Madrid · Domestic and International Service info@imts.es
ES / EN / PT

Textos Legales y Políticas
Corporativas

1. LEGAL NOTICE AND TERMS OF USE

  1. GENERAL INFORMATION AND OWNERSHIP In compliance with Article 10 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE), we hereby inform you that the owner of the website www.imts.es (hereinafter, the “Website”) is:
  • Owner: Infraestructuras de Medios Técnicos y Servicios, S.L. (hereinafter, “IMTS”).
  • Tax ID Number (CIF): B84255736
  • Tax Address: Avenida Alberto Alcocer, 46, 3°B, Postal Code 28046, Madrid
  • Registration details: Volume: 21053, Book: 0, Folio: 194, Section 8, Page: M373569
  1. TERMS OF ACCESS AND USE Access to the Website is free of charge and confers the status of User. The User agrees to use the Website, its content, and services in accordance with the law, this Legal Notice, good morals, and public order.

It is expressly prohibited to use the Website for unlawful purposes, or in a manner that harms the property or interests of IMTS or third parties, or that in any other way overloads, damages, or renders inoperable networks, servers, and other computer equipment (hardware) or computer products and applications (software).

  1. INTELLECTUAL AND INDUSTRIAL PROPERTY All content on the Website—including, but not limited to, texts, methodologies, GRC diagrams, photographs, graphics, images, icons, technology, software, as well as its graphic design and source codes—are the intellectual property of IMTS or third parties, and none of the exploitation rights recognized by current intellectual property laws regarding such content shall be deemed to have been transferred to the User.

The reproduction, modification, distribution, public communication, making available, extraction, reuse, or any other use of such content, except in cases where it is legally permitted or expressly authorized in writing by IMTS, is strictly prohibited.

  1. DISCLAIMER The content of this Website relating to Intelligence, Legal-Technical Consulting, GRC, or Information Security services is of a general nature and is provided for informational purposes only. Under no circumstances does it constitute the provision of a binding professional or legal advisory service. IMTS assumes no liability for decisions made based on the information provided on the Website, nor for any damages incurred by the User or third parties as a result of actions based solely on information obtained from the Website.

Despite implementing robust security measures, IMTS cannot guarantee the absence of viruses or other elements that may cause disruptions to the User’s computer systems.

  1. APPLICABLE LAW AND JURISDICTION This Legal Notice is governed in its entirety by Spanish law. For the resolution of any dispute that may arise from access to or use of the Website, the User and IMTS expressly agree to submit to the courts and tribunals of the city of Madrid, waiving any other general or special jurisdiction that may apply to them.

2. PRIVACY POLICY

  1. DATA CONTROLLER Infraestructuras de Medios Técnicos y Servicios (IMTS), with Tax ID No. [Tax ID] and registered address at [Address], is the Data Controller responsible for processing the User’s personal data collected through the Website. For any matters related to privacy and data protection, you may contact us at: RGPD@imts.es.
  2. PURPOSE OF PROCESSING AND LEGAL BASIS At IMTS, we process the information provided to us by data subjects for the following purposes:
  • Handling inquiries and contact: To address and resolve inquiries, requests for technical information, requirements assessments, or quotes submitted via the Website’s forms or email. Legal Basis: The User’s express consent when submitting their inquiry and our legitimate interest in addressing requests from potential clients.
  • Provision of professional services: Administrative, accounting, tax, and operational management for clients who contract our services in Auditing, IT Consulting, GRC, Cybersecurity, OSINT, or Technical Support. Legal basis: The performance of a contract or the implementation of pre-contractual measures.
  • Job applications: Management of resumes received for the recruitment of technical staff or auditors. Legal basis: The candidate’s explicit consent.
  1. DATA RETENTION The personal data provided will be retained for as long as necessary to fulfill the purpose for which it was collected and to determine any potential liabilities that may arise from that purpose, in addition to the periods established in the regulations governing archives and documentation. In the case of customers, data will be retained for the duration of the business relationship and, thereafter, for the periods required by law (tax and commercial).
  2. RECIPIENTS AND INTERNATIONAL TRANSFERS As a general rule, IMTS will not transfer personal data to third parties, unless legally required to do so. However, in order to provide our services, we share information with vendors (Data Processors) who provide us with technological services (web hosting, secure corporate email). IMTS monitors these service providers through its internal ICT Supplier Management process, ensuring they comply with the security measures required by the GDPR. In the event that providers outside the European Economic Area are used, IMTS will ensure that the transfer is supported by valid legal mechanisms, such as the Data Privacy Framework or Standard Contractual Clauses.
  3. SECURITY MEASURES As experts in Information Security, IMTS applies strict technical and organizational measures for both logical and physical security to protect your personal data against unauthorized access, destruction, alteration, loss, or disclosure, in accordance with the requirements of the National Security Scheme (ENS) and the ISO/IEC 27001 standard.
  4. EXERCISING YOUR RIGHTS (ARCO+) Any individual has the right to obtain confirmation as to whether IMTS is processing personal data concerning them. You may exercise your rights of access, rectification, erasure, restriction of processing, data portability, and objection at any time. To do so, you must submit a written request to RGPD@imts.es, attaching proof of your identity. We also inform you of your right to file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you believe that the processing does not comply with current regulations.

3. INFORMATION SECURITY POLICY

(Strategic note: Including this section on the website—either on a dedicated page titled “Security and Compliance” or as a downloadable document—is a powerful selling point for an auditor or a CISO client. It demonstrates maturity and consistency).

MANAGEMENT’S COMMITMENT TO SECURITY AND BUSINESS CONTINUITY

At IMTS, we recognize that information is the primary asset of our company and our clients. We provide highly critical services: external security management, intelligence analysis (OSINT), risk governance (GRC), auditing, and infrastructure support. Our clients’ trust depends directly on our ability to protect their information.

For this reason, IMTS management has driven the development, implementation, and maintenance of an Information Security Management System (ISMS) aligned with international best practices (ISO/IEC 27001) and the Spanish regulatory framework (National Security Scheme – ENS).

This Security Policy establishes the following guiding principles:

  1. Absolute Confidentiality: Ensuring that information (both our own and that of our clients) is accessible only to authorized individuals, based on the strict principle of least privilege. Safeguarding professional confidentiality is the cornerstone of our audit and OSINT services.
  2. Integrity and Traceability: Protecting the accuracy and completeness of information and its processing methods. Maintain auditable records of all support and consulting operations we perform on our clients’ systems.
  3. Availability and Resilience: Ensure that authorized users have access to information and associated assets when needed. We maintain business continuity plans to ensure the uninterrupted delivery of our critical services.
  4. Strategic Regulatory Compliance: Ensure unequivocal compliance with applicable legal, regulatory, and contractual requirements regarding security, particularly the GDPR, the LOPDGDD, the Private Security Act, and obligations arising from NIS2 or clients’ sector-specific regulations.
  5. Proactive Risk Management: Systematically and continuously identify, assess, and address security risks, establishing controls proportionate to the potential impact and rigorously managing risks in our technology supply chain.
  6. Independence: Ensuring the segregation of duties, particularly in our internal audit services, while preserving the impartiality and objectivity required by our clients.
  7. Culture of Security and Continuous Improvement: Continuously train, raise awareness, and evaluate our team of analysts, consultants, and technicians. Security is not a destination, but a process of continuous improvement (PDCA cycle).

All IMTS professionals, as well as our critical suppliers, are responsible for understanding, applying, and ensuring compliance with this Policy within the scope of their duties.

Approved by IMTS Senior Management.