KANATA Privacy Policy
v1.1 | Effective date: 27 August 2026 | Third Scope Asia PTE. LTD.
This English version is a translation of the Japanese original. In the event of any discrepancy between the two, the Japanese version prevails.
1. Introduction
Third Scope Asia PTE. LTD. ("we", "us" or "the Company") is committed to protecting your personal information. This Privacy Policy (this "Policy") explains how personal information is collected, used, provided to third parties, protected and retained in connection with the use of "KANATA", the service we provide (the "Service"). Legal and privacy matters relating to this Policy are handled by our parent company, Third Scope Co., Ltd. (a Japanese corporation).
This Policy has been prepared with the Act on the Protection of Personal Information (個人情報保護法) of Japan (the "APPI") as its principal governing law. The Service is available to users worldwide, and this Policy also addresses and complies with the personal information and data protection laws of the jurisdictions in which users reside, including the European Economic Area, the United Kingdom and the United States.
This Policy forms an integral part of the KANATA Terms of Service (the "Terms of Service"). Terms not defined in this Policy have the meanings given to them in the Terms of Service.
The Service includes an "AI Recording" feature, which admits a recording bot to online meetings and performs recording, transcription and the generation of minutes. This feature may involve the processing of personal data of meeting participants who are not users of the Service. If this applies to you, please refer to Chapters 17 and 18.
2. Personal Data Protection Manager and Contact Point
We have appointed a Personal Data Protection Manager in accordance with the APPI. Inquiries, complaints or requests of any kind concerning the handling of personal information may be directed to the following.
| Item | Details |
|---|---|
| Personal Data Protection Manager | Toshiki Aburatani |
| ga@third-scope.com | |
| Postal address | Third Scope Co., Ltd., Aoyama SI Building 3F, 1-1-11 Shibuya, Shibuya-ku, Tokyo 150-0002, Japan |
| Selling and contracting entity (head office) | Third Scope Asia PTE. LTD. One&Co, 20 Anson Road, #11-01 Twenty Anson, Singapore 079912 |
3. Establishments and Representatives in Each Jurisdiction
| Category | Contact |
|---|---|
| Representative in the European Economic Area (GDPR Article 27) | DataRep. For the address in your country of residence, please refer to the Annex at the end of this Policy. |
| Representative in the United Kingdom (UK GDPR Article 27) | DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom |
| Representative in Switzerland | DataRep, Leutschenbachstrasse 95, ZURICH, 8050, Switzerland |
| Contact point for customers in the European Economic Area and the United Kingdom | info.eu@third-scope.com |
| Group company in the United Kingdom | ThirdScope Europe Co., Ltd. https://eu.third-scope.com/contact/ |
| Japan | Third Scope Co., Ltd. (same postal address as in Chapter 2) |
| Data Protection Officer (DPO) (GDPR Article 37) | Toshiki Aburatani (油谷 敏樹) ga@third-scope.com The same person as the Personal Data Protection Manager in Chapter 2 |
When contacting DataRep by post, the item must be addressed to "DataRep". Items addressed to us may not be accepted by DataRep.
4. Personal Information We Collect
In providing the Service, we may collect the following categories of personal information. For the benefit of users residing in the United States, the corresponding categories under U.S. state law are also shown.
| Category | Examples | U.S. state law category | Purpose of use |
|---|---|---|---|
| Account information | Name, email address, company name, job title, telephone number, password (hashed) | Identifiers, professional information | Provision of the Service, authentication, support |
| Usage information | Login history, feature usage, content creation history | Internet activity information | Provision and improvement of the Service |
| Technical information | IP address, browser type, OS, device identifier, time zone, language settings | Identifiers, internet activity, geolocation (approximate) | Provision of the Service, security |
| Payment information | Billing information, billing address, tax registration number (VAT/GST number, etc.), transaction history, status of your contract. Credit card numbers are not provided to us and are not stored on our servers. Payments are handled by Link, the Seller (Chapter 19) | Commercial information | Management of billing, monitoring of the status of your contract |
| Content data | Text, video, images, documents and the like uploaded by users | Internet activity information | Provision of the Service (AI content generation) |
| Meeting audio and video recording data | Audio and video of online meetings, participants' names and display names, meeting titles, dates and times and URLs, manually uploaded audio and video recording files | Audio information, visual information, identifiers | Provision of AI Recording (Chapter 17) |
| Transcripts and minutes | Transcripts of what is said in meetings, speaker attribution, generated minutes and summaries | Audio information, internet activity information, inferences | Provision of AI Recording, accumulation in the Library, reference from AI chat |
| Communications | Content of support inquiries, survey responses | Identifiers | Customer support, improvement |
| Cookie data | Session cookies, analytics cookies, similar technologies | Internet activity information | Provision of the Service, analytics |
| Inferences | Preference profiles derived from usage patterns | Inferences | Improvement of the Service |
5. Legal Bases for Processing
5.1 All Users
Under the APPI, we specify the purposes of use of personal information (Article 17) and do not handle personal information beyond the scope necessary to achieve those purposes. Consent is obtained at the time of registration for the Service. For requests to cease use or to cease provision, please refer to Chapter 13.
5.2 European Economic Area and the United Kingdom
For users residing in the EEA and the United Kingdom, we process personal data on the following legal bases.
| Purpose of processing | Legal basis |
|---|---|
| Provision of the Service and account management | Performance of a contract |
| Billing and payment processing | Performance of a contract |
| Security and fraud prevention | Legitimate interests |
| Improvement and analysis of the Service | Legitimate interests |
| Legal and regulatory compliance | Legal obligation |
| Marketing communications | Consent |
| AI content generation | Performance of a contract / Consent |
| Recording and transcription of meetings by AI Recording (in relation to the User) | Performance of a contract |
| Processing of personal data of meeting participants (other than the User) in AI Recording | We process such data as a processor on the instructions of the User (the corporate customer), who is the controller. Securing a legal basis as controller is the User's responsibility (Chapters 17 and 18). |
For processing based on legitimate interests, we carry out a balancing test to confirm that your rights and freedoms are not overridden.
5.3 United States
Under U.S. state privacy laws, we act as a "business" or "controller" when we process your personal information in connection with the Service. When we process personal information on behalf of corporate users, we act as a "service provider" or "processor".
6. Purposes of Use of Personal Information
We use personal information for the following purposes.
- Providing, operating and maintaining the Service (including account creation, identity verification and customer support)
- Billing and payment processing (including determining applicable tax amounts)
- Improving the Service, developing new features and enhancing quality (including analysis of usage patterns)
- Ensuring security and preventing and detecting improper use
- Complying with applicable laws, regulations and regulatory requirements
- Sending notices and updates concerning the Service
- Recording online meetings, generating transcripts and minutes, and accumulating the generated minutes in the Library and making them available for reference from other Apps
We do not use personal information beyond the scope necessary to achieve the purposes set out above (the principle of data minimization).
7. Consent and Withdrawal of Consent
We obtain your consent by obtaining agreement to this Policy at the time of registration for the Service. For matters requiring separate consent under the APPI (such as provision to third parties and the handling of special care-required personal information), we obtain consent individually.
You may withdraw your consent at any time via the contact point (Chapter 2) or from the "Privacy Settings" page within the Service. Please note that withdrawal of consent may make it impossible for us to provide all or part of the Service.
8. Provision to Third Parties and Entrustment
We may provide personal information to third parties only in the following cases.
- Service providers (entrusted parties): cloud hosting, databases, authentication infrastructure, analytics, email delivery and AI service providers. Under the APPI, these constitute entrustment of handling and do not constitute "provision to a third party"
- The Seller (Link/Stripe): information relating to payments. Link is not an entrusted party of ours but an independent controller. The provision of information from us to Link is characterized under the APPI as provision to a third party rather than entrustment. For details, please refer to Chapter 19
- Where required by law: where required by law, or in response to a request from a court, a regulatory authority or a law enforcement agency
- Business succession: in connection with a merger, acquisition or transfer of business
- Where you have consented: where your prior consent has been obtained
A list of the entrusted parties (sub-processors) that we use is published in the sub-processor list on our website, together with each entity's name, country of location, purpose of processing, data processed and safeguards. Where we add or change a sub-processor, we will publish the change on our website at least 30 days before the effective date of the change.
We have entered into contracts with our entrusted parties requiring them to implement appropriate security control measures in accordance with applicable laws.
9. Sale and Sharing of Personal Information
We do not sell your personal information. Nor do we provide personal information to third parties for the purposes of cross-context behavioral advertising.
We do not process sensitive personal information without your consent beyond the purposes necessary to provide the Service. Should this policy change in the future, we will update this Policy and provide the required opt-out mechanisms.
10. Cross-Border Transfers of Data
Because the Service is provided globally, personal information may be transferred outside Japan. The principal transfer destinations and safeguards are as follows.
| Nature of processing | Country of location | Principal entities | Safeguards |
|---|---|---|---|
| Storage and delivery of content | United States (Japan region is used) | Amazon Web Services, Inc. | SCCs, SOC 2 Type II, ISO 27001, AES-256 encryption at rest |
| Database | Singapore | Supabase, Inc. | SCCs, encryption, access controls |
| User authentication | United States | Clerk, Inc. | SCCs, AES-256 encryption |
| Payments and sales (the Seller) | United States/Ireland | Stripe (Link) Acquirer of payments: Stripe Payments Company or Stripe Technology Europe, Limited | PCI DSS Level 1, SCCs, tokenization (card numbers are not stored on our servers). Link is an independent controller and handles information in accordance with its own privacy policy (Chapter 19) |
| Processing by generative AI | United States | OpenAI, LLC/Anthropic PBC/Google LLC | SCCs (2021/914), DPAs with each provider, inputs and outputs deleted within 30 days, not used for model training |
| Meeting recording and transcription | United States | Hyperdoc Inc. (Recall.ai) | EU SCCs and the UK Addendum, DPA, SOC 2, ISO 27001, operated with a defined retention period |
| Audio transcription | United States | OpenAI, LLC (Whisper API and the like) | SCCs, DPA, audio data deleted after processing |
| Security logs | Singapore | Amazon Web Services, Inc. | Stored within the region, log encryption, restricted access |
- Japan: where personal data is provided to a third party located in a foreign country under the APPI, we obtain your prior consent, or confirm that the recipient has established a system conforming to the standards prescribed by the rules of the Personal Information Protection Commission, or that the recipient is located in a country recognized as having an equivalent level of protection
- EEA and the United Kingdom: we implement the Standard Contractual Clauses (SCCs 2021/914) and the UK International Data Transfer Addendum (UK Addendum), and carry out transfer impact assessments
- Other jurisdictions: we enter into data processing agreements or other legally binding instruments to ensure an appropriate level of protection
11. Data Security
In accordance with the security control measures required by the APPI (organizational, human, physical and technical measures), we implement security measures including the following.
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Access controls, role-based access management and multi-factor authentication
- Tenant isolation
- Regular vulnerability scanning, security assessments and audits
- Education and training of employees on the protection of personal information
No method of transmission over the internet or method of electronic storage is completely secure, and absolute security cannot be guaranteed.
12. Data Retention Periods
We retain personal information for the period necessary to achieve the purposes of collection, or for the period required by law. The principal retention periods are as follows.
| Data | Retention period | Basis |
|---|---|---|
| Account information, content data, usage information | While the account exists and for 30 days after termination of the contract | Article 9 of the Terms of Service |
| Recording data, audio data, transcripts, minutes | While the account exists and for 30 days after termination of the contract | Article 9 of the Terms of Service |
| Transaction records, invoices | Statutory retention period (Japan: 7 years/Singapore: 5 years) | Tax and accounting legislation |
| Security logs, authentication logs | 1 year | Legitimate interests (fraud detection) |
| Support inquiries | 3 years after resolution | Legitimate interests |
| Website analytics data | 14 months | Google Analytics retention period setting |
| Marketing communication settings | Until consent is withdrawn | Consent |
After termination of the contract, we will delete or anonymize user data upon expiry of the periods set out above (except where retention is required by law).
13. Your Rights
You may exercise the following rights in respect of your personal information. The availability of each right depends on the applicable law based on your place of residence.
| Right | Description | All users | EEA/UK | United States |
|---|---|---|---|---|
| Disclosure/access | Request for disclosure of the personal information we hold | ✓ | ✓ | ✓ |
| Correction | Request for correction of inaccurate personal information | ✓ | ✓ | ✓ * |
| Cessation of use/deletion | Request for cessation of use or deletion of personal information | ✓ | ✓ | ✓ |
| Cessation of provision to third parties | Request for cessation of provision of personal data to third parties | ✓ | — | — |
| Notification of the purpose of use | Request for notification of the purpose of use of personal information | ✓ | — | — |
| Data portability | Receipt of data in a portable, machine-readable format | ✓ ** | ✓ | ✓ |
| Restriction of processing | Request for restriction of processing under certain conditions | — | ✓ | — |
| Objection to processing | Objection to processing based on legitimate interests | — | ✓ | — |
| Opt-out of sale/sharing | Opt-out of the sale or sharing of personal information (we do not currently sell or share) | — | — | ✓ |
| Opt-out of targeted advertising | Opt-out of targeted advertising (we do not engage in targeted advertising) | — | — | ✓ |
| Opt-out of profiling | Opt-out of automated decision-making with legal or similarly significant effects | — | ✓ | ✓ |
| Non-discrimination | The right not to be discriminated against for exercising your rights | — | — | ✓ |
| Complaint to a supervisory authority | Lodging a complaint with a data protection authority | ✓ | ✓ | ✓ *** |
* Not available in every U.S. state. ** Under the APPI, disclosure may be provided by electromagnetic record. *** Complaints are made through the state attorney general.
13.1 How to Exercise Your Rights
- Email: ga@third-scope.com
- Web form: from the "Privacy Settings" page within the Service
We will process your request after verifying your identity. The period required for a response is within 30 days.
Where you are an employee or other person related to a corporate customer, we handle personal data as a processor and may therefore direct you to contact that corporation (the controller) first. If you are making a request as a meeting participant, please refer to Chapter 18.
Under the personal information protection laws of each country, we may charge a fee for disclosure requests. The amount of any fee will be notified to you at the time of the request. Users in the United States may also make requests through an authorized agent.
13.2 Supervisory Authorities
If you are not satisfied with our response, you may lodge a complaint with the following supervisory authorities.
- Japan: Personal Information Protection Commission (PPC) — https://www.ppc.go.jp
- EEA: the data protection supervisory authority of your Member State of residence — https://edpb.europa.eu/about-edpb/about-edpb/members_en
- United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk
- United States: the office of the attorney general of your state of residence
14. Universal Opt-Out Mechanisms
We recognize and honor browser-based universal opt-out mechanism signals, including Global Privacy Control (GPC). Where you access the Service from a browser or device that transmits such a signal, we treat it as a valid opt-out request in accordance with applicable law.
15. Cookies and Tracking Technologies
The Service uses cookies and similar technologies. For details, please refer to our Cookie Policy (https://kanata-ai.com/ja/cookie-policy/). For users in the EEA and the United Kingdom, we obtain consent through a cookie consent banner before placing non-essential cookies.
16. Special Provisions Concerning Generative AI
KANATA uses generative AI technology to create content. The following provisions apply.
- Text entered and content uploaded by users may be transmitted to third-party AI service providers for the purpose of content generation. The AI service providers we currently use are OpenAI, LLC, Anthropic PBC and Google LLC.
- We do not use users' Input Data or Output for the purpose of training AI models. We have also contractually secured with the AI service providers listed above that data transmitted via API will not be used for model training.
- Input and output data transmitted to AI service providers is deleted by those providers within 30 days.
- We limit the data we transmit to the scope necessary for processing (data minimization) and implement prompt injection countermeasures and output filtering.
- Generated content may contain statements that differ from fact, omissions or other errors. We do not warrant the accuracy, completeness or fitness for a particular purpose of the Output (Article 12, paragraphs 5 and 6 of the Terms of Service).
- Pursuant to Article 50 of the European Union Regulation on Artificial Intelligence (the AI Act), we display on the screens of the Service that the user is interacting with an AI system and that the output has been generated by AI.
For users in the EEA and the United Kingdom, the legal basis for this processing is performance of a contract or consent. Under the APPI, this processing falls within the purposes of use set out in Chapter 6.
17. Special Provisions Concerning AI Recording
AI Recording is a feature that admits a recording bot to online meetings such as Zoom or Google Meet and performs recording, transcription and the generation of minutes. Audio and video recording files already in your possession may also be imported. Because this feature involves a broader range of personal data than ordinary use of the Service, separate provisions are set out in this Chapter.
17.1 Data We Collect
- Audio and video of meetings
- Names or display names of meeting participants
- Meeting titles, dates and times, participant lists and meeting URLs
- Transcripts of what is said, and speaker attribution
- Generated minutes and summaries
- Manually uploaded audio and video recording files and their contents
17.2 Our Role
Where you are a corporation or other organization, we process meeting recording data and the transcripts and minutes generated from it as a processor (a party entrusted with handling under the APPI), on your instructions as controller. Notifying meeting participants and obtaining any consent required under applicable law is your responsibility as controller. Details are set out in the AI Recording Terms of Use and the Data Processing Agreement (DPA).
17.3 Processing Routes
| Processing | Country of location | Entity | Handling |
|---|---|---|---|
| Storage of recording and audio data | Japan (Tokyo region) | Amazon Web Services, Inc. | AES-256 encryption at rest, tenant isolation |
| Audio transcription | United States | OpenAI, LLC | Transferred temporarily for transcription and deleted after processing |
| Generation of minutes and summaries | United States | OpenAI, LLC/Anthropic PBC/Google LLC | Input and output data is deleted by each provider within 30 days. Not used for model training |
| Entry of the recording bot into meetings, recording, and generation of speaker-labeled transcripts | United States | Hyperdoc Inc. (Recall.ai) | Our sub-processor. A DPA has been concluded. EU SCCs and the UK Addendum. Operated with a defined retention period so that recording data is not retained indefinitely |
17.4 Retention and Deletion
Recording data, audio data, transcripts and minutes are retained while the account exists and for 30 days after termination of the contract, and are then deleted. You may delete the record of any individual meeting at any time from the screens of the Service.
17.5 Scope of Sharing of Minutes
Generated minutes are accumulated in the Library of the relevant Project, can be viewed by Members of that same Project, and are subject to reference from AI chat. Even Members who did not attend the meeting may be able to access the contents if they are Members of that Project. This scope of sharing is managed by you (the controller) through the Project settings.
17.6 Accuracy
Transcripts and minutes may contain mishearings, incorrect conversion of technical terms, incorrect speaker attribution and omissions of content. We do not warrant their accuracy.
18. Personal Data of Meeting Participants and Others Who Have No Direct Contractual Relationship with Us
Persons who have no direct contractual relationship with us may participate in meetings hosted or attended by customers using AI Recording. In such cases, we handle the audio and video of the meeting, the names or display names, and the content of what is said.
18.1 Route of Acquisition and Legal Basis
We acquire this personal data not directly from the data subject but through our customer. We handle it as a processor, and the controller is our customer (the corporate customer) who hosted and recorded the meeting. Notification of recording and obtaining any consent required under applicable law are carried out under the responsibility of the controller.
18.2 Indication That Recording Is Taking Place
The recording bot joins under a name displayed in the meeting's participant list, so that meeting participants can recognize that recording is taking place. Depending on the specifications of the meeting platform, a notification may be displayed when it joins.
18.3 Requests from Data Subjects
Where a person who has been recorded as a meeting participant wishes to exercise rights of disclosure, deletion or otherwise in respect of their own data, either of the following methods may be used.
- Contacting the organization that hosted the meeting (our customer). Because we are a processor, we will in principle respond through the controller.
- Contacting our contact point (Chapter 2) directly. In this case, we will promptly refer the matter to our customer, who is the controller, and respond in accordance with the controller's instructions.
Where we receive a request, we will verify the identity of the data subject and respond within the period prescribed by applicable law.
18.4 Objection to Recording
Where an objection to recording is raised during a meeting, the decision to stop recording that meeting or to delete content already recorded is made by our customer who hosts the meeting. We provide the means to stop and delete recordings so that the customer can give effect to that decision.
19. Payment Services (Link)
19.1 The Seller
Payments for the BUSINESS plan and Additional Credits use Managed Payments provided by Stripe. Under this arrangement, Stripe (displayed to you under the name "Link") is the Seller (merchant of record). Receipt of consideration, the issuance of receipts and invoices, refunds, and the collection and remittance of consumption tax and similar taxes are, in principle, carried out by Link.
The Service itself is provided by us.
19.2 The Relationship Between Us and Link
Link is not an entrusted party (processor) that processes personal data on our instructions. Link sells in its own name, files its own taxes and has a direct relationship with you (a Link account). We therefore treat Link as an independent controller.
The handling of information you provide to Link in connection with payment is governed by the privacy policy established by Link. We bear no responsibility as controller in respect of such information.
19.3 Information We Receive
In connection with payments, we receive the following information from Link and use it to manage billing and to monitor the status of your contract.
- Name, email address
- Billing address, tax registration number (VAT/GST number, etc.)
- Transaction history and the status of your contract (active, payment being retried, terminated)
Credit card numbers are not provided to us and are never stored on our servers.
19.4 Link Accounts
When making a payment, you may either create a Link account or purchase as a guest without creating one. If you have a Link account, you may review your order history, cancel your contract, and change your payment method and billing address at link.com.
Receipts, invoices, refund notices and notices concerning the renewal of your contract are sent to you directly by Link.
19.5 Requests to Link for Deletion of Data
Where you request Link to delete your information, Link will do the following.
- Cancel the contract (subscription) taken out through Managed Payments
- Delete data relating to payments (including data stored within our Stripe account)
- Notify us
As a result, your contract for the Service will also terminate and all Seats you have purchased will cease to exist. It is not possible to delete only the information relating to payments while continuing to use the Service. We are unable to stop such a request.
19.6 Cross-Border Transfers
Information relating to payments is transferred outside Japan through Link and Stripe affiliates. Payments are acquired by Stripe Payments Company or Stripe Technology Europe, Limited.
20. Children's Privacy
The Service is intended primarily for business use and is not directed at children.
- Under 13: we do not knowingly collect personal information from children under 13. If we discover that such information has been collected, we will delete it promptly in accordance with applicable law.
- Under 16: we do not sell or share the personal information of minors under 16, in accordance with applicable law.
21. Data Protection Impact Assessments
We carry out data protection impact assessments for processing activities that may present a high risk to the rights and freedoms of individuals. These include the content processing features based on generative AI and the recording and transcription of meetings by AI Recording. The results of assessments will be provided upon request by the relevant supervisory authority.
22. Response to Personal Data Breaches
In the event of a personal data breach, we will promptly assess the scope and impact of the breach, report it to the supervisory authority within the time limits prescribed by applicable law, and notify the data subjects without delay. The principal time limits are as follows.
| Jurisdiction | Report to the supervisory authority | Notification to data subjects |
|---|---|---|
| Japan (APPI) | Preliminary report: promptly after becoming aware of the incident (generally within 3 to 5 days) Final report: within 30 days in principle; within 60 days where the incident results from unauthorized access or the like | Promptly, depending on the circumstances of the incident |
| EEA/UK (GDPR/UK GDPR) | Within 72 hours of becoming aware | Without undue delay where there is a high risk to the rights and freedoms of individuals |
| United States (state law) | In accordance with the time limits prescribed by each state law | In accordance with the time limits prescribed by each state law |
Our internal response procedures are designed to meet the shortest of the above time limits (72 hours).
23. Financial Incentives
We do not offer any financial incentive program in connection with the collection, retention, sale or sharing of personal information.
24. Changes to This Policy
We may update this Policy from time to time. The updated Policy will be published on our website. In the case of material changes, we will notify you by email or in-app notification. Where a material change requires a new legal basis in relation to users, we will obtain consent before the change takes effect.
25. Complaints and Inquiries
If you have any questions, complaints or concerns about this Policy, please contact our contact point (Chapter 2). If you are not satisfied with our response, you may lodge a complaint with the relevant supervisory authority (Section 13.2).
26. Governing Law
This Policy is governed by the laws of Japan. Disputes arising out of or in connection with this Policy shall be resolved in accordance with Article 29 of the Terms of Service. This governing law provision does not limit any rights you have under mandatory data protection laws applicable in your place of residence.
Annex List of Contact Addresses for the Data Protection Representative (DataRep)
We have appointed DataRep as our data protection representative under Article 27 of the GDPR and Article 27 of the UK GDPR. Customers residing in the European Economic Area, the United Kingdom or Switzerland may contact us in writing at the address below for their country of residence.
When sending by post, the item must be addressed to "DataRep". Items sent to the addresses below and addressed to us (Third Scope Asia PTE. LTD.) may not be accepted by DataRep. Please state clearly in the body of your letter that the correspondence concerns our company and "KANATA".
| Country | Address |
|---|---|
| Iceland | DataRep, Laugavegur 13, 101 Reykjavik, Iceland |
| Ireland | DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland |
| Italy | DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy |
| Estonia | DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia |
| Austria | DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Netherlands | DataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands |
| Cyprus | DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus |
| Greece | DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece |
| Croatia | DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia |
| Switzerland | DataRep, Leutschenbachstrasse 95, ZURICH, 8050, Switzerland |
| Sweden | DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden |
| Spain | DataRep, Calle de Manzanares 4, Madrid, 28005, Spain |
| Slovakia | DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia |
| Slovenia | DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia |
| Czech Republic | DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic |
| Denmark | DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark |
| Germany | DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany |
| Norway | DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway |
| Hungary | DataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary |
| Finland | DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland |
| France | DataRep, 72 rue de Lessard, Rouen, 76100, France |
| Bulgaria | DataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria |
| Belgium | DataRep, Rue des Colonies 11, Brussels, 1000 |
| Poland | DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland |
| Portugal | DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal |
| Malta | DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta |
| Latvia | DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia |
| Lithuania | DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania |
| Liechtenstein | DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria |
| Luxembourg | DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg |
| Romania | DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania |
| United Kingdom | DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom |
Enacted: 7 May 2026 / Revised: 27 August 2026 (v1.1)
Third Scope Asia PTE. LTD.
One&Co, 20 Anson Road, #11-01 Twenty Anson, Singapore 079912