INFORMATION SECURITY AND QUALITY MANAGEMENT SYSTEM POLICIES

QARACTER, which for the purposes of this Integrated Management System comprises the entities QARACTER TECNOLOGÍA Y OPERACIONES S.L.U., QARACTER USA LLC, and QARACTER INTERNATIONAL CORP, is a multinational company in the information technology sector that provides comprehensive consulting and outsourcing services, primarily to entities in the financial and insurance sectors.

QARACTER’s management has established an Integrated Management System in accordance with the UNE-EN ISO 9001:2015 and ISO/IEC 27001:2022 standards. Its purpose is to ensure the quality of the services provided and to protect the confidentiality, integrity, and availability of our own information and that of our clients against internal or external threats, whether deliberate or accidental.

This policy serves as the framework for establishing, reviewing, and monitoring quality and information security objectives, which are set annually, are measurable, and are consistent with the principles outlined herein.

Quality Commitments:
‍

• Equip employees with the skills and knowledge necessary to properly perform their duties.
‍
• Keep project planning up to date and carry out the necessary monitoring and control to meet time, cost, and quality objectives.
‍
• Ensure the proper implementation of the requirements agreed upon with the client and manage any changes in a controlled manner.

• Analyze alternative solutions and select, design, and implement the one that best meets the required functionality.
‍
• Ensure the proper operation and integration of system components and validate with the user that they meet the expected functionality.
‍
• Monitor changes to project deliverables and ensure they are correctly deployed to the client’s production environments.
‍
• Measure our clients’ satisfaction and use that information to improve our services.
‍
Information Security Commitments:
‍
• Protect our own information and that of our clients, ensuring its confidentiality, integrity, and availability.

• Identify, assess, and address information security risks using a risk analysis methodology, and implement the necessary controls to maintain them at acceptable levels.

• Manage access to information according to the principle of least privilege and implement robust authentication mechanisms.

• Ensure the continuity of critical services through business continuity plans that are tested periodically.

• Require suppliers and third parties to comply with security requirements appropriate to the service provided, including cloud services and artificial intelligence tools.

• Promote ongoing training and awareness among all staff regarding information security, including the responsible use of artificial intelligence.

Common Commitments:
‍
• Comply with the legal, regulatory, and contractual requirements applicable to our business in each country where we operate, particularly those related to the protection of personal data, as well as the commitments made to customers and third parties.
‍
• Continuously improve the effectiveness of the Integrated Management System through the monitoring of indicators, internal audits, and management review.

• Provide the necessary resources for the operation and improvement of the Integrated Management System.

This Quality Policy is understood, implemented and kept up to date at all levels of the organization and has the full commitment and support of the management at Qaracter.

Signed by management dated 29/01/2026


By clicking 'Accept All Cookies', you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our privacy policy for more information.