COMPLIANCE

Our Integrated Quality and Information Security Policy

Mission

The mission of APPrendere is: “We transform the way organizations learn by creating meaningful and engaging experiences that empower people to grow and prosper, generating a real impact on business.”

In the provision of its product, our company follows the guidelines and objectives defined by its Integrated Quality and Information Security Management System, according to the relevant international standards ISO 9001 and ISO/IEC 27001. We consider the management of quality and the security of our own information and data, as well as that of interested parties, to be an indispensable factor.

To ensure the pursuit of its mission, APPrendere Srl dynamically analyzes its context, identifying the internal and external factors that are decisive for achieving its strategic objectives and the expected results of the company’s Management System.

The distinctive element of APPrendere S.r.l. lies in the contribution, in consulting and implementation activities, of professionals with proven competence and consolidated experience gained in business contexts. This approach allows us to effectively transfer know-how and best practices, fostering professional growth and increasing the competitiveness of companies. Our Company Policy is oriented towards Continuous Improvement in all activities, considered a fundamental strategic tool for achieving business objectives.

Sopra un rettangolo arancio con una freccia che punta verso l'alto. Sotto due ragazzi che progettano qualcosa di nuovo.

The company also considers the Confidentiality, Integrity, and Availability of its information assets fundamental and a strategic factor that can be transformed into a competitive advantage within the scope of the services offered. For this reason, it places similar attention on the choice of suppliers and collaborators with whom it shares information, and on the elements that support it and allow its management: the organization and processes, the technological and physical infrastructures, and people.

Through the identification, evaluation, and treatment of risks, APPrendere Srl defines a set of organizational, technical, and procedural measures to guarantee the satisfaction of the basic security requirements listed below:

  • Confidentiality: information is accessible exclusively to authorized people/resources and is therefore precluded from all others;
  • Integrity: information is accurate, complete, reliable, and changes are controlled; any attempt to tamper with data by unauthorized persons or caused by events is prevented/reported;
  • Availability: information is available to authorized parties in the times and ways established by company policies.

Principles and Objectives

With the adoption of the Integrated Management System, the Company aims to achieve substantial and measurable results regarding the following principles and objectives:

  • Ensure compliance with business objectives as well as the monitoring of processes and continuous improvement activities;
  • Ensure the quality of the solutions provided, including in terms of information security, as a guarantee of return (including economic) and customer loyalty;
  • Ensure correct management and protection of company information assets, as well as personal data;
  • Provide continuous services and products, constantly monitoring and improving their quality and information security, managing changes while respecting the standards set by the competent bodies;
  • Ensure the adoption and maintenance of a process for identifying potential threats to the company and the impacts that such threats, if materialized, could cause on information assets and services provided, defining a system capable of improving resilience and recovery capacity;
  • Minimize the duration of any service interruptions and maintain effective and efficient economic management through the adoption of the most advanced and functional technological, organizational, and procedural solutions;
  • Effectively manage information security incidents, including data breaches, through timely communication and the adoption of appropriate countermeasures;
  • Ensure collaborations with qualified technological partners, which guarantee reliability in terms of the quality of the services offered and the guarantee of information security and personal data protection;
  • Promote personnel training and information programs to ensure competent and efficient work groups trained in relation to the role they cover;
  • Promote Awareness and culture within the Organization regarding topics related to quality and information security;
  • Guarantee a risk management-oriented approach and the implementation of adequate actions to address risks and opportunities for every objective and business process identified in the System;
  • Ensure compliance with applicable mandatory legal requirements.

The Management of APPrendere Srl undertakes to play an active role in promoting all activities that influence the integrated system through:

  • The dissemination and knowledge, at all levels and to all interested parties, of this Policy and the concepts expressed therein;
  • The full availability of means and resources necessary for the instruction and maintenance of this System;
  • The preparation of a monitoring plan for the proposed objectives.

This policy is constantly updated and verified to ensure continuous improvement. The policy is shared with the entire organization and is available to customers, stakeholders, members, and third parties.stakeholder, soci e terze parti.

Edoardo Gironi
Data: 02/10/2025