Security Policy

Kapture Global Quality S.L. (hereinafter Kapture.IO), agrees that the development of the company’s activities and the achievement of its strategic objectives requires ensuring, at all times, compliance with the established levels of confidentiality, integrity and availability for its information assets. At the same time, it also requires demonstrating its ability to provide its own solutions and services in a coherent manner, as well as to efficiently manage the information security and cybersecurity services it offers its clients.

To this end, an Information Security Management System (ISMS) has been developed and implemented based on the prestigious ISO 27001 and ISO 27002 standards, which establish the reference framework for the secure handling of the organization’s assets, and which guarantees customer confidence and satisfaction by integrating an efficient service delivery methodology.

Kapture.IO’s commitment to information security management is as follows:

  • To make clear the commitment of the Management with the ISMS, with the management of information security, both its own and that of its customers.
  • Integrate ISMS requirements into the organization’s business processes.
  • Define, develop and implement the necessary controls promoting the use of the process approach and risk-based thinking to ensure compliance, at all times, with the risk levels approved by the organization.
  • Comply at all times with current legislation, in addition to the particular standards and specifications applicable to the services provided by Kapture.IO and aimed at customer satisfaction.
  • Create a culture of integrated management of information systems, both internally, to all personnel, and externally to customers and suppliers.
  • Engage, direct and support staff in order to contribute to the effectiveness of the ISMS, ensure the availability of the necessary resources for it, as well as support other relevant management roles in the way they apply the management system in their areas of responsibility.
  • Maintain customer confidence and satisfaction.

1 Objectives and Requirements

In order to guarantee its commitment, and being aware that the objective of information security is to ensure business continuity in the organization and to minimize the risk of damage by preventing security incidents and reducing their potential impact when unavoidable, Kapture.IO establishes the following information security objectives, compatible with the context and strategic direction of the organization:

  • Incorporate safety into the organization’s culture and management framework.
  • Align information security, i.e. the confidentiality, availability and integrity of the organization’s information so that it can meet its business strategy, as well as existing contractual and legal requirements.
  • Risk-focused analysis and management.
  • Optimize security investments in support of business objectives.
  • Efficient and effective utilization of security knowledge and infrastructure.
  • Protect Kapture.IO information resources and the technology used for their processing from internal or external, deliberate or accidental threats.
  • Monitoring and reporting of processes to ensure that objectives are achieved.

Likewise, as established in the standard, the requirements of the interested parties must be included, as well as the objectives of information security to ensure business continuity in the organization and minimize the risk of damage by preventing security incidents, as well as reducing their potential impact when unavoidable.

Likewise, the strategic responsibilities for information security within the organization, such as responsibilities for risk management, conducting internal audits or managing information security incidents, are described in the document “Roles and Responsibilities”.

This policy is supported by lower level IT-specific policies, such as access controls, physical and environmental security and end-user oriented topics, such as acceptable use of assets, desktop policy, mobile devices, restrictions on software installation and use, backups, protection against malware, corporate policy of good use, and finally a security policy and procedures; documents that are part of the ISMS ecosystem.

2 Personal Data

Kapture.IO, in the development of its functions, requires the use of personal data. Therefore, the rights and freedoms of the interested parties will be guaranteed, as well as the security of the information, communications and information systems that support the processing in accordance with the measures provided for in current legislation.

In order to achieve the necessary guarantees, all of the following actions will be carried out:

  • Conducting risk analyses of processing operations, and privacy impact assessments where processing operations are likely to result in a high risk to the rights and freedoms of data subjects.
  • The preparation of all the necessary documentation to support the processes and guarantee the rights and freedoms of those affected, complying with the principles established by current regulations.
  • The transfer of obligations to all personnel who have access to personal data and the management of relationships with data processors based on established criteria, including regulation through contracts that formalize obligations and security requirements.
  • The maintenance of a record of treatment activities.
  • The information within the required deadlines, based on the provisions of the applicable laws, to the corresponding competent data protection authority.
  • Layered information on treatments to those affected by them, in a concise, transparent, intelligible and easily accessible form.
  • The collection of the consent of the affected parties expressly and unequivocally, and prior to the start of the processing and/or establishment of assignments.
  • Notifying those affected of security breaches that pose a high risk to their rights and freedoms, within 72 hours of their detection

This Data Protection policy is based on specific current and future policies, which will follow their own approval and supervision channels.
Finally, the management of Kapture.IO is committed to ensuring the understanding and involvement of all staff in achieving the objectives of the ISMS. Furthermore, this policy will be reviewed annually and modified when it is considered pertinent for its continuous improvement.

Scroll to Top