AMPLÍA SOLUCIONES S.L., as a company dedicated to the provision of DEVELOPMENT, IMPLEMENTATION, AND SUPPORT PROCESSES FOR SOFTWARE PRODUCTS FOR IOT APPLICATIONS, openly declares its intention to offer competitive services to all its clients. For this reason, it has implemented a quality and information security management system within the organization, whose main objective is to achieve the expected satisfaction of clients through established processes based on continuous improvement, ensuring the continuity of information systems, minimizing risks of damage, and ensuring the achievement of set objectives to guarantee at all times the confidentiality, integrity, and availability of information.
To this end, it commits to quality and information security according to the reference standards UNE/EN-ISO 9001 and ISO /IEC 27001, for which Senior Management establishes the following principles:
- Competence and leadership by senior management as a commitment to developing the Quality and Information Security Management system.
- Determine the internal and external interested parties that are relevant to the quality management system and meet their requirements.
- Understand the context of the organization and determine its opportunities and risks as a basis for planning actions to address, assume, or treat them.
- Ensure the satisfaction of our clients, including the interested parties in the company’s results, regarding the performance of our activities and their impact on society.
- Establish objectives and goals focused on evaluating quality performance, as well as continuous improvement in our activities, regulated in the Management System that develops this policy.
- Compliance with the requirements of applicable and regulatory legislation to our activity, commitments made with clients and interested parties, and all internal standards or guidelines to which the company is subject.
- Ensure the confidentiality of data managed by the company and the availability of information systems, both in the services offered to clients and in internal management, preventing undue alterations to the information.
- Ensure the response capacity in emergency situations, restoring the operation of critical services as soon as possible.
- Establish appropriate measures for the treatment of risks arising from the identification and evaluation of assets.
- Motivate and train all personnel working in the organization, both for the correct performance of their job and to act in accordance with the requirements imposed by the reference standard, providing an adequate environment for the operation of processes.
- Maintain fluid communication both internally, between the different levels of the company, and with clients.
- Evaluate and ensure the technical competence of personnel for the performance of their functions, as well as ensuring their adequate motivation for participation in the continuous improvement of our processes.
- Ensure the correct state of the facilities and adequate equipment, in correspondence with the company’s activity, objectives, and goals.
- Ensure a continuous analysis of all relevant processes, establishing pertinent improvements in each case, based on the results obtained and the objectives set.
These principles are assumed by Senior Management, which provides the necessary means and equips its employees with sufficient resources for their compliance, embodying them and making them publicly known through this Quality and Information Security Policy.
February 18, 2025 Annex I. Ed. 02