Rosepetal Compliance
Internal documentation
This document is for internal use only and must not be distributed to third parties. © Rosepetal SL. All rights reserved.
Table of Contents
- Introduction
- Objectives and scope of this document
- Commitment to regulatory compliance
- General regulatory framework applicable in the EU
- Compliance by subject area
- a. Intellectual property and software licensing
- b. GDPR (General Data Protection Regulation)
- c. ISO 27001 (Information Security Management)
- d. Cyber Resilience Act
- e. NIS2 Directive (Network and Information Systems Security)
- Compliance by sector
- a. Software for the public and government sector
- b. Pharmaceutical and healthcare sector (FDA 21 CFR Part 11, MDR, IEC 62304, ISO 13485)
- c. Food sector (HACCP, ISO 22000)
- Internal implementation: policies, training and audits
- Auditing, monitoring and continuous improvement
- Annexes
Introduction
Rosepetal's mission is to develop cutting-edge AI-powered machine vision solutions for quality control of manufactured products, ensuring our customers' operational excellence. From the outset we have taken a proactive approach to regulatory compliance: our customers' trust and the reliability of our solutions depend on strict adherence to the applicable regulations. Our technology is integrated into diverse and highly regulated industrial environments, so we ensure that every aspect of our software and operations complies with the legal and quality standards in force in the European Union and internationally.
We serve a wide range of industrial sectors, each with its own regulatory requirements:
- Manufacturing industry (general manufacturing and industrial assembly)
- Food and beverages (food processing, bottling, packaging)
- Graphic arts (industrial printing, graphic packaging)
- Pharmaceutical products (drug manufacturing and biotechnology)
- Rubber and plastics (production of plastic and rubber components)
- Non-metallic products (ceramics, glass, construction materials)
- Metal products (metallurgy, metal parts, capital goods)
- Electronic products (circuits, semiconductors, electronic devices)
- Electrical equipment and materials (electrical components and appliances)
- Machinery and equipment (manufacturers of industrial machinery and equipment)
- Motor vehicles (automotive and transport industry)
- Medical and aerospace research (R&D environments with high quality standards)
Across all these sectors we apply the highest standards of regulatory compliance, adapting our solutions to the specific regulations of each industry and country, always within the general framework of European legislation.
Objectives and scope of this document
The purpose of this document is to inform our customers and stakeholders about the company's regulatory compliance policies and practices. It describes the legal requirements and standards applicable to our AI-powered machine vision software solutions for quality control, as well as the compliance measures implemented. The scope covers:
- Products and services developed by the company, especially the machine vision software and any accompanying hardware components.
- Internal processes for development, implementation, maintenance and support, insofar as they are subject to regulation (data management, information security, quality management).
- Relationships with customers and partners: how we protect the information entrusted to us, how we respect intellectual property, and how we guarantee the continuity and security of our services.
- Regulated sectors we serve, specifying particular regulatory frameworks (public sector, healthcare/pharmaceutical, food, etc.) and how we adjust our practices to each context.
This document does not replace specific legal advice, but it demonstrates our transparent commitment to compliance. Customers may use it in their due diligence processes and audits. We also define the boundaries and responsibilities: our compliance covers the company's obligations as a technology provider, while customers must ensure compliance in their integration and end use of the solutions.
Commitment to regulatory compliance
Senior management has established a culture of compliance as a fundamental pillar of our mission and corporate values. Specific commitments:
- Proactive compliance: we stay ahead of legal obligations, integrating regulatory requirements from the earliest design phases (compliance by design). We carry out initial regulatory impact assessments for every new project.
- Continuous updating: we maintain a regulatory watch system to track changes in laws, regulations and technical standards in the EU, including the EU AI Act.
- Dedicated resources: we have a multidisciplinary regulatory compliance team (legal, quality, IT security and privacy specialists) that works cross-functionally with all departments.
- Transparency and ethics: we foster transparency in operations and respond promptly and honestly to any compliance-related query or incident.
- Zero tolerance for non-compliance: any deviation is addressed immediately through correction and improvement procedures; we conduct internal investigations of incidents and make no concessions that compromise the security or legality of our products.
In short, we aim to turn compliance into a competitive advantage: securing our customers' trust and facilitating the integration of our solutions into strict regulatory environments.
General regulatory framework applicable in the EU
The general EU regulatory frameworks most relevant to our operations:
- Personal data protection (GDPR): applicable to any organization processing personal data of EU citizens. It imposes principles of purpose limitation, data minimization and confidentiality, with severe fines for non-compliance. We ensure full compliance through technical and organizational measures.
- Intellectual property and licensing: we are governed by copyright and patent laws, we comply with the license terms of all third-party software, and we protect our own intellectual property through copyright registrations, confidentiality agreements and, where appropriate, patents.
- Cybersecurity and digital resilience: the Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for manufacturers of products with digital components at all stages. From 2027, products must bear the CE marking of conformity under the CRA. We are already adapting proactively: product security risk assessment, cybersecurity documentation (SBOM, incident response plans, security manuals) and certification plans.
- Information security and essential services: the NIS2 Directive (2022) establishes obligations for a broad range of critical sectors. Although our company may not be an "essential entity", many of our customers are; we have therefore aligned our Information Security Management System with the requirements of NIS2 and ISO 27001.
- International standards (ISO):
- ISO 27001 (Information Security): we hold the certification (or faithfully follow its guidelines), ensuring the confidentiality, integrity and availability of information.
- ISO 9001 (Quality Management): we maintain a Quality Management System to ensure consistent quality of products and services.
- Other sector-specific ISO standards: ISO 13485 for medical devices, ISO 22000 for food safety, depending on the customer's sector.
In summary, the framework encompasses horizontal laws (GDPR, CRA/NIS2, intellectual property) and vertical or sector-specific regulations (MDR, food legislation, etc.).
Compliance by subject area
For each area we describe the relevant regulations, their relevance, the key requirements and the compliance strategies implemented.
a) Intellectual property and software licensing
Relevance: protecting the IP of our own developments and respecting third-party IP. Non-compliance could lead to legal disputes, financial losses and reputational damage.
Key requirements:
- Copyright: all the code we write is automatically protected; we do not incorporate third-party code without authorization (except open source under licenses that permit it).
- Third-party software licenses: strict compliance with the terms of each license (GPL requires releasing source code when redistributing derivatives; MIT/BSD require attribution). We control the number of users/installations of commercial software and avoid combinations of incompatible licenses.
- Patents and industrial property: we conduct patent searches in sensitive areas and evaluate patenting significant in-house innovations.
- Trademarks and branding: we respect third-party trademarks and protect our own distinctive signs.
- Confidentiality and trade secrets: NDAs with employees, suppliers and partners who access sensitive information (source code, algorithms, training data).
Compliance strategies:
- Corporate Intellectual Property Policy with zero tolerance for unauthorized code copying.
- Third-party software inventory (SBOM): record of version, license and restrictions for each component; legal/technical review before using any new library.
- Automated license scanning tools on the code.
- Regular training and awareness for developers.
- Specialized IP legal counsel for particular cases.
- IP incident management: protocol for isolation, review, replacement and documentation. To date we have not faced any IP disputes.
Our customer contracts include IP infringement indemnification clauses, backed by specific insurance.
b) GDPR (General Data Protection Regulation)
Relevance: high at three levels: (1) internal operations (employee, customer and supplier data); (2) products, if they process personal data (e.g., images in which people or line operators appear); (3) as data processors for some customers.
Key requirements:
- Lawfulness, fairness and transparency: a valid legal basis for all processing and clear information for data subjects.
- Purpose limitation and data minimization: we only collect strictly necessary data. In algorithm development we use anonymized or synthetic data whenever possible.
- Data security: encryption at rest and in transit, strict access controls, pseudonymization/anonymization, and breach response plans (aligned with ISO 27001).
- Data subject rights: we design our solutions to facilitate the exercise of access, rectification, erasure and objection rights, plus those added by GDPR (restriction, portability, no automated decision-making).
- Impact Assessment and Privacy by Design: we collaborate on DPIAs with customers where appropriate; our interfaces allow enabling/disabling the collection of certain personal data.
- Security breach notification: incident and breach management procedure aligned with GDPR (notification within 72 hours).
Compliance strategies:
- Record of processing activities (Art. 30 GDPR), both as controllers and as processors.
- Privacy policy and contractual clauses: Data Processing Agreements in accordance with Art. 28 GDPR.
- Designated Data Protection Officer (DPO).
- Privacy training and awareness for all employees, tailored to their role.
- Technical privacy measures: pseudonymization, limited retention and testing with synthetic data.
- Regular internal and external privacy audits.
- Insurance and legal backing for privacy/cybersecurity incidents.
To date we are in full compliance with the GDPR, with no sanctions or corrective orders.
c) ISO 27001 (Information Security Management)
Relevance: information security is critical given the sensitivity of the data we may process (quality control results, product images, industrial technical information) and the need for 24/7 availability in production environments. ISO 27001 is the de facto standard that many corporate and government customers require.
Key requirements: implementation of an Information Security Management System (ISMS):
- Context and scope of the ISMS (development, implementation and support of the software, including infrastructure).
- Continuous security risk assessment of information assets.
- Statement of Applicability (SoA) and selection of controls (policies, organizational security, HR, asset management, access control, cryptography, physical security, communications and operations, development, third parties, incidents, continuity, legal compliance).
- Implementation of controls: role-based access control, MFA on critical services, strong encryption, backups and disaster recovery, network monitoring, penetration testing, secure development.
- At least annual training and awareness for all staff.
- Documentation and procedures (policies, procedures, records).
- Regular internal audits and management reviews.
- Continuous improvement under the PDCA cycle (Plan-Do-Check-Act).
- Certification with annual surveillance audits and three-year renewal.
Compliance strategies:
- Dedicated security team with a CISO.
- Information Security Manual containing all policies, available on the intranet and reviewed at least annually.
- Robust technical controls: access management with least privilege and MFA; static code and dependency analysis in CI/CD; infrastructure protection (firewalls, segmentation, 24/7 monitoring, EDR, disk encryption, patch management); Business Continuity and Disaster Recovery Plan; supplier security assessment; strong cryptography (AES-256, TLS 1.2/1.3) with secure key management.
- Semi-annual internal audits and third-party audits (annual pentests), in addition to certification audits.
- Quarterly Information Security Committee with action tracking.
d) Cyber Resilience Act
Relevance: the CRA (adopted in 2024) directly affects manufacturers and developers of products with digital elements. Once fully applicable (end of 2027), we will need to certify that our solutions meet the essential cybersecurity requirements in order to offer them on the European market: it is a market access requirement.
Key requirements:
- Secure design and development (security by design): risk analysis, minimal attack surfaces, secure coding, secure default configuration, data minimization.
- Essential cybersecurity requirements (Annex I): no known vulnerabilities at release, data protection, continuity of critical functions under attack, strong passwords (no universal default credentials), security event logging.
- Security updates and vulnerability management: security support for a defined period (typically ≥5 years), vulnerability monitoring, a responsible disclosure channel and notification of exploited vulnerabilities to the authorities. We already have a vulnerability management procedure, SBOM and a Security Contact channel on our website.
- Technical documentation and conformity: cybersecurity technical documentation per product and EU declaration of conformity.
- Conformity assessment (CE): internal self-assessment for most products; assessment by a notified body for critical products. We anticipate falling into the general category (self-assessment).
Compliance strategies:
- Integration into the development process: CRA cybersecurity checklist before each major release (dependencies free of vulnerabilities, internal pentesting, verification of security functions, checks for the absence of backdoors).
- Hardening and secure configuration by default; hardening guides for customers.
- Bug bounty program or external audits: annual pentests with certified firms; bug bounty under evaluation.
- Update plan and extended support: Security Maintenance Plan with guaranteed patches and customer notification.
- Documentation and conformity management: CRA technical documentation in preparation, following ENISA guidance and harmonized standards (ISO 27002, ETSI EN 303 645).
- CE marking procedure simulation before the effective date.
- Coordination with customers and suppliers: contractual requirement for suppliers to meet equivalent security requirements.
e) NIS2 Directive (Network and Information Systems Security)
Relevance: Directive (EU) 2022/2555 is the European cybersecurity framework for sectors of critical importance. Unlike the CRA (products), NIS2 focuses on organizational cybersecurity and essential services. Many of our customers are essential or important entities (food, pharmaceutical, hospitals, transport, public administration), and our systems are integrated into their infrastructures: we must be a strong link in their cybersecurity chain. In Spain, this connects with the Spanish National Security Framework (ENS).
Key requirements:
- Risk management measures: risk analysis and security policies; incident management; business continuity; supply chain security; network and system security; vulnerability and update management; periodic assessments; cryptography and access control with MFA.
- Incident notification: initial notification within 24 hours, interim report at 72 hours and final report within one month. As a supplier, we contractually commit to informing customers immediately if we detect an incident in our solution that affects them.
- Cooperation and supervision: willingness to provide evidence of compliance (certifications, pentests, questionnaires) under confidentiality agreements.
- Fines and penalties: up to 10 million euros or 2% of global turnover for essential entities, which pressures customers to demand a high level of security from their suppliers.
Compliance strategies:
- Mapping of ISO 27001 controls to NIS2 to ensure our ISMS meets or exceeds NIS2 measures (MFA, supply chain, incidents and continuity per ISO 22301/27031).
- Services for essential customers: robust SLAs with 24/7 support for security incidents and SIEM/SOC integrations.
- ENS compliance (Spain): ENS conformity assessments at Medium or High level depending on the project, including CCN audits.
- Cyber insurance and collaborative response: joint cybersecurity exercises with critical customers, 24/7 contact and cyber insurance in place.
- Regulatory monitoring of NIS2 transposition in the countries where we operate.
Compliance by sector
Each industrial sector has specific regulations. Summary of compliance by sector:
| Sector | Key regulations/standards | Compliance approach |
|---|---|---|
| Public and government sector | Spanish National Security Framework (ENS); NIS2 Directive; GDPR | Controls aligned with the ENS (system classification, strong authentication, activity logging, secure backup); ISO 27001 ISMS covering NIS2; strict privacy and confidentiality policy for citizen data |
| Pharmaceutical and healthcare sector | FDA 21 CFR Part 11; Regulation (EU) 2017/745 (MDR); IEC 62304; ISO 13485; GMP (EU GMP Annex 11) | Software with a unique electronic signature per user, access controls and tamper-proof audit trails; IQ/OQ/PQ validation; development aligned with IEC 62304 and MDR; ISO 13485 QMS; GAMP5 guidelines |
| Food sector | HACCP; ISO 22000; EU food legislation (Regulation (EC) 178/2002, traceability) | Integration into HACCP plans as critical control points (CCPs); reliable, traceable and securely stored data; hygienic equipment design; alignment with ISO 22000 |
Note: we also comply with other applicable sector regulations such as IATF 16949 (automotive), AS9100/DO-178C (aerospace) and accessibility and open-standards requirements in the public sector.
a) Software for the public and government sector
- National security frameworks: in Spain, the ENS is mandatory for public sector systems, with Low, Medium and High levels. We have achieved Medium-level conformity in several deployments (2FA for administrators, full access traceability, encryption with CCN-approved algorithms, offline backups, intrusion testing) and High level in one project (geographic redundancy, approved intrusion detection), following CCN guidance.
- NIS2 compliance in public administrations: we act as a supplier that helps the Administration meet NIS2 for the portion of the system within our remit (incident coordination policies, joint risk assessments, pentest results).
- Accessibility and open standards: compliance with WCAG 2.1 / EN 301 549 in public-facing interfaces; standard export formats (CSV, JSON) and open protocols.
- Public procurement and tenders: transparency in meeting legal requirements, certifications (ISO 27001, ENS), compliance with the Spanish Public Sector Contracts Law and with data protection regulations in the public sector.
- Data sovereignty and location: on-premises deployment options or sovereign clouds in the EU; we do not transfer public bodies' data outside the EU without a legal basis.
- Protection against specific threats: additional code analysis to detect backdoors, code signing, zero trust principles and, if required, cryptography certified by national bodies.
- Training and awareness for the public entity's staff on the secure use of the solution.
- Monitoring and reporting: logs compatible with the body's SIEM and regular security and compliance reports.
b) Pharmaceutical and healthcare sector
A sector governed by especially strict regulations (patient safety, GMP, EMA/FDA). Our machine vision is used in quality inspection in drug production, packaging verification, pill counting, print control on packaging and AI-based automated diagnosis.
- 21 CFR Part 11 (FDA) and EU Annex 11: trusted electronic records and signatures. We comply by implementing:
- Individual access control: individual accounts with unique credentials, no shared generic accounts.
- Electronic signature with traceability: every approval is signed with identity, date, time and reason.
- Audit trail: a secure, tamper-proof audit trail that records all critical actions while preserving previous values; unalterable and always available for inspection (ALCOA+ principle).
- Software validation: validation packages and support for IQ/OQ/PQ qualification; requirements-to-tests traceability matrix.
- Data security and integrity: automatic backups, checksums, permission restrictions.
- Recommended SOPs for using the system in a regulated environment.
- End-user training for pharmaceutical operators and supervisors.
- MDR (Medical Device Regulation) and IEC 62304:
- Classification as a medical device: we determine whether the software qualifies as an MD; if so, we assume the manufacturer's obligations (CE marking, conformity assessment, QMS in accordance with MDR/ISO 13485).
- Design per IEC 62304: safety classification (A/B/C), software risk management integrated with ISO 14971, complete development files.
- MDR/IVDR compliance: technical documentation for the customer's file, post-market surveillance and a Person Responsible for Regulatory Compliance.
- ISO 13485 QMS: documented change control, management of non-conformities and CAPAs, specialized training; medical device customer audits passed.
- GMP and validation in pharmaceutical environments: controlled change under GMP with URS/DS; IQ (installation), OQ (operation) and PQ (performance) qualification; deviation documentation; staff trained in GMP/GDP; support during regulatory audits (FDA/EMA) with no non-conformities to date.
- Confidentiality and R&D protection: strict NDAs, isolated on-premise solutions with no internet connection if requested, and compliance with technology export restrictions.
c) Food sector (Food and beverages)
A sector heavily regulated in food safety. We frame our systems within the customer's food safety plans:
- HACCP system: joint analysis of whether our system acts as a CCP (critical control point) or a quality control point; definition of critical limits; continuous monitoring with alarms and logging of all events; procedures and corrective actions; participation in periodic re-analyses by providing historical data.
- ISO 22000 and food certifications (FSSC 22000, BRC, IFS): we support compliance by ensuring our processes introduce no risks (SOPs for work in food factories, clothing, glass prohibition); documentation for integration into their system; prerequisite programs (maintenance, calibration, cleaning); availability during BRC/IFS audits.
- Hygienic design and material conformity: EHEDG guidelines; food-grade stainless steel, smooth surfaces, rounded edges, IP66/67 protection, certified materials (EU Regulation 10/2011) with certificates of conformity; post-installation validation and swab tests if required.
- Traceability and records: electronic records of all processed batches (Regulation (EC) 178/2002); batch blocking in the event of serious defects; data analytics for management system review; retention per the customer's policy.
- Allergen management and labeling: OCR verification of allergen lists, expiration dates and label swap detection (Regulation 1169/2011).
- Food defense plan: detection of visible contaminants and robust user controls over critical configurations.
- Response to quality/food safety incidents: support in the investigation with system data and participation in corrective actions.
Internal implementation: policies, training and audits
- Internal compliance policies:
- Regulatory Compliance Policy (framework, approved by Management, with confidential whistleblowing channels).
- Information Security Policy (ISO 27001).
- Data Protection Policy (GDPR).
- Secure Software Development Policy (OWASP, code reviews, hardening criteria).
- Quality Control and Validation Policy.
- Intellectual Property and Licensing Policy.
- HR Compliance Policy (confidentiality, Code of Conduct).
- Each policy is communicated to all employees, with signed acknowledgment of receipt for critical ones.
- Training and education: onboarding for new employees; mandatory annual training (information security, data protection) with assessments (>95% pass rate); role-specific training (development, sales, projects); drills and awareness campaigns.
- Internal audits:
- Annual ISO audits (27001, 9001) by staff independent of the area audited.
- Legal compliance audits (GDPR, licenses using SAM tools).
- Pre-delivery industrial compliance inspections for highly regulated customers.
- After each audit, an action plan with owners and deadlines.
- Management reviews: annual Regulatory Compliance Review meeting (regulatory changes, audit results, incidents, KPIs, investments).
- Integration into day-to-day management: compliance review at the proposal stage of every project; compliance guidelines in kickoff meetings; compliance checklists per department; compliance calendar with milestones.
- Compliance culture: internal ticketing system for compliance questions and public recognition of milestones.
- External resources: specialized consultancies and advisors (legal tech, cybersecurity, healthcare regulation) and participation in professional associations.
Our internal implementation is based on structures (policies), people (training) and verification (audits).
Auditing, monitoring and continuous improvement
Compliance is a continuous process:
- Active compliance monitoring:
- Compliance KPIs: % of training completed (target 100% annually), security incidents (0 serious), critical vulnerability patching time (<1 week), contracts updated with the latest clauses (100% on renewals). Monthly review.
- Technical monitoring tools: SIEM, DLP and configuration alerts.
- Legal tracking: monitoring of official gazettes and agencies (AEPD, ENISA, EMA).
- Customer and employee feedback: open channels to flag improvements.
- External audits and certifications: annual ISO certification audits; customer audits (pharmaceutical, automotive); assessment schemes such as security CMMI or TISAX.
- Incident management and lessons learned: formal procedure (detection, containment, eradication, recovery, communication, recording); blameless post-mortem investigation; preventive actions; internal knowledge base.
- Continuous improvement — PDCA cycle: annual Compliance Improvement Plan with specific objectives, execution with assigned owners, verification in committees and adjustment of the following plan.
- Compliance innovation: AI for compliance, automation (repository scanning, cookie/ePrivacy verification), benchmarking and tracking of emerging certifications (trustworthy AI certification).
- Improvement commitment to customers: a compliance section in QBRs and voluntary assessment against customers' checklists.
Annexes
Annex A: Regulatory and legislative references
- GDPR – Regulation (EU) 2016/679: the EU General Data Protection Regulation.
- ISO/IEC 27001:2013/2022: Information security management systems — Requirements.
- Cyber Resilience Act: Regulation on horizontal cybersecurity requirements for products with digital elements, COM(2022) 454 final (entry into force December 2024, applicable from 2027).
- Directive (EU) 2022/2555 (NIS2): measures for a high common level of cybersecurity across the Union.
- Spanish National Security Framework (ENS): Royal Decree 311/2022.
- 21 CFR Part 11 (FDA): Electronic Records, Electronic Signatures.
- EU GMP Annex 11: EudraLex Vol.4 — Computerised Systems (European equivalent of 21 CFR 11).
- Regulation (EU) 2017/745 (MDR): medical devices.
- Regulation (EU) 2017/746 (IVDR): in vitro diagnostic medical devices.
- IEC 62304:2006/AMD:2015: Medical device software — Software life cycle processes.
- ISO 13485:2016: Medical devices — Quality management systems.
- ISO 9001:2015: Quality management systems — Requirements.
- ISO 22000:2018: Food safety management systems.
- HACCP: Hazard Analysis and Critical Control Points (Codex Alimentarius, CAC/RCP 1-1969, Rev.4-2003).
- BRCGS Food Safety Standard / IFS: global food safety standards.
- IATF 16949:2016: quality requirements for automotive production.
- AS9100: aerospace quality systems.
- ENSIA / ENS: national information security frameworks.
- EU AI Act: regulation on AI by risk level (an emerging framework to monitor).
Annex B: Internal compliance templates and documents
Available to customers or auditors upon request, under confidentiality agreements where appropriate:
- Data Protection Impact Assessment (DPIA) template in accordance with Art. 35 GDPR.
- Security Incident Response Procedure (flowchart and checklist).
- Secure Release Checklist (licenses, security testing, documentation).
- Non-Conformity and Action Record (CAPA) form.
- Sample EU Declaration of Conformity (directives/regulations and harmonized standards).
- Executive compliance summary for customers (certifications, GDPR adherence, supplier commitments).
- Audit History of external and internal audits with dates, scope and results.