Ethics & compliance
CAPTiX code of ethics, anti-corruption policy, data security principles and whistleblowing channel.
Our commitment
At CAPTiX, integrity is the foundation of our business. We are committed to conducting all our activities in a lawful, ethical, and socially responsible manner. This policy outlines the core principles that guide our employees, contractors, and partners. We aim to protect the interests of our customers, shareholders, employees, and the industrial ecosystem we serve.
The elements of our ethics and compliance program:
- Code of Ethics & Business Conduct
- Anti-Corruption & Anti-Bribery Policy
- SaaS Security & Data Integrity Principles
- Whistleblowing Policy (Reporting Violations)
Code of Ethics & Business Conduct
This Code of Ethics & Business Conduct outlines the fundamental principles and values that guide CAPTiX in its daily operations. It applies to all employees, contractors, consultants, and agents acting on behalf of CAPTiX.
Compliance with laws — CAPTiX is committed to full compliance with all applicable laws and regulations in Poland and the European Union. Employees must respect the legal framework of the jurisdictions in which we operate, including but not limited to labor laws, competition laws, and data protection regulations (GDPR).
Honesty — we communicate openly and truthfully with our clients, partners, and colleagues.
Conflict of interest — employees must avoid situations where their personal interests conflict, or appear to conflict, with the interests of CAPTiX. Any potential conflict must be immediately disclosed to the Compliance Officer.
Fair competition — we compete vigorously but fairly. We do not enter into anti-competitive agreements or discuss pricing/market allocation with competitors.
Respect and non-discrimination — CAPTiX fosters a workplace free from discrimination and harassment. We treat everyone with dignity and respect, regardless of race, gender, religion, age, disability, or sexual orientation.
Anti-Corruption & Anti-Bribery Policy
Zero tolerance — CAPTiX maintains a zero-tolerance approach to bribery and corruption. This policy complies with relevant Polish anti-corruption laws and international standards.
Prohibited actions:
- No bribery — employees and representatives are strictly prohibited from offering, promising, giving, or accepting any financial or other advantage to induce or reward improper performance of a relevant function or activity.
- No grease payments — employees and representatives are strictly prohibited from making "facilitation payments" (small payments to speed up routine government actions).
- No self-funding — employees and representatives are strictly prohibited from using personal funds to accomplish what cannot be done with Company funds.
Gifts and hospitality:
- Acceptable: modest gifts or hospitality (e.g., a business lunch, branded promotional items) that are reasonable, proportionate, and intended to build business relationships.
- Prohibited: cash gifts, lavish entertainment, or any gift offered during a tender process or contract negotiation intended to influence a decision.
- Threshold: any gift or hospitality given or received exceeding the value of 450 PLN / 100 EUR must be recorded in the Gift Register and approved by the Compliance Officer.
SaaS Security & Data Integrity Principles
Data protection (GDPR) — as a provider of SaaS solutions for the industrial sector, CAPTiX acts as a Data Processor for its clients. We commit to:
- Processing data solely on documented instructions from the Client.
- Ensuring all personnel authorized to process data have committed themselves to confidentiality.
- Implementing appropriate Technical and Organizational Measures (TOMs) to ensure a level of security appropriate to the risk.
Intellectual property — every employee acts as a guardian of CAPTiX's Intellectual Property (source code, algorithms, trade secrets). Unauthorized disclosure is strictly prohibited. We respect the IP rights of our clients regarding their operational data. CAPTiX does not claim ownership of Client Data unless explicitly agreed otherwise for the purpose of service improvement (e.g., anonymized aggregation).
Cybersecurity — employees must adhere to strict security protocols, including:
- Use of strong, unique passwords and Multi-Factor Authentication (MFA).
- Immediate reporting of lost devices or suspected phishing attempts.
- Prohibition of using unauthorized software ("Shadow IT") on company devices.
Whistleblowing Policy (Reporting Violations)
In compliance with the EU Directive 2019/1937 and relevant Polish regulations, CAPTiX guarantees a safe and confidential channel for reporting suspected misconduct.
What can be reported? Reports may concern, but are not limited to:
- Breaches of GDPR or data security
- Corruption, theft, or fraud
- Workplace harassment or discrimination
- Violations of competition law
Protection against retaliation — CAPTiX strictly prohibits retaliation against any whistleblower who reports a concern in good faith. "Good faith" means the individual reasonably believes the information is true. Retaliation (firing, demotion, harassment) is a serious disciplinary offense.
Confidentiality — the identity of the whistleblower will be protected and disclosed only to authorized personnel involved in the investigation, or where required by law.
Reporting channels
Reports go directly to compliance@captix.eu and are handled confidentially, without retaliation against good-faith reporters.