Information Security Policy

This policy aims to protect WECONNECT’s information from internal and external threats, ensuring the confidentiality, integrity, and availability of data for both clients and business operations.

The policy applies to all employees, partners, and external suppliers who have access to WECONNECT’s information systems, data, and infrastructure.

Through its management, WECONNECT is committed to adhering to the following fundamental principles of information security:

  • Confidentiality: Client and company data is accessible only to authorized individuals.
  • Integrity: Information remains accurate and complete, preventing unauthorized modifications.
  • Availability: Information and systems are accessible when needed.

The company adopts a continuous risk management process, including regular identification and assessment of threats related to information security.

Employee Responsibilities:

  • Comply with the prescribed security procedures.
  • Promptly report any security incidents or suspicious activities.
  • Participate in training programs related to information security.

This policy fully complies with the ISO 27001:2022 standard, the General Data Protection Regulation (GDPR), and other applicable data security laws.

The policy will be reviewed annually or whenever significant business changes occur to ensure the continuous improvement of the Information Security Management System (ISMS), as committed by the company’s management.

The company provides ongoing training to employees, keeping them informed about security procedures and current threats in the field of information security.

This policy has been approved by WECONNECT’s management and is communicated to all employees and partners for immediate implementation and compliance.

Marianna Diamantopoulou

Manager and Legal Representative

02.09.2024