MegazoneCloud (US), LLC (“MZUS,” “we,” “us,” or “our”), with its principal office at 3031 Tisch Way 110 Plaza West, San Jose, California 95128, operates the website at megazone.com/us (“Website”). This Privacy Policy describes how we collect, use, disclose, and retain personal information of visitors to the Website, and how you may exercise the privacy rights available to you under applicable law.
1. introduction
We care about your privacy, and we keep this site simple. A few principles guide this policy, and we want you to know them up front:
We collect only a small set of information — a few web forms and basic website analytics.
We keep information only as long as we have a reason to, then we delete it.
We don't sell your information for money, and you can opt out of anything that legally counts as a "sale" or "sharing."
Marketing email and our newsletter are opt-in — we send those only if you ask; if you submit an inquiry, we will follow up about it.
We aim to be straight with you about what we collect, why, and who we share it with.
2. Who We Are and What This Policy Covers
We are MegazoneCloud US ("MZUS," "we," "us") — MegazoneCloud Co., Ltd., the United States subsidiary of MegazoneCloud Corporation, a business-to-business cloud and AI services company. We help organizations adopt and run cloud platforms such as AWS, Google Cloud, and Microsoft Azure, and to adopt artificial intelligence (including generative AI and data services) built on those platforms. Our registered address is `300 Willowbrook Office Park Suite 300, Fairport, NY 14450`.
For the privacy laws that use the term, MegazoneCloud Co., Ltd. is the "data controller" — in plain terms, the company responsible for the personal information this policy covers. You can reach us using the details in "How to Reach Us."
This policy explains what personal information we collect from visitors and what we do with it. We built this site primarily for visitors in the United States and Canada, but anyone in the world can visit them, and this policy covers you wherever you are. Where a specific law gives you specific rights, we say so in "Your Rights."
Two things this policy does not cover:
Customer data we handle when delivering services. For instance, when we manage cloud environments for customers under contract, that work is governed by our customer agreements, not this policy.
Other MegazoneCloud regional websites. Each has its own privacy policy.
You'll find a link to this policy in the footer of every page on our site.
3. Information We Collect
We collect only a small set of information, in two ways: what you give us through our forms, and what we collect automatically when you visit.
Information you give us
We ask for personal information in a few web forms in our site:
Inquiry / "Contact Us" forms. Our "Contact Us" and inquiry forms feed our Salesforce system. If you submit either, we collect your name, company name, job title, business email address, and phone number, plus your reason for inquiry (a free-text description of what you need).
There are no accounts or logins on these sites, nothing to buy, and no payment information to enter.
Sensitive information. As a rule we don't ask for (and don't want) sensitive personal information, such as government ID numbers, financial account details, or anything that reveals your racial or ethnic origin, political or religious beliefs, trade-union membership, or sex life or sexual orientation. We also don't ask for your precise location. Please don't put any of this in a free-text field. If you include some anyway when you contact us, we use it only to respond to your inquiry — we don't use it to infer anything about you.
There is one deliberate exception. At event registration, we ask, only from those who choose to provide it, for food allergies and dietary restrictions (which can in some cases touch on a religious or ethical practice) so we can accommodate you at the event. When you give us that information:
we collect it only at event registration;
it is your choice whether to provide it;
we use it only to provide the accommodation you asked for at the event;
we don't use it to infer any characteristic about you; and
we delete it on the event-data schedule (see "How Long We Keep Information").
We may add other web forms in the future. We'll update this policy before any new feature that collects personal information launches.
Information we collect automatically
Like most websites, our servers and analytics tools record some technical information when you visit: your IP address, browser and device information, the page that referred you, the pages you visit, and your session activity.
We use Google Analytics to understand how visitors use the site, and a cookie consent banner to let you choose which non-essential cookies you accept. We also keep a record of the cookie choices you make, so we can honor them.
Cookies that are strictly necessary to run the site work without asking. For all other cookies (including analytics) we give you the choice to accept or decline through the banner, and where the law where you are requires your consent before non-essential cookies are set (for example, in the EU and the UK), we rely on that consent. You can change your choice anytime through the banner.
Apart from Google Analytics, we don't currently use this site to let other companies track what you do over time and across other websites for advertising. We're still finalizing our cookie and tag inventory; if that changes, we'll update this policy and the choices we offer.
Information collected by others. Where third-party tools (such as analytics, or marketing-automation tracking we may add later) set their own cookies or similar technologies, those providers' own privacy policies govern what they collect. This policy covers only the information we collect; it does not cover information collected by third-party advertisers or analytics providers.
Those are the only two sources: you, and your visit itself. We don't buy contact lists or personal information about you from data brokers.
4. How and Why We Use Your Information
We use the information above to:
Respond to you. This is the main reason the inquiry forms exist: you ask about our services, and we get back to you to handle your consultation. Replying to an inquiry you started isn't marketing and doesn't depend on the marketing checkbox.
Follow up on sales inquiries. We'll be honest about what our site is: the marketing of a B2B company. A form submission is a sales lead, and our US sales and marketing teams will follow up on it. Where the GDPR applies to you, you can object to this follow-up — see "Your Rights."
Send marketing email — only if you opt in. Our inquiry forms include a separate, optional marketing checkbox, unchecked by default. If you check it, we may send you email about products, services, and events. If you don't, we'll still answer your inquiry — the checkbox never gates your submission. You can opt out anytime (see "Your Choices").
Send our newsletter and company communications — to people who sign up. If you sign up through the newsletter form, we send you our newsletter and related company communications. Signing up is the opt-in; you can unsubscribe anytime (see "Your Choices").
Register you for events and communicate about them. If you register for one of our events, we use your details to confirm your registration (RSVP) and to send you event-related communications. Where you tell us your food allergies or dietary restrictions, we use that information to accommodate you at the event.
Operate, secure, and improve the website. Analytics tells us what's working. Monitoring for abnormal activity helps keep the site safe.
Comply with the law. Sometimes we're legally required to keep or produce information.
Where the law that applies to you, such as the EU or UK GDPR, requires us to have a legal basis to use your information, these are ours:
To answer the inquiry you sent us and follow up about it, we rely on taking the steps you asked us to take and on our legitimate interest in responding to a business contact.
To send you marketing email and our newsletter, we rely on your consent (the marketing box, or your newsletter signup), which you can withdraw anytime.
To register you for an event and send you event-related communications, we rely on your consent given at registration; and where you give us food allergies or dietary restrictions, we rely on your explicit consent to use that information to accommodate you.
To run, secure, and improve the site and its analytics cookies, we rely on your consent for non-essential cookies and on our legitimate interest in keeping the site working and safe, including operating as part of the MegazoneCloud group.
To meet legal requirements, we rely on our legal obligations.
5. How We Share Information
We share personal information in a few defined situations:
Service providers. Companies that process information on our behalf, under contract and on our instructions: Salesforce (the customer-relationship-management system where we store inquiry submissions from our website), HubSpot (our CRM and marketing-automation platform, which holds the inquiry, newsletter, and event-registration data collected on our website), Google Analytics, our analytics provider, our cookie-consent platform, and our website hosting provider. Inside MZUS, access is limited to the teams that handle inquiries, communications, and events — principally our US marketing and sales teams.
Vendor partners, when your inquiry is about their products. We're a partner-led cloud business. If your inquiry concerns a specific vendor's products (say, AWS or Google Cloud) we may pass your contact and company details, and the substance of your inquiry, to that vendor partner so it can help respond. We tell you this in the form, too.
Event co-hosts, when you register for an event we co-host. When you register for an event we co-host with a partner (for example AWS, Google, or SHI) we share a limited set of your registration details (your name, company name, and job title) with that co-host so they are aware of who is attending. We do this under a written data-protection agreement with the co-host, with your consent at registration, and we share only those fields — not your phone number, your dietary or allergy information, or other details.
Within the MegazoneCloud group. Our parent company and affiliates may, for limited internal purposes such as group reporting and administration, have access to information held by MZUS — see "Where Your Information Is Stored."
Legal reasons. If we're required to by law (a court order or lawful government request, for example) or where necessary to protect our rights, our users, or the public.
Business transfers. If MZUS goes through a merger, acquisition, reorganization, or sale of assets, the information described in this policy may transfer as part of that transaction and would remain subject to the commitments here unless you are notified otherwise.
Do we "sell" or "share" personal information?
We don't sell it for money. But California, and other US state privacy laws, define "sale" more broadly than money changing hands (it can cover other exchanges of value) and separately define "sharing": disclosing information to advertising partners for cross-context behavioral advertising (ads targeted to you based on what you did on other, unrelated websites). Depending on the advertising tools running on this site, some cookie-based disclosures could count as a "sale" or "sharing" under some US state privacy laws. If any such disclosure occurs, it would involve cookie or device identifiers and website-activity data — not the name, business email, phone number, or inquiry details you submit through our forms. When we pass your details to a vendor partner, we do it to respond to your inquiry.
When we share your registration details with an event co-host, we do it for a business purpose (so the co-host knows who is attending the event it is co-hosting) with your consent and under a written contract. That is not a "sale" (no money or other valuable consideration changes hands) and not "sharing" for cross-context behavioral advertising (the purpose is event awareness, not advertising targeted to you based on your activity on other sites). It does not create any new opt-out beyond the footer link already described below.
Whatever the label, you can opt out anytime using the "Do Not Sell or Share My Personal Information" link in the website footer, or through Global Privacy Control (see "Your Choices").
6. Where Your Information Is Stored
We're a US company and we run these sites from the United States. Wherever you are when you contact us, the information you submit is processed and stored on our systems in the United States. If you are outside the United States, your information will be transferred to and handled in the United States, where data–protection laws may differ from those in the country where you live. Where the law of your country requires safeguards for that transfer, we are working on building the protections it requires.
We store website inquiry, newsletter, and event-registration data in our own systems in the United States — Salesforce for inquiries, and HubSpot for the inquiry, newsletter, and event-registration data collected on our site. As part of the MegazoneCloud group, your information may be accessed by our parent company or affiliates for limited internal purposes such as group reporting and administration. Where that access involves our parent company in the Republic of Korea or another affiliate outside the United States, we treat it as an international transfer and are currently working on putting in place the protections your local law requires.
7. How Long We Keep Information
We keep information only as long as we have a reason to:
Inquiry and lead data (from both the Salesforce and HubSpot inquiry forms): we keep it for three years after the purpose for collecting it is fulfilled (for example, three years after your consultation is complete) and then destroy it through periodic bulk deletion.
Newsletter data: we keep it until you unsubscribe or opt out, or until you have not engaged with our communications for 12 consecutive months (no email opens or clicks). At that point we stop sending to you and permanently remove your data during routine database maintenance.
Event-registration data (including any food-allergy or dietary information you gave us): we keep it for three years after the event purpose is fulfilled (for example, three years after the event is over) and then destroy it through periodic bulk deletion. Your dietary or allergy information is deleted on this same schedule.
For information collected automatically: we keep Google Analytics data for 14 months, and we keep the record of your cookie choices for 12 months. Individual cookies expire on their own schedules, and you can review or change your cookie choices anytime through the banner. We'll update these periods as we finalize our cookie and tag inventory.
We keep information longer only where the law requires it.
8. How We Protect Information
We encrypt information in transit using SSL/TLS — the standard technology behind the padlock icon in your browser's address bar. Form submissions stored in our CRM systems (Salesforce) are encrypted at rest using industry-standard encryption. Access is role-based and limited to the teams that need it to do their jobs. We monitor and log access and review these practices periodically.
No website or storage system is perfectly secure, and we won't pretend otherwise. We work to protect your information with measures that fit what we collect — which, as you've seen above, is deliberately little.
9. Your Choices
You have real choices here, starting before we collect anything:
Give us less. Our forms are the only place we ask for personal information. You decide whether to submit them and what to put in a free-text field.
Marketing and the newsletter are opt-in, and opting out is easy. We send marketing email only if you checked the marketing box, and we send the newsletter only if you signed up for it. Every marketing email and every newsletter identifies us as the sender and includes an unsubscribe link, and we honor unsubscribes within 10 business days. You can also email privacy_north_america@megazone.com anytime to opt out.
Withdraw your consent. Where we rely on your consent (for marketing email, the newsletter, event communications, and non-essential cookies) you can withdraw it anytime, and it's as easy as giving it: unsubscribe from any marketing email or newsletter, or email privacy_north_america@megazone.com, and change your cookie choices through the banner. Withdrawing consent doesn't affect anything we already did before you withdrew it.
Control cookies. The cookie consent banner lets you accept or decline non-essential cookies and change your preferences later. Your browser's cookie settings work too, though blocking some cookies may stop parts of the site from working as intended. Opt out of "sale" or "sharing." Use the "Do Not Sell or Share My Personal Information" link in the website footer.
Use Global Privacy Control (GPC). Global Privacy Control (GPC) is a browser setting or extension that signals to the websites you visit that you want to opt out of the sale or sharing of your information and of targeted advertising. We treat a GPC signal as a valid opt-out request for that browser, and when we honor it the site displays a confirmation so you know it worked.
10. Your Rights
The core rights below are yours wherever you live — we extend them to everyone who uses this site. Specific laws give some visitors more, and we cover those next.
Everyone can ask us to:
Tell you what we have about you (access/know), including the categories and specific pieces of personal information;
Correct information that's wrong;
Delete your information;
Give you a copy of it in a portable format.
To exercise any of these rights and, where they apply to you, to object to or restrict certain uses or to withdraw consent, you can:
We verify requests by matching what you tell us against the information we hold (usually your email address) and we'll only ask for what we need to confirm it's really you. You can also use an authorized agent to submit a request on your behalf; we'll ask for proof of the agent's authority, such as your signed authorization, and we may still confirm your identity with you directly.
We respond as quickly as we can, and in any event within 45 days — or sooner if the law that applies to you sets a shorter deadline. If a request is complex and the law allows, we may extend once and we'll tell you why before the first period ends.
If we deny your request, you can appeal. Reply to our decision and ask us to take another look. We'll review it again and respond with the outcome and the reasons. We'll respond to your appeal within the timeframe required by applicable law. If we deny your appeal, in some US states you can also raise the denial with your state attorney general.
We won't penalize you for exercising any right you have.
California residents
The California Consumer Privacy Act (CCPA) gives you the rights above, plus the right to opt out of "sale" or "sharing" of personal information and the right to limit the use of sensitive personal information. On the limit right: the only sensitive personal information we intentionally collect is the food allergies and dietary restrictions you may choose to give us at event registration. We use that information only to provide the accommodation you asked for at the event; we don't use it to infer any characteristics about you, and we don't disclose it to anyone outside MegazoneCloud group (it is not part of what we share with event co-hosts). Because we use that sensitive information only for the purpose you requested and don't use or disclose it for any purpose that would trigger the right to limit, the CCPA's "limit" right doesn't attach, and we don't post a "Limit the Use of My Sensitive Personal Information" link. We otherwise don't ask for sensitive personal information, and we ask you not to include any in a free-text field; if you include some anyway, we use it only to handle your inquiry — we don't use it to infer characteristics about you.
A short notice at collection (what we collect and why, with a link to this policy) appears at the form itself, at or before the point where you submit. The table below supplements that notice, organized into the categories California law uses. It describes our current practices:
Category under California law
What that means on this site
Where it comes from
Why we use it
Who we disclose it to
Identifiers
Name, business email address, phone number
You, via our inquiry, newsletter, and event-registration forms
Responding to your inquiry and handling your consultation; sending the newsletter and event communications you signed up for; sales follow-up; marketing, if you opted in
Service providers (Salesforce, website hosting); a vendor partner, if your inquiry concerns its products; an event co-host (AWS, Google, or SHI) — of the Identifier fields, only your name; see the Professional-information row for the company name and job title also shared (event registration only); our US sales and marketing teams; our parent company and affiliates, where access occurs for the limited internal business purposes described in "How We Share Information"
Professional or employment-related information
Company name, job title
You, via our inquiry
Understanding and routing your inquiry; sales follow-up; event registration
Same as above, including an event co-host (AWS, Google, or SHI) for company name and job title (event registration only)
Sensitive personal information (health: food allergies and dietary restrictions)
Food allergies and dietary restrictions you choose to provide
You, at event registration only
To accommodate you at the event
No one outside MZUS — handled within our own event-management systems; NOT shared with event co-hosts
Free-text inquiry content (information you choose to type)
Your "reason for inquiry" description
You, via the inquiry form
Understanding, routing, and responding to your inquiry, including deciding whether a vendor partner should help, and sales follow-up
Same recipients as Identifiers above (Salesforce; a vendor partner if your inquiry concerns its products; US sales and marketing; parent and affiliates where access occurs). To the extent the free text contains identifiers, it also falls under Identifiers.
Internet or other electronic network activity information
IP address, browser and device information, referring URL, pages visited, session activity, your cookie-consent choices
Automatically, via cookies and Google Analytics
Website analytics; security and abnormal-activity monitoring; improving the site
Service providers (Google Analytics, our cookie-consent platform, website hosting); advertising partners, if and to the extent the advertising tools on this site involve such disclosure (see "How We Share Information"); our parent company and affiliates, where access occurs (see "Where Your Information Is Stored")
Retention for each category is described in "How Long We Keep Information" above, which forms part of this notice.
Your free-text "reason for inquiry" travels with the form too; we use it to understand, route, and respond to your inquiry (including deciding whether a vendor partner should help) and for the sales follow-up described above. We don't intentionally collect the other CCPA categories — no biometric information, and no precise geolocation (your IP address tells us only your general area).
In the preceding 12 months we have not sold personal information for money; whether any cookie-based disclosure counts as a "sale" or "sharing" under California's broader definitions depends on the advertising tools on the site — see "How We Share Information" above, including the pending inventory confirmation noted there. We have, through our event-registration flow, disclosed registrants' identifiers and professional information (name, company name, job title) to event co-hosts (AWS, Google, SHI) for event-awareness purposes, with the registrant's consent and under a written agreement, as described in "How We Share Information"; that disclosure is for a business purpose, not a “sale” or a "share." Going forward, the categories of recipients are those listed in the table above and in "How We Share Information." Either way, you can opt out of any "sale" or "sharing" via the footer link or GPC, as described in "Your Choices."
Residents of other US states
Several other US states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing list of others) give their residents rights similar to California's: to access, correct, delete, and obtain a portable copy of their personal information; to opt out of the sale of personal information and of targeted advertising; and to appeal if we deny a request. We extend the core access, correction, deletion, and portability rights to everyone (see "Your Rights"), we honor the Global Privacy Control signal as your opt-out of sale and targeted advertising (see "Your Choices"), and we offer an appeal on any denial — including the same no-penalty commitment described under "California residents." For opt-outs of cookie-based "sale," "sharing," or targeted advertising, the footer link, the Global Privacy Control signal, and the cookie banner are the controls that take effect in your browser; for everything else, make the request through either method in "Your Rights" and we'll handle it.
Visitors in the EU, UK, and elsewhere
If a law like the EU or UK GDPR applies to how we handle your information, you also have the right to object to certain uses (for example, our sales follow-up), to ask us to restrict certain uses, to withdraw any consent you gave us (which doesn't affect anything we did before you withdrew it), and to complain to your local data protection supervisory authority. To withdraw marketing or newsletter consent, just unsubscribe or email privacy_north_america@megazone.com; to use the others, contact us the same way as above. If you live somewhere else, your local privacy law may give you additional rights (including, where they apply, to access, correct, or delete your information, to object to or restrict certain uses, or to withdraw a consent you gave); use the same request channels and we'll honor what applies to you.
Canadian residents
This site is addressed to Canadian as well as US visitors. Canada's private-sector privacy laws (including the federal PIPEDA) apply to the personal information we collect from you. You can ask to access and correct your information (see above), and you can withdraw consent to our use of it, subject to legal and contractual limits — withdrawing consent to marketing or to the newsletter is as simple as unsubscribing. You can also ask us about our personal-information handling practices and who is accountable for them. Our designated Privacy Officer, accountable for our handling of personal information, is Scott Weber (see "How to Reach Us").
If you are not satisfied with how we have handled your personal information or a request, you can contact our Privacy Officer (see "How to Reach Us"); you also have the right to complain to the Office of the Privacy Commissioner of Canada, and, if you are in Quebec, to the Commission d'accès à l'information du Québec.
Visitors elsewhere
If you contact us from outside the United States and Canada, your own country's privacy law may give you rights — for example, to access, correct, or delete your information, to object to or restrict certain uses, or to withdraw a consent you gave. We extend the core rights above to everyone, and where your local law gives you more, we honor those rights too. Tell us what you need at privacy_north_america@megazone.com and we will handle it under the law that applies to you.
11. Children
This is a business-to-business website. It is not directed to children, we do not knowingly collect personal information from children (under 13 in the United States, or any higher age set by the law where you live) and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has submitted personal information through our sites, email privacy_north_america@megazone.com and we'll delete it.
12. How to Reach Us
For anything in this policy — questions, rights requests, appeals, or complaints:
Email: privacy_north_america@megazone.com Privacy Officer: Scott Weber, Chief Technology Officer, MegazoneCloud US Mail: 3031 Tisch Way 110 Plaza West, San Jose, California 95128
13. Changes to This Policy
We may update this policy as our site, our tools, and the law change. When we do, we'll post the new version here and update the "Last updated" date at the top. If a change is material (a new category of data, say, or a new kind of sharing) we'll flag it prominently on the site before it takes effect.