Information Security Policies

About Autana

Information Security Policies

Last updated: April 2, 2025

AUTANA BUSINESS PARTNERS SL, a company dedicated to providing support services for our clients’ business processes using the appropriate technologies, seeking process optimization in the areas of Consultancy specialized in technologies associated with customer management within Analytics, Customer Engagement, Digital Marketing, Data Management, Cloud Computing, and Training services—covering all channels and points of interaction between the company and its customers—has decided to implement an Information Security Management System based on the ISO 27001 standard with the objective of preserving the confidentiality, integrity, and availability of information and protecting it from a wide range of threats. This Management System is designed to ensure business continuity, minimize damage, maximize return on investment and business opportunities, and drive continuous improvement.

 

The Management of AUTANA BUSINESS PARTNERS SL, is aware that information is an asset of high value to the Organization and, therefore, requires adequate protection.

 

The Management of AUTANA BUSINESS PARTNERS SL, establishes the following as base objectives, starting points, and support for the information security objectives and principles:

 

  • The protection of personal data and individual privacy
  • The safeguarding of organization records
  • The protection of intellectual property rights
  • The documentation of the information security policy
  • The assignment of security responsibilities
  • Information security training and capacity building
  • The logging of security incidents
  • Business continuity management
  • The management of changes within the company that could affect security

 

The Management of AUTANA BUSINESS PARTNERS SL, through the development and implementation of this Information Security Management System, the company assumes the following commitments:

 

  • To develop products and services that comply with legislative requirements, identifying the applicable laws for the business lines developed by the organization and included within the scope of the Information Security Management System.
  • To establish and fulfill contractual requirements with interested parties.
  • To define security training requirements and provide the necessary training in this area to interested parties through the establishment of training plans.
  • To prevent and detect viruses and other malicious software through the development of specific policies and the establishment of contractual agreements with specialized organizations.
  • To manage business continuity by developing continuity plans in compliance with internationally recognized methodologies.
  • To establish the consequences of security policy violations, which will be reflected in the contracts signed with interested parties, suppliers, and subcontractors.
  • To act at all times within the strictest professional ethics.

 

This Policy provides the framework for the continuous improvement of the Information Security Management System and for establishing and reviewing the objectives of the Information Security Management System. It is communicated to the entire Organization through the document manager installed in the organization and its publication on information boards. It is reviewed annually for its adequacy, and extraordinarily when special situations and/or substantial changes in the Information Security Management System occur, being available to the general public.