Information Security Policy
Share-Me Co., Ltd. (hereinafter referred to as the “Company”) recognizes information security as one of its key management priorities. As a cloud-based SaaS provider handling information assets such as business card information and activity logs of employees and customers, the Company is committed to maintaining and enhancing information security. In consideration of our fully remote work environment and business model involving outsourced development teams overseas, the Company implements and continuously improves information security based on the following policy.
1. Scope This policy applies to all information assets managed or used by the Company, as well as all officers, employees, and contractors of the Company (hereinafter collectively referred to as “Related Parties”).
2. Compliance with Laws and Contracts The Company complies with the Act on the Protection of Personal Information and other applicable laws, regulations, and guidelines, as well as information security requirements stipulated in contracts with customers and business partners.
3. Management of Information Assets The Company recognizes information assets, including business card information, activity logs, customer information, and business-related information, as important corporate assets and manages them appropriately based on the following principles: ● Clearly define the purpose of use and handle information only to the extent necessary. ● Implement appropriate technical and organizational measures to prevent unauthorized access, information leakage, tampering, loss, or destruction.
4. Security Measures for Cloud Services and Remote Work Based on our cloud-based environment and fully remote work model, the Company implements the following measures: ● Appropriate selection and configuration management of cloud services used for business purposes. ● Restriction of access privileges to the minimum necessary and regular review of access rights. ● Ensuring the security of devices used for business purposes, including personally owned devices.
5. Management of Contractors For contractors, including those located overseas, the Company clearly defines information security requirements appropriate to the nature of the services provided and manages contractors appropriately through contractual agreements and operational controls.
6. Education and Security Awareness The Company continuously provides education and awareness activities to Related Parties to ensure that they understand the importance of information security.
7. Incident Response and Prevention of Recurrence In the event of, or in anticipation of, an information security incident, the Company will respond promptly to minimize potential damage and take appropriate measures to prevent recurrence.
8. Continuous Improvement The Company regularly reviews this policy and its information security management framework and strives for continuous improvement.
January 15, 2026 Share-Me Co., Ltd. President & CEO
|