Integrated Management Policy

Quality and Information Security

Digiheart brings together a committed and cohesive team, focused on customer satisfaction and supported by approachable leadership that values people, well-being, ethics and organisational responsibility. Committed to the satisfaction of its customers, Digiheart establishes this Integrated Quality and Information Security Management Policy with the aim of ensuring that its services and products meet the applicable contractual, legal and regulatory requirements, and provide adequate levels of information security, in order to protect information system resources and the confidentiality, integrity and availability of the information processed, stored or transmitted.

Digiheart's Integrated Management Policy is based on the following principles:

• Ensure customer satisfaction by understanding customers' needs and expectations and providing solutions tailored to their requests;
• Promote continuous improvement by adapting processes and procedures to eliminate the causes that may affect the quality of its services and products;
• Set and monitor objectives aligned with the company's strategy;
• Ensure a Management System based on risk analysis and treatment;
• Ensure the confidentiality, integrity and availability of information, both its own and its customers', throughout the entire service lifecycle, and ensure the proper management of information security incidents, minimising operational impact;
• Comply with applicable legal, contractual and regulatory requirements;
• Commit to the continuous improvement of partner and supplier performance, guiding relationships with them so as to meet customer needs and ensure compliance with appropriate information security requirements.

The principles of the Integrated Management Policy are shared across the entire organisation, with Management committed to ensuring their communication and implementation, fostering conduct focused on achieving the objectives.

Approved by Management on 2 July 2026