Last updated: 18 September 2026
( Contents )
This Information Security Policy (the “Policy”) describes the principles and measures by which Made in Evolve S.r.l. (Via Rosalba Carriera 26, 41126 San Damaso, Modena, tax code and VAT no. 03497200364; “Made in Evolve”) protects the information it processes in delivering its eCommerce agency and system integration services and the Nucleo Platform SaaS. It is the public version of the internal document and is addressed to clients, partners and suppliers.
The Policy applies to all information processed by Made in Evolve, in any format, and to all systems, networks, devices and cloud services used to process it; it binds employees, contractors and suppliers who access those resources. It covers client data processed on clients’ behalf, under the data processing agreement, and the personal data for which Made in Evolve is the controller, described in the privacy policy.
The objectives are to ensure confidentiality (information is accessible only to those authorised), integrity (information is accurate and complete) and availability (information and services are accessible when needed), and to ensure compliance with Regulation (EU) 2016/679 (GDPR), Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 and the contractual commitments made to clients.
Overall responsibility for information security is assigned to the CTO of Made in Evolve, who defines the measures, verifies their implementation, manages incidents and reports to management. Each area lead is accountable for applying the Policy within their area; each person is responsible for the information they handle and the tools they use. Matters concerning personal data are coordinated with the privacy contact (privacy@madeinevolve.com).
Made in Evolve structures its security management system in alignment with the principles of ISO/IEC 27001:2022 and the controls of its Annex A, without holding a certification. Made in Evolve is not among the essential or important entities under Directive (EU) 2022/2555 (NIS2), but voluntarily adopts its risk management principles: risk analysis, supply chain security, incident management, business continuity and training. The risk analysis is updated at least once a year and upon any significant change.
Information and systems are recorded in an inventory indicating their owner and classification. Information is classified as public, internal, confidential and client data; each level carries its own rules for access, sharing and deletion. Assets assigned to staff are returned and wiped at the end of the engagement.
Devices used to access company information have disk encryption, automatic operating system and application updates, automatic screen lock, anti-malware protection and remote wipe capability. Personal devices may be used only if they meet the same requirements.
Data is encrypted in transit with TLS 1.2 or higher on all external connections and at rest on databases, storage and backups. Application secrets (API keys, service credentials, certificates) are kept in dedicated secret managers, rotated periodically and never placed in source code or messaging systems.
The production infrastructure is hosted on DigitalOcean in the Frankfurt (Germany) data centre. Networks are protected by firewalls with restrictive inbound rules; services are exposed only when necessary and administrative access uses keys and MFA. Development, test and production environments are separated at infrastructure and credential level. In Nucleo Platform each client’s data is isolated per tenant at application and database level. Infrastructure configurations are managed as code and subject to review.
Systems log access, administrative operations and relevant security events. Logs are protected against tampering, retained for a maximum of 12 months and used only for security, diagnostic and legal compliance purposes. Availability and error monitoring raises alerts to the technical team.
Production data is subject to encrypted daily backups, stored separately from the source systems. Restores are tested periodically to verify backup integrity and recovery times. Continuity procedures define restore priorities, responsibilities and communication channels with clients in the event of a prolonged outage.
Vulnerabilities are identified through automated analysis of dependencies and systems, vendor bulletins and external reports. Fixes are applied according to severity, prioritising critical and actively exploited vulnerabilities. Operating system and infrastructure component updates are applied regularly.
Made in Evolve has an incident management procedure covering detection, classification by severity, containment, root cause analysis, recovery and post-incident review. Where an incident constitutes a personal data breach:
All incidents are recorded and lessons learned feed into the updating of the measures.
Suppliers that process information on behalf of Made in Evolve are selected through prior due diligence on their security and data protection safeguards, bound by a data processing agreement and by appropriate safeguards for transfers outside the EU (Standard Contractual Clauses, Decision 2021/914, and the EU-US Data Privacy Framework where applicable). The list of suppliers and their safeguards is reviewed at least once a year. The list of sub-processors is published in the data processing agreement.
All staff receive training on joining and periodically thereafter on data protection, phishing recognition, credential management, secure use of devices and the incident reporting procedure. Training includes the responsible use of artificial intelligence tools (OpenAI, Anthropic, Google Gemini, Microsoft Copilot): personal data and confidential information in prompts only where necessary, through business plans that exclude model training, with human oversight of the output, in line with Regulation (EU) 2024/1689 (AI Act).
Company tools are intended for work activities. It is not permitted to disable security protections, install unauthorised software, share credentials, transfer confidential information or client data to unapproved services, or upload them to artificial intelligence tools lacking adequate contractual safeguards. Breaches of the Policy are handled under internal procedures and, where relevant, employment law.
The Policy is reviewed by the CTO at least once a year and following significant incidents, organisational or technological changes and regulatory developments. The date of the latest update is shown at the top of the document.
Made in Evolve encourages the responsible reporting of vulnerabilities affecting madeinevolve.com, Nucleo Platform or other systems managed by Made in Evolve. Reports should be sent to help@madeinevolve.com with a description of the issue, the steps to reproduce it and, if available, a proof of concept. Made in Evolve acknowledges receipt within 5 working days, keeps the reporter informed of progress and does not take legal action against anyone acting in good faith, without accessing data beyond what is necessary, without degrading services and without disclosing the vulnerability before it is fixed. For reports of corporate wrongdoing, the help@madeinevolve.com channel is available (Legislative Decree 24/2023).
This English version is provided for convenience; in case of discrepancy the Italian version prevails.