Skip to main content
Last updated: 2026/5/28

SocialDog's security, privacy, costs, and operations

This page describes details regarding security and operational systems, including SocialDog's authentication, personal information handling, costs, and plan cancellation.

1. Authentication (MFA / Password Management)

1-1. About Multi-Factor Authentication (MFA)

  • SocialDog offers Multi-Factor Authentication (MFA) functionality to all users.
  • The authentication method is a one-time password (TOTP method) via an authenticator app.
  • The use of MFA is optional and not mandatory.

1-2. Password Expiration (Periodic Change)

  • We do not provide a function to set a Password expiration period (mandatory Change after a certain period).

1-3. Account Lockout

  • For measures against unauthorized access in case of repeated authentication failures, the system implements certain safeguards.
  • Details such as specific attempts or conditions are not disclosed as they could facilitate unauthorized access.

1-4. Password Complexity Requirements

  • Passwords must be alphanumeric, include at least one number or symbol, one uppercase alphabet character, and be 8 characters or more in length.

2. Confidentiality (NDA)

3. Handling of Personal Information (Responsibility System)

  • We handle personal information appropriately based on our "Privacy Policy" and "Information Security Policy."
  • We have an "ISMS Manager" in-house, who is responsible for overseeing information Security and personal information protection (this is a Role-based position, not an individual's name).

4. Intellectual Property (Post Data, etc.) and Scope of Use

  • Rights related to data created and posted by customers on SocialDog (Post text, images, Analytics data, etc.) are handled based on our Terms of Use and Privacy Policy.
  • While the rights held by customers are reserved by them, we utilize the data to the extent necessary for service provision, incident response, quality improvement, and functional enhancements.
  • For some functions such as payment processing, we provide services in cooperation with outsourced partners like payment service providers. We provide only the minimum necessary information to these entrusted parties based on contracts and ensure proper management.
    • Payment processing: Stripe, NP Invoice payment

5. Costs (Conditions for Additional Costs) / Linked Services

5-1. Conditions for Additional Costs Due to SocialDog Usage

  • A basic fee will be incurred according to your contracted Plan.
  • Additional fees are incurred upon upgrading to a higher Plan and upon contract Refresh (next billing cycle).
  • For specific amounts and conditions, please check your current Plan and the pricing page.

5-2. Cost Burden for Linked Services (e.g., X)

  • Currently, SocialDog does not charge additional fees for costs associated with the use of external services like X or API charges.
  • The contract terms and billing conditions (e.g., X Premium) for each SNS service must comply with the terms of each service provider.

6. Cancel plan Conditions (Penalty Fees / Refunds)

  • No penalty fees or Cancel plan charges will be incurred upon Plan Cancel plan.
  • Your contract will be on a "monthly" or "Yearly" basis, and even in the event of early Plan Cancel plan, no pro-rated refunds will be issued for the period already Paid.
  • Even after the Plan Cancel plan procedure, you can continue to use the service until the contract expiration date.

7. Human Security Measures (Education / Disciplinary Actions, etc.)

  • We provide information Security education to all employees at least once every six months.
  • Based on internal regulations regarding information Security, in the event of a violation, we have established a system to ascertain the facts and implement necessary corrective actions and disciplinary measures.
  • Specific details of disciplinary actions and internal regulations are internal information and are not publicly disclosed.

8. ID Federation

  • Currently, we do not provide Single Sign-On (SSO) functionality using SAML / OIDC or similar protocols.

9. ID Management (Centralized Management / Authorization Management)

  • SocialDog allows you to set administrator and general user permissions for each team through its "Team functionality."
  • Users with administrator privileges can access some management functions, such as Team settings and member management.

10. Session Management

  • In SocialDog, if the logged-in state persists for a certain period, the session will automatically expire, requiring re-login.
  • Sessions are set to be valid for a maximum of two weeks.
  • Specific session timeout conditions are partially undisclosed to prevent unauthorized use. The system is designed to prevent continuous access from devices that have been inactive for an extended period.

11. Device Identification

  • Currently, we do not provide device identification or device control features (such as forcefully blocking access from non-specific devices) that require device certificates.
  • Customers are responsible for managing device-side Security (e.g., OS and browser updates, device locking).

12. DDoS Countermeasures

  • SocialDog operates on Google Cloud Platform (GCP) data centers and is prepared for external attacks and failures through network-level defense features and infrastructure redundancy provided by GCP.
  • At the application level, rate limiting and other controls are applied to some APIs to mitigate service impact from excessive requests.
  • Specific rules and components are not publicly disclosed in detail as they relate to attack resilience.

13. Mass Writing / Malicious Input Countermeasures

  • On some screens, such as login and inquiry forms, reCAPTCHA has been implemented to mitigate unauthorized access by bots and large-scale automated input.
  • Rate limiting is applied to some APIs to ensure that high volumes of requests in a short period do not impact the service.
  • Specific thresholds and rules for these measures are not disclosed as they could provide clues for malicious use.

14. Sub-processors (Subcontractors) / Data Storage Location

14-1. Sub-processors (Subcontractors)

The subcontractors currently in use are as follows:

  • Payment processing
    • Stripe (Credit card payment)
    • NP Invoice payment (Invoice payment)

We collaborate with these businesses based on contracts that define the scope of information handling and security management measures.

14-2. Data Storage Location

  • SocialDog operates on Google Cloud Platform (GCP) data centers, and its primary production data is stored in the Tokyo region.
  • From the perspective of availability and disaster recovery, some data backups are maintained in regions within Asia.
  • These operations are carried out in compliance with applicable laws and contractual requirements.

15. Security Incident Notification / Contact Point / Audit (Third-Party Assessment)

  • We have obtained ISO27001 (ISMS) certification, an international standard, and operate our information Security management system according to this framework.
  • In the event of a Security incident, we will ascertain the situation, identify the scope of impact, analyze the cause, and consider and implement recurrence prevention measures based on our internal incident response process.
  • Notification conditions, initial response time, and communication methods to customers will be determined individually based on the nature of the incident and contractual terms.