Legal

Information security policy

Version of July 10, 2026Approved by Management

English translation provided for convenience. In the event of any discrepancy, the Spanish version prevails.

1. Introduction

NEETY's Security Policy sets out the concepts, principles, responsibilities and objectives in matters of security, the results of which allow the company to be guaranteed the freedom of action it needs.

The aim of NEETY's Comprehensive Security is to protect the people who work at the company, the confidentiality of their communications, and the availability and integrity of their information. It also looks after the other assets that make up the company's property, such as its facilities and content of every kind.

Comprehensive Security covers the traditional concepts of physical security and logical (technological) security in order to maintain business continuity in any adverse circumstance.

A stronger “security culture” among the company's staff will bring clear benefits by increasing the security of systems and procedures, and will minimise the risk of potential malicious actions.

It is essential that all information relating to security matters flows through the appropriate channels to the company's decision-making bodies.

2. Principles

Integration

Global Security is an integrated process aligned with the business, in which the whole company takes part.

Cost-effectiveness

Security is guided by business criteria, taking into account the relationship between expenditure and investment. Its criteria are set centrally, making use of any existing synergy. This management allows an overall reduction in expenditure and a better return on the effort devoted to security.

Continuity

Security must be present throughout its entire working cycle: protection, prevention, detection, response and recovery.

Suitability

The means employed must be adapted to the business environment. Among other factors, those that stand out for their impact on the business and on the organisation's security levels are competition with other companies, social, political and economic unrest, amateur or professional “hacking”…

3. Responsibilities

Ultimate responsibility for security lies with the executive team, which is directly responsible for managing its development and implementation.

The management team will analyse the security risks and vulnerabilities that may affect the proper functioning of the business and will propose the appropriate rules, means and measures to minimise them.

All staff in the organisation must take responsibility for maintaining the security of the assets in their charge, observing the security rules put in place by the management team.

4. Objectives

  • To achieve and maintain the level of security required to adequately guarantee business continuity, even in adverse situations.
  • To increase the integration and mutual support of the physical and logical aspects of security.
  • To collaborate in the management of the other security disciplines, including occupational and environmental aspects, in line with criteria that strengthen Corporate Social Responsibility.
  • To establish the corporate security structure defined by the organisation's decision-making bodies and to create the appropriate communication channels between all those involved.
  • To comply with official security regulations and other requirements.
  • To establish and implement Security Training and Awareness Plans to improve staff training.
  • An express commitment to continuous improvement.
  • To integrate the company's different departments into a security management system that, under common criteria, makes use of synergies and achieves consistency in resources and actions.
  • All NEETY staff will know and apply the rules that develop this Security Policy.