Legal

Information Security & Confidentiality Statement

Website publication copy · Version 1.0 · Issued 25 August 2026 · Next review August 2027

How Rockstone protects information entrusted to the group

POSITIONControls are selected according to risk, contractual duties and applicable law. This statement does not claim certification to ISO/IEC 27001 or any other information-security standard.

Scope

This statement applies to Rockstone Engineering Switzerland Sàrl and Rockstone Engineering Limited, their personnel, systems, information and approved suppliers. It covers personal data, candidate information, client and project information, commercial records, credentials and other confidential material.

Security principles

  • collect and retain only information needed for a defined purpose;
  • classify and handle information according to sensitivity and contractual restriction;
  • grant least-privilege access based on role, review access and remove it promptly when no longer required;
  • use approved managed devices, strong authentication and multi-factor authentication for material systems where supported;
  • protect information in transit and at rest where appropriate to the risk;
  • maintain secure configuration, patching, malware protection, logging, backup and recovery arrangements; and
  • embed confidentiality, privacy and security requirements in procurement, contracting and change management.

People and acceptable use

Personnel receive proportionate security and confidentiality instruction and are bound by contractual duties. Business information must be handled only in approved systems. Credentials must not be shared. Identifiable candidate, client or project information must not be entered into unapproved public AI, file-sharing, messaging or transcription services.

Suppliers and cross-border access

Suppliers are assessed according to the data and service risk. Contracts address confidentiality, security, sub-processing, incident notification, deletion or return and audit or assurance where appropriate. Cross-border personal-data access also requires a lawful transfer mechanism.

Incident management

Suspected loss, misdirection, unauthorised access, phishing, malware, credential compromise or service disruption must be reported immediately. Rockstone contains and investigates incidents, preserves evidence, assesses legal and contractual notification duties, communicates with affected parties where required and records lessons and corrective actions.

Business continuity

Critical services and information are considered in continuity and recovery planning. Backups and recovery procedures are proportionate to business impact and are tested at intervals based on risk. Manual workarounds must not weaken confidentiality or data integrity.

Confidentiality

Confidential information is used only for authorised purposes and disclosed only to people with a legitimate need to know. Confidentiality continues after an engagement ends. Legal compulsion to disclose is escalated and, where lawful, the information owner is notified before disclosure.

Assurance and review

Rockstone reviews controls through access reviews, supplier reviews, incident and action tracking, training records and proportionate technical checks. Material weaknesses are risk-assessed, assigned to an owner and tracked to closure. This statement is reviewed at least annually and after a significant incident or system change.

Contact

Questions or concerns about information security or confidentiality may be sent to info@rockstoneengineering.com. Please identify the Rockstone entity, project, system or information concerned. Rockstone will route the matter to the responsible team and entity.

You may also complain to the Irish Data Protection Commission (www.dataprotection.ie) or the Swiss Federal Data Protection and Information Commissioner (www.edoeb.admin.ch). You may contact the authority in the country connected with your matter; other competent authorities may also be available under applicable law.

Approval

APPROVED BY ROLE EFFECTIVE / REVIEW
Christopher Greenan Director, for and on behalf of both Rockstone entities 25 August 2026 / August 2027