The principles and the technical and organisational measures Apollotec applies to protect the confidentiality, integrity and availability of the information it processes.
Last updated: 24/08/2026
This is a translation provided for convenience. In the event of any discrepancy, the Portuguese version prevails.
This policy sets out the principles and measures Apollotec adopts to protect the confidentiality, integrity and availability of the information it processes, whether its own, its clients' or its partners'. It is also the answer to Article 32 GDPR — the technical and organisational measures appropriate to the risk — to which the Privacy Policy refers.
It applies to all Apollotec information systems, infrastructure, staff, service providers and processes involved in processing, storing or transmitting information, including the cloud and hosting services Apollotec manages for its clients.
Our data centres operate under ISO 27001 certification and are located in the European Union. Internal processes are designed for compliance with the GDPR, with Portuguese Law no. 58/2019 and with other applicable legislation in Portugal and the European Union.
We maintain a formal process for detecting, containing, responding to, resolving and reviewing security incidents.
Where a personal data breach is involved, and under Articles 33 and 34 GDPR:
Backups and recovery procedures are tested periodically, so that service restoration is not verified for the first time during an incident.
All Apollotec staff and service providers are responsible for complying with this policy and for immediately reporting any incident or suspected incident.
If you find a vulnerability in our systems, write to info@apollotec.pt with a description and reproduction steps. We ask that you do not publicly disclose the flaw before we have had a chance to fix it, and that you do not access, alter or exfiltrate third-party data while testing. We respond to every report.
This policy is reviewed periodically, and whenever there is a material change in our processes, in the technology used or in applicable legislation.
To report a security incident or a vulnerability, or for any question about this policy, contact info@apollotec.pt.