The purpose of this legal disclaimer is to tell you who we are, how you can contact us, and what the rules and contents of our websites of https://www.paradigmadigital.com/ https://goodly.tech/ and https://pleg.com (hereinafter, “our websites”, the “Website”) are. Please read this Legal Disclaimer and our Privacy Policy carefully as these are the rules that govern our website. Access to this website and its contents is free but it implies that you have read and accept this Legal Disclaimer and our Privacy Policy. If you do not agree with any of them, please do not use the website or the services we provide through it. Please note that you can access our Cookies Policy by clicking on this link.
Who are we and what do we use this website for?
https://www.paradigmadigital.com/ (hereinafter, the “Website”) is the property of Paradigma Digital, S.L. (hereinafter, “Paradigma” or we), a company with registered office at Edificio Ática 2, Vía de las Dos Castillas, 33, Pozuelo de Alarcón 28224, Madrid, Spain, tax identification code B84946656 and e-mail address info@paradigmadigital.com. Paradigma is registered with the Mercantile Registry of Madrid, in Volume 23,604, Book 0, Sheet 195, Section 8, Page M-423565. Through our Website we provide information about our specialized services and contents, subject to the rules that we have set forth below. We reserve the right to deny, suspend, interrupt or cancel access to or the use of this Website, in whole or in part, to those users or visitors who fail to comply with any of the conditions provided for in this Legal Disclaimer or our Privacy Policy. In our Website we may include materials such as articles, studies, project descriptions, and so on for information purposes only. We may modify, develop or update these materials at any time without notice. We periodically update this Legal Disclaimer and our Privacy Policy, so those which are in force and published at the time of use of the Website shall apply. If you have any questions regarding this Legal Disclaimer or the Privacy Policy, you can contact us by sending an email to dpo@paradigmadigital.com.
What is our intellectual and industrial property policy regarding the Website?
This Website and all its contents, its structure and its design, as well as its graphic design and source code, its brands, commercial names and/or distinctive signs, are protected by intellectual and industrial property rights, which are held by Paradigma or by third parties. Accessing or using the Website shall not be considered in any case a waiver, transfer, licence or total or partial assignment of said rights by Paradigma. The removal or manipulation of this Legal Disclaimer, the Privacy Policy and any other piece of identification data pertaining to the rights of Paradigma or its respective owners (including the contents and products) is strictly forbidden. Reproducing, transforming, distributing, publicly communicating, making available to the public or exploiting in any other form our Website, its contents, its design and/or the presentation and form of its materials, by any procedure, is strictly forbidden unless you obtain our prior express authorisation. In any case, you must refer to our ownership of the rights.
How should you use the Website?
We allow our users to upload content to some parts of our Website, such as the blog. We expect you to use it properly and will reject uses such as the following:
- Posting commercial communications on the Website.
- Collecting contents or information about other users
- Uploading viruses or malicious code of any kind.
- Requesting login information from or accessing an account belonging to another user.
- Causing Destroying, altering, rendering useless or damaging, by any means, the data, programmes or electronic documents of Paradigma, its providers or third parties, as well as introducing or spreading over the Internet programmes, viruses or any physical or electronic instrument that causes or is capable of causing any type of alteration in the network, system, or equipment of Paradigma or of third parties.
- Bothering, intimidating or harassing any user.
- Performing illegal, misleading, malicious or discriminatory acts on the Website as defined by these conditions and the Spanish legal system.
- Decompiling, disassembling, reverse engineering, sublicensing or transmitting in any way, translating or making works stemming from the computer programmes that are necessary for the operation of and to access and use this Website and the services contained therein, as well as performing, with respect to such programmes, any of the acts of exploitation described in the preceding paragraph.
As a user of the Website, keep in mind that you are not allowed to remove, alter, circumvent or tamper with any protective device or security system that may be installed thereon. We reserve the right to interrupt access to all or part of the Website at any time and without prior notice, whether for technical, security, control or maintenance reasons or due to power outages or any other reason, if we can not guarantee the availability or the continuity of the Website or its contents. Therefore, we do not assume any responsibility for any service interruptions, delays, errors, malfunctions of the Website or any incidents stemming from causes beyond our control. We are not responsible for damages of any kind that might be caused by a lack of availability of the Website, the transmission of viruses or malicious or harmful programmes in the contents, despite having taken all technological measures to prevent this, or the improper use that is made of them, their being the exclusive responsibility of the person who accesses or uses them. As a user of the Website, you undertake to defend and indemnify Paradigma and its directors, employees, contractors, agents, suppliers, providers, licensors, successors and assignees and to hold them harmless from and against any and all losses, claims, lawsuits, liabilities and damages, including any legal fees arising out of or in connection with your illegal access to or use of the Website, any false accusations you make against us or your failure to comply with this Legal Disclaimer or our Privacy Policy.
How do the links and comments on our Website work?
Links We do not control other websites and contents that may be available on our Website through links and, hence, we shall not assume any responsibility whatsoever for the information contained therein. The presence of these links is for information purposes only and does not constitute a suggestion, invitation or recommendation on our part or imply any kind of association, merger or participation with the linked entities. Should you discover that any link redirects you to pages with illegal, harmful, denigrating, violent or immoral services or contents, contact us at dpo@paradigmadigital.com indicating the following in your message:
- Your full name, address, phone number and email address;
- a description of the facts that reveal the illegal or improper nature of the link in question;
- If any rights, such as intellectual and industrial property rights, are violated, the personal data of the holder of the infringed right – if they are a person other than you. You must also provide proof of ownership of the rights and, where applicable, of the right of representation enabling you to act on behalf of the holder.
- The receipt by us of the type of communication provided for in this clause shall not entail, in accordance with the provisions of the regulations relating to the information society and e-commerce services, the effective knowledge by us of the activities and/or contents indicated by the communicator.
Comments Paradigma rejects any responsibility for the opinions expressed by users on its Website, the individuals who make the statements being responsible for them.
What is the applicable legislation and which courts are competent to resolve the matters arising from the use of the Website?
The use of the Website is governed by Spanish law. Any dispute arising from or in connection with the use of the Website shall be subject to the jurisdiction of the Courts and Tribunals of the city where Paradigma has its registered office – unless the regulations in force establish a different forum.
Privacy Policy of Paradigma Digital, S.L.’s Websites
PARADIGMA DIGITAL, S.L. (hereinafter, "PARADIGMA" or us) is aware of the importance for you of the use we make of your personal information and the way in which we share it. This document details the Privacy Policy that is always in force, and the user is obliged to review said text periodically to verify that they are satisfied with it.
From the moment you visit the pages https://www.paradigmadigital.com/, https://goodly.tech/ and https://pleg.com (hereinafter, “our websites”), you accept and consent to the conditions described in this Privacy Policy. Please, in case you do not agree with our Privacy Policies, do not continue browsing our websites or do not include information in the forms. We update our Privacy Policy and our Legal Notice periodically and we will apply the latest version that we have uploaded in each case.
Who is responsible for the data?
PARADIGMA DIGITAL, S.L. is responsible for the personal data collected through our websites. Our websites are the property of PARADIGMA. You can find all our contact information in the footer of our websites. The purpose of this Privacy Policy is to explain to you how we collect your personal data and how we treat it. In addition, this policy is also intended to explain what rights you have as a user of our websites and how to exercise them. We are committed to protecting your privacy online and we want to ensure that we will use your data in a transparent and secure way, respecting current legislation on the protection of personal data and adopting the necessary legal, technical, and organizational measures to avoid damage, alterations, or loss of personal data of our customers.
For what purpose do you provide us with the data?
The data that you provide through the forms available on the portal are necessary to be able to fulfil the purposes of the forms that we indicate in each of them, and which are:
- The "Contact" form is created to respond to all requests related to the Contents and Services we offer.
- The "Events" forms are created to send you information about the Paradigma events to which you are registered or that may be of interest to you. In case you have indicated it, we will keep you informed about our job offers, by contacting the email you have indicated to register for the event, or through your LinkedIn profile. "
- The "Ebook" form is created so that interested users can have access to our Ebooks of their interest.
- The "Employment" form is created to evaluate your candidacy for possible vacancies at Paradigma Digital.
- The “Newsletter” Form allows you to subscribe to our database so that we can send you the Paradigma Newsletters that may be of interest to you.
In each of the forms you will be informed of the mandatory or optional nature of your answers by including an asterisk. If you do not provide us with any of the information that we ask for, we cannot guarantee to meet the request or provide the service that corresponds to each form. The data that you provide us in no case will be used for purposes other than those that we indicate in each case.
How long will we keep your data?
The personal data provided will not be kept for longer than is necessary for the purposes of the treatment and, specifically, regarding the data that we request in each of the forms:
- Data of your contact requests: we will keep your data until we have processed your request or answered the information for which you contacted us.
- Data for subscription to events: we will keep your data until you ask us to unsubscribe from the link available in the corresponding communications.
- Data for e-book subscription: we will keep your data until you ask us to unsubscribe from the link available in the corresponding communications.
- Job application data: we will keep your data for a maximum of two years.
- Newsletter subscription: we will keep your data until you ask us to unsubscribe in the corresponding communications.
If you revoke your consent to the processing of your personal data, we will proceed to delete your data. This means that we will not be able to access your information and it will only be stored during the periods established by the applicable regulations to be able to respond to requests from the competent authorities and attend to possible responsibilities derived from the treatment.
What is our legitimacy for the treatment?
The legal basis for the treatment of your data is your consent. You can revoke it at any time, but the data processing for this purpose carried out previously will not lose its legality since the consent has been revoked.
Who do we communicate your data to?
PARADIGMA will not transfer the personal data of the users to any third party without a legal basis that legitimizes this treatment. This means that we will not share your personal data with third parties except for:
In the case of the "Events" forms, if we work with other companies in the organization, we can transmit your data to them with the sole purpose of being able to manage your registration for the event.
In the case of the “Employment” forms, we may communicate your data to the companies that are part of the Paradigma Business Group and to the Paradigma Clients in which the services are to be provided or may be provided.
When we have a legal obligation to do so, we can communicate your data to the authorities and entities that require it.
The correct provision of the services requested by the user. The PARADIGMA treatment managers, that is, the service providers who must access your personal data to perform the functions for which they were hired, may have access to your personal data. In addition, we want to inform you that with these service providers contracts are signed for treatment managers that cover all the appropriate security measures to guarantee the protection of your data in accordance with current data protection regulations. Our data processor is Hubspot, Inc. You can access Hubspot's privacy policy here.
We will not make international transfers of your personal data apart from the cases that we have just indicated.
What are your rights as the owner of personal data?
As a user of our websites, you have the right to exercise the following rights by sending an email to dpo@paradigmadigital.com:
- Right of access: you have the right to request information about what personal data of yours we are processing, if any. The information that we can give you in this regard is what data it is, for what purpose we use it or if we have communicated it to third parties or managers, among other aspects.
- Right of rectification: it is necessary that the information you provide us is correct and exact. In case you think that we must rectify any data, you can ask us to correct it as soon as possible.
- Right of deletion and limitation of treatment: in case you do not want us to continue using your data, or that we only use it for limited purposes, you can exercise this right by indicating if you want us to proceed in this way either because you do not want us to continue treating the data. data for the purpose for which we collect them or because the reason for their treatment has disappeared.
- Right of opposition and not to be the subject of individualized decisions: we will not treat your information in any case if you object to the treatment, nor to make individualized decisions or develop personalized profiles.
Privacy Policy regarding the processing of customer data
Identity: Paradigma Digital S.L.
NIF: B84946656
Postal address: Ática 2 Building, Vía de las Dos Castillas, 33, Pozuelo de Alarcón 28224, Madrid, Spain
Telephone: 913 525 942
Email: dpo@paradigmadigital.com
Purposes of the treatment
The personal data that may be provided during the contracting and execution phases of the contract will be processed for the following purposes:
- Presentation and management of the offer directed to the client.
- Management, development, and fulfillment of the Contract.
- Compliance with applicable legal obligations.
- Have a uniform relationship of Clients and / or Suppliers, respectively, for the maintenance of the commercial relationship and inform, where appropriate, of products and / or services related to the object of the Contract that may be of interest to them.
Legal basis for the processing
The legitimacy of the treatments is, respectively, the execution of the Contract, the fulfillment of the applicable legal obligations, the legitimate interest in managing the relations with its Clients and / or Suppliers, and the consent, where appropriate. Profiles will not be made from the information obtained, nor will automated decisions be made.
If the data provided refers to individuals other than the participants in the processes described, the client must inform them in advance of the provisions set forth in this clause. The Parties guarantee the accuracy and veracity of the personal data provided, committing to keep them duly updated and to communicate any variation that occurs in them.
Likewise, in the cases in which, during the provision of services, the Provider conducts evaluations of the degree of Customer satisfaction that may involve processing of Personal data, the Provider will previously inform the interested parties of said circumstance. The legal basis of the treatment in these cases is the legitimate interest of the Provider in knowing the degree of satisfaction of the Client with the services provided. In any case, the information that is treated in relation to these evaluations will be strictly confidential, both with respect to the Provider and the Client´s data.
Retention period
The data will be kept for the time necessary for the execution of the contract and the fulfillment of the respective legal obligations, as well as, in relation to the maintenance of the Client / Supplier commercial relationship, if its deletion is not requested. The Parties will implement all the security measures that are necessary to protect the data against any type of unauthorized, accidental, or illegal access, partial or total destruction, loss, or alteration. After the indicated deadlines, they will be deleted, unless they must be kept restricted to comply with the applicable legal obligations.
Communications and transfers
No international data transfers will be made, except for those necessary for the execution of the service or where there is a legal obligation. In any case, it is guaranteed that such communications will be made to entities and complying with the requirements imposed by Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016 (RGPD) and other applicable legislation.
Exercise of rights
The owners of the Data may exercise their rights of access, rectification, cancellation, deletion, opposition, and limitation to treatment, as well as portability, unless they are subject to individualized automated decisions, and any others that may be applicable, in relation to the treatment of your personal data. For this purpose, the following channels may be used, accompanying a photocopy of the DNI or any other document that allows proof of identity:
Email: dpo@paradigmadigital.com
Postal Address: Paradigma Digital, S.L. Vía de las Dos Castillas, 33, Ática, 2, 28224 Pozuelo de Alarcón, Madrid.
If you consider that you have not obtained satisfaction in the exercise of your rights, you may file a claim with the competent Supervisory Authority.
If you consider that your rights have been violated, you can file a claim with the Spanish Agency for Data Protection on the website www.agpd.es.
Privacy Policy for Data Processing: Candidates
In compliance with the General Data Protection Regulation (GDPR) 2016/679 and other applicable data protection regulations, we provide the following information and necessary authorizations regarding the processing of your personal data during the selection process:
Identity: Paradigma Digital S.L.
NIF: B84946656
Postal address: Ática 2 Building, Vía de las Dos Castillas, 33, Pozuelo de Alarcón 28224, Madrid, Spain
Telephone: 913 525 942
Email: dpo@paradigmadigital.com
Purposes of the treatment
To assess and manage the candidate's application in both current and future recruitment processes at Paradigma and, where applicable, to carry out the necessary steps for selection and hiring.
Legal basis for the processing
The candidate´s consent, which may be withdrawn at any time. However, withdrawing consent will result in the application not being considered in our selection processes.
Source of Data
The candidate has provided their data through participation in one of Paradigma’s selection processes or via one of our employment contact channels (job portals, referrals from Paradigma employees, recruitment agencies we collaborate with, or employment databases such as InfoJobs or LinkedIn).
Retention period
Candidates authorize the retention of their data for future selection processes for a maximum period of two years if not selected in the current process. If the candidate does not wish for their data to be retained, they may indicate so by selecting the corresponding checkbox or by withdrawing consent by contacting people@paradigmadigital.com or as outlined in the “Exercise of Rights” section.
Data Recipients and Transfers
Companies within the Paradigma Group (Grupo Indra) and Paradigma clients where services are or may be provided, to assess the candidate’s suitability.
Exercise of Rights
Interested parties may exercise their rights of access, rectification, deletion, restriction, data portability, objection, and the right not to be subject to automated individual decision-making. They may also withdraw their consent by contacting dpo@paradigmadigital.com or in writing to Paradigma Digital S.L., Vía de las Dos Castillas, 33, Ática, 2, 28224 Pozuelo de Alarcón, Madrid.
Contact
Privacy Policy for Data Processing: Suppliers
Identity: Paradigma Digital S.L.
NIF: B84946656
Postal address: Ática 2 Building, Vía de las Dos Castillas, 33, Pozuelo de Alarcón 28224, Madrid, Spain
Telephone: 913 525 942
Email: dpo@paradigmadigital.com
Purposes of the treatment
To manage the relationship with suppliers, including communication with their representatives and contact persons, administrative, accounting, and tax management, service evaluation, invoicing, and compliance with applicable legal obligations.
Legal basis for the processing
Execution of a contract when processing is necessary for service provision or goods supply.
Compliance with legal obligations, such as those derived from tax and accounting regulations.
Legitimate interest of Paradigma in managing supplier relationships and informing them about related products and services. No profiling or automated decision-making will be conducted based on the provided data.
Source of Data
The data processed has been provided directly by the supplier or their representatives in the context of the business relationship, or it may have been obtained from publicly accessible sources in the case of supplier companies.
Retention Period
Data will be retained for the duration of the contractual relationship and, once concluded, for the periods required by applicable regulations. If there is no formal contract, data will be retained as necessary to manage the business relationship or until deletion is requested.
Data Recipients and Transfers
Companies within the Paradigma Group (Grupo Indra) and public administrations, banks, and financial entities when necessary for compliance with legal or contractual obligations.
Paradigma Digital S.L. clients when necessary for service provision and business relationship management.
Exercise of Rights
Interested parties may exercise their rights of access, rectification, deletion, restriction, data portability, objection, and the right not to be subject to automated individual decision-making. They may also withdraw their consent by contacting dpo@paradigmadigital.com or in writing to Paradigma Digital S.L., Vía de las Dos Castillas, 33, Ática, 2, 28224 Pozuelo de Alarcón, Madrid.
Information Security Policy at Paradigma Digital
Purpose
The purpose of Paradigma Digital's Information Security Policy is to establish the guidelines and objectives necessary to protect the confidentiality, integrity, and availability of information within the organization. This policy ensures that all employees, contractors, and third parties understand and assume their responsibilities regarding information protection.
This policy reflects the commitment of Paradigma Digital's management to information security, as well as to the specific security policies and regulations referenced herein.
Scope
This policy applies to all information and information assets belonging to Paradigma Digital, including but not limited to electronic and printed data, systems, infrastructure, equipment, networks, applications, and third-party services. Furthermore, it applies to all employees, contractors, and third parties who access, handle, or manage the organization's information. In particular, it applies to:
- All information for which our organization is responsible, as well as any information we may have access to within the services we provide to our clients, regardless of the medium on which it is stored.
- Any electronic or computing device, or network resource that forms part of the corporate IT infrastructure, as well as proprietary or acquired software used in the company's daily operations.
- Paradigma Digital employees and professionals working for us under any arrangement, provided they may have access, in any manner, to the aforementioned information.
This document and other related Paradigma policies must be shared with stakeholders as necessary.
General Principles
Information security consists of a set of measures and actions aimed at ensuring that the organization's information is maintained in its intended state, preventing its use and access from deviating from authorized purposes. To achieve this, five fundamental dimensions guide the security principles:
- Availability. Information and systems shall be available to authorized personnel whenever needed for the proper operation of the organization.
- Integrity. Information must only be modified by authorized users or processes, and must not undergo accidental changes. Therefore, the necessary measures will be taken to protect the accuracy and completeness of the information, preventing any unauthorized alteration.
- Confidentiality. Information must only be accessible to authorized users or processes. In this regard, the confidentiality of the information will be guaranteed and protected from unauthorized access.
- Auditability. It must be possible to know the history of actions that led to the current state of the information.
- Authenticity. The identity of the sources or recipients of the information must be guaranteed.
This Information Security Policy reflects Paradigma Digital's main concerns regarding these dimensions, establishing the guidelines to address them in a way that keeps the risk of security incidents under control.
Thus, this policy provides guidance and support for information security management, aligned with business needs and in compliance with current laws and regulations. All security-related actions must comply with this policy, which serves as a fundamental reference to guide decisions and resolve any doubts that may arise during the execution of security measures.
Objectives
Paradigma's Information Security Policy is the framework and top-level document from which all other specific information security policies for different areas are derived. Its objective is to establish a set of specific policies, procedures, and security measures designed appropriately and proportionally to the risks associated at any given time.
Specifically, the objectives of this policy are:
- To ensure compliance with legal and regulatory standards related to information security, such as ISO 27001 and the Spanish Organic Law on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
- To protect the availability, confidentiality, integrity, Auditability, and authenticity of Paradigma Digital's and its clients' information assets against internal and external threats and vulnerabilities.
- To reduce the impact of potential security incidents, including the loss, theft, or unauthorized disclosure of sensitive data.
- To foster a culture of security and responsibility throughout the organization, including employees and contractors, through awareness and training.
- To define roles and responsibilities regarding information security management.
- To promote the commitment to satisfy applicable requirements and the continuous improvement of the information security management system.
Roles and Responsibilities
- Paradigma Digital’s Management Committee: Review and approve Security policies, and commit to their execution by allocating the necessary resources.
- Chief Information Security Officer and Cybersecurity team: Establish and review security guidelines. Ensure proper dissemination within the organization and oversee the implementation of and compliance with this policy, as well as its associated procedures and measures, in addition to coordinating risk management activities.
- Data Protection Officer: Responsible for maintaining compliance with relevant laws and regulations regarding data privacy and information security.
- All Employees and contractors: Accept and comply with security policies and procedures, and report any security incident or suspicious activity to the Paradigma Cybersecurity team. Additionally, they must cooperate during the investigation and resolution of incidents.
- Suppliers and Third parties: Suppliers and third parties handling Paradigma's information must immediately report any security incident that affects or could potentially affect the organization's systems, collaborating in the investigation and response to these events.
Security organization
The organization of security at Paradigma is structured around several specialized committees that ensure the integration and effectiveness of security at all levels.
- Strategic Cybersecurity Committee: This committee is responsible for aligning security with business goals and strategic decisions. Its duties include:
- Integrating security into the business strategy from the outset.
- Evaluating the impact of strategic decisions on security and vice versa.
- Establishing guidelines for the implementation of secure technologies.
- Ensuring that security is aligned with the company's objectives and strategy.
- Cybersecurity Committee: As the core governing body, it is responsible for establishing and reviewing security policies, assessing and managing risks, ensuring regulatory compliance, reviewing the impact of incidents, and coordinating corrective actions. It also defines and oversees security training programs as well as security commitments in contracts and projects.
- Cybersecurity operational meetings: These are the forums where operational security measures for systems and projects are designed, implemented, and managed. Their duties include:
- Implementing and managing operational measures to guarantee security.
- Developing and reviewing procedures and guides related to the Information Security Policy and Specific policies.
- Coordinating and responding to security incidents.
- Overseeing and supporting continuous security training and awareness.
- Managing and keeping Paradigma's assets (systems, firewalls, applications, etc.) up to date to mitigate risks and vulnerabilities.
- Providing support and guidance throughout projects (KPIs, audits, etc.).
Basic principles
The general principles governing actions related to information security at Paradigma are as follows:
- Risk-Driven Governance. The Management Committee must know at all times the state of risk to which information is exposed, and must provide the means to maintain it within acceptable limits through prevention, detection, response, and incident recovery measures. This must be the primary criterion guiding actions aimed at improving security.
- Secure by Default. All systems and products used or developed at Paradigma must be secure by default. In particular, it must be taken into account that Paradigma is primarily dedicated to developing applications to manage its clients' information, which are often deployed on infrastructures designed and managed by Paradigma. Therefore, security must be considered a fundamental requirement from design through to the end of support.
- Shared Responsibility. Security is everyone's business. It is important that all Paradigma employees remain aware of this, integrate security into their daily work, consult on their doubts, and report any flaws or deficiencies they find so that appropriate measures can be taken to keep risk under control.
- Non-intrusive Security. Since its inception, Paradigma has been an agile company, and security should impact the working capacity of teams as little as possible. This must be an important criterion to consider when multiple alternatives exist for controlling risks.
- Agile Decision-Making. Security decision-making must remain agile. Efforts should be made to resolve each problem only once, and to reuse lessons learned when a similar case arises. To achieve this, whenever possible, assessments and classifications of security needs will be carried out by categories.
- Legal Compliance. Security must comply with legal requirements, especially those relating to personal data protection (the Spanish Organic Law on Data Protection and Guarantee of Digital Rights, and the European General Data Protection Regulation) and intellectual property. Furthermore, if they can serve as a guide, other legal frameworks should be taken into account, even if they do not directly apply to our organization, such as the National Security Scheme (ENS).
- Measurable Effectiveness. The effectiveness of security must be measured. KPIs must be established and periodic assessments taken to understand the current state of security and how it evolves over time.
- Privacy Safeguards. Maintaining security can often involve accessing sensitive information for individuals or the organization, whether intentionally or accidentally. It is strictly forbidden to use implemented security mechanisms to intentionally invade user privacy, except in the course of a police investigation or by judicial order. Personnel will be notified regarding implemented measures that could at any point constitute an invasion of their privacy.
- Principle of Least Privilege. By default, each person will only have access to the minimum information necessary to perform their duties, for which appropriate access control measures will be established.
- Identification and Accountability. By default, access control systems will be configured to identify the authors of actions performed on information or systems, avoiding the use of shared credentials except in duly justified cases. User and process activities will be logged for incident investigation purposes.
Policy framework
Paradigma's Information Security Policy is the master document and top-level policy, from which all other regulations and security documents are derived. These specific policies elaborate on concrete points within each area and must comply with and support the general principles established in this document.
Each document will have an owner who must:
- Ensure that it is understandable, pragmatic, enforceable, adequate, and proportionate, and that it is made available to the relevant personnel (who may be internal or external to the organization).
- Review and maintain the documents in accordance with the document on the Cybersecurity Documentation Lifecycle.
- Manage the registration, authorization, and tracking of exemptions and exceptions.
Both this policy and its derived documentation must be approved following the guidelines indicated in the corresponding documentation management standard and will be available to all personnel on the corporate intranet.
Any security policy generated and approved by the committee must be read, understood, and complied with by all personnel.
- Through security regulations or standards, applicable to a specific area, such as vulnerability management, risk management, continuity management, etc.
- Through procedures, guides, manuals, or technical documents that expressly state how to perform the requirements set by a standard (for example, workstation hardening, incident notification, etc.).
The general areas to be addressed within Paradigma's Information Security Management System are detailed below:
- Information Security Governance
- Risk Management
- Access Control
- Incident Management
- Continuity Management
- Data Protection
- Application and Supplier Approval
- Physical and Environmental Security
- Cryptography and Key Management
- Classification and Handling of Assets and Information
- Secure Development
- Communications Security
- Operations Security
- People Management
- Regulatory Compliance
Within the domains indicated above, the standards, procedures, manuals, and templates relating to each point of the regulatory framework are developed.
Review of Information Security Policies
A review of all documentation within the regulatory framework is conducted at least once a year, or whenever significant changes occur. This is done in alignment with the procedure relating to the Lifecycle of Security Documentation.
The purpose of this standard is to ensure that the organization's information security policies are reviewed at planned intervals and kept up to date in the face of various technological, organizational, or regulatory changes, guaranteeing their continuous suitability, adequacy, and effectiveness.
Compliance
All employees, contractors, and third parties with access to Paradigma Digital's information assets must comply with this policy and its related standards and procedures. Non-compliance may lead to disciplinary actions and, in severe cases, the termination of the employment or contractual relationship.
The Cybersecurity team will measure and verify compliance with the Security Policies through controls, assessments, and internal or external audits as determined.
Consequences of Non-Compliance
Non-compliance with Paradigma's security policies and standards can lead to legal, reputational, and financial consequences for the company. Any violation of this policy or existing standards by an employee may result in an investigation and the enforcement of disciplinary measures, in accordance with the organizational Disciplinary Process.
Furthermore, at a technical level, violations of security policies and standards may lead to the immediate suspension of access privileges to Paradigma's network, systems, and applications.
It is the responsibility of all employees to report any concerns regarding ethical code violations or suspected breaches of law or applicable regulations. Paradigma strictly prohibits any retaliation against employees who report an ethical violation or a suspected legal breach in good faith. Any retaliation will be penalized with disciplinary measures, which could include dismissal.
Exceptions handling
Exceptions to security policies, standards, and procedures must be approved by the Chief Information Security Officer and formally documented. Such exceptions must be justified, including an assessment of the associated risks and the additional control measures that will be implemented to mitigate those risks.
Exceptions must be temporary and will be subject to periodic review.
Policy approval and communication
This policy has been approved by Paradigma Digital’s Management Committee, becomes effective on the date of its publication.
This Policy, together with all other Information Security Policies, will be communicated to all employees, contractors, and stakeholders, and will be made available on the Paradigma Intranet to ensure compliance and dissemination.
Contact
dpo@paradigmadigital.com
Code of Ethics
Our Code of Ethics is publicly available for review at any time. You can take a look at it here.