Velatia Cybersecurity Policy

Ormazabal, a company belonging to the Velatia Group, agrees to adhere to the Velatia Group Cybersecurity Policy, approved on 27 May 2025, undertaking to comply with and implement it within the scope of its activities, without prejudice to compliance with any legal and regulatory obligations specifically applicable to Ormazabal, as well as the adoption of any additional measures, procedures, and internal controls that may be necessary.

 

Corporate Security Framework Policy

 

  1. CORPORATE SECURITY

VELATIA demonstrates the utmost commitment and sensitivity towards the security of its Organization and conceives security as a comprehensive and integrated whole, consisting of the set of physical, technological, and organizational measures that, by combining human and technical resources across time and space, provide effective and overall protection for its people and assets (both tangible and intangible).

 

  1. PURPOSE

The purpose of this Corporate Security Framework Policy is to ensure the continuity of business operations and their long-term sustainability.

Accordingly, this Corporate Security Framework Policy is structured around a series of guiding principles, both general in nature and more specific to the areas of physical security, cybersecurity, and data protection.

 

  1. TOOLS AND AREAS OF ACTION

To achieve the objectives outlined above, VELATIA embraces and promotes the following areas of action:

 

2.1. PHYSICAL SECURITY

The specific guiding principles on which Physical Security is based are:

  1. A comprehensive approach to protecting people, assets, and intangible resources within physical environments.
  2. Preventive, reactive, and resilient adaptation of protection measures for people and the physical and geographical locations in which operations are conducted.
  3. A balance between effectiveness and minimum intervention.
  4. Compliance with applicable legal and regulatory requirements.
  5.  

2.2. CYBERSECURITY

The specific guiding principles that summarize and inspire all actions undertaken within virtual environments to provide adequate protection for data, information, communications, and other information technology assets are:

  1. Comprehensive protection of critical information and communication assets through a resilience-oriented approach.
  2. Establishment of protection levels appropriate to identified risks.
  3. Continuous software updating.
  4. Accountability by design.
  5. A balance between effectiveness and minimum intervention.
  6. Confidentiality and compliance with applicable laws.
  7. A multidisciplinary approach to cybersecurity.
  8.  

2.3. DATA PROTECTION

The specific guiding principles regarding privacy protection, understood as an individual and inalienable right of the Organization’s personnel and third parties, as recognized by the Charter of Fundamental Rights of the European Union, are:

  1. Lawful use of personal data, understood as processing supported by a valid legal basis.
  2. Use and storage of only the minimum and strictly necessary data.
  3. Implementation of appropriate technical and organizational protection measures.
  4. Accountability by design.
  5. A proactive approach to compliance.
  6.  

This Corporate Security Framework Policy was approved by the Board of Directors at its meeting held on 27 May 2025.