Information Security Basic Policy

HARO Inc. (hereinafter, the “Company”) believes that earning the trust of our customers is of the utmost importance in realizing our corporate philosophy. Accordingly, we hereby establish this “Information Security Basic Policy,” ensure that the following items are always kept in mind and thoroughly communicated to all employees, including management, and strive to properly protect our information assets in accordance with this Policy.

1. Initiatives

  1. We strengthen relationships of trust with our customers by protecting customer information.
  2. We fulfill our social responsibility as a company by adhering to our corporate philosophy and complying with all relevant laws and regulations.
  3. We implement robust security measures for the information assets entrusted to us by our customers in the course of our business, and continuously work to prevent, in advance, risks such as loss, destruction, tampering, and leakage.
  4. We regularly provide employees with education and training on information security so that they can acquire the necessary skills and ensure a solid commitment to information security.
  5. In the event of any incident or violation related to information security, we will respond appropriately and promptly, and strive to prevent recurrence.
  6. We set, implement, and maintain objectives related to information security.
  7. We comply with all applicable requirements related to information security.
  8. We continuously collect the latest information on threats, technologies, and other matters related to information security, and strive to enhance our security measures by responding to new risks in a timely manner.

2. Responsibilities, Obligations, and Disciplinary Action

In accordance with the procedures established to maintain this Basic Policy, all employees have a responsibility to report any incidents and vulnerabilities related to information security. Any person who engages in conduct that jeopardizes the protection of any information assets handled by the Company will be subject to disciplinary action in accordance with our work rules and applicable laws and regulations.

3. Regular Review

Our information security management system will be regularly checked and reviewed for compliance, and we will strive for continuous improvement in line with changes in society and our internal environment.

Established in 2021   Revised on November 10, 2024
HARO Inc.