Menu

Compliance Policy of AMICUM PHARMA LLC

Last updated 19 June 2026

Compliance Policy of AMICUM PHARMA LLC

Last updated 19 June 2026

Compliance Policy of AMICUM PHARMA LLC

Last updated 19 June 2026

1. TERMS AND ABBREVIATIONS

For the purposes of this Compliance Policy, terms and abbreviations are used with the following meanings.

Affiliated Persons

Related Persons of Officials, as well as legal entities and/or individuals connected to Officials and/or Related Persons through a relationship of Control.

Direct Supervisor

A person who exercises direct organisational or legal control over a subordinate, including through decisions on appointment, dismissal, remuneration beyond base salary, disciplinary sanctions, and the issuing and oversight of instructions and assignments.

Requirements

Specific Compliance Requirements and Other Compliance‑Related Requirements.

Involved Persons

The Director (Executive Body), any employees and individuals working under employment or civil contracts with the Company, and other persons acting on the Company’s behalf.

Restricted Information

See the meaning in clause 4.6 of this Policy

Other Compliance‑Related Requirements

Requirements of applicable law, ethical values, Compliance Regulations and this Policy that apply to the Company and/or Involved Persons in their relations with the Company, relating to: (1) procurement; (2) labour law; (3) environmental safety; (4) occupational and fire safety; (5) covenants; (6) information and cyber security.

Covenants

Obligations and restrictions imposed on the Company under financing agreements.

Control

Used within the meaning of Article 1 of the Law of Ukraine “On Protection of Economic Competition”.

Controller

An Official responsible for overseeing the Company’s compliance with Requirements in a given area.

Conflict of Interest

See the meaning in clause 4.4.1 of this Policy.

Public Authorities

State and local authorities that regulate, monitor and control the Company’s activities, as well as law enforcement bodies that may investigate the Company and/or Involved Persons, including but not limited to the Antimonopoly Committee of Ukraine, the Office of the Prosecutor General, and the State Bureau of Investigation.

Policy

This Compliance Policy

Compliance Regulations

See the meaning in clause 2.8 of this Policy.

Officials

The Director (Executive Body), Deputy Director, department and standalone unit heads, Chief Accountant, Chief Operating/Financial Officer, Compliance Manager, authorised procurement officer, heads of structural units, and project/programme managers.

Interested‑Party Transaction

A transaction that (i) is entered into and/or performed by the Company; and/or (ii) is entered into and/or performed in the interests of the Company or in which the Company is the ultimate beneficiary (including, without limitation, cases where such contracts are financed by international financial organizations/institutions) and in which at least one of the following interests of an Involved Person and/or an Affiliated Person exists:

  • The Involved and/or Affiliated Person acts as a business partner in the transaction;

  • The Involved and/or Affiliated Person represents a business partner and/or is an officer of such business partner in the transaction;

  • The Involved and/or Affiliated Person benefits (directly or indirectly) from the initiation and/or performance of the transaction;

  • The Involved and/or Affiliated Person is a supplier,

(sub)contractor or performer of any goods, works or services that are the subject of the transaction.

Private Interest

Any proprietary or non-proprietary interest of an Involved Person or their Affiliated Person, including one arising from personal, family, friendship or other non-official relationships with individuals or legal entities, including those arising from membership or activity in public, political, religious or other organisations.

Action Programme

The programme of measures to prevent Conflicts of Interest in the provision of services.

Related Persons

Spouse, son, daughter, stepson, stepdaughter, father, mother, stepfather, stepmother, sibling, grandparent, great-grandparent, grandchild, great-grandchild, son-in-law, daughter-in-law, father-in-law, mother-in-law, adoptive parent or adopted child, guardian or ward, a person under the guardianship or care of the Involved Person and/or their spouse, and other persons who cohabit, are connected by a shared household, and have mutual rights and obligations with the Involved Person and/or their spouse, including cohabiting unmarried partners. Related Persons also include a former spouse of the Involved Person where no more than five years have passed between the date of divorce and the date of concluding and performing the relevant agreement.

Company Participant

The founder(s) and/or ultimate beneficial owner(s) of the Company, holding a share in its charter capital and voting rights under the Company’s Charter.

Specific Compliance Requirements

Requirements of applicable law, ethical values, Compliance Regulations and this Policy that apply to the Company and/or Involved Persons in their relations with the Company, relating to: (i) conduct of business (non-discrimination, confidentiality, transparency, independence, unbundling); (ii) anti-corruption; (iii) prevention of conflicts of interest (including in procurement); (iv) antitrust law; (v) personal data processing.

Company

AMICUM PHARMA LLC and its legal successors.

Compliance Manager

The person authorised to implement the Company’s anti-corruption programme (compliance).

2. PURPOSE AND SCOPE OF APPLICATION

2.1. The purpose of this Policy is to enable the Company to:
(i) establish an effective compliance risk management system;
(ii) communicate key compliance principles to Involved Persons, business partners and stakeholders;
(iii) maintain a culture of zero tolerance for corruption;
(iv) support the avoidance and resolution of any breaches of Requirements; and
(v) achieve the objectives set out in its Charter.

2.2. The Policy defines the key roles, principles, procedures and standards designed to ensure compliance with the Requirements in the day-to-day activities of the Company and Involved Persons.

2.3. For the purposes of this Policy, compliance means the Company’s and Involved Persons’ adherence to Requirements applicable in areas including:
(i) the Company’s conduct of business (non-discrimination, confidentiality, transparency, independence, unbundling);
(ii) anti-corruption;
(iii) prevention of conflicts of interest;
(iv) antitrust regulation;
(v) labour regulation;
(vi) personal data processing;
(vii) procurement;
(viii) environmental safety;
(ix) occupational and fire safety;
(x) information and cyber security, and other areas defined by the Company.

2.4. This Policy does not cover every situation or Requirement to be observed, but it addresses the most important of them.

2.5. This Policy applies to the Company and Involved Persons.

2.6. The Company expects its business partners and stakeholders to adhere to the core principles of this Policy. Third parties, including business partners, may be required to comply with this Policy and (parts of) the Compliance Regulations under their contract with the Company.

2.7. A breach and/or non-compliance with this Compliance Policy may result in:
(i) civil liability;
(ii) administrative liability;
(iii) criminal liability;
(iv) financial liability;
(v) reputational damage to the Company;
(vi) revocation/suspension of permits and licences and/or refusal of certification;
(vii) refusal to enter into, or termination of, contracts/business relationships;
(viii) denial of access to the European pharmaceutical market.

2.8. Detailed provisions that supplement, explain and clarify this Policy are developed by the Company and include, but are not limited to, the following internal documents:

  • the Anti-Corruption Programme;

  • policies and procedures on counterparty due diligence, gifts, entertainment, donations and other corruption-sensitive areas;

  • the Long-Term Compliance Policy Implementation Programme;

  • the Annual Compliance Policy Implementation Plan;

  • the Corporate Code of Ethics;

  • the Corporate Governance Code;

  • the Conflict of Interest Management Policy;

  • the Compliance Risk Management Policy;

  • the Information Policy;

  • the Regulation on Trade Secrets and Confidential Information;

  • the Action Programme;

  • the Whistleblower Reporting Procedure;

  • and other compliance regulations and internal instructions (together, the “Compliance Regulations”).”

3. KEY ROLES AND RESPONSIBILITIES OF THE COMPANY’S BODIES AND STRUCTURAL UNITS

3.1. All Involved Persons are required to comply with this Policy and the Compliance Regulations. At the same time, the following governing bodies, Officials and structural units have specific functions and roles in ensuring compliance within the Company:

3.2. Company Participant

  • oversees the Director’s compliance-related activities;

  • receives compliance reports from the Director and the Compliance Manager;

  • receives whistleblower reports of compliance breaches committed by the Director, arranges their review, analyses the results and takes appropriate decisions, and manages any Conflict of Interest that may arise for the Director;

  • shapes corporate social responsibility policy;

  • ensures internal audit is carried out through the Audit Committee;

  • and approves Interested-Party Transactions.

3.3. Director

  • approves the Policy and the Corporate Code of Ethics;

  • is responsible for the Company’s and Involved Persons’ compliance with Requirements;

  • appoints and dismisses the Compliance Manager in accordance with this Policy;

  • sets the Company’s compliance objectives;

  • approves the Compliance Regulations and the Corporate Code of Ethics;

  • oversees compliance with this Policy and the Compliance Regulations;

  • identifies key compliance risks;

  • promotes a culture of compliance and risk-management awareness;

  • monitors information disclosure and communication processes;

  • assesses the effectiveness of this Policy and the Compliance Regulations;

  • periodically monitors compliance with them;

  • jointly with the Compliance Manager informs the Company Participant of risks and any instances of non-compliance;

  • supports the Compliance Manager in performing their duties.

3.4. The Compliance Manager

3.4.1. The Compliance Manager reports directly to the Director and serves as an objective gatekeeper, ensuring the Company’s compliance with Specific Compliance Requirements by identifying, monitoring and managing compliance risks, particularly those relating to discrimination, breaches of confidentiality, and conflicts of interest.

3.4.2. The Compliance Manager forms part of the second line of defence in the Company’s internal control system.

3.4.3. The list of compliance risks overseen by the Compliance Manager is set out in Annex 1 to this Policy.

3.4.4. The Compliance Manager serves as the Company’s Authorised Person for the implementation of the anti-corruption programme, as required by the Law of Ukraine “On Prevention of Corruption”.

3.4.5–3.4.7. The Compliance Manager is appointed and dismissed by the Director and reports to the Director.

3.4.8. The Compliance Manager oversees the structural units responsible for corruption prevention and detection, as well as for general compliance and compliance relating to the specific activities of the Company; with the Director’s permission, the Compliance Manager may involve other employees in the performance of their duties.

3.4.9. To avoid conflicts of interest, the Compliance Manager may hold no operational and/or functional duties other than those related to ensuring compliance with Specific Compliance Requirements.

3.4.10. Interference with the Compliance Manager’s work, or assigning them duties outside their authority or creating a conflict of interest, is prohibited.

3.4.11. The Compliance Manager oversees implementation of the Company’s anti-corruption programme.

3.4.12. The Compliance Manager’s activities include: overseeing compliance with Specific Compliance Requirements; developing compliance and anti-corruption mechanisms; monitoring implementation of the Anti-Corruption Programme; overseeing compliance generally; handling corruption and compliance breaches; approving draft Interested-Party Transactions; managing compliance-related communications; responding to enquiries from Involved Persons; and reporting to the Director.

3.4.13. The Compliance Manager is entitled to: request information, documents and explanations from Involved Persons, and access relevant Company premises; have direct access to the Director and other Officials; attend meetings, raise questions and provide recommendations (which must be considered, with any rejection documented in writing and justified); access the whistleblower reporting system; analyse higher-risk transactions; participate in internal reviews and investigations; and provide the Director with reports containing findings and recommendations.

3.4.14. The Compliance Manager ensures adequate understanding of and engagement with risk management among Involved Persons through training, reporting and discussion.

3.4.15. The Compliance Manager cooperates with all Company departments to achieve compliance objectives.

3.5. Head of the Legal Department and subordinates

3.5.1. Head of the Legal Department and subordinates:

  • provide advice and support to the Compliance Manager and the Director on legal aspects of compliance with Requirements;

  • monitor changes in legal and regulatory requirements;

  • participate in internal reviews and investigations;

  • review procurement and sales contracts;

  • respond to enquiries from Public Authorities, where provided for by internal policy.

3.6. HR Inspector

3.7. HR Inspector cooperates with the Compliance Manager on:

  • building corporate culture;

  • personal data matters;

  • employee briefings on this Policy and the Compliance Regulations;

  • approval of KPIs;

  • and employee performance evaluation.

3.8. Chief Operating/Financial Officer and subordinates

3.8.1. Chief Operating/Financial Officer and subordinates:

  • support compliance with this Policy by overseeing compliance with Covenants.

3.9. IT Department and staff

3.9.1. IT Department and staff:

  • support compliance with this Policy by ensuring, and monitoring, compliance with information and cyber security Requirements.

4. COMPANY COMPLIANCE PRINCIPLES

4.1. Legislation and Sanctions

4.1.1. The Company strictly complies with all Requirements, including the Laws of Ukraine “On Prevention of Corruption”, the Code of Ethics, and other legislation on the pharmaceutical market, corporate governance, disclosure, public procurement, labour regulation, taxation, antitrust regulation, environmental protection, and international standards, including relevant European rules. The Company screens its business partners, including prospective ones, for corruption and sanctions risk (including under the Law of Ukraine “On Sanctions” and FATF standards). The Company cooperates with Public Authorities during inspections, investigations and market studies, and other regulatory procedures, to the extent required by the Requirements or necessary to protect the Company’s legitimate interests.

4.1.2. The Company conducts checks on its business partners, including potential business partners, in respect of corruption violations and sanctions (including, without limitation, sanctions under the Law of Ukraine “On Sanctions”, the Financial Action Task Force (FATF), and others).

4.1.3. The Company cooperates with Public Authorities during inspections, investigations, and market studies, as well as other regulatory procedures, to the extent required by the Requirements or necessary to protect the Company\’s legitimate interests.

4.2. Anti-Bribery and Anti-Corruption

4.2.1. The Company declares and upholds a policy of zero tolerance towards bribery and corruption. These provisions and procedures on anti-bribery and anti-corruption comply with the legislation of Ukraine and leading international practices.

4.2.2. The Company develops and maintains an Anti-Corruption Programme as defined by the Law of Ukraine “On Prevention of Corruption” and other regulatory acts.

4.2.3. The Anti-Corruption Programme defines the principal measures aimed at preventing, detecting, and combating bribery and corruption, and includes the following:

  • Ongoing public declarations by the Company\’s senior management of their own and the Company\’s commitment to conducting business ethically, to zero tolerance of bribery and corruption, and to specific management actions demonstrating compliance with those commitments;

  • Appointment of the Anti-Corruption Programme Officer and definition of their functions and powers;

  • Regular identification and assessment of corruption risks with a view to developing appropriate and adequate control measures to reduce those risks to an acceptable level;

  • Conducting anti-corruption due diligence on counterparties;

  • Special provisions and restrictions on political and charitable activities of the Company;

  • Special provisions on gifts and entertainment;

  • Procedures for identifying and managing Conflicts of Interest;

  • Prohibition on the unauthorised use and/or transfer of Company assets to third parties;

  • Familiarisation of new employees with anti-corruption provisions and procedures;

  • Regular training and communication with Involved Persons on anti-corruption matters;

  • Support for and facilitation of channels for receiving reports from Involved Persons on ethics violations and possible corruption offences; protection of whistleblowers and their confidentiality;

  • Procedures for internal investigations and relevant remedial measures in respect of identified violations;

  • Periodic review of the effectiveness of anti-corruption controls and their continuous improvement.

4.2.4. The Company may not gratuitously transfer its assets to other legal entities or individuals, except in cases provided for by law.

4.2.5. No political parties are established or operate within the structure of the Company. The Company is prohibited from making contributions in support of political parties.

4.3. Business Ethics

4.3.1. The Company develops and maintains a Corporate Ethics Code that establishes mandatory rules of business conduct and defines the principal ethical values.

4.3.2. Involved Persons treat the political views, ideological and religious beliefs of others with tolerance and respect, and undertake not to use their powers in the interests of political parties and/or politicians.

4.3.3. Involved Persons act objectively, independently, impartially, and neutrally, regardless of Private Interests, personal attitudes towards any individuals, their political views, ideological, religious, or other personal views or beliefs.

4.3.4. Involved Persons must not abuse or use the funds and assets of the Company inefficiently.

4.3.5. Involved Persons, regardless of private interests, shall refrain from carrying out decisions or instructions of Officials if they pose a threat to rights, freedoms, or interests of individuals or legal entities as defined by law, or to state or public interests, or if they are contrary to the law.

4.3.6. Involved Persons shall independently assess the lawfulness of decisions/instructions issued by Officials and the potential harm that may be caused if such decisions/instructions are carried out.

4.3.7. Unethical behaviour is strictly prohibited and is subject to internal investigation. Involved Persons may submit information on their concerns regarding ethics violations to the Company\’s hotline.

4.3.8. Upon receiving for execution decisions or instructions that Involved Persons consider unlawful or posing a threat to rights, freedoms, or interests protected by law of individuals or legal entities, or to state or public interests, they must immediately notify the Compliance Manager in writing.

In the event of an unlawful decision/order by the Director, Involved Persons must immediately notify the Compliance Manager in writing. The Compliance Manager shall inform the Director of such a case.

4.4. Management of Conflicts of Interest

4.4.1. A Conflict of Interest is a situation in which the Private Interest of an Involved Person and/or their Affiliated Persons conflicts with or may potentially conflict with the interests of the Company and/or their obligations to the Company.

4.4.2. There are two types of Conflict of Interest:

  • Potential Conflict of Interest — the existence of a Private Interest of a person in an area in which they exercise their official or representative powers, which may affect the objectivity or impartiality of their decision-making, or the performance or non-performance of actions in the exercise of those powers;

  • Actual Conflict of Interest — a conflict between a person\’s Private Interest and their official or representative powers that affects the objectivity or impartiality of decision-making, or the performance or non-performance of actions in the exercise of those powers.

4.4.3. The Company ensures effective management of Conflicts of Interest. The procedure for managing Conflicts of Interest is set out in the Conflict of Interest Management Policy.

4.4.4. Conflicts of Interest of Involved Persons must be reported to the Compliance Manager and the Direct Supervisor.

Where the Conflict of Interest concerns an Involved Person and their Direct Supervisor, the Conflict of Interest shall be reported exclusively to the Compliance Manager.

Where the Compliance Manager has a Conflict of Interest, they shall report it to the Director. Where the Director has a Conflict of Interest, they shall report it to the Compliance Manager and the Company Participant.

4.4.5. A Conflict of Interest shall be reported in writing within one business day of the Involved Person becoming aware of the Conflict of Interest.

4.4.6. In decision-making, Involved Persons shall consider the interests of the Company and shall not pursue their own Private Interest.

4.4.7. In its activities, the Company may encounter the following principal types of Conflict of Interest:

(i) Conflict between the personal interests of Involved Persons and their obligations to the Company

  1. Involved Persons must act impartially, in good faith, and in the interests of the Company. This means that business decisions must be made without any influence or Private Interest on the part of the decision-maker and/or Affiliated Persons.

  2. A Conflict of Interest may arise where the Private interests/activities of Involved Persons conflict with their obligations to the Company.

  3. A person\’s personal activity shall be regarded as a Conflict of Interest if it:

  • adversely affects the good-faith decision-making of Involved Persons or their judgment in the performance of their duties;

  • adversely affects the Company\’s reputation or its relationships with business partners.

(b) Involved Persons and Affiliated Persons shall never:

  • use their powers/positions to obtain unjustified advantages or benefits for themselves, Affiliated Persons, or third parties;

  • enter into contracts in their own name and for personal purposes with business partners with whom they cooperate in their professional activities, if they may derive personal benefit from such contracts. This includes situations where Involved Persons may have a direct or indirect influence on whether the business partner enters into a contract;

  • use the assets, resources, information, or connections of the Company obtained in the course of their duties at the Company for personal gain or for the benefit of Affiliated Persons or third parties.

(e) The Company prohibits any activity by Involved Persons aimed at inducing and/or participating in any Conflict of Interest.

(i) Any situations that are regarded as (or resemble) a Conflict of Interest must (i) where possible, be avoided; and (ii) be reported immediately in the manner provided for in clause 4.4.4 of this Policy.

(d) Involved Persons under the influence of a Conflict of Interest shall not make any decisions concerning such Involved Persons or their Affiliated Persons.

(b) In order to prevent Involved Persons from making decisions under the influence of a Conflict of Interest, the Compliance Manager shall review and provide findings, conclusions, and recommendations to the Director regarding:

  • draft Interested-Party Transactions;

  • appointment, dismissal, imposition of liability, and suspension of Officials;

  • payment of any remuneration beyond the base salary to Officials, where such payments:

  • are not provided for in the collective agreement;

  • are not made in accordance with the standards established by the collective agreement;

  • one-off and individual payments unrelated to specific performance results, including payments for the completion of important and particularly important tasks, and payments for anniversaries and memorable dates.

(i) An Involved Person may not hold the position of Direct Supervisor or a position subordinate to the Direct Supervisor in relation to their Related Person. Holding such positions gives rise to a Conflict of Interest.

(]) Involvement of Involved Persons in political parties or other public or political organisations is permissible provided it does not interfere with the fulfilment of their obligations to the Company. When expressing personal opinions publicly, employees must not create the impression that those opinions reflect the views of the Company.

(k) The Company shall take all permissible measures to resolve Conflicts of Interest.

(l) Neither Involved Persons nor Affiliated Persons may participate in procurement, initiate, facilitate the conclusion of, and/or accept proposals to negotiate, conclude, perform, and/or receive performance of any Interested-Party Transactions.

(t) Involved Persons shall never make decisions on the following matters of the Company:

  • appointment, dismissal, suspension, and imposition of disciplinary sanctions in respect of themselves or their Affiliated Persons;

  • payment of remuneration beyond the base salary to themselves or their Affiliated Persons.

(ii) Conflict of interest in the performance by the Company of four functions

  1. In the course of providing services, the Company takes all necessary measures to prevent Conflicts of Interest.

  2. In order to prevent, detect, and counter Conflicts of Interest, the Company develops an Action Programme. The Action Programme ensures:

  • independence in decision-making by officials of structural divisions responsible for the provision of services;

  • prevention of combinations of roles and positions that may lead to a Conflict of Interest;

  • restriction of access to commercial information, ensuring the physical and IT security of information, differentiation of access to various categories of data in information systems, defining the range of persons and cases of access to restricted information, and exercising appropriate oversight of employees who have been granted access to restricted information;

  • segregation of reporting lines for Involved Persons performing related functions;

  • ensuring the formalisation of relations between officials of structural divisions responsible for the provision of services

  1. The Company ensures continuous monitoring and updating of the Action Programme in order to achieve full readiness to resolve Conflicts of Interest.

  2. The Company approves regulations on structural divisions and job descriptions, taking into account the segregation of responsibilities and reporting lines of departments and divisions responsible for the provision of services.

  3. The Company carries out any structural reorganisations, internal transformations, changes of functions, appointments, transfers, combinations or concurrences of positions.

4.5. Personal Data

4.5.1. In the course of its activities, the Company may process personal data. The processing and protection of personal data is carried out in strict compliance with Ukrainian legislation and leading practices, and is directed at protecting the legitimate rights and interests of all persons involved.

4.5.2. In the course of its activities, the Company may process the personal data of the following persons:

  • Employees (including prospective employees and employees whose employment has been terminated) and their family members;

  • Business partners (including prospective business partners);

  • Other persons.

4.5.3. The Company processes personal data in accordance with the following principles:

  • The existence of a lawful purpose for processing personal data. This purpose must be communicated to the data subject prior to the commencement of personal data processing;

  • Personal data is processed on the basis of the clear written consent of the data subject, unless otherwise provided by law;

  • Where personal data is obtained directly from the data subject, advance notice of the processing of personal data shall be provided to them. Where personal data is obtained from third parties, notice of the processing of personal data shall be provided to the data subject within 30 days;

  • Personal data is obtained or collected from lawful sources. Data subjects shall be informed of the sources of personal data collection;

  • The volume of personal data must correspond to the purpose of processing. Under no circumstances may the Company process an excessive volume of personal data. The Company must ensure the accuracy, reliability, and relevance of personal data. Personal data must be deleted once the purpose of its processing has been achieved or ceases to exist;

  • Personal data must not be disclosed to third parties without the written consent of the data subject, except where disclosure of personal data is required or permitted by applicable law;

  • Technical and administrative measures must be taken to prevent the unlawful or accidental processing, loss, or disclosure of personal data. The Company must ensure that access to personal data is granted only to authorised persons.

4.5.4. Cross-border transfer of personal data may be carried out on the basis of the consent of the data subject, or in cases provided for by law. Cross-border transfer of personal data may be carried out where the relevant country applies appropriate measures to protect personal data.

4.6. Confidentiality

4.6.1. The Company processes confidential information in the course of its day-to-day and operational activities.

4.6.2. The Company treats the following as confidential information:

  • all information received from third parties (including market participants) that is not publicly available;

  • information relating to its activities that is not publicly available, and the disclosure of which may cause harm to:

  • the legitimate rights and interests of the Company;

  • competition in the market (for example, may confer commercial advantages on market participants), hereinafter — “Restricted Information».

4.6.3. The Company, taking into account the requirements of applicable law, classifies confidential information at the following levels:

  1. for official (internal) use;

  2. confidential;

  3. strictly confidential.

4.6.4. Taking into account the above classification, the Company applies the most appropriate method of information exchange in order to ensure the corresponding level of confidentiality;

4.6.5. The Company ensures the complete confidentiality of Restricted Information by establishing the necessary procedural and technical conditions, on the basis of national and international legislation;

4.6.6. The Policy provides that confidentiality is important for the following reasons:

  • The need to prevent the flow of Restricted Information from market participants to their competitors;

  • The need to preserve the Company\’s Restricted Information;

  • The need to protect commercial information.

4.6.7. The Company processes confidential information guided by the following principles:

Access and use:

  • access to the relevant information shall be granted to Involved Persons only for the purpose of performing the functional duties assigned to them in the interests of the Company. Access to information must be granted in compliance with regulatory requirements and with a view to eliminating Conflicts of Interest in the provision of services;

  • access to and use of information shall be permitted only after the Company has provided a written non-disclosure undertaking;

  • access to information shall be granted only where it is used for purposes permitted by applicable law. Use of information by Involved Persons for their own benefit and in the interests of Affiliated Persons or third parties is prohibited.

  • access shall be granted to the minimum necessary information required solely for the performance of the relevant functional duties;

  • The Company counters any attempts by Involved Persons to misuse Restricted Information.

Storage and protection:

  • The Company organises an information security management system aimed at protecting Restricted Information from unauthorised access and provides the necessary support for it. The Company ensures information security through the implementation of a high-performance IT infrastructure.

Transfer of information to third parties:

  • transfer of information to third parties shall be carried out only where there is a justified purpose;

  • transfer of information to third parties must be duly authorised/approved;

  • transfer of information to third parties must be carried out in accordance with applicable law, internal regulatory requirements, and obligations;

  • transfer of information to third parties must be carried out on the basis of written consent or another legal instrument governing the appropriate handling and protection of confidential information, unless otherwise provided by applicable law;

  • The Company must transfer to third parties only the minimum necessary information required solely for the fulfilment of the relevant obligations.

Public disclosure of information:

  • information may be made public only where required by applicable law or provided for by the Company\’s Information Policy and the Regulations on Commercial Secrets and Confidential Information.

4.6.8. The Company is obliged to ensure the confidentiality of all documents classified as state secrets that are of strategic and national significance.

4.6.9. The Company ensures an appropriate level of confidentiality in the exchange of information with other organisations.

4.6.10. In order to ensure the appropriate use of Restricted Information, the Company establishes the necessary internal policies and procedures defining the rights, obligations, and responsibilities of Involved Persons with regard to confidentiality.

4.6.11. Other details regarding the procedures for handling and exchanging confidential information shall be determined by the relevant documents.

4.7. Transparency and Disclosure

4.7.1. The Company ensures open and transparent relations with all stakeholders, including clients, Public Authorities, suppliers, and European institutions. Transparency is a precondition for the functioning of a competitive market and Ukraine\’s preparation for integration into the European market.

4.7.2. The Company ensures full transparency in its activities as a responsible market participant, on the basis of Ukrainian and international legislation, as well as European rules and requirements:

(i) Adherence to the principle of transparency is one of the best ways to remain independent of all market participants and not act in their favour. The Company ensures transparency through:

  • Publication of service tariffs on the official website within three days of their approval;

  • Publication of standard contracts;

  • Preparation and publication of required reports as provided by applicable law;

  • Additional transparency and disclosure requirements may arise from bilateral agreements between the Company and national stakeholders.

4.7.3. The Company ensures timely publication and disclosure of the required data on the basis of the principles and conditions defined in the Company\’s Information Policy, taking into account the necessary confidentiality requirements.

4.7.4. The Company is obliged to ensure the proper and effective functioning of the relevant business process related to transparency and information disclosure.

4.8. Non-Discrimination (Equal Treatment of Market Participants)

4.8.1. The Company undertakes not to discriminate against any market participant. The Company ensures access to its services on a non-discriminatory and transparent basis to all users.

4.9. Procurement and Sales

4.9.1. The Company ensures the transparency and lawfulness of procurement and sales procedures.

4.9.2. The Company strictly complies with Ukrainian procurement legislation and adheres to the principles established by the Law of Ukraine “On Public Procurement”. In furtherance of this, the Company undertakes to:

  • Promote fair competition among all participants;;

  • Ensure maximum economy and efficiency;

  • Guarantee openness and transparency at all stages of procurement;

  • Avoid discrimination against participants;

  • Conduct objective and impartial evaluation of tender proposals;

  • Prevent corrupt acts and abuses.

4.9.3. The Company strives to conduct business with honest and reputable business partners with a good business reputation. Prior to entering into a transaction, the Company conducts an anti-corruption due diligence check on counterparties using lawful methods. The procedure for conducting such checks is established by the Regulations on the Procedure for Conducting Anti-Corruption Due Diligence on the Company\’s Business Partners.

4.9.4. Involved Persons and their Affiliated Persons are prohibited from participating in any procurement and sales of assets conducted by the Company.

4.10. Antitrust Regulation

4.10.1. In the sphere of antitrust regulation, the Company adheres to the following position:

  • does not participate in any coordinated anti-competitive activities under antitrust law, in particular in relation to prices, market share, capacity, distribution of regional markets, or price-fixing;

  • does not abuse a monopoly (dominant) position;

  • does not engage in restrictive or discriminatory activities;

  • does not engage in other activities prohibited by antitrust law.

4.11. Health and Safety

4.11.1. The Company conducts its activities in strict compliance with legislation, with a view to ensuring the health and safety of Involved Persons.

4.11.2. The Company complies with the Requirements and maintains a policy of zero tolerance towards occupational safety violations. The Company takes a proactive stance on occupational safety risk management and applies its resources to prevent workplace accidents through the following measures:

  • Obtaining and maintaining the validity of all required permits and licences (e.g. for high-risk works and high-risk equipment);

  • Proper technical maintenance and operation of equipment and ensuring workplace safety;

  • Provision of work clothing, helmets, and other items required for individual and collective protection;

  • Training and briefing of Involved Persons on occupational and health and safety matters;

  • Establishing internal rules and procedures in addition to the requirements established by law;

  • Ensuring that all employees undergo the medical examinations required by law;

  • Internal monitoring of compliance with both statutory and internal rules and procedures.

4.12. Environmental Safety

4.12.1. The Company seeks to enhance environmental safety and to minimise its negative impact on the environment. The Company aims to use resources efficiently and to minimise waste and emissions.

4.12.2. Where possible, the Company uses equipment, tools, and office supplies suitable for reuse and recycling. The Company must continuously strive to optimise and modernise production in order to reduce emissions and preserve natural resources.

4.12.3. The Company promotes environmental safety by ensuring compliance with Ukrainian and international legislation and the Requirements. It is prohibited to discharge pollutants or to make special use of natural resources without authorisation from the relevant public authority in cases provided for by law, or in contravention of the Company\’s internal regulations.

5. PRINCIPAL COMPLIANCE PROCEDURES

5.1. The Company organises the following procedures to ensure compliance with the Requirements:

  • This Policy, Compliance Regulations, and amendments thereto are approved, put into effect, made available to the relevant Involved Persons; periodic monitoring is carried out and updates are made as necessary;

  • The principal legal, regulatory, and ethical requirements applicable to the Company (i.e. the Requirements) are defined, documented, and communicated to Involved Persons;

  • All Involved Persons are notified of this Policy and the Compliance Regulations and have undertaken to comply with them;

  • All Involved Persons receive introductory anti-corruption and compliance briefings, as well as periodic follow-up briefings;

  • The Long-Term Action Programme for Implementation of the Compliance Policy and Annual Plans for Implementation of the Compliance Policy are developed, approved, and communicated to the responsible Involved Persons;

  • A Compliance Manager (with sufficient powers and resources) is appointed;

  • Corruption and other compliance risks are properly identified, registered (documented), assessed, and measures taken to mitigate them;

  • Anti-corruption and other compliance due diligence checks on business partners (including prospective business partners) are conducted;

  • Anti-corruption provisions and other compliance provisions for contracts and agreements with business partners are developed and implemented;

  • Criteria for approving business partners are developed;

  • Draft Interested-Party Transactions are approved by the Compliance Manager;

  • Conflicts of Interest are properly identified, disclosed, and resolved through reporting and financial disclosure declarations;

  • Restrictions on gifts and participation in political and charitable activities are established;

  • Proper compliance monitoring and oversight is exercised by the Company and Involved Persons;

  • All Involved Persons are obliged to report compliance violations;

  • A violation reporting system (including anonymous reporting) is available and properly maintained;

  • All alleged violations are properly recorded and investigated;

  • All Involved Persons and/or third parties who have violated the Requirements are held liable;

  • All the Company\’s obligations with respect to disclosure, transparency, and non-discrimination are identified and fulfilled;

  • Restricted Information relating to the activities of the Company and third parties is properly protected and structured; appropriate technical security measures are in place.


6. IDENTIFICATION, ASSESSMENT AND MANAGEMENT OF COMPLIANCE RISKS

6.1. The Company identifies and assesses compliance risks on an ongoing basis in order to ensure their timely prevention, detection, and elimination.

6.2. The Company (through the Compliance Manager) maintains and updates a register of compliance risks and business processes with a high level of compliance risk.

6.3. The Company establishes minimum risk management standards applicable to its day-to-day activities.

6.4. The Company may not be involved in any suspicious activities that undermine its reputation.

6.5. The Company blocks any unlawful activities of third parties aimed at violating compliance requirements.

6.6. Detailed information on the principles and procedures for the effective identification, assessment, and management of compliance risks is set out in the Compliance Risk Management Policy.

7. COMMUNICATION AND TRAINING

7.1. The Company regularly carries out internal and external communication on compliance activities.

7.2. External communication includes the publication of this Policy and the Anti-Corruption Programme on the corporate website and the collection of proposals from all interested parties for their improvement.

7.3. Internal communication involves regular notifications from management on all material changes to this Policy, Compliance Regulations, and compliance-related procedures and practices.

7.4. Involved Persons may contact the Compliance Manager directly with written enquiries. The Compliance Manager must provide the persons who submitted an enquiry with a written response/clarification within 5 business days of receipt of the relevant enquiry.

7.5. The Company regularly conducts training for Involved Persons on anti-corruption matters, standards and requirements applicable to TSOs, and other compliance matters, developed in accordance with the needs, circumstances, functions, and duties of Involved Persons.

7.6. All Involved Persons must successfully complete all compliance training.

8. VIOLATION REPORTING

8.1. Upon discovering a violation, any Involved Person must immediately notify the Compliance Manager and the Director. If an Involved Person becomes aware of a violation committed by the Compliance Manager and/or their subordinate, the Involved Person must immediately notify the Director by sending a message to their personal email address: gudilin.a@amicum.com.ua or compliance@amicum.com.ua

All reports of compliance violations committed by the Director must be sent by the Compliance Manager to the Company Participant immediately, but no later than the following business day.

8.2. If a violation was committed by an Official of a public administration authority, the Compliance Manager shall analyse the report of such violation and shall inform the authorised division of the violation committed by its official.

8.3. The Compliance Manager is responsible for organising an effective violation reporting system. The reporting system is accessible, ensures the protection of anonymity, and upholds the rights of the reporting person. Reporting is carried out by:

  • calling the hotline;

  • sending an email;

  • in-person reception;

  • mailbox.

8.4. Detailed information (telephone number, email address, Compliance Manager\’s reception hours) is available on the Company\’s website under the heading About Us -> Anti-Corruption.

8.5. The Company organises technical solutions that ensure the anonymity of the reporting person. These technical solutions also enable documents to be submitted. The violation reporting system also complies with personal data protection requirements. Personal data that no longer needs to be processed in connection with a report of a possible violation must be deleted.

8.6. All reports must be duly registered and analysed by the Compliance Manager or the Director (in the manner provided for in clause 8.1 of this Policy).

8.7. Anonymous reports shall be considered where they contain information about specific persons and facts that may be verified. No person may suffer adverse consequences for reporting a violation, except where the report contains knowingly false information. Where a person reports a violation they committed or in which they participated, their good faith and cooperation shall be taken into account in determining the liability to be imposed on that person.

8.8. After reviewing the report or complaint, the Compliance Manager shall appoint a service review or initiate a service investigation before the Director, as provided for in Section 9. Where the report contains information about a violation committed by the Compliance Manager and/or their subordinate, the Director shall review the report and appoint a service review or service investigation.

9. OVERSIGHT. SERVICE REVIEWS AND SERVICE INVESTIGATIONS

9.1. The Compliance Manager, the Director, and department directors, within the limits of their competence, are responsible for ensuring that Involved Persons comply with the Requirements.

9.2. The Company has the following levels of internal control:

1st Line of Defence
Officials (except the Compliance Manager and others listed in the 2nd line of defence)
  • Risk management (identification and mitigation)

  • Compliance with rules and procedures

  • Adherence to legislation

2nd Line of Defence
Compliance Manager, Head of Legal Department, IT, Risk Manager (if established), HR Inspector, Chief Operating / Financial Officer
  • Rule-setting, control and monitoring of compliance
  • Coordination of the risk management process
  • Supporting the 1st line of defence in implementing the internal control system
3rd Line of Defence
Internal Auditor
  • Independent reviews of departments

  • Assessment of the effectiveness of the internal control system (1st and 2nd lines of defence).

External Oversight
External auditors, state regulatory authorities

9.2.1. The owner of compliance risks and the party obliged to take measures to identify and mitigate them is and remains the 1st line of defence — managers and their subordinate employees (operational/functional divisions);

9.2.2. The Compliance Manager\’s task is to help risk owners — i.e. the heads of those divisions — identify these risks, develop an action plan to mitigate them, implement internal controls, and monitor the execution of that action plan. In particular, countering and preventing corruption is, first and foremost, the responsibility of top management, heads of structural and standalone divisions of the Company, and all employees in the broader sense.

9.3. The Controller continuously monitors compliance with the Requirements, paying particular attention to business processes with elevated compliance risk.

9.4. Distribution of the Controller\’s responsibility for compliance with the Requirements:

1. TERMS AND ABBREVIATIONS

1
Specific Compliance Requirements
Compliance Manager
2
Other Compliance-Related Requirements:
  • Rule-setting, control and monitoring of compliance
  • Coordination of the risk management process
  • Supporting the 1st line of defence in implementing the internal control system
2.1
Procurement (except where a conflict of interest arises)
Authorised procurement officers
Head of Legal Department
2.2
Covenants
Chief Operating Officer / Chief Financial Officer
2.3
Labour Law
HR Inspector
2.4
Environmental Safety
Compliance Manager
2.5
Occupational and Fire Safety
HR Inspector
2.6
State Secret
Compliance Manager
2.7
Information and Cyber Security
IT Department

9.5. The Controller initiates a Service Review under the following conditions:

  • monitoring has given rise to suspicions or identified signs of a violation;

  • a notification or complaint regarding a compliance violation has been received;

  • a request and/or investigation by a Public Authority is in progress.

9.6. The procedure for conducting a Service Review is governed by the Regulations on the Conduct of Internal Investigations and Reviews.

9.7. If monitoring or a service review reveals a violation committed by an Official, or one that may potentially cause significant harm to the Company (proprietary or non-proprietary), the Controller must initiate a Service Investigation before the Director. The Director must provide the Controller with approval or a refusal to conduct an internal investigation within 2 business days.

9.8. If the violation was committed by the Director, the service investigation shall be conducted in accordance with the procedure established by the Company Participant.

9.9. The Compliance Manager may involve employees of other departments or divisions in service reviews or service investigations with the consent of the Direct Supervisor or the Director. If a service investigation is being conducted in respect of the Direct Supervisor of such a person, their involvement must be approved by the Director.

9.10. The specifics of conducting an internal anti-corruption investigation are governed by the Regulations on the Procedure for Conducting an Internal Anti-Corruption Investigation of Violations by Company Employees of the Requirements of the Anti-Corruption Programme or Indications of a Corruption or Corruption-Related Offence.

9.11. The IT Department participates in a Service Investigation in the compliance sphere if so provided by the Director\’s order.

9.12. If a report of an offence has been confirmed, the Controller shall take measures, such as:

  • propose recommendations for optimising the relevant process;

  • inform the Director of the results of the service review or service investigation and provide recommendations on remedying the violation or imposing liability.

10. LIABILITY

10.1. In the event that Involved Persons violate the Requirements, the following types of liability shall be imposed on them:

  • Disciplinary (including termination of employment);

  • Administrative;

  • Criminal;

  • Full compensation for damages, unless otherwise provided by Ukrainian law.

10.2. A violation of this Policy by an Involved Person is regarded as a gross breach of their employment/contractual obligations towards the Company.

11. COMPLIANCE REPORTING

11.1. The Compliance Manager reports to the Director in the following cases:

  • at least once every six months;

  • at any time on their own initiative;

  • at any time at the request of the Director;

  • in the event of systematic and/or significant violations of this Policy, Compliance Regulations, or other Requirements.

11.2. This Policy does not govern matters relating to reporting on the implementation of the Anti-Corruption Programme. The procedure for reporting on the implementation of the Anti-Corruption Programme is regulated by the Anti-Corruption Programme.

12. APPROVAL, ENTRY INTO FORCE AND VALIDITY OF THIS POLICY

12.1. The Director introduces this Policy into force by their order.

12.2. This Policy enters into force on the date of its publication.

12.3. All new Involved Persons must familiarise themselves with this Policy before commencing their duties. Existing Involved Persons must familiarise themselves with this Policy no later than 5 days before it enters into force.

12.4. This Policy shall remain valid until (i) it is replaced by another relevant regulation; or (ii) its effect is terminated. The Director, upon a proposal by the Compliance Manager and following approval by the Supervisory Board, takes a decision to replace or terminate the Policy.

13. UPDATING THIS POLICY

13.1. The Compliance Manager, together with the Director, conducts an assessment of this Policy at least once a year and, where necessary, introduces amendments to it. In addition, amendments to this Policy shall be introduced under the following circumstances:

  • significant changes in legislative and/or regulatory requirements;

  • identification of deficiencies and/or risks that are insufficiently addressed in this Policy.

13.2. The amended Policy shall be brought to the attention of Involved Persons by publishing it on the Company\’s website no later than 5 days before it enters into force.

14. IMPLEMENTATION OF THIS POLICY

14.1. In order to ensure the proper implementation of the compliance system (including this Policy), the Compliance Manager develops a Long-Term Action Programme for Implementation of the Compliance Policy and Annual Plans for Implementation of the Compliance Policy.

14.2. The programme and plan referred to above shall be agreed with the Director and brought to the attention of Involved Persons.

14.3. The Compliance Manager shall report on the implementation of the compliance system, including the Long-Term Action Programme for Implementation of the Compliance Policy and the Annual Plans for Implementation of the Compliance Policy.

14.4. The Compliance Manager shall provide reports on the implementation of the compliance system, including the Long-Term Action Programme for Implementation of the Compliance Policy and the Annual Plans for Implementation of the Compliance Policy, in the following cases:

  • at least once every six months;

  • at any time at the request of the Director;

  • at any time on their own initiative.

15. RELATIONSHIP WITH COMPLIANCE REGULATIONS

15.1. In the event of a conflict between policies, the provisions of this Policy shall prevail, except in the sphere of anti-corruption, where the provisions of the Anti-Corruption Programme shall take precedence.

9.5. The Controller initiates a Service Review under the following conditions:

  • monitoring has given rise to suspicions or identified signs of a violation;

  • a notification or complaint regarding a compliance violation has been received;

  • a request and/or investigation by a Public Authority is in progress.

9.6. The procedure for conducting a Service Review is governed by the Regulations on the Conduct of Internal Investigations and Reviews.

9.7. If monitoring or a service review reveals a violation committed by an Official, or one that may potentially cause significant harm to the Company (proprietary or non-proprietary), the Controller must initiate a Service Investigation before the Director. The Director must provide the Controller with approval or a refusal to conduct an internal investigation within 2 business days.

9.8. If the violation was committed by the Director, the service investigation shall be conducted in accordance with the procedure established by the Company Participant.

9.9. The Compliance Manager may involve employees of other departments or divisions in service reviews or service investigations with the consent of the Direct Supervisor or the Director. If a service investigation is being conducted in respect of the Direct Supervisor of such a person, their involvement must be approved by the Director.

9.10. The specifics of conducting an internal anti-corruption investigation are governed by the Regulations on the Procedure for Conducting an Internal Anti-Corruption Investigation of Violations by Company Employees of the Requirements of the Anti-Corruption Programme or Indications of a Corruption or Corruption-Related Offence.

9.11. The IT Department participates in a Service Investigation in the compliance sphere if so provided by the Director\’s order.

9.12. If a report of an offence has been confirmed, the Controller shall take measures, such as:

  • propose recommendations for optimising the relevant process;

  • inform the Director of the results of the service review or service investigation and provide recommendations on remedying the violation or imposing liability.

10. LIABILITY

10.1. In the event that Involved Persons violate the Requirements, the following types of liability shall be imposed on them:

  • Disciplinary (including termination of employment);

  • Administrative;

  • Criminal;

  • Full compensation for damages, unless otherwise provided by Ukrainian law.

10.2. A violation of this Policy by an Involved Person is regarded as a gross breach of their employment/contractual obligations towards the Company.

11. COMPLIANCE REPORTING

11.1. The Compliance Manager reports to the Director in the following cases:

  • at least once every six months;

  • at any time on their own initiative;

  • at any time at the request of the Director;

  • in the event of systematic and/or significant violations of this Policy, Compliance Regulations, or other Requirements.

11.2. This Policy does not govern matters relating to reporting on the implementation of the Anti-Corruption Programme. The procedure for reporting on the implementation of the Anti-Corruption Programme is regulated by the Anti-Corruption Programme.

12. APPROVAL, ENTRY INTO FORCE AND VALIDITY OF THIS POLICY

12.1. The Director introduces this Policy into force by their order.

12.2. This Policy enters into force on the date of its publication.

12.3. All new Involved Persons must familiarise themselves with this Policy before commencing their duties. Existing Involved Persons must familiarise themselves with this Policy no later than 5 days before it enters into force.

12.4. This Policy shall remain valid until (i) it is replaced by another relevant regulation; or (ii) its effect is terminated. The Director, upon a proposal by the Compliance Manager and following approval by the Supervisory Board, takes a decision to replace or terminate the Policy.

13. UPDATING THIS POLICY

13.1. The Compliance Manager, together with the Director, conducts an assessment of this Policy at least once a year and, where necessary, introduces amendments to it. In addition, amendments to this Policy shall be introduced under the following circumstances:

  • significant changes in legislative and/or regulatory requirements;

  • identification of deficiencies and/or risks that are insufficiently addressed in this Policy.

13.2. The amended Policy shall be brought to the attention of Involved Persons by publishing it on the Company\’s website no later than 5 days before it enters into force.

14. IMPLEMENTATION OF THIS POLICY

14.1. In order to ensure the proper implementation of the compliance system (including this Policy), the Compliance Manager develops a Long-Term Action Programme for Implementation of the Compliance Policy and Annual Plans for Implementation of the Compliance Policy.

14.2. The programme and plan referred to above shall be agreed with the Director and brought to the attention of Involved Persons.

14.3. The Compliance Manager shall report on the implementation of the compliance system, including the Long-Term Action Programme for Implementation of the Compliance Policy and the Annual Plans for Implementation of the Compliance Policy.

14.4. The Compliance Manager shall provide reports on the implementation of the compliance system, including the Long-Term Action Programme for Implementation of the Compliance Policy and the Annual Plans for Implementation of the Compliance Policy, in the following cases:

  • at least once every six months;

  • at any time at the request of the Director;

  • at any time on their own initiative.

15. RELATIONSHIP WITH COMPLIANCE REGULATIONS

15.1. In the event of a conflict between policies, the provisions of this Policy shall prevail, except in the sphere of anti-corruption, where the provisions of the Anti-Corruption Programme shall take precedence.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Ready to Work Together?

Get in touch, and let's discuss your product and possible ways of working together.

Create a free website with Framer, the website builder loved by startups, designers and agencies.