Circuit Breaker
Privacy, minimized.
Effective August 16, 2026. This notice covers the website, Stripe Checkout, support, license administration, and local plugin counters.
1. Controller
Creator’s NEXT, Inc. is the data controller. Address: NTT DATA Shinagawa Building 13F, 1-9-36 Konan, Minato-ku, Tokyo 108-0075, Japan. Privacy manager: Nozomu Kubota. Contact: info@cnxt.jp or +81-3-4405-0319.
2. Data we receive
We may receive your name, email, billing address, country, WordPress site URL, plan, payment and subscription status, Stripe identifiers, activation records, support messages, cancellation requests, IP address, and security logs. Stripe receives payment credentials directly; we do not store full card numbers or card security codes. Japanese invoice applicants also provide a postal code. When they choose address lookup, only that postal code is sent to the ZipCloud address-search API to return an address candidate.
3. Plugin data
The usage-counter function is designed not to store prompts, AI responses, API keys, or direct user identifiers. Counters and settings remain in the customer’s WordPress environment. License validation may use the licensed site URL, a one-way site identifier, license status, plugin version, timestamps, and security information needed to prevent credential sharing.
4. Purposes and GDPR legal bases
We process data to perform the subscription contract and provide activation; comply with accounting, tax, consumer, and legal duties; and pursue legitimate interests in security, fraud prevention, support, and service improvement. Where consent is the legal basis, it may be withdrawn at any time without affecting earlier lawful processing.
5. Data minimization and cookies
This site uses necessary storage for consent and requested functions. Google Analytics measurement ID G-27PHWLZV9T is blocked until explicit consent and advertising storage remains disabled. Consent can be withdrawn at any time through Cookie settings.
6. Recipients
Data is disclosed only as needed to Stripe for billing, hosting and communications providers, professional advisers, and public authorities where legally required. Vendors receive only data necessary for their role and are subject to appropriate contractual and security obligations. We do not sell personal information or share it for cross-context behavioral advertising.
7. International transfers
Creator’s NEXT is in Japan. The European Commission recognizes Japan as providing adequate protection for transfers covered by its adequacy decision. Other vendors may process data outside your country under an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Details are available on request.
8. Retention
Subscription, consent, transaction, tax, and accounting records are retained for legally required periods. License and security records are retained while the subscription is active and for a limited period needed for fraud, dispute, and legal claims. Support records are kept only as long as needed. Data is then deleted or anonymized unless a legal hold applies.
9. Your rights
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, cessation of use or disclosure, and information about data practices. EEA/UK users may object to legitimate-interest processing and withdraw consent. We verify requests and generally respond to GDPR requests within one month, subject to lawful extensions.
10. Complaints and EEA contact
Contact info@cnxt.jp first so we can address your concern. EEA users may also complain to the data protection authority where they live, work, or believe an infringement occurred. If an EU representative becomes legally required for the scope of our EEA offering, its identity and contact details will be published here.
11. Automated decisions
We do not use personal data collected through checkout or support to make solely automated decisions that produce legal or similarly significant effects. Smart Protection classifies website traffic for the customer’s cost-control function; it does not decide an individual’s legal rights.
12. Security and incidents
We use access controls, data minimization, vendor oversight, encrypted transport, and separation of payment credentials. No method is completely secure. We assess incidents and notify authorities or affected people when applicable law requires it.
13. Children and changes
The service is intended for website operators and not directed to children under 13. We may update this Policy for service or legal changes; material changes receive notice where required.