Supplier Policy
RPE 01 01 / Rev:1 / November 2025
NPS SEGURIDAD considers its suppliers and partners a fundamental part of achieving its objectives in quality, sustainability, information security, and workplace well-being. To this end, the company has established a supplier evaluation and control policy within its Integrated Management System, in accordance with ISO 9001, ISO 14001, ISO 27001, and ISO 45001.
The purpose of this policy is to ensure that all products and services supplied meet the organization’s requirements for quality, the environment, information security, and occupational health and safety. Suppliers will also be assessed annually to verify their performance and promote continuous improvement.
Supplier Evaluation
The evaluation will be carried out annually, considering the following general criteria:
– Economic criterion: from cheapest (2) to most expensive (1).
– Delivery lead time criterion: from shortest (3) to longest (1).
– Availability criterion: immediate (3) to more than one week (1).
– Personal service criterion: from best service (3) to worst service (1).
The evaluation results will make it possible to measure suppliers’ progress and performance, supporting continuous improvement.
General Supplier Requirements
All suppliers must comply with the following principles:
– Regulatory compliance: compliance with applicable legislation on quality, the environment, data protection, information security, and occupational risk prevention.
– Confidentiality: protection of all information and data to which they have access.
– Integrity: maintaining the accuracy and reliability of the information and products supplied.
– Availability: ensuring continuity of services and uninterrupted supply.
– Occupational Health and Safety: compliance with ORP regulations and implementation of preventive measures to protect the health of their workers and third parties.
– Risk management: identifying and controlling risks that may affect security, quality, the environment, or occupational health.
Suppliers must implement appropriate measures to protect information and technological assets, including:
– Secure systems (firewalls, encryption, access control, updates, and backups).
– Protection against unauthorized access and external attacks.
– Immediate communication of any security incident or data breach that may affect NPS SEGURIDAD.
Suppliers must ensure the confidentiality, integrity, and availability of the information they access while providing their services.
Confidentiality:
– Do not store personal data on local drives.
– Any release or sending of information must be authorized and recorded.
– Media containing confidential information must be identified, inventoried, and stored in secure locations.
– The transmission of sensitive data must be encrypted or carried out using secure methods.
Intellectual property:
– Only material and software authorized by the organization may be used.
– The use of unlicensed software or the reproduction of protected works without authorization is prohibited.
Information sharing:
– Sharing information with unauthorized third parties or disseminating offensive, illegal content, or content unrelated to professional activity is prohibited.
– The use of the Internet for personal purposes or activities that damage the company’s image will not be permitted.
User responsibilities:
– Do not use other people’s credentials.
– Keep passwords secure, up to date, and confidential.
– Report any incident related to password security.
Suppliers must demonstrate a genuine commitment to environmental protection and to the health and safety of their workers, ensuring:
– Compliance with current environmental legislation.
– Efficient use of resources and waste reduction.
– Implementation of preventive measures against occupational risks.
– Reporting of any incident that may affect the environment or people’s safety.
Supplier contracts will include specific clauses on security, confidentiality, regulatory compliance, sustainability, and occupational safety. Serious non-compliance with these requirements may result in the review or termination of the contractual relationship. The organization may carry out periodic reviews to verify compliance with this policy and promote continuous improvement.
NPS SEGURIDAD will promote smooth and transparent communication with its suppliers, sharing evaluation results and opportunities for improvement. Collaboration and mutual commitment are essential to maintaining a secure, sustainable, and responsible supply chain. Through this Policy, NPS SISTEMAS S.L. reinforces its commitment to:
– Quality and customer satisfaction.
– Environmental protection.
– Information and data security.
– The health and safety of all people involved in its activities.
In Málaga, on November 4, 2025.
Management of NAPAU SISTEMAS S.L.