BREXA Group Cookie Policy
The BREXA Group (a company in which BREXA Holdings Inc. (hereinafter referred to as the "Company") directly or indirectly holds a majority of the issued and outstanding voting shares or interests (hereinafter referred to as the "Group Companies", and the Company and the Group Companies, hereinafter collectively referred to as the "BREXA Group") hereby establishes this policy. The websites and web services operated by the BREXA Group may use cookies and similar technologies to collect certain information in accordance with this policy.
1. Cookies
2. Purposes of Use of Collected Information
3. Provision of Collected Information
Users may be categorized based on specific conditions inferred from information obtained through cookies. Information related to such classifications may be provided to partner companies, including advertising service providers, media companies, advertising agencies, and advertisers.
4. Analytics and Advertising Services Used by the BREXA Group
Please refer to the respective websites of each service provider for details regarding the services, the types of data collected, and the purposes of use. If you wish to disable these services in your browser, please consult the opt-out (deactivation) pages provided by each service provider.
5. Rejection or Restriction of Cookies
Users may refuse or restrict the use of cookies by changing the settings of their browser. Cookies stored on the device may also be deleted at any time.
However, please note that if cookies are not accepted or are deleted, certain functions of the BREXA Group website may become unavailable.
6. Changes to the Cookie Policy
Please note that this Cookie Policy is subject to change without notice.
Any changes to the Cookie Policy will be announced on the Company's website.
Effective Date: 1 July 2025
BREXA Group Information Security Policy
The BREXA Group (the companies in which BREXA Holdings Inc.( hereinafter referred to as the "Company") directly or indirectly holds a majority of the issued and outstanding voting shares or interests (hereinafter referred to as the "Group Companies",; the Company and the Group Companies are hereinafter collectively referred to as the "BREXA Group") recognizes the importance of the appropriate operation and management of information in its business activities in light of the development of the advanced information society. In view of the development of the advanced information society, we, the BREXA Group recognize that the appropriate operation and management of information in our business activities is an important issue, and hereby declare our Information Security Policy (hereinafter referred to as "Policy") based on the Purpose and BREXA Group Code of Conduct in order to ensure that all stakeholders can engage with the BREXA Group with confidence. The Policy is based on the following principles. The information assets covered by this Policy are all information obtained and acquired in the course of the BREXA Group's corporate activities and all information held in the course of business.
1. Basic Principles and Scope of Application of this Policy
This Policy is the basic principle of information security measures and applies to all information assets used in the business activities of the BREXA Group and it also applies to all individuals who use such assets, including but not limited to the representative directors, directors, corporate auditors, executive officers, advisors, executive director, employees, contract workers, and part-time workers, and any other personnel regardless of their title or employment status (hereinafter collectively referred to as “Employees”).
2. Information Security Governance Structure
The BREXA Group shall appoint a Chief Information Security Officer (CISO) and designate an Information Security Manager for each individual company of the BREXA Group. Through this structure, the BREXA Group shall establish and operate a framework that ensures the effectiveness of information security measures.
3. Maintenance and Implementation of Internal Regulations
In order to protect and properly manage information assets, the BREXA Group shall establish information security regulations and other related rules. These shall be thoroughly communicated to all Employees, and actively implemented to uphold information security across the organization.
4. Operation and Management of Information Assets
The BREXA Group shall implement appropriate and thorough information security measures to protect its information assets. In addition, risk assessments of information assets are carried out and appropriate preventive measures and countermeasures are taken according to the results to reduce risks.
5. Information Security Education and Training
The BREXA Group continuously provides the necessary information security education and training to its Employees, including users and managers of information assets, in order to maintain and improve their awareness of information security measures and to put them into practice. The BREXA Group will ensure that everyone involved in the information assets of the BREXA Group possess the necessary information security literacy to perform their duties appropriately.
6. Establishment and Operation of Audit Framework
In order to ensure the effectiveness of information security, the BREXA Group shall conduct regular and as-needed audits to ensure that it complies with information security regulations and other relevant rules, relevant laws and regulations, as well as information security standards and guidelines issued by governmental agencies and industry associations, and that it functions effectively. If any deficiencies or improper operations are identified, the BREXA Group shall promptly recommend improvements or revisions to the relevant rules based on the audit findings.
7. Information Security Measures
The BREXA Group implements information security measures in terms of organizational, physical, technical and personnel safety control measures in order to prevent accidents related to the operation and management of information assets, including leaks, falsification, damage and unauthorized access. In the event of an accident, corrective measures and measures to prevent recurrence are promptly implemented.
8. Reinforcement of Management Framework for External Contractors
When outsourcing operations to external contractors, the BREXA Group shall rigorously assess the eligibility of such contractors. The BREXA Group shall require them to implement information security measures that are equivalent to or exceed those of the BREXA Group. Furthermore, to ensure that these measures are properly executed, the BREXA Group shall conduct regular audits and other necessary evaluations of the contractors.
9. Compliance with Laws, Standards, and Contractual Obligations
The BREXA Group shall comply with all laws, government-issued guidelines, and other relevant standards related to information security, as well as the provisions of applicable contracts. In the event of any violation of laws or contracts, or the occurrence of an information security incident, the BREXA Group shall take appropriate corrective actions and strive to prevent recurrence.
10. Continuous Improvement
To further ensure the effectiveness of its information security measures, the BREXA Group shall regularly monitor and evaluate the initiatives outlined above and shall continuously improve its information security practices based on the results of such assessments.
Effective Date: 1 July 2025