Code of Business Ethics and Conduct

Code of Business Ethics and Conduct

1.1 Message from Management

At Runitas Technologies, our reputation is one of our most valuable assets. Every relationship we establish with our customers, suppliers, employees, regulators and business partners is built upon trust. That trust is earned through the decisions we make every day and through our commitment to acting with integrity, professionalism and accountability.
As a technology company, we develop software, provide technology services and manage information that is often confidential, business-critical and commercially valuable. Our customers rely on us not only for technical expertise but also for our ability to protect their information, comply with legal requirements and conduct business responsibly.
This Code of Business Ethics and Conduct reflects the principles that guide our daily activities. It is intended to help every employee understand what is expected when making business decisions, interacting with customers, selecting suppliers, participating in public procurements or representing Runitas in any capacity.
No Code can anticipate every situation that may arise. Employees are therefore expected to exercise sound judgment, seek guidance whenever uncertainty exists and always choose the course of action that best protects the interests, reputation and values of Runitas.
Ethics is not solely the responsibility of the Compliance Officer or senior management. It is a responsibility shared by every individual working for or on behalf of the Company.
By acting ethically, we strengthen our business, protect our customers and contribute to the long-term success of Runitas Technologies.

1.2 Purpose
The purpose of this Code of Business Ethics and Conduct ("Code") is to establish the ethical principles, behavioural expectations and professional standards applicable throughout Runitas Technologies.
The Company believes that sustainable business success depends not only upon innovation and technical excellence but also upon honesty, fairness, transparency and compliance with applicable laws.
This Code has been developed to:
• promote an ethical corporate culture;
• support compliance with applicable laws and regulations;
• protect the reputation of Runitas;
• provide practical guidance when ethical questions arise;
• establish consistent standards across all business activities;
• reinforce accountability at every level of the organisation.
The Code complements all other corporate policies, including the Competition / Antitrust Compliance Policy, Anti-Bribery and Anti-Corruption Policy, Information Security Policy and Personal Data Protection Policy.
Where local legislation establishes stricter requirements than those contained in this Code, the stricter requirement shall prevail.

1.3 Scope
This Code applies to every individual acting on behalf of Runitas Technologies, including:
• Members of the Board of Directors;
• Executive Management;
• Managers;
• Permanent employees;
• Temporary personnel;
• Consultants;
• Contractors;
• Interns;
• Agency personnel;
• Suppliers providing services within Company premises;
• Business partners representing the Company;
• Distributors and authorised representatives where applicable.
Employees are expected not only to comply with this Code themselves but also to encourage ethical behaviour within their teams and to report concerns whenever inappropriate conduct is observed.
Managers have an additional responsibility to promote an environment where employees feel comfortable raising questions without fear of retaliation.
Business partners are expected to maintain standards consistent with the principles contained in this Code whenever they act on behalf of Runitas or participate in Company projects.

1.4 Our Values
The culture of Runitas Technologies is built upon a number of core values that influence every business decision.
Integrity
We act honestly, ethically and transparently, even when doing so may be difficult or commercially inconvenient.
Integrity means that our commitments are reliable, our communications are truthful and our decisions are made for legitimate business reasons.
Respect
We treat colleagues, customers, suppliers and competitors with dignity and professionalism.
Different opinions are valued because they contribute to innovation and better decision-making.
Discrimination, intimidation, harassment and disrespectful behaviour have no place within Runitas.
Accountability
Every employee is personally responsible for his or her decisions.
Employees are expected to acknowledge mistakes, cooperate during investigations and take corrective actions where necessary.
Customer Commitment
We seek to build long-term relationships by delivering reliable technology solutions, protecting confidential information and providing services that meet contractual and regulatory requirements.
Customer trust shall never be compromised for short-term commercial gain.
Innovation
Innovation is fundamental to our business.
However, innovation must always be pursued responsibly, ethically and in compliance with applicable laws, contractual obligations and intellectual property rights.
Professional Excellence
Employees are encouraged to continuously improve their professional knowledge, technical competence and awareness of legal and ethical obligations.
Learning is regarded as an essential component of sustainable business success.

1.5 Ethical Decision Making
Not every situation can be addressed through written policies.
Employees are therefore expected to exercise professional judgment whenever faced with an ethical dilemma.
Before making any significant business decision, employees should consider the following questions:
• Is my decision lawful?
• Is it consistent with the values of Runitas?
• Could my decision damage the Company's reputation?
• Would I feel comfortable explaining this decision to my manager, a customer or a regulator?
• Does this decision create an unfair advantage?
• Could this decision appear improper if publicly disclosed?
If uncertainty remains after considering these questions, employees should seek advice from their manager, the Legal Department or the Compliance Officer before proceeding.
Good judgment often requires asking questions rather than making assumptions.

1.6 Responsibilities
Every individual working for or on behalf of Runitas Technologies shares responsibility for maintaining the Company's ethical culture. Ethical conduct is not limited to compliance personnel or management; rather, it is an essential part of every employee's daily responsibilities and professional judgement.
All employees are expected to understand this Code, comply with applicable laws and Company policies, and act in a manner that protects the reputation and legitimate interests of Runitas. Employees shall seek guidance whenever they are uncertain about the appropriate course of action and are encouraged to raise concerns before a potential issue develops into a violation.
Managers have additional responsibilities. In addition to complying with this Code themselves, managers are expected to promote ethical leadership by setting a positive example, encouraging open communication and ensuring that members of their teams understand the Company's expectations. Managers should never ignore reports of misconduct or discourage employees from raising concerns.
Senior Management is responsible for providing adequate resources to support the Company's compliance program, ensuring that appropriate internal controls are maintained and promoting a culture where ethical business conduct is recognized as an essential business objective.
The Compliance Officer, together with the Legal Department and other control functions, is responsible for supporting the implementation of this Code, providing guidance, coordinating investigations where appropriate and periodically reviewing the effectiveness of the Company's ethics and compliance program.
Business partners acting on behalf of Runitas are also expected to conduct themselves in accordance with the principles described in this Code. Where appropriate, contractual arrangements may require suppliers, subcontractors and consultants to maintain equivalent ethical standards.

1.7 Compliance with Laws
Runitas Technologies conducts its operations in multiple jurisdictions and is committed to complying with all applicable laws, regulations and contractual obligations wherever it conducts business.
Compliance with the law represents the minimum standard expected from every employee. In many situations, the Company's own policies establish standards that exceed minimum legal requirements in order to protect customers, employees and the Company's long-term reputation.
Employees are expected to understand the legal requirements relevant to their responsibilities, including but not limited to:
• corporate and commercial law;
• competition and antitrust law;
• anti-bribery and anti-corruption legislation;
• public procurement regulations;
• labour and employment legislation;
• information security requirements;
• personal data protection laws;
• export control and trade compliance regulations;
• intellectual property legislation;
• environmental and occupational safety requirements.
Employees shall never deliberately disregard legal obligations in order to achieve commercial objectives.
Where local legal requirements differ from Company policies, employees should seek guidance from the Legal Department before taking action. If a conflict cannot be resolved, the stricter requirement shall generally apply unless otherwise advised by legal counsel.
Ignorance of the law is not considered an acceptable justification for non-compliance. Employees are therefore expected to complete all mandatory compliance training assigned by the Company and remain informed about legal developments relevant to their work.

1.8 Anti-Bribery and Anti-Corruption
Integrity forms the foundation of every business relationship established by Runitas Technologies. The Company maintains a zero-tolerance approach towards bribery, corruption and all forms of improper influence.
Employees shall never directly or indirectly offer, promise, authorize, request or accept anything of value for the purpose of obtaining an improper business advantage or influencing an official or commercial decision.
Bribery can take many forms. It is not limited to cash payments and may include:
• gifts of excessive value;
• luxury hospitality;
• travel or accommodation unrelated to legitimate business purposes;
• personal services;
• employment opportunities offered to relatives;
• charitable donations intended to influence a decision;
• political contributions made for improper purposes;
• hidden commissions or kickbacks.
Employees should exercise particular caution when dealing with government officials, procurement authorities, customs officers, licensing bodies and state-owned enterprises. Even the appearance of improper influence may seriously damage the reputation of both the employee and the Company.
Facilitation payments, regardless of their value, are prohibited unless there is an immediate threat to personal health or safety. Any such exceptional circumstance must be reported immediately to the Compliance Officer.
Third parties present particular compliance risks because their actions may expose Runitas to legal liability. Appropriate due diligence shall therefore be performed before engaging consultants, sales representatives, intermediaries, lobbyists or other business partners acting on behalf of the Company.
Employees must accurately record all business expenses. False invoices, misleading accounting entries, undisclosed commissions or off-the-books payments are strictly prohibited.
Practical Example
A sales consultant proposes paying an "expediting fee" to accelerate the approval of a government permit for an important customer project.
Although the payment appears relatively small and is described as a common local practice, making such a payment could constitute bribery under applicable laws and Company policy.
The employee should refuse the request, immediately notify the Compliance Officer and seek guidance before any further action is taken.

1.9 Competition and Antitrust
Runitas Technologies believes that fair competition promotes innovation, customer confidence and sustainable economic growth. The Company competes on the basis of quality, technical expertise, customer service and innovation rather than unlawful business practices.
Employees shall make commercial decisions independently and must never coordinate business strategies with competitors.
The following conduct is strictly prohibited:
• fixing prices or pricing methodologies;
• agreeing discounts or commercial terms;
• allocating customers or geographic territories;
• coordinating participation in public or private tenders;
• limiting production or service capacity;
• exchanging confidential commercial information;
• agreeing not to compete for specific projects;
• coordinating future pricing strategies.
Employees should also avoid informal discussions with competitors regarding commercially sensitive matters during conferences, trade association meetings, exhibitions or other industry events.
Particular caution should be exercised when communicating through emails, messaging applications or social media. Written communications may later be reviewed by regulators during investigations. Employees should therefore communicate professionally and avoid language that could be interpreted as suggesting anti-competitive behaviour.
Participation in legitimate professional associations is encouraged where such participation supports technological development or industry cooperation. However, discussions must remain limited to lawful technical, regulatory or educational topics.
Practical Example
During an international cybersecurity conference, a representative of another software company proposes discussing future pricing trends for managed security services "to better understand the market."
Although presented as an informal conversation, participating in such a discussion could violate competition laws.
The appropriate response is to politely decline the discussion, make it clear that Runitas does not engage in conversations concerning commercially sensitive information, leave the discussion if necessary and inform the Legal or Compliance function upon returning to the office.

1.10 Public Procurement
Runitas Technologies frequently participates in procurement activities conducted by public institutions and private sector organizations. The Company is committed to ensuring that every tender, proposal and procurement process is conducted honestly, independently and transparently.
Employees involved in procurement activities shall:
• prepare bids independently;
• protect confidential tender information;
• avoid all contact with competitors regarding active tenders;
• ensure that pricing reflects independent commercial judgement;
• comply with procurement laws and contractual requirements;
• maintain complete and accurate documentation supporting bid preparation.
Employees shall never attempt to obtain confidential competitor information through improper means or seek preferential treatment from procurement officials.
Any attempt by another participant to exchange bid information, coordinate pricing or influence procurement outcomes must be immediately rejected and reported to the Compliance Officer.

1.11 Conflicts of Interest
Employees are expected to make business decisions solely in the best interests of Runitas Technologies. Personal relationships, financial interests or outside activities must never influence professional judgement or create the appearance of improper influence.
A conflict of interest may arise whenever an employee's personal interests interfere, or appear to interfere, with the interests of the Company. Not every conflict is prohibited; however, every actual, potential or perceived conflict must be disclosed promptly so that it can be appropriately managed.
Examples of situations that may give rise to a conflict of interest include:
• having a financial interest in a supplier, customer or competitor;
• employing or supervising a close relative;
• participating in the selection of a company owned by a family member or close friend;
• accepting personal benefits that could influence business decisions;
• performing outside employment that competes with or interferes with Company responsibilities;
• using Company information or resources for personal business activities.
Employees must immediately disclose any potential conflict to their manager or the Compliance Officer. Where necessary, appropriate measures may include reassignment of responsibilities, exclusion from procurement decisions or other actions designed to protect the integrity of the decision-making process.
Practical Example
A project manager is responsible for selecting a subcontractor for a software development project. One of the bidders is a company partly owned by the manager's sibling.
Even if the bidder offers the most competitive proposal, the manager must disclose the relationship immediately and remove themselves from the evaluation process. Another qualified manager should oversee the selection to ensure fairness and transparency.

1.12 Gifts, Hospitality and Business Courtesies
Runitas recognizes that modest gifts and reasonable business hospitality may play a legitimate role in developing professional relationships. However, gifts or hospitality must never influence, or appear to influence, business decisions.
Employees may only offer or accept gifts when they:
• are lawful under applicable legislation;
• are reasonable in value;
• are infrequent;
• are openly given and accurately recorded where required;
• are not intended to obtain an improper business advantage.
The following are generally prohibited:
• cash or cash equivalents;
• personal loans;
• expensive luxury items;
• extravagant entertainment;
• gifts during active procurement or contract negotiations;
• gifts offered in exchange for favourable treatment.
Business meals and hospitality may be appropriate where they support legitimate business discussions and remain proportionate to the business relationship.
Employees should exercise additional caution when dealing with government officials because many jurisdictions prohibit even modest gifts.
Whenever uncertainty exists regarding the appropriateness of a gift or invitation, employees should consult the Compliance Officer before accepting or offering it.
Practical Example
Following the successful completion of a customer implementation project, a supplier offers an employee an all-expenses-paid weekend holiday for two people.
Although presented as a gesture of appreciation, the invitation exceeds acceptable business hospitality standards and may create the appearance of improper influence. The employee should politely decline the offer and notify their manager.

1.13 Gifts, Hospitality and Business Courtesies
Every employee shares responsibility for protecting the assets entrusted to Runitas Technologies. Company assets include not only physical equipment but also software, intellectual property, confidential information, financial resources and business reputation.
Assets shall be used solely for legitimate business purposes unless personal use has been specifically authorized.
Examples of Company assets include:
• laptop computers;
• mobile devices;
• software licenses;
• development environments;
• cloud infrastructure;
• customer documentation;
• proprietary methodologies;
• trademarks;
• databases;
• business records.
Employees shall take reasonable measures to prevent theft, misuse, unauthorized disclosure or damage to Company assets.
Company equipment should never be used for unlawful activities or activities that could expose Runitas to legal, cybersecurity or reputational risks.
Managers are responsible for ensuring that Company assets assigned to their teams are appropriately safeguarded and returned when employment or contractual relationships end.

1.14 Confidential Information
The success of Runitas depends upon the trust placed in the Company by its customers and business partners. Employees frequently have access to confidential information that must be protected throughout its lifecycle.
Confidential information may include:
• customer source code;
• software architecture;
• cybersecurity reports;
• penetration testing results;
• pricing models;
• financial information;
• contracts;
• product roadmaps;
• business strategies;
• technical documentation;
• employee information;
• supplier information.
Confidential information shall only be accessed by individuals who have a legitimate business need and appropriate authorization.
Employees must never disclose confidential information to unauthorized persons, including family members, friends or former colleagues.
Special care should be taken when working remotely, travelling or participating in online meetings to prevent unauthorized disclosure of sensitive information.
The obligation to protect confidential information continues after employment or contractual relationships with Runitas have ended.
Practical Example
A software developer receives a request from a former colleague asking for technical documentation prepared for an existing customer project.
Although the former colleague previously worked at Runitas, they are no longer authorized to access Company information. The employee must decline the request and notify their manager if any concerns exist regarding unauthorized disclosure.

1.15 Information Security and Responsible Use of Technology
Information security is a fundamental business responsibility at Runitas Technologies. Because the Company develops software, manages customer environments and processes sensitive information, every employee contributes to maintaining a secure operating environment.
Employees are expected to:
• protect passwords and authentication credentials;
• use multi-factor authentication where required;
• lock devices when unattended;
• install only authorized software;
• promptly apply security updates where applicable;
• report suspected cybersecurity incidents immediately;
• comply with secure development practices;
• protect customer environments from unauthorized access.
Employees shall not attempt to bypass security controls, disable monitoring systems or use unauthorized cloud services to store Company information.
Generative Artificial Intelligence tools may improve productivity but must be used responsibly. Employees shall never upload customer source code, confidential documentation, security configurations, personal data or other protected information into publicly available AI systems unless specifically authorized under Company policy.
Where AI-assisted software development tools are approved for use, employees remain fully responsible for verifying the accuracy, security and legal compliance of all generated content.
Protecting information is not solely the responsibility of the Information Security Department. It is a shared responsibility of every employee, contractor and business partner working with Runitas Technologies.

İş Ortaklarımız

client
client
client
client
client
client
client
client