Graphenus is aware of the importance of information security and personal data protection as key factors in achieving organisational excellence, market competitiveness, business sustainability and regulatory compliance.
Accordingly, the group has established processes within the organisation for planning and implementing controls, as well as for monitoring and improvement, in order to ensure the confidentiality, integrity, authenticity, traceability and availability of information and services.
The Graphenus management team is responsible for implementing, updating, improving, accrediting and maintaining an Information Security Management System, in accordance with good practices and international standards, specifically in accordance with the standard "UNE-EN ISO/IEC 27001:2017. Information technology. Security techniques. Information Security Management Systems. Requirements". It has established the following objectives:
Graphenus and all its members undertake to carry out their activities in accordance with current national and international data protection legislation, paying particular attention to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of the European Union.
Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the GDPR); and to Organic Law 3/2018 of 5 December 2018 on the Protection of Personal Data and the Protection of Individuals with regard to the Processing of Personal Data (hereinafter referred to as the GDPR); and to Organic Law 3/2018 of 5 December 2018 on the Protection of Personal Data (hereinafter referred to as the GDPR).
guarantee of digital rights (hereinafter, LOPD).
Graphenus has a Data Protection Officer (DPO) in charge of supervising data protection compliance.
The actions of the group and all its employees in the processing of personal data are in line with the basic principles set out in Article 5 of the GDPR:
a) Principle of legality, transparency and fairness.
b) Purpose limitation principle. It implies that the data must be processed for specified, explicit and legitimate purposes, and prohibits the data collected from being further processed in a way incompatible with those purposes.
(c) Principle of data minimisation. Technical and organisational measures must be implemented to ensure that only data that are strictly necessary ('adequate, relevant and limited') for each purpose are processed.
d) Principle of accuracy. Data must be kept up to date and must be deleted or rectified if inaccurate.
e) Principle of limitation of the storage period. Once the purposes of the processing have been achieved, the data should be erased, blocked or anonymised.
f) Principle of integrity and confidentiality. The processing must ensure the integrity, availability and confidentiality of personal data.
The data controller shall be responsible for ensuring compliance with the above principles and for demonstrating compliance with them, in accordance with the principle of proactive responsibility. The General Management of Graphenus, consequently, with the above, is committed to the allocation of reasonable and proportional human and material resources for the achievement of the above objectives. The responsibility for the good functioning of the Information Security Management System falls, therefore, on the General Management, delegating to the Information Security Manager the necessary authority and competences for its effective implementation, its accreditation, its maintenance and improvement, counting, for this purpose, on the support of the management team and the Graphenus staff and collaborators.
Cookie | Duración | Descripción |
---|---|---|
cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category. |
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
CookieLawInfoConsent | 1 year | Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie. |
elementor | never | This cookie is used by the website's WordPress theme. It allows the website owner to implement or change the website's content in real-time. |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
Cookie | Duración | Descripción |
---|---|---|
_ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
_ga_SCQRDDZPR92 | 2 years | This cookie is installed by Google Analytics. |