
Information security
Security Policy
MyFincaLink
Protecting our clients’ information is part of the design, development and operation of MyFincaLink.
1. Commitment to security
Information security, data protection and our clients’ trust are fundamental principles in the design, development and operation of MyFincaLink.
The application was designed to protect client-managed information through technical and organisational measures intended to reduce the risks of unauthorised access, loss, alteration, disclosure or destruction.
Security is a continuous process. MyFincaLink is maintained and updated periodically to add improvements, address potential vulnerabilities and progressively strengthen the platform.
2. Security objectives
The main objectives are:
- Protect the confidentiality, integrity and availability of information.
- Comply with applicable data protection and information-security law.
- Prevent unauthorised access to systems, databases and client documents.
- Reduce the risk of improper loss, alteration, destruction or disclosure.
- Provide recovery mechanisms for technical failures or incidents.
- Keep systems, servers and applications updated.
- Apply the principle of least privilege.
- Continuously improve implemented security measures.
3. Protection of sensitive data
MyFincaLink pays particular attention to data requiring a high level of security. Where technically necessary and appropriate, sensitive data and credentials are protected with encryption, secure cryptographic functions or equivalent safeguards.
- Passwords protected by secure hashing algorithms and never stored as plain text.
- Encryption of credentials, keys and other particularly sensitive data.
- Secure HTTPS/TLS communications.
- Restricted access to databases and internal services.
- Separation of credentials and permissions by service function.
- Protection of configuration files and application secrets.
- Access limited to authorised users and processes.
Where possible, MyFincaLink avoids storing sensitive information that is not strictly required.
4. Database security
The architecture limits access to each client’s data. Databases use specific users and permissions so that each service or process has only the privileges required for its function.
- Independent users and credentials.
- Least privilege.
- Restricted direct external access.
- Logical separation where required by the architecture.
- Periodic database backups.
- Periodic recovery checks.
5. Backups
Service continuity and recoverability are essential. The application and databases are backed up periodically, with an independent copy outside the primary infrastructure to reduce the risks arising from hardware failures, human error, data corruption or security incidents.
Backups may include application code and components, recovery configuration, client databases and information needed to rebuild the environment. Procedures are automated where possible and restoration checks and tests are performed.
6. Security updates and maintenance
The application, server and components are reviewed periodically to incorporate security updates, vulnerability fixes, authentication, authorisation and encryption improvements, dependency updates and new prevention mechanisms.
When a vulnerability is identified, its impact is assessed and it is addressed as diligently as possible.
7. Access control
Access is based on authentication and authorisation according to user profile. Users should access only the information and functions necessary for their duties. The platform supports different profiles and permissions, while administrative privileges are particularly restricted.
8. Infrastructure security
Measures may include restricted administrative access, secure remote protocols, restriction of unnecessary ports and services, HTTPS certificates, logging and monitoring, operating-system updates, separation of services and system users, and external backups.
9. Incident management
If an incident may affect security, availability or confidentiality, its scope is analysed in order to:
- Contain the incident.
- Identify its origin.
- Fix the vulnerability or cause.
- Recover affected systems or data.
- Adopt preventive measures.
Authorities and affected individuals will also be notified when legally required.
10. Personal data protection
Personal-data processing must comply with current law, including the GDPR and applicable Spanish legislation where relevant. Measures are reviewed according to the nature of the data, existing risks and the evolution of security technology.
11. Continuous improvement
Cybersecurity evolves constantly, and no infrastructure can be considered permanently protected solely by measures in place at a given time.
MyFincaLink periodically reviews its architecture, procedures, backups, encryption and access controls. Information protection is built into the platform and is a key criterion in its future development.