At Grupo Orenes, and especially in the Technology and Innovation area, we recognize the importance of Information and Communication Technologies (ICT) as the foundation of our services and a support for business objectives. Therefore, we consider information security a differentiating factor and a commitment we assume both internally and externally.

Compliance with the international standard ISO 27001

We maintain an Information Security Management System (ISMS) compliant with ISO 27001, ensuring a systematic, documented, and continuously improving approach.

Confidentiality, integrity and availability

We protect information and services from threats and vulnerabilities, applying controls and procedures adapted to the real needs of the business and technological evolution.

We conduct periodic risk analyses and contingency plans to ensure service continuity at all times.

Legal compliance and good practices

We ensure compliance with the EU General Data Protection Regulation (GDPR), Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD), and Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE).

We consistently integrate legal requirements and industry best practices into our security strategy and all related processes.

Our commitment to security translates into the protection of customer information, continuity in service delivery, and transparency in incident management.

We foster customer and employee trust and satisfaction by proactively safeguarding the information they entrust to us.

Culture of safety and continuous improvement

We develop and promote training and awareness-raising activities for staff so that each member understands their responsibilities and best practices regarding safety.

We define clear roles and functions for effective coordination and a spirit of collaboration in the event of any eventuality.

We constantly seek the best solutions to strengthen information security, aligning technology with business strategy.

We apply a preventive and corrective approach, periodically reviewing this policy and all security procedures to adapt to changes in the internal context, the regulatory environment, and emerging threats.

Communication and incident response

We establish flexible communication channels and formal procedures for managing security incidents.

We ensure the adoption of effective and coordinated measures to minimize the impact and prevent its recurrence, always seeking the continuity of services and the protection of information.

Management Commitment

The Orenes Group Management fully supports this policy and guarantees the necessary resources for its implementation and maintenance, fostering a culture of safety at all levels of the organization.

Our goal is to offer reliable, high-quality solutions that comply with current standards and regulations, and strengthen the trust of our clients and strategic partners.

The Management, the various internal executive bodies specific to security, and all Technology and Innovation staff ensure compliance with this policy and the standards derived from it.

Our policy will be reviewed periodically and updated as necessary to reflect changes in our context, security requirements, or evolving threats.