In an environment characterised by technological innovation, where information technology and telecommunications are revolutionising business productivity, Auditech Soluciones Tecnológicas S.L. is strongly committed to fields such as regulatory law, audit services, specialised advisory and training, security processes, Information Technology governance, systems and security administration in a holistic manner.

It is essential to implement good security practices in order to guarantee the confidentiality, integrity, availability and legal compliance of all the information managed by our services and by the organisation.

As a commitment, Auditech Soluciones Tecnológicas S.L. implements the following guidelines within the context of its Information Security Management System (ISMS).

·         Confidentiality: We guarantee that all the information managed will be accessible only by duly authorised persons and within a controlled access framework. This means that confidential data will be protected against unauthorised access or improper disclosure, using appropriate authentication and encryption methods.

·         Integrity: At Auditech, we ensure that the information stored, processed and transmitted is accurate and reliable, protecting it against unauthorised alteration, loss or damage. Any modification of the data will be duly recorded and audited in order to preserve confidence in the accuracy of the information.

·         Availability: At Auditech we maintain a robust and secure technological environment that guarantees that the information is accessible and usable by authorised users whenever they need it, without unplanned interruptions. Disaster recovery measures and contingency plans are implemented in order to ensure service continuity even in critical situations.

·         Legal Compliance: Auditech will ensure compliance with all relevant laws. Specifically, complying with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Ley Orgánica 3/2018, of 5 December, on the Protection of Personal Data and the Guarantee of Digital Rights (Spanish LOPDGDD), and Real Decreto 311/2022, of 3 May, which regulates the Esquema Nacional de Seguridad (ENS, Spanish National Security Framework).

This policy will be reviewed periodically in order to guarantee continual improvement and compliance with the established security objectives, so that it remains relevant and effective.

Likewise, all the policies and procedures included in the ISMS will be reviewed, approved and promoted by the General Management of Auditech Soluciones Tecnológicas S.L..

This Security and Privacy Policy will be maintained, updated and adapted to the purposes of the organisation, aligned with the strategic risk management context of the company. To this end, it will be reviewed at planned intervals or whenever significant changes occur, in order to ensure that its suitability, adequacy and effectiveness are maintained.

 Signed: Josué López - CEO

In Madrid, on 08 October 2024