Basic policy
We are entrusted with our clients’ business data in order to design, build and run AI agents. To handle it safely, we comply with the applicable laws and our contracts, and work according to this policy.
- Person responsible for information security
- [Information security officer]
Scope
This policy applies to the information we handle in our work (data entrusted by clients, the AI agents we build and run and their settings, and internal information) and to everyone who works with us.
Data in private environments
Client data is stored and processed in a private environment that is not open to the public.
- Environment
- [How the private environment is set up (client’s or ours, which cloud, which country the data is in)]
- Separation by client
- [How each client’s data is kept separate]
- Encryption
- [Encryption in transit and at rest]
- Retention and deletion
- [How long data is kept, and how it is returned or deleted when a contract ends]
Access control
Only the people whose work requires it can access data and AI agent settings. AI agents, too, act only within the permissions set for them.
- Who has access
- [Who can access, and how access is granted and reviewed]
- Authentication
- [How sign-in is authenticated (multi-factor authentication, etc.)]
- AI agent permissions
- [How permissions for AI agents are decided]
Activity logs
Every AI agent action is logged. Logs are used to find the cause when something goes wrong, and to improve.
- What is logged
- [Which actions are logged (including whether human access to data is)]
- Fields
- [Fields recorded (the action, time, who approved, etc.)]
- Retention
- [How long logs are kept]
- How to check
- [How clients can check the logs]
Human approval (approval gates)
Before an AI agent carries out an important action, a person checks and approves it. Which actions need approval, we decide with the client at the design stage.
- Actions that need approval
- [List of actions that need approval]
- Who approves
- [How the approver is chosen]
How responsibility is shared for approved actions is set out in the guarantee and support terms.
Your data is never used for training
We never use entrusted data to train AI models.
[External AI services used, and the settings or contract terms confirming that input data is not used for training]
Managing processors
When we use outside services such as cloud hosting or email delivery, we check that they handle information properly before choosing them, and share only the information they need.
[What we check when choosing processors, and how often we review them]
Examples and the list of processors are in our privacy policy.
Training
Everyone who works with us is informed about this policy and trained in how to handle information. [Training content and frequency]
Incident response
If an incident such as a data leak occurs or may have occurred, we act to limit the damage, investigate the cause and prevent it from happening again. Where the Act on the Protection of Personal Information requires a report to the Personal Information Protection Commission or notice to the people affected, we make it as the law requires.
- Telling affected clients
- [How and how quickly affected clients are told]
- Stopping AI agents
- [How a problematic AI agent is paused]
- Where to report
- Security reports are accepted at [Contact email].
Ongoing review
We review this policy and our practices [Regular review frequency], and also when technology, threats or laws change, and keep improving them.