Procedure

Internal Whistleblowing Procedure

DELEGATE IT · INTERNAL WHISTLEBLOWING PROCEDURE · I/09/2024

Document code: I/09/2024 · Compliance with the Polish Whistleblower Protection Act of 14 June 2024 (Journal of Laws 2024, item 928)

Whistleblowing Reporting Channels

Full confidentiality guaranteed
Email address:[email protected]
Direct telephone lines:+48 508 009 635 / +48 697 410 659
Postal address:ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola
Data Protection Officer:[email protected]

1. General Provisions

This "Internal Whistleblowing Procedure" (hereinafter: Procedure) sets out the rules and manner of reporting legal violations by whistleblowers at Delegate IT Sp. z o.o. with its registered office in Stalowa Wola, ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola (hereinafter: Employer/Company).

2. Glossary of Terms

Data Controller – means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. The Data Controller is Delegate IT Sp. z o.o., with registered office in Stalowa Wola, ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola;

Employer / Company – Delegate IT Sp. z o.o., with registered office in Stalowa Wola, ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola;

Retaliation – means any direct or indirect action or omission in a work-related context, prompted by internal or external reporting or public disclosure, which violates or may violate the whistleblower's rights or causes or may cause unjustified harm to the whistleblower, including unfounded initiation of proceedings against the whistleblower;

Follow-up action – means any action taken by the legal entity or public authority to assess the accuracy of the allegations made in the report and to address the breach reported, in particular through internal inquiries, investigation, prosecution, action for recovery of funds, or closure of the procedure;

Information on breaches of law – means information, including reasonable suspicions, about actual or potential breaches of law that have occurred or are very likely to occur in the legal entity in which the whistleblower works or worked, or in another legal entity with which the whistleblower is or was in contact through their work-related activities, or attempts to conceal such breaches;

Feedback – means the provision to the whistleblower of information on the action envisaged or taken as follow-up and on the grounds for such follow-up;

Whistleblower – means a natural person who reports or publicly discloses information on breaches acquired in the context of their work-related activities;

Work-related context – means current or past work activities through which, irrespective of the nature of those activities, persons acquire information on breaches and within which they could suffer retaliation if they were to report such information;

Malpractice / Abuse – an action or omission by an Employee or a third party constituting a breach of law or internal regulations of the Company, which has caused or may cause unjustified harm to the Company or endanger its interests;

Breach / Violation – an act or omission that is unlawful or aimed at circumventing the law;

Designated Persons – persons holding formal authorization to receive internal reports and conduct proceedings regarding Breaches pursuant to a resolution of the Company's Management Board / Data Controller; Designated Persons form part of the Team;

Team – an impartial internal organizational unit within the organizational structure of the legal entity authorized to undertake follow-up actions, including verification of internal reports and further communication with the whistleblower;

Person assisting in making a report – a natural person who assists a Whistleblower in reporting or public disclosure in a work-related context and whose assistance should be confidential;

Person connected with the whistleblower – a natural person who may suffer retaliation, including a co-worker or a relative of the whistleblower within the meaning of Art. 115 § 11 of the Polish Penal Code;

Person concerned – a natural or legal person who is referred to in the report or public disclosure as a person to whom the breach is attributed or with whom that person is associated;

Register of Internal Reports – includes: report number, subject of the breach, personal data of the whistleblower and the person concerned, contact address of the whistleblower, date of the report, information on follow-up actions taken, date of closure;

Report – means an oral or written internal or external report submitted in accordance with statutory requirements;

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data;

Act – Polish Act of 14 June 2024 on the Protection of Whistleblowers;

Internal report – oral or written communication of information on breaches of law to a legal entity.

3. Objective and Scope of the Procedure

The objective of this Procedure is: a) creating comprehensive regulation of the disclosure of irregularities and whistleblower protection, b) improving social perception of reporting misconduct, c) protecting whistleblowers reporting breaches of law, d) protecting the Company through early detection and removal of reported irregularities, and promoting civic responsibility.

The Procedure: a) enables transparent, confidential reporting, b) guarantees diligent, objective, and timely examination of reports, c) ensures protection of persons submitting reports and persons associated with them.

Conditions for whistleblower protection under this Procedure: a) The whistleblower acts in good faith and provides truthful information; b) in the event of untruthful information or lack of good faith, the whistleblower is not subject to protection.

4. Responsibilities and Competences

4.1 The Management Board of Delegate IT Sp. z o.o. is responsible for ensuring the implementation of the procedure and providing necessary resources.

4.2 The following entities and roles are responsible for executing tasks arising from the Procedure:

Management Board of the Company: actively participates in the implementation of this Procedure, promotes organizational culture against irregularities, provides financial/organizational resources, and notifies competent public authorities when required.

HR Department: exercises direct supervision over employee documentation, informs candidates during recruitment, and familiarizes new employees with this Procedure.

Designated Persons: receive reports, maintain the register of internal reports, ensure impartial investigation, fulfill information obligations, and guarantee confidentiality.

Heads of organizational units: cooperate with Designated Persons in monitoring compliance and clarifying circumstances of reported incidents.

The Team: impartial body authorized to take follow-up action, verify reports, communicate with whistleblowers, and recommend corrective actions.

Employees of the Company: follow ethical values and legal provisions, analyze risks, report observed irregularities promptly, and provide required information.

5. General Principles

A breach of law is an unlawful action or omission or an action aimed at circumventing the law.

The Whistleblower is obliged to act in good faith.

The subject of an internal report may concern breaches regarding: 1. corruption, 2. public procurement, 3. financial services, products, and markets, 4. prevention of money laundering and terrorist financing, 5. product safety and compliance, 6. transport safety, 7. environmental protection, 8. radiation protection and nuclear safety, 9. food and feed safety, 10. animal health and welfare, 11. public health, 12. consumer protection, 13. protection of privacy and personal data, 14. security of network and information systems.

Reports are accepted in written or oral form: 1) electronically by sending the report to the dedicated e-mail address: [email protected]; 2) orally via unrecorded telephone line or direct meeting with a Designated Person within 14 days of request.

In the case of written reports, the Whistleblower receives an information clause compliant with Art. 13 of the GDPR via autoreply. In the case of oral reports, the Art. 13 GDPR clause is provided during the meeting or attached to the minutes.

The Company guarantees full confidentiality of the identity of the Whistleblower, the person concerned, and third parties mentioned. Anonymous reports are not accepted.

6. Course of Action and Handling of Reports

6.1 Receiving an internal report The Company does not accept anonymous reports. Written reports can be submitted to: [email protected]. Oral reports are recorded in minutes. Designated persons confirm receipt within 7 days. Proceedings are initiated upon entry into the Register of Internal Reports and must be concluded within 3 months with a final Report.

6.2 Preliminary analysis of the report Designated Persons verify the admissibility and credibility of the report. If the report is manifestly unfounded or unviable, the investigation may be discontinued with notification to the Management Board. If substantiated, an inquiry is opened.

6.3 Examination of the report The Team verifies the merits of the report in an impartial and confidential investigation. The Team may hear witnesses and inspect documents. Within 3 months from acknowledgement of receipt, feedback is provided to the Whistleblower on planned or taken actions.

6.4 Maintaining the register of internal reports Maintained electronically in a secure file with restricted access. Data is stored for 3 years after the end of the calendar year in which follow-up actions were completed.

6.5 Protection of personal data Personal data of the Whistleblower is confidential and will not be disclosed without express consent, unless required by mandatory provisions of law. Access is restricted exclusively to authorized personnel.

6.6 Prohibition of retaliation Retaliation against the Whistleblower, persons assisting, or connected persons is strictly prohibited. Whistleblowers are protected from dismissal, demotion, harassment, discrimination, and unfavorable treatment. Retaliation entitles the whistleblower to compensation and damages.

6.7 External reporting A Whistleblower may submit an external report to public authorities (e.g., Ombudsman, President of UOKiK) without first submitting an internal report.

7. Final Provisions

7.1 Authorized persons exercise due diligence to conduct proceedings only for the time necessary for an objective explanation. 7.2 A person who makes a report knowing that no breach occurred is subject to penalties provided in the Act (fine, restriction of liberty, or imprisonment for up to 2 years). 7.3 A person who suffered damage due to a knowingly false report has the right to compensation or damages from the reporting person. 7.4 The Internal Whistleblowing Procedure enters into force 7 days after its announcement to employees. 7.5 Candidates for employment receive information about this Procedure upon commencing recruitment. 7.6 Personal data irrelevant to the case is not collected and, if collected inadvertently, is deleted within 14 days. 7.7 In matters not regulated herein, applicable provisions of the Polish Labor Code, Penal Code, Code of Criminal Procedure, and the Polish Whistleblower Protection Act of 14 June 2024 apply.

8. Annexes

Annex No. 1 – Information clause pursuant to Art. 13 of Regulation (EU) 2016/679 (GDPR)

Annex No. 2 – Information clause pursuant to Art. 14 of Regulation (EU) 2016/679 (GDPR)

Annex No. 3 – Minutes of oral breach report pursuant to the internal whistleblowing procedure at Delegate IT Sp. z o.o.

Annex No. 4 – Statement of acknowledgement of the internal whistleblowing procedure applicable at Delegate IT Sp. z o.o.

Annex No. 1 – Information Clause (Art. 13 GDPR)

Pursuant to Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR), we inform that:

The Data Controller of your personal data processed in connection with the report of a breach of law is Delegate IT Sp. z o.o. Contact: [email protected], phone: +48 508 009 635 or +48 697 410 659, postal address: ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola. Data Protection Officer: [email protected].

1. The legal basis for data processing is compliance with a legal obligation (Art. 6(1)(c) GDPR in connection with the Polish Whistleblower Protection Act of 14 June 2024). 2. The purpose of data collection is taking action to determine whether the reported action or omission constitutes a breach of law and executing follow-up activities under the Procedure. 3. For oral reports, voice data may be recorded or documented in minutes pursuant to Art. 6(1)(f) GDPR (legitimate interest in conducting accurate and diligent proceedings). 4. Categories of data processed: name, phone number, email address, postal address, and other details provided in the report. Providing data is voluntary. Reports without identification details where permissible will also be examined. Data is disclosed solely to authorized persons. No data is transferred to third countries or international organizations. Data is retained for 3 years following the end of the calendar year in which follow-up actions were completed.

You have the right to: access data (Art. 15), rectify data (Art. 16), restrict processing (Art. 18), lodge a complaint with the President of UODO, and erase data (Art. 17 where applicable under Art. 6(1)(f)). You do not have the right to data portability (Art. 20) or objection (Art. 21) where processing is based on Art. 6(1)(c) GDPR.

Annex No. 2 – Information Clause for Persons Named in the Report (Art. 14 GDPR)

Pursuant to Art. 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), we inform that:

The Data Controller is Delegate IT Sp. z o.o., ul. Eugeniusza Kwiatkowskiego 1, 37-450 Stalowa Wola. Contact: [email protected], phone: +48 508 009 635 / +48 697 410 659. Data Protection Officer: [email protected].

Your personal data was obtained in connection with a breach report received by the Data Controller. Legal basis: Art. 6(1)(c) GDPR in connection with the Polish Whistleblower Protection Act of 14 June 2024. Purpose: conducting actions related to the report received. Categories of data: first name, last name, contact details, and details indicated in the report. Recipients: authorized personnel and competent public authorities where required by law. No transfer outside the EEA. Retention period: 3 years following the end of the calendar year in which follow-up actions were completed.

Rights: access (Art. 15), rectification (Art. 16), restriction of processing (Art. 18), complaint to UODO, and erasure (Art. 17 where applicable). Right to portability (Art. 20) and objection (Art. 21) do not apply under Art. 6(1)(c) GDPR.