Management System Policy
Last updated January 2026
Legal documentsManagement System Policy
CommerceClarity S.r.l. adopts this Management System Policy as an expression of its strategic vision regarding information security. It is the top-level document of the Information Security Management System (ISMS) and provides the frame of reference for defining and pursuing information security objectives.
The Policy applies to all personnel, collaborators and authorized third parties, and is aligned with ISO/IEC 27001:2022 and the GDPR.
1. Purpose
CommerceClarity S.r.l. adopts this Management System Policy as an expression of its strategic vision regarding information security. The organization recognizes that protecting the confidentiality, integrity and availability of information is an enabling factor for its activities of designing, developing and marketing artificial-intelligence-based software solutions for the e-commerce sector, as well as for delivering the related digital services in SaaS mode.
Through this document, the organization provides the frame of reference for defining information security objectives, ensuring that such objectives are consistent with the operating context, the expectations of interested parties and the company’s strategic direction. The Policy is the top-level document of the Information Security Management System and guides the set of procedures, operating instructions and daily practices that derive from it.
CommerceClarity promotes a security culture founded on shared responsibility, a risk-based approach and continual improvement, so that the protection of information assets accompanies business growth and the trust of the enterprise and mid-market clients served in digital markets.
2. Scope
This Policy applies to all activities of CommerceClarity S.r.l. carried out at the registered office at Via di Affogalasino 34, 00148 Rome, the operating office at Via del Fosso di Radicelli 92, 00143 Rome, and any other workstation used by personnel in remote or hybrid mode. The perimeter includes the processes of development, production, marketing, delivery and support of the software solutions and SaaS services for e-commerce, including information, applications, databases, cloud services and assigned devices. The Policy binds all personnel, collaborators and authorized third parties who access company information or assets, regardless of geographic location.
3. Normative references
- ISO/IEC 27001:2022
- GDPR
4. Terms and definitions
Information Security Management System (ISMS): part of the overall management system that, based on a business-risk approach, establishes, implements, operates, monitors, reviews, maintains and improves information security.
Information security: preservation of the confidentiality, integrity and availability of information.
Confidentiality: the property whereby information is not made available or disclosed to unauthorized individuals, entities or processes.
Integrity: the property of accuracy and completeness of information.
Availability: the property of being accessible and usable on demand by an authorized entity.
Risk: the effect of uncertainty on objectives.
Policy: intentions and direction of an organization as formally expressed by its top management.
Continual improvement: recurring activity to enhance performance.
5. Roles and responsibilities
Management system manager: coordinates the drafting, periodic review, controlled distribution and monitoring of this Policy, ensuring its alignment with the business context and the identified risks.
6. Commitment and objectives of the management system
CommerceClarity recognizes information security as a strategic factor for the sustainability of its business model and for the trust that clients, investors and partners place in the services delivered. The organization therefore commits to maintaining an Information Security Management System appropriate to the nature of its digital services, to the complexity of the multi-supplier and multi-market catalogs managed by the AI platform, and to the continuously evolving European regulatory context.
The organization pursues the following information security objectives:
- Protect company, client and technical, commercial and operational information according to business needs and the associated level of risk.
- Ensure that access to information and associated assets remains authorized, traceable and limited to legitimate activities, in compliance with the principle of least privilege.
- Promote the timely reporting of observed or suspected security events, so that anomalies, incidents and vulnerabilities can be assessed, recorded and handled without delay.
- Protect devices, documents and information used outside company premises, so that remotely performed activities do not expose the information assets to loss, theft, alteration or unauthorized access.
- Maintain a governance model in which policies, procedures, reviews and communications remain up to date, proportionate to the size of the organization and responsive to changes in risk, technology, services and applicable requirements.
- Support the continual improvement of the ISMS through periodic risk review, management review, performance monitoring and documented follow-up actions.
To give substance to these objectives, the organization commits to meeting the applicable information security requirements (whether legislative, regulatory, contractual or arising from the expectations of interested parties) and to allocating adequate resources to maintaining and evolving the management system. The commitment to continual improvement translates into a structured cycle of risk assessment, internal audits, indicator monitoring and management review, the outcomes of which feed the revision of objectives and the adoption of corrective and preventive actions.
This Policy is inspired by the following fundamental principles:
- Governance and responsibility: the organization maintains a documented set of security rules, reviews them at planned intervals and communicates their requirements to personnel and interested external parties.
- Appropriate and authorized use: information, devices, applications and tools are used solely for legitimate business purposes and within the access rights formally granted.
- Protection of information in daily operations: the organization promotes handling practices that prevent the unnecessary exposure of information during ordinary activities.
- Timely reporting and learning: any observed or suspected event that may affect confidentiality, integrity or availability is considered relevant and is promptly entered into the reporting and response flow.
- Protection of assets outside company premises: devices, credentials, documents and connections used for company work are protected against loss, theft, unauthorized access and accidental disclosure.
- Continual alignment with business and risk: security decisions remain proportionate to the services offered, contractual obligations, stakeholder expectations and the evolving threat landscape.
The Policy is communicated internally to all personnel, collaborators and critical suppliers through approved company channels (corporate email, the SharePoint platform, training sessions and dedicated meetings) and is made available to external interested parties through the company website and, where contractually required, in the documentation provided to clients. The management system manager verifies the adequacy of the Policy at least once a year and whenever significant changes occur in the business context, the services delivered, the information security risks or the applicable requirements; any changes are submitted for management approval and managed as controlled documented information.
7. Storage and updating
This Policy is managed as controlled documented information in accordance with the PRO Documented Information Management Procedure. The document is stored on the company SharePoint platform, with access regulated according to the assigned classification, and previous versions are retained to ensure traceability of revisions. The management system manager submits the Policy for review at least annually, during the management review, or following significant changes affecting the organizational context, the services, the risks or the regulatory requirements. Every approved update is distributed through the company communication channels with evidence of transmission.
8. Reference documents
- POL Information Security Policy
- PRO Management Processes
- PRO Documented Information Management Procedure
- PRO Management Review Handling