heydiga

Security policy

HEYDIGA TECH, S.L.

1.- Introduction

This Information Security Policy is established to protect the confidentiality, integrity, availability, traceability and authenticity of HeyDiga's information assets. It complies with ISO/IEC 27001:2022 and with Royal Decree 311/2022, which governs the Spanish National Security Framework (ENS).

It applies to all employees, contractors and third-party users who access or use HeyDiga's information assets.

The CCN-STIC 800 guides have been taken as a reference for the definition of this and the organisation's other policies, even where this is not explicitly stated in the specific documentation.

2.- Purpose

The purpose of this policy is to guarantee the protection of information assets against all threats, whether internal or external, deliberate or accidental. It seeks to ensure compliance with all applicable laws, regulations and contractual obligations.

The policy establishes a framework for setting, reviewing and achieving information security objectives, and defines the responsibilities of employees, contractors and third-party users in protecting HeyDiga's information assets.

The policy also seeks to promote awareness, train employees and guide decision-making processes relating to information security within the organisation.

3.- Scope

HeyDiga, a company dedicated to developing conversational AI that understands, automates and scales every business interaction, has decided to implement an Information Security Management System (ISMS) to improve the services it provides to its clients.

This policy applies to all information assets owned, leased, processed or otherwise controlled by HeyDiga, including information stored on physical or electronic media, information transmitted over networks or any communication channel, and information processed or handled by employees, contractors or third-party users.

4.- Objectives

The main objectives of this policy are to protect the confidentiality of information to prevent its unauthorised disclosure, to guarantee the integrity of information to prevent its unauthorised modification, and to ensure the availability of information to authorised users when they need it.

The policy also seeks to ensure compliance with applicable laws, regulations and contractual obligations, such as the General Data Protection Regulation (GDPR), the Spanish Organic Act on Data Protection and the guarantee of digital rights (LOPDGDD) or Act 10/2021 on remote working, among others, while continuously improving the information security management system (ISMS).

5.- Security organisation and responsibilities

HeyDiga's Management is responsible for providing leadership and commitment to information security. It ensures that adequate resources exist to implement and maintain the information security management system, and reviews and approves information security policies and procedures.

The Information Security Management System Manager (ISMS Manager) is responsible for developing, implementing and maintaining the information security management system. This includes carrying out risk analyses, implementing the appropriate controls and reporting to senior management on the system's effectiveness.

Employees, contractors and third-party users are responsible for complying with this policy and all related information security procedures. They must report to the ISMS Manager any information security incident or vulnerability they suspect, and take part in information security training and awareness programmes.

6.- Security measures

In line with our commitment to safeguarding information assets and maintaining the integrity of our operations, we have established a comprehensive set of security measures. These measures cover a range of strategies and technologies aimed at protecting our systems, data and resources against potential threats, guaranteeing the confidentiality, integrity and availability of information critical to our business.

  • Human resources: human resources security measures are implemented to ensure that employees, contractors and third-party users know their responsibilities and are prepared to safeguard information assets.
  • Asset management: asset management measures are implemented to ensure that all information assets are properly identified, classified and protected throughout their life cycle. This includes maintaining an accurate inventory of assets, assigning ownership and defining usage guidelines. Regular audits and reviews are carried out to ensure that assets are adequately protected.
  • Access control: access to information assets is limited to authorised users only. Robust authentication and authorisation mechanisms are implemented, and access rights are reviewed regularly to confirm that they remain appropriate.
  • Network security: measures are implemented to protect the company's network infrastructure against unauthorised access, breaches and other security threats. This includes firewalls, intrusion detection systems and regular network monitoring.
  • Operations security: operations security measures are applied to preserve the integrity of operational processes and guarantee the secure execution of daily activities. This includes implementing monitoring systems and robust logging mechanisms to identify and respond quickly to suspicious activity.
  • Configuration management: a configuration management procedure is implemented to ensure that all configurations of information systems and related assets are managed, documented and monitored systematically throughout their life cycle. This process supports the organisation's information security objectives by maintaining the integrity and consistency of configurations.
  • Secure development: security practices are integrated into the software development life cycle to ensure that applications are designed, developed and maintained securely. This includes code reviews, vulnerability scanning and regular security testing.
  • Change management: a procedure is established to control and document changes to information systems and infrastructure. This ensures that changes are reviewed, approved and implemented in a controlled way, minimising the risk of security incidents and operational disruption.
  • Risk management: regular risk analyses are carried out to identify and assess risks to information assets. Appropriate controls are implemented to mitigate the risks identified, and the effectiveness of these risk management activities is continuously monitored and reviewed.
  • Data management: information is classified according to its sensitivity and criticality. Appropriate handling procedures are defined for each classification level to guarantee the protection of information throughout its life cycle.
  • Incident management: an incident management process is established and maintained to detect, respond to and recover from information security incidents. All security incidents must be reported without delay to the designated incident response team. Incidents are investigated to determine their root cause and prevent recurrence.
  • Business continuity: plans are established and maintained to guarantee the continuity of critical business functions in the event of disruption. These plans are tested and updated regularly to ensure their effectiveness.
  • Third-party management: security requirements are defined and enforced for suppliers and external partners. Regular assessments and reviews are carried out to confirm that third parties meet the company's information security standards.
  • Compliance: compliance is guaranteed with all applicable laws, regulations and contractual obligations relating to information security. Regular audits and reviews are carried out to verify compliance with this policy and with the information security management system.
  • Awareness and communication: regular information security training is delivered to all employees, contractors and third-party users. Knowledge of information security policies, procedures and good practice is promoted throughout the organisation.

7.- Security improvement

HeyDiga is committed to the principle of continuous improvement in its information security management practices. Regular assessments and reviews are carried out to identify areas for improvement in the ISMS.

Audit findings, incident reports and employee suggestions are assessed systematically in order to implement improvements. Metrics and performance indicators are monitored to measure the effectiveness of information security controls and identify opportunities for refinement.

This continuous improvement effort ensures that the ISMS remains effective, responds to emerging threats and stays aligned with HeyDiga's strategic objectives.

8.- Approval

Management Team, HeyDiga. 16 March 2026.

9.- Languages of this policy

This Security Policy is published in Spanish, Catalan, English, French, Italian and Portuguese. In the event of any discrepancy between versions, the Spanish version shall prevail.

Servers in the European UnionGDPR complianceENS medium category (RD 311/2022)ISO 27001Data encryption and anonymisation

© 2026 heydiga · Barcelona · Madrid