

Basic Policy on Information Security
HITOHATA, INC. ("we", "us" or "our") is entrusted by many clients, including local governments, cultural facilities, commercial facilities and business corporations, with important information assets such as unreleased project information, production data including video and audio materials, facility operation information and information relating to visitors, through the planning, direction, production and operation of projection mapping, immersive art museums, immersive shows and similar experiences. We recognise that protecting these information assets appropriately is the foundation of our business operations, and we establish this Basic Policy on Information Security (this "Policy") as set out below, which our directors and all employees shall observe.
Article 1 (Purpose)
The purpose of this Policy is to protect the information assets we handle from the threats of leakage, alteration, loss, damage and unauthorised access, and to maintain their confidentiality, integrity and availability.
Article 2 (Scope)
This Policy applies to our directors, employees, contract employees, temporary staff, part-time staff and all other persons engaged in our business (collectively, "Employees"). The information assets covered by this Policy are all information and information systems that we obtain, hold or use in our business activities, including the following.
(1) Project information, design and construction information, production data such as video, audio and 3D data, and the materials thereof, entrusted to us by clients, business partners and collaborators
(2) Original recordings and master data of the works we produce, and intermediate data generated during production
(3) Personal information of visitors, applicants, personnel of business partners and others (details of its handling are set out in our Privacy Policy)
(4) Control systems for exhibition and screening equipment, operation management systems, business systems and networks
(5) Contracts, quotations, cost information and other management information
Article 3 (Information Security Management Structure)
We appoint our Representative Director as the chief officer responsible for information security, clarify where responsibility lies, establish the structure necessary to maintain and improve information security, and allocate the necessary management resources.
Article 4 (Compliance with Laws and Regulations and with Contracts with Clients)
We comply with the Act on the Protection of Personal Information, the Unfair Competition Prevention Act, the Copyright Act and other related laws and regulations and government guidelines, as well as with the security requirements set out in non-disclosure agreements, outsourcing agreements and other contracts concluded with our clients, business partners and collaborators.
Article 5 (Management of Information Assets)
We classify information assets according to their importance and establish the methods for handling, storing, taking out, copying, providing and disposing of them. In particular, for unreleased project information and unreleased production data, we limit the persons who may access them on a project-by-project basis.
Article 6 (Safety Management Measures)
In accordance with the importance of the information assets, we take the following safety management measures.
(1) Organisational safety management measures: appointment of responsible officers, establishment of handling rules, recording of the handling status and periodic inspections
(2) Human safety management measures: confidentiality arrangements with Employees, and periodic education and awareness-raising
(3) Physical safety management measures: entry and exit control for our offices and on-site work areas, locked storage of equipment and recording media, and control over taking them out
(4) Technical safety management measures: management of access privileges, appropriate operation of authentication information, encryption of communications and stored data, countermeasures against unauthorised access and malware, collection and monitoring of logs, and creation of backups
Article 7 (Management of Subcontractors)
Where we outsource part of our operations, we select the subcontractor after confirming its level of information security in advance, clarify matters concerning confidentiality and safety management by contract, and check the status of the outsourced operations as necessary. Where production data is shared, we determine the scope of sharing and the retention period, and require its return or deletion after the work has been completed.
Article 8 (Education of Employees)
We provide our Employees with education on the content of this Policy and the related internal rules, the importance of the information they handle, and the reporting procedures in the event of an incident, both upon hiring and on a regular basis. We also inform short-term staff working at event venues of the necessary matters before they begin work.
Article 9 (Response to Information Security Incidents)
If we become aware of an information security incident or the possibility of one, we will immediately take measures to prevent the damage from spreading and to restore operations, and will report to the affected clients and other relevant parties as well as to the relevant authorities as required by law. We will also investigate the cause of the incident and take measures to prevent any recurrence.
Article 10 (Business Continuity)
Even in the event of a disaster, a large-scale system failure or a similar situation, we give priority to the safe operation of the events then in progress and to the preservation of important information assets, and we maintain data backups and an emergency contact structure so that we can continue our business to the extent necessary or restore it at an early stage.
Article 11 (Continual Improvement)
We periodically review the operation of this Policy and the related internal rules, and continually improve our information security management structure in light of amendments to laws and regulations, changes in our business and changes in technology and threats.
Article 12 (Amendment of this Policy)
We may amend this Policy as necessary. The amended Policy takes effect when it is posted on this website.
Article 13 (Contact Point)
Please direct any inquiries regarding this Policy to the contact point below.
HITOHATA, INC.
Nagono Campus 3F 3-2, 2-14-1 Nagono, Nishi-ku, Nagoya, Aichi 451-0042, Japan
Email: info@hitohata.jp
Inquiry form: https://www.hitohata.jp/contact
Established August 29, 2026
BACK TO TOP PAGE
Get in Touch
For project and service requests and inquiries, requests for interviews and speaking engagements, employment and other inquiries to HITOHATA,INC.