Information Security Policy
Purpose
Pirika, Inc. (the "Company") provides cloud services that aim to solve environmental problems, including the litter-picking social network Pirika, carries out surveys and consulting on solving environmental problems, and manages its personnel (together, the "Business"). Because the Business uses many information assets, we recognize that achieving information security and protecting these assets is essential to running our operations with the trust of society, and is also an important social responsibility. In light of the importance of information security, the Company establishes this Information Security Policy (the "Policy"), and will establish, implement, maintain, and continually improve an information security management system to put it into practice.
Definition of Information Security
We define information security as maintaining confidentiality, integrity, and availability.
-
Confidentiality
Protecting information assets from unauthorized access and not leaking them to anyone without permission to view them. (The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.) -
Integrity
Protecting information assets from tampering and errors, and keeping them accurate and complete. (The property of accuracy and completeness.) -
Availability
Protecting information assets from loss, damage, and system outages, and keeping them usable when needed. (The property of being accessible and usable on demand by an authorized entity.)
Scope
This Policy applies to all information assets managed by the Company. Information assets include not only electronic devices and electronic data but all forms, including paper.
-
Organization
Pirika, Inc. (all personnel) -
Facilities
Head office (address: 1-4-7-802 Kudankita, Chiyoda-ku, Tokyo, Japan) -
Operations
Providing cloud services that aim to solve environmental problems, and surveys and consulting on solving environmental problems -
Assets
Documents, data, information systems, and networks related to the operations and services above
Measures We Take
In line with this Policy and the Company's information security management system, we carry out the following.
-
Information security objectives
We set information security objectives that are consistent with this Policy and take into account applicable information security requirements and the results of risk assessment and risk treatment. We share them with all personnel and review them whenever the Company's environment changes, and regularly even when it does not. -
Handling of information assets
- Access rights are given only to those who need them for their work.
- Information assets are managed in accordance with legal, regulatory, and contractual requirements and the rules of the Company's information security management system.
- Information assets are classified and managed appropriately according to their importance, in terms of value, confidentiality, integrity, and availability.
- We monitor continuously to confirm that information assets are properly managed.
-
Risk assessment
- We carry out risk assessment, apply appropriate risk treatment to the information assets we judge most important given the nature of the Business, and introduce controls.
- We analyze the causes of information security incidents and take measures to prevent them from happening again.
-
Business continuity management
We keep interruptions to the Business from disasters, failures, and the like to a minimum and secure our ability to continue operating. -
Education
We provide information security education and training to all personnel. -
Compliance with rules and procedures
We comply with the rules and procedures of the information security management system. -
Compliance with legal, regulatory, and contractual requirements
We comply with legal, regulatory, and contractual requirements related to information security. -
Continual improvement
We work to continually improve the information security management system.
Responsibilities, Duties, and Penalties
Top management is responsible for the information security management system, including this Policy. Personnel within the scope are obliged to comply with the established rules and procedures. Personnel who neglect this duty and commit violations will be subject to disciplinary action under the rules of employment. For employees of partner companies, we respond in accordance with individually agreed contracts and similar documents.
ISMS Certification
Obtained September 18, 2025 / Renewed July 29, 2026
Details (in Japanese)
Periodic Review
The information security management system is reviewed regularly and whenever necessary, and is maintained and managed.
Established: June 1, 2021
Last revised: September 11, 2026
Top Management: Fujio Kojima
