Skip to main content

Quality and Information Security Policy

ROOX Quality and Information Security Policy

ROOX, fully aware of the strategic importance of its customers, partners, employees, and other interested parties, as well as the impact that service quality and information protection have on the sustainability of its business, establishes this Quality and Information Security Policy, aligned with the organization’s context, strategic direction, and the principles of continual improvement.

ROOX is committed to delivering high-quality services that meet the needs and expectations of its customers while fostering relationships based on trust, proximity, and added value. This commitment is founded on a culture of operational excellence, innovation, and responsibility, ensuring compliance with all applicable legal, regulatory, normative, and contractual requirements.

Quality

ROOX has established its Quality Policy based on the following principles:

  • Meeting customers’ needs and expectations by responding to their quality requirements and any agreed changes thereto;
  • Complying with all applicable legal and contractual requirements;
  • Developing employees’ competencies through education, continuous training, and experience;
  • Continually improving the products and services provided, as well as the effectiveness of the Quality Management System, which is periodically reviewed;
  • Establishing realistic quality objectives and targets.

Information Security

ROOX also recognizes that information is a strategic asset that is fundamental to business success, customer confidence, and business continuity. Accordingly, the organization is committed to protecting its information assets against both internal and external threats, ensuring appropriate levels of confidentiality, integrity, and availability according to their criticality and sensitivity.

To fulfil these commitments, ROOX conducts its activities in accordance with the following principles:

  • Integrating Information Security into the organization’s business processes and objectives to ensure that information security requirements, and any agreed changes thereto, are met for customers and other relevant interested parties;
  • Ensuring that information protection complies with the organization’s internal information policies, as well as with applicable laws, regulations, internal organizational requirements, customer requirements, and other external obligations;
  • Ensuring the confidentiality, integrity, and availability of information by protecting and classifying information and its supporting assets according to their criticality for the organization and other interested parties;
  • Safeguarding the right to privacy of all individuals by protecting the personal data of customers, employees, and other data subjects;
  • Ensuring the development, implementation, and periodic review of policies, processes, and security and privacy measures to address both internal and external threats;
  • Ensuring effective information security incident management through the prevention, detection, recording, reporting, response, and investigation of security incidents and other vulnerabilities that could compromise information security, the protection of personal data, or business continuity;
  • Promoting awareness and training among employees in the field of Information Security to ensure their active participation and commitment;
  • Periodically assessing and monitoring information security risks in order to identify threats, evaluate risks, and implement appropriate control and mitigation measures;
  • Establishing realistic information security objectives and targets;
  • Fostering a collective and organization-wide commitment to compliance with all applicable requirements and to the continual improvement of information security and the Information Security Management System.

Current version: 5 May 2026

Please note, your browser is out of date.
For a good browsing experience we recommend using the latest version of Chrome, Firefox, Safari, Opera or Internet Explorer.