Kufa

Information Security Policy

Established: August 1, 2026 / Published: August 19, 2026 / Last updated: August 22, 2026 / 日本語

1. Purpose

This policy defines how Daiichi Co., Ltd. (the "Company") protects the information assets it handles — in particular, user personal data and confidential information obtained from external platforms such as TikTok Partner Center — and prevents information security incidents.

2. Scope

This policy applies to all business operations, systems, services, and information assets (data, source code, server environments, etc.) managed by the Company.

3. Governance and Responsibility

The Company operates as a small organization. The representative director serves as the Chief Information Security Officer (CISO) and bears full responsibility for maintaining and improving information security and ensuring legal compliance.

4. Information Asset Management and Data Security

  1. Encryption:
    • All data in transit is encrypted using HTTPS/TLS.
    • Customer personal data (names, addresses, etc.) is stored within the systems of the EC marketplaces (TikTok Shop, BASE, Qoo10). The Company handles only the minimum fields necessary for shipping and customer support, and does not retain such data long-term in its own environment.
    • Confidential information stored in the Company's own environment (API credentials, configuration files, etc.) is kept in separate, access-restricted configuration files and is excluded from shared areas such as source code repositories.
    • The disk of the development PC (Windows) is encrypted with BitLocker.
  2. Access Control (Principle of Least Privilege):
    • The Company operates with an effective staff of one person. Access to servers, databases, and administrative consoles is restricted to the sole representative director.
    • Important online accounts (email, etc.) are protected with multi-factor authentication (MFA).
    • Server logins permit SSH public-key authentication only; password authentication is disabled. Administrative work from external networks is performed via VPN connections.
    • Access privileges that are no longer needed for business purposes are revoked immediately.
  3. Data Minimization and Retention Limits:
    • Data obtained from TikTok APIs and similar sources is limited to the minimum fields required to provide our services.
    • Obtained data is retained only for as long as necessary to achieve the purpose of use, and data that is no longer needed is promptly and securely erased.

5. Data Classification

The Company classifies the information it handles into the following three categories and applies protections appropriate to each.

6. Network Security

7. Legal and Platform Compliance

The Company complies with Japanese privacy laws including the Act on the Protection of Personal Information, and strictly observes TikTok's Developer Terms of Service, Data Security Policy, and other applicable terms. The Company responds promptly to user requests for data disclosure or deletion.

8. Training and Fundamental Security Practices

The representative director and any future team members maintain regular security knowledge updates to protect information assets from malware and unauthorized access. The following fundamental practices are implemented:

9. Incident Response

In the event of a data breach, unauthorized access, or any suspected security incident, the Company will immediately take measures to contain the damage and promptly report to all relevant parties, including TikTok and regulatory authorities. Detailed procedures are defined in our Incident Response Policy.

Established: August 1, 2026
Organization: Daiichi Co., Ltd.
Representative: Koji Sugawa, Representative Director