Effective Date: May 31, 2026

Last Updated: May 31, 2026

PREAMBLE

Welcome to Shugyokai (“we,” “our,” or “us”). We operate the website https://shugyokai.org (the “Site”). We respect your privacy and are committed to protecting your personal data in accordance with applicable global data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).


SECTION 1: WHO WE ARE AND HOW TO CONTACT US

The data controller responsible for your personal data is Shugyokai.

If you have any questions about this Privacy Policy, how we handle your data, or if you wish to exercise your legal rights, please contact us at:

  • Email: [Insert Contact Email Address]
  • Mailing Address: [Insert Physical Address, if applicable]

SECTION 2: WHAT PERSONAL DATA WE COLLECT AND WHY WE COLLECT IT

We only collect and process personal data when we have a valid legal basis to do so (e.g., your consent, the performance of a contract, or our legitimate business interests).

  1. Comments: When visitors leave comments on the Site, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string. This data is processed based on our legitimate interest in detecting and preventing spam. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
  2. Media: If you upload images to the Site, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the Site can download and extract any location data from images hosted on the website.
  3. Contact Forms & Communication: If you contact us directly via a contact form or email, we collect your name, email address, and any information you choose to provide. We process this data to respond to your inquiries based on our legitimate interest in providing user support.
  4. Cookies and Tracking Technologies: We use cookies to optimize your experience, analyze site performance, and remember your preferences. You can manage or disable cookies through your browser settings.
    • Comment Cookies: If you leave a comment, you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so you do not have to fill in your details again. These cookies last for one year.
    • Session Cookies: If you visit our login page, we set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
    • Login & Display Cookies: When you log in, we set up several cookies to save your login information and screen choices. Login cookies last for two days, and screen options cookies last for one year. If you select “Remember Me”, your login persists for two weeks. Logging out removes these cookies.
    • Editor Cookies: If you edit or publish an article, an additional cookie is saved indicating the post ID of the article. It contains no personal data and expires after 1 day.
  5. Analytics & Third-Party Tools: We use analytics tools (such as WordPress) to evaluate content engagement and optimize Site performance. These platforms collect anonymized usage data, such as page views and interactions. We do not engage in invasive automated profiling or behavior tracking across the web for advertising purposes.

SECTION 3: EMBEDDED CONTENT FROM OTHER WEBSITES

Articles on this Site may include embedded content (e.g., videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website. We encourage you to review the privacy policies of those third-party websites.


SECTION 4: WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We only share your data with trusted service providers to run our website and business, subject to strict data protection agreements:

  1. Spam Detection: Visitor comments may be checked through an automated spam detection service.
  2. Payment Processing (Stripe): If you make a transaction on our Site, payment processing is handled securely by Stripe. Our e-commerce system does not store or record confidential payment information (such as credit card numbers); we only retain transaction metadata necessary to identify and validate your transaction.
  3. Hosting Providers: Our Site is hosted through WordPress.com (Automattic), which processes data in secure data centers worldwide.
  4. Password Resets: If you request a password reset, your IP address will be included in the reset email.

SECTION 5: INTERNATIONAL DATA TRANSFERS

Because our hosting provider (WordPress.com) and third-party services (such as Stripe) operate globally, the personal data we collect may be transferred to, and stored in, countries outside of your home region (including the United States). Where required by law, we ensure these transfers are protected by appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission.


SECTION 6: HOW LONG WE RETAIN YOUR DATA

We only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including legal, accounting, or reporting requirements.

  1. Comments: If you leave a comment, the comment and its metadata are retained indefinitely so we can recognize and approve follow-up comments automatically.
  2. Registered Users: For users that register on our website (if any), we store the personal information provided in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

7. Your Legal Privacy Rights

Depending on your geographic location (such as the EU/UK or California), you may have the following rights regarding your personal data:

  1. Right to Access/Portability: You can request an exported file of the personal data we hold about you.
  2. Right to Erasure (“Right to be Forgotten”): You can request that we delete your personal data. This does not include data we are legally obligated to keep for administrative, legal, or security purposes.
  3. Right to Rectification: You can request that we correct inaccurate or incomplete personal data.
  4. Right to Object or Restrict Processing: You have the right to object to or restrict our processing of your data under certain circumstances.
  5. Right to Opt-Out of Data Sales/Sharing: We do not sell your data. However, you have the right to control any automated sharing via cookie preferences.

To exercise any of these rights, please contact us via the email listed in Section 1. We will respond to your request within the legally mandated timeframe (typically 30 days).


SECTION 8: HOW WE PROTECT YOUR DATA & BREACH PROCEDURES

We take security seriously. Your data is protected by the security infrastructure of WordPress.com, utilizing encrypted data transfers (HTTPS/SSL) and secure data centers.

In the highly unlikely event of a data breach that compromises your personal information, we have procedures in place to assess the risk and notify affected users and relevant regulatory authorities within 72 hours, where legally required.


SECTION 9: CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices or international legal requirements. We will notify you of any material changes by posting the updated policy on this page and updating the “Effective Date” at the top.