EU/UK Privacy Supplement
Effective date: August 11, 2026
This Supplement is published pursuant to Article 31 (Regional Supplements) of the Meowsaur Terms of Service and supplements the Privacy Policy. It applies to individuals in the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland whose Personal Data we process in connection with the Meowsaur service. Where this Supplement conflicts with the Privacy Policy on a matter it specifically addresses, this Supplement controls, but only to that extent.
1. Who This Supplement Applies To
This Supplement applies where the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing of your Personal Data — typically because you are located in the EEA, the UK, or Switzerland, or because you are an employee or authorized user of a Customer located there. For most Meowsaur Customers, we act as a data Processor on your employer's or organization's instructions; in that case, your primary point of contact for exercising your rights is your employer or organization, and the terms of our Data Processing Addendum govern our processing on their behalf. Where we determine the purposes and means of processing your Personal Data ourselves — for example, in relation to our own marketing communications, or the operation of our public website — we act as the Controller, and the rest of this Supplement is addressed to you directly in that capacity.
2. Legal Bases for Processing
Where we act as Controller, we rely on the following legal bases under Article 6 GDPR (and the equivalent provisions of the UK GDPR) for the purposes described in Article 2 of the Privacy Policy.
| Purpose | Legal basis |
|---|---|
| Providing the Service, authentication, billing | Performance of a contract (Art. 6(1)(b)) |
| Responding to inquiries and support requests | Performance of a contract; legitimate interest in resolving your request (Art. 6(1)(b)/(f)) |
| Security, fraud and abuse prevention, service integrity | Legitimate interest in protecting the Service and its users (Art. 6(1)(f)) |
| Statistical, cross-tenant analysis of de-identified usage data (Article 2 of the Privacy Policy) | Legitimate interest in understanding aggregate trends without identifying individuals (Art. 6(1)(f)) |
| Sending important service notices (Terms changes, service changes) | Performance of a contract; legal obligation, where applicable (Art. 6(1)(b)/(c)) |
| Marketing communications, where we send them | Consent (Art. 6(1)(a)), or legitimate interest for similar B2B products with an opt-out, as permitted under applicable e-Privacy implementation |
| Non-essential cookies, where used (see Section 6) | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interest, we have considered that interest against your rights and freedoms and concluded it does not override them. You may object to processing based on legitimate interest at any time, as described in Section 3.
3. Your Rights
Subject to the conditions and exemptions under applicable law, you have the right to: (a) request access to your Personal Data; (b) request rectification of inaccurate Personal Data; (c) request erasure of your Personal Data; (d) request restriction of processing; (e) request portability of Personal Data you have provided to us; (f) object to processing based on legitimate interest, including profiling; (g) withdraw consent at any time, without affecting the lawfulness of processing before withdrawal, where processing is based on consent; and (h) lodge a complaint with a supervisory authority.
To exercise these rights, contact us at the address in Section 8. Where you are an authorized user of a Customer's account, we may direct your request to that Customer, who is typically better positioned to fulfil it as Controller, and we will provide reasonable assistance to the Customer in doing so.
4. Automated Decision-Making
We do not use your Personal Data to make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The Service's AI-generated analysis and recommendations concern the visibility of a Customer's business and website — not decisions about individuals.
5. International Transfers
Where we transfer your Personal Data outside the EEA, the UK, or Switzerland, we do so in accordance with Section 8 (International Transfers) of our Data Processing Addendum, which describes the transfer mechanisms we rely on, including Japan's status as a country recognized by the European Commission and the UK as providing an adequate level of data protection, and our use of Standard Contractual Clauses (or the UK's International Data Transfer Addendum) for onward transfers to Sub-processors located in countries not covered by an adequacy decision.
6. Cookies and Similar Technologies
The cookies and similar technologies we currently set on our own website (as distinct from third-party cookies set by services you connect to the Service, such as Google Search Console) are limited to those strictly necessary to operate the site — for example, maintaining your login session, preventing fraudulent or abusive access, and operating an anonymous visitor identifier used solely to associate a free diagnostic scan you request with its result. We do not currently set advertising or third-party tracking cookies of our own. Under the e-Privacy Directive as implemented in EEA/UK member states, strictly necessary cookies of this kind do not require prior consent, and we display a notice, rather than a consent gate, accordingly.
If we introduce non-essential cookies (for example, our own analytics or marketing cookies) on our website, we will, before doing so, implement an opt-in consent mechanism appropriate for EEA/UK visitors — including a "reject" option displayed with equal prominence to "accept," no pre-ticked boxes, and category-level granularity — and update this Section accordingly.
7. EU and UK Representatives; Data Protection Officer
The Company is headquartered in Japan and does not currently have an establishment in the EEA or the UK. Where Article 27 GDPR or the equivalent UK GDPR provision requires the Company to designate a representative in the EEA and/or the UK, the Company will designate such representative(s) and publish their contact details in this Section. Until such designation is published, please direct any request that would otherwise be made to a representative to the contact point in Section 8, and we will respond directly.
Based on the nature and scale of our processing — which does not involve large-scale, regular, and systematic monitoring of individuals, or large-scale processing of special categories of data — we have assessed that we are not currently required to designate a Data Protection Officer under Article 37 GDPR. We keep this assessment under review as our processing activities evolve. For privacy-related inquiries in the meantime, please use the contact point in Section 8.
8. Contact and Complaints
For any request or inquiry relating to this Supplement, please contact info@public-design.co.jp. If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your place of habitual residence, place of work, or the place of the alleged infringement. A list of EEA supervisory authorities is available from the European Data Protection Board; in the UK, the relevant authority is the Information Commissioner's Office (ICO).