Information security policy

The primary mission of vBote Innovation S.L. is the design and personalized development of software, offering comprehensive support to our clients from the initial analysis and design phase to final implementation, also including necessary training. Likewise, we are dedicated to the continuous development, evolution and commercial distribution of Tweem, a cloud-based human resources management solution, operating under the Software as a Service (SaaS) model.

Our extensive experience working for large companies in the installation and maintenance of their computer systems gives us sufficient guarantees to offer services of the highest quality, implementing a set of measures, controls, procedures and actions designed to protect all assets, including both information and the processes that support it, as well as systems and networks, establishing policies, practices, procedures, organizational structures and software functions.

The Information Security Policy is based on the following aspects and for this purpose, Management has made a commitment to:

  • Understand the needs of interested parties and satisfy their requirements, always trying to exceed their expectations.
  • Comply with legislation, regulations and requirements required by interested parties, even beyond the legal minimums that are economically and technologically viable.
  • Promote training and awareness actions for workers in order to improve their performance within the organization, and ensure involvement in meeting the established objectives and goals.
  • Consider management aspects as an integral part of planning processes, periodically establishing programs, objectives and goals that guarantee compliance with policy requirements and continuously improve the effectiveness of the management system.
  • Protect the company's information resources and the technology used for their processing, against threats, internal or external, deliberate or accidental, in order to ensure compliance with confidentiality, integrity, authenticity, traceability, availability, legality and reliability of information.
  • Continuous improvement must be present in all processes.
  • Protect information appropriately regardless of how it is presented, stored or communicated.
  • Establish notification, management and registration methods for incidents related to Information Security Management Systems (ISMS).
  • Define a strict policy for copying and storing information relevant to the company. This storage is carried out under the responsibility of qualified personnel in charge of preserving and maintaining these backup copies in perfect condition, thus safeguarding our competitiveness and autonomy.
  • Guarantee adequate access management to our systems through the implementation of an identification and authentication system. Which not only restricts access to third parties but also facilitates the work of our employees in a completely secure environment.
  • Define action rules that ensure an adequate balance between user needs, security requirements and respect for current laws.

Management extends this commitment to all interested parties so that they comply with the guidelines of this policy, which will be periodically reviewed in order to ensure that they are always appropriate to the organization's activities.

Signed

Management

March 2024