Supplier Code of Conduct

1. Purpose

2. Social and environmental responsibility
2.1 Human rights, forced labor and child labor
2.2 Health and safety in the workplace
2.3 Equal treatment and respectful treatment
2.4 Fair working conditions
2.5 Sustainability

3. Corporate responsibility
3.1 Cartels, collusion and competition
3.2 Corruption, bribery and conflicts of interest
3.3 Data protection
3.4 Information security
3.5 Patents and other industrial property rights
3.6 International trade and combating money laundering
3.7 Due diligence in the supply chain
3.8 Maintaining accurate records and disclosure
3.9 Compliance organization

4. List of abbreviations

1. Purpose

All expectations formulated in this Supplier Code of Conduct form a framework of requirements that is directed at our direct business partners. youknow is convinced that this will make an important contribution to avoiding legal violations and preventing them in the long term. In this context, we particularly expect our suppliers to pass on our requirements in their respective supply chains and to actively put them into practice.

2. Social and ecological responsibility

Our business partners, their experience and their quality are an essential part of our company's success. With their help and commitment, youknow can fulfill its corporate duty of care and, in addition to fair competition, contribute to decent working conditions and sustainability in the value chain in the value chain.

2.1 Human rights, forced labor and child labor

Within its sphere of influence, youknow GmbH respects the internationally recognized human rights of all individuals and respects the basic principles set out in the "Universal Declaration of Human Rights" and corresponding UN documents. Furthermore, we reject all forms of forced labor and child labor and are fundamentally opposed to all forms of compulsory labor. We respect collective rights guaranteed by law. We also expect this understanding and strict compliance from our suppliers.

2.2 Health and safety in the workplace

The health and safety of all employees in the workplace is a top priority. youknow expects its suppliers to take the necessary measures to ensure that the working environment is safely and, as far as possible, without health risk factors. Continuous development of occupational health and safety processes at our suppliers' facilities is intended to prevent accidents. Training and safety instructions should be carried out regularly and sufficient protective equipment should be provided.

2.3 Equal treatment and respectful interaction

In its dealings with employees and business partners, youknow respects the personal dignity, privacy and personal rights of each individual. We do not tolerate any unlawful unequal treatment, insults or harassment. Equal opportunities and tolerance are essential elements of successful cooperation for us. We expect the same from our suppliers, also when dealing with their business partners.

2.4 Fair working conditions

youknow expects each of its suppliers to pay its employees appropriate wages and provide fair working conditions that at least comply with local legal requirements, for example on working hours. If not available, a living wage must be guaranteed in accordance with local living conditions.

2.5 Sustainability

In addition to social responsibility, environmental and climate protection is a central aspect of business decisions in order to operate sustainably for our and future generations today to operate sustainably today. For example, youknow also expects its suppliers to use energy and other valuable resources efficiently and to recycle raw materials throughout the value chain. The use of modern, environmentally friendly and energy-efficient technologies should also play a central role for our suppliers in order to continuously improve processes.

3. Corporate responsibility

youknow is committed to free and fair competition. Unlawful restrictions on this competition are not in line with our values, are prohibited and will be sanctioned. We expect our suppliers to adhere to this principle as well.

3.1 Cartels, agreements and competition

youknow strictly distances itself from formal or informal agreements that have the effect of unlawfully hindering competition. This also applies to unspoken, deliberately coordinated unlawful agreements and behavior. All suppliers are also obliged to comply with the relevant laws against restraints of competition.

3.2 Corruption, bribery and conflicts of interest

youknow strictly rejects any form of corruption, whether in active or passive form, and takes appropriate precautions within its area of responsibility to ensure that the applicable anti-corruption laws are strictly complied with. Personal interests must not unduly influence our professional judgment. We disclose and manage actual and potential conflicts of interest in accordance with our internal guidelines. We expect the same from our suppliers.

3.3 Data protection

Compliance with national and international regulations on the protection of personal data is a matter of course for youknow GmbH. We take suitable precautions to protect the privacy of our employees, suppliers and other data subjects professionally and in accordance with the statutory provisions. We adhere to these requirements and expect the same from our suppliers. Data protection incidents must be reported immediately to the DPO (Data Protection Officer) at .

3.4 Information security

As soon as a contractor or supplier gains access to confidential or secret information of youknow and its customers, information security requirements must be complied with.

The basic protection objectives of information security are defined as follows a) Availability (authorized users have access to information and systems at all times), b) Confidentiality (confidential information is not disclosed or passed on to third parties without authorization) and c) Integrity (the correctness of information and the functioning of systems is ensured)

Compliance with the defined information security requirements is integrated into the supplier review process. This is carried out at least once a year. a) Access and access to confidential and secret information is secured. b) Subcontractors must be notified to and approved by youknow GmbH. c) Confidential information may only be disclosed/transmitted to the extent and in the manner authorized by youknow. d) Information security incidents must be reported immediately to the ISB (Information Security Officer, at ). e) Youknow GmbH shall be entitled to audit the implementation of and compliance with the security regulations and the agreed measures after prior notice. This may be done by examining suitable documentation and records and/or through on-site inspections.

3.5 Patents and other industrial property rights

Inventions and technologies make an important contribution to the success of a company. The protection of these assets through industrial property rights is essential for the competitiveness of any company. youknow respects the effective intellectual property rights of third parties and expects the same from its suppliers.

3.6 International trade and combating money laundering

As an international group of companies, cross-border trade is a matter of course for us. youknow complies with the applicable legal requirements, e.g. for imports, exports, intra-Community transfers, applicable sanctions and sanctions lists. We also take appropriate measures to prevent money laundering. We expect the same from our suppliers.

3.7 Due diligence in the supply chain

youknow is committed to diligence in the supply chain. We expect our suppliers to take the necessary steps to identify and consider the risks in their supply chain and to inform us accordingly.

3.8 Maintaining accurate records and disclosure

youknow shall maintain accurate, complete, timely, appropriate and understandable records in accordance with the relevant legal and regulatory requirements. Where statutory provisions require disclosure of records, we shall comply with this obligation. We expect the same from our suppliers.

3.9 Compliance organization

youknow maintains a compliance organization that meets the applicable legal requirements and expects the same from its suppliers. You have the right and the opportunity to report violations of this Supplier Code of Conduct or suspected violations. This report or other questions can be made via your contact person in the respective specialist department or via the e-mail address . All information and reports as well as the identity of the reporter and all persons concerned will be treated in strict confidence.

4. List of abbreviations

  • BSI: Federal Office for Information Security
  • GDPR: General Data Protection Regulation
  • DPO: Data Protection Officer
  • GF: Management Board
  • ISB: Information Security Officer
  • ISMS: Information Security Management System
  • LK: Steering committee
Cookies

Cookies?

In addition to necessary technical cookies, we also use cookies on our website to analyze website access or to personalize your individual user experience. You can revoke your consent to their use at any time. For more information, please read our privacy policy: Data privacy