information to 3H, this information alone does not enable 3H to identify the individual. Note that to facilitate such data collection, 3H may embed images in webpages. For more details on cookies, please visit: https://3h-ms.co.jp/cookie
l) Handling of Sensitive Personal Information 3H may collect, use, and provide necessary sensitive personal information—such as users’ physical and health conditions, medical history, medication history, and lifestyle habits—only within the scope required to achieve the intended purposes of use.
m) International Transfer of Personal Information 3H does not provide acquired personal information to third parties located outside Japan without the individual’s consent. However, personal data provided may be stored on dedicated servers operated by 3H and hosted by “Google.”
Although Google’s data centers are located in foreign countries, access to the data is restricted to authorized 3H personnel only, regardless of location. The data is encrypted and managed in accordance with global privacy compliance standards. For a list of countries where Google’s data centers are located, please refer to: https://www.google.com/about/datacenters/locations/
n) Retention Period of Personal Information and Measures After Expiry
1.
3H defines retention periods for personal information based on the purpose of use and promptly deletes or disposes of such information after the retention period expires. For more information on purposes of use, see section c).
①
Life science service-related personal information: Retained for the duration of 3H’s business unless a deletion request is made. For deletion requests, see section i).
②
Business activity-related personal information: Retained as long as 3H’s business continues unless otherwise specified in a confidentiality agreement, etc.
③
Employee-related personal information: Retained during employment and for the period stipulated by applicable laws after termination. Personal information of applicants not hired is retained until the relevant recruitment process is complete.
④
Call recordings: Retained for 10 years
2.
If a user has given separate consent specifying a different retention period in advance, that period takes precedence.
o) Creation and Provision of Anonymized Processed Information
1.
When 3H creates anonymized processed information (as defined by the Act on the Protection of Personal Information), the company will: ① Properly process the data in accordance with legal standards ② Take safety control measures to prevent leakage of removed information and details of processing methods ③ Publicly disclose the types of information included in the anonymized data ④ Not attempt to re-identify individuals from the anonymized data
2.
When providing anonymized data to third parties, 3H will publicly disclose the types of information included and the method of provision and will clearly indicate to the recipient that the data is anonymized.
3.
For more details on anonymized information handled and provided by 3H, please visit: https://3h-ms.co.jp/tokumei
p) Revisions to This Policy 3H continuously reviews and improves its privacy practices and may revise this “Handling of Personal Information” notice without prior notice.
Established: April 22, 2019 Revised: July 1, 2024