INFORMATION
TECHNOLOGY

3.0
código de conducta, DESC
[conduct]
código de conducta, DESC

3.1    INFORMATION SECURITY

We recognize that Information is an essential and strategic asset of the organization; therefore, we have established guidelines designed to protect DESC’s digital identity, data, technology infrastructure, devices, and applications.
código de conducta, DESC
Our objective is to prevent the unauthorized access, use, alteration, modification, extraction, or destruction of information through monitoring mechanisms and risk management processes that reduce Cybersecurity risks and enable an effective response to safeguard the integrity, confidentiality, and availability of the organization’s environment.

We prohibit the creation, storage, or distribution of messages or files containing harassment, bullying, discriminatory content of any kind, offensive, defamatory, pornographic, fraudulent, or intimidating material, or any content that is contrary to the values and principles governing conduct at DESC; likewise, “chain” messages are prohibited.

3.2     SOCIAL MEDIA

Social media constitutes an important tool for our corporate communications, recruitment, brand positioning, and the strengthening of the Group’s culture.
código de conducta, DESC
When used for business purposes, it must be used in accordance with this Code, applicable law, and our institutional principles of respect, non-discrimination, and personal data protection.

We do not publish the Group’s confidential information through social media, nor do we participate in the dissemination of false information. The Group’s official social media accounts and those of its businesses may only be managed by authorized departments.

On their personal accounts, employees are free to express their opinions, provided they do not compromise the Group’s confidential information or create the impression that they are speaking on behalf of DESC without proper authorization.

3.3     SOFTWARE

We prohibit the use of software for illegal activities or for inappropriate conduct or actions that violate the DESC Code of Conduct. Software must always be used lawfully, ethically, and responsibly; this includes compliance with laws and regulations relating to privacy and copyright, payment of the applicable license and/or subscription fees, and proper maintenance, among other requirements. Our employees comply with the corresponding internal regulations.
código de conducta, DESC

3.4     USERS AND PASSWORDS

User accounts and passwords (access credentials) are personal and non-transferable. Each employee is responsible for using their user account solely for business purposes and must never share their credentials, since any actions performed using such credentials shall be the responsibility of the employee to whom they were assigned.

As employees of DESC, we comply with the Information Technology policies and procedures and report any deviations that we identify.
código de conducta, DESC

3.5     CYBERSECURITY

We protect the organization’s information, systems, and digital assets against cyber risks and threats.
código de conducta, DESC
We operate under a cybersecurity framework that enables us to prevent, detect, and respond promptly to incidents that may compromise the confidentiality, integrity, and availability of data. We maintain practices and controls that ensure the secure and responsible use of information technologies, as well as the protection of the personal data and confidential information of our employees, customers, suppliers, and other stakeholders.

3.6     RESPONSIBLE USE OF ARTIFICIAL INTELLIGENCE

We recognize both the potential and the risks associated with the use of Artificial Intelligence (AI) in our operations. Its adoption is governed by the principles of transparency, human oversight, and personal data protection, under a responsible innovation approach.
código de conducta, DESC

2.1.1    Creación de valor

La Creación de Valor y la protección del patrimonio de los socios y accionistas son nuestra prioridad como Grupo DESC, y es responsabilidad primaria la generación de rentabilidad sin comprometer el crecimiento y sustentabilidad de los negocios en el largo plazo.

2.1.2    Protección de activos

Salvaguardamos y conservamos los activos de Grupo DESC, protegiéndolos de toda pérdida, sustracción y uso indebido, con el propósito de generar beneficios para nuestro Grupo.

2.1.3    Manejo adecuado de la información

La información generada y desarrollada por el personal como resultado de sus actividades laborales es propiedad de Grupo DESC.Nos comprometemos a asegurar el buen uso y cuidar las patentes, marcas y derechos de propiedad intelectual e industrial de Grupo DESC.Protegemos la información que nos confían nuestros accionistas, socios comerciales, empleados, clientes y proveedores. El acceso a este tipo de información obligará a celebrar los convenios de confidencialidad correspondientes, cuando así se requiera. Cualquier intercambio de información confidencial con competidores, organismos o cualquier persona ajena a Grupo DESC debe estar previamente consultado con la Dirección General Adjunta (a cargo del área Jurídica) y autorizado por la Dirección General, en términos de las disposiciones legales aplicables.

2.1.4    Participación o interés financiero en otras empresas

Evitamos tener cualquier participación o interés financiero directo con cualquier cliente, proveedor o competidor actual. Se entiende como “interés financiero activo” como el ser dueño, accionista o familiar directo de un socio o algún otro empleado de cualquier empresa o sociedad que sea cliente, proveedor o competidor de algún negocio de Grupo DESC. En caso de tener un interés financiero directo adquirido con anterioridad a la relación de dicho tercero con Grupo DESC, esta situación deberá revelarse al Director superior responsable, y se deberá abstener de participar en la toma de cualquier decisión en relación con dicho tercero. Cualquier excepción a lo anterior, deberá tener previa notificación y autorización de la Dirección superior responsable. En caso de Consejeros que se encuentren en dicha situación se procederá a comentar con el Comité de Auditoría y Prácticas Societarias.

2.1.4    Consejos de administración externos

Se requiere la aprobación expresa de la Dirección General del Grupo para poder participar en cualquier Consejo de Administración u órgano administrativo similar en alguna compañía o sociedad con fines de lucro que no forme parte de Grupo DESC. En el caso de asociación y organizaciones civiles sin fines de lucro, deberán comunicarlo a su Dirección superior responsable.
Aware of the risks to privacy, human rights, and the security of our assets, we establish the following guidelines:
  • Mandatory authorization: Any AI service or tool must receive prior authorization from the Information Technology Management Department and, where necessary, from the Legal Department
  • Asset protection: It is strictly prohibited to input confidential information, including personal data, trade secrets, internal processes, or similar information, into any unauthorized AI tool.
  • Information integrity: We prohibit the intentional generation of false, harmful, biased, or discriminatory content.