TeraBox Privacy Policy

TeraBox Privacy Policy

Released on April 18, 2023

Effective from April 18, 2023


Thank you for using TeraBox. TeraBox is provided to you by Flextech Inc. (hereinafter referred to as "Flextech", "we", or "us"). We are committed to protecting your privacy. This Privacy Policy sets out how we collect, store, process, share and use your information when you access our website, software, and services (the "Services").

We only collect and use your personal information for legal, legitimate, and necessary purposes. Specifically, we collect and process your personal information to provide you with our services and functions. If you use other people's personal information to access our services and functions, please ensure that you have been authorized to do so, and we reserve the right to verify if such personal information is legally used at any time.

We will ask for your separate consent in specific circumstances in strict accordance with laws and regulations. In addition to this Privacy Policy, we may also explain our rules for processing your personal information through notifications on pages of the product, pop-up prompts, push notifications, and so forth. The processing of personal information for each service or function is subject to specific rules, which have the same effect as this Privacy Policy.

Please note: Your authorization or consent is not required in advance for the collection, use, sharing, transfer, or disclosure of your personal information when such information is:

directly related to national security and national defense security;

necessary for the conclusion and performance of a contract to which you are one of the parties;

necessary for the performance of statutory duties or obligations;

necessary to respond to public health emergencies or to protect the life, health, and property of a natural person in emergencies;

directly related to the investigation, prosecution, trial, or execution of sentence of a crime;

necessary to safeguard the life, property, and other major legitimate rights and interests of you or other individuals under the condition that your consent is difficult to obtain;

disclosed by you to the public or by other legal means (the information is collected in accordance with laws and regulations to a reasonable extent);

legally disclosed through channels such as legitimate news, government notice (the information is collected in accordance with laws and regulations to a reasonable extent);

necessary to publish news, carry out supervision by public opinion, and so on in the public interest (the information is collected to a reasonable extent);

necessary for an academic research institution to conduct statistical or academic research in the public interest (personal information in the results of academic research or descriptions is de-identified before it is revealed to the public);

otherwise required by applicable laws and regulations.

What information is collected and for what purpose

The table below lists the types of information you submit to us when you use the Services and the purposes for which we may use that information. We collect and use the following information to deliver, optimize, protect, and promote the Services.


Type of Information Purpose of Collection
Account information: We collect information such as the email address and phone number that you provide to us when you perform operations such as registering for an account (if you log in with an SNS account, then we will receive your nickname and SNS profile image), and link such information with your account. We may use this information to identify you as the account owner and to keep your account secure. We may collect this information when you log in to your account.
User data: It is data that you store on TeraBox, such as files, documents, photos, videos, and audio ("user data"). We may store, process, and transfer user data and relevant information to ensure proper operations for the Services and enable you to collaborate with others and work across devices and Services. User data includes the information, size, upload date and time, and usage of your configuration files.
Usage information: It is information about how the Services are used, including operations performed in your account such as editing, viewing, creating, and moving files or folders. We can use this information to provide, improve, and promote the Services and protect TeraBox users.
Device information: This refers to information about the device used to access the Services and may include IP address, browser, and device information, web pages visited prior to accessing TeraBox, identifiers tied to the device, and location information depending on the device settings. We may use this information to optimize and protect the Services.
Cookies: Cookies are small pieces of text that are sent to your browser by the website when you visit TeraBox. You can set your browser not to accept cookies, though this may affect the functionality of the Services. We may use cookies and similar technologies to deliver, optimize, protect, and promote the Services. Cookies allow us to remember your username between logins, to better understand how you use the Services, and to improve the Services on the basis of this information. The third-party service providers we work with may also use cookies and similar technologies.
Contact information: You may share your data and information through the Share function of TeraBox or the contacts, mobile phone numbers, and email addresses (including those for Facebook and Twitter) on your phone. Such information is sensitive personal information. If you refuse to provide it, you cannot use the above-mentioned functions but can normally use other TeraBox functions and related services. You can choose to allow TeraBox to access your contact information to facilitate certain operations, such as sharing your data, cooperating with others to process your data, sending messages, and sending emails to invite others to use TeraBox. The above functions are available after you have granted us permission to access your contacts. We store this information on our server for you to use. Before sharing any data, please think through if the recipient is trustworthy. In addition, in order to ensure that prudent decisions are made, we recommend that you check the privacy statements of SNS or third-party service providers to learn how they process your information.
Clipboard: When you register a Terabox account using someone's invitation code, access file links shared by other users, add friends through passwords, or obtain membership services through redemption codes, we will read your clipboard information. We will access the clipboard information to assist you in opening the file corresponding to the link, identify the user corresponding to the password and invitation code, or redeem membership services for you. We will never read your clipboard for any other purpose.

You can create a TeraBox account using your mobile phone number and complete your account information.

In the event that it is required by laws and regulations, necessary for us to provide the product or the Services, or based on your demand to enhance the security of your account, you must provide your real name, identity document number, and facial recognition information for account authentication to use some Terabox services or to meet your further needs. In order to verify that the information you provide is accurate and complete, or ensure the security of your account, we may compare the real-name information you provide to Terabox with that registered at institutions permitted by laws and regulations or authorized by government agencies.


The above information is collected for the purpose of reliably and securely providing the Services and for legitimate business purposes. We or our partners will request your consent prior to processing your information for any other purpose beyond those specifically stated.

You agree that we can aggregate, integrate, identify, analyze, portray, or further process the personal information actively or passively provided by you in the Services through the technology of us or our trustees to form a variety of label information with different degrees of granularity that reflect your operation habits, interests, or credit (hereinafter referred to as "label information"). We will use label information for automated decision-making in specific scenarios and applications, so as to send you personalized information and/or marketing information.

You have the right to refuse the automated decision-making service implemented by us. You may contact us through the contact information in this Policy or require us to stop by using the relevant functional switch in the Services. Additionally, if there are applicable national or regional regulations or regulatory requirements prohibiting automated decision-making, we will follow them as required.

We may use your Account Data for marketing purposes and send you information about TeraBox's new products, upgrades and other marketing material from time to time. You can opt out of receiving marketing material at any time by clicking the 'unsubscribe' link in any emails you receive.

Provision of personal information to third parties

We will not reveal your personal information to any third party without your prior consent, except under any of the following circumstances:

(a) We are required to cooperate with national or regional governmental organizations or their agents in the performance of their duties or obligations under applicable laws and regulations, which may preclude such performance if your consent is required;

(b) Where there is a substantial risk to a person's life or property;

(c) Where there is a particular need to improve public health or promote the healthy development of youth.

For the sharing, transfer, or disclosure of your personal information under the above exceptional circumstances, we will log the basis for processing relevant information, the scope of information being processed, the information on the recipient, and so forth as enumerated below based on the principles of minimization and necessity to protect your legitimate rights and interests.

(1) Names and contact details of the data controller and data protection officer;

(2) Purpose of data processing;

(3) Descriptions of the data subject type and the personal data type;

(4) The type of recipient to whom the personal data has been or will be disclosed (including a recipient in a third country or international organization);

(5) Records of transfer of personal data to a third country or international organization and records of appropriate safeguards;

(6) Expected time to delete different types of data;

(7) General description of technical and organizational security measures.

Sharing data with other users

When you use the Teamwork or Share functions of TeraBox, the Services display your nickname, device information, email address, and usage information to users that you cooperate with, or information that you permit to share. This allows you to be updated on information about the team that you will join and enable other users to share files and folders with you.

We may share your information with third parties

We may work with certain trusted third parties (such as customer support or IT service providers) that can help us better deliver, optimize, protect, and promote the Services. These third parties may have access to your information to perform tasks on our behalf, during which we remain responsible for the third parties' handling of your information in accordance with our requirements.


We may share infrastructure, systems, and technology with Flextech affiliates to deliver, optimize, protect, and promote the Services. These affiliates will use your information in conjunction with us and the information you have listed in the "What information is collected and for what purpose" section for the purposes described therein. We will be responsible for granting these companies access to your information.


You may choose to connect to your TeraBox account through a third-party service. By connecting to a service of this kind, you allow the third parties and us to exchange the information listed in the "What information is collected and for what purpose" section of this Privacy Policy so that the third parties and we can deliver, optimize, protect, and promote their services. In these cases, the use of your information will be governed by the privacy policies and terms of service of the third parties whose services you choose to connect through.


We will establish an output mechanism for cross-border data transfer with reference to the requirements of the GDPR and update it as required. Our processing of personal data will depend on the fundamental principles of the GDPR, the consent of valid data subjects, or other legitimate reasons. Apart from that, additional mechanisms will be put in place to protect data and meet the substantive requirements of the GDPR for data processing.

How we protect and store your information

We have a team dedicated to keeping your information secure and testing for vulnerabilities. In addition to two-factor authentication, encryption of files at rest, and alerts when new devices and apps link to your accounts, we continue to work hard to ensure the security of your information. We deploy automated technology to detect abusive behavior and content that could harm you, other users, or the Services.

After you have signed up for a TeraBox account, we retain the information you store in the Services for as long as your account exists or as long as necessary to provide you with the Services. If you want to delete your account, please send an email to helpdesk@terabox.com with such a request and we will delete your account within 30 days after receiving your request. However, 1) we will not delete your account information until we have verified your user identity; 2) such deletion of information from our servers and backup storage may be delayed; 3) we may retain this information if necessary to fulfill our legal obligations, resolve disputes, or exercise our rights under the Contract.

We will store your personal information for the period required for providing the Services. However, in the event that laws and regulations require otherwise, you agree to keep the information for a longer term, it is necessary to ensure the security and quality of the Services, the information is required to settle disputes, or it is technically intractable to process the information as required, we will extend the retention period as per laws and agreement or to a reasonable extent after the expiration of the aforesaid period.

When the retention period expires, we will delete your personal information or de-identify it in accordance with laws and regulations.

We will collect, use, store, and transfer your information based on the principle of "minimization", and inform you of the purpose and scope of use of the information by means of user agreement, privacy policy, rules, pop-up notifications, notices, and so on.

We attach great importance to information security. We have a dedicated team to develop and employ a variety of security technologies and programs. We carry out security background checks on personnel in charge of security management and those in critical security positions. We have established a complete information security management system and internal mechanisms for handling security events and more. We take appropriate security measures and technical means in line with industry standards to store and protect your personal information, so as to prevent your information from being lost or accessed, disclosed, used, damaged, or revealed without authorization. All reasonable and feasible measures are being taken for protecting your personal information. In addition, we use encryption technology to ensure the confidentiality of data and apply trusted protection mechanisms to prevent malicious attacks on data.

We train and assess our employees in terms of data security awareness and security abilities to enhance their comprehension of the importance of protecting personal information. We authenticate the identity of employees who process personal information and control their access, sign nondisclosure agreements with our employees and partners who have access to your personal information, and clarify job responsibilities and code of conduct, so that only authorized personnel can access personal information. In the event of any violation of the nondisclosure agreements, the employment will be terminated immediately with the violator held accountable by law. Moreover, there are also confidentiality requirements that relevant personnel must follow when they leave their posts.

We kindly remind you that the Internet is not absolutely secure. Hence, you should carefully protect your personal information when you interact with other users through third-party social software, emails, SMS, and other services integrated into TeraBox under the condition that you are uncertain whether your information is completely encrypted during transfer.

Also, we appreciate your understanding that due to the technical restrictions, rapid development, and various latent and malicious attacks pertaining to the Internet industry, we may not be able to keep your information secure a hundred percent even though we make every effort to enhance our security measures. Hence, the system and communication network based on which you use our product and/or the Services may encounter security problems in other processes beyond our control.

Our security management system regards the disclosure, damage, or loss of personal information as the most serious security event. Once it occurs, our highest-level emergency plan will be implemented with multiple departments dealing with the event as one emergency response team.

We formulate an emergency plan for network security events to promptly respond to system vulnerabilities, computer viruses, cyber-attacks, network intrusions, and other security risks. In case of an event endangering network security, we will immediately carry out the plan, take remedial actions, and report to competent authorities as required.

The disclosure, damage, and loss of personal information are regarded as the most serious security events. Accordingly, we organize members of working groups to perform security plan drills on a regular basis to avoid such events. In the event that such events do occur, we will carry out the emergency plan as a top priority and form an emergency response team to trace the cause and mitigate losses in the shortest time possible.

In case of a personal information security event, we will, as required by laws and regulations, inform you of the basic information about the security event and its possible impact, the measures we have taken or will take, recommendations on actively preventing and mitigating risks for you, and remedial measures for you. We will inform you of event-related information in a timely manner through our notifications or the contact information you have provided to us including SMS, phone number, and email address. If it is difficult to inform our users one by one, we will make announcements in a reasonable and effective way. Meanwhile, we will report the disposal of the personal information security event in accordance with the requirements of regulatory authorities. We appreciate your understanding that according to laws and regulations, if measures taken by us can effectively avoid the harm caused by disclosure, tampering, and loss of information, we may choose not to notify you of a personal information security event unless a regulatory authority requires us to do so.

We refer to the requirements of the GDPR, select appropriate measures for technical security protection based on the nature, scope, background, and purpose of data processing, as well as the risks to individuals, and regularly test and evaluate the measures to maintain their effectiveness.

If data is accidentally disclosed, we will notify affected people as soon as possible and report to competent authorities within 72 hours. If it is impossible to report it within 72 hours, the reason for the delay will be clarified.

We take appropriate technical and organizational measures to achieve our data protection objectives, such as the principle of data minimization and the integration of necessary safeguards into data processing to protect the rights of data subjects and make sure any data processed is necessary for a specific purpose by default.

Where we store and process your information

While providing the Services, we may store, process, and transfer your information in Japan, and you agree to provide your information. Your information may also be stored on the local device used to access the Services.

How you control and access your information

In accordance with the laws, regulations, standards, and established practices of the relevant country and region, we guarantee that you can exercise the following rights for your personal information. If you have any questions or claims about the exercise of rights, you may contact us at helpdesk@terabox.com. You can view, change, download, delete, or share your information from your TeraBox account.

1. The right of access

If you wish to know the extent to which your personal information is collected, saved, and shared by TeraBox or the purpose of processing such information, you can contact us for details.

2. The right of rectification and supplementation

If you find any error in your personal information processed by us, you have the right to rectify the error or add the missing information. After your identity has been verified, you can submit your rectification or supplementation application to us by means of feedback and error reporting or through the aforementioned contact information. We will reply to you as soon as possible after receiving your application.

3. The right of erasure

You may request us to delete your personal information in the following circumstances:

Our processing of your personal information is in violation of laws and regulations or the agreement with you;

Our processing purpose has been met, cannot be met, or is no longer necessary;

We have stopped providing the product or the Services, or the retention period has expired;

You have decided to withdraw your consent;

Other circumstances required by laws and administrative regulations.

When you delete information from the Services, we may not immediately delete the corresponding information from our backup system, but will delete it after the backup has been updated. We appreciate your acknowledgment and understanding that if the retention period has not yet expired as required by laws and administrative regulations or set forth in this Privacy Policy, or it is technically difficult to delete your personal information, we will stop processing the information other than storing it and taking necessary security protection measures for it.

4. The right of withdrawal of consent

The implementation of each service or function requires some basic personal information. For any additional collection and use of your personal information, you may give or withdraw your consent at any time.

You can directly disable access to the contacts, photos, camera, and so on in the system of your device, change the scope of consent, or withdraw your authorization.

Following your withdrawal of consent, we cannot continue to provide you with the service involved, and will no longer use the relevant personal information. However, your decision to withdraw your consent will not affect our processing of your personal information previously conducted on the basis of your consent.

5. The right of account deletion

You may delete the account that you have created. You can delete your account in TeraBox at:

[Account Avatar] - [Menu] - [Settings] - [Security Center] - [Account Deletion].

Once you have deleted your account, you will not be able to use the Services of TearBox, so please think it through before deletion. For the sake of protecting the legitimate rights and interests of you or other users, we will determine whether to accept your deletion request based on your usage. For example, if you have unused Premium benefits or any data in your account, we will not accept your request immediately. Unless otherwise required by laws and regulations, we will stop providing you with the product and the Services, and delete your personal information according to your requirements after your account has been deleted.

6. The right of copy and data portability

You have the right to copy your personal information collected by us. On the premise that it is required by laws and regulations, in compliance with the instructions and conditions stipulated by competent authorities, and technically feasible, you may request us to transfer your personal information to another designated subject.

In your exercise of the said rights of personal information subjects, we will update third parties on the relevant information in a timely manner to ensure that the above-mentioned rights are exercised in accordance with laws and regulations, regulatory requirements, and technical feasibility.

If your request is manifestly unjustified or beyond necessity, especially when such request is repetitive, we may:

(a) charge a reasonable fee based on the administrative costs of information provision, communication, or corresponding actions; or

(b) refuse to act on the request.


You can control your retained personal information ("the retained personal information") and decide how it is collected, used, and shared in accordance with the Japan Act on the Protection of Personal Information (APPI). For example, you may

a. request disclosure of the retained personal information that identifies you

b. request corrections, additions, or deletions to the retained personal information when the content of the information that identifies you is not true

c. immediately delete or stop using the retained personal information, if the information was obtained unlawfully by us or if we are using the information in an unlawful manner

d. immediately stop providing the retained personal information if we unlawfully provide the information to a third party

Age requirements

No one under 13 is allowed to use or access the Services. Please read all notices and any Additional Terms carefully when you access the Services.

By using the services, you state that:

(1) you are at least 13 years old and over the minimum age for accessing and using the Services as required by the laws of your country;

(2) you have not been previously suspended or removed from the Services;

(3) your registration and use of the Platform complies with all applicable laws;

If you are accepting these terms on behalf of an entity, you warrant that you have the authority to bind the organization to these Terms and agree to be bound.

Change

In the event of a reorganization, merger, or acquisition of Flextech or the sale of our assets, your information may be transferred to the surviving entity, acquirer, or successor of the transaction. We will notify you of any such transaction (for example, by a message to the email address associated with your account) and outline your choices in that event.


This Privacy Policy may be modified from time to time. We will release the latest version of it on TeraBox's website if a revision is made. We will notify you if any such revision materially affects your rights.

Contact Us

If you have any questions or concerns about TeraBox, the Services, or your privacy, please feel free to contact us at helpdesk@terabox.com.