Information Security Policy
One of the objectives of Avatia Digital Coworkers is to safeguard the security of information, whether personal in nature or not. To that end, it establishes an information-security system aimed at reducing the risks associated with information and cybersecurity, ensuring that information is accessible only to those users with a legitimate need to perform their duties, and that it is protected, available and used for the purposes for which it was obtained.
Strategic objectives
Avatia Digital Coworkers defines the following strategic objectives:
- Minimise the risks of loss of confidentiality, integrity and availability of the information received, generated, processed and stored by Avatia Digital Coworkers.
- Support the company's business areas in securing the information assets that underpin business operations and information containing personal data.
- Raise employee awareness of information security in the performance of their duties.
- Maintain an information-security and cybersecurity programme that supports the organisation's strategic objectives and new business projects.
- Comply with legal requirements, commitments made to customers and suppliers, and any regulations, internal rules or codes of conduct to which the company is subject.
- Continuously improve the information-security system.
- Promote information-security awareness and training.
- Ensure the capacity to respond to emergency situations, restoring the operation of critical services in the shortest possible time.
Scope of application
The Information Security Policy concerns all users and applies to all information created, processed or used by Avatia Digital Coworkers, regardless of the medium, format, presentation or location in which it is found. All security measures adopted are aimed at protecting information and the information systems that support it — including applications, operating-system resources, telecommunications networks, media and computer equipment — whether managed by Avatia Digital Coworkers or by companies or personnel expressly authorised for that purpose, such as those that have signed a service-provision or data-processing agreement with Avatia Digital Coworkers, or legally authorised assignees.
Security scenarios
The Information Security and Cybersecurity Policy is focused on ensuring the following three major scenarios:
- Confidentiality. Critical, sensitive, private or personal information managed by the organisation is not stolen or accessed by unauthorised persons.
- Availability. Minimise impacts in which the services provided by the organisation become inaccessible or unusable.
- Integrity. Ensure the integrity of information systems, preventing the corruption of the organisation's data or systems that would affect the accuracy or integrity of information and processing, and which could also affect the availability of services.
Development and review
The Information Security Policy is developed through security regulations addressing specific matters and is reviewed at least once a year, and whenever relevant changes occur in the organisation, to ensure it remains suited to the organisation's own strategy and needs. This policy applies at all Avatia Digital Coworkers workplaces and is implemented within an information-security framework in accordance with the ISO 27001:2022 standard.
For any question regarding this policy, please contact dpo@avatia.ai.