Information Security Policy
CLOCKIO HR, SL
Reference framework for the information security of the organization: management commitment, objectives and principles, organization and responsibilities, risk management, third parties, incidents, and approval and review regime, in accordance with the National Security Framework (Royal Decree 311/2022).
Company: Clockio HR, SL (B55368062)
Date: 07/21/2026
Version: 1.0
1. Introduction
CLOCKIO HR, SL relies on information systems to achieve its objectives. These systems must be administered diligently and with appropriate measures, based on risk, to protect them against accidental or deliberate damage that could affect the confidentiality, integrity, availability, authenticity, or traceability of the processed information and provided services.
The goal of information security is to ensure that the organization can fulfill its mission, carry out its functions, and deliver its services by acting preventively, monitoring daily activity, and responding promptly to incidents. Given that threats evolve rapidly, security is conceived as an integral part of every stage of the life cycle of systems, from conception to decommissioning, including development or acquisition decisions and operational activities.
The management of CLOCKIO HR, SL is committed to protecting information and services, provides the management system with the necessary resources, and drives its continuous improvement. It approves this Information Security Policy as a reference framework for all security across the organization.
2. Purpose and Scope
This policy establishes the reference framework for information security at CLOCKIO HR, SL, as well as management's commitment, security objectives and principles, organization and responsibilities, risk treatment, and the approval and review regime.
It applies to all information systems of CLOCKIO HR, SL, to all individuals who make up the organization, and to service providers and solution vendors involved. Compliance is mandatory for all of them.
3. Mission of the Organization
CLOCKIO HR, SL's mission is software development and the provision of IT services based on its applications, with the Clockio service (clockio.net) as its main solution—a Software as a Service platform for time tracking and human resource management. To carry out its mission, it processes internal, client, and third-party information, and delivers services whose availability, authenticity, integrity, confidentiality, and traceability are essential to the trust of its clients, particularly the public administrations it serves.
4. Security Objectives
Through this policy, CLOCKIO HR, SL aims to achieve the following security objectives:
- Ensure the confidentiality, integrity, and authenticity of information, as well as continuity in service delivery.
- Implement security measures proportionate to and justified by risk.
- Train and raise awareness among organization members, ensure access traceability, apply the principle of least privilege, and reinforce the duty of confidentiality regarding information known in the performance of duties.
- Physically protect information assets by placing them in secure areas with access controls proportionate to identified risks.
- Protect information transmitted over communications networks using appropriate means.
- Control the acquisition, development, and maintenance of systems throughout their entire life cycle, ensuring security by default.
- Manage security incidents to detect, contain, mitigate, and resolve them, and prevent their recurrence.
- Protect personal information using technical and organizational measures appropriate to processing risks, in accordance with data protection legislation.
- Continuously monitor security, correcting identified inefficiencies and improving the system.
5. Security Principles
Security decision-making is governed by the following guiding principles, which steer all measures and actions of the organization:
- Strategic scope: information security has the commitment and support of all levels of the organization and is coordinated and integrated coherently with other initiatives.
- Comprehensive security: security is understood as a process that integrates technical, human, material, and organizational elements, present from the initial system design and throughout routine operations, avoiding any ad-hoc or temporary measures.
- Risk-based security management: measures are established based on the risks to which information and systems are exposed, are proportionate to the risk addressed, and are justified; risks related to personal data processing are also taken into account.
- Prevention, detection, response, and preservation: preventive actions are implemented to minimize vulnerabilities and prevent threat materialization and, when incidents occur, an agile response is provided to restore information and services while ensuring secure information preservation.
- Lines of defense: protection is designed and implemented in layers so that the failure of one layer does not compromise the overall system.
- Continuous vigilance and periodic re-evaluation: mechanisms are in place to detect and respond to anomalous behavior and to continuously assess security status, supported by a continuous improvement process that reviews and updates measures based on efficacy and evolving risks.
- Security by default and by design: systems are designed and configured to ensure security by default and provide the minimum functionality necessary to deliver the service.
- Separation of duties: the roles of Security Manager and System Manager are distinct.
6. Regulatory Framework
Information security at CLOCKIO HR, SL is framed within obligations arising from its nature, applicable legislation, and contractual commitments with third parties. The main regulations affecting this policy are:
- Royal Decree 311/2022, of May 3, regulating the National Security Framework (ENS).
- Regulation (EU) 2016/679, General Data Protection Regulation, and Organic Law 3/2018, on Personal Data Protection and guarantee of digital rights.
- CCN-STIC guides from the National Cryptologic Centre applicable to the National Security Framework.
- All other sectoral legislation and regulations applicable to the organization's activities, as well as contractual obligations with clients and third parties.
The organization maintains an updated inventory of applicable legislation and regulations and adapts it to any changes that occur.
7. Security Organization
CLOCKIO HR, SL adopts a security governance model based on separation of duties, featuring collegial bodies and individual roles with defined functions, supported by a coordination mechanism among them.
7.1. Information Security Committee
The Information Security Committee is established, comprising Management and the Security Manager, who acts as secretary, with other roles invited when required by the topics under discussion. The Committee meets at least biannually and whenever circumstances require. It serves as the security coordination body and holds, among others, the following functions: approving security regulations; monitoring security status (risks, incidents, indicators, and audits); establishing a baseline valuation for information types and services to harmonize risk analyses; promoting resource availability to meet security needs; resolving responsibility conflicts; and escalating decisions exceeding its authority to management. Its decisions are documented in minutes.
7.2. Security Roles
The following individual security roles are defined, along with their essential functions:
| Role | Essential Functions |
| Information Owner | Determines requirements for processed information and approves its valuation across security dimensions. |
| Service Owner | Determines requirements for provided services, including required service levels. |
| Security Manager | Supervises the implementation of security measures, manages security continuously, reports to the Committee, and acts as the contact point for incident management. |
| System Manager | Develops, operates, and maintains the information system throughout its life cycle and applies approved security measures. |
Given the size of the organization, Information Owner and Service Owner responsibilities rest with the same individual, while Security Manager and System Manager roles are assigned to separate individuals to ensure segregation.
7.3. Appointment and Substitution
All Committee members and security roles are formally designated and appointed in writing by the competent body and expressly accept their functions. Appointments may be reviewed periodically, whenever a position becomes vacant, or in cases of repeated failure to fulfill duties. The organization maintains a mechanism to replace designated managers during absences that could affect system operations.
7.4. Conflict Resolution
Conflicts between different managers are resolved by the Information Security Committee and, ultimately, by Management. The Security Manager is distinct from the System Manager and does not hierarchically report to them in the performance of their duties, ensuring the necessary segregation.
8. Structure and Development of Security Documentation
This policy is developed through a layered document hierarchy: mandatory security regulations, which standardize specific operational aspects of systems and individual obligations; operating procedures, which detail task execution; and records and evidence, which demonstrate system operation. Security regulations are available to all individuals who need to know them—particularly those who use, operate, or
administer information systems—through established corporate channels.
9. Staff Obligations, Awareness, and Training
All personnel at CLOCKIO HR, SL must know and comply with this policy and its supporting regulations. Ignorance of regulations does not excuse non-compliance.
All personnel receive information security awareness training periodically, at least annually, supported by a continuous awareness program that pays special attention to new hires. Individuals responsible for system usage, operation, or administration receive the training required for safe handling. This training is mandatory prior to assuming responsibilities, whether for an initial assignment or
a change in role or duties.
10. Risk Management
Security is managed through risk analysis, evaluating threats and risks to which systems are exposed. Analysis is repeated regularly, at least annually, and whenever changes occur in processed information or provided services, major security incidents happen, severe vulnerabilities are reported, or data protection risks change.
To harmonize evaluations, the Security Committee establishes baseline values for information types and services. Measures are selected proportionally based on risk, and their treatment is planned and prioritized. Residual risk is formally accepted by management.
11. Personal Data Protection
CLOCKIO HR, SL processes personal data as described in its record of processing activities. The organization evaluates risks associated with personal data and establishes an action plan to address those exceeding acceptable thresholds. When high-risk processing is identified, a Data Protection Impact Assessment is conducted if applicable. Measures and data breach responses are coordinated with general security measures, as is the handling of data subject rights requests.
12. Third Parties: Service Providers and Vendors
When CLOCKIO HR, SL provides services to other organizations or processes third-party information, it shares this policy with them, establishes coordination and incident communication channels, and designates a corresponding Point of Contact.
When CLOCKIO HR, SL uses third-party services, transfers information to third parties, or acquires solutions (including cloud services), it contractually requires security guarantees equivalent to those in this policy and compliance with applicable regulations. Third parties are bound by these obligations, may develop their own procedures to meet them, and must allow the organization to supervise or request compliance evidence, including audits. Incidents
are reported through designated contact points. Third parties ensure their staff is security-aware, at minimum to the standard established in this policy.
When a third party cannot meet a policy requirement, the Security Manager issues a report detailing risks and proposed treatments; this report must be approved prior to contracting by the affected Information and Service Owners, who accept the identified risks.
13. Security Incident Management
CLOCKIO HR, SL maintains mechanisms for the agile management of security events and incidents threatening information and services. Responses are coordinated with data protection and regulatory obligations, notifying competent supervisory authorities without undue delay and, when necessary, law enforcement agencies or judicial bodies.
14. Approval, Entry into Force, and Review
This policy is formally approved by the Management of CLOCKIO HR, SL and enters into force on the date of its approval, remaining valid until replaced by a new version. It is disseminated to all personnel and published across corporate channels.
The Information Security Committee reviews the policy at least annually and introduces necessary adaptations. When changes involve substantial modifications to principles or assigned responsibilities, the Committee proposes updates for approval. Policy replacement is communicated to stakeholders through the same channels used for its initial dissemination.