This Privacy Policy explains how Private Wisdom blog (“the Blog” or “we” or “us”) collects, uses, and protects the personal data of its users. The Blog processes personal data in compliance with the EU General Data Protection Regulation (GDPR). This policy is effective as of August 30, 2025. If any changes are made, we will notify you with an updated date.
1. data controller
The data controller of this blog is the operator of the Private Wisdom blog. Contact information is as follows
- E-mail address: praivate.wisdom@outlook.jp
In accordance with the GDPR, we respect the rights of our users as those responsible for processing their personal data.
2. personal data to be collected
The Blog may collect the following types of personal data
- Identifying information: name, email address (via comment submission or contact form).
- Technical information: IP address, browser type, device information, browsing history via cookies (using tools such as Google Analytics).
- Other data: comment content, search queries, or user-provided information.
These data are collected automatically when users access or interact with our blog, or when users voluntarily provide them. We do not knowingly collect personal data from children (under the age of 16). If we do collect it by mistake, we delete it immediately.
3. purpose of data processing and legal basis
The purposes for processing personal data are as follows
- Manage and improve our blog (e.g., comment management, improve user experience).
- Analytics and statistics (e.g., visitor count tracking).
- Compliance with legal requirements.
Legal basis under GDPR:
- Consent: In the case of cookie use and newsletter registration, this is based on the user’s express consent.
- Legitimate interests: processes to improve the security or functionality of the blog (e.g., to prevent spam).
- Contract fulfillment: Responding to user inquiries.
- Legal Obligations: Processing for legal compliance.
4. data sharing and transfer
We may share personal data with third parties:
- Service providers: WordPress hosting, Google Analytics, or security tool providers (these are based on GDPR compliant agreements).
- Legal requirements: When requested by law enforcement agencies.
Data may be transferred outside the EU (e.g., to the United States), subject to the Standard Contractual Clause (SCC) and appropriate safeguards.
5. data retention period
Personal data will be stored only for the period necessary to achieve the purpose:
- Comment data: Permanently stored (until requested for deletion).
- Analysis data: up to 26 months (Google Analytics default).
- Other data: deleted or anonymized immediately after completion of the purpose.
6. user rights (under GDPR)
EU residents (or persons subject to GDPR) have the right to
- Access rights: Request a copy of the data in your possession.
- Right to Correction: Correct inaccurate data.
- Right to be Deleted (Right to be Forgotten): request data deletion (except where there is a legal obligation to do so).
- Restrictive rights: Requests restrictions on processing.
- Right of Objection: objection to processing (if based on legitimate interests).
- Data portability rights: Request data transfer.
- Right to withdraw consent: If processing is based on consent, it can be withdrawn at any time.
To exercise your rights, please contact us at the above address and we will respond within one month, free of charge. If the response is delayed, you will be notified. If you are dissatisfied, you may file a complaint with the EU data protection authority (e.g. the supervisory authority of your country of residence).
7. cookies and tracking technology
This blog uses cookies:
- Required cookies: for site functionality (consent not required).
- Analytics cookies: Traffic analysis with Google Analytics (consent-based).
- Advertising cookies: if applicable (consent-based).
Cookie settings can be managed by your browser. For more information, see [Cookie Policy] (to create a separate page). A consent banner will be displayed on your first visit to obtain your consent.
8. data security
We take reasonable security measures to protect personal data:
- Encryption (HTTPS).
- Access Control.
- Periodic security reviews.
However, due to the nature of the Internet, absolute security cannot be guaranteed. In the event of a breach, we will notify the authorities and contact affected users within 72 hours in accordance with GDPR.
Third Party Links
This blog may contain external links. The privacy policies of these sites are outside our responsibility. Please review the policies of the linked sites.
10. changes to privacy policy
This policy is subject to change. When changes are made, we will notify you on the blog and provide an updated date. Continued use will be considered acceptance of the changes.
11. contact us
If you have any questions about privacy, please contact us using our contact form.
This Privacy Policy has been prepared in compliance with GDPR. For legal advice, please consult an expert.