個人情報保護方針
制定日:2025年9月8日 最終改定日:2026年7月16日
- 当社は、個人情報を適正かつ公正な手段により取得、利用及び提供し、特定された利用目的の範囲内でのみ個人情報を取り扱います。また、利用目的の達成に必要な範囲を超えた個人情報の取扱いを防止するための措置を講じます。
- 当社は、個人情報の漏えい、改ざん、滅失又はき損等を防止及び是正に関して適切な措置を講じます。
- 当社は、当社による個人情報の取り扱いに関する苦情・相談があった場合には適正に対応します。
- 当社は、個人情報保護マネジメントシステムを構築・維持するとともに、その継続的な改善に努めます。
制定日:2025年9月8日
Tenke合同会社
代表社員 グスタフソン春菜
【お問合せ窓口】
個人情報保護方針に関するお問合せにつきましては、下記窓口で受付けております。
Tenke合同会社 個人情報問合せ窓口
〒220-0004 神奈川県横浜市西区北幸2丁目10番48号 むつみビル3階
メールアドレス:info@healthtomo.com(受付時間 平日 10:00–15:00)
(個人情報に関する公表文)
個人情報の取扱いについて
- 当社は、個人情報の取扱いに関する法令、国が定める指針その他の規範を遵守します。
1. 当社が取り扱う個人情報の利用目的
(1)ご本人から直接書面によって取得する個人情報(ホームページや電子メール等によるものを含む)の利用目的
Tenke合同会社(以下、「当社」といいます。)は、皆様の健康維持増進及び豊かな暮らしの実現に貢献すべく、多言語に対応した医療機関の検索及び診療予約のサービス「healthtomo」その他のサービスを提供させていただいております。当社は、事業活動を通じて当社が取り扱う全ての個人情報の保護を重要な責務と認識し、当社が取り扱う個人情報について個人情報保護方針を定め、適切な取扱いに取り組みます。
- 個人のお客様情報(お名前、メールアドレス、電話番号、生年月日、住所、性別、国籍、保険の種別、診察券番号及びご家族に関する情報を含みます。):ユーザー様サポートのため/ご利用履歴管理のため/当社サービスのご案内のため/お問合せ対応のため/診療予約のお申込みのため
- ウェブサイトのご利用情報(ご覧になったページ、日時、滞在時間、参照元、端末・ブラウザ・OSの種別、及びIPアドレスから推定される所在地を含みます。):社内分析およびサービス改善のため/掲載医療機関に対し当該医療機関の掲載情報の閲覧状況に関する統計情報をご提供するため。ログイン中のユーザー様がサイトを閲覧された際は、ページ閲覧の記録をアカウントに紐づけて記録します。ログインしていない訪問者の閲覧は、アカウントには紐づけず、当社が生成する識別用の符号(IPアドレス及び端末情報から生成し、日次で変更されるものをいい、これのみによって特定の個人を識別することはできません。)に紐づけて記録します。当社は、これらの目的のため、Google LLCが提供するアクセス解析ツール「Googleアナリティクス」を利用しており、同ツールはCookie等を用いてご利用情報を収集します。同ツールにおける情報の取扱い及びその収集の停止の方法については、同社の定めるところによります。
- 位置情報:ユーザー様が現在地に基づく検索等の機能を選択し、端末又はブラウザにおいて位置情報の利用を許可された場合に限り取得し、現在地の近隣にある医療機関の検索及び当該医療機関までのおおよその距離の表示のために利用します。取得した位置情報は、ブラウザのセッションの間一時的に保持するにとどめ、当社のデータベースに保存することはありません。
- AIチャット(Ask Tomo)にご入力いただいた内容並びに当社が表示した診療科及び一般用医薬品:AIチャットによる表示内容を生成し、表示するため/AIチャットによる表示内容を検証し、その精度を改善するため。ご入力いただく健康状態に関する記述は要配慮個人情報に該当する場合があります。AIチャットによる表示内容の生成は、当社が委託する外国にある事業者の提供する人工知能サービスを利用して行われます(下記4をご参照ください)。
- 診療予約の内容(ご希望の日時、受診の対象者、連絡方法及びご入力いただいた連絡事項)及び問診票の回答:診療予約のお申込み及びその管理のため/お申込先の医療機関が受診に備えるため/当該予約に関しご連絡するため。問診票の回答その他ご入力いただく健康状態に関する記述は要配慮個人情報に該当する場合があります。これらの情報のお申込先の医療機関への提供については、下記5をご参照ください。
- 通知の送信先に関する情報:待合状況に関する通知(受診の順番が近づいたことをお知らせする通知をいいます。)をご希望の端末に送信するため。当該情報は、当該通知の目的を達した後、速やかに削除します。
- お取引先担当者様情報:発注内容確認のため(通信記録等)
- 当社従業員情報:社員の人事労務管理、業務管理、健康管理、セキュリティ管理のため
- 当社への採用応募者情報:採用応募者への連絡と当社の採用業務管理のため
- 特定個人情報:番号利用法に定められた利用目的のため
(2)前項以外の方法によって取得する個人情報の利用目的
- お取引先担当者様情報:発注内容確認のため(通信記録等)
- 業務の受託に伴い、お客様からお預かりする個人情報:委託された当該業務を適切に遂行するため
2. 当社が取り扱う個人情報の第三者からの取得等
当社は、外部アカウント連携の利用を希望する個人について、別途定める利用規約等で本人の同意を取得の上、当該外部サービスに登録されたユーザーに関する情報を、当社が取得し、前記利用目的に従い、取扱うことがあります。
3. 決済の取扱い
当社のサービスに関する決済は、当社が指定する外部の決済代行事業者(Stripe, Inc.)を通じて処理されます。クレジットカード情報はStripeのシステムにおいてPCI DSS等の業界標準に従って安全に取り扱われ、当社がカード番号の全桁を取得・保管することはありません。Stripeにおける個人情報の取扱いは同社のプライバシーポリシーに従います。当社は、請求の管理に必要な範囲で、決済金額、決済日、カード番号の下4桁等の限られた情報のみを受領します。
4. 業務委託及び外国にある第三者への個人データの提供
当社は、サービスの提供に必要な範囲で、個人データの取扱いの全部又は一部を外部の事業者に委託することがあります。委託先には、クラウド基盤及びデータベース、メール配信、AIによる問合せ応答(チャットの内容の処理を含みます)、アクセス解析、エラー監視、アプリケーションのホスティング等を提供する事業者が含まれます。これらの委託先の一部は日本国外(主として米国)に所在するため、当社は個人データを外国にある第三者へ提供する場合があります。
外国にある第三者への提供にあたり、当社は、個人情報の保護に関する法律(APPI)に基づき、当該第三者が我が国の個人情報取扱事業者に求められる水準に相当する保護措置を継続的に講ずることを内容とするデータ処理契約を締結し、その実施状況を確認します。提供先の国名、当該国における個人情報の保護に関する制度、及び当該第三者が講ずる保護措置の詳細については、上記【お問合せ窓口】までご請求いただくことによりご案内いたします。
5. 登録医療機関に対する個人データの提供
ユーザー様が本サービスを通じて医療機関に対する診療予約をお申し込みになり、又は問診票にご回答になった場合、当社は、当該お申込み又はご回答の内容(要配慮個人情報を含む場合があります。)を、お申込先である当該医療機関に提供します。当該医療機関は、当社の委託先ではなく、自らの責任において診療その他の目的のために当該情報を取り扱う第三者です。当社は、この提供を、ユーザー様のお申込み又はご回答に基づき、当該医療機関の受診に必要な範囲でのみ行います。
当社は、上記の提供を行わない場合、当該医療機関における診療予約の受付ができないため、本サービスの全部又は一部をご利用いただけないことがあります。ユーザー様は、当社に対する開示等の請求とは別に、当該医療機関が保有する情報については、当該医療機関に対して直接お求めいただく必要があります。
保有個人データに関する事項の周知
当社で保有している保有個人データ又は第三者提供記録に関して、ご本人様又はその代理人様からの利用目的の通知、開示、内容の訂正、追加又は削除、利用の停止、消去及び第三者への提供の停止の請求(以下、「開示等の請求」といいます)につきましては、以下の要領にて対応させていただきます。
a) 事業者の名称
Tenke合同会社
〒220-0004 神奈川県横浜市西区北幸2丁目10番48号 むつみビル3階
代表社員 グスタフソン春菜
b) 個人情報の保護管理者
管理者名:グスタフソン春菜
所属部署:ヘルスケア部
メールアドレス:info@healthtomo.com
c) 全ての保有個人データの利用目的
1.(1)をご参照下さい。
d) 保有個人データの取扱いに関する苦情の申し出先
Tenke合同会社 個人情報問合せ窓口
〒220-0004 神奈川県横浜市西区北幸2丁目10番48号 むつみビル3階
メールアドレス:info@healthtomo.com(受付時間 平日 10:00–15:00)
e) 認定個人情報保護団体
現在、当社が加盟する認定個人情報保護団体はありません。
f) 保有個人データの開示等の求めに応じる手続き
- 開示等の求めの申し出先:開示等のお求めは、上記個人情報問合せ窓口にお申し出ください。※電磁的手続きによる開示等をご希望の方は、その旨お申し出ください。原則としてご希望に沿って処理させていただきます。
- 開示等の求めに関するお手続き:① お申し出受付け後、当社からご利用いただく所定の請求書様式「保有個人データ開示等請求書」を郵送いたします。② ご記入いただいた請求書、代理人によるお求めの場合は代理人であることを確認する書類、手数料分の郵便為替(利用目的の通知並びに開示の請求の場合のみ)を上記個人情報問合せ窓口までご郵送ください。③ 上記請求書を受領後、ご本人確認のため、当社に登録していただいている個人情報のうちご本人確認可能な2項目程度(例:電話番号と生年月日等)の情報をお問合せさせていただきます。④ 回答は原則としてご本人に対して書面(封書郵送)にて行ないます。
- 代理人によるお求めの場合、代理人であることを確認する資料:開示等をお求めになる方が代理人様である場合は、代理人である事を証明する資料及び代理人様ご自身を証明する資料を同封してください。各資料に含まれる本籍地情報は都道府県までとし、それ以降の情報は黒塗り等の処理をしてください。また各資料は個人番号を含まないものをお送りいただくか、全桁を墨塗り等の処理をしてください。
- ① 代理人である事を証明する資料:開示等の求めをすることにつき本人が委任した代理人様の場合は本人の委任状(原本)。代理人様が未成年者の法定代理人の場合は戸籍謄本、住民票(続柄の記載されたもの)その他法定代理権の確認ができる公的書類のいずれかの写し。代理人様が成年被後見人の法定代理人の場合は後見登記等に関する登記事項証明書その他法定代理権の確認ができる公的書類のいずれかの写し。
- ② 代理人様ご自身を証明する資料:運転免許証、パスポート、健康保険の被保険者証(被保険者等記号・番号等は全桁を墨塗りしてご提出ください)、住民票。
- 利用目的の通知または開示のお求めについての手数料:1回のお求めにつき1,000円(書面でのご請求の場合は、お送りいただく請求書等に郵便為替を同封していただきます。その他の方法でご請求いただく場合は、ご請求時にご相談させていただきます。)
g) 個人情報の取扱体制や講じている措置の内容
- 基本方針の策定:個人データの適正な取扱いの確保のため、「関係法令・ガイドライン等の遵守」、「質問及び苦情処理の窓口」等について「個人情報保護方針」を策定しています。
- 個人データの取扱いに係る規律の整備:取得、利用、保存、提供、削除・廃棄等の段階ごとに、取扱方法、責任者・担当者及びその任務等について個人情報保護規程を策定しています。
- 組織的安全管理措置:① 個人データの取扱いに関する責任者を設置するとともに、個人データを取り扱う従業者及び当該従業者が取り扱う個人データの範囲を明確化し、法や取扱規程に違反している事実又は兆候を把握した場合の責任者への報告連絡体制を整備しています。② 個人データの取扱状況について、定期的に自己点検を実施するとともに、他部署や外部の者による監査を実施しています。
- 人的安全管理措置:① 個人データの取扱いに関する留意事項について、従業者に定期的な研修を実施しています。② 個人データを含む秘密保持に関する誓約書の提出を全従業者から受けています。
- 物理的安全管理措置:① 個人データを取り扱う区域において、従業者の入退室管理及び持ち込む機器等の制限を行うとともに、権限を有しない者による個人データの閲覧を防止する措置を講じています。② 個人データを取り扱う機器、電子媒体及び書類等の盗難又は紛失等を防止するための措置を講じるとともに、事業所内の移動を含め、当該機器、電子媒体等を持ち運ぶ場合、容易に個人データが判明しないよう措置を講じています。
- 技術的安全管理措置:① アクセス制御を実施して、担当者及び取り扱う個人情報データベース等の範囲を限定しています。② 個人データを取り扱う情報システムを外部からの不正アクセス又は不正ソフトウェアから保護する仕組みを導入しています。
Personal Information Protection Policy
Established: 8 September 2025 · Last updated: 16 July 2026
- The Company will acquire, use and provide personal information by appropriate and fair means and will handle personal information only within the scope of the specified purposes of use. The Company will also implement measures to prevent the handling of personal information beyond the scope necessary to achieve the purposes of use.
- The Company will take appropriate measures to prevent and rectify the leakage, alteration, loss, or damage of personal information.
- The Company will respond appropriately to any complaint or consultation regarding the Company's handling of personal information.
- The Company will establish and maintain a personal-information-protection management system and will strive for its continuous improvement.
Established: 8 September 2025
Tenke GK
Representative Member: Haruna Gustafson
[Inquiry Desk]
Inquiries regarding this Personal Information Protection Policy are accepted at the following desk.
Tenke GK — Personal Information Inquiry Desk
Mutsumi Building 3F, 2-10-48 Kitasaiwai, Nishi-ku, Yokohama-shi, Kanagawa 220-0004, Japan
Email: info@healthtomo.com (Hours: Weekdays 10:00–15:00)
(Public Statement on Personal Information)
Handling of Personal Information
- The Company complies with laws, government-issued guidelines, and other norms relating to the handling of personal information.
1. Purposes for which the Company handles personal information
(1) Purposes of use of personal information acquired directly in writing from the individual (including via website, email and similar channels)
Tenke GK (the “Company”) provides “healthtomo” — a multilingual medical-institution search and appointment-booking service — and other services, with the aim of contributing to the health, well-being and prosperous lives of all. The Company recognizes the protection of all personal information it handles in the course of its business as an important responsibility, and has established this Personal Information Protection Policy and is committed to its appropriate handling.
- Information of individual customers (including name, email address, telephone number, date of birth, address, gender, nationality, insurance type, patient-card number, and information regarding family members): for user support; for usage-history management; for guidance regarding the Company's services; for responding to inquiries; for applying for appointments.
- Website usage information (including the pages viewed, the date and time, dwell time, the referral source, the device, browser and OS type, and the location estimated from the IP address): for internal analytics and service improvement; to provide listed medical institutions with statistical information on the viewing of their listing information. When a signed-in user browses the site, page-view activity is recorded and linked to their account. Browsing by visitors who are not signed in is not linked to an account; it is recorded against an identifying code generated by the Company (generated from the IP address and device information and changed daily, by which no specific individual can be identified on its own). For these purposes the Company uses “Google Analytics”, an access-analysis tool provided by Google LLC, which collects usage information using cookies and similar technologies. The handling of information by that tool, and the means of stopping such collection, are as prescribed by that company.
- Location information: acquired only where the user selects a function such as searching based on their current location and permits the use of location information on their device or browser, and used to search for medical institutions near the user's current location and to display the approximate distance to them. Acquired location information is retained only temporarily for the duration of the browser session and is not stored in the Company's database.
- The content entered into the AI Chat (Ask Tomo) and the medical departments and over-the-counter medicines displayed by the Company: to generate and display the content shown by the AI Chat; to verify the content displayed by the AI Chat and improve its accuracy. Descriptions of health conditions entered by the user may constitute special-care-required personal information. The generation of content displayed by the AI Chat is carried out using an artificial-intelligence service provided by a provider located in a foreign country to which the Company entrusts such processing (please refer to section 4 below).
- The contents of appointments (the requested date and time, the person to be seen, the contact method, and any message entered) and answers to intake forms: to apply for and manage appointments; to enable the medical institution to which the application is made to prepare for the visit; to make contact regarding the appointment. Answers to intake forms and other descriptions of health conditions entered by the user may constitute special-care-required personal information. Regarding the provision of this information to the medical institution to which the application is made, please refer to section 5 below.
- Information regarding notification destinations: to send notifications regarding waiting status (meaning notifications informing the user that their turn to be seen is approaching) to the requested device. Such information is deleted promptly after the purpose of the notification has been achieved.
- Information of business-partner contacts: for confirming the contents of orders (including communications records).
- Information of the Company's employees: for HR/labor management, work management, health management, and security management of employees.
- Information of applicants for employment with the Company: for contacting applicants and managing the Company's recruiting operations.
- Specific Personal Information (Individual Numbers): for the purposes of use prescribed under the Act on the Use of Numbers.
(2) Purposes of use of personal information acquired by methods other than the above
- Information of business-partner contacts: for confirming the contents of orders (including communications records).
- Personal information entrusted to the Company by customers in connection with the outsourcing of operations: in order to appropriately perform the entrusted operations.
2. Acquisition of personal information from third parties
Where an individual wishes to use external-account linkage, the Company may, after obtaining the individual's consent through separately established terms of use, acquire information about the user registered with the relevant external service and handle that information in accordance with the purposes of use stated above.
3. Handling of payments
Payments for the Company's services are processed through the Company's designated third-party payment provider (Stripe, Inc.). Card details are handled securely within Stripe's systems in accordance with industry standards such as PCI DSS; the Company does not receive or store full card numbers. Stripe's handling of personal information is governed by its own privacy policy. The Company receives only the limited information needed to manage billing, such as the payment amount, the payment date, and the last four digits of the card.
4. Outsourcing and provision of personal data to third parties in foreign countries
To provide our service, the Company may entrust all or part of the handling of personal data to external service providers. These include providers of cloud infrastructure and databases, email delivery, AI-based inquiry and chat processing (which processes the content of chat messages), website analytics, error monitoring, and application hosting. Because some of these providers are located outside Japan — principally in the United States — the Company may provide personal data to third parties in a foreign country.
For such transfers, in accordance with the Act on the Protection of Personal Information (APPI), the Company enters into data processing agreements requiring each recipient to maintain, on an ongoing basis, protective measures equivalent to the standards required of a personal-information-handling business operator in Japan, and monitors their implementation. Information about the destination country, that country's personal-information-protection framework, and the measures taken by the recipient is available on request via the contact point above.
5. Provision of personal data to Registered Medical Institutions
Where a user applies, through the Service, for an appointment with a medical institution, or answers an intake form, the Company provides the contents of that application or those answers (which may include special-care-required personal information) to the medical institution to which the application is made. That medical institution is not a party to whom the Company entrusts processing; it is a third party that handles such information under its own responsibility for the purposes of medical care and otherwise. The Company makes this provision only on the basis of the user's application or answers, and only to the extent necessary for the visit to that medical institution.
Where the Company does not make the above provision, appointments cannot be accepted at that medical institution, and the user may therefore be unable to use all or part of the Service. Separately from requests for disclosure, etc. made to the Company, users must make requests regarding information held by a medical institution directly to that medical institution.
Public disclosures regarding retained personal data
With respect to retained personal data and third-party-provision records held by the Company, requests by the individual or their representative for notification of purposes of use, disclosure, correction of contents, addition or deletion, suspension of use, erasure, or suspension of provision to third parties (collectively, “disclosure-etc. requests”) will be handled as set out below.
a) Name of the operator
Tenke GK
Mutsumi Building 3F, 2-10-48 Kitasaiwai, Nishi-ku, Yokohama-shi, Kanagawa 220-0004
Representative Member: Haruna Gustafson
b) Personal-Information Protection Manager
Manager: Haruna Gustafson
Department: Healthcare Department
Email: info@healthtomo.com
c) Purposes of use of all retained personal data
Please refer to Section 1 (1) above.
d) Where to file complaints regarding the handling of retained personal data
Tenke GK — Personal Information Inquiry Desk
Mutsumi Building 3F, 2-10-48 Kitasaiwai, Nishi-ku, Yokohama-shi, Kanagawa 220-0004
Email: info@healthtomo.com (Hours: Weekdays 10:00–15:00)
e) Authorized personal-information protection organization
The Company does not currently belong to any authorized personal-information protection organization.
f) Procedure for responding to disclosure-etc. requests for retained personal data
- Where to submit a disclosure-etc. request: requests for disclosure, etc. should be submitted to the Personal Information Inquiry Desk above. * If you wish to make the request, etc. by electronic means, please indicate so; we will, in principle, process your request in accordance with your wishes.
- Procedure relating to the request: (i) After receiving the request, the Company will mail you the prescribed request form “Request for Disclosure, etc. of Retained Personal Data”; (ii) Please mail the completed request form, together with documents confirming representative status (where requested by a representative) and a postal money order for the fee (only in the case of notification of purposes of use or a disclosure request), to the Personal Information Inquiry Desk above; (iii) After receiving the form, the Company will, for identity verification, ask you about approximately two items of personal information registered with the Company that can confirm your identity (e.g., phone number and date of birth); (iv) Responses will, in principle, be made to the individual in writing (sent by sealed envelope).
- Where requested by a representative, documents confirming representative status: where the person making the disclosure-etc. request is a representative, please enclose documents proving representative status and documents proving the representative's own identity. Information on family registry contained in these documents should be limited to the prefecture, with anything beyond that redacted (e.g., blacked out). Each document should either not contain the My Number or be submitted with the My Number entirely redacted.
- (i) Documents proving representative status: where the representative has been appointed by the individual to make the disclosure-etc. request, the original power of attorney from the individual; where the representative is the legal representative of a minor, a copy of the family register, residence certificate (with relationships shown), or other public document confirming the legal representative authority; where the representative is the legal representative of an adult ward, a copy of the registration certificate concerning guardianship registration, or other public document confirming the legal representative authority.
- (ii) Documents proving the representative's own identity: driver's license, passport, health-insurance card (please redact the entire policyholder number, etc.), or residence certificate.
- Fee for notification of purposes of use or disclosure request: JPY 1,000 per request (where the request is made in writing, please enclose a postal money order with the request form; where the request is made by other means, please consult with us at the time of the request).
g) Structure for the handling of personal information and measures taken
- Establishment of a basic policy: to ensure the appropriate handling of personal data, the Company has established this Personal Information Protection Policy covering matters such as compliance with relevant laws and guidelines and contact points for questions and complaints.
- Establishment of rules concerning the handling of personal data: at each stage — acquisition, use, storage, provision, deletion/disposal — the Company has established personal-information-protection internal rules covering handling methods, responsible persons and personnel and their duties.
- Organizational safety-management measures: (i) The Company has appointed a person responsible for the handling of personal data and has clarified the personnel handling personal data and the scope of the personal data handled by them, and has established a reporting structure to the responsible person where any fact or sign of violation of laws or internal rules is identified. (ii) The status of personal-data handling is regularly self-audited, and audits are conducted by other departments or external parties.
- Human safety-management measures: (i) The Company conducts regular training of its personnel on matters to be observed in the handling of personal data. (ii) All personnel submit a confidentiality oath that includes personal data.
- Physical safety-management measures: (i) In areas where personal data is handled, the Company controls personnel entry and exit and restricts the equipment that may be brought in, and implements measures to prevent the inspection of personal data by unauthorized persons. (ii) The Company implements measures to prevent the theft or loss of equipment, electronic media, and documents that handle personal data, and where such equipment or media are carried (including movement within the office), takes measures so that personal data cannot easily be ascertained.
- Technical safety-management measures: (i) Access controls are implemented to limit the persons in charge and the scope of the personal-information databases handled. (ii) Mechanisms are deployed to protect information systems handling personal data from unauthorized access from outside and from malicious software.