시작하기!

데이터 거버넌스 및 보안 | 고객 데이터 처리

정책

Data governance and security

How DEISO handles client data during an engagement — where it sits, who can reach it, how AI is used, how long it is kept, and what happens if something goes wrong.

What this page is

This page states DEISO’s working practice in plain terms so that a technical or procurement reviewer can assess it before an engagement begins. It is not a certification, and DEISO does not claim one.

검토 범위

This page covers client data: the files, figures, drawings, invoices, supplier information, emission factors, cost records and correspondence a client shares with DEISO in order for work to be carried out.

Personal data collected through the website — enquiry forms, subscriptions, analytics — is covered separately in our privacy policy.

Principles

Four principles govern how DEISO handles client material.

  • Minimum necessary — DEISO asks for the data the work requires, and no more
  • Named purpose — client data is used only for the engagement it was provided for
  • Traceable — figures used in a deliverable are traced to their source, owner and date
  • Returned or removed — client data does not accumulate indefinitely after an engagement closes

Where client data is held

DEISO is based in Japan and client work is carried out from Japan. Client files are held in access-controlled business cloud storage and on DEISO working machines, and are transferred over encrypted connections.

Where a client requires that data be exchanged through the client’s own system — a secure portal, a controlled workspace, or a nominated transfer service — DEISO will work within that system instead.

DEISO does not publish client data, does not sell it, and does not share it with any party outside the engagement without the client’s written agreement.

Who has access

Access to client data is limited to the DEISO personnel assigned to the engagement. Where a specialist is brought in for a defined part of the work, that specialist is bound by the same confidentiality terms and is given access only to the material that part of the work requires.

DEISO working accounts are protected by two-factor authentication, and working machines are protected by full-disk encryption and screen lock.

Confidentiality

Confidentiality applies to every engagement by default, whether or not a separate agreement is signed. DEISO signs client non-disclosure agreements on request, and confidentiality terms are set out in the engagement agreement for each project.

DEISO does not name a client, describe a project, or use project material in marketing, case studies or training without that client’s written permission. Where permission is given, the scope of what may be shown is agreed in advance.

Use of AI in delivery

DEISO is AI-supported. AI 도구 are used to accelerate structuring, drafting, checking and analysis. They do not replace the technical judgement in a deliverable.

  • Human technical review — every figure, method and conclusion in a deliverable is reviewed by a DEISO technical practitioner before it leaves
  • No confidential input to public tools — client-identifying material and confidential figures are not submitted to public or consumer AI services
  • No model training — client data is not used to train third-party AI models, and DEISO does not grant any provider the right to do so
  • Stated on request — where a client asks, DEISO will state which parts of a workflow used AI support

If a client requires that no AI tooling is used on their engagement, DEISO will work to that condition and confirm it in the engagement agreement.

Tools and third parties

Delivery involves ordinary business software: cloud file storage, email, office and spreadsheet applications, life cycle assessment and costing software, and the DEISO website and forms. Each of these is a commercial service operating under its own terms, and each processes only what the work passes through it.

Where a client requires a list of the specific services that would touch their material, DEISO will provide it before the engagement begins.

Retention and deletion

Client data is kept for the duration of the engagement and for a period afterwards, so that results can be defended in review, questions answered, and the study updated in the next cycle without rebuilding it.

Where a client asks in writing for their data to be deleted, DEISO will delete it, subject to any records DEISO is required to retain by Japanese law — principally invoices and accounting records — and will confirm what has been deleted and what has been retained.

Ownership of data and deliverables

Data a client provides remains the client’s data. Ownership of deliverables, models and reports produced during an engagement is set out in the engagement agreement for that project.

DEISO methodology, templates, curriculum and software remain DEISO property and are not transferred by an engagement.

If something goes wrong

If DEISO becomes aware of unauthorised access to, loss of, or disclosure of client data, DEISO will contact the affected client without undue delay, state what is known, state what is being done, and continue to update the client as the position becomes clearer.

To report a security concern about DEISO systems or a DEISO deliverable, email with “Security” in the subject line.

What DEISO does not claim

Clear boundaries matter more than badges, so these are stated directly.

  • DEISO does not hold ISO 27001, SOC 2 or any equivalent information security certification
  • DEISO is not a certification or verification body
  • DEISO does not operate a client-facing data centre or hosting service
  • No system is completely secure, and DEISO does not represent that it is

Where a client’s own procurement process requires a security questionnaire, supplier assessment or specific contractual data terms, DEISO will complete it and negotiate the terms.

Questions before an engagement

If your organisation needs to assess DEISO before sharing data, ask before the engagement rather than after. Send the question to and DEISO will answer it directly, including where the answer is that a formal process does not yet exist.

연락처 정보.

영문 주소:
시오도메 시바리큐 빌딩 21층
미나토구 가이간 1-2-3
일본 도쿄도 105-0022.

일본어 주소:
〒105-0022 東京都港区海岸1-2-3
汐留芝離宮ビルディング21階, 合同会社DEISO.

전화번호(JP): /
전화번호(EN):
팩스: /
이메일:

최신 소식

DEISO로 간편하게 시작하기!

시작하는 7가지 방법

현재 상황에 맞는 시작점을 선택하세요

모든 방문자가 첫날부터 필요한 것을 알고 있는 것은 아닙니다. 이 7가지 온보딩 경로는 원하는 서비스를 정확히 알고 있는 경우 부터 질문에서 시작해 AI의 안내를 받는 경우. 까지 전 범위를 지원합니다. 상황에 맞는 방법을 선택하세요.

1필요한 것이 명확하다면추천 적합한 DEISO 서비스 찾기 몇 번의 클릭으로 요구사항에 맞는 DEISO 서비스를 찾으세요. 다음 기준으로 필터링할 수 있습니다: LCA, GHG, PCF, EPD, ESG, 중대성 검토, S-LCA, 폐기물, 순환경제, EIA, 등. 이미 범위를 알고 있다면 가장 빠른 경로입니다. 적합한 대상 “검증 전 Scope 3 검토 및 제출 전 점검이 필요합니다” 또는 “EPD 15804에 맞춰 EN를 준비해야 합니다.” 서비스 파인더 열기 → 2내부 역량을 구축하고 있다면추천 역량 강화 프로그램 살펴보기 팀에 적합한 DEISO 교육 프로그램을 찾으세요 — LCA, GHG 산정, PCF, EPD 개발, ESG 보고, 환경 검토, ISO 14001 및 산업별 프로그램. 직무, 수준 및 형식별로 필터링할 수 있습니다. 적합한 대상 사내 LCA, GHG 또는 EPD 역량을 구축하는 팀과 사우디아라비아 Vision 2030과 같은 인력 개발 우선순위에 부합하는 조직에 적합합니다. 교육 파인더 열기 → 3업무 착수 전 기술적 방향이 필요하다면추천 무료 기술 평가 전체 업무를 의뢰하기 전에 지속가능성 요구사항에 대한 초기 기술 평가를 요청하세요. DEISO는 귀사의 프로젝트 요구사항, 기술적 맥락, 엔터프라이즈 요구사항, 보고 목표 및 서비스 방향 을 검토하여 적합한 경로를 파악할 수 있도록 지원합니다. 적합한 대상 LCA, GHG, PCF, EPD, ESG 또는 지속가능성 운영체계 업무를 시작하기 전에 기술적 방향이 필요한 기업, 공급업체 및 공공기관 지속가능성 팀에 적합합니다. 무료 평가 시작하기 → 4빠르게 답을 얻고 싶다면 빠른 검색 사용하기 페이지 사이드바의 검색 아이콘을 클릭하거나 Ctrl Shift Del 키를 눌러 사이트 어디에서나 파인더를 여세요. 다음과 같은 용도에 적합합니다: 빠른 키워드 검색 몇 초 안에 결과를 확인하고 싶을 때 유용합니다. 적합한 대상 표준, 서비스명 또는 교육 프로그램 등 찾는 용어를 이미 알고 있으며 탐색 과정 없이 바로 해당 페이지로 이동하고 싶은 모든 분에게 적합합니다. 빠른 검색 열기 → 5심층적으로 살펴보고 싶다면 고급 검색 사용하기 서비스, 솔루션, 방법론, 사례 연구, 아티클 및 기술 리소스를 포함한 DEISO 전체 지식 기반을 검색하세요. 다음과 같은 경우에 가장 적합합니다: 먼저 조사하고 나중에 결정하기. 적합한 대상 대화를 시작하기 전에 방법론의 깊이를 비교하려는 연구자, 조달팀 및 기술 책임자에게 적합합니다. 고급 검색 열기 → 6한 번에 모든 내용을 보고 싶다면 전체 사이트맵 보기 다음을 한곳에 모은 색인 사이트의 모든 페이지와 모든 아티클 — 서비스, 교육 프로그램, 솔루션, 방법론, 사례 연구 및 뉴스. 입력하면서 필터링하거나 구조를 위에서 아래로 살펴보세요. 적합한 대상 이전에 본 페이지를 다시 찾는 재방문자와 필터 질문에 답하기보다 전체 구조를 훑어보기를 선호하는 모든 분을 위한 공간입니다. 사이트맵 열기 → 7질문하고 싶으시다면고급 Mirai AI에게 질문하기 DEISO Mirai™ AI Pro 는 DEISO의 AI 가이드 어시스턴트입니다. 지속가능성 관련 요구사항을 질문하면 적합한 서비스로 안내하고 접근 방식을 설명하며, 준비가 되면 DEISO 팀으로 연결해 드립니다. 이렇게 질문해 보세요 “CSRD Scope 3 공시를 위해 무엇을 준비해야 하나요?” · “제품 탄소발자국을 어떻게 시작하나요?” · “어떤 DEISO 서비스가 EPD 프로젝트에 적합한가요?” Mirai에 문의하기 →
그 밖에 필요한 모든 정보

DEISO 자세히 살펴보기

아직 특정 경로를 시작할 준비가 되지 않으셨나요? 이 페이지에서 핵심 정체성, 플랫폼 계층, 수행 이력 및 팀 연락 방법을 폭넓게 확인할 수 있습니다.