{"id":16026,"date":"2026-05-20T16:25:42","date_gmt":"2026-05-20T14:25:42","guid":{"rendered":"https:\/\/woffu.com\/security-policy\/"},"modified":"2026-05-20T16:25:42","modified_gmt":"2026-05-20T14:25:42","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/woffu.com\/en\/security-policy\/","title":{"rendered":"Security Policy"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row el_class=&#8221;legal-page&#8221; css=&#8221;.vc_custom_1652117793510{padding-bottom: 3rem !important;}&#8221;][vc_column][vc_column_text css=&#8221;&#8221;]<strong>Information Security Policy<\/strong><\/p>\n<p><strong>1. Approval and Effective Date<\/strong><\/p>\n<p>November 18, 2025<\/p>\n<p><strong>2. Our Mission<\/strong><\/p>\n<p>To efficiently digitize time management policies, adapting them to current realities to improve the employee-employer relationship.<\/p>\n<p><strong>3. Objective and Scope<\/strong><\/p>\n<p>The main objective of this policy is to establish a high-level Information Security Policy with basic rules for information security management, to offer a secure service where access to information is exclusive to authorized personnel, information is integral without manipulation, and is available at all times to authorized personnel.<\/p>\n<p>Furthermore, this security policy is available to all our clients, Woffu staff, collaborators, and suppliers with whom we work jointly, so they can be informed about Woffu&#8217;s security and participate in the continuous improvement of our information security and privacy management system.<\/p>\n<p>This policy applies to all members of the organization and to all functionalities of our SaaS (Software as a Service) Woffu.<\/p>\n<p><strong>Woffu Features<\/strong><\/p>\n<ul>\n<li>Vacations and absences<\/li>\n<li>Attendance Control<\/li>\n<li>Shifts<\/li>\n<li>internal communication<\/li>\n<li>Documents<\/li>\n<li>Reports<\/li>\n<li>Whistleblowing channel<\/li>\n<\/ul>\n<p>All our suppliers must comply with our information security policies and procedures according to the service provided.<\/p>\n<p><strong>4. Security Requirements<\/strong><\/p>\n<ul>\n<li>Incorporate robust security measures, including network security, endpoint security, access control, vulnerability management, and encryption.<\/li>\n<li>Maintain a supplier management process that ensures the security of information assets.<\/li>\n<li>Adhere to a &#8220;Security by Design and by Default&#8221; approach by integrating security measures at every stage of your product development lifecycle.<\/li>\n<li>Maintain a business continuity plan.<\/li>\n<li>Ensure sufficient security throughout an employee&#8217;s lifecycle, including pre-employment requirements, security requirements during employment, and after employment termination.<\/li>\n<li>Maintain an inventory of information and other security-related assets.<\/li>\n<li>Establish security objectives annually from management.<\/li>\n<li>Adhere at all times to the principle of least privilege for access to information assets.<\/li>\n<li>Woffu locations must be protected based on the risk profile of the location, area, and assets, to minimize unauthorized access and ensure the security of both employees and company assets.<\/li>\n<li>Non-compliance with this policy will result in disciplinary measures by the company, in accordance with current regulations, which may include, among others, dismissal or termination of contract.<\/li>\n<\/ul>\n<p><strong>5. Regulatory Framework<\/strong><\/p>\n<p>To protect information, we must at all times comply with the current provisions of the European Union and Spain regarding the security and privacy of personal data, and with international and national standards and best practices in Information Security adopted by <strong>Woffu<\/strong>.<\/p>\n<ul>\n<li>Applicable Legislation:\n<ul>\n<li><strong>Workers&#8217; Statute<\/strong>, section 9 of article 34 referring to the daily work record and the retention of work records for four years, which shall remain available to workers, their legal representatives, and the Labor and Social Security Inspectorate.<\/li>\n<li><strong>REGULATION (EU) 2016\/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL<\/strong> of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation)<\/li>\n<li><strong>Organic Law 3\/2018, of December 5<\/strong>, on Personal Data Protection and guarantee of digital rights (LOPDGDD).<\/li>\n<li><strong>Law 2\/2023, of February 20<\/strong>, regulating the protection of persons who report regulatory infringements and fight against corruption.<\/li>\n<li><strong>Law 34\/2002, of July 11<\/strong>, on information society services and electronic commerce.<\/li>\n<li><strong>Law 6\/2020, of November 11<\/strong>, regulating certain aspects of electronic trust services.<\/li>\n<li><strong>Royal Legislative Decree 1\/1996, of April 12<\/strong>, approving the revised text of the Intellectual Property Law, regularizing, clarifying, and harmonizing the legal provisions in force on the matter.<\/li>\n<li><strong>Resolution of February 22, 2018<\/strong>, of the General Directorate of Employment, registering and publishing the XVII State Collective Bargaining Agreement for consulting and market research and public opinion companies.<\/li>\n<li><strong>Royal Decree-Law 8\/2019, of March 8<\/strong>, published on March 12, 2019, in the Official State Gazette, regarding urgent social protection measures and the fight against labor precariousness in working hours.<\/li>\n<li><strong>Law 10\/2021, of July 9<\/strong>, on remote work.<\/li>\n<li><strong>Criminal Code<\/strong><\/li>\n<\/ul>\n<\/li>\n<li>Information Security and Privacy Standards and Best Practices:<br \/>\n<strong>Woffu<\/strong> undergoes annual audits to ensure information security and maintain its certifications.<\/p>\n<ul>\n<li><strong>ISO-27001<\/strong> Audit. Information Security Management Systems, and implementation of ISO-27002 controls <\/li>\n<li><strong>ISO-27701<\/strong> Audit. Extension to ISO\/IEC 27001 and ISO\/IEC 27002 for privacy information management \u2013 Requirements and guidelines. <\/li>\n<li><strong>ISO-27018<\/strong> Audit. Information technology \u2014 Security techniques \u2014 Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors <\/li>\n<li>Annual <strong>Pentest<\/strong> of our Woffu SaaS service.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>6. Organization and Responsibilities<\/strong><\/p>\n<p>The <strong>General Manager<\/strong> is responsible for Woffu&#8217;s security.<\/p>\n<p>The <strong>Security Committee<\/strong> is responsible for overseeing and directing Woffu&#8217;s security performance.<\/p>\n<p><strong>Managers<\/strong> are responsible for ensuring that policies and procedures are implemented and complied with.<\/p>\n<p><strong>Security Contacts<\/strong> are responsible for overseeing general security operations at Woffu and implementing necessary measures to ensure compliance.<\/p>\n<p>All <strong>employees<\/strong> are responsible for adhering to general security policies and the security provisions of their roles and the procedures they perform.<\/p>\n<p>Security incidents and policy violations must be reported to security contacts via <a href=\"mailto:security@woffu.com\"><strong>security@woffu.com<\/strong><\/a>.<\/p>\n<p><strong>7. Personal Data<\/strong><\/p>\n<p>The <a href=\"https:\/\/woffu.com\/en\/privacy-policy\/\">privacy policy<\/a> details the processing of personal data, as well as its purpose, retention period, legitimate basis, data typology, transfers, international transfers, and profiling.<\/p>\n<p>All functionalities of our Woffu SaaS will comply with the security levels required by the GDPR for the nature and purpose outlined in the aforementioned privacy policy.<\/p>\n<p><strong>8. Awareness and Training<\/strong><\/p>\n<p>All <strong>Woffu<\/strong> members must complete security training courses at least once a year.<\/p>\n<p><strong>9. Risk Management<\/strong><\/p>\n<p>For Security Risk Management, a risk analysis is performed on our Woffu SaaS, evaluating the threats and risks it is exposed to for treatment. This analysis will be repeated: <\/p>\n<ul>\n<li>Regularly, at least once a year<\/li>\n<li>When the information handled changes<\/li>\n<li>When the services provided change<\/li>\n<li>When a serious security incident occurs<\/li>\n<li>When serious vulnerabilities are reported<\/li>\n<\/ul>\n<p><strong>10. Approval and Review Process<\/strong><\/p>\n<p>The Information Security Policy will be approved by the <em>General Manager<\/em>, and all <strong>Woffu<\/strong> members are obliged to know and comply with it.<\/p>\n<p>The review of the policy is the responsibility of the security manager.<\/p>\n<p>Likewise, the policy will be subject to an annual review or when significant changes occur in applicable regulations, intrinsic changes in information systems, and the complexity of the organization itself, to ensure its continued suitability, adequacy, effectiveness, and compliance with the legal and regulatory framework in which our activities are carried out.[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row el_class=&#8221;legal-page&#8221; css=&#8221;.vc_custom_1652117793510{padding-bottom: 3rem !important;}&#8221;][vc_column][vc_column_text css=&#8221;&#8221;]Information Security Policy 1. Approval and Effective Date November 18, 2025 2. Our Mission To [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-new-legal.php","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-16026","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Policy | Woffu<\/title>\n<meta name=\"description\" content=\"Learn about Woffu&#039;s security policy, the HR software that protects your data and ensures secure work time management.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/woffu.com\/en\/security-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Policy | Woffu\" \/>\n<meta property=\"og:description\" content=\"Learn about Woffu&#039;s security policy, the HR software that protects your data and ensures secure work time management.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/woffu.com\/en\/security-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Woffu\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/woffu\/\" \/>\n<meta property=\"og:image\" content=\"https:\/\/woffu.com\/wp-content\/uploads\/2025\/07\/woffu-logo-color-marketplace.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"625\" \/>\n\t<meta property=\"og:image:height\" content=\"332\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Woffu_App\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/security-policy\\\/\",\"url\":\"https:\\\/\\\/woffu.com\\\/en\\\/security-policy\\\/\",\"name\":\"Security Policy | Woffu\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#website\"},\"datePublished\":\"2026-05-20T14:25:42+00:00\",\"description\":\"Learn about Woffu's security policy, the HR software that protects your data and ensures secure work time management.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/security-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/woffu.com\\\/en\\\/security-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/security-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/woffu.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/woffu.com\\\/en\\\/\",\"name\":\"Woffu\",\"description\":\"Woffu es una plataforma digital que facilita la gesti\u00f3n del tiempo laboral, control horario, vacaciones y ausencias, optimizando procesos de recursos humanos y asegurando el cumplimiento normativo en las empresas.\",\"publisher\":{\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#organization\"},\"alternateName\":\"Woffu\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/woffu.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#organization\",\"name\":\"Woffu\",\"url\":\"https:\\\/\\\/woffu.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/woffu.com\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/logo-woffu-dark.svg\",\"contentUrl\":\"https:\\\/\\\/woffu.com\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/logo-woffu-dark.svg\",\"width\":161,\"height\":38,\"caption\":\"Woffu\"},\"image\":{\"@id\":\"https:\\\/\\\/woffu.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/woffu\\\/\",\"https:\\\/\\\/x.com\\\/Woffu_App\",\"https:\\\/\\\/www.instagram.com\\\/woffu\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/woffu\\\/\"],\"telephone\":\"+34 932059750\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Carrer de Mexic, 8\",\"postalCode\":\"08004\",\"addressLocality\":\"Barcelona\",\"addressCountry\":\"ES\"},\"contactPoint\":[{\"@type\":\"ContactPoint\",\"contactType\":\"customer support\",\"telephone\":\"+34 932059750\",\"email\":\"help@woffu.com\",\"url\":\"https:\\\/\\\/woffu.com\\\/es\\\/contacto\\\/\",\"areaServed\":\"ES\",\"availableLanguage\":[\"es\",\"en\"],\"hoursAvailable\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"https:\\\/\\\/schema.org\\\/Monday\",\"https:\\\/\\\/schema.org\\\/Tuesday\",\"https:\\\/\\\/schema.org\\\/Wednesday\",\"https:\\\/\\\/schema.org\\\/Thursday\"],\"opens\":\"08:30\",\"closes\":\"19:00\"},{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":\"https:\\\/\\\/schema.org\\\/Friday\",\"opens\":\"08:30\",\"closes\":\"14:00\"}]},{\"@type\":\"ContactPoint\",\"contactType\":\"sales\",\"telephone\":\"+34 932059750\",\"email\":\"sales@woffu.com\",\"url\":\"https:\\\/\\\/woffu.com\\\/es\\\/demo\\\/\",\"areaServed\":\"ES\",\"availableLanguage\":[\"es\",\"en\"],\"hoursAvailable\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"https:\\\/\\\/schema.org\\\/Monday\",\"https:\\\/\\\/schema.org\\\/Tuesday\",\"https:\\\/\\\/schema.org\\\/Wednesday\",\"https:\\\/\\\/schema.org\\\/Thursday\"],\"opens\":\"08:30\",\"closes\":\"19:00\"},{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":\"https:\\\/\\\/schema.org\\\/Friday\",\"opens\":\"08:30\",\"closes\":\"14:00\"}]}]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Policy | Woffu","description":"Learn about Woffu's security policy, the HR software that protects your data and ensures secure work time management.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/woffu.com\/en\/security-policy\/","og_locale":"en_US","og_type":"article","og_title":"Security Policy | Woffu","og_description":"Learn about Woffu's security policy, the HR software that protects your data and ensures secure work time management.","og_url":"https:\/\/woffu.com\/en\/security-policy\/","og_site_name":"Woffu","article_publisher":"https:\/\/www.facebook.com\/woffu\/","og_image":[{"width":625,"height":332,"url":"https:\/\/woffu.com\/wp-content\/uploads\/2025\/07\/woffu-logo-color-marketplace.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@Woffu_App","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/woffu.com\/en\/security-policy\/","url":"https:\/\/woffu.com\/en\/security-policy\/","name":"Security Policy | Woffu","isPartOf":{"@id":"https:\/\/woffu.com\/en\/#website"},"datePublished":"2026-05-20T14:25:42+00:00","description":"Learn about Woffu's security policy, the HR software that protects your data and ensures secure work time management.","breadcrumb":{"@id":"https:\/\/woffu.com\/en\/security-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/woffu.com\/en\/security-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/woffu.com\/en\/security-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/woffu.com\/en\/"},{"@type":"ListItem","position":2,"name":"Security Policy"}]},{"@type":"WebSite","@id":"https:\/\/woffu.com\/en\/#website","url":"https:\/\/woffu.com\/en\/","name":"Woffu","description":"Woffu es una plataforma digital que facilita la gesti\u00f3n del tiempo laboral, control horario, vacaciones y ausencias, optimizando procesos de recursos humanos y asegurando el cumplimiento normativo en las empresas.","publisher":{"@id":"https:\/\/woffu.com\/en\/#organization"},"alternateName":"Woffu","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/woffu.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/woffu.com\/en\/#organization","name":"Woffu","url":"https:\/\/woffu.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/woffu.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/woffu.com\/wp-content\/uploads\/2021\/08\/logo-woffu-dark.svg","contentUrl":"https:\/\/woffu.com\/wp-content\/uploads\/2021\/08\/logo-woffu-dark.svg","width":161,"height":38,"caption":"Woffu"},"image":{"@id":"https:\/\/woffu.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/woffu\/","https:\/\/x.com\/Woffu_App","https:\/\/www.instagram.com\/woffu\/","https:\/\/www.linkedin.com\/company\/woffu\/"],"telephone":"+34 932059750","address":{"@type":"PostalAddress","streetAddress":"Carrer de Mexic, 8","postalCode":"08004","addressLocality":"Barcelona","addressCountry":"ES"},"contactPoint":[{"@type":"ContactPoint","contactType":"customer support","telephone":"+34 932059750","email":"help@woffu.com","url":"https:\/\/woffu.com\/es\/contacto\/","areaServed":"ES","availableLanguage":["es","en"],"hoursAvailable":[{"@type":"OpeningHoursSpecification","dayOfWeek":["https:\/\/schema.org\/Monday","https:\/\/schema.org\/Tuesday","https:\/\/schema.org\/Wednesday","https:\/\/schema.org\/Thursday"],"opens":"08:30","closes":"19:00"},{"@type":"OpeningHoursSpecification","dayOfWeek":"https:\/\/schema.org\/Friday","opens":"08:30","closes":"14:00"}]},{"@type":"ContactPoint","contactType":"sales","telephone":"+34 932059750","email":"sales@woffu.com","url":"https:\/\/woffu.com\/es\/demo\/","areaServed":"ES","availableLanguage":["es","en"],"hoursAvailable":[{"@type":"OpeningHoursSpecification","dayOfWeek":["https:\/\/schema.org\/Monday","https:\/\/schema.org\/Tuesday","https:\/\/schema.org\/Wednesday","https:\/\/schema.org\/Thursday"],"opens":"08:30","closes":"19:00"},{"@type":"OpeningHoursSpecification","dayOfWeek":"https:\/\/schema.org\/Friday","opens":"08:30","closes":"14:00"}]}]}]}},"_links":{"self":[{"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/pages\/16026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/comments?post=16026"}],"version-history":[{"count":2,"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/pages\/16026\/revisions"}],"predecessor-version":[{"id":16028,"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/pages\/16026\/revisions\/16028"}],"wp:attachment":[{"href":"https:\/\/woffu.com\/en\/wp-json\/wp\/v2\/media?parent=16026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}