UNAPPROVED TEMPLATE — not an offered or executed agreement. Qualified counsel must approve the applicable version before it is represented as a Kotobase DPA.
Version: 2026-08-03
This review template is the operational checklist for an agreement between the customer as controller and Gftd Japan K.K. as processor. The signed agreement must identify the parties, effective date, order form and controlling terms.
The completed schedule must state the subject matter, duration, nature and purpose of processing; categories of data subjects; data classes; customer instructions; return/deletion choice; and any customer-specific retention or residency commitments. The data map in docs/DATA-HANDLING.md and the machine registers in this directory are the technical baseline, not contractual promises by themselves.
Counsel must approve provisions covering documented instructions, confidentiality, security measures, subprocessor authorization and change notice, transfer safeguards, rights-request assistance, incident notification, deletion or return, audit information, government requests, liability and the order of precedence with the service terms.
The security schedule must describe only deployed controls. At minimum it must address tenant isolation, authentication, access control, transport protection, secret handling, logging, vulnerability management, recovery, incident response and personnel access. Roadmap KMS/HSM, crypto-shred, legal hold, residency and recovery capabilities must not be described as available until their qualification evidence passes.
Before signature, the accountable owner records the counsel-approved version and expiry/review date, verifies every active processor and transfer entry, selects the applicable retention schedule, completes a live DSAR drill and a live legal-hold drill, and places their secret-free digests in the customer evidence vault. A repository commit or self-attestation is not approval.