Loading JapaReady
Preparing your personalized workspace.
Loading JapaReady
Preparing your personalized workspace.
Contact: compliance contact form
JapaReady is designed around GDPR principles and aligns product practices with privacy expectations that also support CCPA, PIPEDA, and LGPD-style rights workflows for you. We do not claim formal certifications we have not obtained.
We are operating toward ISO 27001-aligned controls, preparing for SOC 2 Type II maturity, and using the NIST Cybersecurity Framework as a practical reference point.
PCI DSS obligations for raw card handling are delegated to Paystack, Flutterwave, and Paddle as Level 1 payment providers. JapaReady does not directly store full card data.
WCAG 2.1 Level AA is the current target. ADA-aligned design and broader multi-language expansion remain active product priorities.
Subscription disclosures, billing expectations, and liability limits are documented plainly in public policy pages so you can make informed decisions.
We cooperate with the KYC and AML processes enforced by payment providers and remain attentive to sanctions-related restrictions where legally required.
Our operating posture includes detection, containment, breach review, and 72-hour notification where GDPR requires it, plus post-incident improvement work.
Supabase supports GDPR-aligned data handling, Vercel provides certified hosting options depending on deployment, Google Generative AI powers certain recommendation features, and payment providers operate as PCI DSS Level 1 vendors under signed DPAs.
We maintain awareness of OFAC and EU sanctions obligations and may restrict access where legally required for sanctioned jurisdictions.
Use /contact?category=compliance for compliance inquiries.