Back to home

Legal

Communication to Suppliers

Information security requirements in the supplier relationship

ENVÍA IT S.L. · Information Security Management System (ISO/IEC 27001:2023)

Dear supplier:

ENVÍA IT S.L. hereby confirms its commitment to information security and that it has implemented and maintains an Information Security Management System (ISMS) compliant with ISO/IEC 27001:2023. The standard requires us to apply controls not only internally, but also to third parties that provide services or process information belonging to Envía IT or its clients.

We therefore share the security requirements applicable to our relationship and ask for your cooperation in meeting them.

1. Supplier documentation and assessment

  • Upon request, we make available our Information Security Policy and the security requirements applicable to the relationship.
  • We will carry out periodic supplier security assessments to verify compliance with these requirements.
  • If your organization holds current certifications (ISO/IEC 27001, SOC 2 Type II, data protection certifications or others), please send them to us so we can add them to your file.

2. Minimum security requirements

  • Personal data protection: if the service involves processing personal data on your part, signing/accepting a data processing agreement (DPA) under art. 28 GDPR is mandatory, as is compliance with the GDPR and the Spanish LOPD-GDD.
  • International transfers: where processing takes place outside the EEA, valid standard contractual clauses (SCCs) or an equivalent mechanism must be in place and duly documented.
  • Security assurance: suppliers that process personal data or support production are required to hold a SOC 2 Type II attestation or a current ISO/IEC 27001 certification.
  • Breach notification: any security incident or breach affecting our information must be reported to Envía IT within a maximum of 72 hours of becoming aware of it.
  • Retention and deletion: upon termination of the contract, deletion or return of Envía IT's information, confirmed in writing.
  • Sub-processors: transparency regarding the sub-processors used (publicly available list or accessible under NDA) and notification of any changes.

3. Access to systems and information (where applicable)

  • Prior authorization: no supplier may access systems, information or facilities without an approved request, express authorization and a defined scope (what, how and for how long).
  • Confidentiality: prior signing of a non-disclosure agreement (NDA) and a commitment to comply with security rules.
  • Credentials: personal and non-transferable, under the principle of least privilege; no shared generic accounts; immediate revocation once the service ends.
  • Traceability: access activity may be logged and monitored so that it is possible to identify who performed each action.
  • Use of information: solely for the authorized purpose and through authorized channels; copying, storing or transferring information outside those channels or via personal accounts and devices is prohibited.

4. Contact

To access the documentation, submit your certifications or resolve any query about our ISMS or the security requirements applicable to the contractual relationship, you can write to [email protected]

We appreciate your cooperation: information security is a shared responsibility across the entire supply chain.

F4.3 — rev.00 · Public document