Information Security Policy
Established: August 1, 2026 / Published: August 19, 2026 / Last updated: August 22, 2026 / 日本語
1. Purpose
This policy defines how Daiichi Co., Ltd. (the "Company") protects the information assets it handles — in particular, user personal data and confidential information obtained from external platforms such as TikTok Partner Center — and prevents information security incidents.
2. Scope
This policy applies to all business operations, systems, services, and information assets (data, source code, server environments, etc.) managed by the Company.
3. Governance and Responsibility
The Company operates as a small organization. The representative director serves as the Chief Information Security Officer (CISO) and bears full responsibility for maintaining and improving information security and ensuring legal compliance.
4. Information Asset Management and Data Security
-
Encryption:
- All data in transit is encrypted using HTTPS/TLS.
- Customer personal data (names, addresses, etc.) is stored within the systems of the EC marketplaces (TikTok Shop, BASE, Qoo10). The Company handles only the minimum fields necessary for shipping and customer support, and does not retain such data long-term in its own environment.
- Confidential information stored in the Company's own environment (API credentials, configuration files, etc.) is kept in separate, access-restricted configuration files and is excluded from shared areas such as source code repositories.
- The disk of the development PC (Windows) is encrypted with BitLocker.
-
Access Control (Principle of Least Privilege):
- The Company operates with an effective staff of one person. Access to servers, databases, and administrative consoles is restricted to the sole representative director.
- Important online accounts (email, etc.) are protected with multi-factor authentication (MFA).
- Server logins permit SSH public-key authentication only; password authentication is disabled. Administrative work from external networks is performed via VPN connections.
- Access privileges that are no longer needed for business purposes are revoked immediately.
-
Data Minimization and Retention Limits:
- Data obtained from TikTok APIs and similar sources is limited to the minimum fields required to provide our services.
- Obtained data is retained only for as long as necessary to achieve the purpose of use, and data that is no longer needed is promptly and securely erased.
5. Data Classification
The Company classifies the information it handles into the following three categories and applies protections appropriate to each.
- Personal Data (customer names, addresses, phone numbers, email addresses, order contents): Stored within marketplace systems and handled by the Company only to the extent necessary for shipping operations. Access is limited to the sole representative director, and data is deleted promptly after statutory retention periods expire.
- Transaction Data (order history, inventory data, etc.): Managed on access-restricted company-owned servers with communications encrypted via TLS. Backups are created regularly.
- System Information (API credentials, server configurations, source code, etc.): API credentials are kept in separate, access-restricted configuration files excluded from version control. Source code change history is tracked in Git, with significant changes reviewed before deployment.
6. Network Security
- A firewall (ufw) blocks inbound access on all ports except those required for business operations.
- SSH access is permitted only from specific IP addresses, using public-key authentication (password authentication disabled).
- fail2ban automatically detects and blocks unauthorized login attempts.
- Security patches for server OS and applications are checked and applied weekly.
7. Legal and Platform Compliance
The Company complies with Japanese privacy laws including the Act on the Protection of Personal Information, and strictly observes TikTok's Developer Terms of Service, Data Security Policy, and other applicable terms. The Company responds promptly to user requests for data disclosure or deletion.
8. Training and Fundamental Security Practices
The representative director and any future team members maintain regular security knowledge updates to protect information assets from malware and unauthorized access. The following fundamental practices are implemented:
- Screen lock (automatic lock when away from the device)
- Use of complex passwords, with no reuse across services
- Clear desk practices (no confidential information left on desks or screens)
- Multifactor authentication (MFA) on important accounts
- Antivirus software installed on development PCs, with up-to-date OS updates applied
9. Incident Response
In the event of a data breach, unauthorized access, or any suspected security incident, the Company will immediately take measures to contain the damage and promptly report to all relevant parties, including TikTok and regulatory authorities. Detailed procedures are defined in our Incident Response Policy.
Established: August 1, 2026
Organization: Daiichi Co., Ltd.
Representative: Koji Sugawa, Representative Director
