株式会社FUJIEN(以下「当社」)は、当社ウェブページ(AI導入支援ページおよび本ページ)を通じてお預かりする個人情報を、個人情報の保護に関する法律その他の法令を遵守し、次のとおり取り扱います。
当社は、Amazon Ads API および Amazon Selling Partner API(SP-API)をはじめとする外部APIを通じて取得する事業データ(以下「Amazon情報」)を、Amazon Ads データ保護ポリシー、Amazon Ads パートナーネットワークポリシー、および Amazon データ保護ポリシー(DPP)に従って取り扱います。この第II部は、当社の安全管理措置・インシデント対応計画・通報窓口を公開するものです。
本方針は、当社が自社の事業および契約先(Amazon販売事業者)への支援業務のためにAPIを通じて取得・保管・処理するすべてのAmazon情報、および第I部でお預かりする個人情報に適用します。
Amazon情報へのアクセスと送受信はすべて暗号化された通信(TLS/HTTPS)のみで行います。
作業端末はファイアウォールとマルウェア対策を有効化し、NATによるネットワーク分離のもとで運用します。外部からの直接着信は受け付けません。
12文字以上・特殊文字を含む強固なパスワードを必須とし、主要アカウントは多要素認証(MFA)を有効化、年1回更新します。
Amazon情報へのアクセスは業務上必要な最小限の担当者に限定します。退職・契約終了時は24時間以内にアクセス権を失効させます。
パスワード・APIキー・トークンは暗号化されたパスワード管理ツールと環境変数でのみ管理し、ソースコード・共有文書・公開リポジトリには置きません。
Amazon情報に関わるインシデントを検知した場合、24時間以内にAmazon(security@amazon.com)へ報告します(詳細は「4. インシデント対応計画」)。
対象事象:Amazon情報の漏えい、不正アクセス、認証情報の流出、Amazon情報の悪用(その疑いを含む)、およびセキュリティ脆弱性の通知。
直ちに該当システムを停止し、疑いのある認証情報(APIトークン等)を即時無効化・再発行します。
Amazon情報に関わるインシデントは、検知から24時間以内に security@amazon.com へ報告します。
アクセスログ・監査ログから影響範囲(対象データ・期間・経路)を特定し、原因を除去します。
原因除去を確認したうえで再開します。影響を受ける契約先・関係者には速やかに状況と対策を通知します。
経緯・原因・対策を記録し、本計画へ反映します。計画は6か月ごと、および重大な変更の後に見直します。
| 事象 | 期限 |
|---|---|
| Amazon情報に関わるセキュリティインシデントのAmazon(security@amazon.com)への報告 | 検知後24時間以内 |
| 退職者・契約終了者のアクセス権の無効化 | 24時間以内 |
| クリティカルと判定した脆弱性の解消 | 7日以内 |
| 高リスクと判定した脆弱性の解消 | 30日以内 |
| 購入者の個人識別情報(PII)の削除(取得する場合) | 注文配送後30日以内 |
脆弱性は、使用するOS・実行環境・依存パッケージのセキュリティ更新を定期的に確認し、検出されたものを上記期限内に解消します。
データプライバシーに関する懸念、セキュリティ脆弱性の通知、Amazon情報の悪用(その疑いを含む)に関する情報は、次の窓口で受け付け、提出・追跡・対応・解決まで一貫して管理します。
本方針とインシデント対応計画は、6か月ごと(次回:2026年12月)、およびシステム構成の重大な変更やインシデントからの教訓が得られた後に見直し、更新します。
This is the English version of the Privacy Policy of FUJIEN Inc. (株式会社FUJIEN, "we" or "the Company"). Part I covers the handling of personal information collected through our web pages, which we handle in compliance with the Act on the Protection of Personal Information and other applicable laws. Part II sets out our Security & Data Protection Policy for business data obtained through external APIs, including the Amazon Ads API and the Amazon Selling Partner API (SP-API) (collectively, "Amazon Information"), which we handle in accordance with the Amazon Ads Data Protection Policy, the Amazon Ads Partner Network Policies, and the Amazon Data Protection Policy (DPP).
This policy applies to all Amazon Information that we obtain, store, or process through APIs, whether for our own business or in support of our clients (Amazon selling partners), and to the personal information described in Part I.
All access to and transmission of Amazon Information takes place exclusively over encrypted connections (TLS/HTTPS).
Work devices run with firewalls and anti-malware protection enabled and operate behind NAT-based network segmentation. No inbound connections from the internet are accepted.
Strong passwords of at least 12 characters including special characters are required; multi-factor authentication (MFA) is enabled on key accounts, and passwords are rotated annually.
Access to Amazon Information is restricted to the minimum personnel whose duties require it. Access is revoked within 24 hours of separation or contract termination.
Passwords, API keys, and tokens are stored only in an encrypted password manager and environment variables — never in source code, shared documents, or public repositories.
Any security incident involving Amazon Information is reported to Amazon (security@amazon.com) within 24 hours of detection (see Section 4).
Covered events: leakage of Amazon Information, unauthorized access, exposure of credentials, actual or suspected misuse of Amazon Information, and security vulnerability notifications.
Immediately stop the affected system and revoke and reissue any potentially compromised credentials (API tokens, etc.).
Report any incident involving Amazon Information to security@amazon.com within 24 hours of detection.
Determine the scope of impact (data, period, path) from access and audit logs, and eliminate the root cause.
Resume operation only after the cause is confirmed removed. Promptly inform affected clients and stakeholders of the situation and remediation.
Document the timeline, cause, and corrective actions, and update this plan. The plan is reviewed every six months and after any major change.
| Event | Deadline |
|---|---|
| Reporting a security incident involving Amazon Information to Amazon (security@amazon.com) | Within 24 hours of detection |
| Revoking access of separated employees or terminated contractors | Within 24 hours |
| Remediating vulnerabilities rated critical | Within 7 days |
| Remediating vulnerabilities rated high | Within 30 days |
| Deleting buyer Personally Identifiable Information (PII), if obtained | Within 30 days after order delivery |
We regularly check security updates for our operating systems, runtimes, and dependencies, and remediate detected vulnerabilities within the deadlines above.
Data privacy concerns, security vulnerability notifications, and information about actual or suspected misuse of Amazon Information are received through the channel below and managed end-to-end through submission, tracking, response, and resolution.
This policy and the Incident Response Plan are reviewed and updated every six months (next review: December 2026), and after any major change to our systems or lessons learned from an incident.
Part I published August 21, 2026 · Part II established June 12, 2026, revised July 20, 2026 · This page published August 28, 2026 · FUJIEN Inc., 3-16-17 Kishi-shinmachi, Moji-ku, Kitakyushu, Fukuoka 800-0118, Japan