CLOUD SECURITY POLICY

Cloud Service Information Security Policy

This English translation is provided for reference only. In the event of any discrepancy, the Japanese version shall prevail.

Basic Philosophy

ShareWis Inc. has established this policy to maintain information security in the provision of cloud services. So that our customers can use our services with confidence, all related parties, including directors and employees, comply with this policy and work on continuous improvement. This policy is positioned as a subordinate policy to our separately established Information Security Policy.

Basic Policy

  1. Information security requirements applied to the design and implementation of cloud services
    We design and implement our services based on customers’ information security requirements, applicable laws including the Act on the Protection of Personal Information, and our company policies.
  2. Addressing insider risks and controlling data access
    Our policy is not to access customer data except where permitted by the customer or where unavoidable for service continuity, and access rights are restricted to the minimum necessary.
  3. Multi-tenancy
    Even in environments adopting a multi-tenant architecture, customer data is appropriately segregated so that it cannot be accessed across tenants.
  4. Notification of service changes
    When service changes occur, such as discontinuation of features or service suspension for maintenance, we notify customers in advance.
  5. Handling of accounts and data after termination
    Upon termination of the contract, customer accounts and data are deleted within the period we specify.
  6. Digital forensics
    In the event of an information security incident, we maintain a structure capable of responding to individual requests for the submission of evidence.