Sustainability

Information Security and Customer Privacy

Information Security Management

MetaAge is committed to protecting the confidentiality, integrity, availability, and compliance of its information assets, including hardware, software, data, documentation, and personnel involved in information processing. To mitigate risks arising from internal or external intentional or accidental threats—including human error, malicious activities, and natural disasters—MetaAge has established an Information and Communication Security Policy and obtained ISO 27001 Information Security Management System certification.

Our information security management covers both internal operations and external business activities. MetaAge conducts regular audits and assessments to monitor the effectiveness of its information security controls and continuously reviews and improves relevant policies and practices. MetaAge also maintains established security incident and contingency management procedures to ensure that employees are prepared to recognize and respond appropriately to information security incidents and emergencies.

Policy Objectives
  • Steady operations: Ensure business continuity of the Company and steady use of the IT services provided.
  • Asset security: Ensure the confidentiality, integrity, and availability of information assets in our custody and protect the privacy of personnel data.
  • Compliance: Establish the business continuity plan and implement IT operations in compliance with related laws and regulations.
Control Measures
esg_control_measures_en
Management Structure

MetaAge has established an Information Security Promotion Committee, comprising the Chief Information Security Officer (CISO) and heads of relevant business functions. The CISO serves as the Committee Chair, while department heads serve as Committee members.

The Committee meets regularly to oversee the development and implementation of information security policies, risk management, and security audits, ensuring a coordinated approach to information security across the organization.

The Information Security Management Review Meeting was held on February 10, 2025, to review the Company's information security management and related measures.

information_security-pic5-en

Customer Privacy Protection

We deeply understand the importance of privacy and are thus committed to ensuring, respecting, and protecting customer privacy and trade secrets. Except for definite authorization or legal requests, we will not disclose or use the privacy or trade secrets off customers for any purpose. We have established the “Information and Communication Security Inspection Management Regulations”, built a secure and trusted IT environment, and equipped the IT environment with various information and communication security equipment such as firewalls and antivirus systems to ensure the security of corporate IT data, systems, equipment, and networks and thereby protect customer privacy data.

To ensure a secure and trustworthy IT environment, MetaAge has established the “Information and Communications Security Inspection Management Measures” and implemented safeguards such as firewalls and antivirus systems to protect data, systems, equipment, and networks—safeguarding customer privacy.

MetaAge has established a “Code of Ethical Conduct for Employees,” which requires employees to carefully manage all confidential information obtained during their duties. Such information must not be disclosed or used for non-work purposes, even after resignation, unless authorized by the Company or necessary for job execution. To prevent unauthorized disclosure due to personal actions, employees are also required to sign a personal data consent form to protect customer rights and prevent misuse of information by third parties.

The Company protects customer data with strict controls and regularly promotes information security awareness through internal emails and onboarding training. Confidential documents are access-controlled; non-designated personnel must obtain supervisor approval. Annual checks are conducted to prevent loss of complaint-related data, with reviews and improvements made if issues arise.

information_security-pic1-en
esg_cybersecurity_incidents_en
Contact Us