Handling of Personal Information
We, TISI Inc. (hereinafter referred to as “TISI”), established the privacy policy and information security policy and have been conducting activities to protect personal information. In accordance with these policies, we utilize frameworks such as PrivacyMark, compliant with JIS Q 15001, and the Information Security Management System, compliant with ISO/IEC 27001, under a management structure tailored to the characteristics of our organization, and are committed to continuous improvement. On this page, we clarify what we are doing to protect personal information with a promise to continue improving our activities. We hope that you will be aware of what efforts are made by TISI and will render further support and advice to TISI.
Fumikazu Tatsumi, Senior Managing Executive Officer, Personal Information Protection Manager
Ⅰ.Personal Information, etc. Handled by TISI
TISI will receive the following personal information and anonymously processed information (hereinafter referred to as “personal information, etc.”) from customers, suppliers, and business partners (hereinafter referred to as the “Clients”) and from shareholders.
- Personal information pertaining to the Clients themselves
- Personal information about shareholders
- Personal information received when business is entrusted
- Anonymously processed information received when business is entrusted
To ensure the proper handling of anonymously processed information, TISI will implement similar measures as those described below for personal information in Safety Control Measures for Personal Information, etc. (VIII).
The personal information of TISI and TIS INTEC Group companies (hereinafter referred to as “group companies”) handled by TISI is as follows:
- Personal information about TISI directors, employees, and their families
- Personal information about group company directors and employees
Anonymously processed information handled by TISI in its own services
- Currently, TISI does not create any anonymously processed information nor does it provide such information to third parties.
Ⅱ.Purpose of Use of Personal Information, etc.
TISI will handle personal information, etc. of the Clients and shareholders within the bounds of the purposes outlined in (Ⅲ-Ⅶ).
When the purpose of use is to be changed, the purpose must be related to that prior to the change and the change must be within reasonable limits.
Ⅲ.Handling of Personal Information pertaining to the Clients
1. Purpose of Use
- Performance of billing, payment, and other business processes, conduct of contractual relations,
and communication for business purposes with Clients - Response to inquiries and requests from the Clients
- Guide for products and services of TISI
- Invitation to seminars, product presentations, and exhibitions held or sponsored by TISI or group companies
- Distribution of questionnaires for customer satisfaction survey
- Sending of New Year's greeting cards, notice of office move, and notice of personnel change
- The following purposes to help TISI provide information on products, services, and events of TISI or group companies that align with the interests and preferences of the Clients, as well as develop and improve the quality of such products and services:
- Analyzing and studying findings from customer satisfaction survey questionnaires
- Surveying, analyzing, and studying Client information collected through sales activities; the Clients' inquiry, event registration, and other action history data; and the Clients' browsing history - Other purposes notified to, and agreed by, the Clients in advance
2. Provision to Third Parties
TISI shall not disclose or provide to third parties personal information about the Clients except in the following cases:
- If the Clients concerned have consented
- If disclosure or provision is required by law
- If disclosure or provision is made in a form in which individual Clients cannot be identified, such as in the form of statistical data
A record will be created if information is provided to a third party.
3.Entrustment of Personal Information
TISI may entrust personal information about Clients that TISI has received with an outside party to fulfill the purpose of use.
In such case, TISI shall enter an agreement on protection of personal information with the entrustees, in case of handling personal information in a foreign country, understand its laws and regulations, etc., and exercise proper control and supervision in accordance with the laws and regulations and TISI standards, and recover the personal information about Clients from the entrustees after termination of the entrustment.
4. Sharing of Personal Information in the TIS INTEC Group
TISI may share personal information with group companies if it judges it appropriate to do so in order to have group companies respond to inquiries, etc. from Clients or to provide information on, deliver, or enhance products and services handled by group companies.
For details, please see Sharing of Personal Information in the TIS INTEC Group .
Ⅳ.Handling of Personal Information about Shareholders
1.Purpose of Use
- Exercise of rights and performance of obligations under the Companies Act
- Provision of convenience by TISI in accordance with status as shareholders
- Consideration and implementation of measures to facilitate relations between shareholders and TISI
- Shareholder management, such as the preparation of shareholder data in accordance with prescribed standards as required by law
2.Provision to Third Parties
TISI shall not disclose or provide to third parties personal information about shareholders except in the following cases:
- If the shareholder concerned has consented
- If disclosure or provision is required by law
- If disclosure or provision is made in a form in which individual shareholders cannot be identified, such as in the form of statistical data
3.Entrustment of Personal Information
TISI may entrust personal information about shareholders received with an outside party to fulfill the purposeof use.
In such case, TISI shall enter an agreement on protection of personal information with the entrustees, in case of handling personal information in a foreign country, understand its laws and regulations, etc., and take proper and thorough safety control measures in accordance with the laws and regulations and TISI standards, exercise proper supervision, and recover the personal information about shareholders from the entrustees after termination of the entrustment.
4.Sharing of Personal Information in the TIS INTEC Group
TISI shall not share personal information about shareholders with group companies.
Ⅴ.Handling of Personal Information, etc. Received When Business Is Entrusted
1.Purpose of Use
TISI shall handle personal information, etc. received from customers to the extent necessary for the purpose of fulfillment of entrusted business, such as data processing.
2.Provision to Third Parties
TISI shall not provide personal information, etc. received from customers to third parties.
3.Entrustment of Personal Information, etc.
TISI may entrust the handling of personal information, etc. received to a third party in order to fulfill entrusted business.
In such case, TISI shall enter an agreement on protection of personal information with the entrustees, in case of handling personal information in a foreign country, understand its laws and regulations, etc., and exercise proper control in accordance with the laws and regulations and TISI standards After termination of the entrustment, TISI shall recover from the entrustees the personal information, etc. received.
4.Sharing of Personal Information, etc. in the TIS INTEC Group
TISI shall not share personal information, etc. received.
Ⅵ.Handling of Personal Information about TISI Directors, Employees, and Their Families
TISI shall handle personal information about TISI directors and employees (permanent employees, senior employees, contract employees, temporary employees, seconded employees and dispatched employees), applicants for positions at TISI, and former employees of TISI (hereinafter referred to collectively as “Employees, etc.”) as follows.
1.Purpose of Use
- Activities related to employment screening (for job applicants) and procedures for entering the company once offered a position
- Employment management, work management, salary administration
- Preparation and filing of notifications, reports, and other materials as required by law
- Employee welfare and management of health and safety
- Education and training
- Communication in emergencies
2.Provision to Third Parties
TISI shall not provide to third parties personal information about Employees, etc. except in the following cases:
- If the Employees, etc. concerned have consented
- If disclosure or provision is required by law
- If disclosure or provision is made in a form in which individual Employees, etc. cannot be identified, such as in the form of statistical data
A record will be created if information is provided to a third party.
In such case, TISI shall enter a non-disclosure agreement on the handling of personal information with the third party.
3.Entrustment of Personal Information
TISI may entrust with a third party personal information about Employees, etc. if necessary to fulfill the purpose of use.
In such cases, TISI shall enter an agreement on protection of personal information with the entrustee, take proper and thorough safety control measures in accordance with the laws and regulations and TISI standards, execute proper supervision, and recover the personal information about Employees, etc. from the entrustee after termination of the entrustment.
4.Handling of Personal Information in Foreign Countries
TISI may provide with a third party entrustee in foreign countries personal information about Employees, etc. if necessary to fulfill business as follows.
In such cases, TISI shall not provide personal information to a third party in a foreign country unless the Employees, etc. concerned have consented.
5.Sharing of Personal Information in the TIS INTEC Group
TISI may share personal information about Employees, etc. with group companies if necessary to fulfill the purpose of use.
For details, please see Sharing of Personal Information in the TIS INTEC Group .
In such case, TISI shall enter a non-disclosure agreement on the handling of personal information with the parties with which personal information is shared.
Ⅶ.Handling of Personal Information regarding Group Company Directors and Employees
1.Purpose of Use
- Activities necessary to the group’s management, including personnel management and education/training
- Communications necessary to the group’s management and administration
2.Provision to Third Parties
TISI shall not provide to third parties personal information about group company directors and employees except in the following cases:
- If the group company directors and employees concerned have consented
- If disclosure or provision is required by law
- If disclosure or provision is made in a form in which individual group company directors and employees cannot be identified, such as in the form of statistical data
A record will be created if information is provided to a third party.
3.Entrustment of Personal Information
TISI may entrust with a third party personal information about group company directors and employees if necessary to fulfill the purpose of use.
In such cases, TISI shall enter an agreement on protection of personal information with the entrustee, take proper and thorough safety control measures in accordance with the laws and regulations and TISI standards, in case of handling personal information in a foreign country, understand its laws and regulations, etc., and exercise proper supervision, and recover the personal information about group company directors and employees from the entrustee after termination of the entrustment.
4.Sharing of Personal Information in the TIS INTEC Group
TISI may share personal information about group company directors and employees with group companies if necessary to fulfill the purpose of use.
For details, please see Sharing of Personal Information in the TIS INTEC Group.
In such case, TISI shall enter an agreement on the sharing of personal information with the parties with which personal information is shared.
Ⅷ.Safety Control Measures for Personal Information, etc.
TISI shall manage all information, including personal information, etc., in accordance with the requirements for the Privacy Mark and information security management systems.
Measures taken by TISI for safety control purposes may include those taken for preventing leakages and other incidents of personal information acquired or to be acquired by TISI that is expected to be handled as personal data held by TISI.
1.Organizational Safety Control Measures
- Development of organizational system
Appointment of the chief manager and operation of the security meeting - Establishment of rules and operation in accordance with the rules
Development and operation of the security policy (i.e., provisions and bylaws) based on the information security policy - Keeping in order records for handling of personal information
Administration of records for businesses for which personal information is entrusted and businesses for which personal information is acquired - Evaluation, review, and improvement of safety control measures
Improvement by voluntary inspection by those who handle information, internal audit, and management review - Response to trouble and violation regarding information security
Establishment of a task force and legal measures against violating party
2.Human Safety Control Measures
- Agreement with employees or entrustees about handling of personal information.
Collecting written oath from employees or entering into contract with entrustees.
- Education and training of employees
Education to all employees by e-learning
3.Physical Safety Control Measures
- Entry and exit control
Control of entry and exit by setting security levels and using IC card - Countermeasures against theft
Locked safekeeping of confidential documents and media, wire lock for portable PCs, and implementation of clear policy - Physical protection of machines and equipment
Implementation of measures against power failure and for disaster prevention and establishment of terminal room exclusive to real business requiring access to confidential information
4.Technical Safety Control Measures
- Identification and authentication of access
Personal authentication by IC card and/or fingerprint - Access control
Minimization and control of access - Control of access authority
Controlled setting of scope and authority of access according to type of job - Access record
Acquisition and storage of work records and access log - Measures against malicious software on information system
Automatic application of the virus definition (DAT) and security patch - Measures for transfer and telecommunication
Use of VPN and secure mail in encoding, electronic transmission, and telecommunication of transport media - Measures when checking the information system operation
Prohibition of use of operation data or, if necessary, restricted use by authorized person in monitored area - Monitoring of information system
Monitoring of access log and verification with work record
5.Supervision of Employees and Entrustees
- Video monitoring in monitored areas and restriction of access to the Internet
- Appointment and periodical education of chief manager of the entrustees and audit of delegated entrusted services
IX.About Cookies
This website uses the cookies.
For details, please refer to TISI Cookie Policy.
X.Disclosure, Correction, and Utilization Cease, etc. of Personal Information
TISI shall make a disclosure without delay in respect of personal information about Clients (excluding personal information received when business is entrusted) received by TISI and personal information about Employees, etc. and group company directors and employees held by TISI upon request by the individual concerned except in the following cases. When a disclosure is not made or there is no applicable personal data, TISI will give a reply to that effect.
- If it would harm the individual concerned or third party's life, body, fortune or other rights and interests
- If it would significantly impede the proper conduct of business
- If it would violate other laws or regulations
TISI shall conduct an investigation and correct, add, delete, cease utilization, eliminate or cease provision to third-parties in respect of the personal data held by TISI in accordance with the laws and regulations upon request by the individual concerned. Please address requests to the point of contact for inquiries shown below.
As a charge for the procedures for disclosure or other actions, TISI may charge the actual expenses incurred (up to 1,000 yen).
XI.About Personal Information Handling Business Operator
TISI Inc.
17-1, Nishishinjuku 8-chome, Shinjuku-ku, Tokyo, 160-0023, Japan
Yasushi Okamoto, President
Contact for Handling of Personal Information
Information Security Promotioin Dept, Corporate Management SBU., TISI Inc.
About Accredited Personal Information Protection Organization
Name of the accredited personal information protection organization and contact for complaints
Name of the accredited personal information protection organization
JIPDEC
Contact for complaints
Accredited Personal Information Protection Organization Office
Address: Roppongi First Building, 9-9, Roppongi 1-chome, Minato-ku, Tokyo 106-0032, Japan
Tel: +81-3-5860-7565; Toll-free number: 0120-700-779
*We only accept complaints regarding the handling of personal information.
*The telephone number and toll-free number stated above are not for inquiries about our products or services.