Security Policy
Public document (Web)
Last updated: 30/01/2026
Introduction
At AFACIS, as specialists in technology consulting, implementation, support and migration of Blue Yonder solutions, we are fully aware of the strategic value of the information we manage.
The confidentiality, integrity and availability of our clients' and partners' data are the fundamental pillar of our operational activity. For this reason, AFACIS Management leads and implements an Information Security Management System (ISMS) based on continuous improvement and aligned with the most demanding international standards.
Regulatory Framework
The reference regulatory framework includes the following legislation:
- REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).
- Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
- International Standard ISO/IEC 27001:2022
- International Standard ISO/IEC 27002:2022
Our Fundamental Principles
All of our technical and operational consulting activity is governed by four non-negotiable principles:
● Confidentiality: We guarantee that project information and the logistics know-how of implementations is only accessible to strictly authorized personnel and under strict non-disclosure agreements (NDAs).
● Integrity: We ensure that system parameterization and data flows are accurate, controlled and fully protected against any unauthorized or accidental alteration.
● Availability: We maintain a resilient digital infrastructure and business continuity plans to ensure that our support and consulting services do not suffer critical interruptions.
● Regulatory Compliance: We scrupulously respect the applicable Legal Framework, including the GDPR (EU 2016/679), the LOPDGDD (3/2018) and the guidelines of the ISO/IEC 27001:2022 standard.
Security Organization
At AFACIS, the fundamental objective of the security strategy is to ensure business continuity, preserve the confidentiality, integrity and availability of information, and minimize the risk of damage by preventing security incidents and reducing their potential impact when they are unavoidable.
Since AFACIS is made up of four founding partners, the senior management and operational supervision functions of the Security Committee are assumed collegially, guaranteeing a direct commitment to the scope of the system. It is thereby ratified that AFACIS's Senior Management and Information Security Committee are collegially composed of the four founding partners.
The ISMS roles are defined as follows:
● Governing Body and Security Committee: Founding partners of AFACIS
● ISMS Manager (RSGSI): Partner with a technical, documentation-focused profile
● Security Officer: Partner with a technical profile
● Remaining Partners: asset owners, part of the decision-making process
● Information Users
Native Security in the Digital Environment
Operating under an agile, 100% remote organizational model, we have moved traditional security controls directly into the workstation environment and cloud infrastructure:
● Endpoint Protection: All workstations of our partners and collaborators feature full encryption of data at rest and advanced protection systems against malicious code (malware).
● Strict Access Control: We internally apply the principle of "least privilege" and "need to know". All access to corporate and client cloud environments requires named identities protected by Multi-Factor Authentication (MFA) systems.
● Environment Isolation: We strictly prohibit the use of real production data in development environments, promoting the use of synthetic data or Blue Yonder's native masking techniques to protect privacy during testing phases.
● Supplier Approval: We require all our external collaborators and technology partners to meet the same levels of robustness, regulatory compliance and commitment to cybersecurity that we apply to ourselves.
Contact and Security Channel
AFACIS maintains a permanent, monitored channel for handling suggestions, legal privacy inquiries or the immediate reporting of any suspected security incident through the corporate email address: incidencias@afacis.com.
Policy Review
Due to the ongoing evolution of technology, security threats and new legal developments in this area, AFACIS reserves the right to modify this Policy when necessary. The review will include evaluation opportunities to improve the policy in response to organizational, business or technical environment changes.
