ACTIONS4MORE - 2024 Sustainability Report

27 SUSTAINABILITY IN OUR DNA Supporting this system, a Whistleblowing procedure is in place, in compliance with Legislative Decree 24/2023, governing the receipt, analysis, and management of reports concerning crimes, violations, or behavior not compliant with internal regulations. The reporting channel is directly accessible through the corporate website, ensuring whistleblowers’ anonymity and confidentiality. Beyond full compliance with current regulations, we have adopted an integrated management system based on Codes, Policies, and Certifications, designed to provide effective and continuous oversight of relevant issues: • Code of Ethics, Corporate Code of Conduct, and Business Partner Code of Conduct: we uphold and promote fundamental principles concerning human rights, health and safety, ethical integrity, and environmental protection, which are essential requirements for all our collaborators. • Quality Policy and ISO 9001 Certification: we are committed to fostering a culture of quality, understood as the ability to meet customer needs in both products and services. To this end, we adopt rigorous internal processes and responsible procurement policies, also aimed at safeguarding food safety. • Social Responsibility Policy and SA 8000 Certification: we operate in line with the principles set out in the Universal Declaration of Human Rights and ILO conventions, committing to safeguard human and labor rights for employees and suppliers. • Product Safety Policy and AEO Certification: as an Authorized Economic Operator (AEO), we ensure the safety of goods throughout the international supply chain, guaranteeing proper documentation transmission and compliance with regulatory requirements. Management provides adequate communication tools and oversees compliance with these documents by internal staff and external partners, enabling them to pursue the Company’s mission as effectively as possible. All collaborators bear the daily responsibility of implementing policy commitments within their scope of activity and promptly reporting any issues encountered through the established channels. Furthermore, with the establishment of the Social Performance Team and the support of external consultants, we identify and manage risks to which we are exposed, with the aim of turning them into opportunities for growth and development. In the ESG domain as well, designated managers provide regular updates to corporate management, which supervises progress and validates the content of both the Report and the Sustainability Plan. In recent years, with the aim of ensuring business continuity and minimizing vulnerability, the Company has undertaken a structured program to strengthen its cybersecurity standards. We have implemented advanced protection systems, including next-generation anti-malware and antivirus solutions, and we rely on external professionals for monitoring and detecting potential data breaches. Server security has also been tested and reinforced, with the introduction of procedures for regular data backups. We have established an access control system and circulated internal regulations on the proper use of IT tools, in compliance with current personal data protection legislation, including the EU GDPR (2016/679).

RkJQdWJsaXNoZXIy NDUyNTU=