Skip to main content

US: (+1) 352 325 4171    |   SPAIN: (+34) 91 685 92 64    |    [email protected]

Information Security Policy

NBU Interactive S.L. and NBU Interactive USA LLC are committed to continuously protecting the confidentiality, integrity, and availability of the information they manage, as well as safeguarding the organization’s assets, employees, and digital environment.

This policy establishes the principles and guidelines for the secure management of information, in support of the company’s strategic and operational objectives. It covers all processes, information, and assets under NBU’s responsibility, including corporate systems, tools, devices, and equipment used in the office, workshop, and remote work environments, and is established taking into account the organization’s context and the needs of relevant stakeholders.

This commitment is realized through the implementation and maintenance of an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022, based on risk management and the application of technical, organizational, and procedural controls appropriate to the organization’s context, associated risks, and dependencies on third parties, including cloud service providers where applicable.

Within this framework, NBU is committed to complying with applicable legislation and requirements related to information security and the protection of personal data (including GDPR and LOPDGDD where applicable), as well as contractual requirements and commitments made to clients, suppliers, and other stakeholders.

To ensure the effectiveness of the ISMS, the organization establishes a systematic approach to identifying, assessing, and addressing risks that may affect information security, and maintains capabilities for incident detection, response, and recovery. Furthermore, it promotes awareness and ongoing training for employees and collaborators, encouraging their active participation and compliance with established guidelines.

The policy provides the framework for defining, communicating, and evaluating measurable information security objectives that are consistent with the business strategy and organizational context, aimed at improving performance and reducing risks.

The Management of NBU Interactive S.L. and NBU Interactive USA LLC. The company is committed to providing the necessary resources, leading by example, and periodically reviewing this policy and the ISMS to ensure they remain relevant, effective, and aligned with the organization’s objectives and the needs of stakeholders.

This policy will be reviewed at least annually or in the event of significant changes, communicated throughout the organization, and made available as documented information in the corporate document repository. It will also be made available to relevant stakeholders as appropriate.