Company Overview

Trade Name soma corp.
Location 2-1-19-10C Tanimachi, Chuo-ku, Osaka, 540-0012
Tel:+81-6-6809-4808
Founded May 2010
Representative Takahiro SHOJI, Representative Director
Capital Japanese Yen 8,000,000
Business Activities
  • Planning, design, and development of business systems and web-based systems
  • Modification, enhancement, and replacement of existing systems
  • System implementation, operation, maintenance, and continuous improvement support
  • Planning, development, operation, and maintenance of websites
  • Consulting and implementation support for system development and IT utilization

Information Security Policy

Established: May 19, 2010
Revised: May 19, 2018
Revised: May 19, 2026
soma corp.
Representative Director: Takahiro SHOJI
soma corp. (the “Company”) recognizes that the appropriate protection of information assets is a critical management responsibility, particularly in light of its business activities involving software development, computer systems, and website development and operation.

To ensure and continuously improve information security, the Company hereby establishes this Information Security Policy and implements the following measures.
  1. Management Responsibility
    The Company’s management takes responsibility for ensuring and improving information security and establishes an appropriate organizational and management framework for this purpose.
  2. Protection of Information Assets
    The Company appropriately manages customer information, personal information, technical information, business information, system information, and other information assets according to their importance and associated risks, and endeavors to maintain their confidentiality, integrity, and availability.
    The Company implements appropriate organizational, personnel, physical, and technical security measures to protect information assets against unauthorized access, information leakage, alteration, loss, destruction, system failure, and other information security threats.
  3. Compliance with Laws, Regulations, and Contractual Obligations
    The Company complies with all applicable laws, regulations, governmental guidelines, and other standards relating to information security and the protection of personal information. The Company also complies with information security obligations arising from contracts and agreements with customers and business partners.
  4. Information Security Risk Management
    The Company identifies threats and vulnerabilities affecting its information assets, assesses information security risks, and implements appropriate measures according to the nature and level of such risks.
    The Company periodically reviews information security risks and related measures in response to changes in its business, technology, and social environment.
  5. Education and Training
    The Company provides its officers and employees with appropriate education and training to ensure that they understand the importance of information security and handle information assets properly.
  6. Management of Contractors and External Services
    When outsourcing business operations or using cloud services or other external services, the Company evaluates the information security measures of contractors and service providers according to the importance of the information involved and the associated risks, and implements appropriate controls.
  7. Response to Information Security Incidents and Business Continuity
    If an information security incident, including information leakage, unauthorized access, cyberattacks, or system failure, occurs or is suspected, the Company promptly investigates the circumstances and takes necessary measures to contain the impact, identify the cause, restore operations, and prevent recurrence.
    The Company also maintains appropriate backups and other measures for important information in order to support business continuity and timely recovery.
  8. Continuous Improvement
    The Company periodically evaluates and reviews this Information Security Policy, related internal rules, management systems, and security measures, and continuously works to improve its information security management.

Privacy Policy

Established: May 19, 2010
Revised: May 19, 2018
Revised: May 19, 2026
soma corp.
Representative Director: Takahiro SHOJI
soma corp. (the “Company”) recognizes that the appropriate handling and protection of personal information obtained through its business activities is an important responsibility of the Company.

Accordingly, the Company establishes this Privacy Policy and implements the following measures to ensure the proper handling and protection of personal information.
  1. Compliance with Laws and Regulations
    The Company complies with the Act on the Protection of Personal Information of Japan (“APPI”), other applicable laws and regulations, governmental guidelines, and other applicable standards relating to the protection of personal information.
  2. Appropriate Collection of Personal Information
    The Company obtains personal information by lawful and fair means.
    When obtaining personal information, the Company specifies the purposes of use in advance and, except where otherwise permitted by applicable laws and regulations, notifies the individual concerned or publicly announces such purposes.
  3. Use Within the Specified Purposes
    The Company uses personal information only to the extent necessary to achieve the purposes of use specified in advance.
    If the Company changes a purpose of use, such change will be made only to the extent reasonably related to the original purpose.
  4. Appropriate Management of Provision to Third Parties
    Except as permitted by applicable laws and regulations, the Company does not provide personal data to any third party without obtaining the prior consent of the individual concerned.
    When providing personal data to a third party located outside Japan, the Company takes the measures required under the APPI and other applicable laws and regulations.
  5. Security Control of Personal Information
    The Company implements appropriate organizational, personnel, physical, and technical security control measures to prevent leakage, loss, damage, unauthorized access, and other risks relating to personal data.
    The Company also provides necessary and appropriate education and supervision to officers and employees who handle personal data.
  6. Appropriate Supervision of Contractors
    When outsourcing all or part of the handling of personal data, the Company selects contractors capable of appropriately handling personal data, establishes necessary requirements through contracts or other arrangements, and exercises necessary and appropriate supervision over their handling of personal data.
  7. Requests and Inquiries Concerning Personal Information
    When an individual or an authorized representative makes a request concerning the individual’s Retained Personal Data as provided under applicable laws and regulations, the Company verifies the identity of the requesting person and responds appropriately in accordance with applicable laws and regulations.
    The Company also endeavors to respond appropriately and promptly to inquiries and complaints regarding its handling of personal information.
  8. Continuous Improvement
    The Company establishes internal rules and management systems for the appropriate handling of personal information and periodically reviews their operation. The Company continuously improves its personal information protection practices in response to changes in applicable laws and regulations, technology, its business environment, and social conditions.

Handling of Personal Information

soma corp. (the “Company”) provides the following information regarding its handling of personal information.
  1. Personal Information Handling Business Operator
    soma corp.
    2-1-19-10C Tanimachi, Chuo-ku, Osaka 540-0012, Japan
    Representative Director: Takahiro SHOJI
  2. Purposes of Use of Personal Information

    (1) Personal Information Relating to Customers and Persons Making Inquiries

    • To respond to inquiries, consultations, and other communications
    • To provide information and proposals concerning the Company’s products, services, and business activities
    • To enter into, perform, and manage contracts
    • To provide, operate, maintain, and support products and services
    • To process billing, payments, and other procedures necessary for business transactions
    • To improve the Company’s products and services and to plan and develop new products and services

    (2) Personal Information Relating to Officers and Employees of Business Partners

    • To conduct business communications, negotiations, meetings, and other business activities
    • To enter into, perform, and manage contracts
    • To process billing, payments, and other procedures necessary for business transactions
    • To maintain and manage business relationships

    (3) Personal Information Handled in the Course of Contracted Services

    When the Company handles personal information in connection with software development, design, development, operation or maintenance of computer systems, website development or operation, or other services entrusted to the Company by a customer, the Company uses such personal information only to the extent necessary to perform the relevant services and in accordance with the applicable contract and instructions of the customer.

    (4) Personal Information Relating to Job Applicants

    • To receive and process applications for employment
    • To conduct recruitment and selection procedures
    • To communicate regarding interviews and other recruitment procedures
    • To complete employment procedures following a hiring decision
    • To analyze and improve recruitment activities

    (5) Personal Information Relating to Officers, Employees, Former Employees, and Related Persons

    • To administer personnel, labor, payroll, employee benefits, occupational health and safety, and other employment-related matters
    • To complete procedures relating to social insurance, taxation, and other legal requirements
    • To conduct communications and management necessary for business operations
    • To communicate following termination of employment and maintain records as required by applicable laws and regulations
  3. Provision of Personal Data to Third Parties
    The Company does not provide personal data to third parties without the prior consent of the individual concerned, except where permitted under the APPI or other applicable laws and regulations.
  4. Outsourcing the Handling of Personal Data
    The Company may outsource all or part of the handling of personal data to external service providers to the extent necessary to achieve the purposes of use.
    In such cases, the Company selects contractors capable of appropriately handling personal data and exercises necessary and appropriate supervision.
  5. Security Control Measures for Personal Data
    The Company implements appropriate organizational, personnel, physical, and technical security control measures, as well as appropriate management of contractors and external services, in order to prevent leakage, loss, or damage of personal data.
  6. Response to Personal Data Breaches and Other Incidents
    If the Company becomes aware of an actual or suspected leakage, loss, damage, or other incident involving personal data, it promptly investigates the facts and causes and takes necessary measures to contain the impact and prevent recurrence.
    Where reporting or notification is required under applicable laws and regulations, the Company takes the necessary actions accordingly.
  7. Requests for Disclosure and Other Actions Concerning Retained Personal Data
    Upon receiving a request from an individual or the individual’s authorized representative concerning Retained Personal Data held by the Company, including notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties, the Company responds in accordance with applicable laws and regulations after verifying the identity of the requesting person.
  8. Contact for Inquiries and Complaints Regarding Personal Information
    soma corp. Personal Information Inquiry Desk
    2-1-19-10C Tanimachi, Chuo-ku, Osaka 540-0012, Japan
    Contact us
  9. Changes to This Notice
    The Company may revise this “Handling of Personal Information” notice as necessary in response to amendments to applicable laws and regulations, changes in its business activities, or other circumstances.
    If the Company makes any material changes, it will provide notice through its website or by other appropriate means.