Information Security Policy

At Deliverea, we develop technology for last-mile logistics, and we know that our customers’ trust is built by protecting what they entrust to us: their information and the continuity of their operations. 

That is why the Management of Deliverea Shipping Solutions, S.L. has implemented an Information Security Management System (ISMS) in accordance with the UNE-EN-ISO/IEC 27001:2022 standard, with a clear objective: to safeguard the confidentiality, integrity and availability of information against any threat — internal or external, deliberate or accidental. 

Our commitments 

  • Protect the information of customers, employees and interested parties, along with the facilities and systems that support it. 
  • Manage risks in a planned way, integrating them into the design of new processes and services and into the improvement of existing ones. 
  • Comply with applicable regulations, including the protection of personal data, individuals’ privacy and intellectual property rights. 
  • Continuously improve our processes, methods and services to deliver an ever more secure and reliable operation. 
  • Ensure operational continuity through adequate human and technical resources, secure facilities and proven control tools. 

A commitment shared across the organisation 

Information security is not the responsibility of a single team: it is a way of working. Management leads this commitment and provides the necessary means, and every member of the Deliverea team plays an active part, identifying opportunities for improvement in their day-to-day work. 

Security that extends across our entire value chain 

Our commitment to information security does not end at our own boundaries: it extends to all interested parties that work with Deliverea — suppliers, maintenance providers, subcontractors and cloud service providers. 

As part of our ISMS, we assess, approve and periodically re-evaluate the companies we work with based on their ability to meet the security, quality and confidentiality commitments they take on with us. We require them to comply with applicable legislation, with our internal procedures and with the relevant security controls — confidentiality agreements, data processing contracts and recognised certifications appropriate to their activity — as well as to immediately report any incident or threat that may affect information. This is how we ensure that the same level of demand is upheld at every link in the delivery of our service. 

A shared responsibility 

This policy is communicated to all employees and made available to customers, partners, suppliers and other interested parties, because security is everyone’s responsibility.