Website Information Security and Personal Data Protection PolicyWebsite Information Security and Personal Data Protection Policy

I. Scope of Information Security Management

The scope of this company's Information Security Management System is as follows:

"Maintenance of the company's information systems (including websites), data processing procedures, and maintenance and management of the data center."

This scope covers information systems, websites, information equipment, data center environment, and related data processing activities. Through the establishment of an Information Security Management System (ISMS), we ensure that information assets are properly protected and maintain the continuous operation of information services.

━━━━━━━━━━━━━━

II. Information Security Policy

This company values ​​information security and aims to provide secure, reliable, and trustworthy information services. We continuously promote our Information Security Management System to ensure the confidentiality, integrity, and availability of all information assets.

Our company's Information Security Management Policy is:

• Establish a cybersecurity culture

• Implement cybersecurity systems

• Strengthen cybersecurity protection

• Reduce operational risks

To achieve the above objectives, the company will continue to:

• Establish and continuously improve the Information Security Management System.

• Strengthen the security protection of information systems, websites, and information equipment.

• Conduct regular information security risk assessments and management.

• Enhance the information security awareness and provide training to all employees.

• Ensure the continuous operation of information services and reduce the impact of information security incidents on operations.

━━━━━━━━━━━━━━

III. Personal Data Protection Policy

Our company complies with the Personal Data Protection Act and related laws and regulations, and has established a comprehensive personal data protection management system to protect the security of personal data at all stages, including collection, processing, use, storage, transmission, and destruction.

To protect the personal data of our customers, partners, and related stakeholders, our company will:

• Collect, process, and use personal data in accordance with the law.

• Take appropriate technical and management measures to prevent unauthorized access, theft, alteration, damage, loss, or leakage.

• Regularly review and continuously improve personal data protection management measures.

• Respect and protect the rights of data subjects, and establish a trustworthy privacy protection environment.

━━━━━━━━━━━━━━

IV. Continuous Improvement

Our company will continue to improve its information security and personal data protection management systems through mechanisms such as risk management, education and training, internal audits, and management reviews, in order to provide customers and partners with safer, more reliable, and trustworthy information services.