Information Security Policy
One2One Digital Strategy S.L. (O2O), empresa dedicada a la prestación de servicios de consultoría de estrategia digital, diseño y desarrollo de producto digital, así como su evolución, soporte y mantenimiento, mantiene un firme compromiso con la protección de la información de clientes, empleados, colaboradores y socios.
With this objective in mind, O2O has implemented an Information Security Management System (ISMS) based on the ISO 27001 standard, whose purpose is to guarantee the confidentiality, integrity and availability of information, as well as to protect it from possible threats that may affect the organisation’s information assets.
O2O’s management recognises that information is a strategic asset for the organisation and its customers, and therefore establishes the following as fundamental principles of its security policy:
- The protection of personal data and privacy.
- The protection of the organisation’s and its customers’ information and records.
- The safeguarding of intellectual property rights.
- Compliance with applicable legal, regulatory and contractual requirements.
- The clear assignment of responsibilities in the area of information security.
- The training and awareness of staff in good security practices.
- The management and recording of information security incidents.
- The protection of information systems against technological threats.
- The business continuity management to ensure service availability.
- The continuous improvement of the information security management system.
Furthermore, O2O undertakes to develop and provide its services in accordance with applicable legal and contractual requirements, establishing adequate controls to protect the information managed in its projects and technological services.
The organisation integrates information security into the life cycle of its technological services and solutions, applying best practices in secure development, data protection and risk management in the projects in which it participates.
This policy constitutes the reference framework for establishing and reviewing the objectives of the Information Security Management System, as well as for the continuous improvement of processes related to information protection.
The policy is communicated to all staff within the organisation and is available to relevant stakeholders when required.
v1.0 January 2026