AI Usage Policy

Introduction

WingArc1st Inc. (the "Company"), as a Data Empowerment Company, is committed to contributing to the development of its customers' businesses and society through data utilization.
Artificial Intelligence (AI) technology has become an important tool for us to enhance the value of our products and services, improve employee productivity, and deliver new value to our customers. On the other hand, the use of AI also entails various risks such as those related to privacy, copyright, security, and ethics.
The Company operates as both an AI Provider, which provides products, cloud services, Web services, and services utilizing AI to customers, whether paid or free, and as an AI User, which utilizes AI in internal operations. This policy clarifies the principles guiding our use of AI in each of these roles, and the responsibilities we fulfill toward our customers, partners, employees, and society.
In line with the rapid evolution of AI technology, this policy will be continuously reviewed.

1. Fundamental Principles

The Company shall adhere to the following fundamental principles regarding the use of AI.

  • (1) Human-centered use of AI
    AI is intended to support human judgment, and ultimate decision-making authority and responsibility remain with humans. As a general rule, we must appropriately verify and judge AI output results rather than accepting them at face value. We will establish human verification and approval processes when AI agents or similar technologies autonomously perform operations or execute tasks on external systems.
  • (2) Safe and secure handling of data
    We will ensure proper protection of the data entrusted to us by customers and our own confidential information. We will handle the data entered into AI services with care after assessing the sensitivity of the information.
  • (3) Transparency and accountability
    We will provide clear explanations to our customers regarding products and services that utilize AI. We will honestly communicate the limitations and uncertainties of AI and avoid language that could lead to misunderstandings.
  • (4) Ensure fairness and ethical conduct
    We prohibit the use of AI that leads to the generation or dissemination of discriminatory or harmful content. We will give fair consideration to our diverse stakeholders.
  • (5) Continuous improvement and governance
    We will continuously strengthen AI governance while adapting to changes in technology, regulations, and society. From an agile governance perspective, we will conduct periodic reviews using the Plan-Do-Check-Act cycle.

2. Use of AI in Our Products and Services

  • (1) Provision of AI service
    We provide an AI service as an addition to our software products (Dr.Sum, MotionBoard, SVF, SVF Archiver, dejiren AI, etc.) and cloud services (refer to the AI Service Agreement). As the foundation for our AI service, we utilize external AI services (ChatGPT/OpenAI, Gemini/Google, Azure OpenAI/Microsoft, Claude/Anthropic, and Amazon Bedrock).
    Additionally, the policies in this chapter shall also apply to the AI-powered services we provide at customer touchpoints other than paid products, such as AI chatbots and AI assistants on our customer support website.
    Please refer to the terms of use of each individual product or service for details.
  • (2) Safety and security policy as an AI provider
    As a provider of products and services incorporating AI functions, we will implement the following safety and security policies.
    • Risk assessment during the design and development phase: When developing or modifying AI functions, we will assess AI-specific risks such as prompt injection, hallucinations, and bias, and conduct tests.
    • Incorporation of security design: When incorporating AI functions into products, we will implement security designs that take into account the prevention of unauthorized access, data leakage, and misuse.
    • Proactive measures against malfunctions and unforeseen risks: We will remain constantly aware of the possibility that AI may make incorrect judgments and establish verification processes during the design and development stages.
    • Selection criteria for external AI services: We select external AI services after evaluating their security levels and data protection requirements, and disclose this information to our customers.
  • (3) Transparency of AI functions in our products
    We are committed to ensuring the following transparency in our products and services that utilize AI functions.
    • Disclosure of AI use: We will clearly disclose to customers, through terms of use, help documentation, and other channels, where AI is utilized in our product and service features. Please note that for AI processing that takes place entirely within our internal environment (such as local LLMs), while we will disclose the existence of such features, we will not disclose the names or providers of the models used.
    • Explanation of AI recommendations and suggestions: For features where AI makes suggestions or recommendations, we will design them so that the rationale and basis behind them can be clearly explained.
    • Disclosure of external AI services used: We will disclose the names and providers of external AI services (such as LLMs) incorporated into our products in our Terms of Use or Policy page.
  • (4) Protection of input data
    Data entered by customers will not be used for training our AI services (unless individually configured by the customer). We have adopted settings that ensure data is not used for the improvement or training of foundation models of external AI services. However, due to the specifications and limitations of external AI service providers, we cannot guarantee that this will be completely prevented.
  • (5) Quality and limitations of AI output
    AI output may contain inaccurate information or unexpected expressions. We do not guarantee the accuracy, completeness, or reliability of AI output and ask that customers verify and judge it themselves.
  • (6) Prohibited uses
    We prohibit the use of our AI service for the following purposes:
    • Use that violates laws, regulations, or public order and morals
    • Generation of misinformation, defamatory, discriminatory, or violent content
    • Exploitation for malware, unauthorized access, prompt injection, etc.
    • Use without professional verification in high-risk fields such as healthcare, law, and finance
    • Making decisions solely based on AI in personnel evaluations, hiring judgments, and similar matters
    • Acts that infringe upon the intellectual property rights or privacy rights of third parties

3. AI Usage by Employees

  • (1) Principles for using approved services
    Our employees shall use only AI services approved by the company for business purposes. It is prohibited to use personal accounts or unapproved services for business. The use of non-standard or new services is permitted only after application to and review by the Information Security Department.
  • (2) Usage according to information confidentiality level
    Employees shall always confirm the confidentiality level (Public, Confidential/Anonymized, Confidential, or Strictly Confidential) of information before inputting it into AI services. It is prohibited to input highly confidential information into AI services without authorization.
  • (3) Responsibility for verifying output
    Employees shall treat AI output as a "suggestion" or "draft" and use it only after verifying facts and consulting experts. When using AI output as is for external purposes, the sender shall bear responsibility for the accuracy of the content.
  • (4) Recording and transcription of business meetings and negotiations
    To improve the quality of our sales and facilitate knowledge sharing, our company records remote meetings (sales calls), transcribes them using AI, and analyzes the transcripts. We shall comply with the following policies when carrying this out.
    • At the start of a business meeting, verbally notify the other party of the recording and obtain their consent
    • Clearly indicate that the meeting is being recorded via system notifications (e.g., meeting tool messages)
    • Immediately stop recording if the other party refuses
    • Use recorded and transcribed data only for internal purposes and prohibit unauthorized disclosure to third parties
    • Manage recorded data in accordance with specified retention periods and management rules, and properly delete it after the period ends
    • Comply with the Act on the Protection of Personal Information and our privacy policy
    • Customer information and knowledge obtained through AI analysis shall be used solely for the purpose of improving sales activities and enhancing customer value, and it is prohibited to use these for any other purpose

4. Data Handling and Protection

  • (1) Protection of personal information and confidential information
    We will comply with the Act on the Protection of Personal Information and other relevant laws and regulations regarding data acquired and processed through AI services. We strictly manage confidential information regarding our customers and business partners in accordance with our contractual confidentiality obligations.
  • (2) Cross-border data transfers
    Due to the nature of external AI services, input data may be transferred outside of Japan. We will select services after confirming their data protection requirements and disclose them to customers in Terms of Service and other documents.
  • (3) Incident response
    In the event of an incident such as an information leak or malfunction resulting from the use of AI, we will promptly verify the facts, identify the scope of damage, report to relevant parties, and implement measures to prevent recurrence.

5. Education and Literacy

We will conduct continuous education and awareness-raising activities to promote the appropriate and responsible use of AI.

  • (1) Employee education
    • We will regularly conduct training and study sessions on the characteristics, risks, and ethics of AI technology.
    • We will ensure that all employees are aware of the contents of this policy and internal AI guidelines, and promote their understanding.
    • We will provide usage guidance when introducing new AI tools and services.
  • (2) Guidance for customers
    • We will prepare guidance and FAQs regarding the use of our products and services equipped with AI functions to support their appropriate use. For information on the scope of support, please refer to the Product Support Service Policy and the Cloud Service Support Policy.

6. Responsibility to Stakeholders

  • (1) Accountability to customers
    For products and services that incorporate AI, we will transparently disclose the AI's functions, limitations, and data handling methods.
  • (2) Responsibility to society
    We are constantly mindful of the impact AI has on society and will not use it in a way that is contrary to public interest. We will promote the responsible use of AI from the perspectives of the environment, human rights, fair competition, and other factors.
  • (3) Expectations for partners and suppliers
    We will also encourage our business partners and associates to utilize AI ethically in line with our AI policy.

7. Governance and continuous improvement

  • (1) Governance structure
    We will establish an AI governance structure centered on the Corporate Security Department. The formulation and revision of key policies related to AI will be implemented following approval by senior management. The Corporate Security Department will collaborate with the Legal, Business, and IT departments to carry out the following:
    • Formulation and revision of AI policies and guidelines
    • Implementation of AI risk assessment and monitoring
    • Receipt of reports and coordination of responses for AI incidents
    • Regular review and reporting of AI usage status (at least once a year to management)
  • (2) Continuous improvement through the PDCA cycle
    We will continuously review this policy and our internal AI guidelines according to the following cycle.
    • Plan: Formulate a policy review plan based on technological trends, legal amendments, and changes in the business environment
    • Do: Dissemination, education, and operation of policies and guidelines
    • Check: Collection of feedback through reviews of AI usage status, incident analysis, surveys, etc.
    • Act (Improve): Revision of policies and guidelines based on evaluation results (conducted at least once a year)
  • (3) Alignment with the AI Guidelines for Business issued by the Ministry of Internal Affairs and Communications and Ministry of Economy, Trade and Industry
    We promote the use of AI in alignment with the intent of the 10 common guiding principles (Human-Centric, Safety, Fairness, Privacy Protection, Ensuring Security, Transparency, Accountability, Education/Literacy, Ensuring Fair Competition, and Innovation) of the AI Guidelines for Business Ver. 1.2 (March 2026) issued by the Ministry of Internal Affairs and Communications and Ministry of Economy, Trade and Industry. We will periodically evaluate the status of alignment.

Related Regulations and Terms and Conditions

    • AI Service Agreement
    • Security Policy
    • Privacy Policy

Contact Us

Please send any inquiries regarding this policy via the inquiry form on our website.
https://corp.wingarc.com/en/contact/index.html