Information security policy
1. Statement of intent
GHI Smart Furnaces, S.L. recognises that information is a critical asset for its business and services. It is therefore committed to protecting the confidentiality, integrity and availability of the information it manages, its own and that of its clients and partners.
2. Scope
This policy applies to all information systems, technology assets, personal data and processes related to the development, operation and maintenance of the Beyond platform, and to all employees, partners and suppliers who access those systems.
3. Governing principles
- Confidentiality: information is accessible only to authorised people.
- Integrity: information is kept complete and accurate; changes are controlled and audited.
- Availability: systems and data are available to authorised users when needed.
- Traceability: actions on systems are logged to enable audits.
- Continuous improvement: security is reviewed regularly against new threats and requirements.
4. Regulatory framework
- GDPR (EU) 2016/679
- Spanish Organic Law 3/2018 (LOPDGDD)
- Royal Decree-Law 12/2018 on network and information systems security
- National Security Framework (RD 311/2022), where applicable
5. Measures applied
- Encryption in transit via TLS 1.2 or higher.
- Multi-factor authentication (MFA) on internal systems.
- Access management on a least-privilege basis.
- Backups with integrity verification.
- Continuous security-event monitoring.
- Vulnerability and patch management.
6. Incident notification
If you detect or suspect a security incident, report it immediately to marketing@ghifurnaces.com with the subject SECURITY INCIDENT. GHI manages incidents within GDPR timeframes, notifying the AEPD within 72 hours where applicable.
7. Responsibility and review
Responsibility for this policy rests with the Management of GHI Smart Furnaces, S.L. The policy is reviewed at least once a year or when there are significant changes in systems, regulations or the threat context.