Legal Notice and Security Policy
Legal Notice
|
Important Notice Accessing, browsing, and using the website www.atlascloud.es implies express and unreserved acceptance of all the conditions set out in this Legal Notice. If the user does not agree with any of these conditions, they must refrain from accessing or using the Website. |
1. Identifying Information of the Owner
In compliance with Article 10 of Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE), the identifying information of the owner responsible for this website is provided below:
|
Company Name |
Atlas Cloud S.L. |
|
NIF |
B-87364709 |
|
Registered Office |
Madrid, Spain |
|
Activity |
Provision of technological services, consulting, cybersecurity, and systems integration |
|
|
info@atlascloud.es |
|
DPO / Privacy |
dpo@atlascloud.es |
|
Website |
www.atlascloud.es |
|
Registration Details |
Registered in the Commercial Registry of Madrid. Volume [___], Page[___] Sheet [___] |
2. Purpose and Scope of Application
This Legal Notice governs the access and use of the website www.atlascloud.es — including all its subdomains and associated pages — owned by Atlas Cloud S.L. (hereinafter, “Atlas Cloud” or “the Company”). It applies to all users who access, browse, or use any content or service available on the website.
Access to the website is free of charge, without prejudice to the fact that certain content, services, or specific areas may be subject to prior subscription, registration, or contractual formalization. Use of the website grants the visitor the status of user and implies full acceptance of the conditions set out herein in their version in force at the time of access.
Atlas Cloud reserves the right to modify the content of this Legal Notice at any time, with such modifications taking effect from the moment of their publication. Users are advised to consult it periodically. Continued use of the website following the publication of any modification shall imply acceptance thereof.
3. Intellectual and Industrial Property
All content on the website — including, by way of example and not limitation, texts, articles, photographs, graphics, images, icons, videos, software, source code, graphic design, structure, information architecture, and any other elements subject to protection — is the exclusive property of Atlas Cloud S.L. or of third parties who have authorized its use, and is protected by Spanish and international regulations on intellectual and industrial property, in particular by Royal Legislative Decree 1/1996, of April 12, Consolidated Text of the Intellectual Property Law, and by Law 17/2001, of December 7, on Trademarks.
The reproduction, distribution, public communication, transformation, or any other form of exploitation, in whole or in part, of the website’s content is expressly prohibited, regardless of the purpose pursued or the means employed, without the prior, express, and written authorization of Atlas Cloud S.L. Failure to comply with this prohibition shall constitute an infringement of the Company’s intellectual or industrial property rights and shall give rise to the exercise of the corresponding civil and criminal actions in accordance with applicable legislation.
The trademarks, trade names, logos, and other distinctive signs of Atlas Cloud S.L. appearing on the website are the property of the Company or of third parties who have authorized their use. Their use, reproduction, distribution, or public communication without express authorization is strictly prohibited.
The user is authorized to view and make copies of the website’s content exclusively for private use, provided that the reproduced elements are not transferred to third parties, are not altered, and their source is expressly acknowledged.
4. Terms of Use
The user agrees to make diligent, correct, and lawful use of the website, in accordance with applicable legislation, good practices, public order, and these conditions. In particular, the user expressly undertakes to refrain from:
- Using the website for unlawful purposes or with effects that are harmful to the rights and interests of third parties, or that may in any way damage, disable, overload, or deteriorate the website or prevent its normal use by other users.
- Disseminating, storing, or transmitting through the website any content that is defamatory, offensive, obscene, threatening, xenophobic, that incites violence or discrimination on any grounds, or that in any way violates morality, public order, fundamental rights, public freedoms, or human dignity.
- Introducing or spreading on the network programs, data, viruses, or any other malicious code capable of causing damage to the information systems of Atlas Cloud, its suppliers, or third parties.
- Attempting to gain unauthorized access to computer systems, networks, restricted areas, or databases related to the website.
- Reproducing, copying, distributing, commercializing, or in any other way exploiting the website’s content without the express authorization of Atlas Cloud S.L.
- Impersonating third parties or entities.
- Engaging in acts of unfair competition or unlawful advertising through the website.
5. Disclaimer of Warranties and Liability
5.1 Availability and Continuity
Atlas Cloud does not guarantee the availability, uninterrupted access, or error-free operation of the website. The Company will take reasonably necessary measures to keep it operational and up to date, but shall not be liable for any damages that may arise from interruptions, access failures, or technical errors caused by circumstances beyond its control, including failures in telecommunications networks or in the systems of third-party internet service providers.
5.2 Accuracy and Currency of Content
Atlas Cloud strives to ensure the accuracy and currency of the content published on the website, but does not guarantee its integrity, completeness, or suitability for any specific purpose. The content is purely informational and does not in any case constitute legal, technical, financial, or any other form of professional advice. For making relevant decisions, the user should seek the advice of a qualified professional.
5.3 Third-Party Websites and External Links
The website may contain hyperlinks to third-party sites over whose content, services, or activities Atlas Cloud exercises no control whatsoever. The inclusion of any link shall not imply approval, sponsorship, or any recommendation of the linked sites, nor any relationship of any kind between Atlas Cloud and their owners. The Company shall not be liable for any damages or losses that may arise from accessing or using such websites.
5.4 Security and Viruses
Atlas Cloud implements security measures it considers reasonably adequate to protect the website. However, the Company cannot absolutely guarantee the absence of viruses or other harmful computer elements. The user is solely responsible for having the necessary tools for detecting and disinfecting their device, and for keeping their security systems up to date.
5.5 Force Majeure
Atlas Cloud shall be exempt from all liability towards the user when damages or breaches are due to circumstances of force majeure or fortuitous events, understood as those beyond the Company’s reasonable control, unforeseeable or unavoidable, including natural disasters, acts of public authority, armed conflicts, or widespread disruptions to telecommunications services.
6. Personal Data Protection
In accordance with Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and with Organic Law 3/2018, of December 5, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), Atlas Cloud S.L., as Data Controller, informs that the personal data provided by the user through the website will be processed exclusively for the purposes specified in each form or collection channel, on the legal bases and for the retention periods detailed in the Company’s Privacy Policy.
Atlas Cloud S.L. has appointed a Data Protection Officer (DPO) in accordance with Article 37 of the GDPR, who will act as the point of contact with the Spanish Data Protection Agency (AEPD) and will handle queries and requests for the exercise of rights by data subjects. For full information on data processing, your rights, and how to exercise them, the user should consult Atlas Cloud’s Privacy Policy, available on the website.
|
Contact for Data Protection Matters Data Protection Officer (DPO): dpo@atlascloud.es You may exercise your rights of access, rectification, erasure, objection, restriction, and portability by sending your request to the above address, attaching a copy of your identity document. If you believe that the processing of your data violates applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency: www.aepd.es |
7. Cookie Policy
The website uses its own and third-party cookies. Technical or strictly necessary cookies are essential for the proper functioning of the website and do not require the user’s consent. Analytical or tracking cookies require the user’s prior, free, specific, and informed consent, which can be managed at any time through the cookie preferences panel available on the website.
For complete and up-to-date information on the types of cookies used, their purpose, their duration, and the procedures for managing preferences, the user should consult Atlas Cloud’s Cookie Policy, available on the website.
8. Commercial Communications by Electronic Means
In compliance with Article 21 of the LSSI-CE, Atlas Cloud will not send advertising or promotional communications by email or other equivalent electronic means of communication without having previously obtained the express consent of the recipient, except in cases where a prior contractual relationship exists and the communications relate to the company’s own products or services of a similar nature to those that were the subject of the contract.
The recipient may object to the processing of their data for commercial communications at any time, without the need for justification, by sending a request to dpo@atlascloud.es with the subject line “Unsubscribe from commercial communications”. The unsubscription will take effect within a maximum period of ten business days from receipt of the request.
9. Establishment of Hyperlinks to the Website
Any website wishing to establish a hyperlink to www.atlascloud.es must obtain the prior and express authorization of Atlas Cloud S.L. The hyperlink must point exclusively to the website’s homepage, and it shall not be possible to reproduce any of its content through framing, embedding, or any other mechanism that could create confusion regarding the authorship or ownership thereof.
In any case, the establishment of hyperlinks from websites containing unlawful content, contrary to morality, public order, or the rights of third parties, or from websites that carry out or promote illegal activities, is strictly prohibited. The establishment of a hyperlink does not in any case imply the existence of any relationship between Atlas Cloud and the owner of the linking site, nor the acceptance or approval of its content by the Company.
10. Applicable Law and Jurisdiction
This Legal Notice is governed entirely by current Spanish legislation, with the following regulations being particularly applicable:
- Law 34/2002, of July 11, on Information Society Services and Electronic Commerce (LSSI-CE).
- Regulation (EU) 2016/679 of the European Parliament and of the Council, of April 27, 2016, on the protection of personal data (GDPR).
- Organic Law 3/2018, of December 5, on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD).
- Royal Legislative Decree 1/1996, of April 12, Consolidated Text of the Intellectual Property Law.
- Law 17/2001, of December 7, on Trademarks.
For the resolution of any disputes or conflicts that may arise from the access, use, or interpretation of this Legal Notice or the website, Atlas Cloud S.L. and the user, expressly waiving any other jurisdiction that may apply to them, submit to the exclusive jurisdiction of the Courts and Tribunals of the city of Madrid, unless applicable regulations establish a different mandatory jurisdiction.
Atlas Cloud S.L. · NIF B-87364709 · Madrid, Spain · www.atlascloud.es
Legal Notice · Law 34/2002 LSSI-CE · Version 1.0 · April 2026
INFORMATION SECURITY POLICY
|
Purpose of this Document This document constitutes the public declaration of the Information Security Policy of Atlas Cloud S.L., prepared in accordance with clause 5.2 of the ISO/IEC 27001:2022 standard. Its purpose is to communicate to clients, suppliers, partners, and other interested parties the framework of principles, commitments, and controls that Atlas Cloud applies to protect information security in the course of its activities. This document is public in nature. The full text of the Information Security Policy (POL-SGSI-001) is confidential and is available to auditors and parties who have signed a confidentiality agreement with Atlas Cloud S.L. |
1. Senior Management Commitment
The Senior Management of Atlas Cloud S.L. explicitly and irrevocably commits to information security as a strategic, differentiating, and cross-cutting element of the organization. This commitment is articulated through the establishment, implementation, maintenance, and continuous improvement of an Information Security Management System (ISMS) in accordance with the requirements of the ISO/IEC 27001:2022 standard.
Information security is not conceived at Atlas Cloud as a reactive measure or a mere formal compliance requirement, but as an intrinsic value of the organizational culture and a determining factor in the relationship of trust with our clients, employees, suppliers, and other interested parties. Senior Management guarantees the availability of the human, technical, and economic resources necessary for the operation and continuous improvement of the ISMS.
The Information Security Policy is formally approved by Senior Management, communicated to the entire organization, and reviewed at least annually, or whenever there is a significant change in the internal or external context of the Company. Compliance with it is mandatory for all own staff, external collaborators, and third parties with access to the systems and information of Atlas Cloud S.L.
2. Scope of the Information Security Management System
The ISMS of Atlas Cloud S.L. covers all processes, information systems, technological assets, and information managed by the Company in the course of its activities providing technology services, consulting, and cybersecurity, including operations carried out at its facilities in Madrid and Segovia and services delivered remotely to its clients.
The ISMS applies to all employees of Atlas Cloud S.L., regardless of their category or contractual relationship, as well as to external collaborators, suppliers, and third parties who access the Company’s systems or information, who are subject to the security obligations established in the contracts and agreements binding them to Atlas Cloud.
3. Guiding Principles
Information security management at Atlas Cloud S.L. is based on the following principles, which are mandatory for the entire organization:
- Confidentiality: information shall be accessible only to persons, systems, and processes duly authorized by virtue of their functions and responsibilities.
- Integrity: information shall be maintained in an accurate, complete manner and protected against unauthorized modifications, alterations, or destruction, whether accidental or deliberate.
- Availability: information systems and data shall be available and accessible to authorized users and processes when needed, in accordance with the service levels committed to clients.
- Least privilege: every user, system, or process shall have exclusively the permissions and access strictly necessary for the performance of their functions, with no possibility of unjustified accumulation of rights.
- Traceability: operations relevant to information security shall be recorded in a manner that enables auditing, investigation, and attribution of responsibilities when necessary.
- Accountability: every member of the organization is personally responsible for protecting the information they access in the course of their duties, in accordance with the established policies and procedures.
- Risk management: information security shall be managed on the basis of a periodic and systematic risk assessment, adopting controls proportional to the identified risk level and the operational context of the Company.
- Continuous improvement: the ISMS shall be subject to ongoing review and improvement through audits, incident analysis, continuity exercises, and periodic assessments of control effectiveness.
- Regulatory compliance: Atlas Cloud shall at all times ensure compliance with applicable legislation on information security, personal data protection, and business continuity.
4. Security Controls Framework
Atlas Cloud S.L. has implemented a comprehensive set of technical and organizational security controls, in accordance with Article 32 of the GDPR and the controls of Annex A of the ISO/IEC 27001:2022 standard. Without prejudice to the confidentiality covering their technical details, Atlas Cloud publicly declares that its security controls cover, among others, the following areas:
4.1 Identity Management and Access Control
- Mandatory strong authentication for access to all corporate systems, with multi-factor authentication applied to all users and additional reinforced controls for staff with privileged administration functions.
- Role-based access control based on the principle of least privilege, with formal and documented review of all access rights at minimum quarterly intervals.
- Formal identity lifecycle management process: creation, modification, and revocation of access rights, with immediate permission revocation upon any termination or change of staff functions.
- Separation of standard user accounts and privileged administration accounts, with activity logging for the latter.
4.2 Information Protection and Cryptography
- Encryption of communications using up-to-date security protocols for all information transmissions, both internal and external.
- Encryption of data stored on corporate systems and devices using recognized market solutions.
- Implementation of corporate email authentication mechanisms that prevent identity spoofing of the Atlas Cloud domain against third parties.
- Cryptographic management policy governing the lifecycle of keys, algorithms, and certificates used by the organization.
4.3 Systems and Infrastructure Security
- Continuous security monitoring of systems through a Security Operations Center (SOC) with the capacity for detection, analysis, and incident response twenty-four hours a day, seven days a week.
- Formal vulnerability management process that includes the identification, assessment, prioritization, and remediation of vulnerabilities in systems and applications, with remediation timeframes defined according to criticality.
- Network traffic segmentation and control through periodically reviewed filtering policies.
- Protection of end-user devices through centrally managed security solutions with automated updates.
- Remote access to corporate systems exclusively through encrypted and authenticated channels.
4.4 Business Continuity and Backup Management
- Formal backup policy with defined frequency, retention, and restoration procedures for each system category. Backups are subject to periodic restoration tests, the results of which are documented.
- Documented ICT Continuity and Disaster Recovery Plan, with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for critical systems, subject to periodic testing and review.
- Storage of backups in geographic locations separate from production systems, with security guarantees equivalent to those of primary environments.
4.5 Security Incident Management
- Formal and documented security incident management process governing the detection, notification, classification, response, escalation, resolution, and closure of incidents, with clearly assigned roles and responsibilities.
- Permanent incident reporting channel, available to employees, clients, and third parties, with immediate response capability.
- Personal data breach notification procedure to the Spanish Data Protection Agency within the timeframes established by the GDPR and, where applicable, to the affected data subjects and to clients acting as Data Controllers.
- Systematic root cause analysis following each significant incident, generating lessons learned and incorporating improvements into the ISMS.
4.6 Supply Chain Security
- Formal evaluation and approval process for suppliers with access to Atlas Cloud’s or its clients’ information, including verification of their security controls, certifications, and regulatory compliance capacity.
- Formalization of non-disclosure agreements (NDAs) and, where applicable, data processing agreements (DPAs) in accordance with Article 28 of the GDPR with all suppliers who access personal data.
- Periodic security performance evaluation of critical suppliers, with follow-up on corrective actions in the event of deviations.
- Management and logging of access granted to suppliers and third parties, with application of the least privilege principle and periodic review.
4.7 Security Awareness and Training
- Mandatory information security and data protection training program for all staff, delivered at the time of onboarding and updated at least annually.
- Periodic social engineering attack simulation exercises directed at staff, with the purpose of evaluating and reinforcing detection and response capabilities.
- Formal confidentiality commitment signed by all employees and external collaborators prior to commencing their activities within the organization.
- Periodic awareness communications on threats, best practices, and updates to security procedures.
5. Regulatory Framework and Certification Status
The SGSI of Atlas Cloud S.L. is structured around the following regulatory and reference framework, compliance with which is subject to periodic verification:
|
Framework / Standard |
Status |
Scope |
|
ISO/IEC 27001:2022 |
Certification in progress |
SGSI implemented with applicable Annex A controls. Certification audit scheduled for December 2026. |
|
RGPD (UE) 2016/679 |
Active compliance |
DPO appointed. Record of processing activities maintained. Breach notification and data subject rights procedures in place and operational. |
|
LOPDGDD 3/2018 |
Active compliance |
Adaptation of processing activities to the Spanish regulatory framework. |
|
NIS2 (Dir. UE 2022/2555) |
Active monitoring |
Management of NIS2 compliance pressure across the supply chain. |
|
ENS (RD 311/2022) |
Reference |
National Security Framework (ENS) controls used as a complementary reference. |
|
LSSI-CE 34/2002 |
Active compliance |
Compliance with information obligations for information society services. |
6. Review and Continuous Improvement
The Information Security Policy of Atlas Cloud S.L. is subject to formal review at minimum annually by the CISO, with subsequent approval by Senior Management. Extraordinary reviews shall be carried out in any of the following circumstances: significant regulatory changes in the field of information security or data protection; substantial modifications to the technological infrastructure, the organization, or the business model; security incidents of particular significance; or recommendations from the competent regulatory authorities.
The ISMS is subject to annual internal audit. The results, including identified non-conformities and associated corrective action plans, are reviewed by the Security Committee and presented to Senior Management. The key performance indicators of the ISMS are continuously monitored and presented to the Security Committee on a quarterly basis.
7. Security Contacts
|
Security incident reporting (24×7) |
security@atlascloud.es |
|
Data Protection Officer (DPO) |
dpo@atlascloud.es |
|
Responsible vulnerability disclosure |
security@atlascloud.es |
|
General security enquiries |
security@atlascloud.es |
|
Technical Support |
it.support@atlascloud.es |
|
Supervisory Authority — AEPD |
www.aepd.es · 900 293 183 |
|
Responsible vulnerability disclosure Atlas Cloud S.L. welcomes the responsible disclosure of any security vulnerability detected in its systems or services. If you have identified a potential vulnerability, we kindly ask you to report it confidentially to security@atlascloud.es prior to any public disclosure. Atlas Cloud commits to: acknowledging receipt of the notification within a maximum of twenty-four hours; investigating and assessing the vulnerability on a priority basis; keeping the reporting party informed of the progress of the investigation; and implementing the necessary corrective measures in the shortest possible time. During the investigation and remediation process, we request that the reporting party refrains from accessing third-party data, causing service disruptions, and publicly disclosing the vulnerability without prior knowledge of Atlas Cloud. |