ARSOFT is a company specialized in the development and implementation of advanced 3D visualization, Augmented Reality, Virtual Reality, and Mixed Reality solutions for the industrial and healthcare sectors. Information security is an essential pillar for ensuring our clients’ trust, protecting processed data, and guaranteeing the continuity of our services.
For this reason, ARSOFT is committed to protecting the information and systems that support its activity, establishing and maintaining a management model aimed at preserving the confidentiality, integrity, availability, authenticity, and traceability of information, in accordance with the principles and requirements of the Spanish National Security Framework (ENS).
This policy forms part of our commitment to continuous improvement and applies to the activities, services, processes, information systems, and people involved in the delivery of our services.
ARSOFT’s Management establishes the following guiding principles regarding information security:
Information security is a strategic and cross-functional objective for ARSOFT.
Security is managed as a comprehensive process, combining organizational, technical, legal, and awareness measures.
Security management is based on the continuous analysis and treatment of risks.
Information protection is applied throughout its entire lifecycle, both in storage and in transit.
Access to information and systems is granted according to the principle of least privilege.
ARSOFT promotes the prevention, detection, response, and recovery of security incidents.
Security requires the active participation of all personnel through training and awareness actions.
The management of third parties, suppliers, and collaborators includes security criteria appropriate to the level of service and information processed.
Business continuity and service availability are priority principles for the organization.
Continuous improvement guides the evolution of the security management system.
ARSOFT develops its Information Security Policy in accordance with applicable regulations on information security, data protection, and electronic services, and especially with Royal Decree 311/2022 of May 3, which regulates the Spanish National Security Framework (ENS), as well as Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018.
ARSOFT’s Management provides the necessary framework to establish security objectives, assign responsibilities, promote risk management, and provide the organization with the resources needed to maintain a level of security appropriate to the category of its systems.
In this context, ARSOFT has defined a security governance structure and maintains mechanisms for the supervision and periodic review of this policy and the rules that implement it.
This Information Security Policy will be reviewed periodically and whenever relevant changes occur in the organization, its information systems, the applicable regulatory framework, or the risk context, in order to ensure its continued suitability and effectiveness.
Mr. Santiago González Izard
ARSOFT Management, March 2026.