Updated July 15th, 2026

Quality and Information Security Policy

Version 1.3

Acuratio Europe, S.L. (hereinafter, "Acuratio") considers information and the systems that support it, together with the quality of its services, to be essential assets for the delivery of its services and the satisfaction of its customers. For this reason, Management is committed to protecting and continuously improving them, and approves this Quality and Information Security Policy, which constitutes the reference framework for its integrated quality and information security management system.

Acuratio has implemented its system in accordance with the National Security Framework (Esquema Nacional de Seguridad, ENS), regulated by Royal Decree 311/2022 of 3 May, and integrated with the ISO 9001 and ISO/IEC 27001 standards within its Integrated Management System (IMS). Its purpose is to guarantee the quality of its services and the satisfaction of its customers, as well as to preserve the confidentiality, integrity, traceability, authenticity, and availability of the information it processes in the course of its activity.

This policy is communicated to all personnel and relevant interested parties, and is reviewed at planned intervals and whenever significant changes occur, ensuring its ongoing suitability to the applicable business, legal, regulatory, and contractual requirements.

Management establishes measurable quality and security objectives, appropriate to the needs of the organization and consistent with the analysis and treatment of risks, and provides the monitoring mechanisms necessary to verify the degree to which they are met.

Acuratio directs all of its quality and information security activities in accordance with the following principles:

  • Customer satisfaction: customer requirements in the use of our platforms and services are met rigorously, guaranteeing the necessary technical support and a service that conforms to the established quality standards.
  • Continuous improvement: nonconformities and incidents are identified and addressed through a continuous improvement cycle (PDCA) aimed at increasing the effectiveness of the system and the satisfaction of customers.
  • Security as an integral process: security is conceived as part of routine operations, involving people, processes, and technology, and personnel are made aware of it so that a lack of knowledge or coordination does not become a source of risk.
  • Risk-based security management: risks are analyzed and managed on an ongoing basis, applying security measures proportionate to the nature of the information and services and to the level of risk to which they are exposed.
  • Prevention, detection, response, and preservation: measures are adopted to prevent and minimize threats, to detect incidents promptly, to respond effectively, and to guarantee the recovery and preservation of information and services.
  • Existence of lines of defense: several layers of security are established so that, if one is compromised, others remain that allow a response and reduce the likelihood of the system being affected as a whole.
  • Continuous monitoring and periodic reassessment: the security of assets is supervised, and measures are updated periodically to adapt them to the evolution of risks, of the system, and of the context.
  • Segregation of responsibilities: the roles of Information Owner, Service Owner, Security Officer, and System Owner are distinguished, keeping responsibility for information security separate from that of systems operation.

Consequently, Acuratio commits to complying with the applicable quality and information security requirements, to assigning the responsibilities and resources necessary for their management, and to continuously improving its integrated management system.

This policy is developed and complemented by specific regulations and procedures — including, among others, those governing access control, asset management, protection of communications and media, cryptography, incident management, backups, service continuity, vulnerability management, and secure development — which reinforce the protection of information assets.

All quality and information security actions respect the legislation in force applicable to Acuratio's activity, with particular attention to personal data protection regulations.

Approved by the Management of Acuratio Europe, S.L. Donostia-San Sebastián, 15 July 2026.