This Information Security Policy was approved on December 4, 2025, by the Management of Hybrid Energy Storage Solutions S.L., hereinafter HESSTEC.
This Information Security Policy remains in effect until it is replaced by a new policy. It will be reviewed, along with any proposed updates or maintenance, at least annually.
To ensure information security and the continued provision of the organization’s services, HESSTEC acts proactively by taking appropriate measures to protect systems against accidental or deliberate damage, monitoring daily activity, and responding promptly to incidents.
To defend systems and information against threats that compromise their confidentiality, integrity, availability, authenticity, and/or traceability, a strategy involving all personnel who handle the organization’s information is required.
Following the requirements defined by ISO 27001, the National Security Framework (hereinafter, ENS), and the NIS2 Directive, as well as other additional security initiatives, HESSTEC considers information security holistically.
Therefore, this Security Policy is defined and communicated to all employees for their awareness and compliance. Both this policy and the regulations and procedures derived from it will be reviewed, updated, and disseminated periodically (and whenever necessary) to address potential new risks and threats and to continuously improve the effectiveness of the information security methods applied.
This document was prepared using as a reference the guides “CCN – STIC 805 Information Security Policy” and “CCN – STIC 801 National Security Framework: Responsibilities and Functions,” prepared by the National Cryptologic Center.
2.1. Prevention
HESSTEC must avoid, or at least prevent to the extent possible, the disruption of information or services due to security incidents. To this end, the minimum security measures determined by the National Security Scheme (ENS) must be implemented, as well as any additional controls identified through a threat and risk assessment. These controls, and the security roles and responsibilities of all personnel, must be clearly defined and documented.
To ensure compliance with the policy, HESSTEC:
• Authorizes systems before they are put into operation.
• Regularly assesses security, including evaluations of routinely performed configuration changes.
• Requests periodic third-party reviews to obtain an independent assessment.
2.2. Detection
Since services can degrade rapidly due to incidents, ranging from a simple slowdown to complete shutdown, service operation must be continuously monitored to detect potential anomalies in service levels and take appropriate action as established in Article 10 of the National Security Framework (ENS).
Monitoring is especially relevant when establishing lines of defense in accordance with Article 9 of the ENS. Detection, analysis, and reporting mechanisms will be established and regularly communicated to the relevant stakeholders, particularly when a significant deviation from pre-established normal parameters occurs.
2.3. Response
HESSTEC:
• Establishes mechanisms to respond effectively to security incidents.
• Designates a point of contact for communicating detected incidents to potential stakeholders (customers, suppliers, partners, regulatory authorities, etc.).
• Establishes protocols for exchanging information related to the incident. This includes two-way communication with Computer Emergency Response Teams (CERTs) and, if necessary, with law enforcement agencies and the Spanish Data Protection Agency.
2.4. Recovery
To ensure the availability of critical services, HESSTEC has developed various measures and strategies, such as identifying and assessing risks to implement preventive measures and mitigate them in a timely manner.
This Policy applies to HESSTEC’s information systems that support the design and engineering services, solutions, and control products for on-premises and cloud-based energy storage, as well as the monitoring and remote operation services provided by HESSTEC, in accordance with the current Statement of Applicability.
This applies specifically to software development and IT systems services, and to all personnel directly or indirectly involved in the provision of these services, whether internal or external to the organization.
HESSTEC is a pioneering company in the design, development, supply, and operation and maintenance (O&M) of hybrid energy storage solutions for the next generation of electrical grids. HESSTEC’s mission is to achieve the effective integration of energy storage into the current energy transition, enabling an environmentally responsible and self-sustaining energy model based on the integration of renewable energy sources and a reduction in the carbon footprint. In this context of change, new energy assets and models are emerging, creating a need for enabling technologies, such as energy storage, that provide manageability and flexibility to the electricity grid (and therefore to its operators), achieving maximum profitability from their assets, both operationally and economically.
HESSTEC was founded in February 2018 and is the continuation of a dream begun in 2008 by a group of professionals, led by Eugenio Domínguez. Eugenio, the company’s CEO, has spent the last 20 years researching and developing enabling technologies for the energy storage industry, and is a renowned expert in energy storage and power electronics technologies at both the academic and business levels. Alongside him is a large, diverse, and multidisciplinary team of professionals with more than 15 years of experience in the technology sector and the innovation ecosystem. HESSTEC is a Spanish limited liability company headquartered in Paterna (Valencia), with its R&D center in Seville.
Mission and Vision
HESSTEC offers turnkey energy storage and grid asset optimization solutions for a wide range of scenarios: from renewable energy integration and distribution/transmission network applications to electric vehicle infrastructure and a variety of microgrids, both isolated and connected. HESSTEC’s solutions are based on a disruptive hybrid approach, built on its patented algorithms and grid asset operation and degradation models. This allows energy storage systems to perform multiple applications, thereby improving the profitability of grid assets.
We are the link between our clients’ needs and the technological capabilities of energy storage and management systems.
HESSTEC Values
• We provide technological solutions that address real-world electrical grid challenges, supporting the energy transition with 20 years of experience.
• Revolutionary proprietary technology focused on cost-effective energy storage and power electronics solutions, maximizing the value and profitability of energy assets.
• We are pioneers in the creation of efficient hybrid energy storage solutions, whose effectiveness has been proven.
• We have an advanced Grid Laboratory, a key factor in testing solutions under real-world conditions.
In order to guarantee the effective protection of information and corporate resources necessary for the proper functioning of the services provided by HESSTEC, from both external and internal threats, and defining said protection in terms of quality and security, the following objectives and basic principles are established:
• Comply with the legal and contractual requirements applicable to the performance of their duties within the organization, especially, and for the purposes of this Policy, in matters related to the provision of services, the protection of personal data, and the continuity of business processes.
• Communicate to all personnel the need and obligation to comply with and enforce applicable information security policies and regulations, individually according to their roles within the organization.
• Restrict the use of both the information itself and the systems that process it to those tasks necessary for the proper performance of each person’s work. The use of any HESSTEC asset for personal gain is prohibited.
Regarding information, considered one of HESSTEC’s main assets, it is the duty of all personnel to maintain its confidentiality and not disclose it to third parties, unless such communications are an essential part of the employment relationship and comply with the established confidentiality guarantees.
• Create and maintain an Information Security Management System (ISMS), which includes the policies, regulations, procedures, and guidelines necessary to communicate security requirements to the various areas of the organization in order to protect HESSTEC’s information and assets.
In general, the most relevant regulations applicable to HESSTEC are included in this policy and are as follows:
• General Data Protection Regulation (Regulation (EU) 2016/679).
• Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights.
• Law 34/2002, of July 11, on Information Society Services and Electronic Commerce.
• Law 1/2019, of February 20, on Trade Secrets.
• Law 10/2021, of July 9, on Remote Work.
• Royal Decree 311/2022, of May 3, regulating the National Security Framework (ENS).
• Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022, on measures for a high common level of cybersecurity across the Union (hereinafter, NIS2).
• Regulation (EU) 2024/1689 of the European Parliament and of the Council of June 13, 2024, laying down harmonised rules in the field of artificial intelligence.
• ISO 27001:2023 and ISO 27002:2023 standards.
• Security Contact Point: For any questions, incidents, or reports related to this policy, please contact:
- Name: David Garcia
Role: Security Officer
Email: ciberseguridad@hesstec.net
In addition, HESSTEC maintains an internal register that compiles all applicable legal and regulatory frameworks.
When HESSTEC provides services to other organizations or handles information from other organizations,
• they will be informed of this Information Security Policy,
• channels will be established for reporting and coordinating the respective security committees, and
• procedures will be established for responding to security incidents.
When HESSTEC uses third-party services or shares information with third parties, they will be informed of this Security Policy and the Security Regulations applicable to those services or information. This third party will be subject to the obligations established in the regulations, and may develop its own operating procedures to comply with them. Specific procedures for reporting and resolving incidents will be established.
The processing of personal data in information systems will at all times comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), as well as the security measures required for the processing of personal data under Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDDGG).
The Record of Processing Activities includes the personal data processing carried out by HESSTEC, as well as other relevant information, such as the legal basis for the processing, the purposes, the retention periods, and the recipients (transfers of personal data).
All HESSTEC information systems will comply with the security levels required by law for the nature and purpose of the personal data collected in the record of processing activities. The security measures implemented will depend on the risk analysis carried out and will aim to reduce the level of risk through the application of technical security measures related to the guidelines of the ENS, ISO 27001 and NIS2, and legal measures related to the articles of the GDPR.

