Legal Information
Zafin Supplier Code of Conduct and Standards
Last Updated: 2026-09-01
1. Overview
1.1 Purpose and Scope
Zafin and its divisions, business units, subsidiaries, and affiliates (collectively “Zafin”) are committed to the highest standards of integrity, ethics, business conduct, privacy, information security, and social responsibility. Zafin expects all suppliers engaged in supplying products and providing services to Zafin to make a similar commitment.
For purposes of this Code, “Supplier” includes, as applicable, sub-processors, service providers, agents, vendors, sellers, contractors, subcontractors, subconsultants, dealers, consultants, manufacturers, distributors, and their lower-tier suppliers.
These Zafin Supplier Standards of Conduct (“Standards”) describe Zafin’s expectations for the conduct, governance, and control environment of its Suppliers.
1.2 Compliance and Governance Expectations
Zafin expects Suppliers to act in accordance with these Standards, and at a minimum requires that all Suppliers abide by all applicable laws and regulations within the countries where they operate and where goods or services are delivered, data is processed, or affected individuals are located. Suppliers must cooperate as required by applicable law, with competent regulatory and supervisory authorities. In instances where expectations outlined in these Standards differ from applicable laws and regulations, Suppliers must follow these expectations within the bounds of applicable laws and regulations.
Suppliers are expected to maintain appropriate governance, risk management, and internal controls to support compliance with these Standards and applicable laws. Such measures must be proportionate to the nature, scale, complexity, criticality, and risk of the goods or services supplied to Zafin.
1.3 Supplier Responsibility and Continuing Obligations
Suppliers must ensure that their staff (at all levels), representatives, subcontractors, sub-processors, agents, and business partners understand and abide by these Standards with respect to work performed on behalf of Zafin.
Suppliers must not consult with other third parties on behalf of Zafin or represent Zafin to other third parties without the express prior written authorization of Zafin.
Where these Standards form part of a contractual agreement, compliance with them is a continuing obligation. Zafin may require evidence of compliance, remediation of identified deficiencies, or other corrective action proportionate to the nature and severity of the non-compliance.
2 Compliance with Laws and Ethical Business Conduct
2.1 Bribery, Anti-Corruption and Business Courtesies
Suppliers must abide by all applicable bribery and anticorruption laws (e.g., U.S. Foreign Corrupt Practices Act, UK Bribery Act). Suppliers must not pay a bribe in any amount, to anyone, anywhere, for any reason whatsoever, whether on their behalf, on Zafin’s behalf, or on behalf of any third party. Suppliers must not offer, promise, authorize, or provide, directly or indirectly, anything of value with the intent or effect of inducing anyone to forego their duties and providing an unfair business advantage to anyone, including facilitating payments.
Suppliers must not offer or accept any business courtesy to obtain improper advantages or influence for the Supplier, Zafin (including Zafin employees, contractors and/or other workers, and their family members and associates), or any third party. Business courtesies include gifts, benefits, fees, commissions, dividends, cash, gratuities, services, or any inducements. Suppliers must ensure that the offering or receipt of any business courtesy is permitted by law and regulation, and that the exchange does not violate the rules and standards of the recipient’s organization and is consistent with reasonable marketplace customs and practices.
2.2 Conflicts of Interest
Suppliers must avoid all conflicts of interest or situations giving the appearance of a conflict of interest in their dealings with Zafin. Suppliers must report to Zafin any instances involving actual or perceived conflicts of interest, whether organizational or personal.
2.3 Fair Competition and Antitrust
Zafin expects the activities of Suppliers to be based on sound business values. Suppliers must conduct their business in a fair, consistent, open, and honest manner, promoting fair competition in their suppliers relationships.
Suppliers must avoid any anti-competitive conduct for any reason whatsoever.
Suppliers must neither participate in price fixing, bid rigging, or cartel activity, nor exchange current, recent, or projected pricing information or other sensitive or non-public information with any other party, except as authorized by the owner of the information.
Suppliers must refrain from abusing their market power by refusing to deal, engaging in predatory or discriminatory pricing practices, conditioning the sale or provision of a particular product or service with that of another product or service, or undertaking similar abusive tactics. Suppliers must not engage in other deceptive or unfair market practices. Suppliers must never make misrepresentations about Zafin’s products or services, their products or services, or the products or services of others. Similarly, Suppliers must never denigrate Zafin’s competitors or their competitors, or their products or services.
2.4 Sanctions, Export Controls, and Trade Compliance
Suppliers must comply with all applicable economic sanctions, export control, and trade compliance laws.
Suppliers must not provide Zafin with goods, software, technology, services, personnel, or counterparties that would cause Zafin to violate applicable trade restrictions.
Suppliers must promptly notify Zafin if the Supplier, a controlling party, a material subcontractor, or any person assigned to Zafin becomes subject to sanctions, export restrictions, debarment, or similar legal restrictions that may affect the relationship.
2.5 Money Laundering
Suppliers must not use their business relationship with Zafin to disguise the sources of illegally obtained funds.
2.6 Insider Trading
Suppliers and their staff (at all levels), representatives, and business partners must not use material, non-public information obtained during their business relationship with Zafin as the basis for trading or enabling others to trade in the stock or securities of any company.
3 Labour, Human Rights, and Workplace Standards
3.1 Non-Discrimination and No Harassment
Suppliers are required to comply with all applicable legislation relating to employment and human rights, including discrimination and equal opportunity. Suppliers must keep a respectful and safe workplace free from physical or psychological harm, including all forms of harassment, intimidation and/or any other form of unwanted or abusive conduct.
3.2 Wage and Labour Laws
Suppliers must ensure that at minimum, wages reflect and adhere to all statutorily wages requirements and labour laws, including those related to minimum wage, overtime pay, benefits, and temporary, dispatch, and outsourced labour. Zafin expects Suppliers to provide its workers with a wage statement that includes enough information to verify correct compensation for work.
3.3 Slavery, Forced Labour, Child Labour, and Human Trafficking
Zafin is committed to respecting internationally recognized human rights and does not tolerate slavery, forced labour, child labour or human trafficking in any form. Suppliers must abide by all applicable human rights and/or other laws relating to any form of slavery, forced labour, bonded labour, indentured labour, involuntary prison labour, and human trafficking.
Zafin does not tolerate child labour in any form. Suppliers must abide by all applicable laws relating to minimum working age, including any laws related to employment, apprenticeships, and internships of youths and students.
3.4 Right to Work
Suppliers must ensure that each current and prospective individual working for or on behalf of the Supplier has the legal right and authorization to work in the location where that individual will perform work. Suppliers must verify that personnel assigned to perform services for Zafin are legally authorized to work in the jurisdiction where the services are performed, in accordance with applicable laws.
3.5 Background Screening
3.6 Drug Free Workplace
Suppliers must keep a workplace free from illegal use, possession, sale, or distribution of controlled substances. Suppliers must ensure that their employees and/or other individuals working for or on behalf of the Supplier arrive to work and remain fit for duty throughout the day, and do not perform work while impaired by alcohol or illicit drugs. Where an individual uses a legally prescribed medication that may affect fitness for duty, Zafin expects the Supplier to manage any required accommodation in accordance with applicable privacy, employment, health and safety, and other applicable laws.
3.7 Health and Safety
Suppliers must abide by all applicable health and safety laws and regulations. Zafin expects Suppliers to adopt practices to minimize health and safety risks, support accident prevention, and ensure a safe workspace for all workers. Suppliers must provide relevant health and safety training, information, and support available to all workers.
Suppliers are encouraged to periodically assess workplace health and safety risks, investigate incidents, implement corrective actions, and provide regular training to promote continual improvement. When driving on behalf of Zafin, all local laws must be adhered to, and individuals must be licensed and safe to drive the relevant vehicle and be provided with legal, safe, fit-for-purpose vehicles maintained in accordance with the manufacturer’s guidelines.
Suppliers must have in place suitable emergency plans across their operations to minimize the potential effects of any emergency either because of its own operations or that of anyone working on their behalf.
4. Information, Privacy, Cybersecurity, and AI
4.1 Sensitive Information, Confidentiality, and Intellectual Property
Suppliers must use appropriate administrative, technical, physical, and organizational safeguards to protect sensitive information, including confidential or proprietary information, trade secrets, credentials, source code, financial information, client information, and personal information. Personal information must also be handled in accordance with the Privacy and Protection of Personal Information section of these Standards.
Suppliers must use sensitive information only for the specific authorized business purpose for which it was provided and only to the extent necessary to perform their
obligations.
Suppliers must:
- Apply least-privilege and need-to-know access principles.
- Ensure personnel with access to sensitive information are subject to appropriate confidentiality obligations.
- Prevent unauthorized copying, downloading, transmission, disclosure, commingling, or use.
- Return or securely destroy sensitive information when no longer required, subject to documented legal retention obligations.
- Protect Zafin information from unauthorized use in demonstrations, analytics, benchmarking, product development, training datasets, artificial intelligence systems, or machine learning models.
Suppliers must comply with all laws governing use, disclosure, and protection of intellectual property, including patents, copyrights, trademarks, and service marks.
4.2 Privacy and Protection of Personal Information
Suppliers must process personal information:
- Lawfully, fairly, and transparently.
- Only for specified and authorized purposes.
- In a manner that is adequate, relevant, and limited to what is necessary.
- Accurately and with appropriate mechanisms for correction.
- Only for as long as required for the authorized purpose or applicable legal obligation.
- Using appropriate security, confidentiality, and accountability safeguards.
Suppliers must not sell, monetize, disclose, combine, analyze, or use personal information obtained in connection with Zafin for advertising, profiling, model development, independent product improvement, or any other purpose not expressly authorized in writing by Zafin.
Where the Supplier processes personal information on behalf of Zafin, the Supplier must act only on documented instructions from Zafin unless otherwise required by law.
4.3 Cybersecurity
Suppliers that access Zafin Information or systems, or support material or critical services, must maintain a documented cybersecurity program proportionate to the nature and risk of the services provided. At a minimum, the program must include appropriate access controls, multifactor authentication for privileged and remote access, least privilege, encryption, secure configuration and change management, vulnerability and patch management, malware protection, logging and security monitoring, incident response, tested backup and recovery procedures, security awareness training, and oversight of relevant subcontractors and sub-processors.
Suppliers must continuously monitor systems used to provide services to Zafin or process Zafin Information for security threats, vulnerabilities, unauthorized activity, control failures, and material changes in risk. Suppliers must promptly notify, investigate, contain, and remediate identified issues.
4.4 Artificial Intelligence
Suppliers must disclose to Zafin any material use of artificial intelligence, machine learning, generative AI, automated decision systems, or similar technologies in providing goods or services to Zafin or processing Zafin information.
Without Zafin’s prior written authorization, Suppliers must not input Zafin Confidential Information, Personal Information, source code, credentials, client information, or other restricted information into publicly available or externally accessible AI systems, or use Zafin Information to train, fine-tune, improve, evaluate, or benchmark any AI model or service. Authorized uses must be protected by appropriate contractual and technical safeguards.
For any AI use connected with Zafin, Suppliers must comply with applicable laws; maintain proportionate, documented governance, accountability, risk assessment, testing, human oversight, and data controls; manage security, privacy, bias, discrimination, explainability, reliability, accuracy, robustness, intellectual property, and reliance risks; validate outputs before material use; promptly report material incidents, failures, regulatory findings, or changes affecting Zafin; and provide information reasonably requested by Zafin regarding the system, use case, controls, limitations, and risks.
4.5 Incident notification
Suppliers must notify Zafin without undue delay, and no later than twenty-four (24) hours after becoming aware, of an actual or reasonably suspected privacy or information security incident that affects, or is reasonably likely to affect, Zafin Information, systems, services, customers, employees, or legal and regulatory obligations. Suppliers must not delay initial notification pending completion of an investigation.
The initial notification must include all information then available regarding the nature, scope, timing, potential impact, affected information and systems, and containment or remediation measures.
Suppliers must provide timely updates, preserve relevant evidence, cooperate with Zafin’s investigation and response, and promptly notify Zafin of any material change. Incident notifications must be sent to [email protected].
5 Operational Resilience and Supply Chain
5.1 Business Continuity
5.2 Quality and Counterfeit Parts
Suppliers must design, produce, and deliver products and services with the paramount consideration being the safety and health of their employees and clients.
Suppliers must have quality assurance processes to detect, communicate, and correct defects to ensure delivery of products and services that meet or exceed contractual quality, legal, and regulatory requirements. Suppliers must complete all required inspection and testing operations by appropriately authorized and qualified individuals.
Suppliers must ensure the existence of methods and processes to minimize the risk of introduction of counterfeit parts into final products; detect and avoid counterfeit parts and materials; provide notification to recipients of counterfeit products; and remove any counterfeit parts from the final products.
Suppliers must hold those in its supply chain accountable for the same obligations with respect to work performed on behalf of Zafin.
5.3 Supply Chain Security
Where applicable to the nature, scope, criticality, and risk of the goods or services provided to Zafin, Suppliers must establish and maintain a documented, risk-based supply chain security program covering all physical goods, equipment, components, services, applications, software, cloud services, personnel, subcontractors, and other third parties used to provide goods or services to Zafin. The program must address supplier due diligence, subcontractor oversight, product authenticity, counterfeit prevention, tamper protection, secure transportation, chain of custody, secure development, software provenance, build and deployment integrity, third-party and open-source components, vulnerability and patch management, malware prevention, incident notification, business continuity, and secure disposal.
Suppliers must ensure that subcontractors and other supply-chain participants are contractually bound by security requirements no less protective than those applicable to the Suppliers, and the Suppliers remain responsible for their acts and omissions. Software and applications must be developed and maintained using a secure development lifecycle and must be protected against unauthorized modification, malicious code, compromised dependencies, and insecure updates. Upon request, and where applicable to supplied software, applications, or technology components, the Suppliers must provide a current Software Bill of Materials (SBOM) and reasonable evidence of the origin, authenticity, integrity, and security testing of supplied software or components.
Suppliers that manufacture, package, store, transport, or ship physical goods must implement controls to prevent theft, tampering, substitution, counterfeit components, malicious implants, and unauthorized modification, including appropriate traceability, secure storage, tamper-evident packaging, inspection, and chain-of-custody controls. Suppliers that ship goods directly or package goods for shipment must comply with applicable customs and cargo security laws and with relevant national programs aligned with the World Customs Organization SAFE Framework of Standards to Secure and Facilitate Global Trade in the countries of origin, transit, and destination.
5.4 Registrations and Certifications
Suppliers must obtain any registrations, certifications, insurance coverage, or other formal documentation that formed a material requirement of their appointment. Suppliers must not misrepresent the scope, status, applicability, validity, or assurance level of any certification, audit, registration, or assessment.
Upon reasonable request, Suppliers must provide current supporting documentation, including certificates, reports, statements of applicability, remediation plans, or evidence of insurance, subject to appropriate confidentiality protections.
If these requirements lapse or change, Suppliers must inform Zafin as soon as possible.
6 Environmental Responsibility
6.1 Environmental Responsibility
Suppliers must comply with all applicable environmental laws and regulations relevant to their operations and maintain any environmental licences, permits or registrations required by law.
Suppliers are expected to manage the environmental impacts associated with the goods or services they provide to Zafin in a manner proportionate to their size, activities and environmental risk. Where relevant, this should include reasonable measures to:
- improve energy and resource efficiency and, where feasible, increase the use of renewable energy;
- measure, manage and seek to reduce greenhouse gas emissions associated with their operations and services;
- prevent pollution and reduce waste through reuse, recycling and responsible disposal, including appropriate management of electronic or hazardous waste where applicable;
- use water and other natural resources responsibly; and
- identify material environmental risks and take reasonable steps to manage and continuously improve environmental performance.
6.2 Environmental Management
Suppliers with significant environmental impacts or those identified by Zafin as higher environmental risk should maintain appropriate environmental management processes. A formal environmental management system or relevant environmental certification may be requested where proportionate to the nature and scale of the supplier’s activities; however, formal certification is not a general requirement for all suppliers.
6.3 Environmental Information and Cooperation
Suppliers shall reasonably cooperate with Zafin’s supplier sustainability assessment and due-diligence processes. Where relevant to the goods or services provided and where the information is reasonably available, Zafin may request environmental information such as:
- greenhouse gas emissions or carbon-footprint information;
- energy consumption and renewable-energy information;
- environmental or emissions-reduction targets;
- waste, recycling or resource-efficiency information; and
- relevant environmental policies, certifications or improvement initiatives.
Suppliers should provide information that is accurate and supported by reasonable records. Where information is not currently measured or available, suppliers should inform Zafin rather than being required to create disproportionate reporting processes solely for the request.
Zafin encourages suppliers, particularly strategic and environmentally significant suppliers, to identify opportunities to reduce emissions, improve resource efficiency and support responsible environmental practices throughout the value chain.
7 Records, Reporting, and Material Changes
7.1 Records Management
7.2 Material Changes
Suppliers must promptly notify Zafin of material changes that could affect the Supplier’s risk profile, contractual performance, or ability to comply with these Standards. Such changes may include:
- Ownership, control, merger, acquisition, divestiture, or restructuring.
- Actual or threatened insolvency, administration, bankruptcy, or material financial deterioration.
- Material litigation, regulatory investigation, enforcement action, or criminal allegation.
- Loss, suspension, qualification, or material change in a relevant licence, certification, registration, insurance policy, or assurance report.
- Significant changes to service locations, data-processing locations, hosting arrangements, subcontractors, sub-processors, or key personnel.
- Material changes to security, privacy, resilience, or control environments.
- Material incidents, disruptions, control failures, or risk exposures.
7.3 Reporting and Non-retaliation
Suppliers must provide their workforce and business partners with reporting channels to raise legal or ethical issues or concerns. Suppliers must promptly notify Zafin of any material, legal, regulatory, cybersecurity, or ethical issue that could affect services provided to Zafin. The policy and process must be transparent and understandable and must protect reporting and participating individuals from any retaliation or other adverse action.
Suppliers must notify Zafin’s Ethics and Compliance officer ([email protected]) of any actual or suspected misconduct related to Zafin’s business involving any person working for or on behalf of Zafin, the Supplier, or any of Supplier’s business partners.
Reports should include sufficient available information to permit Zafin to assess the matter, while respecting applicable confidentiality, whistleblower protection, privacy, and legal privilege requirements.
7.4 Infringements
Suppliers must promptly report to Zafin legal infringements or infringements of these Standards or other Zafin policy. Suppliers must promptly forward to Zafin, if allowed by law, any subpoenas, regulatory requests, media inquiries, or other third-party requests concerning Zafin. To report a Zafin supplier, please email [email protected]. Zafin keeps reported information confidential, provided it does not hinder any investigation and can do so by law.
8 Compliance and Monitoring
8.1 Compliance with these Standards
Compliance with these standards is a continuous obligation. Suppliers must maintain appropriate controls, monitor their compliance, and promptly notify Zafin of any material non-compliance, control deficiency, or change that could affect their ability to comply. Zafin may conduct ongoing, risk-based monitoring throughout the supplier relationship, including reviewing security and compliance indicators, certifications, incidents, control deficiencies, material changes, and remediation activities.
Upon request, Suppliers must certify their compliance, provide reasonable supporting information, cooperate with Zafin’s assessments, and promptly implement appropriate corrective actions for identified deficiencies.
8.2 Consequences of Non-Compliance
Where a Supplier fails to comply with these Standards, Zafin may require one or more of the following, subject to the applicable agreement and law:
- Additional information or assurance.
- A formal remediation or corrective action plan.
- Enhanced monitoring or reporting.
- Temporary restriction or suspension of access or activities.
- Replacement of affected personnel or subcontractors.
- Notification to relevant internal or external parties.
- Suspension or termination of the relationship.
- Other contractual or legal remedies.
Zafin will consider the nature, severity, duration, recurrence, impact, cooperation, and remediation of the non-compliance in determining an appropriate response.
8.3 Order of Precedence
These Standards supplement, and do not replace, the Supplier’s contractual obligations. Where an applicable agreement, data processing agreement, security schedule, service-level agreement, policy, or legal requirement imposes a stricter obligation, the stricter obligation will apply.
Nothing in these Standards limits any contractual right, remedy, audit right, notification requirement, or legal obligation applicable to the Supplier.
9 Reporting and Contact Information
| Purpose | Contact | When to Use |
|---|---|---|
| Ethics, Compliance, and Whistleblower Concerns | Report a Concern or [email protected] | Fraud, bribery, conflicts of interest, Code of Conduct concerns, retaliation, harassment, discrimination, or other ethical concerns |
| Information Security & Privacy Breach Incidents | [email protected] | Security incidents, suspected cyber events, privacy breaches, unauthorized access, ransomware, malware, or other incidents requiring urgent response |
| Privacy | [email protected] | Privacy matters affecting the lawful handling of personal information, data subject requests, regulatory inquiries, new sub-processors, cross-border transfers, AI processing of personal information, or contractual privacy questions |
| Procurement / Vendor Management | [email protected] | Supplier onboarding, certifications, insurance, due diligence, supplier assessments, or contractual supplier questions |
| Legal | [email protected] | Regulatory requests, subpoenas, legal notices, intellectual property matters, or other formal legal communications |