Privacy & Data Protection Policy
Built with Security and Transparency in Mind
Privacy & Data Protection Policy
Built with Security and Transparency in Mind
Privacy & Data Protection Policy
- Statement of Intent
Easianet KK operates as a professional technology partner for global telecommunications and infrastructure providers. We are committed to the Capital Preservation of our clients’ intellectual property and the integrity of their data assets. This policy outlines our rigorous standards for data handling, aligned with ISO 27001 and SOC 2 Type 2 frameworks.
- Data Categories & Minimization
We adhere to the principle of Data Minimization. We only collect data essential for service delivery, which may include:
- Technical Metadata: IP addresses, network topology, and system logs.
- Business Contact Information: Names and professional details of client representatives.
- Operational Data: Performance metrics required for Site Acceptance Testing (SAT) or maintenance.
- Advanced Security Controls
We treat all client data as “Highly Confidential.” Our infrastructure implements:
- Encryption: All data is encrypted using AES-256 at rest and TLS 1.2+ in transit.
- Identity & Access Management (IAM): Strict “Least Privilege” access. Multi-Factor Authentication (MFA) is mandatory for all employees accessing client-related environments.
- Device Posture: Our Zero Trust architecture ensures only compliant, healthy devices can access data repositories.
- Sub-processors & Data Residency
We disclose all third-party service providers (e.g., AWS, Google Cloud, Akamai) used in our service delivery.
- Residency: Data is stored within the jurisdiction agreed upon in the Master Service Agreement (MSA).
- Accountability: We ensure all sub-processors maintain security certifications equivalent to or exceeding our own.
- Incident Response & Reporting
In the event of a suspected security breach, Easianet commits to:
- Notification: Reporting to the client’s security operations center (SOC) within 24 hours of discovery.
- Transparency: Providing a full post-mortem analysis and remediation plan.
- Right to Audit
We recognize the right of enterprise clients to conduct periodic security assessments. We provide:
- We align our internal controls with SOC 2 Type 2 standards and are prepared to undergo third-party assessments as required by client agreements.
Participation in client-led Security Image/SIG questionnaires.
1. Statement of Intent
Easianet KK operates as a professional technology partner for global telecommunications and infrastructure providers. We are committed to the Capital Preservation of our clients’ intellectual property and the integrity of their data assets. This policy outlines our rigorous standards for data handling, aligned with ISO 27001 and SOC 2 Type 2 frameworks.
2. Data Categories & Minimization
We adhere to the principle of Data Minimization. We only collect data essential for service delivery, which may include:
- Technical Metadata: IP addresses, network topology, and system logs.
- Business Contact Information: Names and professional details of client representatives.
- Operational Data: Performance metrics required for Site Acceptance Testing (SAT) or maintenance.
3. Advanced Security Controls
We treat all client data as “Highly Confidential.” Our infrastructure implements:
- Encryption: All data is encrypted using AES-256 at rest and TLS 1.2+ in transit.
- Identity & Access Management (IAM): Strict “Least Privilege” access. Multi-Factor Authentication (MFA) is mandatory for all employees accessing client-related environments.
- Device Posture: Our Zero Trust architecture ensures only compliant, healthy devices can access data repositories.
4. Sub-processors & Data Residency
We disclose all third-party service providers (e.g., AWS, Google Cloud, Akamai) used in our service delivery.
- Residency: Data is stored within the jurisdiction agreed upon in the Master Service Agreement (MSA).
- Accountability: We ensure all sub-processors maintain security certifications equivalent to or exceeding our own.
5. Incident Response & Reporting
In the event of a suspected security breach, Easianet commits to:
- Notification: Reporting to the client’s security operations center (SOC) within 24 hours of discovery.
- Transparency: Providing a full post-mortem analysis and remediation plan.
6. Right to Audit
We recognize the right of enterprise clients to conduct periodic security assessments. We provide:
- We align our internal controls with SOC 2 Type 2 standards and are prepared to undergo third-party assessments as required by client agreements.
- Participation in client-led Security Image/SIG questionnaires.
