Information Security & Data Handling Policy

Last review: 2025-12-1

Version: 1.0

Owner / Responsible: Guadalsistema SL

1. Purpose

The purpose of this policy is to define how we handle, protect and process information and data — whether our own, our clients’, or data intermediated via our services — in order to preserve confidentiality, integrity, and availability, to avoid unauthorized access, leaks or loss, and to ensure trust from our clients and partners. This policy establishes minimum security rules, operational best-practices, and responsibilities for data management within the organization.

2. Scope

This policy applies to all systems, servers, services, processes and data operated by the organization. It includes:

Public or already public data (public web content, anonymized data, etc.) are excluded from the scope of this policy.

3. Security Principles

The organization commits to the following security principles:

4. Data Classification and Handling

4.1 Data Classification

We categorize data handled by our systems into at least the following sensitivity levels:

Classification LevelExamples / Data Types
Public / Non-sensitivePublic content, anonymised data, non-private metadata
Internal / OperationalSystem or application logs, metadata, non-sensitive internal configuration
Confidential / ClientClient data, authentication tokens, customer identifiers, non-public information related to clients
Restricted / Sensitive (if applicable)Highly sensitive personal data, financial data, personal information requiring strict handling

Before storing or transmitting any data, we classify it according to this scheme.

4.2 Data Handling Rules

5. Access Control and Authentication

6. Secure Configuration and Operational Hygiene

7. Data Transfer & Third-Party Communication

8. Logging, Monitoring & Audit

9. Incident Response & Vulnerability Management

Even though our organization is small, we commit to a basic incident response and vulnerability management process:

10. Roles & Responsibilities

11. Review & Update

12. Public Disclosure & Transparency

We commit to publishing this policy (or a summary thereof) in a publicly accessible place (e.g. website), so clients, partners, or external reviewers can understand how we manage data and security — even if our team is small. Transparency helps build trust and demonstrates our commitment to data protection.