Introduction
AIR FLOWS DATA PLATFORM SL, hereinafter AIRFLOWS, depends on information systems to achieve its objectives. These systems must be managed with due diligence, taking appropriate risk-based measures to protect them against accidental or deliberate damage that may affect the authenticity, traceability, integrity or confidentiality of the information processed, or the availability of the services provided.
The ultimate goal of information security is to ensure that the organization can meet its objectives, carry out its functions and deliver the services for which it was established, acting proactively, supervising daily activity and responding promptly to incidents.
ICT systems must be protected against rapidly evolving threats that may affect the confidentiality, integrity, availability, intended use and value of information and services. Defending against these threats requires a strategy that adapts to changing environmental conditions to ensure continuous service delivery. This means departments must apply the minimum security measures required by the National Security Framework (ENS), continuously monitor service levels, track and analyze reported vulnerabilities, and prepare an effective incident response to ensure continuity of services.
AIRFLOWS must ensure that ICT security is an integral part of every stage of the system lifecycle, from conception to decommissioning, including development or acquisition decisions and operational activities. Security requirements and funding needs must be identifiable and included in planning, requests for proposals and tender specifications for projects involving personal data, ICT services or services that affect information systems.
Document information
| Field | Value |
|---|
| Document | Information Security Policy |
| Document type | Regulatory framework |
| Classification | Public |
| Companies | AIR FLOWS DATA PLATFORM SL |
| Purpose | Establish the information systems security policy |
| Author | AIRFLOWS |
| Version | 1.1 |
| Status | Approved |
Review and approval
| Action | By | Date |
|---|
| Reviewed by | Security Officer / System Owner | 29/01/2026 |
| Approved by | Security Committee | 24/06/2026 |
Change control
| Version | Date | Author | Description | Status |
|---|
| 1.0 | 28/01/2026 | Telefónica consultants; Security Officer; System Owner; Information and Service Owners | Initial version | Review |
| 1.1 | 24/06/2026 | Security Committee | Formal approval by the Security Committee | Approved |
Scope
This policy applies to all AIRFLOWS information systems, to the people who make up the organization, and to AIRFLOWS ICT service providers or solution suppliers.
Information system of HIGH category pursuant to Royal Decree 311/2022.
Mission and objectives
At AIRFLOWS we define ourselves as a technology company specialized in the intelligent orchestration of operations through AI, by developing a product made available to customers via SaaS and different partners.
The security objectives that AIRFLOWS aims to ensure with this Policy are:
- Ensure the confidentiality, integrity and authenticity of information and continuity in the delivery of services.
- Implement security measures based on risk.
- Train and raise awareness among AIRFLOWS members regarding information security.
- Implement security measures that enable access traceability and respect, among others, the principle of least privilege, also reinforcing users’ duty of confidentiality regarding information they access in the course of their duties.
- Deploy and control physical security so that information assets are located in secure areas, protected by access controls, according to the risks identified.
- Establish security in communications management through the necessary procedures, ensuring that information transmitted over communications networks is adequately protected.
- Control the acquisition, development and maintenance of information systems throughout their lifecycle, ensuring security by default.
- Control compliance with security measures in service delivery, maintaining control over the acquisition and incorporation of new system components.
- Manage security incidents for their proper detection, containment, mitigation and resolution, adopting the measures necessary to prevent recurrence.
- Protect personal information by adopting technical and organizational measures according to the risks arising from processing, in line with data protection legislation.
- Continuously supervise the security management system, improving and correcting detected inefficiencies.
Guiding principles of the policy
- Strategic scope: information security must have the commitment and support of all levels of the organization and must be coordinated and integrated with other strategic initiatives in a coherent way.
- Comprehensive security: security shall be understood as a comprehensive process made up of all technical, human, material and organizational elements related to information systems, avoiding one-off or ad hoc actions. Information security must be part of day-to-day operations, present and applied from the initial design of ICT systems.
- Risk-based security management: managing security based on identified risks will maintain a controlled environment, minimizing the risks to which information and its systems are exposed; measures shall be proportionate to the risk they address and must be justified. Risks identified in the processing of personal data shall also be taken into account.
- Prevention, detection, response and preservation: by implementing preventive actions against incidents, minimizing detected vulnerabilities, preventing threats from materializing and, when they do, providing an agile response to restore information or services, ensuring secure preservation of information.
- Lines of defense: the organization’s security strategy is designed and implemented in layers.
- Continuous monitoring and periodic reassessment: the organization implements means to detect and respond to anomalous activities or behaviors, as well as others that allow continuous assessment of the security status of assets. There will also be a continuous improvement process for the periodic review and update of security measures according to their effectiveness and the evolution of risks and protection systems.
- Security by default and by design: systems must be designed and configured to ensure security by default. Systems shall provide the minimum functionality necessary to deliver the service for which they were designed.
- Separation of duties: pursuant to this principle, the functions of the Security Officer and the System Owner shall be separated.
Regulatory framework
The main regulations affecting this Policy are:
- Royal Decree 311/2022 of 3 May, regulating the National Security Framework (ENS).
- Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2), on measures for a high common level of cybersecurity across the Union.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), laying down harmonized rules on artificial intelligence.
- Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
- Organic Law 3/2018 of 5 December on Personal Data Protection and guarantee of digital rights.
- Regulation (EU) 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- Royal Decree 1007/2023 (Verifactu Regulation), on requirements for billing IT systems to prevent record alteration.
- Law 18/2022 (Crea y Crece Law), regulating the mandatory use of electronic invoicing in commercial transactions between companies and self-employed persons.
- Information Security standards, especially the latest versions of ISO/IEC 27001 and ISO/IEC 27002, as well as ISO/IEC 27034 (Application security).
Security organization
Taking into account the provisions of the ENS, the organization establishes the following actions to organize Information Security:
- It shall designate security roles: Service Owner(s), Information Owner, Security Officer, System Owner and Data Protection Officer.
- It shall establish an advisory and strategic body for decision-making on Information Security. This body shall be called the Information Security Committee.
Definition of ENS-related roles and responsibilities
Information Owner (RINF) and Service Owner (RSERV)
The functions of the Information and Service Owners shall be:
- Establish the security requirements applicable to information (information security levels) and to Services (service security levels), within the framework set out in Annex I of the ENS Royal Decree, and may request a proposal from the Security Officer taking into account the System Owner’s opinion.
- Decide on access rights to information and services.
- Accept residual risk levels affecting information and services.
- Inform the Security Officer of any change regarding the Information and Services under their responsibility, especially the addition of new Services or Information. The Security Officer shall report such changes to the Information Security Committee at its next meeting.
- They have ultimate responsibility for the use made of certain services and information and, therefore, for their protection.
Security Officer (RSEG)
The functions of the Security Officer shall be:
- Maintain and verify the appropriate security level of the Information handled and of the electronic Services provided by the information systems.
- Promote training and awareness on information security.
- Designate those responsible for carrying out the risk analysis and Statement of Applicability, identify security measures, determine required configurations and prepare system documentation.
- Approve the Statement of Applicability based on the security measures required under Annex II of the ENS, in a separate document.
- Provide advice for determining the System Category, in collaboration with the System Owner and/or ICT Security Committee.
- Participate in preparing and implementing security improvement plans and, where applicable, continuity plans, and validate them.
- Manage external or internal system reviews.
- Manage certification processes.
- Escalate to the Security Committee the approval of changes and other system requirements.
- Approve security procedures that form part of the Regulatory Framework (and are not within the Committee’s remit) and inform the Committee of modifications made during the current period.
- Participate in drafting, within the Information Security Committee, the Information Security Policy for approval by Management.
- Coordinate with the Committee Secretary the calling of meetings and preparation of the agenda: call meetings, prepare topics with timely information for decision-making, and draft meeting minutes.
- Is responsible for the direct or delegated execution of Committee decisions.
System Owner (RSIS)
The functions of the System Owner shall be:
- Develop, operate and maintain the information system throughout its lifecycle, preparing the necessary operating procedures.
- Define the topology and management of the Information System, establishing usage criteria and available services.
- Halt access to information or service delivery if aware of serious security deficiencies.
- Ensure that specific security measures are properly integrated within the general security framework.
- Provide advice for determining the System Category, in collaboration with the Security Officer and/or Information Security Committee.
- Participate in preparing and implementing security improvement plans and, where applicable, continuity plans.
- Coordinate the system security administrator’s functions: management, configuration and updating of security hardware and software; management of user authorizations and privileges, including activity monitoring; approve configuration changes; ensure strict compliance with controls and procedures; supervise installations, modifications and improvements; monitor security status; inform the Security Officer of anomalies, compromises or vulnerabilities; and collaborate in investigating and resolving security incidents.
Data Protection Officer (DPO)
The functions of the Data Protection Officer shall be:
- Inform and advise the organization and users involved in processing of their obligations under applicable Data Protection regulations.
- Supervise compliance with security regulations and the organization’s internal data protection policies, including allocation of responsibilities, awareness and training of staff involved in processing operations, and related audits.
- Provide requested advice on data protection impact assessments and supervise their implementation.
- Cooperate with the Spanish Data Protection Agency when required, acting as the point of contact on data processing matters.
- Perform their duties with attention to the risks associated with processing operations: gather information to determine processing activities; analyze and verify compliance; inform, advise and issue recommendations; supervise the record of processing activities; advise on data protection by design and by default; advise on impact assessments; prioritize activities based on risk; and advise the Controller on areas to audit, training and operations requiring more resources.
Information Security Committee
The organization has established an Information Security Committee composed of a Chair, a Secretary and Members. These members are classified as permanent or non-permanent according to whether participation is mandatory:
Permanent members:
- Chair.
- Security Officer.
- System Owner.
Non-permanent members:
- Service Owners.
- Information Owner.
- Data Protection Officer.
- Organization representatives and external specialists from the public or private sector whose presence is necessary or advisable due to their experience or connection with the matters discussed.
- Advisors deemed appropriate for the topics at hand (with voice but without vote).
Information and Service Owners shall be called by the Chair according to the matters to be discussed, representing the different ICT security areas. Each area shall be represented by one voting member, without prejudice to several representatives attending.
The Data Protection Officer shall participate with voice but without vote in Committee meetings when personal data processing matters are discussed, and whenever their participation is required. In any case, if a matter is put to a vote, the Data Protection Officer’s opinion shall always be recorded in the minutes.
The Committee Secretary shall issue meeting notices and take minutes. Persons whom the Chair deems appropriate may attend sessions as advisors.
Security Committee roles
- Chair: CEO
- Secretary: Head of Operations and Alliances
- Members: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations and Alliances
- System Owner: Head of Product Engineering
- Security Officer: CPO
- Data Protection Officer: external provider (Govertis)
- Information Owner: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations and Alliances
- Service Owner: Head of Product Engineering and Head of Operations and Alliances
Security Committee powers
The functions of the Security Committee shall be:
- Address the concerns of Senior Management and the different departments.
- Regularly report the status of information security to Senior Management.
- Promote continuous improvement of the Information Security Management System.
- Develop the evolution strategy regarding information security.
- Promote periodic audits to verify compliance with the organization’s security obligations.
- Approve information security documentation.
- Remain permanently informed of the regulations governing ENS Conformity Certification, including accreditation and certification rules, guides, manuals, procedures and technical instructions.
- Remain permanently informed of the list of accredited Certification Bodies and certified public and private organizations.
- Remain permanently informed of security certification schemes with which the Public Administration has mutual recognition arrangements or agreements.
- Propose guidelines and recommendations, to be recorded in the corresponding Committee meeting minutes, to which the Chair shall give a full response.
- Coordinate the efforts of the different areas on information security to ensure they are consistent, aligned with the agreed strategy, and to avoid duplication.
- Address Information Security concerns from the Administration and the different areas, regularly reporting the status of information security to Management.
- Resolve responsibility conflicts that may arise between different officers and/or departments, escalating cases where it lacks sufficient authority to decide.
- Advise on information security whenever required.
- Review the Information Security Policy prior to approval by the Superior Body.
Meeting frequency and adoption of resolutions
- The Information Security Committee shall meet at least once a year, without prejudice to more frequent meetings as needed to fulfill its purposes and powers.
- In any case, meetings shall be called by the Chair, through the Secretary, on the Chair’s initiative or by a majority of permanent members.
- Decisions shall be adopted by consensus of the permanent members.
Appointment and conflict resolution
- The creation of the Information Security Committee, the appointment of its members and the designation of the Officers identified in this Policy shall be carried out through an initial constitutive record.
- Named roles shall be renewed annually automatically. Departures or changes in designated roles shall be communicated to the Committee and the established channels followed to appoint the new officer.
- As regulated in Article 13.3 of the ENS Royal Decree, there shall be no hierarchical dependence between the RSEG and the RSIS, except for justified exceptions, which shall entail compensatory measures to ensure the purpose of the separation of duties principle.
- When a conflict arises between the security requirements established in this Policy and operational or business needs, any officer may escalate it to the Information Security Committee for resolution. The Committee shall decide by consensus and the decision shall be documented in the minutes of the corresponding session.
- In situations of operational urgency where the Committee cannot be convened immediately, the Security Officer may adopt a provisional measure, which must be documented and submitted for ratification by the Committee at the next ordinary or extraordinary session.
Processing of personal data
AIRFLOWS processes personal data as described in the Record of Processing Activities. AIRFLOWS shall assess the risks related to the personal data processed and propose an action plan to remediate risks that exceed the authorized threshold.
The risk analysis shall be reassessed periodically, with advice and supervision from the Data Protection Officer, and in any case when high-risk processing is detected, carrying out an impact assessment where appropriate. Implementation of the risk treatment plan shall be coordinated with that of the ENS, as well as with other security procedures or rules derived from data protection obligations, especially regarding control of service providers or response to incidents and/or security breaches.
Risk management
All systems subject to this Policy shall carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be repeated:
- Regularly, at least once a year.
- When there are changes in the information handled.
- When there are changes in the services provided.
- When a serious security incident occurs.
- When serious vulnerabilities are reported.
- When there are modifications to the data protection risk analysis or impact assessments.
To harmonize risk analyses, the Information Security Committee shall establish a reference valuation for the different types of information handled and the different services provided. The Security Committee shall foster the availability of resources to meet the security needs of the different systems, promoting horizontal investments.
Data protection risks shall be taken into account, with the opinion of the Data Protection Officer; risk treatment plans shall also be coordinated.
The Statement of Applicability (SoA) sets out the detail of National Security Framework controls applicable to the AIR FLOWS DATA PLATFORM SL information system, pursuant to Annex II of Royal Decree 311/2022, together with their applicability justification and maturity level.
Development of the Information Security Policy
This Information Security Policy shall be complemented by more specific documents (security standards, procedures and technical instructions) that help carry out what is proposed.
The body of rules shall be developed at three levels:
- First regulatory level: consisting of this Information Security Policy.
- Second regulatory level: consisting of security standards derived from the above, aiming to indicate the correct use of specific aspects of the information security management system.
- Third regulatory level: consisting of security procedures, guides and technical instructions. These are documents that, in compliance with the Information Security Policy, determine the actions or tasks to be performed in carrying out a process.
Management is responsible for approving the Information Security Policy, and the Information Security Committee is the body responsible for approving and disseminating the organization’s other documents, as established in Article 12 of the ENS Royal Decree.
Any change to it shall be disseminated to all affected parties.
Staff obligations
All members of AIRFLOWS are obliged to know and comply with this Information Security Policy and the standards, procedures or guides that develop it. It is the responsibility of AIRFLOWS, through the Security Committee and the people area, to provide the means necessary for the information to reach those affected.
All members of AIRFLOWS shall attend an information security awareness session at least once a year. A continuous awareness program shall be established for all AIRFLOWS members, particularly new joiners.
Persons with responsibility for the use, operation or administration of ICT systems shall receive training for the secure handling of systems to the extent needed to perform their work. Training shall be mandatory before assuming a responsibility, whether it is their first appointment or a change of role or responsibility.
Third parties
When AIRFLOWS provides services to other entities or handles their information, they shall be made aware of this Information Security Policy, without prejudice to data protection obligations if it acts as a processor in providing said services, and channels shall be established for reporting and coordination between the respective Security Committees and procedures for responding to security incidents. In addition, the Security Officer (or their delegate) shall be the Point of Contact (POC).
When AIRFLOWS uses third-party services or discloses information to third parties, they shall be made aware of this Security Policy and the Security Regulations applicable to those services or information, without prejudice to other data protection obligations. When contracting service providers or acquiring products, the contractor’s obligation to comply with the ENS shall be taken into account.
When acquiring rights to use cloud assets, the requirements set out in the security measures of Annex II and the development Guides shall be taken into account.
Such third party shall be subject to the obligations established in said regulations, and may develop its own operating procedures to meet them, so that AIRFLOWS can supervise them or request evidence of compliance, including second- or third-party audits. Specific incident reporting and resolution procedures shall be established and channeled through the POC of the third parties involved and, when personal data is affected, also through the Data Protection Officer. Third parties shall ensure that their staff are adequately security-aware, at least to the same level established in this Policy or as specifically required in the contract.
When any aspect of the Policy cannot be satisfied by a third party as required in the preceding paragraphs, the Security Officer shall issue a report specifying the risks incurred and how they will be treated. Approval of this report by the affected Information and Service Owners shall be required before contracting begins or, where applicable, before award. The report shall be forwarded to the organization’s representative, who must authorize continuation of the third-party contracting process, assuming the risks identified.
When the organization acquires, develops or deploys an Artificial Intelligence system, in addition to complying with applicable regulations, it shall have a report from the Security Officer, who shall consult the Information and Service Owners and, where necessary, the System Owner; the Data Protection Officer shall also issue their opinion.
Security incident management
AIRFLOWS shall have a procedure for the agile management of security events and incidents that pose a threat to information and services.
This procedure shall be integrated with others related to security incidents under other sectoral rules such as personal data protection or others affecting the organization, in order to coordinate the response from different perspectives and notify the relevant supervisory bodies without undue delay and, when necessary, the State Security Forces or the courts.
Approval and entry into force
This Information Security Policy is effective from its approval date on 24 June 2026, until it is replaced by a new Policy.