3. Corporate responsibility
youknow is committed to free and fair competition. Unlawful restrictions on this competition are not in line with our values, are prohibited and will be sanctioned. We expect our suppliers to adhere to this principle as well.
3.1 Cartels, agreements and competition
youknow strictly distances itself from formal or informal agreements that have the effect of unlawfully hindering competition. This also applies to unspoken, deliberately coordinated unlawful agreements and behavior. All suppliers are also obliged to comply with the relevant laws against restraints of competition.
3.2 Corruption, bribery and conflicts of interest
youknow strictly rejects any form of corruption, whether in active or passive form, and takes appropriate precautions within its area of responsibility to ensure that the applicable anti-corruption laws are strictly complied with. Personal interests must not unduly influence our professional judgment. We disclose and manage actual and potential conflicts of interest in accordance with our internal guidelines. We expect the same from our suppliers.
3.3 Data protection
Compliance with national and international regulations on the protection of personal data is a matter of course for youknow GmbH. We take suitable precautions to protect the privacy of our employees, suppliers and other data subjects professionally and in accordance with the statutory provisions. We adhere to these requirements and expect the same from our suppliers. Data protection incidents must be reported immediately to the DPO (Data Protection Officer) at .
3.4 Information security
As soon as a contractor or supplier gains access to confidential or secret information of youknow and its customers, information security requirements must be complied with.
The basic protection objectives of information security are defined as follows
a) Availability (authorized users have access to information and systems at all times),
b) Confidentiality (confidential information is not disclosed or passed on to third parties without authorization) and
c) Integrity (the correctness of information and the functioning of systems is ensured)
Compliance with the defined information security requirements is integrated into the supplier review process. This is carried out at least once a year.
a) Access and access to confidential and secret information is secured.
b) Subcontractors must be notified to and approved by youknow GmbH.
c) Confidential information may only be disclosed/transmitted to the extent and in the manner authorized by youknow.
d) Information security incidents must be reported immediately to the ISB (Information Security Officer, at ).
e) Youknow GmbH shall be entitled to audit the implementation of and compliance with the security regulations and the agreed measures after prior notice. This may be done by examining suitable documentation and records and/or through on-site inspections.
3.5 Patents and other industrial property rights
Inventions and technologies make an important contribution to the success of a company. The protection of these assets through industrial property rights is essential for the competitiveness of any company. youknow respects the effective intellectual property rights of third parties and expects the same from its suppliers.
3.6 International trade and combating money laundering
As an international group of companies, cross-border trade is a matter of course for us. youknow complies with the applicable legal requirements, e.g. for imports, exports, intra-Community transfers, applicable sanctions and sanctions lists. We also take appropriate measures to prevent money laundering. We expect the same from our suppliers.
3.7 Due diligence in the supply chain
youknow is committed to diligence in the supply chain. We expect our suppliers to take the necessary steps to identify and consider the risks in their supply chain and to inform us accordingly.
3.8 Maintaining accurate records and disclosure
youknow shall maintain accurate, complete, timely, appropriate and understandable records in accordance with the relevant legal and regulatory requirements. Where statutory provisions require disclosure of records, we shall comply with this obligation. We expect the same from our suppliers.
3.9 Compliance organization
youknow maintains a compliance organization that meets the applicable legal requirements and expects the same from its suppliers. You have the right and the opportunity to report violations of this Supplier Code of Conduct or suspected violations. This report or other questions can be made via your contact person in the respective specialist department or via the e-mail address .
All information and reports as well as the identity of the reporter and all persons concerned will be treated in strict confidence.