PRIVACY POLICY

プライバシーポリシーPrivacy Policy — FUJIEN Inc.

個人情報の取り扱い 2026年8月21日 掲載セキュリティ・データ保護方針 2026年6月12日 制定/2026年7月20日 改訂本ページ公開 2026年8月28日次回見直し 2026年12月
PART I

個人情報の取り扱いについて

株式会社FUJIEN(以下「当社」)は、当社ウェブページ(AI導入支援ページおよび本ページ)を通じてお預かりする個人情報を、個人情報の保護に関する法律その他の法令を遵守し、次のとおり取り扱います。

事業者
株式会社FUJIEN(〒800-0118 福岡県北九州市門司区吉志新町三丁目16番17号/代表取締役 藤田健太)
取得する情報
お問い合わせフォームにご入力いただく会社名・お名前・メールアドレス・電話番号(任意)・ご相談内容など
利用目的
お問い合わせへの回答、ご相談日程の調整、当社サービスのご案内。目的の範囲を超えて利用しません
第三者提供
法令に基づく場合を除き、ご本人の同意なく第三者に提供しません
利用するサービス
フォームの受付にはGoogle LLCの「Googleフォーム」を利用しており、入力内容はGoogleのサーバーに保存されます。また当社ウェブページの表示にGoogle Fonts(文字の書体)を読み込んでおり、その際にお使いの端末からGoogleへ通信が発生します(いずれもGoogleのプライバシーポリシーが適用されます)
アクセス解析
当社ウェブページでは、Cookieを用いたアクセス解析は行っていません
安全管理措置
お預かりした個人情報は、第II部「セキュリティ・データ保護方針」に定める安全管理措置のもとで取り扱います
開示・訂正・削除
ご本人からの請求には速やかに対応します。窓口:info@fujien-inc.co.jp
改定
本ポリシーは必要に応じて改定し、改定後の内容は本ページに掲載した時点から適用します
PART II

セキュリティ・データ保護方針

当社は、Amazon Ads API および Amazon Selling Partner API(SP-API)をはじめとする外部APIを通じて取得する事業データ(以下「Amazon情報」)を、Amazon Ads データ保護ポリシー、Amazon Ads パートナーネットワークポリシー、および Amazon データ保護ポリシー(DPP)に従って取り扱います。この第II部は、当社の安全管理措置・インシデント対応計画・通報窓口を公開するものです。

1. 適用範囲 SCOPE

本方針は、当社が自社の事業および契約先(Amazon販売事業者)への支援業務のためにAPIを通じて取得・保管・処理するすべてのAmazon情報、および第I部でお預かりする個人情報に適用します。

2. 体制 ORGANIZATION

  • セキュリティ責任者:代表取締役(インシデントの最終判断・対外報告・本方針の承認)
  • 技術運用:代表取締役の管理のもとで検知・調査・復旧を実施
  • 本方針およびインシデント対応計画は、経営責任者(代表取締役)が承認し、6か月ごとに見直します

3. 安全管理措置 SECURITY CONTROLS

1

通信の暗号化

Amazon情報へのアクセスと送受信はすべて暗号化された通信(TLS/HTTPS)のみで行います。

2

ネットワーク制御

作業端末はファイアウォールとマルウェア対策を有効化し、NATによるネットワーク分離のもとで運用します。外部からの直接着信は受け付けません。

3

パスワード要件

12文字以上・特殊文字を含む強固なパスワードを必須とし、主要アカウントは多要素認証(MFA)を有効化、年1回更新します。

4

職務に基づくアクセス制限

Amazon情報へのアクセスは業務上必要な最小限の担当者に限定します。退職・契約終了時は24時間以内にアクセス権を失効させます。

5

認証情報の安全な保管

パスワード・APIキー・トークンは暗号化されたパスワード管理ツールと環境変数でのみ管理し、ソースコード・共有文書・公開リポジトリには置きません。

6

セキュリティインシデントの報告

Amazon情報に関わるインシデントを検知した場合、24時間以内にAmazon(security@amazon.com)へ報告します(詳細は「4. インシデント対応計画」)。

4. インシデント対応計画 INCIDENT RESPONSE PLAN

対象事象:Amazon情報の漏えい、不正アクセス、認証情報の流出、Amazon情報の悪用(その疑いを含む)、およびセキュリティ脆弱性の通知。

1

検知・初動

直ちに該当システムを停止し、疑いのある認証情報(APIトークン等)を即時無効化・再発行します。

2

Amazonへの報告

Amazon情報に関わるインシデントは、検知から24時間以内security@amazon.com へ報告します。

3

調査・封じ込め

アクセスログ・監査ログから影響範囲(対象データ・期間・経路)を特定し、原因を除去します。

4

復旧・通知

原因除去を確認したうえで再開します。影響を受ける契約先・関係者には速やかに状況と対策を通知します。

5

記録・再発防止

経緯・原因・対策を記録し、本計画へ反映します。計画は6か月ごと、および重大な変更の後に見直します。

5. 対応期限 RESPONSE DEADLINES

事象期限
Amazon情報に関わるセキュリティインシデントのAmazon(security@amazon.com)への報告検知後24時間以内
退職者・契約終了者のアクセス権の無効化24時間以内
クリティカルと判定した脆弱性の解消7日以内
高リスクと判定した脆弱性の解消30日以内
購入者の個人識別情報(PII)の削除(取得する場合)注文配送後30日以内

脆弱性は、使用するOS・実行環境・依存パッケージのセキュリティ更新を定期的に確認し、検出されたものを上記期限内に解消します。

6. データの取扱い DATA HANDLING

7. セキュリティに関する通報窓口 REPORTING CHANNEL

データプライバシーに関する懸念、セキュリティ脆弱性の通知、Amazon情報の悪用(その疑いを含む)に関する情報は、次の窓口で受け付け、提出・追跡・対応・解決まで一貫して管理します。

連絡先
info@fujien-inc.co.jp(件名の先頭に「[Security]」とご記入ください)
受付の流れ
受付(2営業日以内に受領のご連絡)→ 記録・追跡 → 調査・対応 → 結果のご連絡
Amazonへの報告
Amazon情報に関わる事象は、当社から検知後24時間以内に security@amazon.com へ報告します

8. 見直し REVIEW

本方針とインシデント対応計画は、6か月ごと(次回:2026年12月)、およびシステム構成の重大な変更やインシデントからの教訓が得られた後に見直し、更新します。

ENGLISH VERSION

Privacy Policy (English)

This is the English version of the Privacy Policy of FUJIEN Inc. (株式会社FUJIEN, "we" or "the Company"). Part I covers the handling of personal information collected through our web pages, which we handle in compliance with the Act on the Protection of Personal Information and other applicable laws. Part II sets out our Security & Data Protection Policy for business data obtained through external APIs, including the Amazon Ads API and the Amazon Selling Partner API (SP-API) (collectively, "Amazon Information"), which we handle in accordance with the Amazon Ads Data Protection Policy, the Amazon Ads Partner Network Policies, and the Amazon Data Protection Policy (DPP).

Part I — Handling of Personal Information

Data controller
FUJIEN Inc. (3-16-17 Kishi-shinmachi, Moji-ku, Kitakyushu, Fukuoka 800-0118, Japan / Representative Director: Kenta Fujita)
Information collected
Company name, name, e-mail address, telephone number (optional), and the content of your inquiry entered in our contact form, and other information you enter
Purpose of use
Responding to inquiries, scheduling consultations, and providing information about our services. We do not use it beyond these purposes
Third-party disclosure
We do not provide personal information to third parties without your consent, except as required by law
Services used
Inquiries are received via Google Forms (Google LLC) and stored on Google's servers. Our web pages load Google Fonts, which causes your device to communicate with Google (Google's privacy policy applies to both)
Analytics
Our web pages do not use cookie-based access analytics
Security
Personal information is protected under the security controls set out in Part II
Access, correction, deletion
We respond promptly to requests from the individual concerned. Contact: info@fujien-inc.co.jp
Amendments
We may amend this policy as necessary. The amended policy takes effect when it is posted on this page

Part II — Security & Data Protection Policy

1. Scope

This policy applies to all Amazon Information that we obtain, store, or process through APIs, whether for our own business or in support of our clients (Amazon selling partners), and to the personal information described in Part I.

2. Organization

  • Security Officer: Representative Director (final decision on incidents, external reporting, and approval of this policy)
  • Technical operations: detection, investigation, and recovery carried out under the supervision of the Representative Director
  • This policy and the Incident Response Plan are approved by senior management (the Representative Director) and reviewed every six months

3. Security Controls

1

Encryption in transit

All access to and transmission of Amazon Information takes place exclusively over encrypted connections (TLS/HTTPS).

2

Network controls

Work devices run with firewalls and anti-malware protection enabled and operate behind NAT-based network segmentation. No inbound connections from the internet are accepted.

3

Password requirements

Strong passwords of at least 12 characters including special characters are required; multi-factor authentication (MFA) is enabled on key accounts, and passwords are rotated annually.

4

Role-based access

Access to Amazon Information is restricted to the minimum personnel whose duties require it. Access is revoked within 24 hours of separation or contract termination.

5

Secured credential storage

Passwords, API keys, and tokens are stored only in an encrypted password manager and environment variables — never in source code, shared documents, or public repositories.

6

Security incident reporting

Any security incident involving Amazon Information is reported to Amazon (security@amazon.com) within 24 hours of detection (see Section 4).

4. Incident Response Plan

Covered events: leakage of Amazon Information, unauthorized access, exposure of credentials, actual or suspected misuse of Amazon Information, and security vulnerability notifications.

1

Detect & respond

Immediately stop the affected system and revoke and reissue any potentially compromised credentials (API tokens, etc.).

2

Notify Amazon

Report any incident involving Amazon Information to security@amazon.com within 24 hours of detection.

3

Investigate & contain

Determine the scope of impact (data, period, path) from access and audit logs, and eliminate the root cause.

4

Recover & inform

Resume operation only after the cause is confirmed removed. Promptly inform affected clients and stakeholders of the situation and remediation.

5

Record & improve

Document the timeline, cause, and corrective actions, and update this plan. The plan is reviewed every six months and after any major change.

5. Response Deadlines

EventDeadline
Reporting a security incident involving Amazon Information to Amazon (security@amazon.com)Within 24 hours of detection
Revoking access of separated employees or terminated contractorsWithin 24 hours
Remediating vulnerabilities rated criticalWithin 7 days
Remediating vulnerabilities rated highWithin 30 days
Deleting buyer Personally Identifiable Information (PII), if obtainedWithin 30 days after order delivery

We regularly check security updates for our operating systems, runtimes, and dependencies, and remediate detected vulnerabilities within the deadlines above.

6. Data Handling

7. Security Reporting Channel

Data privacy concerns, security vulnerability notifications, and information about actual or suspected misuse of Amazon Information are received through the channel below and managed end-to-end through submission, tracking, response, and resolution.

Contact
info@fujien-inc.co.jp (please begin the subject line with "[Security]")
Process
Receipt (acknowledged within 2 business days) → logging and tracking → investigation and response → notification of outcome
Reporting to Amazon
We report any event involving Amazon Information to security@amazon.com within 24 hours of detection

8. Review

This policy and the Incident Response Plan are reviewed and updated every six months (next review: December 2026), and after any major change to our systems or lessons learned from an incident.

Part I published August 21, 2026 · Part II established June 12, 2026, revised July 20, 2026 · This page published August 28, 2026 · FUJIEN Inc., 3-16-17 Kishi-shinmachi, Moji-ku, Kitakyushu, Fukuoka 800-0118, Japan